Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

CLF-C02 Exam Questions & Answers

AWS Certified Cloud Practitioner Exam  •  Amazon

924 Questions 90 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample CLF-C02 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Which of the following are customer responsibilities under the AWS shared responsibility model? (Select TWO.)

Correct Answer: B, C
Explanation:

The AWS shared responsibility model describes how AWS and the customer share responsibility for security and compliance of the AWS environment. AWS is responsible for the security of the cloud, which includes the physical security of AWS facilities, the infrastructure, hardware, software, and networking that run AWS services. The customer is responsible for security in the cloud, which includes the configuration of security groups, the encryption of customer data on AWS, the management of AWS Lambda infrastructure, and the management of network throughput of each AWS Region.

Q2 MultipleChoice

Which AWS service is used to temporarily provide federated security credentials to a

Correct Answer: B
Explanation:

The AWS service that is used to temporarily provide federated security credentials to a user is AWS Security Token Service (AWS STS). AWS STS is a service that enables customers to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that they authenticate (federated users). The company can use AWS STS to grant federated users access to AWS resources without creating permanent IAM users or sharing long-term credentials. AWS STS helps customers manage and secure access to their AWS resources for federated users. Amazon GuardDuty, AWS Secrets Manager, and AWS Certificate Manager are not the best services to use for this purpose. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior across the AWS accounts and resources.AWS Secrets Manager is a service that helps customers manage and rotate secrets, such as database credentials, API keys, and passwords. AWS Certificate Manager is a service that helps customers provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with AWS services and internal connected resources. These services are more useful for different types of security and compliance tasks, rather than providing temporary federated security credentials to a user.

Q3 MultipleChoice

Which of the following describes AWS Local Zones?

Correct Answer: C
Q4 MultipleChoice

Which tasks are the customer's responsibility, according to the AWS shared responsibility model? (Select TWO.)

Correct Answer: B, C
Explanation:

According to the AWS shared responsibility model, AWS is responsible for the security of the cloud, while the customer is responsible for the security in the cloud. This means that AWS is responsible for protecting the infrastructure that runs all of the services offered in the AWS Cloud, such as the global network, the hardware, the software, and the facilities. The customer is responsible for properly configuring the security of the provided service, such as the guest operating system, the application software, the data, and the network traffic.For abstracted services, such as Amazon RDS, AWS operates the infrastructure layer, the operating system, and the database software, while the customer is responsible for managing their data, classifying their assets, and using IAM tools to apply the appropriate permissions12.

Therefore, the tasks that are the customer's responsibility are:

Perform client-side data encryption: The customer is responsible for encrypting their data before sending it to AWS, and decrypting it after receiving it from AWS. This ensures that the data is protected in transit and at rest.AWS provides various encryption options, such as AWS Key Management Service (AWS KMS), AWS CloudHSM, and AWS Certificate Manager (ACM)3.

Configure IAM credentials: The customer is responsible for creating and managing IAM users, groups, roles, and policies that control the access to AWS resources and services.IAM credentials include user names, passwords, access keys, and permissions4.

The tasks that are not the customer's responsibility are:

Establish the global infrastructure: AWS is responsible for building and maintaining the global network of regions, availability zones, and edge locations that provide low latency, high availability, and fault tolerance for the AWS Cloud5.

Secure edge locations: AWS is responsible for protecting the physical security of the edge locations, which are sites that deliver cached content to end users with improved performance6.

Patch Amazon RDS DB instances: AWS is responsible for applying patches and updates to the operating system and the database software of the Amazon RDS DB instances, which are managed relational database service for MySQL, PostgreSQL, Oracle, SQL Server, and Amazon Aurora.Reference:

Shared Responsibility Model - Amazon Web Services (AWS)

Shared responsibility model - Amazon Web Services: Risk and Compliance

Encryption - Amazon Web Services (AWS)

What Is IAM? - AWS Identity and Access Management

Global Infrastructure - Amazon Web Services (AWS)

Amazon CloudFront Features - Content Delivery Network (CDN)

[What Is Amazon Relational Database Service (Amazon RDS)? - Amazon Relational Database Service]

Q5 MultipleChoice

An ecommerce company has migrated its IT infrastructure from an on-premises data center to the AWS Cloud. Which cost is the company's direct responsibility?

Correct Answer: A
Explanation:

The cost of application software licenses is the company's direct responsibility when it migrates its IT infrastructure from an on-premises data center to the AWS Cloud. Application software licenses are the agreements that grant users the right to use specific software products, such as operating systems, databases, or applications. Depending on the type and terms of the license, users may need to pay a fee to the software vendor or provider to use the software legally and access its features and updates. When users migrate their IT infrastructure to the AWS Cloud, they can choose to buy new licenses from AWS, bring their own licenses (BYOL), or use a combination of both. However, regardless of the option they choose, they are still responsible for complying with the license terms and paying the license fees to the software vendor or provider. AWS does not charge users for the application software licenses they bring or buy, but only for the AWS resources they use to run their applications. Therefore, thecost of application software licenses is the only cost among the options that is the company's direct responsibility. The other costs are either included in the AWS service fees or covered by AWS.

:AWS License Manager Pricing,Software licensing: The blind spot in public cloud costs,Cost Optimization tips for SQL Server Licenses on AWS,Microsoft Licensing on AWS

Get access to all 924 verified questions with detailed answers.

Unlock All CLF-C02 Questions

Frequently Asked Questions

The CLF-C02 is an entry-level certification exam from Amazon Web Services that validates foundational knowledge of AWS cloud concepts, services, and best practices. It is designed for individuals with little to no prior AWS experience and serves as a stepping stone to more advanced AWS certifications.

The CLF-C02 exam costs $100 USD. AWS occasionally offers promotional discounts or free exam vouchers through training programs, events, or partner channels, so it's worth checking for special offers before purchasing.

The exam is 90 minutes long and consists of 65 questions in multiple-choice and multiple-response format. You need to score at least 70% to pass the certification.

The exam covers four main domains: Cloud Concepts (26%), Security and Compliance (25%), Technology and Services (33%), and Billing, Pricing, and Support (16%). Topics include AWS services, pricing models, security, compliance, and fundamental cloud computing principles.

AWS recommends 6 months of exposure to the AWS cloud environment, though intensive study for 2-4 weeks can be sufficient. You can prepare using free AWS training resources, Udemy courses, practice exams, hands-on labs, and the official AWS Certified Cloud Practitioner exam guide.
Exam Details
  • Exam CodeCLF-C02
  • VendorAmazon
  • Total Questions924
  • Duration90 min
  • LanguageEnglish
  • Version
  • Last UpdatedSep 4, 2026
4.9/5

Pass CLF-C02 First Time

Get all 924 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals