AWS · CLF-C02
Validates overall knowledge of the AWS Cloud, including cloud concepts, security and compliance, cloud technology and services, and billing and pricing.
Practice Questions
600
≈ 9 practice exams
Duration
90 minutes
Passing Score
700/1000
Difficulty
FoundationalLast Updated
Jan 2026
CLF-C02 is AWS's foundational, role-independent certification, and its weighting reflects that: Cloud Technology and Services carries the largest share at 34 percent of scored content, followed by Security and Compliance at 30 percent, Cloud Concepts at 24 percent, and Billing, Pricing, and Support at 12 percent. With 600 questions in the bank, this practice exam mirrors that split so you spend proportionally more time on AWS services and security fundamentals than on billing trivia.
On test day you get 65 questions in 90 minutes: 50 scored and 15 unscored questions AWS mixes in to evaluate future content, without telling you which is which. Scoring is scaled from 100 to 1,000, and you need 700 to pass. AWS designs CLF-C02 for candidates with up to 6 months of AWS exposure, with no coding, architecture design, or troubleshooting required, so the practice questions focus on recognizing what a service does and when to use it rather than deep hands-on configuration.
There's no formal prerequisite, and CLF-C02 is often the first AWS certification people take before moving to an associate-level exam like Solutions Architect or Developer. The exam costs $100 and the certification is valid for 3 years. Start with the 30 free questions, then work through the full 600-question bank until your accuracy holds steady across all four domains.
The AWS Certified Cloud Practitioner (CLF-C02) is a foundational-level certification from Amazon Web Services that validates a broad, high-level understanding of the AWS Cloud platform, its core services, and its key terminology. The certification demonstrates competency across four core domains: cloud concepts and the AWS value proposition, security and compliance including the shared responsibility model, cloud technology and services spanning compute, networking, database, and storage, and billing, pricing, and support structures. Launched on September 19, 2023 as the successor to CLF-C01, the updated CLF-C02 exam places greater emphasis on governance concepts and the AWS Cloud Adoption Framework (CAF), while increasing the weight of the Security and Compliance domain from 25% to 30%. It is assessed on a compensatory scoring model, meaning candidates must achieve an overall passing score without needing to pass each individual domain section.
The CLF-C02 is designed for individuals who are new to cloud computing or seeking to formalize foundational AWS knowledge, regardless of their technical background. It is particularly well-suited for professionals in non-technical roles — such as sales, marketing, project management, or finance — who work alongside technical teams and need cloud literacy, as well as for IT professionals beginning their AWS journey who plan to advance toward Associate or Specialty certifications. Candidates who have had up to 6 months of exposure to AWS Cloud in any capacity (technical, managerial, sales, or operational) are the primary audience, though no prior cloud experience is strictly required.
There are no formal prerequisites for the CLF-C02 exam. AWS does not require candidates to hold any prior certifications or complete specific training courses before sitting for the exam. AWS recommends that candidates have up to 6 months of exposure to the AWS Cloud in any capacity — technical or non-technical — though even this is not a hard requirement. Candidates benefit from a general familiarity with IT concepts and an understanding of basic cloud terminology. Those with no IT background whatsoever can still successfully prepare through AWS's official training materials available on AWS Skill Builder.
The CLF-C02 exam consists of 65 total questions delivered in 90 minutes, of which 50 questions are scored and 15 are unscored pretest questions that are not identified and do not affect the final score. Questions are presented in two formats: multiple choice (one correct answer from four options) and multiple response (two or more correct answers from five or more options). The exam is available through Pearson VUE either at an authorized testing center or via online proctored delivery in 13 languages, including English, Japanese, Korean, Spanish, Portuguese, French, German, Italian, Arabic, and simplified/traditional Chinese. Scores are reported on a scaled range of 100–1,000, and the minimum passing score is 700. The compensatory scoring model means no individual domain passing threshold exists — only the total score matters. Unanswered questions are counted as incorrect, so guessing carries no additional penalty. The exam fee is $100 USD.
The AWS Certified Cloud Practitioner serves as the entry point into the AWS certification pathway and is widely recognized as a credential that demonstrates cloud literacy across both technical and business roles. Holders of the certification report measurable career impact: according to research by Jefferson Frank, 73% of AWS-certified professionals received a salary raise after certification, averaging 27%. Entry-level roles for CLF-C02 holders in the U.S. average approximately $85,000–$105,000 annually, with the certification functioning primarily as a gateway to higher-paying Associate and Professional-level roles such as Solutions Architect, SysOps Administrator, or Cloud Developer, which command average U.S. salaries of $130,000–$160,000. AWS currently holds approximately 32% of the global public cloud market, sustaining strong employer demand for cloud-credentialed professionals. Passing the CLF-C02 also provides a 50% discount voucher toward the next AWS certification exam, making it a cost-effective first step in building an AWS credential stack.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 9 full-length practice exams.
Preview — answers shown1. A company's security team needs to determine which AWS account administrator changed an IAM policy that inadvertently granted excessive permissions to a developer role. Which AWS service provides an audit trail of this API-level activity? (Select one!)
Explanation
AWS CloudTrail records all API calls made to AWS services, capturing details such as which principal made the call, from which IP address, which service was invoked, and what action was taken. CloudTrail is the correct tool when you need to answer who did what — specifically identifying which IAM user or role changed an IAM policy. Amazon CloudWatch monitors operational metrics, alarms, and application logs but does not track which identity performed a specific API action. AWS Config continuously tracks the configuration state of AWS resources over time and can detect configuration drift, but it is designed to answer whether a resource is configured correctly rather than identifying the actor who performed a change. Amazon GuardDuty uses machine learning to detect threats and anomalous behavior within the AWS environment but does not provide a detailed API call audit trail for compliance and security investigations.
2. Trey Research is bidding on a federal government contract. The procurement officer requires documentation confirming that AWS has completed a SOC 2 Type II audit. Where should the Trey Research cloud team go to download this official compliance report? (Select one!)
Explanation
AWS Artifact is the self-service portal for accessing AWS compliance documentation, including SOC 1, SOC 2, and SOC 3 reports, ISO certifications, PCI DSS attestations, and hundreds of other third-party audit reports. Organizations can download these reports on demand to share with auditors and procurement officers to demonstrate that the underlying AWS infrastructure meets required compliance standards. AWS Trusted Advisor provides automated best-practice recommendations across security, cost, fault tolerance, and performance but does not host or serve official compliance audit reports. Amazon Inspector is an automated vulnerability assessment service for EC2 instances and container images that surfaces security findings — it does not provide third-party compliance certifications. AWS Security Hub aggregates and prioritizes security findings from AWS services and integrated partners but does not serve official compliance audit documentation.
3. A security engineer at Adatum Corporation discovered that an S3 bucket's public access block setting was disabled without authorization. The engineer needs to identify who made the change, when it occurred, and from which IP address. Which AWS service provides this information? (Select one!)
Explanation
AWS CloudTrail records every API call made in an AWS account, capturing the identity of the caller, the source IP address, the timestamp, and the parameters of each request. This makes CloudTrail the correct tool for investigating who changed the S3 bucket setting and when. Amazon CloudWatch collects and monitors performance metrics and logs but does not record API call provenance. Amazon GuardDuty uses threat intelligence and log analysis to detect malicious or anomalous behavior; it can flag suspicious activity but does not serve as a detailed API audit trail. AWS Config tracks the configuration state of resources over time and can detect that a setting changed, but does not capture the identity or IP address of the caller who made the API call.
4. A company's CTO wants to reduce the environmental footprint of their cloud infrastructure and make workloads more sustainable over time. Which pillar of the AWS Well-Architected Framework directly addresses minimizing the environmental impact of cloud workloads? (Select one!)
Explanation
The Sustainability pillar was added as the sixth pillar of the AWS Well-Architected Framework in December 2021. It focuses on minimizing the environmental impact of cloud workloads by maximizing resource utilization, reducing energy consumption, and selecting efficient hardware and software. Cost Optimization focuses on eliminating unnecessary spending and rightsizing resources. Operational Excellence addresses running and monitoring systems to deliver business value. Performance Efficiency focuses on using computing resources efficiently to meet system requirements rather than on environmental outcomes.
5. Woodgrove Retail wants to build a personalized product recommendation engine that delivers real-time, individualized recommendations based on each customer's browsing history, purchase behavior, and on-site interactions. Which AWS service is purpose-built for this use case? (Select one!)
Explanation
Amazon Personalize is a fully managed service specifically designed to create real-time personalization and recommendation systems. It uses the same machine learning technology that powers Amazon.com recommendations and handles data ingestion, model training, and inference without requiring deep ML expertise. Amazon SageMaker is a broad ML platform for building, training, and deploying custom models across many use cases; configuring a recommendation system in SageMaker requires significantly more ML expertise. Amazon Rekognition analyzes images and videos for object detection, facial recognition, and content moderation, which is unrelated to product recommendations. Amazon Forecast is a time-series forecasting service used for demand planning and inventory optimization, not personalized product recommendations.
65 questions in 90 minutes: 50 scored plus 15 unscored questions AWS uses to evaluate future content. You are not told which is which.
700 on AWS’s scaled score of 100 to 1,000.
$100 USD, though the exact price varies by the country or region where you sit the exam.
Cloud Technology and Services (34%), Security and Compliance (30%), Cloud Concepts (24%), and Billing, Pricing, and Support (12%).
None formal. AWS designs it for candidates with up to 6 months of AWS exposure, including people in non-technical roles.
Yes, after 3 years. You renew by retaking the current exam or passing a higher-level AWS exam.
AWS does not publish a pass rate. It is the easiest AWS certification, testing recognition of AWS services and concepts rather than hands-on configuration, coding, or architecture design.
It is optional, but common as a first step. Many candidates use it to build foundational AWS vocabulary before attempting an associate-level exam like Solutions Architect or Developer Associate.
AWS Certified Advanced Networking - Specialty (ANS-C01)
ANS-C01 · 1453 questions
AWS Certified AI Business Strategist (AIB-C01)
AIB-C01 · 341 questions
AWS Certified AI Practitioner (AIF-C01)
AIF-C01 · 426 questions
AWS Certified CloudOps Engineer - Associate (SOA-C03)
SOA-C03 · 2141 questions
AWS Certified Data Engineer - Associate (DEA-C01)
DEA-C01 · 1120 questions
AWS Certified Developer - Associate (DVA-C02)
DVA-C02 · 536 questions
$17.99
One-time access to this exam