What's on the Cloud Practitioner exam
Exam code: CLF-C02
Practice the real format
Do you think you are ready? Put your knowledge to the test with a free, timed practice exam that mirrors the Cloud Practitioner format — with instant scoring, per-domain breakdowns, and full answer explanations.
Start a practice exam →The AWS Certified Cloud Practitioner (CLF-C02) validates an overall understanding of the AWS Cloud, independent of any specific job role. It is designed for people who are new to the cloud and may not have an IT background at all — including sales, marketing, product, project management, and finance roles — as well as technologists who want a structured grounding before moving to associate-level certifications. AWS suggests the target candidate has up to six months of exposure to AWS, though this is not a requirement.
Domains covered
The exam is organized into weighted domains. The percentages indicate roughly how much of the exam each domain represents, which is a useful guide for allocating study time.
Cloud Concepts 24%
The value proposition of the AWS Cloud, the six pillars of the AWS Well-Architected Framework, cloud adoption and migration strategies including the AWS Cloud Adoption Framework, and cloud economics — fixed versus variable costs, rightsizing, licensing models, and economies of scale.
Security and Compliance 30%
The AWS shared responsibility model and how it shifts between services, governance and compliance concepts including AWS Artifact and AWS Config, identity and access management with IAM and IAM Identity Center, the principle of least privilege, root user protection, MFA, and security services such as GuardDuty, Shield, WAF, and Trusted Advisor.
Cloud Technology and Services 34%
Deployment and operating models, AWS global infrastructure — Regions, Availability Zones, and edge locations — and the core service families: compute (EC2, Lambda, ECS, EKS, Fargate), storage (S3, EBS, EFS, FSx), databases (RDS, Aurora, DynamoDB, ElastiCache), networking (VPC, Route 53, Direct Connect), plus AI/ML, analytics, and application integration services.
Billing, Pricing, and Support 12%
Compute purchasing options including On-Demand, Reserved Instances, Spot, and Savings Plans; billing and cost management tools such as AWS Budgets, Cost Explorer, and the Pricing Calculator; AWS Organizations and consolidated billing; and the AWS Support plan tiers, Trusted Advisor, and the AWS Partner Network.
How to prepare
The exam rewards breadth rather than depth: you need to recognize what each core AWS service does and when it applies, not how to configure it. Coding, architecture design, and troubleshooting are explicitly out of scope. Note that of the 65 questions, 50 are scored and 15 are unscored trial questions that do not affect your result, and there is no penalty for guessing — so answer everything. Working through full timed papers is the fastest way to surface the service-recognition gaps that cost marks.
Cloud concepts mapped to AWS services
Most CLF-C02 questions describe a business need and ask which AWS service meets it. This table maps the concept you will see in a question to the service that answers it, grouped by category. Knowing what each service does — and which neighbouring service it is easily confused with — is most of the exam.
| Cloud Concept | AWS Service | How It Links |
|---|---|---|
| Global Infrastructure & Networking | ||
| AWS Regions | AWS Global Infrastructure | Geographic locations where AWS operates data centers |
| High availability | Availability Zones (AZs) | Isolated data centers within a Region for fault tolerance |
| Global content delivery | Amazon CloudFront | Delivers content with low latency using edge locations |
| DNS management | Amazon Route 53 | Highly available and scalable DNS service |
| Virtual networking | Amazon VPC | Creates isolated networks in AWS |
| Hybrid connectivity | AWS Direct Connect | Dedicated private network connection to AWS |
| Site-to-site connectivity | AWS VPN | Secure encrypted connection between on-premises and AWS |
| Compute Services | ||
| Virtual servers | Amazon EC2 | Resizable virtual machines in the cloud |
| Serverless computing | AWS Lambda | Runs code without managing servers |
| Container orchestration | Amazon ECS | Managed container deployment and management |
| Kubernetes management | Amazon EKS | Managed Kubernetes service |
| Automatic scaling | EC2 Auto Scaling | Automatically adjusts compute capacity |
| Traffic distribution | Elastic Load Balancing (ELB) | Distributes incoming traffic across resources |
| Storage Services | ||
| Object storage | Amazon S3 | Highly durable and scalable object storage |
| Block storage | Amazon EBS | Persistent block storage for EC2 instances |
| Shared file storage | Amazon EFS | Managed network file system for Linux workloads |
| Long-term archival | Amazon S3 Glacier | Low-cost storage for backup and archiving |
| Hybrid storage | AWS Storage Gateway | Connects on-premises environments to AWS storage |
| Database Services | ||
| Relational databases | Amazon RDS | Managed relational databases (MySQL, PostgreSQL, and others) |
| Enterprise relational database | Amazon Aurora | High-performance cloud-native relational database |
| NoSQL database | Amazon DynamoDB | Fully managed key-value and document database |
| Data warehousing | Amazon Redshift | Petabyte-scale data warehouse service |
| In-memory caching | Amazon ElastiCache | Improves application performance through caching |
| Security & Identity | ||
| Identity and access management | AWS IAM | Controls access to AWS resources |
| Multi-factor authentication | AWS IAM MFA | Additional security layer for user authentication |
| Temporary access | IAM Roles | Grants temporary permissions to users and services |
| Data encryption | AWS KMS | Creates and manages encryption keys |
| Secret management | AWS Secrets Manager | Secure storage for passwords, API keys, and credentials |
| DDoS protection | AWS Shield | Protects applications from DDoS attacks |
| Web application security | AWS WAF | Protects web applications from common exploits |
| Threat detection | Amazon GuardDuty | Continuous threat detection and monitoring |
| Security posture management | AWS Security Hub | Centralized view of security findings |
| Monitoring & Management | ||
| Resource monitoring | Amazon CloudWatch | Monitors metrics, logs, and alarms |
| API activity auditing | AWS CloudTrail | Tracks and records AWS API activity |
| Configuration compliance | AWS Config | Tracks resource configurations and compliance |
| Best-practice recommendations | AWS Trusted Advisor | Provides cost, security, and performance recommendations |
| Infrastructure automation | AWS CloudFormation | Deploys infrastructure as code |
| Centralized governance | AWS Organizations | Manages multiple AWS accounts centrally |
| Migration & Application Integration | ||
| Server migration | AWS Application Migration Service (MGN) | Migrates servers to AWS with minimal downtime |
| Database migration | AWS Database Migration Service (DMS) | Migrates databases to AWS |
| Application integration | Amazon SQS | Managed message queuing service |
| Event-driven integration | Amazon EventBridge | Routes events between AWS services and applications |
| Workflow orchestration | AWS Step Functions | Coordinates distributed application workflows |
| Cost Management & Billing | ||
| Cost visibility | AWS Cost Explorer | Analyzes AWS spending and usage patterns |
| Budget monitoring | AWS Budgets | Sets cost and usage thresholds with alerts |
| Cost optimization recommendations | AWS Compute Optimizer | Recommends optimal AWS resource sizing |
| Centralized billing | AWS OrganizationsConsolidated Billing | Combines billing across multiple AWS accounts |
| Pricing calculator | AWS Pricing Calculator | Estimates AWS service costs before deployment |
| Business Continuity & Reliability | ||
| Backup management | AWS Backup | Centralized backup management across AWS services |
| Disaster recovery | Multi-AZ RDSCross-Region Replication | Improves availability and disaster recovery |
| High availability | Elastic Load BalancingEC2 Auto Scaling | Ensures applications remain available during failures |
| Data durability | Amazon S3 | Provides 99.999999999% (11 nines) durability |
| Customer Support & Governance | ||
| Technical support | AWS Support Plans | Access to AWS support engineers and guidance |
| Operational insights | AWS Health Dashboard | Personalized alerts on AWS service issues |
| Compliance reporting | AWS Artifact | Access to AWS compliance reports and agreements |
| Service documentation & guidance | AWS DocumentationAWS Knowledge Center | Official AWS learning and troubleshooting resources |
Not every service listed here is heavily tested, but each one appears in the CLF-C02 in-scope list. Focus first on the pairs that are easily confused — CloudWatch versus CloudTrail, EBS versus EFS, RDS versus DynamoDB, and Shield versus WAF.
Exam formats and passing scores are updated periodically by AWS. Always confirm the current details on the official AWS certification page before booking your exam.
Ready to test yourself?
Do you think you are ready? Put your knowledge to the test with a free, timed practice exam that mirrors the Cloud Practitioner format — with instant scoring, per-domain breakdowns, and full answer explanations.
Start a practice exam →