Cloud Practitioner Practice Questions
Prepare for CLF-C02 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 313 questions Current
- CLF-C01Legacy AWS Certified Cloud Practitioner 517 questions Locked
- Exam fee
- $100 USD
- Level
- Foundational
- Valid for
- 3 years
Domains covered on the exam 4
- Cloud Concepts24%
- Security and Compliance30%
- Cloud Technology and Services34%
- Billing, Pricing, and Support12%
- 1
Case Study
A small startup has developed a new web application and deployed it on a single, large Amazon EC2 instance in the us-east-1 region. During their first marketing campaign, the website became unresponsive due to a massive, unexpected surge in traffic. After the campaign, the traffic returned to very low levels, leaving the large EC2 instance mostly idle.
The startup's CEO has tasked the development team with re-architecting the application to meet two key business requirements: the solution must automatically scale to handle unpredictable traffic spikes, and it must minimize costs during periods of low traffic. The team has limited operational staff.
Which architectural approach would best meet the CEO's requirements?
Show answer details
Correct answer: B
This solution directly addresses both requirements. The EC2 Auto Scaling group will automatically add instances during traffic spikes and remove them when traffic subsides, ensuring both scalability and cost-effectiveness (elasticity). The Application Load Balancer distributes the incoming traffic across the instances. Deploying across multiple Availability Zones also adds high availability. This approach requires minimal manual intervention, which is ideal for a team with limited operational staff. The other options are either manual, not scalable, or do not effectively minimize costs during idle periods.
- 2
A user needs to find a third-party security software solution that is pre-configured to run on AWS and can be purchased with consolidated AWS billing. Which AWS service should the user browse?
Show answer details
Correct answer: C
AWS Marketplace is a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on AWS. Purchases made through AWS Marketplace are integrated with the customer's AWS bill. AWS Service Catalog is for creating and managing a catalog of approved internal IT services. AWS Artifact is for compliance reports.
- 3
Which AWS service provides a fully managed, serverless, key-value NoSQL database?
Show answer details
Correct answer: D
Amazon DynamoDB is a fully managed, serverless, key-value NoSQL database designed to run high-performance applications at any scale. Amazon RDS and Aurora are relational database services, and Amazon Redshift is a data warehousing service.
- 4
An administrator is creating an IAM user for a new employee. Following the principle of least privilege, what is the recommended first step?
Show answer details
Correct answer: B
The principle of least privilege dictates that you should grant only the permissions required to perform a task. The best practice is to start with a new IAM user who has no permissions at all. Then, you incrementally add only the specific permissions that the user requires to perform their job functions, either by attaching policies to the user or adding the user to a group with appropriate policies.
- 5
Which AWS service is used to get a copy of AWS's SOC 2 compliance report?
Show answer details
Correct answer: D
AWS Artifact is your go-to, central resource for compliance-related information. It provides on-demand access to AWS’s security and compliance reports, such as SOC, PCI, and ISO certifications. Customers can download these documents to support their own compliance and auditing efforts.
- 6
A financial services company is required by regulation to retain trade confirmation records for seven years. The records must be accessible within 48 hours of a request, but are rarely accessed after the first month. Which Amazon S3 storage class strategy provides the most cost-effective solution while meeting these compliance requirements?
Show answer details
Correct answer: C
This is the most cost-effective strategy. S3 Glacier Flexible Retrieval is designed for long-term archival where data is infrequently accessed but needs to be retrieved within minutes to hours. This fits the 48-hour retrieval requirement perfectly while offering significant cost savings over S3 Standard. S3 Glacier Deep Archive has a longer retrieval time (typically 12+ hours), which might not meet the 48-hour window consistently for all retrieval types, and is designed for even less frequent access. S3 Standard is too expensive for long-term archival. Storing data directly in S3 Glacier Instant Retrieval is more expensive than transitioning it after the initial high-access period.
- 7
A company is using AWS Organizations to manage multiple AWS accounts. The security team wants to prevent any IAM user in a specific member account from deleting Amazon S3 buckets, regardless of the IAM policies attached to them. How can this be enforced centrally?
Show answer details
Correct answer: B
Service Control Policies (SCPs) are a feature of AWS Organizations that offer central control over the maximum available permissions for all accounts in an organization. An SCP with a
Denystatement for thes3:DeleteBucketaction, when applied to an account or an Organizational Unit (OU), will override anyAllowpermissions granted by IAM policies within that account. This provides a centralized, foolproof way to enforce such restrictions. A security group is for network traffic, an S3 bucket policy applies only to a specific bucket, and managing individual IAM policies is not a central or scalable solution. - 8
True or False: Using AWS Cost Explorer, you can visualize and analyze your AWS costs, but you cannot set up alerts to be notified when your spending exceeds a predefined threshold.
Show answer details
Correct answer: A
This statement is true. AWS Cost Explorer is a tool for visualizing, understanding, and managing your AWS costs and usage over time. However, the service used to set up alerts for spending thresholds is AWS Budgets. AWS Budgets allows you to set custom budgets that alert you when your costs or usage exceed (or are forecasted to exceed) your budgeted amount.
- 9
A research institute needs to process a massive 100 TB dataset for a one-time analysis. The processing workload is highly parallelizable and can be stopped and restarted without losing progress. To minimize costs, which AWS compute service and pricing model should be used? (Select TWO)
Show answer details
Correct answer: A, D
For a workload that is massive, parallelizable, and fault-tolerant (can be stopped and restarted), the combination of Amazon EC2 and Spot Instances is the most cost-effective. Amazon EC2 provides the raw compute power. Spot Instances offer up to a 90% discount on On-Demand prices by leveraging unused EC2 capacity. Since the workload can be interrupted, the risk of a Spot Instance being reclaimed is acceptable in exchange for the huge cost savings. Reserved Instances are for long-term, steady-state workloads. AWS Lambda has execution time and payload limits that would make it unsuitable for a 100 TB dataset processing in this manner.
- 10
Which pillar of the AWS Well-Architected Framework focuses on the ability to run workloads effectively, gain insight into their operations, and continuously improve supporting processes and procedures?
Show answer details
Correct answer: D
The Operational Excellence pillar focuses on running and monitoring systems to deliver business value and continually improving processes and procedures. Key topics include automating changes, responding to events, and defining standards to manage daily operations. Reliability is about recovering from failures, Performance Efficiency is about using resources efficiently, and Security is about protecting information and systems.
