Mastering AWS EC2
Amazon EC2 is one of the most frequently tested services on the AWS CLF-C02 exam. A solid understanding of instance types, purchasing options, and security group behavior will help you answer a large portion of exam questions with confidence.
---
What Is Amazon EC2
Amazon EC2 (Elastic Compute Cloud) is a service that lets you rent virtual servers, called instances, in the cloud. You can scale compute capacity up or down based on demand, making it well-suited for workloads with variable traffic patterns.
The key components that make up an EC2 instance are as follows.
| Component | Description | |-----------|-------------| | AMI | Template containing the OS and pre-configured software | | Instance Type | Combination of CPU, memory, and network performance | | Storage | EBS (persistent) or Instance Store (temporary) | | Security Group | Virtual firewall at the instance level | | User Data | Script that runs automatically on first boot |
The User Data script runs only once, on the very first start of an instance. This is a frequently tested detail, so make sure you remember it.
---
EC2 Instance Types
AWS offers instance types optimized for different workloads. Instance names follow a naming convention that combines type, generation, and size. For example, in "m5.xlarge", "m" stands for general purpose (type), "5" is the generation, and "xlarge" is the size.
| Type | Characteristics | Key Use Cases | |------|-----------------|---------------| | General Purpose | Balanced CPU, memory, network | Web servers, small databases, dev/test | | Compute Optimized | High-performance processors | Batch processing, ML inference, game servers | | Memory Optimized | Large memory capacity | In-memory caches (Redis), high-performance databases | | Storage Optimized | High sequential I/O, large storage | NoSQL databases, data warehousing |
Knowing the family prefix letters is also useful. "c" families are optimized for Compute, "r" for RAM (memory), and "i" for I/O (storage). The instance is available under the AWS Free Tier at 750 hours per month at no charge.
---
Security Groups
Security Groups act as virtual firewalls attached to EC2 instances, controlling inbound and outbound traffic. The default behavior is as follows.
| Direction | Default | |-----------|---------| | Inbound | Deny all (you must explicitly allow traffic) | | Outbound | Allow all |
Security Groups operate at the instance level, and a single instance can have multiple security groups applied simultaneously. They support Allow rules only — there is no explicit deny rule. For subnet-level access control, Network ACLs (NACLs) are used instead.
The following port numbers appear frequently on the exam.
| Port | Protocol | Purpose | |------|----------|---------| | 22 | TCP | SSH — remote access for Linux instances | | 80 | TCP | HTTP — web traffic | | 443 | TCP | HTTPS — secure web traffic | | 3389 | TCP | RDP — remote access for Windows instances | | 21 | TCP | FTP control | | 20 | TCP | FTP data transfer |
---
EC2 Purchasing Options
Comparison questions about purchasing options appear frequently on the CLF-C02 exam. It is important to understand each option by connecting it to a real-world usage scenario.
| Option | Discount | Commitment | Best For | |--------|----------|------------|----------| | On-Demand | None | None | Short-term, unpredictable workloads | | Reserved Instances | Up to 72% | 1 or 3 years | Steady-state apps (e.g., databases) | | Savings Plans | Up to 72% | 1 or 3 years | Flexible instance needs with usage commitment | | Spot Instances | Up to 90% | None | Fault-tolerant batch jobs, data analysis | | Dedicated Hosts | None | On-Demand or Reserved | Compliance, BYOL licensing | | Dedicated Instances | None | None | Hardware isolation without a full dedicated host | | Capacity Reservations | None | None | Guaranteed capacity in a specific AZ |
Comparing each option to a hotel reservation makes them easier to remember.
| Option | Analogy | |--------|---------| | On-Demand | Walk in anytime and pay full price | | Reserved Instances | Book 1 to 3 years in advance for a large discount | | Spot Instances | Bid on empty rooms — cheapest rate, but you can be asked to leave at any time | | Dedicated Hosts | Rent an entire wing of the hotel exclusively | | Dedicated Instances | A private room, but shared common areas | | Capacity Reservations | Hold a room whether or not you actually use it |
Key decision criteria when selecting a purchasing option:
Spot Instances offer the deepest discount (up to 90%), but they can be interrupted at any time. Never use Spot Instances for critical databases or production workloads. If you need BYOL (Bring Your Own License) licensing or regulatory compliance, use Dedicated Hosts. Dedicated Hosts are among the most expensive options.
Below is a price comparison for an m4.large instance in us-east-1.
| Option | Hourly | ~Monthly | |--------|--------|---------| | On-Demand | $0.096 | $69.12 | | Reserved (1 year) | $0.054 | $39.24 | | Savings Plans (1 year) | $0.058 | $41.76 | | Spot | $0.028 | $20.16 | | Dedicated Host | $0.120 | $86.40 |
---
Shared Responsibility Model for EC2
Understanding how responsibility is divided between AWS and the customer for EC2 is another common exam topic.
| AWS Responsibility | Customer Responsibility | |--------------------|-------------------------| | Physical server and data center security | OS patching and updates | | Network infrastructure and DDoS protection | Security group and VPC configuration | | Hypervisor security | Application-level security | | Infrastructure compliance | Data encryption management |
OS patching, security group configuration, and application security are always the customer's responsibility. You must be able to distinguish these clearly on the exam.
---
Key Summary
AMI: Base image for an instance (OS + software) User Data: Automation script that runs once on first boot Security Group: Instance-level virtual firewall (inbound denied by default) SSH (Port 22): Remote access for Linux EC2 RDP (Port 3389): Remote access for Windows EC2 t2.micro: Free Tier eligible instance
Before the exam, review the following items.
The 4 instance type categories (general purpose, compute, memory, storage) and their use cases The 7 purchasing options, their differences, and their ideal scenarios Security Group defaults (inbound deny, outbound allow) Port numbers 22, 80, 443, and 3389 Spot Instances: cheapest option but can be interrupted — not for critical workloads Dedicated Hosts: for BYOL licensing and compliance requirements