AWS Certified Cloud Practitioner (CLF-C02) Practice Exam Questions and Answers – Part 17/20

Practice for the AWS Certified Cloud Practitioner (CLF-C02) exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: According to the AWS Well-Architected Framework, which of the following actions is recommended in the Security pillar?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the AWS Certified Cloud Practitioner (CLF-C02) practice test →

What you will practice

  • According to the AWS Well-Architected Framework, which of the following actions is recommended in the Securit…
  • Adding more CPU or RAM to an Amazon Elastic Compute Cloud (Amazon EC2) instance represents which of the follo…
  • A data science team would like to build Machine Learning models for its projects. Which AWS service can it us…
  • An e-commerce company would like to build a chatbot for its customer service using Natural Language Understan…
  • A company is planning to implement chaos engineering to expose any blind spots that can disrupt the resilienc…
  • Which AWS service allows you to quickly and easily add user sign-up, sign-in, and access control to web and m…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. According to the AWS Well-Architected Framework, which of the following actions is recommended in the Security pillar?

Answer: B. Use AWS Key Management Service (AWS KMS) to encrypt data

Using AWS KMS to encrypt data is a core best practice for protecting data at rest and in transit under the Security pillar. Cost Explorer maps to Cost Optimization, while CloudFormation automates infrastructure provisioning rather than enforcing encryption.

Q2. Adding more CPU or RAM to an Amazon Elastic Compute Cloud (Amazon EC2) instance represents which of the following?

Answer: D. Vertical scaling

Upgrading the resources of a single instance, such as adding CPU or RAM, is known as vertical scaling. Horizontal scaling involves adding more instances to a fleet to handle increased load.

Q3. A data science team would like to build Machine Learning models for its projects. Which AWS service can it use?

Answer: C. Amazon SageMaker

Amazon SageMaker provides a fully managed environment for data scientists to build, train, and deploy custom machine learning models. Polly and Comprehend are pre-trained AI services for specific tasks rather than model-building platforms.

Q4. An e-commerce company would like to build a chatbot for its customer service using Natural Language Understanding (NLU). As a Cloud Practitioner, which AWS service would you use?

Answer: B. Amazon Lex

Amazon Lex is the dedicated service for building conversational chatbots, utilizing natural language understanding and speech recognition. Do not confuse this with Amazon Comprehend, which analyzes text for sentiment and key phrases but does not build interactive voice interfaces.

Q5. A company is planning to implement chaos engineering to expose any blind spots that can disrupt the resiliency of the application. Which AWS service will help implement this requirement with the least effort?

Answer: A. AWS Fault Injection Simulator (AWS FIS)

AWS Fault Injection Simulator is the managed service designed specifically for chaos engineering, allowing you to safely inject disruptions to test system resiliency. Security services like Amazon Inspector and GuardDuty focus on vulnerability assessments and threat detection, not performance testing.

Q6. Which AWS service allows you to quickly and easily add user sign-up, sign-in, and access control to web and mobile applications?

Answer: B. Amazon Cognito

Amazon Cognito is specifically designed to add user sign-up, sign-in, and access control features to your mobile and web applications. Remember that IAM manages internal AWS console permissions, whereas Cognito handles external consumer-facing application identities.

Q7. A media company wants to enable customized content suggestions for the users of its movie streaming platform. Which AWS service can provide these personalized recommendations based on historic data?

Answer: C. Amazon Personalize

Amazon Personalize uses machine learning to deliver real-time customized recommendations based on historical user data. Avoid confusing this with Amazon SageMaker, which is a broader platform requiring you to build and train custom machine learning models from scratch.

Q8. An enterprise is planning to move one of its older applications from its local data center to AWS. The IT team wants the fastest migration path and has decided not to update the application code or make any architectural changes. Which mig…

Answer: A. Rehost

Rehosting, or lift and shift, moves applications exactly as they are without code changes, providing the fastest migration path. Replatforming requires minor optimizations, while refactoring requires extensive architectural redesign, both violating the requirement for no modifications.

Q9. A corporation would like to simplify access management to multiple AWS accounts as well as facilitate AWS Single Sign-On (AWS SSO) access to its AWS accounts. As a Cloud Practitioner, which AWS service would you use for this task?

Answer: D. AWS IAM Identity Center

AWS IAM Identity Center is the correct choice because it manages workforce access to multiple accounts and applications from a central location. This service is the direct successor to AWS Single Sign-On.

Q10. An organization would like to copy data across different Availability Zones (AZs) using Amazon EBS snapshots. Where are Amazon EBS snapshots stored in the AWS Cloud?

Answer: C. Amazon Simple Storage Service (Amazon S3)

Amazon EBS snapshots are stored in Amazon S3, providing a durable, incremental backup of your volume data. Remember that EC2 provides compute, EFS is for active shared file storage, and RDS handles relational databases rather than acting as snapshot storage.

Q11. A company would like to create a private, high bandwidth network connection between its on-premises data centers and AWS Cloud. As a Cloud Practitioner, which of the following options would you recommend?

Answer: C. AWS Direct Connect

AWS Direct Connect establishes a dedicated, private network connection from on-premises environments to AWS, bypassing the public internet. Site-to-Site VPN also connects networks but routes traffic over the public internet rather than a private, high-bandwidth line.

Q12. Which AWS service can be used to subscribe to an RSS feed to be notified of the status of all AWS service interruptions?

Answer: D. AWS Health Dashboard – Service Health

The AWS Health Dashboard provides the overall status of all AWS services and offers an RSS feed for service interruptions. Do not confuse this with the Account Health Dashboard, which only provides personalized alerts for events directly impacting your specific AWS resources.

Q13. A production company with predictable usage would like to reduce the cost of its Amazon Elastic Compute Cloud (Amazon EC2) instances by using Reserved Instances (RI). Which of the following length terms are available for Amazon EC2 Reserve…

Answer: B,C. 1 year || 3 years

Standard and Convertible Reserved Instances for Amazon EC2 are available in one-year and three-year term commitments for a significant discount. For the exam, remember that AWS does not offer six-month, two-year, or five-year reservation terms for standard pricing discounts.

Q14. According to the AWS Shared Responsibility Model, which of the following is the responsibility of the customer?

Answer: A. Firewall & networking configuration of Amazon Elastic Compute Cloud (Amazon EC2)

Under the Shared Responsibility Model, customers are responsible for security in the cloud, including configuring firewalls and networking for EC2 instances. AWS manages security of the cloud itself, meaning AWS handles physical hardware and the underlying infrastructure for managed services like DynamoDB.

Q15. A startup would like to monitor its cost on the AWS Cloud and would like to choose an optimal Savings Plan. As a cloud practitioner, which AWS service would you use?

Answer: C. AWS Cost Explorer

AWS Cost Explorer lets you visualize your costs and provides actionable Savings Plan recommendations. While AWS Budgets sends alerts when you exceed your spending limits, it does not generate specific Savings Plan optimization recommendations.

Q16. A company would like to separate costs for AWS services by department for cost allocation. Which of the following is the simplest way to achieve this task?

Answer: D. Create tags for each department

Applying resource tags to designate specific departments is the simplest and most effective way to allocate and separate AWS costs. Creating multiple AWS accounts for different departments complicates billing, whereas using tags on a single account streamlines cost tracking.

More AWS Certified Cloud Practitioner (CLF-C02) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top