AWS Certification · Updated July 2026

AWS CLF-C02 Domain Weightings: Where to Focus Your Study Time

The AWS CLF-C02 exam draws from four distinct domains, each carrying a different weight in your final score. Studying each topic equally is a poor use of your preparation time — some domains contribute more than twice the marks of others. This guide breaks down each domain by weighting, what it specifically tests, and where to concentrate your effort within it.

The weightings at a glance Domain 1: Cloud Concepts (24%) · Domain 2: Security and Compliance (30%) · Domain 3: Cloud Technology and Services (34%) · Domain 4: Billing, Pricing and Support (12%)

How to use domain weightings in your study plan

Domains 2 and 3 together account for 64% of your exam. If you consistently score 70%+ on those two domains in practice, passing becomes much more achievable even if you are weaker on Domain 1 and Domain 4. That does not mean ignoring the lower-weighted domains — the 12% from Billing alone can be the difference between passing and failing if you skip it entirely — but it tells you where your preparation hours produce the highest return.

Domain 1: Cloud Concepts
24% — ~16 questions

This domain covers the foundational "why" of cloud computing — why organisations move to the cloud, what the benefits are, how AWS's global infrastructure works, and the frameworks that guide cloud adoption and architecture.

What it specifically tests:

  • The six advantages of cloud computing (trade capex for opex, economies of scale, stop guessing capacity, increase speed and agility, stop spending on data centres, go global in minutes)
  • The five pillars of the AWS Well-Architected Framework (Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimisation) — and what each focuses on
  • The six perspectives of the AWS Cloud Adoption Framework (Business, People, Governance, Platform, Security, Operations)
  • Cloud deployment models — public cloud, private cloud, hybrid
  • AWS global infrastructure — Regions, Availability Zones, and edge locations and the difference between them
  • The seven Rs of cloud migration (Rehost, Replatform, Repurchase, Refactor, Retire, Retain, Relocate)
Study tip: The CAF and Well-Architected Framework are heavily tested in the CLF-C02 compared to the old CLF-C01. Do not treat these as background reading — learn all six CAF perspectives and all five Well-Architected pillars by name and what each one focuses on.
Domain 2: Security and Compliance
30% — ~20 questions

The second-largest domain and consistently the one where candidates lose the most unexpected marks. Security concepts on the CLF-C02 require precise understanding — vague familiarity is not enough to answer the scenario-based questions correctly.

What it specifically tests:

  • The AWS Shared Responsibility Model in depth — who manages what for EC2, RDS, Lambda, and S3 specifically (the line shifts by service type)
  • IAM — users, groups, roles, and policies, the principle of least privilege, and when to use each identity type
  • MFA — why it matters and how it applies to the root account versus IAM users
  • Security groups versus Network ACLs — stateful vs stateless, instance level vs subnet level
  • AWS Shield Standard vs Advanced — which provides DDoS protection automatically and which costs extra
  • AWS WAF — what it protects against (SQL injection, XSS) and where it sits (layer 7)
  • Amazon GuardDuty vs Amazon Inspector vs Amazon Macie — three distinct threat/vulnerability/data services that the exam tests as distractors against each other
  • AWS CloudTrail vs Amazon CloudWatch — API auditing versus performance monitoring
  • AWS KMS versus AWS CloudHSM — shared managed keys versus dedicated customer-controlled hardware
  • AWS Artifact — where to access compliance reports and certifications
Study tip: The Shared Responsibility Model has a moving line depending on the service. For EC2 (IaaS) the customer manages the OS. For RDS (managed service) AWS manages the OS and database engine. For Lambda (serverless) AWS manages almost everything below the function code. Memorise this distinction across at least those three service types.
Domain 3: Cloud Technology and Services
34% — ~22 questions

The largest domain by weighting and the broadest in scope. It covers the majority of named AWS services across compute, storage, databases, networking, and additional categories including AI/ML and developer tools.

What it specifically tests:

  • Compute: EC2 (virtual servers), Lambda (serverless), ECS/EKS (containers), Fargate (serverless containers), Elastic Beanstalk (PaaS)
  • Storage: S3 (object storage and all storage classes), EBS (block storage for EC2), EFS (shared file storage), Snowball (physical data transfer)
  • Databases: RDS (managed relational), DynamoDB (NoSQL), Aurora (high-performance relational), Redshift (data warehouse), ElastiCache (in-memory caching)
  • Networking: VPC (isolated virtual network), CloudFront (CDN), Route 53 (DNS), ELB types (ALB, NLB), Direct Connect (dedicated on-premises connection)
  • Messaging: SQS (message queuing), SNS (pub/sub notifications), EventBridge (event-driven architecture)
  • AI/ML services: SageMaker (custom ML), Rekognition (image/video analysis), Comprehend (NLP), Polly (text-to-speech), Transcribe (speech-to-text), Lex (conversational bots)
  • Management: CloudWatch (monitoring), CloudTrail (API audit), CloudFormation (IaC), Auto Scaling, Systems Manager
Study tip: The exam tests service differentiation scenarios — "which service should a company use to..." questions where the wrong answers are plausible alternatives. Know not just what each service does, but when you would choose it over the similar services it is most commonly confused with.
Domain 4: Billing, Pricing and Support
12% — ~8 questions

The smallest domain by weighting, but one where well-prepared candidates pick up nearly free marks — and where underprepared candidates lose points they should not. Eight questions is a meaningful block that candidates skip at their peril.

What it specifically tests:

  • EC2 pricing models — On-Demand, Reserved Instances, Spot Instances, Savings Plans, Dedicated Hosts — and when each is appropriate
  • AWS Budgets — setting cost thresholds and receiving alerts
  • AWS Cost Explorer — analysing and visualising historical spend
  • AWS Pricing Calculator — estimating costs for new architectures before deployment
  • AWS Cost and Usage Report — the most detailed billing data source
  • Cost allocation tags — labelling resources by team, project, or environment for cost breakdown
  • AWS Organizations consolidated billing — aggregating charges across multiple accounts
  • Support plans — Basic, Developer, Business, Enterprise On-Ramp, and Enterprise — know what each includes, especially which plans provide 24/7 phone support, which include a TAM, and which have full Trusted Advisor access
  • AWS Free Tier — what is covered and for how long
Study tip: Memorise the four Support plan names and their distinguishing features. The exam distinguishes between them precisely — especially between Business (24/7 phone, no dedicated TAM, full Trusted Advisor) and Enterprise (dedicated TAM, concierge, 15-minute response for business-critical outages).

Building your study plan around the weightings

A practical approach given these weightings: spend roughly 35% of your study time on Domain 3 (it has the most services to cover), 30% on Domain 2 (it requires the most conceptual precision), 20% on Domain 1 (conceptual but can be learned quickly), and 15% on Domain 4 (smaller coverage but very structured and learnable).

After your first full practice exam, check your score by domain rather than just overall. If you are scoring 80% on Domain 1 but 55% on Domain 2, your revision hours should shift heavily toward security — not more time on what you already know.

Track your score by domain across every practice session

GetCert shows you exactly which domains and topics you are weakest on — so you always know where to focus next.

Start practising for R100 →