AWS Cloud Practitioner Master Guide 2026
AWS Certified Cloud Practitioner (CLF-C02) is a foundational certification for broad AWS Cloud knowledge, not a hands-on architect or administrator exam.
- It has 65 multiple-choice or multiple-response questions in 90 minutes; 50 are scored and 15 are unscored.
- A scaled score of 700 out of 1,000 passes.
- The four domains cover cloud concepts, security, services, and billing.
On this page17 sections
- What the Cloud Practitioner certification demonstrates
- The four CLF-C02 content domains
- Domain 1: Cloud Concepts
- Domain 2: Security and Compliance
- Domain 3: Cloud Technology and Services
- Domain 4: Billing, Pricing, and Support
- Original scenario: select a cost tool
- Original scenario: apply shared responsibility
- Scoring and interpreting results
- A practical study path
- Exam-day pacing and response strategy
- What the certification does not establish
- Who should consider CLF-C02
- Distinguish common service categories
- Understand availability, elasticity, and scale
- Original scenario: choose a resilience concept
- Read the service reference without trying to master every feature
What the Cloud Practitioner certification demonstrates
AWS Certified Cloud Practitioner is a foundational credential that validates a high-level understanding of AWS Cloud, services, and terminology. The current exam is CLF-C02. AWS describes it as suitable for candidates new to cloud who may not have an IT background, as well as line-of-business professionals who work with technical teams or customers. Up to six months of AWS exposure is the target profile, but prior cloud experience is not required.
The credential is useful for building a common vocabulary: what cloud computing changes, how AWS organizes infrastructure and services, where security responsibilities sit, and how costs and support work. It is not designed to prove that a candidate can deploy an application, troubleshoot a production incident, write code, or design a cloud architecture. AWS lists those implementation-oriented tasks outside the target candidate's scope for this exam.
| Exam fact | CLF-C02 detail |
|---|---|
| Level | Foundational |
| Questions presented | 65 total: 50 scored and 15 unscored |
| Question formats | Multiple choice and multiple response |
| Time | 90 minutes |
| Score | Scaled from 100 to 1,000; minimum passing score is 700 |
| Unanswered items | Scored as incorrect; there is no penalty for guessing |
| Delivery | Pearson VUE test center or online proctored appointment |
| Validity | AWS certification is valid for three years |
The 15 unscored items are not identified during the exam, so treat every question as if it affects your result. The multiple-response format can require selecting two or more correct choices from five or more options. Read the instruction carefully and select the complete set requested. Leaving a question blank counts as incorrect, while guessing has no additional penalty, so answer every item.
The four CLF-C02 content domains
| Domain | Weight of scored content | What it broadly covers |
|---|---|---|
| 1. Cloud Concepts | 24% | Cloud value, AWS design principles, migration approaches, and cloud economics |
| 2. Security and Compliance | 30% | Shared responsibility, governance, access management, compliance resources, and security services |
| 3. Cloud Technology and Services | 34% | Deployment and infrastructure, compute, database, networking, storage, analytics, AI/ML, and other in-scope services |
| 4. Billing, Pricing, and Support | 12% | Pricing models, budgets and cost tools, billing resources, support plans, and partner roles |
Domain percentages apply to scored content. Cloud Technology and Services has the largest weight, followed by Security and Compliance. That helps prioritize study time, but do not ignore Billing, Pricing, and Support. The percentages are not promises of an exact item count on an individual's form, and AWS uses compensatory scoring: section feedback is diagnostic, but the candidate needs to pass the overall exam rather than each section separately.
Domain 1: Cloud Concepts
Cloud Concepts asks candidates to explain the value of AWS Cloud, identify design principles, understand migration strategies, and reason about cloud economics. AWS highlights elasticity, agility, global reach, high availability, and the Well-Architected Framework. Learn the six pillars by their purpose: operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability. Questions can ask which principle or benefit best matches a business requirement.
Migration is not one single activity. An organization may move an application with limited changes, modify it, replace it with a managed service, or retain some workloads on premises. The exam guide calls out cloud adoption strategies, resources that support migration, database replication, and the AWS Cloud Adoption Framework. Learn why a migration occurs and match an approach to constraints; this exam does not require you to execute a detailed migration.
Cloud economics includes fixed and variable costs, on-premises expenses, licensing choices such as Bring Your Own License versus included licensing, rightsizing, automation, and economies of scale. A cloud bill is not automatically lower. The organization must select appropriate resources, control usage, and consider data transfer, storage classes, and operating costs. A question asking how to understand a planned architecture's price points toward a pricing estimate; a question asking how to inspect historical spending points toward a cost-analysis tool.
For example, a company running a lightly used development server all night may pay for compute capacity that sits idle. Rightsizing the instance or stopping it outside working hours can reduce waste. A different application with unpredictable bursts may value elastic capacity more than a fixed, always-on configuration. The exam tests the economic idea and tool purpose, not a guarantee that every cloud design costs less than an on-premises alternative.
Domain 2: Security and Compliance
Security and Compliance covers the shared responsibility model, cloud governance, compliance concepts, IAM capabilities, and AWS security resources. The foundational rule is that responsibility depends on the service. AWS is responsible for security of the cloud, including the physical infrastructure and managed layers it operates. Customers remain responsible for what they put in the cloud and the configuration and data controls assigned to them.
On Amazon EC2, the customer manages the guest operating system, patching, applications, and security group configuration. With a more managed service such as AWS Lambda, AWS operates more of the underlying stack, while the customer still manages code, identities, permissions, data, and configuration relevant to the application. For a database service such as Amazon RDS, the split differs again. Do not memorize a single responsibility boundary for all services.
Learn the roles of the root user, IAM users and roles, policies, groups, least privilege, multi-factor authentication, and federated access. Protect the root user and avoid using it for everyday tasks. Know service categories: AWS CloudTrail records account activity, AWS Config tracks resource configuration and evaluates rules, Amazon CloudWatch monitors metrics and logs, AWS Artifact provides compliance reports, and services such as GuardDuty, Security Hub, Shield, WAF, and Inspector address different security needs. The exam tests purpose and fit at a foundational level.
AWS and the customer also share responsibility for controls and compliance evidence. AWS supplies documentation about its environment; customers evaluate how those controls work in their own architecture and meet their legal and business requirements. Using AWS does not automatically make a customer's system compliant. The customer still configures access, classifies and protects data, and chooses services appropriate to regulatory obligations.
Domain 3: Cloud Technology and Services
This domain covers how people access and operate AWS, the global infrastructure, and the purpose of services across major categories. Distinguish a Region, a geographically separate area, from an Availability Zone, an isolated location within a Region, and an edge location used to bring content or services closer to users. Multi-AZ designs support availability within a Region; multiple Regions may support recovery, latency, or data-residency requirements.
| Need in a scenario | Common AWS service or concept |
|---|---|
| Virtual machines and control of the operating system | Amazon EC2 |
| Event-driven code without managing servers | AWS Lambda |
| Managed relational database | Amazon RDS or Amazon Aurora |
| Managed NoSQL key-value/document use cases | Amazon DynamoDB |
| Object storage | Amazon S3 |
| Block storage for an EC2 instance | Amazon EBS |
| Shared file storage | Amazon EFS or Amazon FSx, depending on need |
| Virtual private network boundary | Amazon VPC |
| Domain registration and DNS routing | Amazon Route 53 |
| Global content delivery | Amazon CloudFront |
The point is to recognize service fit, not memorize every feature or configuration setting. EC2 provides virtual servers; ECS and EKS support container orchestration; Fargate runs containers without customers managing the underlying server fleet; Lambda supports event-driven serverless code. Auto Scaling adjusts capacity as demand changes, while load balancers distribute incoming requests across targets.
Storage choices differ. S3 stores objects, EBS provides block volumes for compute, and EFS or FSx offer file-system services for different workloads. S3 storage classes provide different access and cost characteristics; lifecycle policies can transition or expire objects. AWS Backup helps centralize and automate protection for supported resources. Know whether a prompt asks for object, block, or file storage before choosing a service.
The outline also names analytics and AI/ML, application integration, business applications, developer tools, end-user computing, frontend and mobile, IoT, and support services. At the exam's intended depth, recognize what services accomplish: SQS queues messages, SNS publishes notifications, EventBridge routes events, Athena queries data in S3, Kinesis handles streaming data, Glue supports data integration, and QuickSight provides business intelligence visualization. The outline's service-reference lists define the scope; this is not a requirement to configure each service.
Domain 4: Billing, Pricing, and Support
Billing questions connect pricing models, cost tools, account structures, and help resources. Know the basic use of On-Demand, Reserved Instances, Spot Instances, Savings Plans, Dedicated Hosts, Dedicated Instances, and Capacity Reservations. Each meets a different mix of commitment, flexibility, interruption tolerance, and capacity need. Do not assume that the lowest unit price is right if a workload is unpredictable or cannot tolerate interruption.
AWS Pricing Calculator estimates future service costs from a proposed design. Cost Explorer helps analyze historical or current spending patterns. AWS Budgets can set cost or usage thresholds and notify when limits are approached or exceeded. Cost allocation tags identify business dimensions such as department or project in billing data. AWS Organizations supports multiple accounts and consolidated billing. The AWS Cost and Usage Report provides detailed billing information.
Support resources include AWS documentation, Knowledge Center, Prescriptive Guidance, re:Post, AWS Support Center, and paid support plans. Trusted Advisor offers recommendations in areas such as cost optimization and service limits; AWS Health Dashboard reports events that can affect resources. AWS Partners, including independent software vendors and systems integrators, can provide products and implementation assistance. Identify the right resource for the need rather than treating all support options as interchangeable.
Original scenario: select a cost tool
A nonprofit is planning to launch a new web application and wants a rough cost estimate before choosing its architecture. The finance manager also wants monthly alerts if actual AWS spending approaches a department limit. Which two tools best fit those separate needs?
- A. AWS Pricing Calculator for the planned design and AWS Budgets for threshold alerts.
- B. Cost Explorer for the future architecture and CloudTrail for budget alerts.
- C. AWS Artifact for estimating virtual machine charges and AWS Config for consolidated billing.
- D. Trusted Advisor for calculating a full application quote and Route 53 for cost notifications.
Best answer: A. Pricing Calculator estimates future costs based on a planned architecture. AWS Budgets monitors cost or usage against thresholds and can generate alerts. Cost Explorer is better for exploring spending data that has already been recorded. CloudTrail logs account activity, Artifact provides compliance reports, Config tracks configuration, and Route 53 handles DNS and routing. The distractors name real services but mismatch the requested job.
Original scenario: apply shared responsibility
A company stores customer files in Amazon S3. It wants to prevent public access and ensure that only a small finance group can read a sensitive bucket. Which responsibility belongs to the customer?
- A. Physically secure the AWS data center where the bucket's storage hardware is located.
- B. Configure access policies and identities appropriately and protect the data stored in the bucket.
- C. Maintain the underlying storage device firmware in the AWS facility.
- D. Replace AWS's physical environmental monitoring controls.
Best answer: B. AWS operates the underlying facilities and service infrastructure, but the customer configures identities, policies, and data protection for its use of S3. The other actions concern the physical infrastructure operated by AWS. Shared responsibility is service dependent, but a customer never delegates every access and data decision simply by choosing cloud storage.
Scoring and interpreting results
AWS reports a pass or fail and a scaled score from 100 to 1,000; 700 is the passing threshold. The score is not a raw percentage. AWS uses scaled scoring to help equate forms that may differ slightly in difficulty. Domain-level feedback may indicate relative strengths and weaknesses, but the exam uses compensatory scoring: a candidate does not need to pass each domain independently.
The 65 presented questions include 15 unscored items, which are not marked during the exam. Since candidates cannot distinguish them, treat every item seriously. Unanswered questions are scored incorrect, and AWS states there is no penalty for guessing. A practice score cannot be converted directly to an official 700 score, so use practice to identify gaps rather than predict an exact outcome.
A practical study path
Start with the official CLF-C02 exam guide. Read the domain tasks and service references, then mark what you can already explain and what is unfamiliar. AWS Skill Builder provides a four-step Exam Prep Plan, official practice questions, an official pretest, digital courses, and the official practice exam. AWS also points candidates to Builder Labs, Cloud Quest, AWS Jam, SimuLearn, flashcards, and instructor walkthroughs as learning options. Use the exam guide to keep optional training tied to assessed scope.
- Learn the cloud concepts and distinguish availability, elasticity, scalability, agility, and global reach.
- Study the shared responsibility model and core identity, compliance, logging, and security service purposes.
- Group services by job: compute, storage, database, network, analytics, messaging, and support.
- Practice pricing and account tools with short scenarios: estimate a future design, inspect past usage, set an alert, or allocate costs.
- Use original or official question sets, read every explanation, and track confusion by domain and service purpose.
- Take a timed practice test, review weak areas, and confirm exam appointment details before test day.
The certification is foundational, so prioritize conceptual understanding over deep configuration. You should be able to match a common business need to a service category and explain the tradeoff in plain language. Hands-on exploration can make those concepts concrete, but avoid spending most preparation time building architectures or troubleshooting tasks that AWS lists outside the target exam scope.
Exam-day pacing and response strategy
Ninety minutes for 65 questions gives an average of about 83 seconds each. Multiple-response questions can take longer because you must evaluate each option, so answer simpler items efficiently. Read whether the item asks for one response or multiple responses, identify the business requirement, eliminate choices that solve a different problem, and select all options required by the prompt. Leave no question blank; an unanswered response is incorrect.
Do not let a service name alone trigger an answer. Read the need: object storage, managed relational database, queueing, notification, DNS, content delivery, historical cost analysis, or future estimate. Several services may sound related, but the requested outcome distinguishes them. If unsure, make the best choice, mark it for review if the exam interface permits, and continue while protecting time for the full set.
What the certification does not establish
A passing result shows foundational AWS knowledge. It does not certify that the holder can design production architectures, perform incident response, administer a workload, or code cloud applications. AWS positions associate-level certifications such as Solutions Architect, Developer, and SysOps Administrator as possible next steps for candidates pursuing those role paths. Practical skill comes from further study and work, and a certification alone does not guarantee a job, salary, or promotion.
The credential is valid for three years. AWS currently lists recertification by passing the latest Cloud Practitioner exam or a qualifying Associate- or Professional-level exam before expiration. Certification holders also receive a 50 percent discount on other AWS certification exams according to AWS's certification page. Confirm current recertification and scheduling rules through the AWS Certification account because program details can change.
Who should consider CLF-C02
The exam can help someone new to cloud create a foundation, and it can help sales, marketing, product, project, procurement, or compliance staff communicate about AWS services and costs. It can also be a structured vocabulary check for early-career technology staff. Candidates seeking implementation depth should view Cloud Practitioner as an introductory step rather than a substitute for role-specific training and practice.
Distinguish common service categories
A major study task is recognizing service purpose from the business need. Start with categories, then learn representative names. For compute, compare virtual servers such as EC2, containers, serverless functions, and managed application platforms. For databases, distinguish relational workloads, key-value or document access patterns, and in-memory caching. For storage, identify whether the application needs object, block, or file storage. For connectivity, separate network isolation and routing from DNS and content delivery.
| Requirement in a question | How to reason about the category |
|---|---|
| Keep uploaded photos and documents durably as objects | Object storage; Amazon S3 is the core example |
| Attach a disk volume to a virtual server | Block storage; Amazon EBS is the familiar option |
| Share files among Linux servers | Managed file storage such as Amazon EFS may fit |
| Run a conventional application with operating-system control | Virtual compute such as Amazon EC2 |
| Run code when an event occurs without managing servers | Serverless compute such as AWS Lambda |
| Route user requests to the closest content copy | Content delivery through Amazon CloudFront |
| Resolve a domain name and direct traffic | DNS through Amazon Route 53 |
| Decouple services by holding messages until consumers process them | A queue such as Amazon SQS |
The exam guide includes many service names, but candidates do not need to treat each as an isolated flashcard. Learn the function, then compare close alternatives. SNS is for publish-and-subscribe notifications, while SQS holds messages in a queue for consumers. CloudWatch monitors metrics, logs, and events; CloudTrail records API and account activity. A service can participate in a broader solution, but a clear requirement usually points to its primary role.
Understand availability, elasticity, and scale
Availability means a service can be accessed when needed; resilience is its ability to withstand or recover from disruption. Elasticity is the ability to add or remove capacity as demand changes. Scalability describes the ability to handle growth by increasing resources. Agility refers to the speed and flexibility of provisioning and changing resources. These terms overlap in business value, but they are not interchangeable in a question.
For example, an online store expects a seasonal traffic spike. Auto Scaling can adjust compute capacity, while a load balancer distributes requests across healthy targets. A multi-AZ design can reduce dependence on a single location within a Region. CloudFront can improve content delivery to geographically distributed users. The best choice depends on whether the prompt emphasizes variable capacity, traffic distribution, fault tolerance, or global latency.
Original scenario: choose a resilience concept
A news site has users in several countries and wants images to load quickly from locations near readers. It also expects sudden traffic increases when a major story breaks. Which two ideas most directly address these needs?
- A. Use a content delivery network for cached content and scale application capacity as demand changes.
- B. Store all images in an EBS volume attached to one server and reserve fixed capacity for average traffic.
- C. Use AWS Artifact to distribute images and CloudTrail to add compute capacity.
- D. Use one Availability Zone and disable scaling to keep costs constant.
Best answer: A. A content delivery network such as CloudFront can serve cached content closer to users, and scaling addresses variable demand. The remaining options confuse service purposes or weaken availability. EBS is block storage associated with compute, Artifact is for compliance reports, and CloudTrail logs account activity. The question asks for global delivery and elasticity, not a detailed architecture.
Read the service reference without trying to master every feature
AWS's CLF-C02 guide includes in-scope and out-of-scope service lists and technology concepts. Use them as boundaries. Learn the purpose of in-scope services and how they relate to common business problems. If a service appears only in an advanced configuration guide, do not assume that every feature is tested at the foundational level. The target profile and task statements emphasize broad knowledge, not implementation expertise.
A useful preparation outcome is the ability to explain why a business would use cloud, who configures each security layer, which AWS service category addresses a requirement, and how an organization monitors and manages cost. If you can reason through those decisions in unfamiliar examples and complete the exam at a steady pace, your preparation is aligned to what CLF-C02 is designed to assess.
Common questions
What is the current AWS Cloud Practitioner exam code?
The current foundational exam is AWS Certified Cloud Practitioner CLF-C02.
How many questions and how much time are on CLF-C02?
The exam presents 65 questions and allows 90 minutes. Fifty questions are scored and 15 are unscored.
What score do I need to pass AWS Cloud Practitioner?
AWS reports a scaled score from 100 to 1,000, and 700 is the minimum passing score.
Do I need IT experience before taking Cloud Practitioner?
No. AWS says prior cloud experience is not required. The exam targets broad foundational knowledge rather than a specific job role.
Is CLF-C02 a hands-on technical exam?
No. AWS lists coding, architecture design, troubleshooting, implementation, and performance testing outside the target candidate's exam scope.
How long is AWS Cloud Practitioner certification valid?
AWS states that the certification is valid for three years. Check the current AWS Certification page for recertification options.