Free AWS Cloud Practitioner (CLF-C02) Practice Questions
Practice with real exam-style AWS Certified Cloud Practitioner (CLF-C02) questions, each paired with a full explanation of why the right answer is right and the others aren't. Every question links to the official AWS documentation that backs it up, and nothing here requires signing up. 25 questions below, free with no signup. Last updated 2026-07-19.
Every question is verified against official AWS documentation, linked below each answer.
- Question 1Billing, Pricing, and Support
A company runs a production e-commerce workload that is important to revenue but is not classified as business-critical. It wants 24/7 access to Cloud Support Engineers by phone, chat, and email, with a target response time of under one hour for 'production system down' cases, but it does not need a dedicated, named Technical Account Manager. Which support plan is the most cost-effective fit?
Reveal answer & explanation
Answer: B. Business Support
Business Support provides 24/7 phone, chat, and email access to Cloud Support Engineers with a target response time of under one hour for production-system-down cases, and it does not include a named Technical Account Manager, matching exactly what this company needs without paying for unneeded features.
Go deeper: What specifically does a Technical Account Manager add that this company said it doesn't need? Why does 'important to revenue' not automatically mean 'business-critical' in AWS support terms?
Source: official AWS documentation · verified 2026-07-19
- Question 2Billing, Pricing, and Support
A team on the Basic Support plan opens AWS Trusted Advisor and notices it only shows checks for service quotas and a handful of security items - not the full library of cost-optimization checks such as idle load balancers or low-utilization EC2 instances that a colleague at another company described. What is the most likely explanation, and what would resolve it?
Reveal answer & explanation
Answer: C. The full set of Trusted Advisor checks, including all cost-optimization checks, requires a Business-tier support plan or higher; Basic Support only includes a limited set of checks
The full catalog of Trusted Advisor checks across cost optimization, performance, security, fault tolerance, and service limits is available only to accounts on a Business-tier support plan or higher. Accounts on Basic Support get just Service Limits checks plus a limited set of Security and Fault Tolerance checks, with no automatic refresh, matching the team's experience exactly.
Go deeper: Which Trusted Advisor check categories does Basic Support actually include? What support tier is the minimum needed to unlock the full checklist?
Source: official AWS documentation · verified 2026-07-19
- Question 3Billing, Pricing, and Support
A company wants to purchase a pre-configured security appliance, sold as an Amazon Machine Image by an independent software vendor, and have the charge appear on its existing AWS bill rather than paying the vendor through a separate invoice. Where should the finance manager direct the team to find and purchase this software?
Reveal answer & explanation
Answer: D. AWS Marketplace
AWS Marketplace is a curated digital catalog for finding, buying, and deploying third-party software, including pre-configured AMIs, with billing and payment handled by AWS so the charge appears directly on the customer's AWS bill instead of a separate vendor invoice.
Go deeper: How does buying through AWS Marketplace change who you get billed by? What's the difference between browsing AWS Marketplace and negotiating a separate contract with a vendor?
Source: official AWS documentation · verified 2026-07-19
- Question 4Billing, Pricing, and Support
A media company runs a nightly video-transcoding batch job. The job can be safely paused and resumed at any point without affecting customers, and the team wants to minimize compute cost for this fault-tolerant, flexible-timing workload. Which EC2 purchasing option typically offers the largest discount for this use case?
Reveal answer & explanation
Answer: D. Spot Instances
Spot Instances let you use spare EC2 capacity at discounts of up to about 90% off On-Demand prices, making them ideal for fault-tolerant, interruptible workloads like nightly batch transcoding that can tolerate an interruption notice.
Go deeper: What tradeoff do you accept in exchange for a Spot Instance's discount? Why wouldn't a 1- or 3-year Reserved Instance commitment fit a job that only runs some nights?
Source: official AWS documentation · verified 2026-07-19
- Question 5Cloud Concepts
A company's data platform team explains that their system can add many more database read replicas over the next year to support permanent growth in the user base, but that this expansion is planned and carried out manually rather than happening automatically within minutes. Which term best describes this characteristic?
Reveal answer & explanation
Answer: A. Scalability
Scalability is the broader capacity of a system to grow (or shrink) to meet demand over time; it can be planned and executed manually, as in this scenario of adding replicas over a year for permanent growth.
Go deeper: What's the key difference between scaling that happens automatically and scaling that's planned out manually? Why doesn't a year-long, manually-executed expansion count as elasticity?
Source: official AWS documentation · verified 2026-07-19
- Question 6Cloud Concepts
An e-commerce company's engineering team has historically had to predict server demand months in advance for the holiday shopping season, often over-provisioning and wasting money, or under-provisioning and causing outages. Which cloud benefit directly solves this problem?
Reveal answer & explanation
Answer: C. Stop guessing capacity
Cloud computing lets you access as much or as little capacity as you need and scale up or down with only minutes' notice, eliminating the need to guess infrastructure capacity in advance, which is exactly the problem described.
Go deeper: How does being able to provision capacity within minutes remove the need to forecast demand months out? Why is this benefit about avoiding guesswork rather than about the CapEx-to-OpEx shift?
Source: official AWS documentation · verified 2026-07-19
- Question 7Cloud Concepts
A photo-sharing application experiences a sudden tenfold spike in traffic when a post goes viral, then returns to normal traffic levels a few hours later. The application's infrastructure automatically adds compute capacity during the spike and automatically removes the extra capacity afterward. Which cloud characteristic does this describe?
Reveal answer & explanation
Answer: D. Elasticity
Elasticity is the ability of a system to automatically grow and shrink capacity in near real time to match changing demand, exactly as shown by the automatic add-and-remove behavior in this scenario.
Go deeper: What makes this scenario different from plain scalability, which also involves adding capacity? Why does 'automatically removes the extra capacity afterward' matter for identifying elasticity?
Source: official AWS documentation · verified 2026-07-19
- Question 8Cloud Concepts
A marketing team wants to test a new promotional website and, thanks to AWS, can provision the needed servers within minutes instead of submitting a hardware purchase request that used to take weeks under the old on-premises process. Which cloud benefit does this scenario best illustrate?
Reveal answer & explanation
Answer: B. Increased speed and agility
In a cloud computing environment, new IT resources are only a click away, reducing the time to make resources available from weeks to minutes, which increases organizational agility and the ability to experiment quickly and cheaply - exactly what the marketing team experiences.
Go deeper: How does cutting provisioning time from weeks to minutes change what a team is willing to try? Why isn't this scenario about AWS's lower per-unit pricing?
Source: official AWS documentation · verified 2026-07-19
- Question 9Cloud Concepts
A developer wants to run backend code that responds to events without provisioning, patching, or managing any servers, and wants to pay only for the compute time actually used while the code is running. Which cloud computing concept does this describe?
Reveal answer & explanation
Answer: C. Serverless computing
Serverless computing lets you run code without provisioning or managing servers, with the underlying provider handling scaling and availability, and you pay only for the compute time you actually consume, with no charge when code is not running - matching the developer's requirements exactly.
Go deeper: What does 'no charge when code isn't running' tell you about how this billing model works? Why doesn't a Reserved Instance commitment fit an event-driven workload like this?
Source: official AWS documentation · verified 2026-07-19
- Question 10Cloud Concepts
A startup founder wants to launch a new mobile app but does not want to spend a large amount of money upfront purchasing physical servers before knowing whether the app will succeed. Which AWS Cloud benefit addresses this concern?
Reveal answer & explanation
Answer: A. Trading capital expense for variable expense
A core AWS Cloud value proposition is trading upfront capital expenditure - buying servers and data centers before you know your needs - for variable operating expenditure, where you pay only for what you consume. This directly matches the founder's concern about large upfront spending.
Go deeper: Why does paying only for what you use reduce the risk of launching an unproven idea? How is trading CapEx for OpEx different from economies of scale?
Source: official AWS documentation · verified 2026-07-19
- Question 11Security and Compliance
A compliance officer wants to track how an S3 bucket's configuration, such as its public access settings, has changed over time, and be alerted automatically if a resource drifts away from an approved configuration baseline. Which service is designed for this?
Reveal answer & explanation
Answer: D. AWS Config
AWS Config continuously records the configuration state of AWS resources over time and can evaluate them against defined rules, alerting when a resource such as an S3 bucket drifts from an approved baseline like 'block all public access' - exactly the described requirement.
Go deeper: Why can't CloudTrail alone show you how a resource's configuration looked last month? What role do Config rules play in catching a resource that's drifted from its baseline?
Source: official AWS documentation · verified 2026-07-19
- Question 12Security and Compliance
A prospective enterprise customer's legal team requests AWS's SOC 2 report and ISO 27001 certification before agreeing to sign a contract. Where can the company download these AWS compliance reports on demand?
Reveal answer & explanation
Answer: A. AWS Artifact
AWS Artifact is the self-service portal where customers can download AWS's compliance reports and certifications, such as SOC 1/2/3 reports and ISO certifications, as well as agreements like the Business Associate Addendum, on demand.
Go deeper: Why wouldn't Trusted Advisor be the right place to find a SOC 2 report? What kinds of documents does AWS Artifact make available on demand?
Source: official AWS documentation · verified 2026-07-19
- Question 13Security and Compliance
A company wants to add an extra layer of protection so that even if an IAM user's password is stolen, an attacker still cannot sign in without a second piece of proof, such as a rotating code from a mobile authenticator app or a hardware security key. Which AWS feature should they enable?
Reveal answer & explanation
Answer: D. Multi-factor authentication (MFA)
Multi-factor authentication requires a second, independent factor - something the user has, like a virtual MFA device, hardware token, or authenticator app code - in addition to the password, so a stolen password alone is not enough to sign in.
Go deeper: Why doesn't a longer password alone solve the 'stolen password' problem? What does 'something you have' add to sign-in security that a password alone doesn't?
Source: official AWS documentation · verified 2026-07-19
- Question 14Security and Compliance
A company's public-facing web application has recently been targeted by SQL injection and cross-site scripting (XSS) attempts. Which AWS service lets them create rules to filter and monitor HTTP/HTTPS requests before they reach the application?
Reveal answer & explanation
Answer: B. AWS WAF (Web Application Firewall)
AWS WAF operates at the application layer, letting customers write and apply rules that inspect HTTP/HTTPS requests and block common web exploits such as SQL injection and cross-site scripting before they reach the application.
Go deeper: Why is Shield the wrong tool for filtering malicious HTTP requests? What layer of the application stack does WAF inspect that a DDoS service doesn't?
Source: official AWS documentation · verified 2026-07-19
- Question 15Security and Compliance
A startup's compliance team asks who is responsible for the physical security of the data centers, and for maintaining the underlying host hardware and hypervisor, that run their EC2 instances. Under the AWS shared responsibility model, which party owns this responsibility?
Reveal answer & explanation
Answer: A. AWS is responsible for security 'of' the cloud, which includes physical data center security, the host hardware, and the hypervisor layer.
Under the shared responsibility model, AWS is responsible for security 'of' the cloud: the physical facilities, hardware, networking infrastructure, and the virtualization (hypervisor) layer that hosts customer instances.
Go deeper: Why can't a customer audit AWS's data centers directly, even if their compliance team wants to? What does 'security of the cloud' cover that 'security in the cloud' doesn't?
Source: official AWS documentation · verified 2026-07-19
- Question 16Security and Compliance
A company launches Amazon EC2 instances to host a new web application. Under the AWS shared responsibility model, which of the following tasks is the customer's responsibility rather than AWS's?
Reveal answer & explanation
Answer: B. Patching the guest operating system, configuring security group rules, and choosing how to encrypt application data.
For EC2, an unmanaged (infrastructure-as-a-service) offering, the customer is responsible for security 'in' the cloud: patching the guest operating system, configuring network controls like security groups, managing identity and access, and deciding how to encrypt their data.
Go deeper: Which of these four tasks would still be the customer's job even on a fully managed database service? Why is patching the hypervisor never something a customer can do, even if they wanted to?
Source: official AWS documentation · verified 2026-07-19
- Question 17Security and Compliance
A company currently runs a self-managed database on EC2 instances, where they patch the OS and the database engine themselves. They are evaluating a move to Amazon RDS instead. Under the shared responsibility model, what changes when they make this move?
Reveal answer & explanation
Answer: C. AWS takes on responsibility for patching the underlying operating system and database engine software, shifting more of the operational burden to AWS compared with self-managed EC2.
Moving from self-managed EC2 to a managed service like RDS shifts the shared responsibility line: AWS now handles OS patching and database engine maintenance, tasks the customer previously owned on EC2. This is the core benefit of managed services.
Go deeper: What operational burden does AWS take on when a team moves from self-managed EC2 to RDS? What does the customer still have to manage even after switching to a managed database service?
Source: official AWS documentation · verified 2026-07-19
- Question 18Cloud Technology and Services
A company runs a small script that resizes images uploaded to a website. The script runs for only a few seconds, is triggered only when a new image is uploaded, and sometimes goes days without running at all. The company does not want to pay for idle compute capacity or manage servers.
Reveal answer & explanation
Answer: A. Use AWS Lambda to run the resizing code only when triggered by an upload, paying only for the compute time used
Lambda is the serverless choice for short, event-triggered, intermittent workloads: it runs code only when triggered and bills only for the compute time consumed, with no servers to provision or manage.
Go deeper: Why does an idle EC2 instance still cost money even when the script isn't running? What about this workload makes 'pay only when triggered' especially valuable?
Source: official AWS documentation · verified 2026-07-19
- Question 19Cloud Technology and Services
A research team is running a scientific application that performs heavy in-memory processing on very large datasets that must be held entirely in RAM, while CPU demand remains only moderate. They want to choose an EC2 instance family optimized for this workload.
Reveal answer & explanation
Answer: B. A memory-optimized instance family, chosen for a high ratio of RAM to vCPU
Memory-optimized instance families provide a large amount of RAM relative to compute, which matches workloads that must hold big datasets entirely in memory, such as in-memory databases or real-time analytics.
Go deeper: Why would a compute-optimized instance be the wrong fit for a dataset that must live entirely in RAM? What ratio of resources is characteristic of a memory-optimized instance family?
Source: official AWS documentation · verified 2026-07-19
- Question 20Cloud Technology and Services
A freelance web designer wants to launch a simple WordPress blog for a small business client. They want a pre-configured virtual server bundled with storage and networking at a low, predictable monthly price, without individually configuring compute, storage, and networking components.
Reveal answer & explanation
Answer: C. Amazon Lightsail, which bundles compute, storage, and networking into a simple, low-cost monthly plan
Lightsail is built for exactly this scenario: simple virtual private servers bundled with storage and networking at a fixed, predictable monthly price, ideal for beginners and small projects like a single WordPress blog.
Go deeper: Why is Elastic Beanstalk more complexity than this scenario actually needs? What three components does Lightsail bundle into a single predictable price?
Source: official AWS documentation · verified 2026-07-19
- Question 21Cloud Technology and Services
A developer has written a Java web application and wants to deploy it to AWS quickly by uploading the application code. They want AWS to automatically provision and manage the underlying EC2 instances, load balancer, and Auto Scaling group, without configuring each resource by hand.
Reveal answer & explanation
Answer: D. AWS Elastic Beanstalk, which provisions and manages the underlying infrastructure automatically from uploaded application code
Elastic Beanstalk is AWS's platform-as-a-service offering: developers upload application code and Elastic Beanstalk automatically provisions and manages the EC2 instances, load balancing, and scaling behind the scenes.
Go deeper: What infrastructure pieces does Elastic Beanstalk provision for you automatically? Why wouldn't Route 53 or Direct Connect solve the developer's actual problem?
Source: official AWS documentation · verified 2026-07-19
- Question 22Cloud Technology and Services
A company wants to run containerized microservices on AWS but does not want to provision, patch, or scale the underlying EC2 servers that would normally host the container cluster. They still want AWS to handle scheduling and orchestrating their containers.
Reveal answer & explanation
Answer: A. Run containers on AWS Fargate, a serverless compute engine for containers that removes the need to manage EC2 instances
Fargate is the serverless compute engine available for both ECS and EKS that removes the need to provision, patch, or manage EC2 instances for a container cluster, letting AWS handle the underlying compute while the customer focuses on containers.
Go deeper: What's the difference between running ECS on Fargate versus ECS on the EC2 launch type? Why does 'still requires provisioning EC2' rule out two of these options?
Source: official AWS documentation · verified 2026-07-19
- Question 23Cloud Technology and Services
A retail website experiences unpredictable spikes in traffic during flash sales, followed by long stretches of low traffic. The company wants the number of running EC2 instances to automatically increase during spikes and decrease afterward, without manual intervention.
Reveal answer & explanation
Answer: B. Amazon EC2 Auto Scaling, which automatically adjusts the number of instances based on demand
EC2 Auto Scaling is designed to automatically add or remove EC2 instances in response to changing demand, matching compute capacity to load without requiring manual intervention, which directly addresses the flash-sale traffic pattern.
Go deeper: Why doesn't Route 53 or Direct Connect solve a compute-capacity problem like this one? What triggers EC2 Auto Scaling to add or remove instances?
Source: official AWS documentation · verified 2026-07-19
- Question 24Cloud Technology and Services
A company runs a web application across multiple EC2 instances spread over two Availability Zones for high availability. They need incoming traffic to be automatically distributed across all healthy instances so no single instance becomes overloaded and traffic avoids unhealthy instances.
Reveal answer & explanation
Answer: C. Elastic Load Balancing, which distributes incoming traffic across multiple instances and Availability Zones
Elastic Load Balancing automatically distributes incoming application traffic across multiple targets, such as EC2 instances, spanning one or more Availability Zones, and routes traffic away from instances that fail health checks.
Go deeper: How does a load balancer decide to stop sending traffic to an unhealthy instance? Why is EBS Multi-Attach unrelated to distributing incoming traffic?
Source: official AWS documentation · verified 2026-07-19
- Question 25Cloud Technology and Services
A media company needs to store an ever-growing archive of video files, potentially reaching petabytes over time, with extremely high durability so files are virtually never lost, and without pre-provisioning a fixed amount of storage capacity in advance.
Reveal answer & explanation
Answer: D. Amazon S3, an object storage service designed for virtually unlimited scale and 99.999999999% (11 nines) durability
S3 is purpose-built object storage that scales to any amount of data automatically and is engineered for 11 nines of durability, with no need to pre-provision capacity, matching the archival growth requirement exactly.
Go deeper: Why is EBS a poor fit for a dataset that keeps growing unpredictably over time? What does '11 nines of durability' mean for an archive like this one?
Source: official AWS documentation · verified 2026-07-19
CLF-C02 exam — common questions
What is the AWS Certified Cloud Practitioner (CLF-C02) exam?
CLF-C02 is AWS's foundational certification and the most common first AWS certification for people starting out with cloud computing. It has no prerequisites and requires no coding, so it's suitable for non-engineers as well as technical staff.
How is the CLF-C02 exam structured, and what score do I need to pass?
The exam has 65 questions (50 scored and 15 unscored) and runs 90 minutes. Scores are reported on a scale of 100-1000, and you need a score of 700 or higher to pass.
How much does the CLF-C02 exam cost, and how long should I study?
The exam costs $100 USD. Typical preparation time is 2-3 weeks, depending on how much hands-on AWS exposure you already have.
What topics does the CLF-C02 exam cover?
The exam spans four domains: Cloud Concepts (24%), Security and Compliance (30%), Cloud Technology and Services (34%), and Billing, Pricing, and Support (12%).
More practice sets: AI Practitioner (AIF-C01) · Developer (DVA-C02) · Solutions Architect (SAA-C03)