Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

AWS Cloud Practitioner Exam Domains: CLF-C02 Outline

Updated 10 min read
Key takeaway

The CLF-C02 exam guide defines four domains: Cloud Concepts (24%), Security and Compliance (30%), Cloud Technology and Services (34%), and Billing, Pricing, and Support (12%).

  • Questions test foundational recognition and decisions, not hands-on implementation.
On this page8 sections
  1. The CLF-C02 outline at a glance
  2. Domain 1: Cloud Concepts - 24%
  3. Domain 2: Security and Compliance - 30%
  4. Domain 3: Cloud Technology and Services - 34%
  5. Domain 4: Billing, Pricing, and Support - 12%
  6. Worked domain decisions
  7. How to study the outline efficiently
  8. Questions candidates commonly ask

The CLF-C02 outline at a glance

The current AWS Certified Cloud Practitioner exam guide groups scored content into four domains. These percentages describe the approximate share of scored content assigned to each domain; they are useful for planning, not a promise that every form contains a fixed number of questions from each topic. The exam presents 65 items, of which 50 are scored and 15 are unscored, so do not try to infer the domain count of a particular form from the percentages.

DomainPublished weightWhat candidates should be able to do
1. Cloud Concepts24%Explain cloud value, design principles, and migration concepts
2. Security and Compliance30%Recognize security responsibilities, controls, identity, and compliance concepts
3. Cloud Technology and Services34%Identify AWS infrastructure, service categories, and common use cases
4. Billing, Pricing, and Support12%Understand cost tools, pricing models, billing support, and support plans

Domain 1: Cloud Concepts - 24%

This domain asks why organizations use cloud computing and how cloud changes the way they obtain technology. Be ready to distinguish agility, elasticity, scalability, high availability, and global reach. Agility is the ability to provision and change resources quickly. Elasticity is adjusting resources as demand rises or falls. Scalability is the capacity to accommodate growth. Availability concerns keeping a service accessible. A scenario may mention several benefits, but the best answer matches the business problem described.

For example, a retailer has unpredictable weekly demand and wants to avoid purchasing enough servers for its busiest hour. That points to elasticity and pay-for-use economics. A business expanding to users in new regions may value global infrastructure. A team that needs to experiment quickly may value agility. Do not answer every cloud-value question with “lower cost”: cloud can reduce upfront capital commitments, but a poorly managed cloud workload can still cost more than expected.

Know the broad cloud deployment and service models. Public cloud services are delivered by a provider over shared infrastructure with logically separated customer resources. Hybrid approaches connect on-premises environments with cloud resources. Infrastructure as a Service gives customers more responsibility for operating systems and applications; Platform as a Service abstracts more of the underlying platform; Software as a Service delivers a ready-to-use application. The exam tests the responsibility and abstraction distinction, not vendor marketing labels.

Migration questions often describe moving applications or data from a local environment to AWS. Understand the reasons organizations migrate-scalability, resilience, speed, global access, or reducing undifferentiated infrastructure work-and the fact that migration is a business and technical decision, not an automatic cost reduction. AWS global infrastructure concepts include Regions and Availability Zones. A Region is a separate geographic area; Availability Zones are distinct locations within a Region designed to support resilient architectures. A question about failure isolation is different from a question about serving users near their location.

Domain 2: Security and Compliance - 30%

Security is the largest domain in the published outline. Begin with the shared responsibility model. AWS is responsible for security of the cloud: the facilities, hardware, networking, and foundational services it operates. The customer is responsible for security in the cloud: customer data, identity and access choices, workload configuration, and other controls according to the service used. With managed services, AWS operates more of the stack, but the customer still controls important configuration and data decisions.

The service model changes the boundary. For an EC2 instance, AWS operates the physical host while the customer typically manages the guest operating system, patches it, configures security groups, and protects application data. With a managed database service, AWS handles more database infrastructure, while the customer still manages data access, credentials, and service settings. Do not treat “AWS service” as shorthand for “AWS handles every security task.” Identify the exact layer in the scenario.

Identity and Access Management (IAM) is the core service for controlling identities and permissions. Understand users, groups, roles, policies, and least privilege at a conceptual level. A role can grant temporary permissions to an AWS service or a trusted principal. A policy states allowed or denied actions on resources. Root-user protection and multifactor authentication are basic account security practices. If the problem is controlling who can perform an action, think identity and permissions before network security.

Know the broad purpose of encryption, logging, and compliance resources. Encryption protects data confidentiality; AWS Key Management Service (KMS) helps create and control encryption keys. CloudTrail records account activity and API events, supporting investigation of who did what. AWS Config can track resource configuration and evaluate it against rules. Security Hub aggregates security findings. GuardDuty detects potential threats using analyzed activity. These services are not interchangeable: audit history, configuration assessment, findings aggregation, and threat detection are different jobs.

Compliance questions ask what AWS makes available to support a customer’s own compliance work. AWS provides certifications, reports, and compliance information through resources such as AWS Artifact. A customer remains responsible for determining whether its own use of AWS satisfies applicable legal, regulatory, or contractual requirements. A provider certification does not automatically certify every customer workload. Match the answer to the control or evidence actually requested.

Domain 3: Cloud Technology and Services - 34%

This is the largest domain and spans the AWS global infrastructure, deployment methods, and service categories. Learn the purpose of common services rather than memorizing a deep configuration procedure. Compute examples include Amazon EC2 for virtual servers, AWS Lambda for event-driven serverless code, and Amazon ECS or EKS for container orchestration. Storage includes Amazon S3 for object storage, Amazon EBS for block storage used with EC2, and Amazon EFS for shared file storage. The first question is usually about workload need, not product feature minutiae.

Database categories also matter. Amazon RDS is managed relational database service; Amazon Aurora is a relational database compatible with MySQL and PostgreSQL; DynamoDB is a managed NoSQL key-value and document database; Redshift is for analytics and data warehousing. If a prompt describes transactions and relationships among records, a relational service may fit. If it emphasizes massive scale and flexible key-value access, DynamoDB may fit. If it describes analytical queries over large datasets, Redshift is more likely.

Networking and content delivery concepts include Amazon VPC for logically isolated virtual networking, security groups as stateful virtual firewalls for associated resources, and Amazon CloudFront for content delivery at edge locations. Route 53 provides DNS services. Direct Connect establishes a dedicated network connection from an organization to AWS; VPN connections use encrypted tunnels over the internet. A global website that must deliver cached content close to users points toward CloudFront, while name resolution points toward Route 53.

Application integration and analytics services appear as broad categories. Amazon SQS provides message queuing to decouple components; Amazon SNS supports pub/sub messaging and notifications. Amazon Kinesis supports streaming data use cases. Amazon Athena can query data in S3 using SQL, while AWS Glue supports data integration and cataloging. At this level, know the primary purpose and how services fit into a simple architecture. Do not assume the exam expects you to write code or design a production topology.

Management and deployment questions may describe provisioning resources consistently, monitoring performance, or deploying an application. AWS CloudFormation uses templates to provision infrastructure as code. CloudWatch collects metrics and logs and can trigger alarms. CloudTrail provides event history. AWS Systems Manager helps manage operational tasks across resources. Elastic Beanstalk can simplify application deployment. Distinguish deployment and management tools from the underlying compute resource being deployed.

Domain 4: Billing, Pricing, and Support - 12%

The billing domain has the smallest published weight but includes practical decisions candidates should understand. AWS pricing commonly reflects consumption, with different pricing options depending on service and commitment. On-Demand pricing avoids long-term commitment; Savings Plans and Reserved Instances can offer lower prices in exchange for defined commitment terms and applicable usage conditions; Spot Instances use spare EC2 capacity at discounts but can be interrupted. A workload’s flexibility and predictability matter when comparing options.

Recognize the primary cost tools. AWS Pricing Calculator estimates planned costs before deploying a solution. AWS Cost Explorer analyzes historical and forecast costs. AWS Budgets sets cost or usage thresholds and can notify users when conditions are reached. Cost and Usage Reports provide detailed billing and usage data. These tools serve distinct stages: estimate a design, understand spend trends, alert against a limit, and analyze detailed line items.

Know that consolidated billing through AWS Organizations can combine billing for multiple accounts and support management at the organization level. Cost allocation tags help categorize resources for reporting, but tags must be activated for cost allocation use. AWS Support plans differ in technical support and response options. Trusted Advisor provides checks and recommendations across categories such as cost optimization, security, fault tolerance, and service limits; the available checks depend on the current offering and plan.

Support questions require reading the business need carefully. A billing or account question may be answered through the AWS Support Center or documentation, while a production system interruption may require a support plan with an appropriate response target. Do not invent a guaranteed resolution time from a plan name. Understand that support plan levels describe access and response objectives, not a promise that AWS will repair a customer’s application.

Worked domain decisions

A company asks who patches the operating system on an EC2 instance. This is Domain 2: identify the service boundary and answer that the customer manages the guest operating system. If the same company asks who maintains the physical server, that is AWS security of the cloud. The service itself is the same; the layer in question changes the responsible party.

A development team wants to run code in response to an event without provisioning or managing servers. That is a Domain 3 service-selection question, and AWS Lambda is the direct category match. If instead the question asks why the team can increase or reduce capacity as traffic changes, it tests a Domain 1 benefit: elasticity. The scenario can mention one service and one concept; select what it asks for rather than what it happens to mention.

A manager wants to estimate the monthly cost of a proposed architecture before building it. Use the AWS Pricing Calculator. If the manager already has a running account and wants to compare past monthly spend by service, use Cost Explorer. If the requirement is an alert when a budget threshold is crossed, use AWS Budgets. The verbs estimate, analyze, and alert map to different tools.

How to study the outline efficiently

  1. Use the current CLF-C02 exam guide as the source of scope. Mark each task statement as understood, uncertain, or unfamiliar.
  2. Spend study time in proportion to both domain weight and your own weakness. Security and services together account for most of the published blueprint, but do not ignore cloud concepts or billing.
  3. Build comparison notes for services that solve adjacent problems: CloudTrail versus CloudWatch, Cost Explorer versus Budgets versus Pricing Calculator, RDS versus DynamoDB, and S3 versus EBS.
  4. For every service, learn its category, core use, one common alternative, and a boundary or responsibility. Avoid deep implementation labs unless they help clarify a foundational concept.
  5. Practice with new scenarios. Explain why the best answer matches the requirement and why the tempting alternatives do not.

The exam guide is a content outline, not a guarantee that every service name listed in study materials will appear or that each concept receives a fixed item count. AWS can revise exam content. Confirm that a course, book, or question set names CLF-C02 and aligns to the current exam guide. The goal is broad, accurate recognition and sound judgment at a foundational level.

Questions candidates commonly ask

The published weights are Cloud Concepts 24%, Security and Compliance 30%, Cloud Technology and Services 34%, and Billing, Pricing, and Support 12%. AWS may update the guide, so use the current CLF-C02 page when you book or begin a new study cycle.

No single domain guarantees a pass. The score is scaled and AWS describes scoring as compensatory, so candidates should prepare across the complete outline. Use the weights as a planning signal, not as permission to leave an entire domain unstudied.

Common questions

What is the current AWS Cloud Practitioner exam code?

The current foundational exam is AWS Certified Cloud Practitioner CLF-C02.

How many questions and how much time are on CLF-C02?

The exam presents 65 questions and allows 90 minutes. Fifty questions are scored and 15 are unscored.

What score do I need to pass AWS Cloud Practitioner?

AWS reports a scaled score from 100 to 1,000, and 700 is the minimum passing score.

Do I need IT experience before taking Cloud Practitioner?

No. AWS says prior cloud experience is not required. The exam targets broad foundational knowledge rather than a specific job role.

Is CLF-C02 a hands-on technical exam?

No. AWS lists coding, architecture design, troubleshooting, implementation, and performance testing outside the target candidate's exam scope.

How long is AWS Cloud Practitioner certification valid?

AWS states that the certification is valid for three years. Check the current AWS Certification page for recertification options.