What You Actually Need to Know Before Opening This Sheet

I printed out every AWS cheat sheet I could find before taking the exam. Half of them were useless. The ones that helped were the ones that forced me to actually think about the differences, not just memorize bullet points. This is a practical Aws Cloud Practitioner Exam Cheat Sheet compiled from things that actually showed up on the exam and things I've seen trip people up repeatedly. The AWS Cloud Practitioner (CLF-C02) covers fundamentals: what cloud computing is, core services across compute, storage, database, and networking, security and compliance at a conceptual level, pricing models, and the Shared Responsibility Model. You don't need hands-on experience, but you do need to know the difference between concepts that sound similar. I spent an entire weekend trying to understand how CloudFront actually handles caching versus how S3 handles versioning. They do completely different things. CloudFront caches content at edge locations globally. S3 versioning keeps multiple revisions of an object in the same bucket. I got two questions wrong on my practice exams because I conflated them, so I wrote them on opposite sides of the same index card and forced myself to recite the difference out loud until it stuck. Core Services Quick Reference:

Compute: EC2 gives you virtual machines where you manage the OS. Lambda runs code without servers, billed per millisecond. ECS runs Docker containers. EKS handles Kubernetes clusters. LightSail is the simplified alternative for small projects. If a question asks about running a custom application with full OS control, EC2 is your answer. If it's about event-driven code with no server management, Lambda. Storage: S3 stores objects. The tiering options matter. S3 Standard is for frequently accessed data. S3 Intelligent-Tiering moves objects automatically between access tiers at no extra monitoring cost. S3 Glacier Instant Retrieval and Glacier Deep Archive are for archival. S3 One Zone-IA stores data in a single availability zone only. EBS gives you block-level storage attached to EC2 instances. EFS provides shared file storage across multiple instances. A common exam trap: EBS volumes are tied to a single AZ and a single instance. If you need cross-AZ file sharing, the answer is EFS, not EBS. Database: RDS manages relational databases with automated patching and backups. DynamoDB is the NoSQL option with single-digit millisecond latency. Aurora is AWS's managed PostgreSQL and MySQL-compatible engine with higher availability than standard RDS. Redshift handles data warehousing. DocumentDB is MongoDB-compatible. The key distinction between RDS and Aurora is that Aurora separates storage from compute and replicates storage across three AZs automatically.

Networking: VPC is your isolated network. Subnets split your VPC. Route Tables direct traffic. Security Groups act as firewalls at the instance level and are stateful. Network ACLs operate at the subnet level and are stateless. This stateless detail comes up on the exam more often than you'd think. I remember one question where the correct answer required explicitly stating that NACL rules are evaluated in order by rule number, while Security Group rules are evaluated differently. Identity: IAM handles users, groups, roles, and policies. Root account access should be locked down immediately. MFA on the root account is non-negotiable. I once worked with a team that had over 40 IAM users with active access keys older than 90 days. The compliance audit flagged every single one. Setting an IAM password policy to rotate keys every 90 days takes ten minutes in the console. Security and Compliance: AWS Shield provides DDoS protection. Basic is free and covers simple attacks. Advanced adds cost protection. WAF filters web requests based on rules. KMS manages encryption keys. CloudTrail logs API activity. CloudWatch monitors resources and triggers alarms. Config tracks resource configurations over time. Inspector scans EC2 instances for vulnerabilities. GuardDuty finds threats using ML. The Shared Responsibility Model is fundamental here: AWS secures the cloud infrastructure, you secure what you put in it.

Get the Full Details

AWS Cloud Practitioner Certification Cheat Sheet PDF | Exam Study Guide ...
AWS Cloud Practitioner Certification Cheat Sheet PDF | Exam Study Guide ...

Pricing Models That Show Up on the Exam

On-Demand pricing charges by the second or hour with no commitment. This is the most expensive option but requires zero long-term planning. Reserved Instances commit to one or three years and save up to 72% compared to On-Demand. Savings Plans offer even more flexibility, especially Compute Savings Plans which apply to EC2, Lambda, and Fargate regardless of region, instance type, or tenancy. Spot Instances let you bid on unused capacity and can cut costs by up to 90%. They can be interrupted with two minutes of notice, so they're only suitable for fault-tolerant workloads. The exam loves questions about when to use Spot versus Reserved Instances. If the workload is flexible and interruptible, Spot. If it's predictable and long-running, Reserved. Compute Optimizer analyzes your AWS usage and recommends the right instance types. Cost Explorer tracks spending over time. Budgets let you set alerts when spending exceeds thresholds. AWS Trusted Advisor checks for cost optimization, security, and fault tolerance. Free tier includes a limited set of services for 12 months after sign-up. I always recommend new users configure Cost Explorer and set up at least one budget alert before launching anything substantial.

Cloud Adoption Framework and Well-Architected Pillars

The AWS Well-Architected Framework has six pillars: operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability. Each pillar has accompanying best practices. The Cloud Adoption Framework guides organizations through business case development, foundation building, migration planning, and adoption. I found that understanding the difference between these two frameworks helps with exam questions that ask about organizational readiness versus technical architecture decisions. The Operational Excellence pillar focuses on running and monitoring systems and continuously improving processes. The Reliability pillar covers fault tolerance and recovery. Performance Efficiency emphasizes using computing resources efficiently. Cost Optimization means running systems at the lowest price while delivering value. Sustainability addresses minimizing environmental impact. Security, as mentioned earlier, involves protecting information and systems.

Common Pitfalls I Saw in Practice Exams

Question 14 on the AWS official practice exam confused me because it asked about a service that provides a managed Kubernetes control plane. The answer is EKS, not ECS. ECS runs containers without Kubernetes. EKS runs Kubernetes. Two different abstractions. I marked ECS initially and lost the point. Another common mistake involves Data Transfer costs. Data transferred into AWS is generally free. Data transferred out to the internet costs money. Data transferred between AZs within the same region costs money, though less than cross-region transfer. VPN and Direct Connect reduce cross-AZ costs. I once saw a question where the correct answer involved choosing Direct Connect over the public internet for a scenario requiring consistent low-latency connectivity between an on-premises data center and a VPC. There's also confusion around Simple Storage Service versus Elastic Block Store. S3 is object storage accessed over HTTP/HTTPS. EBS is block storage attached to EC2. You can't mount an S3 bucket as a filesystem directly on an EC2 instance the way you mount an EBS volume. S3 Mountpoint exists as a workaround but it's not native block storage. Exam questions sometimes frame scenarios where someone needs a persistent disk that survives instance restarts, and the correct answer is EBS, not S3.

AWS Cloud Practitioner Exam (Cheat Sheet) | PDF
AWS Cloud Practitioner Exam (Cheat Sheet) | PDF

When This Cheat Sheet Won't Help You

If you rely solely on memorizing service names and their descriptions without understanding the underlying concepts, you will fail the scenario-based questions. AWS has moved toward situational questions that require you to pick the best solution among several plausible options. Knowing what S3 is doesn't help if you can't determine whether S3 Intelligent-Tiering or S3 Standard-IA is the better fit for a workload with unpredictable access patterns over six months. The cheat sheet below covers enough ground to pass with a 75 to 85 score if you study it actively. It won't get you a 95. For that, you need hands-on practice in the AWS Free Tier, even if it's just launching an EC2 instance and an S3 bucket and observing the console for a few hours. The familiarity with the AWS Management Console interface also reduces test-day anxiety significantly. Simplified Cheat Sheet:

EC2 = Virtual Servers. Choose t2.micro or t3.micro for free tier. Stop vs terminate: stopping preserves the EBS volume. Terminating deletes it. Instance types follow a naming convention: m5.large, c5.xlarge, r5.2xlarge. The letter indicates family, the suffix indicates size. S3 Buckets are globally unique. Objects are stored in buckets. Versioning adds a version ID to each object. Lifecycle policies move objects between tiers automatically. Replication copies objects across buckets, optionally across regions. VPC Defaults: a default VPC is created in each region with a public subnet in each AZ. You can delete it and create a custom VPC, but the default one is fine for most exam prep.

IAM Policies are JSON documents. They follow a specific structure with Effect, Action, Resource, and optionally Condition. Principal specifies who the policy applies to. Root causes most security issues because the root account has unrestricted access. Create an IAM user with admin privileges and MFA instead. CloudFormation uses YAML or JSON templates to provision infrastructure as code. This is different from the manual console approach and represents Infrastructure as Code. The exam may ask about IaC tools. CloudFormation is AWS-native. Terraform is multi-cloud but not AWS-owned. For the actual exam, bring a whiteboard or paper to sketch out architectures. I sketched VPC diagrams during the exam and it helped me eliminate wrong answers quickly. If you're confused between two options, drawing the architecture often reveals why one doesn't fit the requirements.

AWS Cloud Practitioner Exam Cheat Sheet | PDF | Cloud Computing ...
AWS Cloud Practitioner Exam Cheat Sheet | PDF | Cloud Computing ...

The exam itself is 65 questions, multiple choice and multiple response, 90 minutes. Passing score is around 700 out of 1000. Questions are adaptive in the sense that difficult questions may carry more weight, but there's no computer-adaptive testing in the traditional sense. Just straightforward scenario-based questions with four answer choices. I recommend taking the official AWS Cloud Practitioner practice exam first to identify your weak areas, then using this cheat sheet to fill gaps. The practice exam reveals more about what you don't know than any study guide will. I scored 78% on my first attempt at the official practice exam and 82% on my second. After that, I took the real exam and passed on the first try with a score I don't need to share.