Step2Study
IT & TechnologyCLF-C02100% Free

AWS Certified Cloud Practitioner (CLF-C02)

Practice bank
200 Qs
Real exam
65 Qs
Time limit
90 min
Passing
700 on a 100–1000 scale (~70%)

Exam blueprint

Cloud Concepts
24%
Security and Compliance
30%
Cloud Technology and Services
34%
Billing, Pricing, and Support
12%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 125 min · pass 70% · 200 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Part of a learning path

Study with friends

Challenge a friend to beat your score.

AWS Certified Cloud Practitioner (CLF-C02) practice test questions

Sample questions from the 200-question bank, with answers and explanations.

All questions
  1. 1. A company wants AWS to automatically apply an IAM policy that restricts EC2 launches once a defined monthly budget threshold is exceeded, without manual intervention. Which AWS Budgets feature enables this automated response?

    Billing, Pricing, and Support

    • A. Budget reports
    • B. Budget actions
    • C. Budget alerts
    • D. Cost anomaly detection
    Show answer

    B. Budget actions

    AWS Budgets Actions allow you to define automated or approval-based responses—such as applying an IAM or SCP policy, or stopping/terminating EC2 or RDS instances—when a budget threshold is exceeded. Budget alerts only send notifications and do not take direct action on resources.

  2. 2. A company's public web application already benefits, at no additional charge, from protection against the most common network and transport layer DDoS attacks. To gain access to the 24/7 DDoS Response Team (DRT) and cost protection for scaling during an attack, which AWS offering must the company subscribe to?

    Security and Compliance

    • A. AWS Shield Standard, which already provides this
    • B. AWS WAF managed rule groups
    • C. AWS Shield Advanced
    • D. AWS Firewall Manager
    Show answer

    C. AWS Shield Advanced

    AWS Shield Standard is automatically included at no cost and protects against common infrastructure-layer DDoS attacks, but 24/7 access to the DDoS Response Team and DDoS cost protection require an AWS Shield Advanced subscription, which is a paid service.

  3. 3. A large enterprise wants its cloud security team to set a maximum permission ceiling for a delegated administrator IAM role, ensuring that even if the role's attached policy is later broadened, the effective permissions can never exceed a defined limit. Which IAM feature should be used?

    Security and Compliance

    • A. IAM group policy
    • B. Service control policy (SCP)
    • C. Resource-based policy
    • D. IAM permissions boundary
    Show answer

    D. IAM permissions boundary

    An IAM permissions boundary is an advanced feature that sets the maximum permissions an identity-based policy can grant to a user or role; the effective permissions are the intersection of the boundary and the identity policy. SCPs apply at the AWS Organizations account level, not to individual roles within an account. Group policies and resource-based policies do not function as a permission ceiling for a single role.

  4. 4. An e-commerce company wants to route 80% of user traffic to a new application version and 20% to the legacy version to test performance before a full rollout. Which Route 53 routing policy should they configure?

    Cloud Technology and Services

    • A. Failover routing
    • B. Weighted routing
    • C. Geolocation routing
    • D. Latency-based routing
    Show answer

    B. Weighted routing

    Weighted routing lets you assign relative weights to resource records, allowing traffic to be split by percentage between multiple versions of an application, ideal for canary testing or gradual rollouts.

  5. 5. A compliance analyst needs to view a timeline showing how the configuration of a specific Amazon EC2 security group changed over the past six months, including a snapshot of its settings at each point in time. Which AWS service provides this capability?

    Security and Compliance

    • A. AWS Trusted Advisor
    • B. AWS CloudTrail
    • C. AWS Config
    • D. Amazon GuardDuty
    Show answer

    C. AWS Config

    AWS Config continuously records resource configuration changes and maintains a configuration history/timeline, letting you view a resource's state at any past point in time. CloudTrail logs API calls (who did what) but does not store configuration snapshots over time.

  6. 6. A holding company uses AWS Organizations with consolidated billing across two member accounts using Amazon S3 Standard storage, priced at $0.023/GB for the first 50,000 GB and $0.022/GB for the next tier. Account A stores 30,000 GB and Account B stores 40,000 GB in the same Region. How much does consolidated billing save compared to billing each account separately?

    Billing, Pricing, and Support

    • A. $20
    • B. $1,590
    • C. $200
    • D. $0
    Show answer

    A. $20

    Billed separately: Account A pays 30,000 × $0.023 = $690; Account B pays 40,000 × $0.023 = $920 (both under the 50,000GB tier), totaling $1,610. Combined under consolidated billing, total usage is 70,000GB: 50,000 × $0.023 = $1,150 plus 20,000 × $0.022 = $440, totaling $1,590. The savings is $1,610 − $1,590 = $20.

  7. 7. A security team needs to control traffic at the subnet level within a VPC, including the ability to explicitly DENY specific IP ranges, and wants the rules evaluated in numbered order as stateless filters. Which VPC feature should they configure?

    Cloud Technology and Services

    • A. Security Groups
    • B. VPC Peering
    • C. Route Tables
    • D. Network ACLs
    Show answer

    D. Network ACLs

    Network ACLs (NACLs) operate at the subnet level, are stateless, evaluate numbered rules in order, and support both ALLOW and explicit DENY rules, unlike Security Groups which only support ALLOW rules and are stateful.

  8. 8. During an AWS Cloud Adoption Framework (CAF) assessment, business managers, finance leaders, and program managers evaluate how cloud migration will support strategic business outcomes, improve time-to-market, and align IT spending with business value. Which CAF perspective does this represent?

    Cloud Concepts

    • A. Business Perspective
    • B. Operations Perspective
    • C. Platform Perspective
    • D. Governance Perspective
    Show answer

    A. Business Perspective

    The Business Perspective of the AWS CAF helps stakeholders such as business managers and finance ensure that cloud investments accelerate digital transformation and align with business strategy and ROI targets.

  9. 9. A retail analytics company stores customer usage logs with highly unpredictable and changing access patterns—some objects are accessed daily for weeks, then not touched for months, with no way to predict which. The company wants AWS to automatically move objects between access tiers to optimize cost without manual lifecycle rules. Which S3 storage class should they use?

    Cloud Technology and Services

    • A. S3 Intelligent-Tiering
    • B. S3 Standard-IA
    • C. S3 Glacier Instant Retrieval
    • D. S3 One Zone-IA
    Show answer

    A. S3 Intelligent-Tiering

    S3 Intelligent-Tiering automatically moves objects between frequent, infrequent, and archive access tiers based on changing access patterns, without operational overhead or retrieval fees, making it ideal for unpredictable workloads.

  10. 10. A company running a globally distributed e-commerce site is repeatedly targeted by large-scale volumetric DDoS attacks and needs proactive DDoS response support along with cost protection for scaling charges incurred during attacks. Which service tier should they subscribe to?

    Security and Compliance

    • A. Amazon GuardDuty with S3 protection enabled
    • B. AWS WAF managed rule groups
    • C. AWS Shield Standard
    • D. AWS Shield Advanced
    Show answer

    D. AWS Shield Advanced

    AWS Shield Advanced provides enhanced DDoS protection, 24/7 access to the AWS DDoS Response Team (DRT), and cost protection against scaling charges resulting from DDoS attacks, whereas Shield Standard offers only basic automatic protection with no DRT access or cost protection.

  11. 11. A company's cloud architecture diagram shows a single geographic location containing three physically separate data centers, each with independent power, cooling, and networking, connected by high-bandwidth, low-latency links. What does this diagram represent?

    Cloud Technology and Services

    • A. A single Availability Zone
    • B. A single data center with redundant racks
    • C. A Region containing multiple Availability Zones
    • D. An Edge Location
    Show answer

    C. A Region containing multiple Availability Zones

    An AWS Region is a geographic area containing multiple isolated Availability Zones (AZs), each consisting of one or more discrete data centers with independent power and networking, interconnected by high-bandwidth, low-latency links.

  12. 12. A security architect needs to grant a partner AWS account direct decrypt access to objects encrypted with a customer managed KMS key, without adding that partner account's IAM users into the key owner's account. Where must this cross-account permission be defined?

    Security and Compliance

    • A. In a CloudTrail trail configuration
    • B. In an S3 bucket policy only
    • C. In the KMS key policy of the key owner's account
    • D. In an IAM group policy in the partner account
    Show answer

    C. In the KMS key policy of the key owner's account

    KMS key policies are resource-based policies attached directly to the key and are the only mechanism that governs access to a KMS key from outside the key owner's account. To grant cross-account access, the key policy must explicitly allow the external account, which can then delegate use of the key to its own IAM principals via IAM policies. A bucket policy alone cannot grant decrypt permission on a KMS key.

  13. 13. A developer has long-lived IAM access keys embedded in a script that has not been rotated in over two years. A security audit flags this as a risk. What is the recommended best practice to remediate this finding?

    Security and Compliance

    • A. Attach an SCP that permanently blocks the sts:GetSessionToken action
    • B. Increase the IAM password policy expiration period to cover access keys as well
    • C. Replace long-lived access keys with an IAM role that provides temporary credentials, or rotate the keys regularly if a role cannot be used
    • D. Enable GuardDuty to automatically delete old access keys after 90 days
    Show answer

    C. Replace long-lived access keys with an IAM role that provides temporary credentials, or rotate the keys regularly if a role cannot be used

    AWS best practice is to avoid long-lived credentials altogether by using IAM roles that provide short-term temporary credentials via STS; when access keys are unavoidable, they should be rotated regularly and unused ones removed.

  14. 14. A security team wants a service that automatically analyzes findings from GuardDuty and other data sources, visually mapping relationships between resources, IP addresses, and users to help investigate the root cause of a potential security incident. Which AWS service should they use?

    Security and Compliance

    • A. AWS Artifact
    • B. AWS Trusted Advisor
    • C. AWS Config
    • D. Amazon Detective
    Show answer

    D. Amazon Detective

    Amazon Detective automatically collects log data from sources like GuardDuty, VPC Flow Logs, and CloudTrail, and builds a graph-based model to help security teams visualize relationships and investigate the root cause of findings. AWS Config tracks resource configuration compliance, AWS Artifact provides compliance documentation, and Trusted Advisor gives account optimization recommendations, none of which perform security investigation visualization.

  15. 15. A company is decoupling a web application from a backend order-processing service using a message queue. Message order does not need to be strictly preserved, but the company wants a highly scalable, fully managed queue that guarantees each message is delivered at least once. Which AWS service and queue type BEST fits this need?

    Cloud Technology and Services

    • A. Amazon SNS topic
    • B. Amazon Kinesis Data Streams
    • C. Amazon SQS FIFO queue
    • D. Amazon SQS Standard queue
    Show answer

    D. Amazon SQS Standard queue

    Amazon SQS Standard queues provide nearly unlimited throughput, at-least-once delivery, and best-effort ordering, making them ideal for decoupling applications when strict message order isn't required.

  16. 16. A company is designing a VPC architecture for a three-tier web application. Web servers must be reachable from the internet, while the database servers must never be directly accessible from the internet. How should the company design the subnets to meet this requirement?

    Cloud Technology and Services

    • A. Place both the web servers and database servers in the same public subnet
    • B. Place both the web servers and database servers in a private subnet with no internet gateway
    • C. Place the web servers in a public subnet and the database servers in a private subnet
    • D. Place the web servers in a private subnet and the database servers in a public subnet
    Show answer

    C. Place the web servers in a public subnet and the database servers in a private subnet

    Public subnets have a route to an internet gateway and should host resources like web servers that need direct internet access, while private subnets lack a direct internet gateway route and are appropriate for backend resources like databases that should stay isolated from the public internet.

  17. 17. A small business on the Basic Support plan wants to check whether any of its S3 buckets are publicly accessible using AWS Trusted Advisor, even though it has not upgraded to a paid support plan. Is this possible?

    Billing, Pricing, and Support

    • A. No, Trusted Advisor is only available with Enterprise Support
    • B. No, Trusted Advisor requires at least Business Support for any checks
    • C. Yes, all customers have access to a core set of checks including some security checks regardless of plan
    • D. Yes, but only if the account is part of an AWS Organizations consolidated billing family
    Show answer

    C. Yes, all customers have access to a core set of checks including some security checks regardless of plan

    Trusted Advisor provides a limited set of core checks—covering service limits and certain security checks like S3 bucket permissions and security group rules—free to all customers regardless of support plan. Full access to all checks across cost optimization, performance, fault tolerance, and service limits requires Business or Enterprise Support.

  18. 18. A company sets up an AWS Budget with an alert configured to trigger when forecasted spend is projected to exceed the monthly budget amount, rather than waiting until actual spend exceeds it. What is the primary advantage of using a forecasted-based alert instead of an actual-cost alert?

    Billing, Pricing, and Support

    • A. It notifies stakeholders proactively before overspending actually occurs
    • B. It reduces the AWS bill automatically when triggered
    • C. It automatically shuts down resources exceeding budget
    • D. It replaces the need for Cost Explorer entirely
    Show answer

    A. It notifies stakeholders proactively before overspending actually occurs

    Forecasted alerts use trend data to predict whether spend will exceed the budget by the end of the period, allowing teams to take corrective action proactively rather than after the overage has already occurred.

  19. 19. A new AWS customer wants to experiment with a small workload using S3, Lambda, and EC2 t2.micro instances for the first 12 months without incurring charges, as long as usage stays within specified monthly limits. Which AWS offering enables this?

    Billing, Pricing, and Support

    • A. AWS Budgets
    • B. AWS Free Tier
    • C. Savings Plans
    • D. AWS Marketplace free trial
    Show answer

    B. AWS Free Tier

    The AWS Free Tier provides limited free usage of many services, including 750 hours/month of t2.micro EC2 usage and 5GB of S3 storage, for 12 months after account creation, as well as some always-free services. This lets new customers explore AWS at no cost within defined limits.

  20. 20. A company wants to conduct authorized penetration testing against its EC2 instances and Application Load Balancer to validate its security posture. According to AWS's customer policies, what must the company do before starting the test?

    Security and Compliance

    • A. Purchase AWS Shield Advanced, which is a mandatory prerequisite for any penetration testing
    • B. Nothing; AWS permits penetration testing on most owned services without prior approval for commonly tested services
    • C. Obtain written approval from every third-party vendor whose software is hosted on the instances
    • D. Submit a request and wait for AWS Support to personally perform the test on their behalf
    Show answer

    B. Nothing; AWS permits penetration testing on most owned services without prior approval for commonly tested services

    AWS has published a policy that allows customers to perform penetration testing against their own AWS resources for a defined list of commonly tested services (including EC2 instances, NAT gateways, and ELBs) without prior approval, as long as testing complies with AWS's Acceptable Use Policy and does not target prohibited activities like DDoS simulation. There is no requirement for AWS Support to personally run the test, third-party vendor approval, or Shield Advanced purchase.

  21. 21. A developer wants to understand how AWS KMS efficiently encrypts large objects without sending the entire object to the KMS service for direct encryption. Which encryption approach does AWS KMS use to accomplish this?

    Security and Compliance

    • A. Client-side encryption using only the application's local library
    • B. Direct symmetric encryption of the full object using the customer master key
    • C. Envelope encryption using a data key generated and encrypted by KMS
    • D. Asymmetric encryption of the entire object using a public/private key pair
    Show answer

    C. Envelope encryption using a data key generated and encrypted by KMS

    KMS uses envelope encryption: it generates a unique data key, which is used locally to encrypt the actual data, and then the data key itself is encrypted by the KMS key (CMK) and stored alongside the ciphertext. This avoids sending large amounts of data to KMS directly, since the CMK never leaves KMS and only the small data key is encrypted/decrypted through the service.

  22. 22. A company wants to deploy a managed network security service that provides stateful traffic inspection, intrusion prevention, and fine-grained filtering rules for traffic entering and leaving its Amazon VPCs. Which AWS service best fits this requirement?

    Security and Compliance

    • A. AWS Network Firewall
    • B. AWS WAF
    • C. AWS Shield
    • D. Security groups
    Show answer

    A. AWS Network Firewall

    AWS Network Firewall is a managed, stateful network firewall service designed for VPC-level traffic filtering, including intrusion prevention and detection. WAF protects web applications at the HTTP layer, Shield defends against DDoS attacks, and security groups are instance-level stateful firewalls without intrusion prevention capabilities.

  23. 23. A security team enables a GuardDuty feature that automatically scans Amazon EBS volumes attached to EC2 instances flagged with suspicious activity, looking for known malware file signatures. Which GuardDuty capability does this describe?

    Security and Compliance

    • A. GuardDuty EKS Protection
    • B. GuardDuty S3 Protection
    • C. GuardDuty Malware Protection
    • D. GuardDuty Threat Intelligence Feeds
    Show answer

    C. GuardDuty Malware Protection

    GuardDuty Malware Protection scans EBS volumes attached to EC2 instances or container workloads when suspicious behavior is detected, checking for malware signatures. S3 Protection monitors S3 data events, EKS Protection analyzes Kubernetes audit logs, and Threat Intelligence Feeds are data sources GuardDuty uses broadly, not a volume-scanning feature.

  24. 24. A company runs a containerized application on Amazon ECS and wants full control over the underlying EC2 instances, including the ability to install custom monitoring agents directly on the host operating system and choose specific instance types for cost optimization. Which ECS launch type should the company use?

    Cloud Technology and Services

    • A. EC2 launch type
    • B. AWS Fargate launch type
    • C. External launch type only
    • D. Lambda launch type
    Show answer

    A. EC2 launch type

    The ECS EC2 launch type requires the customer to provision and manage the underlying EC2 instances, giving full control over instance types, host-level agents, and OS configuration, unlike Fargate which abstracts away the infrastructure entirely.

  25. 25. A developer wants an AWS storage service that multiple EC2 instances across different Availability Zones can mount and read/write simultaneously using standard file system protocols. Which service should they use?

    Cloud Technology and Services

    • A. Amazon EFS
    • B. Instance Store
    • C. Amazon EBS
    • D. Amazon S3
    Show answer

    A. Amazon EFS

    Amazon EFS is a fully managed, scalable NFS file system that can be mounted concurrently by multiple EC2 instances across multiple Availability Zones, providing shared file storage.

AWS Certified Cloud Practitioner (CLF-C02) flashcards

Tap a card to flip it. 171 flashcards in the full deck.

  • AWS Budgets Actions

    Flip card

    A feature of AWS Budgets that triggers automated or approval-based actions, such as applying IAM policies or stopping instances, when budget thresholds are exceeded.

    • Can apply IAM or SCP policies automatically
    • Can stop or terminate EC2/RDS instances
    • Actions can require manual approval or run automatically
    Study this card →
  • Shield Standard vs Shield Advanced

    Flip card

    AWS Shield Standard provides free, automatic protection against common DDoS attacks; Shield Advanced is a paid tier adding DDoS Response Team access, cost protection, and advanced mitigation for larger/sophisticated attacks.

    • Shield Standard: free, automatic, all AWS customers
    • Shield Advanced: paid subscription with DRT support and cost protection
    • Shield Advanced also integrates with WAF for enhanced application-layer mitigation
    Study this card →
  • IAM Permissions Boundary

    Flip card

    An advanced IAM feature that defines the maximum permissions an identity-based policy can grant to a user or role.

    • Effective permissions = intersection of boundary and identity policy
    • Used for delegated administration
    • Different from SCPs which apply at the Organizations account level
    Study this card →
  • Route 53 Weighted Routing

    Flip card

    A routing policy that distributes traffic across multiple resources based on assigned weight values, useful for testing and gradual deployments.

    • Weights determine traffic percentage
    • Common for A/B testing and canary releases
    • Weights can be adjusted dynamically
    Study this card →
  • AWS Config Configuration Timeline

    Flip card

    AWS Config records resource configuration changes over time, enabling review of a resource's configuration history and compliance status.

    • Config records configuration snapshots and change history
    • Config Rules evaluate compliance continuously
    • Different from CloudTrail, which logs API calls
    Study this card →
  • Consolidated Billing Volume Discounts

    Flip card

    AWS Organizations consolidated billing aggregates usage across accounts, letting combined usage reach lower-priced volume tiers faster.

    • Applies to services like S3 with tiered pricing
    • Master/management account receives one combined bill
    • Savings arise because usage tiers are combined across accounts
    Study this card →
  • Network ACLs

    Flip card

    A stateless, subnet-level firewall in a VPC that evaluates numbered rules in order and supports both allow and explicit deny rules.

    • Operate at the subnet level, not instance level
    • Stateless — return traffic must be explicitly allowed
    • Support explicit DENY rules, unlike Security Groups
    Study this card →
  • CAF Business Perspective

    Flip card

    A CAF perspective helping business managers, finance, and strategy stakeholders align cloud investments with business outcomes.

    • Involves finance and program managers
    • Focuses on ROI and business case for cloud
    • One of six CAF perspectives
    Study this card →
  • S3 Intelligent-Tiering

    Flip card

    An S3 storage class that automatically moves objects between access tiers based on changing access patterns to optimize storage cost.

    • No retrieval fees for tier changes
    • Ideal for unpredictable or unknown access patterns
    • Monitors access and moves objects automatically
    Study this card →
  • AWS Shield Advanced

    Flip card

    A paid DDoS protection service offering enhanced detection, 24/7 DDoS Response Team access, and cost protection against attack-related scaling charges.

    • Shield Standard is free and automatically enabled for all AWS customers
    • Shield Advanced requires a subscription with a 1-year commitment
    • Provides cost protection for scaling charges due to DDoS attacks on protected resources
    Study this card →
  • Regions and Availability Zones

    Flip card

    An AWS Region is a geographic area containing multiple isolated Availability Zones (AZs), each made up of one or more data centers with independent infrastructure.

    • Regions contain 2 or more AZs (most have 3+)
    • AZs are physically separated but connected via low-latency links
    • Edge locations are separate, used for CloudFront caching
    Study this card →
  • KMS Key Policy

    Flip card

    A resource-based policy attached to a KMS key that controls who can use and manage the key, required for cross-account access.

    • Every KMS key must have a key policy
    • Cross-account access requires both key policy and IAM policy grants
    • Default key policy gives full access only to the account root
    Study this card →
  • Access Key Rotation Best Practice

    Flip card

    AWS recommends using IAM roles for temporary credentials instead of long-lived access keys, and rotating any necessary access keys regularly.

    • Long-lived access keys increase risk if leaked or forgotten
    • IAM roles issue temporary credentials via AWS STS automatically
    • When keys are required, rotate periodically and remove unused/old keys
    Study this card →
  • Amazon Detective

    Flip card

    A service that automatically collects and analyzes log data to build visual graphs helping security teams investigate the root cause of security findings.

    • Ingests data from GuardDuty, VPC Flow Logs, CloudTrail
    • Provides interactive visualizations of resource relationships
    • Used for root-cause investigation, not initial detection
    Study this card →
  • SQS Standard Queue

    Flip card

    A fully managed message queue offering nearly unlimited throughput and at-least-once delivery, with best-effort message ordering.

    • Default SQS queue type
    • At-least-once delivery, possible duplicates
    • Higher throughput than FIFO queues
    Study this card →
  • Public vs Private Subnets

    Flip card

    Public subnets route traffic to an internet gateway, allowing direct internet access; private subnets do not have this direct route, isolating resources from the internet.

    • Public subnets host internet-facing resources like web servers or load balancers
    • Private subnets host backend resources like databases
    • NAT gateways allow private subnet outbound internet access without inbound exposure
    Study this card →
  • Trusted Advisor Core Checks

    Flip card

    A limited free set of Trusted Advisor checks (including service limits and select security checks) available to all AWS customers regardless of support plan.

    • Core checks include service limits and some security checks
    • Full 100+ checks require Business or Enterprise Support
    • Business/Enterprise also add programmatic access via API
    Study this card →
  • AWS Budgets Forecasted Alerts

    Flip card

    A budget alert type that notifies users when AWS predicts spend will exceed a set threshold by period end, based on usage trends.

    • Alert types include Actual and Forecasted cost/usage.
    • Notifications can go to SNS topics, email, or chatbot integrations.
    • Budgets can also trigger automated actions like applying IAM policies or stopping instances (Budgets Actions).
    Study this card →
  • AWS Free Tier

    Flip card

    A program offering limited free usage of AWS services for new accounts, including 12-month trials and always-free offers.

    • 750 hrs/month t2.micro EC2 for 12 months
    • 5GB S3 standard storage for 12 months
    • Some services like Lambda have an always-free tier
    Study this card →
  • AWS Penetration Testing Policy

    Flip card

    AWS allows customers to conduct penetration tests against their own resources for a list of commonly tested services without prior approval, subject to the Acceptable Use Policy.

    • No prior approval needed for permitted services (EC2, ELB, NAT gateways, etc.)
    • Prohibited actions include DNS zone walking and DDoS simulation
    • Some services still require special permission requests
    Study this card →
  • Envelope Encryption (KMS)

    Flip card

    A technique where a data key encrypts the actual data locally, and the data key itself is then encrypted by a KMS master key, avoiding sending large data to KMS.

    • KMS generates a plaintext and encrypted copy of the data key via GenerateDataKey
    • The CMK never leaves the KMS service boundary
    • Only the small encrypted data key needs to be decrypted by KMS to unlock the data
    Study this card →
  • AWS Network Firewall

    Flip card

    A managed, stateful network firewall and intrusion prevention service for filtering traffic to and from Amazon VPCs.

    • Operates at the VPC level, unlike security groups which are per-instance
    • Supports domain filtering, stateful rules, and intrusion prevention signatures
    • Integrates with AWS Firewall Manager for centralized policy management
    Study this card →
  • GuardDuty Malware Protection

    Flip card

    A GuardDuty feature that automatically scans EBS volumes attached to EC2 instances or containers flagged with suspicious findings, checking for malware.

    • Triggered by suspicious GuardDuty findings tied to an EC2 instance
    • Performs agentless scanning of EBS snapshots
    • Generates malware findings that feed into the GuardDuty console and Security Hub
    Study this card →
  • ECS EC2 Launch Type

    Flip card

    An ECS launch type where customers manage and provision the underlying EC2 instances that host containers, offering full control over infrastructure.

    • Contrasts with Fargate's serverless model
    • Requires capacity planning and instance management
    • Allows custom AMIs, agents, and instance type selection
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.