CLF-C02 — Frequently Asked Questions

Community-vetted answers to 20 common questions about this exam.

Questions from real practice questions

Each Q&A comes from a specific community question — follow the link for its full analysis.

AWS Organizations for Cost Separation and Tracking

Tagging requires strict governance and continuous monitoring to ensure all resources are tagged correctly. It adds operational overhead compared to the automatic separation provided by separate accounts.

No. Consolidated billing aggregates payments into one bill, but each linked account retains its own separate detailed invoice and cost breakdown, preserving visibility per business unit.

AWS CAF Business Perspective Capability

Program and project management is categorized under the Governance perspective in AWS CAF, which focuses on managing resources and processes rather than direct business value creation.

It focuses on aligning IT with business needs, linking investments to key business results, and leveraging capabilities like data science for decision-making.

AWS IAM Identity Center for Centralized Workforce Access

Cognito is designed for external customer apps, whereas IAM Identity Center is built for internal workforce management and multi-account access.

It refers to internal employees who need access to corporate AWS accounts, requiring an enterprise-grade identity solution like IAM Identity Center.

AWS Cloud Cost-Effectiveness Principles

Patching is a security responsibility under the shared model. While it saves labor, it is not a primary economic driver like variable pricing or economies of scale.

No, deploying globally affects latency and reach. It does not inherently reduce costs compared to local deployment.

AWS Well-Architected Framework Pillars Identification

Operational Excellence focuses on people, processes, and tools to support continuous improvement. Reliability focuses on the system's ability to recover from failures and maintain performance.

Look for phrases like 'continuous improvement', 'iterative improvements', 'learning', and 'operating effectively' in the context of processes and procedures.

AWS Shared Responsibility for Amazon RDS

Yes, Amazon RDS automatically manages the maintenance of the guest operating system, including applying security patches and updates.

It refers to customer responsibilities such as managing data encryption, configuring security groups, and creating IAM policies for access control.

Launching Third-Party IDS in AWS

Quick Starts automate deployments of best-practice architectures, often using AWS-native services. While some partners have listings there, AWS Marketplace is the dedicated storefront for buying and licensing third-party software.

No. AWS Security Center (or GuardDuty/Security Hub) are native AWS security management services. They do not provide a mechanism to purchase or install software from external third-party vendors.

AWS Transit Gateway for Simplified VPC and On-Premises Connectivity

Direct Connect connects on-premises to AWS but does not simplify VPC-to-VPC peering. Transit Gateway is needed for multi-VPC hub-and-spoke architecture.

It doesn't replace peering technically, but it simplifies the topology by acting as a central hub, avoiding the need for full-mesh peering connections.

Lowest Cost S3 Storage Class for Rare Access

Intelligent-Tiering has retrieval fees for the Archive Access Tier. For known rare access (twice/year), Glacier Instant Retrieval's lower storage rate outweighs these fees.

Yes, Glacier Deep Archive is cheaper for storage, but it has slower retrieval times (minutes to hours). This question implies need for standard access, and Deep Archive wasn't an option.

Identifying On-Premises to Hybrid Cloud Migration

Cloud native implies using cloud-specific services and architectures exclusively. Since the solution retains on-premises components, it is hybrid, not pure cloud native.

A hybrid cloud architecture integrates at least one public cloud service with existing on-premises infrastructure, allowing data and applications to be shared between them.

Ready to practice?

Access 120 CLF-C02 questions with instant feedback and detailed explanations.

View CLF-C02 Practice Questions →

← Back to CLF-C02 AWS Certified Cloud Practitioner Study Guide