AWS Training
Modules Listen All tracks

← Design Cost-Optimized Architectures

Starts this lesson and continues through 7 more to the end of certification prep.

The cost management toolkit — see it, allocate it, cap it, fix it

Why this lesson comes first

Open the Domain 4 page of the exam guide (fetched 2026-09-25) and look at the first two "Knowledge of" bullets under every one of the four task statements. They are identical:

"AWS cost management service features (for example, cost allocation tags, multi-account billing)" "AWS cost management tools with appropriate use cases (for example, AWS Cost Explorer, AWS Budgets, AWS Cost and Usage Report)"

Four task statements, the same two bullets, four times. That's AWS telling you the tools are not a storage topic or a compute topic. They sit under all of them. So this lesson covers them once, and the other four lessons assume them.

Task 4.4 also has a skill that is really about these tools: "Reviewing existing workloads for network optimizations". You cannot review what you cannot see.

The distinguishing question is: what does the stem want to do with the money?

   understand where it went, spot a trend     →  Cost Explorer
   be warned (or stopped) before it goes      →  AWS Budgets (+ budget actions)
   the raw line items, into your own tools    →  Cost and Usage Report / Data Exports
   split one bill by team, app, cost centre   →  cost allocation tags
   one bill, pooled discounts, many accounts  →  Organizations consolidated billing
   tell me what to resize or delete           →  Compute Optimizer (+ Trusted Advisor)

Cost Explorer — look and forecast

From Analyzing your costs and usage with AWS Cost Explorer, fetched 2026-09-25:

"AWS Cost Explorer is a tool that enables you to view and analyze your costs and usage. … You can view data for up to the last 13 months, forecast how much you're likely to spend for the next 18 months, and get recommendations for what Reserved Instances to purchase."

Fact Value, verbatim where quoted
History "up to the last 13 months"
Forecast "the next 18 months"
Refresh "at least once every 24 hours"
First-time setup current month "available for viewing in about 24 hours"; the rest "a few days longer"
Console "free of charge"
API "Each paginated API request incurs a charge of $0.01"
Can you turn it off? "You can't disable Cost Explorer after you enable it."
Dataset "the same dataset that is used to generate the AWS Cost and Usage Reports"

⚠️ The API charge is the trap in the lab, not on the exam. A script that pages through get-cost-and-usage in a loop is billed per request. The console is free.

Cost Explorer is also where Savings Plans recommendations live — the Savings Plans guide says to "use AWS Cost Explorer to view your recommended Savings Plans commitment" (lesson 3).

AWS Budgets — warn, and optionally act

From Managing your costs with AWS Budgets, fetched 2026-09-25. Six budget types, verbatim names:

Budget type What it alerts on
Cost "costs approach or exceed your defined threshold"
Usage "usage approaches or exceeds your set threshold"
RI utilization RI usage "falls below this level" → unused RIs
RI coverage "percentage of your instance hours covered by RIs falls below this level"
Savings Plans utilization SP usage "drops below this level"
Savings Plans coverage "percentage of your eligible usage covered by Savings Plans falls below this level"

Two details the exam uses:

And the freshness caveat, verbatim — it matters for "why didn't the alert stop the overspend?":

"AWS Budgets information is updated up to three times a day. Updates typically occur 8–12 hours after the previous update."

"There can be a delay between when you incur a charge and when you receive a notification … You might incur additional costs or usage that exceed your budget notification threshold before AWS Budgets can notify you."

⚠️ A budget is a smoke alarm, not a circuit breaker. It can fire late, and on its own it stops nothing.

Budget actions — the circuit breaker

From Configuring budget actions, fetched 2026-09-25:

"You can use AWS Budgets to run an action on your behalf when a budget exceeds a certain cost or usage threshold. … configure a budget action to run either automatically or after your manual approval."

"Your available actions include applying an IAM policy or a service control policy (SCP). They also include targeting specific Amazon EC2 or Amazon RDS instances in your account."

⚠️ Cross-account limit, verbatim: "From the management account, you can apply an SCP to another account. However, you can't target Amazon EC2 or Amazon RDS instances in another account."

So "stop developers provisioning anything once the sandbox hits its budget" → budget action applying a deny SCP or IAM policy. "Stop the instances in this account" → budget action targeting EC2/RDS.

Cost and Usage Report, and Data Exports — the raw data

From What are AWS Cost and Usage Reports?, fetched 2026-09-25:

"AWS Cost and Usage Reports (AWS CUR) contains the most comprehensive set of cost and usage data available. You can use Cost and Usage Reports to publish your AWS billing reports to an Amazon Simple Storage Service (Amazon S3) bucket that you own. You can receive reports that break down your costs by the hour, day, or month, by product or product resource, or by tags that you define yourself."

The name change you need to know

From What is AWS Data Exports?, fetched 2026-09-25, the current home for this data is Data Exports, with export types including:

⚠️ The exam guide still says "AWS Cost and Usage Report". The HTML guide wording is unchanged (fetched 2026-09-25). On the exam, "Cost and Usage Report" is the answer to "most granular / most comprehensive / hourly / by resource / load into Athena". In the console you will find it under Data Exports as CUR 2.0.

Discriminator: Cost Explorer vs CUR

Cost Explorer CUR / Data Exports
Shape interactive graphs, filters, forecast files in your S3 bucket
Depth 13 months back the full line-item detail, per hour/resource
Who uses it a person looking a pipeline querying (Athena, Redshift, Quick)
Answer to "which service grew last quarter?" "charge back every resource-hour to its team"

Reading data transfer in the CUR

The skill "Reviewing existing workloads for network optimizations" is a CUR job. From Understanding data transfer charges, fetched 2026-09-25, the lineItem/UsageType column tells you which kind of transfer you're paying for:

Usage type pattern What it is
<Region>-DataTransfer-Regional-Bytes between AZs in one Region
<Src>-<Dst>-AWS-Out-Bytes out of one Region into another (this line carries the charge)
<Region>-DataTransfer-Out-Bytes to the internet
ends DataXfer-Out / DataXfer-Out:dc.3 Direct Connect (public / private-or-transit VIF)

Lesson 5 is built on those rows.

Cost allocation tags — splitting one bill

From Organizing and tracking costs using AWS cost allocation tags, fetched 2026-09-25:

"AWS provides two types of cost allocation tags, an AWS-generated tags and user-defined tags. … You must activate both types of tags separately before they can appear in Cost Explorer or on a cost allocation report."

The details that decide questions:

⚠️ Tagging a resource is not enough. The tag has to be activated for cost allocation, by the management account, and it takes up to a day to appear. "We tagged everything last week and Cost Explorer shows nothing grouped by tag" → nobody activated them.

⚠️ The page lists a "Backfill cost allocation tags" topic but I did not fetch it. Do not assume tags apply retroactively or that they don't — read docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/cost-allocation-backfill.html.

Multi-account billing — consolidated billing in Organizations

From Consolidating billing for AWS Organizations, fetched 2026-09-25:

"Every organization in AWS Organizations has a management account that pays the charges of all the member accounts."

The four benefits, verbatim headings:

  1. One bill — "one bill for multiple accounts" (per seller of record)
  2. Easy tracking — "track the charges across multiple accounts and download the combined cost and usage data"
  3. Combined usage — "This shares the volume pricing discounts, Reserved Instance discounts, and Savings Plans."
  4. No extra fee — "Consolidated billing is offered at no additional cost."

⚠️ The discount-sharing line is the examinable one. A Reserved Instance or Savings Plan bought in one account can reduce the bill for matching usage in another account in the same organization. The RDS reserved-instance guide says the same for databases: "all accounts in the organization can receive the hourly cost benefit of reserved DB instances that are purchased by any other account" (lesson 4).

And a quirk worth one sentence in an interview: "When a member account leaves an organization, the member account can no longer access Cost Explorer data that was generated when the account was in the organization."

Compute Optimizer — right-sizing recommendations

From What is AWS Compute Optimizer?, fetched 2026-09-25:

"AWS Compute Optimizer is a service that analyzes your AWS resources' configuration and utilization metrics to provide you with rightsizing recommendations and identify idle resources."

Fact Verbatim
Opt-in "You must opt in to have Compute Optimizer analyze your AWS resources."
Default lookback CloudWatch metrics "for the last 14 days"
Extended lookback "enhanced infrastructure metrics (paid feature)… extends the metrics analysis lookback period … to 93 days"
Org-wide findings "across multiple accounts, if you opt in the management account of an organization"

Supported resources (from the page): EC2 instances · EC2 Auto Scaling groups · EBS volumes · Lambda functions · ECS services on Fargate · commercial software licenses · Aurora and RDS databases · NAT Gateway · DynamoDB · ElastiCache · MemoryDB · DocumentDB · WorkSpaces · SageMaker.

⚠️ Memory is the blind spot. The page lists the EC2 metrics it analyzes as "CPU utilization, network in and out, disk read and write", and separately notes it "can ingest and analyze external EC2 memory utilization metrics from observability products like Datadog and Dynatrace". I did not fetch the metrics page, so I make no claim about whether CloudWatch-agent memory metrics are used — read docs.aws.amazon.com/compute-optimizer/latest/ug/metrics.html before relying on it.

Trusted Advisor — cost checks

From Cost optimization checks, fetched 2026-09-25. Check names that appear on the page include:

⚠️ Which support plans unlock which cost checks is not on the page I fetched in a form I can quote. Do not answer a "which Support plan gives full Trusted Advisor" question from this lesson — read docs.aws.amazon.com/awssupport/latest/user/trusted-advisor.html. I also don't quote each check's thresholds here; read the check definitions on the page.

Discriminator: Compute Optimizer vs Trusted Advisor. Compute Optimizer is resize this to that from 14 (or 93) days of metrics. Trusted Advisor is a checklist across many categories, of which cost is one, and it catches waste that isn't a sizing problem — an unattached Elastic IP, an idle load balancer.

Choosing, under exam conditions

The stem says Answer
"visualise spend by service over the last year and forecast next quarter" Cost Explorer
"alert finance when forecasted monthly spend exceeds $X" AWS Budgets, forecasted threshold
"automatically prevent new resources once the sandbox exceeds its budget" Budget action → deny SCP / IAM policy
"most granular, hourly, per-resource data, queried with Athena" Cost and Usage Report (CUR 2.0 via Data Exports)
"charge back costs to each department" cost allocation tags, activated in the management account
"tags applied but not showing in Cost Explorer" tags not activated (or < 24 h)
"share Reserved Instance discounts across 12 accounts" Organizations consolidated billing
"recommend smaller instance types from utilisation" Compute Optimizer
"find unattached Elastic IPs and idle load balancers" Trusted Advisor cost checks
"alert when RIs are going unused" RI utilization budget

Check yourself

  1. Tags were applied to every resource a week ago; Cost Explorer can't group by them. Most likely cause?
  2. Finance wants to be warned before the month's spend crosses $50,000. Which feature and setting?
  3. A sandbox account must stop accepting new EC2 launches the moment it passes its budget. What do you configure, and from where?
  4. Cost Explorer or CUR for "every resource-hour, into Athena, joined to our CMDB"?
  5. What does Compute Optimizer look at by default, and how do you get more history?
Answers
  1. The tags haven't been activated as cost allocation tags. "You must activate both types of tags separately before they can appear in Cost Explorer", only the management account (or a standalone account) can, and "All tags can take up to 24 hours to appear."
  2. AWS Budgets cost budget with a forecasted threshold — "forecasted (before accruing)". Add an SNS topic or email as the target.
  3. A budget action that applies a deny SCP (or IAM policy), configured to run automatically. From the management account you can apply the SCP to the member account. You can't target that account's EC2 instances directly from the management account.
  4. CUR — "the most comprehensive set of cost and usage data available", delivered to your S3 bucket, with Athena integration.
  5. 14 days of CloudWatch metrics after opt-in. Enhanced infrastructure metrics (paid) extend it to 93 days.

Teaching this section

Next →Storage cost — classes, minimums, lifecycle, and who pays