← Amazon Web Services

AWS Certified Cloud Practitioner (CLF-C02)

Foundational, role-agnostic exam covering AWS Cloud concepts, security, core services, and billing.

Passing score
70%
Per attempt
15 questions
Question pool
67
Suggested time
90 min

Content last updated Aug 14, 2026

About this exam

The exam validates overall knowledge of the AWS Cloud, independent of a specific job role: explaining the value of the AWS Cloud, the shared responsibility model, the Well-Architected Framework, security best practices, AWS Cloud costs/economics/billing, and identifying core AWS services (compute, network, database, storage) for common use cases.

Out of scope for the target candidate: coding, designing cloud architecture, troubleshooting, implementation, load/performance testing.

Question format: multiple choice (1 correct + 3 distractors) and multiple response (2+ correct out of 5+ options). 50 scored questions, scaled score 100–1000, passing score 700.

Exam details

Exam code
CLF-C02
Exam fee
$100 USD
Item format
65 questions — multiple choice or multiple response
Prerequisites
None required — up to 6 months of general AWS Cloud exposure is recommended
Exam structure
65 questions
Delivery method
Pearson VUE testing center or online proctored exam
Target audience
Individuals in technical or non-technical roles who need an overall understanding of the AWS Cloud, including line-of-business roles such as sales, marketing, or project management
Result reporting
Pass/fail
Certification validity
3 years

Content domains

Expand a domain for what it covers and what you'll need to know.

Cloud Concepts 24%

Task Statement 1.1: Define the benefits of the AWS Cloud

  • Knowledge of: value proposition of the AWS Cloud
  • Skills in: benefits of global infrastructure (speed of deployment, global reach); advantages of high availability, elasticity, and agility

Task Statement 1.2: Identify design principles of the AWS Cloud

  • Knowledge of: AWS Well-Architected Framework
  • Skills in: the six pillars (operational excellence, security, reliability, performance efficiency, cost optimization, sustainability); differences between the pillars

Task Statement 1.3: Understand the benefits of and strategies for migration to the AWS Cloud

  • Knowledge of: cloud adoption strategies; resources supporting the migration journey
  • Skills in: components of the AWS Cloud Adoption Framework (AWS CAF) — reduced business risk, improved ESG performance, increased revenue, increased operational efficiency; migration strategies (e.g. database replication)

Task Statement 1.4: Understand concepts of cloud economics

  • Knowledge of: aspects of cloud economics; cost savings of moving to the cloud
  • Skills in: fixed vs. variable costs; on-premises environment costs; licensing strategies (BYOL vs. included licenses); rightsizing; benefits of automation; economies of scale
Security and Compliance 30%

Task Statement 2.1: Understand the AWS shared responsibility model

  • Knowledge of: AWS shared responsibility model
  • Skills in: customer responsibilities; AWS responsibilities; shared responsibilities; how responsibilities shift by service (e.g. RDS, Lambda, EC2)

Task Statement 2.2: Understand AWS Cloud security, governance, and compliance concepts

  • Knowledge of: compliance/governance concepts; benefits of cloud security (e.g. encryption); where security logs are captured
  • Skills in: finding AWS compliance info (AWS Artifact); geographic/industry compliance needs; securing resources (Amazon Inspector, AWS Security Hub, Amazon GuardDuty, AWS Shield); encryption options (in transit, at rest); governance/compliance services (CloudWatch monitoring, CloudTrail/Config auditing)

Task Statement 2.3: Identify AWS access management capabilities

  • Knowledge of: IAM; protecting the root user; principle of least privilege; IAM Identity Center
  • Skills in: access keys, password policies, credential storage (Secrets Manager, Systems Manager); authentication methods (MFA, IAM Identity Center, cross-account IAM roles); groups/users/custom/managed policies; root-user-only tasks; root user protection methods; identity types (e.g. federated)

Task Statement 2.4: Identify components and resources for security

  • Knowledge of: AWS security capabilities; AWS security documentation
  • Skills in: security features/services (AWS WAF, AWS Firewall Manager, AWS Shield, Amazon GuardDuty); third-party security products via AWS Marketplace; where security info is published (Knowledge Center, Security Center, Security Blog); AWS Trusted Advisor for identifying security issues
Cloud Technology and Services 34%

Task Statement 3.1: Define methods of deploying and operating in the AWS Cloud

  • Knowledge of: ways of provisioning/operating; ways to access AWS services; cloud deployment models
  • Skills in: programmatic access (APIs, SDKs, CLI) vs. Management Console vs. infrastructure as code (IaC); one-time vs. repeatable processes; deployment models (cloud, hybrid, on-premises)

Task Statement 3.2: Define the AWS global infrastructure

  • Knowledge of: Regions, Availability Zones, edge locations; high availability; multi-Region use; edge location benefits
  • Skills in: relationships among Regions/AZs/edge locations; achieving HA via multiple AZs; AZs don't share single points of failure; when to use multiple Regions (disaster recovery, business continuity, low latency, data sovereignty)

Task Statement 3.3: Identify AWS compute services

  • Knowledge of: AWS compute services
  • Skills in: EC2 instance type families (compute optimized, storage optimized); container options (Amazon ECS, Amazon EKS); serverless compute (AWS Fargate, AWS Lambda); auto scaling for elasticity; purpose of load balancers

Task Statement 3.4: Identify AWS database services

  • Knowledge of: AWS database services; database migration
  • Skills in: EC2-hosted vs. managed databases; relational DBs (Amazon RDS, Amazon Aurora); NoSQL (Amazon DynamoDB); in-memory (Amazon ElastiCache); migration tools (AWS DMS, AWS SCT)

Task Statement 3.5: Identify AWS network services

  • Knowledge of: AWS network services
  • Skills in: VPC components (subnets, gateways); VPC security (network ACLs, security groups, Amazon Inspector); purpose of Amazon Route 53; connectivity options (AWS VPN, AWS Direct Connect)

Task Statement 3.6: Identify AWS storage services

  • Knowledge of: AWS storage services
  • Skills in: object storage use cases; S3 storage class differences; block storage (Amazon EBS, instance store); file services (Amazon EFS, Amazon FSx); cached file systems (AWS Storage Gateway); lifecycle policies; AWS Backup use cases

Task Statement 3.7: Identify AWS AI/ML and analytics services

  • Knowledge of: AWS AI/ML services; AWS analytics services
  • Skills in: AI/ML services and their tasks (Amazon SageMaker AI, Amazon Lex); data analytics services (Amazon Athena, Amazon Kinesis, AWS Glue, Amazon QuickSight)

Task Statement 3.8: Identify services from other in-scope categories

  • Knowledge of: application integration (Amazon EventBridge, SNS, SQS); business applications (Amazon Connect, Amazon SES); customer enablement (AWS Support); developer tools (AWS CodeBuild, AWS CodePipeline, AWS X-Ray); end-user computing (Amazon AppStream 2.0, Amazon WorkSpaces, WorkSpaces Secure Browser); frontend/mobile (AWS Amplify); IoT (AWS IoT Core)
  • Skills in: choosing services for messaging/alerts/notifications, business application needs, business support tiers, dev/deploy/troubleshoot tooling, presenting VM output to end users, building frontend/mobile apps, managing IoT devices
Billing, Pricing, and Support 12%

Task Statement 4.1: Compare AWS pricing models

  • Knowledge of: compute purchasing options (On-Demand, Reserved, Spot, Savings Plans, Dedicated Hosts/Instances, Capacity Reservations); storage options/tiers
  • Skills in: when to use each purchasing option; Reserved Instance flexibility; Reserved Instance behavior in AWS Organizations; data transfer costs (cross-Region, same-Region); storage pricing by tier

Task Statement 4.2: Understand resources for billing, budget, and cost management

  • Knowledge of: billing support/info; AWS service pricing info; AWS Organizations; cost allocation tags
  • Skills in: AWS Budgets and Cost Explorer; AWS Pricing Calculator; Organizations consolidated billing/cost allocation; cost allocation tags and the Cost and Usage Report

Task Statement 4.3: Identify AWS technical resources and Support options

  • Knowledge of: official AWS documentation/resources; AWS Support plans; AWS Partner Network (ISVs, system integrators); AWS Support Center
  • Skills in: locating whitepapers/blogs/docs; technical resources (AWS Prescriptive Guidance, Knowledge Center, re:Post); Support plan tiers (Developer, Business, Enterprise On-Ramp, Enterprise); AWS Trusted Advisor / Health Dashboard / Health API for cost optimization and monitoring; AWS Trust and Safety team's role; AWS Partner benefits; AWS Marketplace's role; AWS Professional Services / solutions architects

Key concepts

In-Scope AWS Services by Category
Applied Use Cases (from AWS's own service/pricing pages — for scenario grounding)

S3 storage classes, by access pattern

  • S3 Standard: general-purpose, frequently accessed data, needs low latency.
  • S3 Intelligent-Tiering: workload has unknown or changing access patterns; AWS automatically moves data between tiers to manage cost.
  • S3 Express One Zone: most frequently accessed data, needs single-digit-millisecond latency (highest performance tier).
  • S3 Standard-IA: infrequently accessed but needs rapid access when it is needed — e.g. backups, disaster recovery.
  • S3 One Zone-IA: infrequently accessed, easily re-creatable data; cheaper than Standard-IA by storing in a single AZ only.
  • S3 Glacier Instant Retrieval: archive data that still needs millisecond, immediate access.
  • S3 Glacier Flexible Retrieval: rarely accessed backup/archive data; retrieval ranges from minutes to hours.
  • S3 Glacier Deep Archive: long-term archival/compliance data accessed maybe once or twice a year; cheapest, slowest tier.

EC2 purchasing options, by workload pattern

  • On-Demand: pay by the hour/second, no upfront commitment; best for unpredictable or short-term workloads.
  • Savings Plans: commit to steady usage in exchange for up to ~72% off On-Demand pricing; best for predictable, steady-state workloads.
  • Reserved Instances: similar commitment-based discount model to Savings Plans, tied to instance attributes.
  • Spot Instances: bid for spare AWS capacity at up to ~90% off On-Demand; can be reclaimed by AWS with short notice, so only for fault-tolerant, interruption-tolerant workloads (e.g. batch processing, stateless web tiers, some CI jobs) — never for workloads that can't tolerate sudden termination.
  • On-Demand Capacity Reservations: reserve capacity in a specific AZ without a long-term commitment; used for business-critical events, HA requirements, disaster recovery readiness.
  • Dedicated Hosts: a physical server dedicated to one customer, supporting bring-your-own licensing tied to hardware (e.g. per-socket/per-core licenses) and workloads with strict compliance/isolation requirements.

AWS database services, by category and workload fit

  • Relational (Amazon RDS, Amazon Aurora): traditional structured-data apps — ERP, CRM, ecommerce order systems — where transactions and joins matter.
  • Key-value (Amazon DynamoDB): high-traffic web/mobile apps, ecommerce carts, gaming leaderboards needing single-digit-millisecond latency at massive scale.
  • In-memory (Amazon ElastiCache): caching layer in front of a database, session storage, leaderboards — anything needing sub-millisecond real-time reads.
  • Document (Amazon DocumentDB): semi-structured JSON-like data — content catalogs, user profiles.
  • Graph (Amazon Neptune): highly connected data needing relationship traversal — fraud detection, social networks, recommendation engines.

Shared responsibility model, concretely

  • AWS is responsible for security OF the cloud: physical hardware, host infrastructure, networking, and facilities — patching and configuring the infrastructure layer itself.
  • The customer is responsible for security IN the cloud, and exactly what that means shifts by service:
Start Practice

Practice by SuperML.org is an independent study resource and is not affiliated with, endorsed by, or officially connected to Amazon Web Services. Questions are AI-generated for practice purposes only.