Objective 3.5

CLF-C02

Identify AWS network services.

Objective 3.5 sits in Cloud Technology and Services, which carries 34% of the Cloud Practitioner exam. The questions below are original, written from the official objective title above, and each explanation cites the Amazon Web Services (AWS) page it rests on.

Objective title verbatim from the official objectives. Amazon Web Services (AWS) exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

3-5Cloud Technology and Services

Inbound HTTPS is allowed by a network ACL, but the responses leaving the subnet are dropped. What explains that?

Network ACLs do not track connectionsCorrect · your answerCorrect. Allowing specific inbound traffic on a network ACL does not automatically allow the responses to that traffic.
Outbound traffic needs an internet gatewayA gateway governs whether the subnet can reach the internet at all. The request already arrived, so routing is plainly working.
The ACL rule number is set too highNumbering sets evaluation order, lowest first. A high number can be shadowed by an earlier rule, but it never switches a rule off.
Security groups override the ACL rulesSecurity groups and network ACLs are evaluated independently at different layers. Neither one cancels out the decision of the other.

Correct.

Checked against docs.aws.amazon.com, August 2026

Concept

A packet filter either remembers the conversations it has seen or it does not. That single property decides whether you write one rule per flow or two, and it is the commonest surprise inside a subnet.

Why A

With nothing remembered about the request, the reply is judged on its own against the outbound rules. Permitting the inbound port still leaves the ephemeral ports the reply goes out on to deal with.

Source

NACLs are stateless, which means that information about previously sent or received traffic is not saved. If, for example, you create a NACL rule to allow specific inbound traffic to a subnet, responses to that traffic are not automatically allowed…

AWS Docs: VPC network ACLs, checked August 2026
#network-acl#vpc#stateless

Now you: objective 3.5 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

3-5Cloud Technology and Services

An EC2 instance makes an outbound API call. Its security group has no inbound rule covering the reply. Does the response arrive?

Sample question 2 of 3

3-5Cloud Technology and Services

Two of six web servers behind a load balancer start failing health checks. What does Elastic Load Balancing do with them?

Sample question 3 of 3

3-5Cloud Technology and Services

A firm needs consistent throughput between its own data center and AWS, off the public internet. Which service provides that?

That’s 3 of the full Cloud Practitioner bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Cloud Technology and Services