AWS Certified Cloud Practitioner (CLF-C02) — Questions and Answers
Question 1: A company's DynamoDB table experiences throttling during traffic spikes. Which feature should they enable to handle unpredictable workloads automatically?
- DynamoDB TTL
- DynamoDB Streams
- DynamoDB Global Tables
- DynamoDB On-Demand Mode (Correct answer)
Correct answer: DynamoDB On-Demand Mode
DynamoDB On-Demand Mode automatically scales read and write capacity to handle any traffic volume without capacity planning.
Question 2: Which AWS networking component acts as a virtual firewall controlling inbound and outbound traffic at the instance level?
- Route Table
- Internet Gateway
- Network ACL
- Security Group (Correct answer)
Correct answer: Security Group
Security Groups are stateful virtual firewalls applied to EC2 instances that control inbound and outbound traffic at the instance level.
Question 3: Which AWS service provides hardware security modules (HSMs) in the cloud to generate and manage your own encryption keys with exclusive single-tenant access?
- AWS Certificate Manager
- AWS Key Management Service (KMS)
- AWS Secrets Manager
- AWS CloudHSM (Correct answer)
Correct answer: AWS CloudHSM
AWS CloudHSM provides dedicated, single-tenant HSM appliances in the cloud, giving customers exclusive control over their cryptographic keys.
Question 4: What is the primary purpose of an AWS Availability Zone (AZ)?
- To serve content to users with low latency globally
- To reduce data transfer costs between services
- To separate development and production workloads
- To provide fault isolation so a failure in one AZ does not affect others (Correct answer)
Correct answer: To provide fault isolation so a failure in one AZ does not affect others
Availability Zones are physically separate data centers within a Region, designed so failures (power, cooling, network) are isolated and do not cascade.
Question 5: How are AWS Lambda function costs primarily calculated?
- By the amount of memory allocated only
- By the number of concurrent executions per hour
- By the number of functions deployed
- By the number of requests and duration of execution (Correct answer)
Correct answer: By the number of requests and duration of execution
Lambda charges are based on the total number of requests and the duration (in GB-seconds) each function runs, with a generous free tier included.
Question 6: A developer needs to allow EC2 instances in a private subnet to download software updates from the internet. What combination of resources is required?
- NAT Gateway in a public subnet and a route in the private subnet's route table (Correct answer)
- AWS Direct Connect and a virtual private gateway
- Internet Gateway only
- VPC Peering and a security group
Correct answer: NAT Gateway in a public subnet and a route in the private subnet's route table
A NAT Gateway placed in a public subnet, combined with a route in the private subnet's route table pointing to the NAT Gateway, allows outbound internet access for private instances.
Question 7: What is the MOST effective way for new CLF-C02 professionals to build competency in their field?
- Learning entirely through trial and error
- Studying certification materials exclusively
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Focusing solely on the most advanced topics
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 8: In AWS Certified Cloud Practitioner, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To satisfy insurance requirements only
- To reduce daily workload
- To evaluate employee performance reviews
- To ensure personnel can respond effectively in emergencies (Correct answer)
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies. Practice builds muscle memory, identifies gaps in emergency procedures, and improves overall response times.
Question 9: Which AWS Well-Architected Framework pillar focuses on protecting information, systems, and assets while delivering business value?
- Cost Optimization
- Reliability
- Performance Efficiency
- Security (Correct answer)
Correct answer: Security
The Security pillar covers protecting data, systems, and assets through risk assessments and mitigation strategies.
Question 10: What is the value of continuing education in billing and pricing for CLF-C02 professionals?
- It keeps professionals current with evolving standards and practices (Correct answer)
- It is primarily a social activity
- It replaces workplace experience
- It is only needed for recertification
Correct answer: It keeps professionals current with evolving standards and practices
Continuing education ensures professionals stay current with the latest developments, standards, and best practices in their field.
Question 11: A company runs a fleet of EC2 instances and wants to automatically replace any instance that fails a health check. Which feature provides this?
- AWS Shield
- EC2 Auto Scaling (Correct answer)
- Amazon CloudWatch Alarms
- Elastic Load Balancing
Correct answer: EC2 Auto Scaling
EC2 Auto Scaling monitors instance health and automatically terminates and replaces unhealthy instances to maintain the desired capacity.
Question 12: A developer wants to serve static website content globally with low latency. Which combination of services is most appropriate?
- EFS + Route 53
- EBS + Elastic Load Balancing
- S3 + CloudFront (Correct answer)
- EC2 + RDS
Correct answer: S3 + CloudFront
S3 hosts static website files and CloudFront distributes them via a global CDN, minimizing latency for worldwide users.
Question 13: What are IAM access keys used for?
- Programmatic access to AWS services via CLI or SDK (Correct answer)
- Logging into the AWS Management Console
- Encrypting data stored in Amazon S3
- Enabling MFA for IAM users
Correct answer: Programmatic access to AWS services via CLI or SDK
IAM access keys (consisting of an access key ID and secret access key) are used for programmatic access to AWS through the CLI, SDK, or direct API calls.
Question 14: What is a key benefit of using a microservices architecture compared to a monolithic architecture in the cloud?
- Independent scaling and deployment of individual services (Correct answer)
- Easier initial development
- Lower network latency between components
- Reduced number of API calls
Correct answer: Independent scaling and deployment of individual services
Microservices allow each service to be scaled, deployed, and updated independently, improving agility and resource efficiency.
Question 15: What is the purpose of an Auto Scaling group in AWS?
- To automatically adjust capacity to maintain performance (Correct answer)
- To back up user data
- To scale data manually
- To manage billing
Correct answer: To automatically adjust capacity to maintain performance
An Auto Scaling group in AWS is designed to automatically adjust the number of EC2 instances in your application to maintain performance and availability. It dynamically adds or removes instances based on predefined policies, ensuring your application has sufficient capacity to handle demand without over-provisioning.
Question 16: A company uses AWS Organizations with multiple accounts. Under the Shared Responsibility Model, who manages the AWS account root user credentials?
- AWS manages root credentials for security purposes
- The customer is responsible for securing and restricting root user access (Correct answer)
- AWS Support can manage root credentials on behalf of customers
- Root credentials are shared between AWS and the customer
Correct answer: The customer is responsible for securing and restricting root user access
Customers are fully responsible for securing root user credentials, including enabling MFA and avoiding routine use of the root account.
Question 17: What AWS service provides content delivery with low latency?
- AWS Elastic Beanstalk
- Amazon S3
- Amazon Route 53
- Amazon CloudFront (Correct answer)
Correct answer: Amazon CloudFront
Amazon CloudFront is a Content Delivery Network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency. It achieves this by caching content at edge locations closer to users, reducing the distance data travels. This significantly improves performance and user experience for web applications and content delivery.
Question 18: Which of the following is a security best practice for the AWS root account?
- Create access keys for the root account for programmatic access
- Share root account credentials with trusted team members only
- Use the root account for daily administrative tasks to save time
- Enable MFA and avoid using the root account for routine tasks (Correct answer)
Correct answer: Enable MFA and avoid using the root account for routine tasks
AWS best practice is to enable MFA on the root account and use it only for tasks that absolutely require root access, performing all other work with IAM users or roles.
Question 19: Which AWS service enables you to estimate the cost of a new AWS architecture before you build it?
- AWS Trusted Advisor
- AWS Budgets
- AWS Cost Explorer
- AWS Pricing Calculator (Correct answer)
Correct answer: AWS Pricing Calculator
AWS Pricing Calculator lets you model your architecture and generate an estimated monthly cost before provisioning any resources.
Question 20: Which AWS service provides a global content delivery network (CDN) that caches content at edge locations worldwide?
- AWS Direct Connect
- AWS Global Accelerator
- Amazon Route 53
- Amazon CloudFront (Correct answer)
Correct answer: Amazon CloudFront
Amazon CloudFront is a CDN service that delivers content through a worldwide network of edge locations, reducing latency for end users.
Question 21: What is the primary use case for Amazon Redshift?
- Storing document data for web apps
- Running transactional OLTP workloads
- Caching frequently accessed data
- Performing large-scale data analytics and business intelligence (Correct answer)
Correct answer: Performing large-scale data analytics and business intelligence
Amazon Redshift is a petabyte-scale data warehouse designed for OLAP queries and business intelligence workloads.
Question 22: Which document typically outlines the compliance requirements for CLF-C02 professionals?
- Marketing brochure
- Annual financial report
- Standards of practice and code of conduct (Correct answer)
- Employee handbook
Correct answer: Standards of practice and code of conduct
Standards of practice and codes of conduct define the professional and ethical requirements practitioners must follow.
Question 23: Which professional attribute is most valued in compute services within the CLF-C02 field?
- Working in isolation
- Prioritizing personal convenience
- Accountability and commitment to standards (Correct answer)
- Avoiding challenging situations
Correct answer: Accountability and commitment to standards
Accountability and commitment to professional standards build trust and ensure consistent, high-quality practice.
Question 24: Under the AWS Shared Responsibility Model, who is responsible for patching the underlying hypervisor in an EC2 environment?
- A third-party vendor
- AWS (Correct answer)
- Both AWS and the customer share this equally
- The customer
Correct answer: AWS
AWS is responsible for patching the hypervisor and underlying infrastructure (security 'of' the cloud), while customers patch the guest OS and applications.
Question 25: What does the AWS penetration testing policy require customers to do before conducting penetration tests on their AWS environment?
- Submit a formal written request to AWS 30 days in advance
- No prior approval is required for tests on permitted services (Correct answer)
- Notify all other AWS customers in the same region
- Purchase AWS Shield Advanced
Correct answer: No prior approval is required for tests on permitted services
AWS no longer requires prior approval for penetration testing on a defined list of permitted services owned by the customer.
Question 26: Under the Shared Responsibility Model, who is responsible for ensuring high availability of a web application deployed on AWS?
- The customer is responsible for designing the application for high availability using AWS services (Correct answer)
- AWS automatically makes all deployed applications highly available
- High availability is jointly designed by AWS and the customer together
- AWS guarantees application-level availability as part of its SLA
Correct answer: The customer is responsible for designing the application for high availability using AWS services
While AWS provides highly available infrastructure, customers must architect their applications to use multiple AZs and fault-tolerant design patterns.
Question 27: An application needs to process thousands of jobs simultaneously. The jobs are fault-tolerant and can restart if interrupted. Which option is most cost-effective?
- Dedicated Hosts
- Spot Instances (Correct answer)
- On-Demand Instances
- Reserved Instances
Correct answer: Spot Instances
Spot Instances can be up to 90% cheaper than On-Demand and are ideal for fault-tolerant, interruptible batch workloads.
Question 28: Which of the following is a security best practice in AWS?
- Use least privilege principles (Correct answer)
- Grant access to all services by default
- Allow full admin access to everyone
- Avoid using IAM roles
Correct answer: Use least privilege principles
Using the least privilege principle is a fundamental security best practice in AWS. This means granting users, roles, or services only the minimum permissions necessary to perform their required tasks, and no more. By limiting access, you reduce the potential impact of a compromised credential or malicious activity, significantly enhancing the overall security posture of your AWS environment.
Question 29: Which practice improves the security of database services implementations?
- Disabling all logging
- Input validation and principle of least privilege (Correct answer)
- Granting maximum permissions to all users
- Using default credentials
Correct answer: Input validation and principle of least privilege
Input validation prevents injection attacks while the principle of least privilege limits the damage potential of any compromised component.
Question 30: What role does collaboration play in storage services for CLF-C02 professionals?
- It reduces individual accountability
- It slows down work unnecessarily
- It enhances outcomes through diverse perspectives and shared expertise (Correct answer)
- It is only needed in emergencies
Correct answer: It enhances outcomes through diverse perspectives and shared expertise
Collaboration leverages diverse perspectives and combined expertise to achieve better outcomes than any individual could alone.
Question 31: What type of AWS Savings Plan specifically targets EC2 usage within a single instance family in a specific region?
- Compute Savings Plans
- SageMaker Savings Plans
- RDS Savings Plans
- EC2 Instance Savings Plans (Correct answer)
Correct answer: EC2 Instance Savings Plans
EC2 Instance Savings Plans offer a higher discount than Compute Savings Plans in exchange for committing to a specific instance family and AWS region.
Question 32: Which AWS service provides a managed threat detection capability that analyzes CloudTrail, VPC Flow Logs, and DNS logs to identify malicious activity?
- Amazon GuardDuty (Correct answer)
- AWS Shield
- AWS WAF
- Amazon Inspector
Correct answer: Amazon GuardDuty
Amazon GuardDuty is a managed threat detection service that continuously analyzes CloudTrail, VPC Flow Logs, and DNS logs to identify threats.
Question 33: Which of the following AWS Support plans provides access to a Technical Account Manager (TAM)?
- Developer
- Enterprise (Correct answer)
- Basic
- Business
Correct answer: Enterprise
The Enterprise Support plan is the only plan that includes a dedicated Technical Account Manager (TAM) for proactive guidance.
Question 34: What is the maximum execution duration for a single AWS Lambda function invocation?
- 5 minutes
- 10 minutes
- 60 minutes
- 15 minutes (Correct answer)
Correct answer: 15 minutes
AWS Lambda functions can run for a maximum of 15 minutes (900 seconds) per invocation.
Question 35: A company wants to protect their web application from common exploits like SQL injection and cross-site scripting. Which AWS service should they use?
- Amazon VPC Security Groups
- AWS Shield Standard
- AWS Network Firewall
- AWS WAF (Correct answer)
Correct answer: AWS WAF
AWS WAF (Web Application Firewall) filters HTTP/HTTPS traffic and protects against common web exploits like SQL injection and XSS.
Question 36: Under the Shared Responsibility Model, who is responsible for configuring Multi-Factor Authentication (MFA) for AWS IAM users?
- AWS Support configures MFA during account setup
- MFA is managed by AWS Security Hub automatically
- The customer must configure and enforce MFA for their IAM users (Correct answer)
- AWS enables MFA automatically for all IAM users
Correct answer: The customer must configure and enforce MFA for their IAM users
Enabling and enforcing MFA for IAM users is a customer responsibility under the identity and access management category.
Question 37: Under the Shared Responsibility Model, who is responsible for the availability of the AWS global infrastructure?
- AWS, by maintaining its global network and data centers (Correct answer)
- Third-party providers contracted by AWS
- Both share equal responsibility for global availability
- The customer, by designing for multi-region redundancy
Correct answer: AWS, by maintaining its global network and data centers
AWS is responsible for the availability and reliability of its global infrastructure, including regions, Availability Zones, and edge locations.
Question 38: A company uses AWS Support and wants to get guidance on migrating a legacy application to AWS. Which support feature provides this architectural guidance?
- AWS Well-Architected Tool
- AWS Trusted Advisor
- AWS Personal Health Dashboard
- Consultative reviews with a TAM (Correct answer)
Correct answer: Consultative reviews with a TAM
A Technical Account Manager (TAM) available in Enterprise Support provides consultative architectural reviews and migration guidance tailored to your specific workloads.
Question 39: Which AWS service lets you run code in response to events such as an S3 object upload without provisioning any servers?
- AWS Elastic Beanstalk
- Amazon EC2 Auto Scaling
- Amazon ECS
- AWS Lambda (Correct answer)
Correct answer: AWS Lambda
AWS Lambda executes code triggered by events and automatically manages all the underlying compute infrastructure.
Question 40: A company wants to use AWS services but needs connectivity with guaranteed bandwidth and lower latency than a VPN over the internet. Which service should they choose?
- Amazon Route 53
- AWS VPN
- AWS Direct Connect (Correct answer)
- Amazon CloudFront
Correct answer: AWS Direct Connect
AWS Direct Connect provides a dedicated private network connection between your premises and AWS, offering consistent performance and potentially lower data transfer costs.
Question 41: Which professional attribute is most valued in shared responsibility within the CLF-C02 field?
- Accountability and commitment to standards (Correct answer)
- Working in isolation
- Prioritizing personal convenience
- Avoiding challenging situations
Correct answer: Accountability and commitment to standards
Accountability and commitment to professional standards build trust and ensure consistent, high-quality practice.
Question 42: Which AWS service provides a global DNS service that can route users to the nearest healthy endpoint using latency-based routing?
- Amazon CloudFront
- AWS Global Accelerator
- Elastic Load Balancing
- Amazon Route 53 (Correct answer)
Correct answer: Amazon Route 53
Amazon Route 53 is AWS's highly available DNS service that supports routing policies including latency-based routing to direct users to the lowest-latency endpoint.
Question 43: Which AWS pricing model offers the largest discount (up to 90%) compared to On-Demand pricing in exchange for a one- or three-year commitment?
- Dedicated Hosts
- Savings Plans
- Spot Instances (Correct answer)
- Reserved Instances
Correct answer: Spot Instances
Spot Instances use spare AWS capacity and can be up to 90% cheaper than On-Demand, though AWS can reclaim them with a 2-minute warning.
Question 44: Which AWS service enables you to provision a logically isolated section of the AWS Cloud where you can launch resources in a virtual network you define?
- AWS Direct Connect
- AWS Transit Gateway
- AWS PrivateLink
- Amazon VPC (Correct answer)
Correct answer: Amazon VPC
Amazon VPC (Virtual Private Cloud) lets you define your own isolated virtual network with custom IP ranges, subnets, route tables, and gateways.
Question 45: In AWS Certified Cloud Practitioner practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Document it for the next safety audit
- Wait for a supervisor to notice the issue
- Continue working and report at end of shift
- Immediately secure the area and report the hazard (Correct answer)
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels. Delaying action increases the risk of incidents.
Question 46: Which EC2 pricing model provides the largest discount in exchange for a firm 1- or 3-year commitment with full upfront payment?
- Reserved Instances (Correct answer)
- Savings Plans
- Spot Instances
- On-Demand
Correct answer: Reserved Instances
Reserved Instances with an all-upfront, 3-year term offer the steepest discount (up to ~72%) compared to On-Demand pricing.
Question 47: Which pricing model allows you to save money on AWS services based on long-term usage?
- Free tier
- Spot Instances
- Pay-as-you-go
- Reserved Instances (Correct answer)
Correct answer: Reserved Instances
Reserved Instances is an AWS pricing model that allows customers to save money on services by committing to a specific usage level for a 1-year or 3-year term. By reserving compute capacity in advance, users receive a significant discount compared to on-demand pricing. This model is ideal for applications with predictable and steady workloads, offering substantial cost optimization for long-term usage.
Question 48: A company needs to send transactional emails (order confirmations, password resets) at scale from their AWS-hosted application. Which service should they use?
- Amazon SQS
- Amazon Pinpoint
- Amazon SNS
- Amazon SES (Correct answer)
Correct answer: Amazon SES
Amazon SES (Simple Email Service) is designed for sending large volumes of transactional or marketing emails from applications.
Question 49: Which AWS service performs automated security assessments of EC2 instances and container workloads to identify software vulnerabilities and unintended network exposure?
- Amazon Macie
- Amazon Inspector (Correct answer)
- AWS GuardDuty
- AWS Trusted Advisor
Correct answer: Amazon Inspector
Amazon Inspector automatically assesses EC2 instances and ECR container images for software vulnerabilities (CVEs) and unintended network accessibility.
Question 50: Which capability allows an IAM role in one AWS account to be assumed by a user or service in a different AWS account?
- VPC Peering
- Cross-account role assumption (Correct answer)
- AWS Direct Connect
- IAM User Federation
Correct answer: Cross-account role assumption
Cross-account role assumption allows an entity in one AWS account to assume an IAM role that belongs to a different account, enabling controlled cross-account access.
Question 51: In CLF-C02 practice, what is the best approach to quality improvement in compute services?
- Use data-driven methods with measurable outcomes (Correct answer)
- Wait for problems to occur before acting
- Copy what other organizations do without analysis
- Make changes without measuring results
Correct answer: Use data-driven methods with measurable outcomes
Data-driven quality improvement with measurable outcomes ensures that changes actually produce the intended improvements and can be verified.
Question 52: Which EC2 pricing model provides the highest potential discount but can be interrupted by AWS with a two-minute warning?
- Dedicated Hosts
- Reserved Instances
- Savings Plans
- Spot Instances (Correct answer)
Correct answer: Spot Instances
Spot Instances can provide up to 90% discount compared to On-Demand pricing but AWS can reclaim them when capacity is needed, with a two-minute interruption notice.
Question 53: In CLF-C02 practice, what is the best approach to quality improvement in shared responsibility?
- Copy what other organizations do without analysis
- Make changes without measuring results
- Wait for problems to occur before acting
- Use data-driven methods with measurable outcomes (Correct answer)
Correct answer: Use data-driven methods with measurable outcomes
Data-driven quality improvement with measurable outcomes ensures that changes actually produce the intended improvements and can be verified.
Question 54: A company wants to migrate to AWS but is concerned about compliance with data residency laws that require data to stay within a specific country. How does AWS address this?
- AWS automatically replicates data globally for durability
- Customers choose which AWS Region to deploy in, keeping data within that geography (Correct answer)
- Data residency is managed through AWS Shield
- AWS guarantees data never leaves the country where the account was created
Correct answer: Customers choose which AWS Region to deploy in, keeping data within that geography
AWS Regions are isolated geographic areas, and data you store in a Region does not leave that Region unless you explicitly move it, supporting data residency compliance.
Question 55: A startup uses Amazon EKS (Elastic Kubernetes Service). Under the Shared Responsibility Model, who is responsible for securing the Kubernetes control plane?
- AWS manages the EKS control plane; customers manage their worker nodes and workloads (Correct answer)
- The Kubernetes community is responsible for control plane security on EKS
- Control plane security is shared 50/50 between AWS and the customer
- The customer manages the control plane entirely
Correct answer: AWS manages the EKS control plane; customers manage their worker nodes and workloads
AWS manages and secures the EKS control plane, while customers are responsible for their worker nodes, pod security, and application workloads.
Question 56: Which tool provides a visual interface to explore and analyze AWS costs and usage over time?
- AWS Billing Dashboard
- AWS Budgets
- AWS Pricing Calculator
- AWS Cost Explorer (Correct answer)
Correct answer: AWS Cost Explorer
AWS Cost Explorer provides interactive charts and filtering to visualize spending patterns, identify trends, and forecast future costs.
Question 57: Which AWS service is used to store and retrieve any amount of data at any time?
- AWS Lambda
- Amazon S3 (Correct answer)
- Amazon EC2
- Amazon RDS
Correct answer: Amazon S3
Amazon S3 (Simple Storage Service) is the AWS service specifically designed for storing and retrieving any amount of data from anywhere on the web. It is an object storage service known for its scalability, data availability, security, and performance. S3 is commonly used for backups, data archiving, content distribution, and hosting static websites, making it a versatile solution for various data storage needs.
Question 58: Which approach best demonstrates mastery of compute services in CLF-C02 practice?
- Relying entirely on technology
- Following procedures without understanding
- Avoiding complex scenarios
- Applying principles to novel situations with sound judgment (Correct answer)
Correct answer: Applying principles to novel situations with sound judgment
True mastery involves understanding underlying principles well enough to apply them to new and unfamiliar situations with professional judgment.
Question 59: What is the difference between an AWS Site-to-Site VPN and AWS Direct Connect?
- Site-to-Site VPN creates an encrypted tunnel over the internet; Direct Connect provides a dedicated private connection (Correct answer)
- Both use the same underlying technology with different pricing
- Site-to-Site VPN is only for connecting VPCs; Direct Connect is for on-premises connections
- Site-to-Site VPN provides a physical dedicated line; Direct Connect uses the internet
Correct answer: Site-to-Site VPN creates an encrypted tunnel over the internet; Direct Connect provides a dedicated private connection
Site-to-Site VPN creates an IPsec-encrypted tunnel over the public internet for quick setup, while Direct Connect provides a dedicated physical connection bypassing the internet for consistent performance.
Question 60: Which encryption option allows Amazon S3 to manage the encryption keys on behalf of the customer?
- SSE-KMS
- Client-side encryption
- SSE-S3 (Correct answer)
- SSE-C
Correct answer: SSE-S3
SSE-S3 (Server-Side Encryption with S3-managed keys) lets S3 handle key management entirely on the customer's behalf.
Question 61: An architect recommends using loosely coupled components in a cloud application. What is the primary benefit of this approach?
- Simplified code development
- Failure of one component does not cascade to others (Correct answer)
- Reduced latency between services
- Lower data transfer costs
Correct answer: Failure of one component does not cascade to others
Loose coupling prevents failures in one component from propagating to other components, improving overall system resilience.
Question 62: What happens to an EC2 Spot Instance when AWS needs the capacity back?
- It receives a 2-minute warning and is then terminated (Correct answer)
- It is paused and resumed later
- It is migrated to another Availability Zone
- It is converted to On-Demand automatically
Correct answer: It receives a 2-minute warning and is then terminated
AWS provides a 2-minute interruption notice before reclaiming a Spot Instance, after which it is stopped or terminated.
Question 63: A company is evaluating cloud providers and wants to benefit from the massive purchasing power AWS has built through millions of customers. Which cloud advantage does this describe?
- Increased agility
- High availability
- Benefit from massive economies of scale (Correct answer)
- Global reach
Correct answer: Benefit from massive economies of scale
AWS aggregates usage from hundreds of thousands of customers, achieving economies of scale that result in lower pay-as-you-go prices.
Question 64: Which AWS service would you use to monitor CPU utilization of your EC2 instances and set alarms when thresholds are breached?
- AWS Config
- AWS CloudTrail
- Amazon CloudWatch (Correct answer)
- AWS Trusted Advisor
Correct answer: Amazon CloudWatch
Amazon CloudWatch collects metrics like CPU utilization and lets you create alarms that trigger notifications or actions when thresholds are exceeded.
Question 65: What is the key difference between Convertible Reserved Instances and Standard Reserved Instances?
- Convertible RIs can be exchanged for different RI attributes during the term (Correct answer)
- Convertible RIs offer higher discounts than Standard RIs
- Convertible RIs only support Linux operating systems
- Standard RIs can be sold on the Reserved Instance Marketplace; Convertible cannot
Correct answer: Convertible RIs can be exchanged for different RI attributes during the term
Convertible RIs allow you to exchange for different instance families, OS types, or tenancies during the commitment period, offering flexibility at a slightly lower discount than Standard RIs.
Question 66: Which service provides a fully managed NoSQL key-value and document database with single-digit millisecond performance at any scale?
- Amazon DynamoDB (Correct answer)
- Amazon Aurora
- Amazon RDS
- Amazon ElastiCache
Correct answer: Amazon DynamoDB
Amazon DynamoDB is a fully managed NoSQL database that delivers consistent single-digit millisecond performance regardless of scale.
AWS Certified Cloud Practitioner (CLF-C02)
The AWS Certified Cloud Practitioner exam validates a candidate's overall understanding of the AWS Cloud, including its core services, security, architecture, pricing, and support.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds