Most people start preparing for Cloud Practitioner the same way. They open the service list, see a few hundred names, and try to memorize what each one does. Two weeks later they can recite definitions, but they freeze when a question describes a business problem without naming a single service.
The fix isn't simply adding more flashcards. It's studying by domain, so you know what each part of the exam is asking you to do. Here's how to think about each of the four CLF-C02 domains, what they're really testing, and how to tell when you're ready to move on.
Start with what the exam is, and isn't
AWS's CLF-C02 exam guide describes the target candidate as someone with up to six months of exposure to AWS design, implementation, or operations. That could be someone early in a cloud career, or someone who works alongside cloud teams. The guide lists coding, designing cloud architecture, troubleshooting, implementation, and load testing as out of scope.
That tells you what depth to aim for. You need to recognize services, explain what they're for, and choose a sensible one for a described need. You don't need to build anything.
Domain weights: what they mean and what they don't
The current weights, as a share of scored content, are:
- Domain 1, Cloud Concepts: 24%
- Domain 2, Security and Compliance: 30%
- Domain 3, Cloud Technology and Services: 34%
- Domain 4, Billing, Pricing, and Support: 12%
Under AWS's current exam structure, the exam has 65 questions: 50 scored and 15 unscored. The unscored questions are used to evaluate content for future exams, and AWS doesn't identify them, so you can't tell which questions don't count. Treat every question as if it does.
The weights are a planning tool, not a forecast. You can't work out exactly how many questions from each domain will appear on your exam form, so don't build a plan around skipping anything.
The exam also uses compensatory scoring, which means you don't need to pass each section, only the exam overall. Your score report may include section-level feedback, but AWS advises caution in interpreting it. A weak-looking section isn't a failed domain, and a strong-looking one isn't permission to stop reviewing it. Use that feedback as a hint about where to look, not as a prediction of anything.
Domain 1: Cloud Concepts (24%)
This domain is less about services and more about how AWS thinks. It covers the benefits of the cloud, Well-Architected design principles, migration strategies, and cloud economics.
Here's where many candidates get tripped up. They skim this domain as common sense, then miss questions because every answer sounds reasonable and only one uses the concept the way AWS does.
Start with a few distinctions. Elasticity means adding and removing resources to match demand, so you aren't paying for idle capacity or running short during a spike. High availability means the application keeps working when something fails, which comes from redundancy. A system can have one without the other. Agility is about speed: how quickly a team can provision resources, try an idea, and move on if it doesn't work.
The Well-Architected Framework has six pillars: operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability. The exam guide asks you to identify the differences between them, so practice with scenarios. Automating deployments points to operational excellence. Recovering from failure points to reliability. Choosing the right resource type for a workload points to performance efficiency. Reducing the environmental impact of workloads points to sustainability.
On economics, two ideas often get blurred. Pay-as-you-go means you pay for what you use instead of buying capacity up front, which shifts fixed costs to variable ones. Economies of scale means AWS aggregates usage from a very large number of customers, which lets it operate at lower unit costs than most organizations could manage alone. Also know the costs hiding behind an on-premises environment (facilities, power, cooling, staff, hardware refresh), the difference between bring-your-own-license and license-included models, and what rightsizing and automation contribute. For migration, know that the AWS Cloud Adoption Framework helps organizations plan the move around outcomes like reduced risk, improved ESG performance, increased revenue, and operational efficiency.
How to study it: Explain each pillar and each benefit in a sentence or two, in your own words. If you can explain the difference without notes, you're in much better shape than if you can only recognize it.
Domain 2: Security and Compliance (30%)
This is the second-heaviest domain, and the one where understanding pays off most. Start with the shared responsibility model, because it ties everything else together.
Don't stop at "AWS secures the cloud, customers secure what they put in it." The exam guide expects you to understand how responsibilities shift depending on the service. With Amazon EC2, you manage the guest operating system, including patching, plus your applications, data, and network configuration. With Amazon RDS, AWS handles much more of the operating system and database maintenance, but you still control who can access the database, how the data is protected, and how the instance is configured. With AWS Lambda, AWS manages the servers and operating system, while your function code, its permissions, and your data remain yours. A good question to ask for any service is: what could I still misconfigure here?
Next, access management. Least privilege means giving an identity only the permissions it needs to do its job. The reasoning is practical: if credentials leak or someone makes a mistake, narrow permissions limit the damage. In IAM that shows up as using groups and roles instead of broad access, writing policies that name specific actions and resources, and protecting the root user with MFA and keeping it out of everyday use. Know which few tasks only the root user can perform, and know that roles provide temporary credentials, which is why they're used for things like cross-account access. IAM Identity Center and federated identity round out the picture.
The security services need a simple mental model, because they're easy to blur together:
- Amazon GuardDuty detects suspicious activity and potential threats.
- Amazon Inspector scans workloads for software vulnerabilities.
- AWS Shield protects against DDoS attacks.
- AWS WAF filters web requests against rules you define.
- AWS Security Hub consolidates findings from services like GuardDuty and Inspector into one place.
For governance, keep three services separate. Amazon CloudWatch is about monitoring: metrics, logs, and alarms. AWS CloudTrail records API activity, so it answers who did what and when. AWS Config tracks resource configurations and changes over time, so it answers what something looks like and whether it drifted. Also know that AWS Artifact is where you find AWS compliance reports.
How to study it: Build a table with three columns: the service, the question it answers, and the service people confuse it with. The last column is where the learning happens.
Domain 3: Cloud Technology and Services (34%)
This is the largest domain and the one most likely to feel overwhelming, because it spans eight task areas: deployment methods, global infrastructure, compute, databases, networking, storage, AI/ML and analytics, and other in-scope service categories. Don't try to learn every service equally. Learn each category by the question it answers.
Global infrastructure. A Region is a geographic area. Each Region has multiple Availability Zones, which AWS describes as isolated locations within the Region. Because AZs are designed to be isolated from one another, running an application across more than one improves its resilience and availability if something goes wrong in one location. That doesn't make an application immune to every failure, since design and configuration still matter. Multiple Regions come into play for disaster recovery, lower latency for distant users, or data sovereignty. Edge locations are a different idea: services like Amazon CloudFront use them to deliver content closer to users.
Compute. EC2 gives you virtual servers and the most control, along with the most to manage. Amazon ECS and Amazon EKS orchestrate containers (EKS runs Kubernetes). AWS Fargate runs containers without you managing servers, and Lambda runs your code in response to events, also without servers to manage. Auto Scaling provides elasticity, and load balancers distribute traffic.
Databases. Amazon RDS provides managed relational databases, and Amazon Aurora is a MySQL- and PostgreSQL-compatible relational option. Amazon DynamoDB is managed NoSQL, a fit for key-value and document access patterns at scale. Amazon ElastiCache is in-memory, commonly used to speed up reads. Also understand the tradeoff between running a database on EC2 yourself and using a managed service: managed means less operational work for you.
Networking. Security groups and network ACLs both control traffic in a VPC, but they work differently. Security groups operate at the instance level and are stateful, so return traffic is automatically allowed. Network ACLs operate at the subnet level and are stateless, so return traffic must be explicitly allowed. Know that Route 53 is AWS's DNS service, and that a VPN connects over the internet while Direct Connect is a dedicated network connection.
Storage. The core distinction is object, block, and file. Amazon S3 is object storage, accessed through an API. Amazon EBS provides block volumes attached to EC2 instances. Amazon EFS is a shared file system, and Amazon FSx offers managed file systems for specific needs. Then learn the S3 storage classes as a tradeoff between cost and access pattern, plus lifecycle policies and AWS Backup.
AI/ML, analytics, and integration. Aim for a one-line purpose each. Amazon SageMaker AI builds, trains, and deploys machine learning models. Amazon Athena queries data in S3 with SQL. Amazon Kinesis handles streaming data, AWS Glue handles data preparation and integration, and Amazon Quick Sight builds dashboards. For messaging, Amazon SNS pushes notifications to subscribers, Amazon SQS queues messages so components can work independently, and Amazon EventBridge routes events based on rules.
How to study it: Short hands-on sessions help the vocabulary stick, even though the exam doesn't test implementation. Launch an instance, create a bucket, change a storage class, look at a VPC.
Domain 4: Billing, Pricing, and Support (12%)
It's the smallest domain, but don't treat it as the easy one. Its questions can be precise, and the answer options are often close.
Learn the compute purchasing options by the situation they fit. On-Demand suits unpredictable or short-term usage with no commitment. Reserved Instances and Savings Plans offer discounts in exchange for a usage commitment, with Savings Plans generally the more flexible of the two. Spot uses spare capacity at a steep discount but can be interrupted, so it suits fault-tolerant work. Also understand at a conceptual level that data transfer in and out, and between Regions, is priced differently.
The cost tools are easy to mix up. AWS Pricing Calculator estimates costs before you build. AWS Budgets lets you set thresholds and get alerts. AWS Cost Explorer analyzes what you've already spent. Add AWS Organizations consolidated billing and cost allocation tags, and you've covered most of the billing material.
Support is where outdated study material can hurt you. The current exam guide lists Basic Support, AWS Business Support+, AWS Enterprise Support, and AWS Unified Operations, and AWS's Support plans page reflects the same lineup. If a course or video uses different plan names, check it against the current page. Also be familiar with Trusted Advisor, the AWS Health Dashboard, AWS Partners and the Marketplace, and resources like re:Post and the Knowledge Center.
Using practice questions to find gaps, not collect answers
Practice questions are most useful when each wrong answer becomes information. After every session, for each miss, ask why the right answer was right and why your choice wasn't. Then write down which concept you actually misunderstood. If all you remember is "the answer was C," you've learned nothing that transfers.
Two habits help. Keep a short error log sorted by domain so patterns show up, and be wary of repeating the same question set until your score climbs, because by then you're measuring memory of the questions rather than understanding of AWS.
If you'd like a quick starting point, CloudExamPro, an independent practice platform not affiliated with AWS, offers a free CLF-C02 diagnostic made up of 25 original practice questions. It's a short sample rather than a full exam simulation, so use it to spot areas worth reviewing, not as a prediction of how you'll score on the real exam.
From studying to being ready
A few signs you're close:
- You can explain each domain's main ideas without notes.
- When you miss a question, you can usually say why, and your misses aren't clustered in one area.
- You can choose between similar services (CloudTrail versus Config, security groups versus network ACLs, Budgets versus Cost Explorer) and explain your reasoning.
If one area keeps producing misses, go back to the concept rather than more questions. And keep the scoring model in mind: you need to pass the exam overall, not every section, but a persistent gap in a 30% or 34% domain deserves real attention.
Where this leaves you
CLF-C02 rewards candidates who understand how AWS approaches cloud, security, services, and cost. Study each domain by asking what problem it solves, and the service names will start attaching to something real. Use AWS's exam guide as your map, build your own notes, and let your practice results tell you where to spend the next hour.
Top comments (0)