Skip to content

Cloud Practitioner Practice Questions

Prepare for CLF-C02 with more than an answer.

313 questions in the full set20 sample questionsUpdated Jan 28, 2026

Unlock the full exam and previous versions

  • v1Version 1 313 questions Current
  • CLF-C01Legacy AWS Certified Cloud Practitioner 517 questions Locked
Exam fee
$100 USD
Level
Foundational
Valid for
3 years
Domains covered on the exam 4
  1. Cloud Concepts24%
  2. Security and Compliance30%
  3. Cloud Technology and Services34%
  4. Billing, Pricing, and Support12%
  1. 1

    A university wants to provide its researchers with a simple way to launch pre-approved, standardized computing environments for data analysis, without giving them full access to the underlying AWS services. Which AWS service is designed for this purpose?

    Show answer details

    Correct answer: B

    AWS Service Catalog allows organizations to create and manage catalogs of IT services that are approved for use on AWS. These IT services can include everything from virtual machine images, servers, software, and databases to complete multi-tier application architectures. This enables the university to provide standardized, pre-approved environments (products) that researchers can deploy on-demand, ensuring compliance and governance without granting them direct access to provision underlying services.

  2. 2

    What is the economic benefit of moving from an on-premises data center to the AWS Cloud?

    Show answer details

    Correct answer: D

    A primary economic benefit of the cloud is the shift from capital expenditure (CapEx) to operational expenditure (OpEx). Instead of investing heavily in data centers and servers before you know how you’re going to use them (CapEx), you can pay only when you consume computing resources, and pay only for how much you consume (OpEx).

  3. 3

    Case Study

    A small startup has developed a new web application and deployed it on a single, large Amazon EC2 instance in the us-east-1 region. During their first marketing campaign, the website became unresponsive due to a massive, unexpected surge in traffic. After the campaign, the traffic returned to very low levels, leaving the large EC2 instance mostly idle.

    The startup's CEO has tasked the development team with re-architecting the application to meet two key business requirements: the solution must automatically scale to handle unpredictable traffic spikes, and it must minimize costs during periods of low traffic. The team has limited operational staff.

    Which architectural approach would best meet the CEO's requirements?

    Show answer details

    Correct answer: B

    This solution directly addresses both requirements. The EC2 Auto Scaling group will automatically add instances during traffic spikes and remove them when traffic subsides, ensuring both scalability and cost-effectiveness (elasticity). The Application Load Balancer distributes the incoming traffic across the instances. Deploying across multiple Availability Zones also adds high availability. This approach requires minimal manual intervention, which is ideal for a team with limited operational staff. The other options are either manual, not scalable, or do not effectively minimize costs during idle periods.

  4. 4

    A user needs to find a third-party security software solution that is pre-configured to run on AWS and can be purchased with consolidated AWS billing. Which AWS service should the user browse?

    Show answer details

    Correct answer: C

    AWS Marketplace is a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on AWS. Purchases made through AWS Marketplace are integrated with the customer's AWS bill. AWS Service Catalog is for creating and managing a catalog of approved internal IT services. AWS Artifact is for compliance reports.

  5. 5

    Which AWS service provides a fully managed, serverless, key-value NoSQL database?

    Show answer details

    Correct answer: D

    Amazon DynamoDB is a fully managed, serverless, key-value NoSQL database designed to run high-performance applications at any scale. Amazon RDS and Aurora are relational database services, and Amazon Redshift is a data warehousing service.

  6. 6

    An administrator is creating an IAM user for a new employee. Following the principle of least privilege, what is the recommended first step?

    Show answer details

    Correct answer: B

    The principle of least privilege dictates that you should grant only the permissions required to perform a task. The best practice is to start with a new IAM user who has no permissions at all. Then, you incrementally add only the specific permissions that the user requires to perform their job functions, either by attaching policies to the user or adding the user to a group with appropriate policies.

  7. 7

    Which AWS service is used to get a copy of AWS's SOC 2 compliance report?

    Show answer details

    Correct answer: D

    AWS Artifact is your go-to, central resource for compliance-related information. It provides on-demand access to AWS’s security and compliance reports, such as SOC, PCI, and ISO certifications. Customers can download these documents to support their own compliance and auditing efforts.

  8. 8

    A financial services company is required by regulation to retain trade confirmation records for seven years. The records must be accessible within 48 hours of a request, but are rarely accessed after the first month. Which Amazon S3 storage class strategy provides the most cost-effective solution while meeting these compliance requirements?

    Show answer details

    Correct answer: C

    This is the most cost-effective strategy. S3 Glacier Flexible Retrieval is designed for long-term archival where data is infrequently accessed but needs to be retrieved within minutes to hours. This fits the 48-hour retrieval requirement perfectly while offering significant cost savings over S3 Standard. S3 Glacier Deep Archive has a longer retrieval time (typically 12+ hours), which might not meet the 48-hour window consistently for all retrieval types, and is designed for even less frequent access. S3 Standard is too expensive for long-term archival. Storing data directly in S3 Glacier Instant Retrieval is more expensive than transitioning it after the initial high-access period.

  9. 9

    A company is using AWS Organizations to manage multiple AWS accounts. The security team wants to prevent any IAM user in a specific member account from deleting Amazon S3 buckets, regardless of the IAM policies attached to them. How can this be enforced centrally?

    Show answer details

    Correct answer: B

    Service Control Policies (SCPs) are a feature of AWS Organizations that offer central control over the maximum available permissions for all accounts in an organization. An SCP with a Deny statement for the s3:DeleteBucket action, when applied to an account or an Organizational Unit (OU), will override any Allow permissions granted by IAM policies within that account. This provides a centralized, foolproof way to enforce such restrictions. A security group is for network traffic, an S3 bucket policy applies only to a specific bucket, and managing individual IAM policies is not a central or scalable solution.

  10. 10

    True or False: Using AWS Cost Explorer, you can visualize and analyze your AWS costs, but you cannot set up alerts to be notified when your spending exceeds a predefined threshold.

    Show answer details

    Correct answer: A

    This statement is true. AWS Cost Explorer is a tool for visualizing, understanding, and managing your AWS costs and usage over time. However, the service used to set up alerts for spending thresholds is AWS Budgets. AWS Budgets allows you to set custom budgets that alert you when your costs or usage exceed (or are forecasted to exceed) your budgeted amount.

Create an account to continue.