30 free AWS Cloud Practitioner (CLF-C02) practice questions
Thirty questions split the way the official exam guide weights the four domains, 7 on Cloud Concepts, 9 on Security and Compliance, 10 on Cloud Technology and Services and 4 on Billing, Pricing and Support. Some ask for two answers, like the real exam.
The part that matters to me is the proof. After you check an answer, you get the sentence from the AWS documentation that backs it, with the link. If AWS changes a page and a question goes stale, you will see it before I do, and I would like to hear about it.
A company runs a business-critical web application on Amazon EC2 in a single location inside one AWS Region. The company wants the application to keep running if that one location fails. What should the company do?
Answer A. Launching EC2 instances in multiple Availability Zones protects applications from the failure of a single location in the Region. If an instance in one zone fails, an instance in another zone can handle requests.
- B. A larger instance in the same location is still exposed to the failure of that single location.
- C. Edge caching speeds content delivery but does not run the application's compute in a second location.
- D. A single Local Zone is still one location and does not provide failover by itself.
“By launching EC2 instances in multiple Availability Zones, you can protect your applications from the failure of a single location in the Region.”
docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html
A company is reviewing the AWS global infrastructure before migrating a production database. Which TWO characteristics describe Availability Zones? (Select TWO.)
Answer C, E. AWS describes Availability Zones as one or more discrete data centers, each with redundant power, networking, and connectivity, housed in separate facilities. This design allows workloads that are more highly available than a single data center could offer.
- A. Availability Zones are housed in separate facilities, not a single shared building.
- B. Content caches are CloudFront edge locations, not Availability Zones.
- D. Availability Zones are AWS data centers within a Region, not racks in a customer facility.
“Availability Zones consist of one or more discrete data centers, each with redundant power, networking, and connectivity, housed in separate facilities.”
docs.aws.amazon.com/whitepapers/latest/aws-overview/global-infrastructure.html
A company's development and test environments are used only during business hours on weekdays, but they currently run 24 hours a day, 7 days a week. Which AWS Well-Architected cost optimization design principle would help the company save up to 75% on these environments?
Answer C. Adopt a consumption model means paying only for the resources you require. AWS gives the example of stopping development and test environments outside working hours for potential savings of 75% (40 hours versus 168 hours).
- A. Analyzing and attributing expenditure helps identify who spends what, but it does not by itself stop idle resources.
- B. Cloud Financial Management builds organizational capability; it is not the principle that describes stopping unused environments.
- D. Maximize utilization is a sustainability principle about right-sizing and high utilization, not the cost principle in question.
“You can stop these resources when they are not in use for a potential cost savings of 75% (40 hours versus 168 hours).”
docs.aws.amazon.com/wellarchitected/latest/framework/cost-dp.html
A company's engineering leaders want guidance on building an enterprise-grade, scalable, hybrid cloud platform, modernizing existing workloads, and implementing cloud-native solutions. Which AWS CAF perspective provides this guidance?
Answer C. The Platform perspective helps build an enterprise-grade, scalable, hybrid cloud platform, modernize existing workloads, and implement cloud-native solutions. Its common stakeholders include the CTO, architects, and engineers.
- A. The Operations perspective focuses on delivering cloud services at a level that meets business needs.
- B. The Governance perspective focuses on orchestrating cloud initiatives while minimizing transformation risk.
- D. The Business perspective focuses on cloud investments accelerating digital transformation and business outcomes.
“Platform perspective helps you build an enterprise-grade, scalable, hybrid cloud platform, modernize existing workloads, and implement new cloud-native solutions.”
docs.aws.amazon.com/whitepapers/latest/overview-aws-cloud-adoption-framework/foundational-capabilities.html
A company wants to migrate a Microsoft SQL Server database to a different database engine on AWS. Before moving the data, it needs to assess and convert the source schemas to the new target engine. Which AWS capability should it use?
Answer B. To migrate to a different database engine, DMS Schema Conversion automatically assesses and converts source schemas to the new target engine. The data can then be migrated with AWS DMS.
- A. AWS Migration Hub tracks migration progress across tools; it does not convert schemas.
- C. AWS Application Discovery Service gathers on-premises server information; it does not convert schemas.
- D. Amazon CloudFront is a content delivery network unrelated to schema conversion.
“To migrate to a different database engine, you can use DMS Schema Conversion. This service automatically assesses and converts your source schemas to a new target engine.”
docs.aws.amazon.com/dms/latest/userguide/Welcome.html
An IT manager explains that the on-premises data center always has expensive spare capacity. According to AWS, what is the main reason on-premises environments carry this extra cost compared with cloud environments?
Answer A. AWS notes that IT departments have historically had to provision for peak demand. Cloud environments minimize costs because capacity is provisioned based on average usage rather than peak usage.
- B. On-premises servers can run virtualization; this is not the reason for spare capacity.
- C. Cloud compute is charged based on usage; it is not free.
- D. On-premises environments can be monitored; monitoring is not the cause of overprovisioning.
“Historically, IT departments have had to provision for peak demand. However, cloud environments minimize costs because capacity is provisioned based on average usage rather than peak usage.”
docs.aws.amazon.com/whitepapers/latest/cost-optimization-right-sizing/right-size-before-migrating.html
A small business has never used AWS and wants to model the cost of a proposed architecture before building anything. Which AWS tool should it use?
Answer B. AWS Pricing Calculator is a web-based service for creating cost estimates for AWS use cases. It is useful for people who have never used AWS and lets them model solutions before building.
- A. AWS Compute Optimizer needs metrics from existing resources to make recommendations.
- C. AWS Trusted Advisor inspects an existing AWS environment rather than estimating a proposed one.
- D. AWS License Manager tracks software licenses and does not estimate architecture costs.
“AWS Pricing Calculator is a web-based service that you can use to create cost estimates to suit your AWS use cases.”
docs.aws.amazon.com/whitepapers/latest/how-aws-pricing-works/aws-pricingtco-tools.html
An AWS Lambda function uses a managed Python runtime configured with the Auto runtime update mode. A security patch is released for the runtime. Who applies the patched runtime to the existing function?
Answer B. For functions that use the Auto runtime update mode, Lambda is responsible for applying runtime updates. This is an example of a responsibility that shifts toward AWS with a serverless service.
- A. Rebuilding from a base image applies to functions deployed as container images, not managed runtimes.
- C. Patch Manager patches managed nodes such as EC2 instances, not Lambda managed runtimes.
- D. Redeploying to pick up patches is the customer's job only in Function update mode, not Auto mode.
“Lambda is responsible for applying runtime updates to all functions configured to use the Auto runtime update mode.”
docs.aws.amazon.com/lambda/latest/dg/runtime-management-shared.html
Which TWO components does AWS operate, manage, and control under the shared responsibility model? (Select TWO.)
Answer A, B. AWS manages everything from the host operating system and virtualization layer down to the physical security of the facilities. Guest operating systems, data classification, and security group rules are customer responsibilities.
- C. Security group configuration is explicitly a customer responsibility.
- D. The guest OS, including its patches, is managed by the customer.
- E. Only the customer can classify its own data.
“AWS operates, manages and controls the components from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates.”
aws.amazon.com/compliance/shared-responsibility-model/
A software vendor wants to sell its cloud application to US federal agencies. Which compliance program standardizes the security assessment and continuous monitoring of cloud services used by those agencies?
Answer A. FedRAMP is the US government-wide program that standardizes security assessment, certification, and continuous monitoring for cloud products used by federal agencies. Compliance needs therefore depend on the industry and country a customer serves.
- B. GDPR is a European Union privacy regulation.
- C. HIPAA protects health information in the US healthcare sector.
- D. PCI DSS applies to entities handling payment card data.
“The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program intended to standardize the security assessment, certification, and continuous monitoring for cloud products and services used by federal agencies.”
aws.amazon.com/compliance/fedramp/
An Amazon S3 bucket was deleted overnight. The operations manager needs to find which IAM user or role made the API call. Which service records this information?
Answer C. AWS CloudTrail records actions taken by users, roles, and AWS services as events, including actions from the console, CLI, SDKs, and APIs. It is the service used to audit who did what in an account.
- A. CloudWatch metrics track performance data, not the identity behind API calls.
- B. Inspector scans for vulnerabilities, not account activity.
- D. Trusted Advisor gives recommendations, not an activity log.
“Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. Events include actions taken in the AWS Management Console, AWS Command Line Interface, and AWS SDKs and APIs.”
docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-user-guide.html
A compliance analyst must confirm that Amazon EC2 is covered by a specific compliance program and then obtain the related third-party audit report. Which TWO resources should the analyst use? (Select TWO.)
Answer A, B. AWS directs customers to the Services in Scope by Compliance Program page to check whether a service is covered, and to AWS Artifact to download third-party audit reports. Coverage can differ between services, which is why the per-service check matters.
- C. Trusted Advisor checks best practices in the customer's account, not compliance program scope.
- D. Inspector scans workloads for vulnerabilities.
- E. The Health Dashboard reports operational events.
“To learn whether an AWS service is within the scope of specific compliance programs, see AWS services in Scope by Compliance Program and choose the compliance program that you are interested in. [...] You can download third-party audit reports using AWS Artifact.”
docs.aws.amazon.com/AWSEC2/latest/UserGuide/compliance-validation.html
A team grants permissions using only AWS managed policies. A security consultant warns that this may not be least privilege. Why?
Answer C. Because AWS managed policies are written for all customers, they might grant more than a specific workload needs. AWS recommends reducing permissions further with customer managed policies tailored to the use case.
- A. AWS managed policies can be attached to users, groups, and roles.
- B. AWS managed policies do not expire.
- D. Many AWS managed policies grant read-only or partial access, not full admin.
“Keep in mind that AWS managed policies might not grant least-privilege permissions for your specific use cases because they are available for use by all AWS customers.”
docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
In AWS IAM Identity Center, an administrator wants to define a Database Admin access template once and assign it to a group across several AWS accounts. What should the administrator create?
Answer D. A permission set is a template that defines one or more IAM policies. IAM Identity Center uses it to create matching roles in each target account and assign access to users and groups.
- A. IAM groups are per-account and are not how Identity Center assigns access.
- B. Bucket policies control access to a single S3 bucket.
- C. SCPs limit maximum permissions but do not grant access to users.
“A permission set is a template that you create and maintain that defines a collection of one or more IAM policies.”
docs.aws.amazon.com/singlesignon/latest/userguide/permissionsetsconcept.html
An ecommerce company sees bots sending malicious HTTP requests to its application behind Amazon CloudFront. It wants to inspect and filter these web requests based on rules it defines. Which service should it use?
Answer A. AWS WAF is a web application firewall that monitors HTTP(S) requests forwarded to protected resources such as CloudFront distributions. Customers define rules that allow, block, or customize the response to requests.
- B. Shield Standard mitigates common network and transport layer DDoS attacks, not custom HTTP request filtering.
- C. Network ACLs filter IP traffic at the subnet level and cannot inspect HTTP requests or protect CloudFront.
- D. Inspector scans workloads for software vulnerabilities and does not filter traffic.
“AWS WAF is a web application firewall that lets you monitor the HTTP(S) requests that are forwarded to your protected web application resources.”
docs.aws.amazon.com/waf/latest/developerguide/waf-chapter.html
A new cloud team wants an AWS website that introduces cloud security at AWS, including identity, infrastructure and data protection, logging and monitoring, and incident response. Which resource should it start with?
Answer B. The AWS cloud security site at aws.amazon.com/security presents AWS security, identity, and compliance services around identity, infrastructure, and data protection, logging and monitoring, and incident response. It is the entry point AWS offers for security information.
- A. The Cost and Usage Report contains billing data.
- C. CloudWatch dashboards visualize a customer's own metrics.
- D. The seller portal is for vendors listing products.
“Define user permissions and identities, infrastructure protection and data protection measures for a smooth and planned AWS adoption strategy. [...] Gain visibility into your organization's security posture with logging and monitoring services. [...] Automated incident response and recovery to help shift the primary focus of security teams from response to analyzing root cause.”
aws.amazon.com/security/
An organization keeps all of its servers in its own data center. It uses virtualization and resource management tools to improve utilization and to provide dedicated resources to teams. Which deployment model is this?
Answer C. Deploying resources on premises with virtualization and resource management tools is called a private cloud. It is chosen for dedicated resources but does not give many of the benefits of cloud computing.
- A. The cloud model runs all application parts in the cloud, not in the company data center.
- B. A hybrid model connects cloud resources with on-premises ones, and this organization uses no cloud resources.
- D. Serverless is a way of running code without managing servers, not a deployment model based on an owned data center.
“The deployment of resources on-premises, using virtualization and resource management tools, is sometimes called the private cloud”
docs.aws.amazon.com/whitepapers/latest/aws-overview/types-of-cloud-computing.html
Which statement about Availability Zones in the same AWS Region is correct?
Answer C. Availability Zones are designed so that they do not share single points of failure. Generators and cooling equipment are not shared, and zones are supplied by different power substations.
- A. Zones are designed to be supplied by different power substations.
- B. Zones are meaningfully distant from each other to prevent correlated failures.
- D. Deployments to zones in the same Region are separated in time to prevent correlated failure.
“Common points of failure, like generators and cooling equipment, are not shared across Availability Zones and are designed to be supplied by different power substations.”
docs.aws.amazon.com/whitepapers/latest/aws-fault-isolation-boundaries/availability-zones.html
A company runs a high-throughput NoSQL database on Amazon EC2 that requires millions of low-latency, random I/O operations per second on local storage. Which instance family should the company choose?
Answer A. Storage optimized instances deliver millions of low-latency, random I/O operations per second and are designed for high sequential read and write access to very large local data sets, such as high-throughput databases.
- B. Accelerated computing instances use hardware accelerators for tasks such as graphics processing or floating point calculations.
- C. General purpose instances balance resources and are not designed for extreme local I/O.
- D. Compute optimized instances focus on processor performance, not local storage I/O.
“Storage optimized instances deliver millions of low-latency, random I/O operations per second to applications.”
aws.amazon.com/ec2/instance-types/
Which AWS compute options are serverless, meaning the customer does not provision or manage servers? (Select TWO.)
Answer A, D. Fargate is a serverless, pay-as-you-go compute engine for containers, and Lambda runs code without provisioning or managing servers. In both cases AWS manages the underlying infrastructure.
- B. EC2 instances are virtual servers that the customer selects and manages.
- C. Outposts is AWS hardware installed on premises, with instances the customer manages.
- E. Lightsail offers virtual private servers that the customer manages.
“AWS Lambda lets you run code without provisioning or managing servers. [...] AWS Fargate is a compute engine for Amazon ECS that allows you to run containers without having to manage servers or clusters.”
docs.aws.amazon.com/whitepapers/latest/aws-overview/compute-services.html
A company is moving an on-premises database to AWS. The source database must stay online during the move, and changes made during the migration must keep flowing to the target until cutover. Which service should the company use?
Answer D. AWS DMS migrates relational databases, data warehouses, NoSQL databases, and other data stores. It can perform one-time migrations or replicate ongoing changes to keep the source and target in sync.
- A. AWS SCT converts schemas between engines, it does not replicate the data changes.
- B. Storage Gateway connects on-premises applications to cloud storage, it is not a database migration tool.
- C. AWS Backup centralizes backups, it does not keep a live target database in sync.
“You can perform one-time migrations or replicate ongoing changes to keep sources and targets in sync.”
docs.aws.amazon.com/dms/latest/userguide/Welcome.html
A security team must block a specific range of IP addresses from reaching any instance in a subnet. Which VPC feature can explicitly deny that traffic at the subnet level?
Answer D. A network ACL allows or denies specific inbound or outbound traffic at the subnet level. Because it supports deny rules, it can block an IP range for the whole subnet.
- A. Security groups support allow rules only and apply to instances, so they cannot express a deny.
- B. Route tables decide where traffic is sent, they do not filter it by source address.
- C. An internet gateway connects the VPC to the internet and has no filtering rules.
“A network access control list (ACL) allows or denies specific inbound or outbound traffic at the subnet level.”
docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html
A hospital must retain patient records for many years to meet regulations. The records are almost never read, and a retrieval time of up to two days is acceptable. Which S3 storage class offers the lowest cost?
Answer D. S3 Glacier Deep Archive is recommended for archive data accessed less than once a year and for keeping data for years to meet compliance requirements. AWS describes it as the lowest-cost storage option in AWS.
- A. Glacier Instant Retrieval offers millisecond access and costs more than Deep Archive, which is not needed here.
- B. S3 Standard-IA keeps data available in milliseconds at a higher storage price.
- C. Intelligent-Tiering is for unknown access patterns, and the pattern here is known to be very rare.
“We recommend using S3 Glacier Deep Archive for archive data that's accessed less than once a year. This storage class is designed for retaining data sets for multiple years to meet compliance requirements”
docs.aws.amazon.com/AmazonS3/latest/userguide/glacier-storage-classes.html
An airline wants a chatbot on its website and mobile app that understands customers' typed and spoken requests, such as changing a booking. Which AWS service is designed to build these conversational interfaces?
Answer C. Amazon Lex builds conversational interfaces using voice and text. It combines automatic speech recognition and natural language understanding so developers can create chatbots without deep learning expertise.
- A. Polly converts text to speech but does not understand user intent or manage a conversation.
- B. Translate translates text between languages, it does not run conversations.
- D. Rekognition analyzes images and videos.
“Amazon Lex V2 is an AWS service for building conversational interfaces for applications using voice and text.”
docs.aws.amazon.com/lexv2/latest/dg/what-is.html
A company needs a serverless service to discover data across many sources, catalog its schema, and run extract, transform, and load (ETL) jobs that load the data into a data lake. Which service should it use?
Answer C. AWS Glue is a serverless data integration service used to discover, prepare, move, and integrate data from multiple sources. It keeps a centralized data catalog and runs ETL pipelines.
- A. Kinesis ingests streaming data, it is not a catalog and ETL service.
- B. Quick Sight builds dashboards and visualizations.
- D. OpenSearch Service runs search and analytics clusters, it is not a data catalog and ETL tool.
“AWS Glue is a serverless data integration service that makes it easy for analytics users to discover, prepare, move, and integrate data from multiple sources.”
docs.aws.amazon.com/glue/latest/dg/what-is-glue.html
A company wants to give each remote employee a persistent Windows or Linux desktop that runs in AWS and can be reached from various devices, without buying and deploying desktop hardware. Which service should it use?
Answer C. Amazon WorkSpaces provisions virtual, cloud-based desktops running Windows or Linux. WorkSpaces Personal offers persistent desktops assigned to individual users, accessible from many devices.
- A. WorkSpaces Applications, formerly AppStream 2.0, streams individual applications rather than providing a full persistent desktop per user.
- B. WorkSpaces Secure Browser provides a hosted browser for web applications, not a full desktop.
- D. Lightsail offers virtual private servers for websites, not managed end-user desktops.
“Amazon WorkSpaces enables you to provision virtual, cloud-based desktops known as WorkSpaces for your users.”
docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces.html
A retailer creates an immediate-use On-Demand Capacity Reservation for 10 instances in one Availability Zone to guarantee capacity for a two-week sales event. During the first three days, only 6 matching instances are running. How is the Capacity Reservation billed during those three days?
Answer B. Capacity Reservations are charged at the equivalent On-Demand rate whether or not instances are running in the reserved capacity. Unused capacity shows up as unused reservation on the EC2 bill, so the retailer pays for all 10.
- A. Reserved capacity is billed even when no instance is using it.
- C. Capacity Reservations are not billed at Spot prices.
- D. Immediate-use Capacity Reservations have no term commitment and can be canceled at any time to stop charges.
“Capacity Reservations are charged at the equivalent On-Demand rate whether you run instances in reserved capacity or not, including any applicable regional surcharge for Dedicated Instances. If you do not use the reservation, this shows up as unused reservation on your Amazon EC2 bill.”
docs.aws.amazon.com/AWSEC2/latest/UserGuide/capacity-reservations-pricing-billing.html
A startup's finance lead wants an email when the current month's AWS spend is forecasted to exceed $5,000, before the money is actually spent. The lead also wants the option to apply an IAM policy automatically at a threshold to stop new resources from being provisioned. Which AWS service meets these requirements?
Answer B. AWS Budgets lets customers set cost budgets and receive alerts on both actual and forecasted spend. Budgets can also trigger actions, such as applying a custom IAM policy that denies provisioning of additional resources.
- A. Cost Explorer is for viewing and analyzing costs and forecasts, while threshold alerts and automated actions are configured in AWS Budgets.
- C. AWS Pricing Calculator creates estimates for planned workloads and does not monitor actual spend.
- D. Cost and Usage Reports deliver detailed billing data to Amazon S3 but do not send threshold alerts or take actions.
“Setting a monthly cost budget with a fixed target amount to track all costs associated with your account. You can choose to be alerted for both actual (after accruing) and forecasted (before accruing) spends.”
docs.aws.amazon.com/cost-management/latest/userguide/budgets-managing-costs.html
A company on the Basic Support plan opens AWS Trusted Advisor and sees only a limited set of checks. It wants all Trusted Advisor checks, including cost optimization checks, and programmatic access through the Trusted Advisor API. What is the minimum change that meets this goal?
Answer D. With Business Support+, Enterprise Support, or Unified Operations, customers can use the Trusted Advisor console and API to access all checks. Basic Support is limited to the service limits checks and selected security and fault tolerance checks, so Business Support+ is the minimum change.
- A. Basic Support provides only the service limits checks and a few security and fault tolerance checks.
- B. Enterprise Support works but is not the minimum, because Business Support+ already unlocks all checks and the API.
- C. AWS Organizations does not change which Trusted Advisor checks are available, since access depends on the support plan.
“If you have a AWS Business Support+, AWS Enterprise Support, or AWS Unified Operations plan, you can use the Trusted Advisor console and the AWS Trusted Advisor API to access all Trusted Advisor checks.”
docs.aws.amazon.com/awssupport/latest/user/trusted-advisor.html
A manufacturing company is planning a large-scale migration to AWS. It wants a team of AWS experts who use proven frameworks to help it design, build, and migrate its workloads. Which AWS offering is designed for this?
Answer A. AWS Professional Services provides AWS experts, specialized solutions, and proven frameworks to help organizations design, build, migrate, and manage workloads on AWS. Large-scale migration is one of its core focus areas.
- B. The Trust and Safety team handles reports of abuse of AWS resources.
- C. re:Post is a community knowledge resource, not a delivery team for migration projects.
- D. Trusted Advisor runs automated best-practice checks and does not deliver migration projects.
“AWS Professional Services combines AI-enhanced delivery, specialized solutions, deep industry expertise, and dedicated centers of delivery excellence (VMware, SAP, and more) to help organizations design, build, migrate, and manage their AWS workloads and applications.”
aws.amazon.com/professional-services/
These 30 come from a set of 300, four full 65 question exams at the same weights plus a 40 question drill, in one PDF with the same sourced answer key. It is 12 euros on Ko-fi, no account needed to buy.
If you would rather sit them timed in the browser with a score by domain at the end, the same 300 questions are also a Udemy practice test course, 12.99 dollars with that link until November 4.

