Cost visibility
Tagging, cost categories, Cost Explorer, Budgets, Data Exports, anomaly detection and rightsizing tools for seeing and controlling spend across an organization.
Exam tasks: 1.5 (determine cost optimization and visibility strategies), 3.5 (identify opportunities for cost optimization)
The decision: who spent what, is it within budget, and what should happen automatically when it isn't? Pick the tool that answers the question at the granularity asked, with the least custom work.
Which tool answers which question
| Tool | Answers | Granularity | Acts on its own? |
|---|---|---|---|
| Cost Explorer | Spend and usage trends, forecasts, RI and Savings Plans coverage | Monthly and daily; hourly opt-in for recent days | No |
| Data Exports / CUR | Every line item with tags, cost categories and discounts | Hourly, resource-level | No, you query it |
| AWS Budgets | Actual or forecast spend against a threshold | Updated several times a day | Yes, with budget actions |
| Cost Anomaly Detection | Unexpected spikes, with a likely root cause | Daily ML evaluation | Alerts only |
| Compute Optimizer | Right size for compute resources | Per resource | No |
| S3 Storage Lens | Storage growth, cold data, missing lifecycle rules | Org, account, bucket, prefix | No |
| Trusted Advisor | Idle resources, low RI use, security and limits checks | Per check | No |
Tagging for cost allocation
- User-defined tags are the keys you apply, such as
CostCenterorProduct. In reports they appear with auser:prefix. - AWS-generated tags are applied by AWS, such as
aws:createdByor the CloudFormation stack name tag. - Neither appears in billing data until it's activated in the Billing console, and only the management account (the payer) can activate tags for the organization. Activated tags can take up to 24 hours to show up.
- Tags apply to usage from activation onward. You can request a backfill of up to 12 months to apply current activations to history.
- Accounts are the cleanest cost boundary. A one-account-per-workload strategy often answers "who spent it" better than tags alone.
Tagged but invisible
A team tags every resource with Project, but Cost Explorer shows nothing when grouped by that tag. The tag was
never activated as a cost allocation tag. Tagging resources isn't enough on its own.
Keeping tags consistent
| Need | Mechanism |
|---|---|
Standard key spelling and allowed values (CostCenter, not costcenter) | Tag policy in Organizations |
| Require a tag when a resource is created | SCP denying the create action when aws:RequestTag/CostCenter is null |
| Tag everything a product creates | Service Catalog TagOptions, CloudFormation stack tags |
| Find untagged resources | Tag Editor, the AWS Config required-tags rule |
See multi-account governance for tag policy behaviour.
Cost Categories
Rules that map costs into business groupings, such as "Platform", "Checkout team" or "Shared", using accounts, tags, services, charge types or other categories.
- Fix messy data without retagging:
CostCentervaluescc-104,CC104and account2222...can all map to "Checkout". - Split charges spread a shared cost, such as a central networking account, across other categories evenly, proportionally or by fixed percentages.
- Categories appear in Cost Explorer, Budgets, Anomaly Detection and Data Exports.
Consolidated billing and discount sharing
- One bill for the organization. Usage from all accounts is combined for volume pricing tiers, such as S3 and data transfer tiers.
- Reserved Instances and Savings Plans are shared across accounts by default. A commitment first covers the account that bought it, then applies to matching usage elsewhere.
- The management account can turn off discount sharing for specific accounts, for example a subsidiary that must be billed at its own rates.
- AWS Billing Conductor produces pro forma bills with custom rates for chargeback or reselling, without changing the real bill.
See pricing models for choosing between RIs, Savings Plans and Spot.
Cost Explorer
- Group and filter by service, account, Region, tag, cost category, usage type and more.
- History of 13 months by default, and a forecast up to 12 months ahead.
- Reports for RI and Savings Plans utilization (are we using what we bought?) and coverage (how much eligible usage is covered?), plus purchase recommendations.
- Rightsizing recommendations for EC2, powered by the same engine as Compute Optimizer.
AWS Budgets
- Budget types: cost, usage, RI utilization and coverage, Savings Plans utilization and coverage.
- Alert on actual or forecasted amounts, by email, SNS or chat channels.
- Filter by account, tag or cost category, so each team can have its own budget.
- Budget actions run when a threshold is crossed, automatically or after approval:
- apply an IAM policy to a user, group or role (for example, deny
ec2:RunInstances), - apply an SCP to an account or OU,
- stop specific EC2 or RDS instances.
- apply an IAM policy to a user, group or role (for example, deny
Exam signal
"Notify when spend is forecast to exceed" is Budgets with a forecasted alert. "Automatically stop developers from launching more resources when the sandbox budget is exhausted" is a budget action applying an SCP or IAM policy. A custom Lambda function on a CloudWatch billing alarm is more work.
Data Exports and the Cost and Usage Report
- Data Exports delivers billing data to S3 on a schedule, in CSV or Parquet. Export types include CUR 2.0, FOCUS (the open FinOps schema) and cost optimization recommendations.
- CUR data is the most detailed: hourly, per resource ID, with tags, cost categories, RI and Savings Plans amortization.
- Query it with Athena (a Glue table over the S3 prefix) and build dashboards with QuickSight, for example the Cloud Intelligence Dashboards.
- Deliver it to the management account or a dedicated FinOps account and share it from there.
Legacy: use Data Exports (CUR 2.0) instead
The original Cost and Usage Report (now called legacy CUR) still works, but new reports should use Data Exports, which has a fixed schema and supports column selection.
Cost Explorer for per-resource chargeback
Cost Explorer shows resource-level data only for a short recent window and only for some services. For hourly, resource-level chargeback over months, or joins with your own data, use CUR 2.0 with Athena.
Cost Anomaly Detection
- Machine learning monitors watch AWS services, linked accounts, cost categories or cost allocation tags.
- Alert subscriptions set a threshold (absolute or percentage impact) and a frequency: individual alerts through SNS, or daily or weekly email summaries.
- Each anomaly shows a likely root cause: the service, account, Region and usage type behind it.
Use it when the question says "unexpected", "unusual" or "detect a spike without setting fixed thresholds".
Recommendation tools
- Compute Optimizer: opt in at the organization level from the management account or a delegated admin. Covers EC2, Auto Scaling groups, EBS, Lambda, ECS services on Fargate, RDS and Aurora, and flags idle resources. Memory recommendations need the CloudWatch agent to publish memory metrics.
- S3 Storage Lens: organization-wide dashboards of object counts, bytes, request activity and data-protection settings. Advanced metrics add prefix-level detail, activity metrics and recommendations. Export metrics to S3 or publish to CloudWatch.
- Trusted Advisor: checks for idle load balancers, unassociated Elastic IPs, low-utilization instances and RI expirations, plus security, fault tolerance and service quota checks. The full set of checks and the organization view need a Business, Enterprise On-Ramp or Enterprise support plan.
Acting on these findings is covered in cost optimization and performance and rightsizing.
Scenarios
Cost categories map inconsistent tag values without retagging, and split charges allocate the shared account's cost by percentage. The tag must be activated first to appear in billing data. Retagging and a custom Lambda function are far more work. Budgets track thresholds, not allocation reports. Trusted Advisor gives recommendations, not a chargeback view.
Budgets alert the developer, and a budget action applying an SCP blocks further launches without custom code. Anomaly Detection only sends alerts and can't act. A billing alarm with Lambda is custom code and deleting users is destructive. Compute Optimizer recommends instance sizes but doesn't enforce spending limits.
CUR 2.0 has hourly, resource-level line items for the whole organization, and Athena can join it with other tables using SQL. Cost Explorer's hourly and resource-level data only covers a short recent window and can't be joined with your own data. Budgets reports and Trusted Advisor don't provide line-item data.
Further reading
Multi-account governance
Structuring an AWS organization with OUs, guardrails from SCPs, RCPs and Control Tower, and sharing or deploying resources across accounts with RAM, StackSets and Service Catalog.
Domain 2 · New solutions
29% of the exam, the largest domain. Designing a new workload for deployment, continuity, security, reliability, performance and cost.