AWS Certified Cloud Practitioner (CLF-C02) — Questions and Answers
Question 1: Which AWS Well-Architected pillar focuses on using cloud resources efficiently to deliver business value?
- Operational Excellence
- Performance Efficiency (Correct answer)
- Reliability
- Cost Optimization
Correct answer: Performance Efficiency
The Performance Efficiency pillar focuses on using computing resources efficiently and maintaining that efficiency as demand changes and technologies evolve.
Question 2: What does 'designing for failure' mean in AWS cloud architecture?
- Building systems that assume component failures will happen and remain operational anyway (Correct answer)
- Running systems in degraded mode permanently
- Expecting systems to always fail
- Reducing feature scope to avoid bugs
Correct answer: Building systems that assume component failures will happen and remain operational anyway
Designing for failure means architecting systems with redundancy and auto-recovery so they remain available even when individual components fail.
Question 3: What is the maximum retention period for Amazon S3 object lock in compliance mode?
- 7 years
- 1 year
- 100 years (Correct answer)
- 10 years
Correct answer: 100 years
Amazon S3 Object Lock in compliance mode supports retention periods up to 100 years to meet strict regulatory requirements.
Question 4: Which Well-Architected Framework pillar addresses reducing the environmental impact of your cloud workloads?
- Sustainability (Correct answer)
- Performance Efficiency
- Cost Optimization
- Operational Excellence
Correct answer: Sustainability
The Sustainability pillar, added in 2021, focuses on minimizing the environmental impact of running cloud workloads through efficient resource utilization.
Question 5: What is VPC Peering?
- A networking connection between two VPCs that enables routing traffic between them using private IP addresses (Correct answer)
- A service that replicates your VPC configuration to multiple AWS Regions automatically
- A method to connect your VPC to the public internet through a managed gateway
- A tool that monitors network traffic between subnets for security threats
Correct answer: A networking connection between two VPCs that enables routing traffic between them using private IP addresses
VPC Peering is a networking connection between two VPCs that enables you to route traffic between them using private IPv4 or IPv6 addresses, as if they were in the same network.
Question 6: What is the benefit of deploying an application across multiple AWS Availability Zones?
- Lower data transfer costs
- Increased fault tolerance and high availability (Correct answer)
- Simplified IAM management
- Faster global content delivery
Correct answer: Increased fault tolerance and high availability
Deploying across multiple Availability Zones ensures that a failure in one zone does not take down the entire application, improving high availability.
Question 7: Which service centralizes security findings from multiple AWS security services into a single dashboard?
- AWS CloudTrail
- AWS Security Hub (Correct answer)
- AWS Config
- Amazon Detective
Correct answer: AWS Security Hub
AWS Security Hub aggregates, organizes, and prioritizes security findings from services like GuardDuty, Inspector, and Macie in one place.
Question 8: Which AWS Support plan is the minimum tier that offers 24/7 access to Cloud Support Engineers via phone, chat, and email?
- Enterprise
- Developer
- Business (Correct answer)
- Basic
Correct answer: Business
AWS Business Support is the minimum plan that includes 24/7 access to Cloud Support Engineers via phone, chat, and email, plus a 1-hour response SLA for urgent issues.
Question 9: What is an IAM role used for in AWS?
- Granting temporary permissions to entities that need access to AWS resources (Correct answer)
- Creating groups of users with shared permissions
- Storing long-term access credentials for a user
- Defining password policies for AWS accounts
Correct answer: Granting temporary permissions to entities that need access to AWS resources
IAM roles are used to delegate access to AWS resources with temporary security credentials, without sharing long-term keys.
Question 10: Which design principle recommends replacing failed components automatically rather than fixing them in place?
- Principle of Least Privilege
- Treat servers as cattle, not pets (Correct answer)
- Defense in Depth
- Infrastructure as Code
Correct answer: Treat servers as cattle, not pets
The 'cattle not pets' principle means servers are disposable and interchangeable — when one fails, it's replaced automatically rather than manually nursed back to health.
Question 11: Which S3 storage class is designed for data that is accessed less than once a month and requires millisecond retrieval?
- S3 One Zone-IA
- S3 Standard-Infrequent Access (S3 Standard-IA) (Correct answer)
- S3 Standard
- S3 Glacier
Correct answer: S3 Standard-Infrequent Access (S3 Standard-IA)
S3 Standard-IA is for data accessed less frequently but that requires rapid access when needed — it has lower storage cost but a per-retrieval fee.
Question 12: Which AWS service provides a centralized view of security alerts and compliance status across your AWS accounts?
- AWS Shield
- AWS Security Hub (Correct answer)
- Amazon GuardDuty
- AWS Inspector
Correct answer: AWS Security Hub
AWS Security Hub provides a comprehensive view of your security state in AWS and helps you check your environment against security industry standards.
Question 13: What is a VPC Endpoint used for?
- To allow private communication between a VPC and supported AWS services without requiring internet access (Correct answer)
- To monitor and log all network traffic within a VPC for compliance purposes
- To extend a VPC's IP address range when the original CIDR block is exhausted
- To expose a private application to the public internet through a managed gateway
Correct answer: To allow private communication between a VPC and supported AWS services without requiring internet access
A VPC Endpoint enables private connections between your VPC and supported AWS services without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect.
Question 14: What does AWS data sovereignty mean in the context of Regions?
- Data is replicated globally by default for redundancy
- Your data does not leave a Region unless you explicitly move it (Correct answer)
- AWS owns all data stored in its cloud
- Only AWS employees can access data in government regions
Correct answer: Your data does not leave a Region unless you explicitly move it
AWS guarantees that your data and services stay within the Region you choose unless you take explicit actions to replicate or transfer data elsewhere.
Question 15: A company needs to run a Windows-based application on AWS with complete control over the underlying server. Which option is best?
- Amazon EC2 Dedicated Hosts (Correct answer)
- AWS Fargate
- Amazon Lightsail
- AWS Lambda
Correct answer: Amazon EC2 Dedicated Hosts
EC2 Dedicated Hosts provide a physical server fully dedicated to your use, giving complete control over instance placement and underlying hardware.
Question 16: What does 'high availability' mean in AWS architecture?
- Using only the latest EC2 instance families
- Designing systems to remain operational despite component failures by eliminating single points of failure (Correct answer)
- Running instances with premium hardware
- Guaranteed zero downtime
Correct answer: Designing systems to remain operational despite component failures by eliminating single points of failure
High availability means designing architectures with redundancy and automatic failover so systems remain accessible even when individual components fail.
Question 17: What is the primary difference between AWS Developer Support and AWS Business Support?
- Developer includes a TAM; Business does not
- Business includes 24/7 phone and chat support; Developer is email-only during business hours (Correct answer)
- Developer supports multiple accounts; Business supports one
- Business is free; Developer is paid
Correct answer: Business includes 24/7 phone and chat support; Developer is email-only during business hours
AWS Developer Support provides email support during business hours, while Business Support adds 24/7 phone, chat, and faster response SLAs.
Question 18: What is the purpose of AWS Artifact?
- Monitoring network traffic
- Providing on-demand access to AWS compliance reports and agreements (Correct answer)
- Scanning for security vulnerabilities
- Managing encryption keys
Correct answer: Providing on-demand access to AWS compliance reports and agreements
AWS Artifact is a self-service portal for accessing AWS compliance reports, certifications, and agreements such as SOC, PCI, and ISO.
Question 19: A Cosmo Property AWS solution architect is outlining the advantages of transferring a data center to the cloud. What is the main advantage of this?
- Cost savings due to provisioning and decommissioning of resources based on varying traffic and workloads (Correct answer)
- Secured storage, retrieval and transmission of data
- Eliminating dependence on internet connections
- Avoiding patch management and its associated costs
Correct answer: Cost savings due to provisioning and decommissioning of resources based on varying traffic and workloads
A data center's ability to adapt to seasonal workload will enhance after moving to the AWS cloud. Since it has to do with IT infrastructure resources, elasticity can increase or decrease allotted resources in accordance with compute and storage needs. An e-commerce site could scale back its web server during peak buying seasons or hours.
Question 20: Which of the following is NOT a benefit of moving to the AWS cloud?
- Trading capital expense for variable expense
- Eliminating the need to guess capacity
- Eliminating all operational responsibilities (Correct answer)
- Increasing speed and agility
Correct answer: Eliminating all operational responsibilities
Moving to AWS reduces but does not eliminate all operational responsibilities; customers still manage their applications, data, and some infrastructure.
Question 21: Which AWS service scans EC2 instances and container images for software vulnerabilities and unintended network exposure?
- Amazon Inspector (Correct answer)
- Amazon Macie
- AWS Security Hub
- AWS Shield
Correct answer: Amazon Inspector
Amazon Inspector automatically assesses EC2 instances and ECR container images for vulnerabilities and deviations from best practices.
Question 22: Which deployment strategy releases new application versions to a small subset of users before a full rollout?
- Immutable Deployment
- Blue/Green Deployment
- Canary Deployment (Correct answer)
- Rolling Deployment
Correct answer: Canary Deployment
A Canary deployment routes a small percentage of traffic to the new version first, allowing issues to be detected before affecting all users.
Question 23: Which AWS pricing benefit consolidates billing for multiple accounts and applies volume discounts across the entire organization?
- Consolidated Billing (Correct answer)
- Savings Plans
- Reserved Instance Sharing
- Enterprise Discount Program
Correct answer: Consolidated Billing
Consolidated Billing through AWS Organizations combines usage across all member accounts, enabling volume pricing tiers and a single invoice.
Question 24: What AWS tool helps you identify S3 buckets that contain sensitive data such as PII?
- AWS Trusted Advisor
- AWS Inspector
- Amazon Macie (Correct answer)
- Amazon GuardDuty
Correct answer: Amazon Macie
Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data in Amazon S3.
Question 25: Which AWS encryption option allows you to manage your own encryption keys using dedicated hardware security modules?
- AWS CloudHSM (Correct answer)
- AWS Secrets Manager
- AWS KMS with AWS-managed keys
- Server-Side Encryption with S3 keys
Correct answer: AWS CloudHSM
AWS CloudHSM provides dedicated Hardware Security Modules so you have full control over your encryption keys.
Question 26: Which AWS pricing model lets you commit to a consistent amount of compute usage (measured in $/hour) for 1 or 3 years across any EC2 instance family?
- Spot Instances
- Reserved Instances
- Savings Plans (Correct answer)
- Dedicated Hosts
Correct answer: Savings Plans
Savings Plans offer flexible pricing in exchange for a commitment to a consistent usage level in $/hour for 1 or 3 years, applying across instance families and regions.
Question 27: What does 'infrastructure as code' (IaC) mean in cloud architecture?
- Defining and managing infrastructure through machine-readable configuration files (Correct answer)
- Using GUI consoles to configure services
- Writing application code that runs on servers
- Manually scripting server configurations in bash
Correct answer: Defining and managing infrastructure through machine-readable configuration files
Infrastructure as Code means defining your servers, networks, and services in code files (like CloudFormation templates), enabling repeatable, version-controlled deployments.
Question 28: Which AWS service provides a fully managed message queuing service to decouple application components?
- Amazon MQ
- Amazon SQS (Correct answer)
- AWS EventBridge
- Amazon SNS
Correct answer: Amazon SQS
Amazon SQS (Simple Queue Service) is a fully managed message queuing service that enables decoupling of application components.
Question 29: Which AWS feature allows you to consolidate billing across multiple AWS accounts and potentially receive volume discounts?
- AWS Pricing Calculator
- AWS Organizations consolidated billing (Correct answer)
- AWS Budgets
- AWS Cost Explorer
Correct answer: AWS Organizations consolidated billing
AWS Organizations consolidated billing lets you combine usage across all accounts to qualify for volume pricing tiers and view all charges in a single bill.
Question 30: Which service continuously monitors AWS accounts and workloads for malicious activity using machine learning and threat intelligence?
- AWS Security Hub
- Amazon Macie
- Amazon Inspector
- Amazon GuardDuty (Correct answer)
Correct answer: Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously analyzes CloudTrail logs, VPC Flow Logs, and DNS logs to identify suspicious activity.
AWS Certified Cloud Practitioner (CLF-C02)
The AWS Certified Cloud Practitioner validates foundational, high-level understanding of AWS Cloud concepts, services, security, and economics. It is intended for individuals seeking to demonstrate overall AWS knowledge independent of a specific job role.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds