Month End Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Amazon Web Services CLF-C02 Dumps Questions Answers

Page: 1 / 60
Total 794 questions

AWS Certified Cloud Practitioner Questions and Answers

Question 1

Which AWS services or tools are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks? (Select TWO.)

Options:

A.

VPC endpoint

B.

Virtual private gateway

Q C. AWS Shield Standard

C.

AWS Config

D.

AWS WAF

Buy Now
Question 2

A company is planning a migration to the AWS Cloud and wants to examine the costs that are associated with different workloads.

Which AWS tool will meet these requirements?

Options:

A.

AWS Budgets

B.

AWS Cost Explorer

C.

AWS Pricing Calculator

D.

AWS Cost and Usage Report

Question 3

Which credential allows programmatic access to AWS resources for use from the AWS CLI or the AWS API?

Options:

A.

User name and password

B.

Access keys

C.

SSH public keys

D.

AWS Key Management Service (AWS KMS) keys

Question 4

A company plans to migrate its on-premises workload to AWS. Before the migration, the company needs to estimate its future AWS service costs.

Which AWS service or tool should the company use to meet this requirement?

Options:

A.

AWS Trusted Advisor

B.

AWS Budgets

C.

AWS Pricing Calculator

D.

AWS Cost Explorer

Question 5

A company has a single Amazon EC2 instance. The company wants to adopt a highly available architecture.

What can the company do to meet this requirement?

Options:

A.

Scale vertically to a larger EC2 instance size.

B.

Scale horizontally across multiple Availability Zones.

C.

Purchase an EC2 Dedicated Instance.

D.

Change the EC2 instance family to a compute optimized instance.

Question 6

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances. The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 7

Which design principle is included in the operational excellence pillar of the AWS Well-Architected Framework?

Options:

A.

Create annotated documentation.

B.

Anticipate failure.

C.

Ensure performance efficiency.

D.

Optimize costs.

Question 8

Which AWS service is designed to help users build conversational interfaces into applications using voice and text?

Options:

A.

Amazon Lex

B.

Amazon Transcribe

C.

Amazon Comprehend

D.

Amazon Timestream

Question 9

A company wants to migrate to the AWS Cloud. The company needs the ability to acquire resources when the resources are necessary.

The company also needs the ability to release those resources when the resources are no longer necessary.

Which architecture concept of the AWS Cloud meets these requirements?

Options:

A.

Elasticity

B.

Availability

C.

Reliability

D.

Durability

Question 10

A company provides a software as a service (SaaS) application. The company has a new customer that is based in a different country.

The new customer's data needs to be hosted in that country.

Which AWS service or infrastructure component should the company use to meet this requirement?

Options:

A.

AWS Shield

B.

Amazon S3 Object Lock

C.

AWS Regions

D.

Placement groups

Question 11

A company is using AWS Organizations to configure AWS accounts.

A company is planning its migration to the AWS Cloud. The company is identifying its capability gaps by using the AWS Cloud Adoption Framework (AWS CAF) perspectives.

Which phase of the cloud transformation journey includes these identification activities?

Options:

A.

Envision

B.

Align

C.

Scale

D.

Launch

Question 12

A company suspects that its AWS resources are being used for illegal activities.

Which AWS group or team should the company notify?

Options:

A.

AWS Abuse team

B.

AWS Support team

C.

AWS technical account managers

D.

AWS Professional Services team

Question 13

A company wants guidance to optimize the cost and performance of its current AWS environment.

Which AWS service or tool should the company use to identify areas for optimization?

Options:

A.

Amazon QuickSight

B.

AWS Trusted Advisor

C.

AWS Organizations

D.

AWS Budgets

Question 14

A company needs to centralize its operational data. The company also needs to automate tasks across all of its Amazon EC2 instances.

Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

AWS Systems Manager

C.

AWS CodeDeploy

D.

AWS Elastic Beanstalk

Question 15

A company needs Amazon EC2 instances for a workload that can tolerate interruptions.

Which EC2 instance purchasing option meets this requirement with the LARGEST discount compared to On-Demand prices?

Options:

A.

Spot Instances

B.

Convertible Reserved Instances

C.

Standard Reserved Instances

D.

Dedicated Hosts

Question 16

Which task is the responsibility of AWS when using AWS services?

Options:

A.

Management of IAM user permissions

B.

Creation of security group rules for outbound access

C.

Maintenance of physical and environmental controls

D.

Application of Amazon EC2 operating system patches

Question 17

A retail company has recently migrated its website to AWS. The company wants to ensure that it is protected from SQL injection attacks. The website uses an Application Load Balancer to distribute traffic to multiple Amazon EC2 instances.

Which AWS service or feature can be used to create a custom rule that blocks SQL injection attacks?

Options:

A.

Security groups

B.

AWS WAF

C.

Network ACLs

D.

AWS Shield

Question 18

Which option is a pillar of the AWS Well-Architected Framework?

Options:

A.

Patch management

B.

Cost optimization

C.

Business technology strategy

D.

Physical and environmental controls

Question 19

A company does not want to rely on elaborate forecasting to determine its usage of compute resources. Instead, the company wants to pay only for the resources that it uses. The company also needs the ability to increase or decrease its resource usage to meet business requirements.

Which pillar of the AWS Well-Architected Framework aligns with these requirements?

Options:

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Question 20

What is an AWS responsibility under the AWS shared responsibility model?

Options:

A.

Configure the security group rules that determine which ports are open on an Amazon EC2 Linux instance.

B.

Ensure the security of the internal network in the AWS data centers.

C.

Patch the guest operating system with the latest security patches on Amazon EC2.

D.

Turn on server-side encryption for Amazon S3 buckets.

A company wants to deploy its critical application on AWS and maintain high availability.

Question 21

In which categories does AWS Trusted Advisor provide recommended actions? (Select TWO.)

Options:

A.

Operating system patches

B.

Cost optimization

C.

Repetitive tasks

D.

Service quotas

E.

Account activity records

Question 22

A company has multiple AWS accounts that include compute workloads that cannot be interrupted. The company wants to obtain billing discounts that are based on the company's use of AWS services.

Which AWS feature or purchasing option will meet these requirements?

Options:

A.

Resource tagging

B.

Consolidated billing

C.

Pay-as-you-go pricing

D.

Spot Instances

Question 23

Which benefit of AWS Cloud computing provides lower latency between users and applications?

Options:

A.

Agility

B.

Economies of scale

C.

Global reach

D.

Pay-as-you-go pricing

Question 24

What is a characteristic of Convertible Reserved Instances (RIs)?

Options:

A.

Users can exchange Convertible RIs for other Convertible RIs from a different instance family.

B.

Users can exchange Convertible RIs for other Convertible RIs in different AWS Regions.

C.

Users can sell and buy Convertible RIs on the AWS Marketplace.

D.

Users can shorten the term of their Convertible RIs by merging them with other Convertible RIs.

Question 25

Which AWS solution should the company use to meet this requirement?

Options:

A.

AWS Config

B.

AWS software development kits (SDKs)

C.

AWS Service Catalog

D.

AWS AppSync

Question 26

A company wants to use Amazon EC2 instances to run a stateless and restartable process after business hours.

Which AWS service provides DNS resolution?

Options:

A.

Amazon CloudFront

B.

Amazon VPC

C.

Amazon Route 53

D.

AWS Direct Connect

Question 27

A company wants to run its production workloads on AWS. The company needs concierge service, a designated AWS technical account manager (TAM), and technical support that is available 24 hours a day, 7 days a week.

Which AWS Support plan will meet these requirements?

Options:

A.

AWS Basic Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Developer Support

Question 28

A company is setting up AWS Identity and Access Management (IAM) on an AWS account.

Which recommendation complies with IAM security best practices?

Options:

A.

Use the account root user access keys for administrative tasks.

B.

Grant broad permissions so that all company employees can access the resources they need.

C.

Turn on multi-factor authentication (MFA) for added security during the login process.

D.

Avoid rotating credentials to prevent issues in production applications.

Question 29

Which AWS service provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning (ML)?

Options:

A.

Amazon Kendra

B.

Amazon SageMaker

C.

Amazon Augmented Al (Amazon A2I)

D.

Amazon Polly

Question 30

A company wants to create a chatbot and integrate the chatbot with its current web application.

Which AWS service will meet these requirements?

Options:

A.

AmazonKendra

B.

Amazon Lex

C.

AmazonTextract

D.

AmazonPolly

Question 31

Which AWS service provides the SIMPLEST way for the company to establish a website on AWS?

Options:

A.

Amazon Elastic File System (Amazon EFS)

B.

AWS Elastic Beanstalk

C.

AWS Lambda

D.

Amazon Lightsail

Question 32

A company manages factory machines in real time. The company wants to use AWS technology to deploy its monitoring applications as close to the factory machines as possible.

Which AWS solution will meet these requirements with the LEAST latency?

Options:

A.

AWS Outposts

B.

Amazon EC2

C.

AWS App Runner

D.

AWS Batch

Question 33

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

Options:

A.

Third-party vendors

B.

Customers

C.

Reseller partners

D.

Internet providers

Question 34

A company wants its workload to perform consistently and correctly.

Which benefit of AWS Cloud computing does this goal represent?

Options:

A.

Security

B.

Elasticity

C.

Pay-as-you-go pricing

D.

Reliability

Question 35

Which AWS service or tool helps companies measure the environmental impact of their AWS usage?

Options:

A.

AWS customer carbon footprint tool

B.

AWS Compute Optimizer

C.

Sustainability pillar

D.

OS-Climate (Open Source Climate Data Commons)

Question 36

A manufacturing company has a critical application that runs at a remote site that has a slow internet connection. The company wants to migrate the workload to AWS. The application is sensitive to latency and interruptions in connectivity. The company wants a solution that can host this application with minimum latency.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

Availability Zones

B.

AWS Local Zones

C.

AWS Wavelength

D.

AWS Outposts

Question 37

Which encryption types can be used to protect objects at rest in Amazon S3? (Select TWO.)

Options:

A.

Server-side encryption with AmazonS3 managed encryption keys (SSE-S3)

B.

Server-side encryption with AWS KMSmanaged keys (SSE-KMS)

C.

TLS

D.

SSL

E.

Transparent Data Encryption (TDE)

Question 38

Which controls are the responsibility of both AWS and AWS customers, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Physical and environmental controls

B.

Patch management

C.

Configuration management

D.

Account structures

E.

Choice of the AWS Region where data is stored

Question 39

A company is preparing to launch a redesigned website on AWS. Users from around the world will download digital handbooks from the website.

Which AWS solution should the company use to provide these static files securely?

Options:

A.

Amazon Kinesis Data Streams

B.

Amazon CloudFront with Amazon S3

C.

Amazon EC2 instances with an Application Load Balancer

D.

Amazon Elastic File System (Amazon EFS)

Question 40

A company wants to create multiple isolated networks in the same AWS account.

Which AWS service or component will provide this functionality?

Options:

A.

AWS Transit Gateway

B.

Internet gateway

C.

Amazon VPC

D.

Amazon EC2

Question 41

Which of the following is entirely the responsibility of AWS, according to the AWS shared responsibility model?

Options:

A.

Security awareness and training

B.

Development of an IAM password policy

C.

Patching of the guest operating system

D.

Physical and environmental controls

Question 42

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

Options:

A.

Sustainability

B.

Operations

C.

Performance efficiency

D.

Reliability

Question 43

A company is running an application on AWS. The company wants to identify and prevent the accidental

Which AWS service or feature will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

Network ACL

C.

AWS WAF

D.

AWS Network Firewall

Question 44

Which AWS service is always free of charge for users?

Options:

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

AWS Identity and Access Management (IAM)

Question 45

A company must store call recordings for 6 years. The storage system should be highly durable and cost-effective.

Which AWS service meets these requirements?

Options:

A.

AWS Snowball

B.

Amazon S3

C.

AWS Storage Gateway

D.

Amazon Kinesis

Question 46

A company has an AWS-hosted website located behind an Application Load Balancer. The company wants to safeguard the website from SQL injection or cross-site scripting.

Which AWS service should the company use?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Trusted Advisor

D.

Amazon Inspector

Question 47

How should the company deploy the application to meet these requirements?

Options:

A.

Ina single Availability Zone

B.

On AWS Direct Connect

C.

On Reserved Instances

D.

In multiple Availability Zones

Question 48

A company is using Amazon RDS.

A company is launching a critical business application in an AWS Region.

How can the company increase resilience for this application?

Options:

A.

Deploy a copy of the application in another AWS account.

B.

Deploy the application by using multiple VPCs.

C.

Deploy the application by using multiple subnets.

D.

Deploy the application by using multiple Availability Zones.

Question 49

A company migrated its core application onto multiple workloads in the AWS Cloud. The company wants to improve the application's reliability.

Which cloud design principle should the company implement to achieve this goal?

Options:

A.

Maximize utilization.

B.

Decouple the components.

C.

Rightsize the resources.

D.

Adopt a consumption model.

Question 50

A developer wants to use an Amazon S3 bucket to store application logs that contain sensitive data.

Which AWS service or feature should the developer use to restrict read and write access to the S3 bucket?

Options:

A.

Security groups

B.

Amazon CloudWatch

C.

AWS CloudTrail

D.

ACLs

Question 51

A company needs to design a solution for the efficient use of compute resources for an enterprise workload. The company needs to make informed decisions as its technology needs evolve.

Which pillar of the AWS Well-Architected Framework do these requirements represent?

Options:

A.

Operational excellence

B.

Performance efficiency

C.

Cost optimization

D.

Reliability

Question 52

Which AWS service requires the customer to patch the guest operating system?

Options:

A.

AWS Lambda

B.

Amazon OpenSearch Service

C.

Amazon EC2

D.

Amazon ElastiCache

Question 53

A company provides a web-based ecommerce service that runs in two Availability Zones within a single AWS Region. The web service distributes content that is stored in the Amazon S3 Standard storage class. The company wants to improve the web service's performance globally.

What should the company do to meet this requirement?

Options:

A.

Change the S3 storage class to S3 Intelligent-Tiering.

B.

Deploy an Amazon CloudFront distribution to cache web server content in edge locations.

C.

Use Amazon API Gateway for the web service.

D.

Migrate the website ecommerce servers to Amazon EC2 with enhanced networking.

Question 54

Which aspect of security is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Patch and configuration management

B.

Service and communications protection or zone security

C.

Physical and environmental controls

D.

Awareness and training

Question 55

Which AWS service or tool provides on-demand access to AWS security and compliance reports and AWS online agreements?

Options:

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS Billing console

Question 56

A company wants to migrate its on-premises application to the AWS Cloud. The company is legally obligated to retain certain data in its onpremises data center.

Which AWS service or feature will support this requirement?

Options:

A.

AWS Wavelength

B.

AWS Local Zones

C.

VMware Cloud on AWS

D.

AWS Outposts

Question 57

A company wants to move its iOS application development and build activities to AWS.

Which AWS service or resource should the company use for these activities?

Options:

A.

AWS CodeCommit

B.

Amazon EC2 M1 Mac instances

C.

AWS Amplify

D.

AWS App Runner

Question 58

A company wants its Amazon EC2 instances to share the same geographic area but use redundant underlying power sources.

Which solution will meet these requirements?

Options:

A.

Use EC2 instances across multiple Availability Zones in the same AWS Region.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in AWS OpsWorks stacks in different AWS Regions.

Question 59

Which AWS service or tool offers consolidated billing?

Options:

A.

AWS Artifact

B.

AWS Budgets

C.

AWS Organizations

D.

AWS Trusted Advisor

A company wants to limit its employees' AWS access to a portfolio of predefined AWS resources.

Question 60

A company has an application workload that is stateless by design and can sustain occasional downtime. The application performs massively parallel computations.

Which Amazon EC2 pricing model should the company choose for its application to reduce cost?

Options:

A.

On-Demand Instances

B.

Spot Instances

C.

Reserved Instances

D.

Dedicated Instances

Question 61

A company has an environment that includes Amazon EC2 instances, Amazon Lightsail, and on-premises servers. The company wants to automate the security updates for its operating systems and applications.

Which solution will meet these requirements with the LEAST operational effort?

Options:

A.

Use AWS Shield to identify and manage security events.

B.

Connect to each server by using a remote desktop connection. Run an update script.

C.

Use the AWS Systems Manager Patch Manager capability.

D.

Schedule Amazon GuardDuty to run on a nightly basis.

Question 62

A developer needs to maintain a development environment infrastructure and a production environment infrastructure in a repeatable fashion.

Which AWS service should the developer use to meet these requirements?

Options:

A.

AWS Ground Station

B.

AWS Shield

C.

AWS loT Device Defender

D.

AWS CloudFormation

Question 63

An application runs on multiple Amazon EC2 instances that access a shared file system simultaneously.

Which AWS storage service should be used?

Options:

A.

Amazon EBS

B.

Amazon EFS

C.

Amazon S3

D.

AWS Artifact

Question 64

A company is running an application that is hosted on Amazon EC2 instances. The usage of the EC2 instances is higher during daytime hours than nighttime hours. The company wants to optimize the number of EC2 instances based on this usage pattern.

Which AWS service or instance purchasing option should the company use to meet these requirements?

Options:

A.

Spot Instances

B.

Reserved Instances

C.

AWS CloudFormation

D.

AWS Auto Scaling

Question 65

A user is moving a workload from a local data center to an architecture that is distributed between the local data center and the AWS Cloud.

Which type of migration is this?

Options:

A.

On-premises to cloud native

B.

Hybrid to cloud native

C.

On-premises to hybrid

D.

Cloud native to hybrid

Question 66

A company needs to host a web server on Amazon EC2 instances for at least 1 year. The web server cannot tolerate interruption.

Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

Options:

A.

On-Demand Instances

B.

Partial Upfront Reserved Instances

C.

Spot Instances

D.

No Upfront Reserved Instances

Question 67

A company has a compliance requirement to record and evaluate configuration changes, as well as perform remediation actions on AWS resources.

Which AWS service should the company use?

Options:

A.

AWS Config

B.

AWS Secrets Manager

C.

AWS CloudTrail

D.

AWS Trusted Advisor

Question 68

Which task can a company perform by using security groups in the AWS Cloud?

Options:

A.

Allow access to an Amazon EC2 instance through only a specific port.

B.

Deny access to malicious IP addresses at a subnet level.

C.

Protect data that is cached by Amazon CloudFront.

D.

Apply a stateless firewall to an Amazon EC2 instance.

Question 69

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

Options:

A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Question 70

A company that is planning to migrate to the AWS Cloud is based in an isolated area that has limited internet connectivity. The company needs to perform local data processing on premises. The company needs a solution that can operate without a stable internet connection.

Which AWS service will meet these requirements?

Options:

A.

Amazon S3

B.

AWS Snowball Edge

C.

AWS StorageGateway

D.

AWS Backup

Question 71

Which benefit of the AWS Cloud helps companies achieve lower usage costs because of the aggregate usage of all AWS users?

Options:

A.

No need to guess capacity

B.

Ability to go global in minutes

C.

Economies of scale

D.

Increased speed and agility

Question 72

A company wants to access a report about the estimated environmental impact of the company's AWS usage.

Which AWS service or feature should the company use to meet this requirement?

Options:

A.

AWS Organizations

B.

IAM policy

C.

AWS Billing console

D.

Amazon Simple Notification Service (Amazon SNS)

Question 73

A company needs to host a highly available application in the AWS Cloud. The application runs infrequently for short periods of time.

Which AWS service will meet these requirements with the LEAST amount of operational overhead?

Options:

A.

Amazon EC2

B.

AWS Fargate

C.

AWS Lambda

D.

Amazon Aurora

Question 74

An ecommerce company wants to design a highly available application that will be hosted on multiple Amazon EC2 instances.

How should the company deploy the EC2 instances to meet these requirements?

Options:

A.

Across multiple edge locations

B.

Across multiple VPCs

C.

Across multiple Availability Zones

D.

Across multiple AWS accounts

Question 75

Which AWS services allow users to monitor and retain records of account activities that include governance, compliance, and auditing?

(Select TWO.)

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

Amazon GuardDuty

D.

AWS Shield

E.

AWS WAF

Question 76

A company has set up a VPC in its AWS account and has created a subnet in the VPC. The company wants to make the subnet public.

Which AWS features should the company use to meet this requirement? (Select TWO.)

Options:

A.

Amazon VPC internet gateway

B.

Amazon VPC NAT gateway

C.

Amazon VPC route tables

D.

Amazon VPC network ACL

E.

Amazon EC2 security groups

Question 77

Which AWS service or tool provides recommendations to help users get rightsized Amazon EC2 instances based on historical workload usage data?

Options:

A.

AWS Pricing Calculator

B.

AWS Compute Optimizer

C.

AWS App Runner

D.

AWS Systems Manager

Question 78

A company wants to migrate its application to AWS. The company wants to replace upfront expenses with variable payment that is based on usage.

What should the company do to meet these requirements?

Options:

A.

Use pay-as-you-go pricing.

B.

Purchase Reserved Instances.

C.

Pay less by using more.

D.

Rightsize instances.

Question 79

A company wants to develop a shopping application that records customer orders. The application needs to use an AWS managed database service to store data.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon ElastiCache

D.

Amazon Neptune

Question 80

A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access.

According to the AWS shared responsibility model, which task is the responsibility of the customer?

Options:

A.

Protect the global infrastructure that runs all of the services offered in the AWS Cloud.

B.

Configure logical access controls for resources, and protect account credentials.

C.

Configure the security used by managed services.

D.

Patch and back up Amazon Aurora.

Question 81

Amazon Elastic File System (Amazon EFS) and Amazon FSx offer which type of storage?

Options:

A.

File storage

B.

Object storage

C.

Block storage

D.

Instance store

Question 82

A company wants to use a managed service to simplify the setup, operation, and scaling of its MySQL database in the AWS Cloud.

Which AWS service will meet these requirements?

Options:

A.

Amazon EMR

B.

Amazon RDS

C.

Amazon Redshift

D.

Amazon DynamoDB

Question 83

Which of the following is a cost efficiency principle related to the AWS Cloud?

Options:

A.

Right-size services based on capacity requirements.

B.

Use the Billing Dashboard to access information about monthly bills.

C.

Use AWS Organizations to combine the expenses of multiple accounts into a single bill.

D.

Tag all AWS resources.

Question 84

Which AWS features will meet these requirements? (Select TWO.)

Options:

A.

Security groups

B.

Network ACLs

C.

S3 bucket policies

D.

IAM user policies

E.

S3 bucket versioning

Question 85

In which of the following AWS services should database credentials be stored for maximum security?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS Secrets Manager

C.

Amazon S3

D.

AWS Key Management Service (AWS KMS)

Question 86

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

Options:

A.

AWS CloudTrail

B.

AWS Cost and Usage Reports

C.

AWS Trusted Advisor

D.

AWS Budgets

Question 87

A company is designing a web application that will run on Amazon EC2 instances.

Which AWS services and features will improve availability and reduce the impact of failures for this application?

(Select TWO.)

Options:

A.

Amazon EC2 Auto Scaling for the EC2 instances

B.

VPC subnet ACLs to check the health of a service

C.

Resources that are distributed across multiple Availability Zones

D.

Configuration of AWS Server Migration Service (AWS SMS) to move the EC2 instances to a different

AWS Region

E.

Resources that are distributed across multiple AWS points of presence

Question 88

A company has an online shopping website and wants to store customers' credit card data. The company must meet Payment Card Industry (PCI) standards.

Which service can the company use to access AWS compliance documentation?

Options:

A.

Amazon Cloud Directory

B.

AWS Artifact

C.

AWS Trusted Advisor

D.

Amazon Inspector

Question 89

A company needs to migrate all of its development teams to a cloud-based integrated development environment (IDE).

Which AWS service should the company use?

Options:

A.

AWS CodeBuild

B.

AWS Cloud9

C.

AWS OpsWorks

D.

AWS Cloud Development Kit (AWS CDK)

Question 90

A company needs to test a new application that was written in Python. The code will activate when new images are stored in an Amazon S3 bucket. The application will put a watermark on each image and then will store the images in a different S3 bucket.

Which AWS service should the company use to conduct the test with the LEAST amount of operational

overhead?

Options:

A.

Amazon EC2

B.

AWS CodeDeploy

C.

AWS Lambda

D.

Amazon Lightsail

Question 91

A company deploys its application on Amazon EC2 instances. The application occasionally experiences sudden increases in demand. The company wants to ensure that its application can respond to changes in demand at the lowest possible cost.

Which AWS service or tool will meet these requirements?

Options:

A.

AWS Auto Scaling

B.

AWS Compute Optimizer

C.

AWS Cost Explorer

D.

AWS Well-Architected Framework

Question 92

A company's IT team is managing MySQL database server clusters. The IT team has to patch the database and take backup snapshots of the data in the clusters. The company wants to move this workload to AWS so that these tasks will be completed automatically.

What should the company do to meet these requirements?

Options:

A.

Deploy MySQL database server clusters on Amazon EC2 instances.

B.

Use Amazon RDS with a MySQL database.

C.

Use an AWS Cloud Form at ion template to deploy MySQL database servers on Amazon EC2 instances.

D.

Migrate all the MySQL database data to Amazon S3.

Question 93

Which AWS service provides highly durable object storage?

Options:

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon FSx

Question 94

Which AWS service aggregates, organizes, and prioritizes security alerts and findings from multiple AWS services?

Options:

A.

Amazon Detective

B.

Amazon Inspector

C.

Amazon Macie

D.

AWS Security Hub

Question 95

Which AWS service can report how AWS resource configurations have changed over time?

Options:

A.

AWS CloudTrail

B.

Amazon CloudWatch

C.

AWS Config

D.

Amazon Inspector

Question 96

Which AWS services or features can control VPC traffic? (Select TWO.)

Options:

A.

Security groups

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

Network ACLs

E.

Amazon Connect

Question 97

An Availability Zone consists of:

Options:

A.

one or more data centers in a single location.

B.

two or more data centers in multiple locations.

C.

one or more physical hosts in a single data center.

D.

two or more physical hosts in multiple data centers.

Question 98

An application is running on multiple Amazon EC2 instances. The company wants to make the application highly available by configuring a load balancer with requests forwarded to the EC2 instances based on URL paths.

Which AWS load balancer will meet these requirements and take the LEAST amount of effort to deploy?

Options:

A.

Network Load Balancer

B.

Application Load Balancer

C.

AWS OpsWorks Load Balancer

D.

Custom Load Balancer on Amazon EC2

Question 99

What is an Availability Zone?

Options:

A.

A location where users can deploy compute, storage, database, and other select AWS services

where no AWS Region currently exists

B.

One or more discrete data centers with redundant power, networking, and connectivity

C.

One or more clusters of servers where new workloads can be deployed

D.

A fast content delivery network (CDN) service that securely delivers data, videos, applications, and

APIs to users globally

Question 100

A user wants to identify any security group that is allowing unrestricted incoming SSH traffic.

Which AWS service can be used to accomplish this goal?

Options:

A.

Amazon Cognito

B.

AWS Shield

C.

Amazon Macie

D.

AWS Trusted Advisor

Question 101

Which of the following are advantages of moving to the AWS Cloud? (Select TWO.)

Options:

A.

The ability to turn over the responsibility for all security to AWS.

B.

The ability to use the pay-as-you-go model.

C.

The ability to have full control over the physical infrastructure.

D.

No longer having to guess what capacity will be required.

E.

No longer worrying about users access controls.

Question 102

A company deploys its application to multiple AWS Regions and configures automatic failover between those Regions.

Which cloud concept does this architecture represent?

Options:

A.

Security

B.

Reliability

C.

Scalability

D.

Cost optimization

Question 103

Which AWS service meets this requirement?

Options:

A.

AWS CloudFormation

B.

AWS Elastic Beanstalk

C.

AWS Cloud9

D.

AWS CloudShell

Question 104

A company has two AWS accounts in an organization in AWS Organizations for consolidated billing. All of the company's AWS resources are hosted in one AWS Region.

Account A has purchased five Amazon EC2 Standard Reserved Instances (RIs) and has four EC2 instances

running. Account B has not purchased any RIs and also has four EC2 instances running.

Which statement is true regarding pricing for these eight instances?

Options:

A.

The eight instances will be charged as regular instances.

B.

Four instances will be charged as RIs, and four will be charged as regular instances.

C.

Five instances will be charged as RIs, and three will be charged as regular instances.

D.

The eight instances will be charged as RIs.

Question 105

Which statement describes a characteristic of the AWS global infrastructure?

Options:

A.

Edge locations contain multiple AWS Regions.

B.

AWS Regions contain multiple Regional edge caches.

C.

Availability Zones contain multiple data centers.

D.

Each data center contains multiple edge locations.

Question 106

A company has an application that uses AWS services. During scaling events, the company wants to keep

application usage within AWS service quotas.

Which AWS services or tools can report on the quotas so that the company can improve the reliability of the application? (Select TWO.)

Options:

A.

Service Quotas console

B.

AWS Trusted Advisor

C.

AWS Systems Manager

D.

AWS Shield

E.

AWS Cost Explorer

Question 107

A company is reviewing its operating policies.

Which policy complies with guidance in the security pillar of the AWS Well-Architected Framework?

Options:

A.

Ensure that employees have access to all company data.

B.

Expand employees' permissions as they gain more experience.

C.

Grant all privileges and access to all users.

D.

Apply security requirements at all layers of a process.

Question 108

A company needs to continuously monitor its environment to analyze network and account activity and identify potential security threats.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Artifact

B.

Amazon Macie

C.

AWS Identity and Access Management (IAM)

D.

Amazon GuardDuty

Question 109

A company runs thousands of simultaneous simul-ations using AWS Batch. Each simul-ation is stateless, is fault tolerant, and runs for up to 3 hours.

Which pricing model enables the company to optimize costs and meet these requirements?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

Dedicated Instances

Question 110

Which design principles support the reliability pillar of the AWS Well-Architected Framework? (Select TWO.)

Options:

A.

Perform operations as code.

B.

Enable traceability.

C.

Automatically scale to meet demand.

D.

Deploy resources globally to improve response time.

E.

Automatically recover from failure.

Question 111

Which of the following is an advantage that users experience when they move on-premises workloads to the AWS Cloud?

Options:

A.

Elimination of expenses for running and maintaining data centers

B.

Price discounts that are identical to discounts from hardware providers

C.

Distribution of all operational controls to AWS

D.

Elimination of operational expenses

Question 112

Which benefit does Amazon Rekognition provide?

Options:

A.

The ability to place watermarks on images

B.

The ability to detect objects that appear in pictures

C.

The ability to resize millions of images automatically

D.

The ability to bid on object detection jobs

Question 113

Which task is a customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Management of the guest operating systems

B.

Maintenance of the configuration of infrastructure devices

C.

Management of the host operating systems and virtualization

D.

Maintenance of the software that powers Availability Zones

A company has refined its workload to use specific AWS services to improve efficiency and reduce cost.

Question 114

A large company wants to track the combined AWS usage costs of all of its linked accounts.

How can this be accomplished?

Options:

A.

Use AWS Trusted Advisor to generate customized summary reports.

B.

Use AWS Organizations to generate consolidated billing reports.

C.

Use AWS Budgets to set utilization targets and receive summary reports.

D.

Use the AWS Control Tower dashboard to get a summary report of all linked account costs.

Question 115

A company recently migrated to the AWS Cloud. The company needs to determine whether its newly imported Amazon EC2 instances are the appropriate size and type.

Which AWS services can provide this information to the company? {Select TWO.)

Options:

A.

AWS Auto Scaling

B.

AWS Control Tower

C.

AWS Trusted Advisor

D.

AWS Compute Optimizer

E.

Amazon Forecast

Question 116

Which AWS network services or features allow Cl DR block notation when providing an IP address range?

(Select TWO.)

Options:

A.

Security groups

B.

Amazon Machine Image (AMI)

C.

Network access control list (network ACL)

D.

AWS Budgets

E.

Amazon Elastic Block Store (Amazon EBS)

Question 117

A company needs a content delivery network that provides secure delivery of data, videos, applications, and APIs to users globally with low latency and high transfer speeds.

Which AWS service meets these requirements?

Options:

A.

Amazon CloudFront

B.

Elastic Load Balancing

C.

Amazon S3

D.

Amazon Elastic Transcoder

Question 118

A company wants to migrate its on-premises data warehouse to AWS. The information in the data warehouse is

used to populate analytics dashboards.

Which AWS service should the company use for the data warehouse?

Options:

A.

Amazon ElastiCache

B.

Amazon Aurora

C.

Amazon RDS

D.

Amazon Redshift

Question 119

Which of the following is an advantage of AWS Cloud computing?

Options:

A.

Trade security for elasticity.

B.

Trade operational excellence for agility.

C.

Trade fixed expenses for variable expenses.

D.

Trade elasticity for performance.

Question 120

Which AWS service or feature offers HTTP attack protection to users running public-facing web applications?

Options:

A.

Security groups

B.

Network ACLs

C.

AWS Shield Standard

D.

AWS WAF

Question 121

Which of the following are advantages of the AWS Cloud? (Select TWO.)

Options:

A.

Trade variable expenses for capital expenses

B.

High economies of scale

C.

Launch globally in minutes

D.

Focus on managing hardware infrastructure

E.

Overprovision to ensure capacity

Question 122

Which AWS feature or resource is a deployable Amazon EC2 instance template that is prepackaged with

software and security requirements?

Options:

A.

Amazon Elastic Block Store (Amazon EBS) volume

B.

AWS CloudFormation template

C.

Amazon Elastic Block Store (Amazon EBS) snapshot

D.

Amazon Machine Image (AMI)

Question 123

company wants to protect its AWS Cloud information, systems, and assets while performing risk assessment and mitigation tasks.

Which pillar of the AWS Well-Architected Framework is supported by these goals?

Options:

A.

Reliability

B.

Security

C.

Operational excellence

D.

Performance efficiency

Question 124

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

Options:

A.

Perform quarterly disaster recovery tests.

B.

Place the main component on the us-east-1 Region.

C.

Design for automatic failover to healthy resources.

D.

Design workloads to fit on a single Amazon EC2 instance.

Question 125

A retail company is migrating its IT infrastructure applications from on premises to the AWS Cloud.

Which costs will the company eliminate with this migration? (Select TWO.)

Options:

A.

Cost of data center operations

B.

Cost of application licensing

C.

Cost of marketing campaigns

D.

Cost of physical server hardware

E.

Cost of network management

Question 126

Which design principle should be considered when architecting in the AWS Cloud?

Options:

A.

Think of servers as non-disposable resources.

B.

Use synchronous integration of services.

C.

Design loosely coupled components.

D.

Implement the least permissive rules for security groups.

Question 127

Which AWS solution gives companies the ability to use protocols such as NFS to store and retrieve objects in Amazon S3?

Options:

A.

Amazon FSx for Lustre

B.

AWS Storage Gateway volume gateway

C.

AWS Storage Gateway file gateway

D.

Amazon Elastic File System (Amazon EFS)

Question 128

A company plans to migrate to AWS and wants to create cost estimates for its AWS use cases.

Which AWS service or tool can the company use to meet these requirements?

Options:

A.

AWS Pricing Calculator

B.

Amazon CloudWatch

C.

AWS Cost Explorer

D.

AWS Budgets

Question 129

Which AWS service or feature is used to send both text and email messages from distributed applications?

Options:

A.

Amazon Simple Notification Service (Amazon SNS)

B.

Amazon Simple Email Service (Amazon SES)

C.

Amazon CloudWatch alerts

D.

Amazon Simple Queue Service (Amazon SQS)

Question 130

A company needs to store data across multiple Availability Zones in an AWS Region. The data will not be

accessed regularly but must be immediately retrievable.

Which Amazon Elastic File System (Amazon EFS) storage class meets these requirements MOST cost effectively?

Options:

A.

EFS Standard

B.

EFS Standard-Infrequent Access(EFS Standard-IA)

C.

EFS One Zone

D.

EFS One Zone-Infrequent Access (EFS One Zone-IA)

Question 131

A company hosts an application on an Amazon EC2 instance. The EC2 instance needs to access several AWS resources, including Amazon S3 and Amazon DynamoDB.

What is the MOST operationally efficient solution to delegate permissions?

Options:

A.

Create an IAM role with the required permissions. Attach the role to the EC2 instance.

B.

Create an IAM user and use its access key and secret access key in the application.

C.

Create an IAM user and use its access key and secret access key to create a CLI profile in the EC2 instance.

D.

Create an IAM role with the required permissions. Attach the role to the administrativeIAM user.

Question 132

A company is running applications on Amazon EC2 instances in the same AWS account for several different projects. The company wants to track the infrastructure costs for each of the projects separately. The company must conduct this tracking with the least possible impact to the existing infrastructure and with no additional cost.

What should the company do to meet these requirements?

Options:

A.

Use a different EC2 instance type for each project.

B.

Publish project-specific custom Amazon CloudWatch metrics for each application.

C.

Deploy EC2 instances for each project in a separate AWS account.

D.

Use cost allocation tags with values that are specific to each project.

Question 133

Which option is an advantage of AWS Cloud computing that minimizes variable costs?

Options:

A.

High availability

B.

Economies of scale

C.

Global reach

D.

Agility

Question 134

Which task is the responsibility of a company that is using Amazon RDS?

Options:

A.

Provision the underlying infrastructure.

B.

Create IAM policies to control administrative access to the service.

C.

Install the cables to connect the hardware for compute and storage.

D.

Install and patch the RDS operating system.

Question 135

A company is migrating an application that includes an Oracle database to AWS. The company cannot rewrite the application.

To which AWS service could the company migrate the database?

Options:

A.

Amazon Athena

B.

Amazon DynamoDB

®C. Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

Question 136

Which options does AWS make available for customers who want to learn about security in the cloud in an instructor-led setting? (Select TWO.)

Options:

A.

AWS Trusted Advisor

B.

AWS Online Tech Talks

C.

AWS Blog

D.

AWS Forums

E.

AWS Classroom Training

Question 137

A company has an application with robust hardware requirements. The application must be accessed by students who are using lightweight, low-cost laptops.

Which AWS service will help the company deploy the application without investing in backend infrastructure or high end client hardware?

Options:

A.

Amazon AppStream 2.0

B.

AWS AppSync

C.

Amazon WorkLink

D.

AWS Elastic Beanstalk

Question 138

A company wants to deploy and manage a Docker-based application on AWS.

Which solution meets these requirements with the LEAST amount of operational overhead?

Options:

A.

An open-source Docker orchestrator on Amazon EC2 instances

B.

AWS AppSync

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

Amazon Elastic Container Service (Amazon ECS)

Question 139

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO.)

Options:

A.

Availability

B.

Reliability

C.

Scalability

D.

Responsive design

E.

Operational excellence

Question 140

What are some advantages of using Amazon EC2 instances lo host applications in the AWS Cloud instead of on premises? (Select TWO.)

Options:

A.

EC2 includes operating system patch management

B.

EC2 integrates with Amazon VPC. AWS CloudTrail, and AWS Identity and Access Management (IAM)

C.

EC2 has a 100% service level agreement (SLA).

D.

EC2 has a flexible, pay-as-you-go pricing model.

E.

EC2 has automatic storage cost optimization.

Question 141

Which AWS service should a cloud engineer use to view API calls to AWS services?

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Config

D.

AWS Artifact

Question 142

A company uses Amazon Aurora as its database service. The company wants to encrypt its databases and database backups.

Which party manages the encryption of the database clusters and database snapshots, according to the AWS shared responsibility

model?

Options:

A.

AWS

B.

The company

C.

AWS Marketplace partners

D.

Third-party partners

Question 143

Which of the following are design principles for reliability in the AWS Cloud? (Select TWO.)

Options:

A.

Build architectures with tightly coupled resources.

B.

Use AWS Trusted Advisor to meet security best practices.

C.

Use automation to recover immediately from failure.

D.

Rightsize Amazon EC2 instances to ensure optimal performance.

E.

Simulate failures to test recovery processes.

Question 144

Which of the following describes an AWS Region?

Options:

A.

A specific location within a geographic area that provides high availability

B.

A set of data centers spanning multiple countries

C.

A global picture of a user's cloud computing environment

D.

A collection of databases that can be accessed from a specific geographic area only

Question 145

A company wants to ensure that two Amazon EC2 instances are in separate data centers with minimal

communication latency between the data centers.

How can the company meet this requirement?

Options:

A.

Place the EC2 instances in two separate AWS Regions connected with a VPC peering connection.

B.

Place the EC2 instances in two separate Availability Zones within the same AWS Region.

C.

Place one EC2 instance on premises and the other in an AWS Region. Then connect them by using an

AWS VPN connection.

D.

Place both EC2 instances in a placement group for dedicated bandwidth.

Question 146

Which of the following is an AWS value proposition that describes a user's ability to scale infrastructure based on demand?

Options:

A.

Speed of innovation

B.

Resource elasticity

C.

Decoupled architecture

D.

Global deployment

Question 147

A cloud practitioner is analyzing Amazon EC2 instance performance and usage to provide recommendations for potential cost savings.

Which cloud concept does this analysis demonstrate?

Options:

A.

Auto scaling

B.

Rightsizing

C.

Load balancing

D.

High availability

Question 148

A developer needs to build an application for a retail company. The application must provide real-time product recommendations that are based on machine learning.

Which AWS service should the developer use to meet this requirement?

Options:

A.

AWS Health Dashboard

B.

Amazon Personalize

C.

Amazon Forecast

D.

Amazon Transcribe

Question 149

How can an AWS user conduct security assessments of Amazon EC2 instances, NAT gateways, and Elastic

Load Balancers in a way that is approved by AWS?

Options:

A.

Flood a target with requests.

B.

Use Amazon Inspector.

C.

Perform penetration testing.

D.

Use the AWS Service Health Dashboard.

Question 150

Which AWS service or feature captures information about the network traffic to and from an Amazon EC2 instance?

Options:

A.

VPC Reachability Analyzer

B.

Amazon Athena

C.

VPC Flow Logs

D.

AWS X-Ray

Question 151

Which AWS service can a company use to perform complex analytical queries?

Options:

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon ElastiCache

Question 152

What does the Amazon S3 Intelligent-Tiering storage class offer?

Options:

A.

Payment flexibility by reserving storage capacity

B.

Long-term retention of data by copying the data to an encrypted Amazon Elastic Block Store (Amazon

EBS) volume

C.

Automatic cost savings by moving objects between tiers based on access pattern changes

D.

Secure, durable, and lowest cost storage for data archival

Question 153

Who is responsible for decommissioning end-of-life underlying storage devices that are used to host data on AWS?

Options:

A.

Customer

B.

AWS

C.

Account creator

D.

Auditing team

Question 154

Which AWS service will help a company identify the user who deleted an Amazon EC2 instance yesterday?

Options:

A.

Amazon CloudWatch

B.

AWS Trusted Advisor

C.

AWS CloudTrail

D.

Amazon Inspector

Question 155

A company wants to establish a security layer in its VPC that will act as a firewall to control subnet traffic.

Which AWS service or feature will meet this requirement?

Options:

A.

Routing tables

B.

Network access control lists (network ACLs)

C.

Security groups

D.

Amazon GuardDuty

Question 156

When a user wants to utilize their existing per-socket, per-core, or per-virtual machine software licenses for a Microsoft Windows server running on AWS, which Amazon EC2 instance type is required?

Options:

A.

Spot Instances

B.

Dedicated Instances

C.

Dedicated Hosts

D.

Reserved Instances

Question 157

A company needs to use dashboards and charts to analyze insights from business data.

Which AWS service will provide the dashboards and charts for these insights?

Options:

A.

Amazon Macie

B.

Amazon Aurora

C.

Amazon QuickSight

D.

AWS CloudTrail

Question 158

Which AWS service is a highly available and scalable DNS web service?

Options:

A.

Amazon VPC

B.

Amazon CloudFront

C.

Amazon Route 53

D.

Amazon Connect

Question 159

A company is designing an identity access management solution for an application. The company wants users to be able to use their social media, email, or online shopping accounts to access the application.

Which AWS service provides this functionality?

Options:

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Config

C.

Amazon Cognito

D.

AWS Identity and Access Management (IAM)

Question 160

Which AWS Support plan provides customers with access to an AWS technical account manager (TAM)?

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Question 161

A company wants a key-value NoSQL database that is fully managed and serverless.

Which AWS service will meet these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon RDS

C.

Amazon Aurora

D.

Amazon Memory DB for Redis

Question 162

A developer needs to use a standardized template to create copies of a company's AWS architecture for development test, and production environments. Which AWS service should the developer use to meet this requirement?

Options:

A.

AWS Cloud Map

B.

AWS Cloud Formation

C.

Amazon CloudFront

D.

AWS CloudTrail

Question 163

Which AWS feature provides a no-cost platform for AWS users to join community groups, ask questions, find answers, and read community-generated articles about best practices?

Options:

A.

AWS Knowledge Center

B.

AWS re:Post

C.

AWS 10

D.

AWS Enterprise Support

Question 164

A company wants to deploy a web application as a containerized application. The company wants to use a managed service that can automatically create container images from source code and deploy the containerized application.

Which AWS service will meet these requirements?

Options:

A.

AWS Elastic Beanstalk

B.

Amazon Elastic Container Service (Amazon ECS)

C.

AWS App Runner

D.

Amazon EC2

Question 165

Which options are AWS Cloud Adoption Framework (AWS CAF) cloud transformation journey

recommendations? (Select TWO.)

Options:

A.

Envision phase

B.

Align phase

C.

Assess phase

D.

Mobilize phase

E.

Migrate and modernize phase

Question 166

A company plans to migrate to the AWS Cloud. The company is gathering information about its on-premises infrastructure and requires information such as the hostname, IP address, and MAC address.

Which AWS service will meet these requirements?

Options:

A.

AWS DataSync

B.

AWS Application Migration Service

C.

AWS Application Discovery Service

D.

AWS Database Migration Service (AWS DMS)

Question 167

Which AWS service uses edge locations to cache content?

Options:

A.

Amazon Kinesis

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon CloudFront

D.

Amazon Route 53

Question 168

Which AWS Cloud benefit is shown by an architecture’s ability to withstand failures with minimal downtime?

Options:

A.

Agility

B.

Elasticity

C.

Scalability

D.

High availability

Question 169

A company processes personally identifiable information (Pll) and must keep data in the country where it was generated. The company wants to use Amazon EC2 instances for these workloads.

Which AWS service will meet these requirements?

Options:

A.

AWS Outposts

B.

AWS Storage Gateway

C.

AWS DataSync

D.

AWS OpsWorks

Question 170

A company is planning to move data backups to the AWS Cloud. The company needs to replace on-premises storage with storage that is cloud-based but locally cached.

Which AWS service meets these requirements?

Options:

A.

AWS Storage Gateway

B.

AWS Snowcone

C.

AWS Backup

D.

Amazon Elastic File System (Amazon EFS)

Question 171

Which AWS service can provide a dedicated network connection with consistent low latency from on premises to the AWS Cloud?

Options:

A.

Amazon VPC

B.

Amazon Kinesis Data Streams

C.

AWS Direct Connect

D.

Amazon OpenSearch Service

Question 172

A company is migrating its public website to AWS. The company wants to host the domain name for the website on AWS.

Which AWS service should the company use to meet this requirement?

Options:

A.

AWS Lambda

B.

Amazon Route 53

C.

Amazon CloudFront

D.

AWS Direct Connect

Question 173

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO)

Options:

A.

High availability

B.

Performance efficiency

C.

Cost optimization

D.

Going global in minutes

E.

Continuous development

Question 174

Which of the following can be components of a VPC in the AWS Cloud? (Select TWO.)

Options:

A.

Amazon API Gateway

B.

Amazon S3 buckets and objects

C.

AWS Storage Gateway

D.

Internet gateway

E.

Subnet

Question 175

A company needs to track the activity in its AWS accounts, and needs to know when an API call is made against its AWS resources. Which AWS tool or service can be used to meet these requirements?

Options:

A.

Amazon CloudWatch

B.

Amazon Inspector

C.

AWS CloudTrail

D.

AWS IAM

Question 176

A company has moved all its infrastructure to the AWS Cloud. To plan ahead for each quarter, the finance team wants to track the cost and usage data of all resources from previous months. The finance team wants to automatically generate reports that contains the data.

Which AWS service or feature should the finance team use to meet these requirements?

Options:

A.

Amazon Detective

B.

AWS Pricing Calculator

C.

AWS Budgets

D.

AWS Savings Plans

Question 177

What is the MOST secure way to store passwords on AWS?

Options:

A.

Store passwords in an Amazon S3 bucket.

B.

Store passwords as AWS CloudFormation parameters

C.

Store passwords in AWS Storage Gateway.

D.

Store passwords in AWS Secrets Manager.

Question 178

A company is assessing its AWS Business Support plan to determine if the plan still meets the company's needs. The company is considering switching to

AWS Enterprise Support.

Which additional benefit will the company receive with AWS Enterprise Support?

Options:

A.

A full set of AWS Trusted Advisor checks

B.

Phone, email, and chat access to cloud support engineers 24 hours a day, 7 days a week

C.

A designated technical account manager (TAM) to assist in monitoring and optimization

D.

A consultative review and architecture guidance for the company's applications

Question 179

A company wants to monitor its workload performance. The company wants to ensure that the cloud services are delivered at a level that meets its business needs.

Which AWS Cloud Adoption Framework (AWS CAF) perspective will meet these requirements?

Options:

A.

Business

B.

Governance

C.

Platform

D.

Operations

Question 180

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance state changes to RUNNING.

Which AWS service can the company use to meet this requirement?

Options:

A.

Amazon SageMaker

B.

Amazon Connect

C.

Amazon EventBridge

D.

AWS Fargate

Question 181

A company is launching a mobile app. The company wants customers to be able to use the app without upgrading their mobile devices.

Which pillar of the AWS Well-Architected Framework does this goal represent?

Options:

A.

Security

B.

Reliability

C.

Cost optimization

D.

Sustainability

Question 182

A company has a client that uses an Amazon RDS database. The client requests Information about operating system-level upgrades on the AWS resources that host the RDS database. The company employs a third-party provider to monitor the RDS database.

Who is responsible for upgrading the operating systems for Amazon RDS under the AWS shared responsibility model?

Options:

A.

The client

B.

The company

C.

AWS

D.

The third-party provider

Question 183

A company is building AWS architecture to deliver real-time data feeds from an on-premises data center into an application that runs on AWS. The company needs a consistent network connection with minimal latency.

What should the company use to connect the application and the data center to meet these requirements?

Options:

A.

AWS Direct Connect

B.

Public internet

C.

AWS VPN

D.

Amazon Connect

Question 184

A company wants to visualize and manage AWS Cloud costs and usage for a specific period of time.

Which AWS service or feature will meet these requirements?

Options:

A.

Cost Explorer

B.

Consolidated billing

C.

AWS Organizations

D.

AWS Budgets

Question 185

Which of the following is a fully managed graph database service on AWS?

Options:

A.

Amazon Aurora

B.

Amazon FSx

C.

Amazon DynamoDB

D.

Amazon Neptune

Question 186

Which AWS service can a company use to find security and compliance reports, including International Organization for Standardization (ISO) reports?

Options:

A.

AWS Artifact

B.

Amazon CloudWatch

C.

AWS Config

D.

AWS Audit Manager

Question 187

Which task does AWS perform automatically?

Options:

A.

Encrypt data that is stored in Amazon DynamoDB.

B.

Patch Amazon EC2 instances.

C.

Encrypt user network traffic.

D.

Create TLS certificates for users' websites.

Question 188

Which AWS service or feature improves network performance by sending traffic through the AWS worldwide network infrastructure?

Options:

A.

Route table

B.

AWS Transit Gateway

C.

AWS Global Accelerator

D.

Amazon VPC

Question 189

According to the AWS shared responsibility model, which task is the customer's responsibility?

Options:

A.

Maintaining the infrastructure needed to run AWS Lambda

B.

Updating the operating system of Amazon DynamoDB instances

C.

Maintaining Amazon S3 infrastructure

D.

Updating the guest operating system on Amazon EC2 instances

Question 190

A company has an application that produces unstructured data continuously. The company needs to store the data so that the data is durable and easy to query.

Which AWS service can the company use to meet these requirements?

Options:

A.

Amazon RDS

B.

Amazon Aurora

C.

Amazon QuickSight

D.

Amazon DynamoDB

Question 191

What is the purpose of having an internet gateway within a VPC?

Options:

A.

To create a VPN connection to the VPC

B.

To allow communication between the VPC and the internet

C.

To impose bandwidth constraints on internet traffic

D.

To load balance traffic from the internet across Amazon EC2 instances

Question 192

Which guidelines are best practices for using AWS Identity and Access Management (1AM)? (Select TWO.)

Options:

A.

Share access keys.

B.

Create individual 1AM users.

C.

Use inline policies instead of customer managed policies.

D.

Grant maximum privileges to 1AM users.

E.

Use groups to assign permissions to 1AM users.

Question 193

What is a benefit of using AWS serverless computing?

Options:

A.

Application deployment and management are not required

B.

Application security will be fully managed by AWS

C.

Monitoring and logging are not needed

D.

Management of infrastructure is offloaded to AWS

Question 194

Which AWS service or feature allows users to create new AWS accounts, group multiple accounts to organize workflows, and apply policies to groups of accounts?

Options:

A.

AWS Identity and Access Management (1AM)

B.

AWS Trusted Advisor

C.

AWS CloudFormation

D.

AWS Organizations

Question 195

A company is using a central data platform to manage multiple types of data for its customers. The company wants to use AWS services to discover, transform, and visualize the data.

Which combination of AWS services should the company use to meet these requirements? (Select TWO.)

Options:

A.

AWS Glue

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Redshift

D.

Amazon QuickSight

E.

Amazon Quantum Ledger Database (Amazon QLDB)

Question 196

A company runs a legacy workload in an on-premises data center. The company wants to migrate the workload to AWS. The company does not want to make any changes to the workload.

Which migration strategy should the company use?

Options:

A.

Repurchase

B.

Replatform

C.

Rehost

D.

Refactor

Question 197

Which tasks are customer responsibilities, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Configure the AWS provided security group firewall.

B.

Classify company assets in the AWS Cloud.

C.

Determine which Availability Zones to use for Amazon S3 buckets.

D.

Patch or upgrade Amazon DynamoDB.

E.

Select Amazon EC2 instances to run AWS Lambda on.

F.

AWS Config

Question 198

A company wants to design a reliable web application that is hosted on Amazon EC2.

Which approach will achieve this goal?

Options:

A.

Launch large EC2 instances in the same Availability Zone.

B.

Spread EC2 instances across more than one security group.

C.

Spread EC2 instances across more than one Availability Zone.

D.

Use an Amazon Machine Image (AMI) from AWS Marketplace.

Question 199

A company is operating several factories where it builds products. The company needs the ability to process data, store data, and run applications with local system interdependencies that require low latency.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS loT Greengrass

B.

AWS Lambda

C.

AWS Outposts

D.

AWS Snowball Edge

Question 200

A company wants to migrate critical on-premises production systems to Amazon EC2 instances. The production instances will be used for at least 3 years. The company wants a pricing option that will minimize cost.

Which solution will meet these requirements?

Options:

A.

On-Demand Instances

B.

Reserved Instances

C.

Spot Instances

D.

AWS Free Tier

Question 201

Which AWS service is a fully managed NoSQL database service?

Options:

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon DynamoDB

D.

Amazon Aurora

Question 202

Which AWS services or features provide disaster recovery solutions for Amazon EC2 instances? (Select TWO.)

Options:

A.

EC2 Reserved Instances

B.

EC2 Amazon Machine Images (AMIs)

C.

Amazon Elastic Block Store (Amazon EBS) snapshots

D.

AWS Shield

E.

Amazon GuardDuty

Question 203

A company uses AWS for its web application. The company wants to minimize latency and perform compute operations for the application as close to end users as possible.

Which AWS service or infrastructure component will provide this functionality?

Options:

A.

AWS Regions

B.

Availability Zones

C.

Edge locations

D.

AWS Direct Connect

Question 204

A company has created an AWS Cost and Usage Report and wants to visualize the report.

Which AWS service should the company use to ingest and display this information?

Options:

A.

Amazon QuickSight

B.

Amazon Pinpoint

C.

Amazon Neptune

D.

Amazon Kinesis

Question 205

A company wants to run a graph query that provides credit card users' names, addresses, and transactions. The company wants the graph to show if the names, addresses, and transactions indicates possible fraud.

Which AWS database service will meet these requirements?

Options:

A.

Amazon DocumenlDB (with MongoDB compatibility)

B.

Amazon Timestream

C.

Amazon DynamoDB

D.

Amazon Neptune

Question 206

Which AWS service provides command line access to AWS tools and resources directly (torn a web browser?

Options:

A.

AWS CIoudHSM

B.

AWS CloudShell

C.

Amazon Workspaces

D.

AWS Cloud Map

Question 207

Which AWS service gives users on-demand, sell-service access to AWS compliance control reports?

Options:

A.

AWS Config

B.

Amazon GuardDuty

C.

AWS Trusted Advisor

D.

AWS Artifact

Question 208

Which AWS service is a cloud security posture management (CSPM) service that aggregates alerts from various AWS services and partner products in a standardized format?

Options:

A.

AWS Security Hub

B.

AWS Trusted Advisor

C.

Amazon EventBndge

D.

Amazon GuardDuty

Question 209

A company wants to automatically add and remove Amazon EC2 instances. The company wants the EC2 instances to adjust to varying workloads dynamically.

Which service or feature will meet these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon EC2 Spot Instances

C.

AWS Snow Family

D.

Amazon EC2 Auto Scaling

Question 210

Which AWS service provides this functionality?

Options:

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Systems Manager

C.

AWS Config

D.

AWS Control Tower

Question 211

A company plans to launch an ecommerce website that contains many images for a product catalog. The company wants to keep the cost of running the website within a specific budget.

Which AWS service or tool should the company use to monitor the ongoing costs of the website?

Options:

A.

AWS Cost Explorer

B.

AWS SDKs

C.

EC2 Image Builder

D.

AWS CloudFormation

Question 212

A company has teams that have different job roles and responsibilities. The company's employees often change teams. The company needs to manage permissions for the employees so that the permissions are appropriate for the job responsibilities.

Which IAM resource should the company use to meet this requirement with the LEAST operational overhead?

Options:

A.

IAM user groups

B.

IAM roles

C.

IAM instance profiles

D.

IAM policies for individual users

Question 213

A company wants to rightsize its Amazon EC2 instances.

Which configuration change will meet this requirement with the LEAST operational overhead?

Options:

A.

Add EC2 instances in another Availability Zone.

B.

Change the size and type of the EC2 instances based on utilization.

C.

Convert the payment method from On-Demand to Savings Plans.

D.

Reprovision the EC2 instances with a larger instance type.

Question 214

A company hosts a large amount of data in AWS. The company wants to identify if any of the data should be considered sensitive.

Which AWS service will meet the requirement?

Options:

A.

Amazon Inspector

B.

Amazon Macie

C.

AWS Identity and Access Management (IAM)

D.

Amazon CloudWatch

Question 215

A company wants to build, tram, and deploy machine learning (ML) models.

Which AWS service can the company use to meet this requirement?

Options:

A.

Amazon Personalize

B.

Amazon Comprehend

C.

Amazon Forecast

D.

Amazon SageMaker

Question 216

Which of the following is an advantage that the AWS Cloud provides to users?

Options:

A.

Users eliminate the need to guess about infrastructure capacity requirements.

B.

Users decrease their variable costs by maintaining sole ownership of IT hardware.

C.

Users maintain control of underlying IT infrastructure hardware.

D.

Users maintain control of operating systems for managed services.

Question 217

A company runs an uninterruptible Amazon EC2 workload on AWS 24 hours a day. 7 days a week. The company will require the same instance family and instance type to run the workload for the next 12 months.

Which combination of purchasing options should the company choose to MOST optimize costs? (Select TWO.)

Options:

A.

Standard Reserved Instance

B.

Convertible Reserved Instance

C.

Compute Savings Plan

D.

Spot Instance

E.

All Upfront payment

Question 218

Which AWS Support plan provides the full set of AWS Trusted Advisor checks at the LOWEST cost?

Options:

A.

AWS Developer Support

B.

AWS Business Support

C.

AWS Enterprise On-Ramp Support

D.

AWS Enterprise Support

Question 219

A company has a centralized group of users with large file storage requirements that have exceeded the space available on premises. The company wants to extend its file storage capabilities for this group while retaining the performance benefit of sharing content locally.

What is the MOST operationally efficient AWS solution for this scenario?

Options:

A.

Create an Amazon S3 bucket for each user. Mount each bucket by using an S3 file system mounting utility.

B.

Configure and deploy an AWS Storage Gateway file gateway. Connect each user's workstation to the file gateway.

C.

Move each user's working environment to Amazon Workspaces. Set up an Amazon WorkDocs account for each user.

D.

Deploy an Amazon EC2 instance and attach an Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS volume. Share the EBS volume directly with the users.

Question 220

Which fully managed AWS service assists with the creation, testing, and management of custom Amazon EC? images?

Options:

A.

EC2 Image Builder

B.

Amazon Machine Image (AMI)

C.

AWS Launch Wizard

D.

AWS Elastic Beanstalk

Question 221

A company wants to run a NoSQL database on Amazon EC2 instances.

Which task is the responsibility of AWS in this scenario"?

Options:

A.

Update the guest operating system of the EC2 instances

B.

Maintain high availability at the database layer

C.

Patch the physical infrastructure that hosts the EC2 instances

D.

Configure the security group firewall

Question 222

A company that has multiple business units wants to centrally manage and govern its AWS Cloud environments. The company wants to automate the creation of AWS accounts, apply service control policies (SCPs), and simplify billing processes.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

AWS Organizations

B.

Cost Explorer

C.

AWS Budgets

D.

AWS Trusted Advisor

Question 223

What is the total volume of data that can be stored in Amazon S3?

Options:

A.

10 PB

B.

50 PB

C.

100 PB

D.

Virtually unlimited

Question 224

Which benefit is always free of charge with AWS, regardless of a user's AWS Support plan?

Options:

A.

AWS Developer Support

B.

AWS Developer Forums

C.

Programmatic case management

D.

AWS technical account manager (TAM)

Question 225

A company needs to convert video files and audio files to a format that will play on smartphones.

Which AWS service will meet this requirement?

Options:

A.

Amazon Comprehend

B.

Amazon Rekognition

C.

Amazon Elastic Transcoder

D.

Amazon Polly

Question 226

Which type of AWS storage is ephemeral and is deleted when an Amazon EC2 instance is stopped or terminated?

Options:

A.

Amazon Elastic Block Store (Amazon EBS)

B.

Amazon EC2 instance store

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3

Question 227

A software engineer wants to launch a virtual machine (VM) and MySQL database on AWS.

Which AWS service will meet these requirements with the LEAST operational effort?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Elastic Beanstalk

C.

Amazon Lightsail

D.

Amazon EC2

Question 228

A company wants an AWS service to provide product recommendations based on its customer data.

Which AWS service will meet this requirement?

Options:

A.

Amazon Polly

B.

Amazon Personalize

C.

Amazon Comprehend

D.

Amazon Rekognition

Question 229

Which AWS service helps users plan and track their server and application inventory migration data to AWS?

Options:

A.

Amazon CloudWatch

B.

AWS DataSync

C.

AWS Migration Hub

D.

AWS Application Migration Service

Question 230

Which AWS services can a company use to achieve a loosely coupled architecture? (Select TWO.)

Options:

A.

Amazon Workspaces

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon Connect

D.

AWS Trusted Advisor

E.

AWS Step Functions

Question 231

For which AWS service is the customer responsible for maintaining the underlying operating system?

Options:

A.

Amazon DynamoDB

B.

Amazon S3

C.

Amazon EC2

D.

AWS Lambda

Question 232

A company has a compute workload that is steady, predictable, and uninterruptible.

Which Amazon EC2 instance purchasing options meet these requirements MOST cost-effectively? (Select TWO.)

Options:

A.

On-Demand Instances

B.

Reserved Instances

C.

Spot Instances

D.

Saving Plans

E.

Dedicated Hosts

Question 233

A company has a workload that will run continuously for 1 year. The workload cannot tolerate service interruptions.

Which Amazon EC2 purchasing option will be MOST cost-effective?

Options:

A.

All Upfront Reserved Instances

B.

Partial Upfront Reserved Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 234

A company hosts its website on Amazon EC2 instances. The company needs to ensure that the website reaches a global audience and provides minimum latency to users.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Route 53

B.

Amazon CloudFront

C.

Elastic Load Balancing

D.

AWS Lambda

Question 235

Which options are AWS Cloud Adoption Framework (AWS CAF) cloud transformation journey recommendations? (Select TWO.)

Options:

A.

Envision phase

B.

AIign phase

C.

Assess phase

D.

Mobilize phase

E.

Migrate and modernize phase

Question 236

A company wants to monitor for misconfigured security groups that are allowing unrestricted access to specific ports. Which AWS service will meet this requirement?

Options:

A.

AWS Trusted Advisor

B.

Amazon CloudWatch

C.

Amazon GuardDuty

D.

AWS Health Dashboard

Question 237

Which AWS Cloud deployment model uses AWS Outposts as part of the application deployment infrastructure?

Options:

A.

On-premises

B.

Serverless

C.

Cloud-native

D.

Hybrid

Question 238

Which AWS service or feature identifies whether an Amazon S3 bucket or an IAM role has been shared with an external entity?

Options:

A.

AWS Service Catalog

B.

AWS Systems Manager

C.

AWS IAM Access Analyzer

D.

AWS Organizations

Exam Detail
Exam Code: CLF-C02
Last Update: Jan 24, 2025
CLF-C02 Question Answers
Page: 1 / 60
Total 794 questions