Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS logo

AWSCertified Cloud Practitioner

Domain 2Objective 3

Task Statement 2.3: Identify AWS Access Management Capabilities. CLF-C02 Practice Questions (Page 6)

Part of the Security and Compliance domain, which makes up ~24% of our current practice bank. AWS does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
8concepts

Questions 26–28

  1. 26application · medium

    A company uses AWS Organizations to manage 20 AWS accounts. The security team wants to ensure that no user in any member account can delete an S3 bucket, even if an administrator in that account grants themselves full permissions. What is the MOST effective way to enforce this restriction?

    Select an answer first
  2. 27expert · medium

    A company has a fleet of Amazon EC2 instances that need to access an Amazon S3 bucket. The instances are currently using long-term IAM access keys that are stored on the instances. The security team wants to eliminate the use of long-term keys on EC2 instances. What is the MOST secure and operationally efficient solution?

    Select an answer first
  3. 28foundation · easy

    Which AWS service allows you to centrally manage multiple AWS accounts and apply service control policies (SCPs) to them?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CLF-C02

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “CLF-C02” is a trademark of its owner, used for identification only.