CloudWatch or CloudTrail? The AWS services candidates confuse, one difference at a time
Many wrong answers on the Cloud Practitioner exam come from services with similar purposes. CloudWatch watches performance and alarms; CloudTrail records who did what. Security groups protect individual resources; network ACLs protect whole subnets. AWS Budgets alerts you before you overspend; Cost Explorer analyses past spending. Learn each group as a contrast, then learn how responsibility shifts from EC2 to RDS to Lambda.
You can define CloudWatch and CloudTrail perfectly and still lose the mark. The question asks which service shows who deleted a database last night, and both options sound right. Eight groups of look-alike services cause many of those lost marks, and a failed attempt costs the full fee again and a 14-day wait.
Why do look-alike services cost so many marks?
The exam rarely asks what a service is called. It describes a business need and asks which service fits. When two options both monitor, protect or store, a definition will not separate them. You need the one difference that answers the question.
Read the last line of the question first, so you know what you are choosing. Then remove every option that does something different from the need described.
These groups sit across task statements 2.2, 2.4, 3.4, 3.5, 3.6, 3.8, 4.1 and 4.2. The CLF-C02 exam guide in plain English sets out all 19 with their weights. Here are the groups, one difference at a time.
Which services do candidates confuse, and when do you use each?
| Group | Service | Use this when |
|---|---|---|
| Monitoring and records | Amazon CloudWatch | You need to watch performance and set alarms |
| AWS CloudTrail | You need a record of who did what in the account | |
| AWS Config | You need to track how settings change | |
| Threat protection | Amazon GuardDuty | You need threats detected |
| Amazon Inspector | You need resources scanned for vulnerabilities | |
| AWS Shield | You need protection against DDoS attacks | |
| AWS WAF | You need web requests filtered | |
| Network protection | Security groups | You need to protect individual resources (stateful) |
| Network ACLs | You need to protect a whole subnet (stateless) | |
| Storage | Amazon S3 | You need object storage for files and backups |
| Amazon EBS | You need a disk for one server | |
| Amazon EFS | You need a shared file system for many servers | |
| Databases | Amazon RDS | You need a managed relational database |
| Amazon DynamoDB | You need a NoSQL key-value database | |
| Amazon ElastiCache | You need an in-memory cache | |
| Messaging | Amazon SNS | You need to push messages to many subscribers |
| Amazon SQS | You need to queue messages for later processing | |
| Amazon EventBridge | You need to route events between services | |
| Cost tools | AWS Budgets | You need an alert before you overspend |
| AWS Cost Explorer | You need to analyse past spending | |
| AWS Pricing Calculator | You need a cost estimate before you build | |
| Buying compute | Reserved Instances | You can commit to specific instances |
| Savings Plans | You can commit to an amount of spending per hour | |
| Spot Instances | You want spare capacity cheaply and can accept interruptions |
A DDoS attack, short for distributed denial of service, floods a website with traffic to knock it offline. A NoSQL database stores data without the fixed schema of rows and columns that a relational one requires.
How do you tell the hardest pairs apart?
CloudWatch or CloudTrail. CloudWatch answers "how is it running?" and CloudTrail answers "who did that?". A rise in server load is a CloudWatch question. A deleted resource is a CloudTrail question. AWS Config answers a third: how has this setting changed?
Security groups or network ACLs. Look at the scope. One server or resource points to a security group. A subnet, a section of your private network in AWS, points to a network ACL. Stateful means a security group remembers traffic it allowed and lets the reply through automatically. A stateless network ACL checks each direction separately.
AWS Budgets or Cost Explorer. Look at the tense. Future spending and an alert point to AWS Budgets. Past spending points to Cost Explorer. A system not yet built points to the Pricing Calculator.
Savings Plans, Reserved Instances or Spot. A workload that runs steadily for years suits a commitment, through Savings Plans or Reserved Instances. Spot is cheap but can be interrupted, so it never suits work that must not stop.
The last contrast is not between services at all. It is about who is responsible.
How does shared responsibility change from EC2 to RDS to Lambda?
The shared responsibility model sets out which security duties belong to AWS and which belong to you. It is task statement 2.1, in the domain that carries 30 per cent of the exam. The split is not fixed: it shifts as services become more managed.
| Responsibility | Amazon EC2 | Amazon RDS | AWS Lambda |
|---|---|---|---|
| Data centres and hardware | AWS | AWS | AWS |
| Operating system patches | You | AWS | AWS |
| Database or runtime software | You | AWS | AWS |
| Network and firewall settings | You | Shared | Shared |
| Your data and encryption choices | You | You | You |
| Users and access permissions | You | You | You |
Amazon EC2 gives you a virtual server, so you manage its operating system, patches and firewall settings. Amazon RDS shifts more to AWS, which patches the database software. With AWS Lambda, AWS runs almost everything except your code, data and access settings.
Three rows never move. AWS always owns the data centres and hardware. You always own your data, your encryption choices and who can reach it.
A common slip is to answer "the customer" when asked who patches database software on Amazon RDS, because the database holds customer data. Check the service first, then the row.
How should you practise the contrasts?
Learn the groups as contrasts, not as separate definitions. Cover the right-hand column of the table and say each difference aloud. The book's readiness test asks you to explain every contrast this way without notes.
When you review a practice set, label each wrong answer with the group it confused. One candidate found that seven of her errors came from shared responsibility and pricing models, and gave both extra time.
A little hands-on practice makes services easier to tell apart, even though the exam does not test building. Set up the account safely first. Create it under the free plan and turn on multi-factor authentication for the root user, the account's original identity with full access. Then set a budget alert in AWS Budgets. How to build your Cloud Practitioner study plan gives the full order.
Then try five short tasks. Store a file in S3, and launch and stop a small EC2 instance. Read the events in CloudTrail. Explore Cost Explorer, and price a small website in the Pricing Calculator.
What to do next
Test the contrasts under exam conditions with the AWS Cloud Practitioner practice questions, and note which group each mistake comes from. If shared responsibility or pricing keeps catching you, move hours towards those task statements now, not in the final week.
Every service name here was checked against AWS's documents in October 2026. Chapter 5 of the book sets out these contrasts as a table to practise as a quiz, beside all 19 task statements. Chapter 7 gives the five-step safe account set-up. Appendix G adds 17 practice questions with short explanations.
- Cover the right-hand column of the contrast table and say each difference aloud, without notes.
- Label every wrong answer in your last practice set with the pair or group it confused.
- Draw the shared responsibility table for EC2, RDS and Lambda from memory, then check it against this page.
- Set a monthly budget alert in AWS Budgets before you create anything in a practice account.
Questions readers ask
Which support plans should I learn for the exam?
Where does a company find AWS's compliance reports for an auditor?
What is the difference between a Region and an Availability Zone?
Which service names have changed recently?
- AWS Certified Cloud Practitioner page
- CLF-C02 exam guide (AWS documentation)
- AWS Support plans page
- AWS Free Tier page
This guide is independent and is not endorsed by AWS. Facts change: confirm them on the official page before you act.