Amazon

CLF-C02 Practice Test: 10 Original Questions

Ten questions across the four CLF-C02 domains: cloud concepts, security and compliance, cloud technology and services, and billing and support. They test whether you can match a business need to the right AWS idea or service, and each answer links to the AWS page it rests on.

These questions were written for CertBlaze from the official AWS Certified Cloud Practitioner exam guide, with AI assistance. They are not taken from the real exam, an exam dump or any other question bank. Each answer names the official page it is based on; if you spot a mistake, please tell us.

What this set covers

  • Cloud Concepts: 2 questions
  • Security and Compliance: 4 questions
  • Cloud Technology and Services: 3 questions
  • Billing, Pricing, and Support: 1 question

Question 1

Cloud Concepts

A retailer buys enough on-premises servers to handle its holiday peak, so the servers sit mostly idle for the rest of the year. Which advantage of cloud computing addresses this problem most directly?

A. Go global in minutes
B. Stop spending money running and maintaining data centers
C. Benefit from massive economies of scale
D. Stop guessing capacity
Show Answer
Correct Answer: D
Explanation:
Stop guessing capacity means provisioning for actual demand and scaling up or down as it changes, instead of buying for the peak and leaving hardware idle. The other three are also advantages of the cloud, but none of them is about matching capacity to a fluctuating load.
Source: Six advantages of cloud computing (Overview of Amazon Web Services)

Question 2

Cloud Concepts

Which pillar of the AWS Well-Architected Framework covers a workload's ability to perform its intended function correctly and consistently, including recovering from failures?

A. Reliability
B. Operational excellence
C. Performance efficiency
D. Cost optimization
Show Answer
Correct Answer: A
Explanation:
The reliability pillar is about a workload doing what it should, consistently, and recovering from failure. Operational excellence covers running and improving operations, performance efficiency covers using resources efficiently as demand changes, and cost optimization covers avoiding unnecessary spend.
Source: The pillars of the framework (AWS Well-Architected Framework)

Question 3

Security and Compliance

A company runs its database on Amazon RDS. Under the AWS shared responsibility model, which task belongs to the customer?

A. Patching the operating system of the host that runs the database
B. Replacing failed storage hardware
C. Managing database users and the security group rules that control who can connect
D. Physically securing the data center
Show Answer
Correct Answer: C
Explanation:
With a managed service such as RDS, AWS runs the infrastructure, host operating system and hardware, while the customer stays responsible for its data, who can access it, and the network rules around it. Host patching (A), hardware replacement (B) and physical security (D) are AWS's side of the model.
Source: Shared Responsibility Model (AWS)

Question 4

Security and Compliance

A company wants every employee who signs in to the AWS Management Console to complete a second verification step in addition to a password. What should it enable?

A. AWS Key Management Service (AWS KMS)
B. Amazon Inspector
C. Multi-factor authentication (MFA)
D. Security groups
Show Answer
Correct Answer: C
Explanation:
MFA adds a second factor, such as an authenticator app or security key, to the password sign-in. AWS KMS (A) manages encryption keys, Amazon Inspector (B) scans workloads for vulnerabilities, and security groups (D) filter network traffic to resources. None of those changes how a person signs in.
Source: AWS Multi-factor authentication in IAM (IAM User Guide)

Question 5

Security and Compliance

An auditor asks a company for AWS's own SOC 2 report and PCI DSS attestation. Where can the company download these documents?

A. AWS Config
B. AWS Audit Manager
C. AWS Artifact
D. Amazon Macie
Show Answer
Correct Answer: C
Explanation:
AWS Artifact is the self-service portal for AWS compliance reports such as SOC and PCI, and for agreements with AWS. AWS Config (A) records resource configurations, Audit Manager (B) collects evidence about the customer's own AWS usage, and Macie (D) finds sensitive data in S3.
Source: What is AWS Artifact? (AWS Artifact User Guide)

Question 6

Security and Compliance

Which AWS service continuously analyzes AWS CloudTrail events, VPC Flow Logs and DNS logs to detect threats such as cryptocurrency mining or use of stolen credentials?

A. Amazon Inspector
B. Amazon GuardDuty
C. AWS Shield
D. AWS WAF
Show Answer
Correct Answer: B
Explanation:
GuardDuty is a threat detection service that analyzes those data sources for malicious or unexpected activity. Inspector (A) scans for software vulnerabilities and network exposure, Shield (C) protects against DDoS attacks, and WAF (D) filters web requests by rules.
Source: What is Amazon GuardDuty? (GuardDuty User Guide)

Question 7

Cloud Technology and Services

A company must keep an application running if one data center fails, and compliance rules require all of its data to stay in one geographic area. What is the recommended deployment?

A. Use several Availability Zones in one AWS Region
B. Use several edge locations
C. Use several AWS Regions
D. Use one Availability Zone with larger instances
Show Answer
Correct Answer: A
Explanation:
Availability Zones are isolated groups of data centers inside one Region, so spreading the application across them survives a data center failure while the data stays in that Region. Edge locations (B) cache content and do not run the application tier. Several Regions (C) would move data across geographic areas. One Availability Zone (D) remains a single point of failure.
Source: Regions and Availability Zones (AWS Global Infrastructure)

Question 8

Cloud Technology and Services

A developer wants code to run each time an image is uploaded to an S3 bucket, without provisioning or managing servers and paying only for the compute time used. Which service fits?

A. Amazon EC2
B. Amazon Lightsail
C. AWS Lambda
D. AWS Elastic Beanstalk
Show Answer
Correct Answer: C
Explanation:
Lambda runs functions in response to events such as an S3 upload, manages the servers for you, and bills for the compute time the function uses. EC2 (A) and Lightsail (B) are servers you manage and pay for while they run. Elastic Beanstalk (D) deploys applications onto EC2 instances that keep running.
Source: What is AWS Lambda? (AWS Lambda Developer Guide)

Question 9

Cloud Technology and Services

A company needs a fully managed NoSQL key-value database that keeps single-digit millisecond performance at any scale. Which AWS service should it use?

A. Amazon RDS
B. Amazon Redshift
C. Amazon DynamoDB
D. Amazon Neptune
Show Answer
Correct Answer: C
Explanation:
DynamoDB is a serverless NoSQL key-value and document database built for consistent single-digit millisecond performance. RDS (A) is relational, Redshift (B) is a data warehouse for analytics, and Neptune (D) is a graph database.
Source: What is Amazon DynamoDB? (Amazon DynamoDB Developer Guide)

Question 10

Billing, Pricing, and Support

A finance team wants an email alert when the forecasted AWS bill for the month is expected to go over $5,000. Which tool should it use?

A. AWS Cost Explorer
B. AWS Pricing Calculator
C. AWS Budgets
D. AWS Trusted Advisor
Show Answer
Correct Answer: C
Explanation:
AWS Budgets lets you set a cost budget and alert on actual or forecasted spend crossing a threshold. Cost Explorer (A) is for analyzing and forecasting costs, the Pricing Calculator (B) estimates costs before you build, and Trusted Advisor (D) gives best-practice checks.
Source: Managing your costs with AWS Budgets (AWS Cost Management User Guide)