CLF-C02 Core Concepts: A Complete Guide From Cloud Computing Basics to the Shared Responsibility Model
This guide covers key topics from Domain 1 (Cloud Concepts) and Domain 2 (Security) of the AWS Cloud Practitioner (CLF-C02) exam.
---
What is Cloud Computing?
Cloud computing is the on-demand delivery of IT resources over the internet with pay-as-you-go pricing. AWS owns and maintains the physical hardware — you simply access servers, storage, databases, and more through a web console or API and pay only for what you use.
---
3 Cloud Deployment Models
Cloud deployments fall into three categories. The right choice depends on security requirements, cost structure, and operational flexibility.
| Type | Description | Key Characteristic | |------|-------------|--------------------| | Private Cloud | Used by a single organization | Full control, ideal for sensitive workloads | | Public Cloud | Owned by a third-party provider (e.g., AWS) | Cost-effective, highly scalable | | Hybrid Cloud | Mix of on-premises and public cloud | Flexibility, disaster recovery, data sovereignty |
Hybrid cloud keeps some servers on-premises while extending capabilities to the cloud. It is commonly adopted by enterprises with strict data residency requirements.
---
5 Characteristics of Cloud Computing
The following five characteristics come from the NIST definition and are essential knowledge for the exam.
On-demand self-service — Provision resources automatically without human intervention Broad network access — Access via standard network mechanisms from anywhere Resource pooling — Multi-tenant model shared across multiple customers Rapid elasticity — Scale up or down quickly based on demand Measured service — Usage is monitored and billed accordingly
---
6 Advantages of Cloud Computing
| Advantage | Description | |-----------|-------------| | Cost Savings | Pay only for what you use, no upfront investment | | Speed and Agility | Deploy services in minutes | | Scalability | Adjust resources on demand | | High Availability | Ensures business continuity | | Global Reach | Serve customers worldwide | | Security | Leverage AWS's robust security infrastructure |
---
Cloud Service Types: IaaS / PaaS / SaaS
Service types are categorized by how much of the stack you manage. Remembering the AWS example for each type is helpful for exam questions.
| Type | Description | AWS Example | Non-AWS Example | |------|-------------|-------------|-----------------| | IaaS | Virtualized infrastructure | EC2 | GCP, Azure, Linode | | PaaS | App development and runtime platform | Elastic Beanstalk | Heroku, Google App Engine | | SaaS | Ready-to-use software | AWS Chime | Gmail, Zoom, Dropbox |
A simple way to remember the distinction:
---
AWS Pricing: 3 Core Principles
AWS charges are based on three dimensions.
| Principle | Description | Example | |-----------|-------------|---------| | Compute | Pay for compute time used | EC2 instance hours, Lambda invocations | | Storage | Pay for data stored | S3 capacity, EBS volumes | | Data Transfer OUT | Pay for outbound data | Data Transfer IN is always free |
Data coming into AWS (IN) is always free; you only pay for data going out (OUT). This distinction is a frequently tested point.
---
AWS Global Infrastructure
Hierarchy
The AWS global infrastructure is organized into three layers.
Regions
A region is a geographically isolated cluster of AWS data centers. There are 30+ regions worldwide. When selecting a region, consider the following four criteria.
| Criteria | Description | |----------|-------------| | Latency | Choose the region closest to your users | | Compliance | Meet data residency laws such as GDPR | | Service Availability | Verify your required services are available there | | Pricing | Prices vary by region |
Availability Zones (AZs)
Availability Zones are physically separate data center groups within a region. Each AZ has independent power, cooling, and networking. AZs are connected via high-bandwidth, ultra-low-latency links and have no single point of failure. For high availability, always deploy across at least two AZs.
Edge Locations (Points of Presence)
With 400+ locations worldwide, Edge Locations are used by Amazon CloudFront (CDN) and AWS Global Accelerator to deliver content with low latency to end users.
Edge Locations, AZs, and Regions serve different purposes at different layers of the hierarchy. Knowing how to distinguish them is a common exam requirement.
---
AWS Shared Responsibility Model
The Shared Responsibility Model is one of the most heavily tested topics on the exam. Security and compliance is a shared responsibility between AWS and the customer.
The core principle is:
AWS Responsibilities
Physical data center security (access control, environmental controls) Hypervisor, host OS, network infrastructure Global network operations including DDoS protection
Customer Responsibilities
Data encryption (in transit and at rest) IAM configuration (users, roles, policies) OS and application patching Security group and NACL rules Regulatory compliance
Responsibility Comparison by Service
| Service | AWS Responsibility | Customer Responsibility | |---------|-------------------|------------------------| | IaaS (EC2) | Physical infra, hypervisor | OS security, patching, data, network config | | PaaS (RDS) | DB engine, backups, patching | Data encryption, DB access control, IAM | | SaaS (S3) | Underlying infrastructure | Bucket policies, permissions, data lifecycle |
The more managed a service is (such as RDS or Lambda), the more AWS takes on responsibility. The more control you retain (as with EC2), the more responsibility falls to you.
---
Final Concept Summary
| Concept | Key Takeaway | |---------|-------------| | Deployment Models | Private / Public / Hybrid | | Service Types | IaaS (EC2) / PaaS (Beanstalk) / SaaS (Chime) | | Pricing | Compute / Storage / Data Transfer OUT | | Global Infrastructure | Region > AZ > Edge Location | | AZ Feature | Independent power, cooling, and network — no single point of failure | | Shared Responsibility | AWS = OF the Cloud / Customer = IN the Cloud |
A solid grasp of these foundational concepts makes every other domain significantly easier to navigate.