Amazon

CLF-C02 Free Practice Questions

This is the free Amazon CLF-C02 practice question bank — 360 of 715 total questions, each with a full explanation, free to read with no signup required. Updated 2026-04-24.

Every answer is verified against official Amazon documentation — see our methodology.

Question 1

Which of the following are advantages of moving to the AWS Cloud? (Choose two.)

A. Users can implement all AWS services in seconds.
B. AWS assumes all responsibility for the security of infrastructure and applications.
C. Users experience increased speed and agility.
D. Users benefit from massive economies of scale.
E. Users can move hardware from their data center to the AWS Cloud.
Show Answer
Correct Answer: C, D
Explanation:
Moving to the AWS Cloud provides increased speed and agility through rapid provisioning, scaling, and experimentation. It also offers massive economies of scale, as AWS’s global infrastructure lowers costs compared to maintaining on-premises resources. The other options are incorrect because AWS does not take responsibility for application security, not all services can be implemented instantly, and hardware is not physically moved into the AWS Cloud.

Question 2

Which AWS compute service gives users the ability to securely and reliably run containers at scale?

A. Amazon Elastic Container Service (Amazon ECS)
B. Amazon Aurora
C. Amazon Athena
D. Amazon Polly
Show Answer
Correct Answer: A
Explanation:
Amazon Elastic Container Service (ECS) is a fully managed AWS compute service designed to securely deploy, manage, and scale containerized applications. The other options are database (Aurora), analytics (Athena), and text-to-speech (Polly) services, not container orchestration.

Question 3

A developer needs to use a standardized template to create copies of a company's AWS architecture for development, test, and production environments. Which AWS service should the developer use to meet this requirement?

A. AWS Cloud Map
B. AWS CloudFormation
C. Amazon Cloud Front
D. AWS CloudTrail
Show Answer
Correct Answer: B
Explanation:
AWS CloudFormation allows developers to define AWS infrastructure using standardized templates (in JSON or YAML) and consistently create, update, and replicate identical environments such as development, test, and production. The other options do not provide infrastructure templating or environment replication capabilities.

Question 4

A company has a website on AWS. The company wants to deliver the website to a worldwide audience and provide low-latency response times for global users. Which AWS service will meet these requirements?

A. AWS CloudFormation
B. Amazon CloudFront
C. Amazon ElastiCache
D. Amazon DynamoDB
Show Answer
Correct Answer: B
Explanation:
Amazon CloudFront is a global content delivery network (CDN) that caches and delivers website content from edge locations worldwide, providing low-latency responses for global users. The other options do not provide global content delivery or latency optimization.

Question 5

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

A. Apply guest operating system patches to Amazon EC2 instances.
B. Provide monitoring of human resources information management (HRIM) systems.
C. Perform automated backups of Amazon RDS instances.
D. Optimize the costs of running AWS services.
Show Answer
Correct Answer: C
Explanation:
Under the AWS shared responsibility model, AWS is responsible for managing and operating the underlying infrastructure and managed services. For Amazon RDS, AWS handles automated backups as part of the managed database service. Applying guest OS patches on EC2, monitoring HR systems, and optimizing costs are customer responsibilities.

Question 6

Which AWS service provides a fully managed graph database for highly connected datasets?

A. Amazon DynamoDB
B. Amazon RDS
C. Amazon Neptune
D. Amazon Aurora
Show Answer
Correct Answer: C
Explanation:
Amazon Neptune is AWS’s fully managed graph database service, purpose-built for storing and querying highly connected datasets using graph models. The other options are key-value or relational databases, not graph databases.

Question 7

A company wants to run relationship databases in the AWS Cloud. The company wants to use a managed service that will install the database and run regular software updates. Which AWS service will meet these requirements?

A. Amazon S3
B. Amazon RDS
C. Amazon Elastic Block Store (Amazon EBS)
D. Amazon DynamoDB
Show Answer
Correct Answer: B
Explanation:
Amazon RDS is a fully managed relational database service that installs the database engine, handles routine maintenance tasks such as patching, backups, and software updates, and manages underlying infrastructure. The other options are not managed relational database services.

Question 8

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

A. Third-party vendors
B. Customers
C. Reseller partners
D. Internet providers
Show Answer
Correct Answer: B
Explanation:
Under the AWS Shared Responsibility Model, AWS secures the underlying cloud infrastructure, while customers are responsible for security and compliance *in* the cloud, including their accounts, configurations, data, and access management. Therefore, customers share responsibility with AWS.

Question 9

Why are AWS CloudFormation templates used?

A. To reduce provisioning time by using automation.
B. To transfer existing infrastructure to another company.
C. To reuse on-premises infrastructure in the AWS Cloud.
D. To deploy large infrastructure with no cost implications.
Show Answer
Correct Answer: A
Explanation:
AWS CloudFormation templates define infrastructure as code, allowing automated, repeatable provisioning of AWS resources. This automation significantly reduces manual effort and provisioning time. The other options do not reflect the purpose of CloudFormation.

Question 10

Which of the following actions are controlled with AWS Identity and Access Management (IAM)? (Choose two.)

A. Control access to AWS service APIs and to other specific resources.
B. Provide intelligent threat detection and continuous monitoring.
C. Protect the AWS environment using multi-factor authentication (MFA).
D. Grant users access to AWS data centers.
E. Provide firewall protection for applications from common web attacks.
Show Answer
Correct Answer: A, C
Explanation:
IAM is used to control access to AWS service APIs and specific resources through users, roles, and policies, and it supports enforcing multi-factor authentication (MFA) for added security. Threat detection is handled by services like GuardDuty, physical data center access is managed by AWS internally, and web application firewall protection is provided by AWS WAF, not IAM.

$19

Get all 715 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.