Skip to main content

AWS Certified Cloud Practitioner Exam (CLF-CO2)

Updated

Domains

  1. Cloud Concepts (24%)
  2. Security and Compliance (30%)
  3. Cloud Technology and Services (34%)
  4. Billing, Pricing, and Support (12%)

Domain 1: Cloud Concepts (24%)

Task Statement 1.1: Define the benefits of the AWS Cloud.

Knowledge of:

  • Valid proposition of the AWS Cloud

Skills in:

Task Statement 1.2: Identify design principles of the AWS Cloud.

Knowledge of:

Skills in:

  • Understanding the pillars of the Well-Architected Framework (for example, operational excellence, security, reliability, performance efficiency, cost optimization, sustainability)
  • Identifying differences between the pillars of the Well-Architected Framework

Task Statement 1.3: Understand the benefits of and strategies for migration to the AWS Cloud.

Knowledge of:

  • Cloud adoption strategies
  • Resources to support the cloud migration journey

Skills in:

  • Understanding the benefits of the AWS Cloud Adoption Framework (CAF) (for example, reduced business risk; improved environmental, social, and governance [ESG]performance; increased revenue; increased operational efficiency)
  • Identifying appropriate migration strategies (for example, database replication, use of AWS Snowball)

Task Statement 1.4: Understand concepts of cloud economics.

Knowledge of:

  • Aspects of cloud economics
  • Cost savings of moving to the cloud

Skills in:

  • Understanding the role of fixed costs compared with variable costs
  • Understanding costs that are associated with on-premises environments
  • Understanding the differences between licensing strategies (for example, Bring Your Own License [BYOL] model compared with included licenses)
  • Understanding the concept of Right-sizing
  • Identifying benefits of automation (for example, provisioning and configuration management with AWS CloudFormation)
  • Identifying managed AWS services (for example, Amazon RDS, Amazon Elastic Container Service [Amazon ECS], Amazon Elastic Kubernetes Service [Amazon EKS], Amazon DynamoDB)

Domain 2: Security and Compliance (30%)

Task Statement 2.1: Understand the AWS shared responsibility model.

Knowledge of:

Skills in:

  • Recognizing the components of the AWS shared responsibility model
  • Describing the customer’s responsibilities on AWS
  • Describing AWS responsibilities
  • Describing responsibilities that the customer and AWS share
  • Describing how AWS responsibilities and customer responsibilities can shift, depending on the service used (for example, Amazon RDS, AWS Lambda, Amazon EC2)

Task Statement 2.2: Understand AWS Cloud security, governance, and compliance concepts.

Knowledge of:

  • AWS compliance and governance concepts
  • Benefits of cloud security (for example, encryption)
  • Where to capture and locate logs that are associated with cloud security

Skills in:

  • Identifying where to find AWS compliance information (for example, AWS Artifact)
  • Understanding compliance needs among geographic locations or industries (for example, AWS Compliance)
  • Describing how customers secure resources on AWS (for example, Amazon Inspector, AWS Security Hub, Amazon GuardDuty, AWS Shield)
  • Identifying different encryption options (for example, encryption in transit, encryption at rest)
  • Recognizing services that aid in governance and compliance (for example, monitoring with Amazon CloudWatch; auditing with AWS CloudTrail, AWS Audit Manager, and AWS Config; reporting with access reports)
  • Recognizing compliance requirements that vary among AWS services

Task Statement 2.3: Identify AWS access management capabilities.

Knowledge of:

  • Identity and access management (for example, AWS Identity and Access Management [IAM])
  • Importance of protecting the AWS root user account
  • Principle of least privilege
  • AWS IAM Identity Center (AWS Single Sign-On)

Skills in:

  • Understanding access keys, password policies, and credential storage (for example, AWS Secrets Manager, AWS Systems Manager)
  • Identifying authentication methods in AWS (for example, multi-factor authentication [MFA], IAM Identity Center, cross-account IAM roles)
  • Defining groups, users, custom policies, and managed policies in compliance with the principle of least privilege
  • Identifying tasks that only the account root user can perform
  • Understanding which methods can achieve root user protection
  • Understanding the types of identity management (for example, federated)

Task Statement 2.4: Identify components and resources for security.

Knowledge of:

  • Security capabilities that AWS provides
  • Security-related documentation that AWS provides

Skills in:

Domain 3: Cloud Technology and Services (34%)

Task Statement 3.1: Define methods of deploying and operating in the AWS Cloud.

Knowledge of:

  • Different ways of provisioning and operating in the AWS Cloud
  • Different ways to access AWS services
  • Types of cloud deployment models
  • Connectivity options

Skills in:

Task Statement 3.2: Define the AWS global infrastructure.

Knowledge of:

Skills in:

  • Describing relationships among Regions, Availability Zones, and edge locations
  • Describing how to achieve high availability by using multiple Availability Zones
  • Recognizing that Availability Zones do not share single points of failure
  • Describing when to use multiple Regions (for example, disaster recovery, business continuity, low latency for end users, data sovereignty)
  • Describing at a high level the benefits of edge locations (for example, Amazon CloudFront, AWS Global Accelerator)

Task Statement 3.3: Identify AWS compute services.

Knowledge of:

  • AWS compute services

Skills in:

  • Recognizing the appropriate use of different EC2 instance types (for example, compute optimized, storage optimized)
  • Recognizing the appropriate use of different container options (for example, Amazon ECS, Amazon EKS)
  • Recognizing the appropriate use of different serverless compute options (for example, AWS Fargate, Lambda)
  • Recognizing that auto scaling provides Elasticity
  • Identifying the purposes of load balancers

Task Statement 3.4: Identify AWS database services.

Knowledge of:

  • AWS database services
  • Database migration

Skills in:

Task Statement 3.5: Identify AWS network services.

Knowledge of:

  • AWS network services

Skills in:

Task Statement 3.6: Identify AWS storage services.

Knowledge of:

  • AWS storage services

Skills in:

Task Statement 3.7: Identify AWS artificial intelligence and machine learning (AI/ML) services and analytics services.

Knowledge of:

  • AWS AI/ML services
  • AWS analytics services

Skills in:

Task Statement 3.8: Identify services from other in-scope AWS service categories.

Knowledge of:

Skills in:

  • Choosing the appropriate service to deliver messages and to send alerts and notifications
  • Choosing the appropriate service to meet business application needs
  • Choosing the appropriate service for AWS customer support
  • Choosing the appropriate option for business support assistance
  • Identifying the tools to develop, deploy, and troubleshoot applications
  • Identifying the services that can present the output of virtual machines (VMs) on end-user machines
  • Identifying the services that can create and deploy frontend and mobile services
  • Identifying the services that manage IoT devices

Domain 4: Billing, Pricing, and Support (12%)

Task Statement 4.1: Compare AWS pricing models.

Knowledge of:

Skills in:

  • Identifying and comparing when to use various compute purchasing options
  • Describing Reserved Instance flexibility
  • Describing Reserved Instance behavior in AWS Organizations
  • Understanding incoming data transfer costs and outgoing data transfer costs (for example, from one Region to another Region, within the same Region)
  • Understanding different pricing options for various storage options and tiers

Task Statement 4.2: Understand resources for billing, budget, and cost management.

Knowledge of:

Skills in:

Task Statement 4.3: Identify AWS technical resources and AWS Support options.

Knowledge of:

  • Resources and documentation available on official AWS websites
  • AWS Support plans
  • Role of the AWS Partner Network, including independent software vendors and system integrators
  • AWS Support Center

Skills in:

  • Locating AWS whitepapers, blogs, and documentation on official AWS websites
  • Identifying and locating AWS technical resources (for example, AWS Prescriptive Guidance, AWS Knowledge Center, AWS re:Post)
  • Identifying AWS Support options for AWS customers (for example, customer service and communities, AWS Developer Support, AWS Business Support, AWS Enterprise On-Ramp Support, AWS Enterprise Support)
  • Identifying the role of Trusted Advisor, AWS Health Dashboard, and the AWS Health API to help manage and monitor environments for cost optimization
  • Identifying the role of the AWS Trust and Safety team to report abuse of AWS resources
  • Understanding the role of AWS Partners (for example, AWS Marketplace, independent software vendors, system integrators)
  • Identifying the benefits of being an AWS Partner (for example, partner training and certification, partner events, partner volume discounts)
  • Identifying the key services that AWS Marketplace offers (for example, cost management, governance and entitlement)
  • Identifying technical assistance options available at AWS (for example, AWS Professional Services, AWS Solutions Architects)

Key Tools, Technologies, and Concepts

Non-exhaustive. Order implies no weight or importance.

In-Scope AWS Services and Features

Analytics:

Application Integration:

Business Productivity:

Compute:

Containers:

Cost Management:

Customer Engagement:

Database:

Developer Tools:

End-User Computing:

Frontend Web and Mobile:

Internet of Things (IoT):

Machine Learning:

Management and Governance:

Migration and Transfer:

Networking and Content Delivery:

Security, Identity, and Compliance:

Serverless:

Storage:

Question Types and Examples

  • The exam has only two question formats
    • Multiple choice — 4 options, exactly 1 correct, 3 distractors.
    • Multiple response — 5 or more options, 2 or more correct; you must select every correct one, no partial credit.
    • Unscored questions: 15 of the 65 are unscored pretest items that do not count. You cannot tell which, so answer all.
    • There is no penalty for guessing — never leave a question blank.
  • Logistics worth memorizing
    • 65 questions, 90 minutes. Passing score 700 out of 1000 (scaled, not a raw percentage).
    • Result is pass/fail; the scaled score shows how far above or below the line you landed.

How the distractors are built

  • The wrong answers are usually real AWS services in the wrong role
    • The test rarely invents fake services. It offers a real service that does a similar-sounding job.
    • This is why the “vs” contrasts in these notes matter more than any single definition.
  • Recurring distractor traps
    • Monitoring question → offers Amazon CloudWatch (performance) vs AWS CloudTrail (who did what) vs AWS Config (resource state). Pick by the verb: slow → CloudWatch, who deleted → CloudTrail, did it drift → Config.
    • “Block a specific IP” → network ACLs, because security groups cannot deny.
    • “Cheapest and interruption is fine” → Spot Instances; if interruption is unacceptable, Spot is always wrong.
    • “Designated TAM” → Enterprise AWS Support only; “pool of TAMs” → Enterprise On-Ramp.
    • Root-user-only tasks, and “which is AWS’s responsibility vs yours” → AWS shared responsibility model.

Reading the question stem

  • Look for the qualifier that eliminates options
    • MOST cost-effective, LEAST operational overhead, fastest to set up, highest availability — several options “work”, only one fits the qualifier.
    • “Least operational overhead” almost always points at a serverless or fully managed option over a self-run one.
  • Map keyword to service
    • “GraphQL” → AWS AppSync. “Natural-language search of internal docs” → Amazon Kendra. “Serverless ETL” → AWS Glue. “In-memory durable” → Amazon MemoryDB for Redis. “Discover PII in S3” → Amazon Macie.
  • Ignore backstory
    • Company size, industry, and names are usually filler. Find the one technical requirement that decides the answer.

Worked examples

  • Multiple choice — cost economics
    • A company wants to stop guessing capacity and pay only for what it uses. Which cloud benefit is this?
    • A) High availability — B) Trade fixed costs for variable costs ✅ — C) Economies of Scale — D) Agility
    • Trap: C is true of AWS but does not describe pay-for-use; read what the stem actually asks.
  • Multiple choice — service selection
  • Multiple response — security (pick TWO)
    • Which are the customer’s responsibility under the AWS shared responsibility model?
    • A) Patching the Amazon S3 host OS — B) Configuring security groups ✅ — C) Client-side data encryption ✅ — D) Physical data center security — E) Hypervisor maintenance
    • A, D, E are all “security of the cloud” = AWS. Customer owns “security in the cloud”.
  • Multiple response — support/billing (pick TWO)

Study tactic

  • Drill the contrasts, not the definitions
    • Most losses come from confusing two similar services, not from never having heard of one.
    • For each “Not to be confused with” block in these notes, be able to state the one-line difference from memory.
  • Weight by domain
    • Security & Compliance is 30% and Cloud Technology & Services is 34% — together two-thirds of the exam. Spend time there before Billing (12%).
Practice Questions36 questions with answers you can reveal.

Linked from