AWS Certified Cloud Practitioner
CLF-C02 2026/2027: Comprehensive
Test Bank with Verified Practice
Questions
Question 1:
A financial institution requires a predictable, high-bandwidth connection between its
on-premises data center and AWS. The organization does not want its network traffic
to depend primarily on the public internet. Which AWS service best meets these
requirements?
A. Amazon Route 53
B. AWS Direct Connect
C. VPC peering
D. Amazon Connect
Correct Answer: B. AWS Direct Connect
Rationale: AWS Direct Connect establishes a dedicated network connection between
an organization’s premises and AWS, offering more consistent performance than an
internet-based connection. Route 53 provides DNS services, while VPC peering
connects VPCs rather than an on-premises network. Amazon Connect is a cloud
contact-center service and does not provide hybrid network connectivity.
Question 2:
A security team wants to continuously scan Amazon EC2 instances for known
software vulnerabilities and unintended network exposure. Which AWS service
should the team implement?
A. AWS Config
B. Amazon GuardDuty
C. Amazon Inspector
D. AWS Artifact
Correct Answer: C. Amazon Inspector
Rationale: Amazon Inspector automatically assesses supported workloads, including
EC2 instances, for software vulnerabilities and unintended network exposure. AWS
Config records and evaluates resource configurations but does not perform
vulnerability scanning. GuardDuty identifies suspicious or malicious activity, while
AWS Artifact provides access to AWS compliance reports and agreements.
,2026/2027
Question 3:
A company’s on-premises employees need low-latency access to shared files, but the
company has exhausted its local storage capacity. The company wants files stored in
AWS while frequently accessed data remains cached locally. Which solution is most
operationally efficient?
A. Mount individual Amazon S3 buckets on every workstation
B. Deploy an AWS Storage Gateway file gateway
C. Attach one Amazon EBS volume to all workstations
D. Move all employees to Amazon EC2 instances
Correct Answer: B. Deploy an AWS Storage Gateway file gateway
Rationale: A file gateway presents cloud-backed storage through standard file
protocols while maintaining a local cache for frequently accessed content. Mounting
separate S3 buckets increases administrative effort, and EBS volumes are not
designed for direct sharing with on-premises workstations. Moving users to EC2
would unnecessarily redesign their working environments.
Question 4:
An application running on an Amazon EC2 instance must upload reports to a specific
Amazon S3 bucket. Which approach follows AWS security best practices?
A. Embed an IAM user’s access keys in the application
B. Store access keys in a configuration file on the instance
C. Attach an IAM role with limited S3 permissions to the instance
D. Allow public write access to the S3 bucket
Correct Answer: C. Attach an IAM role with limited S3 permissions to the
instance
Rationale: An IAM role supplies temporary credentials to the EC2 application without
requiring stored long-term access keys. Permissions can be restricted to the required
bucket and actions. Embedded or locally stored keys can be exposed, while public
write access would allow unauthorized users or services to place objects in the bucket.
Question 5:
A company uses Amazon DynamoDB to store customer orders. Under the AWS
shared responsibility model, which task remains the company’s responsibility?
A. Replacing failed physical storage devices
B. Patching the DynamoDB operating environment
,2026/2027
C. Configuring access permissions for the tables
D. Maintaining the physical data center
Correct Answer: C. Configuring access permissions for the tables
Rationale: DynamoDB is a fully managed service, so AWS maintains the
infrastructure, hardware, operating environment, and physical facilities. The customer
remains responsible for security in the cloud, including IAM policies, table
permissions, data classification, and application-level controls. Therefore, controlling
who can access DynamoDB tables is the customer’s responsibility.
Question 6:
An organization is defining policies, decision rights, accountability structures, and
cloud financial controls for its migration program. Which AWS Cloud Adoption
Framework perspective is most directly involved?
A. Governance
B. Platform
C. People
D. Operations
Correct Answer: A. Governance
Rationale: The governance perspective helps an organization align cloud initiatives
with business requirements while establishing policies, decision-making structures,
accountability, risk controls, and financial management. The platform perspective
focuses on cloud architecture, people addresses skills and organizational change, and
operations focuses on running and supporting cloud workloads effectively.
Question 7:
A development team currently manages Docker containers and the underlying EC2
cluster. The team wants AWS to manage server provisioning and cluster capacity
while the developers specify only container resource requirements. Which service
should the team use?
A. AWS Lambda
B. AWS Fargate
C. Amazon Athena
D. Amazon RDS
Correct Answer: B. AWS Fargate
Rationale: AWS Fargate is a serverless compute engine for containers used with
Amazon ECS or Amazon EKS. It removes the need to provision and maintain
container hosts. Lambda runs functions rather than general container clusters, Athena
, 2026/2027
queries data in S3, and RDS provides managed relational databases rather than
container compute capacity.
Question 8:
A company installs a NoSQL database on Amazon EC2 instances. According to the
AWS shared responsibility model, which task is performed by AWS?
A. Patching the guest operating system
B. Configuring database replication
C. Patching the underlying physical infrastructure
D. Creating security group rules
Correct Answer: C. Patching the underlying physical infrastructure
Rationale: AWS secures and maintains the physical hosts, networking equipment,
facilities, and virtualization layer supporting EC2. The customer manages the guest
operating system, database software, security groups, replication, backups, and
application configuration. Running a database on EC2 therefore gives the customer
more administrative responsibility than using a managed database service.
Question 9:
A cloud administrator wants recommendations for reducing costs by selecting more
appropriate EC2 instance sizes based on historical utilization. Which two AWS tools
can provide relevant guidance?
A. AWS Cost Explorer
B. AWS Billing Conductor
C. Amazon CodeGuru
D. AWS Compute Optimizer
E. Amazon SageMaker
Correct Answer: A. AWS Cost Explorer and D. AWS Compute Optimizer
Rationale: Cost Explorer can present EC2 rightsizing recommendations and cost
trends, while Compute Optimizer analyzes utilization metrics to recommend
appropriate instance types and sizes. Billing Conductor supports customized billing
views. CodeGuru evaluates application code and runtime performance, and
SageMaker supports machine-learning development rather than EC2 cost-rightsizing
analysis.
Question 10:
A company wants an AWS tool that checks its environment for underutilized
resources and selected security risks, such as unrestricted ports or missing security
controls. Which service best meets the requirement?