AWSSeptember 30, 202623 min read

AWS Cloud Practitioner Glossary: 55 Terms for CLF-C02 (2026)

The 55 terms the CLF-C02 exam guide actually tests, each with a plain-English definition and the cue words that signal it in a question, plus 6 look-alike pairs and 60+ acronyms.

  • 55Terms defined
  • 65Acronyms
  • CLF-C02Exam
  • 50 of 65Scored Qs
  • 700 / 1000Pass mark
AWS Cloud Practitioner CLF-C02 glossary of key terms and acronyms

How to use this glossary

CLF-C02 is a vocabulary exam in disguise. It never asks you to build anything; it describes a business need and offers four AWS service names that sound alike. Candidates who fail usually knew the services existed but mixed up CloudTrail with CloudWatch, or AWS Budgets with Cost Explorer. This glossary defines the 55 terms the exam guide leans on and shows how each one is phrased in questions.

Version check (September 2026): CLF-C02 is still the current exam and AWS has not announced a CLF-C03 or a retirement date. The exam guide has been refreshed in place, though: support options now read Basic, Business Support+, Enterprise and Unified Operations, because Developer, Business and Enterprise On-Ramp support end on January 1, 2027. The Italian and German exam versions retire after December 31, 2026.

Every term below is tagged with the exam domain it belongs to. This is where the vocabulary load sits across the CLF-C02 blueprint:

  • D1Cloud Concepts24%9 terms
  • D2Security and Compliance30%15 terms
  • D3Cloud Technology and Services34%21 terms
  • D4Billing, Pricing, and Support12%10 terms

Each card has three layers: a plain-English definition, an On the exam line describing how questions use the term, and — where one exists — the term it is most often confused with. Click that link to jump straight to the rival definition.

The A–Z glossary

Amazon InspectorD2

An automated vulnerability-management service that scans EC2 instances, container images and Lambda functions for known software vulnerabilities and unintended network exposure.

On the examCue: 'scan for CVEs', 'software vulnerabilities', 'unpatched packages'. It is not a firewall and not threat detection - those answers are AWS WAF and GuardDuty.

Don’t confuse with GuardDuty

Availability ZoneD3

One or more discrete data centers with redundant power, networking and connectivity inside a Region, physically separated from other AZs so they share no single point of failure.

On the examCue: 'high availability' or 'survive a data center failure' - deploy across multiple AZs. Multi-Region is for disaster recovery or global latency, a bigger and costlier step.

Don’t confuse with Region

AWS ArtifactD2

A self-service portal for downloading AWS's own compliance reports, such as SOC and ISO attestations, and for accepting agreements like the HIPAA Business Associate Addendum.

On the examWhenever an auditor needs AWS compliance reports or certifications, the answer is Artifact. AWS Config and CloudTrail describe your resources, not AWS's attestations.

AWS BudgetsD4

Lets you set custom cost, usage, Reserved Instance or Savings Plans budgets and sends alerts, or triggers actions, when actual or forecasted amounts cross a threshold.

On the examCue: 'alert me when spending exceeds', 'notify before we overspend', 'threshold'. Budgets looks forward and alerts; Cost Explorer looks back and analyzes.

Don’t confuse with Cost Explorer

AWS CAFAWS Cloud Adoption FrameworkD1

Guidance that helps an organization plan its cloud adoption across six perspectives - Business, People, Governance, Platform, Security and Operations - and tie the move to business outcomes.

On the examScenarios about organizational change, staff skills or business outcomes of migration point to the CAF. Know the guide's listed benefits: reduced business risk, better ESG performance, increased revenue, operational efficiency.

Don’t confuse with Well-Architected Framework

AWS ConfigD2

Continuously records the configuration of your AWS resources, keeps a history of changes and evaluates resources against rules to flag non-compliant settings.

On the examCue: 'what did this security group look like last week', 'check resources comply with a rule'. Config tracks resource state; CloudTrail tracks the API call that changed it.

Don’t confuse with CloudTrail

AWS ShieldD2

Managed DDoS protection. Shield Standard is automatic and free for every customer; Shield Advanced adds enhanced detection, a response team and DDoS cost protection for a fee.

On the examCue: 'DDoS'. Shield Standard is already included at no cost; pick Shield Advanced when the scenario wants 24/7 DDoS response team access or protection from scaling charges.

Don’t confuse with AWS WAF

AWS WAFAWS Web Application FirewallD2

A web application firewall that filters HTTP(S) requests to CloudFront, Application Load Balancer or API Gateway using rules, blocking patterns such as SQL injection and cross-site scripting.

On the examCue: 'SQL injection', 'block requests from certain IPs or countries', 'layer 7'. WAF inspects requests, Shield absorbs volumetric DDoS, and security groups filter at the resource level.

Don’t confuse with AWS Shield

Business Support+AWS Business Support+D4

The entry paid plan in AWS's current support lineup, combining AI-powered assistance with 24/7 access to AWS experts. It replaces Developer and Business Support, which end on January 1, 2027.

On the examThe current CLF-C02 guide lists Basic, Business Support+, Enterprise and Unified Operations. Older practice banks still cite Developer, Business and Enterprise On-Ramp - learn the current names.

Don’t confuse with Enterprise Support

CapExCapital ExpenditureD1

Up-front spending on physical assets such as servers and data centers. Moving to AWS trades this fixed capital expense for a variable operating expense (OpEx) billed only for what you use.

On the examThe classic cloud benefit is 'trade fixed expense for variable expense'. If a scenario mentions big upfront hardware purchases or guessing capacity, the cloud answer turns CapEx into OpEx.

CloudFormationAWS CloudFormationD3

Infrastructure as code: you describe AWS resources in JSON or YAML templates and CloudFormation creates, updates and deletes them together as a stack, repeatably.

On the examCue: 'repeatable', 'infrastructure as code', 'provision identical environments'. The guide contrasts IaC with one-time console clicks; repeatable deployments point to CloudFormation.

CloudFrontAmazon CloudFrontD3

AWS's content delivery network, caching static and dynamic content at edge locations worldwide to cut latency for users who are far from the origin server.

On the examCue: 'global users', 'reduce latency', 'cache videos or images'. It integrates with Shield and WAF at the edge. Route 53 resolves names; CloudFront delivers content.

CloudTrailAWS CloudTrailD2

Records API calls and account activity - who did what, when and from where - creating an audit trail of actions taken through the console, CLI and SDKs.

On the examCue words: 'who deleted', 'which user', 'audit API calls'. CloudTrail answers who did it; CloudWatch answers how the resource is performing.

Don’t confuse with CloudWatch

CloudWatchAmazon CloudWatchD3

The monitoring service that collects metrics, logs and events from AWS resources and applications, and drives alarms and dashboards based on thresholds.

On the examCue: 'CPU utilization', 'set an alarm', 'monitor performance'. The exam guide files CloudWatch under monitoring and CloudTrail and Config under auditing - keep that split.

Don’t confuse with CloudTrail

Consolidated BillingD4

An AWS Organizations feature that rolls all member accounts into one bill paid by the management account, pooling usage so the organization reaches volume pricing tiers sooner.

On the examCue: 'single bill for multiple accounts', 'combine usage for volume discounts'. Reserved Instance and Savings Plans discounts can also be shared across accounts in the organization.

Cost ExplorerAWS Cost ExplorerD4

An interactive tool to visualize, filter and analyze your past AWS costs and usage, with forecasts and Reserved Instance or Savings Plans purchase recommendations.

On the examCue: 'analyze spending trends', 'which service cost the most last quarter'. To estimate a workload you have not built yet, the answer is AWS Pricing Calculator instead.

Direct ConnectAWS Direct ConnectD3

A dedicated private network connection from your data center or office to AWS that bypasses the public internet for more consistent bandwidth and latency.

On the examCue: 'dedicated', 'private', 'consistent performance', 'does not traverse the internet'. Site-to-Site VPN is quicker to set up and encrypted but runs over the public internet.

DynamoDBAmazon DynamoDBD3

A fully managed, serverless NoSQL key-value and document database that delivers single-digit millisecond performance at virtually any scale.

On the examCue: 'NoSQL', 'key-value', 'millions of requests per second', 'serverless database'. A relational schema or complex joins points back to RDS or Aurora.

Don’t confuse with RDS

EBSAmazon Elastic Block StoreD3

Block-storage volumes that attach to EC2 instances like a network hard drive, persisting independently of the instance and backed up with point-in-time snapshots.

On the examCue: 'boot volume', 'database on an EC2 instance', 'block storage'. A volume lives in a single AZ; instance store is temporary storage lost when the instance stops.

Don’t confuse with S3

EC2Amazon Elastic Compute CloudD3

Resizable virtual servers, called instances, where you choose the instance type, operating system and storage, and you manage the OS, patching and applications.

On the examKnow instance families by use case: general purpose, compute optimized, memory optimized, storage optimized. Full OS control or long-running servers point to EC2.

EC2 Auto ScalingAmazon EC2 Auto ScalingD3

Automatically adds or removes EC2 instances based on demand, schedules or health checks, keeping the right capacity running and replacing unhealthy instances.

On the examOften paired with ELB in one scenario. Auto Scaling changes how many instances exist; ELB spreads traffic across them. Elasticity questions resolve to Auto Scaling.

Don’t confuse with ELB

Economies of ScaleD1

AWS buys hardware, power and network capacity at enormous volume and passes the lower unit cost on to customers through pay-as-you-go prices that tend to fall over time.

On the examQuestion asks why AWS can charge less than running your own data center, or why prices drop over time. The answer is economies of scale, not elasticity or agility.

Edge LocationD3

A site in AWS's global network, far more numerous than Regions, where CloudFront caches content and Route 53 answers DNS queries close to end users.

On the examCue: 'lower latency for global users', 'cache static content near viewers'. Edge locations do not run your EC2 instances; that is a Region and Availability Zone job.

ElasticityD1

The ability to add or remove resources automatically as demand rises and falls, so you pay only for the capacity you actually use instead of buying for peak load.

On the examCue words: 'unpredictable traffic', 'scale in and out automatically'. Elasticity is the benefit; EC2 Auto Scaling is the service that delivers it. Don't pick 'high availability' for a demand-driven scenario.

ELBElastic Load BalancingD3

Distributes incoming traffic across multiple targets, such as EC2 instances in several Availability Zones, and routes requests only to targets that pass health checks.

On the examCue: 'distribute traffic', 'single point of entry', 'route around unhealthy instances'. It does not launch new instances - that is EC2 Auto Scaling.

Enterprise SupportAWS Enterprise SupportD4

The support tier for business-critical workloads, including a designated Technical Account Manager, 15-minute response for critical cases and proactive guidance. Enterprise On-Ramp customers are being moved to it during 2026.

On the examCue: 'designated TAM', 'proactive architecture guidance', 'business-critical'. AWS Unified Operations sits above it for the most demanding mission-critical environments.

GuardDutyAmazon GuardDutyD2

A managed threat-detection service that analyzes sources such as CloudTrail events, VPC Flow Logs and DNS logs with machine learning to spot malicious or unusual activity.

On the examCue: 'detect compromised instances', 'unusual API activity', 'intelligent threat detection'. GuardDuty watches behavior; Inspector scans workloads for software vulnerabilities.

Don’t confuse with Amazon Inspector

IAM Identity CenterD2

The AWS service, successor to AWS Single Sign-On, for centrally managing workforce access to multiple AWS accounts and applications, optionally federated with an external identity provider.

On the examCue: 'employees need single sign-on across many accounts in AWS Organizations' or 'use our existing corporate directory'. Creating IAM users in every account is the wrong answer.

IAM RoleD2

An identity with permissions but no permanent credentials. A trusted user, AWS service or another account assumes it and receives temporary security credentials.

On the examPick a role when an EC2 instance needs to call S3, or for cross-account access. Storing access keys on the instance is the distractor.

Don’t confuse with IAM User

IAM UserD2

An identity inside an AWS account representing one person or application, with long-term credentials such as a password or access keys and permissions granted through policies.

On the examBest-practice answers assign permissions through groups and prefer roles or IAM Identity Center over long-term access keys. 'Share one IAM user across the team' is always wrong.

Don’t confuse with IAM Role

KMSAWS Key Management ServiceD2

A managed service to create, control and audit the cryptographic keys used to encrypt data across AWS services, with keys protected by hardware security modules.

On the examCue: 'create and manage encryption keys', 'encryption at rest'. Don't confuse it with Secrets Manager, which stores and rotates passwords and API keys rather than encryption keys.

LambdaAWS LambdaD3

Serverless compute that runs your code in response to events and scales automatically, billed by number of requests and execution duration, with no servers to manage.

On the examCue: 'run code without provisioning servers', 'triggered by an S3 upload'. Under shared responsibility AWS manages the OS and runtime; you still own the code and its permissions.

Don’t confuse with EC2

Least PrivilegeD2

Granting only the permissions required to perform a task and nothing more, then reviewing and trimming access over time as needs change.

On the examWhen options differ in how much access they grant, the least-privilege answer is the narrowest one that still works. Granting AdministratorAccess 'to be safe' is the trap.

MFAMulti-Factor AuthenticationD2

Sign-in that requires a second factor, such as a code from an authenticator app or a hardware security key, in addition to the password.

On the examThe top answer for 'how do you protect the root user' and for adding a layer of sign-in security. A stronger password policy alone does not satisfy 'second factor'.

Network ACLNetwork Access Control ListD3

A stateless firewall at the subnet boundary, with numbered allow and deny rules evaluated in order; inbound and outbound traffic are checked separately.

On the examCue: 'subnet level', 'stateless', 'deny a specific IP range'. Security groups cannot deny, so blocking one address for a whole subnet points to a network ACL.

Don’t confuse with Security Group

On-Demand InstancesD4

Pay for compute by the second or hour with no commitment or upfront payment. The highest per-hour rate, but you can start and stop whenever you like.

On the examCue: 'short-term', 'unpredictable', 'cannot be interrupted', 'testing a new app'. If the workload runs steadily for a year or more, commit with Reserved Instances or Savings Plans.

Performance EfficiencyD1

The Well-Architected pillar about using computing resources efficiently to meet requirements and keeping that efficiency as demand and technology change, for example by choosing the right instance type or going serverless.

On the examKeywords: 'select the right resource type', 'go global in minutes', 'experiment more often'. Distinct from Reliability (recovering from failure) and Cost Optimization (eliminating waste).

Don’t confuse with Reliability

RDSAmazon Relational Database ServiceD3

Managed relational databases such as MySQL, PostgreSQL, MariaDB, Oracle and SQL Server, where AWS handles provisioning, engine patching, backups and Multi-AZ failover.

On the examCue: 'SQL', 'relational', 'joins', 'reduce admin work'. With RDS, AWS patches the database engine; on EC2 you would. Aurora is the AWS-built, MySQL- and PostgreSQL-compatible option.

Don’t confuse with DynamoDB

RegionD3

A separate geographic area containing multiple isolated Availability Zones. You choose a Region based on compliance, latency to users, service availability and price.

On the examFour selection factors appear constantly: data sovereignty or compliance, proximity to users, available services, pricing. Multiple Regions answer disaster recovery and data residency scenarios.

ReliabilityD1

The Well-Architected pillar about a workload performing its intended function correctly and consistently, including recovering automatically from failure and regularly testing recovery procedures.

On the examKeywords: 'recover from failure', 'multiple Availability Zones', 'test recovery procedures'. Pick Reliability over Performance Efficiency when the goal is staying up, not running faster.

Don’t confuse with Performance Efficiency

Reserved InstancesD4

A billing discount of up to roughly 72% versus On-Demand in exchange for a 1- or 3-year commitment to a specific instance configuration; Standard and Convertible types exist.

On the examCue: 'steady-state', 'predictable usage', '1 or 3 years'. Know that Reserved Instance discounts can be shared across accounts under consolidated billing in AWS Organizations.

Don’t confuse with Savings Plans

RightsizingD1

Matching instance types and sizes to a workload's real performance needs, then downsizing or switching instance families when monitoring shows resources are underused.

On the examCost-optimization cue: 'instances average 10% CPU'. Rightsizing is the action; Cost Explorer and Trusted Advisor are tools that surface the recommendation. Buying bigger instances is never the answer.

Root UserD2

The identity created with the AWS account's email address. It has unrestricted access and is required for a few account-level tasks, such as closing the account or changing the root email and password.

On the examCorrect answers: enable MFA on root, don't create root access keys, use it only for root-only tasks. Using root for daily administration is always the wrong option.

S3Amazon Simple Storage ServiceD3

Object storage for virtually unlimited data, accessed over the web through an API, designed for eleven nines of durability, with storage classes priced by access frequency.

On the examCue: 'static website', 'backups', 'data lake', 'store objects'. Lifecycle policies move objects between storage classes automatically. S3 is not a boot volume for EC2 - that is EBS.

Don’t confuse with EBS

S3 Glacier Deep ArchiveD3

The lowest-cost S3 storage class, meant for data accessed once or twice a year and retained for long periods, with standard retrievals completing within hours.

On the examCue: 'retain for 7-10 years', 'rarely accessed', 'lowest cost'. If retrieval must take milliseconds, choose S3 Glacier Instant Retrieval or S3 Standard-IA instead.

Savings PlansD4

A flexible pricing model where you commit to a consistent amount of compute spend, in dollars per hour, for 1 or 3 years and get discounted rates on matching usage.

On the examCue: 'commit to spend, not to a specific instance'. Compute Savings Plans also cover Fargate and Lambda and follow usage across instance families and Regions - Reserved Instances cannot.

Don’t confuse with Reserved Instances

Security GroupD3

A stateful virtual firewall attached to instances and other resources, with allow rules only; return traffic for an allowed request is permitted automatically.

On the examCue: 'instance level', 'stateful', 'allow rules only'. If the scenario needs an explicit deny rule or subnet-wide filtering, the answer is a network ACL instead.

Don’t confuse with Network ACL

Shared Responsibility ModelD2

The split of security duties: AWS secures the cloud itself (facilities, hardware, global network, managed-service software), while customers secure what they put in it (data, identities, configuration).

On the examClassic stems: 'who patches the guest OS on EC2?' (customer) versus 'on RDS?' (AWS). Responsibility shifts toward AWS as services become more managed, such as Lambda.

SNSAmazon Simple Notification ServiceD3

A publish/subscribe messaging service that pushes each message to many subscribers at once, such as email addresses, SMS numbers, Lambda functions or SQS queues.

On the examCue: 'send alerts', 'notify', 'fan out', 'push to many subscribers'. CloudWatch alarms commonly publish to an SNS topic to email administrators.

Don’t confuse with SQS

Spot InstancesD4

Spare EC2 capacity sold at discounts of up to 90% off On-Demand, which AWS can reclaim with a two-minute interruption notice.

On the examCue: 'flexible start and end times', 'fault tolerant', 'batch jobs', 'cheapest option'. If the job cannot tolerate interruption, Spot is wrong however cheap it is.

Don’t confuse with On-Demand Instances

SQSAmazon Simple Queue ServiceD3

A fully managed message queue that stores messages until a consumer polls and processes them, decoupling application components so each can scale and fail independently.

On the examCue: 'decouple', 'buffer', 'queue', 'process asynchronously'. SQS holds messages for a consumer to pull; SNS pushes them out to subscribers immediately.

Don’t confuse with SNS

SustainabilityD1

The newest Well-Architected pillar, focused on reducing the environmental impact of cloud workloads, for example by maximizing utilization and choosing efficient managed services and hardware.

On the examKeywords: 'carbon footprint', 'energy consumption', 'environmental impact'. When a question lists five pillars and asks for the missing sixth, Sustainability is the one candidates forget.

Trusted AdvisorAWS Trusted AdvisorD4

Inspects your AWS account against best-practice checks and recommends improvements across cost optimization, performance, security, fault tolerance, service limits and operational excellence.

On the examCue: 'identify idle resources', 'check service quotas', 'find open S3 permissions'. The full set of checks comes with higher support plans; Basic Support gets only core checks.

VPCAmazon Virtual Private CloudD3

A logically isolated virtual network in AWS where you define IP ranges, subnets, route tables and gateways that control how resources reach the internet and each other.

On the examKnow the parts: public subnet (route to an internet gateway), private subnet, NAT gateway for outbound-only access. Security groups and network ACLs filter traffic inside it.

Well-Architected FrameworkD1

AWS's best practices and review questions for building cloud workloads, organized into six pillars: operational excellence, security, reliability, performance efficiency, cost optimization and sustainability.

On the examExpect 'which pillar' questions: match the scenario keyword to one pillar. The framework guides workload design, while the CAF guides organizational adoption - a frequent distractor swap.

Don’t confuse with AWS CAF

Terms the exam loves to confuse

These six look-alike pairs cost more CLF-C02 points than any service you have never heard of. Each card gives the one clue that decides it.

CloudTrailAn audit log of API calls and account activity: which identity did what, to which resource, when and from where.

CloudWatchPerformance monitoring: metrics, logs and alarms that show how resources and applications are behaving right now and over time.

The tellAsk whether the stem wants 'who did it' (CloudTrail) or 'how is it running' (CloudWatch). Alarms and CPU metrics are always CloudWatch.

Security GroupA stateful firewall at the instance or resource level with allow rules only; return traffic is allowed automatically.

Network ACLA stateless firewall at the subnet level with ordered allow and deny rules; return traffic must be explicitly allowed.

The tellAn explicit deny, or blocking one IP for a whole subnet, can only be a network ACL. The word 'stateful' always means security group.

Reserved InstancesA 1- or 3-year commitment to a specific instance configuration in exchange for a large discount versus On-Demand pricing.

Savings PlansA 1- or 3-year commitment to a dollar-per-hour compute spend, applied flexibly to whatever matching usage you run.

The tellIf the scenario stresses flexibility across instance families, Regions, Fargate or Lambda, pick Savings Plans; a fixed instance commitment points to Reserved Instances.

AWS BudgetsA forward-looking guardrail: set a cost or usage threshold and get alerts or automated actions when it is crossed or forecast to be.

Cost ExplorerBackward-looking analysis: charts and filters of historical spend and usage, plus forecasts and purchase recommendations.

The tell'Alert', 'notify' and 'threshold' mean Budgets. 'Analyze', 'visualize', 'trend' and 'which service cost most' mean Cost Explorer.

AWS ShieldManaged DDoS protection; Standard is automatic and free, while Advanced adds a response team and DDoS cost protection.

AWS WAFA rule-based web application firewall that inspects HTTP(S) requests and blocks SQL injection, cross-site scripting, bad bots or specific IPs.

The tellThe word DDoS in the stem means Shield. SQL injection, cross-site scripting or custom request-filtering rules mean WAF.

GuardDutyContinuous threat detection that analyzes logs and account activity for signs of compromise or malicious behavior.

Amazon InspectorAutomated vulnerability scanning of EC2 instances, container images and Lambda functions for known software flaws and network exposure.

The tell'Threat', 'suspicious' and 'compromised' mean GuardDuty. 'Vulnerability', 'CVE' and 'unpatched software' mean Inspector.

Acronym quick-scan

AWS does not publish an official acronym list for CLF-C02, so this list is drawn from the exam guide's task statements and in-scope services. Expansions use AWS's own service names.

  • ACLAccess Control List
  • AIArtificial Intelligence
  • AMIAmazon Machine Image
  • APIApplication Programming Interface
  • APNAWS Partner Network
  • ARNAmazon Resource Name
  • AWSAmazon Web Services
  • AZAvailability Zone
  • BYOLBring Your Own License
  • CAFCloud Adoption Framework
  • CapExCapital Expenditure
  • CDNContent Delivery Network
  • CLICommand Line Interface
  • CURAWS Cost and Usage Report
  • CVECommon Vulnerabilities and Exposures
  • DDoSDistributed Denial of Service
  • DMSAWS Database Migration Service
  • DNSDomain Name System
  • EBSAmazon Elastic Block Store
  • EC2Amazon Elastic Compute Cloud
  • ECSAmazon Elastic Container Service
  • EFSAmazon Elastic File System
  • EKSAmazon Elastic Kubernetes Service
  • ELBElastic Load Balancing
  • ESGEnvironmental, Social, and Governance
  • GDPRGeneral Data Protection Regulation
  • HIPAAHealth Insurance Portability and Accountability Act
  • IAInfrequent Access (S3 Standard-IA, S3 One Zone-IA)
  • IaaSInfrastructure as a Service
  • IaCInfrastructure as Code
  • IAMAWS Identity and Access Management
  • IGWInternet Gateway
  • IoTInternet of Things
  • ISOInternational Organization for Standardization
  • ISVIndependent Software Vendor
  • KMSAWS Key Management Service
  • MFAMulti-Factor Authentication
  • MLMachine Learning
  • NACLNetwork Access Control List
  • NATNetwork Address Translation
  • NoSQLNot Only SQL (non-relational database)
  • OpExOperational Expenditure
  • PaaSPlatform as a Service
  • PCI DSSPayment Card Industry Data Security Standard
  • PIIPersonally Identifiable Information
  • RDSAmazon Relational Database Service
  • RIReserved Instance
  • S3Amazon Simple Storage Service
  • SaaSSoftware as a Service
  • SCPService Control Policy
  • SCTAWS Schema Conversion Tool
  • SDKSoftware Development Kit
  • SESAmazon Simple Email Service
  • SISystem Integrator
  • SLAService Level Agreement
  • SNSAmazon Simple Notification Service
  • SOCSystem and Organization Controls
  • SQSAmazon Simple Queue Service
  • SSOSingle Sign-On
  • TAMTechnical Account Manager
  • TCOTotal Cost of Ownership
  • TLSTransport Layer Security
  • VPCAmazon Virtual Private Cloud
  • VPNVirtual Private Network
  • WAFWeb Application Firewall

How to make the terms stick

Reading a glossary once will not survive 65 scenario questions; use it this way instead.

  1. Study in domain-weight orderCloud Technology and Services (34%) and Security and Compliance (30%) carry almost two-thirds of the scored questions. Learn those service names first, then Cloud Concepts, then the Billing, Pricing, and Support terms.
  2. Drill the look-alike pairsMost CLF-C02 misses come from near-twins: CloudTrail versus CloudWatch, Budgets versus Cost Explorer, Shield versus WAF. For each pair, write the single cue word that picks one side, then quiz yourself cue-first.
  3. Tie every service to a verbThe exam rarely asks for a definition; it describes a need. Attach each term to a verb - audit, monitor, alert, cache, queue, decouple, archive - and scan each question stem for that verb before reading the options.

Knowing the word is not the same as answering the question

CLF-C02 never asks you to define a term in isolation - it hides the term inside a business scenario. Practice questions are the fastest way to check you can spot CloudTrail, Savings Plans or Shield when the stem never names them.

App StoreGoogle PlayFree practice testAWS Cloud Practitioner exam page

FAQ

How many questions are on the AWS Cloud Practitioner exam?

CLF-C02 has 65 questions: 50 scored and 15 unscored, and you cannot tell which are which. You get 90 minutes, results are reported on a scaled score from 100 to 1,000, and 700 is the passing score. Scoring is compensatory, so you only need to pass the exam overall, not each of the four domains.

Is CLF-C02 being replaced by CLF-C03 in 2026?

As of September 2026, AWS has not announced a CLF-C03 or a retirement date for CLF-C02, which launched in September 2023. AWS has updated the exam guide content in place, for example to the new support plan names, and the Italian and German exam versions retire after December 31, 2026. Check the official certification page before you book.

Which AWS support plans are on the CLF-C02 exam now?

The current exam guide names Basic Support, AWS Business Support+, AWS Enterprise Support and AWS Unified Operations. Developer Support, Business Support and Enterprise On-Ramp are being discontinued on January 1, 2027, so older courses and question banks still mention them. Focus on what separates the tiers, such as the designated Technical Account Manager that comes with Enterprise Support.

Do I need to memorize every AWS acronym for Cloud Practitioner?

No. Recognize the roughly 60 acronyms on this page, but spend more effort matching each service to the scenario it solves. Questions describe a business need and offer four similar-sounding services, so knowing that SQS decouples components while SNS pushes notifications earns more points than reciting expansions word for word.

Sources

Scope and domain names on this page come from AWS’s published exam objectives; definitions are ours, written for exam prep:

Checked September 30, 2026. Exam objectives are revised on the vendor’s schedule — if a term here is not in the current objectives, the objectives win.