AWS Cloud Practitioner sample questions with answers

10 free AWS Cloud Practitioner sample questions across the exam's domains, each with its answer and an explanation. No account needed.

AWS Cloud Practitioner sample questions

AWS Certified Cloud Practitioner, Amazon Web Services (AWS).

  1. Question 1

    Domain: Cloud Concepts

    A finance-led review proposes paying only for the capacity each team actually consumes, stopping development environments when they are unused, and letting AWS carry the undifferentiated heavy lifting of running data centres.

    Which Well-Architected pillar is the proposal most closely aligned with?

    1. Operational excellence
    2. Performance efficiency
    3. Sustainability
    4. Cost optimisation
    Show the answer

    Answer: D. Cost optimisation

    Adopting a consumption model, measuring overall efficiency and stopping spending on undifferentiated heavy lifting are design principles of the cost optimisation pillar. Operational excellence is the tempting choice because managed services reduce operational toil, but paying only for what you consume and attributing expenditure are cost principles.

    Checked against: https://docs.aws.amazon.com/wellarchitected/latest/framework/cost-dp.html

  2. Question 2

    Domain: Cloud Concepts

    A company owns Windows Server licences that are licensed per physical core and wants to bring them to AWS under its existing licence terms.

    Which EC2 purchasing option lets the company use these existing licences?

    1. Dedicated Instances
    2. Dedicated Hosts
    3. Spot Instances
    4. Shared-tenancy On-Demand Instances
    Show the answer

    Answer: B. Dedicated Hosts

    Dedicated Hosts give you a physical server with visibility of its sockets and physical cores, so you can bring your own per-socket or per-core licences. Dedicated Instances are the tempting option because they also run on single-tenant hardware, but they do not give you visibility or control of the underlying sockets and cores that such licences require.

    Checked against: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-overview.html

  3. Question 3

    Domain: Cloud Concepts

    A team with no existing Microsoft SQL Server licences wants to run SQL Server on Amazon RDS and pay for the licence as part of its hourly usage.

    Which licensing model on Amazon RDS for SQL Server fits this requirement?

    1. Bring Your Own License (BYOL)
    2. Dedicated Host licensing
    3. AWS Marketplace annual subscription
    4. License Included
    Show the answer

    Answer: D. License Included

    With the License Included model, the SQL Server licence cost is built into the hourly price of the RDS DB instance, so no separately purchased licence is needed. BYOL is the trap: it only applies when the customer already owns eligible licences, which this team does not.

    Checked against: https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/SQLServer.Concepts.General.Licensing.html

  4. Question 4

    Domain: Security and Compliance

    Logs show attackers sending HTTP requests containing SQL injection and cross-site scripting payloads to a web application behind an Application Load Balancer.

    Which AWS service should be placed in front of the application to block these requests?

    1. AWS Shield Standard
    2. Network access control lists
    3. Amazon GuardDuty
    4. AWS WAF
    Show the answer

    Answer: D. AWS WAF

    AWS WAF is a web application firewall that inspects HTTP(S) requests to resources such as CloudFront, Application Load Balancers and API Gateway, with rules that block patterns like SQL injection and cross-site scripting. Shield Standard is the trap: it protects against common network and transport layer DDoS attacks, not application-layer injection attacks.

    Checked against: https://docs.aws.amazon.com/waf/latest/developerguide/waf-chapter.html

  5. Question 5

    Domain: Security and Compliance

    A team sees repeated malicious traffic from one external IP address to every instance in a public subnet and wants to block that address for the whole subnet.

    Which control should the team use?

    1. A security group rule on the instances that denies traffic from that IP address
    2. An IAM policy that denies the IP address access to the instances
    3. A network ACL rule on the subnet that denies traffic from that IP address
    4. An AWS Shield Standard rule that blocks the IP address
    Show the answer

    Answer: C. A network ACL rule on the subnet that denies traffic from that IP address

    Network ACLs operate at the subnet level, are stateless and support both allow and deny rules, so they can block a specific address range. Security groups are the trap: they are stateful and support allow rules only, so you cannot write an explicit deny rule in a security group.

    Checked against: https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html

  6. Question 6

    Domain: Security and Compliance

    A security team uses GuardDuty, Inspector and Macie across many accounts and wants a single view that aggregates their findings and checks resources against security best-practice standards.

    Which AWS service provides this?

    1. AWS Security Hub
    2. Amazon Detective
    3. AWS Trusted Advisor
    4. Amazon Inspector
    Show the answer

    Answer: A. AWS Security Hub

    Security Hub aggregates and prioritises security findings from services such as GuardDuty, Inspector and Macie, and runs automated checks against security best-practice standards. Trusted Advisor is tempting because it includes some security checks, but it does not aggregate findings from other security services into one view.

    Checked against: https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub.html

  7. Question 7

    Domain: Cloud Technology and Services

    A web application must send requests for /api/* to one group of containers and requests for /images/* to another, based on the URL path.

    Which load balancer type should the architect choose?

    1. Network Load Balancer
    2. Application Load Balancer
    3. Gateway Load Balancer
    4. Classic Load Balancer
    Show the answer

    Answer: B. Application Load Balancer

    An Application Load Balancer operates at layer 7 and can route HTTP and HTTPS requests to different target groups based on content such as the URL path or host header. Network Load Balancer is the trap: it operates at layer 4 and handles very high volumes of TCP and UDP traffic with low latency, but it does not route on URL paths.

    Checked against: https://docs.aws.amazon.com/elasticloadbalancing/latest/application/introduction.html

  8. Question 8

    Domain: Cloud Technology and Services

    Processing a loan application involves validating data, running a credit check, waiting for human approval and then sending a contract, with retries if the credit check service fails.

    Which AWS service lets the team model this workflow as a state machine with built-in retries and error handling?

    1. Amazon SQS
    2. Amazon EventBridge
    3. AWS Step Functions
    4. AWS CodePipeline
    Show the answer

    Answer: C. AWS Step Functions

    Step Functions orchestrates multiple AWS services into workflows defined as state machines, with built-in retries, error handling and visual monitoring of each step. EventBridge is tempting because it connects services through events, but it routes events to targets rather than coordinating a sequential multi-step process with state.

    Checked against: https://docs.aws.amazon.com/step-functions/latest/dg/welcome.html

  9. Question 9

    Domain: Cloud Technology and Services

    A company wants to give 500 remote employees a persistent, managed Windows desktop they can access from personal laptops, without shipping company hardware.

    Which AWS service provides this?

    1. Amazon WorkSpaces
    2. AWS Client VPN
    3. Amazon Lightsail
    4. AWS Outposts
    Show the answer

    Answer: A. Amazon WorkSpaces

    WorkSpaces provides managed, persistent virtual desktops for Windows or Linux that users can reach from many devices. AWS Client VPN is the trap: it gives remote users secure network access to AWS and on-premises resources, but the employees would still need a company-managed computer to work on.

    Checked against: https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces.html

  10. Question 10

    Domain: Billing, Pricing, and Support

    A team is running a new application for an eight-week pilot. Usage is unpredictable, the application cannot tolerate interruptions, and the project may be cancelled at any time.

    Which EC2 pricing option is most appropriate?

    1. On-Demand Instances
    2. Standard Reserved Instances with a three-year term
    3. Spot Instances
    4. Dedicated Hosts with a reservation
    Show the answer

    Answer: A. On-Demand Instances

    On-Demand Instances have no long-term commitment and are billed only while running, which suits short-term, unpredictable workloads that must not be interrupted. Spot Instances are the tempting cheaper option, but they can be interrupted, which is unacceptable for this workload.

    Checked against: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-purchasing-options.html

More practice

A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.

AWS Cloud Practitioner course and practice exam: CLF-C02: the exam guide, with the format, cost, pass mark and domains from the vendor.