AWS Certified Cloud Practitioner (CLF-C02)
Foundational, role-agnostic exam covering AWS Cloud concepts, security, core services, and billing.
- Passing score
- 70%
- Per attempt
- 15 questions
- Question pool
- 67
- Suggested time
- 90 min
Content last updated Aug 14, 2026
About this exam
The exam validates overall knowledge of the AWS Cloud, independent of a specific job role: explaining the value of the AWS Cloud, the shared responsibility model, the Well-Architected Framework, security best practices, AWS Cloud costs/economics/billing, and identifying core AWS services (compute, network, database, storage) for common use cases.
Out of scope for the target candidate: coding, designing cloud architecture, troubleshooting, implementation, load/performance testing.
Question format: multiple choice (1 correct + 3 distractors) and multiple response (2+ correct out of 5+ options). 50 scored questions, scaled score 100–1000, passing score 700.
Exam details
- Exam code
- CLF-C02
- Exam fee
- $100 USD
- Item format
- 65 questions — multiple choice or multiple response
- Prerequisites
- None required — up to 6 months of general AWS Cloud exposure is recommended
- Exam structure
- 65 questions
- Delivery method
- Pearson VUE testing center or online proctored exam
- Target audience
- Individuals in technical or non-technical roles who need an overall understanding of the AWS Cloud, including line-of-business roles such as sales, marketing, or project management
- Result reporting
- Pass/fail
- Certification validity
- 3 years
Content domains
Expand a domain for what it covers and what you'll need to know.
Cloud Concepts 24% ▾
Task Statement 1.1: Define the benefits of the AWS Cloud
- Knowledge of: value proposition of the AWS Cloud
- Skills in: benefits of global infrastructure (speed of deployment, global reach); advantages of high availability, elasticity, and agility
Task Statement 1.2: Identify design principles of the AWS Cloud
- Knowledge of: AWS Well-Architected Framework
- Skills in: the six pillars (operational excellence, security, reliability, performance efficiency, cost optimization, sustainability); differences between the pillars
Task Statement 1.3: Understand the benefits of and strategies for migration to the AWS Cloud
- Knowledge of: cloud adoption strategies; resources supporting the migration journey
- Skills in: components of the AWS Cloud Adoption Framework (AWS CAF) — reduced business risk, improved ESG performance, increased revenue, increased operational efficiency; migration strategies (e.g. database replication)
Task Statement 1.4: Understand concepts of cloud economics
- Knowledge of: aspects of cloud economics; cost savings of moving to the cloud
- Skills in: fixed vs. variable costs; on-premises environment costs; licensing strategies (BYOL vs. included licenses); rightsizing; benefits of automation; economies of scale
Security and Compliance 30% ▾
Task Statement 2.1: Understand the AWS shared responsibility model
- Knowledge of: AWS shared responsibility model
- Skills in: customer responsibilities; AWS responsibilities; shared responsibilities; how responsibilities shift by service (e.g. RDS, Lambda, EC2)
Task Statement 2.2: Understand AWS Cloud security, governance, and compliance concepts
- Knowledge of: compliance/governance concepts; benefits of cloud security (e.g. encryption); where security logs are captured
- Skills in: finding AWS compliance info (AWS Artifact); geographic/industry compliance needs; securing resources (Amazon Inspector, AWS Security Hub, Amazon GuardDuty, AWS Shield); encryption options (in transit, at rest); governance/compliance services (CloudWatch monitoring, CloudTrail/Config auditing)
Task Statement 2.3: Identify AWS access management capabilities
- Knowledge of: IAM; protecting the root user; principle of least privilege; IAM Identity Center
- Skills in: access keys, password policies, credential storage (Secrets Manager, Systems Manager); authentication methods (MFA, IAM Identity Center, cross-account IAM roles); groups/users/custom/managed policies; root-user-only tasks; root user protection methods; identity types (e.g. federated)
Task Statement 2.4: Identify components and resources for security
- Knowledge of: AWS security capabilities; AWS security documentation
- Skills in: security features/services (AWS WAF, AWS Firewall Manager, AWS Shield, Amazon GuardDuty); third-party security products via AWS Marketplace; where security info is published (Knowledge Center, Security Center, Security Blog); AWS Trusted Advisor for identifying security issues
Cloud Technology and Services 34% ▾
Task Statement 3.1: Define methods of deploying and operating in the AWS Cloud
- Knowledge of: ways of provisioning/operating; ways to access AWS services; cloud deployment models
- Skills in: programmatic access (APIs, SDKs, CLI) vs. Management Console vs. infrastructure as code (IaC); one-time vs. repeatable processes; deployment models (cloud, hybrid, on-premises)
Task Statement 3.2: Define the AWS global infrastructure
- Knowledge of: Regions, Availability Zones, edge locations; high availability; multi-Region use; edge location benefits
- Skills in: relationships among Regions/AZs/edge locations; achieving HA via multiple AZs; AZs don't share single points of failure; when to use multiple Regions (disaster recovery, business continuity, low latency, data sovereignty)
Task Statement 3.3: Identify AWS compute services
- Knowledge of: AWS compute services
- Skills in: EC2 instance type families (compute optimized, storage optimized); container options (Amazon ECS, Amazon EKS); serverless compute (AWS Fargate, AWS Lambda); auto scaling for elasticity; purpose of load balancers
Task Statement 3.4: Identify AWS database services
- Knowledge of: AWS database services; database migration
- Skills in: EC2-hosted vs. managed databases; relational DBs (Amazon RDS, Amazon Aurora); NoSQL (Amazon DynamoDB); in-memory (Amazon ElastiCache); migration tools (AWS DMS, AWS SCT)
Task Statement 3.5: Identify AWS network services
- Knowledge of: AWS network services
- Skills in: VPC components (subnets, gateways); VPC security (network ACLs, security groups, Amazon Inspector); purpose of Amazon Route 53; connectivity options (AWS VPN, AWS Direct Connect)
Task Statement 3.6: Identify AWS storage services
- Knowledge of: AWS storage services
- Skills in: object storage use cases; S3 storage class differences; block storage (Amazon EBS, instance store); file services (Amazon EFS, Amazon FSx); cached file systems (AWS Storage Gateway); lifecycle policies; AWS Backup use cases
Task Statement 3.7: Identify AWS AI/ML and analytics services
- Knowledge of: AWS AI/ML services; AWS analytics services
- Skills in: AI/ML services and their tasks (Amazon SageMaker AI, Amazon Lex); data analytics services (Amazon Athena, Amazon Kinesis, AWS Glue, Amazon QuickSight)
Task Statement 3.8: Identify services from other in-scope categories
- Knowledge of: application integration (Amazon EventBridge, SNS, SQS); business applications (Amazon Connect, Amazon SES); customer enablement (AWS Support); developer tools (AWS CodeBuild, AWS CodePipeline, AWS X-Ray); end-user computing (Amazon AppStream 2.0, Amazon WorkSpaces, WorkSpaces Secure Browser); frontend/mobile (AWS Amplify); IoT (AWS IoT Core)
- Skills in: choosing services for messaging/alerts/notifications, business application needs, business support tiers, dev/deploy/troubleshoot tooling, presenting VM output to end users, building frontend/mobile apps, managing IoT devices
Billing, Pricing, and Support 12% ▾
Task Statement 4.1: Compare AWS pricing models
- Knowledge of: compute purchasing options (On-Demand, Reserved, Spot, Savings Plans, Dedicated Hosts/Instances, Capacity Reservations); storage options/tiers
- Skills in: when to use each purchasing option; Reserved Instance flexibility; Reserved Instance behavior in AWS Organizations; data transfer costs (cross-Region, same-Region); storage pricing by tier
Task Statement 4.2: Understand resources for billing, budget, and cost management
- Knowledge of: billing support/info; AWS service pricing info; AWS Organizations; cost allocation tags
- Skills in: AWS Budgets and Cost Explorer; AWS Pricing Calculator; Organizations consolidated billing/cost allocation; cost allocation tags and the Cost and Usage Report
Task Statement 4.3: Identify AWS technical resources and Support options
- Knowledge of: official AWS documentation/resources; AWS Support plans; AWS Partner Network (ISVs, system integrators); AWS Support Center
- Skills in: locating whitepapers/blogs/docs; technical resources (AWS Prescriptive Guidance, Knowledge Center, re:Post); Support plan tiers (Developer, Business, Enterprise On-Ramp, Enterprise); AWS Trusted Advisor / Health Dashboard / Health API for cost optimization and monitoring; AWS Trust and Safety team's role; AWS Partner benefits; AWS Marketplace's role; AWS Professional Services / solutions architects
Key concepts
In-Scope AWS Services by Category ▾
Applied Use Cases (from AWS's own service/pricing pages — for scenario grounding) ▾
S3 storage classes, by access pattern
- S3 Standard: general-purpose, frequently accessed data, needs low latency.
- S3 Intelligent-Tiering: workload has unknown or changing access patterns; AWS automatically moves data between tiers to manage cost.
- S3 Express One Zone: most frequently accessed data, needs single-digit-millisecond latency (highest performance tier).
- S3 Standard-IA: infrequently accessed but needs rapid access when it is needed — e.g. backups, disaster recovery.
- S3 One Zone-IA: infrequently accessed, easily re-creatable data; cheaper than Standard-IA by storing in a single AZ only.
- S3 Glacier Instant Retrieval: archive data that still needs millisecond, immediate access.
- S3 Glacier Flexible Retrieval: rarely accessed backup/archive data; retrieval ranges from minutes to hours.
- S3 Glacier Deep Archive: long-term archival/compliance data accessed maybe once or twice a year; cheapest, slowest tier.
EC2 purchasing options, by workload pattern
- On-Demand: pay by the hour/second, no upfront commitment; best for unpredictable or short-term workloads.
- Savings Plans: commit to steady usage in exchange for up to ~72% off On-Demand pricing; best for predictable, steady-state workloads.
- Reserved Instances: similar commitment-based discount model to Savings Plans, tied to instance attributes.
- Spot Instances: bid for spare AWS capacity at up to ~90% off On-Demand; can be reclaimed by AWS with short notice, so only for fault-tolerant, interruption-tolerant workloads (e.g. batch processing, stateless web tiers, some CI jobs) — never for workloads that can't tolerate sudden termination.
- On-Demand Capacity Reservations: reserve capacity in a specific AZ without a long-term commitment; used for business-critical events, HA requirements, disaster recovery readiness.
- Dedicated Hosts: a physical server dedicated to one customer, supporting bring-your-own licensing tied to hardware (e.g. per-socket/per-core licenses) and workloads with strict compliance/isolation requirements.
AWS database services, by category and workload fit
- Relational (Amazon RDS, Amazon Aurora): traditional structured-data apps — ERP, CRM, ecommerce order systems — where transactions and joins matter.
- Key-value (Amazon DynamoDB): high-traffic web/mobile apps, ecommerce carts, gaming leaderboards needing single-digit-millisecond latency at massive scale.
- In-memory (Amazon ElastiCache): caching layer in front of a database, session storage, leaderboards — anything needing sub-millisecond real-time reads.
- Document (Amazon DocumentDB): semi-structured JSON-like data — content catalogs, user profiles.
- Graph (Amazon Neptune): highly connected data needing relationship traversal — fraud detection, social networks, recommendation engines.
Shared responsibility model, concretely
- AWS is responsible for security OF the cloud: physical hardware, host infrastructure, networking, and facilities — patching and configuring the infrastructure layer itself.
- The customer is responsible for security IN the cloud, and exactly what that means shifts by service:
Official resources
Practice by SuperML.org is an independent study resource and is not affiliated with, endorsed by, or officially connected to Amazon Web Services. Questions are AI-generated for practice purposes only.