EnglishDeutschFrançaisEspañolPortuguês

AWS · CLF-C02 · Beginner

AWS Cloud Practitioner (CLF-C02) — Practice Questions and Mock Exam

Prepare for CLF-C02 with original practice questions and clear answer explanations. Ask Alex, your AI tutor, when you need more detail, use your results to identify topics to review, and practice your pacing with timed mock exams.

65Mock exam questions
90minTime limit
700/ 1000Passing score

Checked against AWS · September 2026 · Current exam version

About the exam

The AWS Certified Cloud Practitioner is Amazon Web Services' foundational credential, validating a broad understanding of AWS Cloud concepts, services, security, architecture, pricing, and support. It covers the cloud value proposition, shared responsibility model, security best practices, and an overview of core services across compute, storage, networking, and databases.

This is the recommended starting point for anyone entering the AWS ecosystem, including business professionals, managers, and early-career technologists. It demonstrates fundamental cloud literacy and the ability to articulate the benefits and considerations of operating on the AWS platform.

Try five CLF-C02 questions

Try five practice questions from the app’s current AWS Certified Cloud Practitioner question bank, with answers and explanations.

Security and Compliance1 / 5

Which type of IAM policy is attached directly to an IAM user, group, or role?

AlexFull explanation from Alex

Identity-based policies are JSON permissions documents attached directly to an IAM user, group, or role, defining what actions that identity can perform. They come in two forms: managed policies (standalone, reusable, versioned) and inline policies (embedded in a single identity). Resource-based policies attach to resources like S3 buckets or SQS queues and specify who can access them. Service control policies (SCPs) are Organization-level guardrails applied to accounts, not IAM identities. Access control lists (ACLs) are legacy mechanisms on resources like S3 and VPCs. The key distinction: identity-based = who can do what; resource-based = who can access this resource.

Sourcedocs.aws.amazon.com

Cloud Concepts3 / 5

Which type of cloud computing model provides the most control over the underlying infrastructure?

AlexFull explanation from Alex

IaaS provides maximum control over cloud infrastructure: virtual machines, networking, and storage. You manage the OS, middleware, runtime, and applications. PaaS abstracts infrastructure management, providing a platform for deploying applications without managing servers. SaaS delivers complete applications with no infrastructure control. FaaS (serverless) abstracts everything except your code, executing functions on demand. The control spectrum runs: IaaS (most) → PaaS → FaaS → SaaS (least). More control means more operational responsibility — IaaS requires patching, scaling, and security configuration. AWS examples: EC2 (IaaS), Elastic Beanstalk (PaaS), Lambda (FaaS), WorkMail (SaaS).

Sourceaws.amazon.com

Billing, Pricing, and Support4 / 5

Which AWS service provides recommendations to help reduce costs, improve performance, and address security gaps across an AWS account?

AlexFull explanation from Alex

Trusted Advisor is the AWS service for account-level best-practice recommendations across cost, performance, security, fault tolerance, service limits, and operational excellence. Cost Explorer analyzes cost and usage trends, Budgets alerts on spending or usage thresholds, and Pricing Calculator estimates costs for planned workloads. Those services do not provide the same broad operational recommendation coverage as Trusted Advisor.

Sourcedocs.aws.amazon.com

Security and Compliance5 / 5

A company wants to protect its web application from common exploits such as SQL injection and cross-site scripting (XSS). Which AWS service should they use?

AlexFull explanation from Alex

AWS WAF is a web application firewall that monitors HTTP/HTTPS requests to protected resources including CloudFront, ALB, API Gateway, AppSync, and Cognito. It blocks SQL injection and cross-site scripting (XSS) through configurable rules and AWS Managed Rule Groups covering OWASP Top 10 threats. Why not other options? Shield protects against DDoS attacks at layers 3/4/7 — not application-layer exploits like SQLi/XSS. GuardDuty analyzes CloudTrail, VPC Flow Logs, and DNS logs for threat detection, not real-time request filtering. Macie discovers and protects sensitive data in S3, unrelated to web exploit prevention. WAF operates at Layer 7, inspecting request content for malicious patterns.

Sourcedocs.aws.amazon.com

453 practice questions

The Pass-IT question pool gives you material to practice for CLF-C02. A Pass-IT mock exam uses 65 questions and a 90-minute time limit; these are practice settings.

Pool details: CLF-C02

Exam details checked against AWSSeptember 6, 2026

date of the last check against the official AWS source

Passing score700 / 1,000

as published by AWS

Objectives in the guide19 objectives listed in the official guide

across 4 domains in the official exam guide

Pool size453 questions

= The pool size is equivalent to 6 sets of 65 questions; this does not mean that each mock exam uses a separate set.

Blueprint domains4 domains in the exam blueprint

Cloud Concepts 98 · Security and Compliance 120 · Cloud Technology and Services 167 · Billing, Pricing, and Support 68

Recorded as checked against sources453 of 453

questions recorded as having their answer, options, and explanation checked against official AWS documentation

What's on the exam

Cloud Technology and Services carries the most weight at 34%, the exam's broadest domain, spanning deployment methods, global infrastructure, and the core service families — compute, database, network, storage, plus AI/ML, analytics, and a long tail of other AWS categories. Security and Compliance follows close behind at 30%, covering the shared responsibility model, IAM and access management, and the AWS services that support governance and compliance.

Cloud Concepts takes 24%, testing the business case for AWS adoption and the Well-Architected Framework's pillars rather than service mechanics. Billing, Pricing, and Support closes the blueprint at 12% — the smallest domain, but not a safe one to skip: purchasing options, cost-management tooling, and AWS support-plan tiers show up reliably, and candidates who leave it for last after compute and storage lose points they didn't expect to.

Exam blueprint: CLF-C02

Cloud Concepts24%

Weigh the reasons organizations move to AWS against the framework used to judge whether an architecture is well built, and understand both the paths into the cloud and the cost logic that makes the move worthwhile.

≈ 6 h
Security and Compliance30%

Understand where AWS's security responsibilities end and the customer's begin, the governance and compliance concepts that follow from that split, how to manage access with IAM and MFA, and which AWS services and resources exist to help secure an account.

≈ 8 h
Cloud Technology and Services34%

Identify ways to provision and operate in the AWS Cloud and describe AWS global infrastructure, and recognize core AWS compute, database, network, and storage services and their appropriate use cases. Also covers AWS AI/ML and analytics services, and services across other categories such as application integration, developer tools, and IoT.

≈ 9 h
Billing, Pricing, and Support12%

Compare AWS purchasing options like On-Demand, Reserved, and Spot pricing, keep spend visible through tools such as AWS Budgets and Cost Explorer, and know where to find technical documentation and which support plan fits.

≈ 3 h

Exam format and question types

The exam draws 65 questions (50 scored, 15 unscored) from multiple-choice and multiple-response formats inside a 90-minute window. Questions test conceptual understanding of AWS services, cloud economics, and the shared responsibility model rather than hands-on configuration. At under 1.4 minutes per question there's no time pressure, and unanswered questions score as incorrect, so answering everything beats leaving anything blank.

Question types: CLF-C02

Multiple Choice70%

Select the single answer that best meets the question’s requirements.

Multiple Response30%

Select multiple answers. Follow the question’s instructions on how many to choose.

See AWS for official question-format information. The shares shown describe the Pass-IT practice pool; they do not establish the proportions on the official exam.

Preparing for CLF-C02

The exam runs through Pearson VUE, either at a testing center or online with a remote proctor, and is offered in Arabic, English, Bahasa Indonesia, French, German, Italian, Japanese, Korean, Portuguese (Brazil), Spanish (Latin America and Spain), Simplified Chinese, and Traditional Chinese. Certification holds for 3 years; renewal means passing a recertification exam before it expires, or earning a higher-level AWS certification, which renews it automatically.

Preparation and logistics: CLF-C02

Preparation

Illustrative study time15–40 h

illustrative planning range: 15 h with relevant experience to 40 h when starting out; your needs may fall outside this range

LevelBeginner

Taking and maintaining the certification

DeliveryPearson VUE testing center or online proctored exam
Retake policy14-day waiting period between exam attempts, no limit on total number of attempts
Certification validity3 years

Pass a recertification exam before the 3-year expiration date, or earn a higher-level AWS certification to automatically renew

Common pitfalls

Topics to review: CLF-C02

  1. 01Service Confusion

    Mixing up similar services like S3 vs EBS vs EFS or CloudWatch vs CloudTrail leads to incorrect answers on core service questions.

  2. 02Shared Responsibility

    Misunderstanding the boundary between AWS and customer responsibilities is a frequent cause of failed security and compliance questions.

  3. 03Pricing Models

    Confusing On-Demand, Reserved, Spot, and Savings Plans pricing leads to wrong answers on cost optimization questions.

  4. 04Support Plans

    Not knowing the differences between Basic, Developer, Business, and Enterprise support plan features costs easy points.

  5. 05Skipping Scenarios

    Focusing only on memorizing definitions without understanding when and why to apply each service in real-world contexts.

Frequently asked questions

How long is the AWS Certified Cloud Practitioner exam?

The CLF-C02 exam has 65 questions and a 90-minute time limit.

What is the passing score for AWS Certified Cloud Practitioner?

The passing score for the CLF-C02 exam is 700 / 1000.

Which pitfalls should I review when preparing for AWS Certified Cloud Practitioner?

Topics to review include Service Confusion, Shared Responsibility, Pricing Models, Support Plans, Skipping Scenarios. Work through examples to check that you understand the distinctions and can explain your answer.

Should you take CLF-C02 or go straight to SAA-C03?

It depends on whether you have ever used AWS. CLF-C02 is the foundational exam with a roughly 25-hour study budget, and it covers the vocabulary that SAA-C03 assumes you already have. Our guide walks through both routes and who each one actually suits. Read the CLF-C02 decision guide

Does CLF-C02 expire?

Yes, after three years. You can either sit the recertification exam before that date or earn any higher-level AWS certification, which renews Cloud Practitioner automatically. Most people renew by moving up to an associate exam rather than by repeating this one.

Which CLF-C02 topics carry the most marks?

Cloud technology and services is the largest domain at 34%, with security and compliance at 30% and cloud concepts at 24%. The fourth domain, which covers billing and support, closes the exam at 12%. Almost two thirds of the questions therefore sit in services and security, not in concepts.

Do you need experience before taking CLF-C02?

No. AWS sets no prerequisite, and the exam is written for people who work around cloud projects rather than inside them. The catalog budget is about 25 hours, the shortest of any AWS exam we cover.

What should you take after CLF-C02?

SAA-C03 is the usual next step if you are heading towards architecture, DVA-C02 if you write the code, and SOA-C03 if you run the platform. None of the three require CLF-C02 first. Passing any of them also renews your Cloud Practitioner certification.

One certification, 12 months

Practice for CLF-C02

Focus your practice on one certification, or choose Pro to practice across all certifications.

Start a free practice sessionTry the first 20 questions without a card to see whether the practice suits you.

For eligible purchases: money-back guarantee if you fail your exam.

View guarantee terms →