Summer Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

CLF-C02 Questions and Answers

Question # 6

Which AWS service is always provided at no charge?

A.

Amazon S3

B.

AWS Identity and Access Management (IAM)

C.

Elastic Load Balancers

D.

AWS WAF

Full Access
Question # 7

A company wants to create a globally accessible ecommerce platform for its customers. The company wants to use a highly available and scalable DNS web service to connect users to the platform.

Which AWS service will meet these requirements?

A.

Amazon EC2

B.

Amazon VPC

C.

Amazon Route 53

D.

Amazon RDS

Full Access
Question # 8

A company needs a firewall that will control network connections to and from a single Amazon EC2 instance. This firewall will not control network connections to and from other instances that are in the same subnet.

Which AWS service or feature can the company use to meet these requirements?

A.

Network ACL

B.

AWS WAF

C.

Route table

D.

Security group

Full Access
Question # 9

A company has multiple SQL-based databases located in a data center. The company needs to migrate all database servers to the AWS Cloud to reduce the cost of operating physical servers.

Which AWS service or resource will meet these requirements with the LEAST operational overhead?

A.

Amazon EC2 instances

B.

Amazon RDS

C.

Amazon DynamoDB

D.

OpenSearch

Full Access
Question # 10

A company is using multiple AWS accounts for different business teams. The finance team wants to receive one bill for all of the company's accounts.

Which AWS service or tool should the finance team use to meet this requirement?

A.

AWS Organizations

B.

AWS Trusted Advisor

C.

Cost Explorer

D.

AWS Budgets

Full Access
Question # 11

A company wants to discover, prepare, move, and integrate data from multiple sources for data analytics and machine learning.

Which AWS serverless data integration service should the company use to meet these requirements?

A.

AWS Glue

B.

AWS Data Exchange

C.

Amazon Athena

D.

Amazon EMR

Full Access
Question # 12

A company wants to add a conversational chatbot to its website.

Which AWS service can the company use to meet this requirement?

A.

Amazon Textract

B.

Amazon Lex

C.

AWS Glue

D.

Amazon Rekognition

Full Access
Question # 13

A company needs a managed NFS file system that the company can use with its AWS compute....

Which AWS service or feature will meet these requirements?

A.

Amazon Elastic Block Store (Amazon EBS)

B.

AWS Storage Gateway Tape Gateway

C.

Amazon S3 Glacier Flexible Retrieval

D.

Amazon Elastic Pile System (Amazon EFS)

Full Access
Question # 14

Which task is the responsibility of the customer, according to the AWS shared responsibility model?

A.

Patch the Amazon DynamoDB operating system.

B.

Secure Amazon CloudFront edge locations by allowing physical access according to the principle of least privilege.

C.

Protect the hardware that runs AWS services.

D.

Use AWS Identity and Access Management (1AM) according to the principle of least privilege.

Full Access
Question # 15

A company wants to establish a private network connection between AWS and its corporate network.

Which AWS service or feature will meet this requirement?

A.

Amazon Connect

B.

Amazon Route 53

C.

AWS Direct Connect

D.

VPC peering

Full Access
Question # 16

An administrator observed that multiple AWS resources were deleted yesterday.

Which AWS service will help identify the cause and determine which user deleted the resources?

A.

AWS CtoudTrail

B.

Amazon Inspector

C.

Amazon GuardDuty

D.

AWS Trusted Advisor

Full Access
Question # 17

Which task is the customer's responsibility, according to the AWS shared responsibility model?

A.

Patch a guest operating system that is deployed on an Amazon EC2 instance.

B.

Control physical access to an AWS data center

C.

Control access to AWS underlying hardware.

D.

Patch a host operating system that is deployed on Amazon S3.

Full Access
Question # 18

Which characteristic of the AWS Cloud helps users eliminate underutilized CPU capacity'?

A.

Agility

B.

Elasticity

C.

Reliability

D.

Durability

Full Access
Question # 19

Which programming languages does AWS Cloud Development Kit (AWS CDK) currently support? (Select TWO.)

A.

Python

B.

Swift

C.

TypeScript

D.

Ruby

E.

PHP

Full Access
Question # 20

A company wants to use the latest technologies and wants to minimize its capital investment. Instead of upgrading on-premises infrastructure, the company wants to move to the AWS Cloud.

Which AWS Cloud benefit does this scenario describe?

A.

Increased speed to market

B.

The trade of infrastructure expenses for operating expenses

C.

Massive economies of scale

D.

The ability to go global in minutes

Full Access
Question # 21

Which AWS Cloud Adoption Framework (AWS CAF) capability belongs to the people perspective?

A.

Data architecture

B.

Event management

C.

Cloud fluency

D.

Strategic partnership

Full Access
Question # 22

Elasticity in the AWS Cloud refers to which of the following? (Select TWO.)

A.

How quickly an Amazon EC2 instance can be restarted

B.

The ability to rightsized resources as demand shifts

C.

The maximum amount of RAM an Amazon EC2 instance can use

D.

The pay-as-you-go billing model

E.

How easily resources can be procured when they are needed

Full Access
Question # 23

A company is migrating its workloads to the AWS Cloud. The company must retain full control of patch management for the guest operating systems that host its applications.

Which AWS service should the company use to meet these requirements?

A.

Amazon DynamoDB

B.

Amazon EC2

C.

AWS Lambda

D.

Amazon RDS

Full Access
Question # 24

A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify infrastructure deployments that do not meet best practices. Which AWS service can the company use to meet these requirements?

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWSConfig

D.

Amazon GuardDuty

Full Access
Question # 25

A company is planning to migrate to the AWS Cloud. The company is conducting organizational transformation and wants to become more responsive to customer inquiries and feedback.

Which tasks should the company perform to meet these requirements, according to the AWS Cloud Adoption

Framework (AWS CAF)? (Select TWO.)

A.

Realign teams to focus on products and value streams.

B.

Create new value propositions with new products and services.

C.

Use agile methods to rapidly iterate and evolve.

D.

Use a new data and analytics platform to create actionable insights.

E.

Migrate and modernize legacy infrastructure.

Full Access
Question # 26

A company wants to migrate its application to AWS. The company wants to replace upfront expenses with variable payment that is based on usage.

What should the company do to meet these requirements?

A.

Use pay-as-you-go pricing.

B.

Purchase Reserved Instances.

C.

Pay less by using more.

D.

Rightsize instances.

Full Access
Question # 27

A company website is experiencing DDoS attacks.

Which AWS service can help protect the company website against these attacks?

A.

AWS Resource Access Manager

B.

AWS Amplify

C.

AWS Shield

D.

Amazon GuardDuty

Full Access
Question # 28

Which AWS service or feature can a company use to apply security rules to specific Amazon EC2 instances?

A.

Network ACLs

B.

Security groups

C.

AWS Trusted Advisor

D.

AWS WAF

Full Access
Question # 29

A company needs to identify who accessed an AWS service and what action was performed for a given time period.

Which AWS service should the company use to meet this requirement?

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Security Hub

D.

Amazon Inspector

Full Access
Question # 30

Which of the following is a software development framework that a company can use to define cloud resources as code and provision the resources through AWS CloudFormation?

A.

AWS CLI

B.

AWS Developer Center

C.

AWS Cloud Development Kit (AWS CDK)

D.

AWS CodeStar

Full Access
Question # 31

A company is running its application in the AWS Cloud and wants to protect against a DDoS attack. The company's security team wants near real-time visibility into DDoS attacks.

Which AWS service or traffic filter will meet these requirements with the MOST features for DDoS protection?

A.

AWS Shield Advanced

B.

AWS Shield

C.

Amazon GuardDuty

D.

Network ACLs

Full Access
Question # 32

According to the AWS shared responsibility model, which task is the customer's responsibility?

A.

Maintaining the infrastructure needed to run AWS Lambda

B.

Updating the operating system of Amazon DynamoDB instances

C.

Maintaining Amazon S3 infrastructure

D.

Updating the guest operating system on Amazon EC2 instances

Full Access
Question # 33

A company is hosting an application in the AWS Cloud. The company wants to verify that underlying AWS services and general AWS infrastructure are operating normally.

Which combination of AWS services can the company use to gather the required information? (Select TWO.)

A.

AWS Personal Health Dashboard

B.

AWS Systems Manager

C.

AWS Trusted Advisor

D.

AWS Service Health Dashboard

E.

AWS Service Catalog

Full Access
Question # 34

What is the purpose of having an internet gateway within a VPC?

A.

To create a VPN connection to the VPC

B.

To allow communication between the VPC and the internet

C.

To impose bandwidth constraints on internet traffic

D.

To load balance traffic from the internet across Amazon EC2 instances

Full Access
Question # 35

Which options are AWS Cloud Adoption Framework (AWS CAF) people perspective capabilities? (Select TWO.)

A.

Organizational alignment

B.

Portfolio management

C.

Organization design

D.

Risk management

E.

Modern application development

Full Access
Question # 36

Which AWS service provides threat detection by monitoring for malicious activities and unauthorized actions to protect AWS accounts, workloads, and data that is stored in Amazon S3?

A.

AWS Shield

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

Amazon Inspector

Full Access
Question # 37

Which AWS services can be used to store files? (Select TWO.)

A.

Amazon S3

B.

AWS Lambda

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon SageMaker

E.

AWS Storage Gateway

Full Access
Question # 38

A customer runs an On-Demand Amazon Linux EC2 instance for 3 hours, 5 minutes, and 6 seconds.

For how much time will the customer be billed?

A.

3 hours, 5 minutes

B.

3 hours, 5 minutes, and 6 seconds

C.

3 hours, 6 minutes

D.

4 hours

Full Access
Question # 39

A company wants a list of all users in its AWS account, the status of all of the users' access keys, and if multi-factor authentication (MFA) has been configured.

Which AWS service or feature will meet these requirements?

A.

AWS Key Management Service (AWS KMS)

B.

IAM Access Analyzer

C.

IAM credential report

D.

Amazon CloudWatch

Full Access
Question # 40

A company wants to store data with high availability, encrypt the data at rest, and have direct access to the data over the internet.

Which AWS service will meet these requirements MOST cost-effectively?

A.

Amazon Elastic Block Store (AmazonEBS)

B.

Amazon S3

C.

Amazon Elastic File System (Amazon EFS)

D.

AWS Storage Gateway

Full Access
Question # 41

Which option is the default pricing model for Amazon EC2 instances?

A.

On-Demand Instances

B.

Savings Plans

C.

Spot Instances

D.

Reserved Instances

Full Access
Question # 42

A company has a single Amazon EC2 instance. The company wants to adopt a highly available architecture.

What can the company do to meet this requirement?

A.

Scale vertically to a larger EC2 instance size.

B.

Scale horizontally across multiple Availability Zones.

C.

Purchase an EC2 Dedicated Instance.

D.

Change the EC2 instance family to a compute optimized instance.

Full Access
Question # 43

In which categories does AWS Trusted Advisor provide recommended actions? (Select TWO.)

A.

Operating system patches

B.

Cost optimization

C.

Repetitive tasks

D.

Service quotas

E.

Account activity records

Full Access
Question # 44

A company manages factory machines in real time. The company wants to use AWS technology to deploy its monitoring applications as close to the factory machines as possible.

Which AWS solution will meet these requirements with the LEAST latency?

A.

AWS Outposts

B.

Amazon EC2

C.

AWS App Runner

D.

AWS Batch

Full Access
Question # 45

Which AWS service or feature can be used to control inbound and outbound traffic on an Amazon EC2 instance?

A.

Internet gateways

B.

AWS Identity and Access Management (IAM)

C.

Network ACLs

D.

Security groups

Full Access
Question # 46

A company seeks cost savings in exchange for a commitment to use a specific amount of an AWS service or category ofAWS services for 1 year or 3 years.

Which AWS pricing model or offering will meet these requirements?

A.

Pay-as-you-go pricing

B.

Savings Plans

C.

AWS Free Tier

D.

Volume discounts

Full Access
Question # 47

Which of the following actions are controlled with AWS Identity and Access Management (IAM)? (Select TWO.)

A.

Control access to AWS service APIs and to other specific resources.

B.

Provide intelligent threat detection and continuous monitoring.

C.

Protect the AWS environment using multi-factor authentication (MFA).

D.

Grant users access to AWS data centers.

E.

Provide firewall protection for applications from common web attacks.

Full Access
Question # 48

A company is building an application that needs to deliver images and videos globally with minimal latency.

Which approach can the company use to accomplish this in a cost effective manner?

A.

Deliver the content through Amazon CloudFront.

B.

Store the content on Amazon S3 and enable S3 cross-region replication.

C.

Implement a VPN across multiple AWS Regions.

D.

Deliver the content through AWS PrivateLink.

Full Access
Question # 49

A company needs a graph database service that is scalable and highly available.

Which AWS service meets these requirements?

A.

Amazon Aurora

B.

Amazon Redshift

C.

Amazon DynamoDB

D.

Amazon Neptune

Full Access
Question # 50

Which benefits can customers gain by using AWS Marketplace? (Select TWO.)

A.

Speed of business

B.

Fewer legal objections

C.

Ability to pay with credit cards

D.

No requirement for product licenses for any products

E.

Free use of all services for the first hour

Full Access
Question # 51

A company is storing sensitive customer data in an Amazon S3 bucket. The company wants to protect the data from accidental deletion or overwriting.

Which S3 feature should the company use to meet these requirements?

A.

S3 Lifecycle rules

B.

S3 Versioning

C.

S3 bucket policies

D.

S3 server-side encryption

Full Access
Question # 52

A company migrated its core application onto multiple workloads in the AWS Cloud. The company wants to improve the application's reliability.

Which cloud design principle should the company implement to achieve this goal?

A.

Maximize utilization.

B.

Decouple the components.

C.

Rightsize the resources.

D.

Adopt a consumption model.

Full Access
Question # 53

A company provides a web-based ecommerce service that runs in two Availability Zones within a single AWS Region. The web service distributes content that is stored in the Amazon S3 Standard storage class. The company wants to improve the web service's performance globally.

What should the company do to meet this requirement?

A.

Change the S3 storage class to S3 Intelligent-Tiering.

B.

Deploy an Amazon CloudFront distribution to cache web server content in edge locations.

C.

Use Amazon API Gateway for the web service.

D.

Migrate the website ecommerce servers to Amazon EC2 with enhanced networking.

Full Access
Question # 54

A company that has multiple business units wants to centrally manage and govern its AWS Cloud environments. The company wants to automate the creation of AWS accounts, apply service control policies (SCPs), and simplify billing processes.

Which AWS service or tool should the company use to meet these requirements?

A.

AWS Organizations

B.

Cost Explorer

C.

AWS Budgets

D.

AWS Trusted Advisor

Full Access
Question # 55

Which statements explain the business value of migration to the AWS Cloud? (Select TWO.)

A.

The migration of enterprise applications to the AWS Cloud makes these applications automatically available on mobile devices.S B. AWS availability and security provide the ability to improve service level agreements (SLAs) while reducing risk and unplanned downtime.

B.

Companies that migrate to the AWS Cloud eliminate the need to plan for high availability and disaster recovery.

C.

Companies that migrate to the AWS Cloud reduce IT costs related to infrastructure, freeing budget for reinvestment in otherareas.

D.

Applications are modernized because migration to the AWS Cloud requires companies to rearchitect and rewrite allenterprise applications.

Full Access
Question # 56

Which option is AWS responsible for under the AWS shared responsibility model?

A.

Network and firewall configuration

B.

Client-side data encryption

C.

Management of user permissions

D.

Hardware and infrastructure

Full Access
Question # 57

An IT engineer needs to access AWS services from an on-premises application.

Which credentials or keys does the application need for authentication?

A.

AWS account user name and password

B.

IAM access key and secret

C.

Amazon EC2 key pairs

D.

AWS Key Management Service (AWS KMS) keys

Full Access
Question # 58

An ecommerce company wants to distribute traffic between the Amazon EC2 instances that host its website.

Which AWS service or resource will meet these requirements?

A.

Application Load Balancer

B.

AWS WAF

C.

AWS CloudHSM

D.

AWS Direct Connect

Full Access
Question # 59

A company is running its application in the AWS Cloud. The company wants to periodically review its AWS account for cost optimization opportunities.

Which AWS service or tool can the company use to meet these requirements?

A.

AWS Cost Explorer

B.

AWS Trusted Advisor

C.

AWS Pricing

D.

AWS Budgets

Full Access
Question # 60

A company wants to migrate its on-premises application to the AWS Cloud. The company is legally obligated to retain certain data in its onpremises data center.

Which AWS service or feature will support this requirement?

A.

AWS Wavelength

B.

AWS Local Zones

C.

VMware Cloud on AWS

D.

AWS Outposts

Full Access
Question # 61

Which actions are examples of a company's effort to right size its AWS resources to control cloud costs? (Select TWO.)

A.

Switch from Amazon RDS to Amazon DynamoDB to accommodate NoSQL datasets.Q B. Base the selection of Amazon EC2 instance types on past utilization patterns.

B.

Use Amazon S3 Lifecycle policies to move objects that users access infrequently to lower-cost storage tiers.

C.

Use Multi-AZ deployments for Amazon RDS.

D.

Replace existing Amazon EC2 instances with AWS Elastic Beanstalk.

Full Access
Question # 62

A company wants a time-series database service that makes it easier to store and analyze trillions of events each day.

Which AWS service will meet this requirement?

A.

Amazon Neptune

B.

Amazon Timestream

C.

Amazon Forecast

D.

Amazon DocumentDB (with MongoDB compatibility)

Full Access
Question # 63

A company wants to set AWS spending targets and track costs against those targets.

Which AWS tool or feature should the company use to meet these requirements?

A.

AWS Cost Explorer

B.

AWS Budgets

C.

AWS Cost and Usage Report

D.

Savings Plans

Full Access
Question # 64

According to the AWS shared responsibility model, who is responsible for the virtualization layer down to the

physical security of the facilities in which AWS services operate?

A.

It is the sole responsibility of the customer.

B.

It is the sole responsibility of AWS.

C.

It is a shared responsibility between AWS and the customer.

D.

The customer's AWS Support plan tier determines who manages the configuration.

Full Access
Question # 65

A company wants to migrate a database from an on-premises environment to Amazon RDS.

After the migration is complete, which management task will the company still be responsible for?

A.

Hardware lifecycle management

B.

Application optimization

C.

Server maintenance

D.

Power, network, and cooling provisioning

Full Access
Question # 66

Which actions are best practices for an AWS account root user? (Select TWO.)

A.

Share root user credentials with team members.

B.

Create multiple root users for the account, separated by environment.

C.

Enable multi-factor authentication (MFA) on the root user.

D.

Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user.

E.

Use programmatic access instead of the root user and password.

Full Access
Question # 67

A company wants to develop a shopping application that records customer orders. The application needs to use an AWS managed database service to store data.

Which AWS service should the company use to meet these requirements?

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon ElastiCache

D.

Amazon Neptune

Full Access
Question # 68

A company wants to minimize network latency between its Amazon EC2 instances. The EC2 instances do not need to be highly available.

Which solution meets these requirements?

A.

Use EC2 instances in a single Availability Zone.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Full Access
Question # 69

A company must store call recordings for 6 years. The storage system should be highly durable and cost-effective.

Which AWS service meets these requirements?

A.

AWS Snowball

B.

Amazon S3

C.

AWS Storage Gateway

D.

Amazon Kinesis

Full Access
Question # 70

A company encourages its teams to test failure scenarios regularly and to validate their understanding of the impact of potential failures.

Which pillar of the AWS Well-Architected Framework does this philosophy represent?

A.

Operational excellence

B.

Cost optimization

C.

Performance efficiency

D.

Security

Full Access
Question # 71

Which AWS service provides storage that can be mounted across multiple Amazon EC2 instances?

A.

Amazon Workspaces

B.

Amazon Elastic File System (Amazon EFS)

C.

AWS Database Migration Service (AWS DMS)

D.

AWS Snowball Edge

Full Access
Question # 72

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

A.

Sustainability

B.

Security

C.

Performance efficiency

D.

Reliability

Full Access
Question # 73

A company wants to build a new web application by using AWS services. The application must meet the on-demand load for periods of heavy activity.

Which AWS services or resources provide the necessary workload adjustments to meet these requirements? (Select TWO.)

A.

Amazon Machine Image (AMI)

B.

Amazon EC2 Auto Scaling

C.

Amazon EC2 instance

D.

AWS Lambda

E.

EC2 Image Builder

Full Access
Question # 74

Which AWS service converts text to lifelike voices?

A.

Amazon Transcribe

B.

Amazon Rekognition

C.

Amazon Polly

D.

Amazon Textract

Full Access
Question # 75

A company is building an application in the AWS Cloud. The company wants to use temporary credentials for the application to access other AWS resources.

Which AWS service will meet these requirements?

A.

AWS Key Management Service (Aws KMS)

B.

AWS CloudHSM

C.

Amazon Cognito

D.

AWS Security Token Service (Aws STS)

Full Access
Question # 76

Which of the following is a fully managed MySQL-compatible database?

A.

Amazon S3

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon Aurora

Full Access
Question # 77

A company wants to use an AWS networking solution that can act as a centralized gateway between multiple VPCs and on-premises networks. Which AWS service or feature will meet this requirement?

A.

Gateway VPC endpoint

B.

AWS Direct Connect

C.

AWS Transit Gateway

D.

AWS PrivateLink

Full Access
Question # 78

Which AWS service can generate information that can be used by external auditors?

A.

Amazon Cognito

B.

Amazon FSx

C.

AWS Config

D.

Amazon Inspector

Full Access
Question # 79

Which AWS service provides machine learning capability to detect and analyze content in images and videos?

A.

Amazon Connect

B.

Amazon Lightsail

C.

Amazon Personalize

D.

Amazon Rekognition

Full Access
Question # 80

For which AWS service is the customer responsible for maintaining the underlying operating system?

A.

Amazon DynamoDB

B.

Amazon S3

C.

Amazon EC2

D.

AWS Lambda

Full Access
Question # 81

A company is preparing for an audit and wants documentation that AWS complies with the Payment Card Industry Data Security Standard (PCI DSS).

Where can the company find this documentation?

A.

AWS Artifact

B.

AWS Organizations

C.

AWS Trusted Advisor

D.

AWS Support Center

Full Access
Question # 82

What can a cloud practitioner use to retrieve AWS security and compliance documents and submit them as evidence to an auditor or regulator?

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS Artifact

D.

Amazon Inspector

Full Access
Question # 83

Which cloud concept is demonstrated by using AWS Compute Optimizer?

A.

Security validation

B.

Rightsizing

C.

Elasticity

D.

Global reach

Full Access
Question # 84

Which Amazon S3 storage class is the MOST cost-effective for long-term storage?

A.

S3 Glacier Deep Archive

B.

S3 Standard

C.

S3 Standard-Infrequent Access (S3 Standard-IA)

D.

S3 One Zone-Infrequent Access (S3 One Zone-IA)

Full Access
Question # 85

A company wants to monitor for misconfigured security groups that are allowing unrestricted access to specific ports.

Which AWS service will meet this requirement?

A.

AWS Trusted Advisor

B.

Amazon CloudWatch

C.

Amazon GuardDuty

D.

AWS Health Dashboard

Full Access
Question # 86

Which AWS service or feature should a company use between two microservices to ensure that messages are sent and received in exact order?

A.

Amazon Simple Email Service (Amazon SES)

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon S3 Event Notifications

D.

Amazon Simple Queue Service (Amazon SQS) FIFO queues

Full Access
Question # 87

A company needs to request temporary, limited-privilege credentials for IAM users and for the federated users that the company authenticates.

Which AWS service will provide these credentials?

A.

Amazon GuardDuty

B.

AWS Key Management Service (AWS KMS)

C.

AWS Security Token Service (AWS STS)

D.

AWS Identity and Access Management Access Analyzer

Full Access
Question # 88

A company has an Amazon S3 bucket containing images of scanned financial invoices. The company is building an artificial intelligence (Al)-based application on AWS. The company wants the application to identify and read total balance amounts on the invoices.

Which AWS service will meet these requirements?

A.

Amazon Forecast

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Lex

Full Access
Question # 89

A company wants to provide one of its employees with access to Amazon RDS. The company also wants to limit the interaction to only the AWS CLl and AWS software development kits (SDKs).

Which combination of actions should the company take to meet these requirements while following the principles of least privilege? (Select TWO)

A.

Create an 1AM user and provide AWS Management Console access only.

B.

Create an 1AM user and provide programmatic access only.

C.

Create an 1AM role and provide AWS Management Console access only.

D.

Create an 1AM policy with administrator access and attach it to the 1AM user.

E.

Create an 1AM policy with Amazon RDS access and attach it to the 1AM user.

Full Access
Question # 90

Which AWS service can a company use to build conversational chatbots for customer service?

A.

Amazon Lex

B.

AWS Amplify

C.

Amazon Comprehend

D.

Amazon Polly

Full Access
Question # 91

A company needs access to checks and recommendations that help the company follow AWS best practices for cost optimization, security, fault tolerance, performance, and service quotas.

Which combination of an AWS service and AWS Support plan on the AWS account will meet these requirements?

A.

AWS Trusted Advisor with AWS Developer Support

B.

AWS Health Dashboard with AWS Enterprise Support

C.

AWS Trusted Advisor with AWS Business Support

D.

AWS Health Dashboard with AWS Enterprise On-Ramp Support

Full Access
Question # 92

A company's IT administrator needs to configure the AWS CLI for programmatic access to AWS services for the company's employees. Which combination of credential components must the IT administrator use to meet this requirement? (Select TWO.)

A.

A public key

B.

A secret access key

C.

An IAM role

D.

An access key ID

E.

A private key

Full Access
Question # 93

A company needs to store infrequently used data for data archives and long-term backups.

Which AWS service or storage class will meet these requirements MOST cost-effectively?

A.

Amazon FSx for Lustre

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3 Glacier Flexible Retrieval

Full Access
Question # 94

A company wants to move its iOS application development and build activities to AWS.

Which AWS service or resource should the company use for these activities?

A.

AWS CodeCommit

B.

Amazon EC2 M1 Mac instances

C.

AWS Amplify

D.

AWS App Runner

Full Access
Question # 95

A company is releasing a business-critical application. Before the release, the company needs strategic planning assistance from AWS. During the release, the company needs AWS infrastructure event management and real-time support.

What should the company do to meet these requirement?

A.

Access AWS Trusted Advisor.

B.

Contact the AWS Partner Network (APN).

C.

Sign up for AWS Enterprise Support.

D.

Contact AWS Professional Services.

Full Access
Question # 96

A company is building a web application using AWS.

Which AWS service will help prevent network layer DDoS attacks against the web application?

A.

AWS WAF

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

AWS Shield

Full Access
Question # 97

Which action should a company take to improve security in its AWS account?

A.

Require multi-factor authentication (MFA) for privileged users.

B.

Remove the root user account.

C.

Create an access key for the AWS account root user.

D.

Create an access key for each privileged user.

Full Access
Question # 98

A company needs to establish a dedicated network connection from on premises to AWS. The connection must provide consistent, low-latency network performance.

Which AWS service should the company use to meet this requirement?

A.

AWS Direct Connect

B.

AWS Site-to-Site VPN

C.

AWS Directory Service

D.

AWS Transit Gateway

Full Access
Question # 99

A company is moving some of its on-premises IT services to the AWS Cloud. The finance department wants to see the entire bill so it can forecast spending limits.

Which AWS service can the company use to set spending limits and receive notifications if those limits are exceeded?

A.

AWS Cost and Usage Reports

B.

AWS Budgets

C.

AWS Organizations consolidated billing

D.

Cost Explorer

Full Access
Question # 100

Which best practice for cost governance does this example show?

A.

Resource controls

B.

Cost allocation

C.

Architecture optimization

D.

Tagging enforcement

Full Access
Question # 101

Which AWS solution gives companies the ability to use protocols such as NFS to store and retrieve objects in Amazon S3?

A.

Amazon FSx for Lustre

B.

AWS Storage Gateway volume gateway

C.

AWS Storage Gateway file gateway

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 102

An application is running on multiple Amazon EC2 instances. The company wants to make the application highly available by configuring a load balancer with requests forwarded to the EC2 instances based on URL paths.

Which AWS load balancer will meet these requirements and take the LEAST amount of effort to deploy?

A.

Network Load Balancer

B.

Application Load Balancer

C.

AWS OpsWorks Load Balancer

D.

Custom Load Balancer on Amazon EC2

Full Access
Question # 103

A company needs to store data across multiple Availability Zones in an AWS Region. The data will not be

accessed regularly but must be immediately retrievable.

Which Amazon Elastic File System (Amazon EFS) storage class meets these requirements MOST cost effectively?

A.

EFS Standard

B.

EFS Standard-Infrequent Access(EFS Standard-IA)

C.

EFS One Zone

D.

EFS One Zone-Infrequent Access (EFS One Zone-IA)

Full Access
Question # 104

An Availability Zone consists of:

A.

one or more data centers in a single location.

B.

two or more data centers in multiple locations.

C.

one or more physical hosts in a single data center.

D.

two or more physical hosts in multiple data centers.

Full Access
Question # 105

A company wants to manage access and permissions for its third-party software as a service (SaaS)

applications. The company wants to use a portal where end users can access assigned AWS accounts and AWS Cloud applications.

Which AWS service should the company use to meet these requirements?

A.

Amazon Cognito

B.

AWS IAM Identity Center (AWS Single Sign-On)

C.

AWS Identity and Access Management (IAM)

D.

AWS Directory Service for Microsoft Active Directory

Full Access
Question # 106

A company wants to migrate to the AWS Cloud. The company needs the ability to acquire resources when the resources are necessary.

The company also needs the ability to release those resources when the resources are no longer necessary.

Which architecture concept of the AWS Cloud meets these requirements?

A.

Elasticity

B.

Availability

C.

Reliability

D.

Durability

Full Access
Question # 107

A company has an environment that includes Amazon EC2 instances, Amazon Lightsail, and on-premises servers. The company wants to automate the security updates for its operating systems and applications.

Which solution will meet these requirements with the LEAST operational effort?

A.

Use AWS Shield to identify and manage security events.

B.

Connect to each server by using a remote desktop connection. Run an update script.

C.

Use the AWS Systems Manager Patch Manager capability.

D.

Schedule Amazon GuardDuty to run on a nightly basis.

Full Access
Question # 108

Which activity is a customer responsibility in the AWS Cloud according to the AWS shared responsibility model?

A.

Ensuring network connectivity from AWS to the internet

B.

Patching and fixing flaws within the AWS Cloud infrastructure

C.

Ensuring the physical security of cloud data centers

D.

Ensuring Amazon EBS volumes are backed up

Full Access
Question # 109

A company needs to design a solution for the efficient use of compute resources for an enterprise workload. The company needs to make informed decisions as its technology needs evolve.

Which pillar of the AWS Well-Architected Framework do these requirements represent?

A.

Operational excellence

B.

Performance efficiency

C.

Cost optimization

D.

Reliability

Full Access
Question # 110

Which statement describes a characteristic of the AWS global infrastructure?

A.

Edge locations contain multiple AWS Regions.

B.

AWS Regions contain multiple Regional edge caches.

C.

Availability Zones contain multiple data centers.

D.

Each data center contains multiple edge locations.

Full Access
Question # 111

A company plans to migrate to AWS and wants to create cost estimates for its AWS use cases.

Which AWS service or tool can the company use to meet these requirements?

A.

AWS Pricing Calculator

B.

Amazon CloudWatch

C.

AWS Cost Explorer

D.

AWS Budgets

Full Access
Question # 112

Which of the following is the customer's responsibility, according to the AWS shared responsibility model?

A.

Identity and access management

B.

Hard drive initialization

C.

Protection of data center hardware

D.

Security of Availability Zones

Full Access
Question # 113

Which services can be used to deploy applications on AWS? (Select TWO.)

A.

AWS Elastic Beanstalk

B.

AWS Config

C.

AWS OpsWorksQ D. AWS Application Discovery Service

D.

Amazon Kinesis

Full Access
Question # 114

Which benefit is included with an AWS Enterprise Support plan?

A.

AWS Partner Network (APN) support at no cost

B.

Designated support from an AWS technical account manager (TAM)

C.

On-site support from AWS engineers

D.

AWS managed compliance as code with AWS Config

Full Access
Question # 115

A security engineer wants a single-tenant AWS solution to create, control, and manage their own cryptographic keys to meet regulatory compliance requirements for data security.

Which AWS service should the engineer use?

A.

AWS Key Management Service (AWS KMS)

B.

AWS Certificate Manager (ACM)

C.

AWS CloudHSM

D.

AWS Systems Manager

Full Access
Question # 116

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Full Access
Question # 117

Which AWS service is a highly available and scalable DNS web service?

A.

Amazon VPC

B.

Amazon CloudFront

C.

Amazon Route 53

D.

Amazon Connect

Full Access
Question # 118

A company wants an in-memory data store that is compatible with open source in the cloud.

Which AWS service should the company use?

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon Redshift

Full Access
Question # 119

A company needs to use dashboards and charts to analyze insights from business data.

Which AWS service will provide the dashboards and charts for these insights?

A.

Amazon Macie

B.

Amazon Aurora

C.

Amazon QuickSight

D.

AWS CloudTrail

Full Access
Question # 120

Which activity can companies complete by using AWS Organizations?

A.

Troubleshoot the performance of applications.

B.

Manage service control policies (SCPs).

C.

Migrate applications to microservices.

D.

Monitor the performance of applications.

Full Access
Question # 121

A company runs thousands of simultaneous simul-ations using AWS Batch. Each simul-ation is stateless, is fault tolerant, and runs for up to 3 hours.

Which pricing model enables the company to optimize costs and meet these requirements?

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

Dedicated Instances

Full Access
Question # 122

Who is responsible for decommissioning end-of-life underlying storage devices that are used to host data on AWS?

A.

Customer

B.

AWS

C.

Account creator

D.

Auditing team

Full Access
Question # 123

Which of the following are advantages of the AWS Cloud? (Select TWO.)

A.

Trade variable expenses for capital expenses

B.

High economies of scale

C.

Launch globally in minutes

D.

Focus on managing hardware infrastructure

E.

Overprovision to ensure capacity

Full Access
Question # 124

A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access.

According to the AWS shared responsibility model, which task is the responsibility of the customer?

A.

Protect the global infrastructure that runs all of the services offered in the AWS Cloud.

B.

Configure logical access controls for resources, and protect account credentials.

C.

Configure the security used by managed services.

D.

Patch and back up Amazon Aurora.

Full Access
Question # 125

A company wants to use Amazon EC2 instances to run a stateless and restartable process after business hours.

Which AWS service provides DNS resolution?

A.

Amazon CloudFront

B.

Amazon VPC

C.

Amazon Route 53

D.

AWS Direct Connect

Full Access
Question # 126

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

A.

Perform quarterly disaster recovery tests.

B.

Place the main component on the us-east-1 Region.

C.

Design for automatic failover to healthy resources.

D.

Design workloads to fit on a single Amazon EC2 instance.

Full Access
Question # 127

Using Amazon Elastic Container Service (Amazon ECS) to break down a monolithic architecture into microservices is an example of:

A.

a loosely coupled architecture.

B.

a tightly coupled architecture.

C.

a stateless architecture.

D.

a stateful architecture.

Full Access
Question # 128

A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a

natural disaster in a particular geographic area.

Which solution achieves this goal?

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple edge locations.

D.

Use Amazon CloudFront with the EC2 instances configured as the source.

Full Access
Question # 129

Which AWS Support plan provides customers with access to an AWS technical account manager (TAM)?

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Full Access
Question # 130

A company wants to use a managed service to simplify the setup, operation, and scaling of its MySQL database in the AWS Cloud.

Which AWS service will meet these requirements?

A.

Amazon EMR

B.

Amazon RDS

C.

Amazon Redshift

D.

Amazon DynamoDB

Full Access
Question # 131

Which AWS service or tool offers consolidated billing?

A.

AWS Artifact

B.

AWS Budgets

C.

AWS Organizations

D.

AWS Trusted AdvisorA company wants to limit its employees' AWS access to a portfolio of predefined AWS resources.

Full Access
Question # 132

When a user wants to utilize their existing per-socket, per-core, or per-virtual machine software licenses for a Microsoft Windows server running on AWS, which Amazon EC2 instance type is required?

A.

Spot Instances

B.

Dedicated Instances

C.

Dedicated Hosts

D.

Reserved Instances

Full Access
Question # 133

A company does not want to rely on elaborate forecasting to determine its usage of compute resources. Instead, the company wants to pay only for the resources that it uses. The company also needs the ability to increase or decrease its resource usage to meet business requirements.

Which pillar of the AWS Well-Architected Framework aligns with these requirements?

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Full Access
Question # 134

Which design principle aligns with performance efficiency pillar of the AWS Well-Architected Framework?

A.

Using serverless architectures

B.

Scaling horizontally

C.

Measuring the cost of workloads

D.

Using managed services

Full Access
Question # 135

Which AWS services and features are provided to all customers at no charge? (Select TWO.)

A.

Amazon Aurora

B.

VPC

C.

Amazon SageMaker

D.

AWS Identity and Access Management (IAM)

E.

Amazon Polly

Full Access
Question # 136

Which task is a customer's responsibility, according to the AWS shared responsibility model?

A.

Management of the guest operating systems

B.

Maintenance of the configuration of infrastructure devices

C.

Management of the host operating systems and virtualization

D.

Maintenance of the software that powers Availability ZonesA company has refined its workload to use specific AWS services to improve efficiency and reduce cost.

Full Access
Question # 137

A user wants to identify any security group that is allowing unrestricted incoming SSH traffic.

Which AWS service can be used to accomplish this goal?

A.

Amazon Cognito

B.

AWS Shield

C.

Amazon Macie

D.

AWS Trusted Advisor

Full Access
Question # 138

Which of the following is entirely the responsibility of AWS, according to the AWS shared responsibility model?

A.

Security awareness and training

B.

Development of an IAM password policy

C.

Patching of the guest operating system

D.

Physical and environmental controls

Full Access
Question # 139

Which design principles should a company apply to AWS Cloud workloads to maximize sustainability and minimize environmental impact? (Select TWO.)

A.

Maximize utilization of Amazon EC2 instances.

B.

Minimize utilization of Amazon EC2 instances.

C.

Minimize usage of managed services.

D.

Force frequent application reinstallations by users.

E.

Reduce the need for users to reinstall applications.

Full Access
Question # 140

Which AWS features will meet these requirements? (Select TWO.)

A.

Security groups

B.

Network ACLs

C.

S3 bucket policies

D.

IAM user policies

E.

S3 bucket versioning

Full Access
Question # 141

Which of the following describes an AWS Region?

A.

A specific location within a geographic area that provides high availability

B.

A set of data centers spanning multiple countries

C.

A global picture of a user's cloud computing environment

D.

A collection of databases that can be accessed from a specific geographic area only

Full Access
Question # 142

A company is hosting a web application in a Docker container on Amazon EC2.

AWS is responsible for which of the following tasks?

A.

Scaling the web application and services developed with Docker

B.

Provisioning or scheduling containers to run on clusters and maintain their availability

C.

Performing hardware maintenance in the AWS facilities that run the AWS Cloud

D.

Managing the guest operating system, including updates and security patches

Full Access
Question # 143

Which AWS benefit is demonstrated by on-demand technology services that enable companies to replace upfront fixed expenses with variable expenses?

A.

High availability

B.

Economies of scale

C.

Pay-as-you-go pricing

D.

Global reach

Full Access
Question # 144

Which AWS services or features can control VPC traffic? (Select TWO.)

A.

Security groups

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

Network ACLs

E.

Amazon Connect

Full Access
Question # 145

Which AWS service or tool helps companies measure the environmental impact of their AWS usage?

A.

AWS customer carbon footprint tool

B.

AWS Compute Optimizer

C.

Sustainability pillar

D.

OS-Climate (Open Source Climate Data Commons)

Full Access
Question # 146

A company is migrating a relational database server to the AWS Cloud. The company wants to minimize

administrative overhead of database maintenance tasks.

Which AWS service will meet these requirements?

A.

Amazon DynamoDB

B.

Amazon EC2

C.

Amazon Redshift

D.

Amazon RDS

Full Access
Question # 147

A company wants to deploy and manage a Docker-based application on AWS.

Which solution meets these requirements with the LEAST amount of operational overhead?

A.

An open-source Docker orchestrator on Amazon EC2 instances

B.

AWS AppSync

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

Amazon Elastic Container Service (Amazon ECS)

Full Access
Question # 148

Amazon Elastic File System (Amazon EFS) and Amazon FSx offer which type of storage?

A.

File storage

B.

Object storage

C.

Block storage

D.

Instance store

Full Access
Question # 149

A company needs to reserve a certain amount of Amazon EC2 compute resources in a specific Availability Zone within an AWS Region. Which purchasing option should the company use to meet this requirement?

A.

EC2 Instance Savings Plans

B.

Compute Savings Plans

C.

Regional Reserved Instances

D.

Zonal Reserved Instances

Full Access
Question # 150

A company is building AWS architecture to deliver real-time data feeds from an on-premises data center into an application that runs on AWS. The company needs a consistent network connection with minimal latency.

What should the company use to connect the application and the data center to meet these requirements?

A.

AWS Direct Connect

B.

Public internet

C.

AWS VPN

D.

Amazon Connect

Full Access
Question # 151

A company is moving Us development and test environments to AWS to increase agility and reduce cost. Because these are not production workloads and the servers are not fully utilized, occasional unavailability is acceptable.

What is the MOST cost-effective Amazon EC2 pricing model that will meet these requirements?

A.

Reserved instances

B.

On-Demand Instances

C.

Spot Instances

D.

Dedicated Hosts

Full Access
Question # 152

Which AWS service provides on-premises applications with low-latency access to data that is stored in the AWS Cloud?

A.

Amazon CloudFront

B.

AWS Storage Gateway

C.

AWS Backup

D.

AWS DataSync

Full Access
Question # 153

A company has multiple AWS accounts. The company needs to receive a consolidated bill from AWS and must centrally manage security and compliance. Which AWS service or feature should the company use to meet these requirements?

A.

AWS Cost and Usage Report

B.

AWS Organizations

C.

AWS Config

D.

AWS Security Hub

Full Access
Question # 154

A company wants to minimize network latency between its Amazon EC2 instances. The EC2 instances do not need to be highly available. Which solution meets these requirements?

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple edge locations.

C.

Use EC2 instances in the same Availability Zone but in different AWS Regions.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Full Access
Question # 155

Which AWS service is a fully managed NoSQL database service?

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon DynamoDB

D.

Amazon Aurora

Full Access
Question # 156

A company wants a report that lists the status of multi-factor authentication (MFA) devices that all users in the company's AWS account use.

Which AWS feature or service will meet this requirement?

A.

AWS Cost and Usage Reports

B.

IAM credential reports

C.

Detailed Billing Reports

D.

AWS Cost Explorer reports

Full Access
Question # 157

A company wants to know more about the benefits offered by cloud computing. The company wants to understand the operational advantage of agility.

How does AWS provide agility for users?

A.

The ability the ensure high availability by deploying workloads to multiple regions.

B.

A pay-as-you-go model for many services and resources

C.

The ability to transfer infrastructure management to the AWS Cloud

D.

The ability to provision and deprovision resources quickly with minimal effort

Full Access
Question # 158

Which AWS service provides storage-optimized and compute-optimized device configurations?

A.

AWS Snowcone

B.

AWS Storage Gateway

C.

AWS Snowball Edge

D.

AWS DataSync

Full Access
Question # 159

A company is building a business intelligence solution that uses Amazon Redshift. The company wants to use an AWS service to create interactive dashboards and not pay any upfront costs for it.

Which service should the company use?

A.

Amazon CloudWatch

B.

AWS Health Dashboard

C.

AWS Service Catalog

D.

Amazon QuickSight

Full Access
Question # 160

A company wants to securely rehost databases to AWS with minimal downtime. Which AWS service will meet these requirements?

A.

AWS Database Migration Service (AWS DMS)

B.

AWS Snow Family

C.

AWSDataSync

D.

AWS Mainframe Modernization

Full Access
Question # 161

A company runs a legacy workload in an on-premises data center. The company wants to migrate the workload to AWS. The company does not want to make any changes to the workload.

Which migration strategy should the company use?

A.

Repurchase

B.

Replatform

C.

Rehost

D.

Refactor

Full Access
Question # 162

A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account.

Which AWS service or resource should the company use to meet this requirement?

A.

AWS Security Hub

B.

AWS Marketplace

C.

AWS Quick Starts

D.

AWS Security Center

Full Access
Question # 163

Treating infrastructure as code in the AWS Cloud allows users to:

A.

automate migration of on-premises hardware to AWS data centers.

B.

let a third party automate an audit of the AWS infrastructure.

C.

turn over application code to AWS so it can run on the AWS infrastructure.

D.

automate the infrastructure provisioning process.

Full Access
Question # 164

Which task is a responsibility of AWS, according to the AWS shared responsibility model?

A.

Configure identity and access management for applications.

B.

Manage encryption options for data that is stored on AWS.

C.

Configure security groups for Amazon EC2 instances.

D.

Maintain the physical hardware of the infrastructure.

Full Access
Question # 165

A cloud engineer wants to store data in Amazon S3. The engineer will access some of the data yearly and some of the data dally.

Which S3 storage class will meet these requirements MOST cost-effectively?

A.

S3 Standard

B.

S3 Glacier Deep Archive

C.

S3 One Zone-Infrequent Access (S3 One Zone-IA)

D.

S3 Intelligent-Tiering

Full Access
Question # 166

A developer needs to use a standardized template to create copies of a company's AWS architecture for development test, and production environments. Which AWS service should the developer use to meet this requirement?

A.

AWS Cloud Map

B.

AWS Cloud Formation

C.

Amazon CloudFront

D.

AWS CloudTrail

Full Access
Question # 167

A company has an on-premises application. The application has processing times of less than 5 minutes and is invoked only a few times each day. The company wants to move the application to the AWS Cloud.

Which AWS service will support this application MOST cost-effectively?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Lambda

C.

Amazon Elastic Kubernetes Service (Amazon EKS)

D.

Amazon EC2

Full Access
Question # 168

A company wants to secure its consumer web application by using SSL/TLS to encrypt traffic.

Which AWS service can the company use to meet this goal?

A.

AWS WAF

B.

AWS Shield

C.

Amazon VPC

D.

AWS Certificate Manager (ACM)

Full Access
Question # 169

Which AWS service can create a private network connection from on premises to the AWS Cloud?

A.

AWS Config

B.

Virtual Private Cloud (Amazon VPC)

C.

AWS Direct Connect

D.

Amazon Route 53

Full Access
Question # 170

A company hosts an application on an Amazon EC2 instance. The EC2 instance needs to access several AWS resources, including Amazon S3 and Amazon DynamoDB.

What is the MOST operationally efficient solution to delegate permissions?

A.

Create an IAM role with the required permissions. Attach the role to the EC2 instance.

B.

Create an IAM user and use its access key and secret access key in the application.

C.

Create an IAM user and use its access key and secret access key to create a CLI profile in the EC2 instance.

D.

Create an IAM role with the required permissions. Attach the role to the administrativeIAM user.

Full Access
Question # 171

Which AWS service or feature is used to send both text and email messages from distributed applications?

A.

Amazon Simple Notification Service (Amazon SNS)

B.

Amazon Simple Email Service (Amazon SES)

C.

Amazon CloudWatch alerts

D.

Amazon Simple Queue Service (Amazon SQS)

Full Access
Question # 172

Which AWS services or tools are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks? (Select TWO.)

A.

VPC endpoint

B.

Virtual private gatewayQ C. AWS Shield Standard

C.

AWS Config

D.

AWS WAF

Full Access
Question # 173

Which AWS service gives users the ability to provision a dedicated and private network connection from their internal

network to AWS?

A.

AWS CloudHSM

B.

AWS Direct Connect

C.

AWS VPN

D.

Amazon Connect

Full Access
Question # 174

Which AWS service can a company use to perform complex analytical queries?

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon ElastiCache

Full Access
Question # 175

Which AWS service provides highly durable object storage?

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon FSx

Full Access
Question # 176

Which AWS service allows users to model and provision AWS resources using common programming languages?

A.

AWS CloudFormation

B.

AWS CodePipeline

C.

AWS Cloud Development Kit (AWS CDK)

D.

AWS Systems Manager

Full Access
Question # 177

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on organizing an inventory of data products in a data catalog?

A.

Operations

B.

Governance

C.

Business

D.

Platform

Full Access
Question # 178

A user wants to invoke an AWS Lambda function when an Amazon EC2 instance enters the "stopping" state.

Which AWS service is appropriate for this use case?

A.

Amazon EventBridge

B.

AWS Config

C.

Amazon Simple Notification Service (Amazon SNS)

D.

AWS CloudFormation

Full Access
Question # 179

Which AWS service helps users plan and track their server and application inventory migration data to AWS?

A.

Amazon CloudWatch

B.

AWS DataSync

C.

AWS Migration Hub

D.

AWS Application Migration Service

Full Access
Question # 180

A company wants to securely access an Amazon S3 bucket from an Amazon EC2 instance without accessing the internet.

What should the company use to accomplish this goal?

A.

VPN connection

B.

Internet gateway

C.

VPC endpoint

D.

NAT gateway

Full Access
Question # 181

Which AWS services can host PostgreSQL databases? (Select TWO.)

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

Amazon OpenSearch Service

E.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 182

A user wants to review all Amazon S3 buckets with ACLs and S3 bucket policies in the S3 console. Which AWS service or resource will meet this requirement?

A.

S3 Multi-Region Access Points

B.

S3 Storage Lens

C.

AWS IAM Identity Center

D.

Access Analyzer for S3

Full Access
Question # 183

A cloud practitioner wants a repeatable way to deploy identical AWS resources by using infrastructure templates. Which AWS service will meet these requirements?

A.

AWS CloudFormation

B.

AWS Directory Service

C.

Amazon Lightsail

D.

AWS CodeDeploy

Full Access
Question # 184

Which design principle is related to the reliability pillar according to the AWS Well-Architected Framework?

A.

Test recovery procedures

B.

Experiment more often

C.

Go global in minutes

D.

Analyze and attribute to expenditure

Full Access
Question # 185

A company wants its Amazon EC2 instances to be in different locations but share the same geographic area. The company also wants to use multiple power grids and independent networking connectivity for the EC2 instances.

Which solution meets these requirements?

A.

Use EC2 instances in multiple edge locations in the same AWS Region.

B.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

C.

Use EC2 instances in multiple Amazon Connect locations in the same AWS Region

D.

Use EC2 instances in multiple AWS Artifact locations in the same AWS Region.

Full Access
Question # 186

A company wants to rightsize its Amazon EC2 instances.

Which configuration change will meet this requirement with the LEAST operational overhead?

A.

Add EC2 instances in another Availability Zone.

B.

Change the size and type of the EC2 instances based on utilization.

C.

Convert the payment method from On-Demand to Savings Plans.

D.

Reprovision the EC2 instances with a larger instance type.

Full Access
Question # 187

A company needs to create a portfolio that provides central management of approved IT services. Which AWS service offers this functionality?

A.

AWS Service Catalog

B.

AWS Control Tower

C.

AWS Cloud Map

D.

AWS Clean Rooms

Full Access
Question # 188

Which AWS service or feature allows users to securely store encrypted credentials and retrieve these credentials when required?

A.

AWS Encryption SDK

B.

AWS Security Hub

C.

AWS Secrets Manager

D.

AWS Artifact

Full Access
Question # 189

Which design principles are included in the reliability pillar of the AWS Well-Architected Framework? (Select TWO.)

A.

Automatically recover from failure.

B.

Grant everyone access to increase AWS service quotas.

C.

Stop guessing capacity.

D.

Design applications to run in a single Availability Zone.

E.

Plan to increase AWS service quotas first in a secondary AWS Region.

Full Access
Question # 190

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance state changes to RUNNING.

Which AWS service can the company use to meet this requirement?

A.

Amazon SageMaker

B.

Amazon Connect

C.

Amazon EventBridge

D.

AWS Fargate

Full Access
Question # 191

Which AWS service or resource can a company use to deploy AWS WAF rules?

A.

Amazon EC2

B.

Application Load Balancer

C.

AWS Trusted Advisor

D.

Network Load Balancer

Full Access
Question # 192

Which of the following are features of network ACLs as they are used in the AWS Cloud? (Select TWO.)

A.

They are stateless.

B.

They are stateful.

C.

They evaluate all rules before allowing traffic.

D.

They process rules in order, starting with the lowest numbered rule, when deciding whether to allow traffic.

E.

They operate at the instance level.

Full Access
Question # 193

Where can users find examples of AWS Cloud solution designs?

A.

AWS Marketplace

B.

AWS Service Catalog

C.

AWS Architecture Center

D.

AWS Trusted Advisor

Full Access
Question # 194

A company's gaming application has been gaining popularity. There has been high demand for the gaming application in countries where the company does not currently deploy the application.

Which advantage of the AWS Cloud can help the company to deploy the application to more countries around the world?

A.

Increase speed and agility

B.

Go global in minutes

C.

Trade fixed expense for variable expense

D.

Benefit from massive economies of scale

Full Access
Question # 195

A company's workload can recover with minimal downtime when failures occur. Which AWS Cloud benefit does this scenario represent?

A.

Agility

B.

Elasticity

C.

Resiliency

D.

Scalability

Full Access
Question # 196

A company is connecting multiple VPCs and on-premises networks. The company needs to use an AWS service as a cloud router to simplify peering relationships.

Which AWS service can the company use to meet this requirement?

A.

AWS Direct Connect

B.

AWS Transit Gateway

C.

Amazon Connect

D.

Amazon Route 53

Full Access
Question # 197

Which of the following AWS services are serverless? (Select TWO.)

A.

AWS Outposts

B.

Amazon EC2

C.

Amazon Elastic Kubernetes Service (Amazon EKS)

D.

AWS Fargate

E.

AWS Lambda

Full Access
Question # 198

Which AWS service or tool inspects a user's AWS environment and makes recommendations for cost savings and system performance improvements?

A.

Cost Explorer

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS Budgets

Full Access
Question # 199

Which AWS service provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning (ML)?

A.

Amazon Kendra

B.

Amazon SageMaker

C.

Amazon Augmented Al (Amazon A2I)

D.

Amazon Polly

Full Access
Question # 200

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

A.

AWS CloudTrail

B.

AWS Cost and Usage Reports

C.

AWS Trusted Advisor

D.

AWS Budgets

Full Access
Question # 201

Which pillar of the AWS Well-Architected Framework focuses on the ability to run workloads effectively, gain insight into operations, and continuously improve supporting processes and procedures?

A.

Cost optimization

B.

Reliability

C.

Operational excellence

D.

Performance efficiency

Full Access
Question # 202

A company plans to migrate its on-premises workload to AWS. Before the migration, the company needs to estimate its future AWS service costs.

Which AWS service or tool should the company use to meet this requirement?

A.

AWS Trusted Advisor

B.

AWS Budgets

C.

AWS Pricing Calculator

D.

AWS Cost Explorer

Full Access
Question # 203

Which AWS service or tool provides a visualization of historical AWS spending patterns and projections of future AWS costs?

A.

AWS Cos! and Usage Report

B.

AWS Budgets

C.

Cost Explorer

D.

Amazon CloudWatch

Full Access
Question # 204

company wants to protect its AWS Cloud information, systems, and assets while performing risk assessment and mitigation tasks.

Which pillar of the AWS Well-Architected Framework is supported by these goals?

A.

Reliability

B.

Security

C.

Operational excellence

D.

Performance efficiency

Full Access
Question # 205

A company wants to host its relational databases on AWS. The databases have predefined schemas that the company needs to replicate on AWS.

Which AWS services could the company use for the databases? (Select TWO.)

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

E.

Amazon DynamoDB

Full Access
Question # 206

Which benefits does a company gain when the company moves from on-premises IT architecture to the AWS Cloud? (Select TWO.)

A.

Reduced or eliminated tasks for hardware troubleshooting, capacity planning, and procurement

B.

Elimination of the need for trained IT staff

C.

Automatic security configuration of all applications that are migrated to the cloud

D.

Elimination of the need for disaster recovery planning

E.

Faster deployment of new features and applications

Full Access
Question # 207

An ecommerce company has deployed a new web application on Amazon EC2 Instances. The company wants to distribute incoming HTTP traffic evenly across all running instances.

Which AWS service or resource will meet this requirement?

A.

Amazon EC2 Auto Scaling

B.

Application Load Balancer

C.

Gateway Load Balancer

D.

Network Load Balancer

Full Access
Question # 208

A company has a physical tape library to store data backups. The tape library is running out of space. The company needs to extend the tape library's capacity to the AWS Cloud.

Which AWS service should the company use to meet this requirement?

A.

Amazon Elastic File System (Amazon EFS)

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon S3

D.

AWS Storage Gateway

Full Access
Question # 209

A company wants to build, tram, and deploy machine learning (ML) models.

Which AWS service can the company use to meet this requirement?

A.

Amazon Personalize

B.

Amazon Comprehend

C.

Amazon Forecast

D.

Amazon SageMaker

Full Access
Question # 210

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on real-time insights and answers questions about strategy?

A.

Operations

B.

People

C.

Business

D.

Platform

Full Access
Question # 211

A company has a compute workload that is steady, predictable, and uninterruptible.

Which Amazon EC2 instance purchasing options meet these requirements MOST cost-effectively? (Select TWO.)

A.

On-Demand Instances

B.

Reserved Instances

C.

Spot Instances

D.

Saving Plans

E.

Dedicated Hosts

Full Access
Question # 212

What is the recommended use case for Amazon EC2 On-Demand Instances?

A.

A steady-state workload that requires a particular EC2 instance configuration for a long period of time

B.

A workload that can be interrupted for a project that requires the lowest possible cost

C.

An unpredictable workload that does not require a long-term commitment

D.

A workload that is expected to run for longer than 1 year

Full Access
Question # 213

Which AWS Support plan provides the full set to AWS Trusted Advisor checks at the LOWEST cost?

A.

AWS Developer Support

B.

AWS Business Support

C.

AWS Enterprise On-Ramp Support

D.

AWS Enterprise Support

Full Access
Question # 214

A company wants to automatically add and remove Amazon EC2 instances. The company wants the EC2 instances to adjust to varying workloads dynamically.

Which service or feature will meet these requirements?

A.

Amazon DynamoDB

B.

Amazon EC2 Spot Instances

C.

AWS Snow Family

D.

Amazon EC2 Auto Scaling

Full Access
Question # 215

Which of the following is a fully managed graph database service on AWS?

A.

Amazon Aurora

B.

Amazon FSx

C.

Amazon DynamoDB

D.

Amazon Neptune

Full Access
Question # 216

An independent software vendor wants to deliver and share its custom Amazon Machine images (AMIs) to prospective customers.

Which AWS service will meet these requirements?

A.

AWS Marketplace

B.

AWS Data Exchange

C.

Amazon EC2

D.

AWS Organizations

Full Access
Question # 217

Which mechanism allows developers to access AWS services from application code?

A.

AWS Software Development Kit

B.

AWS Management Console

C.

AWS CodePipeline

D.

AWS Config

Full Access
Question # 218

A company wants to deploy a web application as a containerized application. The company wants to use a managed service that can automatically create container images from source code and deploy the containerized application.

Which AWS service will meet these requirements?

A.

AWS Elastic Beanstalk

B.

Amazon Elastic Container Service (Amazon ECS)

C.

AWS App Runner

D.

Amazon EC2

Full Access
Question # 219

Which AWS services or features give users the ability to create a network connection between two VPCs? (Select TWO.)

A.

VPC endpoints

B.

Amazon Route 53

C.

VPC peering

D.

AWS Direct Connect

E.

AWS Transit Gateway

Full Access
Question # 220

Which combination of AWS services can be used to move a commercial relational database to an Amazon-managed open-source database? (Select TWO.)

A.

AWS Database Migration Service (AWS DMS)

B.

AWS software development kits (SDKs)

C.

AWS Schema Conversion Tool

D.

AWS Systems Manager

E.

Amazon EMR

Full Access
Question # 221

A company needs to convert video files and audio files to a format that will play on smartphones.

Which AWS service will meet this requirement?

A.

Amazon Comprehend

B.

Amazon Rekognition

C.

Amazon Elastic Transcoder

D.

Amazon Polly

Full Access
Question # 222

A user wants to allow applications running on an Amazon EC2 instance to make calls to other AWS services. The access granted must be secure. Which AWS service or feature should be used?

A.

Security groups

B.

AWS Firewall Manager

C.

IAM roles

D.

IAM user SSH keys

Full Access
Question # 223

A company wants to manage its cloud resources by using infrastructure as code (laC) template…..

Which AWS service should the company use to meet these requirements?

A.

AWS Artifact

B.

AWS Resource Explorer

C.

AWS License Manager

D.

AWS Service Catalog

Full Access
Question # 224

Which AWS service can run a managed PostgreSQL database that provides online transaction processing (OLTP)?

A.

Amazon DynamoDB

B.

Amazon Athena

C.

Amazon RDS

D.

Amazon EMR

Full Access
Question # 225

Which option is an environment that consists of one or more data centers?

A.

Amazon CloudFront

B.

Availability Zone

C.

VPC

D.

AWS Outposts

Full Access
Question # 226

Which AWS service enables companies to deploy an application dose to end users?

A.

Amazon CloudFront

B.

AWS Auto Scaling

C.

AWS AppSync

D.

Amazon Route S3

Full Access
Question # 227

Which benefit is always free of charge with AWS, regardless of a user's AWS Support plan?

A.

AWS Developer Support

B.

AWS Developer Forums

C.

Programmatic case management

D.

AWS technical account manager (TAM)

Full Access
Question # 228

Which AWS service gives users the ability to discover and protect sensitive data that is stored in Amazon S3 buckets?

A.

Amazon Macie

B.

Amazon Detective

C.

Amazon GuardDuty

D.

AWS I AM Access Analyzer

Full Access
Question # 229

Which AWS Cloud service can send alerts to customers if custom spending thresholds are exceeded?

A.

AWS Budgets

B.

AWS Cost Explorer

C.

AWS Cost Allocation Tags

D.

AWS Organizations

Full Access
Question # 230

Which AWS service supports user sign-up functionality and authentication to mobile and web applications?

A.

Amazon Cognito

B.

AWS Config

C.

Amazon GuardDuty

D.

AWS Systems Manager

Full Access
Question # 231

A team of researchers is going to collect data at remote locations around the world Many locations do not have internet connectivity. The team needs to capture the data in the field, and transfer it to the AWS Cloud later

Which AWS service will support these requirements?

A.

AWS Outposts

B.

AWS Transfer Family

C.

AWS Snow Family

D.

AWS Migration Hub

Full Access
Question # 232

What is a benefit of using AWS serverless computing?

A.

Application deployment and management are not required

B.

Application security will be fully managed by AWS

C.

Monitoring and logging are not needed

D.

Management of infrastructure is offloaded to AWS

Full Access
Question # 233

Which AWS service or feature allows users to create new AWS accounts, group multiple accounts to organize workflows, and apply policies to groups of accounts?

A.

AWS Identity and Access Management (1AM)

B.

AWS Trusted Advisor

C.

AWS CloudFormation

D.

AWS Organizations

Full Access
Question # 234

A company wants to manage its AWS Cloud resources through a web interface.

Which AWS service will meet this requirement?

A.

AWS Management Console

B.

AWS CLI

C.

AWS SDK

D.

AWS Cloud

Full Access
Question # 235

A development team wants to deploy multiple test environments for an application in a fast repeatable manner.

Which AWS service should the team use?

A.

Amazon EC2

B.

AWS CloudFormation

C.

Amazon QuickSight

D.

Amazon Elastic Container Service (Amazon ECS)

Full Access
Question # 236

A cloud practitioner needs to obtain AWS compliance reports before migrating an environment to the AWS Cloud How can these reports be generated?

A.

Contact the AWS Compliance team

B.

Download the reports from AWS Artifact

C.

Open a case with AWS Support

D.

Generate the reports with Amazon Macie.

Full Access
Question # 237

Which AWS Cloud benefit gives a company the ability to quickly deploy cloud resources to access compute, storage, and database infrastructures in a matter of minutes?

A.

Elasticity

B.

Cost savings

C.

Agility

D.

Reliability

Full Access
Question # 238

A company wants to implement detailed tracking of its cloud costs by department and project.

Which AWS feature or service should the company use?

A.

Consolidated billing

B.

Cost allocation tags

C.

AWS Marketplace

D.

AWS Budgets

Full Access
Question # 239

Which option is a benefit of the economies of scale based on the advantages of cloud computing?

A.

The ability to trade variable expense for fixed expense

B.

Increased speed and agility

C.

Lower variable costs over fixed costs

D.

Increased operational costs across data centers

Full Access
Question # 240

A company migrated its systems to the AWS Cloud. The systems are rightsized, and a security review did not reveal any issues. The company must ensure that additional developments, integrations, changes, and system usage growth do not jeopardize this optimized AWS infrastructure.

Which AWS service should the company use to report ongoing optimization and security?

A.

AWS Trusted Advisor

B.

AWS Health Dashboard

C.

Amazon Connect

D.

AWS Systems Manager

Full Access
Question # 241

Which tasks are responsibilities of the customer, according to the AWS shared responsibility model? (Select TWO.)

A.

Secure the virilization layer.

B.

Encrypt data and maintain data integrity.

C.

Patch the Amazon RDS operating system.

D.

Maintain identity and access management controls.

E.

Secure Availability Zones.

Full Access
Question # 242

A company wants to provision and manage its AWS infrastructure by using the common programming languages TypeScript, Python, Java, and .NET. Which h AWS service will meet this requirement?

A.

AWS CodeBuild

B.

AWS CloudFormation

C.

AWSCLI

D.

AWS Cloud Development Kit (AWS CDK)

Full Access
Question # 243

Which of the following can be components of a VPC in the AWS Cloud? (Select TWO.)

A.

Amazon API Gateway

B.

Amazon S3 buckets and objects

C.

AWS Storage Gateway

D.

Internet gateway

E.

Subnet

Full Access
Question # 244

A company wants to migrate critical on-premises production systems to Amazon EC2 instances. The production instances will be used for at least 3 years. The company wants a pricing option that will minimize cost.

Which solution will meet these requirements?

A.

On-Demand Instances

B.

Reserved Instances

C.

Spot Instances

D.

AWS Free Tier

Full Access
Question # 245

Which AWS service is designed to help users handle large amounts of data in a data warehouse environment?

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon Aurora

Full Access
Question # 246

Which maintenance task is the customer's responsibility, according to the AWS shared responsibility model?

A.

Physical connectivity among Availability Zones

B.

Network switch maintenance

C.

Hardware updates and firmware patches

D.

Amazon EC2 updates and security patches

Full Access