SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
CLF-C02 · Domain 3

Cloud Technology and Services practice questions

Cloud Technology and Services is worth 34% of the CLF-C02 exam — the heaviest of the 4 domains. How to deploy and operate in AWS, the global infrastructure, and the core service portfolio: compute, database, network, storage, AI/ML, and analytics. 6 fully worked examples are further down this page, answers included.

Exam weight
34%
the heaviest of the 4 domains
Questions
160
across 8 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 4 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Cloud Technology and Services questions, fully explained

Questions from the CLF-C02 bank mapped to domain 3, with the answer key and the reasoning behind every option. None of them repeat the examples on the main CLF-C02 practice page.

Question 1Cloud Technology and Services

A systems administrator must run a scheduled nightly job from a terminal that stops all development EC2 instances and produces a report of running resources. The steps should be captured in a script that runs the same way every night. Which access method fits this requirement?

Choose one.

  • a
    AWS Management Console

    Console work is manual clicking in a browser; it cannot be scheduled and a human repeating it nightly invites errors and inconsistency.

  • b
    The AWS Console Mobile Application

    The mobile console lets a person monitor resources and respond to alarms from a phone; it does not run scheduled scripts.

  • c
    AWS Direct Connect

    Direct Connect is a dedicated physical network connection to AWS, not a tool for scripting administrative tasks.

  • d
    AWS CLI Correct

    The CLI turns AWS operations into terminal commands that can be chained into a shell script and run on a schedule, identically every time.

The concept

The AWS Command Line Interface (AWS CLI) controls AWS services through terminal commands, which can be combined into scripts for repeatable, schedulable administrative automation.

Why that’s the answer

The scenario contains the two classic CLI triggers: a person's operational task performed from a terminal, and a requirement that it be scripted and scheduled to run identically every night. The CLI converts each step into a text command, so the whole sequence becomes a script that a scheduler can invoke. The Management Console fails because manual browser work cannot be scheduled and does not reproduce itself consistently. The Console Mobile Application fails for the same reason — it is a monitoring convenience for humans. Direct Connect fails because it is a network connectivity option and has nothing to do with executing administrative tasks.

How to reason it out
  1. Identify the actor and context: an administrator working from a terminal.
  2. Spot the keywords: scheduled, script, runs the same way every time.
  3. Match scripted, repeatable admin operations to the AWS CLI.
  4. Eliminate both console options as manual human interfaces and Direct Connect as a networking service.

Exam tip: Scripted, scheduled administrative tasks from a terminal are the home turf of the AWS CLI.

Deploying and Operating in AWS: Console, CLI, SDKs, IaC, and Connectivity — the lesson that teaches this.

Question 2Cloud Technology and Services

Which statement describes what the AWS Management Console, the AWS CLI, and the AWS SDKs all have in common?

Choose one.

  • a
    They all require the user to sign in through a web browser

    Only the console uses browser sign-in; the CLI and SDKs authenticate with credentials such as access keys or temporary role credentials.

  • b
    They all require writing code in a programming language

    The console requires no code at all, and the CLI uses typed commands rather than a programming language.

  • c
    They all provision infrastructure from declarative templates

    Declarative templates describe infrastructure as code with CloudFormation; the console, CLI, and SDKs perform direct actions rather than reading templates.

  • d
    They all ultimately make calls to the same underlying AWS APIs over HTTPS Correct

    Every access method is a layer on top of the AWS service APIs; the console, CLI, and SDKs all translate user actions into the same signed HTTPS API calls.

The concept

AWS exposes every service as a set of API operations over HTTPS; the Management Console, CLI, and SDKs are simply different ways for humans and software to reach that single interface.

Why that’s the answer

The unifying fact behind all AWS access methods is the API layer: clicking a button in the console, typing a CLI command, and calling an SDK function each result in the same authenticated API call over HTTPS. This is also why anything done manually can be automated. Browser sign-in is wrong because it applies only to the console — programmatic access uses access keys or temporary credentials. Requiring code is wrong because the console is code-free and the CLI uses commands, not programs. Declarative templates are wrong because that describes CloudFormation, a separate infrastructure-as-code approach, not something the three methods share.

How to reason it out
  1. Recall the layered model: the AWS APIs form the foundation, and every access method sits on top of them.
  2. Test each option against all three methods rather than just one.
  3. Note that authentication styles differ (browser versus credentials), eliminating the sign-in option.
  4. Conclude that the common thread is that all methods issue the same underlying API calls.

Exam tip: Every AWS access method — console, CLI, or SDK — is a different front door to the same AWS APIs.

Deploying and Operating in AWS: Console, CLI, SDKs, IaC, and Connectivity — the lesson that teaches this.

Question 3Cloud Technology and Services

A company wants to reduce manual work by adopting programmatic ways to operate its AWS environment. Which TWO access methods are programmatic? (Select TWO.)

Choose TWO.

  • a
    AWS Management Console

    The console is the manual, graphical method: a human clicks through forms in a browser, which is the opposite of programmatic access.

  • b
    A documented runbook of console steps

    A written procedure is still executed manually by a person; documenting clicks does not make them programmatic or consistent.

  • c
    AWS CLI Correct

    The CLI is programmatic: its text commands can be scripted and automated, and it authenticates with credentials rather than a browser sign-in.

  • d
    The AWS Console Mobile Application

    The mobile console is another graphical human interface for monitoring on the go, not a programmatic access method.

  • e
    AWS SDKs Correct

    SDKs are programmatic by definition — they let applications call AWS services directly from code in languages such as Python and Java.

The concept

Programmatic access means software or scripts interacting with AWS through credentials and API calls, in contrast to a human working through a graphical interface.

Why that’s the answer

The CLI and the SDKs are the two programmatic methods CLF-C02 names: the CLI turns operations into terminal commands that scripts can automate, and SDKs embed AWS API calls inside application code. Both authenticate with access keys or temporary credentials and both issue the same underlying API calls. The Management Console and its mobile application are graphical interfaces operated by people, so they are manual, not programmatic. A documented runbook is a trap answer — writing down console steps produces a manual procedure with all the same risks of typos and skipped steps, because only code executes identically every time.

How to reason it out
  1. Define programmatic: driven by scripts or application code, not human clicks.
  2. Accept the CLI as programmatic because commands can be scripted and scheduled.
  3. Accept SDKs as programmatic because applications call AWS directly from code.
  4. Reject both console variants and the runbook because a human still performs every step manually.

Exam tip: Programmatic access to AWS means the CLI and the SDKs; the console in any form is manual.

Deploying and Operating in AWS: Console, CLI, SDKs, IaC, and Connectivity — the lesson that teaches this.

Question 4Cloud Technology and Services

A development team works in a niche programming language for which AWS does not publish an SDK. The team's application must still interact with AWS services directly. What can the team do?

Choose one.

  • a
    Use the AWS Management Console, because it is language-independent

    The console is language-independent only because a human operates it; an application cannot use a browser interface during normal operation.

  • b
    Accept that AWS cannot be used from that language

    AWS is not limited to SDK-supported languages; the HTTPS APIs are open to any code that can make signed web requests.

  • c
    Make signed HTTPS calls directly to the underlying AWS service APIs Correct

    Every AWS service is exposed as API operations over HTTPS; when no SDK exists for a language, code can craft and sign those API requests itself.

  • d
    Write an AWS CloudFormation template in the niche language

    CloudFormation templates are written in JSON or YAML and provision infrastructure; they do not let a running application call AWS services.

The concept

The AWS APIs are the foundation beneath every access method; the console, CLI, and SDKs are convenience layers, and direct API calls remain possible when no higher-level tool fits.

Why that’s the answer

Because AWS delivers each service as a set of HTTPS API operations, any code that can send signed web requests can use AWS — an SDK is a convenience that handles signing and retries, not a requirement. Direct API use is rare but is exactly the fallback for an environment with no SDK support. The console option fails because a browser interface cannot serve an application's runtime needs. Declaring AWS unusable is wrong because the API layer is universally reachable. The CloudFormation option fails twice: templates are JSON or YAML, not arbitrary languages, and CloudFormation provisions resources rather than serving runtime application calls.

How to reason it out
  1. Recall that SDKs are wrappers over the AWS HTTPS APIs, not the only path to them.
  2. Recognize the scenario constraint: no SDK exists, but the application must call AWS directly.
  3. Conclude that the application can issue signed HTTPS requests to the APIs itself.
  4. Eliminate the console (human-only), giving up (the APIs are open), and CloudFormation (provisioning, wrong format).

Exam tip: When no SDK exists, code can still call the underlying AWS HTTPS APIs directly — the API is the foundation of all access.

Deploying and Operating in AWS: Console, CLI, SDKs, IaC, and Connectivity — the lesson that teaches this.

Question 5Cloud Technology and Services

Which AWS service provisions a collection of related resources as a single managed unit from templates written in JSON or YAML?

Choose one.

  • a
    AWS CloudFormation Correct

    CloudFormation reads JSON or YAML templates and provisions everything they declare as a managed stack, the flagship infrastructure-as-code service on AWS.

  • b
    AWS CLI

    The CLI runs individual commands or imperative scripts; it does not read declarative templates or manage resources as a single stack.

  • c
    AWS Management Console

    The console is a graphical interface for manual actions; it does not provision environments from template files.

  • d
    Amazon CloudFront

    CloudFront is a content delivery network that caches content at edge locations; its similar name is the trap, but it has nothing to do with provisioning.

The concept

Infrastructure as code (IaC) means describing infrastructure in machine-readable definition files; AWS CloudFormation is the AWS IaC service that turns JSON or YAML templates into provisioned stacks.

Why that’s the answer

CloudFormation matches every element of the stem: templates in JSON or YAML, provisioning of many related resources, and management of them together as a single unit called a stack. Deploying the same template again produces an identical environment. The CLI is imperative — it lists commands to run in order — rather than declarative, and it has no stack concept. The console is manual and template-free. CloudFront is a deliberate name-alike distractor: it is a CDN for caching content near users and is entirely unrelated to infrastructure provisioning.

How to reason it out
  1. Spot the IaC signals in the stem: templates, JSON or YAML, resources managed as one unit.
  2. Recall that CloudFormation is the AWS infrastructure-as-code service and its unit is the stack.
  3. Distinguish declarative templates from the CLI's imperative commands.
  4. Beware the CloudFront name trap — CDN, not IaC.

Exam tip: CloudFormation is the AWS IaC service: JSON or YAML templates in, managed stacks out.

Deploying and Operating in AWS: Console, CLI, SDKs, IaC, and Connectivity — the lesson that teaches this.

Question 6Cloud Technology and Services

A company must create identical development, test, and production environments on AWS and be able to recreate them quickly without manual errors. Which approach meets this requirement?

Choose one.

  • a
    Define the environments in an AWS CloudFormation template and deploy it for each environment Correct

    One template deployed multiple times produces identical environments every time — repeatable, consistent, and free of manual missteps.

  • b
    Build each environment in the AWS Management Console and document the steps carefully

    A documented manual procedure is still manual; three console sessions will produce three slightly different environments.

  • c
    Build the first environment in the console and photograph each configuration screen for reference

    Screenshots are just another form of manual documentation and cannot guarantee that repeated builds come out identical.

  • d
    Have a different administrator build each environment to cross-check the work

    More people doing manual work increases inconsistency; different humans make different choices and different mistakes.

The concept

When environments must be repeatable and consistent, infrastructure as code is the answer: a CloudFormation template defines the environment once and provisions it identically any number of times.

Why that’s the answer

The stem contains the strongest IaC triggers on the exam: identical environments, recreated quickly, without manual errors. Only a machine-readable definition satisfies all three — CloudFormation deploys the same template as many times as needed, eliminating drift between environments and removing the typos and skipped steps that creep into manual work. Every distractor is a variation on manual process: careful documentation, screenshots, and extra reviewers all still depend on humans executing steps by hand, and no amount of documentation makes manual work reproduce itself exactly. Only code guarantees consistency.

How to reason it out
  1. Identify the requirement type: repeatable provisioning of whole environments.
  2. Map identical plus repeatable plus error-free to infrastructure as code.
  3. Select CloudFormation as the AWS IaC service that deploys a template into identical stacks.
  4. Reject all manual variants — documentation and extra people do not remove human inconsistency.

Exam tip: Identical, repeatable environments call for a CloudFormation template, never a documented manual procedure.

Deploying and Operating in AWS: Console, CLI, SDKs, IaC, and Connectivity — the lesson that teaches this.

What CLF-C02 domain 3 tests, topic by topic

The official exam guide breaks Cloud Technology and Services into 8 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published CLF-C02 practice questions per topic in Cloud Technology and Services
TopicWhat it coversQuestions
Define methods of deploying and operating in the AWS CloudExam guide task 3.1. Access and provisioning methods: programmatic access (APIs, SDKs, CLI) vs the Management Console vs infrastructure as code; one-time vs repeatable processes; cloud, hybrid, and on-premises deployment models.20
Define the AWS global infrastructureExam guide task 3.2. Relationships among Regions, Availability Zones, and edge locations; high availability through multiple AZs (which share no single point of failure); when to use multiple Regions (disaster recovery, business continuity, low latency for end users, data sovereignty); the benefits of edge locations.20
Identify AWS compute servicesExam guide task 3.3. EC2 instance families (e.g. compute optimized, storage optimized); container options (ECS, EKS); serverless compute (Lambda, Fargate); elasticity through auto scaling; the purposes of load balancers.20
Identify AWS database servicesExam guide task 3.4. EC2-hosted vs AWS managed databases; relational databases (RDS, Aurora); NoSQL (DynamoDB); memory-based databases (ElastiCache); database migration tools (AWS DMS, AWS SCT).20
Identify AWS network servicesExam guide task 3.5. VPC components (subnets, gateways); VPC security (network ACLs, security groups, Amazon Inspector); the purpose of Route 53; network connectivity options to AWS (AWS VPN, Direct Connect).20
Identify AWS storage servicesExam guide task 3.6. Object storage use cases; differences between S3 storage classes; block storage (EBS, instance store); file services (EFS, FSx); cached file systems (Storage Gateway); lifecycle policies; AWS Backup use cases.20
Identify AWS artificial intelligence and machine learning (AI/ML) services and analytics servicesExam guide task 3.7. AI/ML services and the tasks they perform (SageMaker AI, Lex) and the data analytics portfolio (Athena, Kinesis, AWS Glue, Amazon Quick Sight).20
Identify services from other in-scope AWS service categoriesExam guide task 3.8. The rest of the in-scope catalog: application integration (EventBridge, SNS, SQS); business applications (Connect, SES); customer enablement (AWS Support) and choosing business support assistance; developer tools to build, deploy, and troubleshoot (CodeBuild, CodePipeline, X-Ray); end-user computing (AppStream 2.0, WorkSpaces, WorkSpaces Secure Browser); frontend web/mobile (Amplify); IoT (IoT Core).20
Total160

Revise Cloud Technology and Services before you drill it

Other CLF-C02 domains

Cloud Technology and Services: your questions

Cloud Technology and Services is domain 3 of the CLF-C02 exam guide and carries 34% of the scored content — the heaviest of the 4 domains. On a 65-question paper that works out to roughly 22 questions, though AWS does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official CLF-C02 exam guide.