Month End Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Amazon Web Services CLF-C02 AWS Certified Cloud Practitioner Exam Practice Test

Page: 1 / 79
Total 794 questions

AWS Certified Cloud Practitioner Questions and Answers

Question 1

A company's IT team is managing MySQL database server clusters. The IT team has to patch the database and take backup snapshots of the data in the clusters. The company wants to move this workload to AWS so that these tasks will be completed automatically.

What should the company do to meet these requirements?

Options:

A.

Deploy MySQL database server clusters on Amazon EC2 instances.

B.

Use Amazon RDS with a MySQL database.

C.

Use an AWS Cloud Form at ion template to deploy MySQL database servers on Amazon EC2 instances.

D.

Migrate all the MySQL database data to Amazon S3.

Question 2

Which of the following describes an AWS Region?

Options:

A.

A specific location within a geographic area that provides high availability

B.

A set of data centers spanning multiple countries

C.

A global picture of a user's cloud computing environment

D.

A collection of databases that can be accessed from a specific geographic area only

Question 3

Which AWS benefit is demonstrated by on-demand technology services that enable companies to replace upfront fixed expenses with variable expenses?

Options:

A.

High availability

B.

Economies of scale

C.

Pay-as-you-go pricing

D.

Global reach

Question 4

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

Options:

A.

Set up multi-factor authentication (MFA) for each Workspaces user account.

B.

Ensure the environmental safety and security of the AWS infrastructure that hosts Workspaces.

C.

Provide security for Workspaces user accounts through AWS Identity and Access Management

(IAM).

D.

Configure AWS CloudTrail to log API calls and user activity.

A company stores data in an Amazon S3 bucket. The company must control who has permission to read, write,

or delete objects that the company stores in the S3 bucket.

Question 5

An Availability Zone consists of:

Options:

A.

one or more data centers in a single location.

B.

two or more data centers in multiple locations.

C.

one or more physical hosts in a single data center.

D.

two or more physical hosts in multiple data centers.

Question 6

A cloud engineer needs to download AWS security and compliance documents for an upcoming audit.

Which AWS service can provide the documents?

Options:

A.

AWS Trusted Advisor

B.

AWS Artifact

C.

AWS Well-Architected Tool

D.

AWS Systems Manager

Question 7

A company has an application with robust hardware requirements. The application must be accessed by students who are using lightweight, low-cost laptops.

Which AWS service will help the company deploy the application without investing in backend infrastructure or high end client hardware?

Options:

A.

Amazon AppStream 2.0

B.

AWS AppSync

C.

Amazon WorkLink

D.

AWS Elastic Beanstalk

Question 8

Which AWS solution gives companies the ability to use protocols such as NFS to store and retrieve objects in Amazon S3?

Options:

A.

Amazon FSx for Lustre

B.

AWS Storage Gateway volume gateway

C.

AWS Storage Gateway file gateway

D.

Amazon Elastic File System (Amazon EFS)

Question 9

A company wants to centrally manage security policies and billing services within a multi-account AWS environment. Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Resource Access Manager (AWS RAM)

D.

AWS Config

Question 10

Which AWS service provides the ability to host a NoSQL database in the AWS Cloud?

Options:

A.

Amazon Aurora

B.

Amazon DynamoDB

C.

Amazon RDS

D.

Amazon Redshift

Question 11

Which AWS service or tool does AWS Control Tower use to create resources?

Options:

A.

AWS CloudFormation

B.

AWS Trusted Advisor

C.

AWS Directory Service

D.

AWS Cost Explorer

Question 12

A company is running applications on Amazon EC2 instances in the same AWS account for several different projects. The company wants to track the infrastructure costs for each of the projects separately. The company must conduct this tracking with the least possible impact to the existing infrastructure and with no additional cost.

What should the company do to meet these requirements?

Options:

A.

Use a different EC2 instance type for each project.

B.

Publish project-specific custom Amazon CloudWatch metrics for each application.

C.

Deploy EC2 instances for each project in a separate AWS account.

D.

Use cost allocation tags with values that are specific to each project.

Question 13

What is the total amount of storage offered by Amazon S3?

Options:

A.

WOMB

B.

5 GB

C.

5 TB

D.

Unlimited

Question 14

Which AWS service gives users the ability to provision a dedicated and private network connection from their internal

network to AWS?

Options:

A.

AWS CloudHSM

B.

AWS Direct Connect

C.

AWS VPN

D.

Amazon Connect

Question 15

A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a

natural disaster in a particular geographic area.

Which solution achieves this goal?

Options:

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple edge locations.

D.

Use Amazon CloudFront with the EC2 instances configured as the source.

Question 16

A company needs to use dashboards and charts to analyze insights from business data.

Which AWS service will provide the dashboards and charts for these insights?

Options:

A.

Amazon Macie

B.

Amazon Aurora

C.

Amazon QuickSight

D.

AWS CloudTrail

Question 17

Which AWS Support plan provides customers with access to an AWS technical account manager (TAM)?

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Question 18

A company needs to run code in response to an event notification that occurs when objects are uploaded to an Amazon S3 bucket.

Which AWS service will integrate directly with the event notification?

Options:

A.

AWS Lambda

B.

Amazon EC2

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

AWS Elastic Beanstalk

Question 19

A company is configuring its AWS Cloud environment. The company's administrators need to group users together and apply permissions to the group.

Which AWS service or feature can the company use to meet these requirements?

Options:

A.

AWS Organizations

B.

Resource groups

C.

Resource tagging

D.

AWS Identity and Access Management (IAM)

Question 20

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO.)

Options:

A.

Availability

B.

Reliability

C.

Scalability

D.

Responsive design

E.

Operational excellence

Question 21

Which AWS services or features can control VPC traffic? (Select TWO.)

Options:

A.

Security groups

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

Network ACLs

E.

Amazon Connect

Question 22

A company's information security manager is supervising a move to AWS and wants to ensure that AWS best practices are followed. The manager has concerns about the potential misuse of AWS account root user credentials.

Which of the following is an AWS best practice for using the AWS account root user credentials?

Options:

A.

Allow only the manager to use the account root user credentials for normal activities.

B.

Use the account root user credentials only for Amazon EC2 instances from the AWS Free Tier.

C.

Use the account root user credentials only when they alone must be used to perform a required

function.

D.

Use the account root user credentials only for the creation of private VPC subnets.

Question 23

A company's application stores data in an Amazon S3 bucket. The company has an AWS Lambda function that processes data in the S3

bucket. The company needs to invoke the function once a day at a specific time.

Which AWS service should the company use to meet this requirement?

Options:

A.

AWS Managed Services (AMS)

B.

AWS CodeStar

C.

Amazon EventBridge

D.

AWS Step Functions

Question 24

Which option is an advantage of AWS Cloud computing that minimizes variable costs?

Options:

A.

High availability

B.

Economies of scale

C.

Global reach

D.

Agility

Question 25

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

Options:

A.

AWS CloudTrail

B.

AWS Cost and Usage Reports

C.

AWS Trusted Advisor

D.

AWS Budgets

Question 26

A company is migrating a relational database server to the AWS Cloud. The company wants to minimize

administrative overhead of database maintenance tasks.

Which AWS service will meet these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon EC2

C.

Amazon Redshift

D.

Amazon RDS

Question 27

An application is running on multiple Amazon EC2 instances. The company wants to make the application highly available by configuring a load balancer with requests forwarded to the EC2 instances based on URL paths.

Which AWS load balancer will meet these requirements and take the LEAST amount of effort to deploy?

Options:

A.

Network Load Balancer

B.

Application Load Balancer

C.

AWS OpsWorks Load Balancer

D.

Custom Load Balancer on Amazon EC2

Question 28

Which AWS service or feature is used to send both text and email messages from distributed applications?

Options:

A.

Amazon Simple Notification Service (Amazon SNS)

B.

Amazon Simple Email Service (Amazon SES)

C.

Amazon CloudWatch alerts

D.

Amazon Simple Queue Service (Amazon SQS)

Question 29

A company wants to establish a security layer in its VPC that will act as a firewall to control subnet traffic.

Which AWS service or feature will meet this requirement?

Options:

A.

Routing tables

B.

Network access control lists (network ACLs)

C.

Security groups

D.

Amazon GuardDuty

Question 30

Which AWS service or feature offers HTTP attack protection to users running public-facing web applications?

Options:

A.

Security groups

B.

Network ACLs

C.

AWS Shield Standard

D.

AWS WAF

Question 31

A company needs a content delivery network that provides secure delivery of data, videos, applications, and APIs to users globally with low latency and high transfer speeds.

Which AWS service meets these requirements?

Options:

A.

Amazon CloudFront

B.

Elastic Load Balancing

C.

Amazon S3

D.

Amazon Elastic Transcoder

Question 32

Which tasks are customer responsibilities according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Determine application dependencies with operating systems.

B.

Provide user access with AWS Identity and Access Management (IAM).

C.

Secure the data center in an Availability Zone.

D.

Patch the hypervisor.

E.

Provide network availability in Availability Zones.

Question 33

company wants to protect its AWS Cloud information, systems, and assets while performing risk assessment and mitigation tasks.

Which pillar of the AWS Well-Architected Framework is supported by these goals?

Options:

A.

Reliability

B.

Security

C.

Operational excellence

D.

Performance efficiency

Question 34

A company has two AWS accounts in an organization in AWS Organizations for consolidated billing. All of the company's AWS resources are hosted in one AWS Region.

Account A has purchased five Amazon EC2 Standard Reserved Instances (RIs) and has four EC2 instances

running. Account B has not purchased any RIs and also has four EC2 instances running.

Which statement is true regarding pricing for these eight instances?

Options:

A.

The eight instances will be charged as regular instances.

B.

Four instances will be charged as RIs, and four will be charged as regular instances.

C.

Five instances will be charged as RIs, and three will be charged as regular instances.

D.

The eight instances will be charged as RIs.

Question 35

Which of the following is an advantage that users experience when they move on-premises workloads to the AWS Cloud?

Options:

A.

Elimination of expenses for running and maintaining data centers

B.

Price discounts that are identical to discounts from hardware providers

C.

Distribution of all operational controls to AWS

D.

Elimination of operational expenses

Question 36

Which of the following are user authentication services managed by AWS? (Select TWO.)

Options:

A.

Amazon Cognito

B.

AWS Lambda

C.

AWS License Manager

D.

AWS Identity and Access Management (IAM)

E.

AWS CodeStar

Question 37

Which AWS service meets this requirement?

Options:

A.

AWS CloudFormation

B.

AWS Elastic Beanstalk

C.

AWS Cloud9

D.

AWS CloudShell

Question 38

A company is designing a web application that will run on Amazon EC2 instances.

Which AWS services and features will improve availability and reduce the impact of failures for this application?

(Select TWO.)

Options:

A.

Amazon EC2 Auto Scaling for the EC2 instances

B.

VPC subnet ACLs to check the health of a service

C.

Resources that are distributed across multiple Availability Zones

D.

Configuration of AWS Server Migration Service (AWS SMS) to move the EC2 instances to a different

AWS Region

E.

Resources that are distributed across multiple AWS points of presence

Question 39

Which options does AWS make available for customers who want to learn about security in the cloud in an instructor-led setting? (Select TWO.)

Options:

A.

AWS Trusted Advisor

B.

AWS Online Tech Talks

C.

AWS Blog

D.

AWS Forums

E.

AWS Classroom Training

Question 40

A large company has a workload that requires hardware to remain on premises. The company wants to use the same management and control plane services that it currently uses on AWS.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Device Farm

B.

AWS Fargate

C.

AWS Outposts

D.

AWS Ground Station

Question 41

Which AWS service provides highly durable object storage?

Options:

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon FSx

Question 42

Which of the following are benefits that a company receives when it moves an on-premises production workload to AWS? (Select TWO.)

Options:

A.

AWS trains the company's staff on the use of all the AWS services.

B.

AWS manages all security in the cloud.

C.

AWS offers free support from technical account managers (TAMs).

D.

AWS offers high availability.

E.

AWS provides economies of scale.

Question 43

Which of the following acts as an instance-level firewall to control inbound and outbound access?

Options:

A.

Network access control list

B.

Security groups

C.

AWS Trusted Advisor

D.

Virtual private gateways

Question 44

A company deploys its application on Amazon EC2 instances. The application occasionally experiences sudden increases in demand. The company wants to ensure that its application can respond to changes in demand at the lowest possible cost.

Which AWS service or tool will meet these requirements?

Options:

A.

AWS Auto Scaling

B.

AWS Compute Optimizer

C.

AWS Cost Explorer

D.

AWS Well-Architected Framework

Question 45

Who is responsible for decommissioning end-of-life underlying storage devices that are used to host data on AWS?

Options:

A.

Customer

B.

AWS

C.

Account creator

D.

Auditing team

Question 46

Which design principle is achieved by following the reliability pillar of the AWS Well-Architected Framework?

Options:

A.

Vertical scaling

B.

Manual failure recovery

C.

Testing recovery procedures

D.

Changing infrastructure manually

Question 47

Which task requires the use of AWS account root user credentials?

Options:

A.

The deletion of IAM users

B.

The change to a different AWS Support plan

C.

The creation of an organization in AWS Organizations

D.

The deletion of Amazon EC2 instances

Question 48

A large company wants to track the combined AWS usage costs of all of its linked accounts.

How can this be accomplished?

Options:

A.

Use AWS Trusted Advisor to generate customized summary reports.

B.

Use AWS Organizations to generate consolidated billing reports.

C.

Use AWS Budgets to set utilization targets and receive summary reports.

D.

Use the AWS Control Tower dashboard to get a summary report of all linked account costs.

Question 49

A cloud practitioner is analyzing Amazon EC2 instance performance and usage to provide recommendations for potential cost savings.

Which cloud concept does this analysis demonstrate?

Options:

A.

Auto scaling

B.

Rightsizing

C.

Load balancing

D.

High availability

Question 50

What can a user accomplish using AWS CloudTrail?

Options:

A.

Generate an IAM user credentials report.

B.

Record API calls made to AWS services.

C.

Assess the compliance of AWS resource configurations with policies and guidelines.

D.

Ensure that Amazon EC2 instances are patched with the latest security updates.

A company uses Amazon Workspaces.

Question 51

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

Options:

A.

Perform quarterly disaster recovery tests.

B.

Place the main component on the us-east-1 Region.

C.

Design for automatic failover to healthy resources.

D.

Design workloads to fit on a single Amazon EC2 instance.

Question 52

Which of the following is a characteristic of the AWS account root user?

Options:

A.

The root user is the only user that can be configured with multi-factor authentication (MFA).

B.

The root user is the only user that can access the AWS Management Console.

C.

The root user is the first sign-in identity that is available when an AWS account is created.

D.

The root user has a password that cannot be changed.

Question 53

Which AWS service or tool helps to centrally manage billing and allow controlled access to resources across AWS accounts?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Cost Explorer

D.

AWS Budgets

Question 54

A company is developing an application that uses multiple AWS services. The application needs to use

temporary, limited-privilege credentials for authentication with other AWS APIs.

Which AWS service or feature should the company use to meet these authentication requirements?

Options:

A.

Amazon API Gateway

B.

IAM users

C.

AWS Security Token Service (AWS STS)

D.

IAM instance profiles

Question 55

A company has a workload that requires data to be collected, analyzed, and stored on premises. The company wants to extend the use of AWS services to run on premises with access to the company network and the company's VPC.

Which AWS service meets this requirement?

Options:

A.

AWS Outposts

B.

AWS Storage Gateway

C.

AWS Direct Connect

D.

AWS Snowball

Question 56

A company needs to run its existing custom, nonproduction workloads in the AWS Cloud quickly and cost-effectively.

The workloads can recover from interruptions easily.

Which pricing model should the company use?

Options:

A.

Reserved Instances

B.

On-Demand Instances

C.

Spot Instances

D.

Dedicated Hosts

Question 57

When a user wants to utilize their existing per-socket, per-core, or per-virtual machine software licenses for a Microsoft Windows server running on AWS, which Amazon EC2 instance type is required?

Options:

A.

Spot Instances

B.

Dedicated Instances

C.

Dedicated Hosts

D.

Reserved Instances

Question 58

Which AWS service should a cloud practitioner use to receive real-time guidance for provisioning resources, based on AWS best practices related to security, cost optimization, and service limits?

Options:

A.

AWS Trusted Advisor

B.

AWS Config

C.

AWS Security Hub

D.

AWS Systems Manager

Question 59

Which AWS service or tool can be used to consolidate payments for a company with multiple AWS accounts?

Options:

A.

AWS Cost and Usage Report

B.

AWS Organizations

C.

Cost Explorer

D.

AWS Budgets

Question 60

Which of the following is a benefit of decoupling an AWS Cloud architecture?

Options:

A.

Reduced latency

B.

Ability to upgrade components independently

C.

Decreased costs

D.

Fewer components to manage

Question 61

Which of the following is a cloud benefit that AWS offers to its users?

Options:

A.

The ability to configure AWS data center hypervisors

B.

The ability to purchase hardware in advance of increased traffic

C.

The ability to deploy to AWS on a global scale

D.

Compliance audits for user IT environments

Question 62

Which pillar of the AWS Well-Architected Framework focuses on the ability to run workloads effectively, gain insight into operations, and continuously improve supporting processes and procedures?

Options:

A.

Cost optimization

B.

Reliability

C.

Operational excellence

D.

Performance efficiency

Question 63

A company is migrating an application that includes an Oracle database to AWS. The company cannot rewrite the application.

To which AWS service could the company migrate the database?

Options:

A.

Amazon Athena

B.

Amazon DynamoDB

®C. Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

Question 64

Which AWS Support plan assigns an AWS concierge agent to a company's account?

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Question 65

A developer needs to build an application for a retail company. The application must provide real-time product recommendations that are based on machine learning.

Which AWS service should the developer use to meet this requirement?

Options:

A.

AWS Health Dashboard

B.

Amazon Personalize

C.

Amazon Forecast

D.

Amazon Transcribe

Question 66

A company wants to ensure that two Amazon EC2 instances are in separate data centers with minimal

communication latency between the data centers.

How can the company meet this requirement?

Options:

A.

Place the EC2 instances in two separate AWS Regions connected with a VPC peering connection.

B.

Place the EC2 instances in two separate Availability Zones within the same AWS Region.

C.

Place one EC2 instance on premises and the other in an AWS Region. Then connect them by using an

AWS VPN connection.

D.

Place both EC2 instances in a placement group for dedicated bandwidth.

Question 67

A company needs to migrate all of its development teams to a cloud-based integrated development environment (IDE).

Which AWS service should the company use?

Options:

A.

AWS CodeBuild

B.

AWS Cloud9

C.

AWS OpsWorks

D.

AWS Cloud Development Kit (AWS CDK)

Question 68

A company has a social media platform in which users upload and share photos with other users. The company wants to identify and remove inappropriate photos. The company has no machine learning (ML) scientists and must build this detection capability with no ML expertise.

Which AWS service should the company use to build this capability?

Options:

A.

Amazon SageMaker

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Comprehend

Question 69

A company needs to identify the last time that a specific user accessed the AWS Management Console.

Which AWS service will provide this information?

Options:

A.

Amazon Cognito

B.

AWS CloudTrail

C.

Amazon Inspector

D.

Amazon GuardDuty

Question 70

A company has an application that uses AWS services. During scaling events, the company wants to keep

application usage within AWS service quotas.

Which AWS services or tools can report on the quotas so that the company can improve the reliability of the application? (Select TWO.)

Options:

A.

Service Quotas console

B.

AWS Trusted Advisor

C.

AWS Systems Manager

D.

AWS Shield

E.

AWS Cost Explorer

Question 71

Which AWS database service provides in-memory data storage?

Options:

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon RDS

D.

Amazon Timestream

Question 72

Which AWS service is a highly available and scalable DNS web service?

Options:

A.

Amazon VPC

B.

Amazon CloudFront

C.

Amazon Route 53

D.

Amazon Connect

Question 73

Which database engine is compatible with Amazon RDS?

Options:

A.

Apache Cassandra

B.

MongoDB

C.

Neo4j

D.

PostgreSQL

Question 74

Which services can be used to deploy applications on AWS? (Select TWO.)

Options:

A.

AWS Elastic Beanstalk

B.

AWS Config

C.

AWS OpsWorks

Q D. AWS Application Discovery Service

D.

Amazon Kinesis

Question 75

A company needs to test a new application that was written in Python. The code will activate when new images are stored in an Amazon S3 bucket. The application will put a watermark on each image and then will store the images in a different S3 bucket.

Which AWS service should the company use to conduct the test with the LEAST amount of operational

overhead?

Options:

A.

Amazon EC2

B.

AWS CodeDeploy

C.

AWS Lambda

D.

Amazon Lightsail

Question 76

A company is hosting a web application in a Docker container on Amazon EC2.

AWS is responsible for which of the following tasks?

Options:

A.

Scaling the web application and services developed with Docker

B.

Provisioning or scheduling containers to run on clusters and maintain their availability

C.

Performing hardware maintenance in the AWS facilities that run the AWS Cloud

D.

Managing the guest operating system, including updates and security patches

Question 77

What is an Availability Zone?

Options:

A.

A location where users can deploy compute, storage, database, and other select AWS services

where no AWS Region currently exists

B.

One or more discrete data centers with redundant power, networking, and connectivity

C.

One or more clusters of servers where new workloads can be deployed

D.

A fast content delivery network (CDN) service that securely delivers data, videos, applications, and

APIs to users globally

Question 78

Which best practice for cost governance does this example show?

Options:

A.

Resource controls

B.

Cost allocation

C.

Architecture optimization

D.

Tagging enforcement

Question 79

A retail company is building a new mobile app. The company is evaluating whether to build the app at an on-premises data center or in the AWS Cloud.

Which of the following are benefits of building this app in the AWS Cloud? (Select TWO.)

Options:

A.

A large upfront capital expense and low variable expenses

B.

Increased speed for trying out new projects

C.

Complete control over the physical security of the infrastructure

D.

Flexibility to scale up in minutes as the application becomes popular

E.

Ability to pick the specific data centers that will host the application servers

Question 80

Which activity can companies complete by using AWS Organizations?

Options:

A.

Troubleshoot the performance of applications.

B.

Manage service control policies (SCPs).

C.

Migrate applications to microservices.

D.

Monitor the performance of applications.

Question 81

Which AWS service can a company use to visually design and build serverless applications?

Options:

A.

AWS Lambda

B.

AWS Batch

C.

AWS Application Composer

D.

AWS App Runner

Question 82

A company wants to provision and manage its AWS infrastructure by using the common programming languages TypeScript, Python, Java, and .NET. Which h AWS service will meet this requirement?

Options:

A.

AWS CodeBuild

B.

AWS CloudFormation

C.

AWSCLI

D.

AWS Cloud Development Kit (AWS CDK)

Question 83

Which responsibility belongs to AWS when a company hosts its databases on Amazon EC2 instances?

Options:

A.

Database backups

B.

Database software patches

C.

Operating system patches

D.

Operating system installations

Question 84

A company needs to implement identity management for a fleet of mobile apps that are running in the AWS Cloud.

Which AWS service will meet this requirement?

Options:

A.

Amazon Cognito

B.

AWS Security Hub

C.

AWS Shield

D.

AWS WAF

Question 85

A company is assessing its AWS Business Support plan to determine if the plan still meets the company's needs. The company is considering switching to AWS Enterprise Support.

Which additional benefit will the company receive with AWS Enterprise Support?

Options:

A.

A full set of AWS Trusted Advisor checks

B.

Phone, email, and chat access to cloud support engineers 24 hours a day, 7 days a week

C.

A designated technical account manager (TAM) to assist in monitoring and optimization

D.

A consultative review and architecture guidance for the company's applications

Question 86

Which of the following can be components of a VPC in the AWS Cloud? (Select TWO.)

Options:

A.

Amazon API Gateway

B.

Amazon S3 buckets and objects

C.

AWS Storage Gateway

D.

Internet gateway

E.

Subnet

Question 87

A company is building a new application on AWS. The company needs the application to remain available if an individual application component fails.

Which design principle should the company use to meet this requirement?

Options:

A.

Disposable resources

B.

Automation

C.

Rightsizing

D.

Loose coupling

Question 88

A company wants to migrate its on_premises workloads to the AWS Cloud. The company wants to separate workloads for chargeback to different departments.

Which AWS services or features will meet these requirements? (Select TWO.)

Options:

A.

Placement groups

B.

Consolidated billing

C.

Edge locations

D.

AWS Config

E.

Multiple AWS accounts

Question 89

Which AWS service is an in-memory data store service?

Options:

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DynamoDB

D.

Amazon ElastiCache

Question 90

In which situations should a company create an 1AM user instead of an 1AM role? (Select TWO.)

Options:

A.

When an application that runs on Amazon EC2 instances requires access to other AWS services

B.

When the company creates AWS access credentials for individuals

C.

When the company creates an application that runs on a mobile phone that makes requests to AWS

D.

When the company needs to add users to 1AM groups

E.

When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time

Question 91

A company is using Amazon DynamoDB.

Which task is the company's responsibility, according to the AWS shared responsibility model?

Options:

A.

Patch the operating system

B.

Provision hosts

C.

Manage database access permissions.

D.

Secure the operating system

Question 92

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on organizing an inventory of data products in a data catalog?

Options:

A.

Operations

B.

Governance

C.

Business

D.

Platform

Question 93

A company runs its production workload in the AWS Cloud. The company needs to choose one of the AWS Support Plans.

Which of the AWS Support Plans will meet these requirements at the LOWEST cost?

Options:

A.

Developer

B.

Enterprise On-Ramp

C.

Enterprise

D.

Business

Question 94

Which of the following can the AWS Pricing Calculator do?

Options:

A.

Project monthly AWS costs.

B.

Calculate historical AWS costs.

C.

Provide in-depth information about AWS pricing strategies.

D.

Provide users with access to their monthly bills.

Question 95

Which actions are best practices for an AWS account root user? (Select TWO.)

Options:

A.

Share root user credentials with team members.

B.

Create multiple root users for the account, separated by environment.

C.

Enable multi-factor authentication (MFA) on the root user.

D.

Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user.

E.

Use programmatic access instead of the root user and password.

Question 96

A company uses AWS for its web application. The company wants to minimize latency and perform compute operations for the application as close to end users as possible.

Which AWS service or infrastructure component will provide this functionality?

Options:

A.

AWS Regions

B.

Availability Zones

C.

Edge locations

D.

AWS Direct Connect

Question 97

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance state changes to RUNNING.

Which AWS service can the company use to meet this requirement?

Options:

A.

Amazon SageMaker

B.

Amazon Connect

C.

Amazon EventBridge

D.

AWS Fargate

Question 98

A company wants to use guidelines from the AWS Well-Architected Framework to limit human error and facilitate consistent responses to events.

Which of the following is a Well-Architected design principle that will meet these requirements?

Options:

A.

Use AWS CodeDeploy.

B.

Perform operations as code.

C.

Migrate workloads to a Dedicated Host.

D.

Use AWS Compute Optimizer.

Question 99

What does the concept of agility mean in AWS Cloud computing? (Select TWO.)

Options:

A.

The speed at which AWS resources are implemented

B.

The speed at which AWS creates new AWS Regions

C.

The ability to experiment quickly

D.

The elimination of wasted capacity

E.

The low cost of entry into cloud computing

Question 100

An administrator observed that multiple AWS resources were deleted yesterday.

Which AWS service will help identify the cause and determine which user deleted the resources?

Options:

A.

AWS CtoudTrail

B.

Amazon Inspector

C.

Amazon GuardDuty

D.

AWS Trusted Advisor

Question 101

What is a benefit of using an Elastic Load Balancing (ELB) load balancer with applications running in the AWS Cloud?

Options:

A.

An ELB will automatically scale resources to meet capacity needs.

B.

An ELB can balance traffic across multiple compute resources.

C.

An ELB can span multiple AWS Regions.

D.

An ELB can balance traffic between multiple internet gateways.

Question 102

What is the total volume of data that can be stored in Amazon S3?

Options:

A.

10 PB

B.

50 PB

C.

100 PB

D.

Virtually unlimited

Question 103

Which AWS service or feature is associated with a subnet in a VPC and is used to control inbound and outbound traffic?

Options:

A.

Amazon Inspector

B.

Network ACLs

C.

AWS Shield

D.

VPC Flow Logs

Question 104

Which AWS service is used to provide encryption for Amazon EBS?

Options:

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS KMS

D.

AWS Config

Question 105

A company has multiple AWS accounts. The company needs to receive a consolidated bill from AWS and must centrally manage security and compliance. Which AWS service or feature should the company use to meet these requirements?

Options:

A.

AWS Cost and Usage Report

B.

AWS Organizations

C.

AWS Config

D.

AWS Security Hub

Question 106

A company is building a web application using AWS.

Which AWS service will help prevent network layer DDoS attacks against the web application?

Options:

A.

AWS WAF

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

AWS Shield

Question 107

A company has a workload that will run continuously for 1 year. The workload cannot tolerate service interruptions.

Which Amazon EC2 purchasing option will be MOST cost-effective?

Options:

A.

All Upfront Reserved Instances

B.

Partial Upfront Reserved Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 108

Which benefit is always free of charge with AWS, regardless of a user's AWS Support plan?

Options:

A.

AWS Developer Support

B.

AWS Developer Forums

C.

Programmatic case management

D.

AWS technical account manager (TAM)

Question 109

A company needs to evaluate its AWS environment and provide best practice recommendations in five categories: cost, performance, service limits, fault tolerance, and security. Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Shield

B.

AWS WAF

C.

AWS Trusted Advisor

D.

AWS Service Catalog

Question 110

Which task must a user perform by using the AWS account root user credentials?

Options:

A.

Make changes to AWS production resources.

B.

Change AWS Support plans.

C.

Access AWS Cost and Usage Reports.

D.

Grant auditors’ access to an AWS account for a compliance audit.

Question 111

Which capabilities are in the platform perspective of the AWS Cloud Adoption Framework (AWS CAF)? (Select TWO.)

Options:

A.

Performance and capacity management

B.

Data engineering

C.

Continuous integration and continuous delivery (CI/CD)

D.

Infrastructure protection

E.

Change and release management

Question 112

A company wants to integrate natural language processing (NLP) into business intelligence (Bl) dashboards. The company wants to ask questions and

receive answers with relevant visualizations.

Which AWS service or tool will meet these requirements?

Options:

A.

Amazon Macie

B.

Amazon Rekognition

C.

Amazon QuickSight Q

D.

Amazon Lex

Question 113

According to the AWS shared responsibility model, who is responsible for the virtualization layer down to the

physical security of the facilities in which AWS services operate?

Options:

A.

It is the sole responsibility of the customer.

B.

It is the sole responsibility of AWS.

C.

It is a shared responsibility between AWS and the customer.

D.

The customer's AWS Support plan tier determines who manages the configuration.

Question 114

A company needs to perform data processing once a week that typically takes about 5 hours to complete. Which AWS service should the company use for this workload?

Options:

A.

AWS Lambda

B.

Amazon EC2

C.

AWS CodeDeploy

D.

AWS Wavelength

Question 115

Which AWS Support plan is the minimum recommended tier for users who have production workloads on AWS?

Options:

A.

AWS Developer Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Enterprise On-Ramp Support

Question 116

Which tasks are responsibilities of the customer, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Secure the virilization layer.

B.

Encrypt data and maintain data integrity.

C.

Patch the Amazon RDS operating system.

D.

Maintain identity and access management controls.

E.

Secure Availability Zones.

Question 117

An ecommerce company wants to provide relevant product recommendations to its customers. The recommendations will include products that are frequently purchased with other products that the customer already purchased. The recommendations also will include

products of a specific color and products from the customer’s favorite brand.

Which AWS service or feature should the company use to meet these requirements with the LEAST development effort?

Options:

A.

Amazon Comprehend

B.

Amazon Forecast

C.

Amazon Personalize

D.

Amazon SageMaker Studio

Question 118

Which of the following are general AWS Cloud design principles described in the AWS Well-Architected Framework?

Options:

A.

Consolidate key components into monolithic architectures.

B.

Test systems at production scale.

C.

Provision more capacity than a workload is expected to need.

D.

Drive architecture design based on data collected about the workload behavior and requirements.

E.

Make AWS Cloud architectural decisions static, one-time events.

Question 119

A company is moving Us development and test environments to AWS to increase agility and reduce cost. Because these are not production workloads and the servers are not fully utilized, occasional unavailability is acceptable.

What is the MOST cost-effective Amazon EC2 pricing model that will meet these requirements?

Options:

A.

Reserved instances

B.

On-Demand Instances

C.

Spot Instances

D.

Dedicated Hosts

Question 120

A developer has been hired by a large company and needs AWS credentials.

Which are security best practices that should be followed? (Select TWO.)

Options:

A.

Grant the developer access to only the AWS resources needed to perform the job.

B.

Share the AWS account root user credentials with the developer.

C.

Add the developer to the administrator's group in AWS IAM.

D.

Configure a password policy that ensures the developer's password cannot be changed.

E.

Ensure the account password policy requires a minimum length.

Question 121

A company wants to securely access an Amazon S3 bucket from an Amazon EC2 instance without accessing the internet.

What should the company use to accomplish this goal?

Options:

A.

VPN connection

B.

Internet gateway

C.

VPC endpoint

D.

NAT gateway

Question 122

Which combination of AWS services can be used to move a commercial relational database to an Amazon-managed open-source database? (Select TWO.)

Options:

A.

AWS Database Migration Service (AWS DMS)

B.

AWS software development kits (SDKs)

C.

AWS Schema Conversion Tool

D.

AWS Systems Manager

E.

Amazon EMR

Question 123

What is the MOST secure way to store passwords on AWS?

Options:

A.

Store passwords in an Amazon S3 bucket.

B.

Store passwords as AWS CloudFormation parameters

C.

Store passwords in AWS Storage Gateway.

D.

Store passwords in AWS Secrets Manager.

Question 124

Which database engines does Amazon Aurora support? (Select TWO.)

Options:

A.

Oracle

B.

Microsoft SQL Server

C.

MySQL

D.

PostgreSQL

E.

MongoDB

Question 125

Amazon Elastic File System (Amazon EFS) and Amazon FSx offer which type of storage?

Options:

A.

File storage

B.

Object storage

C.

Block storage

D.

Instance store

Question 126

Which AWS Support plan provides the full set of AWS Trusted Advisor checks at the LOWEST cost?

Options:

A.

AWS Developer Support

B.

AWS Business Support

C.

AWS Enterprise On-Ramp Support

D.

AWS Enterprise Support

Question 127

Which task is the responsibility of the customer, according to the AWS shared responsibility model?

Options:

A.

Patch the Amazon DynamoDB operating system.

B.

Secure Amazon CloudFront edge locations by allowing physical access according to the principle of least privilege.

C.

Protect the hardware that runs AWS services.

D.

Use AWS Identity and Access Management (1AM) according to the principle of least privilege.

Question 128

A company needs to engage third-party consultants to help maintain and support its AWS environment and the company's business needs.

Which AWS service or resource will meet these requirements?

Options:

A.

AWS Support

B.

AWS Organizations

C.

AWS Service Catalog

D.

AWS Partner Network (APN)

Question 129

A company wants its Amazon EC2 instances to be in different locations but share the same geographic area. The company also wants to use multiple power grids and independent networking connectivity for the EC2 instances.

Which solution meets these requirements?

Options:

A.

Use EC2 instances in multiple edge locations in the same AWS Region.

B.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

C.

Use EC2 instances in multiple Amazon Connect locations in the same AWS Region

D.

Use EC2 instances in multiple AWS Artifact locations in the same AWS Region.

Question 130

A company is building an application that needs to deliver images and videos globally with minimal latency.

Which approach can the company use to accomplish this in a cost effective manner?

Options:

A.

Deliver the content through Amazon CloudFront.

B.

Store the content on Amazon S3 and enable S3 cross-region replication.

C.

Implement a VPN across multiple AWS Regions.

D.

Deliver the content through AWS PrivateLink.

Question 131

Which action should a company take to improve security in its AWS account?

Options:

A.

Require multi-factor authentication (MFA) for privileged users.

B.

Remove the root user account.

C.

Create an access key for the AWS account root user.

D.

Create an access key for each privileged user.

Question 132

Which AWS service provides encryption at rest for Amazon RDS and for Amazon Elastic Block Store (Amazon EBS) volumes?

Options:

A.

AWS Lambda

B.

AWS Key Management Service (AWS KMS)

C.

AWSWAF

D.

Amazon Rekognition

Question 133

A company operates a petabyte-scale data warehouse to analyze its data. The company wants a solution that will not require manual hardware and software management. Which AWS service will meet these requirements?

Options:

A.

Amazon DocumentDB (with MongoDB compatibility)

B.

Amazon Redshift

C.

Amazon Neptune

D.

Amazon ElastiCache

Question 134

Which AWS service can identify when an Amazon EC2 instance was terminated?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS CloudTrail

C.

AWS Compute Optimizer

D.

Amazon EventBridge

Question 135

A company has created an AWS Cost and Usage Report and wants to visualize the report.

Which AWS service should the company use to ingest and display this information?

Options:

A.

Amazon QuickSight

B.

Amazon Pinpoint

C.

Amazon Neptune

D.

Amazon Kinesis

Question 136

A company needs stateless network filtering for its VPC.

Which AWS service, tool, or feature will meet this requirement?

Options:

A.

AWS PrivateLink

B.

Security group

C.

Network access control list (ACL)

D.

AWS WAF

Question 137

A company runs an application on AWS that performs batch jobs. The application is fault-tolerant and can handle interruptions. The company wants to optimize the cost to run the application.

Which AWS offering will meet these requirements?

Options:

A.

Amazon Macie

B.

Amazon Neptune

C.

Amazon EC2 Spot Instances

D.

Amazon EC2 On-Demand Instances

Question 138

A company is planning to migrate its application to the AWS Cloud.

Which AWS tool or set of resources should the company use to analyze and asses its readiness for migration?

Options:

A.

AWS Cloud Adoption Framework (AWS CAF)

B.

AWS Pricing Calculator

C.

AWS Well-Architected Framework

D.

AWS Budgets

Question 139

A company has all of its servers in the us-east-1 Region. The company is considering the deployment of additional servers different Region.

Which AWS tool should the company use to find pricing information for other Regions?

Options:

A.

Cost Explorer

B.

AWS Budgets

C.

AWS Purchase Order Management

D.

AWS Pricing Calculator

Question 140

A company uses a third-party identity provider (IdP). The company wants to provide its employees with access to AWS accounts and services without requiring another set of login credentials.

Which AWS service will meet this requirement?

Options:

A.

AWS Directory Service

B.

Amazon Cognito

C.

AWS IAM Identity Center

D.

AWS Resource Access Manager (AWS RAM)

Question 141

Which benefits can customers gain by using AWS Marketplace? (Select TWO.)

Options:

A.

Speed of business

B.

Fewer legal objections

C.

Ability to pay with credit cards

D.

No requirement for product licenses for any products

E.

Free use of all services for the first hour

Question 142

Which AWS service can a company use to find security and compliance reports, including International Organization for Standardization (ISO) reports?

Options:

A.

AWS Artifact

B.

Amazon CloudWatch

C.

AWS Config

D.

AWS Audit Manager

Question 143

A company is moving to the AWS Cloud to reduce operational overhead for its application infrastructure.

Which IT operation will the company still be responsible for after the migration to AWS?

Options:

A.

Security patching of AWS Elastic Beanstalk

B.

Backups of data that is stored in Amazon Aurora

C.

Termination of Amazon EC2 instances that are managed by AWS Auto Scaling

D.

Configuration of IAM access controls

Question 144

What can a cloud practitioner use to retrieve AWS security and compliance documents and submit them as evidence to an auditor or regulator?

Options:

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS Artifact

D.

Amazon Inspector

Question 145

A company wants to migrate to AWS and use the same security software it uses on premises. The security software vendor offers its security software as a service on AWS.

Where can the company purchase the security solution?

Options:

A.

AWS Partner Solutions Finder

B.

AWS Support Center

C.

AWS Management Console

D.

AWS Marketplace

Question 146

A company needs to store infrequently used data for data archives and long-term backups.

Which AWS service or storage class will meet these requirements MOST cost-effectively?

Options:

A.

Amazon FSx for Lustre

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3 Glacier Flexible Retrieval

Question 147

Which AWS service or feature provides a firewall at the subnet level within a VPC?

Options:

A.

Security group

B.

Network ACL

C.

Elastic network interface

D.

AWS WAF

Question 148

A company is preparing for an audit and wants documentation that AWS complies with the Payment Card Industry Data Security Standard (PCI DSS).

Where can the company find this documentation?

Options:

A.

AWS Artifact

B.

AWS Organizations

C.

AWS Trusted Advisor

D.

AWS Support Center

Question 149

A company has batch workloads that need to run for short periods of time on Amazon EC2. The workloads can handle interruptions and can start again from where they ended.

What is the MOST cost-effective EC2 instance purchasing option to meet these requirements?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 150

A company wants an AWS service to provide product recommendations based on its customer data.

Which AWS service will meet this requirement?

Options:

A.

Amazon Polly

B.

Amazon Personalize

C.

Amazon Comprehend

D.

Amazon Rekognition

Question 151

AWS has the ability to achieve lower pay-as-you-go pricing by aggregating usage across hundreds of thousands of users.

This describes which advantage of the AWS Cloud?

Options:

A.

Launch globally in minutes

B.

Increase speed and agility

C.

High economies of scale

D.

No guessing about compute capacity

Question 152

An ecommerce company plans to move its data center workload to the AWS Cloud to support highly dynamic usage patterns. Which benefits make the AWS Cloud cost-effective for the migration of this type of workload? (Select TWO.)

Options:

A.

Reliability

B.

Security

C.

Elasticity

D.

Pay-as-you-go resource pricing

E.

High availability

Question 153

Which AWS service or feature gives users the ability to connect VPCs and on-premises networks to a central hub?

Options:

A.

Virtual private gateway

B.

AWS Transit Gateway

C.

Internet gateway

D.

Customer gateway

Question 154

Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?

Options:

A.

AWS CloudFormation

B.

AWS CodeDeploy

C.

AWS CodeBuild

D.

AWS Systems Manager

Question 155

A company is considering migration to the AWS Cloud. The company wants a fully managed service or feature that can transfer streaming data from multiple sources to an Amazon S3 bucket.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

AWS DataSync

B.

Amazon Kinesis Data Firehose

C.

S3 Select

D.

AWS Transfer Family

Question 156

A company will run a predictable compute workload on Amazon EC2 Instances for the next 3 years. The workload is critical for the company. The company wants to optimize costs to run the workload.

Which solution will meet these requirements?

Options:

A.

Spot Instances

B.

Dedicated Hosts

C.

Savings Plans

D.

On-Demand Instances

Question 157

A company has 5 TB of data stored in Amazon S3. The company plans to occasionally run queries on the data for analysis.

Which AWS service should the company use to run these queries in the MOST cost-effective manner?

Options:

A.

Amazon Redshift

B.

Amazon Athena

C.

Amazon Kinesis

D.

Amazon RDS

Question 158

A company needs to convert video files and audio files to a format that will play on smartphones.

Which AWS service will meet this requirement?

Options:

A.

Amazon Comprehend

B.

Amazon Rekognition

C.

Amazon Elastic Transcoder

D.

Amazon Polly

Question 159

A company wants its Amazon EC2 instances to share the same geographic area but use multiple independent underlying power sources.

Which solution achieves this goal?

Options:

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Question 160

Which tool should a developer use lo integrate AWS service features directly into an application?

Options:

A.

AWS Software Development Kit

B.

AWS CodeDeploy

C.

AWS Lambda

D.

AWS Batch

Question 161

Which AWS service or tool should a company use to forecast AWS spending?

Options:

A.

Amazon DevPay

B.

AWS Organizations

C.

AWS Trusted Advisor

D.

Cost Explorer

Question 162

A company wants to create multiple isolated networks in the same AWS account.

Which AWS service or component will provide this functionality?

Options:

A.

AWS Transit Gateway

B.

Internet gateway

C.

Amazon VPC

D.

Amazon EC2

Question 163

A company runs a database on Amazon Aurora in the us-east-1 Region. The company has a disaster recovery requirement that the database be available in another Region.

Which solution meets this requirement with minimal disruption to the database operations?

Options:

A.

Perform an Aurora Multi-AZ deployment.

B.

Deploy Aurora cross-Region read replicas.

C.

Create Amazon Elastic Block Store (Amazon EBS) volume snapshots for Aurora and copy them to another Region.

D.

Deploy Aurora Replicas.

Question 164

What is a characteristic of Convertible Reserved Instances (RIs)?

Options:

A.

Users can exchange Convertible RIs for other Convertible RIs from a different instance family.

B.

Users can exchange Convertible RIs for other Convertible RIs in different AWS Regions.

C.

Users can sell and buy Convertible RIs on the AWS Marketplace.

D.

Users can shorten the term of their Convertible RIs by merging them with other Convertible RIs.

Question 165

A company has multiple AWS accounts that include compute workloads that cannot be interrupted. The company wants to obtain billing discounts that are based on the company's use of AWS services.

Which AWS feature or purchasing option will meet these requirements?

Options:

A.

Resource tagging

B.

Consolidated billing

C.

Pay-as-you-go pricing

D.

Spot Instances

Question 166

A company is running an application on AWS. The company wants to identify and prevent the accidental

Which AWS service or feature will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

Network ACL

C.

AWS WAF

D.

AWS Network Firewall

Question 167

A company has an application workload that is stateless by design and can sustain occasional downtime. The application performs massively parallel computations.

Which Amazon EC2 pricing model should the company choose for its application to reduce cost?

Options:

A.

On-Demand Instances

B.

Spot Instances

C.

Reserved Instances

D.

Dedicated Instances

Question 168

A company wants to migrate its applications to the AWS Cloud. The company plans to identify and prioritize any business transformation opportunities and evaluate its AWS Cloud readiness.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

AWS Cloud Adoption Framework (AWS CAF)

B.

AWS Managed Services (AMS)

C.

AWS Well-Architected Framework

D.

AWS Migration Hub

Question 169

Which of the following is entirely the responsibility of AWS, according to the AWS shared responsibility model?

Options:

A.

Security awareness and training

B.

Development of an IAM password policy

C.

Patching of the guest operating system

D.

Physical and environmental controls

Question 170

A company wants to develop a shopping application that records customer orders. The application needs to use an AWS managed database service to store data.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon ElastiCache

D.

Amazon Neptune

Question 171

Which AWS service can defend against DDoS attacks?

Options:

A.

AWS Firewall Manager

B.

AWS Shield Standard

C.

AWS WAF

D.

Amazon Inspector

Question 172

A company is setting up AWS Identity and Access Management (IAM) on an AWS account.

Which recommendation complies with IAM security best practices?

Options:

A.

Use the account root user access keys for administrative tasks.

B.

Grant broad permissions so that all company employees can access the resources they need.

C.

Turn on multi-factor authentication (MFA) for added security during the login process.

D.

Avoid rotating credentials to prevent issues in production applications.

Question 173

A company has an environment that includes Amazon EC2 instances, Amazon Lightsail, and on-premises servers. The company wants to automate the security updates for its operating systems and applications.

Which solution will meet these requirements with the LEAST operational effort?

Options:

A.

Use AWS Shield to identify and manage security events.

B.

Connect to each server by using a remote desktop connection. Run an update script.

C.

Use the AWS Systems Manager Patch Manager capability.

D.

Schedule Amazon GuardDuty to run on a nightly basis.

Question 174

A company wants to use Amazon EC2 instances for a stable production workload that will run for 1 year.

Which instance purchasing option meets these requirements MOST cost-effectively?

Options:

A.

Dedicated Hosts

B.

Reserved Instances

C.

On-Demand Instances

D.

Spot Instances

Question 175

Which options are perspectives that include foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)? (Select TWO.)

Options:

A.

Sustainability

B.

Security

C.

Operations

D.

Performance efficiency

E.

Reliability

Question 176

Which perspective of the AWS Cloud Adoption Framework (AWS CAF) connects technology and business?

Options:

A.

Operations

B.

People

C.

Security

D.

Governance

Question 177

A company wants guidance to optimize the cost and performance of its current AWS environment.

Which AWS service or tool should the company use to identify areas for optimization?

Options:

A.

Amazon QuickSight

B.

AWS Trusted Advisor

C.

AWS Organizations

D.

AWS Budgets

Question 178

A manufacturing company has a critical application that runs at a remote site that has a slow internet connection. The company wants to migrate the workload to AWS. The application is sensitive to latency and interruptions in connectivity. The company wants a solution that can host this application with minimum latency.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

Availability Zones

B.

AWS Local Zones

C.

AWS Wavelength

D.

AWS Outposts

Question 179

A retail company has recently migrated its website to AWS. The company wants to ensure that it is protected from SQL injection attacks. The website uses an Application Load Balancer to distribute traffic to multiple Amazon EC2 instances.

Which AWS service or feature can be used to create a custom rule that blocks SQL injection attacks?

Options:

A.

Security groups

B.

AWS WAF

C.

Network ACLs

D.

AWS Shield

Question 180

A company wants to securely store Amazon RDS database credentials and automatically rotate user passwords periodically.

Which AWS service or capability will meet these requirements?

Options:

A.

Amazon S3

B.

AWS Systems Manager Parameter Store

C.

AWS Secrets Manager

D.

AWS CloudTrail

Question 181

Which AWS service provides the SIMPLEST way for the company to establish a website on AWS?

Options:

A.

Amazon Elastic File System (Amazon EFS)

B.

AWS Elastic Beanstalk

C.

AWS Lambda

D.

Amazon Lightsail

Question 182

Which options are common stakeholders for the AWS Cloud Adoption Framework (AWS CAF) platform perspective? (Select TWO.)

Options:

A.

Chief financial officers (CFOs)

B.

IT architects

C.

Chief information officers (CIOs)

D.

Chief data officers (CDOs)

E.

Engineers

Question 183

A company needs to host a web server on Amazon EC2 instances for at least 1 year. The web server cannot tolerate interruption.

Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

Options:

A.

On-Demand Instances

B.

Partial Upfront Reserved Instances

C.

Spot Instances

D.

No Upfront Reserved Instances

Question 184

A company wants to move its data warehouse application to the AWS Cloud. The company wants to run and scale its analytics services without needing to provision and manage data warehouse clusters.

Which AWS service will meet these requirements?

Options:

A.

Amazon Redshift provisioned data warehouse

B.

Amazon Redshift Serverless

C.

Amazon Athena

D.

Amazon S3

Question 185

What does "security of the cloud" refer to in the AWS shared responsibility model?

Options:

A.

Availability of AWS services such as Amazon EC2

B.

Security of the cloud infrastructure that runs all the AWS services

C.

Implementation of password policies for IAM users

D.

Security of customer environments by using AWS Network Firewall partners

Question 186

In which categories does AWS Trusted Advisor provide recommended actions? (Select TWO.)

Options:

A.

Operating system patches

B.

Cost optimization

C.

Repetitive tasks

D.

Service quotas

E.

Account activity records

Question 187

A company wants to access a report about the estimated environmental impact of the company's AWS usage.

Which AWS service or feature should the company use to meet this requirement?

Options:

A.

AWS Organizations

B.

IAM policy

C.

AWS Billing console

D.

Amazon Simple Notification Service (Amazon SNS)

Question 188

A company needs a repository that stores source code. The company needs a way to update the running software when the code changes.

Which combination of AWS services will meet these requirements? (Select TWO.)

Options:

A.

AWS CodeCommit

B.

AWS CodeDeploy

C.

Amazon DynamoDB

D.

Amazon S3

E.

Amazon Elastic Container Service (Amazon ECS)

Question 189

A company wants its workload to perform consistently and correctly.

Which benefit of AWS Cloud computing does this goal represent?

Options:

A.

Security

B.

Elasticity

C.

Pay-as-you-go pricing

D.

Reliability

Question 190

A company wants to migrate to the AWS Cloud. The company needs the ability to acquire resources when the resources are necessary.

The company also needs the ability to release those resources when the resources are no longer necessary.

Which architecture concept of the AWS Cloud meets these requirements?

Options:

A.

Elasticity

B.

Availability

C.

Reliability

D.

Durability

Question 191

A company wants an in-memory data store that is compatible with open source in the cloud.

Which AWS service should the company use?

Options:

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon Redshift

Question 192

A new AWS user who has little cloud experience wants to build an application by using AWS services. The user wants to learn how to implement specific AWS services from other customer examples. The user also wants to ask questions to AWS experts.

Which AWS service or resource will meet these requirements?

Options:

A.

AWS Online Tech Talks

B.

AWS documentation

C.

AWS Marketplace

D.

AWS Health Dashboard

Question 193

A company needs to host a highly available application in the AWS Cloud. The application runs infrequently for short periods of time.

Which AWS service will meet these requirements with the LEAST amount of operational overhead?

Options:

A.

Amazon EC2

B.

AWS Fargate

C.

AWS Lambda

D.

Amazon Aurora

Question 194

Which AWS solution provides the ability for a company to run AWS services in the company's on-premises data center?

Options:

A.

AWS Direct Connect

B.

AWS Outposts

C.

AWS Systems Manager hybrid activations

D.

AWS Storage Gateway

Question 195

Which AWS services can a company use to host and run a MySQL database? (Select TWO.)

Options:

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon S3

D.

Amazon EC2

E.

Amazon MQ

Question 196

A company has set up a VPC in its AWS account and has created a subnet in the VPC. The company wants to make the subnet public.

Which AWS features should the company use to meet this requirement? (Select TWO.)

Options:

A.

Amazon VPC internet gateway

B.

Amazon VPC NAT gateway

C.

Amazon VPC route tables

D.

Amazon VPC network ACL

E.

Amazon EC2 security groups

Question 197

Which task is the responsibility of AWS when using AWS services?

Options:

A.

Management of IAM user permissions

B.

Creation of security group rules for outbound access

C.

Maintenance of physical and environmental controls

D.

Application of Amazon EC2 operating system patches

Question 198

A company does not want to rely on elaborate forecasting to determine its usage of compute resources. Instead, the company wants to pay only for the resources that it uses. The company also needs the ability to increase or decrease its resource usage to meet business requirements.

Which pillar of the AWS Well-Architected Framework aligns with these requirements?

Options:

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Question 199

A company needs help managing multiple AWS linked accounts that are reported on a consolidated bill.

Which AWS Support plan includes an AWS concierge whom the company can ask for assistance?

Options:

A.

AWS Developer Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Basic Support

Question 200

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

Options:

A.

Sustainability

B.

Operations

C.

Performance efficiency

D.

Reliability

Question 201

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

Options:

A.

Third-party vendors

B.

Customers

C.

Reseller partners

D.

Internet providers

Question 202

Which AWS solution should the company use to meet this requirement?

Options:

A.

AWS Config

B.

AWS software development kits (SDKs)

C.

AWS Service Catalog

D.

AWS AppSync

Question 203

A company is running workloads for multiple departments within a single VPC. The company needs to be able to bill each department for its resource usage.

Which action should the company take to accomplish this goal with the LEAST operational overhead?

Options:

A.

Add a department tag to each resource and configure cost allocation tags.

B.

Move each department resource to its own VPC.

C.

Move each department resource to its own AWS account.

D.

Use AWS Organizations to get a billing report for each department.

Question 204

A company wants to migrate its application to AWS. The company wants to replace upfront expenses with variable payment that is based on usage.

What should the company do to meet these requirements?

Options:

A.

Use pay-as-you-go pricing.

B.

Purchase Reserved Instances.

C.

Pay less by using more.

D.

Rightsize instances.

Question 205

Which of the following is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Identity and access management

B.

Hard drive initialization

C.

Protection of data center hardware

D.

Security of Availability Zones

Question 206

An application runs on multiple Amazon EC2 instances that access a shared file system simultaneously.

Which AWS storage service should be used?

Options:

A.

Amazon EBS

B.

Amazon EFS

C.

Amazon S3

D.

AWS Artifact

Question 207

A company is building an application that will receive millions of database queries each second. The company needs the data store for the application to scale to meet these needs.

Which AWS service will meet this requirement?

Options:

A.

Amazon DynamoDB

B.

AWS Cloud9

C.

Amazon ElastiCache for Memcached

D.

Amazon Neptune

Question 208

A company needs to launch an Amazon EC2 instance.

Which of the following can the company use during the launch process to configure the root volume of the EC2 instance?

Options:

A.

Amazon EC2 Auto Scaling

B.

Amazon Data Lifecycle Manager (Amazon DLM)

C.

Amazon Machine Image (AMI)

D.

Amazon Elastic Block Store (Amazon EBS) volume

Question 209

A company wants to run its production workloads on AWS. The company needs concierge service, a designated AWS technical account manager (TAM), and technical support that is available 24 hours a day, 7 days a week.

Which AWS Support plan will meet these requirements?

Options:

A.

AWS Basic Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Developer Support

Question 210

Which AWS service is designed to help users orchestrate a workflow process for a set of AWS Lambda functions?

Options:

A.

Amazon DynamoDB

B.

AWS CodePipeline

C.

AWS Batch

D.

AWS Step Functions

Question 211

A company needs to centralize its operational data. The company also needs to automate tasks across all of its Amazon EC2 instances.

Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

AWS Systems Manager

C.

AWS CodeDeploy

D.

AWS Elastic Beanstalk

Question 212

Which service is an AWS in-memory data store service?

Options:

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DynamoDB

D.

Amazon ElastiCache

Question 213

A company has an AWS-hosted website located behind an Application Load Balancer. The company wants to safeguard the website from SQL injection or cross-site scripting.

Which AWS service should the company use?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Trusted Advisor

D.

Amazon Inspector

Question 214

Which tasks are the responsibility of AWS according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Configure AWS Identity and Access Management (IAM).

B.

Configure security groups on Amazon EC2 instances.

C.

Secure the access of physical AWS facilities.

D.

Patch applications that run on Amazon EC2 instances.

E.

Perform infrastructure patching and maintenance.

Question 215

A company has a single Amazon EC2 instance. The company wants to adopt a highly available architecture.

What can the company do to meet this requirement?

Options:

A.

Scale vertically to a larger EC2 instance size.

B.

Scale horizontally across multiple Availability Zones.

C.

Purchase an EC2 Dedicated Instance.

D.

Change the EC2 instance family to a compute optimized instance.

Question 216

Which AWS service or tool helps companies measure the environmental impact of their AWS usage?

Options:

A.

AWS customer carbon footprint tool

B.

AWS Compute Optimizer

C.

Sustainability pillar

D.

OS-Climate (Open Source Climate Data Commons)

Question 217

A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access.

According to the AWS shared responsibility model, which task is the responsibility of the customer?

Options:

A.

Protect the global infrastructure that runs all of the services offered in the AWS Cloud.

B.

Configure logical access controls for resources, and protect account credentials.

C.

Configure the security used by managed services.

D.

Patch and back up Amazon Aurora.

Question 218

A company has a compliance requirement to record and evaluate configuration changes, as well as perform remediation actions on AWS resources.

Which AWS service should the company use?

Options:

A.

AWS Config

B.

AWS Secrets Manager

C.

AWS CloudTrail

D.

AWS Trusted Advisor

Question 219

A company is using Amazon RDS.

A company is launching a critical business application in an AWS Region.

How can the company increase resilience for this application?

Options:

A.

Deploy a copy of the application in another AWS account.

B.

Deploy the application by using multiple VPCs.

C.

Deploy the application by using multiple subnets.

D.

Deploy the application by using multiple Availability Zones.

Question 220

A company wants its Amazon EC2 instances to share the same geographic area but use redundant underlying power sources.

Which solution will meet these requirements?

Options:

A.

Use EC2 instances across multiple Availability Zones in the same AWS Region.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in AWS OpsWorks stacks in different AWS Regions.

Question 221

Which AWS service is always free of charge for users?

Options:

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

AWS Identity and Access Management (IAM)

Question 222

A company suspects that its AWS resources are being used for illegal activities.

Which AWS group or team should the company notify?

Options:

A.

AWS Abuse team

B.

AWS Support team

C.

AWS technical account managers

D.

AWS Professional Services team

Question 223

Which AWS service is always available free of charge to users?

Options:

A.

Amazon Athena

B.

AWS Identity and Access Management (IAM)

C.

AWS Secrets Manager

D.

Amazon ElastiCache

A company has only basic knowledge of AWS technologies.

Question 224

A company has an Amazon S3 bucket containing images of scanned financial invoices. The company is building an artificial intelligence (Al)-based application on AWS. The company wants the application to identify and read total balance amounts on the invoices.

Which AWS service will meet these requirements?

Options:

A.

Amazon Forecast

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Lex

Question 225

Which AWS service or tool provides recommendations to help users get rightsized Amazon EC2 instances based on historical workload usage data?

Options:

A.

AWS Pricing Calculator

B.

AWS Compute Optimizer

C.

AWS App Runner

D.

AWS Systems Manager

Question 226

A developer needs to maintain a development environment infrastructure and a production environment infrastructure in a repeatable fashion.

Which AWS service should the developer use to meet these requirements?

Options:

A.

AWS Ground Station

B.

AWS Shield

C.

AWS loT Device Defender

D.

AWS CloudFormation

Question 227

A user is moving a workload from a local data center to an architecture that is distributed between the local data center and the AWS Cloud.

Which type of migration is this?

Options:

A.

On-premises to cloud native

B.

Hybrid to cloud native

C.

On-premises to hybrid

D.

Cloud native to hybrid

Question 228

Which AWS service offers a global content delivery network (CDN) that helps companies securely deliver websites, videos, applications,

and APIs at high speeds with low latency?

Options:

A.

Amazon EC2

B.

Amazon CloudFront

C.

Amazon CloudWatch

D.

AWS CloudFormation

Question 229

Which AWS service can a company use to securely store and encrypt passwords for a database?

Options:

A.

AWS Shield

B.

AWS Secrets Manager

C.

AWS Identity and Access Management (IAM)

D.

Amazon Cognito

Question 230

A company wants to migrate its on-premises application to the AWS Cloud. The company is legally obligated to retain certain data in its onpremises data center.

Which AWS service or feature will support this requirement?

Options:

A.

AWS Wavelength

B.

AWS Local Zones

C.

VMware Cloud on AWS

D.

AWS Outposts

Question 231

Which AWS service is used to temporarily provide federated security credentials to a

Options:

A.

Amazon GuardDuty

B.

AWS Simple Token Service (AWS STS)

C.

AWS Secrets Manager

D.

AWS Certificate Manager

Question 232

Which benefit of the AWS Cloud helps companies achieve lower usage costs because of the aggregate usage of all AWS users?

Options:

A.

No need to guess capacity

B.

Ability to go global in minutes

C.

Economies of scale

D.

Increased speed and agility

Question 233

A company wants to migrate its Microsoft SQL Server database management system from on premises to the AWS Cloud.

Which AWS service should the company use to reduce management overhead for this environment?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon SageMaker

C.

Amazon RDS

D.

Amazon Athena

Question 234

A company is preparing to launch a redesigned website on AWS. Users from around the world will download digital handbooks from the website.

Which AWS solution should the company use to provide these static files securely?

Options:

A.

Amazon Kinesis Data Streams

B.

Amazon CloudFront with Amazon S3

C.

Amazon EC2 instances with an Application Load Balancer

D.

Amazon Elastic File System (Amazon EFS)

Question 235

A user discovered that an Amazon EC2 instance is missing an Amazon Elastic Block Store (Amazon EBS) data volume. The user wants to determine when the EBS volume was removed.

Which AWS service will provide this information?

Options:

A.

AWS Config

B.

AWS Trusted Advisor

C.

Amazon Timestream

D.

Amazon QuickSight

Question 236

Which AWS service provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning (ML)?

Options:

A.

Amazon Kendra

B.

Amazon SageMaker

C.

Amazon Augmented Al (Amazon A2I)

D.

Amazon Polly

Question 237

Which AWS services allow users to monitor and retain records of account activities that include governance, compliance, and auditing?

(Select TWO.)

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

Amazon GuardDuty

D.

AWS Shield

E.

AWS WAF

Question 238

Which AWS service or tool provides on-demand access to AWS security and compliance reports and AWS online agreements?

Options:

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS Billing console

Page: 1 / 79
Total 794 questions