
AWSCertified Cloud Practitioner
Domain 2Objective 4
Task Statement 2.4: Identify Components and Resources for Security. CLF-C02 Practice Questions (Page 6)
Part of the Security and Compliance domain, which makes up ~24% of our current practice bank. AWS does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
14concepts
Questions 26–30
- 26
A company has a VPC with a public subnet containing web servers and a private subnet containing database servers. They want to control traffic at the instance level, allowing only HTTP and HTTPS from the internet to the web servers, and only MySQL traffic from the web servers to the database servers. Which AWS service should they use for this?
Select an answer first - 27
Which of the following is an example of a security responsibility that remains with AWS, even for a customer-managed Amazon EC2 instance?
Select an answer first - 28
What is a key feature of AWS Secrets Manager?
Select an answer first - 29
A company has a compliance requirement that all S3 buckets must have versioning enabled. The security team wants to continuously monitor all accounts to identify any buckets that do not have versioning enabled and receive a notification when a non-compliant bucket is found. Which combination of AWS services should they use?
Select an answer first - 30
What is the primary purpose of an SSL/TLS certificate managed by AWS Certificate Manager?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “CLF-C02” is a trademark of its owner, used for identification only.