AWS Certified Cloud Practitioner
Master your AWS Certified Cloud Practitioner exam with our Practice Exam Simulator. Prepare effectively and assess your readiness with realistic practice exams designed to mirror the most popular official AWS exam.
Exam domains
The CLF-C02 questions are grouped into 4 domains divided into 19 tasks.
CLF-C02 example questions
One example question per domain from the CLF-C02 question bank, with the correct answer and its explanation. Sign in to the simulator to answer them with all answer options.
A mobile gaming company with a global user base is experiencing variable workloads and unpredictable traffic spikes, especially during the launch of new games or gaming events. They currently host their player data on-premises but are considering migrating to AWS to improve their service. How can transitioning their player data management to Amazon DynamoDB enhance their system's availability, elasticity, and agility?
Show answer
CORRECT ANSWERAmazon DynamoDB can provide high availability and fault tolerance by automatically replicating data across multiple AWS Availability Zones, dynamically adjust capacity to handle varying workloads, and allow the company to quickly roll out new features or adapt to changes.
The correct answer reflects DynamoDB's core features such as built-in fault tolerance through multi-AZ replication, on-demand scaling to handle changes in demand seamlessly, and agility through easy integration with other AWS services and quick iteration.
A company is using AWS to host their web application. After a recent increase in popularity, the application suffered from a Distributed Denial of Service (DDoS) attack, which impacted its availability. The company had AWS Shield Standard enabled on their account. Given this scenario, which of the following statements correctly describes AWS's responsibility under the AWS shared responsibility model in the context of protection against DDoS attacks?
Show answer
CORRECT ANSWERAWS is responsible for providing the basic infrastructure-level protection against common DDoS attacks with AWS Shield Standard at no additional cost.
Correct: AWS Shield Standard provides automatic protection against foundational DDoS attacks that target websites and applications running on AWS, which is part of AWS's responsibility in the shared responsibility model.
A company has adopted the DevOps culture and is looking for ways to automate their deployment pipelines for multiple applications to improve efficiency. They decide to use AWS services for their continuous integration and continuous deployment (CI/CD) workflow. Given the need for frequent, automated, and reliable application deployments, which method would be the most suitable for setting up and managing their pipelines using AWS CodePipeline?
Show answer
CORRECT ANSWERUsing infrastructure as code (IaC) to define and manage AWS CodePipeline resources
Infrastructure as Code enables teams to automatically manage and provision the technology stack for an application through code, which is ideal for maintaining consistency, version control, and automation in a CI/CD workflow. This is highly compatible with AWS CodePipeline, which can be defined as a set of declarative AWS CloudFormation templates or through other IaC tools, allowing for scalable and repeatable pipeline creation.
You have set up a multi-tier application on AWS, which uses services spread across the us-east-1 (N. Virginia) and us-west-2 (Oregon) Regions. To help keep costs under control, you have configured AWS Budgets to alert you when your estimated charges exceed your budgeted amount. Your application recently began to see increased traffic, which led to a rise in data transfer between regions. Given this scenario, how do AWS data transfer costs impact your budget alerts for the cross-region traffic?
Show answer
CORRECT ANSWERYou will receive alerts if the estimated charges for the data transfers exceed the thresholds set in your AWS Budgets, since AWS charges for data transfer out from one region to another.
AWS charges for data transfer out from one region to another at the specified rate. Thus, data transferred between us-east-1 and us-west-2 will incur charges that will contribute to the estimated charges monitored by AWS Budgets. If these charges exceed the budgeted amount, AWS Budgets will send alerts.
Exam mode and practice mode
| Exam mode | Practice mode | |
|---|---|---|
| Questions count | 65 | 1 - 75 |
| Time limit | 90 minutes | Optional, 10 - 90 minutes |
| Exam scope | 4 domains with the official questions ratio | Selected domains with the official questions ratio |
| Correct answers | After exam submission | After exam submission or after each answer |
| Question types | Mix of single and multiple correct answers | Single, multiple or both |
| Question hints | Never | Optional |
| Question domain | Revealed after exam submission | Revealed after submission or during the exam |
| Scoring | 15 of 65 questions do not count towards the result | Official AWS method or mathematical mean |
See all simulator features on the AWS Exam Simulator page.
About the CLF-C02 exam
While the AWS Certification exams are known to be challenging, the easiest one among them is still not easy by any means.
The scope of the CCP exam is quite broad, encompassing various aspects of the AWS ecosystem. Candidates are expected to demonstrate their knowledge in several key areas, including the basics of cloud computing, AWS global infrastructure, core AWS services, security and compliance, pricing and support plans, and the fundamentals of deploying and operating in the AWS cloud. This includes understanding the purpose and basic functions of essential services like Amazon EC2, S3, RDS, and Lambda, as well as more general concepts like billing, pricing models, and cloud architecture principles.
The exam places significant emphasis on AWS cloud concepts such as Elasticity, Availability, Serverless, AWS global infrastructure, and principles outlined in the Well-Architected Framework.
A significant portion of the exam focuses on ensuring that candidates can differentiate between different AWS services and their appropriate use cases. This requires not only memorization but also the ability to apply theoretical knowledge to practical scenarios. For instance, understanding when to use specific storage solutions like S3 versus EBS, or recognizing the best use cases for different database services such as RDS, DynamoDB, or Redshift, is crucial.
Moreover, the exam includes questions on security and compliance, which involves understanding AWS's shared responsibility model, basic security practices, and key AWS security services like IAM, KMS, and CloudTrail. This aspect tests a candidate's ability to ensure secure cloud environments, a critical skill for any AWS practitioner.
You can expect rather straightforward questions with limited text distractors and moderate difficulty.
Technologies and concepts
Compute
Computing involves the use of computers to process data, execute tasks, and run applications. In the context of cloud computing, this translates to leveraging remote servers hosted on the internet to perform these functions rather than relying on local servers or personal computers. AWS supports this with Amazon EC2 for scalable virtual servers, AWS Lambda for serverless computing that executes code in response to events, Amazon ECS and EKS for managing containerized applications, and AWS Fargate for running containers without managing servers.
Cost management
Cost management involves monitoring, controlling, and optimizing spending on cloud resources. AWS supports this with AWS Cost Explorer for visualizing and analyzing cost and usage over time, AWS Budgets for setting and tracking custom cost and usage budgets, AWS Trusted Advisor for providing recommendations to optimize costs, and AWS Cost and Usage Report for detailed billing information. These services help organizations gain visibility into their spending, identify cost-saving opportunities, and ensure efficient use of resources to control and reduce cloud expenses
Database
Database services in cloud computing provide scalable and managed database solutions for various applications. AWS supports this with Amazon RDS for managed relational databases, Amazon DynamoDB for NoSQL databases, Amazon Aurora for high-performance relational databases compatible with MySQL and PostgreSQL, Amazon Redshift for data warehousing, Amazon Neptune for graph databases, Amazon DocumentDB for MongoDB-compatible document databases, and Amazon Timestream for time series data. These services ensure high availability, scalability, and security, allowing organizations to focus on their applications without managing the underlying database infrastructure, and support diverse data management needs efficiently.
Management and governance
Management and governance in cloud computing involve overseeing and controlling cloud resources to ensure compliance, security, and operational efficiency. AWS supports this with AWS CloudTrail for logging and monitoring account activity, AWS Config for tracking and auditing resource configurations, AWS Systems Manager for operational data management and automation, AWS Organizations for centralized management of multiple AWS accounts, and AWS Control Tower for setting up and governing a secure, multi-account AWS environment. These services help organizations maintain visibility, enforce policies, and automate processes, ensuring effective management and governance of their AWS environment.
Migration and data transfer
Migration and data transfer in cloud involve moving applications, data, and workloads from on-premises or other cloud environments to AWS. AWS supports this with AWS Migration Hub for tracking and managing migrations, AWS Database Migration Service (DMS) for migrating databases with minimal downtime, AWS Server Migration Service (SMS) for migrating on-premises servers, AWS Snowball for transferring large amounts of data, and AWS DataSync for automating data transfer between on-premises storage and AWS. These services enable efficient, secure, and seamless migration and data transfer, helping organizations transition to AWS with minimal disruption.
Networking, connectivity, and content delivery
Networking, connectivity, and content delivery in cloud involve connecting and securing resources across cloud and on-premises environments, and efficiently delivering content to users globally. AWS supports this with Amazon VPC for creating isolated cloud resources, AWS Direct Connect for dedicated network connections, Amazon Route 53 for scalable DNS and traffic management, AWS CloudFront for content delivery with low latency and high transfer speeds, and AWS Transit Gateway for connecting VPCs and on-premises networks. These services ensure high availability, security, and performance, enabling robust networking, reliable connectivity, and efficient content delivery.
Security
Security in cloud computing involves protecting data, applications, and infrastructure while ensuring regulatory compliance, supported by AWS services like IAM, KMS, Shield, WAF, GuardDuty, and CloudTrail, which collectively provide robust security measures for data confidentiality, integrity, and availability.
Storage
Storage in cloud computing involves secure, efficient data management and access, supported by AWS services like Amazon S3, EBS, EFS, Glacier, and Backup, providing durable, scalable, and flexible solutions for various use cases.
APIs
APIs enable integration and automation between applications, with AWS supporting this through services like API Gateway, AppSync, Lambda, Amplify, and Cognito for secure, scalable, and efficient API management.
Benefits of migrating to the AWS Cloud
Migrating to AWS Cloud provides scalability, cost-efficiency, enhanced security, and reliability through on-demand resources, pay-as-you-go pricing, robust security compliance, and a wide range of tools for disaster recovery, data storage, and application management, making it ideal for modernizing IT infrastructure and driving business innovation.
AWS Cloud Adoption Framework (AWS CAF)
The AWS Cloud Adoption Framework (AWS CAF) provides a structured approach to cloud migration, guiding organizations through six key perspectives—Business, People, Governance, Platform, Security, and Operations—ensuring alignment of IT strategy with business goals, effective change management, compliance, robust cloud infrastructure and security, and efficient operations, facilitating a seamless and effective transition to the AWS Cloud.
AWS Compliance
AWS Compliance provides a framework and services to help organizations meet regulatory and industry requirements through certifications like ISO 27001, HIPAA, SOC 1/2/3, and GDPR, supported by tools like AWS Artifact, Config, Security Hub, Audit Manager, Shield, and WAF for managing, monitoring, and auditing AWS environments to ensure adherence to compliance standards.
Amazon EC2 instance types
Amazon EC2 instance types offer flexible and scalable configurations to suit different use cases, including General Purpose (e.g., T3, M5), Compute Optimized (e.g., C5, C6g), Memory Optimized (e.g., R5, X1), Storage Optimized (e.g., I3, D2), Accelerated Computing (e.g., P3, G4), and Bare Metal (e.g., i3.metal, m5.metal), enabling organizations to select the right configuration for cost-efficiency and optimal performance.
AWS global infrastructure
AWS global infrastructure provides a robust, scalable, and secure environment with data centers worldwide, organized into Regions and Availability Zones (AZs) for redundancy and fault tolerance, Edge Locations for low-latency content delivery, and Local Zones for extending AWS services to more geographic locations, ensuring high performance, availability, and resilience for diverse workloads and disaster recovery strategies.
Infrastructure as code (IaC)
Infrastructure as Code (IaC) involves managing and provisioning computing infrastructure via machine-readable definition files, supported by AWS services like CloudFormation for automating resource setup, CDK for defining infrastructure with programming languages, OpsWorks for configuration management, Elastic Beanstalk for simplified application deployment, and the widely-used Terraform for multi-cloud infrastructure management, enabling consistent, error-free, and streamlined deployment across environments.
AWS Knowledge Center
The AWS Knowledge Center is a comprehensive resource offering support through detailed documentation, tutorials, FAQs, personalized support via the AWS Support Center, and community assistance on AWS Forums, helping users effectively utilize AWS services, troubleshoot issues, and implement best practices.
Machine learning
Machine learning enables scalable model development, training, and deployment, supported by AWS services like SageMaker for building and deploying models, Deep Learning AMIs for setting up deep learning environments, Comprehend for NLP insights, Rekognition for image and video analysis, Lex for conversational interfaces, Polly for text-to-speech, and the Machine Learning Marketplace for pre-trained models, providing powerful machine learning capabilities without the need to manage underlying infrastructure.
AWS Partner Network
The AWS Partner Network (APN) is a global program that helps partners build, market, and sell AWS offerings through Technology Partners providing software solutions, Consulting Partners offering professional services, Training Partners delivering AWS courses, a Marketplace for software solutions, Competency Programs recognizing expertise, and APN Funding Programs offering financial incentives, supporting partners in delivering enhanced solutions, driving innovation, and achieving business success for AWS customers.
AWS Prescriptive Guidance
AWS Prescriptive Guidance offers best practices, strategies, and detailed steps for successful cloud adoption and optimization through comprehensive guides, reusable patterns, reference architectures, playbooks, and best practices, helping organizations confidently implement effective and reliable solutions tailored to their needs using AWS expertise.
AWS Pricing Calculator
The AWS Pricing Calculator helps customers estimate monthly AWS costs and plan their cloud budget with service cost estimates, customizable inputs, cost comparison, exportable reports, and pre-built templates, enabling accurate spending forecasts, cost optimization, and informed financial decisions.
AWS Professional Services
AWS Professional Services provides expert guidance and support for successful cloud adoption and optimization through advisory services for strategic planning, implementation services for deploying AWS solutions, optimization services for performance and cost-efficiency, customized training programs, and specialized expertise in areas like data analytics, machine learning, and DevOps.
AWS re:Post
AWS re:Post is an online, community-driven platform where users can ask questions, share knowledge, and find answers about AWS services, featuring community support, a knowledge base of FAQs, categorized tags and topics, powerful search tools, and expert contributions, enabling efficient problem-solving and enhanced understanding of AWS services.
AWS SDKs
AWS SDKs simplify building applications that interact with AWS services by offering support for multiple programming languages, simplified API integration, pre-written code samples, developer tools like AWS CLI and CodeBuild, and built-in security features, enhancing productivity and reducing development time.
AWS Security Blog
The AWS Security Blog provides insights, updates, and best practices on securing AWS environments through detailed security guides, updates on the latest features and services, real-world case studies, expert insights, and strategies for compliance and governance, helping users stay informed and effectively secure their cloud environments.
AWS Security Center
The AWS Security Center provides resources and information to help users secure their AWS environments, offering detailed security best practices, compliance resources, access to security tools like IAM, KMS, and GuardDuty, case studies of successful implementations, and learning resources such as whitepapers and training courses, ensuring robust security measures and compliance.
AWS shared responsibility model
The AWS Shared Responsibility Model outlines security roles, with AWS responsible for "Security of the Cloud" (protecting the infrastructure running AWS services) and customers responsible for "Security in the Cloud" (configuring and managing their AWS services securely), ensuring clarity in security responsibilities and helping customers implement effective security measures while AWS handles infrastructure security.
AWS Solutions Architects
AWS Solutions Architects provide expert guidance for designing, building, and optimizing applications on AWS, offering architecture design, best practices for security and performance, technical guidance on AWS services, workshops and training sessions, and support for developing proof of concepts, ensuring optimized cloud infrastructure for performance, security, and cost-efficiency.
AWS Support Center
The AWS Support Center provides comprehensive assistance with technical support from AWS engineers, various support plans (Basic, Developer, Business, Enterprise), a knowledge base of articles and FAQs, case management tools, and account and billing support, ensuring users have the resources needed to efficiently manage and optimize their AWS environments.
AWS Support plans
AWS Support Plans offer varying levels of assistance to meet customer needs: Basic Support provides free access to customer service, documentation, and community resources; Developer Support adds business hours email access for one primary contact with 24-hour response time; Business Support includes 24/7 access via phone, chat, and email for unlimited contacts, faster response times, AWS Trusted Advisor, and architectural guidance; Enterprise Support adds a dedicated Technical Account Manager, 15-minute response times for critical issues, and access to AWS Infrastructure Event Management for event planning and support, ensuring customers can choose the level of support that fits their requirements and budget.
AWS Well-Architected Framework
The AWS Well-Architected Framework provides best practices for designing and operating reliable, secure, efficient, and cost-effective cloud systems, focusing on operational excellence (running and monitoring systems), security (protecting information and assets), reliability (recovering from disruptions), performance efficiency (efficient resource use), and cost optimization (minimizing costs while delivering value), helping organizations build resilient and adaptable cloud architectures.
Services on the exam
All 120 AWS services that can appear on the CLF-C02 exam.