Cloud Practitioner
Monitoring, logging and auditing
CloudWatch, CloudTrail, AWS Config, Trusted Advisor and the difference between a metric, a log and an audit trail.
Foundational notes for AWS Certified Cloud Practitioner (CLF-C02). Read them in order the first time through, then use them as a revision sweep before you book.
11 study points. Everything here is exam-oriented: each point is a fact or a distinction that CLF-C02 items are built on. Test yourself against the practice exam once you can explain a section without re-reading it.
Logs & Monitoring
AWS CloudTrail is your audit trail for everything that happens in your AWS account. It records every API call, including who made the call, when, from what IP address, and what the result was. If S3 buckets go missing or resources are unexpectedly deleted, CloudTrail logs are the first place to investigate. Think of CloudTrail as a security camera for your AWS account; it gives you a complete, chronological record of all activity.
Amazon CloudWatch is AWS’s monitoring and observability service. It collects metrics, logs, and events from virtually every AWS service and lets you set alarms based on thresholds. For example, you can set a CloudWatch alarm to notify you when CPU utilization on your EC2 instances exceeds 80%, or when your estimated AWS charges exceed a specific dollar amount. CloudWatch is the central hub for understanding the health and performance of your AWS resources.
AWS Trusted Advisor is an automated service that scans your AWS environment and provides recommendations across five categories: Cost Optimization, Performance, Security, Fault Tolerance, and Service Limits. For example, it might flag that you have idle EC2 instances wasting money, or that your S3 buckets are publicly accessible. The basic checks are available to all customers, while the full set of checks requires a Business or Enterprise support plan.
CloudWatch Logs lets you collect, store, and analyze log files from EC2 instances, Lambda functions, CloudTrail, Route 53, and other sources in a single place. You can create metric filters that search for specific patterns in your logs and trigger alarms. For example, you could create a filter that counts the number of “404 Not Found” errors in your web server logs and alerts you if the rate spikes. This turns your raw log data into actionable intelligence.
Amazon SNS (Simple Notification Service) works closely with CloudWatch to deliver alerts to the right people. When a CloudWatch alarm triggers, it can publish a message to an SNS topic, which then delivers notifications via SMS, email, Lambda functions, or SQS queues. Note that FTP is not a supported SNS endpoint. This event-driven notification chain ensures that the right team members are informed immediately when something requires attention.
AWS Config is a service that continuously monitors and records the configuration of your AWS resources. While CloudTrail tells you who did what, Config tells you what your resources looked like at any point in time and whether they comply with your desired configurations. For example, Config can alert you if someone modifies a security group to allow unrestricted SSH access. It provides a complete configuration history and change timeline for compliance auditing.
VPC Flow Logs capture information about the IP traffic going to and from network interfaces in your VPC. They are invaluable for troubleshooting connectivity issues, identifying security threats, and monitoring network traffic patterns. Flow Logs can be published to CloudWatch Logs or S3. For example, if an EC2 instance can’t connect to a database, Flow Logs can show you whether the traffic is being rejected by a security group or network ACL.
Amazon GuardDuty is an intelligent threat detection service that continuously monitors your AWS accounts and workloads for malicious activity. It analyzes CloudTrail logs, VPC Flow Logs, and DNS logs using machine learning to identify threats like compromised instances, reconnaissance attacks, and cryptocurrency mining. GuardDuty requires no infrastructure to manage and can be enabled with a single click, making it one of the easiest security tools to deploy.
AWS X-Ray helps you analyze and debug distributed applications, particularly those built with microservices or serverless architectures. It traces requests as they travel through your application, showing you a visual map of how services interact and where bottlenecks or errors occur. For example, if an API call is slow, X-Ray can show you that 80% of the latency comes from a single Lambda function making a slow database query.
The combination of CloudTrail, CloudWatch, Config, and GuardDuty forms a comprehensive monitoring and security strategy. CloudTrail records who did what. CloudWatch monitors performance and health. Config tracks resource configurations over time. GuardDuty detects threats automatically. Using all four services together gives you complete visibility into the security, compliance, and operational health of your AWS environment. This layered approach is a best practice recommended by the AWS Well-Architected Framework.
AWS Personal Health Dashboard provides alerts and remediation guidance when AWS experiences events that may affect your resources. Unlike the Service Health Dashboard, which shows the general status of all AWS services, the Personal Health Dashboard gives you a personalized view based on the specific resources you’re using. For example, if a hardware issue affects the physical host running your EC2 instance, you’ll receive a proactive notification with steps to migrate your instance before it’s impacted.
Where to go next
- Back to the AWS Cloud Practitioner overview.
- Look up any service you could not name in the AWS services glossary.
- Sit the 80-item practice exam once two or three note pages are solid.
Dernière mise à jour le 18 sept. 2026