AWS Certified Cloud Practitioner (CLF-C02) — Questions and Answers
Question 1: Which metric does AWS use to charge for Amazon S3 storage?
- Number of S3 buckets created
- Number of EC2 instances connected to S3
- Total storage used per gigabyte per month (Correct answer)
- Number of IAM users accessing the bucket
Correct answer: Total storage used per gigabyte per month
Amazon S3 charges based on the amount of data stored (GB per month), along with additional charges for requests, data retrieval, and data transfer out.
Question 2: A company's EC2 instances in a private subnet need to access AWS services like S3 and DynamoDB. Which solution keeps this traffic within the AWS network?
- Use NAT Gateway for all AWS service traffic
- Set up AWS Direct Connect
- Use VPC Endpoints for S3 and DynamoDB (Correct answer)
- Route all traffic through an Internet Gateway
Correct answer: Use VPC Endpoints for S3 and DynamoDB
VPC Endpoints (Gateway Endpoints for S3 and DynamoDB, Interface Endpoints for other services) allow private connectivity to AWS services without traversing the public internet.
Question 3: Which professional attribute is most valued in billing and pricing within the CLF-C02 field?
- Accountability and commitment to standards (Correct answer)
- Working in isolation
- Prioritizing personal convenience
- Avoiding challenging situations
Correct answer: Accountability and commitment to standards
Accountability and commitment to professional standards build trust and ensure consistent, high-quality practice.
Question 4: Which AWS storage class is designed for data that is accessed less than once a month and offers the lowest storage cost in S3?
- S3 Standard-IA
- S3 Glacier Deep Archive (Correct answer)
- S3 Standard
- S3 One Zone-IA
Correct answer: S3 Glacier Deep Archive
S3 Glacier Deep Archive is the lowest-cost S3 storage class, designed for long-term retention of data accessed rarely (once or twice a year).
Question 5: A developer account accidentally leaves a large EC2 instance running for an entire month. How does AWS charge for this usage?
- AWS charges only for the first 72 hours as a trial period
- AWS charges for the full month of On-Demand usage at standard rates (Correct answer)
- AWS caps the charge at the Reserved Instance equivalent price
- AWS waives the charge since it was accidental
Correct answer: AWS charges for the full month of On-Demand usage at standard rates
AWS charges for all running EC2 instances at On-Demand rates based on actual usage time, regardless of intent; there are no automatic waivers for accidental usage.
Question 6: What does the principle of 'design for failure' mean in AWS cloud architecture?
- Intentionally introducing bugs to test systems
- Assuming components will fail and building systems that continue operating (Correct answer)
- Failing fast to reduce development time
- Designing minimal viable products
Correct answer: Assuming components will fail and building systems that continue operating
Designing for failure means assuming any component can fail at any time and architecting systems to continue functioning despite those failures.
Question 7: A company wants to avoid upfront capital expenses for IT infrastructure and instead pay only for what they use. Which cloud benefit does this represent?
- Increased speed and agility
- Economies of scale
- Stop guessing capacity
- Trade capital expense for variable expense (Correct answer)
Correct answer: Trade capital expense for variable expense
Trading capital expense (CapEx) for variable expense (OpEx) is a key cloud benefit that lets companies pay only for what they consume.
Question 8: What is VPC Peering?
- A networking connection between two VPCs that enables traffic routing using private IP addresses (Correct answer)
- A way to connect VPCs to the internet
- A service that monitors VPC traffic flow
- A VPN connection between AWS and on-premises networks
Correct answer: A networking connection between two VPCs that enables traffic routing using private IP addresses
VPC Peering is a networking connection between two VPCs that allows traffic to be routed between them using private IPv4 or IPv6 addresses as if on the same network.
Question 9: Which AWS service enables you to estimate the cost of a new AWS architecture before you build it?
- AWS Trusted Advisor
- AWS Pricing Calculator (Correct answer)
- AWS Budgets
- AWS Cost Explorer
Correct answer: AWS Pricing Calculator
AWS Pricing Calculator lets you model your architecture and generate an estimated monthly cost before provisioning any resources.
Question 10: Which AWS service provides a managed relational database that automates backups, patching, and failover?
- Amazon RDS (Correct answer)
- Amazon ElastiCache
- Amazon DynamoDB
- Amazon Redshift
Correct answer: Amazon RDS
Amazon RDS (Relational Database Service) automates common DBA tasks like backups, software patching, and multi-AZ failover.
Question 11: Which AWS tool provides a centralized view of billing and usage across multiple AWS accounts in an organization?
- AWS Trusted Advisor
- AWS Cost Explorer
- AWS Organizations with Consolidated Billing (Correct answer)
- AWS Budgets
Correct answer: AWS Organizations with Consolidated Billing
AWS Organizations with Consolidated Billing aggregates charges from all member accounts into a single payer account, simplifying billing management.
Question 12: Which EC2 pricing model provides the highest potential discount but can be interrupted by AWS with a two-minute warning?
- Dedicated Hosts
- Reserved Instances
- Savings Plans
- Spot Instances (Correct answer)
Correct answer: Spot Instances
Spot Instances can provide up to 90% discount compared to On-Demand pricing but AWS can reclaim them when capacity is needed, with a two-minute interruption notice.
Question 13: Which AWS Well-Architected Framework pillar focuses on protecting information and systems?
- Security (Correct answer)
- Performance Efficiency
- Reliability
- Cost Optimization
Correct answer: Security
The Security pillar encompasses the ability to protect data, systems, and assets to take advantage of cloud technologies to improve security.
Question 14: Which AWS service runs managed Kubernetes clusters, abstracting away the control plane management?
- Amazon EKS (Correct answer)
- Amazon ECS
- AWS App Runner
- AWS Fargate
Correct answer: Amazon EKS
Amazon Elastic Kubernetes Service (EKS) provides a managed Kubernetes control plane, handling upgrades, patching, and availability automatically.
Question 15: A customer wants to understand who is responsible for applying security patches to an AWS managed NAT Gateway. Who handles this?
- AWS, because NAT Gateway is a managed service maintained by AWS (Correct answer)
- The customer, because network components are the customer's responsibility
- The customer and AWS share patching responsibility equally
- AWS provides patches but the customer must apply them
Correct answer: AWS, because NAT Gateway is a managed service maintained by AWS
NAT Gateway is a fully managed AWS service, so AWS is responsible for patching and maintaining the underlying infrastructure.
Question 16: How does the Shared Responsibility Model change when a customer moves from EC2 to AWS Fargate?
- The customer becomes responsible for the underlying hardware
- Responsibility remains exactly the same
- The customer takes on more responsibility for OS management
- AWS takes on more responsibility as it manages the container infrastructure (Correct answer)
Correct answer: AWS takes on more responsibility as it manages the container infrastructure
With Fargate, AWS manages the underlying container infrastructure and OS, reducing the customer's operational responsibilities compared to EC2.
Question 17: Which task is the customer responsible for when using Amazon EC2?
- Replacing failed physical hard drives
- Maintaining power and cooling in the data center
- Patching the guest operating system (Correct answer)
- Managing the virtualization layer
Correct answer: Patching the guest operating system
With EC2, customers are responsible for patching and maintaining the guest operating system running on their instances.
Question 18: What is the shared responsibility model in AWS?
- The customer is responsible for everything in the cloud.
- AWS and the customer share different responsibilities based on services used (Correct answer)
- AWS is responsible for securing all customer data.
- Security is managed by third-party services only.
Correct answer: AWS and the customer share different responsibilities based on services used
The AWS Shared Responsibility Model defines security responsibilities between AWS and the customer. AWS is responsible for the security *of* the cloud, meaning the underlying infrastructure, while the customer is responsible for security *in* the cloud, which includes their data, applications, operating systems, and network configurations. This division ensures clarity and accountability for different aspects of cloud security.
Question 19: Which AWS pricing model offers the largest discount (up to 90%) compared to On-Demand pricing in exchange for a one- or three-year commitment?
- Spot Instances (Correct answer)
- Savings Plans
- Dedicated Hosts
- Reserved Instances
Correct answer: Spot Instances
Spot Instances use spare AWS capacity and can be up to 90% cheaper than On-Demand, though AWS can reclaim them with a 2-minute warning.
Question 20: What AWS service provides content delivery with low latency?
- AWS Elastic Beanstalk
- Amazon CloudFront (Correct answer)
- Amazon S3
- Amazon Route 53
Correct answer: Amazon CloudFront
Amazon CloudFront is a Content Delivery Network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency. It achieves this by caching content at edge locations closer to users, reducing the distance data travels. This significantly improves performance and user experience for web applications and content delivery.
Question 21: A company wants to receive compliance reports and security documentation about AWS services such as SOC 2 and ISO 27001. Which service should they use?
- AWS Security Hub
- AWS Trusted Advisor
- AWS Artifact (Correct answer)
- AWS Config
Correct answer: AWS Artifact
AWS Artifact is a self-service portal that provides on-demand access to AWS compliance reports and security agreements such as SOC, PCI, and ISO certifications.
Question 22: Which AWS service provides virtual servers?
- Amazon EC2 (Correct answer)
- Amazon CloudFront
- Amazon Redshift
- Amazon S3
Correct answer: Amazon EC2
Amazon EC2 (Elastic Compute Cloud) is the AWS service that provides resizable compute capacity in the cloud, essentially offering virtual servers. Users can launch and configure virtual machines (instances) with various operating systems and software, scaling them up or down as needed. EC2 is fundamental for running applications, websites, and performing computational tasks without the need for physical hardware.
Question 23: Which of the following is a security best practice for the AWS root account?
- Use the root account for daily administrative tasks to save time
- Enable MFA and avoid using the root account for routine tasks (Correct answer)
- Share root account credentials with trusted team members only
- Create access keys for the root account for programmatic access
Correct answer: Enable MFA and avoid using the root account for routine tasks
AWS best practice is to enable MFA on the root account and use it only for tasks that absolutely require root access, performing all other work with IAM users or roles.
Question 24: Which AWS service enables management of user access and permissions?
- AWS CloudTrail
- Amazon SQS
- AWS Shield
- AWS IAM (Correct answer)
Correct answer: AWS IAM
AWS Identity and Access Management (IAM) is a web service that helps you securely control access to AWS resources. With IAM, you can manage users, groups, and roles, and define granular permissions to specify who can access which services and resources under what conditions. This ensures that only authorized entities can perform specific actions within your AWS environment.
Question 25: What happens to the overall per-unit price when a company uses Consolidated Billing with multiple AWS accounts that have high S3 usage?
- Only the payer account qualifies for volume discounts
- Each account is billed separately at standard rates
- AWS charges a consolidation fee on top of usage
- Usage is combined, potentially reaching lower pricing tiers (Correct answer)
Correct answer: Usage is combined, potentially reaching lower pricing tiers
Consolidated Billing combines usage across all member accounts, which can help the organization cross volume discount tiers faster and reduce per-unit costs.
Question 26: What is the MOST effective way for new CLF-C02 professionals to build competency in their field?
- Studying certification materials exclusively
- Focusing solely on the most advanced topics
- Learning entirely through trial and error
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 27: A solutions architect needs to run EC2 instances that are physically isolated at the host level but does NOT need to use their own software licenses. Which option should they choose?
- Spot Instances
- Dedicated Instances (Correct answer)
- Reserved Instances
- Dedicated Hosts
Correct answer: Dedicated Instances
Dedicated Instances run on hardware dedicated to a single customer but AWS manages host placement; Dedicated Hosts are needed when per-host visibility and license control are required.
Question 28: What is the primary purpose of AWS Identity and Access Management (IAM)?
- To monitor AWS infrastructure performance
- To configure network security groups
- To manage encryption keys for AWS services
- To control who can access AWS services and what actions they can perform (Correct answer)
Correct answer: To control who can access AWS services and what actions they can perform
IAM is used to manage authentication and authorization, controlling which users and services can access AWS resources and what actions they can take.
Question 29: Which AWS architecture principle suggests avoiding manual processes and using automation wherever possible?
- Allow for evolutionary architectures
- Test systems at production scale
- Stop guessing capacity needs
- Automate to make architectural experimentation easier (Correct answer)
Correct answer: Automate to make architectural experimentation easier
Automating changes allows you to create and replicate workloads at low cost and avoid the expense of manual effort.
Question 30: A developer accidentally committed AWS access keys to a public GitHub repository. What is the FIRST action they should take?
- Change their AWS account root email
- Enable MFA on their GitHub account
- Delete the GitHub repository
- Rotate or deactivate the compromised access keys immediately (Correct answer)
Correct answer: Rotate or deactivate the compromised access keys immediately
Immediately rotating or deactivating the exposed access keys prevents unauthorized use before any damage can be done.
Question 31: How does the CLF-C02 body of knowledge relate to daily professional practice?
- It is relevant only for academic research
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
- It is theoretical and has limited practical application
- It only applies during certification exams
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 32: Which risk management approach is MOST effective for CLF-C02 professionals when evaluating potential workplace hazards?
- Proactive hazard identification and assessment (Correct answer)
- Relying solely on historical accident data
- Delegating all safety decisions to management
- Reactive analysis after incidents occur
Correct answer: Proactive hazard identification and assessment
Proactive hazard identification and assessment allows professionals to identify and mitigate risks before incidents occur, which is far more effective than reactive approaches that only address problems after they happen.
Question 33: Which AWS service provides a virtual private network connection between an on-premises network and a VPC using the public internet?
- Amazon VPC Peering
- AWS Transit Gateway
- AWS Direct Connect
- AWS VPN (Correct answer)
Correct answer: AWS VPN
AWS VPN creates an encrypted IPsec tunnel over the public internet connecting your on-premises network to your VPC.
Question 34: Which AWS service provides DDoS protection automatically for all AWS customers at no additional cost?
- AWS Firewall Manager
- AWS WAF
- AWS Shield Advanced
- AWS Shield Standard (Correct answer)
Correct answer: AWS Shield Standard
AWS Shield Standard is automatically enabled for all AWS customers at no extra charge and provides protection against common network and transport layer DDoS attacks.
Question 35: Which AWS database service is MongoDB-compatible and fully managed?
- Amazon QLDB
- Amazon Keyspaces
- Amazon DocumentDB (Correct answer)
- Amazon Neptune
Correct answer: Amazon DocumentDB
Amazon DocumentDB is a fully managed document database service that is compatible with MongoDB workloads and drivers.
Question 36: AWS Security Groups act as virtual firewalls. What is a key characteristic that differentiates them from Network ACLs?
- Security groups support deny rules
- Security groups operate at the subnet level
- Security groups are stateless
- Security groups are stateful and track connection state (Correct answer)
Correct answer: Security groups are stateful and track connection state
Security groups are stateful, meaning if you allow inbound traffic on a port, the return traffic is automatically allowed without needing an explicit outbound rule.
Question 37: In CLF-C02 certification, what does redundancy in system design primarily provide?
- Lower initial cost
- Fault tolerance and high availability (Correct answer)
- Simplified maintenance
- Increased complexity
Correct answer: Fault tolerance and high availability
Redundancy provides fault tolerance by ensuring that if one component fails, backup components maintain system availability.
Question 38: What is the AWS Free Tier offer for Amazon EC2 in the first 12 months?
- 750 hours per month of t2.micro or t3.micro instances (Correct answer)
- Unlimited t2.nano usage for 12 months
- 1,000 hours per month of t3.small instances
- 500 hours per month of any EC2 instance type
Correct answer: 750 hours per month of t2.micro or t3.micro instances
The AWS Free Tier provides 750 hours per month of t2.micro (or t3.micro in regions where t2.micro is unavailable) Linux/Windows instances for 12 months.
Question 39: A company uses AWS Organizations with multiple accounts. Under the Shared Responsibility Model, who manages the AWS account root user credentials?
- AWS manages root credentials for security purposes
- AWS Support can manage root credentials on behalf of customers
- The customer is responsible for securing and restricting root user access (Correct answer)
- Root credentials are shared between AWS and the customer
Correct answer: The customer is responsible for securing and restricting root user access
Customers are fully responsible for securing root user credentials, including enabling MFA and avoiding routine use of the root account.
Question 40: How are AWS Lambda function costs primarily calculated?
- By the number of requests and duration of execution (Correct answer)
- By the amount of memory allocated only
- By the number of functions deployed
- By the number of concurrent executions per hour
Correct answer: By the number of requests and duration of execution
Lambda charges are based on the total number of requests and the duration (in GB-seconds) each function runs, with a generous free tier included.
Question 41: What is a key benefit of using a microservices architecture compared to a monolithic architecture in the cloud?
- Easier initial development
- Independent scaling and deployment of individual services (Correct answer)
- Reduced number of API calls
- Lower network latency between components
Correct answer: Independent scaling and deployment of individual services
Microservices allow each service to be scaled, deployed, and updated independently, improving agility and resource efficiency.
Question 42: Which type of policy is used with AWS Organizations to set the maximum available permissions for all accounts within an organization or organizational unit?
- Service Control Policy (SCP) (Correct answer)
- Permissions boundary
- Identity-based policy
- Resource-based policy
Correct answer: Service Control Policy (SCP)
Service Control Policies (SCPs) are applied at the AWS Organizations level to set guardrails on the maximum permissions available to accounts within an organization or OU.
Question 43: A startup needs a simple way to host a static website with low latency globally. Which AWS combination is most cost-effective?
- Elastic Beanstalk + RDS
- Lambda + API Gateway
- S3 + CloudFront (Correct answer)
- EC2 + EBS
Correct answer: S3 + CloudFront
Amazon S3 can host static website files, and CloudFront serves them from edge locations worldwide with low latency at minimal cost.
Question 44: Which approach best demonstrates mastery of shared responsibility in CLF-C02 practice?
- Following procedures without understanding
- Applying principles to novel situations with sound judgment (Correct answer)
- Relying entirely on technology
- Avoiding complex scenarios
Correct answer: Applying principles to novel situations with sound judgment
True mastery involves understanding underlying principles well enough to apply them to new and unfamiliar situations with professional judgment.
Question 45: What does 'encryption at rest' mean in the context of AWS security?
- Applications pause encryption during maintenance windows
- Encryption keys are kept offline in a secure facility
- Data stored on disk or in a database is encrypted when not actively being used (Correct answer)
- Data is encrypted while being transmitted over a network
Correct answer: Data stored on disk or in a database is encrypted when not actively being used
Encryption at rest means that data stored on physical media (disks, databases, backups) is encrypted to protect it from unauthorized physical access.
Question 46: What is one key advantage of using cloud over on-premises infrastructure?
- More physical space needed
- Scalability and elasticity (Correct answer)
- Increased capital expenditure
- Manual server configuration
Correct answer: Scalability and elasticity
Scalability and elasticity are key advantages of cloud computing over on-premises infrastructure. Cloud environments allow you to easily scale resources up or down automatically based on demand, ensuring your applications can handle varying workloads without over-provisioning. This dynamic adjustment of resources helps optimize costs and maintain performance, which is difficult and expensive to achieve with fixed on-premises hardware.
Question 47: A company is evaluating whether to use AWS for storing health data subject to HIPAA. What does the Shared Responsibility Model imply about HIPAA compliance?
- AWS provides HIPAA-eligible services, but customers must configure and use them correctly to achieve compliance (Correct answer)
- HIPAA compliance is not possible on public cloud platforms
- AWS handles all HIPAA requirements on behalf of the customer
- Using AWS automatically makes the application HIPAA-compliant
Correct answer: AWS provides HIPAA-eligible services, but customers must configure and use them correctly to achieve compliance
AWS offers HIPAA-eligible services and signs a BAA, but customers must properly configure those services and implement appropriate safeguards to be compliant.
Question 48: Which AWS service provides a global DNS service that can route users to the nearest healthy endpoint using latency-based routing?
- Elastic Load Balancing
- Amazon CloudFront
- Amazon Route 53 (Correct answer)
- AWS Global Accelerator
Correct answer: Amazon Route 53
Amazon Route 53 is AWS's highly available DNS service that supports routing policies including latency-based routing to direct users to the lowest-latency endpoint.
Question 49: What is the most important professional competency for CLF-C02 certification in storage services?
- Speed of task completion
- Ability to work alone exclusively
- Deep knowledge combined with practical application skills (Correct answer)
- Memorization of all reference materials
Correct answer: Deep knowledge combined with practical application skills
Professional competency requires both deep knowledge of the subject matter and the ability to apply that knowledge in practical situations.
Question 50: What does enabling MFA (Multi-Factor Authentication) on an AWS root account protect against?
- DDoS attacks on resources in the account
- Account takeover if the root account password is compromised (Correct answer)
- Accidental deletion of IAM roles
- Unauthorized S3 bucket access via public URLs
Correct answer: Account takeover if the root account password is compromised
MFA on the root account adds a second authentication factor so that even if the password is stolen, an attacker cannot access the account without the physical MFA device or app.
Question 51: A startup expects variable compute workloads with no predictable pattern. Which EC2 purchasing option minimizes cost while accepting possible interruption?
- Dedicated Hosts
- Spot Instances (Correct answer)
- On-Demand Instances
- Reserved Instances
Correct answer: Spot Instances
Spot Instances use spare AWS capacity and can offer up to 90% savings compared to On-Demand, but AWS can reclaim them with a two-minute warning.
Question 52: What is the primary benefit of cloud computing?
- Manual hardware scaling
- On-demand resource availability and cost savings (Correct answer)
- Unlimited internet access
- Permanent software ownership
Correct answer: On-demand resource availability and cost savings
The primary benefit of cloud computing is its ability to provide on-demand access to computing resources, such as servers, storage, and databases, over the internet. This eliminates the need for organizations to purchase and maintain their own physical infrastructure, leading to significant cost savings. Users only pay for the resources they consume, allowing for greater flexibility, scalability, and efficiency compared to traditional IT setups.
Question 53: Which AWS service allows you to run code without provisioning or managing servers?
- AWS Lambda (Correct answer)
- AWS Elastic Beanstalk
- Amazon ECS
- Amazon EC2
Correct answer: AWS Lambda
AWS Lambda is a serverless compute service that runs your code in response to events without requiring server management.
Question 54: What is the main purpose of an Internet Gateway in a VPC?
- To connect two VPCs together
- To cache frequently accessed content
- To filter malicious internet traffic
- To provide a target in VPC route tables for internet-routable traffic (Correct answer)
Correct answer: To provide a target in VPC route tables for internet-routable traffic
An Internet Gateway serves as a horizontally scaled, redundant VPC component that provides a target in route tables for internet-bound traffic and performs NAT for instances with public IPs.
Question 55: Which foundational principle is MOST important for success in the AWS Certified Cloud Practitioner profession?
- Specializing in only one narrow area of practice
- Maintaining the minimum requirements for certification
- Maximizing financial returns on every engagement
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 56: A company wants to cache frequently accessed data to reduce database load. Which AWS service is best suited for this?
- AWS Glue
- Amazon ElastiCache (Correct answer)
- Amazon S3
- Amazon Kinesis
Correct answer: Amazon ElastiCache
Amazon ElastiCache is a fully managed in-memory caching service compatible with Redis and Memcached that reduces database read pressure.
Question 57: What durability does Amazon S3 Standard guarantee for stored objects?
- 99% (two nines)
- 99.999999999% (eleven nines) (Correct answer)
- 99.9% (three nines)
- 99.99% (four nines)
Correct answer: 99.999999999% (eleven nines)
Amazon S3 is designed for 99.999999999% (11 nines) durability by redundantly storing data across multiple AZs within a Region.
Question 58: A customer accidentally exposes an S3 bucket to the public. Under the Shared Responsibility Model, who is accountable?
- The customer, because S3 bucket policies and ACLs are the customer's responsibility (Correct answer)
- AWS's compliance team, for not detecting the exposure
- Shared equally between AWS and the customer
- AWS, because it should prevent misconfiguration
Correct answer: The customer, because S3 bucket policies and ACLs are the customer's responsibility
Configuring S3 bucket access controls is a customer responsibility, so misconfiguration resulting in public exposure is the customer's accountability.
Question 59: A startup needs a serverless database that scales automatically and charges only for actual usage. Which service fits best?
- Amazon Redshift
- Amazon Aurora Serverless (Correct answer)
- Amazon RDS Multi-AZ
- Amazon DocumentDB
Correct answer: Amazon Aurora Serverless
Amazon Aurora Serverless automatically starts, scales, and shuts down based on application demand, charging only for consumed capacity.
Question 60: Which AWS service provides DDoS protection and is automatically included at no extra charge for all AWS customers?
- AWS WAF
- AWS Shield Standard (Correct answer)
- Amazon GuardDuty
- AWS Shield Advanced
Correct answer: AWS Shield Standard
AWS Shield Standard is automatically enabled for all AWS customers at no additional cost and provides protection against common, most frequently occurring DDoS attacks.
Question 61: A company needs 24/7 phone support and access to Infrastructure Event Management (IEM). Which AWS Support plan includes IEM as a standard feature?
- Enterprise On-Ramp
- Enterprise (Correct answer)
- Business
- Developer
Correct answer: Enterprise
Infrastructure Event Management is included in the Enterprise Support plan, while it is available as a paid add-on for Business plan customers.
Question 62: Which of the following infrastructure components is AWS responsible for under the Shared Responsibility Model?
- Security group rules for EC2 instances
- Fiber optic cables and networking hardware connecting AWS regions (Correct answer)
- S3 bucket versioning settings
- VPC subnet configuration
Correct answer: Fiber optic cables and networking hardware connecting AWS regions
The physical network hardware and fiber connections between AWS facilities are part of the global infrastructure that AWS is fully responsible for.
Question 63: Which documentation is essential when working with aws architecture in CLF-C02?
- General descriptions without specifics
- Only verbal notes
- Detailed technical specifications and as-built diagrams (Correct answer)
- Marketing materials
Correct answer: Detailed technical specifications and as-built diagrams
Detailed technical specifications and as-built diagrams provide the accurate reference information needed for maintenance and troubleshooting.
Question 64: What role does collaboration play in shared responsibility for CLF-C02 professionals?
- It enhances outcomes through diverse perspectives and shared expertise (Correct answer)
- It is only needed in emergencies
- It reduces individual accountability
- It slows down work unnecessarily
Correct answer: It enhances outcomes through diverse perspectives and shared expertise
Collaboration leverages diverse perspectives and combined expertise to achieve better outcomes than any individual could alone.
Question 65: What type of endpoint does AWS PrivateLink provide to access AWS services without traversing the public internet?
- Direct Connect endpoint
- Transit endpoint
- Internet Gateway endpoint
- VPC Endpoint (Correct answer)
Correct answer: VPC Endpoint
AWS PrivateLink uses VPC Endpoints (Interface Endpoints) to enable private connectivity to AWS services directly from your VPC without using internet gateways or NAT devices.
Question 66: What is the AWS best practice recommendation for the root account?
- Use it for all daily administrative tasks
- Delete it after creating IAM users
- Share it with trusted administrators only
- Enable MFA and avoid using it for everyday tasks (Correct answer)
Correct answer: Enable MFA and avoid using it for everyday tasks
AWS recommends enabling MFA on the root account and reserving its use only for tasks that specifically require root-level access.
AWS Certified Cloud Practitioner (CLF-C02)
The AWS Certified Cloud Practitioner exam validates a candidate's overall understanding of the AWS Cloud, including its core services, security, architecture, pricing, and support.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds