Black Friday Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Amazon Web Services > AWS Certified Foundational > CLF-C02

CLF-C02 AWS Certified Cloud Practitioner Question and Answers

Question # 4

A company purchased Amazon EC2 Standard Reserved Instances (Rls) for a workload in the AWS Cloud. The company needs to move part of the workload to an instance family that does not match the instance family of these Standard RIs.

How can the company take advantage of the Standard RIs that it no longer needs?

A.

Contact the AWS Support team, and ask the team to sell the Standard RIs.

B.

Sell the Standard RIs on the Amazon EC2 Reserved Instance Marketplace.

C.

Sell the Standard RIs as a third-party seller on the AWS Marketplace.

D.

Convert the Standard RIs to Savings Plans.

Full Access
Question # 5

Which AWS services are serverless? (Select TWO.)

A.

AWS Fargate

B.

Amazon Managed Streaming for Apache Kafka

C.

Amazon EMR

D.

Amazon S3

E.

Amazon EC2

Full Access
Question # 6

Which of the following are customer responsibilities under the AWS shared responsibility model? (Select TWO.)

A.

Physical security of AWS facilities

B.

Configuration of security groupsQ C. Encryption of customer data on AWS

C.

Management of AWS Lambda infrastructureQ E. Management of network throughput of each AWS Region

Full Access
Question # 7

Which AWS service is a fully managed NoSQL database service?

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon DynamoDB

D.

Amazon Aurora

Full Access
Question # 8

A company needs to evaluate its AWS environment and provide best practice recommendations in five categories: cost, performance, service limits, fault tolerance, and security. Which AWS service can the company use to meet these requirements?

A.

AWS Shield

B.

AWS WAF

C.

AWS Trusted Advisor

D.

AWS Service Catalog

Full Access
Question # 9

A company needs to request temporary, limited-privilege credentials for IAM users and for the federated users that the company authenticates.

Which AWS service will provide these credentials?

A.

Amazon GuardDuty

B.

AWS Key Management Service (AWS KMS)

C.

AWS Security Token Service (AWS STS)

D.

AWS Identity and Access Management Access Analyzer

Full Access
Question # 10

A company wants to migrate its applications to the AWS Cloud. The company plans to identity and prioritize any business transformation opportunities and evaluate its AWS Cloud readiness. Which AWS service or tool should the company use to meet these requirements?

A.

AWS Cloud Adoption Framework (AWS CAF)

B.

AWS Managed Services (AMS)

C.

AWS Well-Architected Framework

D.

AWS Migration Hub

Full Access
Question # 11

A company wants durable storage for static content and infinitely scalable data storage infrastructure at the lowest cost.

Which AWS service should the company choose?

A.

Amazon Elastic Block Store (Amazon EBS)

B.

Amazon S3

C.

AWS Storage Gateway

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 12

A company uses AWS and has a VPC that includes two public subnets. The company needs to allow and deny specific inbound and outbound traffic for each public subnet.

Which AWS service or tool can the company use to meet this requirement?

A.

Network ACL

B.

AWSWAF

C.

VPC route table entry

D.

Security group

Full Access
Question # 13

Which AWS service should a company use to organize characterize, and search large numbers of images?

A.

Amazon Transcribe

B.

Amazon Rekognition

C.

Amazon Aurora

D.

Amazon QuickSight

Full Access
Question # 14

A company wants to visualize and manage AWS Cloud costs and usage for a specific period of time.

Which AWS service or feature will meet these requirements?

A.

Cost Explorer

B.

Consolidated billing

C.

AWS Organizations

D.

AWS Budgets

Full Access
Question # 15

A cloud engineer wants to store data in Amazon S3. The engineer will access some of the data yearly and some of the data dally.

Which S3 storage class will meet these requirements MOST cost-effectively?

A.

S3 Standard

B.

S3 Glacier Deep Archive

C.

S3 One Zone-Infrequent Access (S3 One Zone-IA)

D.

S3 Intelligent-Tiering

Full Access
Question # 16

Which options are AWS Cloud Adoption Framework (AWS CAF) cloud transformation journey recommendations? (Select TWO.)

A.

Envision phase

B.

AIign phase

C.

Assess phase

D.

Mobilize phase

E.

Migrate and modernize phase

Full Access
Question # 17

Which AWS service or tool helps companies measure the environmental impact of their AWS usage?

A.

AWS customer carbon footprint tool

B.

AWS Compute Optimizer

C.

Sustainability pillar

D.

OS-Climate (Open Source Climate Data Commons)

Full Access
Question # 18

Which AWS service or tool should a company use to forecast AWS spending?

A.

Amazon DevPay

B.

AWS Organizations

C.

AWS Trusted Advisor

D.

Cost Explorer

Full Access
Question # 19

A company wants to migrate to the AWS Cloud. The company needs the ability to acquire resources when the resources are necessary.

The company also needs the ability to release those resources when the resources are no longer necessary.

Which architecture concept of the AWS Cloud meets these requirements?

A.

Elasticity

B.

Availability

C.

Reliability

D.

Durability

Full Access
Question # 20

A company wants to migrate its on-premises PostgreSQL database to a managed PostgreSQL database on AWS. Which AWS service will meet this requirement?

A.

Amazon DynamoDB

B.

Amazon Neptune

C.

Amazon RDS

D.

Amazon Redshift

Full Access
Question # 21

Which AWS service provides machine learning capability to detect and analyze content in images and videos?

A.

Amazon Connect

B.

Amazon Lightsail

C.

Amazon Personalize

D.

Amazon Rekognition

Full Access
Question # 22

Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?

A.

AWS CloudFormation

B.

AWS CodeDeploy

C.

AWS CodeBuild

D.

AWS Systems Manager

Full Access
Question # 23

A company needs to establish a dedicated network connection from on premises to AWS. The connection must provide consistent, low-latency network performance.

Which AWS service should the company use to meet this requirement?

A.

AWS Direct Connect

B.

AWS Site-to-Site VPN

C.

AWS Directory Service

D.

AWS Transit Gateway

Full Access
Question # 24

A development team wants to deploy multiple test environments for an application in a fast repeatable manner.

Which AWS service should the team use?

A.

Amazon EC2

B.

AWS CloudFormation

C.

Amazon QuickSight

D.

Amazon Elastic Container Service (Amazon ECS)

Full Access
Question # 25

Which AWS services can host PostgreSQL databases? (Select TWO.)

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

Amazon OpenSearch Service

E.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 26

Which AWS service provides automated backups of data by default?

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon ElastiCache (Memcached)

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 27

A user wants to review all Amazon S3 buckets with ACLs and S3 bucket policies in the S3 console. Which AWS service or resource will meet this requirement?

A.

S3 Multi-Region Access Points

B.

S3 Storage Lens

C.

AWS IAM Identity Center

D.

Access Analyzer for S3

Full Access
Question # 28

Which of the following describes AWS Local Zones?

A.

A cluster of data centers in one geographic location

B.

A site used by Amazon CloudFront to cache frequently accessed content

C.

An extension of an AWS Region to more granular locations

D.

One or more data centers with redundant power and networking

Full Access
Question # 29

Which AWS service or tool can be used to capture information about inbound and outbound traffic in an Amazon VPC?

A.

Amazon Inspector

B.

VPC endpoint services

C.

VPC Flow Logs

D.

NAT gateway

Full Access
Question # 30

A company wants to monitor and block malicious HTTP and HTTPS requests that its Amazon CloudFront distributions receive.

Which AWS service should the company use to meet these requirements?

A.

Amazon GuardDuty

B.

Amazon Inspector

C.

AWS WAF

D.

Amazon Detective

Full Access
Question # 31

Which AWS service or feature provides log information of the inbound and outbound traffic on network interfaces in a VPC?

A.

Amazon CloudWatch Logs

B.

AWS CloudTrail

C.

VPC Flow Logs

D.

AWS Identity and Access Management (IAM)

Full Access
Question # 32

Which AWS service or feature identifies whether an Amazon S3 bucket or an IAM role has been shared with an external entity?

A.

AWS Service Catalog

B.

AWS Systems Manager

C.

AWS IAM Access Analyzer

D.

AWS Organizations

Full Access
Question # 33

A company is moving its on-premises IT services to the AWS Cloud. The company wants to set spending limits and to receive notifications if the limits are exceeded.

Which AWS service or resource will meet these requirements?

A.

AWS Budgets

B.

AWS Cost and Usage Reports

C.

AWS Cost Explorer

D.

AWS Organizations consolidated billing

Full Access
Question # 34

A company wants to transport 100 TB of data from its data center to AWS without using internet.

Which AWS service will meet this requirement?

A.

AWS Snowcone

B.

AWS Snowball Edge

C.

AWS Data Exchange

D.

AWS DataSync

Full Access
Question # 35

A company wants to run a graph query that provides credit card users' names, addresses, and transactions. The company wants the graph to show if the names, addresses, and transactions indicates possible fraud.

Which AWS database service will meet these requirements?

A.

Amazon DocumenlDB (with MongoDB compatibility)

B.

Amazon Timestream

C.

Amazon DynamoDB

D.

Amazon Neptune

Full Access
Question # 36

Which AWS Support plan provides customers with access to an AWS technical account manager (TAM)?

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Full Access
Question # 37

A company wants to rightsize its Amazon EC2 instances.

Which configuration change will meet this requirement with the LEAST operational overhead?

A.

Add EC2 instances in another Availability Zone.

B.

Change the size and type of the EC2 instances based on utilization.

C.

Convert the payment method from On-Demand to Savings Plans.

D.

Reprovision the EC2 instances with a larger instance type.

Full Access
Question # 38

A company wants to centrally manage Its employee's access to multiple AWS accounts.

Which AWS service or feature should the company use to meet this requirement?

A.

AWS Identity and Access Management Access Analyzer

B.

AWS Secrets Manager

C.

AWS IAM Identity Center

D.

AWS Security Token Service (AWS STS)

Full Access
Question # 39

A company's user base needs to remotely access virtual desktop computers from the internet Which AWS service provides this functionality?

A.

Amazon Connect

B.

Amazon Cognito

C.

Amazon Workspaces

D.

Amazon Upstream 2.0

Full Access
Question # 40

Which AWS service or feature can a company use to create a private, secured, and scalable network environment in the AWS Cloud?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon S3

C.

Amazon VPC

D.

Route tables

Full Access
Question # 41

A company is connecting multiple VPCs and on-premises networks. The company needs to use an AWS service as a cloud router to simplify peering relationships.

Which AWS service can the company use to meet this requirement?

A.

AWS Direct Connect

B.

AWS Transit Gateway

C.

Amazon Connect

D.

Amazon Route 53

Full Access
Question # 42

A company's workload can recover with minimal downtime when failures occur. Which AWS Cloud benefit does this scenario represent?

A.

Agility

B.

Elasticity

C.

Resiliency

D.

Scalability

Full Access
Question # 43

Where can users find examples of AWS Cloud solution designs?

A.

AWS Marketplace

B.

AWS Service Catalog

C.

AWS Architecture Center

D.

AWS Trusted Advisor

Full Access
Question # 44

An ecommerce company has been monitoring usage of its online store that is hosted on a fleet of Amazon EC2 instances. Surges in traffic occur every weekend day at the same time and last for approximately 4 hours.

A.

AWS Lambda

B.

Amazon EventBridge

C.

Elastic Load Balancing (ELB)

D.

Amazon EC2 Auto Scaling

Full Access
Question # 45

A company is considering a move to the AWS Cloud. The company wants to be able to scale its compute resources as needed to accommodate changing loads.

Which benefit of the AWS Cloud does this scenario describe?

A.

Global deployment in minutes

B.

Cost savings

C.

Agility

D.

Elasticity

Full Access
Question # 46

A company plans to host its data warehouse application on AWS. The company has a machine learning (ML) model and wants to use that model within its data warehouse for data forecasting.

A.

Amazon DynamoDB

B.

Amazon Redshift ML

C.

Amazon Aurora ML

D.

Amazon MemoryDB

Full Access
Question # 47

A company has a social media platform in which users upload and share photos with other users. The company wants to identify and remove inappropriate photos. The company has no machine learning (ML) scientists and must build this detection capability with no ML expertise.

Which AWS service should the company use to build this capability?

A.

Amazon SageMaker

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Comprehend

Full Access
Question # 48

A company is migrating its public website to AWS. The company wants to host the domain name for the website on AWS.

Which AWS service should the company use to meet this requirement?

A.

AWS Lambda

B.

Amazon Route 53

C.

Amazon CloudFront

D.

AWS Direct Connect

Full Access
Question # 49

Which design principle aligns with the performance efficiency pillar of the AWS Well-Architected Framework?

A.

Enable traceability

B.

Measure the cost of workloads

C.

Scale vertically

D.

Use serverless architectures

Full Access
Question # 50

A company has a client that uses an Amazon RDS database. The client requests Information about operating system-level upgrades on the AWS resources that host the RDS database. The company employs a third-party provider to monitor the RDS database.

Who is responsible for upgrading the operating systems for Amazon RDS under the AWS shared responsibility model?

A.

The client

B.

The company

C.

AWS

D.

The third-party provider

Full Access
Question # 51

A company wants to automatically patch its Windows instances that are deployed on Amazon EC2.

Which AWS service will meet these requirements?

A.

AWS Systems Manager

B.

AWS Organizations

C.

AWS Control Tower

D.

Elastic Load Balancing (ELB)

Full Access
Question # 52

A company is running a reporting web server application on Amazon EC2 instances. The application runs once every week and once again at the end of the month. The EC2 instances can be shut down when they are not in use.

What is the MOST cost-effective billing model for this use case?

A.

Standard Reserved Instances

B.

Convertible Reserved Instances

C.

On-Demand Capacity Reservations

D.

On-Demand Instances

Full Access
Question # 53

A company wants to track its AWS account's service costs. The company also wants to receive notifications when costs are forecasted to reach a specific level.

Which AWS service or tool provides this functionality?

A.

AWS Budgets

B.

AWS Cost Explorer

C.

Savings Plans

D.

AWS Billing Conductor

Full Access
Question # 54

A company wants to manage access and permissions for its third-party software as a service (SaaS)

applications. The company wants to use a portal where end users can access assigned AWS accounts and AWS Cloud applications.

Which AWS service should the company use to meet these requirements?

A.

Amazon Cognito

B.

AWS IAM Identity Center (AWS Single Sign-On)

C.

AWS Identity and Access Management (IAM)

D.

AWS Directory Service for Microsoft Active Directory

Full Access
Question # 55

A retail company is migrating its IT infrastructure applications from on premises to the AWS Cloud.

Which costs will the company eliminate with this migration? (Select TWO.)

A.

Cost of data center operations

B.

Cost of application licensing

C.

Cost of marketing campaigns

D.

Cost of physical server hardware

E.

Cost of network management

Full Access
Question # 56

A company uses Amazon EC2 instances to run its application. The application needs to be available and running continuously for three or more years. What type of EC2 instance should the company purchase for a discount on the EC2 pricing?

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

EC2 Fleet

Full Access
Question # 57

Which AWS service or feature is used to Troubleshoot network connectivity issues between Amazon EC2 instances?

A.

AWS Certificate Manager (ACM)

B.

Internet gateway

C.

VPC Flow Logs

D.

AWS CloudHSM

Full Access
Question # 58

Using Amazon Elastic Container Service (Amazon ECS) to break down a monolithic architecture into microservices is an example of:

A.

a loosely coupled architecture.

B.

a tightly coupled architecture.

C.

a stateless architecture.

D.

a stateful architecture.

Full Access
Question # 59

A developer needs to use a standardized template to create copies of a company's AWS architecture for development test, and production environments. Which AWS service should the developer use to meet this requirement?

A.

AWS Cloud Map

B.

AWS Cloud Formation

C.

Amazon CloudFront

D.

AWS CloudTrail

Full Access
Question # 60

A company has an on-premises application. The application has processing times of less than 5 minutes and is invoked only a few times each day. The company wants to move the application to the AWS Cloud.

Which AWS service will support this application MOST cost-effectively?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Lambda

C.

Amazon Elastic Kubernetes Service (Amazon EKS)

D.

Amazon EC2

Full Access
Question # 61

A company has an application that uses AWS services. During scaling events, the company wants to keep

application usage within AWS service quotas.

Which AWS services or tools can report on the quotas so that the company can improve the reliability of the application? (Select TWO.)

A.

Service Quotas console

B.

AWS Trusted Advisor

C.

AWS Systems Manager

D.

AWS Shield

E.

AWS Cost Explorer

Full Access
Question # 62

A company wants its Amazon EC2 instances to share the same geographic area but use redundant underlying power sources.

Which solution will meet these requirements?

A.

Use EC2 instances across multiple Availability Zones in the same AWS Region.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in AWS OpsWorks stacks in different AWS Regions.

Full Access
Question # 63

A company wants to securely log in to Linux Amazon EC2 instances.

A.

Use end-to-end encryption.

B.

Use multi-factor authentication (MFA).

C.

Use AWS Systems Manager Session Manager.

D.

Use AWS Systems Manager State Manager.

Full Access
Question # 64

A company needs a content delivery network that provides secure delivery of data, videos, applications, and APIs to users globally with low latency and high transfer speeds.

Which AWS service meets these requirements?

A.

Amazon CloudFront

B.

Elastic Load Balancing

C.

Amazon S3

D.

Amazon Elastic Transcoder

Full Access
Question # 65

A company Is designing its AWS workloads so that components can be updated regularly and so that changes can be made in small, reversible increments.

Which pillar of the AWS Well-Architected Framework does this design support?

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Full Access
Question # 66

Amazon Elastic File System (Amazon EFS) and Amazon FSx offer which type of storage?

A.

File storage

B.

Object storage

C.

Block storage

D.

Instance store

Full Access
Question # 67

A company's information security manager is supervising a move to AWS and wants to ensure that AWS best practices are followed. The manager has concerns about the potential misuse of AWS account root user credentials.

Which of the following is an AWS best practice for using the AWS account root user credentials?

A.

Allow only the manager to use the account root user credentials for normal activities.

B.

Use the account root user credentials only for Amazon EC2 instances from the AWS Free Tier.

C.

Use the account root user credentials only when they alone must be used to perform a requiredfunction.

D.

Use the account root user credentials only for the creation of private VPC subnets.

Full Access
Question # 68

A company wants to test a new application.

Which AWS principle will help the company test the application?

A.

Make long-term commitments in exchange for a cost discount.

B.

Scale up and down when needed without any long-term commitments.

C.

Have total control over the application infrastructure.

D.

Manage all of the maintenance tasks associated with the cloud.

Full Access
Question # 69

Which AWS service can run a managed PostgreSQL database that provides online transaction processing (OLTP)?

A.

Amazon DynamoDB

B.

Amazon Athena

C.

Amazon RDS

D.

Amazon EMR

Full Access
Question # 70

A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a

natural disaster in a particular geographic area.

Which solution achieves this goal?

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple edge locations.

D.

Use Amazon CloudFront with the EC2 instances configured as the source.

Full Access
Question # 71

A company wants to control the protection of its AWS resources. The company wants to block SQL injection attacks and cross-site scripting.

Which AWS service or feature meets these requirements?

A.

Amazon GuardDuty

B.

AWSWAF

C.

Security groups

D.

AWS Shield

Full Access
Question # 72

Which of the following is a cloud benefit that AWS offers to its users?

A.

The ability to configure AWS data center hypervisors

B.

The ability to purchase hardware in advance of increased traffic

C.

The ability to deploy to AWS on a global scale

D.

Compliance audits for user IT environments

Full Access
Question # 73

A company is running workloads for multiple departments within a single VPC. The company needs to be able to bill each department for its resource usage.

Which action should the company take to accomplish this goal with the LEAST operational overhead?

A.

Add a department tag to each resource and configure cost allocation tags.

B.

Move each department resource to its own VPC.

C.

Move each department resource to its own AWS account.

D.

Use AWS Organizations to get a billing report for each department.

Full Access
Question # 74

A company operates a petabyte-scale data warehouse to analyze its data. The company wants a solution that will not require manual hardware and software management. Which AWS service will meet these requirements?

A.

Amazon DocumentDB (with MongoDB compatibility)

B.

Amazon Redshift

C.

Amazon Neptune

D.

Amazon ElastiCache

Full Access
Question # 75

A company wants an in-memory data store that is compatible with open source in the cloud.

Which AWS service should the company use?

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon Redshift

Full Access
Question # 76

Which AWS service or tool can be used to consolidate payments for a company with multiple AWS accounts?

A.

AWS Cost and Usage Report

B.

AWS Organizations

C.

Cost Explorer

D.

AWS Budgets

Full Access
Question # 77

Which activity can companies complete by using AWS Organizations?

A.

Troubleshoot the performance of applications.

B.

Manage service control policies (SCPs).

C.

Migrate applications to microservices.

D.

Monitor the performance of applications.

Full Access
Question # 78

A company needs a hybrid cloud storage service to connect its on-premises environment to scalable AWS Cloud storage. Which AWS service will meet these requirements?

A.

Amazon S3

B.

Amazon FSx

C.

AWS Storage Gateway

D.

AWS Fargate

Full Access
Question # 79

A company migrated to the AWS Cloud. Now the company pays for services on an as-needed basis.

Which advantage of cloud computing is the company benefiting from?

A.

Stop spending money running and maintaining data centers

B.

Increase speed and agility

C.

Go global in minutes

D.

Trade fixed expense for variable expense

Full Access
Question # 80

A company recently migrated to the AWS Cloud. The company needs to determine whether its newly imported Amazon EC2 instances are the appropriate size and type.

Which AWS services can provide this information to the company? {Select TWO.)

A.

AWS Auto Scaling

B.

AWS Control Tower

C.

AWS Trusted Advisor

D.

AWS Compute Optimizer

E.

Amazon Forecast

Full Access
Question # 81

Which task is the responsibility of a company that is using Amazon RDS?

A.

Provision the underlying infrastructure.

B.

Create IAM policies to control administrative access to the service.

C.

Install the cables to connect the hardware for compute and storage.

D.

Install and patch the RDS operating system.

Full Access
Question # 82

A company has a workload that requires data to be collected, analyzed, and stored on premises. The company wants to extend the use of AWS services to run on premises with access to the company network and the company's VPC.

Which AWS service meets this requirement?

A.

AWS Outposts

B.

AWS Storage Gateway

C.

AWS Direct Connect

D.

AWS Snowball

Full Access
Question # 83

A company's IT team is managing MySQL database server clusters. The IT team has to patch the database and take backup snapshots of the data in the clusters. The company wants to move this workload to AWS so that these tasks will be completed automatically.

What should the company do to meet these requirements?

A.

Deploy MySQL database server clusters on Amazon EC2 instances.

B.

Use Amazon RDS with a MySQL database.

C.

Use an AWS Cloud Form at ion template to deploy MySQL database servers on Amazon EC2 instances.

D.

Migrate all the MySQL database data to Amazon S3.

Full Access
Question # 84

A company needs to run code in response to an event notification that occurs when objects are uploaded to an Amazon S3 bucket.

Which AWS service will integrate directly with the event notification?

A.

AWS Lambda

B.

Amazon EC2

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

AWS Elastic Beanstalk

Full Access
Question # 85

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

A.

AWS CloudTrail

B.

AWS Cost and Usage Reports

C.

AWS Trusted Advisor

D.

AWS Budgets

Full Access
Question # 86

A company hosts an application on an Amazon EC2 instance. The EC2 instance needs to access several AWS resources, including Amazon S3 and Amazon DynamoDB.

What is the MOST operationally efficient solution to delegate permissions?

A.

Create an IAM role with the required permissions. Attach the role to the EC2 instance.

B.

Create an IAM user and use its access key and secret access key in the application.

C.

Create an IAM user and use its access key and secret access key to create a CLI profile in the EC2 instance.

D.

Create an IAM role with the required permissions. Attach the role to the administrativeIAM user.

Full Access
Question # 87

A company is reviewing its operating policies.

Which policy complies with guidance in the security pillar of the AWS Well-Architected Framework?

A.

Ensure that employees have access to all company data.

B.

Expand employees' permissions as they gain more experience.

C.

Grant all privileges and access to all users.

D.

Apply security requirements at all layers of a process.

Full Access
Question # 88

Which design principle should be considered when architecting in the AWS Cloud?

A.

Think of servers as non-disposable resources.

B.

Use synchronous integration of services.

C.

Design loosely coupled components.

D.

Implement the least permissive rules for security groups.

Full Access
Question # 89

Which database engine is compatible with Amazon RDS?

A.

Apache Cassandra

B.

MongoDB

C.

Neo4j

D.

PostgreSQL

Full Access
Question # 90

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

A.

Third-party vendors

B.

Customers

C.

Reseller partners

D.

Internet providers

Full Access
Question # 91

Which best practice for cost governance does this example show?

A.

Resource controls

B.

Cost allocation

C.

Architecture optimization

D.

Tagging enforcement

Full Access
Question # 92

A company is configuring its AWS Cloud environment. The company's administrators need to group users together and apply permissions to the group.

Which AWS service or feature can the company use to meet these requirements?

A.

AWS Organizations

B.

Resource groups

C.

Resource tagging

D.

AWS Identity and Access Management (IAM)

Full Access
Question # 93

A company has an application with robust hardware requirements. The application must be accessed by students who are using lightweight, low-cost laptops.

Which AWS service will help the company deploy the application without investing in backend infrastructure or high end client hardware?

A.

Amazon AppStream 2.0

B.

AWS AppSync

C.

Amazon WorkLink

D.

AWS Elastic Beanstalk

Full Access
Question # 94

A company wants to create multiple isolated networks in the same AWS account.

Which AWS service or component will provide this functionality?

A.

AWS Transit Gateway

B.

Internet gateway

C.

Amazon VPC

D.

Amazon EC2

Full Access
Question # 95

A company is preparing to launch a redesigned website on AWS. Users from around the world will download digital handbooks from the website.

Which AWS solution should the company use to provide these static files securely?

A.

Amazon Kinesis Data Streams

B.

Amazon CloudFront with Amazon S3

C.

Amazon EC2 instances with an Application Load Balancer

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 96

A company wants to ensure that two Amazon EC2 instances are in separate data centers with minimal

communication latency between the data centers.

How can the company meet this requirement?

A.

Place the EC2 instances in two separate AWS Regions connected with a VPC peering connection.

B.

Place the EC2 instances in two separate Availability Zones within the same AWS Region.

C.

Place one EC2 instance on premises and the other in an AWS Region. Then connect them by using anAWS VPN connection.

D.

Place both EC2 instances in a placement group for dedicated bandwidth.

Full Access
Question # 97

Which factors affect costs in the AWS Cloud? (Select TWO.)

A.

The number of unused AWS Lambda functions

B.

The number of configured Amazon S3 buckets

C.

Inbound data transfers without acceleration

D.

Outbound data transfers without acceleration

E.

Compute resources that are currently in use

Full Access
Question # 98

Which AWS service is a highly available and scalable DNS web service?

A.

Amazon VPC

B.

Amazon CloudFront

C.

Amazon Route 53

D.

Amazon Connect

Full Access
Question # 99

Which pillar of the AWS Well-Architected Framework includes a design principle about measuring the overall efficiency of workloads in terms of business value?

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Full Access
Question # 100

Which task can a company perform by using security groups in the AWS Cloud?

A.

Allow access to an Amazon EC2 instance through only a specific port.

B.

Deny access to malicious IP addresses at a subnet level.

C.

Protect data that is cached by Amazon CloudFront.

D.

Apply a stateless firewall to an Amazon EC2 instance.

Full Access
Question # 101

A company wants to centrally manage security policies and billing services within a multi-account AWS environment. Which AWS service should the company use to meet these requirements?

A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Resource Access Manager (AWS RAM)

D.

AWS Config

Full Access
Question # 102

A company runs thousands of simultaneous simul-ations using AWS Batch. Each simul-ation is stateless, is fault tolerant, and runs for up to 3 hours.

Which pricing model enables the company to optimize costs and meet these requirements?

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

Dedicated Instances

Full Access
Question # 103

An ecommerce company wants to design a highly available application that will be hosted on multiple Amazon EC2 instances.

How should the company deploy the EC2 instances to meet these requirements?

A.

Across multiple edge locations

B.

Across multiple VPCs

C.

Across multiple Availability Zones

D.

Across multiple AWS accounts

Full Access
Question # 104

A company wants to implement controls (guardrails) in a newly created AWS Control Tower landing zone.

Which AWS services or features can the company use to create and define these controls (guardrails)? (Select TWO.)

A.

AWS Config

B.

Service control policies (SCPs)

C.

Amazon GuardDuty

D.

AWS Identity and Access Management (IAM)

E.

Security groups

Full Access
Question # 105

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

A.

Set up multi-factor authentication (MFA) for each Workspaces user account.

B.

Ensure the environmental safety and security of the AWS infrastructure that hosts Workspaces.

C.

Provide security for Workspaces user accounts through AWS Identity and Access Management(IAM).

D.

Configure AWS CloudTrail to log API calls and user activity.A company stores data in an Amazon S3 bucket. The company must control who has permission to read, write,or delete objects that the company stores in the S3 bucket.

Full Access
Question # 106

Which AWS service or tool helps to centrally manage billing and allow controlled access to resources across AWS accounts?

A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Cost Explorer

D.

AWS Budgets

Full Access
Question # 107

A developer wants to use an Amazon S3 bucket to store application logs that contain sensitive data.

Which AWS service or feature should the developer use to restrict read and write access to the S3 bucket?

A.

Security groups

B.

Amazon CloudWatch

C.

AWS CloudTrail

D.

ACLs

Full Access
Question # 108

A company wants to move its data warehouse application to the AWS Cloud. The company wants to run and scale its analytics services without needing to provision and manage data warehouse clusters.

Which AWS service will meet these requirements?

A.

Amazon Redshift provisioned data warehouse

B.

Amazon Redshift Serverless

C.

Amazon Athena

D.

Amazon S3

Full Access
Question # 109

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO.)

A.

Availability

B.

Reliability

C.

Scalability

D.

Responsive design

E.

Operational excellence

Full Access
Question # 110

A company is hosting a web application on Amazon EC2 instances. The company wants to implement custom conditions to filter and control inbound web traffic.

Which AWS service will meet these requirements?

A.

Amazon GuardDuty

B.

AWSWAF

C.

Amazon Macie

D.

AWS Shield

Full Access
Question # 111

Which AWS service or feature provides a firewall at the subnet level within a VPC?

A.

Security group

B.

Network ACL

C.

Elastic network interface

D.

AWS WAF

Full Access
Question # 112

A company is building a serverless architecture that connects application data from multiple data sources. The company needs a solution that does not require additional code.

Which AWS service meets these requirements?

A.

AWS Lambda

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon CloudWatch

D.

Amazon EventBridge

Full Access
Question # 113

Which AWS Cloud design principle is a company using when the company implements AWS CloudTrail?

A.

Activate traceability.

B.

Use serverless compute architectures.

C.

Perform operations as code.

D.

Go global in minutes.

Full Access
Question # 114

Which AWS solution gives companies the ability to use protocols such as NFS to store and retrieve objects in Amazon S3?

A.

Amazon FSx for Lustre

B.

AWS Storage Gateway volume gateway

C.

AWS Storage Gateway file gateway

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 115

A company needs to configure rules to identify threats and protect applications from malicious network access.

Which AWS service should the company use to meet these requirements?

A.

AWS Identity and Access Management (IAM)

B.

Amazon QuickSight

C.

AWS WAF

D.

Amazon Detective

Full Access
Question # 116

What does "security of the cloud" refer to in the AWS shared responsibility model?

A.

Availability of AWS services such as Amazon EC2

B.

Security of the cloud infrastructure that runs all the AWS services

C.

Implementation of password policies for IAM users

D.

Security of customer environments by using AWS Network Firewall partners

Full Access
Question # 117

Which of the following is an advantage of AWS Cloud computing?

A.

Trade security for elasticity.

B.

Trade operational excellence for agility.

C.

Trade fixed expenses for variable expenses.

D.

Trade elasticity for performance.

Full Access
Question # 118

A cloud practitioner is analyzing Amazon EC2 instance performance and usage to provide recommendations for potential cost savings.

Which cloud concept does this analysis demonstrate?

A.

Auto scaling

B.

Rightsizing

C.

Load balancing

D.

High availability

Full Access
Question # 119

Which task is the responsibility of the customer, according to the AWS shared responsibility model?

A.

Patch the Amazon DynamoDB operating system.

B.

Secure Amazon CloudFront edge locations by allowing physical access according to the principle of least privilege.

C.

Protect the hardware that runs AWS services.

D.

Use AWS Identity and Access Management (1AM) according to the principle of least privilege.

Full Access
Question # 120

Which of the following is the customer's responsibility, according to the AWS shared responsibility model?

A.

Identity and access management

B.

Hard drive initialization

C.

Protection of data center hardware

D.

Security of Availability Zones

Full Access
Question # 121

Which of the following can be components of a VPC in the AWS Cloud? (Select TWO.)

A.

Amazon API Gateway

B.

Amazon S3 buckets and objects

C.

AWS Storage Gateway

D.

Internet gateway

E.

Subnet

Full Access
Question # 122

A company wants to store its files in the AWS Cloud. Users need to be able to download these files directly using a public URL.

Which AWS service or feature will meet this requirement?

A.

Amazon Redshift

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3

Full Access
Question # 123

A cloud practitioner needs to obtain AWS compliance reports before migrating an environment to the AWS Cloud How can these reports be generated?

A.

Contact the AWS Compliance team

B.

Download the reports from AWS Artifact

C.

Open a case with AWS Support

D.

Generate the reports with Amazon Macie.

Full Access
Question # 124

An application runs on multiple Amazon EC2 instances that access a shared file system simultaneously.

Which AWS storage service should be used?

A.

Amazon EBS

B.

Amazon EFS

C.

Amazon S3

D.

AWS Artifact

Full Access
Question # 125

A company is planning to migrate applications to the AWS Cloud. During a system audit, the company finds that its content management system (CMS) application is incompatible with cloud environments.

Which migration strategies will help the company to migrate the CMS application with the LEAST effort? (Select TWO.)

A.

Retire

B.

Rehost

C.

Repurchase

D.

Replatform

E.

Refactor

Full Access
Question # 126

Which of the following is a characteristic of the AWS account root user?

A.

The root user is the only user that can be configured with multi-factor authentication (MFA).

B.

The root user is the only user that can access the AWS Management Console.

C.

The root user is the first sign-in identity that is available when an AWS account is created.

D.

The root user has a password that cannot be changed.

Full Access
Question # 127

Which cloud concept is demonstrated by using AWS Cost Explorer?

A.

Rightsizing

B.

Reliability

C.

Resilience

D.

Modernization

Full Access
Question # 128

How does AWS Cloud computing help businesses reduce costs? (Select TWO.)

A.

AWS changes the name prices for servicers in every AWS Region.

B.

AWS enables capacity in be adjusted un demand.

C.

AWS offers discounts tor Amazon LC2 instances that remain Idle tor more man 1 week.

D.

AWS does not charge for data sent from the AWS Cloud to the internet.

E.

AWS eliminates many of the costs of building and maintaining on-premises data centers.

Full Access
Question # 129

Which AWS services or features provide disaster recovery solutions for Amazon EC2 instances? (Select TWO.)

A.

EC2 Reserved Instances

B.

EC2 Amazon Machine Images (AMIs)

C.

Amazon Elastic Block Store (Amazon EBS) snapshots

D.

AWS Shield

E.

Amazon GuardDuty

Full Access
Question # 130

A company is migrating its applications from on-premises to the AWS Cloud. The company wants to ensure that the applications are assigned only the minimum permissions that are needed to perform all operations.

Which AWS service will meet these requirements'?

A.

AWS Identity and Access Management (IAM)

B.

Amazon CloudWatch

C.

Amazon Macie

D.

Amazon GuardDuty

Full Access
Question # 131

An ecommerce company wants to use Amazon EC2 Auto Scaling to add and remove EC2 instances based on CPU utilization.

Which AWS service or feature can initiate an Amazon EC2 Auto Scaling action to achieve this goal?

A.

Amazon Simple Queue Service (Amazon SQS)

B.

Amazon Simple Notification Service (Amazon SNS)

C.

AWS Systems Manager

D.

Amazon CloudWatch alarm

Full Access
Question # 132

Which design principle is included in the operational excellence pillar of the AWS Well-Architected Framework?

A.

Create annotated documentation.

B.

Anticipate failure.

C.

Ensure performance efficiency.

D.

Optimize costs.

Full Access
Question # 133

A company is requesting Payment Card Industry (PCI) reports that validate the operating effectiveness of AWS security controls.

How should the company obtain these reports?

A.

Contact AWS Support

B.

Download reports from AWS Artifact.

C.

Download reports from AWS Security Hub.

D.

Contact an AWS technical account manager (TAM).

Full Access
Question # 134

Which benefit does Amazon Rekognition provide?

A.

The ability to place watermarks on images

B.

The ability to detect objects that appear in pictures

C.

The ability to resize millions of images automatically

D.

The ability to bid on object detection jobs

Full Access
Question # 135

A company has a set of ecommerce applications. The applications need to be able to send messages to each other. Which AWS service meets this requirement?

A.

AWS Auto Scaling

B.

Elastic Load Balancing

C.

Amazon Simple Queue Service (Amazon SOS)

D.

Amazon Kinesis Data Streams

Full Access
Question # 136

A company wants to set up its workloads to perform their intended functions and recover quickly from failure. Which pillar of the AWS Well-Architected Framework aligns with these goals?

A.

Performance efficiency

B.

Sustainability

C.

Reliability

D.

Security

Full Access
Question # 137

A company needs to provision uninterruptible Amazon EC2 instances, when needed, and pay for compute capacity by the second. Which EC2 instance purchasing option will meet these requirements?

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

Dedicated Instances

Full Access
Question # 138

A user wants to allow applications running on an Amazon EC2 instance to make calls to other AWS services. The access granted must be secure. Which AWS service or feature should be used?

A.

Security groups

B.

AWS Firewall Manager

C.

IAM roles

D.

IAM user SSH keys

Full Access
Question # 139

Which AWS service is a cloud security posture management (CSPM) service that aggregates alerts from various AWS services and partner products in a standardized format?

A.

AWS Security Hub

B.

AWS Trusted Advisor

C.

Amazon EventBndge

D.

Amazon GuardDuty

Full Access
Question # 140

Which of the following is a customer responsibility according to the AWS shared responsibility model?

A.

Apply security patches for Amazon S3 infrastructure devices.

B.

Provide physical security for AWS datacenters.

C.

Install operating system updates on Lambda@Edge.

D.

Implement multi-factor authentication (MFA) for 1AM user accounts.

Full Access
Question # 141

Which options are perspectives that include foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)? (Select TWO.)

A.

Sustainability

B.

Security

C.

Operations

D.

Performance efficiency

E.

Reliability

Full Access
Question # 142

Which tasks are the customer's responsibility, according to the AWS shared responsibility model? (Select TWO.)

A.

Establish the global infrastructure.

B.

Perform client-side data encryption.

C.

Configure 1AM credentials.

D.

Secure edge locations.

E.

Patch Amazon RDS DB instances.

Full Access
Question # 143

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance state changes to RUNNING.

Which AWS service can the company use to meet this requirement?

A.

Amazon SageMaker

B.

Amazon Connect

C.

Amazon EventBridge

D.

AWS Fargate

Full Access
Question # 144

A company wants to create a globally accessible ecommerce platform for its customers. The company wants to use a highly available and scalable DNS web service to connect users to the platform.

Which AWS service will meet these requirements?

A.

Amazon EC2

B.

Amazon VPC

C.

Amazon Route 53

D.

Amazon RDS

Full Access
Question # 145

A social media company wants to protect its web application from common web exploits such as SQL injections and cross-site scripting. Which AWS service will meet these requirements?

A.

Amazon Inspector

B.

AWS WAF

C.

Amazon GuardDuty

D.

Amazon CloudWatch

Full Access
Question # 146

A company is planning to move data backups to the AWS Cloud. The company needs to replace on-premises storage with storage that is cloud-based but locally cached.

Which AWS service meets these requirements?

A.

AWS Storage Gateway

B.

AWS Snowcone

C.

AWS Backup

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 147

A company is creating a web application that requires a relational database to store customer data. Which AWS service should the company use to host the database?

A.

Amazon Aurora

B.

Amazon DynamoDB

C.

Amazon ElastiCache

D.

Amazon Redshift

Full Access
Question # 148

What is the total volume of data that can be stored in Amazon S3?

A.

10 PB

B.

50 PB

C.

100 PB

D.

Virtually unlimited

Full Access
Question # 149

A company wants to migrate its on-premises NoSQL workload to Amazon DynamoDB. Which AWS service will meet this requirement?

A.

AWS Migration Hub

B.

AWS Database Migration Service (AWS DMS)

C.

Migration Evaluator

D.

AWS Application Migration Service

Full Access
Question # 150

Which AWS service or feature allows users to create new AWS accounts, group multiple accounts to organize workflows, and apply policies to groups of accounts?

A.

AWS Identity and Access Management (1AM)

B.

AWS Trusted Advisor

C.

AWS CloudFormation

D.

AWS Organizations

Full Access
Question # 151

Which AWS service can generate information that can be used by external auditors?

A.

Amazon Cognito

B.

Amazon FSx

C.

AWS Config

D.

Amazon Inspector

Full Access
Question # 152

A company is moving some of its on-premises IT services to the AWS Cloud. The finance department wants to see the entire bill so it can forecast spending limits.

Which AWS service can the company use to set spending limits and receive notifications if those limits are exceeded?

A.

AWS Cost and Usage Reports

B.

AWS Budgets

C.

AWS Organizations consolidated billing

D.

Cost Explorer

Full Access
Question # 153

A company's application is running on Amazon EC2 instances. The company is planning a partial migration to a serverless architecture in the next year and wants to pay for resources up front.

Which AWS purchasing option will optimize the company's costs?

A.

Convertible Reserved Instances

B.

Spot Instances

C.

EC2 Instance Savings Plans

D.

Compute Savings Plan

Full Access
Question # 154

Which AWS service or feature can a company use to determine which business unit is using specific AWS resources?

A.

Cost allocation tags

B.

Key pairs

C.

Amazon Inspector

D.

AWS Trusted Advisor

Full Access
Question # 155

Which of the following are advantages of moving to the AWS Cloud? (Select TWO.)

A.

Users can implement all AWS services in seconds.

B.

AWS assumes all responsibility for the security of infrastructure and applications.

C.

Users experience increased speed and agility.

D.

Users benefit from massive economies of scale.

E.

Users can move hardware from their data center to the AWS Cloud.

Full Access
Question # 156

A company wants to migrate to AWS and use the same security software it uses on premises. The security software vendor offers its security software as a service on AWS.

Where can the company purchase the security solution?

A.

AWS Partner Solutions Finder

B.

AWS Support Center

C.

AWS Management Console

D.

AWS Marketplace

Full Access
Question # 157

Which action should a company take to improve security in its AWS account?

A.

Require multi-factor authentication (MFA) for privileged users.

B.

Remove the root user account.

C.

Create an access key for the AWS account root user.

D.

Create an access key for each privileged user.

Full Access
Question # 158

A company needs a bridge between technology and business to help evolve to a culture of continuous growth and learning.

Which perspective in the AWS Cloud Adoption Framework (AWS CAF) serves as this bridge?

A.

People

B.

Governance

C.

Operations

D.

Security

Full Access
Question # 159

Which of the following is a fully managed graph database service on AWS?

A.

Amazon Aurora

B.

Amazon FSx

C.

Amazon DynamoDB

D.

Amazon Neptune

Full Access
Question # 160

Which benefit is always free of charge with AWS, regardless of a user's AWS Support plan?

A.

AWS Developer Support

B.

AWS Developer Forums

C.

Programmatic case management

D.

AWS technical account manager (TAM)

Full Access
Question # 161

An AWS user wants to proactively detect when an instance or account might be compromised or if there are threats from attacks.

Which AWS service should the user choose?

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Shield

D.

Amazon Inspector

Full Access
Question # 162

Which AWS Support plan provides the full set of AWS Trusted Advisor checks at the LOWEST cost?

A.

AWS Developer Support

B.

AWS Business Support

C.

AWS Enterprise On-Ramp Support

D.

AWS Enterprise Support

Full Access
Question # 163

A company is building a new application on AWS. The company needs the application to remain available if an individual application component fails.

Which design principle should the company use to meet this requirement?

A.

Disposable resources

B.

Automation

C.

Rightsizing

D.

Loose coupling

Full Access
Question # 164

Which AWS Well-Architected Framework pillar focuses on structured and streamlined allocation of computing resources?

A.

Reliability

B.

Operational excellence

C.

Performance efficiency

D.

Sustainability

Full Access
Question # 165

What is a customer responsibility when using AWS Lambda according to the AWS shared responsibility model?

A.

Managing the code within the Lambda function

B.

Confirming that the hardware is working in the data center

C.

Patching the operating system

D.

Shutting down Lambda functions when they are no longer in use

Full Access
Question # 166

Which AWS service provides storage-optimized and compute-optimized device configurations?

A.

AWS Snowcone

B.

AWS Storage Gateway

C.

AWS Snowball Edge

D.

AWS DataSync

Full Access
Question # 167

What is a benefit of using AWS serverless computing?

A.

Application deployment and management are not required

B.

Application security will be fully managed by AWS

C.

Monitoring and logging are not needed

D.

Management of infrastructure is offloaded to AWS

Full Access
Question # 168

A company wants to allow users to authenticate and authorize multiple AWS accounts by using a single set of credentials.

Which AWS service or resource will meet this requirement?

A.

AWS Organizations

B.

IAM user

C.

AWS IAM Identity Center (AWS Single Sign-On)

D.

AWS Control Tower

Full Access
Question # 169

Which of the following is an advantage that the AWS Cloud provides to users?

A.

Users eliminate the need to guess about infrastructure capacity requirements.

B.

Users decrease their variable costs by maintaining sole ownership of IT hardware.

C.

Users maintain control of underlying IT infrastructure hardware.

D.

Users maintain control of operating systems for managed services.

Full Access
Question # 170

A user has been granted permission to change their own IAM user password.

Which AWS services can the user use to change the password? (Select TWO.)

A.

AWS Command Line Interface (AWS CLI)

B.

AWS Key Management Service (AWS KMS)

C.

AWS Management Console

D.

AWS Resource Access Manager (AWS RAM)

E.

AWS Secrets Manager

Full Access
Question # 171

Which AWS services make use of global edge locations'? (Select TWO.)

A.

AWS Fargate

B.

Amazon CloudFront

C.

AWS Global Accelerator

D.

AWS Wavelength

E.

Amazon VPC

Full Access
Question # 172

Which option is a customer responsibility when using Amazon DynamoDB under the AWS Shared Responsibility Model?

A.

Physical security of DynamoDB

B.

Patching of DynamoDB

C.

Access to DynamoDB tables

D.

Encryption of data at rest in DynamoDB

Full Access
Question # 173

Which programming languages does AWS Cloud Development Kit (AWS CDK) currently support? (Select TWO.)

A.

Python

B.

Swift

C.

TypeScript

D.

Ruby

E.

PHP

Full Access
Question # 174

A cloud practitioner wants a repeatable way to deploy identical AWS resources by using infrastructure templates. Which AWS service will meet these requirements?

A.

AWS CloudFormation

B.

AWS Directory Service

C.

Amazon Lightsail

D.

AWS CodeDeploy

Full Access
Question # 175

A company wants to migrate critical on-premises production systems to Amazon EC2 instances. The production instances will be used for at least 3 years. The company wants a pricing option that will minimize cost.

Which solution will meet these requirements?

A.

On-Demand Instances

B.

Reserved Instances

C.

Spot Instances

D.

AWS Free Tier

Full Access
Question # 176

A company is migrating to the AWS Cloud to meet storage needs. The company wants to optimize costs based on the amount of storage that the company uses.

Which AWS offering or benefit will meet these requirements MOST cost-effectively?

A.

Pay-as-you-go pricing

B.

Savings Plans

C.

AWS Free Tier

D.

Volume-based discounts

Full Access
Question # 177

Which AWS service provides on-premises applications with low-latency access to data that is stored in the AWS Cloud?

A.

Amazon CloudFront

B.

AWS Storage Gateway

C.

AWS Backup

D.

AWS DataSync

Full Access
Question # 178

A company migrated its systems to the AWS Cloud. The systems are rightsized, and a security review did not reveal any issues. The company must ensure that additional developments, integrations, changes, and system usage growth do not jeopardize this optimized AWS infrastructure.

Which AWS service should the company use to report ongoing optimization and security?

A.

AWS Trusted Advisor

B.

AWS Health Dashboard

C.

Amazon Connect

D.

AWS Systems Manager

Full Access
Question # 179

Which maintenance task is the customer's responsibility, according to the AWS shared responsibility model?

A.

Physical connectivity among Availability Zones

B.

Network switch maintenance

C.

Hardware updates and firmware patches

D.

Amazon EC2 updates and security patches

Full Access
Question # 180

Which AWS service or feature gives users the ability to capture information about network traffic in a VPC?

A.

VPC Flow Logs

B.

Amazon Inspector

C.

VPC route tables

D.

AWS CloudTrail

Full Access
Question # 181

Which AWS service or tool can be used to set up a firewall to control traffic going into and coming out of an Amazon VPC subnet?

A.

Security group

B.

AWS WAF

C.

AWS Firewall Manager

D.

Network ACL

Full Access
Question # 182

A company is using AWS for all its IT Infrastructure. The company's developers are allowed to deploy applications on their own. The developers want to deploy their applications without having to provision the infrastructure themselves.

Which AWS service should the developers use to meet these requirements?

A.

AWS Cloud Formation

B.

AWS CodeBuild

C.

AWS Elastic Beanstalk

D.

AWS CodeDeploy

Full Access
Question # 183

Which tool should a developer use lo integrate AWS service features directly into an application?

A.

AWS Software Development Kit

B.

AWS CodeDeploy

C.

AWS Lambda

D.

AWS Batch

Full Access
Question # 184

Which AWS service integrates with other AWS services to provide the ability to encrypt data at rest?

A.

AWS Key Management Service (AWS KMS)

B.

AWS Certificate Manager (ACM)

C.

AWS Identity and Access Management (1AM)

D.

AWS Security Hub

Full Access
Question # 185

A company wants its AWS usage to be more sustainable. The company wants to track, measure, review, and forecast polluting emissions that result from its AWS applications.

Which AWS service or tool can the company use to meet these requirements?

A.

AWS Health Dashboard

B.

AWS customer carbon footprint tool

C.

AWS Support Center

D.

Amazon QuickSight

Full Access
Question # 186

A company needs to block SQL injection attacks.

Which AWS service or feature can meet this requirement?

A.

AWS WAF

B.

AWS Shield

C.

Network ACLs

D.

Security groups

Full Access
Question # 187

Which combination of AWS services can be used to move a commercial relational database to an Amazon-managed open-source database? (Select TWO.)

A.

AWS Database Migration Service (AWS DMS)

B.

AWS software development kits (SDKs)

C.

AWS Schema Conversion Tool

D.

AWS Systems Manager

E.

Amazon EMR

Full Access
Question # 188

A company has deployed an Amazon EC2 instance.

Which option is an AWS responsibility under the AWS shared responsibility model?

A.

Managing and encrypting application data

B.

Installing updates and security patches of guest operating system

C.

Configuration of infrastructure devices

D.

Configuration of security groups on each instance

Full Access
Question # 189

A company needs to organize its resources and track AWS costs on a detailed level. The company needs to categorize costs by business department, environment, and application. Which solution will meet these requirements'?

A.

Access the AWS Cost Management console to organize resources set an AWS budget, and receive notifications of unintentional usage.

B.

Use tags to organize the resources. Activate cost allocation tags to track AWS costs on a detailed level.

C.

Create Amazon CloudWatch dashboards to visually organize and track costs individually.

D.

Access the AWS Billing and Cost Management dashboard to organize and track resource consumption on a detailed level.

Full Access
Question # 190

Which AWS service or tool gives users the ability to connect with AWS and deploy resources programmatically?

A.

Amazon quickSight

B.

AWS PrivateLink

C.

AWS Direct Connect

D.

AWS SDKs

Full Access
Question # 191

A company wants to monitor its workload performance. The company wants to ensure that the cloud services are delivered at a level that meets its business needs.

Which AWS Cloud Adoption Framework (AWS CAF) perspective will meet these requirements?

A.

Business

B.

Governance

C.

Platform

D.

Operations

Full Access
Question # 192

Which AWS services or features can a company use to connect the network of its on-premises data center to AWS? (Select TWO.)

A.

AWS VPN

B.

AWS Directory Service

C.

AWS Data Pipeline

D.

AWS Direct Connect

E.

AWS CloudHSM

Full Access
Question # 193

A company wants to migrate its application to AWS. The company wants to replace upfront expenses with variable payment that is based on usage.

What should the company do to meet these requirements?

A.

Use pay-as-you-go pricing.

B.

Purchase Reserved Instances.

C.

Pay less by using more.

D.

Rightsize instances.

Full Access
Question # 194

A company must archive Amazon S3 data that the company's business units no longer need to access.

Which S3 storage class will meet this requirement MOST cost-effectively?

A.

S3 Glacier Instant Retrieval

B.

S3 Glacier Flexible Retrieval

C.

S3 Glacier Deep Archive

D.

S3 One Zone-Infrequent Access (S3 One Zone-IA)

Full Access
Question # 195

A software engineer wants to launch a virtual machine (VM) and MySQL database on AWS.

Which AWS service will meet these requirements with the LEAST operational effort?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Elastic Beanstalk

C.

Amazon Lightsail

D.

Amazon EC2

Full Access
Question # 196

A company runs a MySQL database in its on-premises data center. The company wants to run a copy of this database in the AWS

Cloud.

Which AWS service would support this workload?

A.

Amazon RDS

B.

Amazon Neptune

C.

Amazon ElastiCache for Redis

D.

Amazon Quantum Ledger Database (Amazon QLDB)

Full Access
Question # 197

A company needs to identify who accessed an AWS service and what action was performed for a given time period.

Which AWS service should the company use to meet this requirement?

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Security Hub

D.

Amazon Inspector

Full Access
Question # 198

A company is running its application in the AWS Cloud. The company wants to periodically review its AWS account for cost optimization opportunities.

Which AWS service or tool can the company use to meet these requirements?

A.

AWS Cost Explorer

B.

AWS Trusted Advisor

C.

AWS Pricing

D.

AWS Budgets

Full Access
Question # 199

A company wants to integrate natural language processing (NLP) into business intelligence (Bl) dashboards. The company wants to ask questions and receive answers with relevant visualizations.

Which AWS service or tool will meet these requirements?

A.

Amazon Macie

B.

Amazon Rekognition

C.

Amazon QuickSight Q

D.

Amazon Lex

Full Access
Question # 200

A company wants to develop a shopping application that records customer orders. The application needs to use an AWS managed database service to store data.

Which AWS service should the company use to meet these requirements?

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon ElastiCache

D.

Amazon Neptune

Full Access
Question # 201

A company uses AWS for its web application. The company wants to minimize latency and perform compute operations for the application as close to end users as possible.

Which AWS service or infrastructure component will provide this functionality?

A.

AWS Regions

B.

Availability Zones

C.

Edge locations

D.

AWS Direct Connect

Full Access
Question # 202

A company deployed an application on an Amazon EC2 instance. The application ran as expected for 6 months. In the past week, users

have reported latency issues. A system administrator found that the CPU utilization was at 100% during business hours. The company

wants a scalable solution to meet demand.

Which AWS service or feature should the company use to handle the load for its application during periods of high demand?

A.

Auto Scaling groups

B.

AWS Global Accelerator

C.

Amazon Route 53

D.

An Elastic IP address

Full Access
Question # 203

A company wants to verify if multi-factor authentication (MFA) is enabled for all users within its AWS accounts.

Which AWS service or resource will meet this requirement?

A.

AWS Cost and Usage Report

B.

IAM credential reports

C.

AWS Artifact

D.

Amazon CloudFront reports

Full Access
Question # 204

To reduce costs, a company is planning to migrate a NoSQL database to AWS.

Which AWS service is fully managed and can automatically scale throughput capacity to meet database workload demands?

A.

Amazon Redshift

B.

Amazon Aurora

C.

Amazon DynamoDB

D.

Amazon RDS

Full Access
Question # 205

A company is planning to migrate to the AWS Cloud. The company is conducting organizational transformation and wants to become more responsive to customer inquiries and feedback.

Which tasks should the company perform to meet these requirements, according to the AWS Cloud Adoption

Framework (AWS CAF)? (Select TWO.)

A.

Realign teams to focus on products and value streams.

B.

Create new value propositions with new products and services.

C.

Use agile methods to rapidly iterate and evolve.

D.

Use a new data and analytics platform to create actionable insights.

E.

Migrate and modernize legacy infrastructure.

Full Access
Question # 206

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on real-time insights and answers questions about strategy?

A.

Operations

B.

People

C.

Business

D.

Platform

Full Access
Question # 207

A company is building AWS architecture to deliver real-time data feeds from an on-premises data center into an application that runs on AWS. The company needs a consistent network connection with minimal latency.

What should the company use to connect the application and the data center to meet these requirements?

A.

AWS Direct Connect

B.

Public internet

C.

AWS VPN

D.

Amazon Connect

Full Access
Question # 208

A company is launching a mobile app. The company wants customers to be able to use the app without upgrading their mobile devices.

Which pillar of the AWS Well-Architected Framework does this goal represent?

A.

Security

B.

Reliability

C.

Cost optimization

D.

Sustainability

Full Access
Question # 209

Which option is AWS responsible for under the AWS shared responsibility model?

A.

Network and firewall configuration

B.

Client-side data encryption

C.

Management of user permissions

D.

Hardware and infrastructure

Full Access
Question # 210

A company wants a customized assessment of its current on-premises environment. The company wants to understand its projected running costs in the AWS Cloud.

Which AWS service or tool will meet these requirements?

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWS Control Tower

D.

Migration Evaluator

Full Access
Question # 211

A company is running an application that is hosted on Amazon EC2 instances. The usage of the EC2 instances is higher during daytime hours than nighttime hours. The company wants to optimize the number of EC2 instances based on this usage pattern.

Which AWS service or instance purchasing option should the company use to meet these requirements?

A.

Spot Instances

B.

Reserved Instances

C.

AWS CloudFormation

D.

AWS Auto Scaling

Full Access
Question # 212

Which Amazon EC2 instan ce pricing model can provide discounts of up to 90%?

A.

Reserved Instances

B.

On-Demand

C.

Dedicated Hosts

D.

Spot Instances

Full Access
Question # 213

A company is looking for a managed machine learning (ML) service that can recommend products based on a customer's previous behaviors.

Which AWS service meets this requirement?

A.

Amazon Personalize

B.

Amazon SageMaker

C.

Amazon Pinpoint

D.

Amazon Comprehend

Full Access
Question # 214

Which options are AWS Cloud Adoption Framework (AWS CAF) cloud transformation journey

recommendations? (Select TWO.)

A.

Envision phase

B.

Align phase

C.

Assess phase

D.

Mobilize phase

E.

Migrate and modernize phase

Full Access
Question # 215

Which abilities are benefits of the AWS Cloud? (Select TWO.)

A.

Trade variable expenses for capital expenses.

B.

Deploy globally in minutes.

C.

Plan capacity in advance of deployments.

D.

Take advantage of economies of scale.

E.

Reduce dependencies on network connectivity.

Full Access
Question # 216

Which AWS service helps developers use loose coupling and reliable messaging between microservices?

A.

Elastic Load Balancing

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon CloudFront

D.

Amazon Simple Queue Service (Amazon SQS)

Full Access
Question # 217

Which AWS service provides threat detection by monitoring for malicious activities and unauthorized actions to protect AWS accounts, workloads, and data that is stored in Amazon S3?

A.

AWS Shield

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

Amazon Inspector

Full Access
Question # 218

Which AWS service or feature will search for and identify AWS resources that are shared externally?

A.

Amazon OpenSearch Service

B.

AWS Control Tower

C.

AWS IAM Access Analyzer

D.

AWS Fargate

Full Access
Question # 219

A company deployed an Amazon EC2 instance last week. A developer realizes that the EC2 instance is no longer running. The developer reviews a list of provisioned EC2 instances, and the EC2 instance is no longer on the list.

What can the developer do to generate a recent history of the EC2 instance?

A.

Run Cost Explorer to identify the start time and end time of the EC2 instance.

B.

Use Amazon Inspector to find out when the EC2 instance was stopped.

C.

Perform a search in AWS CloudTrail to find all EC2 instance-related events.

D.

Use AWS Secrets Manager to display hidden termination logs of the EC2 instance.

Full Access
Question # 220

For which AWS service is the customer responsible for maintaining the underlying operating system?

A.

Amazon DynamoDB

B.

Amazon S3

C.

Amazon EC2

D.

AWS Lambda

Full Access
Question # 221

An IT engineer needs to access AWS services from an on-premises application.

Which credentials or keys does the application need for authentication?

A.

AWS account user name and password

B.

IAM access key and secret

C.

Amazon EC2 key pairs

D.

AWS Key Management Service (AWS KMS) keys

Full Access
Question # 222

What is an AWS responsibility under the AWS shared responsibility model?

A.

Configure the security group rules that determine which ports are open on an Amazon EC2 Linux instance.

B.

Ensure the security of the internal network in the AWS data centers.

C.

Patch the guest operating system with the latest security patches on Amazon EC2.

D.

Turn on server-side encryption for Amazon S3 buckets.A company wants to deploy its critical application on AWS and maintain high availability.

Full Access
Question # 223

Which aspect of security is the customer's responsibility, according to the AWS shared responsibility model?

A.

Patch and configuration management

B.

Service and communications protection or zone security

C.

Physical and environmental controls

D.

Awareness and training

Full Access
Question # 224

Which benefit does AWS offer exclusively to users who have an AWS Enterprise Support plan?

A.

Access to a technical project manager

B.

Access to a technical account manager (TAM)

C.

Access to a cloud support engineer

D.

Access to a solutions architectA company wants to automatically set up and govern a multi-account AWS environment.

Full Access
Question # 225

A company wants to build a new web application by using AWS services. The application must meet the on-demand load for periods of heavy activity.

Which AWS services or resources provide the necessary workload adjustments to meet these requirements? (Select TWO.)

A.

Amazon Machine Image (AMI)

B.

Amazon EC2 Auto Scaling

C.

Amazon EC2 instance

D.

AWS Lambda

E.

EC2 Image Builder

Full Access
Question # 226

Which AWS service provides protection against DDoS attacks for applications that run in the AWS Cloud?

A.

Amazon VPC

B.

AWS Shield

C.

AWS Audit Manager

D.

AWS Config

Full Access
Question # 227

A company is planning to migrate to the AWS Cloud and wants to become more responsive to customer inquiries and feedback. The company wants to focus on organizational transformation.

A company wants to give its customers the ability to view specific data that is hosted in Amazon S3 buckets. The company wants to keep control over the full datasets that the company shares with the customers.

Which S3 feature will meet these requirements?

A.

S3 Storage Lens

B.

S3 Cross-Region Replication (CRR)

C.

S3 Versioning

D.

S3 Access Points

Full Access
Question # 228

Which actions are best practices for an AWS account root user? (Select TWO.)

A.

Share root user credentials with team members.

B.

Create multiple root users for the account, separated by environment.

C.

Enable multi-factor authentication (MFA) on the root user.

D.

Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user.

E.

Use programmatic access instead of the root user and password.

Full Access
Question # 229

A company uses AWS Organizations. The company wants to apply security best practices from the AWS Well-Architected Framework to all of its AWS accounts.

Which AWS service will meet these requirements?

A.

Amazon Macie

B.

Amazon Detective

C.

AWS Control Tower

D.

AWS Secrets Manager

Full Access
Question # 230

A company needs a graph database service that is scalable and highly available.

Which AWS service meets these requirements?

A.

Amazon Aurora

B.

Amazon Redshift

C.

Amazon DynamoDB

D.

Amazon Neptune

Full Access
Question # 231

A company needs to migrate a PostgreSQL database from on-premises to Amazon RDS.

Which AWS service or tool should the company use to meet this requirement?

A.

Cloud Adoption Readiness Tool

B.

AWS Migration Hub

C.

AWS Database Migration Service (AWS DMS)

D.

AWS Application Migration Service

Full Access
Question # 232

A company has a MySQL database running on a single Amazon EC2 instance. The company now requires higher availability in the event of an outage.

Which set of tasks would meet this requirement?

A.

Add an Application Load Balancer in front of the EC2 instance.

B.

Configure EC2 Auto Recovery to move the instance to another Availability Zone.

C.

Migrate to Amazon RDS and enable Multi-AZ.

D.

Enable termination protection for the EC2 instance to avoid outages.

Full Access
Question # 233

In which categories does AWS Trusted Advisor provide recommended actions? (Select TWO.)

A.

Operating system patches

B.

Cost optimization

C.

Repetitive tasks

D.

Service quotas

E.

Account activity records

Full Access
Question # 234

A company needs to apply security rules to specific Amazon EC2 instances.

Which AWS service or feature provides this functionality?

A.

AWS Shield

B.

Network ACLs

C.

Security groups

D.

AWS Firewall Manager

Full Access
Question # 235

A company plans to migrate to the AWS Cloud. The company is gathering information about its on-premises infrastructure and requires information such as the hostname, IP address, and MAC address.

Which AWS service will meet these requirements?

A.

AWS DataSync

B.

AWS Application Migration Service

C.

AWS Application Discovery Service

D.

AWS Database Migration Service (AWS DMS)

Full Access
Question # 236

A company wants to use the AWS Cloud to deploy an application globally.

Which architecture deployment model should the company use to meet this requirement?

A.

Multi-Region

B.

Single-Region

C.

Multi-AZ

D.

Single-AZ

Full Access
Question # 237

A company is running a monolithic on-premises application that does not scale and is difficult to maintain. The company has a plan to migrate the application to AWS and divide the application into microservices.

Which best practice of the AWS Well-Architected Framework is the company following with this plan?

A.

Integrate functional testing as part of AWS deployment.

B.

Use automation to deploy changes.

C.

Deploy the application to multiple locations.

D.

Implement loosely coupled dependencies.

Full Access
Question # 238

What can a cloud practitioner use to retrieve AWS security and compliance documents and submit them as evidence to an auditor or regulator?

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS Artifact

D.

Amazon Inspector

Full Access
Question # 239

A company wants to launch its web application in a second AWS Region. The company needs to determine which services must be regionally configured for this launch.

Which AWS services can be configured at the Region level? (Select TWO.)

A.

Amazon EC2

B.

Amazon Route 53

C.

Amazon CloudFront

D.

AWS WAF

E.

Amazon DynamoDB

Full Access
Question # 240

A company has a large number of Linux Amazon EC2 instances across several Availability Zones in an AWS Region. Applications that run on the EC2 instances need access to a common set of files.

Which AWS service or device should the company use to meet this requirement?

A.

AWS Backup

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

AWS Snowball Edge Storage Optimized

Full Access
Question # 241

Which company needs to apply security rules to a subnet for Amazon EC2 instances.

Which AWS service or feature provides this functionality?

A.

Network ACLs

B.

Security groups

C.

AWS Certificate Manager (ACM)

D.

AWS Config

Full Access
Question # 242

A company wants to use Amazon EC2 instances for a stable production workload that will run for 1 year.

Which instance purchasing option meets these requirements MOST cost-effectively?

A.

Dedicated Hosts

B.

Reserved Instances

C.

On-Demand Instances

D.

Spot Instances

Full Access
Question # 243

A company hosts a large amount of data in AWS. The company wants to identify if any of the data should be considered sensitive.

Which AWS service will meet the requirement?

A.

Amazon Inspector

B.

Amazon Macie

C.

AWS Identity and Access Management (IAM)

D.

Amazon CloudWatch

Full Access
Question # 244

A company is running an Amazon EC2 instance in a VPC.

An ecommerce company is using Amazon EC2 Auto Scaling groups to manage a fleet of web servers running on Amazon EC2.

This architecture follows which AWS Well-Architected Framework best practice?

A.

Secure the workload

B.

Decouple infrastructure components

C.

Design for failure

D.

Think parallel

Full Access
Question # 245

A company plans to migrate to the AWS Cloud. The company wants to use the AWS Cloud Adoption Framework (AWS CAF) to define and track business outcomes as part of its cloud transformation journey.

Which AWS CAF governance perspective capability will meet these requirements?

A.

Benefits management

B.

Risk management

C.

Application portfolio management

D.

Cloud financial management

Full Access
Question # 246

A company has a centralized group of users with large file storage requirements that have exceeded the space available on premises. The company wants to extend its file storage capabilities for this group while retaining the performance benefit of sharing content locally.

What is the MOST operationally efficient AWS solution for this scenario?

A.

Create an Amazon S3 bucket for each user. Mount each bucket by using an S3 file system mounting utility.

B.

Configure and deploy an AWS Storage Gateway file gateway. Connect each user's workstation to the file gateway.

C.

Move each user's working environment to Amazon Workspaces. Set up an Amazon WorkDocs account for each user.

D.

Deploy an Amazon EC2 instance and attach an Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS volume. Share the EBS volume directly with the users.

Full Access
Question # 247

A company is running a workload in the AWS Cloud.

Which AWS best practice ensures the MOST cost-effective architecture for the workload?

A.

Loose coupling

B.

Rightsizing

C.

Caching

D.

Redundancy

Full Access
Question # 248

A company manages factory machines in real time. The company wants to use AWS technology to deploy its monitoring applications as close to the factory machines as possible.

Which AWS solution will meet these requirements with the LEAST latency?

A.

AWS Outposts

B.

Amazon EC2

C.

AWS App Runner

D.

AWS Batch

Full Access
Question # 249

A company is collecting user behavior patterns to identify how to meet goals for sustainability impact.

Which guidelines are best practices for the company to implement to meet these goals? (Select TWO.)

A.

Scale infrastructure with user load.

B.

Maximize the geographic distance between workloads and user locations.

C.

Eliminate creation and maintenance of unused assets.

D.

Scale resources with excess capacity and remove auto scaling.

E.

Scale infrastructure based on the number of users.

Full Access
Question # 250

A company wants to migrate its server-based applications to the AWS Cloud. The company wants to determine the total cost of ownership for its compute resources that will be hosted on the AWS Cloud.

Which combination of AWS services or tools will meet these requirements?

A.

AWS Pricing Calculator

B.

Migration Evaluator

C.

AWS Support Center

D.

AWS Application Discovery Service

E.

AWS Database Migration Service (AWS DMS)

Full Access
Question # 251

A company is operating several factories where it builds products. The company needs the ability to process data, store data, and run applications with local system interdependencies that require low latency.

Which AWS service should the company use to meet these requirements?

A.

AWS loT Greengrass

B.

AWS Lambda

C.

AWS Outposts

D.

AWS Snowball Edge

Full Access
Question # 252

A developer has been hired by a large company and needs AWS credentials.

Which are security best practices that should be followed? (Select TWO.)

A.

Grant the developer access to only the AWS resources needed to perform the job.

B.

Share the AWS account root user credentials with the developer.

C.

Add the developer to the administrator's group in AWS IAM.

D.

Configure a password policy that ensures the developer's password cannot be changed.

E.

Ensure the account password policy requires a minimum length.

Full Access
Question # 253

Which AWS service converts text to lifelike voices?

A.

Amazon Transcribe

B.

Amazon Rekognition

C.

Amazon Polly

D.

Amazon Textract

Full Access
Question # 254

Which task does AWS perform automatically?

A.

Encrypt data that is stored in Amazon DynamoDB.

B.

Patch Amazon EC2 instances.

C.

Encrypt user network traffic.

D.

Create TLS certificates for users' websites.

Full Access
Question # 255

Which AWS service provides encryption at rest for Amazon RDS and for Amazon Elastic Block Store (Amazon EBS) volumes?

A.

AWS Lambda

B.

AWS Key Management Service (AWS KMS)

C.

AWSWAF

D.

Amazon Rekognition

Full Access
Question # 256

A user has a stateful workload that will run on Amazon EC2 for the next 3 years.

What is the MOST cost-effective pricing model for this workload?

A.

On-Demand Instances

B.

Reserved Instances

C.

Dedicated Instances

D.

Spot Instances

Full Access
Question # 257

A company wants to log in securely to Linux Amazon EC2 instances.

How can the company accomplish this goal?

A.

Use SSH keys.

B.

Use a VPN.

C.

Use end-to-end encryption.

D.

Use Amazon Route 53.

Full Access
Question # 258

A company is using Amazon EC2 instances.

Which tasks are the company's responsibility, according to the AWS shared responsibility model? (Select TWO.)

A.

Maintain the network infrastructure.

B.

Patch the guest operating system.

C.

Configure a security group on deployed EC2 instances.

D.

Provide physical security for the underlying hardware of the EC2 instances.

E.

Manage the underlying hypervisor.

Full Access
Question # 259

A user wants to invoke an AWS Lambda function when an Amazon EC2 instance enters the "stopping" state.

Which AWS service is appropriate for this use case?

A.

Amazon EventBridge

B.

AWS Config

C.

Amazon Simple Notification Service (Amazon SNS)

D.

AWS CloudFormation

Full Access
Question # 260

Which AWS service can a company use to directly query and analyze AWS Cost and Usage Reports?

A.

Amazon OpenSearch Service

B.

Amazon Athena

C.

Amazon Aurora

D.

AWS Glue

Full Access
Question # 261

A company is running Amazon EC2 instances in a private subnet in a VPC.

Which AWS service or feature can provide the EC2 instances with network connections to the internet?

A.

Gateway endpoint

B.

NAT gateway

C.

Network Load Balancer

D.

Amazon Route 53

Full Access
Question # 262

A company is designing AWS architecture that will add compute resources when the company needs them. The architecture also includes a disaster recovery plan with automatic failover.

A.

Reliability

B.

Operational excellence

C.

Security

D.

Performance efficiency

Full Access
Question # 263

Which design principle aligns with performance efficiency pillar of the AWS Well-Architected Framework?

A.

Using serverless architectures

B.

Scaling horizontally

C.

Measuring the cost of workloads

D.

Using managed services

Full Access