
AWSCertified Cloud Practitioner
Domain 2Objective 3
Task Statement 2.3: Identify AWS Access Management Capabilities. CLF-C02 Practice Questions (Page 4)
Part of the Security and Compliance domain, which makes up ~24% of our current practice bank. AWS does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
8concepts
Questions 16–20
- 16
An application running on an Amazon EC2 instance needs to read objects from an Amazon S3 bucket. Which IAM construct is designed to grant the application temporary permissions without embedding long-term credentials in the instance?
Select an answer first - 17
What are AWS access keys used for?
Select an answer first - 18
A company has a team of developers who need to manage their own IAM users and groups. The security team wants to ensure that the developers can create and manage IAM resources, but they must NOT be able to delete the root user or modify the IAM password policy. What is the MOST appropriate way to grant these permissions?
Select an answer first - 19
A company has an AWS Organization with multiple accounts. The security team wants to ensure that no IAM user in any member account can launch EC2 instances with a public IP address. The team also wants to allow account administrators to manage their own IAM users. What is the MOST effective way to enforce this restriction?
Select an answer first - 20
A company is using AWS IAM Identity Center for SSO. The security team wants to add an extra layer of security by requiring all users to provide a one-time code from a mobile authenticator app in addition to their password. What is the MOST appropriate way to configure this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “CLF-C02” is a trademark of its owner, used for identification only.