Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Amazon Web Services CLF-C02 Dumps

Page: 1 / 79
Total 794 questions

AWS Certified Cloud Practitioner Questions and Answers

Question 1

A company wants to migrate its on-premises application to the AWS Cloud. The company is legally obligated to retain certain data in its onpremises data center.

Which AWS service or feature will support this requirement?

Options:

A.

AWS Wavelength

B.

AWS Local Zones

C.

VMware Cloud on AWS

D.

AWS Outposts

Question 2

Which aspect of security is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Patch and configuration management

B.

Service and communications protection or zone security

C.

Physical and environmental controls

D.

Awareness and training

Question 3

Which AWS service can a company use to securely store and encrypt passwords for a database?

Options:

A.

AWS Shield

B.

AWS Secrets Manager

C.

AWS Identity and Access Management (IAM)

D.

Amazon Cognito

Question 4

A company wants to use Amazon EC2 instances to run a stateless and restartable process after business hours.

Which AWS service provides DNS resolution?

Options:

A.

Amazon CloudFront

B.

Amazon VPC

C.

Amazon Route 53

D.

AWS Direct Connect

Question 5

A company is setting up AWS Identity and Access Management (IAM) on an AWS account.

Which recommendation complies with IAM security best practices?

Options:

A.

Use the account root user access keys for administrative tasks.

B.

Grant broad permissions so that all company employees can access the resources they need.

C.

Turn on multi-factor authentication (MFA) for added security during the login process.

D.

Avoid rotating credentials to prevent issues in production applications.

Question 6

A company wants to move its data warehouse application to the AWS Cloud. The company wants to run and scale its analytics services without needing to provision and manage data warehouse clusters.

Which AWS service will meet these requirements?

Options:

A.

Amazon Redshift provisioned data warehouse

B.

Amazon Redshift Serverless

C.

Amazon Athena

D.

Amazon S3

Question 7

Which options are perspectives that include foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)? (Select TWO.)

Options:

A.

Sustainability

B.

Security

C.

Operations

D.

Performance efficiency

E.

Reliability

Question 8

A company wants an in-memory data store that is compatible with open source in the cloud.

Which AWS service should the company use?

Options:

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon Redshift

Question 9

Which credential allows programmatic access to AWS resources for use from the AWS CLI or the AWS API?

Options:

A.

User name and password

B.

Access keys

C.

SSH public keys

D.

AWS Key Management Service (AWS KMS) keys

Question 10

Which AWS service is designed to help users build conversational interfaces into applications using voice and text?

Options:

A.

Amazon Lex

B.

Amazon Transcribe

C.

Amazon Comprehend

D.

Amazon Timestream

Question 11

Which AWS Cloud design principle does a company follow by using AWS CloudTrail?

Options:

A.

Recover automatically.

B.

Perform operations as code.

C.

Measure efficiency.

D.

Ensure traceability.

Question 12

A developer wants to use an Amazon S3 bucket to store application logs that contain sensitive data.

Which AWS service or feature should the developer use to restrict read and write access to the S3 bucket?

Options:

A.

Security groups

B.

Amazon CloudWatch

C.

AWS CloudTrail

D.

ACLs

Question 13

Which AWS service requires the customer to patch the guest operating system?

Options:

A.

AWS Lambda

B.

Amazon OpenSearch Service

C.

Amazon EC2

D.

Amazon ElastiCache

Question 14

A retail company has recently migrated its website to AWS. The company wants to ensure that it is protected from SQL injection attacks. The website uses an Application Load Balancer to distribute traffic to multiple Amazon EC2 instances.

Which AWS service or feature can be used to create a custom rule that blocks SQL injection attacks?

Options:

A.

Security groups

B.

AWS WAF

C.

Network ACLs

D.

AWS Shield

Question 15

Which AWS service is used to temporarily provide federated security credentials to a

Options:

A.

Amazon GuardDuty

B.

AWS Simple Token Service (AWS STS)

C.

AWS Secrets Manager

D.

AWS Certificate Manager

Question 16

Which benefit of the AWS Cloud helps companies achieve lower usage costs because of the aggregate usage of all AWS users?

Options:

A.

No need to guess capacity

B.

Ability to go global in minutes

C.

Economies of scale

D.

Increased speed and agility

Question 17

Which AWS services or tools are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks? (Select TWO.)

Options:

A.

VPC endpoint

B.

Virtual private gateway

Q C. AWS Shield Standard

C.

AWS Config

D.

AWS WAF

Question 18

A company moves a workload to AWS to run on Amazon EC2 instances. The company needs to run the workload in the most cost-effective way.

What can the company do to meet this requirement?

Options:

A.

Use AWS Key Management Service (AWS KMS).

B.

Use multiple AWS accounts and consolidated billing.

C.

Use AWS CloudFormation to deploy the infrastructure.

D.

Rightsized all the EC2 instances that are used in the deployment.

Question 19

A company wants to implement controls (guardrails) in a newly created AWS Control Tower landing zone.

Which AWS services or features can the company use to create and define these controls (guardrails)? (Select TWO.)

Options:

A.

AWS Config

B.

Service control policies (SCPs)

C.

Amazon GuardDuty

D.

AWS Identity and Access Management (IAM)

E.

Security groups

Question 20

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

Options:

A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Question 21

A company must store call recordings for 6 years. The storage system should be highly durable and cost-effective.

Which AWS service meets these requirements?

Options:

A.

AWS Snowball

B.

Amazon S3

C.

AWS Storage Gateway

D.

Amazon Kinesis

Question 22

A company is running an order processing system on Amazon EC2 instances. The company wants to migrate microservices-based application.

Which combination of AWS services can the application use to meet these requirements? (Select TWO.)

Options:

A.

Amazon Simple Queue Service (Amazon SQS)

B.

AWS Lambda

C.

AWS Migration Hub

D.

AWS AppSync

E.

AWS Application Migration Service

Question 23

A large company has multiple departments. Each department has its own AWS account. Each department has purchased Amazon EC2 Reserved Instances. Some departments do not use all the Reserved Instances that they purchased, and other departments need more Reserved Instances than they purchased.

The company needs to manage the AWS accounts for all the departments so that the departments can share the Reserved Instances.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

AWS Systems Manager

B.

Cost Explorer

C.

AWS Trusted Advisor

D.

AWS Organizations

Question 24

A company is hosting a web application on Amazon EC2 instances. The company wants to implement custom conditions to filter and control inbound web traffic.

Which AWS service will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

AWSWAF

C.

Amazon Macie

D.

AWS Shield

Question 25

A company wants to migrate its applications to the AWS Cloud. The company plans to identify and prioritize any business transformation opportunities and evaluate its AWS Cloud readiness.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

AWS Cloud Adoption Framework (AWS CAF)

B.

AWS Managed Services (AMS)

C.

AWS Well-Architected Framework

D.

AWS Migration Hub

Question 26

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

Options:

A.

Sustainability

B.

Operations

C.

Performance efficiency

D.

Reliability

Question 27

A company needs to launch an Amazon EC2 instance.

Which of the following can the company use during the launch process to configure the root volume of the EC2 instance?

Options:

A.

Amazon EC2 Auto Scaling

B.

Amazon Data Lifecycle Manager (Amazon DLM)

C.

Amazon Machine Image (AMI)

D.

Amazon Elastic Block Store (Amazon EBS) volume

Question 28

Which AWS service or tool should a company use to forecast AWS spending?

Options:

A.

Amazon DevPay

B.

AWS Organizations

C.

AWS Trusted Advisor

D.

Cost Explorer

Question 29

A company is running an application that is hosted on Amazon EC2 instances. The usage of the EC2 instances is higher during daytime hours than nighttime hours. The company wants to optimize the number of EC2 instances based on this usage pattern.

Which AWS service or instance purchasing option should the company use to meet these requirements?

Options:

A.

Spot Instances

B.

Reserved Instances

C.

AWS CloudFormation

D.

AWS Auto Scaling

Question 30

A company has an Amazon S3 bucket containing images of scanned financial invoices. The company is building an artificial intelligence (Al)-based application on AWS. The company wants the application to identify and read total balance amounts on the invoices.

Which AWS service will meet these requirements?

Options:

A.

Amazon Forecast

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Lex

Question 31

Which AWS service or tool provides recommendations to help users get rightsized Amazon EC2 instances based on historical workload usage data?

Options:

A.

AWS Pricing Calculator

B.

AWS Compute Optimizer

C.

AWS App Runner

D.

AWS Systems Manager

Question 32

Which AWS service is always free of charge for users?

Options:

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

AWS Identity and Access Management (IAM)

Question 33

A manufacturing company has a critical application that runs at a remote site that has a slow internet connection. The company wants to migrate the workload to AWS. The application is sensitive to latency and interruptions in connectivity. The company wants a solution that can host this application with minimum latency.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

Availability Zones

B.

AWS Local Zones

C.

AWS Wavelength

D.

AWS Outposts

Question 34

Which of the following is entirely the responsibility of AWS, according to the AWS shared responsibility model?

Options:

A.

Security awareness and training

B.

Development of an IAM password policy

C.

Patching of the guest operating system

D.

Physical and environmental controls

Question 35

A company is collecting user behavior patterns to identify how to meet goals for sustainability impact.

Which guidelines are best practices for the company to implement to meet these goals? (Select TWO.)

Options:

A.

Scale infrastructure with user load.

B.

Maximize the geographic distance between workloads and user locations.

C.

Eliminate creation and maintenance of unused assets.

D.

Scale resources with excess capacity and remove auto scaling.

E.

Scale infrastructure based on the number of users.

Question 36

A company needs to host a web server on Amazon EC2 instances for at least 1 year. The web server cannot tolerate interruption.

Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

Options:

A.

On-Demand Instances

B.

Partial Upfront Reserved Instances

C.

Spot Instances

D.

No Upfront Reserved Instances

Question 37

A company wants to run its production workloads on AWS. The company needs concierge service, a designated AWS technical account manager (TAM), and technical support that is available 24 hours a day, 7 days a week.

Which AWS Support plan will meet these requirements?

Options:

A.

AWS Basic Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Developer Support

Question 38

A company wants to securely store Amazon RDS database credentials and automatically rotate user passwords periodically.

Which AWS service or capability will meet these requirements?

Options:

A.

Amazon S3

B.

AWS Systems Manager Parameter Store

C.

AWS Secrets Manager

D.

AWS CloudTrail

Question 39

A company is preparing to launch a redesigned website on AWS. Users from around the world will download digital handbooks from the website.

Which AWS solution should the company use to provide these static files securely?

Options:

A.

Amazon Kinesis Data Streams

B.

Amazon CloudFront with Amazon S3

C.

Amazon EC2 instances with an Application Load Balancer

D.

Amazon Elastic File System (Amazon EFS)

Question 40

Which AWS service provides the SIMPLEST way for the company to establish a website on AWS?

Options:

A.

Amazon Elastic File System (Amazon EFS)

B.

AWS Elastic Beanstalk

C.

AWS Lambda

D.

Amazon Lightsail

Question 41

A company needs Amazon EC2 instances for a workload that can tolerate interruptions.

Which EC2 instance purchasing option meets this requirement with the LARGEST discount compared to On-Demand prices?

Options:

A.

Spot Instances

B.

Convertible Reserved Instances

C.

Standard Reserved Instances

D.

Dedicated Hosts

Question 42

A company wants to move its iOS application development and build activities to AWS.

Which AWS service or resource should the company use for these activities?

Options:

A.

AWS CodeCommit

B.

Amazon EC2 M1 Mac instances

C.

AWS Amplify

D.

AWS App Runner

Question 43

A company wants its Amazon EC2 instances to share the same geographic area but use redundant underlying power sources.

Which solution will meet these requirements?

Options:

A.

Use EC2 instances across multiple Availability Zones in the same AWS Region.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in AWS OpsWorks stacks in different AWS Regions.

Question 44

Which AWS services allow users to monitor and retain records of account activities that include governance, compliance, and auditing?

(Select TWO.)

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

Amazon GuardDuty

D.

AWS Shield

E.

AWS WAF

Question 45

A company has an application workload that is stateless by design and can sustain occasional downtime. The application performs massively parallel computations.

Which Amazon EC2 pricing model should the company choose for its application to reduce cost?

Options:

A.

On-Demand Instances

B.

Spot Instances

C.

Reserved Instances

D.

Dedicated Instances

Question 46

Which option is a pillar of the AWS Well-Architected Framework?

Options:

A.

Patch management

B.

Cost optimization

C.

Business technology strategy

D.

Physical and environmental controls

Question 47

What is a characteristic of Convertible Reserved Instances (RIs)?

Options:

A.

Users can exchange Convertible RIs for other Convertible RIs from a different instance family.

B.

Users can exchange Convertible RIs for other Convertible RIs in different AWS Regions.

C.

Users can sell and buy Convertible RIs on the AWS Marketplace.

D.

Users can shorten the term of their Convertible RIs by merging them with other Convertible RIs.

Question 48

Which AWS services can a company use to host and run a MySQL database? (Select TWO.)

Options:

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon S3

D.

Amazon EC2

E.

Amazon MQ

Question 49

A company wants its workload to perform consistently and correctly.

Which benefit of AWS Cloud computing does this goal represent?

Options:

A.

Security

B.

Elasticity

C.

Pay-as-you-go pricing

D.

Reliability

Question 50

A company wants to migrate its Microsoft SQL Server database management system from on premises to the AWS Cloud.

Which AWS service should the company use to reduce management overhead for this environment?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon SageMaker

C.

Amazon RDS

D.

Amazon Athena

Question 51

Which benefit of AWS Cloud computing provides lower latency between users and applications?

Options:

A.

Agility

B.

Economies of scale

C.

Global reach

D.

Pay-as-you-go pricing

Question 52

A company wants guidance to optimize the cost and performance of its current AWS environment.

Which AWS service or tool should the company use to identify areas for optimization?

Options:

A.

Amazon QuickSight

B.

AWS Trusted Advisor

C.

AWS Organizations

D.

AWS Budgets

Question 53

A company wants to migrate its application to AWS. The company wants to replace upfront expenses with variable payment that is based on usage.

What should the company do to meet these requirements?

Options:

A.

Use pay-as-you-go pricing.

B.

Purchase Reserved Instances.

C.

Pay less by using more.

D.

Rightsize instances.

Question 54

Which AWS service or tool provides on-demand access to AWS security and compliance reports and AWS online agreements?

Options:

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS Billing console

Question 55

Which AWS service provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning (ML)?

Options:

A.

Amazon Kendra

B.

Amazon SageMaker

C.

Amazon Augmented Al (Amazon A2I)

D.

Amazon Polly

Question 56

Which AWS service can defend against DDoS attacks?

Options:

A.

AWS Firewall Manager

B.

AWS Shield Standard

C.

AWS WAF

D.

Amazon Inspector

Question 57

Which task is the responsibility of AWS when using AWS services?

Options:

A.

Management of IAM user permissions

B.

Creation of security group rules for outbound access

C.

Maintenance of physical and environmental controls

D.

Application of Amazon EC2 operating system patches

Question 58

Which AWS solution should the company use to meet this requirement?

Options:

A.

AWS Config

B.

AWS software development kits (SDKs)

C.

AWS Service Catalog

D.

AWS AppSync

Question 59

A company migrated its core application onto multiple workloads in the AWS Cloud. The company wants to improve the application's reliability.

Which cloud design principle should the company implement to achieve this goal?

Options:

A.

Maximize utilization.

B.

Decouple the components.

C.

Rightsize the resources.

D.

Adopt a consumption model.

Question 60

A company has an application that runs periodically in an on-premises environment. The application runs for a few hours most days, but runs for 8 hours a day for a week at the end of each month.

Which AWS service or feature should be used to host the application in the AWS Cloud?

Options:

A.

Amazon EC2 Standard Reserved Instances

B.

Amazon EC2 On-Demand Instances

C.

AWS Wavelength

D.

Application Load Balancer

Question 61

A company has an AWS-hosted website located behind an Application Load Balancer. The company wants to safeguard the website from SQL injection or cross-site scripting.

Which AWS service should the company use?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Trusted Advisor

D.

Amazon Inspector

Question 62

Which controls are the responsibility of both AWS and AWS customers, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Physical and environmental controls

B.

Patch management

C.

Configuration management

D.

Account structures

E.

Choice of the AWS Region where data is stored

Question 63

A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access.

According to the AWS shared responsibility model, which task is the responsibility of the customer?

Options:

A.

Protect the global infrastructure that runs all of the services offered in the AWS Cloud.

B.

Configure logical access controls for resources, and protect account credentials.

C.

Configure the security used by managed services.

D.

Patch and back up Amazon Aurora.

Question 64

In which categories does AWS Trusted Advisor provide recommended actions? (Select TWO.)

Options:

A.

Operating system patches

B.

Cost optimization

C.

Repetitive tasks

D.

Service quotas

E.

Account activity records

Question 65

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances. The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 66

Which options are common stakeholders for the AWS Cloud Adoption Framework (AWS CAF) platform perspective? (Select TWO.)

Options:

A.

Chief financial officers (CFOs)

B.

IT architects

C.

Chief information officers (CIOs)

D.

Chief data officers (CDOs)

E.

Engineers

Question 67

How should the company deploy the application to meet these requirements?

Options:

A.

Ina single Availability Zone

B.

On AWS Direct Connect

C.

On Reserved Instances

D.

In multiple Availability Zones

Question 68

Which actions are examples of a company's effort to right size its AWS resources to control cloud costs? (Select TWO.)

Options:

A.

Switch from Amazon RDS to Amazon DynamoDB to accommodate NoSQL datasets.

Q B. Base the selection of Amazon EC2 instance types on past utilization patterns.

B.

Use Amazon S3 Lifecycle policies to move objects that users access infrequently to lower-cost storage tiers.

C.

Use Multi-AZ deployments for Amazon RDS.

D.

Replace existing Amazon EC2 instances with AWS Elastic Beanstalk.

Question 69

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

Options:

A.

Third-party vendors

B.

Customers

C.

Reseller partners

D.

Internet providers

Question 70

An application runs on multiple Amazon EC2 instances that access a shared file system simultaneously.

Which AWS storage service should be used?

Options:

A.

Amazon EBS

B.

Amazon EFS

C.

Amazon S3

D.

AWS Artifact

Question 71

A company wants to use Amazon EC2 instances for a stable production workload that will run for 1 year.

Which instance purchasing option meets these requirements MOST cost-effectively?

Options:

A.

Dedicated Hosts

B.

Reserved Instances

C.

On-Demand Instances

D.

Spot Instances

Question 72

Which AWS service or tool helps companies measure the environmental impact of their AWS usage?

Options:

A.

AWS customer carbon footprint tool

B.

AWS Compute Optimizer

C.

Sustainability pillar

D.

OS-Climate (Open Source Climate Data Commons)

Question 73

A company has a single Amazon EC2 instance. The company wants to adopt a highly available architecture.

What can the company do to meet this requirement?

Options:

A.

Scale vertically to a larger EC2 instance size.

B.

Scale horizontally across multiple Availability Zones.

C.

Purchase an EC2 Dedicated Instance.

D.

Change the EC2 instance family to a compute optimized instance.

Question 74

Which design principles should a company apply to AWS Cloud workloads to maximize sustainability and minimize environmental impact? (Select TWO.)

Options:

A.

Maximize utilization of Amazon EC2 instances.

B.

Minimize utilization of Amazon EC2 instances.

C.

Minimize usage of managed services.

D.

Force frequent application reinstallations by users.

E.

Reduce the need for users to reinstall applications.

Question 75

What is an AWS responsibility under the AWS shared responsibility model?

Options:

A.

Configure the security group rules that determine which ports are open on an Amazon EC2 Linux instance.

B.

Ensure the security of the internal network in the AWS data centers.

C.

Patch the guest operating system with the latest security patches on Amazon EC2.

D.

Turn on server-side encryption for Amazon S3 buckets.

A company wants to deploy its critical application on AWS and maintain high availability.

Question 76

A company that is planning to migrate to the AWS Cloud is based in an isolated area that has limited internet connectivity. The company needs to perform local data processing on premises. The company needs a solution that can operate without a stable internet connection.

Which AWS service will meet these requirements?

Options:

A.

Amazon S3

B.

AWS Snowball Edge

C.

AWS StorageGateway

D.

AWS Backup

Question 77

A company wants to create multiple isolated networks in the same AWS account.

Which AWS service or component will provide this functionality?

Options:

A.

AWS Transit Gateway

B.

Internet gateway

C.

Amazon VPC

D.

Amazon EC2

Question 78

A company has set up a VPC in its AWS account and has created a subnet in the VPC. The company wants to make the subnet public.

Which AWS features should the company use to meet this requirement? (Select TWO.)

Options:

A.

Amazon VPC internet gateway

B.

Amazon VPC NAT gateway

C.

Amazon VPC route tables

D.

Amazon VPC network ACL

E.

Amazon EC2 security groups

Question 79

Which encryption types can be used to protect objects at rest in Amazon S3? (Select TWO.)

Options:

A.

Server-side encryption with AmazonS3 managed encryption keys (SSE-S3)

B.

Server-side encryption with AWS KMSmanaged keys (SSE-KMS)

C.

TLS

D.

SSL

E.

Transparent Data Encryption (TDE)

Question 80

A company wants to create a chatbot and integrate the chatbot with its current web application.

Which AWS service will meet these requirements?

Options:

A.

AmazonKendra

B.

Amazon Lex

C.

AmazonTextract

D.

AmazonPolly

Question 81

A company needs to run code in response to an event notification that occurs when objects are uploaded to an Amazon S3 bucket.

Which AWS service will integrate directly with the event notification?

Options:

A.

AWS Lambda

B.

Amazon EC2

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

AWS Elastic Beanstalk

Question 82

Which AWS service or feature is used to send both text and email messages from distributed applications?

Options:

A.

Amazon Simple Notification Service (Amazon SNS)

B.

Amazon Simple Email Service (Amazon SES)

C.

Amazon CloudWatch alerts

D.

Amazon Simple Queue Service (Amazon SQS)

Question 83

What is an Availability Zone?

Options:

A.

A location where users can deploy compute, storage, database, and other select AWS services

where no AWS Region currently exists

B.

One or more discrete data centers with redundant power, networking, and connectivity

C.

One or more clusters of servers where new workloads can be deployed

D.

A fast content delivery network (CDN) service that securely delivers data, videos, applications, and

APIs to users globally

Question 84

An application is running on multiple Amazon EC2 instances. The company wants to make the application highly available by configuring a load balancer with requests forwarded to the EC2 instances based on URL paths.

Which AWS load balancer will meet these requirements and take the LEAST amount of effort to deploy?

Options:

A.

Network Load Balancer

B.

Application Load Balancer

C.

AWS OpsWorks Load Balancer

D.

Custom Load Balancer on Amazon EC2

Question 85

A cloud engineer wants to know the percentage of the allocated compute units that are in use for a specific Amazon EC2 instance.

Which AWS service can provide this information?

Options:

A.

AWS CloudTrail

B.

AWS Config

C.

Amazon CloudWatch

D.

AWS Artifact

Question 86

Which pillar of the AWS Well-Architected Framework focuses on the return on investment of moving into the AWS Cloud?

Options:

A.

Sustainability

B.

Cost optimization

C.

Operational excellence

D.

Reliability

Question 87

Which AWS service or feature can be used to estimate costs before deployment?

Options:

A.

AWS Free Tier

B.

AWS Pricing Calculator

C.

AWS Billing and Cost Management

D.

AWS Cost and Usage Report

Question 88

A company wants to establish a security layer in its VPC that will act as a firewall to control subnet traffic.

Which AWS service or feature will meet this requirement?

Options:

A.

Routing tables

B.

Network access control lists (network ACLs)

C.

Security groups

D.

Amazon GuardDuty

Question 89

Which AWS service gives users the ability to provision a dedicated and private network connection from their internal

network to AWS?

Options:

A.

AWS CloudHSM

B.

AWS Direct Connect

C.

AWS VPN

D.

Amazon Connect

Question 90

A company is designing an identity access management solution for an application. The company wants users to be able to use their social media, email, or online shopping accounts to access the application.

Which AWS service provides this functionality?

Options:

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Config

C.

Amazon Cognito

D.

AWS Identity and Access Management (IAM)

Question 91

Which of the following are design principles for reliability in the AWS Cloud? (Select TWO.)

Options:

A.

Build architectures with tightly coupled resources.

B.

Use AWS Trusted Advisor to meet security best practices.

C.

Use automation to recover immediately from failure.

D.

Rightsize Amazon EC2 instances to ensure optimal performance.

E.

Simulate failures to test recovery processes.

Question 92

Which AWS service will help protect applications running on AWS from DDoS attacks?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Shield

D.

Amazon Inspector

Question 93

A large company wants to track the combined AWS usage costs of all of its linked accounts.

How can this be accomplished?

Options:

A.

Use AWS Trusted Advisor to generate customized summary reports.

B.

Use AWS Organizations to generate consolidated billing reports.

C.

Use AWS Budgets to set utilization targets and receive summary reports.

D.

Use the AWS Control Tower dashboard to get a summary report of all linked account costs.

Question 94

A company uses Amazon Aurora as its database service. The company wants to encrypt its databases and database backups.

Which party manages the encryption of the database clusters and database snapshots, according to the AWS shared responsibility

model?

Options:

A.

AWS

B.

The company

C.

AWS Marketplace partners

D.

Third-party partners

Question 95

A company recently migrated to the AWS Cloud. The company needs to determine whether its newly imported Amazon EC2 instances are the appropriate size and type.

Which AWS services can provide this information to the company? {Select TWO.)

Options:

A.

AWS Auto Scaling

B.

AWS Control Tower

C.

AWS Trusted Advisor

D.

AWS Compute Optimizer

E.

Amazon Forecast

Question 96

A company wants to host its relational databases on AWS. The databases have predefined schemas that the company needs to replicate on AWS.

Which AWS services could the company use for the databases? (Select TWO.)

Options:

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

E.

Amazon DynamoDB

Question 97

Which of the following is an advantage of AWS Cloud computing?

Options:

A.

Trade security for elasticity.

B.

Trade operational excellence for agility.

C.

Trade fixed expenses for variable expenses.

D.

Trade elasticity for performance.

Question 98

Which AWS service can a company use to perform complex analytical queries?

Options:

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon ElastiCache

Question 99

A retail company is migrating its IT infrastructure applications from on premises to the AWS Cloud.

Which costs will the company eliminate with this migration? (Select TWO.)

Options:

A.

Cost of data center operations

B.

Cost of application licensing

C.

Cost of marketing campaigns

D.

Cost of physical server hardware

E.

Cost of network management

Question 100

A company has an application that uses AWS services. During scaling events, the company wants to keep

application usage within AWS service quotas.

Which AWS services or tools can report on the quotas so that the company can improve the reliability of the application? (Select TWO.)

Options:

A.

Service Quotas console

B.

AWS Trusted Advisor

C.

AWS Systems Manager

D.

AWS Shield

E.

AWS Cost Explorer

Question 101

Which of the following are AWS Cloud design principles? (Select TWO.)

Options:

A.

Pay for compute resources in advance.

B.

Make data-driven decisions to determine cloud architectural design.

C.

Emphasize manual processes to allow for changes.

D.

Test systems at production scale.

E.

Refine operational procedures infrequently.

Question 102

Which design principle should be considered when architecting in the AWS Cloud?

Options:

A.

Think of servers as non-disposable resources.

B.

Use synchronous integration of services.

C.

Design loosely coupled components.

D.

Implement the least permissive rules for security groups.

Question 103

Which AWS service is a highly available and scalable DNS web service?

Options:

A.

Amazon VPC

B.

Amazon CloudFront

C.

Amazon Route 53

D.

Amazon Connect

Question 104

When a user wants to utilize their existing per-socket, per-core, or per-virtual machine software licenses for a Microsoft Windows server running on AWS, which Amazon EC2 instance type is required?

Options:

A.

Spot Instances

B.

Dedicated Instances

C.

Dedicated Hosts

D.

Reserved Instances

Question 105

Which of the following is a recommended design principle of the AWS Well-Architected Framework?

Options:

A.

Reduce downtime by making infrastructure changes infrequently and in large increments.

B.

Invest the time to configure infrastructure manually.

C.

Learn to improve from operational failures.

D.

Use monolithic application design for centralization.

Question 106

A company has a social media platform in which users upload and share photos with other users. The company wants to identify and remove inappropriate photos. The company has no machine learning (ML) scientists and must build this detection capability with no ML expertise.

Which AWS service should the company use to build this capability?

Options:

A.

Amazon SageMaker

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Comprehend

Question 107

A company is designing a web application that will run on Amazon EC2 instances.

Which AWS services and features will improve availability and reduce the impact of failures for this application?

(Select TWO.)

Options:

A.

Amazon EC2 Auto Scaling for the EC2 instances

B.

VPC subnet ACLs to check the health of a service

C.

Resources that are distributed across multiple Availability Zones

D.

Configuration of AWS Server Migration Service (AWS SMS) to move the EC2 instances to a different

AWS Region

E.

Resources that are distributed across multiple AWS points of presence

Question 108

Which AWS service will help a company identify the user who deleted an Amazon EC2 instance yesterday?

Options:

A.

Amazon CloudWatch

B.

AWS Trusted Advisor

C.

AWS CloudTrail

D.

Amazon Inspector

Question 109

Which AWS service or tool does AWS Control Tower use to create resources?

Options:

A.

AWS CloudFormation

B.

AWS Trusted Advisor

C.

AWS Directory Service

D.

AWS Cost Explorer

Question 110

Which database engine is compatible with Amazon RDS?

Options:

A.

Apache Cassandra

B.

MongoDB

C.

Neo4j

D.

PostgreSQL

Question 111

Which option is an advantage of AWS Cloud computing that minimizes variable costs?

Options:

A.

High availability

B.

Economies of scale

C.

Global reach

D.

Agility

Question 112

Using Amazon Elastic Container Service (Amazon ECS) to break down a monolithic architecture into microservices is an example of:

Options:

A.

a loosely coupled architecture.

B.

a tightly coupled architecture.

C.

a stateless architecture.

D.

a stateful architecture.

Question 113

A company's user base needs to remotely access virtual desktop computers from the internet Which AWS service provides this functionality?

Options:

A.

Amazon Connect

B.

Amazon Cognito

C.

Amazon Workspaces

D.

Amazon Upstream 2.0

Question 114

Which task requires the use of AWS account root user credentials?

Options:

A.

The deletion of IAM users

B.

The change to a different AWS Support plan

C.

The creation of an organization in AWS Organizations

D.

The deletion of Amazon EC2 instances

Question 115

A company needs to use dashboards and charts to analyze insights from business data.

Which AWS service will provide the dashboards and charts for these insights?

Options:

A.

Amazon Macie

B.

Amazon Aurora

C.

Amazon QuickSight

D.

AWS CloudTrail

Question 116

Which services can be used to deploy applications on AWS? (Select TWO.)

Options:

A.

AWS Elastic Beanstalk

B.

AWS Config

C.

AWS OpsWorks

Q D. AWS Application Discovery Service

D.

Amazon Kinesis

Question 117

A company needs to use standard SQL to query and combine exabytes of structured and semi-structured data across a data warehouse, operational database, and data lake.

Which AWS service meets these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon Athena

D.

Amazon Redshift

Question 118

Which pillar of the AWS Well-Architected Framework focuses on the ability to run workloads effectively, gain insight into operations, and continuously improve supporting processes and procedures?

Options:

A.

Cost optimization

B.

Reliability

C.

Operational excellence

D.

Performance efficiency

Question 119

Which AWS service is a key-value database that provides sub-millisecond latency on a large scale?

Options:

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

Question 120

Which AWS service provides highly durable object storage?

Options:

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon FSx

Question 121

What are the characteristics of Availability Zones? (Select TWO.)

Options:

A.

All Availability Zones in an AWS Region are interconnected with high-bandwidth, low-latency networking

B.

Availability Zones are physically separated by a minimum of distance of 150 km (100 miles).

C.

All traffic between Availability Zones is encrypted.

D.

Availability Zones within an AWS Region share redundant power, networking, and connectivity.

E.

Every Availability Zone contains a single data center.

Question 122

A company is using AWS Lambda functions to build an application.

Which tasks are the company's responsibility, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Patch the servers where the Lambda functions are deployed.

B.

Establish the IAM permissions that define who can run the Lambda functions.

C.

Write the code for the Lambda functions to define the application logic.

D.

Deploy Amazon EC2 instances to support the Lambda functions.

E.

Scale out the Lambda functions when the load increases.

Question 123

A company is launching a new application in the AWS Cloud. The application will run on an Amazon EC2 instance. More EC2 instances will be needed when the workload increases.

Which AWS service or tool can the company use to launch the number of EC2 instances that will be needed to handle the workload?

Options:

A.

Elastic Load Balancing

B.

Amazon EC2 Auto Scaling

C.

AWS App2Container (A2C)

D.

AWS Systems Manager

Question 124

Which task is the responsibility of a company that is using Amazon RDS?

Options:

A.

Provision the underlying infrastructure.

B.

Create IAM policies to control administrative access to the service.

C.

Install the cables to connect the hardware for compute and storage.

D.

Install and patch the RDS operating system.

Question 125

A company needs to configure rules to identify threats and protect applications from malicious network access.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Identity and Access Management (IAM)

B.

Amazon QuickSight

C.

AWS WAF

D.

Amazon Detective

Question 126

Which of the following is a characteristic of the AWS account root user?

Options:

A.

The root user is the only user that can be configured with multi-factor authentication (MFA).

B.

The root user is the only user that can access the AWS Management Console.

C.

The root user is the first sign-in identity that is available when an AWS account is created.

D.

The root user has a password that cannot be changed.

Question 127

A company is building a serverless architecture that connects application data from multiple data sources. The company needs a solution that does not require additional code.

Which AWS service meets these requirements?

Options:

A.

AWS Lambda

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon CloudWatch

D.

Amazon EventBridge

Question 128

What does the Amazon S3 Intelligent-Tiering storage class offer?

Options:

A.

Payment flexibility by reserving storage capacity

B.

Long-term retention of data by copying the data to an encrypted Amazon Elastic Block Store (Amazon

EBS) volume

C.

Automatic cost savings by moving objects between tiers based on access pattern changes

D.

Secure, durable, and lowest cost storage for data archival

Question 129

A company wants to use the AWS Cloud as an offsite backup location for its on-premises infrastructure.

Which AWS service will meet this requirement MOST cost-effectively?

Options:

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon FSx

D.

Amazon Elastic Block Store (Amazon EBS)

Question 130

Which of the following promotes AWS Cloud architectural best practices for designing and operating reliable, secure, efficient, and cost-effective systems?

Options:

A.

AWS Serverless Application Model framework

B.

AWS Business Support

C.

Principle of least privilege

D.

AWS Well-Architected Framework

Question 131

A retail company is building a new mobile app. The company is evaluating whether to build the app at an on-premises data center or in the AWS Cloud.

Which of the following are benefits of building this app in the AWS Cloud? (Select TWO.)

Options:

A.

A large upfront capital expense and low variable expenses

B.

Increased speed for trying out new projects

C.

Complete control over the physical security of the infrastructure

D.

Flexibility to scale up in minutes as the application becomes popular

E.

Ability to pick the specific data centers that will host the application servers

Question 132

What can a user accomplish using AWS CloudTrail?

Options:

A.

Generate an IAM user credentials report.

B.

Record API calls made to AWS services.

C.

Assess the compliance of AWS resource configurations with policies and guidelines.

D.

Ensure that Amazon EC2 instances are patched with the latest security updates.

A company uses Amazon Workspaces.

Question 133

A company wants to ensure that two Amazon EC2 instances are in separate data centers with minimal

communication latency between the data centers.

How can the company meet this requirement?

Options:

A.

Place the EC2 instances in two separate AWS Regions connected with a VPC peering connection.

B.

Place the EC2 instances in two separate Availability Zones within the same AWS Region.

C.

Place one EC2 instance on premises and the other in an AWS Region. Then connect them by using an

AWS VPN connection.

D.

Place both EC2 instances in a placement group for dedicated bandwidth.

Question 134

What are some advantages of using Amazon EC2 instances lo host applications in the AWS Cloud instead of on premises? (Select TWO.)

Options:

A.

EC2 includes operating system patch management

B.

EC2 integrates with Amazon VPC. AWS CloudTrail, and AWS Identity and Access Management (IAM)

C.

EC2 has a 100% service level agreement (SLA).

D.

EC2 has a flexible, pay-as-you-go pricing model.

E.

EC2 has automatic storage cost optimization.

Question 135

Which factors affect costs in the AWS Cloud? (Select TWO.)

Options:

A.

The number of unused AWS Lambda functions

B.

The number of configured Amazon S3 buckets

C.

Inbound data transfers without acceleration

D.

Outbound data transfers without acceleration

E.

Compute resources that are currently in use

Question 136

A cloud practitioner is analyzing Amazon EC2 instance performance and usage to provide recommendations for potential cost savings.

Which cloud concept does this analysis demonstrate?

Options:

A.

Auto scaling

B.

Rightsizing

C.

Load balancing

D.

High availability

Question 137

Which AWS service or tool can be used to consolidate payments for a company with multiple AWS accounts?

Options:

A.

AWS Cost and Usage Report

B.

AWS Organizations

C.

Cost Explorer

D.

AWS Budgets

Question 138

A company's application stores data in an Amazon S3 bucket. The company has an AWS Lambda function that processes data in the S3

bucket. The company needs to invoke the function once a day at a specific time.

Which AWS service should the company use to meet this requirement?

Options:

A.

AWS Managed Services (AMS)

B.

AWS CodeStar

C.

Amazon EventBridge

D.

AWS Step Functions

Question 139

Which task is a customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Management of the guest operating systems

B.

Maintenance of the configuration of infrastructure devices

C.

Management of the host operating systems and virtualization

D.

Maintenance of the software that powers Availability Zones

A company has refined its workload to use specific AWS services to improve efficiency and reduce cost.

Question 140

Which tasks are customer responsibilities according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Determine application dependencies with operating systems.

B.

Provide user access with AWS Identity and Access Management (IAM).

C.

Secure the data center in an Availability Zone.

D.

Patch the hypervisor.

E.

Provide network availability in Availability Zones.

Question 141

A company needs to test a new application that was written in Python. The code will activate when new images are stored in an Amazon S3 bucket. The application will put a watermark on each image and then will store the images in a different S3 bucket.

Which AWS service should the company use to conduct the test with the LEAST amount of operational

overhead?

Options:

A.

Amazon EC2

B.

AWS CodeDeploy

C.

AWS Lambda

D.

Amazon Lightsail

Question 142

Which of the following are components of an AWS Site-to-Site VPN connection? (Select TWO.)

Options:

A.

AWS Storage Gateway

B.

Virtual private gateway

C.

NAT gateway

D.

Customer gateway

E.

Internet gateway

Question 143

Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Patch AWS network devices.

B.

Set user password rules.

C.

Provide physical security for compute resources.

D.

Configure security groups.

E.

Patch the operating system of an Amazon EC2 instance.

Question 144

Which design principle is achieved by following the reliability pillar of the AWS Well-Architected Framework?

Options:

A.

Vertical scaling

B.

Manual failure recovery

C.

Testing recovery procedures

D.

Changing infrastructure manually

Question 145

A company needs to migrate all of its development teams to a cloud-based integrated development environment (IDE).

Which AWS service should the company use?

Options:

A.

AWS CodeBuild

B.

AWS Cloud9

C.

AWS OpsWorks

D.

AWS Cloud Development Kit (AWS CDK)

Question 146

A company has a workload that requires data to be collected, analyzed, and stored on premises. The company wants to extend the use of AWS services to run on premises with access to the company network and the company's VPC.

Which AWS service meets this requirement?

Options:

A.

AWS Outposts

B.

AWS Storage Gateway

C.

AWS Direct Connect

D.

AWS Snowball

Question 147

Which AWS service or feature offers HTTP attack protection to users running public-facing web applications?

Options:

A.

Security groups

B.

Network ACLs

C.

AWS Shield Standard

D.

AWS WAF

Question 148

A company needs to store data across multiple Availability Zones in an AWS Region. The data will not be

accessed regularly but must be immediately retrievable.

Which Amazon Elastic File System (Amazon EFS) storage class meets these requirements MOST cost effectively?

Options:

A.

EFS Standard

B.

EFS Standard-Infrequent Access(EFS Standard-IA)

C.

EFS One Zone

D.

EFS One Zone-Infrequent Access (EFS One Zone-IA)

Question 149

In which of the following AWS services should database credentials be stored for maximum security?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS Secrets Manager

C.

Amazon S3

D.

AWS Key Management Service (AWS KMS)

Question 150

Which AWS services or features can control VPC traffic? (Select TWO.)

Options:

A.

Security groups

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

Network ACLs

E.

Amazon Connect

Question 151

Which options does AWS make available for customers who want to learn about security in the cloud in an instructor-led setting? (Select TWO.)

Options:

A.

AWS Trusted Advisor

B.

AWS Online Tech Talks

C.

AWS Blog

D.

AWS Forums

E.

AWS Classroom Training

Question 152

A newly created IAM user has no IAM policy attached.

What will happen when the user logs in and attempts to view the AWS resources in the account?

Options:

A.

All AWS services will be read-only access by default.

B.

Access to all AWS resources will be denied.

C.

Access to the AWS billing services will be allowed.

D.

Access to AWS resources will be allowed through the AWS CLL

Question 153

Which of the following is a cost efficiency principle related to the AWS Cloud?

Options:

A.

Right-size services based on capacity requirements.

B.

Use the Billing Dashboard to access information about monthly bills.

C.

Use AWS Organizations to combine the expenses of multiple accounts into a single bill.

D.

Tag all AWS resources.

Question 154

What is a benefit of moving to the AWS Cloud in terms of improving time to market?

Options:

A.

Decreased deployment speed

B.

Increased application security

C.

Increased business agility

D.

Increased backup capabilities

Question 155

A company is developing an application that uses multiple AWS services. The application needs to use

temporary, limited-privilege credentials for authentication with other AWS APIs.

Which AWS service or feature should the company use to meet these authentication requirements?

Options:

A.

Amazon API Gateway

B.

IAM users

C.

AWS Security Token Service (AWS STS)

D.

IAM instance profiles

Question 156

Which AWS features will meet these requirements? (Select TWO.)

Options:

A.

Security groups

B.

Network ACLs

C.

S3 bucket policies

D.

IAM user policies

E.

S3 bucket versioning

Question 157

A company has an application with robust hardware requirements. The application must be accessed by students who are using lightweight, low-cost laptops.

Which AWS service will help the company deploy the application without investing in backend infrastructure or high end client hardware?

Options:

A.

Amazon AppStream 2.0

B.

AWS AppSync

C.

Amazon WorkLink

D.

AWS Elastic Beanstalk

Question 158

Which activity can companies complete by using AWS Organizations?

Options:

A.

Troubleshoot the performance of applications.

B.

Manage service control policies (SCPs).

C.

Migrate applications to microservices.

D.

Monitor the performance of applications.

Question 159

Which activity is a customer responsibility in the AWS Cloud according to the AWS shared responsibility model?

Options:

A.

Ensuring network connectivity from AWS to the internet

B.

Patching and fixing flaws within the AWS Cloud infrastructure

C.

Ensuring the physical security of cloud data centers

D.

Ensuring Amazon EBS volumes are backed up

Question 160

Which AWS network services or features allow Cl DR block notation when providing an IP address range?

(Select TWO.)

Options:

A.

Security groups

B.

Amazon Machine Image (AMI)

C.

Network access control list (network ACL)

D.

AWS Budgets

E.

Amazon Elastic Block Store (Amazon EBS)

Question 161

A company needs to manage multiple logins across AWS accounts within the same organization in AWS Organizations.

Which AWS service should the company use to meet this requirement?

Options:

A.

Amazon VPC

B.

Amazon GuardDuty

C.

Amazon Cognito

D.

AWS IAM Identity Center

Question 162

A company plans to migrate to the AWS Cloud. The company is gathering information about its on-premises infrastructure and requires information such as the hostname, IP address, and MAC address.

Which AWS service will meet these requirements?

Options:

A.

AWS DataSync

B.

AWS Application Migration Service

C.

AWS Application Discovery Service

D.

AWS Database Migration Service (AWS DMS)

Question 163

A company has multiple AWS accounts. The company needs to receive a consolidated bill from AWS and must centrally manage security and compliance. Which AWS service or feature should the company use to meet these requirements?

Options:

A.

AWS Cost and Usage Report

B.

AWS Organizations

C.

AWS Config

D.

AWS Security Hub

Question 164

A company wants its Amazon EC2 instances to be in different locations but share the same geographic area. The company also wants to use multiple power grids and independent networking connectivity for the EC2 instances.

Which solution meets these requirements?

Options:

A.

Use EC2 instances in multiple edge locations in the same AWS Region.

B.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

C.

Use EC2 instances in multiple Amazon Connect locations in the same AWS Region

D.

Use EC2 instances in multiple AWS Artifact locations in the same AWS Region.

Question 165

Which tool should a developer use lo integrate AWS service features directly into an application?

Options:

A.

AWS Software Development Kit

B.

AWS CodeDeploy

C.

AWS Lambda

D.

AWS Batch

Question 166

A company runs an application on AWS that performs batch jobs. The application is fault-tolerant and can handle interruptions. The company wants to optimize the cost to run the application.

Which AWS offering will meet these requirements?

Options:

A.

Amazon Macie

B.

Amazon Neptune

C.

Amazon EC2 Spot Instances

D.

Amazon EC2 On-Demand Instances

Question 167

A company has 5 TB of data stored in Amazon S3. The company plans to occasionally run queries on the data for analysis.

Which AWS service should the company use to run these queries in the MOST cost-effective manner?

Options:

A.

Amazon Redshift

B.

Amazon Athena

C.

Amazon Kinesis

D.

Amazon RDS

Question 168

A company runs a legacy workload in an on-premises data center. The company wants to migrate the workload to AWS. The company does not want to make any changes to the workload.

Which migration strategy should the company use?

Options:

A.

Repurchase

B.

Replatform

C.

Rehost

D.

Refactor

Question 169

A company wants to implement detailed tracking of its cloud costs by department and project.

Which AWS feature or service should the company use?

Options:

A.

Consolidated billing

B.

Cost allocation tags

C.

AWS Marketplace

D.

AWS Budgets

Question 170

A company wants to deploy a web application as a containerized application. The company wants to use a managed service that can automatically create container images from source code and deploy the containerized application.

Which AWS service will meet these requirements?

Options:

A.

AWS Elastic Beanstalk

B.

Amazon Elastic Container Service (Amazon ECS)

C.

AWS App Runner

D.

Amazon EC2

Question 171

A company wants to set AWS spending targets and track costs against those targets.

Which AWS tool or feature should the company use to meet these requirements?

Options:

A.

AWS Cost Explorer

B.

AWS Budgets

C.

AWS Cost and Usage Report

D.

Savings Plans

Question 172

A company wants to design a reliable web application that is hosted on Amazon EC2.

Which approach will achieve this goal?

Options:

A.

Launch large EC2 instances in the same Availability Zone.

B.

Spread EC2 instances across more than one security group.

C.

Spread EC2 instances across more than one Availability Zone.

D.

Use an Amazon Machine Image (AMI) from AWS Marketplace.

Question 173

A company is planning to migrate its application to the AWS Cloud.

Which AWS tool or set of resources should the company use to analyze and asses its readiness for migration?

Options:

A.

AWS Cloud Adoption Framework (AWS CAF)

B.

AWS Pricing Calculator

C.

AWS Well-Architected Framework

D.

AWS Budgets

Question 174

In which situations should a company create an 1AM user instead of an 1AM role? (Select TWO.)

Options:

A.

When an application that runs on Amazon EC2 instances requires access to other AWS services

B.

When the company creates AWS access credentials for individuals

C.

When the company creates an application that runs on a mobile phone that makes requests to AWS

D.

When the company needs to add users to 1AM groups

E.

When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time

Question 175

According to security best practices, how should an Amazon EC2 instance be given access to an Amazon S3 bucket?

Options:

A.

Hard code an IAM user's secret key and access key directly in the application, and upload the file.

B.

Store the IAM user's secret key and access key in a text file on the EC2 instance, read the keys, then upload the file.

C.

Have the EC2 instance assume a role to obtain the privileges to upload the file.

D.

Modify the S3 bucket policy so that any service can upload to it at any time.

Question 176

Which task can an IAM user perform without AWS account root user credentials?

Options:

A.

Change to a different AWS Support plan.

B.

Close an AWS account.

C.

View the AWS Billing console.

D.

Activate access to the AWS Billing console.

Question 177

A company wants to migrate its applications to the AWS Cloud. The company plans to identity and prioritize any business transformation opportunities and evaluate its AWS Cloud readiness. Which AWS service or tool should the company use to meet these requirements?

Options:

A.

AWS Cloud Adoption Framework (AWS CAF)

B.

AWS Managed Services (AMS)

C.

AWS Well-Architected Framework

D.

AWS Migration Hub

Question 178

Which AWS services or features can a company use to connect the network of its on-premises data center to AWS? (Select TWO.)

Options:

A.

AWS VPN

B.

AWS Directory Service

C.

AWS Data Pipeline

D.

AWS Direct Connect

E.

AWS CloudHSM

Question 179

A company needs to store infrequently used data for data archives and long-term backups.

Which AWS service or storage class will meet these requirements MOST cost-effectively?

Options:

A.

Amazon FSx for Lustre

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3 Glacier Flexible Retrieval

Question 180

Which options are AWS Cloud Adoption Framework (AWS CAF) cloud transformation journey recommendations? (Select TWO.)

Options:

A.

Envision phase

B.

AIign phase

C.

Assess phase

D.

Mobilize phase

E.

Migrate and modernize phase

Question 181

A company needs access to checks and recommendations that help the company follow AWS best practices for cost optimization, security, fault tolerance, performance, and service quotas.

Which combination of an AWS service and AWS Support plan on the AWS account will meet these requirements?

Options:

A.

AWS Trusted Advisor with AWS Developer Support

B.

AWS Health Dashboard with AWS Enterprise Support

C.

AWS Trusted Advisor with AWS Business Support

D.

AWS Health Dashboard with AWS Enterprise On-Ramp Support

Question 182

Which AWS service provides a single location to track the progress of application migrations?

Options:

A.

AWS Application Discovery Service

B.

AWS Application Migration Service

C.

AWS Service Catalog

D.

AWS Migration Hub

Question 183

A company is planning to migrate to the AWS Cloud. The company is conducting organizational transformation and wants to become more responsive to customer inquiries and feedback.

Which tasks should the company perform to meet these requirements, according to the AWS Cloud Adoption

Framework (AWS CAF)? (Select TWO.)

Options:

A.

Realign teams to focus on products and value streams.

B.

Create new value propositions with new products and services.

C.

Use agile methods to rapidly iterate and evolve.

D.

Use a new data and analytics platform to create actionable insights.

E.

Migrate and modernize legacy infrastructure.

Question 184

A company needs to run a workload for several batch image rendering applications. It is acceptable for the workload to experience downtime.

Which Amazon EC2 pricing model would be MOST cost-effective in this situation?

Options:

A.

On-Demand Instances

B.

Reserved Instances

C.

Dedicated Instances

D.

Spot Instances

Question 185

A company wants to define a central data protection policy that works across AWS services for compute, storage, and database resources.

Which AWS service will meet this requirement?

Options:

A.

AWS Batch

B.

AWS Elastic Disaster Recovery

C.

AWS Backup

D.

Amazon FSx

Question 186

A company's application has high customer usage during certain times of the day. The company wants to reduce the number of Amazon EC2 instances that run when application usage is low.

Which AWS service or instance purchasing option should the company use to meet this requirement?

Options:

A.

EC2 Instance Savings Plans

B.

Spot Instances

C.

Reserved Instances

D.

Amazon EC2 Auto Scaling

Question 187

A company has created an AWS Cost and Usage Report and wants to visualize the report.

Which AWS service should the company use to ingest and display this information?

Options:

A.

Amazon QuickSight

B.

Amazon Pinpoint

C.

Amazon Neptune

D.

Amazon Kinesis

Question 188

Which AWS service is an in-memory data store service?

Options:

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DynamoDB

D.

Amazon ElastiCache

Question 189

What is a benefit of using AWS serverless computing?

Options:

A.

Application deployment and management are not required

B.

Application security will be fully managed by AWS

C.

Monitoring and logging are not needed

D.

Management of infrastructure is offloaded to AWS

Question 190

Which AWS service helps developers use loose coupling and reliable messaging between microservices?

Options:

A.

Elastic Load Balancing

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon CloudFront

D.

Amazon Simple Queue Service (Amazon SQS)

Question 191

In the AWS shared responsibility model, which tasks are the responsibility of AWS? (Select TWO.)

Options:

A.

Patch an Amazon EC2 instance operating system.

B.

Configure a security group.

C.

Monitor the health of an Availability Zone.

D.

Protect the infrastructure that runs Amazon EC2 instances.

E.

Manage access to the data in an Amazon S3 bucket

Question 192

A company seeks cost savings in exchange for a commitment to use a specific amount of an AWS service or category ofAWS services for 1 year or 3 years.

Which AWS pricing model or offering will meet these requirements?

Options:

A.

Pay-as-you-go pricing

B.

Savings Plans

C.

AWS Free Tier

D.

Volume discounts

Question 193

A company needs to block SOL injection attacks.

Which AWS service or feature provides this functionality?

Options:

A.

AWS WAF

B.

Network ACLs

C.

Security groups

D.

AWS Trusted Advisor

Question 194

Which AWS service gives users on-demand, sell-service access to AWS compliance control reports?

Options:

A.

AWS Config

B.

Amazon GuardDuty

C.

AWS Trusted Advisor

D.

AWS Artifact

Question 195

What is the MOST secure way to store passwords on AWS?

Options:

A.

Store passwords in an Amazon S3 bucket.

B.

Store passwords as AWS CloudFormation parameters

C.

Store passwords in AWS Storage Gateway.

D.

Store passwords in AWS Secrets Manager.

Question 196

A company is preparing for an audit and wants documentation that AWS complies with the Payment Card Industry Data Security Standard (PCI DSS).

Where can the company find this documentation?

Options:

A.

AWS Artifact

B.

AWS Organizations

C.

AWS Trusted Advisor

D.

AWS Support Center

Question 197

A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account.

Which AWS service or resource should the company use to meet this requirement?

Options:

A.

AWS Security Hub

B.

AWS Marketplace

C.

AWS Quick Starts

D.

AWS Security Center

Question 198

Which AWS service provides the ability to manage infrastructure as code?

Options:

A.

AWS CodePipeline

B.

AWS CodeDeploy

C.

AWS Direct Connect

D.

AWS CloudFormation

Question 199

A company needs to store data from a recommendation engine in a database.

Which AWS service provides this functionality with the LEAST operational overhead?

Options:

A.

Amazon RDS for PostgreSQL

B.

Amazon DynamoDB

C.

Amazon Neptune

D.

Amazon Aurora

Question 200

A company wants to use an AWS networking solution that can act as a centralized gateway between multiple VPCs and on-premises networks. Which AWS service or feature will meet this requirement?

Options:

A.

Gateway VPC endpoint

B.

AWS Direct Connect

C.

AWS Transit Gateway

D.

AWS PrivateLink

Question 201

Which AWS service or tool can be used to set up a firewall to control traffic going into and coming out of an Amazon VPC subnet?

Options:

A.

Security group

B.

AWS WAF

C.

AWS Firewall Manager

D.

Network ACL

Question 202

A company wants to run its workload on Amazon EC2 instances for more than 1 year. This workload will run continuously.

Which option offers a discounted hourly rate compared to the hourly rate of On-Demand Instances?

Options:

A.

AWS Graviton processor

B.

Dedicated Hosts

C.

EC2 Instance Savings Plans

D.

Amazon EC2 Auto Scaling instances

Question 203

How does the AWS Enterprise Support Concierge team help users?

Options:

A.

Supporting application development

B.

Providing architecture guidance

C.

Answering billing and account inquiries

D.

Answering questions regarding technical support cases

Question 204

An administrator observed that multiple AWS resources were deleted yesterday.

Which AWS service will help identify the cause and determine which user deleted the resources?

Options:

A.

AWS CtoudTrail

B.

Amazon Inspector

C.

Amazon GuardDuty

D.

AWS Trusted Advisor

Question 205

Which AWS service or storage class provides low-cost, long-term data storage?

Options:

A.

Amazon S3 Glacier Deep Archive

B.

AWS Snowball

C.

Amazon MQ

D.

AWS Storage Gateway

Question 206

A company needs to provision uninterruptible Amazon EC2 instances, when needed, and pay for compute capacity by the second. Which EC2 instance purchasing option will meet these requirements?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

Dedicated Instances

Question 207

Which Amazon S3 storage class is MOST cost-effective for unknown access patterns?

Options:

A.

S3 Standard

B.

S3 Standard-Infrequent Access (S3 Standard-IA)

C.

S3 One Zone-Infrequent Access (S3 One Zone-IA)

D.

S3 Intelligent-Tiering

Question 208

A company has batch workloads that need to run for short periods of time on Amazon EC2. The workloads can handle interruptions and can start again from where they ended.

What is the MOST cost-effective EC2 instance purchasing option to meet these requirements?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 209

A company wants to migrate its server-based applications to the AWS Cloud. The company wants to determine the total cost of ownership for its compute resources that will be hosted on the AWS Cloud.

Which combination of AWS services or tools will meet these requirements?

Options:

A.

AWS Pricing Calculator

B.

Migration Evaluator

C.

AWS Support Center

D.

AWS Application Discovery Service

E.

AWS Database Migration Service (AWS DMS)

Question 210

A company stores data in an Amazon S3 bucket.

Which task is the responsibility of AWS?

Options:

A.

Configure an S3 Lifecycle policy.

B.

Activate S3 Versioning.

C.

Configure S3 bucket policies.

D.

Protect the infrastructure that supports S3 storage.

Question 211

A company needs to evaluate its AWS environment and provide best practice recommendations in five categories: cost, performance, service limits, fault tolerance, and security. Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Shield

B.

AWS WAF

C.

AWS Trusted Advisor

D.

AWS Service Catalog

Question 212

A company wants to migrate its workloads to AWS, but it lacks expertise in AWS Cloud computing.

Which AWS service or feature will help the company with its migration?

Options:

A.

AWS Trusted Advisor

B.

AWS Consulting Partners

C.

AWS Artifacts

D.

AWS Managed Services

Question 213

Which characteristic of the AWS Cloud helps users eliminate underutilized CPU capacity'?

Options:

A.

Agility

B.

Elasticity

C.

Reliability

D.

Durability

Question 214

Which AWS service provides encryption at rest for Amazon RDS and for Amazon Elastic Block Store (Amazon EBS) volumes?

Options:

A.

AWS Lambda

B.

AWS Key Management Service (AWS KMS)

C.

AWSWAF

D.

Amazon Rekognition

Question 215

AWS has the ability to achieve lower pay-as-you-go pricing by aggregating usage across hundreds of thousands of users.

This describes which advantage of the AWS Cloud?

Options:

A.

Launch globally in minutes

B.

Increase speed and agility

C.

High economies of scale

D.

No guessing about compute capacity

Question 216

A company simulates workflows to review and validate that all processes are effective and that staff are familiar with the processes.

Which design principle of the AWS Well-Architected Framework is the company following with this practice?

Options:

A.

Perform operations as code.

B.

Refine operation procedures frequently.

C.

Make frequent, small, reversible changes.

D.

Structure the company to support business outcomes.

Question 217

Which AWS services can host PostgreSQL databases? (Select TWO.)

Options:

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

Amazon OpenSearch Service

E.

Amazon Elastic File System (Amazon EFS)

Question 218

Which option is a shared responsibility between AWS and its customers under the AWS shared responsibility model?

Options:

A.

Configuration of Amazon EC2 instance operating systems

B.

Application file system server-side encryption

C.

Patch management

D.

Security of the physical infrastructure

Question 219

What is the LEAST expensive AWS Support plan that provides the full set of AWS Trusted Advisor best practice checks for cost optimization?

Options:

A.

AWS Enterprise Support

B.

AWS Business Support

C.

AWS Developer Support

D.

AWS Basic Support

Question 220

A company needs to identify who accessed an AWS service and what action was performed for a given time period.

Which AWS service should the company use to meet this requirement?

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Security Hub

D.

Amazon Inspector

Question 221

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on organizing an inventory of data products in a data catalog?

Options:

A.

Operations

B.

Governance

C.

Business

D.

Platform

Question 222

Which complimentary AWS service or tool creates data-driven business cases for cloud planning?

Options:

A.

Migration Evaluator

B.

AWS Billing Conductor

C.

AWS Billing Console

D.

Amazon Forecast

Question 223

What can a cloud practitioner use to retrieve AWS security and compliance documents and submit them as evidence to an auditor or regulator?

Options:

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS Artifact

D.

Amazon Inspector

Question 224

A developer wants to deploy an application quickly on AWS without manually creating the required resources. Which AWS service will meet these requirements?

Options:

A.

Amazon EC2

B.

AWS Elastic Beanstalk

C.

AWS CodeBuild

D.

Amazon Personalize

Question 225

Which AWS services can a company use to achieve a loosely coupled architecture? (Select TWO.)

Options:

A.

Amazon Workspaces

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon Connect

D.

AWS Trusted Advisor

E.

AWS Step Functions

Question 226

Which option is an AWS Cloud Adoption Framework (AWS CAF) foundational capability for the operations perspective?

Options:

A.

Performance and capacity management

B.

Application portfolio management

C.

Identity and access management

D.

Product management

Question 227

Which service enables customers to audit API calls in their AWS accounts'?

Options:

A.

AWS CloudTrail

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS X-Ray

Question 228

Which of the following is an advantage that the AWS Cloud provides to users?

Options:

A.

Users eliminate the need to guess about infrastructure capacity requirements.

B.

Users decrease their variable costs by maintaining sole ownership of IT hardware.

C.

Users maintain control of underlying IT infrastructure hardware.

D.

Users maintain control of operating systems for managed services.

Question 229

A company wants to ensure that all of its Amazon EC2 instances have compliant operating system patches.

Which AWS service will meet these requirements?

Options:

A.

AWS Compute Optimizer

B.

AWS Elastic Beanstalk

C.

AWS AppSync

D.

AWS Systems Manager

Question 230

Which of the following is a pillar of the AWS Well-Architected Framework?

Options:

A.

Redundancy

B.

Operational excellence

C.

Availability

D.

Multi-Region

Question 231

A company is migrating its public website to AWS. The company wants to host the domain name for the website on AWS.

Which AWS service should the company use to meet this requirement?

Options:

A.

AWS Lambda

B.

Amazon Route 53

C.

Amazon CloudFront

D.

AWS Direct Connect

Question 232

Which AWS service or feature can a company use to apply security rules to specific Amazon EC2 instances?

Options:

A.

Network ACLs

B.

Security groups

C.

AWS Trusted Advisor

D.

AWS WAF

Question 233

Which AWS service or tool gives a company the ability to release application changes in an automated way?

Options:

A.

Amazon AppFlow

B.

AWS CodeDeploy

C.

AWS PrivateLink

D.

Amazon EKS Distro

Question 234

Which task is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Maintain the security of the AWS Cloud.

B.

Configure firewalls and networks.

C.

Patch the operating system of Amazon RDS instances.

D.

Implement physical and environmental controls.

Question 235

Which option is an environment that consists of one or more data centers?

Options:

A.

Amazon CloudFront

B.

Availability Zone

C.

VPC

D.

AWS Outposts

Question 236

A company wants to create a globally accessible ecommerce platform for its customers. The company wants to use a highly available and scalable DNS web service to connect users to the platform.

Which AWS service will meet these requirements?

Options:

A.

Amazon EC2

B.

Amazon VPC

C.

Amazon Route 53

D.

Amazon RDS

Question 237

Which of the following are advantages of moving to the AWS Cloud? (Select TWO.)

Options:

A.

Users can implement all AWS services in seconds.

B.

AWS assumes all responsibility for the security of infrastructure and applications.

C.

Users experience increased speed and agility.

D.

Users benefit from massive economies of scale.

E.

Users can move hardware from their data center to the AWS Cloud.

Question 238

A company's application is running on Amazon EC2 instances. The company is planning a partial migration to a serverless architecture in the next year and wants to pay for resources up front.

Which AWS purchasing option will optimize the company's costs?

Options:

A.

Convertible Reserved Instances

B.

Spot Instances

C.

EC2 Instance Savings Plans

D.

Compute Savings Plan

Page: 1 / 79
Total 794 questions