โ† All courses
AWS ยท Cloud ยท Fundamental level

Learn AWS by actually building on it.

From zero to the AWS Cloud Practitioner (CLF-C02) exam: core services, IAM, billing and the thinking behind production cloud. Read the notes, then move to the hands-on labs.

Start learning See the labs
Level
Fundamental
Exam
AWS CLF-C02
Lessons
27 notes
Labs
8 guided
Price
Free to read
Your progress0%
The curriculum

Read, do, complete, move on.

Open a lesson, read the notes, then mark it complete. Your progress is saved on this device.

00

Orientation & votre compte AWS sรฉcurisรฉ

Dรฉmarrage
โ€บWhat this certification proves, who it is for, and how the exam worksโœ“

The AWS Certified Cloud Practitioner (CLF-C02) proves you understand the cloud and AWS well enough to talk about it, make sensible decisions, and support a team using AWS. It is the foundation certification: no coding, no architecture design, just a solid, broad understanding.

Who it is for

  • Students and career-switchers who want a recognised first cloud credential.
  • Business owners and non-technical staff who work alongside cloud.
  • Developers and IT people who want the fundamentals right before the deeper certifications.

How the exam works

  • 65 questions, multiple choice and multiple response, 90 minutes.
  • Pass mark is 700 out of 1000 (a scaled score, so it is not simply 70% of questions).
  • Costs 100 USD, taken online or at a test centre.
Think of it like a driving theory test. You are not asked to build the car or race it. You are asked to prove you understand the rules of the road well enough to be trusted on it.
โ€บCreate your AWS account, turn on MFA, and lock the root userโœ“

Your first real task. When you create an AWS account, the email you sign up with becomes the root user โ€” it can do anything, including close the account and spend money. So the very first thing we do is protect it.

  • Create the account at aws.amazon.com (you need an email and a card; the Free Tier means you will not be charged for the labs in this course if you follow the steps).
  • Turn on MFA (multi-factor authentication) on the root user โ€” a second code from your phone, so a stolen password alone is useless.
  • Then stop using root for daily work. We create a normal user for that in Module 2.
Why this matters here: a leaked AWS root login with no MFA is one of the fastest ways to lose money in the cloud. Treat it like the master key to your whole shop.
โ€บSet a billing alarm on day one, so you never get a surprise billโœ“

Before you launch anything, set up a budget alert. This emails you the moment your spending crosses an amount you choose โ€” even a few hundred FCFA worth of dollars.

  • Open Billing โ†’ Budgets, create a monthly budget, set a small limit, add your email.
  • Also enable the free Free Tier usage alerts.
For us especially: most of us do not have a large dollar cushion on the card. A budget alarm is the seatbelt that lets you practise freely without fear. We set it on day one, every time.
โ€บA tour of the console, Regions, and how to find anythingโœ“

The AWS Management Console is the website where you click to use AWS. Two things to notice immediately:

  • The Region selector (top right). AWS runs in many Regions around the world; what you create in one Region is not visible in another. Pick one close to your users for speed and keep to it.
  • The search bar at the top. AWS has hundreds of services โ€” do not memorise menus, just type the name (S3, EC2) and go.
Example: if most of your users are in Cameroon or West/Central Africa, a European Region like Europe (Paris) often gives lower latency than a US one. We will come back to Region choice properly in Module 2.
01

Concepts du cloud

Fondations
โ€บWhat the cloud really is, and the six advantagesโœ“

Cloud computing is renting computing โ€” servers, storage, databases โ€” over the internet, and paying only for what you use, instead of buying and running your own machines.

The six advantages AWS teaches (know these for the exam)

  • Trade capital expense for variable expense โ€” pay as you go instead of buying servers upfront.
  • Benefit from massive economies of scale โ€” AWS buys at huge scale, so prices fall.
  • Stop guessing capacity โ€” scale up or down on demand.
  • Increase speed and agility โ€” a new server in minutes, not weeks.
  • Stop spending money running data centres.
  • Go global in minutes.
Example: a Dschang shop launches an online store. On-premises, they would buy a server and hope it is enough. On the cloud, they start tiny, pay almost nothing, and if a promotion goes viral they scale up for a day and back down after โ€” paying only for that day.
โ€บDeployment models, and service models (IaaS, PaaS, SaaS)โœ“

Deployment models = where it runs: cloud (all on AWS), on-premises (your own machines), or hybrid (a mix).

More controlLess to manageIaaSYou manageVMs, OS, runtime, appProvider managesPaaSYou manageJust your appProvider managesSaaSYou manageNothing โ€” just use itProvider manages
IaaS โ†’ PaaS โ†’ SaaS: how much you manage

Service models = how much AWS manages for you:

  • IaaS (Infrastructure as a Service) โ€” you rent raw servers and manage the rest. Example: EC2.
  • PaaS (Platform as a Service) โ€” AWS manages the servers, you just deploy your app. Example: Elastic Beanstalk.
  • SaaS (Software as a Service) โ€” finished software you just use. Example: Gmail, or AWS's own managed tools.
Analogy (pizza): IaaS is buying ingredients and cooking at home; PaaS is takeaway you reheat; SaaS is eating at the restaurant. The more "as a service", the less you manage.
โ€บGlobal infrastructure: Regions, Availability Zones, edge locationsโœ“

AWS is physically organised in three layers:

Region (e.g. Europe)AZ 1data centreAZ 2data centreAZ 3data centrespread across zones = survive one failingUserscloser = fasterPick region near users
Regions, zones & latency
  • Regions โ€” geographic areas (e.g. Europe-Paris, US-East). You choose which Region your resources live in.
  • Availability Zones (AZs) โ€” separate data centres inside a Region. Spreading across AZs keeps your app running if one data centre fails.
  • Edge locations โ€” many more small sites worldwide that cache content close to users (used by CloudFront).
Why it matters for us: there is no AWS Region inside Cameroon yet, so Region choice (latency + data-residency law) is a real decision for African projects. Edge locations still bring content closer to local users.
โ€บThe Well-Architected Framework, in plain languageโœ“

AWS's checklist for building good systems. Six pillars:

  • Operational excellence โ€” run and monitor well.
  • Security โ€” protect data and systems.
  • Reliability โ€” recover from failure.
  • Performance efficiency โ€” use the right resources.
  • Cost optimisation โ€” avoid waste.
  • Sustainability โ€” minimise environmental impact.

For the exam you need to recognise the pillars and what each is about, not design against them.

โ€บCloud economics and the migration mindset (the seven Rs)โœ“

Moving to the cloud has a vocabulary. The seven Rs are the strategies for migrating an existing system: Rehost (lift-and-shift), Replatform (small tweaks), Repurchase (switch to SaaS), Refactor (rebuild for cloud), Retire (switch off), Retain (keep as is), Relocate.

On economics, know CapEx vs OpEx (big upfront purchase vs pay-as-you-go) and TCO (total cost of ownership โ€” the real cost including power, staff, space, not just the server price).

02

Sรฉcuritรฉ & conformitรฉ

Confiance
โ€บThe Shared Responsibility Model: what AWS secures, and what you mustโœ“

The single most important security idea in AWS. Security is shared:

YOU secure IN the cloudYour dataAccounts & accessConfigurationAWS/cloud secures OFHardwareGlobal networkData centres
The shared responsibility model
  • AWS secures the cloud itself โ€” the buildings, hardware, and the services they run ("security of the cloud").
  • You secure what you put in it โ€” your data, who can access it, your settings ("security in the cloud").

The split shifts by service: with a raw server (EC2) you manage a lot; with a managed service (like S3 or Lambda) AWS manages more, but you always own your data and access control.

Example: AWS guarding the data centre does not help if you leave a storage bucket open to the public. The lock on the warehouse is AWS's job; locking your own crate inside it is yours.
โ€บIAM done right: root vs users, groups, roles, policies, least privilegeโœ“

IAM (Identity and Access Management) controls who can do what in your account.

Too much accessLeast privilegeAppALL resources(risky)App1 bucketread only
Least privilege: grant only what is needed
  • Root user โ€” all-powerful; use it almost never.
  • IAM users โ€” a login per person.
  • Groups โ€” bundle users and give permissions once (e.g. a "Developers" group).
  • Roles โ€” temporary permissions a service or user can assume, with no password. The safe modern way.
  • Policies โ€” the documents that say what is allowed.

Least privilege: give the smallest permission needed, nothing more. And turn on MFA for everyone.

โ€บThe security toolbox: Shield, WAF, GuardDuty, Inspector, Macie, KMS, Secrets Managerโœ“

Know what each one is for (not how to configure it):

  • Shield โ€” protects against DDoS (flood) attacks.
  • WAF โ€” web application firewall, filters bad web requests.
  • GuardDuty โ€” watches for threats/suspicious activity.
  • Inspector โ€” scans for vulnerabilities.
  • Macie โ€” finds sensitive data (like personal info) in S3.
  • KMS โ€” manages encryption keys.
  • Secrets Manager โ€” stores passwords/API keys safely.
Exam tip: questions often describe a problem ("flood of traffic", "find credit-card numbers in storage") and ask which service. Match the problem to the tool.
โ€บSeeing what happened: CloudTrail, Config, Security Hub, Trusted Advisorโœ“
  • CloudTrail โ€” records who did what in your account (an audit log).
  • Config โ€” records how your resources are set up and tracks changes.
  • Security Hub โ€” one dashboard of your security findings.
  • Trusted Advisor โ€” automatic recommendations on cost, security, and limits.
Remember the pair: CloudTrail = who did what (actions); CloudWatch (next module) = how things are performing (metrics). Exams love to test this difference.
โ€บCompliance and data residency, and why Region choice matters in Africaโœ“

AWS Artifact is where you download AWS's compliance reports (SOC, ISO, PCI, etc.). Compliance programs prove AWS meets various standards.

Data residency means where your data physically lives โ€” and that is decided by your Region choice.

For Cameroon/Africa: Cameroon's data-protection law (Law No. 2024/017) and client contracts may require data to stay in certain places or be handled a certain way. Because the Region decides physical location, choosing a Region is a legal decision, not only a speed one.
03

Technologies & services de base

La boรฎte ร  outils
โ€บWays in: the Console, CLI, SDKs, and a first look at infrastructure as codeโœ“

Four ways to tell AWS what to do:

  • Console โ€” click in the website. Best for learning.
  • CLI โ€” type commands in a terminal. Fast and scriptable.
  • SDKs โ€” call AWS from your code (Python, JavaScript, etc.).
  • Infrastructure as Code (CloudFormation) โ€” describe your whole setup in a file so it can be rebuilt identically, any time.
โ€บCompute: EC2, Auto Scaling, load balancing, Lambda, and containersโœ“
More controlLess managementVM / EC2you manage the serverContainerspackaged appServerlessjust your function
The compute ladder
  • EC2 โ€” virtual servers you rent by the second/hour.
  • Auto Scaling โ€” adds/removes servers automatically with demand.
  • Elastic Load Balancing โ€” spreads traffic across servers.
  • Lambda โ€” run code with no server to manage, pay per run. "Serverless".
  • Containers (ECS/EKS) โ€” package an app with everything it needs, run it anywhere.
Example: a results-checking site for a school spikes the day grades drop. Auto Scaling + a load balancer handle the rush, then shrink back so you are not paying for idle servers the rest of the term.
โ€บStorage: S3, EBS, EFS, and the Glacier archive tiersโœ“
Match storage class to how often you read itHot / Standardused oftenCool / Nearlinenow & thenCold / Archiverarely, cheapLifecycle rule moves data automatically โ†’ saves money
Storage tiers & lifecycle
  • S3 โ€” object storage for files (images, videos, backups, website files). Extremely durable, cheap, scales endlessly.
  • EBS โ€” a hard drive attached to one EC2 server.
  • EFS โ€” a shared file system many servers can use at once.
  • Glacier โ€” very cheap storage for archives you rarely touch.
Example: a media team stores terabytes of event videos in S3, moves last year's footage to Glacier to cut cost, and serves the current ones fast through CloudFront.
โ€บDatabases: RDS, Aurora, and DynamoDB, and when to pick whichโœ“
  • RDS โ€” managed traditional (relational/SQL) databases: MySQL, PostgreSQL, etc.
  • Aurora โ€” AWS's faster, cloud-native relational database.
  • DynamoDB โ€” a managed NoSQL database for huge scale and speed.

Rule of thumb: structured data with relationships โ†’ relational (RDS/Aurora); massive, simple, fast lookups โ†’ DynamoDB.

โ€บNetworking & delivery: VPC, subnets, security groups, Route 53, CloudFrontโœ“
  • VPC โ€” your own private network inside AWS.
  • Subnets โ€” sections of that network (public vs private).
  • Security groups โ€” firewalls around your servers.
  • Route 53 โ€” AWS's DNS (turns a domain name into an address).
  • CloudFront โ€” the CDN that caches content at edge locations close to users for speed.
For African users: CloudFront is how you make a site feel fast locally even when the servers are in Europe โ€” the content is cached nearer the visitor.
โ€บIntegration & monitoring: SNS, SQS, EventBridge, CloudWatchโœ“
  • SNS โ€” send notifications/messages (e.g. email/SMS alerts).
  • SQS โ€” a queue that lets parts of a system talk without waiting on each other.
  • EventBridge โ€” routes events between services.
  • CloudWatch โ€” metrics, logs and alarms: how your systems are performing.

SQS/SNS/EventBridge "decouple" systems so one slow part does not break the rest.

04

Facturation, tarification & support

Dรฉpenser avec sagesse
โ€บPricing models: On-Demand, Reserved, Savings Plans, Spot, and the Free Tierโœ“
  • On-Demand โ€” pay as you go, no commitment. Flexible, most expensive per hour.
  • Reserved Instances / Savings Plans โ€” commit to 1โ€“3 years for a big discount.
  • Spot โ€” use spare capacity very cheaply, but AWS can reclaim it. Good for flexible work.
  • Free Tier โ€” a set of services free for 12 months or always, within limits. This is what makes the labs in this course free.
โ€บSeeing and forecasting spend: Pricing Calculator, Cost Explorer, Budgetsโœ“
  • Pricing Calculator โ€” estimate a bill before you build.
  • Cost Explorer โ€” see and analyse what you have actually spent.
  • Budgets โ€” the alerts you set in Module 0.

Use tags (labels) on resources so you can see cost by project or client.

โ€บAccounts at scale: Organizations and consolidated billingโœ“

AWS Organizations lets you manage many AWS accounts together (e.g. one per client or project) under one roof, with consolidated billing (one bill, shared volume discounts) and central rules.

โ€บSupport plans and where to get helpโœ“

AWS support tiers: Basic (free), Developer, Business, Enterprise โ€” more money buys faster response and, higher up, a dedicated contact (a TAM). Free help: documentation, re:Post (Q&A), and Trusted Advisor.

05

Prรชt pour lโ€™examen

Rรฉussir
โ€บA domain-by-domain review built around the exam's own weightingโœ“

Spend your revision time where the marks are: Cloud technology & services (34%) and Security & compliance (30%) together are nearly two-thirds of the exam. Cloud concepts is 24%, Billing & support 12%. Review in that order.

โ€บHow to read a tricky question and spot the keyword that gives the answerโœ“

Most questions hide the answer in one keyword. "Flood of traffic" โ†’ Shield. "Who deleted this?" โ†’ CloudTrail. "No server to manage" โ†’ Lambda. "Cheapest for rarely-used archives" โ†’ Glacier. Read the question for the requirement word, then match the service.

โ€บTwo full-length, timed practice exams with explanationsโœ“

Sit two timed 65-question mocks under real conditions. Review every question you got wrong and every one you guessed. The practice exams and the hands-on labs are in the Pro track โ€” create a free account to unlock them and save your results.

Ready to practise for real? Create a free account to run the 8 labs, take the mock exams and keep your progress.

Create free account
Where you actually build

Eight labs on real AWS

Reading is free and open. The labs are where it becomes real, so they live behind a free account, which keeps your progress and gives you a certificate.

Create a free Kaevor account to launch any lab and earn your certificate. One account, all your courses.

Create free account
๐Ÿ”’

Lab 1 โ€” Secure your root & create a power user

MFA on root, an IAM group with a policy, a real working user, and a budget alert.

IAM
๐Ÿ”’

Lab 2 โ€” Host a website on S3

Stand up object storage and serve a real static site from it.

S3
๐Ÿ”’

Lab 3 โ€” Launch your first EC2 web server

Spin up a free-tier server, open the right ports, reach your page, then tear it down.

EC2
๐Ÿ”’

Lab 4 โ€” Put S3 behind CloudFront

Deliver your site worldwide through the CDN and lock the bucket private.

CloudFront
๐Ÿ”’

Lab 5 โ€” A managed database with RDS

Launch a free-tier database and connect to it from your server.

RDS
๐Ÿ”’

Lab 6 โ€” Your first serverless function

Run code with no server, trigger it, and read the output in the logs.

Lambda
๐Ÿ”’

Lab 7 โ€” Watch the spend

Set a budget, read Cost Explorer, and build a real estimate in the Pricing Calculator.

Budgets
๐Ÿ”’

Lab 8 โ€” Audit trail & recommendations

See every action in CloudTrail, read your free Trusted Advisor checks.

CloudTrail
Where this takes you

Two levels, one path

You are here ยท Fundamental

AWS Cloud Practitioner

Understand the cloud, deploy real AWS resources, control cost, and pass CLF-C02.

Next ยท Intermediate

AWS Solutions Architect โ€” Associate

Design secure, resilient, high-performing and cost-optimised architectures (SAA-C03). Opens after you are comfortable here.