Certablo
← Knowledge Base

AWS Trusted Advisor

Automated AWS best-practice checks and recommendations across cost, performance, security, fault tolerance, service limits and operational excellence, with plan-dependent access and organization views.

CLF-C02SAA-C03SOA-C03

Visual overview

OPERATING LOOPDefine, deploy, observe, govern, and improve the environment continuously
01DefineInfrastructure + policy
02OperateFleet + workload actions
03ObserveMetrics · logs · events
04GovernAccounts · config · evidence
Management services answer different operational questions: what changed, how the workload behaves, whether configuration is compliant, and how repeatably infrastructure is managed.
AWS SERVICE MAPFrom findings to architecture improvement

Trusted Advisor surfaces recommendations, Organizations can aggregate them, and Well-Architected places findings in a broader workload-review process.

Trusted AdvisorAutomated best-practice findings
OrganizationsMulti-account recommendation scope
Well-ArchitectedWorkload-level review context
EXAM-RELEVANT MECHANICS

Technical reference

Trusted Advisor is a recommendation system whose catalog, refresh cadence and support entitlements evolve. Treat current AWS documentation as authoritative for plan-specific availability.

Check domainsCost · performance · security · fault tolerance · service limits · operational excellence

Checks are grouped by the operational outcome they help evaluate, and each check has its own alert criteria and recommended action.

Basic SupportLimited Trusted Advisor check access

Current documentation exposes Service Limits plus selected Security and Fault Tolerance checks; broader plans add substantially more checks and capabilities.

RefreshCheck-specific automatic/manual behavior

Some checks refresh automatically and cannot be manually refreshed, so the displayed result may follow the source integration's update cadence.

Organization viewCentralized member-account recommendations

With the required Organizations integration and entitlement, central administrators can report across member accounts.

Status automationTrusted Advisor → EventBridge

EventBridge can react to supported check status changes and route them to notification or automated targets.

Trusted Advisor PrioritySupport-led prioritized recommendations

Priority is an eligible higher-tier support capability and is conceptually separate from the ordinary automated check catalog.

Service limits and capabilities can change. Values shown here reflect the current AWS documentation; use the linked official sources below as the source of truth.

Trusted Advisor evaluates AWS environments against operational best practices

AWS Trusted Advisor runs checks and presents recommendations intended to highlight opportunities or risks in an AWS environment. The current check reference groups checks into cost optimization, performance, security, fault tolerance, service limits and operational excellence. A check is targeted evidence about a specific condition—such as a resource configuration, utilization pattern or quota risk—not a blanket certification that the entire account is secure, reliable or cost optimized.

This makes Trusted Advisor useful as a recurring review signal. Teams can use check results to find neglected resources, configuration risks or capacity concerns and then evaluate the recommended action in the workload's real context. Some recommendations are powered by integrations with services such as AWS Config, Compute Optimizer or the Well-Architected Tool. The source and refresh behavior of each check therefore matter when interpreting how current the recommendation is.

Check availability and refresh behavior depend on current support entitlements

Trusted Advisor access is not identical for every AWS Support plan. AWS documentation currently gives Basic Support access to the Service Limits category and selected checks in Security and Fault Tolerance, while higher support plans expose a substantially broader check set and additional APIs or organization capabilities. The Support-plan portfolio has changed over time, so old exam-prep tables that list legacy plan names can become inaccurate.

Refresh behavior also varies by check. Some checks refresh automatically and cannot be manually refreshed; some integrations update on their own cadence; and plan-level behavior can affect refresh availability. When a finding has operational urgency, read its Last Updated information and current check documentation instead of assuming the console reflects a just-made change immediately. EventBridge integration can detect status changes for supported Trusted Advisor checks and route them to notification or automation targets.

  • Check the current Support plan before assuming a specific check, API or organization feature is available.
  • Some checks are automatically refreshed and reject manual refresh attempts; update cadence is check-specific.
  • A recommendation can remain visible briefly after the environment changes because the underlying check has not refreshed yet.

Organizational view and Trusted Advisor Priority solve different governance needs

Trusted Advisor can aggregate recommendations across an AWS Organizations environment when the required trusted access, organization configuration and support entitlements are present. Central reporting lets a cloud platform or governance team compare recommendations across member accounts rather than exporting one account at a time. As with other Organizations integrations, delegated administration can move supported central operations out of the management account.

Trusted Advisor Priority is a distinct experience for prioritized recommendations associated with eligible higher-tier support relationships. It can include recommendations prioritized by AWS account teams and supports organization-wide workflows for management or delegated administrator accounts. For certification reasoning, the safer mental model is to separate automated Trusted Advisor checks from human-prioritized support engagement, and to verify the current plan requirements whenever a scenario depends on a specific entitlement.

Key takeaways

  1. 01

    Trusted Advisor presents best-practice checks and recommendations rather than acting as a universal compliance certificate.

  2. 02

    Current check categories include cost optimization, performance, security, fault tolerance, service limits and operational excellence.

  3. 03

    Check availability, APIs and organization features depend on the current AWS Support plan.

  4. 04

    Refresh cadence varies by check; not every result can be manually refreshed.

  5. 05

    Trusted Advisor Priority is separate from ordinary automated checks and is tied to eligible support engagements.

Official AWS sources

Use these primary AWS resources for the source material behind this article and for deeper reference.