AWS Certified Cloud Practitioner (CLF-C02)
The AWS Certified Cloud Practitioner is the foundational Amazon Web Services certification for explaining cloud value, security and compliance, core AWS services, and cloud economics without implementing or troubleshooting workloads.
Exam at a glance
- Questions: 65 total; 50 scored and 15 unscored.
- Question styles: multiple choice and multiple response.
- Passing score: 700 on a 100-1,000 scale; scoring is compensatory across domains.
- Target experience: up to six months of exposure to AWS Cloud design, implementation, or operations.
- Out of scope: coding, architecture design, troubleshooting, implementation, and load/performance testing.
Domain map
- CLF-C02 Domain 1 - Cloud Concepts - 24%
- CLF-C02 Domain 2 - Security and Compliance - 30%
- CLF-C02 Domain 3 - Cloud Technology and Services - 34%
- CLF-C02 Domain 4 - Billing Pricing and Support - 12%
Domain 3 is the largest, but Domains 2 and 3 together make up 64% of scored content. Learn the boundary between services and the reason for choosing one, not implementation commands.
2026 version drift from the supplied study material
The supplied course PDF, cheat sheet, and terminology workbook are useful term banks, but they preserve several older names and services. AWS’s live exam guide is the source of truth for exam scope. As of August 17, 2026:
- Amazon QuickSight is still the name in the live CLF-C02 list, while the product evolved into Amazon Quick Suite and the BI capability is called Quick Sight. Know both labels.
- Amazon SageMaker AI, AWS Health Dashboard, Amazon WorkSpaces Secure Browser, and AWS Security Hub CSPM replace older SageMaker, Personal Health Dashboard, WorkSpaces Web, and Security Hub naming.
- The exam list still says AWS Application Migration Service, but the live product is now AWS Transform MGN. AWS Migration Hub stopped accepting new customers in November 2025; AWS points new migrations to AWS Transform.
- The guide still names AWS Schema Conversion Tool (SCT), but AWS now recommends DMS Schema Conversion; SCT is the legacy downloadable option.
- AWS Snow Family is no longer on the current in-scope list (verified against the live exam guide and the supplied exam-guide PDF, which agree exactly); it has been removed from the in-scope sections below. AWS also no longer offers Snow Family devices to new customers — current alternatives include AWS DataSync, AWS Data Transfer Terminal, partner devices, and AWS Outposts for edge compute.
- AWS Support Plans now center on Basic, Business Support+, Enterprise Support, and AWS Unified Operations. Developer, plain Business, and Enterprise On-Ramp continue only during their transition to January 1, 2027.
- The post-July-15-2025 AWS Free Tier provides new customers 100 more, a six-month Free plan or a Paid plan, and always-free offers. The older universal “12-month free tier” summary applies only to legacy offers/accounts.
- Amazon Kinesis Data Firehose is now Amazon Data Firehose; Amazon Kinesis Data Analytics is now Amazon Managed Service for Apache Flink; CloudWatch Evidently was discontinued in October 2025.
- CodeStar, Server Migration Service, OpsWorks, QLDB, and other older workbook/course entries are not on the current in-scope list. Keep their notes as historical or distractor context, not study priorities.
- Amazon Kendra, AWS AppSync, and AWS Audit Manager have also dropped off the current in-scope list — verified against both the live exam guide and the supplied exam-guide PDF, which agree exactly. They no longer appear in either the in-scope or out-of-scope sections of the guide; only AWS Firewall Manager remains in-scope for that role in the Security category, and AWS Artifact remains in-scope for compliance-document retrieval.
Current in-scope services
Analytics
- Amazon Athena
- Amazon EMR
- AWS Glue
- Amazon Kinesis
- Amazon OpenSearch Service
- Amazon QuickSight
- Amazon Redshift
Application integration and business applications
- Amazon EventBridge
- Amazon Simple Notification Service (Amazon SNS)
- Amazon Simple Queue Service (Amazon SQS)
- AWS Step Functions
- Amazon Connect
- Amazon Simple Email Service (Amazon SES)
Cloud financial management
Compute and containers
- AWS Batch
- Amazon EC2
- AWS Elastic Beanstalk
- Amazon Lightsail
- AWS Outposts
- Amazon Elastic Container Registry (ECR)
- Amazon Elastic Container Service (ECS)
- Amazon Elastic Kubernetes Service (EKS)
Customer enablement
Database
Developer tools
End-user, frontend, and mobile
Internet of Things
Machine learning
- Amazon Comprehend
- Amazon Lex
- Amazon Polly
- Amazon Q
- Amazon Rekognition
- Amazon SageMaker AI
- Amazon Textract
- Amazon Transcribe
- Amazon Translate
Management and governance
- AWS Auto Scaling
- AWS CloudFormation
- AWS CloudTrail
- Amazon CloudWatch
- AWS Compute Optimizer
- AWS Config
- AWS Control Tower
- AWS Health Dashboard
- AWS License Manager
- AWS Management Console
- AWS Organizations
- AWS Service Catalog
- Service Quotas
- AWS Systems Manager
- AWS Trusted Advisor
- AWS Well-Architected Tool
Migration and transfer
- AWS Application Discovery Service
- AWS Application Migration Service
- AWS Database Migration Service (DMS)
- Migration Evaluator
- AWS Migration Hub
- AWS Schema Conversion Tool (SCT)
Networking and content delivery
- Amazon API Gateway
- Amazon CloudFront
- AWS Direct Connect
- AWS Global Accelerator
- AWS PrivateLink
- Amazon Route 53
- AWS Transit Gateway
- Amazon VPC
- AWS VPN
- AWS Site-to-Site VPN
- AWS Client VPN
Security, identity, and compliance
- AWS Artifact
- AWS Certificate Manager (ACM)
- AWS CloudHSM
- Amazon Cognito
- Amazon Detective
- AWS Directory Service
- AWS Firewall Manager
- Amazon GuardDuty
- AWS Identity and Access Management (IAM)
- AWS IAM Identity Center
- Amazon Inspector
- AWS Key Management Service (KMS)
- Amazon Macie
- AWS Resource Access Manager (RAM)
- AWS Secrets Manager
- AWS Security Hub
- AWS Shield
- AWS WAF
Serverless and storage
- AWS Fargate
- AWS Lambda
- AWS Backup
- Amazon Elastic Block Store (EBS)
- Amazon Elastic File System (EFS)
- AWS Elastic Disaster Recovery
- Amazon FSx
- Amazon S3
- Amazon S3 Glacier
- AWS Storage Gateway
High-yield service boundaries
- CloudTrail vs CloudWatch vs Config: API activity vs operational telemetry/alarms vs resource configuration history/rules.
- GuardDuty vs Inspector vs Macie vs Detective vs Security Hub: threats vs workload vulnerabilities vs sensitive S3 data vs investigation vs aggregation/posture.
- SQS vs SNS vs EventBridge vs Step Functions: queue/buffer vs push fan-out vs event routing vs workflow orchestration.
- EBS vs EFS vs S3: block storage for compute, shared file storage, and object storage.
- Site-to-Site VPN vs Client VPN vs Direct Connect: encrypted network-to-network internet tunnel, encrypted user remote access, and dedicated private connectivity.
- RDS/Aurora vs DynamoDB vs ElastiCache: relational, NoSQL key-value/document, and in-memory cache/data store.
- Application Migration vs DMS: move whole servers vs move/replicate database data.