AWS Certified Cloud Practitioner (CLF-C02) Vocabulary Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/88

flashcard set

Earn XP

Description and Tags

Vocabulary terms and definitions extracted directly from the AWS Certified Cloud Practitioner (CLF-C02) exam preparation notes.

Last updated 8:58 PM on 9/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

89 Terms

1
New cards

AWS WAF

A web application firewall that protects OSI Layer 7 (the application layer) by inspecting HTTP/HTTPS requests.

2
New cards

AWS Shield

A managed service providing protection against distributed denial-of-service (DDoS) attacks.

3
New cards

AWS Shield Standard

A DDoS protection tier automatically available to all AWS customers at no extra charge.

4
New cards

AWS Shield Advanced

A paid DDoS protection tier offering enhanced detection, mitigation, visibility, and response capabilities.

5
New cards

Amazon Macie

A security service that identifies sensitive data in Amazon S3, such as personally identifiable information (PII).

6
New cards

Amazon Inspector

An automated security assessment service that assesses software vulnerabilities and unintended network exposure in supported workloads.

7
New cards

Amazon GuardDuty

A threat detection service that continuously detects suspicious or malicious activity using AWS data sources.

8
New cards

AWS Artifact

A portal providing on-demand access to AWS compliance reports, certifications, and agreements.

9
New cards

AWS Secrets Manager

A service used to store and manage secrets such as database credentials, API keys, and other sensitive credentials.

10
New cards

AWS KMS

AWS Key Management Service, used for creating and controlling cryptographic keys to encrypt data.

11
New cards

Customer Managed KMS Key

A KMS key created and configured by the customer, giving them the most direct control over key permissions and rotation.

12
New cards

Client-Side Encryption

The process of encrypting data locally before it is sent to an AWS service such as Amazon S3.

13
New cards

Server-Side Encryption

The process where an AWS service encrypts data after receiving it and before storing it.

14
New cards

Security OF the Cloud

AWS's responsibility under the shared responsibility model, covering data centres, physical infrastructure, and underlying host systems.

15
New cards

Security IN the Cloud

The customer's responsibility under the shared responsibility model, covering IAM permissions, customer data access, and guest OS patching.

16
New cards

Principle of Least Privilege

The security best practice of granting only the permissions required to perform the necessary task.

17
New cards

AWS CloudTrail

A service that records API calls and account activity for auditing and governance.

18
New cards

AWS Config

A service that records resource configuration changes and evaluates configuration compliance against desired rules.

19
New cards

Amazon CloudWatch

A monitoring and management service that tracks performance metrics, logs, and operational alarms.

20
New cards

AWS Pricing Calculator

A web-based planning tool used to estimate AWS costs before deploying resources.

21
New cards

AWS Cost Explorer

A service used to visualize, analyze, and track historical AWS cost and usage over time.

22
New cards

AWS Budgets

A service that allows setting custom spending targets and alerts when cost, usage, or reservation targets cross thresholds.

23
New cards

AWS Cost and Usage Report (CUR)

The most comprehensive and detailed set of AWS cost and usage data available.

24
New cards

AWS Compute Optimizer

A service that recommends right-sized resource configurations using machine learning analysis of historical utilization data.

25
New cards

AWS Trusted Advisor

An automated tool giving best-practice recommendations across cost optimization, security, fault tolerance, performance, and service limits.

26
New cards

EC2 On-Demand Instances

Compute instances paid for by the second or hour with no long-term commitment, suitable for short-term, unpredictable, or flexible workloads.

27
New cards

EC2 Spot Instances

Unused EC2 compute capacity available at up to 90% discount compared to On-Demand, ideal for fault-tolerant, interruption-flexible workloads.

28
New cards

EC2 Reserved Instance

A billing discount commitment model for predictable EC2 usage providing a significant discount over On-Demand pricing.

29
New cards

Savings Plans

A flexible commitment-based pricing model offering lower compute costs across EC2, Fargate, and Lambda in exchange for a consistent hourly usage commitment.

30
New cards

Amazon EC2 Dedicated Host

A physical server dedicated fully to one customer, allowing use of eligible server-bound software licenses and compliance adherence.

31
New cards

Economies of Scale

The economic principle where AWS passes on savings to customers in the form of lower pay-as-you-go prices due to aggregate usage from hundreds of thousands of customers.

32
New cards

AWS Organizations

An account management service enabling consolidated billing, centralized control, and sharing of eligible volume discounts across multiple AWS accounts.

33
New cards

Amazon EBS

Persistent block storage designed primarily for EC2 workloads, bound to a single Availability Zone.

34
New cards

Amazon EFS

Managed, elastic file storage using the NFS protocol that can be accessed concurrently by multiple EC2 instances across multiple Availability Zones.

35
New cards

Amazon S3

A highly scalable object storage service accessed via HTTP/HTTPS web APIs.

36
New cards

EC2 Instance Store

Temporary block storage physically attached to the host computer, offering very low latency but losing all data when the instance terminates.

37
New cards

S3 Standard

An Amazon S3 object storage class designed for high availability and frequently accessed data.

38
New cards

S3 Standard-Infrequent Access (S3 Standard-IA)

An S3 storage class for data that is accessed less frequently but requires rapid millisecond access when needed.

39
New cards

S3 Intelligent-Tiering

An S3 storage class that automatically moves objects between access tiers based on changing access patterns to optimize costs without operational overhead.

40
New cards

S3 Glacier Deep Archive

The lowest-cost S3 storage class designed for long-term archive data with retrieval times ranging from hours to 12 hours.

41
New cards

S3 Glacier Instant Retrieval

An S3 archive storage class offering the lowest-cost storage for long-lived archive data that requires immediate millisecond retrieval.

42
New cards

AWS Storage Gateway

A hybrid storage service that connects on-premises applications to AWS cloud storage.

43
New cards

Amazon VPC

A logically isolated virtual network section in the AWS cloud dedicated to a single AWS account.

44
New cards

Security Group

A stateful virtual firewall operating at the network interface level (e.g., EC2) containing allow rules only.

45
New cards

Network ACL

A stateless subnet-level firewall that evaluates inbound and outbound traffic using ordered allow and deny rules.

46
New cards

Internet Gateway

A VPC component allowing bidirectional communication between resources inside a public subnet and the public internet.

47
New cards

NAT Gateway

An AWS-managed service allowing resources in private subnets to initiate outbound internet connections without receiving unsolicited inbound connections.

48
New cards

AWS Direct Connect

A cloud service solution that establishes a dedicated private network connection from an on-premises facility directly to AWS.

49
New cards

AWS Site-to-Site VPN

An encrypted connection linking an on-premises network to an AWS VPC over the public internet.

50
New cards

VPC Gateway Endpoints

Specialized VPC endpoints supported specifically for routing private traffic to Amazon S3 and Amazon DynamoDB without needing an internet gateway.

51
New cards

AWS PrivateLink

A technology powering interface endpoints that provides private connectivity between VPCs and AWS services without traversing the public internet.

52
New cards

AWS Transit Gateway

A network transit hub used to simplify connectivity between multiple Amazon VPCs and on-premises networks.

53
New cards

Elastic Load Balancing (ELB)

A service that automatically distributes incoming application traffic across multiple target instances, containers, or IP addresses.

54
New cards

Amazon Route 53

A highly available and scalable Domain Name System (DNS) web service designed for routing user requests to internet applications.

55
New cards

Weighted Routing Policy

A Route 53 policy that sends defined proportions of traffic to different resources based on designated relative weights.

56
New cards

Latency-Based Routing Policy

A Route 53 policy that routes end-user requests to the AWS region that provides the lowest network latency.

57
New cards

Failover Routing Policy

A Route 53 policy configured for active-passive disaster recovery to route traffic to a secondary site if the primary resource becomes unhealthy.

58
New cards

Amazon CloudFront

A fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs globally using edge locations.

59
New cards

IaaS

Infrastructure as a Service; the cloud service model providing raw compute, networking, and storage capabilities (e.g., Amazon EC2).

60
New cards

AWS Lambda

A event-driven serverless compute service that runs code automatically without provisioning or managing underlying servers.

61
New cards

AWS Elastic Beanstalk

A Platform as a Service (PaaS) offering that simplifies web application deployment by automatically handling infrastructure setup, load balancing, and scaling.

62
New cards

EC2 Auto Scaling

A feature that automatically adds or removes EC2 instances to maintain predictable performance and match workload demand.

63
New cards

Amazon SQS

Amazon Simple Queue Service; a fully managed message queuing service for decoupling and scaling distributed application components.

64
New cards

Amazon SNS

Amazon Simple Notification Service; a managed publish/subscribe messaging service for high-throughput, fan-out event notifications.

65
New cards

AWS X-Ray

A service that helps developers analyze, trace, and debug distributed applications and microservices.

66
New cards

AWS Fargate

A serverless compute engine for containers that works with both Amazon ECS and Amazon EKS so you don't manage instances.

67
New cards

Amazon ECS

Amazon Elastic Container Service; AWS's native container orchestration service for running and scaling containerized applications.

68
New cards

Amazon EKS

Amazon Elastic Kubernetes Service; a managed service used to run Kubernetes container environments on AWS.

69
New cards

AWS CloudFormation

An Infrastructure as Code (IaC) service allowing users to model and provision AWS resources consistently using JSON or YAML templates.

70
New cards

Agility

The ability to rapidly develop, test, and launch resources and applications in the cloud with minimal friction.

71
New cards

Elasticity

The ability to automatically and dynamically add or remove cloud resources to match real-time demand changes.

72
New cards

Scalability

A system's capability to handle growth or reduction in workload demand by adjusting capacity.

73
New cards

Horizontal Scaling

Scaling out by adding more discrete compute instances or nodes to share workload capacity and improve fault tolerance.

74
New cards

Vertical Scaling

Scaling up by adding more CPU, RAM, or storage capacity to an existing server or instance.

75
New cards

Availability Zone

One or more discrete data centres with independent power, cooling, and networking within an AWS Region.

76
New cards

Rehost

A cloud migration strategy commonly called 'lift and shift', moving applications to the cloud without architectural modification.

77
New cards

Replatform

A cloud migration strategy moving workloads to the cloud with minor optimizations ('lift, tinker, and shift') without core redesign.

78
New cards

Refactor / Re-architect

A cloud migration strategy involving significant architectural redesign to fully adopt cloud-native features and capabilities.

79
New cards

Repurchase

A cloud migration strategy that replaces an existing application with a different product or commercial Software-as-a-Service (SaaS) solution.

80
New cards

Amazon RDS

Amazon Relational Database Service; a managed relational database service supporting multiple SQL engine types.

81
New cards

RDS Multi-AZ Deployment

A high-availability feature for Amazon RDS providing synchronous standby replication in a separate Availability Zone with automatic failover.

82
New cards

RDS Read Replica

An asynchronous copy of a primary RDS database instance used to scale read-heavy database workloads.

83
New cards

Amazon DynamoDB

A fully managed, serverless NoSQL database service delivering single-digit millisecond latency for key-value and document workloads.

84
New cards

DynamoDB Global Tables

A fully managed feature that provides active-active multi-Region replication for DynamoDB databases.

85
New cards

Amazon Redshift

A managed petabyte-scale cloud data warehouse optimized for complex analytical SQL processing.

86
New cards

Amazon Transcribe

An AWS AI service that uses automatic speech recognition (ASR) to convert audio speech into text.

87
New cards

Amazon Polly

An AWS AI service that converts written text into lifelike spoken audio.

88
New cards

Amazon Translate

An AWS AI service providing neural machine translation to convert text between languages.

89
New cards

AWS CAF Platform Perspective

A perspective within the AWS Cloud Adoption Framework focused on building scalable, enterprise-grade cloud platforms and accelerating delivery capabilities.