CertSafari

    Free AWS Certified Cloud Practitioner (CLF-C02) Sample Questions

    35 free sample questions from our bank of 407+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Cloud Concepts

    Subdomain 1.1: Define the benefits of the AWS Cloud.

    1.A retailer's e-commerce site normally handles steady traffic but experiences an unpredictable surge whenever a product goes viral on social media. The retailer wants the infrastructure to handle these surges without the team manually adding servers each time. Which AWS Cloud capability best supports this requirement?

    1. A.Elasticity, which allows compute capacity to automatically increase and decrease in response to real-time demand
    2. B.Global reach, which allows the retailer to serve viral traffic from Regions physically closer to the affected customers
    3. C.Agility, which allows the development team to build and test a new checkout feature more quickly than before
    4. D.High availability, which allows the site to remain online if one Availability Zone in the Region becomes unavailable
    Show answer & explanation

    Correct answer: A — Elasticity, which allows compute capacity to automatically increase and decrease in response to real-time demand

    • A. This is correct because elasticity is the capability that automatically scales compute capacity up during unpredictable demand spikes and back down afterward, removing the need for manual intervention.
    • B. This is incorrect because global reach addresses proximity to users to reduce latency, not the automatic scaling of capacity needed to absorb a sudden unpredictable traffic surge.
    • C. This is incorrect because agility describes how quickly new features or environments can be built and tested, not how the running production site automatically handles a traffic spike.
    • D. This is incorrect because high availability protects against infrastructure failures such as a zone outage, but it does not by itself add the extra capacity needed to absorb a viral traffic surge.

    Subdomain 1.1: Define the benefits of the AWS Cloud.

    2.A news publisher wants a single article to load quickly for readers in Singapore, Ireland, and Canada at the same time, right after publishing. Which explanation best describes how AWS's global infrastructure supports this goal?

    1. A.Content and application resources can be served from AWS locations near each reader population, shortening the network path
    2. B.AWS automatically compresses every article into a smaller file size the moment it detects readers located in more than one country
    3. C.AWS requires publishers to choose only one Region for all readers, and page load speed is not affected by the reader's location
    4. D.AWS assigns every new AWS account a single fixed Region for life, and content cannot be served from any other Region afterward
    Show answer & explanation

    Correct answer: A — Content and application resources can be served from AWS locations near each reader population, shortening the network path

    • A. This is correct because AWS's global infrastructure lets the publisher place or serve resources from locations near each reader population, shortening the network path and reducing load time for readers in different regions.
    • B. This is incorrect because AWS does not automatically compress content based on detecting readers in multiple countries; content delivery performance comes from where resources are located and served from.
    • C. This is incorrect because publishers are not limited to a single Region, and reader location does affect load time when resources are not served from a nearby location.
    • D. This is incorrect because AWS accounts are not permanently locked to one Region; resources and content delivery can span multiple Regions as the publisher chooses.

    Subdomain 1.3: Understand the benefits of and strategies for migration to the AWS Cloud.

    3.A company runs an aging, custom-built customer relationship management (CRM) system that is expensive to maintain. As part of its AWS migration, leadership decides to shut down the custom system entirely and subscribe to a commercial SaaS CRM product instead. Which migration strategy does this decision represent?

    1. A.Repurchase the CRM capability by adopting a commercial SaaS product instead of migrating the old application
    2. B.Rehost the CRM system by moving its existing servers onto AWS infrastructure while keeping the custom application code unchanged
    3. C.Replatform the CRM system by moving its database to a managed AWS service while keeping the rest of the application as is
    4. D.Retire the CRM system by decommissioning it without replacing its functionality, since the company no longer needs that capability
    Show answer & explanation

    Correct answer: A — Repurchase the CRM capability by adopting a commercial SaaS product instead of migrating the old application

    • A. This is correct because repurchasing means moving to a different product, typically a SaaS offering, instead of migrating the existing application, which matches replacing the custom CRM with a commercial product.
    • B. Rehosting would mean lifting the existing custom CRM onto AWS as is, but the scenario describes shutting it down and switching to a different product entirely.
    • C. Replatforming implies keeping the existing application while changing part of its infrastructure, which does not match replacing the whole system with a SaaS product.
    • D. Retiring means decommissioning a capability the business no longer needs, but this scenario still needs CRM functionality, just delivered through a different product.

    Subdomain 1.3: Understand the benefits of and strategies for migration to the AWS Cloud.

    4.A company runs thousands of VMware virtual machines in its own data center and wants to move them onto AWS infrastructure with no changes to the guest operating systems, applications, or existing VMware management tools. Which approach best matches this requirement?

    1. A.Relocate the virtual machines using VMware Cloud on AWS, moving the existing VMware environment onto AWS as is
    2. B.Rehost the virtual machines by rebuilding each one as a new Amazon EC2 instance configured to match the original settings
    3. C.Replatform the virtual machines by migrating their storage volumes to Amazon EBS while keeping the compute layer on VMware
    4. D.Refactor the virtual machines by converting them into containerized workloads managed through Amazon ECS or Amazon EKS
    Show answer & explanation

    Correct answer: A — Relocate the virtual machines using VMware Cloud on AWS, moving the existing VMware environment onto AWS as is

    • A. This is correct because relocating is the strategy for moving infrastructure such as VMware environments onto AWS at the hypervisor level, without changing the applications or existing management tools.
    • B. Rehosting to native EC2 instances would require rebuilding each virtual machine outside of VMware, which does not preserve the existing VMware management tools as required.
    • C. Replatforming here would still split the environment between AWS storage and VMware compute, which does not match the requirement to move the whole VMware environment unchanged.
    • D. Refactoring into containers is a significant architectural change that contradicts the requirement of making no changes to the applications or operating systems.

    Subdomain 1.2: Identify design principles of the AWS Cloud.

    5.A retail analytics team wants to add a recommendation engine but has no in-house data science expertise, so it adopts a managed machine learning service instead of hiring specialists to build and operate the infrastructure themselves. Which performance efficiency design principle does this decision reflect?

    1. A.Democratizing advanced technologies, which lets a team consume specialized technology like machine learning as a managed service
    2. B.Using serverless architectures, which removes the need to run or patch physical servers for traditional compute activities entirely
    3. C.Going global in minutes, which deploys workloads into additional AWS Regions around the world to improve latency for customers
    4. D.Considering mechanical sympathy, which aligns the technology approach chosen with the workload's specific data access patterns
    Show answer & explanation

    Correct answer: A — Democratizing advanced technologies, which lets a team consume specialized technology like machine learning as a managed service

    • A. Correct. Democratizing advanced technologies is the design principle describing how consuming specialized technologies such as machine learning as a managed service lets a team benefit without needing to build deep, hard-to-hire expertise in-house.
    • B. Incorrect. Using serverless architectures is about removing physical server management for compute activities generally, which is a broader operational concern rather than specifically avoiding the need for specialized ML expertise.
    • C. Incorrect. Going global in minutes concerns multi-Region deployment for latency, which is unrelated to a team's decision to consume machine learning as a service due to lacking in-house expertise.
    • D. Incorrect. Considering mechanical sympathy is about aligning storage or database choices with data access patterns, not about outsourcing specialized technology implementation to a managed service.

    Subdomain 1.2: Identify design principles of the AWS Cloud.

    6.A cloud practitioner is asked to explain the key difference between the reliability pillar and the performance efficiency pillar of the Well-Architected Framework to a non-technical stakeholder. Which explanation correctly distinguishes the two?

    1. A.Reliability means a workload performs its intended function correctly and consistently, while performance efficiency means using cloud resources efficiently as demand and technology change
    2. B.Reliability is about minimizing the financial cost of running a workload over its full lifecycle, while performance efficiency is about minimizing the environmental impact of the resources that workload consumes
    3. C.Reliability is about protecting data and systems from unauthorized access across every architectural layer, while performance efficiency is about organizing teams and processes to deliver a great customer experience
    4. D.Reliability is about attributing cloud spending accurately to the correct business unit for reporting purposes, while performance efficiency is about deploying a workload into new AWS Regions worldwide
    Show answer & explanation

    Correct answer: A — Reliability means a workload performs its intended function correctly and consistently, while performance efficiency means using cloud resources efficiently as demand and technology change

    • A. Correct. Reliability is defined as a workload's ability to perform its intended function correctly and consistently, including recovering from failure, while performance efficiency is defined as using cloud resources efficiently to meet requirements and maintaining that efficiency as demand and technology evolve.
    • B. Incorrect. Minimizing financial cost describes the cost optimization pillar and minimizing environmental impact describes the sustainability pillar, so this pairing misattributes both definitions away from reliability and performance efficiency.
    • C. Incorrect. Protecting data and systems from unauthorized access describes the security pillar, and organizing teams for customer experience describes operational excellence, so neither definition belongs to reliability or performance efficiency.
    • D. Incorrect. Attributing cloud spending to a business unit is a cost optimization concern, and deploying to new Regions is one performance efficiency technique rather than its definition, so this option mismatches both pillars' actual scope.

    Subdomain 1.4: Understand concepts of cloud economics.

    7.A hospital network's IT team sized its on-premises imaging-archive servers for the busiest flu season week, so the hardware sits at 20% utilization the rest of the year. Which cloud economics concept explains the cost this represents?

    1. A.Economies of scale, where the hospital's one-time hardware purchase lets it negotiate lower per-server pricing than any cloud vendor could offer.
    2. B.Rightsizing, where the hospital matched its server capacity precisely to average demand and accepted brief periods of reduced performance.
    3. C.Over-provisioning for peak capacity, where a fixed hardware footprint must be bought for the worst case and then remains partly idle year-round.
    4. D.License Included pricing, where the imaging software's per-core license cost is bundled into the hourly rate charged for each server.
    Show answer & explanation

    Correct answer: C — Over-provisioning for peak capacity, where a fixed hardware footprint must be bought for the worst case and then remains partly idle year-round.

    • A. This is incorrect because a single hospital buying its own hardware cannot achieve the aggregated, cross-customer purchasing power that produces economies of scale; that benefit belongs to a large cloud provider, not the hospital itself.
    • B. This is incorrect because rightsizing means matching capacity to actual demand, which is the opposite of sizing for the worst-case peak and running at 20% utilization the rest of the year.
    • C. This is correct because on-premises environments must be sized for peak demand, so capacity purchased for the flu-season spike sits mostly idle the rest of the year, an on-premises fixed cost the cloud avoids.
    • D. This is incorrect because License Included pricing is a software-licensing model bundled into hourly billing; it has nothing to do with why fixed on-premises hardware sits idle outside peak season.

    Subdomain 1.4: Understand concepts of cloud economics.

    8.A law firm processes huge volumes of discovery documents only during active litigation, with quiet months in between, but its owned on-premises servers cost the same to maintain whether they're busy or idle. What cost benefit would moving this workload to AWS provide?

    1. A.The firm would still pay a fixed cost identical to on-premises, since AWS charges a flat annual subscription regardless of usage.
    2. B.The firm would eliminate variable costs entirely, since AWS converts all infrastructure spending into a single upfront capital purchase like owned servers.
    3. C.The firm would gain no cost benefit, since litigation workloads are considered too unpredictable for any cloud pricing model to accommodate.
    4. D.The firm would pay variable costs tied to actual document-processing usage, avoiding payment for idle capacity during quiet months between cases.
    Show answer & explanation

    Correct answer: D — The firm would pay variable costs tied to actual document-processing usage, avoiding payment for idle capacity during quiet months between cases.

    • A. This is incorrect because AWS does not bill a flat annual subscription; usage-based pricing is exactly what differentiates it from the firm's current fixed on-premises cost.
    • B. This is incorrect because it reverses the direction of the shift; cloud economics moves spending toward variable OpEx, not toward a single upfront capital purchase.
    • C. This is incorrect because variable, unpredictable workloads are exactly the scenario where pay-as-you-go pricing provides the clearest cost benefit over fixed on-premises capacity.
    • D. This is correct because pay-as-you-go pricing turns fixed on-premises maintenance cost into a variable cost, so the firm pays for processing only when litigation activity actually occurs.

    Domain 2: Security and Compliance

    Subdomain 2.1: Understand the AWS shared responsibility model.

    9.An organization sets up AWS IAM Identity Center so employees can sign in with a corporate identity provider across multiple AWS accounts. Who is responsible for configuring this federated access?

    1. A.The customer configures federated access settings, since authentication design is part of security in the cloud.
    2. B.AWS configures federated access settings automatically once a new AWS account is created within the organization.
    3. C.AWS Artifact configures federated access settings as part of its automated compliance reporting for the organization.
    4. D.AWS Shield configures federated access settings to protect the organization from account takeover attempts.
    Show answer & explanation

    Correct answer: A — The customer configures federated access settings, since authentication design is part of security in the cloud.

    • A. Deciding how employees authenticate, including connecting a corporate identity provider through IAM Identity Center, is a configuration choice the customer makes under security in the cloud.
    • B. Creating a new AWS account does not automatically set up federated identity; the customer must explicitly configure the identity provider connection.
    • C. AWS Artifact provides access to compliance documentation; it has no role in configuring identity federation or authentication settings.
    • D. AWS Shield protects against distributed denial-of-service attacks and does not configure identity federation or authentication settings.

    Subdomain 2.2: Understand AWS Cloud security, governance, and compliance concepts.

    10.A company processes credit card payments and must comply with PCI DSS. During due diligence, the security team learns that not every AWS service carries the same compliance certifications. What does this mean for their architecture decisions?

    1. A.They must verify each AWS service used for the cardholder data workload appears on the relevant compliance scope before adopting it.
    2. B.They can use any AWS service for the workload, since AWS Artifact automatically restricts non-compliant services from being launched.
    3. C.They only need to verify compliance for the AWS Region selected, since all services within a compliant Region inherit the same certifications.
    4. D.They can rely on AWS Trusted Advisor to automatically reconfigure any non-compliant service selection to a certified alternative.
    Show answer & explanation

    Correct answer: A — They must verify each AWS service used for the cardholder data workload appears on the relevant compliance scope before adopting it.

    • A. Because compliance certifications apply per service rather than uniformly, the team must confirm each service handling cardholder data is within the relevant compliance scope, which is exactly the architectural discipline this fact requires.
    • B. AWS Artifact only provides access to documentation; it does not technically prevent an account from launching a service that lacks a particular certification.
    • C. Region selection affects data residency, but it does not mean every service available in that Region automatically shares the same compliance certifications as every other service there.
    • D. AWS Trusted Advisor offers best-practice recommendations but does not automatically substitute or reconfigure service choices based on compliance certification status.

    Subdomain 2.2: Understand AWS Cloud security, governance, and compliance concepts.

    11.A company operating in a heavily regulated industry needs to demonstrate to a government regulator that AWS's data centers meet specific physical and operational security standards. Which AWS resource provides evidence for this claim?

    1. A.Third-party audit reports available through AWS Artifact, which attest to AWS's physical and operational security controls.
    2. B.Amazon CloudWatch dashboards, which display operational metrics about the performance of the company's own deployed resources.
    3. C.AWS Config compliance rules, which evaluate the company's resource configurations against internally defined rules.
    4. D.IAM access reports, which summarize which users in the company's account have used which permissions recently.
    Show answer & explanation

    Correct answer: A — Third-party audit reports available through AWS Artifact, which attest to AWS's physical and operational security controls.

    • A. Third-party audit reports obtained through AWS Artifact are the evidence that independently attest to AWS's physical and operational security controls, which is what a regulator would need to see.
    • B. CloudWatch dashboards show performance metrics for the company's own resources, not independent attestations about AWS's physical data center security.
    • C. AWS Config rules evaluate the company's own resource configurations, not the physical or operational security of AWS's underlying data centers.
    • D. IAM access reports describe how the company's own users are using permissions, which is unrelated to demonstrating AWS's physical data center security standards.

    Subdomain 2.4: Identify components and resources for security.

    12.Which AWS service allows a customer to create rules that filter web requests based on conditions such as IP address ranges, HTTP headers, or request rate, and apply those rules to CloudFront distributions, Application Load Balancers, and API Gateway?

    1. A.AWS WAF, a web application firewall that filters web requests using customizable rules matched against IP ranges, headers, body content.
    2. B.AWS Shield, a managed service that automatically protects internet-facing resources against distributed denial-of-service network flood attacks.
    3. C.Amazon GuardDuty, an intelligent threat detection service that continuously monitors account activity for malicious or unauthorized behavior.
    4. D.AWS Firewall Manager, a management tool that centrally administers WAF, Shield Advanced, and security group policies across an organization.
    Show answer & explanation

    Correct answer: A — AWS WAF, a web application firewall that filters web requests using customizable rules matched against IP ranges, headers, body content.

    • A. AWS WAF is purpose-built to define web request filtering rules based on IP ranges, headers, body patterns, and rate limits, and to attach those rules directly to CloudFront, ALB, and API Gateway.
    • B. Shield focuses on absorbing and mitigating denial-of-service flood traffic rather than evaluating individual request attributes like headers or rate.
    • C. GuardDuty is a detection service that surfaces findings from log analysis; it does not create or attach request-filtering rules to resources.
    • D. Firewall Manager orchestrates the deployment of WAF and other policies across many accounts, but the rule engine described in the stem is WAF itself.

    Subdomain 2.4: Identify components and resources for security.

    13.A cloud architect is evaluating AWS Firewall Manager to decide whether it fits the team's need to centrally manage WAF rules, Shield Advanced protections, and security groups across many accounts. Which statement correctly describes what the service does?

    1. A.It centrally configures and manages firewall-related services, including AWS WAF rules, AWS Shield Advanced protections, and VPC security groups.
    2. B.It is a standalone network firewall appliance that customers install on individual EC2 instances to filter traffic at the operating system level.
    3. C.It is a machine learning service that automatically classifies and labels sensitive data discovered inside Amazon S3 buckets across an account.
    4. D.It is a credential vault that stores database passwords and API keys and rotates them automatically on a schedule defined by the account owner.
    Show answer & explanation

    Correct answer: A — It centrally configures and manages firewall-related services, including AWS WAF rules, AWS Shield Advanced protections, and VPC security groups.

    • A. Firewall Manager centrally manages firewall-related protections such as WAF rules, Shield Advanced, and security groups across the accounts in an AWS Organization, which is its actual role.
    • B. There is no per-instance firewall appliance called Firewall Manager; it is a management layer over existing account-level and organization-level firewall services.
    • C. Discovering and classifying sensitive data inside S3 describes Amazon Macie's function, not Firewall Manager's centralized policy management role.
    • D. Storing and rotating credentials describes AWS Secrets Manager, a completely different service from the network policy management Firewall Manager performs.

    Subdomain 2.3: Identify AWS access management capabilities.

    14.An operations team needs to store plain configuration values, such as an application's API endpoint URL and a feature-flag setting, that change occasionally but are not sensitive secrets. Which AWS capability is the most appropriate fit for this use case?

    1. A.AWS Systems Manager Parameter Store, which lets applications retrieve named configuration values through a simple API call.
    2. B.AWS Secrets Manager, which is purpose-built for storing highly sensitive credentials with mandatory automatic rotation schedules.
    3. C.AWS IAM Identity Center, which centralizes workforce sign-in but does not provide a mechanism for storing configuration data.
    4. D.AWS Key Management Service, which manages encryption keys rather than acting as a general configuration value store.
    Show answer & explanation

    Correct answer: A — AWS Systems Manager Parameter Store, which lets applications retrieve named configuration values through a simple API call.

    • A. Parameter Store is designed to hold configuration data and non-secret or lightly-protected values that applications fetch by name, making it a lightweight fit for endpoint URLs and feature flags.
    • B. Secrets Manager targets sensitive credentials like database passwords and API keys with rotation built in; using it for plain, non-sensitive configuration values adds unnecessary cost and complexity.
    • C. IAM Identity Center manages workforce identities and access to accounts and applications; it has no facility for storing arbitrary configuration values for an application to read.
    • D. AWS KMS creates and manages cryptographic keys used to encrypt data elsewhere; it does not itself provide a place to store and retrieve configuration strings.

    Domain 3: Cloud Technology and Services

    Subdomain 3.1: Define methods of deploying and operating in the AWS Cloud.

    15.A startup's only engineer needs to quickly launch a temporary test EC2 instance to try out a new AMI, and plans to terminate it within the hour after checking a few settings visually. Which method requires the least preparation for this immediate, one-off task?

    1. A.The Management Console, letting the engineer launch and inspect the instance interactively at once
    2. B.A CloudFormation stack, requiring a full template to be authored and validated before it can launch
    3. C.An AWS SDK script, requiring a development environment and language runtime set up beforehand
    4. D.The AWS CLI, requiring installation and credential configuration before any command runs
    Show answer & explanation

    Correct answer: A — The Management Console, letting the engineer launch and inspect the instance interactively at once

    • A. This is correct because the Management Console lets the engineer launch and visually inspect a single temporary instance immediately, without any coding or environment setup.
    • B. This is incorrect because authoring and validating a CloudFormation template is unnecessary overhead for launching one instance that will be terminated within the hour.
    • C. This is incorrect because setting up a development environment and runtime just to launch a single test instance takes longer than the task itself warrants.
    • D. This is incorrect because installing and configuring the CLI adds setup time that is not justified for a quick, one-time visual check of a test instance.

    Subdomain 3.1: Define methods of deploying and operating in the AWS Cloud.

    16.A company wants to extend its on-premises data center storage into AWS so that on-premises applications can access cloud-backed storage using standard file and block protocols, without rewriting those applications to call an AWS API. Which deployment concept does this best describe?

    1. A.Hybrid, using a service such as AWS Storage Gateway to bridge on-premises apps with AWS storage
    2. B.Cloud deployment, where the on-premises applications are first rewritten as AWS Lambda functions
    3. C.On-premises deployment, where all storage stays local and no data is ever sent to AWS
    4. D.A one-time operation, where storage is copied to AWS once and the local copy deleted right after
    Show answer & explanation

    Correct answer: A — Hybrid, using a service such as AWS Storage Gateway to bridge on-premises apps with AWS storage

    • A. This is correct because bridging on-premises applications to AWS-backed storage using standard protocols, without rewriting those applications, is the hybrid pattern that a service like AWS Storage Gateway provides.
    • B. This is incorrect because the scenario explicitly avoids rewriting the applications; converting them to Lambda functions is the opposite of what is described.
    • C. This is incorrect because the scenario explicitly extends storage into AWS, which contradicts keeping everything local with no data sent to the cloud.
    • D. This is incorrect because the goal is ongoing, ordinary access to cloud-backed storage from on-premises applications, not a single migration event after which the local copy disappears.

    Subdomain 3.2: Define the AWS global infrastructure.

    17.According to AWS global infrastructure design, what is the minimum number of Availability Zones that a Region contains?

    1. A.At least three physically separate Availability Zones within the same geographic Region
    2. B.Exactly one Availability Zone that hosts every single service offered inside that entire Region
    3. C.At least ten Availability Zones spread across neighboring countries in that Region
    4. D.A variable count of edge locations rather than any dedicated Availability Zones
    Show answer & explanation

    Correct answer: A — At least three physically separate Availability Zones within the same geographic Region

    • A. AWS designs each Region with a minimum of three independent, physically separate Availability Zones so that workloads can be distributed for resilience.
    • B. A single zone per Region would remove the isolation AWS relies on for fault tolerance, so this does not match how Regions are built.
    • C. Ten zones spanning multiple countries overstates the typical count and misrepresents that Availability Zones sit within one Region's geographic boundary.
    • D. Edge locations are a separate infrastructure layer for content delivery and are not a substitute for the Availability Zones that make up a Region.

    Subdomain 3.2: Define the AWS global infrastructure.

    18.A company's disaster recovery plan requires that if its primary AWS Region becomes completely unavailable, a standby environment in a different Region can take over customer traffic within minutes. Which infrastructure relationship does this plan rely on?

    1. A.Two separate AWS Regions, each with its own independent set of Availability Zones, hosting redundant environments
    2. B.A single Region with additional Availability Zones added specifically to increase overall disaster recovery coverage
    3. C.One Availability Zone configured with a duplicate network interface for redundant traffic handling
    4. D.A set of edge locations configured to store full application backups for use during Regional outages
    Show answer & explanation

    Correct answer: A — Two separate AWS Regions, each with its own independent set of Availability Zones, hosting redundant environments

    • A. A cross-Region disaster recovery plan depends on two independent Regions, each with its own Availability Zones, so a failure of one Region's entire infrastructure does not affect the standby Region.
    • B. Adding more Availability Zones within the same Region improves zone-level resilience but does not protect against the failure of that entire Region.
    • C. A duplicated network interface within a single Availability Zone does not provide the geographic separation needed to survive a full Regional outage.
    • D. Edge locations are built for caching content close to users, not for hosting full application environments or serving as a disaster recovery failover target.

    Subdomain 3.4: Identify AWS database services.

    19.A finance team currently takes nightly backups of their self-managed EC2 database by running a manual export script, and a recent outage revealed they can only restore to the previous night's snapshot. They want the ability to restore to any point in time within the last several minutes. Which capability addresses this without moving off a relational engine?

    1. A.Move the database to Amazon RDS, which supports automated backups with point-in-time recovery
    2. B.Increase the frequency of the manual export script so it runs once every five minutes on the EC2 instance
    3. C.Attach an additional Amazon EBS volume to the EC2 instance to store more backup copies locally
    4. D.Enable Amazon S3 versioning on the bucket that stores the manual database export files
    Show answer & explanation

    Correct answer: A — Move the database to Amazon RDS, which supports automated backups with point-in-time recovery

    • A. Amazon RDS continuously captures transaction logs alongside automated backups, so it can restore the database to any second within the retention window instead of only to the last full snapshot.
    • B. Running the manual export more often still only produces discrete snapshots at fixed intervals and does not give continuous, second-level restore granularity, while also adding load to the production instance.
    • C. Adding more EBS storage only increases where backup files can be kept; it does nothing to change the backup process itself or enable point-in-time recovery between snapshots.
    • D. S3 versioning protects against accidental overwrite or deletion of the stored export files, but it does not add transaction-log-level recovery points to the underlying database.

    Subdomain 3.4: Identify AWS database services.

    20.A SaaS startup has a reporting database that sits idle most of the day but experiences short, unpredictable bursts of heavy query activity when customers run monthly reports. The team does not want to pay for a database instance that runs at full capacity around the clock, and they do not want to manually resize capacity before each burst. Which option fits best?

    1. A.Amazon Aurora Serverless, which scales capacity automatically based on demand and bills for usage
    2. B.A fixed-size Amazon RDS instance sized for the largest expected reporting burst, running continuously
    3. C.A self-managed database on a Reserved Instance sized for average daily load throughout the year
    4. D.Amazon ElastiCache configured as the durable primary store for the full relational reporting dataset
    Show answer & explanation

    Correct answer: A — Amazon Aurora Serverless, which scales capacity automatically based on demand and bills for usage

    • A. Aurora Serverless automatically scales database capacity up and down in response to load and bills for the capacity actually used, which matches idle periods followed by unpredictable bursts.
    • B. Provisioning a fixed instance for peak capacity means paying for that capacity even during long idle periods, which is exactly the cost inefficiency the team wants to avoid.
    • C. A Reserved Instance commits to a fixed capacity for a term and is sized for average load, so it would still require manual resizing or run under capacity during sudden reporting bursts.
    • D. ElastiCache is an in-memory cache rather than a durable relational database, so it cannot serve as the primary store for the reporting workload.

    Subdomain 3.6: Identify AWS storage services.

    21.A company's on-premises database server needs iSCSI block volumes that appear to have the full dataset available locally at all times, because it cannot tolerate the network latency of fetching cold blocks from the cloud. AWS should still keep asynchronous, point-in-time snapshots of those volumes in Amazon S3 for durability. Which AWS Storage Gateway configuration matches this need?

    1. A.Volume Gateway in stored mode, which keeps the full volume on local disks for low-latency access and asynchronously snapshots it to Amazon S3
    2. B.Volume Gateway in cached mode, which keeps only frequently used data locally while retrieving the rest of the volume from Amazon S3 on demand
    3. C.File Gateway, which presents storage as NFS or SMB file shares rather than the iSCSI block volumes the on-premises database expects
    4. D.Tape Gateway, which emulates a virtual tape library for backup applications rather than presenting iSCSI block volumes to a database
    Show answer & explanation

    Correct answer: A — Volume Gateway in stored mode, which keeps the full volume on local disks for low-latency access and asynchronously snapshots it to Amazon S3

    • A. This gateway mode stores the complete volume on local on-premises disks so every read stays low-latency, while it still asynchronously uploads point-in-time snapshots to S3 for durability, matching both requirements in the scenario.
    • B. This gateway mode keeps only the most active data locally and pulls the rest of the volume from S3 when needed, which reintroduces the network latency for cold blocks that the database cannot tolerate.
    • C. This gateway type presents NFS or SMB file shares rather than iSCSI block volumes, so a database expecting block storage would not be able to use it directly.
    • D. This gateway type emulates tape storage for backup software rather than acting as an iSCSI block target for a live database, so it does not match the requirement described.

    Subdomain 3.6: Identify AWS storage services.

    22.Which statement accurately describes AWS Backup?

    1. A.It is a fully managed service that centralizes and automates backup policies across supported AWS services from a single console
    2. B.It is a storage class within Amazon S3 designed for archival data that is restored less than once a year at the lowest cost
    3. C.It is a protocol gateway that lets on-premises backup software write to virtual tapes stored durably in the AWS Cloud
    4. D.It is a block-level snapshot feature built exclusively into Amazon EBS with no support for any other AWS storage or database service
    Show answer & explanation

    Correct answer: A — It is a fully managed service that centralizes and automates backup policies across supported AWS services from a single console

    • A. AWS Backup is defined as a fully managed backup service that lets administrators create policies covering scheduling, retention, and cross-Region copying, then apply them centrally across supported services instead of managing each one separately.
    • B. This describes an S3 Glacier storage class for rarely accessed archive objects, which is a distinct S3 feature and not the identity of the centralized, multi-service backup management tool described in the stem.
    • C. This describes AWS Storage Gateway's Tape Gateway type, a separate hybrid storage service for tape-based backup software, not the centralized backup management service the question asks about.
    • D. EBS snapshots are one capability the centralized service can orchestrate, but the service itself extends across many supported AWS services rather than being exclusive to EBS.

    Subdomain 3.3: Identify AWS compute services.

    23.An analytics team is building a distributed big data cluster that scans and processes petabytes of log data stored across dense local hard disk volumes. The cluster needs very high disk throughput and large local storage capacity per node rather than raw IOPS. Which EC2 instance family fits best?

    1. A.Storage optimized instances, whose dense HDD-based local storage delivers high sequential throughput for massive log data sets
    2. B.Compute optimized instances, because their processor speed determines how fast large log files can be scanned and read
    3. C.Memory optimized instances, because caching the entire data set in RAM avoids the need for high local disk throughput
    4. D.General purpose instances, because their balanced disk and network allocation only matches typical, evenly distributed clusters
    Show answer & explanation

    Correct answer: A — Storage optimized instances, whose dense HDD-based local storage delivers high sequential throughput for massive log data sets

    • A. Dense storage optimized instances pair large local HDD capacity with high sequential throughput, which is exactly what a distributed big data cluster scanning petabytes of log data needs.
    • B. Processor speed matters less here than disk throughput and capacity, since the cluster is bottlenecked by how fast it can read large volumes of data off local storage, not by CPU cycles.
    • C. Petabyte-scale log data cannot realistically fit in RAM, so a memory optimized instance does not remove the need for high-capacity, high-throughput local disk storage.
    • D. General purpose instances provide moderate local storage and throughput, which falls short of the dense, high-throughput local disk capacity a petabyte-scale cluster requires.

    Subdomain 3.3: Identify AWS compute services.

    24.An operations team wants to run containerized microservices using AWS's own container orchestration control plane, while keeping the option to run containers on a self-managed fleet of EC2 instances for tighter cost control through Reserved Instances. Which AWS container service matches this requirement?

    1. A.Amazon ECS with the EC2 launch type, which uses AWS's native orchestrator while the team manages the instance fleet
    2. B.Amazon EKS, which requires adopting the open-source Kubernetes control plane instead of an AWS-native orchestration service
    3. C.AWS Lambda, which runs individual event-driven functions and offers no concept of a managed instance fleet for containers
    4. D.AWS Fargate, which removes all direct access to underlying EC2 instances and therefore blocks Reserved Instance cost optimization
    Show answer & explanation

    Correct answer: A — Amazon ECS with the EC2 launch type, which uses AWS's native orchestrator while the team manages the instance fleet

    • A. Amazon ECS is AWS's own container orchestration service, and its EC2 launch type runs tasks on a customer-managed EC2 fleet, which satisfies both the AWS-native control plane and the Reserved Instance cost goal.
    • B. EKS uses the open-source Kubernetes control plane rather than an AWS-native orchestrator, which does not match a requirement specifically calling for AWS's own orchestration service.
    • C. Lambda runs individual functions rather than containers on a managed instance fleet, so it cannot satisfy a requirement built around EC2-based cost control for container workloads.
    • D. Fargate is a serverless launch type that abstracts away the underlying instances entirely, which conflicts with the requirement to manage EC2 instances directly for Reserved Instance savings.

    Subdomain 3.5: Identify AWS network services.

    25.A company operates two on-premises data centers and wants a resilient hybrid connection to a VPC so that if one physical network path to AWS fails, traffic can continue over a second path without manual intervention. Which combination of AWS network services would satisfy this resiliency requirement?

    1. A.Two Direct Connect connections at separate locations, or one Direct Connect connection paired with a Site-to-Site VPN as backup
    2. B.A single AWS Direct Connect connection combined with a second network ACL rule that automatically reroutes traffic when the first rule is unreachable
    3. C.A single Site-to-Site VPN connection with two internet gateways attached to the same VPC to provide two independent internet paths
    4. D.One VPC peering connection to a second VPC in the same Region, configured so that traffic automatically fails over between the two VPCs
    Show answer & explanation

    Correct answer: A — Two Direct Connect connections at separate locations, or one Direct Connect connection paired with a Site-to-Site VPN as backup

    • A. Provisioning redundant Direct Connect connections at separate locations, or pairing a primary Direct Connect connection with a Site-to-Site VPN as failover, is the standard AWS pattern for eliminating a single point of failure in hybrid connectivity.
    • B. Network ACLs filter traffic based on IP address and port rules; they do not provide path failover or redundancy for a Direct Connect connection, so this does not solve the resiliency problem.
    • C. A VPC can only have one internet gateway attached at a time, and an internet gateway serves general internet traffic rather than providing redundant paths for a specific on-premises VPN connection.
    • D. VPC peering connects two VPCs that a company already owns inside AWS; it does not provide connectivity between an on-premises data center and AWS, so it cannot serve as a redundant hybrid path.

    Subdomain 3.5: Identify AWS network services.

    26.A manufacturing company plans to migrate on-premises workloads to a VPC and needs to choose network connectivity for two use cases: a temporary, low-effort connection to begin testing this week, and a long-term production link that must sustain consistent throughput for continuous sensor data ingestion. Which pairing of connectivity options best matches these two use cases?

    1. A.Use AWS Site-to-Site VPN for the immediate testing connection, then migrate the production workload to AWS Direct Connect for consistent throughput
    2. B.Use AWS Direct Connect for the immediate testing connection, then migrate the production workload to a NAT gateway for consistent throughput
    3. C.Use a VPC peering connection for the immediate testing connection, then migrate the production workload to an internet gateway for consistent throughput
    4. D.Use AWS Transit Gateway for the immediate testing connection, then migrate the production workload to a network ACL for consistent throughput
    Show answer & explanation

    Correct answer: A — Use AWS Site-to-Site VPN for the immediate testing connection, then migrate the production workload to AWS Direct Connect for consistent throughput

    • A. Site-to-Site VPN can be stood up quickly over existing internet connectivity, making it suitable for immediate testing, while Direct Connect's dedicated physical link provides the sustained, predictable throughput needed for continuous production sensor data, matching both use cases correctly.
    • B. Direct Connect requires physical circuit provisioning that takes weeks, so it does not fit an immediate testing need, and a NAT gateway only provides outbound internet access for private subnets rather than a dedicated hybrid connection for production ingestion.
    • C. VPC peering connects two VPCs that are both already in AWS and cannot connect an on-premises data center, and an internet gateway provides general internet access rather than a dedicated, high-throughput hybrid link.
    • D. AWS Transit Gateway connects existing VPCs and VPN or Direct Connect attachments together but does not itself establish an on-premises connection, and a network ACL is a traffic filter, not a connectivity method for on-premises workloads.

    Subdomain 3.7: Identify AWS artificial intelligence and machine learning (AI/ML) services and analytics services.

    27.A retail company wants to build a customer-facing chatbot that lets shoppers ask about order status and return policies using natural spoken or typed language, deployed across a mobile app and a contact center. Which AWS service is purpose-built for this?

    1. A.Amazon Lex, which provides natural language voice and chat interfaces so shoppers can complete tasks through conversational bots across multiple channels
    2. B.Amazon Comprehend, which extracts sentiment, key phrases, and named entities from shopper messages but does not manage conversation flow or multichannel deployment
    3. C.Amazon Textract, which extracts printed and handwritten text and form fields from scanned documents rather than handling live conversational input
    4. D.Amazon Polly, which converts written text into spoken audio output but has no capability to understand shopper questions or route them anywhere
    Show answer & explanation

    Correct answer: A — Amazon Lex, which provides natural language voice and chat interfaces so shoppers can complete tasks through conversational bots across multiple channels

    • A. Amazon Lex is correct because it is designed to build conversational interfaces using voice or text, letting users complete tasks like checking an order across channels such as mobile apps and contact centers.
    • B. Amazon Comprehend is incorrect because it analyzes existing text for sentiment, entities, and key phrases; it does not manage dialogue state or route a conversation across channels.
    • C. Amazon Textract is incorrect because it is built to pull text and form data out of scanned documents and images, not to interpret live conversational requests from shoppers.
    • D. Amazon Polly is incorrect because it only performs text-to-speech synthesis; it cannot interpret a shopper's question or decide how to respond, which a chatbot requires.

    Subdomain 3.7: Identify AWS artificial intelligence and machine learning (AI/ML) services and analytics services.

    28.A global e-learning company wants to automatically translate its written course materials into a dozen languages so international students can read content in their native language. Which AWS service is designed specifically for this task?

    1. A.Amazon Translate, which performs neural machine translation of text between languages to localize content for global audiences
    2. B.Amazon Polly, which converts text into spoken audio in a chosen voice and language rather than translating written text itself
    3. C.Amazon Comprehend, which extracts sentiment and entities from text in a given language rather than translating text between languages
    4. D.Amazon Lex, which builds conversational bots for voice and chat interactions rather than translating written course content
    Show answer & explanation

    Correct answer: A — Amazon Translate, which performs neural machine translation of text between languages to localize content for global audiences

    • A. Amazon Translate is correct because it is a neural machine translation service specifically built to translate large volumes of text between languages for localization.
    • B. Amazon Polly is incorrect because it synthesizes spoken audio from text in a given language; it does not convert the underlying text from one language into another.
    • C. Amazon Comprehend is incorrect because it analyzes text to surface sentiment, entities, and key phrases within a language, not to translate that text into another language.
    • D. Amazon Lex is incorrect because it is designed to build conversational chat and voice bots, which is unrelated to bulk translation of written course materials.

    Subdomain 3.8: Identify services from other in-scope AWS service categories.

    29.A startup wants to launch a customer support phone and chat line within days, without purchasing physical call center hardware or hiring telecom engineers to configure switches. Which AWS service lets them quickly stand up a cloud-based, pay-as-you-go contact center with features like skills-based call routing?

    1. A.Amazon Connect, a cloud contact center that provisions phone and chat support with skills-based routing and no physical telecom hardware.
    2. B.Amazon Simple Email Service (Amazon SES), which sends and receives email messages but cannot handle inbound phone calls or live chat sessions at all.
    3. C.AWS IoT Core, which connects physical devices to the cloud over protocols like MQTT rather than routing customer phone or chat interactions directly.
    4. D.Amazon AppStream 2.0, which streams desktop applications into a browser but provides no call routing or contact center agent interface whatsoever.
    Show answer & explanation

    Correct answer: A — Amazon Connect, a cloud contact center that provisions phone and chat support with skills-based routing and no physical telecom hardware.

    • A. Amazon Connect is a fully managed, cloud-based contact center that provisions phone numbers, chat channels, and skills-based routing without on-premises telecom hardware.
    • B. SES is an email sending and receiving service; it cannot route inbound phone calls or manage live chat sessions for a support line.
    • C. IoT Core connects and manages physical IoT devices using protocols such as MQTT; it has no contact center or call-routing functionality.
    • D. AppStream 2.0 streams the output of applications running on AWS to a browser; it is unrelated to phone or chat-based customer support.

    Subdomain 3.8: Identify services from other in-scope AWS service categories.

    30.A company wants every code change merged to its main branch to automatically flow through a defined sequence of stages, source retrieval, build, automated testing, and deployment, with manual approval gates before production, and a visual view of where each release currently stands. Which AWS service orchestrates this kind of multi-stage release workflow?

    1. A.AWS CodePipeline, a continuous delivery service that models a release as staged steps with approval gates and shows each release's progress.
    2. B.AWS CodeBuild, which compiles and tests code inside a single stage but does not orchestrate the surrounding multi-stage release workflow around it.
    3. C.AWS X-Ray, which traces requests across a deployed application's components to identify where latency or errors occur after a release ships out.
    4. D.AWS IoT Core, which manages secure connections and message routing for fleets of physical IoT devices rather than software release pipelines.
    Show answer & explanation

    Correct answer: A — AWS CodePipeline, a continuous delivery service that models a release as staged steps with approval gates and shows each release's progress.

    • A. CodePipeline models a release as configurable stages, such as source, build, test, and deploy, and supports manual approval actions with a visual pipeline status view.
    • B. CodeBuild performs the compile-and-test work inside a single stage; it does not itself define or orchestrate the surrounding multi-stage release pipeline with approval gates.
    • C. X-Ray provides tracing for a running application after deployment, helping diagnose latency; it does not manage the release pipeline stages leading up to that deployment.
    • D. IoT Core is a device connectivity and messaging service for IoT fleets; it plays no role in orchestrating a software release pipeline.

    Domain 4: Billing, Pricing, and Support

    Subdomain 4.1: Compare AWS pricing models.

    31.An events company is planning a live-streamed product launch three months from now and must guarantee that a specific EC2 instance type will be available in a chosen Availability Zone at that exact time, regardless of discount. Which purchasing option is designed for this guarantee?

    1. A.On-Demand Capacity Reservations, which reserve EC2 capacity in a chosen zone for a defined window
    2. B.Spot Instances, which draw from a shared pool of unused capacity that AWS can reclaim at any time
    3. C.Convertible Reserved Instances, which optimize long-term discount rather than guaranteed short-term capacity
    4. D.Compute Savings Plans, which discount usage but never guarantee that specific capacity will be free
    Show answer & explanation

    Correct answer: A — On-Demand Capacity Reservations, which reserve EC2 capacity in a chosen zone for a defined window

    • A. On-Demand Capacity Reservations let a customer reserve EC2 capacity for a specific instance type in a specific Availability Zone for the exact time window needed, independent of any long-term billing discount.
    • B. Spot Instances draw on spare AWS capacity and can be reclaimed with short notice, which is the opposite of a guarantee that capacity will be available for a specific, time-critical event.
    • C. A Convertible Reserved Instance is built to optimize price over a one- or three-year commitment and does not itself guarantee that capacity will exist at a specific future moment.
    • D. A Savings Plan is a pricing commitment based on hourly spend; it lowers the rate for usage that occurs but provides no mechanism to guarantee capacity availability at a specific future time.

    Subdomain 4.1: Compare AWS pricing models.

    32.Which S3 storage class is the default assigned to an object when no storage class is explicitly specified at upload time?

    1. A.S3 Standard
    2. B.S3 Intelligent-Tiering
    3. C.S3 Standard-IA
    4. D.S3 One Zone-IA
    Show answer & explanation

    Correct answer: A — S3 Standard

    • A. S3 assigns the S3 Standard storage class by default to any object uploaded without an explicit storage class setting, matching what the question asks for.
    • B. S3 Intelligent-Tiering must be selected explicitly, either at upload or through a lifecycle rule; it is not the class assigned automatically when nothing is specified.
    • C. S3 Standard-IA is a class chosen deliberately for infrequently accessed data and is never applied automatically as the default for a new upload.
    • D. S3 One Zone-IA must also be chosen explicitly for single-AZ infrequent-access storage and is not the automatic default class for new objects.

    Subdomain 4.2: Understand resources for billing, budget, and cost management.

    33.An organization has ten linked accounts under AWS Organizations, each individually storing a moderate amount of data in Amazon S3. Under consolidated billing, how does AWS calculate whether the organization reaches the lower per-GB pricing tiers for S3 storage?

    1. A.AWS combines the S3 storage usage from every linked account into one total for the organization, so the group reaches the lower-priced volume tiers faster than any single account would alone.
    2. B.AWS evaluates each linked account's S3 storage usage completely separately, so no account benefits from another account's usage even though they share the same management account.
    3. C.AWS applies the lower-priced volume tiers only to the management account's own S3 usage, while every linked member account is billed exclusively at the highest per-GB rate available.
    4. D.AWS requires the organization to manually request a volume-tier pricing review from AWS Support every month before any combined usage across the linked accounts can be considered for a discount.
    Show answer & explanation

    Correct answer: A — AWS combines the S3 storage usage from every linked account into one total for the organization, so the group reaches the lower-priced volume tiers faster than any single account would alone.

    • A. Consolidated billing aggregates usage such as S3 storage across all linked accounts, so the combined total can reach volume pricing tiers that no individual account's usage would reach on its own.
    • B. Evaluating each account separately is exactly what consolidated billing avoids; the shared benefit of combining usage across linked accounts to reach lower per-GB tiers is a core reason organizations use it.
    • C. The lower-priced tiers are not reserved for the management account alone; the combined usage across all linked accounts, including member accounts, is what determines the tier the whole organization reaches.
    • D. No manual request to AWS Support is needed; AWS automatically aggregates linked account usage for volume pricing as part of how consolidated billing works each billing cycle.

    Subdomain 4.2: Understand resources for billing, budget, and cost management.

    34.What is the primary purpose of AWS Cost Explorer?

    1. A.It lets account owners visualize, analyze, and forecast their AWS cost and usage over time through interactive charts filtered by service, account, or tag.
    2. B.It automatically negotiates lower per-service pricing with AWS on the customer's behalf whenever monthly spend crosses a certain threshold set by the account owner.
    3. C.It enforces spending limits by suspending resources the moment a configured budget threshold is exceeded, without requiring any manual intervention from an administrator.
    4. D.It generates the official monthly invoice PDF for an account and emails it directly to the billing contact listed in the account settings.
    Show answer & explanation

    Correct answer: A — It lets account owners visualize, analyze, and forecast their AWS cost and usage over time through interactive charts filtered by service, account, or tag.

    • A. This describes the core purpose of the tool: an interactive console experience for visualizing, analyzing, and forecasting cost and usage, with filtering and grouping by dimensions like service, account, or tag.
    • B. No AWS billing tool negotiates custom pricing automatically based on spend thresholds; AWS pricing is published and applied according to the purchase options and usage the account already has in place.
    • C. Automatically suspending resources is not a function of this tool; enforcing hard spending limits by stopping resources is not a built-in capability of AWS's standard cost analysis and budgeting tools.
    • D. Generating and emailing the official invoice PDF is handled by the standard AWS Billing console and account settings, not by this cost analysis and forecasting tool.

    Subdomain 4.3: Identify AWS technical resources and AWS Support options.

    35.A company notices that an EC2 instance outside their own AWS account appears to be sending spam email and scanning their network for open ports, and wants to formally report this abusive activity to AWS so it can be investigated. Which AWS team handles this kind of report?

    1. A.The AWS Support Center, because any general technical support case opened there is automatically escalated to a network abuse investigation team
    2. B.AWS Identity and Access Management, because it manages the offending account's permissions and can be used to revoke its AWS access
    3. C.The AWS Trust and Safety team, because it is responsible for investigating and responding to reports that AWS-hosted resources are being used to abuse others
    4. D.AWS Trusted Advisor, because its security checks automatically flag resources across every AWS account that appear misconfigured or potentially malicious in nature
    Show answer & explanation

    Correct answer: C — The AWS Trust and Safety team, because it is responsible for investigating and responding to reports that AWS-hosted resources are being used to abuse others

    • A. The Support Center is incorrect because general technical cases are not automatically routed to abuse investigation; abuse has its own dedicated reporting channel.
    • B. IAM is incorrect because it manages permissions within a single account and gives a third party no mechanism to report or act on another company's abuse.
    • C. The Trust and Safety team is correct because it is the dedicated AWS team for receiving and investigating reports that AWS resources are being used to abuse others.
    • D. Trusted Advisor is incorrect because its checks only evaluate resources within the account it runs against, not resources belonging to other AWS customers.

    Want the full experience?

    These are just samples. Practice the full AWS Certified Cloud Practitioner (CLF-C02) question bank in quiz mode — free, no signup, with domain practice and exam simulation.