Practice for AWS Cloud Practitioner (CLF-C02) with 1150+ AWS Cloud Practitioner Practice Exam Questions (CLF-C02) across multiple full-length tests. Detailed explanations, instant answers, no signup needed.
AWS Cloud Practitioner Practice Exam | 1150+ Free MCQ Questions with Answers and Explanations |1150+ AWS Cloud Practitioner Practice Exam Questions (CLF-C02)
Are you preparing for the AWS Certified Cloud Practitioner (CLF-C02) exam? You have landed on the most comprehensive free AWS Cloud Practitioner practice test resource on the internet. This page contains multiple full-length practice exams with over 1,150 multiple-choice questions, complete with correct answers and detailed explanations — no registration, no payment, no limits.
Whether you are a complete beginner stepping into cloud computing or an IT professional aiming to validate your AWS knowledge, these practice questions are designed to mirror the real CLF-C02 exam format and cover every domain tested by Amazon Web Services.
What Is the AWS Cloud Practitioner Certification?
The AWS Certified Cloud Practitioner (CLF-C02) is the entry-level certification offered by Amazon Web Services. It validates foundational knowledge of the AWS Cloud, its core services, security model, pricing, and architectural best practices. It is ideal for:
- Non-technical business professionals
- Students and freshers entering cloud computing
- Developers and engineers new to AWS
- Project managers and sales professionals working with AWS teams
The exam consists of 65 questions to be completed in 90 minutes, with a passing score of 700 out of 1000. Questions cover four main domains:
| Domain | Weightage |
| Cloud Concepts | 24% |
| Security and Compliance | 30% |
| Cloud Technology and Services | 34% |
| Billing, Pricing, and Support | 12% |
Topics Covered in These Practice Tests
These MCQs comprehensively cover every topic that appears on the real CLF-C02 exam:’
Cloud Concepts
Benefits of AWS Cloud (elasticity, agility, scalability, high availability)
Cloud deployment models (public, private, hybrid)
AWS Global Infrastructure (Regions, Availability Zones, Edge Locations)
Total Cost of Ownership (TCO) and economies of scale
Capital expenditure vs operational expenditure
Security and Compliance
AWS Shared Responsibility Model
AWS Identity and Access Management (IAM)
Multi-Factor Authentication (MFA)
AWS Shield, AWS WAF, Amazon GuardDuty
AWS Artifact, AWS Config, AWS CloudTrail
Encryption at rest and in transit
AWS KMS and AWS CloudHSM
Least privilege access and password policies
Cloud Technology and Services
Amazon EC2 (instance types, pricing models, Auto Scaling)
Amazon S3 (storage classes, lifecycle policies, cross-region replication)
Amazon RDS, Aurora, DynamoDB, Redshift
AWS Lambda and serverless architecture
Amazon VPC (subnets, security groups, NACLs, internet gateways)
Amazon CloudFront and Edge Locations
Amazon Route 53 (DNS and routing policies)
AWS Direct Connect and AWS VPN
Elastic Load Balancing and Auto Scaling
AWS CloudFormation and Elastic Beanstalk
AWS Trusted Advisor and AWS Personal Health Dashboard
Billing, Pricing, and Support
AWS Free Tier
On-Demand, Reserved, Spot, and Dedicated pricing
AWS Pricing Calculator and TCO Calculator
AWS Cost Explorer and AWS Budgets
Consolidated billing and AWS Organizations
AWS Support plans (Basic, Developer, Business, Enterprise)
Technical Account Manager and Concierge team
How to Use These Practice Tests Effectively
Follow this proven 4-step study strategy used by candidates who pass on their first attempt:
Step 1: Attempt each test without looking at answers first.
Go through all 50 questions and mark the ones you are unsure about. This simulates real exam conditions and builds exam stamina.
Step 2: Review every explanation, not just wrong answers.
Even when you get an answer right, read the explanation. Understanding why an answer is correct — and why the other options are wrong — is what builds genuine exam confidence.
Step 3: Identify and focus on your weak domains.
After completing several tests, notice which topics you consistently miss. Revisit those topics in the official AWS documentation or whitepapers before retaking those tests.
Step 4: Repeat until you score 80% or above consistently.
If you are consistently scoring above 80% across multiple tests here, you are well-prepared for the real exam. The actual CLF-C02 passing threshold is 700 out of 1000 (70%).
Frequently Asked Questions
Is the AWS Cloud Practitioner exam hard?
The CLF-C02 exam is considered the most accessible AWS certification but should not be underestimated. Candidates with no prior AWS experience typically need 4–6 weeks of preparation. With consistent practice using these MCQs, most candidates feel ready in 2–4 weeks.
How many questions are on the real AWS CCP exam?
The exam has 65 questions — 50 scored and 15 unscored questions used for future exam development. You will not know which are unscored, so treat every question seriously.
What is the passing score for the AWS Cloud Practitioner exam?
The passing score is 700 out of 1000, which is approximately 70%.
How long is the AWS CCP certification valid?
AWS certifications are valid for 3 years from the date of passing. After that, recertification is required.
Are these practice questions enough to pass?
These 1,150+ questions cover the full breadth of the CLF-C02 exam syllabus. Candidates who thoroughly practice all the tests and understand every explanation report very high pass rates. We recommend combining this with the official AWS Cloud Practitioner Essentials course for maximum preparation.
What is the difference between CLF-C01 and CLF-C02?
CLF-C02 is the current and active version of the AWS Certified Cloud Practitioner exam. It places greater emphasis on security, compliance, and cloud technology services compared to the older CLF-C01. All questions on this page are aligned with the CLF-C02 objectives.
Is the AWS Cloud Practitioner certification worth it?
Absolutely. It is recognized globally, boosts earning potential, and is typically the first step toward more advanced AWS certifications such as Solutions Architect, Developer, and SysOps Administrator.
Can I take the AWS CCP exam online?
Yes. AWS offers both in-person testing at Pearson VUE and PSI centers, as well as online proctored exams you can take from home.
Start Practicing Now
All practice questions are loaded below. Click View Answer after each question to instantly reveal the correct answer and a detailed explanation. There is no time limit here — learn at your own pace.
Full Length Test No. 1
1. AWS allows users to manage their resources using a web based user interface. What is the name of this interface?
- AWS CLI
- AWS API
- AWS SDK
- AWS Management Console
Answer : D Explanation: The AWS Management Console is the web-based user interface that allows users to access and manage all AWS services from a single browser-based application. AWS CLI is a command-line tool, AWS API is for programmatic access, and AWS SDK is used for integrating AWS services into applications using code.
2. Which of the following is an example of horizontal scaling in the AWS Cloud?
- Replacing an existing EC2 instance with a larger, more powerful one
- Increasing the compute capacity of a single EC2 instance to address the growing demands of an application
- Adding more RAM capacity to an EC2 instance
- Adding more EC2 instances of the same size to handle an increase in traffic
Answer : D Explanation: Horizontal scaling means adding more instances of the same size to distribute the load, rather than increasing the size of an existing instance. Options A, B, and C all describe vertical scaling (scaling up), which involves increasing the resources of a single instance.
3. You have noticed that several critical Amazon EC2 instances have been terminated. Which of the following AWS services would help you determine who took this action?
- Amazon Inspector
- AWS CloudTrail
- AWS Trusted Advisor
- EC2 Instance Usage Report
Answer : B Explanation: AWS CloudTrail records all API calls and user activity across your AWS account, including who terminated EC2 instances, when, and from where. Amazon Inspector is for vulnerability assessments, Trusted Advisor provides best practice recommendations, and EC2 Instance Usage Report tracks usage but not user actions.
4. Which of the below options are related to the reliability of AWS? (Choose TWO)
- Applying the principle of least privilege to all AWS resources
- Automatically provisioning new resources to meet demand
- All AWS services are considered Global Services, and this design helps customers serve their international users
- Providing compensation to customers if issues occur
- Ability to recover quickly from failures
Answer : B, E Explanation: Reliability in AWS refers to the ability of a system to recover from failures and dynamically acquire resources to meet demand. Automatically provisioning resources (B) ensures the system can handle demand changes, and the ability to recover quickly from failures (E) directly relates to reliability. Least privilege is a security concept, and AWS does not simply provide compensation as a reliability measure.
5. Which statement is true regarding the AWS Shared Responsibility Model?
- Responsibilities vary depending on the services used
- Security of the IaaS services is the responsibility of AWS
- Patching the guest OS is always the responsibility of AWS
- Security of the managed services is the responsibility of the customer
Answer : A Explanation: Under the AWS Shared Responsibility Model, the division of responsibilities varies depending on the type of service used. For IaaS (like EC2), customers are responsible for the guest OS and above. For managed services (like RDS or DynamoDB), AWS takes on more responsibility. Patching the guest OS is a customer responsibility for IaaS services, not always AWS’s.
6. You have set up consolidated billing for several AWS accounts. One of the accounts has purchased a number of Reserved Instances for 3 years. Which of the following is true regarding this scenario?
- The Reserved Instance discounts can only be shared with the master account
- All accounts can receive the hourly cost benefit of the Reserved Instances
- The purchased instances will have better performance than On-Demand instances
- There are no cost benefits from using consolidated billing; it is for informational purposes only
Answer : B Explanation: With consolidated billing, Reserved Instance discounts are shared across all accounts within the organization. If one account purchases Reserved Instances but does not fully utilize them, other accounts in the same organization can benefit from the discounted pricing. Reserved Instances do not provide better performance than On-Demand instances — the benefit is cost savings only.
7. A company has developed an eCommerce web application in AWS. What should they do to ensure that the application has the highest level of availability?
- Deploy the application across multiple Availability Zones and Edge locations
- Deploy the application across multiple Availability Zones and subnets
- Deploy the application across multiple Regions and Availability Zones
- Deploy the application across multiple VPCs and subnets
Answer : C Explanation: The highest level of availability is achieved by deploying the application across multiple AWS Regions and multiple Availability Zones within those regions. This protects against both regional and zone-level failures. Edge locations are for content delivery (CloudFront), not application hosting, and deploying across subnets or VPCs alone does not provide the same level of fault tolerance.
8. What does AWS Snowball provide? (Choose TWO)
- Built-in computing capabilities that allow customers to process data locally
- A catalog of third-party software solutions that customers need to build solutions and run their businesses
- A hybrid cloud storage between on-premises environments and the AWS Cloud
- An Exabyte-scale data transfer service that allows you to move extremely large amounts of data to AWS
- Secure transfer of large amounts of data into and out of AWS
Answer : A, E Explanation: AWS Snowball is a physical data transport device that provides secure transfer of large amounts of data into and out of AWS (E). Snowball Edge also includes built-in computing capabilities, allowing customers to process data locally before transferring it (A). Option D describes AWS Snowmobile, which handles exabyte-scale transfers. Option B describes AWS Marketplace, and option C describes AWS Storage Gateway.
9. A company has an AWS Enterprise Support plan. They want quick and efficient guidance with their billing and account inquiries. Which of the following should the company use?
- AWS Health Dashboard
- AWS Support Concierge
- AWS Customer Service
- AWS Operations Support
Answer : B Explanation: AWS Support Concierge is a feature exclusive to Enterprise Support plan customers. It provides a dedicated team to help with billing and account inquiries, offering personalized and efficient guidance. The AWS Health Dashboard monitors service health, and general Customer Service handles basic inquiries not specific to Enterprise plans.
10. A Japanese company hosts their applications on Amazon EC2 instances in the Tokyo Region. The company has opened new branches in the United States, and the US users are complaining of high latency. What can the company do to reduce latency for the users in the US while minimizing costs?
- Apply the Amazon Route 53 latency-based routing policy
- Register a new US domain name to serve the users in the US
- Build a new data center in the US and implement a hybrid model
- Deploy new Amazon EC2 instances in a Region located in the US
Answer : D Explanation: Deploying EC2 instances in a US-based AWS Region places the application closer to US users, significantly reducing latency. This is the most cost-effective cloud-native solution. Building a physical data center (C) would be expensive. Registering a new domain (B) does not reduce latency. Route 53 latency-based routing (A) helps route users to the nearest region but requires instances to already exist in that region.
11. An organization has a large number of technical employees who operate their AWS Cloud infrastructure. What does AWS provide to help organize them into teams and then assign the appropriate permissions for each team?
- IAM roles
- IAM users
- IAM user groups
- AWS Organizations
Answer : C Explanation: IAM user groups allow you to organize IAM users into teams and assign permissions to the group as a whole, rather than individually. Any user added to the group inherits the group’s permissions. IAM roles are for temporary access, IAM users are individual identities, and AWS Organizations manages multiple AWS accounts rather than users within an account.
12. A company has decided to migrate its Oracle database to AWS. Which AWS service can help achieve this without negatively impacting the functionality of the source database?
- AWS OpsWorks
- AWS Database Migration Service
- AWS Server Migration Service
- AWS Application Discovery Service
Answer : B Explanation: AWS Database Migration Service (DMS) helps migrate databases to AWS quickly and securely while keeping the source database fully operational during the migration, minimizing downtime. AWS OpsWorks is for configuration management, AWS Server Migration Service migrates on-premises servers (not databases), and AWS Application Discovery Service helps plan migrations by collecting data about on-premises infrastructure.
13. Adjusting compute capacity dynamically to reduce cost is an implementation of which AWS cloud best practice?
- Build security in every layer
- Parallelize tasks
- Implement elasticity
- Adopt monolithic architecture
Answer : C Explanation: Elasticity refers to the ability to dynamically scale computing resources up or down based on demand, ensuring you only pay for what you use. Monolithic architecture is an anti-pattern in cloud design. Building security in every layer and parallelizing tasks are separate best practices unrelated to dynamic capacity adjustment.
14. What are the benefits of having infrastructure hosted in AWS? (Choose TWO)
- Increasing speed and agility
- There is no need to worry about security
- Gaining complete control over the physical infrastructure
- Operating applications on behalf of customers
- All of the physical security and most of the data/network security are taken care of for you
Answer : A, E Explanation: AWS enables increased speed and agility (A) by allowing rapid provisioning of resources. AWS also handles all physical security and much of the underlying data/network security (E) under the shared responsibility model. Security is still a shared concern — customers must still manage their own data and access controls (B is incorrect). AWS does not grant customers control over physical infrastructure (C), and AWS does not operate your applications for you (D).
15. What is the advantage of the AWS-recommended practice of “decoupling” applications?
- Allows treating an application as a single, cohesive unit
- Reduces inter-dependencies so that failures do not impact other components of the application
- Allows updates of any monolithic application quickly and easily
- Allows tracking of any API call made to any AWS service
Answer : B Explanation: Decoupling means designing application components so they are independent of each other. This reduces inter-dependencies, meaning a failure in one component does not cascade to others, improving resilience and fault tolerance. Monolithic architecture (A, C) is the opposite of decoupling. Tracking API calls (D) is the function of AWS CloudTrail.
16. Which of the following helps a customer view the Amazon EC2 billing activity for the past month?
- AWS Budgets
- AWS Pricing Calculator
- AWS Systems Manager
- AWS Cost & Usage Reports
Answer : D Explanation: AWS Cost & Usage Reports provide the most comprehensive and detailed billing data, including EC2 usage and costs for past periods. AWS Budgets is for setting cost thresholds and alerts. AWS Pricing Calculator estimates future costs. AWS Systems Manager is for operational management of resources, not billing.
17. What do you gain from setting up consolidated billing for five different AWS accounts under another master account?
- AWS services’ costs will be reduced to half the original price
- The consolidated billing feature is just for organizational purposes
- Each AWS account gets volume discounts
- Each AWS account gets five times the free-tier services capacity
Answer : C Explanation: With consolidated billing, AWS combines the usage from all accounts to calculate volume pricing tiers. The combined usage across accounts may qualify for volume discounts that individual accounts might not reach on their own. Costs are not simply halved (A), it is not just for organization (B), and free-tier capacity does not multiply per account (D).
18. What should you do in order to keep the data on EBS volumes safe? (Choose TWO)
- Regularly update firmware on EBS devices
- Create EBS snapshots
- Ensure that EBS data is encrypted at rest
- Store a backup daily in an external drive
- Prevent any unauthorized access to AWS data centers
Answer : B, C Explanation: Creating EBS snapshots (B) provides point-in-time backups stored in Amazon S3, allowing data recovery in case of failure. Encrypting EBS data at rest (C) protects the data from unauthorized access. Customers do not manage EBS firmware (A) — that is AWS’s responsibility. Storing backups on an external drive (D) is not an AWS best practice. Preventing physical access to data centers (E) is also AWS’s responsibility.
19. One of the most important AWS best-practices to follow is the cloud architecture principle of elasticity. How does this principle improve your architecture’s design?
- By automatically scaling your on-premises resources based on changes in demand
- By automatically scaling your AWS resources using an Elastic Load Balancer
- By reducing interdependencies between application components wherever possible
- By automatically provisioning the required AWS resources based on changes in demand
Answer : D Explanation: Elasticity in cloud architecture refers to the ability to automatically provision and de-provision resources in response to changes in demand. Elasticity applies to cloud resources, not on-premises (A). An Elastic Load Balancer distributes traffic but does not itself provision resources (B). Reducing interdependencies (C) refers to decoupling, not elasticity.
20. A startup company is operating on limited funds and is extremely concerned about cost overruns. Which of the below options can be used to notify the company when their monthly AWS bill exceeds $2000? (Choose TWO)
- Set up a CloudWatch billing alarm that triggers an SNS notification when the threshold is exceeded
- Configure Amazon Simple Email Service to send billing alerts to their email address on a daily basis
- Configure the AWS Budgets Service to alert the company when the threshold is exceeded
- Configure AWS CloudTrail to automatically delete all AWS resources when the threshold is exceeded
- Configure the Amazon Connect Service to alert the company when the threshold is exceeded
Answer : A, C Explanation: Amazon CloudWatch billing alarms (A) can monitor estimated charges and trigger an SNS notification when the threshold is exceeded. AWS Budgets (C) allows you to set custom cost thresholds and receive alerts via email or SNS when breached. Amazon SES (B) is not a billing alert tool. CloudTrail (D) is for logging API activity, not cost management. Amazon Connect (E) is a contact center service, not a billing alert tool.
21. What does Amazon CloudFront use to distribute content to global users with low latency?
- AWS Global Accelerator
- AWS Regions
- AWS Edge Locations
- AWS Availability Zones
Answer : C Explanation: Amazon CloudFront is a Content Delivery Network (CDN) that uses a global network of Edge Locations to cache and deliver content to users from the location nearest to them, resulting in low latency. AWS Regions and Availability Zones are used for deploying infrastructure, not for CDN edge caching. AWS Global Accelerator improves performance using the AWS global network but is a separate service from CloudFront.
22. What does the “Principle of Least Privilege” refer to?
- You should grant your users only the permissions they need when they need them and nothing more
- All IAM users should have at least the necessary permissions to access the core AWS services
- All trusted IAM users should have access to any AWS service in the respective AWS account
- IAM users should not be granted any permissions to keep your account safe
Answer : A Explanation: The Principle of Least Privilege is an IAM security best practice stating users, roles, and services should only be granted the minimum permissions necessary to perform their required tasks. Granting access to all services (C) is the opposite of this principle. Granting no permissions at all (D) would prevent users from working. Option B is vague and not the correct definition.
23. Which of the following does NOT belong to the AWS Cloud Computing models?
- Platform as a Service (PaaS)
- Infrastructure as a Service (IaaS)
- Software as a Service (SaaS)
- Networking as a Service (NaaS)
Answer : D Explanation: The three standard AWS Cloud Computing models are IaaS (e.g., Amazon EC2), PaaS (e.g., AWS Elastic Beanstalk), and SaaS (e.g., Amazon WorkMail). Networking as a Service (NaaS) is not a recognized AWS cloud computing model.
24. The identification process of an online financial services company requires that new users must complete an online interview with their security team. The completed recorded interviews are only required in the event of a legal issue or a regulatory compliance breach. What is the most cost-effective service to store the recorded videos?
- S3 Intelligent-Tiering
- AWS Marketplace
- Amazon S3 Glacier Deep Archive
- Amazon EBS
Answer : C Explanation: Amazon S3 Glacier Deep Archive is the lowest-cost AWS storage class, designed for data that is rarely accessed and must be retained for long periods — ideal for compliance and legal records. S3 Intelligent-Tiering (A) is for data with unpredictable access patterns. AWS Marketplace (B) is for software, not storage. Amazon EBS (D) is block storage for EC2 instances and is significantly more expensive for archival use.
25. Which service provides DNS in the AWS cloud?
- Route 53
- AWS Config
- Amazon CloudFront
- Amazon EMR
Answer : A Explanation: Amazon Route 53 is AWS’s scalable and highly available Domain Name System (DNS) web service. It translates domain names into IP addresses and routes end-user requests to the appropriate AWS or on-premises resources. AWS Config is for resource configuration tracking, CloudFront is a CDN, and Amazon EMR is a big data processing service.
26. Hundreds of thousands of DDoS attacks are recorded every month worldwide. What service does AWS provide to help protect AWS customers from these attacks? (Choose TWO)
- AWS Shield
- AWS Config
- Amazon Cognito
- AWS WAF
- AWS KMS
Answer : A, D Explanation: AWS Shield (A) is a managed DDoS protection service that safeguards applications running on AWS. AWS WAF (D) is a web application firewall that helps protect web applications from common web exploits and can work alongside Shield to block malicious traffic. AWS Config is for configuration compliance, Amazon Cognito is for user authentication, and AWS KMS is for encryption key management.
27. A company is deploying a new two-tier web application in AWS. Where should the most frequently accessed data be stored so that the application’s response time is optimal?
- AWS OpsWorks
- AWS Storage Gateway
- Amazon EBS volume
- Amazon ElastiCache
Answer : D Explanation: Amazon ElastiCache is an in-memory caching service that stores frequently accessed data in memory, providing sub-millisecond response times. It is ideal for caching database query results or session data to improve application performance. AWS OpsWorks is for configuration management, AWS Storage Gateway is for hybrid cloud storage, and EBS provides block storage with much higher latency compared to in-memory caching.
28. You want to run a questionnaire application for only one day (without interruption), which Amazon EC2 purchase option should you use?
- Reserved instances
- Spot instances
- Dedicated instances
- On-Demand instances
Answer : D Explanation: On-Demand instances are the best choice for short-term, uninterrupted workloads where you cannot tolerate any interruption. Reserved Instances require a 1 or 3-year commitment, making them unsuitable for a one-day task. Spot Instances can be interrupted by AWS at any time. Dedicated Instances provide dedicated hardware but are more expensive and not necessary for this use case.
29. You are working on a project that involves creating thumbnails of millions of images. Consistent uptime is not an issue, and continuous processing is not required. Which EC2 buying option would be the most cost-effective?
- Reserved Instances
- On-Demand Instances
- Dedicated Instances
- Spot Instances
Answer : D Explanation: Spot Instances are the most cost-effective option for workloads that are flexible and can tolerate interruptions, offering discounts of up to 90% compared to On-Demand pricing. Since consistent uptime is not required for batch thumbnail processing, Spot Instances are ideal. Reserved Instances require long-term commitments, and Dedicated Instances are the most expensive option.
30. Which of the following can be described as a global content delivery network (CDN) service?
- AWS VPN
- AWS Direct Connect
- AWS Regions
- Amazon CloudFront
Answer : D Explanation: Amazon CloudFront is AWS’s global Content Delivery Network (CDN) service that delivers data, videos, applications, and APIs to users worldwide with low latency using a network of Edge Locations. AWS VPN and Direct Connect are for network connectivity. AWS Regions are geographic areas for hosting infrastructure, not a CDN service.
31. Which of the following services allows customers to manage their agreements with AWS?
- AWS Artifact
- AWS Certificate Manager
- AWS Systems Manager
- AWS Organizations
Answer : A Explanation: AWS Artifact is a self-service portal that provides access to AWS compliance reports and allows customers to manage and accept agreements such as the Business Associate Addendum (BAA). AWS Certificate Manager handles SSL/TLS certificates. AWS Systems Manager is for operational management. AWS Organizations manages multiple AWS accounts.
32. Which of the following are examples of AWS-Managed Services, where AWS is responsible for the operational and maintenance burdens of running the service? (Choose TWO)
- Amazon VPC
- Amazon DynamoDB
- Amazon Elastic MapReduce (EMR)
- AWS IAM
- Amazon Elastic Compute Cloud (EC2)
Answer : B, C Explanation: Amazon DynamoDB (B) is a fully managed NoSQL database service where AWS handles provisioning, patching, and maintenance. Amazon EMR (C) is a managed big data platform where AWS manages the cluster infrastructure. Amazon VPC, IAM, and EC2 require customers to manage configuration, access policies, and OS-level maintenance respectively.
33. Your company has a data store application that requires access to a NoSQL database. Which AWS database offering would meet this requirement?
- Amazon Aurora
- Amazon DynamoDB
- Amazon Elastic Block Store
- Amazon Redshift
Answer : B Explanation: Amazon DynamoDB is AWS’s fully managed NoSQL database service, designed for key-value and document data models with high performance at any scale. Amazon Aurora is a relational (SQL) database. Amazon EBS is block storage, not a database. Amazon Redshift is a data warehouse for analytical SQL queries.
34. As part of the Enterprise support plan, who is the primary point of contact for ongoing support needs?
- AWS Identity and Access Management (IAM) user
- Infrastructure Event Management (IEM) engineer
- AWS Consulting Partners
- Technical Account Manager (TAM)
Answer : D Explanation: The Technical Account Manager (TAM) is the designated primary point of contact for customers on the AWS Enterprise Support plan. The TAM provides proactive guidance, advocacy, and helps customers get the most out of their AWS environment. IEM engineers assist with specific large-scale events, and AWS Consulting Partners are third-party service providers, not AWS support contacts.
Cloud Computing MCQ Questions and Answers
35. How can you view the distribution of AWS spending in one of your AWS accounts?
- By using Amazon VPC console
- By contacting the AWS Support team
- By using AWS Cost Explorer
- By contacting the AWS Finance team
Answer : C Explanation: AWS Cost Explorer is a tool that allows you to visualize, understand, and manage your AWS costs and usage over time. It provides graphs and reports showing spending distribution by service, region, and time period. The VPC console is for network management. Contacting AWS Support or Finance is unnecessary when self-service tools like Cost Explorer are available.
36. Which of the following must an IAM user provide to interact with AWS services using the AWS Command Line Interface (AWS CLI)?
- Access keys
- Secret token
- UserID
- User name and password
Answer : A Explanation: To use the AWS CLI, an IAM user must configure access keys, which consist of an Access Key ID and a Secret Access Key. These are used to authenticate programmatic requests to AWS. User name and password are used for the AWS Management Console (web-based), not the CLI. UserID and “Secret token” are not standard AWS CLI authentication methods.
37. You have AWS Basic support, and you have discovered that some AWS resources are being used maliciously, and those resources could potentially compromise your data. What should you do?
- Contact the AWS Customer Service team
- Contact the AWS Abuse team
- Contact the AWS Concierge team
- Contact the AWS Security team
Answer : B Explanation: The AWS Abuse team handles reports of AWS resources being used for malicious activities such as spam, port scanning, DDoS attacks, or hosting malware. This team is available to all customers regardless of support plan level. The Concierge team is for Enterprise Support billing inquiries. Customer Service handles general account issues. The Security team is an internal AWS team, not a customer-facing contact.
38. Select TWO examples of AWS shared controls.
- Patch Management
- IAM Management
- VPC Management
- Configuration Management
- Data Center operations
Answer : A, D Explanation: Shared controls are responsibilities that apply to both AWS and the customer. Patch Management (A) is shared — AWS patches the underlying infrastructure, while customers patch their guest OS and applications. Configuration Management (D) is also shared — AWS configures its infrastructure devices, while customers configure their own OS, databases, and applications. IAM and VPC management are customer responsibilities. Data Center operations are solely AWS’s responsibility.
39. In order to implement best practices when dealing with a “Single Point of Failure,” you should attempt to build as much automation as possible in both detecting and reacting to failure. Which of the following AWS services would help? (Choose TWO)
- ELB (Elastic Load Balancer)
- Auto Scaling
- Amazon Athena
- Amazon ECR
- Amazon EC2
Answer : A, B Explanation: Elastic Load Balancer (A) automatically distributes incoming traffic across multiple healthy instances, detecting and routing away from failed instances. Auto Scaling (B) automatically adds or removes EC2 instances based on demand or health checks, reacting to failures by replacing unhealthy instances. Amazon Athena is a query service, Amazon ECR is a container registry, and EC2 alone does not provide automated failure detection or reaction.
40. A company is planning to host an educational website on AWS. Their video courses will be streamed all around the world. Which of the following AWS services will help achieve high transfer speeds?
- Amazon SNS
- Amazon Kinesis Video Streams
- AWS CloudFormation
- Amazon CloudFront
Answer : D Explanation: Amazon CloudFront is a CDN service that caches content at Edge Locations around the world, enabling high-speed delivery of video and other content to global users with low latency. Amazon SNS is a notification service, Kinesis Video Streams is for live video ingestion and processing (not global content delivery), and CloudFormation is an infrastructure-as-code service.
41. A developer is planning to build a two-tier web application that has a MySQL database layer. Which of the following AWS database services would provide automated backups for the application?
- A MySQL database installed on an EC2 instance
- Amazon Aurora
- Amazon DynamoDB
- Amazon Neptune
Answer : B Explanation: Amazon Aurora is a MySQL and PostgreSQL-compatible relational database built for the cloud, and it provides automated backups to Amazon S3 continuously. A MySQL database on an EC2 instance (A) requires manual backup configuration. Amazon DynamoDB (C) is a NoSQL database, not MySQL-compatible. Amazon Neptune (D) is a graph database, not a relational database.
42. What is the AWS service that enables AWS architects to manage infrastructure as code?
- AWS CloudFormation
- AWS Config
- Amazon SES
- Amazon EMR
Answer : A Explanation: AWS CloudFormation allows architects to define and provision AWS infrastructure using code templates (JSON or YAML), implementing the Infrastructure as Code (IaC) practice. AWS Config monitors configuration compliance but does not provision infrastructure. Amazon SES is an email service. Amazon EMR is a big data processing platform.
43. Under the shared responsibility model, which of the following is the responsibility of AWS?
- Client-side encryption
- Configuring infrastructure devices
- Server-side encryption
- Filtering traffic with Security Groups
Answer : B Explanation: Under the AWS Shared Responsibility Model, AWS is responsible for configuring and maintaining the underlying infrastructure devices such as routers, switches, and physical servers. Client-side encryption (A), server-side encryption configuration (C), and Security Group configuration (D) are all customer responsibilities, as they relate to how the customer secures and configures their own applications and data.
44. What does the AWS Health Dashboard provide? (Choose TWO)
- Detailed troubleshooting guidance to address AWS events impacting your resources
- Health checks for Auto Scaling instances
- Recommendations for Cost Optimization
- A dashboard detailing vulnerabilities in your applications
- Personalized view of AWS service health
Answer : A, E Explanation: The AWS Health Dashboard provides a personalized view of the health of AWS services and resources in your account (E), and also provides detailed troubleshooting guidance for events that may impact your specific resources (A). Auto Scaling health checks are managed by Auto Scaling itself. Cost optimization recommendations come from AWS Trusted Advisor. Application vulnerability details are provided by Amazon Inspector.
45. You have deployed your application on multiple Amazon EC2 instances. Your customers complain that sometimes they can’t reach your application. Which AWS service allows you to monitor the performance of your EC2 instances to assist in troubleshooting these issues?
- AWS Lambda
- AWS Config
- Amazon CloudWatch
- AWS CloudTrail
Answer : C Explanation: Amazon CloudWatch is the AWS monitoring and observability service that collects metrics, logs, and events from EC2 instances and other AWS services. It allows you to set alarms and visualize performance data to troubleshoot issues. AWS Lambda is a serverless compute service. AWS Config tracks configuration changes. AWS CloudTrail logs API activity, not performance metrics.
46. Your company is developing a critical web application in AWS, and the security of the application is a top priority. Which of the following AWS services will provide infrastructure security optimization recommendations?
- AWS Shield
- AWS Management Console
- AWS Secrets Manager
- AWS Trusted Advisor
Answer : D Explanation: AWS Trusted Advisor provides real-time best practice recommendations across five categories: Cost Optimization, Performance, Security, Fault Tolerance, and Service Limits. For security, it can identify open security groups, unrestricted S3 buckets, and other vulnerabilities. AWS Shield is for DDoS protection. Secrets Manager manages credentials. The AWS Management Console is just the web UI for accessing AWS services.
47. Which of the following is NOT a benefit of Amazon S3? (Choose TWO)
- Amazon S3 provides unlimited storage for any type of data
- Amazon S3 can run any type of application or backend system
- Amazon S3 stores any number of objects, but with object size limits
- Amazon S3 can be scaled manually to store and retrieve any amount of data from anywhere
- Amazon S3 provides 99.999999999% (11 9’s) of data durability
Answer : B, D Explanation: Amazon S3 cannot run applications or backend systems (B) — it is an object storage service, not a compute service. S3 scales automatically, not manually (D). S3 does provide virtually unlimited storage (A), stores objects up to 5TB each (C), and offers 99.999999999% durability (E).
48. In the AWS Shared Responsibility Model, which of the following are the responsibility of the customer? (Choose TWO)
- Disk disposal
- Controlling physical access to compute resources
- Patching the network infrastructure
- Setting password complexity rules
- Configuring network access rules
Answer : D, E Explanation: Setting password complexity rules (D) for IAM users and configuring network access rules (E) such as Security Groups and NACLs are both customer responsibilities. Disk disposal (A), physical access control (B), and patching the underlying network infrastructure (C) are all AWS responsibilities as part of securing the physical and network layer of the cloud.
49. What does AWS provide to deploy popular technologies such as IBM MQ on AWS with the least amount of effort and time?
- Amazon Aurora
- Amazon CloudWatch
- AWS Quick Start reference deployments
- AWS OpsWorks
Answer : C Explanation: AWS Quick Start reference deployments are automated, gold-standard deployments of popular technologies on AWS, built by AWS solutions architects and partners. They use CloudFormation templates to deploy complex environments quickly with best practices built in. Amazon Aurora is a database service, CloudWatch is for monitoring, and OpsWorks is for configuration management using Chef and Puppet.
50. An organization has decided to purchase an Amazon EC2 Reserved Instance (RI) for three years in order to reduce costs. It is possible that the application workloads could change during the reservation period. What is the EC2 Reserved Instance (RI) type that will allow the company to exchange the purchased reserved instance for another reserved instance with higher computing power if they need to?
- Elastic RI
- Premium RI
- Standard RI
- Convertible RI
Answer : D Explanation: Convertible Reserved Instances allow customers to exchange their reserved instance for another with different attributes (instance type, OS, tenancy, or payment option) as long as the new instance is of equal or greater value. Standard Reserved Instances (C) offer a higher discount but cannot be exchanged. Elastic RI and Premium RI are not real AWS Reserved Instance types.
