CLF-C02 Sample Questions & Answers
Questions span why teams move to the AWS Cloud, who secures what under the shared model, the services and global infrastructure you deploy on, the most heavily weighted area, and how pricing, budgets and support plans work.
Launch the full CLF-C02 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Cloud Technology and Services · Identify AWS network services
A gaming company is deploying a new mobile game with a global user base. To ensure a low-latency experience for all players, the company needs to serve game assets (images, sounds, and configuration files) from locations close to the users. Which AWS service is specifically designed for this purpose?
Show answer & explanation
Correct answer: C
Amazon CloudFront is a content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency and high transfer speeds. It does this by caching content in a worldwide network of edge locations. This is the ideal service for distributing game assets to a global user base. AWS Direct Connect is for private network connections, S3 Transfer Acceleration is for fast uploads to S3, and Elastic Load Balancing distributes traffic to backend servers within a region.
- Question 2Intermediate
Security and Compliance · Identify AWS access management capabilities
A developer needs to give an application running on an Amazon EC2 instance permission to access an Amazon DynamoDB table. What is the most secure way to grant these permissions without hardcoding credentials?
Show answer & explanation
Correct answer: B
The most secure and recommended method is to use an IAM role. An IAM role can be attached to an EC2 instance, which grants the applications on that instance temporary security credentials to access other AWS services. This avoids the need to store long-term credentials (like access keys) on the instance, which is a major security risk. The EC2 instance automatically rotates the temporary credentials provided by the role.
- Question 3Beginner
Billing, Pricing, and Support · Compare AWS pricing models
Which of the following describes the pricing model of the AWS Cloud?
Show answer & explanation
Correct answer: B
The AWS Cloud pricing model is fundamentally pay-as-you-go. This means you pay only for the individual services you need, for as long as you use them, without requiring long-term contracts or complex licensing. This allows businesses to trade capital expense (CapEx) for variable expense (OpEx).
- Question 4Beginner
Cloud Concepts · Define the benefits of the AWS Cloud
What is the primary benefit of deploying an application across multiple Availability Zones within a single AWS Region?
Show answer & explanation
Correct answer: C
Availability Zones (AZs) are distinct locations within an AWS Region that are engineered to be isolated from failures in other AZs. By deploying an application across multiple AZs, it can remain operational even if one of the AZs fails, thus significantly increasing its availability and fault tolerance. Reducing global latency is achieved by using multiple Regions or Amazon CloudFront. Data sovereignty is handled at the Region level.
- Question 5Intermediate
Cloud Technology and Services · Define methods of deploying and operating in the AWS Cloud
A hospital needs to move its on-premises electronic health record (EHR) system to AWS. Due to the sensitive nature of the data, they require a dedicated, private, and high-bandwidth network connection between their data center and their VPC. Which AWS service should they use?
Show answer & explanation
Correct answer: C
AWS Direct Connect is a cloud service solution that makes it easy to establish a dedicated network connection from an on-premises location to AWS. This provides a more consistent network experience than internet-based connections, offering private connectivity and high bandwidth, which are critical for sensitive workloads like an EHR system. A Site-to-Site VPN connects over the public internet, which may not meet the performance or security requirements. VPC Peering connects two VPCs, and a NAT Gateway provides outbound internet access from a private subnet.
- Question 6Beginner
Cloud Technology and Services · Define methods of deploying and operating in the AWS Cloud
Which AWS service allows you to provision your infrastructure as code using templates?
Show answer & explanation
Correct answer: C
AWS CloudFormation provides a common language to model and provision all the infrastructure resources in your cloud environment. It allows you to use a simple text file (in YAML or JSON format) to model and provision, in an automated and secure manner, all the resources needed for your applications across all regions and accounts. This practice is known as Infrastructure as Code (IaC).
- Question 7Intermediate
Billing, Pricing, and Support · Understand resources for billing, budget, and cost management
A company has several departments, each with its own AWS account. The CFO wants a single bill for all accounts to take advantage of volume pricing discounts. Which AWS service or feature should be used?
Show answer & explanation
Correct answer: D
AWS Organizations allows you to centrally govern your environment as you grow and scale your AWS resources. One of its key features is consolidated billing, which combines the usage from all member accounts into a single bill for the management account. This allows the organization to benefit from volume pricing discounts and Reserved Instance sharing across accounts.
- Question 8IntermediateSelect 2
Security and Compliance · Understand the AWS shared responsibility model
According to the AWS shared responsibility model, which of the following are responsibilities of the customer? (Select TWO)
graph TD subgraph SharedResponsibility["Shared Responsibility Model"] subgraph AWS["AWS Responsibility (Security OF the Cloud)"] A[Hardware] --> B[Software] B --> C[Networking] C --> D[Facilities] end subgraph Customer["Customer Responsibility (Security IN the Cloud)"] E[Customer Data] --> F[Platform/IAM] F --> G[Operating System] G --> H[Network & Firewall Config] H --> I[Client/Server-Side Encryption] end endShow answer & explanation
Correct answers: B, C
In the shared responsibility model, AWS is responsible for the security 'of' the cloud (infrastructure, hardware, software, networking, facilities). The customer is responsible for security 'in' the cloud. This includes managing the guest OS on EC2, configuring firewalls like security groups and network ACLs, managing their data, and configuring IAM. Physical security and hypervisor management are AWS's responsibilities.
- Question 9Advanced
Cloud Technology and Services · Identify services from other in-scope AWS service categories
A university wants to provide its researchers with a simple way to launch pre-approved, standardized computing environments for data analysis, without giving them full access to the underlying AWS services. Which AWS service is designed for this purpose?
Show answer & explanation
Correct answer: B
AWS Service Catalog allows organizations to create and manage catalogs of IT services that are approved for use on AWS. These IT services can include everything from virtual machine images, servers, software, and databases to complete multi-tier application architectures. This enables the university to provide standardized, pre-approved environments (products) that researchers can deploy on-demand, ensuring compliance and governance without granting them direct access to provision underlying services.
- Question 10Beginner
Cloud Concepts · Understand concepts of cloud economics
What is the economic benefit of moving from an on-premises data center to the AWS Cloud?
Show answer & explanation
Correct answer: D
A primary economic benefit of the cloud is the shift from capital expenditure (CapEx) to operational expenditure (OpEx). Instead of investing heavily in data centers and servers before you know how you’re going to use them (CapEx), you can pay only when you consume computing resources, and pay only for how much you consume (OpEx).
Ready for the real thing?
The full CLF-C02 simulator has every exam-style question, timed mode, and instant scoring.