Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Amazon Web Services > AWS Certified Foundational > CLF-C02

CLF-C02 AWS Certified Cloud Practitioner Question and Answers

Question # 4

Which AWS service or tool gives a company the ability to release application changes in an automated way?

A.

Amazon AppFlow

B.

AWS CodeDeploy

C.

AWS PrivateLink

D.

Amazon EKS Distro

Full Access
Question # 5

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO)

A.

High availability

B.

Performance efficiency

C.

Cost optimization

D.

Going global in minutes

E.

Continuous development

Full Access
Question # 6

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on organizing an inventory of data products in a data catalog?

A.

Operations

B.

Governance

C.

Business

D.

Platform

Full Access
Question # 7

Which AWS service is used to provide encryption for Amazon EBS?

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS KMS

D.

AWS Config

Full Access
Question # 8

Which AWS service provides a scalable data warehouse solution?

A.

Amazon S3

B.

Amazon DynamoDB

C.

Amazon Kinesis Data Streams

D.

Amazon Redshift

Full Access
Question # 9

A company wants to test a new application.

Which AWS principle will help the company test the application?

A.

Make long-term commitments in exchange for a cost discount.

B.

Scale up and down when needed without any long-term commitments.

C.

Have total control over the application infrastructure.

D.

Manage all of the maintenance tasks associated with the cloud.

Full Access
Question # 10

A company plans to migrate its custom marketing application and order-processing application to AWS. The company needs to deploy the applications on different types of instances with various configurations of CPU, memory, storage, and networking capacity.

Which AWS service should the company use to meet these requirements?

A.

AWS Lambda

B.

Amazon Cognito

C.

Amazon Athena

D.

Amazon EC2

Full Access
Question # 11

A team of researchers is going to collect data at remote locations around the world Many locations do not have internet connectivity. The team needs to capture the data in the field, and transfer it to the AWS Cloud later

Which AWS service will support these requirements?

A.

AWS Outposts

B.

AWS Transfer Family

C.

AWS Snow Family

D.

AWS Migration Hub

Full Access
Question # 12

A company wants to provide managed Windows virtual desktops and applications to its remote employees over secure network connections. Which AWS services can the company use to meet these requirements? (Select TWO.)

A.

Amazon Connect

B.

Amazon AppStream 2.0

C.

Amazon Workspaces

D.

AWS Site-to-Site VPN

E.

Amazon Elastic Container Service (Amazon ECS)

Full Access
Question # 13

Which AWS service or feature allows users to create new AWS accounts, group multiple accounts to organize workflows, and apply policies to groups of accounts?

A.

AWS Identity and Access Management (1AM)

B.

AWS Trusted Advisor

C.

AWS CloudFormation

D.

AWS Organizations

Full Access
Question # 14

A company needs to search for text in documents that are stored in Amazon S3.

Which AWS service will meet these requirements?

A.

Amazon Kendra

B.

Amazon Rekognition

C.

Amazon Polly

D.

Amazon Lex

Full Access
Question # 15

Which AWS service gives companies the ability to create graph applications that can analyze billions of relationships between data points in milliseconds?

A.

Amazon Redshift

B.

Amazon Neptune

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon ElastiCache

Full Access
Question # 16

A company needs stateless network filtering for its VPC.

Which AWS service, tool, or feature will meet this requirement?

A.

AWS PrivateLink

B.

Security group

C.

Network access control list (ACL)

D.

AWS WAF

Full Access
Question # 17

A company migrated its systems to the AWS Cloud. The systems are rightsized, and a security review did not reveal any issues. The company must ensure that additional developments, integrations, changes, and system usage growth do not jeopardize this optimized AWS infrastructure.

Which AWS service should the company use to report ongoing optimization and security?

A.

AWS Trusted Advisor

B.

AWS Health Dashboard

C.

Amazon Connect

D.

AWS Systems Manager

Full Access
Question # 18

Which benefits does a company gain when the company moves from on-premises IT architecture to the AWS Cloud? (Select TWO.)

A.

Reduced or eliminated tasks for hardware troubleshooting, capacity planning, and procurement

B.

Elimination of the need for trained IT staff

C.

Automatic security configuration of all applications that are migrated to the cloud

D.

Elimination of the need for disaster recovery planning

E.

Faster deployment of new features and applications

Full Access
Question # 19

Which AWS Cloud benefit gives a company the ability to quickly deploy cloud resources to access compute, storage, and database infrastructures in a matter of minutes?

A.

Elasticity

B.

Cost savings

C.

Agility

D.

Reliability

Full Access
Question # 20

A company is planning to migrate a monolithic application to AWS. The company wants to modernize the application by splitting it into microservices. The company will deploy the microservices on AWS.

Which migration strategy should the company use?

A.

Rehost

B.

Repurchase

C.

Replatform

D.

Refactor

Full Access
Question # 21

Which task is the responsibility of the customer, according to the AWS shared responsibility model?

A.

Patch the Amazon DynamoDB operating system.

B.

Secure Amazon CloudFront edge locations by allowing physical access according to the principle of least privilege.

C.

Protect the hardware that runs AWS services.

D.

Use AWS Identity and Access Management (1AM) according to the principle of least privilege.

Full Access
Question # 22

A company has deployed an Amazon EC2 instance.

Which option is an AWS responsibility under the AWS shared responsibility model?

A.

Managing and encrypting application data

B.

Installing updates and security patches of guest operating system

C.

Configuration of infrastructure devices

D.

Configuration of security groups on each instance

Full Access
Question # 23

Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?

A.

AWS CloudFormation

B.

AWS CodeDeploy

C.

AWS CodeBuild

D.

AWS Systems Manager

Full Access
Question # 24

A company wants to control the protection of its AWS resources. The company wants to block SQL injection attacks and cross-site scripting.

Which AWS service or feature meets these requirements?

A.

Amazon GuardDuty

B.

AWSWAF

C.

Security groups

D.

AWS Shield

Full Access
Question # 25

A company wants to visualize and manage AWS Cloud costs and usage for a specific period of time.

Which AWS service or feature will meet these requirements?

A.

Cost Explorer

B.

Consolidated billing

C.

AWS Organizations

D.

AWS Budgets

Full Access
Question # 26

A user wants to review all Amazon S3 buckets with ACLs and S3 bucket policies in the S3 console. Which AWS service or resource will meet this requirement?

A.

S3 Multi-Region Access Points

B.

S3 Storage Lens

C.

AWS IAM Identity Center

D.

Access Analyzer for S3

Full Access
Question # 27

An ecommerce company wants to design a highly available application that will be hosted on multiple Amazon EC2 instances.

How should the company deploy the EC2 instances to meet these requirements?

A.

Across multiple edge locations

B.

Across multiple VPCs

C.

Across multiple Availability Zones

D.

Across multiple AWS accounts

Full Access
Question # 28

A company's application is running on Amazon EC2 instances. The company is planning a partial migration to a serverless architecture in the next year and wants to pay for resources up front.

Which AWS purchasing option will optimize the company's costs?

A.

Convertible Reserved Instances

B.

Spot Instances

C.

EC2 Instance Savings Plans

D.

Compute Savings Plan

Full Access
Question # 29

Which design principle is related to the reliability pillar according to the AWS Well-Architected Framework?

A.

Test recovery procedures

B.

Experiment more often

C.

Go global in minutes

D.

Analyze and attribute to expenditure

Full Access
Question # 30

A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account.

Which AWS service or resource should the company use to meet this requirement?

A.

AWS Security Hub

B.

AWS Marketplace

C.

AWS Quick Starts

D.

AWS Security Center

Full Access
Question # 31

Which pillar of the AWS Well-Architected Framework focuses on the ability to run workloads effectively, gain insight into operations, and continuously improve supporting processes and procedures?

A.

Cost optimization

B.

Reliability

C.

Operational excellence

D.

Performance efficiency

Full Access
Question # 32

Which option is a shared responsibility between AWS and its customers under the AWS shared responsibility model?

A.

Configuration of Amazon EC2 instance operating systems

B.

Application file system server-side encryption

C.

Patch management

D.

Security of the physical infrastructure

Full Access
Question # 33

Which options are benefits of using third-party software from AWS Marketplace? (Select TWO.)

A.

The software's data encryption is managed by a third-party vendor.

B.

The software has been evaluated by vendors to ensure that it will run on AWS.

C.

Users do not need to upgrade to newer software versions.

D.

Users do not need to conduct security testing on the software.

E.

Users can launch preconfigured software in only a few steps.

Full Access
Question # 34

Which AWS Cloud service can send alerts to customers if custom spending thresholds are exceeded?

A.

AWS Budgets

B.

AWS Cost Explorer

C.

AWS Cost Allocation Tags

D.

AWS Organizations

Full Access
Question # 35

A company is building AWS architecture to deliver real-time data feeds from an on-premises data center into an application that runs on AWS. The company needs a consistent network connection with minimal latency.

What should the company use to connect the application and the data center to meet these requirements?

A.

AWS Direct Connect

B.

Public internet

C.

AWS VPN

D.

Amazon Connect

Full Access
Question # 36

Which Amazon S3 storage class is the MOST cost-effective for long-term storage?

A.

S3 Glacier Deep Archive

B.

S3 Standard

C.

S3 Standard-Infrequent Access (S3 Standard-IA)

D.

S3 One Zone-Infrequent Access (S3 One Zone-IA)

Full Access
Question # 37

Which of the following AWS services are serverless? (Select TWO.)

A.

AWS Outposts

B.

Amazon EC2

C.

Amazon Elastic Kubernetes Service (Amazon EKS)

D.

AWS Fargate

E.

AWS Lambda

Full Access
Question # 38

Which AWS tool or feature acts as a VPC firewall at the subnet level?

A.

Security group

B.

Network ACL

C.

Traffic Mirroring

D.

Internet gateway

Full Access
Question # 39

Which action should a company take to improve security in its AWS account?

A.

Require multi-factor authentication (MFA) for privileged users.

B.

Remove the root user account.

C.

Create an access key for the AWS account root user.

D.

Create an access key for each privileged user.

Full Access
Question # 40

A company's IT administrator needs to configure the AWS CLI for programmatic access to AWS services for the company's employees. Which combination of credential components must the IT administrator use to meet this requirement? (Select TWO.)

A.

A public key

B.

A secret access key

C.

An IAM role

D.

An access key ID

E.

A private key

Full Access
Question # 41

A company is moving some of its on-premises IT services to the AWS Cloud. The finance department wants to see the entire bill so it can forecast spending limits.

Which AWS service can the company use to set spending limits and receive notifications if those limits are exceeded?

A.

AWS Cost and Usage Reports

B.

AWS Budgets

C.

AWS Organizations consolidated billing

D.

Cost Explorer

Full Access
Question # 42

An ecommerce company plans to move its data center workload to the AWS Cloud to support highly dynamic usage patterns. Which benefits make the AWS Cloud cost-effective for the migration of this type of workload? (Select TWO.)

A.

Reliability

B.

Security

C.

Elasticity

D.

Pay-as-you-go resource pricing

E.

High availability

Full Access
Question # 43

A company purchased Amazon EC2 Standard Reserved Instances (Rls) for a workload in the AWS Cloud. The company needs to move part of the workload to an instance family that does not match the instance family of these Standard RIs.

How can the company take advantage of the Standard RIs that it no longer needs?

A.

Contact the AWS Support team, and ask the team to sell the Standard RIs.

B.

Sell the Standard RIs on the Amazon EC2 Reserved Instance Marketplace.

C.

Sell the Standard RIs as a third-party seller on the AWS Marketplace.

D.

Convert the Standard RIs to Savings Plans.

Full Access
Question # 44

Which AWS service or feature can be used to create a private connection between an on-premises workload and an AWS Cloud workload?

A.

Amazon Route 53

B.

Amazon Macie

C.

AWS Direct Connect

D.

AWS PrivaleLink

Full Access
Question # 45

A company is moving Us development and test environments to AWS to increase agility and reduce cost. Because these are not production workloads and the servers are not fully utilized, occasional unavailability is acceptable.

What is the MOST cost-effective Amazon EC2 pricing model that will meet these requirements?

A.

Reserved instances

B.

On-Demand Instances

C.

Spot Instances

D.

Dedicated Hosts

Full Access
Question # 46

Which AWS Support plans provide access to an AWS technical account manager (TAM)? (Select)

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise On-Ramp Support

E.

AWS Enterprise Support

Full Access
Question # 47

A company is building a business intelligence solution that uses Amazon Redshift. The company wants to use an AWS service to create interactive dashboards and not pay any upfront costs for it.

Which service should the company use?

A.

Amazon CloudWatch

B.

AWS Health Dashboard

C.

AWS Service Catalog

D.

Amazon QuickSight

Full Access
Question # 48

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance state changes to RUNNING.

Which AWS service can the company use to meet this requirement?

A.

Amazon SageMaker

B.

Amazon Connect

C.

Amazon EventBridge

D.

AWS Fargate

Full Access
Question # 49

A company has a client that uses an Amazon RDS database. The client requests Information about operating system-level upgrades on the AWS resources that host the RDS database. The company employs a third-party provider to monitor the RDS database.

Who is responsible for upgrading the operating systems for Amazon RDS under the AWS shared responsibility model?

A.

The client

B.

The company

C.

AWS

D.

The third-party provider

Full Access
Question # 50

Which AWS services can host PostgreSQL databases? (Select TWO.)

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

Amazon OpenSearch Service

E.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 51

Which design principle aligns with performance efficiency pillar of the AWS Well-Architected Framework?

A.

Using serverless architectures

B.

Scaling horizontally

C.

Measuring the cost of workloads

D.

Using managed services

Full Access
Question # 52

Which AWS service helps users plan and track their server and application inventory migration data to AWS?

A.

Amazon CloudWatch

B.

AWS DataSync

C.

AWS Migration Hub

D.

AWS Application Migration Service

Full Access
Question # 53

A company is releasing a business-critical application. Before the release, the company needs strategic planning assistance from AWS. During the release, the company needs AWS infrastructure event management and real-time support.

What should the company do to meet these requirement?

A.

Access AWS Trusted Advisor.

B.

Contact the AWS Partner Network (APN).

C.

Sign up for AWS Enterprise Support.

D.

Contact AWS Professional Services.

Full Access
Question # 54

Which AWS service supports the deployment and management of applications in the AWS Cloud?

A.

Amazon CodeGuru

B.

AWS Fargate

C.

AWS CodeCommit

D.

AWS Elastic Beanstalk

Full Access
Question # 55

Which AWS service uses edge locations to cache content?

A.

Amazon Kinesis

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon CloudFront

D.

Amazon Route 53

Full Access
Question # 56

A company needs to manage multiple logins across AWS accounts within the same organization in AWS Organizations.

Which AWS service should the company use to meet this requirement?

A.

Amazon VPC

B.

Amazon GuardDuty

C.

Amazon Cognito

D.

AWS IAM Identity Center

Full Access
Question # 57

A company is preparing for an audit and wants documentation that AWS complies with the Payment Card Industry Data Security Standard (PCI DSS).

Where can the company find this documentation?

A.

AWS Artifact

B.

AWS Organizations

C.

AWS Trusted Advisor

D.

AWS Support Center

Full Access
Question # 58

Which AWS services are serverless? (Select TWO.)

A.

AWS Fargate

B.

Amazon Managed Streaming for Apache Kafka

C.

Amazon EMR

D.

Amazon S3

E.

Amazon EC2

Full Access
Question # 59

Where can users find examples of AWS Cloud solution designs?

A.

AWS Marketplace

B.

AWS Service Catalog

C.

AWS Architecture Center

D.

AWS Trusted Advisor

Full Access
Question # 60

Which AWS service or tool can a company use to set up consolidated billing?

A.

AWS Billing and Cost Management console

B.

AWS Organizations

C.

AWS Cost and Usage Report

D.

AWS Systems Manager

Full Access
Question # 61

A company has an on-premises application. The application has processing times of less than 5 minutes and is invoked only a few times each day. The company wants to move the application to the AWS Cloud.

Which AWS service will support this application MOST cost-effectively?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Lambda

C.

Amazon Elastic Kubernetes Service (Amazon EKS)

D.

Amazon EC2

Full Access
Question # 62

A company wants a customized assessment of its current on-premises environment. The company wants to understand its projected running costs in the AWS Cloud.

Which AWS service or tool will meet these requirements?

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWS Control Tower

D.

Migration Evaluator

Full Access
Question # 63

A company needs to track the activity in its AWS accounts, and needs to know when an API call is made against its AWS resources. Which AWS tool or service can be used to meet these requirements?

A.

Amazon CloudWatch

B.

Amazon Inspector

C.

AWS CloudTrail

D.

AWS IAM

Full Access
Question # 64

Which task is a responsibility of AWS, according to the AWS shared responsibility model?

A.

Configure identity and access management for applications.

B.

Manage encryption options for data that is stored on AWS.

C.

Configure security groups for Amazon EC2 instances.

D.

Maintain the physical hardware of the infrastructure.

Full Access
Question # 65

A company needs to block SOL injection attacks.

Which AWS service or feature provides this functionality?

A.

AWS WAF

B.

Network ACLs

C.

Security groups

D.

AWS Trusted Advisor

Full Access
Question # 66

A developer has been hired by a large company and needs AWS credentials.

Which are security best practices that should be followed? (Select TWO.)

A.

Grant the developer access to only the AWS resources needed to perform the job.

B.

Share the AWS account root user credentials with the developer.

C.

Add the developer to the administrator's group in AWS IAM.

D.

Configure a password policy that ensures the developer's password cannot be changed.

E.

Ensure the account password policy requires a minimum length.

Full Access
Question # 67

A company is hosting an application in the AWS Cloud. The company wants to verify that underlying AWS services and general AWS infrastructure are operating normally.

Which combination of AWS services can the company use to gather the required information? (Select TWO.)

A.

AWS Personal Health Dashboard

B.

AWS Systems Manager

C.

AWS Trusted Advisor

D.

AWS Service Health Dashboard

E.

AWS Service Catalog

Full Access
Question # 68

According to the AWS shared responsibility model, which task is the customer's responsibility?

A.

Maintaining the infrastructure needed to run AWS Lambda

B.

Updating the operating system of Amazon DynamoDB instances

C.

Maintaining Amazon S3 infrastructure

D.

Updating the guest operating system on Amazon EC2 instances

Full Access
Question # 69

Which tasks are customer responsibilities, according to the AWS shared responsibility model? (Select TWO.)

A.

Configure the AWS provided security group firewall.

B.

Classify company assets in the AWS Cloud.

C.

Determine which Availability Zones to use for Amazon S3 buckets.

D.

Patch or upgrade Amazon DynamoDB.

E.

Select Amazon EC2 instances to run AWS Lambda on.

F.

AWS Config

Full Access
Question # 70

Which AWS services are supported by Savings Plans?(Select TWO.)

A.

Amazon EC2

B.

Amazon RDS

C.

Amazon SageMaker

D.

Amazon Redshift

E.

Amazon DynamoDB

Full Access
Question # 71

A company has set up a VPC in its AWS account and has created a subnet in the VPC. The company wants to make the subnet public.

Which AWS features should the company use to meet this requirement? (Select TWO.)

A.

Amazon VPC internet gateway

B.

Amazon VPC NAT gateway

C.

Amazon VPC route tables

D.

Amazon VPC network ACL

E.

Amazon EC2 security groups

Full Access
Question # 72

A company encourages its teams to test failure scenarios regularly and to validate their understanding of the impact of potential failures.

Which pillar of the AWS Well-Architected Framework does this philosophy represent?

A.

Operational excellence

B.

Cost optimization

C.

Performance efficiency

D.

Security

Full Access
Question # 73

A company wants to build a new web application by using AWS services. The application must meet the on-demand load for periods of heavy activity.

Which AWS services or resources provide the necessary workload adjustments to meet these requirements? (Select TWO.)

A.

Amazon Machine Image (AMI)

B.

Amazon EC2 Auto Scaling

C.

Amazon EC2 instance

D.

AWS Lambda

E.

EC2 Image Builder

Full Access
Question # 74

Which of the following actions are controlled with AWS Identity and Access Management (IAM)? (Select TWO.)

A.

Control access to AWS service APIs and to other specific resources.

B.

Provide intelligent threat detection and continuous monitoring.

C.

Protect the AWS environment using multi-factor authentication (MFA).

D.

Grant users access to AWS data centers.

E.

Provide firewall protection for applications from common web attacks.

Full Access
Question # 75

A company must store call recordings for 6 years. The storage system should be highly durable and cost-effective.

Which AWS service meets these requirements?

A.

AWS Snowball

B.

Amazon S3

C.

AWS Storage Gateway

D.

Amazon Kinesis

Full Access
Question # 76

Which AWS service provides threat detection by monitoring for malicious activities and unauthorized actions to protect AWS accounts, workloads, and data that is stored in Amazon S3?

A.

AWS Shield

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

Amazon Inspector

Full Access
Question # 77

How does the AWS Enterprise Support Concierge team help users?

A.

Supporting application development

B.

Providing architecture guidance

C.

Answering billing and account inquiries

D.

Answering questions regarding technical support cases

Full Access
Question # 78

Which AWS service can provide a dedicated network connection with consistent low latency from on premises to the AWS Cloud?

A.

Amazon VPC

B.

Amazon Kinesis Data Streams

C.

AWS Direct Connect

D.

Amazon OpenSearch Service

Full Access
Question # 79

A company's application has high customer usage during certain times of the day. The company wants to reduce the number of Amazon EC2 instances that run when application usage is low.

Which AWS service or instance purchasing option should the company use to meet this requirement?

A.

EC2 Instance Savings Plans

B.

Spot Instances

C.

Reserved Instances

D.

Amazon EC2 Auto Scaling

Full Access
Question # 80

Which AWS service or tool provides on-demand access to AWS security and compliance reports and AWS online agreements?

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS Billing console

Full Access
Question # 81

Which of the following is a benefit that AWS Professional Services provides?

A.

Management of the ongoing security of user data

B.

Advisory solutions for AWS adoption

C.

Technical support 24 hours a day, 7 days a week

D.

Monitoring of monthly billing costs in AWS accounts

Full Access
Question # 82

What is a characteristic of Convertible Reserved Instances (RIs)?

A.

Users can exchange Convertible RIs for other Convertible RIs from a different instance family.

B.

Users can exchange Convertible RIs for other Convertible RIs in different AWS Regions.

C.

Users can sell and buy Convertible RIs on the AWS Marketplace.

D.

Users can shorten the term of their Convertible RIs by merging them with other Convertible RIs.

Full Access
Question # 83

A company is migrating its data center to AWS. The company needs an AWS Support plan that provides chat access to a cloud sup engineer 24 hours a day, 7 days a week. The company does not require access to infrastructure event management.

What is the MOST cost-effective AWS Support plan that meets these requirements?

A.

AWS Enterprise Support

B.

AWS Business Support

C.

AWS Developer Support

D.

AWS Basic Support

Full Access
Question # 84

Which AWS service is designed to help users build conversational interfaces into applications using voice and text?

A.

Amazon Lex

B.

Amazon Transcribe

C.

Amazon Comprehend

D.

Amazon Timestream

Full Access
Question # 85

A company has created an AWS Cost and Usage Report and wants to visualize the report.

Which AWS service should the company use to ingest and display this information?

A.

Amazon QuickSight

B.

Amazon Pinpoint

C.

Amazon Neptune

D.

Amazon Kinesis

Full Access
Question # 86

A company needs to deploy applications in the AWS Cloud as quickly as possible. The company also needs to minimize the complexity that is related to the management of AWS resources.

Which AWS service should the company use to meet these requirements?

A.

AWS config

B.

AWS Elastic Beanstalk

C.

Amazon EC2

D.

Amazon Personalize

Full Access
Question # 87

A company has a centralized group of users with large file storage requirements that have exceeded the space available on premises. The company wants to extend its file storage capabilities for this group while retaining the performance benefit of sharing content locally.

What is the MOST operationally efficient AWS solution for this scenario?

A.

Create an Amazon S3 bucket for each user. Mount each bucket by using an S3 file system mounting utility.

B.

Configure and deploy an AWS Storage Gateway file gateway. Connect each user's workstation to the file gateway.

C.

Move each user's working environment to Amazon Workspaces. Set up an Amazon WorkDocs account for each user.

D.

Deploy an Amazon EC2 instance and attach an Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS volume. Share the EBS volume directly with the users.

Full Access
Question # 88

A user has a stateful workload that will run on Amazon EC2 for the next 3 years.

What is the MOST cost-effective pricing model for this workload?

A.

On-Demand Instances

B.

Reserved Instances

C.

Dedicated Instances

D.

Spot Instances

Full Access
Question # 89

Which AWS service can a company use to find security and compliance reports, including International Organization for Standardization (ISO) reports?

A.

AWS Artifact

B.

Amazon CloudWatch

C.

AWS Config

D.

AWS Audit Manager

Full Access
Question # 90

A user discovered that an Amazon EC2 instance is missing an Amazon Elastic Block Store (Amazon EBS) data volume. The user wants to determine when the EBS volume was removed.

Which AWS service will provide this information?

A.

AWS Config

B.

AWS Trusted Advisor

C.

Amazon Timestream

D.

Amazon QuickSight

Full Access
Question # 91

A company needs to set a maximum spending limit on AWS services each month. The company also needs to set up alerts for when the company reaches its spending limit.

Which AWS service or tool should the company use to meet these requirements?

A.

Cost Explorer

B.

AWS Trusted Advisor

C.

Service Quotas

D.

AWS Budgets

Full Access
Question # 92

A company wants to monitor for misconfigured security groups that are allowing unrestricted access to specific ports.

Which AWS service will meet this requirement?

A.

AWS Trusted Advisor

B.

Amazon CloudWatch

C.

Amazon GuardDuty

D.

AWS Health Dashboard

Full Access
Question # 93

A company's headquarters is located on a different continent from where the majority of the company's customers live. The company wants an AWS Cloud environment setup that will provide the lowest latency to the customers.

A company wants to automate the creation of new AWS accounts and automatically prevent all users from creating Amazon EC2

instances.

Which AWS service provides this functionality?

A.

AWS Service Catalog

B.

AWS Organizations

C.

EC2 Image Builder

D.

AWS Systems Manager

Full Access
Question # 94

Which AWS service should be used when a company needs to provide its remote employees with virtual desktops?

A.

Amazon Identity and Access Management (IAM)

B.

AWS Directory Service

C.

AWS IAM Identity Center (AWS Single Sign-On)

D.

Amazon Workspaces

Full Access
Question # 95

A company wants a key-value NoSQL database that is fully managed and serverless.

Which AWS service will meet these requirements?

A.

Amazon DynamoDB

B.

Amazon RDS

C.

Amazon Aurora

D.

Amazon Memory DB for Redis

Full Access
Question # 96

A company needs to set up user authentication for a new application. Users must be able to sign in directly with a user name and password, or through a third-party provider.

Which AWS service should the company use to meet these requirements?

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Signer

C.

Amazon Cognito

D.

AWS Directory Service

Full Access
Question # 97

Which AWS services can limit manual errors by consistently provisioning AWS resources in multiple envirom

A.

AWS Config

B.

AWS CodeStar

C.

AWS CloudFormation

D.

AWS Cloud Development Kit (AWS CDK)

E.

AWS CodeBuild

Full Access
Question # 98

An ecommerce company wants to distribute traffic between the Amazon EC2 instances that host its website.

Which AWS service or resource will meet these requirements?

A.

Application Load Balancer

B.

AWS WAF

C.

AWS CloudHSM

D.

AWS Direct Connect

Full Access
Question # 99

Which AWS service provides this functionality?

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Systems Manager

C.

AWS Config

D.

AWS Control Tower

Full Access
Question # 100

A company wants to receive a notification when a specific AWS cost threshold is reached.

Which AWS services or tools can the company use to meet this requirement? (Select TWO.)

A.

Amazon Simple Queue Service (Amazon SQS)

B.

AWS Budgets

C.

Cost Explorer

D.

Amazon CloudWatch

E.

AWS Cost and Usage Report

Full Access
Question # 101

A company has deployed an application in the AWS Cloud. The company wants to ensure that the application is highly resilient.

Which component of AWS infrastructure can the company use to meet this requirement?

A.

Content delivery network (CDN)

B.

Edge locations

C.

Wavelength Zones

D.

Availability Zones

Full Access
Question # 102

Which AWS service or feature will search for and identify AWS resources that are shared externally?

A.

Amazon OpenSearch Service

B.

AWS Control Tower

C.

AWS IAM Access Analyzer

D.

AWS Fargate

Full Access
Question # 103

A company needs a repository that stores source code. The company needs a way to update the running software when the code changes.

Which combination of AWS services will meet these requirements? (Select TWO.)

A.

AWS CodeCommit

B.

AWS CodeDeploy

C.

Amazon DynamoDB

D.

Amazon S3

E.

Amazon Elastic Container Service (Amazon ECS)

Full Access
Question # 104

A company has a MySQL database running on a single Amazon EC2 instance. The company now requires higher availability in the event of an outage.

Which set of tasks would meet this requirement?

A.

Add an Application Load Balancer in front of the EC2 instance.

B.

Configure EC2 Auto Recovery to move the instance to another Availability Zone.

C.

Migrate to Amazon RDS and enable Multi-AZ.

D.

Enable termination protection for the EC2 instance to avoid outages.

Full Access
Question # 105

A company is running an application that is hosted on Amazon EC2 instances. The usage of the EC2 instances is higher during daytime hours than nighttime hours. The company wants to optimize the number of EC2 instances based on this usage pattern.

Which AWS service or instance purchasing option should the company use to meet these requirements?

A.

Spot Instances

B.

Reserved Instances

C.

AWS CloudFormation

D.

AWS Auto Scaling

Full Access
Question # 106

A company needs to run a workload for several batch image rendering applications. It is acceptable for the workload to experience downtime.

Which Amazon EC2 pricing model would be MOST cost-effective in this situation?

A.

On-Demand Instances

B.

Reserved Instances

C.

Dedicated Instances

D.

Spot Instances

Full Access
Question # 107

A company needs to store data from a recommendation engine in a database.

Which AWS service provides this functionality with the LEAST operational overhead?

A.

Amazon RDS for PostgreSQL

B.

Amazon DynamoDB

C.

Amazon Neptune

D.

Amazon Aurora

Full Access
Question # 108

Which options are AWS Cloud Adoption Framework (AWS CAF) cloud transformation journey

recommendations? (Select TWO.)

A.

Envision phase

B.

Align phase

C.

Assess phase

D.

Mobilize phase

E.

Migrate and modernize phase

Full Access
Question # 109

A company that has multiple business units wants to centrally manage and govern its AWS Cloud environments. The company wants to automate the creation of AWS accounts, apply service control policies (SCPs), and simplify billing processes.

Which AWS service or tool should the company use to meet these requirements?

A.

AWS Organizations

B.

Cost Explorer

C.

AWS Budgets

D.

AWS Trusted Advisor

Full Access
Question # 110

A company manages factory machines in real time. The company wants to use AWS technology to deploy its monitoring applications as close to the factory machines as possible.

Which AWS solution will meet these requirements with the LEAST latency?

A.

AWS Outposts

B.

Amazon EC2

C.

AWS App Runner

D.

AWS Batch

Full Access
Question # 111

A company wants an AWS service to provide product recommendations based on its customer data.

Which AWS service will meet this requirement?

A.

Amazon Polly

B.

Amazon Personalize

C.

Amazon Comprehend

D.

Amazon Rekognition

Full Access
Question # 112

A company is moving an on-premises data center to the AWS Cloud. The company must migrate 50 petabytes of file storage data to AWS with the least possible operational overhead.

Which AWS service or resource should the company use to meet these requirements?

A.

AWS Snowmobile

B.

AWS Snowball Edge

C.

AWS Data Exchange

D.

AWS Database Migration Service (AWS DMS)

Full Access
Question # 113

Which AWS service or storage class provides low-cost, long-term data storage?

A.

Amazon S3 Glacier Deep Archive

B.

AWS Snowball

C.

Amazon MQ

D.

AWS Storage Gateway

Full Access
Question # 114

Which pillar of the AWS Well-Architected Framework includes the AWS shared responsibility model?

A.

Operational excellence

B.

Performance efficiency

C.

Reliability

D.

Security

Full Access
Question # 115

A company runs a MySQL database in its on-premises data center. The company wants to run a copy of this database in the AWS

Cloud.

Which AWS service would support this workload?

A.

Amazon RDS

B.

Amazon Neptune

C.

Amazon ElastiCache for Redis

D.

Amazon Quantum Ledger Database (Amazon QLDB)

Full Access
Question # 116

Which AWS services or features provide disaster recovery solutions for Amazon EC2 instances? (Select TWO.)

A.

EC2 Reserved Instances

B.

EC2 Amazon Machine Images (AMIs)

C.

Amazon Elastic Block Store (Amazon EBS) snapshots

D.

AWS Shield

E.

Amazon GuardDuty

Full Access
Question # 117

A company is operating several factories where it builds products. The company needs the ability to process data, store data, and run applications with local system interdependencies that require low latency.

Which AWS service should the company use to meet these requirements?

A.

AWS loT Greengrass

B.

AWS Lambda

C.

AWS Outposts

D.

AWS Snowball Edge

Full Access
Question # 118

A company wants high levels of detection and near-real-time (NRT) mitigation against large and sophisticated distributed denial of service (DDoS) attacks on applications running on AWS.

Which AWS service should the company use?

A.

Amazon GuardDuty

B.

Amazon Inspector

C.

AWS Shield Advanced

D.

Amazon Macie

Full Access
Question # 119

A company needs to identify who accessed an AWS service and what action was performed for a given time period.

Which AWS service should the company use to meet this requirement?

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Security Hub

D.

Amazon Inspector

Full Access
Question # 120

A company wants to migrate its on-premises relational databases to the AWS Cloud. The company wants to use infrastructure as close to its current geographical location as possible.

Which AWS service or resource should the company use to select its Amazon RDS deployment area?

A.

Amazon Connect

B.

AWS Wavelength

C.

AWS Regions

D.

AWS Direct Connect

Full Access
Question # 121

Which database engines does Amazon Aurora support? (Select TWO.)

A.

Oracle

B.

Microsoft SQL Server

C.

MySQL

D.

PostgreSQL

E.

MongoDB

Full Access
Question # 122

Which AWS service integrates with other AWS services to provide the ability to encrypt data at rest?

A.

AWS Key Management Service (AWS KMS)

B.

AWS Certificate Manager (ACM)

C.

AWS Identity and Access Management (1AM)

D.

AWS Security Hub

Full Access
Question # 123

A company wants an automated process to continuously scan its Amazon EC2 instances for software vulnerabilities.

Which AWS service will meet these requirements?

A.

Amazon GuardDuty

B.

Amazon Inspector

C.

Amazon Detective

D.

Amazon Cognito

Full Access
Question # 124

A company is expecting a short-term spike in internet traffic for its application. During the traffic increase, the application cannot be interrupted. The company also needs to minimize cost and maximize flexibility.

A company needs to use a serverless interactive query service to analyze data in Amazon S3. The query service

must support standard SQL.

Which AWS service will meet these requirements?

A.

Amazon Redshift

B.

AWS Glue

C.

Amazon Athena

D.

Amazon Kinesis Data Streams

Full Access
Question # 125

A company wants durable storage for static content and infinitely scalable data storage infrastructure at the lowest cost.

Which AWS service should the company choose?

A.

Amazon Elastic Block Store (Amazon EBS)

B.

Amazon S3

C.

AWS Storage Gateway

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 126

An independent software vendor wants to deliver and share its custom Amazon Machine images (AMIs) to prospective customers.

Which AWS service will meet these requirements?

A.

AWS Marketplace

B.

AWS Data Exchange

C.

Amazon EC2

D.

AWS Organizations

Full Access
Question # 127

A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify infrastructure deployments that do not meet best practices. Which AWS service can the company use to meet these requirements?

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWSConfig

D.

Amazon GuardDuty

Full Access
Question # 128

Which tasks are the customer's responsibility, according to the AWS shared responsibility model? (Select TWO.)

A.

Establish the global infrastructure.

B.

Perform client-side data encryption.

C.

Configure 1AM credentials.

D.

Secure edge locations.

E.

Patch Amazon RDS DB instances.

Full Access
Question # 129

Which AWS Cloud design principle is a company using when the company implements AWS CloudTrail?

A.

Activate traceability.

B.

Use serverless compute architectures.

C.

Perform operations as code.

D.

Go global in minutes.

Full Access
Question # 130

Which AWS service or feature requires an Internet service provider (ISP) and a colocation facility to be Implemented?

A.

AWS VPN

B.

Amazon Conned

C.

AWS Direct Connect

D.

Internet gateway

Full Access
Question # 131

A company wants to generate a list of IAM users. The company also wants to view the status of various credentials that are associated with the users, such as password, access keys: and multi-factor authentication (MFA) devices

Which AWS service or feature will meet these requirements?

A.

IAM credential report

B.

AWS IAM Identity Center (AWS Single Sign-On)

C.

AWS Identity and Access Management Access Analyzer

D.

AWS Cost and Usage Report

Full Access
Question # 132

A company is using AWS Organizations to configure AWS accounts.

A company is planning its migration to the AWS Cloud. The company is identifying its capability gaps by using the AWS Cloud Adoption Framework (AWS CAF) perspectives.

Which phase of the cloud transformation journey includes these identification activities?

A.

Envision

B.

Align

C.

Scale

D.

Launch

Full Access
Question # 133

A company wants to migrate its on_premises workloads to the AWS Cloud. The company wants to separate workloads for chargeback to different departments.

Which AWS services or features will meet these requirements? (Select TWO.)

A.

Placement groups

B.

Consolidated billing

C.

Edge locations

D.

AWS Config

E.

Multiple AWS accounts

Full Access
Question # 134

A network engineer needs to build a hybrid cloud architecture connecting on-premises networks to the AWS Cloud using AWS Direct Connect. The company has a few VPCs in a single AWS Region and expects to increase the number of VPCs to hundreds over time.

Which AWS service or feature should the engineer use to simplify and scale this connectivity as the VPCs increase in number?

A.

VPC endpoints

B.

AWS Transit Gateway

C.

Amazon Route 53

D.

AWS Secrets Manager

Full Access
Question # 135

A company Is designing its AWS workloads so that components can be updated regularly and so that changes can be made in small, reversible increments.

Which pillar of the AWS Well-Architected Framework does this design support?

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Full Access
Question # 136

Which AWS service gives users the ability to discover and protect sensitive data that is stored in Amazon S3 buckets?

A.

Amazon Macie

B.

Amazon Detective

C.

Amazon GuardDuty

D.

AWS I AM Access Analyzer

Full Access
Question # 137

A company wants to manage its AWS Cloud resources through a web interface.

Which AWS service will meet this requirement?

A.

AWS Management Console

B.

AWS CLI

C.

AWS SDK

D.

AWS Cloud

Full Access
Question # 138

Which AWS services can be used to store files? (Select TWO.)

A.

Amazon S3

B.

AWS Lambda

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon SageMaker

E.

AWS Storage Gateway

Full Access
Question # 139

What is the recommended use case for Amazon EC2 On-Demand Instances?

A.

A steady-state workload that requires a particular EC2 instance configuration for a long period of time

B.

A workload that can be interrupted for a project that requires the lowest possible cost

C.

An unpredictable workload that does not require a long-term commitment

D.

A workload that is expected to run for longer than 1 year

Full Access
Question # 140

To assist companies with Payment Card Industry Data Security Standard (PCI DSS) compliance in the cloud. AWS provides:

A.

physical inspections of data centers by appointment.

B.

required PCI compliance certifications for any application running on AWS.

C.

an AWS Attestation of Compliance (AOC) report for specific AWS services.

D.

professional PCI compliance services.

Full Access
Question # 141

Which of the following can be components of a VPC in the AWS Cloud? (Select TWO.)

A.

Amazon API Gateway

B.

Amazon S3 buckets and objects

C.

AWS Storage Gateway

D.

Internet gateway

E.

Subnet

Full Access
Question # 142

A company is planning to migrate applications to the AWS Cloud. During a system audit, the company finds that its content management system (CMS) application is incompatible with cloud environments.

Which migration strategies will help the company to migrate the CMS application with the LEAST effort? (Select TWO.)

A.

Retire

B.

Rehost

C.

Repurchase

D.

Replatform

E.

Refactor

Full Access
Question # 143

Which pricing model will interrupt a running Amazon EC2 instance if capacity becomes temporarily unavailable?

A.

On-Demand Instances

B.

Standard Reserved Instances

C.

Spot Instances

D.

Convertible Reserved Instances

Full Access
Question # 144

A company wants to run its application on Amazon EC2 instances. The company needs to keep the application on-premises to meet a compliance requirement. Which AWS offering will meet these requirements?

A.

Dedicated Instances

B.

Amazon CloudFront

C.

AWS Fargate

D.

AWS Outposts

Full Access
Question # 145

A company operates a petabyte-scale data warehouse to analyze its data. The company wants a solution that will not require manual hardware and software management. Which AWS service will meet these requirements?

A.

Amazon DocumentDB (with MongoDB compatibility)

B.

Amazon Redshift

C.

Amazon Neptune

D.

Amazon ElastiCache

Full Access
Question # 146

Which option is a customer responsibility when using Amazon DynamoDB under the AWS Shared Responsibility Model?

A.

Physical security of DynamoDB

B.

Patching of DynamoDB

C.

Access to DynamoDB tables

D.

Encryption of data at rest in DynamoDB

Full Access
Question # 147

Which options are AWS Cloud Adoption Framework (AWS CAF) security perspective capabilities? (Select TWO.)

A.

Observability

B.

Incident and problem management

C.

Incident response

D.

Infrastructure protection

E.

Availability and continuity

Full Access
Question # 148

Which service enables customers to audit API calls in their AWS accounts'?

A.

AWS CloudTrail

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS X-Ray

Full Access
Question # 149

A company wants to store its files in the AWS Cloud. Users need to be able to download these files directly using a public URL.

Which AWS service or feature will meet this requirement?

A.

Amazon Redshift

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3

Full Access
Question # 150

Which AWS service is designed to help users handle large amounts of data in a data warehouse environment?

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon Aurora

Full Access
Question # 151

A company stores data in an Amazon S3 bucket.

Which task is the responsibility of AWS?

A.

Configure an S3 Lifecycle policy.

B.

Activate S3 Versioning.

C.

Configure S3 bucket policies.

D.

Protect the infrastructure that supports S3 storage.

Full Access
Question # 152

A company needs to provision uninterruptible Amazon EC2 instances, when needed, and pay for compute capacity by the second. Which EC2 instance purchasing option will meet these requirements?

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

Dedicated Instances

Full Access
Question # 153

A company wants to migrate critical on-premises production systems to Amazon EC2 instances. The production instances will be used for at least 3 years. The company wants a pricing option that will minimize cost.

Which solution will meet these requirements?

A.

On-Demand Instances

B.

Reserved Instances

C.

Spot Instances

D.

AWS Free Tier

Full Access
Question # 154

A company needs to run its existing custom, nonproduction workloads in the AWS Cloud quickly and cost-effectively.

The workloads can recover from interruptions easily.

Which pricing model should the company use?

A.

Reserved Instances

B.

On-Demand Instances

C.

Spot Instances

D.

Dedicated Hosts

Full Access
Question # 155

A company wants to move its on-premises databases to managed cloud database services by using a simplified migration process. Which AWS service or tool can help the company meet this requirement?

A.

AWS Storage Gateway

B.

AWS Application Migration Service

C.

AWS DataSync

D.

AWS Database Migration Service (AWS DMS)

Full Access
Question # 156

How does AWS Cloud computing help businesses reduce costs? (Select TWO.)

A.

AWS changes the name prices for servicers in every AWS Region.

B.

AWS enables capacity in be adjusted un demand.

C.

AWS offers discounts tor Amazon LC2 instances that remain Idle tor more man 1 week.

D.

AWS does not charge for data sent from the AWS Cloud to the internet.

E.

AWS eliminates many of the costs of building and maintaining on-premises data centers.

Full Access
Question # 157

Which of the following are AWS Cloud design principles? (Select TWO.)

A.

Pay for compute resources in advance.

B.

Make data-driven decisions to determine cloud architectural design.

C.

Emphasize manual processes to allow for changes.

D.

Test systems at production scale.

E.

Refine operational procedures infrequently.

Full Access
Question # 158

What is the best resource for a user to find compliance-related information and reports about AWS?

A.

AWS Artifact

B.

AWS Marketplace

C.

Amazon Inspector

D.

Increase operational costs across data centers.

Full Access
Question # 159

Which AWS service is a cloud security posture management (CSPM) service that aggregates alerts from various AWS services and partner products in a standardized format?

A.

AWS Security Hub

B.

AWS Trusted Advisor

C.

Amazon EventBndge

D.

Amazon GuardDuty

Full Access
Question # 160

A company is using Amazon DynamoDB for its application database.

Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Select TWO.)

A.

Classify data.

B.

Configure access permissions.

C.

Manage encryption options.

D.

Provide public endpoints to store and retrieve data.

E.

Manage the infrastructure layer and the operating system.

Full Access
Question # 161

Which AWS service or feature allows a user to establish a dedicated network connection between a company's on-premises data center and the AWS Cloud?

A.

AWS Direct Connect

B.

VPC peering

C.

AWS VPN

D.

Amazon Route 53

Full Access
Question # 162

Which AWS service or tool gives users the ability to connect with AWS and deploy resources programmatically?

A.

Amazon quickSight

B.

AWS PrivateLink

C.

AWS Direct Connect

D.

AWS SDKs

Full Access
Question # 163

A company wants to migrate a company's on-premises container Infrastructure to the AWS Cloud. The company wants to prevent unplanned administration and operation cost and adapt to a serverless architecture.

Which AWS service will meet these requirements?

A.

Amazon Connect

B.

AWS Fargate

C.

Amazon Lightsail

D.

Amazon EC2

Full Access
Question # 164

A company has a set of ecommerce applications. The applications need to be able to send messages to each other. Which AWS service meets this requirement?

A.

AWS Auto Scaling

B.

Elastic Load Balancing

C.

Amazon Simple Queue Service (Amazon SOS)

D.

Amazon Kinesis Data Streams

Full Access
Question # 165

A company has a workload that requires data to be collected, analyzed, and stored on premises. The company wants to extend the use of AWS services to run on premises with access to the company network and the company's VPC.

Which AWS service meets this requirement?

A.

AWS Outposts

B.

AWS Storage Gateway

C.

AWS Direct Connect

D.

AWS Snowball

Full Access
Question # 166

A company needs Amazon EC2 instances for a workload that can tolerate interruptions.

Which EC2 instance purchasing option meets this requirement with the LARGEST discount compared to On-Demand prices?

A.

Spot Instances

B.

Convertible Reserved Instances

C.

Standard Reserved Instances

D.

Dedicated Hosts

Full Access
Question # 167

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

A.

Perform quarterly disaster recovery tests.

B.

Place the main component on the us-east-1 Region.

C.

Design for automatic failover to healthy resources.

D.

Design workloads to fit on a single Amazon EC2 instance.

Full Access
Question # 168

A company's workload can recover with minimal downtime when failures occur. Which AWS Cloud benefit does this scenario represent?

A.

Agility

B.

Elasticity

C.

Resiliency

D.

Scalability

Full Access
Question # 169

A company wants to minimize network latency between its Amazon EC2 instances. The EC2 instances do not need to be highly available. Which solution meets these requirements?

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple edge locations.

C.

Use EC2 instances in the same Availability Zone but in different AWS Regions.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Full Access
Question # 170

A company suspects that its AWS resources are being used for illegal activities.

Which AWS group or team should the company notify?

A.

AWS Abuse team

B.

AWS Support team

C.

AWS technical account managers

D.

AWS Professional Services team

Full Access
Question # 171

A company has a physical tape library to store data backups. The tape library is running out of space. The company needs to extend the tape library's capacity to the AWS Cloud.

Which AWS service should the company use to meet this requirement?

A.

Amazon Elastic File System (Amazon EFS)

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon S3

D.

AWS Storage Gateway

Full Access
Question # 172

Which of the following promotes AWS Cloud architectural best practices for designing and operating reliable, secure, efficient, and cost-effective systems?

A.

AWS Serverless Application Model framework

B.

AWS Business Support

C.

Principle of least privilege

D.

AWS Well-Architected Framework

Full Access
Question # 173

A company wants to migrate its PostgreSQL database to AWS. The company does not use the database frequently.

Which AWS service or resource will meet these requirements with the LEAST management overhead?

A.

PostgreSQL on Amazon EC2

B.

Amazon RDS for PostgreSQL

C.

Amazon Aurora PostgreSQL-Compatible Edition

D.

Amazon Aurora Serverless

Full Access
Question # 174

Who enables encryption of data at rest for Amazon Elastic Block Store (Amazon EBS)?

A.

AWS Support

B.

AWS customers

C.

AWS Key Management Service (AWS KMS)

D.

AWS Trusted Advisor

Full Access
Question # 175

A company has multiple AWS accounts that include compute workloads that cannot be interrupted. The company wants to obtain billing discounts that are based on the company's use of AWS services.

Which AWS feature or purchasing option will meet these requirements?

A.

Resource tagging

B.

Consolidated billing

C.

Pay-as-you-go pricing

D.

Spot Instances

Full Access
Question # 176

A company wants to use Amazon EC2 instances to run a stateless and restartable process after business hours.

Which AWS service provides DNS resolution?

A.

Amazon CloudFront

B.

Amazon VPC

C.

Amazon Route 53

D.

AWS Direct Connect

Full Access
Question # 177

What is the total amount of storage offered by Amazon S3?

A.

WOMB

B.

5 GB

C.

5 TB

D.

Unlimited

Full Access
Question # 178

What is a benefit of moving to the AWS Cloud in terms of improving time to market?

A.

Decreased deployment speed

B.

Increased application security

C.

Increased business agility

D.

Increased backup capabilities

Full Access
Question # 179

Which AWS service can defend against DDoS attacks?

A.

AWS Firewall Manager

B.

AWS Shield Standard

C.

AWS WAF

D.

Amazon Inspector

Full Access
Question # 180

A company is using Amazon RDS.

A company is launching a critical business application in an AWS Region.

How can the company increase resilience for this application?

A.

Deploy a copy of the application in another AWS account.

B.

Deploy the application by using multiple VPCs.

C.

Deploy the application by using multiple subnets.

D.

Deploy the application by using multiple Availability Zones.

Full Access
Question # 181

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Full Access
Question # 182

Which AWS service can a company use to securely store and encrypt passwords for a database?

A.

AWS Shield

B.

AWS Secrets Manager

C.

AWS Identity and Access Management (IAM)

D.

Amazon Cognito

Full Access
Question # 183

A company needs to use standard SQL to query and combine exabytes of structured and semi-structured data across a data warehouse, operational database, and data lake.

Which AWS service meets these requirements?

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon Athena

D.

Amazon Redshift

Full Access
Question # 184

Which of the following is an AWS value proposition that describes a user's ability to scale infrastructure based on demand?

A.

Speed of innovation

B.

Resource elasticity

C.

Decoupled architecture

D.

Global deployment

Full Access
Question # 185

Which AWS Well-Architected Framework concept represents a system's ability to remain functional when the system encounters operational problems?

A.

Consistency

B.

Elasticity

C.

Durability

D.

Latency

Full Access
Question # 186

A company wants to implement controls (guardrails) in a newly created AWS Control Tower landing zone.

Which AWS services or features can the company use to create and define these controls (guardrails)? (Select TWO.)

A.

AWS Config

B.

Service control policies (SCPs)

C.

Amazon GuardDuty

D.

AWS Identity and Access Management (IAM)

E.

Security groups

Full Access
Question # 187

Which AWS service is used to temporarily provide federated security credentials to a

A.

Amazon GuardDuty

B.

AWS Simple Token Service (AWS STS)

C.

AWS Secrets Manager

D.

AWS Certificate Manager

Full Access
Question # 188

A company is reviewing its operating policies.

Which policy complies with guidance in the security pillar of the AWS Well-Architected Framework?

A.

Ensure that employees have access to all company data.

B.

Expand employees' permissions as they gain more experience.

C.

Grant all privileges and access to all users.

D.

Apply security requirements at all layers of a process.

Full Access
Question # 189

Which options are common stakeholders for the AWS Cloud Adoption Framework (AWS CAF) platform perspective? (Select TWO.)

A.

Chief financial officers (CFOs)

B.

IT architects

C.

Chief information officers (CIOs)

D.

Chief data officers (CDOs)

E.

Engineers

Full Access
Question # 190

An Availability Zone consists of:

A.

one or more data centers in a single location.

B.

two or more data centers in multiple locations.

C.

one or more physical hosts in a single data center.

D.

two or more physical hosts in multiple data centers.

Full Access
Question # 191

Which AWS service is a key-value database that provides sub-millisecond latency on a large scale?

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

Full Access
Question # 192

Which AWS service provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning (ML)?

A.

Amazon Kendra

B.

Amazon SageMaker

C.

Amazon Augmented Al (Amazon A2I)

D.

Amazon Polly

Full Access
Question # 193

A company provides a software as a service (SaaS) application. The company has a new customer that is based in a different country.

The new customer's data needs to be hosted in that country.

Which AWS service or infrastructure component should the company use to meet this requirement?

A.

AWS Shield

B.

Amazon S3 Object Lock

C.

AWS Regions

D.

Placement groups

Full Access
Question # 194

A company wants to create multiple isolated networks in the same AWS account.

Which AWS service or component will provide this functionality?

A.

AWS Transit Gateway

B.

Internet gateway

C.

Amazon VPC

D.

Amazon EC2

Full Access
Question # 195

A company wants an in-memory data store that is compatible with open source in the cloud.

Which AWS service should the company use?

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon Redshift

Full Access
Question # 196

Which AWS services can a company use to host and run a MySQL database? (Select TWO.)

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon S3

D.

Amazon EC2

E.

Amazon MQ

Full Access
Question # 197

Which activity can companies complete by using AWS Organizations?

A.

Troubleshoot the performance of applications.

B.

Manage service control policies (SCPs).

C.

Migrate applications to microservices.

D.

Monitor the performance of applications.

Full Access
Question # 198

A company runs a database on Amazon Aurora in the us-east-1 Region. The company has a disaster recovery requirement that the database be available in another Region.

Which solution meets this requirement with minimal disruption to the database operations?

A.

Perform an Aurora Multi-AZ deployment.

B.

Deploy Aurora cross-Region read replicas.

C.

Create Amazon Elastic Block Store (Amazon EBS) volume snapshots for Aurora and copy them to another Region.

D.

Deploy Aurora Replicas.

Full Access
Question # 199

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO.)

A.

Availability

B.

Reliability

C.

Scalability

D.

Responsive design

E.

Operational excellence

Full Access
Question # 200

A company is preparing to launch a redesigned website on AWS. Users from around the world will download digital handbooks from the website.

Which AWS solution should the company use to provide these static files securely?

A.

Amazon Kinesis Data Streams

B.

Amazon CloudFront with Amazon S3

C.

Amazon EC2 instances with an Application Load Balancer

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 201

Which of the following are features of network ACLs as they are used in the AWS Cloud? (Select TWO.)

A.

They are stateless.

B.

They are stateful.

C.

They evaluate all rules before allowing traffic.

D.

They process rules in order, starting with the lowest numbered rule, when deciding whether to allow traffic.

E.

They operate at the instance level.

Full Access
Question # 202

Which AWS service can a company use to build conversational chatbots for customer service?

A.

Amazon Lex

B.

AWS Amplify

C.

Amazon Comprehend

D.

Amazon Polly

Full Access
Question # 203

What is a benefit of using an Elastic Load Balancing (ELB) load balancer with applications running in the AWS Cloud?

A.

An ELB will automatically scale resources to meet capacity needs.

B.

An ELB can balance traffic across multiple compute resources.

C.

An ELB can span multiple AWS Regions.

D.

An ELB can balance traffic between multiple internet gateways.

Full Access
Question # 204

An auditor needs to find out whether a specific AWS service is compliant with specific compliance frameworks.

Which AWS service will provide this information?

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon GuardDuty

D.

AWS Certificate Manager (ACM)

Full Access
Question # 205

Which of the following acts as an instance-level firewall to control inbound and outbound access?

A.

Network access control list

B.

Security groups

C.

AWS Trusted Advisor

D.

Virtual private gateways

Full Access
Question # 206

A company needs help managing multiple AWS linked accounts that are reported on a consolidated bill.

Which AWS Support plan includes an AWS concierge whom the company can ask for assistance?

A.

AWS Developer Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Basic Support

Full Access
Question # 207

A company is launching a new application in the AWS Cloud. The application will run on an Amazon EC2 instance. More EC2 instances will be needed when the workload increases.

Which AWS service or tool can the company use to launch the number of EC2 instances that will be needed to handle the workload?

A.

Elastic Load Balancing

B.

Amazon EC2 Auto Scaling

C.

AWS App2Container (A2C)

D.

AWS Systems Manager

Full Access
Question # 208

A company's user base needs to remotely access virtual desktop computers from the internet Which AWS service provides this functionality?

A.

Amazon Connect

B.

Amazon Cognito

C.

Amazon Workspaces

D.

Amazon Upstream 2.0

Full Access
Question # 209

Which of the following is a benefit of decoupling an AWS Cloud architecture?

A.

Reduced latency

B.

Ability to upgrade components independently

C.

Decreased costs

D.

Fewer components to manage

Full Access
Question # 210

Which of the following is a cloud benefit that AWS offers to its users?

A.

The ability to configure AWS data center hypervisors

B.

The ability to purchase hardware in advance of increased traffic

C.

The ability to deploy to AWS on a global scale

D.

Compliance audits for user IT environments

Full Access
Question # 211

Which perspective of the AWS Cloud Adoption Framework (AWS CAF) connects technology and business?

A.

Operations

B.

People

C.

Security

D.

Governance

Full Access
Question # 212

Which AWS service or tool offers consolidated billing?

A.

AWS Artifact

B.

AWS Budgets

C.

AWS Organizations

D.

AWS Trusted AdvisorA company wants to limit its employees' AWS access to a portfolio of predefined AWS resources.

Full Access
Question # 213

Which AWS solution should the company use to meet this requirement?

A.

AWS Config

B.

AWS software development kits (SDKs)

C.

AWS Service Catalog

D.

AWS AppSync

Full Access
Question # 214

What does the Amazon S3 Intelligent-Tiering storage class offer?

A.

Payment flexibility by reserving storage capacity

B.

Long-term retention of data by copying the data to an encrypted Amazon Elastic Block Store (AmazonEBS) volume

C.

Automatic cost savings by moving objects between tiers based on access pattern changes

D.

Secure, durable, and lowest cost storage for data archival

Full Access
Question # 215

Which feature of the AWS Cloud gives users the ability to pay based on current needs rather than forecasted needs?

A.

AWS Budgets

B.

Pay-as-you-go pricing

C.

Volume discounts

D.

Savings Plans

Full Access
Question # 216

Using Amazon Elastic Container Service (Amazon ECS) to break down a monolithic architecture into microservices is an example of:

A.

a loosely coupled architecture.

B.

a tightly coupled architecture.

C.

a stateless architecture.

D.

a stateful architecture.

Full Access
Question # 217

A company needs to run code in response to an event notification that occurs when objects are uploaded to an Amazon S3 bucket.

Which AWS service will integrate directly with the event notification?

A.

AWS Lambda

B.

Amazon EC2

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

AWS Elastic Beanstalk

Full Access
Question # 218

A security engineer wants a single-tenant AWS solution to create, control, and manage their own cryptographic keys to meet regulatory compliance requirements for data security.

Which AWS service should the engineer use?

A.

AWS Key Management Service (AWS KMS)

B.

AWS Certificate Manager (ACM)

C.

AWS CloudHSM

D.

AWS Systems Manager

Full Access
Question # 219

Amazon Elastic File System (Amazon EFS) and Amazon FSx offer which type of storage?

A.

File storage

B.

Object storage

C.

Block storage

D.

Instance store

Full Access
Question # 220

A company is planning a migration to the AWS Cloud and wants to examine the costs that are associated with different workloads.

Which AWS tool will meet these requirements?

A.

AWS Budgets

B.

AWS Cost Explorer

C.

AWS Pricing Calculator

D.

AWS Cost and Usage Report

Full Access
Question # 221

Which AWS service or tool should a company use to forecast AWS spending?

A.

Amazon DevPay

B.

AWS Organizations

C.

AWS Trusted Advisor

D.

Cost Explorer

Full Access
Question # 222

A company has batch workloads that need to run for short periods of time on Amazon EC2. The workloads can handle interruptions and can start again from where they ended.

What is the MOST cost-effective EC2 instance purchasing option to meet these requirements?

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Full Access
Question # 223

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

A.

Set up multi-factor authentication (MFA) for each Workspaces user account.

B.

Ensure the environmental safety and security of the AWS infrastructure that hosts Workspaces.

C.

Provide security for Workspaces user accounts through AWS Identity and Access Management(IAM).

D.

Configure AWS CloudTrail to log API calls and user activity.A company stores data in an Amazon S3 bucket. The company must control who has permission to read, write,or delete objects that the company stores in the S3 bucket.

Full Access
Question # 224

Which of the following are advantages of moving to the AWS Cloud? (Select TWO.)

A.

The ability to turn over the responsibility for all security to AWS.

B.

The ability to use the pay-as-you-go model.

C.

The ability to have full control over the physical infrastructure.

D.

No longer having to guess what capacity will be required.

E.

No longer worrying about users access controls.

Full Access
Question # 225

An application is running on multiple Amazon EC2 instances. The company wants to make the application highly available by configuring a load balancer with requests forwarded to the EC2 instances based on URL paths.

Which AWS load balancer will meet these requirements and take the LEAST amount of effort to deploy?

A.

Network Load Balancer

B.

Application Load Balancer

C.

AWS OpsWorks Load Balancer

D.

Custom Load Balancer on Amazon EC2

Full Access
Question # 226

A company wants to migrate its Microsoft SQL Server database management system from on premises to the AWS Cloud.

Which AWS service should the company use to reduce management overhead for this environment?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon SageMaker

C.

Amazon RDS

D.

Amazon Athena

Full Access
Question # 227

Which of the following are advantages of the AWS Cloud? (Select TWO.)

A.

Trade variable expenses for capital expenses

B.

High economies of scale

C.

Launch globally in minutes

D.

Focus on managing hardware infrastructure

E.

Overprovision to ensure capacity

Full Access
Question # 228

Which AWS service offers a global content delivery network (CDN) that helps companies securely deliver websites, videos, applications,

and APIs at high speeds with low latency?

A.

Amazon EC2

B.

Amazon CloudFront

C.

Amazon CloudWatch

D.

AWS CloudFormation

Full Access
Question # 229

A company is reviewing the design of an application that will be migrated from on premises to a single Amazon EC2 instance.

What should the company do to make the application highly available?

A.

Provision additional EC2 instances in other Availability Zones.

B.

Configure an Application Load Balancer (ALB). Assign the EC2 instance as the ALB's target.

C.

Use an Amazon Machine Image (AMI) to create the EC2 instance.

D.

Provision the application by using an EC2 Spot Instance.

Full Access
Question # 230

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances. The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Full Access
Question # 231

A company is running Amazon EC2 instances in a private subnet in a VPC.

Which AWS service or feature can provide the EC2 instances with network connections to the internet?

A.

Gateway endpoint

B.

NAT gateway

C.

Network Load Balancer

D.

Amazon Route 53

Full Access
Question # 232

A company notices suspicious network activity against an application that is running on a fleet of Amazon EC2 instances. The suspicious activity is coming from a single IP address.

Which AWS service should the company use to block access from this IP address?

A.

AWS Shield

B.

AWS Config

C.

Amazon GuardDuty

D.

AWS WAF

Full Access
Question # 233

A company will run a predictable compute workload on Amazon EC2 Instances for the next 3 years. The workload is critical for the company. The company wants to optimize costs to run the workload.

Which solution will meet these requirements?

A.

Spot Instances

B.

Dedicated Hosts

C.

Savings Plans

D.

On-Demand Instances

Full Access
Question # 234

What is the total volume of data that can be stored in Amazon S3?

A.

10 PB

B.

50 PB

C.

100 PB

D.

Virtually unlimited

Full Access
Question # 235

A company has a MariaDB database on premises. The company wants to move the data to the AWS Cloud. Which AWS service will host this database with the LEAST amount of operational overhead?

A.

Amazon RDS

B.

Amazon Neptune

C.

Amazon S3

D.

Amazon DynamoDB

Full Access
Question # 236

A company wants to transport 100 TB of data from its data center to AWS without using internet.

Which AWS service will meet this requirement?

A.

AWS Snowcone

B.

AWS Snowball Edge

C.

AWS Data Exchange

D.

AWS DataSync

Full Access
Question # 237

A company needs to establish a dedicated network connection from on premises to AWS. The connection must provide consistent, low-latency network performance.

Which AWS service should the company use to meet this requirement?

A.

AWS Direct Connect

B.

AWS Site-to-Site VPN

C.

AWS Directory Service

D.

AWS Transit Gateway

Full Access
Question # 238

A company uploads audio and video files to a centralized Amazon S3 bucket from different geographic locations. Which AWS solution will optimize transfer speeds for these files?

A.

AWS Global Accelerator

B.

S3 Transfer Acceleration

C.

AWS Direct Connect

D.

Amazon CloudFront

Full Access
Question # 239

Which AWS service or feature can a company use to create a private, secured, and scalable network environment in the AWS Cloud?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon S3

C.

Amazon VPC

D.

Route tables

Full Access
Question # 240

Which AWS service or tool provides users with a graphical interface that they can use to manage AWS services?

A.

AWS Copilot

B.

AWS CLI

C.

AWS Management Console

D.

AWS software development kits (SDKs)

Full Access
Question # 241

Which AWS service is a fully managed NoSQL database service?

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon DynamoDB

D.

Amazon Aurora

Full Access
Question # 242

Which AWS service can a company use to directly query and analyze AWS Cost and Usage Reports?

A.

Amazon OpenSearch Service

B.

Amazon Athena

C.

Amazon Aurora

D.

AWS Glue

Full Access
Question # 243

A company needs to organize its resources and track AWS costs on a detailed level. The company needs to categorize costs by business department, environment, and application. Which solution will meet these requirements'?

A.

Access the AWS Cost Management console to organize resources set an AWS budget, and receive notifications of unintentional usage.

B.

Use tags to organize the resources. Activate cost allocation tags to track AWS costs on a detailed level.

C.

Create Amazon CloudWatch dashboards to visually organize and track costs individually.

D.

Access the AWS Billing and Cost Management dashboard to organize and track resource consumption on a detailed level.

Full Access
Question # 244

Treating infrastructure as code in the AWS Cloud allows users to:

A.

automate migration of on-premises hardware to AWS data centers.

B.

let a third party automate an audit of the AWS infrastructure.

C.

turn over application code to AWS so it can run on the AWS infrastructure.

D.

automate the infrastructure provisioning process.

Full Access
Question # 245

Which AWS service or feature should a company use between two microservices to ensure that messages are sent and received in exact order?

A.

Amazon Simple Email Service (Amazon SES)

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon S3 Event Notifications

D.

Amazon Simple Queue Service (Amazon SQS) FIFO queues

Full Access
Question # 246

Which AWS service provides on-premises applications with low-latency access to data that is stored in the AWS Cloud?

A.

Amazon CloudFront

B.

AWS Storage Gateway

C.

AWS Backup

D.

AWS DataSync

Full Access