CLF-C02 Exam Guide: Skills, Domains, and a Practical Study Roadmap
CLF-C02 is the AWS Certified Cloud Practitioner exam. It validates broad knowledge of AWS Cloud concepts, security and compliance, core services, and cloud economics rather than role-specific implementation ability. AWS describes it for candidates who can demonstrate overall AWS Cloud knowledge independently of a specific job role, including people with up to 6 months of exposure to AWS design, implementation, or operations. This guide helps you decide whether your current knowledge is ready, which domains deserve study time, and how to turn the official task statements into a focused preparation plan.
What CLF-C02 validates
CLF-C02 tests whether you can explain the value of AWS Cloud, apply the shared responsibility model, recognize the purpose of common AWS services, and understand billing and support resources. It is a foundational exam about identifying appropriate concepts and services, not about building or troubleshooting a production environment.
AWS identifies cloud concepts, security and compliance, core AWS services, and AWS Cloud economics as recommended knowledge areas. The official exam guide also describes the ability to understand the AWS Well-Architected Framework, security best practices, costs, billing practices, and common use cases for AWS services.
The intended audience is broader than a single technical job title. Someone beginning an AWS career may use the exam to establish vocabulary, while a project manager, sales professional, analyst, administrator, or person working with cloud teams may need the same baseline without becoming an architect or developer.
The target candidate may have up to 6 months of AWS Cloud design, implementation, or operations exposure. That is a description of the candidate profile, not a prerequisite that requires a particular employment history or amount of hands-on work.
Who should take it—and who should choose another target
Choose CLF-C02 when your immediate goal is broad AWS literacy and service recognition. Choose a more specialized path when your goal is to demonstrate hands-on architecture, development, administration, security engineering, or data work, because those activities are not what this foundational exam is designed to measure.
CLF-C02 can be a sensible first certification for a candidate who needs to communicate about cloud projects but does not yet own implementation decisions. It can also provide a structured checkpoint before pursuing an AWS Associate- or Professional-level certification.
Do not treat the exam as a coding assessment or an architecture-design assessment. AWS lists coding, cloud-architecture design, troubleshooting, implementation, and load and performance testing as out of scope. Preparation that spends most of its time writing application code or tuning workloads is therefore poorly aligned with the blueprint.
A practical decision rule is simple: if you can describe why a service or concept fits a scenario, but you are not expected to configure every setting, CLF-C02 may fit. If you need certification evidence for designing and operating detailed solutions, review the requirements for a role-specific AWS certification instead.
How the exam is structured
AWS states that the exam lasts 90 minutes and contains 65 questions consisting of multiple-choice and multiple-response items. The official documentation says 50 questions affect your score and the exam includes 15 unscored questions that do not affect your score; the unscored questions are not identified.
A multiple-choice question has one correct response and three incorrect responses. A multiple-response question has two or more correct responses out of five or more options. Read the instruction on each item instead of assuming that every question requires one selection.
Unanswered questions are scored as incorrect, and AWS states that there is no penalty for guessing. A practical exam-session habit is to select the best available answer before moving on. Do not let one uncertain item consume time that you need for several questions you can answer confidently.
Results are reported as a scaled score of 100–1,000, and the minimum passing score is 700. The score is reported for the exam as a whole. Any section-level performance information should be used cautiously; AWS specifically warns candidates when interpreting section-level feedback.
AWS offers CLF-C02 at Pearson VUE testing centers and through online proctoring. Confirm the current appointment, identification, environment, and delivery requirements with the official AWS certification and test-provider information before scheduling, because operational details can change.
Where the scored content is concentrated
Use the domain weights to allocate study time, but study the tasks inside each domain rather than memorizing the percentages. Cloud Technology and Services and Security and Compliance together represent most of the scored content, while Cloud Concepts and Billing, Pricing, and Support provide essential context and commonly connect to service-selection scenarios.
Content Domain 1: Cloud Concepts represents 24% of the scored content on the exam. It covers the value proposition of AWS Cloud, AWS design principles, migration benefits and strategies, and cloud economics.
Content Domain 2: Security and Compliance represents 30% of the scored content on the exam. It covers the shared responsibility model, security, governance and compliance concepts, access-management capabilities, and security components and resources.
Content Domain 3: Cloud Technology and Services represents 34% of the scored content on the exam. It covers deployment and operating methods, global infrastructure, compute, databases, networking, storage, AI/ML and analytics, and other in-scope service categories.
Content Domain 4: Billing, Pricing, and Support represents 12% of the scored content on the exam. It covers pricing models, billing and cost-management resources, and AWS technical resources and Support options.
These weights should influence your sequence, not eliminate a domain. A candidate who ignores Billing, Pricing, and Support may miss straightforward questions, while a candidate who studies only service names may lack the cloud concepts and security reasoning needed to choose between plausible answers.
What to learn in Cloud Concepts
Study Cloud Concepts as a set of business and design decisions: why an organization might use AWS, how cloud characteristics affect a solution, how migration is approached, and how cloud economics differs from owning infrastructure. The goal is to explain the benefit and recognize the appropriate concept in a scenario.
Task Statement 1.1 focuses on the benefits of AWS Cloud, including the value of global infrastructure and the advantages of high availability, elasticity, and agility. Build your notes around distinctions: high availability concerns continued access, elasticity concerns adjusting capacity, and agility concerns the ability to change and deploy more quickly.
Task Statement 1.2 addresses AWS design principles through the AWS Well-Architected Framework. Learn the differences among operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability. A useful study exercise is to take one scenario and state which pillar is most directly represented, then identify why the other pillars are not the primary answer.
Task Statement 1.3 covers cloud adoption strategies and migration resources, including the AWS Cloud Adoption Framework and appropriate migration strategies. Do not reduce migration to a single “move everything” action. Ask what is being migrated, what constraints exist, and whether the scenario implies replication, modernization, replacement, retention, or another strategy described by the study material.
Task Statement 1.4 covers fixed and variable costs, on-premises costs, licensing approaches such as Bring Your Own License compared with included licenses, rightsizing, automation, and economies of scale. Practice explaining why rightsizing and automation can affect cost without assuming that every cloud workload is automatically cheaper.
A strong revision artifact for this domain is a two-column decision sheet. In the first column, write the requirement—such as global reach, elasticity, or cost control. In the second, write the AWS concept or design principle that addresses it and one reason a tempting alternative is less suitable.
How to prepare for Security and Compliance questions
Security and Compliance requires responsibility mapping, identity fundamentals, governance awareness, and recognition of security services. Start with the shared responsibility model, then connect it to the service type: responsibilities can shift depending on whether the workload uses Amazon EC2, Amazon RDS, or AWS Lambda.
For Task Statement 2.1, make separate notes for AWS responsibilities, customer responsibilities, and responsibilities shared by both parties. The important reasoning pattern is that AWS secures the underlying cloud infrastructure while customers remain responsible for appropriate configuration and protection of their resources; the exact boundary changes with the service used.
Task Statement 2.2 includes AWS compliance and governance concepts, encryption at rest and in transit, and the location of security logs and compliance information. Associate AWS Artifact with compliance information, Amazon CloudWatch with monitoring, AWS CloudTrail with auditing activity, and AWS Config with configuration and compliance visibility.
Task Statement 2.3 focuses on access-management capabilities. Know why the root user requires protection, how MFA contributes to protection, what IAM users, groups, roles, managed policies, and custom policies represent, and how least privilege limits permissions. Also review IAM Identity Center, federated identity, access keys, password policies, and credential storage options such as AWS Secrets Manager and AWS Systems Manager.
Task Statement 2.4 covers security components and resources. Recognize the purposes of AWS WAF, AWS Firewall Manager, AWS Shield, Amazon GuardDuty, Amazon Inspector, and AWS Security Hub at a high level. The exam may test the service’s role, so learn the problem each service helps address rather than memorizing an isolated product description.
A frequent mistake is treating every security service as interchangeable. Build a comparison table with columns for threat detection, vulnerability assessment, web application filtering, DDoS protection, centralized security findings, and policy management. Then place each named service in the role that best matches its documented purpose.
Another mistake is answering a customer-configuration question with an AWS-infrastructure responsibility. For each practice scenario, first identify the service, then ask which layer the customer controls. That sequence prevents shared-responsibility answers from becoming vague slogans.
How to cover Cloud Technology and Services efficiently
Domain 3 is broad, so study services by workload role and decision point rather than attempting to memorize the entire AWS catalog. The official tasks move from deployment methods and infrastructure to compute, databases, networking, storage, AI/ML, analytics, and other service categories.
For Task Statement 3.1, distinguish the AWS Management Console, APIs, SDKs, the AWS CLI, and infrastructure as code. Match the access method to the requirement: a console action may suit an occasional manual task, while a repeatable process points toward programmatic access or IaC. Also recognize cloud, hybrid, and on-premises deployment models.
For Task Statement 3.2, understand the relationship among Regions, Availability Zones, and edge locations. Multiple Availability Zones can support high availability, and AWS states that Availability Zones do not share single points of failure. Multiple Regions may be selected for disaster recovery, business continuity, lower latency for end users, or data-sovereignty needs.
Compute questions are organized around use. Review Amazon EC2 instance categories, container options such as Amazon ECS and Amazon EKS, serverless options such as AWS Fargate and AWS Lambda, auto scaling, and load balancers. Do not confuse elasticity from auto scaling with a specific compute product; one describes a capability and the others provide execution or traffic-management functions.
Database preparation should separate relational, NoSQL, and memory-based use cases. Review Amazon RDS and Amazon Aurora as relational examples, Amazon DynamoDB as a NoSQL example, and Amazon ElastiCache as a memory-based service. Also know the distinction between an EC2-hosted database and an AWS managed database, along with AWS DMS and AWS SCT as migration tools.
For networking, understand the purpose of VPC components such as subnets and gateways, the security roles of network ACLs and security groups, the purpose of Amazon Route 53, and connectivity options such as AWS VPN and AWS Direct Connect. A useful exercise is to draw a simple VPC and label which component provides routing, segmentation, name resolution, or connectivity.
For storage, create a use-case map rather than a list. Separate object, block, and file-storage ideas, then connect each to durability, access pattern, performance, and sharing requirements. Use the official in-scope service list and domain detail to determine which named services require deeper review.
The AI/ML and analytics task includes services such as Amazon SageMaker AI, Amazon Lex, Amazon Athena, Amazon Kinesis, AWS Glue, and Amazon Quick Sight. Learn the task each service accomplishes—for example, machine-learning development, conversational interaction, querying, streaming, data integration, or visualization—without assuming that similar-sounding services perform the same job.
The final task covers other in-scope AWS service categories. Treat this as a controlled breadth exercise. Review service categories and common use cases from the official references, but avoid spending disproportionate time on obscure features when you still confuse foundational choices such as object storage versus databases or a security group versus a network ACL.
What Billing, Pricing, and Support questions demand
Domain 4 is smaller by weighting but practical to prepare because its task statements name concrete decisions. Learn which pricing, cost-management, technical-resource, and Support option fits a stated need; do not rely on the assumption that the lowest apparent price is always the correct answer.
Task Statement 4.1 includes On-Demand Instances, Reserved Instances, Spot Instances, AWS Savings Plans, Dedicated Hosts, Dedicated Instances, and Capacity Reservations. Review when each purchasing option is appropriate, how Reserved Instance flexibility works, and how Reserved Instance behavior relates to AWS Organizations.
Also study storage tiers and incoming versus outgoing data transfer costs, including transfers between AWS Regions and transfers within the same Region. The point is to recognize the cost category and pricing model described by a scenario, not to calculate an unsupported price.
Task Statement 4.2 covers AWS Budgets, AWS Cost Explorer, AWS Pricing Calculator, AWS Organizations consolidated billing, cost allocation tags, and the AWS Cost and Usage Report. Create one sentence for each tool that answers “When would I use this?” Then create a second sentence explaining what it does not replace.
Task Statement 4.3 includes official AWS documentation, whitepapers, blogs, AWS Prescriptive Guidance, the AWS Knowledge Center, AWS re:Post, Support options, AWS Trusted Advisor, the AWS Health Dashboard, the AWS Health API, the AWS Trust and Safety team, AWS Partners, AWS Marketplace, and AWS Professional Services.
A common error is confusing a service-health view with a cost or security recommendation tool. Compare the purpose of the AWS Health Dashboard, AWS Health API, and AWS Trusted Advisor in your notes, and connect each resource to the type of question it answers.
Use official AWS pricing and Support pages for current commercial details. Product pricing, Support-plan terms, regional availability, and purchasing conditions can change; the exam guide establishes the concepts, but a current scheduling decision should not depend on an old third-party summary.
A study sequence that prevents shallow memorization
Begin with the blueprint and task statements, then study concepts before service catalogs. A workable sequence is Cloud Concepts, Security and Compliance, Cloud Technology and Services, and Billing, Pricing, and Support, followed by mixed review. Adjust the order if your diagnostic assessment shows a clear weakness.
First, read the official exam guide and mark every task statement as unfamiliar, partly understood, or explainable. Do not mark a topic complete merely because you recognize its service name. Completion means you can explain the purpose, identify the likely use case, and distinguish it from a plausible alternative.
Next, build a service-role map. For each service, record its category, primary purpose, typical scenario, and one nearby service that it is often confused with. Keep descriptions short. The act of distinguishing services is more useful than copying long product summaries.
Then study the cross-domain links. Cloud economics connects to rightsizing and purchasing options. Security connects to networking, identity, logging, and the shared responsibility model. Global infrastructure connects to high availability, latency, disaster recovery, and data sovereignty. These links resemble the reasoning required by scenario-based questions.
After the first pass, use retrieval practice. Close your notes and explain a task statement aloud or in writing. If your explanation uses only a product name, reopen the material and add the decision it supports. If you cannot distinguish two services, study their boundaries rather than rereading both descriptions passively.
Finish with mixed-domain practice and an error log. Record the question topic, the concept you missed, why your selected option looked attractive, and the rule that would have led you to the better answer. Review the error log by concept, not by question wording, because real exam items will not be identical to practice material.
If you have limited AWS hands-on experience
Use short, low-risk demonstrations to make abstract ideas concrete, but do not turn the preparation plan into a laboratory project. Sketch a Region and Availability Zones, inspect an IAM policy example, compare console and CLI workflows conceptually, and examine the purpose of cost tools through official documentation. Hands-on exposure should clarify vocabulary, not replace blueprint study.
If you already work with AWS
Do not assume operational familiarity covers the whole exam. Experienced candidates often know one service deeply while missing billing tools, governance terminology, migration strategies, or services outside their daily role. Use the domain tasks as a gap check and spend review time on concepts you rarely use at work.
A practical four-stage roadmap
Use the roadmap as a sequence of decisions, not a fixed promise about how long preparation will take. Move forward when you can explain the relevant task statements without notes, and extend a stage when practice reveals repeated confusion.
Stage 1: establish the baseline. Read the official exam guide, list the four domains, and complete a diagnostic set from a legitimate study source. Label each error by task statement. This tells you whether your problem is terminology, service selection, security responsibility, or question interpretation.
Stage 2: build foundational understanding. Study Cloud Concepts and Security and Compliance first. Write brief explanations of the Well-Architected pillars, migration concepts, cloud economics, least privilege, MFA, root-user protection, encryption, logging, and the shared responsibility model.
Stage 3: map services to scenarios. Cover the Domain 3 categories in separate passes: deployment, infrastructure, compute, databases, networking, storage, AI/ML and analytics, and other in-scope categories. For each category, practice choosing a service from a requirement rather than reciting a definition.
Stage 4: validate readiness and schedule deliberately. Complete mixed practice, review every wrong or guessed answer, and revisit the official task statements. Schedule when your performance is stable across all domains, not when one strong domain creates an overconfident average. Recheck official delivery and appointment information before booking.
How to use practice questions without learning the wrong lesson
Practice questions are useful when they reveal a reasoning gap, not when they become a memorization exercise. Use them to test whether you can identify the requirement, eliminate mismatched services, and explain why the selected answer fits better than the distractors.
For every item, identify the tested domain and task before checking the answer. If the topic is security, ask whether the question concerns responsibility, identity, governance, detection, protection, or compliance. If it is billing, identify whether it asks about purchasing, visibility, budgeting, pricing estimation, or Support.
Multiple-response items require a different habit from multiple-choice items. Evaluate each option independently against the requirement and select every response that satisfies the instruction. Do not select an option simply because it is generally useful; it must answer the specific question.
Avoid exam dumps, leaked questions, and memorization claims. They do not establish understanding, may be inaccurate or unauthorized, and cannot guarantee a passing result. Use the official exam guide, AWS service documentation, AWS learning resources, and reputable practice material that explains the underlying concept.
Your error log should include guessed answers as well as incorrect answers. A guess that happened to be correct may conceal a weakness, especially in a domain with similar service names or overlapping security responsibilities.
Scheduling and delivery decisions
Schedule only after checking the current AWS certification page and the applicable Pearson VUE information. AWS states that CLF-C02 is available at Pearson VUE testing centers and through online proctoring, so choose the format that matches your equipment, environment, travel constraints, and ability to follow the provider’s rules.
AWS lists the exam cost as USD 100 and directs candidates to its exam-pricing information for foreign-exchange and additional-cost details. Treat the listed amount as an official reference, not as a guarantee of the final transaction total in every location.
AWS lists CLF-C02 in Arabic, English, Indonesian, French, German, Italian, Japanese, Korean, Brazilian Portuguese, Latin American Spanish, Spain Spanish, Simplified Chinese, and Traditional Chinese. Confirm the language options shown during your booking flow before making a scheduling decision.
The exam guide states that AWS Certifications are valid for three years. AWS provides Cloud Practitioner recertification options including Cloud Quest: Recertify Cloud Practitioner, passing the current exam, or passing an Associate- or Professional-level exam. Review the current recertification page when planning beyond the initial certification.
Test-session tactics grounded in the scoring rules
Use the first pass to answer clear questions and flag items that require comparison. Because unanswered questions are scored as incorrect and there is no penalty for guessing, reserve time to make a selection for every item before the session ends.
Read for the requirement before reading for the product. Words such as “most appropriate,” “least operational effort,” “cost visibility,” “high availability,” “protection,” or “repeatable” often identify the decision being tested. Then eliminate answers that solve a different problem.
Keep responsibility questions anchored to the service named in the scenario. A customer’s responsibility for an EC2 workload is not identical to the responsibility for a managed service or a serverless service. When two answers seem plausible, identify which one matches the customer-controlled layer.
Do not infer that an unscored question is easier or harder. AWS says unscored questions are not identified, so treat every item as if it matters and apply the same careful process throughout.
A score report is a checkpoint, not a complete diagnosis. If section-level classifications appear, use them to select review topics, but also examine your error log and the task statements. AWS cautions candidates to use care when interpreting section-level feedback.
Mistakes that waste preparation time
The most expensive preparation mistake is breadth without discrimination: learning hundreds of names while remaining unable to explain which service addresses a requirement. Replace long lists with small comparison groups and scenario-based recall.
Another mistake is overstudying implementation details that AWS explicitly places outside the exam’s scope. Coding, architecture design, troubleshooting, implementation, and load or performance testing can be valuable professional skills, but they should not displace foundational exam tasks during CLF-C02 preparation.
Candidates also commonly underprepare security because they reduce it to “turn on encryption.” Review responsibility boundaries, root-user protection, least privilege, identity federation, logging, governance, compliance resources, and the distinct roles of security services.
Ignoring cost and Support content is another avoidable error. Domain 4 represents 12% of the scored content on the exam and includes concrete tools and purchasing concepts. Learn the difference between estimating, monitoring, budgeting, analyzing, and receiving technical assistance.
Finally, do not use a single strong practice result as proof of readiness. Check whether you answered by reasoning or recognition, whether you guessed, and whether your weaker domains remain weak. Readiness should mean repeatable understanding across the blueprint.
Your final review checklist
A final review should confirm explainable knowledge across all four domains, accurate service distinctions, and a plan for handling uncertain questions. If you cannot explain an item without seeing its answer choices, keep reviewing the underlying task statement.
Before scheduling or sitting the exam, confirm that you can: explain the main value of AWS Cloud; distinguish the Well-Architected pillars; describe migration and cloud-economics concepts; apply the shared responsibility model; explain least privilege and root-user protection; identify the purpose of core compute, database, network, and storage services; distinguish Regions, Availability Zones, and edge locations; and match billing tools to their uses.
Also confirm that you understand multiple-choice and multiple-response instructions, know that 50 questions affect your score and 15 questions are unscored, and have a method for answering every item. These are official exam facts, but the study habits you use to act on them are practical recommendations.
On the day you schedule, verify the current delivery method, language, price information, appointment requirements, and provider instructions from the official sources. On the day you prepare, use your error log—not a new pile of random topics—to decide what receives the final review.
Next steps after reading this guide
Start with the official CLF-C02 exam guide and four domain pages, then create a task-by-task gap list. Your next useful action is not to collect more product names; it is to identify the first three task statements you cannot explain and study those with official AWS material.
After that, choose a preparation method that fits your background: structured reading for a beginner, targeted gap review for an AWS practitioner, or a combination of official documentation and legitimate practice questions for both. Reassess by explaining scenarios in your own words.
When your review shows consistent understanding across the domains, confirm current booking details through AWS and Pearson VUE, select the delivery option and language that suit your circumstances, and schedule with enough preparation margin for a final error-log review.
Conclusion
CLF-C02 rewards clear foundational reasoning: connect a requirement to an AWS concept or service, understand where responsibility sits, and recognize the cost, security, and operating implications of a choice. Use the official blueprint to control scope, give extra attention to Security and Compliance and Cloud Technology and Services, and use practice results to repair specific gaps. The best next move is to build your task-statement checklist and begin with the areas you cannot yet explain without notes.