Free Cloud Practitioner Cheat Sheet: Six Service Clues to Remember

When a question gives you a short business request, the fastest path is to match the request to the core AWS service, then check one limitation clue so you do not pick a near miss. Use this as a compact memory sheet, and pair it with a broader review like this free AWS Cloud Practitioner cheat sheet when you want to revisit related terms.


Six request-to-service matches


  1. “We need low-cost storage for files, images, or backups that users can retrieve over the internet.” Think S3. It is object storage, so it fits data stored as objects rather than a running operating system. Limitation cue: S3 is not where you launch a virtual server.
  2. “We need a resizable virtual machine to run an application.” Think EC2. It provides compute capacity for workloads that need an operating system and processing power. Limitation cue: EC2 is not a managed relational database service.
  3. “We need a managed relational database without handling so much database infrastructure ourselves.” Think RDS. It is for structured relational data and database engines managed by AWS. Limitation cue: RDS is not general file storage for documents and media objects.
  4. “We need to control who can access AWS resources and what they are allowed to do.” Think IAM. It handles identities, permissions, and access control. Limitation cue: IAM does not monitor CPU graphs or application metrics.
  5. “We need to watch metrics, create alarms, and observe resource performance.” Think CloudWatch. It focuses on monitoring and operational visibility. Limitation cue: CloudWatch is not the service mainly used to record who made an API call for auditing.
  6. “We need an audit record of account activity and API actions.” Think CloudTrail. It records events for governance and review. Limitation cue: CloudTrail is not a storage service for application files.

Study example: eliminate the near miss


Study example: A company says, “Our auditors want to see which user changed a security setting last week.” Two answers may feel close: IAM and CloudTrail. IAM defines permissions and identities, but CloudTrail is the better match because the request is about recorded activity. The clue word is “see which user changed,” which points to an event history, not permission design.


A useful next step is to answer a few mixed-service items from the AWS Cloud Practitioner practice questions bank and sort missed questions by service name on paper. That makes repeated confusions, such as CloudWatch versus CloudTrail, easier to spot.


Quick check question


Which AWS service best matches this request: “Send an alert when a server’s CPU usage stays high”?


  • A: IAM
  • B: CloudWatch
  • C: CloudTrail
  • D: S3

Correct answer: B: CloudWatch.


Reasoning: The request is about observing a performance metric and triggering an alert, which is monitoring. IAM controls access, not metrics. CloudTrail records activity events for auditing. S3 stores objects. If the request had asked who changed a server configuration, CloudTrail would be the stronger choice. If it had asked who is allowed to start or stop that server, IAM would fit better.


Official exam reference: AWS Cloud Practitioner exam guide. These study examples are independently written.