TECHNOLOGY & CERTIFICATION EDITORIAL

AWS Cloud Practitioner: Choosing Core Cloud Services

A startup wants to launch an image-sharing application. One developer proposes a large virtual machine to run the web server, database, and image storage together. Another suggests managed services: object storage for pictures, a database designed for account records, a managed compute option for application logic, and a content delivery network for users around the world. Both approaches can produce a working prototype, but they create different scaling, maintenance, and failure responsibilities. Understanding the basic AWS service categories helps a business recognize those tradeoffs before focusing on implementation details.

The AWS Certified Cloud Practitioner CLF-C02 exam covers cloud technology and services as 34 percent of scored material, including compute, databases, networking, storage, analytics, and AI or machine learning categories. The expectation is conceptual service selection, not writing application code or designing complex production architectures. Strong candidates can explain what problem a service category addresses and which responsibilities remain with its customer.

Begin with compute requirements

Amazon EC2 provides configurable compute instances on which customers manage their operating systems and applications according to the service’s responsibility model. It may suit workloads requiring a particular operating environment or deep control. Container services and serverless approaches offer other ways to run workloads, each changing operational effort and scaling arrangements. The important distinction is not that one is always newer or better, but how much infrastructure the application team must operate.

AWS Lambda can run code in response to supported events without requiring the customer to manage servers in the traditional way. It can suit intermittent or event-driven tasks, with service-specific limits and cost considerations. A long-running, specialized application may require a different compute model. Compare execution behavior, scaling, latency, state management, and team skills rather than selecting serverless solely because its name sounds inexpensive.

Managed compute still requires thoughtful application development and permissions. An event-driven function with broad access to customer data can create the same type of confidentiality risk as an overly privileged virtual machine. The platform can manage infrastructure layers while the customer remains accountable for code, identities, input validation, and correct business behavior.

Distinguish storage from databases

Amazon S3 is object storage suited to files and data objects with service-specific durability, access, and lifecycle capabilities. Amazon EBS provides block storage commonly associated with supported EC2 workloads. Amazon EFS offers a managed shared file system for supported use cases. These storage types solve different access and organization problems; one is not a universal upgrade of another.

A website storing product images may benefit from S3, while a virtual machine running software that expects a block device may require EBS. Several application instances that need shared file access may use an appropriate file service. Cost and performance depend on storage class, throughput, request patterns, and access frequency. Knowing why an application reads the data is more valuable than memorizing a list of product names.

Databases organize structured or other application data with query and consistency behavior suited to their models. Amazon RDS supports managed relational databases, while DynamoDB is a NoSQL option with different access patterns and design considerations. A product catalog needing relational joins may suit one approach; a high-scale key-oriented application may suit another. Managed does not mean the customer no longer chooses schema, access permissions, or how application data is used.

Service selection becomes easier when the team begins with an access pattern rather than a name. A company archiving design files needs durability, access control, and predictable retrieval behavior; object storage may be a good conceptual fit. An order-management application needs structured transactions, relationships, and consistency guarantees, so a database is central to its work. A shared file workflow may require familiar directories and file-system semantics instead. Trying to use one service for every kind of data can produce unnecessary complexity even when that service is technically capable of storing bytes.

Availability requirements matter as much as the data shape. A customer-facing application can benefit from a managed database’s backup and replication options, but the organization still has to configure restoration goals, permissions, and the application connection behavior. Storing copies in several locations does not automatically prove that the application can recover coherently. Foundational candidates should recognize that resilience includes choosing the appropriate type of service and understanding how it responds when a component or location becomes unavailable.

A practical introductory exercise is to trace a single purchase from browser to database and confirmation. The web request needs a network entry point, processing capability, a durable transaction record, and perhaps asynchronous notifications to other systems. Each function suggests a class of cloud service; none requires memorizing every AWS product. This approach also exposes operational ownership: someone must monitor failures, control access, and determine what happens when the confirmation message cannot be delivered, even when AWS manages the physical systems.

Understand networking and content delivery

An Amazon VPC provides a logical network environment where customers design address ranges, subnets, routing, and security boundaries. Security groups and network access controls can help govern traffic according to their semantics. These settings are central to how workloads communicate, but application-layer authorization remains separately necessary. A resource inside a private subnet is not automatically safe if its identity permissions are too broad.

Elastic Load Balancing distributes supported application traffic among appropriate targets. Amazon Route 53 supports DNS-related needs, and Amazon CloudFront can deliver content through a global edge network for suitable use cases. The three are related to connecting users with applications, but they perform different tasks. DNS answers where to go, load distribution chooses healthy serving targets under relevant conditions, and content delivery can reduce latency or origin demand for eligible content.

Hybrid connectivity options such as AWS VPN and Direct Connect support connections between networks and AWS under different performance and service models. They do not automatically replace application security. A private circuit can carry unauthorized traffic if permissions are wrong, and a secure tunnel does not guarantee that the destination application is healthy.

Recognize messaging and application integration

An application with multiple components often benefits from asynchronous communication. Amazon SQS provides managed queues, Amazon SNS supports publish/subscribe messaging, and Amazon EventBridge can route events across supported sources and targets. They address different relationships between producers and consumers. A queue can buffer jobs for workers; a pub/sub topic can distribute notifications; event routing can select interested targets based on event details.

The CLF-C02 candidate does not need to implement complex messaging patterns, but should understand why decoupling matters. If a photo-upload endpoint waits for every thumbnail, email, and analytics task to finish, one slow component affects the user experience. Separating independent work can improve resilience when failures and retries are handled correctly. The architecture still needs business rules for duplicate work and incomplete processing.

API Gateway and related application services can support how clients and systems expose functionality, subject to configuration. Choosing a managed integration service can reduce undifferentiated infrastructure work, but access control, logging, and application design remain essential. Recognizing the service’s purpose is the foundation for deeper learning later.

Place analytics and AI in context

AWS includes services for data processing, warehousing, analytics, and machine learning. Their selection depends on whether the business needs periodic reporting, streaming insights, search, model training, or generative AI. These use cases should not be blurred into ‘AI services’ as if all workloads use the same technology. A data warehouse query and a foundation-model response have different input, cost, and governance characteristics.

For example, a retailer may consolidate transaction data for financial reporting before using any predictive model. The important work is ensuring consistent data definitions, accurate access, and reliable processing. A machine learning service cannot repair inaccurate customer records simply because it is managed. Analytics success depends on source quality and business questions, not only on the selected cloud offering.

Candidates can remember major service categories by the business task they support: storing data, running code, connecting networks, processing events, generating insights, and applying security controls. This is more durable than learning a product list without relationships.

Match regions and availability to business need

AWS Regions are geographically separate areas containing multiple Availability Zones, subject to service and region-specific infrastructure. Using more than one Availability Zone can help certain applications tolerate localized failures when they are architected accordingly. It does not make an application automatically resilient; databases, traffic routing, and application state must also be configured for the chosen continuity objective.

Geographic choice can affect latency, service availability, data residency, and cost. A workload serving customers in one country may have different priorities from a global streaming application. The company should consider local requirements before deploying customer records in an arbitrary region. Moving data among regions may create transfer charges and new compliance obligations.

Cloud architecture is a system of dependencies. A multi-zone web tier that depends on a single unavailable database remains vulnerable. Even at a foundational level, candidates should recognize why the Well-Architected Framework emphasizes reliability, security, and operational decisions alongside service selection.

Recognize shared work in managed services

Managed offerings may remove tasks such as physical maintenance or portions of patching, but they never make customer decisions disappear. Customers still control who can access their resources, which data is stored, and how applications behave. The division changes by service: responsibilities for an EC2 instance differ from those for a managed database or an event-driven function.

The move from ‘what is this service called?’ to ‘what problem does it solve and who operates what remains?’ is the key progression in cloud literacy. More advanced AWS Solutions Architect Associate study adds deeper architecture, but CLF-C02 candidates should already connect compute, data, networking, integration, and governance into a sensible business explanation.

Back to Insights
Explore what matters. Knowledge that goes beyond the exam.
Explore ExamTopics