Amazon

CLF-C02 Free Practice Questions

This is the free Amazon CLF-C02 practice question bank — 360 of 713 total questions, each with a full explanation, free to read with no signup required. Updated 2026-08-05.

Every answer is verified against official Amazon documentation — see our methodology.

Question 1

Which of the following are advantages of moving to the AWS Cloud? (Choose two.)

A. Users can implement all AWS services in seconds.
B. AWS assumes all responsibility for the security of infrastructure and applications.
C. Users experience increased speed and agility.
D. Users benefit from massive economies of scale.
E. Users can move hardware from their data center to the AWS Cloud.
Show Answer
Correct Answer: C, D
Explanation:
The primary advantages of moving to AWS include increased speed and agility through rapid provisioning and deployment, and benefiting from AWS's massive economies of scale, which reduce infrastructure costs. Option A is incorrect because not all AWS services can be implemented in seconds. Option B is incorrect because AWS follows a shared responsibility model; customers remain responsible for security in the cloud, including applications. Option E is incorrect because moving to AWS does not involve physically relocating existing hardware into the AWS Cloud.

Question 2

Which AWS compute service gives users the ability to securely and reliably run containers at scale?

A. Amazon Elastic Container Service (Amazon ECS)
B. Amazon Aurora
C. Amazon Athena
D. Amazon Polly
Show Answer
Correct Answer: A
Explanation:
Amazon Elastic Container Service (Amazon ECS) is AWS's fully managed container orchestration service for securely running and scaling containerized applications. Aurora is a relational database, Athena is a serverless query service, and Polly is a text-to-speech service.

Question 3

A developer needs to use a standardized template to create copies of a company's AWS architecture for development, test, and production environments. Which AWS service should the developer use to meet this requirement?

A. AWS Cloud Map
B. AWS CloudFormation
C. Amazon Cloud Front
D. AWS CloudTrail
Show Answer
Correct Answer: B
Explanation:
AWS CloudFormation uses infrastructure-as-code templates to model and provision AWS resources consistently across multiple environments such as development, testing, and production. AWS Cloud Map is for service discovery, Amazon CloudFront is a content delivery network, and AWS CloudTrail records API activity.

Question 4

A company has a website on AWS. The company wants to deliver the website to a worldwide audience and provide low-latency response times for global users. Which AWS service will meet these requirements?

A. AWS CloudFormation
B. Amazon CloudFront
C. Amazon ElastiCache
D. Amazon DynamoDB
Show Answer
Correct Answer: B
Explanation:
Amazon CloudFront is AWS's global content delivery network (CDN). It caches and delivers website content from edge locations worldwide, reducing latency and improving response times for users across the globe. CloudFormation is for infrastructure as code, ElastiCache is for in-memory caching within applications, and DynamoDB is a NoSQL database.

Question 5

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

A. Apply guest operating system patches to Amazon EC2 instances.
B. Provide monitoring of human resources information management (HRIM) systems.
C. Perform automated backups of Amazon RDS instances.
D. Optimize the costs of running AWS services.
Show Answer
Correct Answer: C
Explanation:
Under the AWS shared responsibility model, AWS is responsible for managing the underlying infrastructure and, for managed services such as Amazon RDS, provides features like automated backups when enabled. Customers are responsible for patching the guest OS on EC2 instances, monitoring their own HRIM systems, and optimizing their AWS costs.

Question 6

Which AWS service provides a fully managed graph database for highly connected datasets?

A. Amazon DynamoDB
B. Amazon RDS
C. Amazon Neptune
D. Amazon Aurora
Show Answer
Correct Answer: C
Explanation:
Amazon Neptune is AWS's fully managed graph database service, designed for storing and querying highly connected datasets using graph models such as Property Graph and RDF. DynamoDB is a NoSQL key-value/document database, while RDS and Aurora are relational database services.

Question 7

A company wants to run relationship databases in the AWS Cloud. The company wants to use a managed service that will install the database and run regular software updates. Which AWS service will meet these requirements?

A. Amazon S3
B. Amazon RDS
C. Amazon Elastic Block Store (Amazon EBS)
D. Amazon DynamoDB
Show Answer
Correct Answer: B
Explanation:
Amazon RDS is AWS's managed relational database service. It provisions the database, automates software patching and updates, backups, and other operational tasks. Amazon S3 is object storage, Amazon EBS is block storage, and DynamoDB is a managed NoSQL database rather than a relational database.

Question 8

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

A. Third-party vendors
B. Customers
C. Reseller partners
D. Internet providers
Show Answer
Correct Answer: B
Explanation:
Under the AWS Shared Responsibility Model, AWS is responsible for security of the cloud, while customers are responsible for security in the cloud, including securing their AWS accounts, configurations, and resources. Therefore, customers share responsibility with AWS for security and compliance.

Question 9

Why are AWS CloudFormation templates used?

A. To reduce provisioning time by using automation.
B. To transfer existing infrastructure to another company.
C. To reuse on-premises infrastructure in the AWS Cloud.
D. To deploy large infrastructure with no cost implications.
Show Answer
Correct Answer: A
Explanation:
AWS CloudFormation templates define infrastructure as code, allowing automated, repeatable provisioning of AWS resources. This reduces manual effort and provisioning time. They are not used to transfer infrastructure to another company, reuse on-premises infrastructure directly in AWS, or guarantee deployments with no cost implications.

Question 10

Which of the following actions are controlled with AWS Identity and Access Management (IAM)? (Choose two.)

A. Control access to AWS service APIs and to other specific resources.
B. Provide intelligent threat detection and continuous monitoring.
C. Protect the AWS environment using multi-factor authentication (MFA).
D. Grant users access to AWS data centers.
E. Provide firewall protection for applications from common web attacks.
Show Answer
Correct Answer: A, C
Explanation:
IAM is used to manage authentication and authorization for AWS. It controls access to AWS service APIs and resources through users, roles, groups, and policies, and it supports multi-factor authentication (MFA) to strengthen account security. Intelligent threat detection is provided by services such as Amazon GuardDuty, firewall protection for web applications is provided by AWS WAF, and IAM does not grant physical access to AWS data centers.

$19

Get all 713 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.