Summer Sale- Special Discount Limited Time 65% Offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

Amazon Web Services CLF-C02 AWS Certified Cloud Practitioner Exam Practice Test

Page: 1 / 82
Total 820 questions

AWS Certified Cloud Practitioner Questions and Answers

Question 1

Which type of AWS storage is ephemeral and is deleted when an Amazon EC2 instance is stopped or terminated?

Options:

A.

Amazon Elastic Block Store (Amazon EBS)

B.

Amazon EC2 instance store

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3

Question 2

Which AWS Support plans provide access to an AWS technical account manager (TAM)? (Select)

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise On-Ramp Support

E.

AWS Enterprise Support

Question 3

Which AWS feature provides a no-cost platform for AWS users to join community groups, ask questions, find answers, and read community-generated articles about best practices?

Options:

A.

AWS Knowledge Center

B.

AWS re:Post

C.

AWS 10

D.

AWS Enterprise Support

Question 4

Which guidelines are best practices for using AWS Identity and Access Management (1AM)? (Select TWO.)

Options:

A.

Share access keys.

B.

Create individual 1AM users.

C.

Use inline policies instead of customer managed policies.

D.

Grant maximum privileges to 1AM users.

E.

Use groups to assign permissions to 1AM users.

Question 5

Which AWS service or feature provides a firewall at the subnet level within a VPC?

Options:

A.

Security group

B.

Network ACL

C.

Elastic network interface

D.

AWS WAF

Question 6

Which options are AWS Cloud Adoption Framework (AWS CAF) cloud transformation journey recommendations? (Select TWO.)

Options:

A.

Envision phase

B.

AIign phase

C.

Assess phase

D.

Mobilize phase

E.

Migrate and modernize phase

Question 7

A company wants a cost-effective option when running its applications in an Amazon EC2 instance for short time periods. The applications can be interrupted.

Which EC2 instance type will meet these requirements?

Options:

A.

Spot Instances

B.

On-Demand Instances

C.

Reserved Instances

D.

Dedicated Instances

Question 8

A company wants to migrate its database to a managed AWS service that is compatible with PostgreSQL.

Which AWS services will meet these requirements? (Select TWO)

Options:

A.

Amazon Athena

B.

Amazon RDS

C.

Amazon EC2

D.

Amazon DynamoDB

E.

Amazon Aurora

Question 9

Which fully managed AWS service assists with the creation, testing, and management of custom Amazon EC? images?

Options:

A.

EC2 Image Builder

B.

Amazon Machine Image (AMI)

C.

AWS Launch Wizard

D.

AWS Elastic Beanstalk

Question 10

Which AWS service or tool gives users the ability to connect with AWS and deploy resources programmatically?

Options:

A.

Amazon quickSight

B.

AWS PrivateLink

C.

AWS Direct Connect

D.

AWS SDKs

Question 11

Which Amazon S3 storage class is MOST cost-effective for unknown access patterns?

Options:

A.

S3 Standard

B.

S3 Standard-Infrequent Access (S3 Standard-IA)

C.

S3 One Zone-Infrequent Access (S3 One Zone-IA)

D.

S3 Intelligent-Tiering

Question 12

Which AWS service gives users the ability to discover and protect sensitive data that is stored in Amazon S3 buckets?

Options:

A.

Amazon Macie

B.

Amazon Detective

C.

Amazon GuardDuty

D.

AWS I AM Access Analyzer

Question 13

Which responsibility belongs to AWS when a company hosts its databases on Amazon EC2 instances?

Options:

A.

Database backups

B.

Database software patches

C.

Operating system patches

D.

Operating system installations

Question 14

Which tool should a developer use lo integrate AWS service features directly into an application?

Options:

A.

AWS Software Development Kit

B.

AWS CodeDeploy

C.

AWS Lambda

D.

AWS Batch

Question 15

Which of the following are advantages of moving to the AWS Cloud? (Select TWO.)

Options:

A.

Users can implement all AWS services in seconds.

B.

AWS assumes all responsibility for the security of infrastructure and applications.

C.

Users experience increased speed and agility.

D.

Users benefit from massive economies of scale.

E.

Users can move hardware from their data center to the AWS Cloud.

Question 16

A company wants to implement detailed tracking of its cloud costs by department and project.

Which AWS feature or service should the company use?

Options:

A.

Consolidated billing

B.

Cost allocation tags

C.

AWS Marketplace

D.

AWS Budgets

Question 17

Which AWS service or feature requires an Internet service provider (ISP) and a colocation facility to be Implemented?

Options:

A.

AWS VPN

B.

Amazon Conned

C.

AWS Direct Connect

D.

Internet gateway

Question 18

Which service enables customers to audit API calls in their AWS accounts'?

Options:

A.

AWS CloudTrail

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS X-Ray

Question 19

Which AWS services or features give users the ability to create a network connection between two VPCs? (Select TWO.)

Options:

A.

VPC endpoints

B.

Amazon Route 53

C.

VPC peering

D.

AWS Direct Connect

E.

AWS Transit Gateway

Question 20

Which AWS service is always provided at no charge?

Options:

A.

Amazon S3

B.

AWS Identity and Access Management (IAM)

C.

Elastic Load Balancers

D.

AWS WAF

Question 21

A company uses a third-party identity provider (IdP). The company wants to provide its employees with access to AWS accounts and services without requiring another set of login credentials.

Which AWS service will meet this requirement?

Options:

A.

AWS Directory Service

B.

Amazon Cognito

C.

AWS IAM Identity Center

D.

AWS Resource Access Manager (AWS RAM)

Question 22

Which advantage of cloud computing allows users to scale resources up and down based on the amount of load that an application supports?

Options:

A.

Go global in minutes

B.

Stop guessing capacity

C.

Benefit from massive economies of scale

D.

Trade fixed expense for variable expense

Question 23

Which AWS service or feature improves network performance by sending traffic through the AWS worldwide network infrastructure?

Options:

A.

Route table

B.

AWS Transit Gateway

C.

AWS Global Accelerator

D.

Amazon VPC

Question 24

An administrator observed that multiple AWS resources were deleted yesterday.

Which AWS service will help identify the cause and determine which user deleted the resources?

Options:

A.

AWS CtoudTrail

B.

Amazon Inspector

C.

Amazon GuardDuty

D.

AWS Trusted Advisor

Question 25

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on real-time insights and answers questions about strategy?

Options:

A.

Operations

B.

People

C.

Business

D.

Platform

Question 26

What is a benefit of using AWS serverless computing?

Options:

A.

Application deployment and management are not required

B.

Application security will be fully managed by AWS

C.

Monitoring and logging are not needed

D.

Management of infrastructure is offloaded to AWS

Question 27

A company Is designing its AWS workloads so that components can be updated regularly and so that changes can be made in small, reversible increments.

Which pillar of the AWS Well-Architected Framework does this design support?

Options:

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Question 28

Which mechanism allows developers to access AWS services from application code?

Options:

A.

AWS Software Development Kit

B.

AWS Management Console

C.

AWS CodePipeline

D.

AWS Config

Question 29

What is the best resource for a user to find compliance-related information and reports about AWS?

Options:

A.

AWS Artifact

B.

AWS Marketplace

C.

Amazon Inspector

D.

Increase operational costs across data centers.

Question 30

A company wants to run its application on Amazon EC2 instances. The company needs to keep the application on-premises to meet a compliance requirement. Which AWS offering will meet these requirements?

Options:

A.

Dedicated Instances

B.

Amazon CloudFront

C.

AWS Fargate

D.

AWS Outposts

Question 31

Which AWS service is a cloud security posture management (CSPM) service that aggregates alerts from various AWS services and partner products in a standardized format?

Options:

A.

AWS Security Hub

B.

AWS Trusted Advisor

C.

Amazon EventBndge

D.

Amazon GuardDuty

Question 32

Which of the following is a managed AWS service that is used specifically for extract, transform, and load (ETL) data?

Options:

A.

Amazon Athena

B.

AWS Glue

C.

Amazon S3

D.

AWS Snowball Edge

Question 33

Which AWS service allows for file sharing between multiple Amazon EC2 Instances?

Options:

A.

AWS Direct Connect

B.

AWS Snowball Edge

C.

AWS Backup

D.

Amazon Elastic File System (Amazon EFS)

Question 34

A company wants to automatically add and remove Amazon EC2 instances. The company wants the EC2 instances to adjust to varying workloads dynamically.

Which service or feature will meet these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon EC2 Spot Instances

C.

AWS Snow Family

D.

Amazon EC2 Auto Scaling

Question 35

At what support level do users receive access to a support concierge?

Options:

A.

Basic Support

B.

Developer Support

C.

Business Support

D.

Enterprise Support

Question 36

A company needs to perform data processing once a week that typically takes about 5 hours to complete. Which AWS service should the company use for this workload?

Options:

A.

AWS Lambda

B.

Amazon EC2

C.

AWS CodeDeploy

D.

AWS Wavelength

Question 37

Which AWS service or feature gives users the ability to connect VPCs and on-premises networks to a central hub?

Options:

A.

Virtual private gateway

B.

AWS Transit Gateway

C.

Internet gateway

D.

Customer gateway

Question 38

Which AWS Support plan provides the full set to AWS Trusted Advisor checks at the LOWEST cost?

Options:

A.

AWS Developer Support

B.

AWS Business Support

C.

AWS Enterprise On-Ramp Support

D.

AWS Enterprise Support

Question 39

A company wants to create a globally accessible ecommerce platform for its customers. The company wants to use a highly available and scalable DNS web service to connect users to the platform.

Which AWS service will meet these requirements?

Options:

A.

Amazon EC2

B.

Amazon VPC

C.

Amazon Route 53

D.

Amazon RDS

Question 40

A user wants to allow applications running on an Amazon EC2 instance to make calls to other AWS services. The access granted must be secure. Which AWS service or feature should be used?

Options:

A.

Security groups

B.

AWS Firewall Manager

C.

IAM roles

D.

IAM user SSH keys

Question 41

A company has batch workloads that need to run for short periods of time on Amazon EC2. The workloads can handle interruptions and can start again from where they ended.

What is the MOST cost-effective EC2 instance purchasing option to meet these requirements?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 42

Which AWS service or resource provides answers to the most frequently askedsecurity-related questions that AWS receives from its users'?

Options:

A.

AWS Artifact

B.

Amazon Connect

C.

AWS Chatbot

D.

AWS Knowledge Center

Question 43

A company is using Amazon DynamoDB for its application database.

Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Classify data.

B.

Configure access permissions.

C.

Manage encryption options.

D.

Provide public endpoints to store and retrieve data.

E.

Manage the infrastructure layer and the operating system.

Question 44

A company has a compute workload that is steady, predictable, and uninterruptible.

Which Amazon EC2 instance purchasing options meet these requirements MOST cost-effectively? (Select TWO.)

Options:

A.

On-Demand Instances

B.

Reserved Instances

C.

Spot Instances

D.

Saving Plans

E.

Dedicated Hosts

Question 45

A company wants to design its cloud architecture so that it can support development innovations, and continuously improve processes and procedures.

This is an example of which pillar of the AWS Well-Architected Framework?

Options:

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Question 46

A company wants to run its workload on Amazon EC2 instances for more than 1 year. This workload will run continuously.

Which option offers a discounted hourly rate compared to the hourly rate of On-Demand Instances?

Options:

A.

AWS Graviton processor

B.

Dedicated Hosts

C.

EC2 Instance Savings Plans

D.

Amazon EC2 Auto Scaling instances

Question 47

A company is planning to move data backups to the AWS Cloud. The company needs to replace on-premises storage with storage that is cloud-based but locally cached.

Which AWS service meets these requirements?

Options:

A.

AWS Storage Gateway

B.

AWS Snowcone

C.

AWS Backup

D.

Amazon Elastic File System (Amazon EFS)

Question 48

Which AWS service or feature allows a user to establish a dedicated network connection between a company's on-premises data center and the AWS Cloud?

Options:

A.

AWS Direct Connect

B.

VPC peering

C.

AWS VPN

D.

Amazon Route 53

Question 49

An ecommerce company has deployed a new web application on Amazon EC2 Instances. The company wants to distribute incoming HTTP traffic evenly across all running instances.

Which AWS service or resource will meet this requirement?

Options:

A.

Amazon EC2 Auto Scaling

B.

Application Load Balancer

C.

Gateway Load Balancer

D.

Network Load Balancer

Question 50

Which of the following is a fully managed graph database service on AWS?

Options:

A.

Amazon Aurora

B.

Amazon FSx

C.

Amazon DynamoDB

D.

Amazon Neptune

Question 51

A company hosts its website on Amazon EC2 instances. The company needs to ensure that the website reaches a global audience and provides minimum latency to users.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Route 53

B.

Amazon CloudFront

C.

Elastic Load Balancing

D.

AWS Lambda

Question 52

Which task is the responsibility of the customer, according to the AWS shared responsibility model?

Options:

A.

Patch the Amazon DynamoDB operating system.

B.

Secure Amazon CloudFront edge locations by allowing physical access according to the principle of least privilege.

C.

Protect the hardware that runs AWS services.

D.

Use AWS Identity and Access Management (1AM) according to the principle of least privilege.

Question 53

A company needs to convert video files and audio files to a format that will play on smartphones.

Which AWS service will meet this requirement?

Options:

A.

Amazon Comprehend

B.

Amazon Rekognition

C.

Amazon Elastic Transcoder

D.

Amazon Polly

Question 54

A company operates a petabyte-scale data warehouse to analyze its data. The company wants a solution that will not require manual hardware and software management. Which AWS service will meet these requirements?

Options:

A.

Amazon DocumentDB (with MongoDB compatibility)

B.

Amazon Redshift

C.

Amazon Neptune

D.

Amazon ElastiCache

Question 55

A company has deployed an Amazon EC2 instance.

Which option is an AWS responsibility under the AWS shared responsibility model?

Options:

A.

Managing and encrypting application data

B.

Installing updates and security patches of guest operating system

C.

Configuration of infrastructure devices

D.

Configuration of security groups on each instance

Question 56

Under the AWS shared responsibility model, which of the following is a responsibility of the customer?

Options:

A.

Shred disk drives before they leave a data center.

B.

Prevent customers from gathering packets or collecting traffic at the hypervisor level.

C.

Patch the guest operating system with the latest security patches.

D.

Maintain security systems that provide physical monitoring of data centers.

Question 57

A company has a workload that will run continuously for 1 year. The workload cannot tolerate service interruptions.

Which Amazon EC2 purchasing option will be MOST cost-effective?

Options:

A.

All Upfront Reserved Instances

B.

Partial Upfront Reserved Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 58

A company plans to launch an ecommerce website that contains many images for a product catalog. The company wants to keep the cost of running the website within a specific budget.

Which AWS service or tool should the company use to monitor the ongoing costs of the website?

Options:

A.

AWS Cost Explorer

B.

AWS SDKs

C.

EC2 Image Builder

D.

AWS CloudFormation

Question 59

An ecommerce company wants to use Amazon EC2 Auto Scaling to add and remove EC2 instances based on CPU utilization.

Which AWS service or feature can initiate an Amazon EC2 Auto Scaling action to achieve this goal?

Options:

A.

Amazon Simple Queue Service (Amazon SQS)

B.

Amazon Simple Notification Service (Amazon SNS)

C.

AWS Systems Manager

D.

Amazon CloudWatch alarm

Question 60

A company runs an application on AWS that performs batch jobs. The application is fault-tolerant and can handle interruptions. The company wants to optimize the cost to run the application.

Which AWS offering will meet these requirements?

Options:

A.

Amazon Macie

B.

Amazon Neptune

C.

Amazon EC2 Spot Instances

D.

Amazon EC2 On-Demand Instances

Question 61

Which pillar of the AWS Well-Architected Framework focuses on the ability to recover automatically from service Interruptions?

Options:

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Question 62

An AWS user wants to proactively detect when an instance or account might be compromised or if there are threats from attacks.

Which AWS service should the user choose?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Shield

D.

Amazon Inspector

Question 63

A company wants an automated process to continuously scan its Amazon EC2 instances for software vulnerabilities.

Which AWS service will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

Amazon Inspector

C.

Amazon Detective

D.

Amazon Cognito

Question 64

Which AWS service or feature can a company use to apply security rules to specific Amazon EC2 instances?

Options:

A.

Network ACLs

B.

Security groups

C.

AWS Trusted Advisor

D.

AWS WAF

Question 65

A company wants to migrate its high-performance computing (HPC) application to Amazon EC2 instances. The application has multiple components. The application must have fault tolerance and must have the ability to fail over automatically.

Which AWS infrastructure solution will meet these requirements with the LEAST latency between components?

Options:

A.

Multiple AWS Regions

B.

Multiple edge locations

C.

Multiple Availability Zones

D.

Regional edge caches

Question 66

A company wants to move its iOS application development and build activities to AWS.

Which AWS service or resource should the company use for these activities?

Options:

A.

AWS CodeCommit

B.

Amazon EC2 M1 Mac instances

C.

AWS Amplify

D.

AWS App Runner

Question 67

A company hosts a large amount of data in AWS. The company wants to identify if any of the data should be considered sensitive.

Which AWS service will meet the requirement?

Options:

A.

Amazon Inspector

B.

Amazon Macie

C.

AWS Identity and Access Management (IAM)

D.

Amazon CloudWatch

Question 68

A company is storing sensitive customer data in an Amazon S3 bucket. The company wants to protect the data from accidental deletion or overwriting.

Which S3 feature should the company use to meet these requirements?

Options:

A.

S3 Lifecycle rules

B.

S3 Versioning

C.

S3 bucket policies

D.

S3 server-side encryption

Question 69

A company wants a customized assessment of its current on-premises environment. The company wants to understand its projected running costs in the AWS Cloud.

Which AWS service or tool will meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWS Control Tower

D.

Migration Evaluator

Question 70

Which AWS service or feature can the company use to limit the access to AWS services for member accounts?

Options:

A.

AWS Identity and Access Management (IAM)

B.

Service control policies (SCPs)

C.

Organizational units (OUs)

D.

Access control lists (ACLs)

Question 71

Which AWS service offers object storage?

Options:

A.

Amazon RDS

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon S3

D.

Amazon DynamoDB

Question 72

What can a cloud practitioner use to retrieve AWS security and compliance documents and submit them as evidence to an auditor or regulator?

Options:

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS Artifact

D.

Amazon Inspector

Question 73

A company is planning to migrate to the AWS Cloud and wants to become more responsive to customer inquiries and feedback. The company wants to focus on organizational transformation.

A company wants to give its customers the ability to view specific data that is hosted in Amazon S3 buckets. The company wants to keep control over the full datasets that the company shares with the customers.

Which S3 feature will meet these requirements?

Options:

A.

S3 Storage Lens

B.

S3 Cross-Region Replication (CRR)

C.

S3 Versioning

D.

S3 Access Points

Question 74

Which AWS service requires the customer to be fully responsible for applying operating system patches?

Options:

A.

Amazon DynamoDB

B.

AWS Lambda

C.

AWS Fargate

D.

Amazon EC2

Question 75

A company wants to make an upfront commitment for continued use of its production Amazon EC2 instances in exchange for a reduced overall cost.

Which pricing options meet these requirements with the LOWEST cost? (Select TWO.)

Options:

A.

Spot Instances

B.

On-Demand Instances

C.

Reserved Instances

D.

Savings Plans

E.

Dedicated Hosts

Question 76

A company is migrating its data center to AWS. The company needs an AWS Support plan that provides chat access to a cloud sup engineer 24 hours a day, 7 days a week. The company does not require access to infrastructure event management.

What is the MOST cost-effective AWS Support plan that meets these requirements?

Options:

A.

AWS Enterprise Support

B.

AWS Business Support

C.

AWS Developer Support

D.

AWS Basic Support

Question 77

A company wants to integrate its online shopping website with social media login credentials.

Which AWS service can the company use to make this integration?

Options:

A.

AWS Directory Service

B.

AWS Identity and Access Management (IAM)

C.

Amazon Cognito

D.

AWS IAM Identity Center (AWS Single Sign-On)

Question 78

A company is expecting a short-term spike in internet traffic for its application. During the traffic increase, the application cannot be interrupted. The company also needs to minimize cost and maximize flexibility.

A company needs to use a serverless interactive query service to analyze data in Amazon S3. The query service

must support standard SQL.

Which AWS service will meet these requirements?

Options:

A.

Amazon Redshift

B.

AWS Glue

C.

Amazon Athena

D.

Amazon Kinesis Data Streams

Question 79

Which AWS service uses AWS Compute Optimizer to provide sizing recommendations based on workload metrics?

Options:

A.

Amazon EC2

B.

Amazon RDS

C.

Amazon Lightsail

D.

AWS Step Functions

Question 80

Which AWS services allow users to monitor and retain records of account activities that include governance, compliance, and auditing?

(Select TWO.)

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

Amazon GuardDuty

D.

AWS Shield

E.

AWS WAF

Question 81

A company manages factory machines in real time. The company wants to use AWS technology to deploy its monitoring applications as close to the factory machines as possible.

Which AWS solution will meet these requirements with the LEAST latency?

Options:

A.

AWS Outposts

B.

Amazon EC2

C.

AWS App Runner

D.

AWS Batch

Question 82

A company migrated its core application onto multiple workloads in the AWS Cloud. The company wants to improve the application's reliability.

Which cloud design principle should the company implement to achieve this goal?

Options:

A.

Maximize utilization.

B.

Decouple the components.

C.

Rightsize the resources.

D.

Adopt a consumption model.

Question 83

Which pillar of the AWS Well-Architected Framework includes the AWS shared responsibility model?

Options:

A.

Operational excellence

B.

Performance efficiency

C.

Reliability

D.

Security

Question 84

What is an AWS responsibility under the AWS shared responsibility model?

Options:

A.

Configure the security group rules that determine which ports are open on an Amazon EC2 Linux instance.

B.

Ensure the security of the internal network in the AWS data centers.

C.

Patch the guest operating system with the latest security patches on Amazon EC2.

D.

Turn on server-side encryption for Amazon S3 buckets.A company wants to deploy its critical application on AWS and maintain high availability.

Question 85

A company needs to set a maximum spending limit on AWS services each month. The company also needs to set up alerts for when the company reaches its spending limit.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

Cost Explorer

B.

AWS Trusted Advisor

C.

Service Quotas

D.

AWS Budgets

Question 86

A company plans to migrate to the AWS Cloud. The company is gathering information about its on-premises infrastructure and requires information such as the hostname, IP address, and MAC address.

Which AWS service will meet these requirements?

Options:

A.

AWS DataSync

B.

AWS Application Migration Service

C.

AWS Application Discovery Service

D.

AWS Database Migration Service (AWS DMS)

Question 87

Which AWS service provides encryption at rest for Amazon RDS and for Amazon Elastic Block Store (Amazon EBS) volumes?

Options:

A.

AWS Lambda

B.

AWS Key Management Service (AWS KMS)

C.

AWSWAF

D.

Amazon Rekognition

Question 88

A company wants to migrate a database from an on-premises environment to Amazon RDS.

After the migration is complete, which management task will the company still be responsible for?

Options:

A.

Hardware lifecycle management

B.

Application optimization

C.

Server maintenance

D.

Power, network, and cooling provisioning

Question 89

A company is running an Amazon EC2 instance in a VPC.

An ecommerce company is using Amazon EC2 Auto Scaling groups to manage a fleet of web servers running on Amazon EC2.

This architecture follows which AWS Well-Architected Framework best practice?

Options:

A.

Secure the workload

B.

Decouple infrastructure components

C.

Design for failure

D.

Think parallel

Question 90

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

Options:

A.

Sustainability

B.

Security

C.

Performance efficiency

D.

Reliability

Question 91

For which AWS service is the customer responsible for maintaining the underlying operating system?

Options:

A.

Amazon DynamoDB

B.

Amazon S3

C.

Amazon EC2

D.

AWS Lambda

Question 92

A company wants to minimize network latency between its Amazon EC2 instances. The EC2 instances do not need to be highly available.

Which solution meets these requirements?

Options:

A.

Use EC2 instances in a single Availability Zone.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Question 93

A company's headquarters is located on a different continent from where the majority of the company's customers live. The company wants an AWS Cloud environment setup that will provide the lowest latency to the customers.

A company wants to automate the creation of new AWS accounts and automatically prevent all users from creating Amazon EC2

instances.

Which AWS service provides this functionality?

Options:

A.

AWS Service Catalog

B.

AWS Organizations

C.

EC2 Image Builder

D.

AWS Systems Manager

Question 94

Which capabilities are in the platform perspective of the AWS Cloud Adoption Framework (AWS CAF)? (Select TWO.)

Options:

A.

Performance and capacity management

B.

Data engineering

C.

Continuous integration and continuous delivery (CI/CD)

D.

Infrastructure protection

E.

Change and release management

Question 95

Which tasks are the responsibility of the customer, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Patch the Amazon RDS operating system.

B.

Upgrade the firmware of the network infrastructure.

C.

Manage data encryption.

D.

Maintain physical access control in an AWS Region.

E.

Grant least privilege access to IAM users.

Question 96

Which abilities are benefits of the AWS Cloud? (Select TWO.)

Options:

A.

Trade variable expenses for capital expenses.

B.

Deploy globally in minutes.

C.

Plan capacity in advance of deployments.

D.

Take advantage of economies of scale.

E.

Reduce dependencies on network connectivity.

Question 97

A company is running its application in the AWS Cloud. The company wants to periodically review its AWS account for cost optimization opportunities.

Which AWS service or tool can the company use to meet these requirements?

Options:

A.

AWS Cost Explorer

B.

AWS Trusted Advisor

C.

AWS Pricing

D.

AWS Budgets

Question 98

A company needs to search for text in documents that are stored in Amazon S3.

Which AWS service will meet these requirements?

Options:

A.

Amazon Kendra

B.

Amazon Rekognition

C.

Amazon Polly

D.

Amazon Lex

Question 99

Which actions are best practices for an AWS account root user? (Select TWO.)

Options:

A.

Share root user credentials with team members.

B.

Create multiple root users for the account, separated by environment.

C.

Enable multi-factor authentication (MFA) on the root user.

D.

Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user.

E.

Use programmatic access instead of the root user and password.

Question 100

A company is collecting user behavior patterns to identify how to meet goals for sustainability impact.

Which guidelines are best practices for the company to implement to meet these goals? (Select TWO.)

Options:

A.

Scale infrastructure with user load.

B.

Maximize the geographic distance between workloads and user locations.

C.

Eliminate creation and maintenance of unused assets.

D.

Scale resources with excess capacity and remove auto scaling.

E.

Scale infrastructure based on the number of users.

Question 101

Which of the following are general AWS Cloud design principles described in the AWS Well-Architected Framework?

Options:

A.

Consolidate key components into monolithic architectures.

B.

Test systems at production scale.

C.

Provision more capacity than a workload is expected to need.

D.

Drive architecture design based on data collected about the workload behavior and requirements.

E.

Make AWS Cloud architectural decisions static, one-time events.

Question 102

A company has deployed an application in the AWS Cloud. The company wants to ensure that the application is highly resilient.

Which component of AWS infrastructure can the company use to meet this requirement?

Options:

A.

Content delivery network (CDN)

B.

Edge locations

C.

Wavelength Zones

D.

Availability Zones

Question 103

A company wants to use the AWS Cloud to deploy an application globally.

Which architecture deployment model should the company use to meet this requirement?

Options:

A.

Multi-Region

B.

Single-Region

C.

Multi-AZ

D.

Single-AZ

Question 104

A company has 5 TB of data stored in Amazon S3. The company plans to occasionally run queries on the data for analysis.

Which AWS service should the company use to run these queries in the MOST cost-effective manner?

Options:

A.

Amazon Redshift

B.

Amazon Athena

C.

Amazon Kinesis

D.

Amazon RDS

Question 105

A company uses AWS Organizations. The company wants to apply security best practices from the AWS Well-Architected Framework to all of its AWS accounts.

Which AWS service will meet these requirements?

Options:

A.

Amazon Macie

B.

Amazon Detective

C.

AWS Control Tower

D.

AWS Secrets Manager

Question 106

Which AWS service helps developers use loose coupling and reliable messaging between microservices?

Options:

A.

Elastic Load Balancing

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon CloudFront

D.

Amazon Simple Queue Service (Amazon SQS)

Question 107

A company wants to grant users in one AWS account access to resources in another AWS account. The users do not currently have permission to access the resources.

Which AWS service will meet this requirement?

Options:

A.

IAM group

B.

IAM role

C.

IAM tag

D.

IAM Access Analyzer

Question 108

A company encourages its teams to test failure scenarios regularly and to validate their understanding of the impact of potential failures.

Which pillar of the AWS Well-Architected Framework does this philosophy represent?

Options:

A.

Operational excellence

B.

Cost optimization

C.

Performance efficiency

D.

Security

Question 109

A company wants its AWS usage to be more sustainable. The company wants to track, measure, review, and forecast polluting emissions that result from its AWS applications.

Which AWS service or tool can the company use to meet these requirements?

Options:

A.

AWS Health Dashboard

B.

AWS customer carbon footprint tool

C.

AWS Support Center

D.

Amazon QuickSight

Question 110

Which VPC component provides a layer of security at the subnet level?

Options:

A.

Security groups

B.

Network ACLs

C.

NAT gateways

D.

Route tables

Question 111

A company wants to monitor its workload performance. The company wants to ensure that the cloud services are delivered at a level that meets its business needs.

Which AWS Cloud Adoption Framework (AWS CAF) perspective will meet these requirements?

Options:

A.

Business

B.

Governance

C.

Platform

D.

Operations

Question 112

Which AWS services are supported by Savings Plans?(Select TWO.)

Options:

A.

Amazon EC2

B.

Amazon RDS

C.

Amazon SageMaker

D.

Amazon Redshift

E.

Amazon DynamoDB

Question 113

Which AWS service can provide a dedicated network connection with consistent low latency from on premises to the AWS Cloud?

Options:

A.

Amazon VPC

B.

Amazon Kinesis Data Streams

C.

AWS Direct Connect

D.

Amazon OpenSearch Service

Question 114

A company seeks cost savings in exchange for a commitment to use a specific amount of an AWS service or category ofAWS services for 1 year or 3 years.

Which AWS pricing model or offering will meet these requirements?

Options:

A.

Pay-as-you-go pricing

B.

Savings Plans

C.

AWS Free Tier

D.

Volume discounts

Question 115

A company is running a workload in the AWS Cloud.

Which AWS best practice ensures the MOST cost-effective architecture for the workload?

Options:

A.

Loose coupling

B.

Rightsizing

C.

Caching

D.

Redundancy

Question 116

Which AWS service is designed to help users build conversational interfaces into applications using voice and text?

Options:

A.

Amazon Lex

B.

Amazon Transcribe

C.

Amazon Comprehend

D.

Amazon Timestream

Question 117

A company wants to run its production workloads on AWS. The company needs concierge service, a designated AWS technical account manager (TAM), and technical support that is available 24 hours a day, 7 days a week.

Which AWS Support plan will meet these requirements?

Options:

A.

AWS Basic Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Developer Support

Question 118

A company is running its application in the AWS Cloud and wants to protect against a DDoS attack. The company's security team wants near real-time visibility into DDoS attacks.

Which AWS service or traffic filter will meet these requirements with the MOST features for DDoS protection?

Options:

A.

AWS Shield Advanced

B.

AWS Shield

C.

Amazon GuardDuty

D.

Network ACLs

Question 119

Which AWS services are connectivity services for a VPC? (Select TWO.)

Options:

A.

AWS Site-to-Site VPN

B.

AWS Direct Connect

C.

Amazon Connect

D.

AWS Key Management Service (AWS KMS)

E.

AWS Identity and Access Management (IAM)

Question 120

A company has set up a VPC on AWS. The company needs a dedicated connection between the VPC and the company’s on-premises network.

Which action should the company take to meet this requirement?

Options:

A.

Establish a VPN connection between the VPC and the company's on-premises network.

B.

Establish an AWS Direct Connect connection between the VPC and the company's on-premisesnetwork.

C.

Attach an internet gateway to the VPC. Use the AWS public endpoints for connectivity.

D.

Configure Amazon Connect to provide connectivity between the VPC and the company's on-premisesnetwork.

Question 121

A company processes personally identifiable information (Pll) and must keep data in the country where it was generated. The company wants to use Amazon EC2 instances for these workloads.

Which AWS service will meet these requirements?

Options:

A.

AWS Outposts

B.

AWS Storage Gateway

C.

AWS DataSync

D.

AWS OpsWorks

Question 122

A company deployed an Amazon EC2 instance last week. A developer realizes that the EC2 instance is no longer running. The developer reviews a list of provisioned EC2 instances, and the EC2 instance is no longer on the list.

What can the developer do to generate a recent history of the EC2 instance?

Options:

A.

Run Cost Explorer to identify the start time and end time of the EC2 instance.

B.

Use Amazon Inspector to find out when the EC2 instance was stopped.

C.

Perform a search in AWS CloudTrail to find all EC2 instance-related events.

D.

Use AWS Secrets Manager to display hidden termination logs of the EC2 instance.

Question 123

To reduce costs, a company is planning to migrate a NoSQL database to AWS.

Which AWS service is fully managed and can automatically scale throughput capacity to meet database workload demands?

Options:

A.

Amazon Redshift

B.

Amazon Aurora

C.

Amazon DynamoDB

D.

Amazon RDS

Question 124

Which AWS Cloud benefit describes the ability to acquire resources as they are needed and release resources when they are no longer needed?

Options:

A.

Economies of scale

B.

Elasticity

C.

Agility

D.

Security

Question 125

Which AWS service will help protect applications running on AWS from DDoS attacks?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Shield

D.

Amazon Inspector

Question 126

A company needs to store data across multiple Availability Zones in an AWS Region. The data will not be

accessed regularly but must be immediately retrievable.

Which Amazon Elastic File System (Amazon EFS) storage class meets these requirements MOST cost effectively?

Options:

A.

EFS Standard

B.

EFS Standard-Infrequent Access(EFS Standard-IA)

C.

EFS One Zone

D.

EFS One Zone-Infrequent Access (EFS One Zone-IA)

Question 127

A company needs Amazon EC2 instances for a workload that can tolerate interruptions.

Which EC2 instance purchasing option meets this requirement with the LARGEST discount compared to On-Demand prices?

Options:

A.

Spot Instances

B.

Convertible Reserved Instances

C.

Standard Reserved Instances

D.

Dedicated Hosts

Question 128

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

Options:

A.

AWS CloudTrail

B.

AWS Cost and Usage Reports

C.

AWS Trusted Advisor

D.

AWS Budgets

Question 129

Which AWS service provides highly durable object storage?

Options:

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon FSx

Question 130

A cloud engineer wants to know the percentage of the allocated compute units that are in use for a specific Amazon EC2 instance.

Which AWS service can provide this information?

Options:

A.

AWS CloudTrail

B.

AWS Config

C.

Amazon CloudWatch

D.

AWS Artifact

Question 131

A cloud practitioner is analyzing Amazon EC2 instance performance and usage to provide recommendations for potential cost savings.

Which cloud concept does this analysis demonstrate?

Options:

A.

Auto scaling

B.

Rightsizing

C.

Load balancing

D.

High availability

Question 132

A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access.

According to the AWS shared responsibility model, which task is the responsibility of the customer?

Options:

A.

Protect the global infrastructure that runs all of the services offered in the AWS Cloud.

B.

Configure logical access controls for resources, and protect account credentials.

C.

Configure the security used by managed services.

D.

Patch and back up Amazon Aurora.

Question 133

Which activity is a customer responsibility in the AWS Cloud according to the AWS shared responsibility model?

Options:

A.

Ensuring network connectivity from AWS to the internet

B.

Patching and fixing flaws within the AWS Cloud infrastructure

C.

Ensuring the physical security of cloud data centers

D.

Ensuring Amazon EBS volumes are backed up

Question 134

A company wants to migrate its on-premises data warehouse to AWS. The information in the data warehouse is

used to populate analytics dashboards.

Which AWS service should the company use for the data warehouse?

Options:

A.

Amazon ElastiCache

B.

Amazon Aurora

C.

Amazon RDS

D.

Amazon Redshift

Question 135

A company is hosting a web application on Amazon EC2 instances. The company wants to implement custom conditions to filter and control inbound web traffic.

Which AWS service will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

AWSWAF

C.

Amazon Macie

D.

AWS Shield

Question 136

Which of the following is a cost efficiency principle related to the AWS Cloud?

Options:

A.

Right-size services based on capacity requirements.

B.

Use the Billing Dashboard to access information about monthly bills.

C.

Use AWS Organizations to combine the expenses of multiple accounts into a single bill.

D.

Tag all AWS resources.

Question 137

A company plans to migrate its on-premises workload to AWS. Before the migration, the company needs to estimate its future AWS service costs.

Which AWS service or tool should the company use to meet this requirement?

Options:

A.

AWS Trusted Advisor

B.

AWS Budgets

C.

AWS Pricing Calculator

D.

AWS Cost Explorer

Question 138

Which AWS services and features are provided to all customers at no charge? (Select TWO.)

Options:

A.

Amazon Aurora

B.

VPC

C.

Amazon SageMaker

D.

AWS Identity and Access Management (IAM)

E.

Amazon Polly

Question 139

Which of the following is a recommended design principle of the AWS Well-Architected Framework?

Options:

A.

Reduce downtime by making infrastructure changes infrequently and in large increments.

B.

Invest the time to configure infrastructure manually.

C.

Learn to improve from operational failures.

D.

Use monolithic application design for centralization.

Question 140

Which database engine is compatible with Amazon RDS?

Options:

A.

Apache Cassandra

B.

MongoDB

C.

Neo4j

D.

PostgreSQL

Question 141

Which encryption types can be used to protect objects at rest in Amazon S3? (Select TWO.)

Options:

A.

Server-side encryption with AmazonS3 managed encryption keys (SSE-S3)

B.

Server-side encryption with AWS KMSmanaged keys (SSE-KMS)

C.

TLS

D.

SSL

E.

Transparent Data Encryption (TDE)

Question 142

Which AWS service is used to temporarily provide federated security credentials to a

Options:

A.

Amazon GuardDuty

B.

AWS Simple Token Service (AWS STS)

C.

AWS Secrets Manager

D.

AWS Certificate Manager

Question 143

Which AWS service offers a global content delivery network (CDN) that helps companies securely deliver websites, videos, applications,

and APIs at high speeds with low latency?

Options:

A.

Amazon EC2

B.

Amazon CloudFront

C.

Amazon CloudWatch

D.

AWS CloudFormation

Question 144

A company needs to host a web server on Amazon EC2 instances for at least 1 year. The web server cannot tolerate interruption.

Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

Options:

A.

On-Demand Instances

B.

Partial Upfront Reserved Instances

C.

Spot Instances

D.

No Upfront Reserved Instances

Question 145

Which of the following are user authentication services managed by AWS? (Select TWO.)

Options:

A.

Amazon Cognito

B.

AWS Lambda

C.

AWS License Manager

D.

AWS Identity and Access Management (IAM)

E.

AWS CodeStar

Question 146

Which AWS Support plan assigns an AWS concierge agent to a company's account?

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Question 147

A company needs to test a new application that was written in Python. The code will activate when new images are stored in an Amazon S3 bucket. The application will put a watermark on each image and then will store the images in a different S3 bucket.

Which AWS service should the company use to conduct the test with the LEAST amount of operational

overhead?

Options:

A.

Amazon EC2

B.

AWS CodeDeploy

C.

AWS Lambda

D.

Amazon Lightsail

Question 148

Which AWS service should a cloud engineer use to view API calls to AWS services?

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Config

D.

AWS Artifact

Question 149

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances. The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 150

A company wants to use a managed service to simplify the setup, operation, and scaling of its MySQL database in the AWS Cloud.

Which AWS service will meet these requirements?

Options:

A.

Amazon EMR

B.

Amazon RDS

C.

Amazon Redshift

D.

Amazon DynamoDB

Question 151

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO.)

Options:

A.

Availability

B.

Reliability

C.

Scalability

D.

Responsive design

E.

Operational excellence

Question 152

A company is reviewing its operating policies.

Which policy complies with guidance in the security pillar of the AWS Well-Architected Framework?

Options:

A.

Ensure that employees have access to all company data.

B.

Expand employees' permissions as they gain more experience.

C.

Grant all privileges and access to all users.

D.

Apply security requirements at all layers of a process.

Question 153

A company suspects that its AWS resources are being used for illegal activities.

Which AWS group or team should the company notify?

Options:

A.

AWS Abuse team

B.

AWS Support team

C.

AWS technical account managers

D.

AWS Professional Services team

Question 154

Which pillar of the AWS Well-Architected Framework includes a design principle about measuring the overall efficiency of workloads in terms of business value?

Options:

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Question 155

Which of the following acts as an instance-level firewall to control inbound and outbound access?

Options:

A.

Network access control list

B.

Security groups

C.

AWS Trusted Advisor

D.

Virtual private gateways

Question 156

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

Options:

A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Question 157

A company provides a software as a service (SaaS) application. The company has a new customer that is based in a different country.

The new customer's data needs to be hosted in that country.

Which AWS service or infrastructure component should the company use to meet this requirement?

Options:

A.

AWS Shield

B.

Amazon S3 Object Lock

C.

AWS Regions

D.

Placement groups

Question 158

What can a user accomplish using AWS CloudTrail?

Options:

A.

Generate an IAM user credentials report.

B.

Record API calls made to AWS services.

C.

Assess the compliance of AWS resource configurations with policies and guidelines.

D.

Ensure that Amazon EC2 instances are patched with the latest security updates.A company uses Amazon Workspaces.

Question 159

Which AWS service or feature can be used to estimate costs before deployment?

Options:

A.

AWS Free Tier

B.

AWS Pricing Calculator

C.

AWS Billing and Cost Management

D.

AWS Cost and Usage Report

Question 160

Which AWS service should a cloud practitioner use to receive real-time guidance for provisioning resources, based on AWS best practices related to security, cost optimization, and service limits?

Options:

A.

AWS Trusted Advisor

B.

AWS Config

C.

AWS Security Hub

D.

AWS Systems Manager

Question 161

A company needs to use dashboards and charts to analyze insights from business data.

Which AWS service will provide the dashboards and charts for these insights?

Options:

A.

Amazon Macie

B.

Amazon Aurora

C.

Amazon QuickSight

D.

AWS CloudTrail

Question 162

A company is running applications on Amazon EC2 instances in the same AWS account for several different projects. The company wants to track the infrastructure costs for each of the projects separately. The company must conduct this tracking with the least possible impact to the existing infrastructure and with no additional cost.

What should the company do to meet these requirements?

Options:

A.

Use a different EC2 instance type for each project.

B.

Publish project-specific custom Amazon CloudWatch metrics for each application.

C.

Deploy EC2 instances for each project in a separate AWS account.

D.

Use cost allocation tags with values that are specific to each project.

Question 163

A company is running an order processing system on Amazon EC2 instances. The company wants to migrate microservices-based application.

Which combination of AWS services can the application use to meet these requirements? (Select TWO.)

Options:

A.

Amazon Simple Queue Service (Amazon SQS)

B.

AWS Lambda

C.

AWS Migration Hub

D.

AWS AppSync

E.

AWS Application Migration Service

Question 164

Which AWS service can report how AWS resource configurations have changed over time?

Options:

A.

AWS CloudTrail

B.

Amazon CloudWatch

C.

AWS Config

D.

Amazon Inspector

Question 165

Which AWS service or feature is used to send both text and email messages from distributed applications?

Options:

A.

Amazon Simple Notification Service (Amazon SNS)

B.

Amazon Simple Email Service (Amazon SES)

C.

Amazon CloudWatch alerts

D.

Amazon Simple Queue Service (Amazon SQS)

Question 166

A company is hosting a web application in a Docker container on Amazon EC2.

AWS is responsible for which of the following tasks?

Options:

A.

Scaling the web application and services developed with Docker

B.

Provisioning or scheduling containers to run on clusters and maintain their availability

C.

Performing hardware maintenance in the AWS facilities that run the AWS Cloud

D.

Managing the guest operating system, including updates and security patches

Question 167

Which AWS Support plan provides customers with access to an AWS technical account manager (TAM)?

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Question 168

A company is migrating an application that includes an Oracle database to AWS. The company cannot rewrite the application.

To which AWS service could the company migrate the database?

Options:

A.

Amazon Athena

B.

Amazon DynamoDB®C. Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

Question 169

Who is responsible for decommissioning end-of-life underlying storage devices that are used to host data on AWS?

Options:

A.

Customer

B.

AWS

C.

Account creator

D.

Auditing team

Question 170

A company needs help managing multiple AWS linked accounts that are reported on a consolidated bill.

Which AWS Support plan includes an AWS concierge whom the company can ask for assistance?

Options:

A.

AWS Developer Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Basic Support

Question 171

Which AWS service gives users the ability to provision a dedicated and private network connection from their internal

network to AWS?

Options:

A.

AWS CloudHSM

B.

AWS Direct Connect

C.

AWS VPN

D.

Amazon Connect

Question 172

Which options are common stakeholders for the AWS Cloud Adoption Framework (AWS CAF) platform perspective? (Select TWO.)

Options:

A.

Chief financial officers (CFOs)

B.

IT architects

C.

Chief information officers (CIOs)

D.

Chief data officers (CDOs)

E.

Engineers

Question 173

A company wants to migrate its applications to the AWS Cloud. The company plans to identify and prioritize any business transformation opportunities and evaluate its AWS Cloud readiness.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

AWS Cloud Adoption Framework (AWS CAF)

B.

AWS Managed Services (AMS)

C.

AWS Well-Architected Framework

D.

AWS Migration Hub

Question 174

Which design principle should be considered when architecting in the AWS Cloud?

Options:

A.

Think of servers as non-disposable resources.

B.

Use synchronous integration of services.

C.

Design loosely coupled components.

D.

Implement the least permissive rules for security groups.

Question 175

A company wants to manage access and permissions for its third-party software as a service (SaaS)

applications. The company wants to use a portal where end users can access assigned AWS accounts and AWS Cloud applications.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Cognito

B.

AWS IAM Identity Center (AWS Single Sign-On)

C.

AWS Identity and Access Management (IAM)

D.

AWS Directory Service for Microsoft Active Directory

Question 176

A company is building an application that will receive millions of database queries each second. The company needs the data store for the application to scale to meet these needs.

Which AWS service will meet this requirement?

Options:

A.

Amazon DynamoDB

B.

AWS Cloud9

C.

Amazon ElastiCache for Memcached

D.

Amazon Neptune

Question 177

A retail company is migrating its IT infrastructure applications from on premises to the AWS Cloud.

Which costs will the company eliminate with this migration? (Select TWO.)

Options:

A.

Cost of data center operations

B.

Cost of application licensing

C.

Cost of marketing campaigns

D.

Cost of physical server hardware

E.

Cost of network management

Question 178

A company wants to host its relational databases on AWS. The databases have predefined schemas that the company needs to replicate on AWS.

Which AWS services could the company use for the databases? (Select TWO.)

Options:

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

E.

Amazon DynamoDB

Question 179

A company wants its Amazon EC2 instances to share the same geographic area but use redundant underlying power sources.

Which solution will meet these requirements?

Options:

A.

Use EC2 instances across multiple Availability Zones in the same AWS Region.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in AWS OpsWorks stacks in different AWS Regions.

Question 180

A company wants its workload to perform consistently and correctly.

Which benefit of AWS Cloud computing does this goal represent?

Options:

A.

Security

B.

Elasticity

C.

Pay-as-you-go pricing

D.

Reliability

Question 181

A company needs to launch an Amazon EC2 instance.

Which of the following can the company use during the launch process to configure the root volume of the EC2 instance?

Options:

A.

Amazon EC2 Auto Scaling

B.

Amazon Data Lifecycle Manager (Amazon DLM)

C.

Amazon Machine Image (AMI)

D.

Amazon Elastic Block Store (Amazon EBS) volume

Question 182

Which tasks are customer responsibilities according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Determine application dependencies with operating systems.

B.

Provide user access with AWS Identity and Access Management (IAM).

C.

Secure the data center in an Availability Zone.

D.

Patch the hypervisor.

E.

Provide network availability in Availability Zones.

Question 183

A company wants to centrally manage security policies and billing services within a multi-account AWS environment. Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Resource Access Manager (AWS RAM)

D.

AWS Config

Question 184

A company that is planning to migrate to the AWS Cloud is based in an isolated area that has limited internet connectivity. The company needs to perform local data processing on premises. The company needs a solution that can operate without a stable internet connection.

Which AWS service will meet these requirements?

Options:

A.

Amazon S3

B.

AWS Snowball Edge

C.

AWS StorageGateway

D.

AWS Backup

Question 185

company wants to protect its AWS Cloud information, systems, and assets while performing risk assessment and mitigation tasks.

Which pillar of the AWS Well-Architected Framework is supported by these goals?

Options:

A.

Reliability

B.

Security

C.

Operational excellence

D.

Performance efficiency

Question 186

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

Options:

A.

Set up multi-factor authentication (MFA) for each Workspaces user account.

B.

Ensure the environmental safety and security of the AWS infrastructure that hosts Workspaces.

C.

Provide security for Workspaces user accounts through AWS Identity and Access Management(IAM).

D.

Configure AWS CloudTrail to log API calls and user activity.A company stores data in an Amazon S3 bucket. The company must control who has permission to read, write,or delete objects that the company stores in the S3 bucket.

Question 187

A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account.

Which AWS service or resource should the company use to meet this requirement?

Options:

A.

AWS Security Hub

B.

AWS Marketplace

C.

AWS Quick Starts

D.

AWS Security Center

Question 188

Which AWS service or feature can a company use to create a private, secured, and scalable network environment in the AWS Cloud?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon S3

C.

Amazon VPC

D.

Route tables

Question 189

A company needs access to checks and recommendations that help the company follow AWS best practices for cost optimization, security, fault tolerance, performance, and service quotas.

Which combination of an AWS service and AWS Support plan on the AWS account will meet these requirements?

Options:

A.

AWS Trusted Advisor with AWS Developer Support

B.

AWS Health Dashboard with AWS Enterprise Support

C.

AWS Trusted Advisor with AWS Business Support

D.

AWS Health Dashboard with AWS Enterprise On-Ramp Support

Question 190

Which design principles are included in the reliability pillar of the AWS Well-Architected Framework? (Select TWO.)

Options:

A.

Automatically recover from failure.

B.

Grant everyone access to increase AWS service quotas.

C.

Stop guessing capacity.

D.

Design applications to run in a single Availability Zone.

E.

Plan to increase AWS service quotas first in a secondary AWS Region.

Question 191

A company uploads audio and video files to a centralized Amazon S3 bucket from different geographic locations. Which AWS solution will optimize transfer speeds for these files?

Options:

A.

AWS Global Accelerator

B.

S3 Transfer Acceleration

C.

AWS Direct Connect

D.

Amazon CloudFront

Question 192

A company needs to store infrequently used data for data archives and long-term backups.

Which AWS service or storage class will meet these requirements MOST cost-effectively?

Options:

A.

Amazon FSx for Lustre

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3 Glacier Flexible Retrieval

Question 193

A company wants to use AWS. The company has stringent requirements about low-latency access to on-premises systems and data residency.

Which AWS service should the company use to design a solution that meets these requirements?

Options:

A.

AWS Wavelength

B.

AWS Transit Gateway

C.

AWS Ground Station

D.

AWS Outposts

Question 194

Which AWS service or resource can a company use to deploy AWS WAF rules?

Options:

A.

Amazon EC2

B.

Application Load Balancer

C.

AWS Trusted Advisor

D.

Network Load Balancer

Question 195

Which AWS service can create a private network connection from on premises to the AWS Cloud?

Options:

A.

AWS Config

B.

Virtual Private Cloud (Amazon VPC)

C.

AWS Direct Connect

D.

Amazon Route 53

Question 196

A company has a client that uses an Amazon RDS database. The client requests Information about operating system-level upgrades on the AWS resources that host the RDS database. The company employs a third-party provider to monitor the RDS database.

Who is responsible for upgrading the operating systems for Amazon RDS under the AWS shared responsibility model?

Options:

A.

The client

B.

The company

C.

AWS

D.

The third-party provider

Question 197

Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?

Options:

A.

AWS CloudFormation

B.

AWS CodeDeploy

C.

AWS CodeBuild

D.

AWS Systems Manager

Question 198

A company is building a business intelligence solution that uses Amazon Redshift. The company wants to use an AWS service to create interactive dashboards and not pay any upfront costs for it.

Which service should the company use?

Options:

A.

Amazon CloudWatch

B.

AWS Health Dashboard

C.

AWS Service Catalog

D.

Amazon QuickSight

Question 199

A company is building AWS architecture to deliver real-time data feeds from an on-premises data center into an application that runs on AWS. The company needs a consistent network connection with minimal latency.

What should the company use to connect the application and the data center to meet these requirements?

Options:

A.

AWS Direct Connect

B.

Public internet

C.

AWS VPN

D.

Amazon Connect

Question 200

Which AWS service gives users on-demand, sell-service access to AWS compliance control reports?

Options:

A.

AWS Config

B.

Amazon GuardDuty

C.

AWS Trusted Advisor

D.

AWS Artifact

Question 201

A company wants to securely rehost databases to AWS with minimal downtime. Which AWS service will meet these requirements?

Options:

A.

AWS Database Migration Service (AWS DMS)

B.

AWS Snow Family

C.

AWSDataSync

D.

AWS Mainframe Modernization

Question 202

What is the total volume of data that can be stored in Amazon S3?

Options:

A.

10 PB

B.

50 PB

C.

100 PB

D.

Virtually unlimited

Question 203

A user wants to invoke an AWS Lambda function when an Amazon EC2 instance enters the "stopping" state.

Which AWS service is appropriate for this use case?

Options:

A.

Amazon EventBridge

B.

AWS Config

C.

Amazon Simple Notification Service (Amazon SNS)

D.

AWS CloudFormation

Question 204

A company plans to migrate to the AWS Cloud. The company wants to gather information about its on-premises data center.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Application Discovery Service

B.

AWS DataSync

C.

AWS Storage Gateway

D.

AWS Database Migration Service (AWS DMS)

Question 205

Which AWS services are serverless? (Select TWO.)

Options:

A.

AWS Fargate

B.

Amazon Managed Streaming for Apache Kafka

C.

Amazon EMR

D.

Amazon S3

E.

Amazon EC2

Question 206

A company wants to test a new application.

Which AWS principle will help the company test the application?

Options:

A.

Make long-term commitments in exchange for a cost discount.

B.

Scale up and down when needed without any long-term commitments.

C.

Have total control over the application infrastructure.

D.

Manage all of the maintenance tasks associated with the cloud.

Question 207

A company wants to control the protection of its AWS resources. The company wants to block SQL injection attacks and cross-site scripting.

Which AWS service or feature meets these requirements?

Options:

A.

Amazon GuardDuty

B.

AWSWAF

C.

Security groups

D.

AWS Shield

Question 208

A company wants to transport 100 TB of data from its data center to AWS without using internet.

Which AWS service will meet this requirement?

Options:

A.

AWS Snowcone

B.

AWS Snowball Edge

C.

AWS Data Exchange

D.

AWS DataSync

Question 209

A company needs to reserve a certain amount of Amazon EC2 compute resources in a specific Availability Zone within an AWS Region. Which purchasing option should the company use to meet this requirement?

Options:

A.

EC2 Instance Savings Plans

B.

Compute Savings Plans

C.

Regional Reserved Instances

D.

Zonal Reserved Instances

Question 210

Where can users find examples of AWS Cloud solution designs?

Options:

A.

AWS Marketplace

B.

AWS Service Catalog

C.

AWS Architecture Center

D.

AWS Trusted Advisor

Question 211

A company needs to block SOL injection attacks.

Which AWS service or feature provides this functionality?

Options:

A.

AWS WAF

B.

Network ACLs

C.

Security groups

D.

AWS Trusted Advisor

Question 212

A company wants to avoid unnecessary charges and run workloads at the lowest price point. Which pillar of the AWS Well-Architected Framework includes these goals?

Options:

A.

Security

B.

Reliability

C.

Sustainability

D.

Cost optimization

Question 213

Which AWS service or tool inspects a user's AWS environment and makes recommendations for cost savings and system performance improvements?

Options:

A.

Cost Explorer

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS Budgets

Question 214

A company is building a web application using AWS.

Which AWS service will help prevent network layer DDoS attacks against the web application?

Options:

A.

AWS WAF

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

AWS Shield

Question 215

A company wants to provide one of its employees with access to Amazon RDS. The company also wants to limit the interaction to only the AWS CLl and AWS software development kits (SDKs).

Which combination of actions should the company take to meet these requirements while following the principles of least privilege? (Select TWO)

Options:

A.

Create an 1AM user and provide AWS Management Console access only.

B.

Create an 1AM user and provide programmatic access only.

C.

Create an 1AM role and provide AWS Management Console access only.

D.

Create an 1AM policy with administrator access and attach it to the 1AM user.

E.

Create an 1AM policy with Amazon RDS access and attach it to the 1AM user.

Question 216

Which AWS service or resource can provide discounts on some AWS service costs in exchange for a spending commitment?

Options:

A.

Amazon Detective

B.

AWS Pricing

C.

Savings Plans

D.

Basic Support

Question 217

Which AWS service provides storage-optimized and compute-optimized device configurations?

Options:

A.

AWS Snowcone

B.

AWS Storage Gateway

C.

AWS Snowball Edge

D.

AWS DataSync

Question 218

A company needs to create a portfolio that provides central management of approved IT services. Which AWS service offers this functionality?

Options:

A.

AWS Service Catalog

B.

AWS Control Tower

C.

AWS Cloud Map

D.

AWS Clean Rooms

Question 219

Which design principle is related to the reliability pillar according to the AWS Well-Architected Framework?

Options:

A.

Test recovery procedures

B.

Experiment more often

C.

Go global in minutes

D.

Analyze and attribute to expenditure

Question 220

A company needs a hybrid cloud storage service to connect its on-premises environment to scalable AWS Cloud storage. Which AWS service will meet these requirements?

Options:

A.

Amazon S3

B.

Amazon FSx

C.

AWS Storage Gateway

D.

AWS Fargate

Question 221

A company needs to manage multiple logins across AWS accounts within the same organization in AWS Organizations.

Which AWS service should the company use to meet this requirement?

Options:

A.

Amazon VPC

B.

Amazon GuardDuty

C.

Amazon Cognito

D.

AWS IAM Identity Center

Question 222

A company is moving some of its on-premises IT services to the AWS Cloud. The finance department wants to see the entire bill so it can forecast spending limits.

Which AWS service can the company use to set spending limits and receive notifications if those limits are exceeded?

Options:

A.

AWS Cost and Usage Reports

B.

AWS Budgets

C.

AWS Organizations consolidated billing

D.

Cost Explorer

Question 223

Which AWS service or tool can a company use to set up consolidated billing?

Options:

A.

AWS Billing and Cost Management console

B.

AWS Organizations

C.

AWS Cost and Usage Report

D.

AWS Systems Manager

Question 224

A company needs to request temporary, limited-privilege credentials for IAM users and for the federated users that the company authenticates.

Which AWS service will provide these credentials?

Options:

A.

Amazon GuardDuty

B.

AWS Key Management Service (AWS KMS)

C.

AWS Security Token Service (AWS STS)

D.

AWS Identity and Access Management Access Analyzer

Question 225

A company's workload can recover with minimal downtime when failures occur. Which AWS Cloud benefit does this scenario represent?

Options:

A.

Agility

B.

Elasticity

C.

Resiliency

D.

Scalability

Question 226

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance state changes to RUNNING.

Which AWS service can the company use to meet this requirement?

Options:

A.

Amazon SageMaker

B.

Amazon Connect

C.

Amazon EventBridge

D.

AWS Fargate

Question 227

Which AWS service provides machine learning capability to detect and analyze content in images and videos?

Options:

A.

Amazon Connect

B.

Amazon Lightsail

C.

Amazon Personalize

D.

Amazon Rekognition

Question 228

A company wants to securely access an Amazon S3 bucket from an Amazon EC2 instance without accessing the internet.

What should the company use to accomplish this goal?

Options:

A.

VPN connection

B.

Internet gateway

C.

VPC endpoint

D.

NAT gateway

Question 229

Which AWS service or feature should a company use between two microservices to ensure that messages are sent and received in exact order?

Options:

A.

Amazon Simple Email Service (Amazon SES)

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon S3 Event Notifications

D.

Amazon Simple Queue Service (Amazon SQS) FIFO queues

Question 230

What is a benefit of using an Elastic Load Balancing (ELB) load balancer with applications running in the AWS Cloud?

Options:

A.

An ELB will automatically scale resources to meet capacity needs.

B.

An ELB can balance traffic across multiple compute resources.

C.

An ELB can span multiple AWS Regions.

D.

An ELB can balance traffic between multiple internet gateways.

Question 231

Which AWS service can a company use to directly query and analyze AWS Cost and Usage Reports?

Options:

A.

Amazon OpenSearch Service

B.

Amazon Athena

C.

Amazon Aurora

D.

AWS Glue

Question 232

A company's IT administrator needs to configure the AWS CLI for programmatic access to AWS services for the company's employees. Which combination of credential components must the IT administrator use to meet this requirement? (Select TWO.)

Options:

A.

A public key

B.

A secret access key

C.

An IAM role

D.

An access key ID

E.

A private key

Question 233

A company uses AWS and has a VPC that includes two public subnets. The company needs to allow and deny specific inbound and outbound traffic for each public subnet.

Which AWS service or tool can the company use to meet this requirement?

Options:

A.

Network ACL

B.

AWSWAF

C.

VPC route table entry

D.

Security group

Question 234

A company needs to mount a file share across multiple Amazon EC2 instances as a mapped drive by using the SMB protocol. Which AWS service will meet these requirements?

Options:

A.

Amazon FSx for Windows File Server

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon S3

D.

AWS DataSync

Question 235

Which AWS service uses edge locations to cache content?

Options:

A.

Amazon Kinesis

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon CloudFront

D.

Amazon Route 53

Question 236

A company has a MariaDB database on premises. The company wants to move the data to the AWS Cloud. Which AWS service will host this database with the LEAST amount of operational overhead?

Options:

A.

Amazon RDS

B.

Amazon Neptune

C.

Amazon S3

D.

Amazon DynamoDB

Question 237

A company is running a key-value NoSQL workload on Amazon EC2 instances. The company needs the workload to have scalability, failover protection, and backup capabilities.

What is the MOST operationally efficient way to meet these requirements?

Options:

A.

Add additional EC2 instances to the database cluster.

B.

Run an identical copy of the database in a second Availability Zone.

C.

Migrate the database to Amazon DynamoDB.

D.

Migrate the database to a relational database.

Question 238

Which action should a company take to improve security in its AWS account?

Options:

A.

Require multi-factor authentication (MFA) for privileged users.

B.

Remove the root user account.

C.

Create an access key for the AWS account root user.

D.

Create an access key for each privileged user.

Question 239

A company wants to automatically run operating system command scripts on Amazon EC2 instances. Which AWS service will meet these requirements in the MOST operationally efficient way?

Options:

A.

AWS Organizations

B.

AWS Control Tower

C.

AWS Lambda

D.

AWS Systems Manager

Question 240

A company purchased Amazon EC2 Standard Reserved Instances (Rls) for a workload in the AWS Cloud. The company needs to move part of the workload to an instance family that does not match the instance family of these Standard RIs.

How can the company take advantage of the Standard RIs that it no longer needs?

Options:

A.

Contact the AWS Support team, and ask the team to sell the Standard RIs.

B.

Sell the Standard RIs on the Amazon EC2 Reserved Instance Marketplace.

C.

Sell the Standard RIs as a third-party seller on the AWS Marketplace.

D.

Convert the Standard RIs to Savings Plans.

Question 241

A user wants to review all Amazon S3 buckets with ACLs and S3 bucket policies in the S3 console. Which AWS service or resource will meet this requirement?

Options:

A.

S3 Multi-Region Access Points

B.

S3 Storage Lens

C.

AWS IAM Identity Center

D.

Access Analyzer for S3

Question 242

Which AWS service or tool provides users with a graphical interface that they can use to manage AWS services?

Options:

A.

AWS Copilot

B.

AWS CLI

C.

AWS Management Console

D.

AWS software development kits (SDKs)

Question 243

A company is planning to migrate a monolithic application to AWS. The company wants to modernize the application by splitting it into microservices. The company will deploy the microservices on AWS.

Which migration strategy should the company use?

Options:

A.

Rehost

B.

Repurchase

C.

Replatform

D.

Refactor

Question 244

A company is releasing a business-critical application. Before the release, the company needs strategic planning assistance from AWS. During the release, the company needs AWS infrastructure event management and real-time support.

What should the company do to meet these requirement?

Options:

A.

Access AWS Trusted Advisor.

B.

Contact the AWS Partner Network (APN).

C.

Sign up for AWS Enterprise Support.

D.

Contact AWS Professional Services.

Question 245

Which AWS service provides on-premises applications with low-latency access to data that is stored in the AWS Cloud?

Options:

A.

Amazon CloudFront

B.

AWS Storage Gateway

C.

AWS Backup

D.

AWS DataSync

Question 246

A company wants a report that lists the status of multi-factor authentication (MFA) devices that all users in the company's AWS account use.

Which AWS feature or service will meet this requirement?

Options:

A.

AWS Cost and Usage Reports

B.

IAM credential reports

C.

Detailed Billing Reports

D.

AWS Cost Explorer reports

Page: 1 / 82
Total 820 questions