Labour Day Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Amazon Web Services > AWS Certified Foundational > CLF-C02

CLF-C02 AWS Certified Cloud Practitioner Question and Answers

Question # 4

Which AWS service provides threat detection by monitoring for malicious activities and unauthorized actions to protect AWS accounts, workloads, and data that is stored in Amazon S3?

A.

AWS Shield

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

Amazon Inspector

Full Access
Question # 5

A company wants to integrate natural language processing (NLP) into business intelligence (Bl) dashboards. The company wants to ask questions and receive answers with relevant visualizations.

Which AWS service or tool will meet these requirements?

A.

Amazon Macie

B.

Amazon Rekognition

C.

Amazon QuickSight Q

D.

Amazon Lex

Full Access
Question # 6

Which task is the customer's responsibility, according to the AWS shared responsibility model?

A.

Maintain the security of the AWS Cloud.

B.

Configure firewalls and networks.

C.

Patch the operating system of Amazon RDS instances.

D.

Implement physical and environmental controls.

Full Access
Question # 7

A company needs a bridge between technology and business to help evolve to a culture of continuous growth and learning.

Which perspective in the AWS Cloud Adoption Framework (AWS CAF) serves as this bridge?

A.

People

B.

Governance

C.

Operations

D.

Security

Full Access
Question # 8

A company has a centralized group of users with large file storage requirements that have exceeded the space available on premises. The company wants to extend its file storage capabilities for this group while retaining the performance benefit of sharing content locally.

What is the MOST operationally efficient AWS solution for this scenario?

A.

Create an Amazon S3 bucket for each user. Mount each bucket by using an S3 file system mounting utility.

B.

Configure and deploy an AWS Storage Gateway file gateway. Connect each user's workstation to the file gateway.

C.

Move each user's working environment to Amazon Workspaces. Set up an Amazon WorkDocs account for each user.

D.

Deploy an Amazon EC2 instance and attach an Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS volume. Share the EBS volume directly with the users.

Full Access
Question # 9

Which AWS Cloud service can send alerts to customers if custom spending thresholds are exceeded?

A.

AWS Budgets

B.

AWS Cost Explorer

C.

AWS Cost Allocation Tags

D.

AWS Organizations

Full Access
Question # 10

Which benefit does AWS offer exclusively to users who have an AWS Enterprise Support plan?

A.

Access to a technical project manager

B.

Access to a technical account manager (TAM)

C.

Access to a cloud support engineer

D.

Access to a solutions architect

A company wants to automatically set up and govern a multi-account AWS environment.

Full Access
Question # 11

A company has migrated its workloads to AWS. The company wants to adopt AWS at scale and operate more efficiently and securely.

Which AWS service or framework should the company use for operational support?

A.

AWS Support

B.

AWS Cloud Adoption Framework (AWS CAF)

C.

AWS Managed Services (AMS)

D.

AWS Well-Architected Framework

Full Access
Question # 12

A company wants to minimize network latency between its Amazon EC2 instances. The EC2 instances do not need to be highly available.

Which solution meets these requirements?

A.

Use EC2 instances in a single Availability Zone.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Full Access
Question # 13

A company uses AWS Organizations. The company wants to apply security best practices from the AWS Well-Architected Framework to all of its AWS accounts.

Which AWS service will meet these requirements?

A.

Amazon Macie

B.

Amazon Detective

C.

AWS Control Tower

D.

AWS Secrets Manager

Full Access
Question # 14

Which scenarios represent the concept of elasticity on AWS? (Select TWO.)

A.

Scaling the number of Amazon EC2 instances based on traffic

B.

Resizing Amazon RDS instances as business needs change

C.

Automatically directing traffic to less-utilized Amazon EC2 instances

D.

Using AWS compliance documents to accelerate the compliance process

E.

Having the ability to create and govern environments using code

Full Access
Question # 15

A company wants to migrate its PostgreSQL database to AWS. The company does not use the database frequently.

Which AWS service or resource will meet these requirements with the LEAST management overhead?

A.

PostgreSQL on Amazon EC2

B.

Amazon RDS for PostgreSQL

C.

Amazon Aurora PostgreSQL-Compatible Edition

D.

Amazon Aurora Serverless

Full Access
Question # 16

AWS has the ability to achieve lower pay-as-you-go pricing by aggregating usage across hundreds of thousands of users.

This describes which advantage of the AWS Cloud?

A.

Launch globally in minutes

B.

Increase speed and agility

C.

High economies of scale

D.

No guessing about compute capacity

Full Access
Question # 17

A company has deployed an application in the AWS Cloud. The company wants to ensure that the application is highly resilient.

Which component of AWS infrastructure can the company use to meet this requirement?

A.

Content delivery network (CDN)

B.

Edge locations

C.

Wavelength Zones

D.

Availability Zones

Full Access
Question # 18

A company uses AWS for its web application. The company wants to minimize latency and perform compute operations for the application as close to end users as possible.

Which AWS service or infrastructure component will provide this functionality?

A.

AWS Regions

B.

Availability Zones

C.

Edge locations

D.

AWS Direct Connect

Full Access
Question # 19

What is the LEAST expensive AWS Support plan that provides the full set of AWS Trusted Advisor best practice checks for cost optimization?

A.

AWS Enterprise Support

B.

AWS Business Support

C.

AWS Developer Support

D.

AWS Basic Support

Full Access
Question # 20

A company is assessing its AWS Business Support plan to determine if the plan still meets the company's needs. The company is considering switching to

AWS Enterprise Support.

Which additional benefit will the company receive with AWS Enterprise Support?

A.

A full set of AWS Trusted Advisor checks

B.

Phone, email, and chat access to cloud support engineers 24 hours a day, 7 days a week

C.

A designated technical account manager (TAM) to assist in monitoring and optimization

D.

A consultative review and architecture guidance for the company's applications

Full Access
Question # 21

A company must be able to develop, test, and launch an application in the AWS Cloud quickly.

Which advantage of cloud computing will meet these requirements?

A.

Stop guessing capacity

B.

Trade fixed expense for variable expense

C.

Achieve economies of scale

D.

Increase speed and agility

Full Access
Question # 22

A company needs to evaluate its AWS environment and provide best practice recommendations in five categories: cost, performance, service limits, fault tolerance, and security. Which AWS service can the company use to meet these requirements?

A.

AWS Shield

B.

AWS WAF

C.

AWS Trusted Advisor

D.

AWS Service Catalog

Full Access
Question # 23

According to the AWS shared responsibility model, who is responsible for the virtualization layer down to the

physical security of the facilities in which AWS services operate?

A.

It is the sole responsibility of the customer.

B.

It is the sole responsibility of AWS.

C.

It is a shared responsibility between AWS and the customer.

D.

The customer's AWS Support plan tier determines who manages the configuration.

Full Access
Question # 24

Which task can only an AWS account root user perform?

A.

Changing the AWS Support plan

B.

Deleting AWS resources

C.

Creating an Amazon EC2 instance key pair

D.

Configuring AWS WAF

Full Access
Question # 25

Which options are AWS Cloud Adoption Framework (AWS CAF) people perspective capabilities? (Select TWO.)

A.

Organizational alignment

B.

Portfolio management

C.

Organization design

D.

Risk management

E.

Modern application development

Full Access
Question # 26

Which of the following is a fully managed MySQL-compatible database?

A.

Amazon S3

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon Aurora

Full Access
Question # 27

A company wants to grant users in one AWS account access to resources in another AWS account. The users do not currently have permission to access the resources.

Which AWS service will meet this requirement?

A.

IAM group

B.

IAM role

C.

IAM tag

D.

IAM Access Analyzer

Full Access
Question # 28

Which benefits can customers gain by using AWS Marketplace? (Select TWO.)

A.

Speed of business

B.

Fewer legal objections

C.

Ability to pay with credit cards

D.

No requirement for product licenses for any products

E.

Free use of all services for the first hour

Full Access
Question # 29

A company wants high levels of detection and near-real-time (NRT) mitigation against large and sophisticated distributed denial of service (DDoS) attacks on applications running on AWS.

Which AWS service should the company use?

A.

Amazon GuardDuty

B.

Amazon Inspector

C.

AWS Shield Advanced

D.

Amazon Macie

Full Access
Question # 30

A company is operating several factories where it builds products. The company needs the ability to process data, store data, and run applications with local system interdependencies that require low latency.

Which AWS service should the company use to meet these requirements?

A.

AWS loT Greengrass

B.

AWS Lambda

C.

AWS Outposts

D.

AWS Snowball Edge

Full Access
Question # 31

Which AWS service enables companies to deploy an application dose to end users?

A.

Amazon CloudFront

B.

AWS Auto Scaling

C.

AWS AppSync

D.

Amazon Route S3

Full Access
Question # 32

A company needs to categorize and track AWS usage cost based on business categories.

Which AWS service or feature should the company use to meet these requirements?

A.

Cost allocation tags

B.

AWS Organizations

C.

AWS Security Hub

D.

AWS Cost and Usage Report

Full Access
Question # 33

Which of the following services can be used to block network traffic to an instance? (Select TWO.)

A.

Security groups

B.

Amazon Virtual Private Cloud (Amazon VPC) flow logs

C.

Network ACLs

D.

Amazon CloudWatch

E.

AWS CloudTrail

Full Access
Question # 34

A software engineer wants to launch a virtual machine (VM) and MySQL database on AWS.

Which AWS service will meet these requirements with the LEAST operational effort?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Elastic Beanstalk

C.

Amazon Lightsail

D.

Amazon EC2

Full Access
Question # 35

Which AWS Support plan is the minimum recommended tier for users who have production workloads on AWS?

A.

AWS Developer Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Enterprise On-Ramp Support

Full Access
Question # 36

A company is using a central data platform to manage multiple types of data for its customers. The company wants to use AWS services to discover, transform, and visualize the data.

Which combination of AWS services should the company use to meet these requirements? (Select TWO.)

A.

AWS Glue

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Redshift

D.

Amazon QuickSight

E.

Amazon Quantum Ledger Database (Amazon QLDB)

Full Access
Question # 37

Which AWS Cloud benefit gives a company the ability to quickly deploy cloud resources to access compute, storage, and database infrastructures in a matter of minutes?

A.

Elasticity

B.

Cost savings

C.

Agility

D.

Reliability

Full Access
Question # 38

A company needs to store data from a recommendation engine in a database.

Which AWS service provides this functionality with the LEAST operational overhead?

A.

Amazon RDS for PostgreSQL

B.

Amazon DynamoDB

C.

Amazon Neptune

D.

Amazon Aurora

Full Access
Question # 39

An auditor is preparing for an annual security audit. The auditor requests certification details for a company's AWS hosted resources across multiple Availability Zones in the us-east-1 Region.

How should the company respond to the auditor's request?

A.

Open an AWS Support ticket to request that the AWS technical account manager (TAM) respond and help the auditor.

B.

Open an AWS Support ticket to request that the auditor receive approval to conduct an onsite assessment of the AWS data centers in

which the company operates.

C.

Explain to the auditor that AWS does not need to be audited because the company's application is hosted in multiple Availability

Zones.

D.

Use AWS Artifact to download the applicable report for AWS security controls. Provide the report to the auditor.

Full Access
Question # 40

According to the AWS shared responsibility model, which task is the customer's responsibility?

A.

Maintaining the infrastructure needed to run AWS Lambda

B.

Updating the operating system of Amazon DynamoDB instances

C.

Maintaining Amazon S3 infrastructure

D.

Updating the guest operating system on Amazon EC2 instances

Full Access
Question # 41

Which AWS service or resource provides answers to the most frequently asked security-related questions that AWS receives from its users'?

A.

AWS Artifact

B.

Amazon Connect

C.

AWS Chatbot

D.

AWS Knowledge Center

Full Access
Question # 42

Which AWS service offers object storage?

A.

Amazon RDS

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon S3

D.

Amazon DynamoDB

Full Access
Question # 43

A company that is planning to migrate to the AWS Cloud is based in an isolated area that has limited internet connectivity. The company needs to perform local data processing on premises. The company needs a solution that can operate without a stable internet connection.

Which AWS service will meet these requirements?

A.

Amazon S3

B.

AWS Snowball Edge

C.

AWS StorageGateway

D.

AWS Backup

Full Access
Question # 44

A company has a single Amazon EC2 instance. The company wants to adopt a highly available architecture.

What can the company do to meet this requirement?

A.

Scale vertically to a larger EC2 instance size.

B.

Scale horizontally across multiple Availability Zones.

C.

Purchase an EC2 Dedicated Instance.

D.

Change the EC2 instance family to a compute optimized instance.

Full Access
Question # 45

A company wants to create multiple isolated networks in the same AWS account.

Which AWS service or component will provide this functionality?

A.

AWS Transit Gateway

B.

Internet gateway

C.

Amazon VPC

D.

Amazon EC2

Full Access
Question # 46

A company runs a database on Amazon Aurora in the us-east-1 Region. The company has a disaster recovery requirement that the database be available in another Region.

Which solution meets this requirement with minimal disruption to the database operations?

A.

Perform an Aurora Multi-AZ deployment.

B.

Deploy Aurora cross-Region read replicas.

C.

Create Amazon Elastic Block Store (Amazon EBS) volume snapshots for Aurora and copy them to another Region.

D.

Deploy Aurora Replicas.

Full Access
Question # 47

Which AWS service can defend against DDoS attacks?

A.

AWS Firewall Manager

B.

AWS Shield Standard

C.

AWS WAF

D.

Amazon Inspector

Full Access
Question # 48

What does "security of the cloud" refer to in the AWS shared responsibility model?

A.

Availability of AWS services such as Amazon EC2

B.

Security of the cloud infrastructure that runs all the AWS services

C.

Implementation of password policies for IAM users

D.

Security of customer environments by using AWS Network Firewall partners

Full Access
Question # 49

Which encryption types can be used to protect objects at rest in Amazon S3? (Select TWO.)

A.

Server-side encryption with AmazonS3 managed encryption keys (SSE-S3)

B.

Server-side encryption with AWS KMSmanaged keys (SSE-KMS)

C.

TLS

D.

SSL

E.

Transparent Data Encryption (TDE)

Full Access
Question # 50

Which AWS service requires the customer to patch the guest operating system?

A.

AWS Lambda

B.

Amazon OpenSearch Service

C.

Amazon EC2

D.

Amazon ElastiCache

Full Access
Question # 51

A company wants to develop a shopping application that records customer orders. The application needs to use an AWS managed database service to store data.

Which AWS service should the company use to meet these requirements?

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon ElastiCache

D.

Amazon Neptune

Full Access
Question # 52

A company has an application workload that is stateless by design and can sustain occasional downtime. The application performs massively parallel computations.

Which Amazon EC2 pricing model should the company choose for its application to reduce cost?

A.

On-Demand Instances

B.

Spot Instances

C.

Reserved Instances

D.

Dedicated Instances

Full Access
Question # 53

Which AWS service or feature can be used to control inbound and outbound traffic on an Amazon EC2 instance?

A.

Internet gateways

B.

AWS Identity and Access Management (IAM)

C.

Network ACLs

D.

Security groups

Full Access
Question # 54

How should the company deploy the application to meet these requirements?

A.

Ina single Availability Zone

B.

On AWS Direct Connect

C.

On Reserved Instances

D.

In multiple Availability Zones

Full Access
Question # 55

Which tasks are the responsibility of AWS according to the AWS shared responsibility model? (Select TWO.)

A.

Configure AWS Identity and Access Management (IAM).

B.

Configure security groups on Amazon EC2 instances.

C.

Secure the access of physical AWS facilities.

D.

Patch applications that run on Amazon EC2 instances.

E.

Perform infrastructure patching and maintenance.

Full Access
Question # 56

Which AWS service or tool provides on-demand access to AWS security and compliance reports and AWS online agreements?

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS Billing console

Full Access
Question # 57

A company must store call recordings for 6 years. The storage system should be highly durable and cost-effective.

Which AWS service meets these requirements?

A.

AWS Snowball

B.

Amazon S3

C.

AWS Storage Gateway

D.

Amazon Kinesis

Full Access
Question # 58

A new AWS user who has little cloud experience wants to build an application by using AWS services. The user wants to learn how to implement specific AWS services from other customer examples. The user also wants to ask questions to AWS experts.

Which AWS service or resource will meet these requirements?

A.

AWS Online Tech Talks

B.

AWS documentation

C.

AWS Marketplace

D.

AWS Health Dashboard

Full Access
Question # 59

A company is preparing to launch a redesigned website on AWS. Users from around the world will download digital handbooks from the website.

Which AWS solution should the company use to provide these static files securely?

A.

Amazon Kinesis Data Streams

B.

Amazon CloudFront with Amazon S3

C.

Amazon EC2 instances with an Application Load Balancer

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 60

Which task is the responsibility of AWS when using AWS services?

A.

Management of IAM user permissions

B.

Creation of security group rules for outbound access

C.

Maintenance of physical and environmental controls

D.

Application of Amazon EC2 operating system patches

Full Access
Question # 61

Which AWS service is designed to help users orchestrate a workflow process for a set of AWS Lambda functions?

A.

Amazon DynamoDB

B.

AWS CodePipeline

C.

AWS Batch

D.

AWS Step Functions

Full Access
Question # 62

A company is collecting user behavior patterns to identify how to meet goals for sustainability impact.

Which guidelines are best practices for the company to implement to meet these goals? (Select TWO.)

A.

Scale infrastructure with user load.

B.

Maximize the geographic distance between workloads and user locations.

C.

Eliminate creation and maintenance of unused assets.

D.

Scale resources with excess capacity and remove auto scaling.

E.

Scale infrastructure based on the number of users.

Full Access
Question # 63

A company manages factory machines in real time. The company wants to use AWS technology to deploy its monitoring applications as close to the factory machines as possible.

Which AWS solution will meet these requirements with the LEAST latency?

A.

AWS Outposts

B.

Amazon EC2

C.

AWS App Runner

D.

AWS Batch

Full Access
Question # 64

Which AWS service offers a global content delivery network (CDN) that helps companies securely deliver websites, videos, applications,

and APIs at high speeds with low latency?

A.

Amazon EC2

B.

Amazon CloudFront

C.

Amazon CloudWatch

D.

AWS CloudFormation

Full Access
Question # 65

Which of the following is entirely the responsibility of AWS, according to the AWS shared responsibility model?

A.

Security awareness and training

B.

Development of an IAM password policy

C.

Patching of the guest operating system

D.

Physical and environmental controls

Full Access
Question # 66

A company wants to move its iOS application development and build activities to AWS.

Which AWS service or resource should the company use for these activities?

A.

AWS CodeCommit

B.

Amazon EC2 M1 Mac instances

C.

AWS Amplify

D.

AWS App Runner

Full Access
Question # 67

Which AWS service can a company use to securely store and encrypt passwords for a database?

A.

AWS Shield

B.

AWS Secrets Manager

C.

AWS Identity and Access Management (IAM)

D.

Amazon Cognito

Full Access
Question # 68

Which benefit of the AWS Cloud helps companies achieve lower usage costs because of the aggregate usage of all AWS users?

A.

No need to guess capacity

B.

Ability to go global in minutes

C.

Economies of scale

D.

Increased speed and agility

Full Access
Question # 69

An ecommerce company wants to design a highly available application that will be hosted on multiple Amazon EC2 instances.

How should the company deploy the EC2 instances to meet these requirements?

A.

Across multiple edge locations

B.

Across multiple VPCs

C.

Across multiple Availability Zones

D.

Across multiple AWS accounts

Full Access
Question # 70

Which statements explain the business value of migration to the AWS Cloud? (Select TWO.)

A.

The migration of enterprise applications to the AWS Cloud makes these applications automatically available on mobile devices.

S B. AWS availability and security provide the ability to improve service level agreements (SLAs) while reducing risk and unplanned downtime.

B.

Companies that migrate to the AWS Cloud eliminate the need to plan for high availability and disaster recovery.

C.

Companies that migrate to the AWS Cloud reduce IT costs related to infrastructure, freeing budget for reinvestment in other

areas.

D.

Applications are modernized because migration to the AWS Cloud requires companies to rearchitect and rewrite all

enterprise applications.

Full Access
Question # 71

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

A.

Third-party vendors

B.

Customers

C.

Reseller partners

D.

Internet providers

Full Access
Question # 72

Which service is an AWS in-memory data store service?

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DynamoDB

D.

Amazon ElastiCache

Full Access
Question # 73

A company has set up a VPC in its AWS account and has created a subnet in the VPC. The company wants to make the subnet public.

Which AWS features should the company use to meet this requirement? (Select TWO.)

A.

Amazon VPC internet gateway

B.

Amazon VPC NAT gateway

C.

Amazon VPC route tables

D.

Amazon VPC network ACL

E.

Amazon EC2 security groups

Full Access
Question # 74

A company is hosting a web application on Amazon EC2 instances. The company wants to implement custom conditions to filter and control inbound web traffic.

Which AWS service will meet these requirements?

A.

Amazon GuardDuty

B.

AWSWAF

C.

Amazon Macie

D.

AWS Shield

Full Access
Question # 75

A company is using Amazon RDS.

A company is launching a critical business application in an AWS Region.

How can the company increase resilience for this application?

A.

Deploy a copy of the application in another AWS account.

B.

Deploy the application by using multiple VPCs.

C.

Deploy the application by using multiple subnets.

D.

Deploy the application by using multiple Availability Zones.

Full Access
Question # 76

A company wants to securely store Amazon RDS database credentials and automatically rotate user passwords periodically.

Which AWS service or capability will meet these requirements?

A.

Amazon S3

B.

AWS Systems Manager Parameter Store

C.

AWS Secrets Manager

D.

AWS CloudTrail

Full Access
Question # 77

Which AWS service or tool offers consolidated billing?

A.

AWS Artifact

B.

AWS Budgets

C.

AWS Organizations

D.

AWS Trusted Advisor

A company wants to limit its employees' AWS access to a portfolio of predefined AWS resources.

Full Access
Question # 78

Which credential allows programmatic access to AWS resources for use from the AWS CLI or the AWS API?

A.

User name and password

B.

Access keys

C.

SSH public keys

D.

AWS Key Management Service (AWS KMS) keys

Full Access
Question # 79

An application runs on multiple Amazon EC2 instances that access a shared file system simultaneously.

Which AWS storage service should be used?

A.

Amazon EBS

B.

Amazon EFS

C.

Amazon S3

D.

AWS Artifact

Full Access
Question # 80

A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access.

According to the AWS shared responsibility model, which task is the responsibility of the customer?

A.

Protect the global infrastructure that runs all of the services offered in the AWS Cloud.

B.

Configure logical access controls for resources, and protect account credentials.

C.

Configure the security used by managed services.

D.

Patch and back up Amazon Aurora.

Full Access
Question # 81

A user is moving a workload from a local data center to an architecture that is distributed between the local data center and the AWS Cloud.

Which type of migration is this?

A.

On-premises to cloud native

B.

Hybrid to cloud native

C.

On-premises to hybrid

D.

Cloud native to hybrid

Full Access
Question # 82

Which perspective of the AWS Cloud Adoption Framework (AWS CAF) connects technology and business?

A.

Operations

B.

People

C.

Security

D.

Governance

Full Access
Question # 83

A company needs help managing multiple AWS linked accounts that are reported on a consolidated bill.

Which AWS Support plan includes an AWS concierge whom the company can ask for assistance?

A.

AWS Developer Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Basic Support

Full Access
Question # 84

A company provides a software as a service (SaaS) application. The company has a new customer that is based in a different country.

The new customer's data needs to be hosted in that country.

Which AWS service or infrastructure component should the company use to meet this requirement?

A.

AWS Shield

B.

Amazon S3 Object Lock

C.

AWS Regions

D.

Placement groups

Full Access
Question # 85

Which aspect of security is the customer's responsibility, according to the AWS shared responsibility model?

A.

Patch and configuration management

B.

Service and communications protection or zone security

C.

Physical and environmental controls

D.

Awareness and training

Full Access
Question # 86

A company does not want to rely on elaborate forecasting to determine its usage of compute resources. Instead, the company wants to pay only for the resources that it uses. The company also needs the ability to increase or decrease its resource usage to meet business requirements.

Which pillar of the AWS Well-Architected Framework aligns with these requirements?

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Full Access
Question # 87

A company has a compliance requirement to record and evaluate configuration changes, as well as perform remediation actions on AWS resources.

Which AWS service should the company use?

A.

AWS Config

B.

AWS Secrets Manager

C.

AWS CloudTrail

D.

AWS Trusted Advisor

Full Access
Question # 88

What is an AWS responsibility under the AWS shared responsibility model?

A.

Configure the security group rules that determine which ports are open on an Amazon EC2 Linux instance.

B.

Ensure the security of the internal network in the AWS data centers.

C.

Patch the guest operating system with the latest security patches on Amazon EC2.

D.

Turn on server-side encryption for Amazon S3 buckets.

A company wants to deploy its critical application on AWS and maintain high availability.

Full Access
Question # 89

A company has an AWS-hosted website located behind an Application Load Balancer. The company wants to safeguard the website from SQL injection or cross-site scripting.

Which AWS service should the company use?

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Trusted Advisor

D.

Amazon Inspector

Full Access
Question # 90

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances. The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Full Access
Question # 91

A company has an environment that includes Amazon EC2 instances, Amazon Lightsail, and on-premises servers. The company wants to automate the security updates for its operating systems and applications.

Which solution will meet these requirements with the LEAST operational effort?

A.

Use AWS Shield to identify and manage security events.

B.

Connect to each server by using a remote desktop connection. Run an update script.

C.

Use the AWS Systems Manager Patch Manager capability.

D.

Schedule Amazon GuardDuty to run on a nightly basis.

Full Access
Question # 92

Which design principle is included in the operational excellence pillar of the AWS Well-Architected Framework?

A.

Create annotated documentation.

B.

Anticipate failure.

C.

Ensure performance efficiency.

D.

Optimize costs.

Full Access
Question # 93

A company is planning a migration to the AWS Cloud and wants to examine the costs that are associated with different workloads.

Which AWS tool will meet these requirements?

A.

AWS Budgets

B.

AWS Cost Explorer

C.

AWS Pricing Calculator

D.

AWS Cost and Usage Report

Full Access
Question # 94

Which AWS services can a company use to host and run a MySQL database? (Select TWO.)

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon S3

D.

Amazon EC2

E.

Amazon MQ

Full Access
Question # 95

Which AWS service is always available free of charge to users?

A.

Amazon Athena

B.

AWS Identity and Access Management (IAM)

C.

AWS Secrets Manager

D.

Amazon ElastiCache

A company has only basic knowledge of AWS technologies.

Full Access
Question # 96

A company wants to migrate its application to AWS. The company wants to replace upfront expenses with variable payment that is based on usage.

What should the company do to meet these requirements?

A.

Use pay-as-you-go pricing.

B.

Purchase Reserved Instances.

C.

Pay less by using more.

D.

Rightsize instances.

Full Access
Question # 97

Which options are common stakeholders for the AWS Cloud Adoption Framework (AWS CAF) platform perspective? (Select TWO.)

A.

Chief financial officers (CFOs)

B.

IT architects

C.

Chief information officers (CIOs)

D.

Chief data officers (CDOs)

E.

Engineers

Full Access
Question # 98

Which design principles should a company apply to AWS Cloud workloads to maximize sustainability and minimize environmental impact? (Select TWO.)

A.

Maximize utilization of Amazon EC2 instances.

B.

Minimize utilization of Amazon EC2 instances.

C.

Minimize usage of managed services.

D.

Force frequent application reinstallations by users.

E.

Reduce the need for users to reinstall applications.

Full Access
Question # 99

Which AWS services or tools are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks? (Select TWO.)

A.

VPC endpoint

B.

Virtual private gateway

Q C. AWS Shield Standard

C.

AWS Config

D.

AWS WAF

Full Access
Question # 100

Which AWS service is designed to help users build conversational interfaces into applications using voice and text?

A.

Amazon Lex

B.

Amazon Transcribe

C.

Amazon Comprehend

D.

Amazon Timestream

Full Access
Question # 101

A company is using AWS Organizations to configure AWS accounts.

A company is planning its migration to the AWS Cloud. The company is identifying its capability gaps by using the AWS Cloud Adoption Framework (AWS CAF) perspectives.

Which phase of the cloud transformation journey includes these identification activities?

A.

Envision

B.

Align

C.

Scale

D.

Launch

Full Access
Question # 102

A company wants to use Amazon EC2 instances to run a stateless and restartable process after business hours.

Which AWS service provides DNS resolution?

A.

Amazon CloudFront

B.

Amazon VPC

C.

Amazon Route 53

D.

AWS Direct Connect

Full Access
Question # 103

Which of the following describes an AWS Region?

A.

A specific location within a geographic area that provides high availability

B.

A set of data centers spanning multiple countries

C.

A global picture of a user's cloud computing environment

D.

A collection of databases that can be accessed from a specific geographic area only

Full Access
Question # 104

A company is reviewing the design of an application that will be migrated from on premises to a single Amazon EC2 instance.

What should the company do to make the application highly available?

A.

Provision additional EC2 instances in other Availability Zones.

B.

Configure an Application Load Balancer (ALB). Assign the EC2 instance as the ALB's target.

C.

Use an Amazon Machine Image (AMI) to create the EC2 instance.

D.

Provision the application by using an EC2 Spot Instance.

Full Access
Question # 105

Which of the following are advantages of the AWS Cloud? (Select TWO.)

A.

Trade variable expenses for capital expenses

B.

High economies of scale

C.

Launch globally in minutes

D.

Focus on managing hardware infrastructure

E.

Overprovision to ensure capacity

Full Access
Question # 106

Which option is an advantage of AWS Cloud computing that minimizes variable costs?

A.

High availability

B.

Economies of scale

C.

Global reach

D.

Agility

Full Access
Question # 107

Which option is an advantage of AWS Cloud computing that minimizes variable costs?

A.

High availability

B.

Economies of scale

C.

Global reach

D.

Agility

Full Access
Question # 108

Which AWS service or feature is used to Troubleshoot network connectivity issues between Amazon EC2 instances?

A.

AWS Certificate Manager (ACM)

B.

Internet gateway

C.

VPC Flow Logs

D.

AWS CloudHSM

Full Access
Question # 109

Which statement describes a characteristic of the AWS global infrastructure?

A.

Edge locations contain multiple AWS Regions.

B.

AWS Regions contain multiple Regional edge caches.

C.

Availability Zones contain multiple data centers.

D.

Each data center contains multiple edge locations.

Full Access
Question # 110

A company wants to deploy and manage a Docker-based application on AWS.

Which solution meets these requirements with the LEAST amount of operational overhead?

A.

An open-source Docker orchestrator on Amazon EC2 instances

B.

AWS AppSync

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

Amazon Elastic Container Service (Amazon ECS)

Full Access
Question # 111

What is the total amount of storage offered by Amazon S3?

A.

WOMB

B.

5 GB

C.

5 TB

D.

Unlimited

Full Access
Question # 112

A company uses Amazon Aurora as its database service. The company wants to encrypt its databases and database backups.

Which party manages the encryption of the database clusters and database snapshots, according to the AWS shared responsibility

model?

A.

AWS

B.

The company

C.

AWS Marketplace partners

D.

Third-party partners

Full Access
Question # 113

A company has an online shopping website and wants to store customers' credit card data. The company must meet Payment Card Industry (PCI) standards.

Which service can the company use to access AWS compliance documentation?

A.

Amazon Cloud Directory

B.

AWS Artifact

C.

AWS Trusted Advisor

D.

Amazon Inspector

Full Access
Question # 114

Which services can be used to deploy applications on AWS? (Select TWO.)

A.

AWS Elastic Beanstalk

B.

AWS Config

C.

AWS OpsWorks

Q D. AWS Application Discovery Service

D.

Amazon Kinesis

Full Access
Question # 115

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

A.

Set up multi-factor authentication (MFA) for each Workspaces user account.

B.

Ensure the environmental safety and security of the AWS infrastructure that hosts Workspaces.

C.

Provide security for Workspaces user accounts through AWS Identity and Access Management

(IAM).

D.

Configure AWS CloudTrail to log API calls and user activity.

A company stores data in an Amazon S3 bucket. The company must control who has permission to read, write,

or delete objects that the company stores in the S3 bucket.

Full Access
Question # 116

Which pillar of the AWS Well-Architected Framework focuses on the ability to run workloads effectively, gain insight into operations, and continuously improve supporting processes and procedures?

A.

Cost optimization

B.

Reliability

C.

Operational excellence

D.

Performance efficiency

Full Access
Question # 117

Which activity can companies complete by using AWS Organizations?

A.

Troubleshoot the performance of applications.

B.

Manage service control policies (SCPs).

C.

Migrate applications to microservices.

D.

Monitor the performance of applications.

Full Access
Question # 118

A company needs to use standard SQL to query and combine exabytes of structured and semi-structured data across a data warehouse, operational database, and data lake.

Which AWS service meets these requirements?

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon Athena

D.

Amazon Redshift

Full Access
Question # 119

Which of the following is a benefit of decoupling an AWS Cloud architecture?

A.

Reduced latency

B.

Ability to upgrade components independently

C.

Decreased costs

D.

Fewer components to manage

Full Access
Question # 120

Which of the following is a cost efficiency principle related to the AWS Cloud?

A.

Right-size services based on capacity requirements.

B.

Use the Billing Dashboard to access information about monthly bills.

C.

Use AWS Organizations to combine the expenses of multiple accounts into a single bill.

D.

Tag all AWS resources.

Full Access
Question # 121

Which pillar of the AWS Well-Architected Framework includes a design principle about measuring the overall efficiency of workloads in terms of business value?

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Full Access
Question # 122

Which factors affect costs in the AWS Cloud? (Select TWO.)

A.

The number of unused AWS Lambda functions

B.

The number of configured Amazon S3 buckets

C.

Inbound data transfers without acceleration

D.

Outbound data transfers without acceleration

E.

Compute resources that are currently in use

Full Access
Question # 123

Which AWS service will help a company identify the user who deleted an Amazon EC2 instance yesterday?

A.

Amazon CloudWatch

B.

AWS Trusted Advisor

C.

AWS CloudTrail

D.

Amazon Inspector

Full Access
Question # 124

In which of the following AWS services should database credentials be stored for maximum security?

A.

AWS Identity and Access Management (IAM)

B.

AWS Secrets Manager

C.

Amazon S3

D.

AWS Key Management Service (AWS KMS)

Full Access
Question # 125

Which of the following is an advantage that users experience when they move on-premises workloads to the AWS Cloud?

A.

Elimination of expenses for running and maintaining data centers

B.

Price discounts that are identical to discounts from hardware providers

C.

Distribution of all operational controls to AWS

D.

Elimination of operational expenses

Full Access
Question # 126

Which of the following are user authentication services managed by AWS? (Select TWO.)

A.

Amazon Cognito

B.

AWS Lambda

C.

AWS License Manager

D.

AWS Identity and Access Management (IAM)

E.

AWS CodeStar

Full Access
Question # 127

Which AWS service can report how AWS resource configurations have changed over time?

A.

AWS CloudTrail

B.

Amazon CloudWatch

C.

AWS Config

D.

Amazon Inspector

Full Access
Question # 128

An auditor needs to find out whether a specific AWS service is compliant with specific compliance frameworks.

Which AWS service will provide this information?

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon GuardDuty

D.

AWS Certificate Manager (ACM)

Full Access
Question # 129

A company needs to configure rules to identify threats and protect applications from malicious network access.

Which AWS service should the company use to meet these requirements?

A.

AWS Identity and Access Management (IAM)

B.

Amazon QuickSight

C.

AWS WAF

D.

Amazon Detective

Full Access
Question # 130

A company runs thousands of simultaneous simul-ations using AWS Batch. Each simul-ation is stateless, is fault tolerant, and runs for up to 3 hours.

Which pricing model enables the company to optimize costs and meet these requirements?

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

Dedicated Instances

Full Access
Question # 131

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO.)

A.

Availability

B.

Reliability

C.

Scalability

D.

Responsive design

E.

Operational excellence

Full Access
Question # 132

A company wants to centrally manage security policies and billing services within a multi-account AWS environment. Which AWS service should the company use to meet these requirements?

A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Resource Access Manager (AWS RAM)

D.

AWS Config

Full Access
Question # 133

What is an Availability Zone?

A.

A location where users can deploy compute, storage, database, and other select AWS services

where no AWS Region currently exists

B.

One or more discrete data centers with redundant power, networking, and connectivity

C.

One or more clusters of servers where new workloads can be deployed

D.

A fast content delivery network (CDN) service that securely delivers data, videos, applications, and

APIs to users globally

Full Access
Question # 134

Which benefit is included with an AWS Enterprise Support plan?

A.

AWS Partner Network (APN) support at no cost

B.

Designated support from an AWS technical account manager (TAM)

C.

On-site support from AWS engineers

D.

AWS managed compliance as code with AWS Config

Full Access
Question # 135

Which tasks are customer responsibilities according to the AWS shared responsibility model? (Select TWO.)

A.

Determine application dependencies with operating systems.

B.

Provide user access with AWS Identity and Access Management (IAM).

C.

Secure the data center in an Availability Zone.

D.

Patch the hypervisor.

E.

Provide network availability in Availability Zones.

Full Access
Question # 136

According to the AWS shared responsibility model, which of the following are AWS responsibilities? (Select TWO.)

A.

Network infrastructure and virtualization of infrastructure

B.

Security of application data

C.

Guest operating systems

D.

Physical security of hardware

E.

Credentials and policies

Full Access
Question # 137

A company has a social media platform in which users upload and share photos with other users. The company wants to identify and remove inappropriate photos. The company has no machine learning (ML) scientists and must build this detection capability with no ML expertise.

Which AWS service should the company use to build this capability?

A.

Amazon SageMaker

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Comprehend

Full Access
Question # 138

A company wants to establish a security layer in its VPC that will act as a firewall to control subnet traffic.

Which AWS service or feature will meet this requirement?

A.

Routing tables

B.

Network access control lists (network ACLs)

C.

Security groups

D.

Amazon GuardDuty

Full Access
Question # 139

Which database engine is compatible with Amazon RDS?

A.

Apache Cassandra

B.

MongoDB

C.

Neo4j

D.

PostgreSQL

Full Access
Question # 140

A company's information security manager is supervising a move to AWS and wants to ensure that AWS best practices are followed. The manager has concerns about the potential misuse of AWS account root user credentials.

Which of the following is an AWS best practice for using the AWS account root user credentials?

A.

Allow only the manager to use the account root user credentials for normal activities.

B.

Use the account root user credentials only for Amazon EC2 instances from the AWS Free Tier.

C.

Use the account root user credentials only when they alone must be used to perform a required

function.

D.

Use the account root user credentials only for the creation of private VPC subnets.

Full Access
Question # 141

A company hosts an application on an Amazon EC2 instance. The EC2 instance needs to access several AWS resources, including Amazon S3 and Amazon DynamoDB.

What is the MOST operationally efficient solution to delegate permissions?

A.

Create an IAM role with the required permissions. Attach the role to the EC2 instance.

B.

Create an IAM user and use its access key and secret access key in the application.

C.

Create an IAM user and use its access key and secret access key to create a CLI profile in the EC2 instance.

D.

Create an IAM role with the required permissions. Attach the role to the administrativeIAM user.

Full Access
Question # 142

A company needs to continuously monitor its environment to analyze network and account activity and identify potential security threats.

Which AWS service should the company use to meet these requirements?

A.

AWS Artifact

B.

Amazon Macie

C.

AWS Identity and Access Management (IAM)

D.

Amazon GuardDuty

Full Access
Question # 143

Which AWS service is a key-value database that provides sub-millisecond latency on a large scale?

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

Full Access
Question # 144

A company plans to migrate to AWS and wants to create cost estimates for its AWS use cases.

Which AWS service or tool can the company use to meet these requirements?

A.

AWS Pricing Calculator

B.

Amazon CloudWatch

C.

AWS Cost Explorer

D.

AWS Budgets

Full Access
Question # 145

A cloud practitioner is analyzing Amazon EC2 instance performance and usage to provide recommendations for potential cost savings.

Which cloud concept does this analysis demonstrate?

A.

Auto scaling

B.

Rightsizing

C.

Load balancing

D.

High availability

Full Access
Question # 146

A company is hosting a web application in a Docker container on Amazon EC2.

AWS is responsible for which of the following tasks?

A.

Scaling the web application and services developed with Docker

B.

Provisioning or scheduling containers to run on clusters and maintain their availability

C.

Performing hardware maintenance in the AWS facilities that run the AWS Cloud

D.

Managing the guest operating system, including updates and security patches

Full Access
Question # 147

Which AWS service should a cloud engineer use to view API calls to AWS services?

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Config

D.

AWS Artifact

Full Access
Question # 148

A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a

natural disaster in a particular geographic area.

Which solution achieves this goal?

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple edge locations.

D.

Use Amazon CloudFront with the EC2 instances configured as the source.

Full Access
Question # 149

A retail company is building a new mobile app. The company is evaluating whether to build the app at an on-premises data center or in the AWS Cloud.

responsibility model?

A.

Amazon FSx for Windows File Server

B.

Amazon Workspaces virtual Windows desktop

C.

AWS Directory Service for Microsoft Active Directory

D.

Amazon RDS for Microsoft SQL Server

Full Access
Question # 150

Amazon Elastic File System (Amazon EFS) and Amazon FSx offer which type of storage?

A.

File storage

B.

Object storage

C.

Block storage

D.

Instance store

Full Access
Question # 151

A company wants to host its relational databases on AWS. The databases have predefined schemas that the company needs to replicate on AWS.

Which AWS services could the company use for the databases? (Select TWO.)

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

E.

Amazon DynamoDB

Full Access
Question # 152

A cloud engineer needs to download AWS security and compliance documents for an upcoming audit.

Which AWS service can provide the documents?

A.

AWS Trusted Advisor

B.

AWS Artifact

C.

AWS Well-Architected Tool

D.

AWS Systems Manager

Full Access
Question # 153

A company is using AWS Lambda functions to build an application.

Which tasks are the company's responsibility, according to the AWS shared responsibility model? (Select TWO.)

A.

Patch the servers where the Lambda functions are deployed.

B.

Establish the IAM permissions that define who can run the Lambda functions.

C.

Write the code for the Lambda functions to define the application logic.

D.

Deploy Amazon EC2 instances to support the Lambda functions.

E.

Scale out the Lambda functions when the load increases.

Full Access
Question # 154

Which of the following are benefits that a company receives when it moves an on-premises production workload to AWS? (Select TWO.)

A.

AWS trains the company's staff on the use of all the AWS services.

B.

AWS manages all security in the cloud.

C.

AWS offers free support from technical account managers (TAMs).

D.

AWS offers high availability.

E.

AWS provides economies of scale.

Full Access
Question # 155

A security engineer wants a single-tenant AWS solution to create, control, and manage their own cryptographic keys to meet regulatory compliance requirements for data security.

Which AWS service should the engineer use?

A.

AWS Key Management Service (AWS KMS)

B.

AWS Certificate Manager (ACM)

C.

AWS CloudHSM

D.

AWS Systems Manager

Full Access
Question # 156

A company wants to use guidelines from the AWS Well-Architected Framework to limit human error and facilitate consistent responses to events.

Which of the following is a Well-Architected design principle that will meet these requirements?

A.

Use AWS CodeDeploy.

B.

Perform operations as code.

C.

Migrate workloads to a Dedicated Host.

D.

Use AWS Compute Optimizer.

Full Access
Question # 157

A company is launching a new application in the AWS Cloud. The application will run on an Amazon EC2 instance. More EC2 instances will be needed when the workload increases.

Which AWS service or tool can the company use to launch the number of EC2 instances that will be needed to handle the workload?

A.

Elastic Load Balancing

B.

Amazon EC2 Auto Scaling

C.

AWS App2Container (A2C)

D.

AWS Systems Manager

Full Access
Question # 158

Which of the following is a cloud benefit that AWS offers to its users?

A.

The ability to configure AWS data center hypervisors

B.

The ability to purchase hardware in advance of increased traffic

C.

The ability to deploy to AWS on a global scale

D.

Compliance audits for user IT environments

Full Access
Question # 159

A company is building a serverless architecture that connects application data from multiple data sources. The company needs a solution that does not require additional code.

Which AWS service meets these requirements?

A.

AWS Lambda

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon CloudWatch

D.

Amazon EventBridge

Full Access
Question # 160

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

A.

AWS CloudTrail

B.

AWS Cost and Usage Reports

C.

AWS Trusted Advisor

D.

AWS Budgets

Full Access
Question # 161

A company is designing an identity access management solution for an application. The company wants users to be able to use their social media, email, or online shopping accounts to access the application.

Which AWS service provides this functionality?

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Config

C.

Amazon Cognito

D.

AWS Identity and Access Management (IAM)

Full Access
Question # 162

A company is developing an application that uses multiple AWS services. The application needs to use

temporary, limited-privilege credentials for authentication with other AWS APIs.

Which AWS service or feature should the company use to meet these authentication requirements?

A.

Amazon API Gateway

B.

IAM users

C.

AWS Security Token Service (AWS STS)

D.

IAM instance profiles

Full Access
Question # 163

A company moves its infrastructure from on premises to the AWS Cloud. The company can now provision additional Amazon EC2 instances whenever the instances are required. With this ability, the company can launch new marketing campaigns in 3 days instead of 3 weeks.

Which benefit of the AWS Cloud does this scenario demonstrate?

A.

Cost savings

B.

Improved operational resilience

C.

Increased business agility

D.

Enhanced security

Full Access
Question # 164

A company needs to migrate all of its development teams to a cloud-based integrated development environment (IDE).

Which AWS service should the company use?

A.

AWS CodeBuild

B.

AWS Cloud9

C.

AWS OpsWorks

D.

AWS Cloud Development Kit (AWS CDK)

Full Access
Question # 165

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

A.

Perform quarterly disaster recovery tests.

B.

Place the main component on the us-east-1 Region.

C.

Design for automatic failover to healthy resources.

D.

Design workloads to fit on a single Amazon EC2 instance.

Full Access
Question # 166

Which AWS service provides the ability to manage infrastructure as code?

A.

AWS CodePipeline

B.

AWS CodeDeploy

C.

AWS Direct Connect

D.

AWS CloudFormation

Full Access
Question # 167

Which AWS service should be used when a company needs to provide its remote employees with virtual desktops?

A.

Amazon Identity and Access Management (IAM)

B.

AWS Directory Service

C.

AWS IAM Identity Center (AWS Single Sign-On)

D.

Amazon Workspaces

Full Access
Question # 168

A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify infrastructure deployments that do not meet best practices. Which AWS service can the company use to meet these requirements?

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWSConfig

D.

Amazon GuardDuty

Full Access
Question # 169

A company's headquarters is located on a different continent from where the majority of the company's customers live. The company wants an AWS Cloud environment setup that will provide the lowest latency to the customers.

A company wants to automate the creation of new AWS accounts and automatically prevent all users from creating Amazon EC2

instances.

Which AWS service provides this functionality?

A.

AWS Service Catalog

B.

AWS Organizations

C.

EC2 Image Builder

D.

AWS Systems Manager

Full Access
Question # 170

An ecommerce company wants to distribute traffic between the Amazon EC2 instances that host its website.

Which AWS service or resource will meet these requirements?

A.

Application Load Balancer

B.

AWS WAF

C.

AWS CloudHSM

D.

AWS Direct Connect

Full Access
Question # 171

A company encourages its teams to test failure scenarios regularly and to validate their understanding of the impact of potential failures.

Which pillar of the AWS Well-Architected Framework does this philosophy represent?

A.

Operational excellence

B.

Cost optimization

C.

Performance efficiency

D.

Security

Full Access
Question # 172

Which service enables customers to audit API calls in their AWS accounts'?

A.

AWS CloudTrail

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS X-Ray

Full Access
Question # 173

Which AWS service can run a managed PostgreSQL database that provides online transaction processing (OLTP)?

A.

Amazon DynamoDB

B.

Amazon Athena

C.

Amazon RDS

D.

Amazon EMR

Full Access
Question # 174

Which capabilities are in the platform perspective of the AWS Cloud Adoption Framework (AWS CAF)? (Select TWO.)

A.

Performance and capacity management

B.

Data engineering

C.

Continuous integration and continuous delivery (CI/CD)

D.

Infrastructure protection

E.

Change and release management

Full Access
Question # 175

At what support level do users receive access to a support concierge?

A.

Basic Support

B.

Developer Support

C.

Business Support

D.

Enterprise Support

Full Access
Question # 176

A company is migrating to the AWS Cloud to meet storage needs. The company wants to optimize costs based on the amount of storage that the company uses.

Which AWS offering or benefit will meet these requirements MOST cost-effectively?

A.

Pay-as-you-go pricing

B.

Savings Plans

C.

AWS Free Tier

D.

Volume-based discounts

Full Access
Question # 177

Which type of AWS storage is ephemeral and is deleted when an Amazon EC2 instance is stopped or terminated?

A.

Amazon Elastic Block Store (Amazon EBS)

B.

Amazon EC2 instance store

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3

Full Access
Question # 178

A company wants to run a NoSQL database on Amazon EC2 instances.

Which task is the responsibility of AWS in this scenario"?

A.

Update the guest operating system of the EC2 instances

B.

Maintain high availability at the database layer

C.

Patch the physical infrastructure that hosts the EC2 instances

D.

Configure the security group firewall

Full Access
Question # 179

Which tasks are the customer's responsibility, according to the AWS shared responsibility model? (Select TWO.)

A.

Establish the global infrastructure.

B.

Perform client-side data encryption.

C.

Configure 1AM credentials.

D.

Secure edge locations.

E.

Patch Amazon RDS DB instances.

Full Access
Question # 180

Which of the following is an AWS Well-Architected Framework design principle for operational excellence in the AWS Cloud?

A.

Go global in minutes

B.

Make frequent, small, reversible changes

C.

Implement a strong foundation of identity and access management

D.

Stop spending money on hardware infrastructure for data center operations

Full Access
Question # 181

A company is running a monolithic on-premises application that does not scale and is difficult to maintain. The company has a plan to migrate the application to AWS and divide the application into microservices.

Which best practice of the AWS Well-Architected Framework is the company following with this plan?

A.

Integrate functional testing as part of AWS deployment.

B.

Use automation to deploy changes.

C.

Deploy the application to multiple locations.

D.

Implement loosely coupled dependencies.

Full Access
Question # 182

A company needs to search for text in documents that are stored in Amazon S3.

Which AWS service will meet these requirements?

A.

Amazon Kendra

B.

Amazon Rekognition

C.

Amazon Polly

D.

Amazon Lex

Full Access
Question # 183

Which AWS service or feature allows users to create new AWS accounts, group multiple accounts to organize workflows, and apply policies to groups of accounts?

A.

AWS Identity and Access Management (1AM)

B.

AWS Trusted Advisor

C.

AWS CloudFormation

D.

AWS Organizations

Full Access