Practice for the AWS Certified Cloud Practitioner (CLF-C02) exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: A company wants a fully managed, flexible, and scalable file storage system, with low latency access, for its Windows-ba. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the AWS Certified Cloud Practitioner (CLF-C02) practice test →
What you will practice
- A company wants a fully managed, flexible, and scalable file storage system, with low latency access, for its…
- Which AWS Support plan provides access to a designated Technical Account Manager (TAM)?
- Which AWS service publishes up-to-the-minute information on the general status and availability of AWS servic…
- Due to regulatory and compliance reasons, an organization is supposed to use a hardware device for any data e…
- An e-commerce company wants to assess its applications deployed on Amazon Elastic Compute Cloud (Amazon EC2)…
- An online gaming company wants to block users from certain geographies from accessing its content. Which AWS…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. A company wants a fully managed, flexible, and scalable file storage system, with low latency access, for its Windows-based applications. Which AWS service is the right choice for the company?
Answer: C. Amazon FSx for Windows File Server
Amazon FSx for Windows File Server provides fully managed shared storage using the native SMB protocol, designed specifically for Windows environments. Amazon EFS uses NFS and is built primarily for Linux-based workloads.
Q2. Which AWS Support plan provides access to a designated Technical Account Manager (TAM)?
Answer: C. AWS Enterprise Support
AWS Enterprise Support provides a designated Technical Account Manager to coordinate proactive guidance and access to subject matter experts. For the exam, remember that Enterprise On-Ramp only provides access to a pool of Technical Account Managers, rather than a dedicated one.
Q3. Which AWS service publishes up-to-the-minute information on the general status and availability of AWS services in all AWS Regions?
Answer: B. AWS Health Dashboard – service health
The AWS Health Dashboard service health view displays the general status and availability of all AWS services across all Regions. Be sure to distinguish this from your account health, which provides personalized alerts about events impacting your specific resources.
Q4. Due to regulatory and compliance reasons, an organization is supposed to use a hardware device for any data encryption operations in the cloud. Which AWS service can be used to meet this compliance requirement?
Answer: C. AWS CloudHSM
AWS CloudHSM provides dedicated hardware security modules for cryptographic operations, meeting strict compliance controls. Remember that Key Management Service uses shared underlying hardware, so it does not satisfy strict regulatory mandates requiring single-tenant hardware.
Q5. An e-commerce company wants to assess its applications deployed on Amazon Elastic Compute Cloud (Amazon EC2) instances for vulnerabilities and deviations from AWS best practices. Which AWS service can be used to facilitate this?
Answer: B. Amazon Inspector
Amazon Inspector automatically assesses deployed applications for vulnerabilities and deviations from established security best practices. Trusted Advisor is the stronger distractor here, but remember it evaluates global infrastructure optimizations rather than scanning application code.
Q6. An online gaming company wants to block users from certain geographies from accessing its content. Which AWS service can be used to accomplish this task?
Answer: D. AWS Web Application Firewall (AWS WAF)
AWS Web Application Firewall allows you to create rules that block or allow web requests based on geographic location. AWS Shield is a strong distractor, but it only provides managed protection against distributed denial of service attacks without geo-blocking capabilities.
Q7. Which of the following solutions can you use to connect your on-premises network with AWS Cloud (Select two)?
Answer: A,C. AWS Virtual Private Network (VPN) || AWS Direct Connect
Both AWS Virtual Private Network and AWS Direct Connect establish secure network connections between your on-premises data centers and the AWS cloud. Be careful choosing an Internet Gateway, as it only enables communication between instances and the public internet.
Q8. Which of the following options can be used to access and manage all AWS services (Select three)?
Answer: A,D,E. AWS Management Console || AWS Software Development Kit (SDK) || AWS Command Line Interface (AWS CLI)
The correct options work because the management console, command line interface, and software development kits are the three primary methods for programmatically or interactively managing AWS services. A helpful exam cue is to distinguish management interfaces from specific infrastructure tools like Systems Manager or Secrets Manager, which manage individual resources.
Q9. Which of the following is the correct statement regarding the AWS Storage services?
Answer: C. Amazon Simple Storage Service (Amazon S3) is object based storage, Amazon Elastic Block Store (Amazon EBS) is block based storage and Amazon Elastic File System (Amazon EFS) is file based storage
The correct answer works because it accurately aligns the storage types with their defining characteristics across the core storage services. A practical exam cue is remembering that S3 stores objects, EBS attaches as block volumes to EC2 instances, and EFS provides shared file systems.
Q10. Which of the following statements are correct about the AWS root user account? (Select two)
Answer: D,E. It is highly recommended to enable Multi-Factor Authentication (MFA) for root user account || Root user access credentials are the email address and password used to create the AWS account
The correct options work because the root user is created using a specific email and password, and securing it with multi-factor authentication is a critical best practice. A key exam cue is that root user permissions cannot be restricted by IAM policies, so the credentials must be locked away securely.
Q11. A gaming company is looking at a technology/service that can deliver a consistent low-latency gameplay to ensure a great user experience for end-users in various locations. Which AWS technology/service will provide the necessary low-latenc…
Answer: C. AWS Local Zones
Local Zones place select AWS services like compute and storage closer to major population centers, delivering the required low latency for local users. However, because Wavelength specifically targets ultra-low latency mobile applications via telecom networks, it is also a defensible choice for local latency requirements.
Q12. Which AWS service can be used to provision resources to run big data workloads on Hadoop clusters?
Answer: B. Amazon EMR
Amazon EMR works because it is a managed cluster platform specifically designed to process vast amounts of data using big data frameworks like Apache Hadoop. A practical exam cue is to associate EMR with big data, whereas AWS Batch is meant for scheduling standard computing jobs.
Q13. An IT company wants to run a log backup process every Monday at 2 AM. The usual runtime of the process is 5 minutes. As a Cloud Practitioner, which AWS services would you recommend to build a serverless solution for this use-case? (Select…
Answer: B,E. Amazon Eventbridge || AWS Lambda
Amazon EventBridge can trigger an AWS Lambda function on a specific schedule for a serverless solution. EC2 is not serverless, and Step Functions orchestrates workflows rather than acting as a standalone scheduler.
Q14. Which of the following use-cases is NOT supported by Amazon Rekognition?
Answer: C. Quickly resize photos to create thumbnails
Amazon Rekognition cannot resize photos or create thumbnails, as it is strictly for image and video analysis. You would use a compute service like Lambda for image manipulation tasks.
Q15. Which of the following AWS services can be used to prevent Distributed Denial-of-Service (DDoS) attack? (Select three)
Answer: A,B,F. AWS Web Application Firewall (AWS WAF) || AWS Shield || Amazon CloudFront with Amazon Route 53
AWS Shield, AWS WAF, and the combination of Amazon CloudFront with Amazon Route 53 are correct because they provide managed DDoS protection, layer seven filtering, and edge network resilience. Services like Amazon Inspector or Trusted Advisor evaluate vulnerabilities and best practices but do not actively block traffic.
Q16. A startup is looking for 24×7 phone-based technical support for its AWS account. Which of the following is the MOST cost-effective AWS support plan for this use-case?
Answer: B. AWS Business Support
AWS Business Support is correct because it is the lowest tier offering twenty four seven phone, email, and chat access for production workloads. Developer Support only provides email during business hours, while Enterprise tiers provide the same access but at a higher cost.
More AWS Certified Cloud Practitioner (CLF-C02) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.