AWS Certified Cloud Practitioner (CLF-C02) — Questions and Answers
Question 1: Which architectural pattern decouples application components so they can scale and fail independently?
- Monolithic architecture
- Tight coupling
- Loose coupling (Correct answer)
- Hard coding
Correct answer: Loose coupling
Loose coupling uses queues, APIs, or events to separate components, so failures or scaling needs in one part don't directly impact others.
Question 2: Which AWS Support plan provides access to a designated Technical Account Manager (TAM)?
- Enterprise (Correct answer)
- Basic
- Business
- Developer
Correct answer: Enterprise
Only the Enterprise Support plan includes a dedicated Technical Account Manager (TAM) for proactive guidance.
Question 3: What does 'elasticity' mean in the context of AWS cloud computing?
- The ability to stretch physical cables longer
- Distributing data across multiple regions
- Automatically scaling resources up or down to match current demand (Correct answer)
- Reserving maximum capacity at all times
Correct answer: Automatically scaling resources up or down to match current demand
Elasticity refers to the ability to automatically provision and de-provision resources to precisely match demand, avoiding both under- and over-provisioning.
Question 4: Which AWS service performs automated security assessments of EC2 instances and container workloads to find vulnerabilities?
- AWS Shield
- Amazon GuardDuty
- AWS Macie
- Amazon Inspector (Correct answer)
Correct answer: Amazon Inspector
Amazon Inspector automatically assesses applications for software vulnerabilities and unintended network exposures on EC2 and container workloads.
Question 5: Which AWS service allows you to audit user activity and API calls across your AWS infrastructure?
- Amazon Inspector
- AWS CloudTrail (Correct answer)
- Amazon CloudWatch
- AWS Config
Correct answer: AWS CloudTrail
AWS CloudTrail records API calls and user activity in your AWS account, providing a complete audit trail for compliance and security analysis.
Question 6: Which Well-Architected Framework pillar addresses reducing the environmental impact of your cloud workloads?
- Operational Excellence
- Cost Optimization
- Performance Efficiency
- Sustainability (Correct answer)
Correct answer: Sustainability
The Sustainability pillar, added in 2021, focuses on minimizing the environmental impact of running cloud workloads through efficient resource utilization.
Question 7: Which AWS Cost Management feature provides the most granular and comprehensive data about your AWS costs and usage?
- AWS Cost Explorer
- AWS Cost and Usage Report (CUR) (Correct answer)
- AWS Budgets
- AWS Trusted Advisor
Correct answer: AWS Cost and Usage Report (CUR)
The AWS Cost and Usage Report (CUR) is the most detailed billing dataset available, breaking down costs to the resource level with hourly or daily granularity.
Question 8: What is Amazon Route 53?
- A VPN gateway service
- A load balancing service
- A scalable Domain Name System (DNS) web service (Correct answer)
- A content delivery network
Correct answer: A scalable Domain Name System (DNS) web service
Amazon Route 53 is a highly available and scalable DNS web service that routes end users to applications running in AWS or anywhere on the internet.
Question 9: Which design principle recommends replacing failed components automatically rather than fixing them in place?
- Defense in Depth
- Treat servers as cattle, not pets (Correct answer)
- Principle of Least Privilege
- Infrastructure as Code
Correct answer: Treat servers as cattle, not pets
The 'cattle not pets' principle means servers are disposable and interchangeable — when one fails, it's replaced automatically rather than manually nursed back to health.
Question 10: Which AWS service helps you centrally manage billing and access for multiple AWS accounts?
- AWS IAM
- AWS Control Tower
- AWS Organizations (Correct answer)
- AWS Config
Correct answer: AWS Organizations
AWS Organizations lets you consolidate multiple AWS accounts into an organization for centralized management and billing.
Question 11: Which service continuously monitors AWS accounts and workloads for malicious activity using machine learning and threat intelligence?
- Amazon Inspector
- Amazon Macie
- Amazon GuardDuty (Correct answer)
- AWS Security Hub
Correct answer: Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously analyzes CloudTrail logs, VPC Flow Logs, and DNS logs to identify suspicious activity.
Question 12: Which AWS service provides recommendations to rightsize EC2 instances based on actual utilization data?
- AWS Compute Optimizer (Correct answer)
- AWS Cost Explorer
- Amazon CloudWatch
- AWS Trusted Advisor
Correct answer: AWS Compute Optimizer
AWS Compute Optimizer uses machine learning to analyze CloudWatch metrics and recommend the optimal instance type for your workloads.
Question 13: What is Amazon EC2 instance store storage?
- Network-attached storage shared between instances
- Persistent storage that survives instance termination
- Encrypted cold storage for archival data
- Temporary storage physically attached to the host computer that is lost when the instance stops (Correct answer)
Correct answer: Temporary storage physically attached to the host computer that is lost when the instance stops
Instance store provides temporary block-level storage located on disks physically attached to the host — data is lost when the instance stops or terminates.
Question 14: Which AWS offering provides automatic protection against DDoS attacks for all AWS customers at no additional cost?
- Amazon GuardDuty
- AWS WAF
- AWS Shield Advanced
- AWS Shield Standard (Correct answer)
Correct answer: AWS Shield Standard
AWS Shield Standard is automatically enabled for all AWS customers at no extra cost and protects against common network and transport-layer DDoS attacks.
Question 15: What is a key characteristic of AWS's pay-as-you-go pricing model?
- You must sign a minimum 1-year contract
- You pay only for the resources you use with no upfront cost (Correct answer)
- You must pay for resources even when they are stopped
- Pricing is fixed regardless of usage
Correct answer: You pay only for the resources you use with no upfront cost
AWS's pay-as-you-go model means you only pay for the exact resources you consume, with no upfront fees or long-term contracts required.
Question 16: Which AWS feature enables you to require a second form of authentication when logging into the AWS Management Console?
- Multi-Factor Authentication (MFA) (Correct answer)
- AWS Cognito
- IAM Password Policy
- AWS SSO
Correct answer: Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) adds an extra layer of protection by requiring a one-time code in addition to a password.
Question 17: Which AWS tool provides automated recommendations to help optimize costs, security, performance, and fault tolerance?
- AWS Trusted Advisor (Correct answer)
- AWS Compute Optimizer
- AWS Cost Explorer
- AWS Config
Correct answer: AWS Trusted Advisor
AWS Trusted Advisor inspects your AWS environment and provides real-time recommendations across cost optimization, security, performance, and fault tolerance.
Question 18: A Cosmo Property AWS solution architect is outlining the advantages of transferring a data center to the cloud. What is the main advantage of this?
- Eliminating dependence on internet connections
- Cost savings due to provisioning and decommissioning of resources based on varying traffic and workloads (Correct answer)
- Avoiding patch management and its associated costs
- Secured storage, retrieval and transmission of data
Correct answer: Cost savings due to provisioning and decommissioning of resources based on varying traffic and workloads
A data center's ability to adapt to seasonal workload will enhance after moving to the AWS cloud. Since it has to do with IT infrastructure resources, elasticity can increase or decrease allotted resources in accordance with compute and storage needs. An e-commerce site could scale back its web server during peak buying seasons or hours.
Question 19: Which AWS service enables customers to discover, purchase, and immediately begin using software solutions in their AWS environment?
- AWS Config
- AWS OpsWorks
- AWS SDK
- AWS Marketplace (Correct answer)
Correct answer: AWS Marketplace
AWS Marketplace is a digital catalog that makes it simple to locate, test, buy, and deploy software that runs on AWS. It features thousands of product listings from independent software suppliers.
Question 20: Which AWS tool lets you estimate the monthly cost of your planned AWS infrastructure before deploying it?
- AWS Pricing Calculator (Correct answer)
- AWS Budgets
- AWS Cost Explorer
- AWS Trusted Advisor
Correct answer: AWS Pricing Calculator
The AWS Pricing Calculator lets you model your expected workloads and estimate monthly costs before committing to any resources.
Question 21: Which compliance framework is most relevant for organizations that handle payment card data on AWS?
- SOC 2
- FedRAMP
- PCI DSS (Correct answer)
- HIPAA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) applies to organizations that process, store, or transmit cardholder payment information.
Question 22: Which AWS service provides a NoSQL key-value and document database with single-digit millisecond performance?
- Amazon DynamoDB (Correct answer)
- Amazon Aurora
- Amazon Redshift
- Amazon RDS
Correct answer: Amazon DynamoDB
Amazon DynamoDB is a fully managed NoSQL database offering consistent single-digit millisecond latency at any scale.
Question 23: Which AWS Well-Architected pillar focuses on the ability of a system to recover from failures and meet demand?
- Sustainability
- Security
- Operational Excellence
- Reliability (Correct answer)
Correct answer: Reliability
The Reliability pillar addresses designing systems that can recover from infrastructure failures, scale to meet demand, and mitigate disruptions.
Question 24: What does the AWS Trusted Advisor security check evaluate?
- Availability of AWS services in a region
- Cost optimization opportunities in S3
- Security gaps such as open ports, unrestricted access, and MFA status (Correct answer)
- Performance of EC2 instances
Correct answer: Security gaps such as open ports, unrestricted access, and MFA status
AWS Trusted Advisor's security checks identify potential vulnerabilities including exposed access keys, open security group ports, and missing MFA on the root account.
Question 25: What is the benefit of using multiple AWS Regions for a global application?
- Reduced latency for users in different geographic locations and improved disaster recovery (Correct answer)
- Simplified IAM management
- Automatic Reserved Instance discounts
- Lower storage costs
Correct answer: Reduced latency for users in different geographic locations and improved disaster recovery
Deploying in multiple Regions reduces latency for globally distributed users and provides geographic redundancy for disaster recovery purposes.
Question 26: Which AWS pricing benefit consolidates billing for multiple accounts and applies volume discounts across the entire organization?
- Savings Plans
- Reserved Instance Sharing
- Enterprise Discount Program
- Consolidated Billing (Correct answer)
Correct answer: Consolidated Billing
Consolidated Billing through AWS Organizations combines usage across all member accounts, enabling volume pricing tiers and a single invoice.
Question 27: Which service provides on-demand access to AWS compliance reports such as SOC and PCI DSS documentation?
- AWS Artifact (Correct answer)
- AWS Trusted Advisor
- AWS Security Hub
- AWS Config
Correct answer: AWS Artifact
AWS Artifact is a self-service portal that gives you on-demand access to AWS compliance reports and agreements.
Question 28: What AWS tool lets you estimate the cost of a new AWS architecture before you deploy it?
- AWS Pricing Calculator (Correct answer)
- AWS Cost and Usage Report
- AWS Cost Explorer
- AWS Budgets
Correct answer: AWS Pricing Calculator
The AWS Pricing Calculator is a free tool that lets you model your solution and estimate the monthly cost before deploying any resources.
Question 29: What is an IAM role used for in AWS?
- Creating groups of users with shared permissions
- Granting temporary permissions to entities that need access to AWS resources (Correct answer)
- Storing long-term access credentials for a user
- Defining password policies for AWS accounts
Correct answer: Granting temporary permissions to entities that need access to AWS resources
IAM roles are used to delegate access to AWS resources with temporary security credentials, without sharing long-term keys.
Question 30: Which AWS service provides managed Kubernetes container orchestration?
- AWS Fargate
- Amazon ECS
- Amazon EKS (Correct answer)
- AWS App Runner
Correct answer: Amazon EKS
Amazon Elastic Kubernetes Service (EKS) is a managed Kubernetes service that makes it easy to run Kubernetes on AWS.
Question 31: Which AWS service is used to send notifications to subscribers via email, SMS, or other endpoints when events occur?
- Amazon SNS (Correct answer)
- Amazon SES
- AWS EventBridge
- Amazon SQS
Correct answer: Amazon SNS
Amazon SNS (Simple Notification Service) is a managed pub/sub messaging service that delivers messages to subscribers via email, SMS, Lambda, SQS, or HTTP endpoints.
Question 32: Which AWS Well-Architected pillar focuses on using cloud resources efficiently to deliver business value?
- Operational Excellence
- Cost Optimization
- Reliability
- Performance Efficiency (Correct answer)
Correct answer: Performance Efficiency
The Performance Efficiency pillar focuses on using computing resources efficiently and maintaining that efficiency as demand changes and technologies evolve.
Question 33: What is data transfer pricing for traffic moving WITHIN the same AWS Availability Zone?
- Free (Correct answer)
- $0.09 per GB
- $0.02 per GB
- $0.01 per GB
Correct answer: Free
Data transfer between EC2 instances within the same Availability Zone using private IP addresses is free.
Question 34: Which AWS service provides a fully managed, scalable, shared file system that can be mounted by multiple EC2 instances simultaneously?
- Amazon S3
- Amazon EBS
- Amazon FSx
- Amazon EFS (Correct answer)
Correct answer: Amazon EFS
Amazon EFS (Elastic File System) is a scalable, managed NFS file system that can be mounted concurrently by thousands of EC2 instances.
Question 35: Which S3 storage class is designed for data that is accessed less than once a month and requires millisecond retrieval?
- S3 Glacier
- S3 Standard-Infrequent Access (S3 Standard-IA) (Correct answer)
- S3 One Zone-IA
- S3 Standard
Correct answer: S3 Standard-Infrequent Access (S3 Standard-IA)
S3 Standard-IA is for data accessed less frequently but that requires rapid access when needed — it has lower storage cost but a per-retrieval fee.
Question 36: Which AWS Partner Network (APN) tier recognizes partners with the deepest technical expertise and proven track record with AWS?
- Advanced Tier
- Select Tier
- Premier Tier (Correct answer)
- Standard Tier
Correct answer: Premier Tier
AWS Premier Tier Partners are the highest designation in the APN, recognizing partners with the most technical certifications and the largest number of successfully completed customer projects.
Question 37: What is AWS Fargate?
- A monitoring service for containerized applications
- A container registry for storing Docker images
- A dedicated hardware service for containers
- A serverless compute engine for containers that removes the need to manage servers or EC2 instances (Correct answer)
Correct answer: A serverless compute engine for containers that removes the need to manage servers or EC2 instances
AWS Fargate is a serverless compute engine for Amazon ECS and EKS that lets you run containers without managing the underlying EC2 servers.
Question 38: Which Amazon VPC component allows instances in a private subnet to access the internet without exposing them to inbound internet traffic?
- NAT Gateway (Correct answer)
- Internet Gateway
- Bastion Host
- VPN Gateway
Correct answer: NAT Gateway
A NAT Gateway allows outbound internet access for instances in private subnets while preventing the internet from initiating connections to those instances.
Question 39: What is the key difference between a Security Group and a Network ACL in AWS?
- Both are stateless
- Security Groups are stateless; NACLs are stateful
- Security Groups are stateful; NACLs are stateless (Correct answer)
- Both are stateful
Correct answer: Security Groups are stateful; NACLs are stateless
Security Groups are stateful (return traffic is automatically allowed), while Network ACLs are stateless (you must explicitly allow both inbound and outbound traffic).
Question 40: Which AWS encryption option allows you to manage your own encryption keys using dedicated hardware security modules?
- AWS CloudHSM (Correct answer)
- Server-Side Encryption with S3 keys
- AWS KMS with AWS-managed keys
- AWS Secrets Manager
Correct answer: AWS CloudHSM
AWS CloudHSM provides dedicated Hardware Security Modules so you have full control over your encryption keys.
Question 41: Which AWS Cost Management tool provides visualizations of your historical and forecasted spending by service, region, or tag?
- AWS Billing Dashboard
- AWS Pricing Calculator
- AWS Cost Explorer (Correct answer)
- AWS Budgets
Correct answer: AWS Cost Explorer
AWS Cost Explorer provides interactive charts and filtering to analyze past spending patterns and forecast future costs.
Question 42: Which S3 storage class is designed for data that is accessed less than once a month but requires rapid access when needed?
- S3 Intelligent-Tiering
- S3 One Zone-IA
- S3 Standard
- S3 Glacier Instant Retrieval (Correct answer)
Correct answer: S3 Glacier Instant Retrieval
S3 Glacier Instant Retrieval offers low-cost archival storage for rarely accessed data with millisecond retrieval times.
Question 43: What AWS feature allows you to set spending limits and receive alerts when costs exceed a threshold?
- AWS Budgets (Correct answer)
- AWS Pricing Calculator
- AWS Trusted Advisor
- AWS Cost Explorer
Correct answer: AWS Budgets
AWS Budgets allows you to set custom cost and usage budgets and sends alerts when your spending exceeds or is forecasted to exceed your thresholds.
Question 44: What does 'high availability' mean in AWS architecture?
- Guaranteed zero downtime
- Running instances with premium hardware
- Designing systems to remain operational despite component failures by eliminating single points of failure (Correct answer)
- Using only the latest EC2 instance families
Correct answer: Designing systems to remain operational despite component failures by eliminating single points of failure
High availability means designing architectures with redundancy and automatic failover so systems remain accessible even when individual components fail.
Question 45: Which AWS Support plan provides the fastest response time for a business-critical system outage?
- Business (1-hour)
- Basic (no SLA)
- Enterprise (15-minute) (Correct answer)
- Developer (12-hour business hours)
Correct answer: Enterprise (15-minute)
AWS Enterprise Support provides a 15-minute response SLA for business-critical system outages, the fastest of all support tiers.
Question 46: Which AWS service helps you centrally manage and enforce policies across multiple AWS accounts in an organization?
- AWS Config
- AWS IAM
- AWS Control Tower
- AWS Organizations (Correct answer)
Correct answer: AWS Organizations
AWS Organizations lets you consolidate multiple accounts and apply Service Control Policies (SCPs) to govern access across your entire organization.
Question 47: Which AWS service scans EC2 instances and container images for software vulnerabilities and unintended network exposure?
- Amazon Inspector (Correct answer)
- Amazon Macie
- AWS Security Hub
- AWS Shield
Correct answer: Amazon Inspector
Amazon Inspector automatically assesses EC2 instances and ECR container images for vulnerabilities and deviations from best practices.
Question 48: Which AWS service helps you assess your on-premises workloads and plan your migration to AWS by collecting server data?
- AWS Migration Hub
- AWS Database Migration Service
- AWS Application Discovery Service (Correct answer)
- AWS Transfer Family
Correct answer: AWS Application Discovery Service
AWS Application Discovery Service collects data about on-premises servers including CPU, memory, and network usage to inform migration planning.
Question 49: What does AWS WAF protect against?
- DDoS attacks at the network layer
- Data loss in S3 buckets
- Common web exploits such as SQL injection and cross-site scripting (Correct answer)
- Unauthorized access to AWS accounts
Correct answer: Common web exploits such as SQL injection and cross-site scripting
AWS WAF (Web Application Firewall) protects web applications from common exploits like SQL injection and XSS that could affect availability or compromise security.
Question 50: Which AWS support plan is the minimum level that provides access to a Technical Account Manager (TAM)?
- Enterprise (Correct answer)
- Enterprise On-Ramp
- Business
- Developer
Correct answer: Enterprise
A dedicated Technical Account Manager (TAM) is included with the AWS Enterprise Support plan.
Question 51: Which AWS Well-Architected Framework pillar focuses on protecting data, systems, and assets through risk assessments and mitigation?
- Performance Efficiency
- Cost Optimization
- Reliability
- Security (Correct answer)
Correct answer: Security
The Security pillar of the Well-Architected Framework covers identity management, detecting incidents, protecting data, and automating security best practices.
Question 52: Which service allows you to centrally manage security policies and compliance across multiple AWS accounts?
- Amazon Cognito
- AWS Organizations with Service Control Policies (Correct answer)
- AWS Control Tower
- AWS IAM
Correct answer: AWS Organizations with Service Control Policies
AWS Organizations with Service Control Policies (SCPs) lets you centrally manage and enforce permission guardrails across all accounts in your organization.
Question 53: Without allowing the traffic to pass across the open internet, Auto Car must deploy AWS resources on-premises. What should they configure to do this?
- NAT Gateway
- AWS Site-to-Site Virtual Private Network
- AWS Direct Connect (Correct answer)
- Virtual Private Cloud
Correct answer: AWS Direct Connect
Organizations should utilize Direct Connect to connect to the AWS cloud directly, avoiding the usage of the open internet. A connection to an AWS Direct Connect site must be purchased or rented by the organization in order to use this.
Question 54: A company wants to run code without provisioning or managing servers. Which AWS service should they use?
- Amazon ECS
- Amazon EC2
- AWS Elastic Beanstalk
- AWS Lambda (Correct answer)
Correct answer: AWS Lambda
AWS Lambda lets you run code without provisioning servers, charging only for compute time consumed during execution.
Question 55: Which Amazon S3 storage class is designed for data that is accessed infrequently but requires millisecond retrieval?
- S3 Glacier Instant Retrieval
- S3 Standard
- S3 One Zone-IA
- S3 Standard-IA (Correct answer)
Correct answer: S3 Standard-IA
S3 Standard-IA (Infrequent Access) is for data accessed less often but still needs rapid access when retrieved, at a lower storage cost than S3 Standard.
Question 56: What is the benefit of using resource tags in AWS for cost management?
- Tags automatically reduce costs
- Tags enable cost allocation so you can track spending by project, team, or environment (Correct answer)
- Tags are required to launch EC2 instances
- Tags improve application performance
Correct answer: Tags enable cost allocation so you can track spending by project, team, or environment
Resource tags are key-value pairs that allow you to categorize AWS resources and then view cost allocation reports broken down by tag.
Question 57: Which AWS service streams real-time data at scale, such as log data, clickstreams, or IoT telemetry?
- Amazon Kinesis (Correct answer)
- Amazon SQS
- Amazon EMR
- AWS Glue
Correct answer: Amazon Kinesis
Amazon Kinesis is a platform for collecting, processing, and analyzing real-time streaming data like application logs, website clickstreams, and IoT sensor data.
Question 58: Which AWS service is used to send automated notifications via email, SMS, or HTTP endpoints?
- Amazon SES
- Amazon SNS (Correct answer)
- AWS EventBridge
- Amazon SQS
Correct answer: Amazon SNS
Amazon Simple Notification Service (SNS) is a fully managed pub/sub messaging service that sends notifications to subscribers via multiple protocols.
Question 59: Under the AWS Shared Responsibility Model, who is responsible for patching the guest operating system on an Amazon EC2 instance?
- A third-party vendor
- Both AWS and the customer equally
- AWS
- The customer (Correct answer)
Correct answer: The customer
Under the shared responsibility model, the customer is responsible for patching and maintaining the guest OS on EC2 instances.
Question 60: Which AWS service provides DDoS protection at no additional cost for all AWS customers?
- AWS Shield Advanced
- AWS Shield Standard (Correct answer)
- Amazon CloudFront
- AWS WAF
Correct answer: AWS Shield Standard
AWS Shield Standard is automatically included for all AWS customers at no extra charge and protects against common DDoS attacks.
Question 61: What does 'infrastructure as code' (IaC) mean in cloud architecture?
- Using GUI consoles to configure services
- Defining and managing infrastructure through machine-readable configuration files (Correct answer)
- Manually scripting server configurations in bash
- Writing application code that runs on servers
Correct answer: Defining and managing infrastructure through machine-readable configuration files
Infrastructure as Code means defining your servers, networks, and services in code files (like CloudFormation templates), enabling repeatable, version-controlled deployments.
Question 62: Under the AWS Shared Responsibility Model, which of the following is AWS responsible for?
- Encrypting application data
- Configuring security groups
- Physical security of data centers (Correct answer)
- Managing IAM users and roles
Correct answer: Physical security of data centers
AWS is responsible for the security OF the cloud, including physical infrastructure, hardware, and the hypervisor layer.
Question 63: Which AWS service lets you set fine-grained permissions for AWS services and resources using JSON-based policies?
- AWS Control Tower
- AWS Organizations
- Amazon Cognito
- AWS IAM (Correct answer)
Correct answer: AWS IAM
AWS Identity and Access Management (IAM) lets you manage access to AWS services and resources securely using policies.
Question 64: Which AWS service enables multi-factor authentication (MFA) enforcement for IAM users?
- AWS Directory Service
- AWS IAM (Correct answer)
- AWS SSO
- Amazon Cognito
Correct answer: AWS IAM
AWS IAM allows administrators to require MFA for individual users or enforce it via IAM policies across the account.
Question 65: Which deployment strategy releases new application versions to a small subset of users before a full rollout?
- Rolling Deployment
- Blue/Green Deployment
- Canary Deployment (Correct answer)
- Immutable Deployment
Correct answer: Canary Deployment
A Canary deployment routes a small percentage of traffic to the new version first, allowing issues to be detected before affecting all users.
AWS Certified Cloud Practitioner (CLF-C02)
The AWS Certified Cloud Practitioner validates foundational, high-level understanding of AWS Cloud concepts, services, security, and economics. It is intended for individuals seeking to demonstrate overall AWS knowledge independent of a specific job role.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds