Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CLF-C02 Exam Dumps - AWS Certified Cloud Practitioner

Question # 4

Which database engine is compatible with Amazon RDS?

A.

Apache Cassandra

B.

MongoDB

C.

Neo4j

D.

PostgreSQL

Full Access
Question # 5

A company uses Amazon Aurora as its database service. The company wants to encrypt its databases and database backups.

Which party manages the encryption of the database clusters and database snapshots, according to the AWS shared responsibility

model?

A.

AWS

B.

The company

C.

AWS Marketplace partners

D.

Third-party partners

Full Access
Question # 6

Which AWS service provides highly durable object storage?

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon FSx

Full Access
Question # 7

Which AWS service or tool provides recommendations to help users get rightsized Amazon EC2 instances based on historical workload usage data?

A.

AWS Pricing Calculator

B.

AWS Compute Optimizer

C.

AWS App Runner

D.

AWS Systems Manager

Full Access
Question # 8

Which of the following are design principles for reliability in the AWS Cloud? (Select TWO.)

A.

Build architectures with tightly coupled resources.

B.

Use AWS Trusted Advisor to meet security best practices.

C.

Use automation to recover immediately from failure.

D.

Rightsize Amazon EC2 instances to ensure optimal performance.

E.

Simulate failures to test recovery processes.

Full Access
Question # 9

A company's IT team is managing MySQL database server clusters. The IT team has to patch the database and take backup snapshots of the data in the clusters. The company wants to move this workload to AWS so that these tasks will be completed automatically.

What should the company do to meet these requirements?

A.

Deploy MySQL database server clusters on Amazon EC2 instances.

B.

Use Amazon RDS with a MySQL database.

C.

Use an AWS Cloud Form at ion template to deploy MySQL database servers on Amazon EC2 instances.

D.

Migrate all the MySQL database data to Amazon S3.

Full Access
Question # 10

Which AWS network services or features allow Cl DR block notation when providing an IP address range?

(Select TWO.)

A.

Security groups

B.

Amazon Machine Image (AMI)

C.

Network access control list (network ACL)

D.

AWS Budgets

E.

Amazon Elastic Block Store (Amazon EBS)

Full Access
Question # 11

A company has a social media platform in which users upload and share photos with other users. The company wants to identify and remove inappropriate photos. The company has no machine learning (ML) scientists and must build this detection capability with no ML expertise.

Which AWS service should the company use to build this capability?

A.

Amazon SageMaker

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Comprehend

Full Access
Question # 12

A company has been storing monthly reports in an Amazon S3 bucket. The company exports the report data into comma-separated values (.csv) files. A developer wants to write a simple query that can read all of these files and generate a summary report.

Which AWS service or feature should the developer use to meet these requirements with the LEAST amount of operational overhead?

A.

Amazon S3 Select

B.

Amazon Athena

C.

Amazon Redshift

D.

Amazon EC2

Full Access
Question # 13

Which activity is a customer responsibility in the AWS Cloud according to the AWS shared responsibility model?

A.

Ensuring network connectivity from AWS to the internet

B.

Patching and fixing flaws within the AWS Cloud infrastructure

C.

Ensuring the physical security of cloud data centers

D.

Ensuring Amazon EBS volumes are backed up

Full Access
Question # 14

A company is migrating a relational database server to the AWS Cloud. The company wants to minimize

administrative overhead of database maintenance tasks.

Which AWS service will meet these requirements?

A.

Amazon DynamoDB

B.

Amazon EC2

C.

Amazon Redshift

D.

Amazon RDS

Full Access
Question # 15

Which AWS service or feature is used to Troubleshoot network connectivity issues between Amazon EC2 instances?

A.

AWS Certificate Manager (ACM)

B.

Internet gateway

C.

VPC Flow Logs

D.

AWS CloudHSM

Full Access
Question # 16

Who enables encryption of data at rest for Amazon Elastic Block Store (Amazon EBS)?

A.

AWS Support

B.

AWS customers

C.

AWS Key Management Service (AWS KMS)

D.

AWS Trusted Advisor

Full Access
Question # 17

Which AWS database service provides in-memory data storage?

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon RDS

D.

Amazon Timestream

Full Access
Question # 18

A company wants to establish a security layer in its VPC that will act as a firewall to control subnet traffic.

Which AWS service or feature will meet this requirement?

A.

Routing tables

B.

Network access control lists (network ACLs)

C.

Security groups

D.

Amazon GuardDuty

Full Access
Question # 19

Which design principles are included in the reliability pillar of the AWS Well-Architected Framework? (Select TWO.)

A.

Automatically recover from failure.

B.

Grant everyone access to increase AWS service quotas.

C.

Stop guessing capacity.

D.

Design applications to run in a single Availability Zone.

E.

Plan to increase AWS service quotas first in a secondary AWS Region.

Full Access
Question # 20

What is a benefit of using an Elastic Load Balancing (ELB) load balancer with applications running in the AWS Cloud?

A.

An ELB will automatically scale resources to meet capacity needs.

B.

An ELB can balance traffic across multiple compute resources.

C.

An ELB can span multiple AWS Regions.

D.

An ELB can balance traffic between multiple internet gateways.

Full Access
Question # 21

Which AWS service can migrate Amazon EC2 instances from one AWS Region to another?

A.

AWS Application Migration Service

B.

AWS Database Migration Service (AWS DMS)

C.

AWS DataSync

D.

AWS Migration Hub

Full Access
Question # 22

A large company wants to track the combined AWS usage costs of all of its linked accounts.

How can this be accomplished?

A.

Use AWS Trusted Advisor to generate customized summary reports.

B.

Use AWS Organizations to generate consolidated billing reports.

C.

Use AWS Budgets to set utilization targets and receive summary reports.

D.

Use the AWS Control Tower dashboard to get a summary report of all linked account costs.

Full Access
Question # 23

Which of the following is a characteristic of the AWS account root user?

A.

The root user is the only user that can be configured with multi-factor authentication (MFA).

B.

The root user is the only user that can access the AWS Management Console.

C.

The root user is the first sign-in identity that is available when an AWS account is created.

D.

The root user has a password that cannot be changed.

Full Access
Question # 24

Which duties are the responsibility of a company that is using AWS Lambda? (Select TWO.)

A.

Security inside of code

B.

Selection of CPU resources

C.

Patching of operating system

D.

Writing and updating of code

E.

Security of underlying infrastructure

Full Access
Question # 25

A company will run a predictable compute workload on Amazon EC2 Instances for the next 3 years. The workload is critical for the company. The company wants to optimize costs to run the workload.

Which solution will meet these requirements?

A.

Spot Instances

B.

Dedicated Hosts

C.

Savings Plans

D.

On-Demand Instances

Full Access
Question # 26

Which AWS service uses AWS Compute Optimizer to provide sizing recommendations based on workload metrics?

A.

Amazon EC2

B.

Amazon RDS

C.

Amazon Lightsail

D.

AWS Step Functions

Full Access
Question # 27

Which best practice for cost governance does this example show?

A.

Resource controls

B.

Cost allocation

C.

Architecture optimization

D.

Tagging enforcement

Full Access
Question # 28

Which statements represent the cost-effectiveness of the AWS Cloud? (Select TWO.)

A.

Users can trade fixed expenses for variable expenses.

B.

Users can deploy all over the world in minutes.

C.

AWS offers increased speed and agility.

D.

AWS is responsible for patching the infrastructure.

E.

Users benefit from economies of scale.

Full Access
Question # 29

An ecommerce company has migrated its IT infrastructure from an on-premises data center to the AWS Cloud.

Which AWS service is used to track, record, and audit configuration changes made to AWS resources?

A.

AWS Shield

B.

AWS Config

C.

AWS IAM

D.

Amazon Inspector

Full Access
Question # 30

What can a user accomplish using AWS CloudTrail?

A.

Generate an IAM user credentials report.

B.

Record API calls made to AWS services.

C.

Assess the compliance of AWS resource configurations with policies and guidelines.

D.

Ensure that Amazon EC2 instances are patched with the latest security updates.

A company uses Amazon Workspaces.

Full Access
Question # 31

A user wants to identify any security group that is allowing unrestricted incoming SSH traffic.

Which AWS service can be used to accomplish this goal?

A.

Amazon Cognito

B.

AWS Shield

C.

Amazon Macie

D.

AWS Trusted Advisor

Full Access
Question # 32

A company wants to ensure that two Amazon EC2 instances are in separate data centers with minimal

communication latency between the data centers.

How can the company meet this requirement?

A.

Place the EC2 instances in two separate AWS Regions connected with a VPC peering connection.

B.

Place the EC2 instances in two separate Availability Zones within the same AWS Region.

C.

Place one EC2 instance on premises and the other in an AWS Region. Then connect them by using an

AWS VPN connection.

D.

Place both EC2 instances in a placement group for dedicated bandwidth.

Full Access
Question # 33

Which feature of the AWS Cloud gives users the ability to pay based on current needs rather than forecasted needs?

A.

AWS Budgets

B.

Pay-as-you-go pricing

C.

Volume discounts

D.

Savings Plans

Full Access
Question # 34

A company wants to track its AWS account's service costs. The company also wants to receive notifications when costs are forecasted to reach a specific level.

Which AWS service or tool provides this functionality?

A.

AWS Budgets

B.

AWS Cost Explorer

C.

Savings Plans

D.

AWS Billing Conductor

Full Access
Question # 35

A company has an application with robust hardware requirements. The application must be accessed by students who are using lightweight, low-cost laptops.

Which AWS service will help the company deploy the application without investing in backend infrastructure or high end client hardware?

A.

Amazon AppStream 2.0

B.

AWS AppSync

C.

Amazon WorkLink

D.

AWS Elastic Beanstalk

Full Access
Question # 36

A company needs to run code in response to an event notification that occurs when objects are uploaded to an Amazon S3 bucket.

Which AWS service will integrate directly with the event notification?

A.

AWS Lambda

B.

Amazon EC2

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

AWS Elastic Beanstalk

Full Access
Question # 37

A company has an application that uses AWS services. During scaling events, the company wants to keep

application usage within AWS service quotas.

Which AWS services or tools can report on the quotas so that the company can improve the reliability of the application? (Select TWO.)

A.

Service Quotas console

B.

AWS Trusted Advisor

C.

AWS Systems Manager

D.

AWS Shield

E.

AWS Cost Explorer

Full Access
Question # 38

Which AWS service or tool does AWS Control Tower use to create resources?

A.

AWS CloudFormation

B.

AWS Trusted Advisor

C.

AWS Directory Service

D.

AWS Cost Explorer

Full Access
Question # 39

Which AWS service or feature is used to send both text and email messages from distributed applications?

A.

Amazon Simple Notification Service (Amazon SNS)

B.

Amazon Simple Email Service (Amazon SES)

C.

Amazon CloudWatch alerts

D.

Amazon Simple Queue Service (Amazon SQS)

Full Access
Question # 40

Which of the following is available to a company that has an AWS Business Support plan?

A.

AWS Support concierge

B.

AWS DDoS Response Team (DRT)

C.

AWS technical account manager (TAM)

D.

AWS Health API

Full Access
Question # 41

A cloud engineer wants to know the percentage of the allocated compute units that are in use for a specific Amazon EC2 instance.

Which AWS service can provide this information?

A.

AWS CloudTrail

B.

AWS Config

C.

Amazon CloudWatch

D.

AWS Artifact

Full Access
Question # 42

Which AWS service or feature offers HTTP attack protection to users running public-facing web applications?

A.

Security groups

B.

Network ACLs

C.

AWS Shield Standard

D.

AWS WAF

Full Access
Question # 43

Which AWS services or features can control VPC traffic? (Select TWO.)

A.

Security groups

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

Network ACLs

E.

Amazon Connect

Full Access
Question # 44

What is an Availability Zone?

A.

A location where users can deploy compute, storage, database, and other select AWS services

where no AWS Region currently exists

B.

One or more discrete data centers with redundant power, networking, and connectivity

C.

One or more clusters of servers where new workloads can be deployed

D.

A fast content delivery network (CDN) service that securely delivers data, videos, applications, and

APIs to users globally

Full Access
Question # 45

Which options does AWS make available for customers who want to learn about security in the cloud in an instructor-led setting? (Select TWO.)

A.

AWS Trusted Advisor

B.

AWS Online Tech Talks

C.

AWS Blog

D.

AWS Forums

E.

AWS Classroom Training

Full Access
Question # 46

When a user wants to utilize their existing per-socket, per-core, or per-virtual machine software licenses for a Microsoft Windows server running on AWS, which Amazon EC2 instance type is required?

A.

Spot Instances

B.

Dedicated Instances

C.

Dedicated Hosts

D.

Reserved Instances

Full Access
Question # 47

Which AWS service should a cloud practitioner use to receive real-time guidance for provisioning resources, based on AWS best practices related to security, cost optimization, and service limits?

A.

AWS Trusted Advisor

B.

AWS Config

C.

AWS Security Hub

D.

AWS Systems Manager

Full Access
Question # 48

Which design principle is achieved by following the reliability pillar of the AWS Well-Architected Framework?

A.

Vertical scaling

B.

Manual failure recovery

C.

Testing recovery procedures

D.

Changing infrastructure manually

Full Access
Question # 49

An Availability Zone consists of:

A.

one or more data centers in a single location.

B.

two or more data centers in multiple locations.

C.

one or more physical hosts in a single data center.

D.

two or more physical hosts in multiple data centers.

Full Access
Question # 50

Which AWS feature or resource is a deployable Amazon EC2 instance template that is prepackaged with

software and security requirements?

A.

Amazon Elastic Block Store (Amazon EBS) volume

B.

AWS CloudFormation template

C.

Amazon Elastic Block Store (Amazon EBS) snapshot

D.

Amazon Machine Image (AMI)

Full Access
Question # 51

What is a benefit of moving to the AWS Cloud in terms of improving time to market?

A.

Decreased deployment speed

B.

Increased application security

C.

Increased business agility

D.

Increased backup capabilities

Full Access
Question # 52

A company deploys its application on Amazon EC2 instances. The application occasionally experiences sudden increases in demand. The company wants to ensure that its application can respond to changes in demand at the lowest possible cost.

Which AWS service or tool will meet these requirements?

A.

AWS Auto Scaling

B.

AWS Compute Optimizer

C.

AWS Cost Explorer

D.

AWS Well-Architected Framework

Full Access
Question # 53

A company needs to identify the last time that a specific user accessed the AWS Management Console.

Which AWS service will provide this information?

A.

Amazon Cognito

B.

AWS CloudTrail

C.

Amazon Inspector

D.

Amazon GuardDuty

Full Access
Question # 54

A cloud engineer needs to download AWS security and compliance documents for an upcoming audit.

Which AWS service can provide the documents?

A.

AWS Trusted Advisor

B.

AWS Artifact

C.

AWS Well-Architected Tool

D.

AWS Systems Manager

Full Access
Question # 55

Which factors affect costs in the AWS Cloud? (Select TWO.)

A.

The number of unused AWS Lambda functions

B.

The number of configured Amazon S3 buckets

C.

Inbound data transfers without acceleration

D.

Outbound data transfers without acceleration

E.

Compute resources that are currently in use

Full Access
Question # 56

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

A.

AWS CloudTrail

B.

AWS Cost and Usage Reports

C.

AWS Trusted Advisor

D.

AWS Budgets

Full Access
Question # 57

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

A.

Perform quarterly disaster recovery tests.

B.

Place the main component on the us-east-1 Region.

C.

Design for automatic failover to healthy resources.

D.

Design workloads to fit on a single Amazon EC2 instance.

Full Access
Question # 58

A company wants to manage access and permissions for its third-party software as a service (SaaS)

applications. The company wants to use a portal where end users can access assigned AWS accounts and AWS Cloud applications.

Which AWS service should the company use to meet these requirements?

A.

Amazon Cognito

B.

AWS IAM Identity Center (AWS Single Sign-On)

C.

AWS Identity and Access Management (IAM)

D.

AWS Directory Service for Microsoft Active Directory

Full Access
Question # 59

A company wants to centrally manage security policies and billing services within a multi-account AWS environment. Which AWS service should the company use to meet these requirements?

A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Resource Access Manager (AWS RAM)

D.

AWS Config

Full Access
Question # 60

Which benefit does Amazon Rekognition provide?

A.

The ability to place watermarks on images

B.

The ability to detect objects that appear in pictures

C.

The ability to resize millions of images automatically

D.

The ability to bid on object detection jobs

Full Access
Question # 61

Which of the following are components of an AWS Site-to-Site VPN connection? (Select TWO.)

A.

AWS Storage Gateway

B.

Virtual private gateway

C.

NAT gateway

D.

Customer gateway

E.

Internet gateway

Full Access
Question # 62

A company recently migrated to the AWS Cloud. The company needs to determine whether its newly imported Amazon EC2 instances are the appropriate size and type.

Which AWS services can provide this information to the company? {Select TWO.)

A.

AWS Auto Scaling

B.

AWS Control Tower

C.

AWS Trusted Advisor

D.

AWS Compute Optimizer

E.

Amazon Forecast

Full Access
Question # 63

Which benefit of AWS Cloud computing provides lower latency between users and applications?

A.

Agility

B.

Economies of scale

C.

Global reach

D.

Pay-as-you-go pricing

Full Access
Question # 64

A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a

natural disaster in a particular geographic area.

Which solution achieves this goal?

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple edge locations.

D.

Use Amazon CloudFront with the EC2 instances configured as the source.

Full Access
Question # 65

A company has a single Amazon EC2 instance. The company wants to adopt a highly available architecture.

What can the company do to meet this requirement?

A.

Scale vertically to a larger EC2 instance size.

B.

Scale horizontally across multiple Availability Zones.

C.

Purchase an EC2 Dedicated Instance.

D.

Change the EC2 instance family to a compute optimized instance.

Full Access
Question # 66

Which service is an AWS in-memory data store service?

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DynamoDB

D.

Amazon ElastiCache

Full Access
Question # 67

A company has an application that runs periodically in an on-premises environment. The application runs for a few hours most days, but runs for 8 hours a day for a week at the end of each month.

Which AWS service or feature should be used to host the application in the AWS Cloud?

A.

Amazon EC2 Standard Reserved Instances

B.

Amazon EC2 On-Demand Instances

C.

AWS Wavelength

D.

Application Load Balancer

Full Access
Question # 68

A company's information security manager is supervising a move to AWS and wants to ensure that AWS best practices are followed. The manager has concerns about the potential misuse of AWS account root user credentials.

Which of the following is an AWS best practice for using the AWS account root user credentials?

A.

Allow only the manager to use the account root user credentials for normal activities.

B.

Use the account root user credentials only for Amazon EC2 instances from the AWS Free Tier.

C.

Use the account root user credentials only when they alone must be used to perform a required

function.

D.

Use the account root user credentials only for the creation of private VPC subnets.

Full Access
Question # 69

Which AWS service or tool provides on-demand access to AWS security and compliance reports and AWS online agreements?

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon Inspector

D.

AWS Billing console

Full Access
Question # 70

A company needs to centralize its operational data. The company also needs to automate tasks across all of its Amazon EC2 instances.

Which AWS service can the company use to meet these requirements?

A.

AWS Trusted Advisor

B.

AWS Systems Manager

C.

AWS CodeDeploy

D.

AWS Elastic Beanstalk

Full Access
Question # 71

A company plans to migrate its on-premises workload to AWS. Before the migration, the company needs to estimate its future AWS service costs.

Which AWS service or tool should the company use to meet this requirement?

A.

AWS Trusted Advisor

B.

AWS Budgets

C.

AWS Pricing Calculator

D.

AWS Cost Explorer

Full Access
Question # 72

Which AWS solution should the company use to meet this requirement?

A.

AWS Config

B.

AWS software development kits (SDKs)

C.

AWS Service Catalog

D.

AWS AppSync

Full Access
Question # 73

Which actions are examples of a company's effort to right size its AWS resources to control cloud costs? (Select TWO.)

A.

Switch from Amazon RDS to Amazon DynamoDB to accommodate NoSQL datasets.

Q B. Base the selection of Amazon EC2 instance types on past utilization patterns.

B.

Use Amazon S3 Lifecycle policies to move objects that users access infrequently to lower-cost storage tiers.

C.

Use Multi-AZ deployments for Amazon RDS.

D.

Replace existing Amazon EC2 instances with AWS Elastic Beanstalk.

Full Access
Question # 74

Which AWS solution provides the ability for a company to run AWS services in the company's on-premises data center?

A.

AWS Direct Connect

B.

AWS Outposts

C.

AWS Systems Manager hybrid activations

D.

AWS Storage Gateway

Full Access
Question # 75

Which of the following is the customer's responsibility, according to the AWS shared responsibility model?

A.

Identity and access management

B.

Hard drive initialization

C.

Protection of data center hardware

D.

Security of Availability Zones

Full Access
Question # 76

A developer needs to maintain a development environment infrastructure and a production environment infrastructure in a repeatable fashion.

Which AWS service should the developer use to meet these requirements?

A.

AWS Ground Station

B.

AWS Shield

C.

AWS loT Device Defender

D.

AWS CloudFormation

Full Access
Question # 77

Which AWS service is used to temporarily provide federated security credentials to a

A.

Amazon GuardDuty

B.

AWS Simple Token Service (AWS STS)

C.

AWS Secrets Manager

D.

AWS Certificate Manager

Full Access
Question # 78

A company is running an order processing system on Amazon EC2 instances. The company wants to migrate microservices-based application.

Which combination of AWS services can the application use to meet these requirements? (Select TWO.)

A.

Amazon Simple Queue Service (Amazon SQS)

B.

AWS Lambda

C.

AWS Migration Hub

D.

AWS AppSync

E.

AWS Application Migration Service

Full Access
Question # 79

A company wants to create multiple isolated networks in the same AWS account.

Which AWS service or component will provide this functionality?

A.

AWS Transit Gateway

B.

Internet gateway

C.

Amazon VPC

D.

Amazon EC2

Full Access
Question # 80

A company is running an application on AWS. The company wants to identify and prevent the accidental

Which AWS service or feature will meet these requirements?

A.

Amazon GuardDuty

B.

Network ACL

C.

AWS WAF

D.

AWS Network Firewall

Full Access
Question # 81

A user discovered that an Amazon EC2 instance is missing an Amazon Elastic Block Store (Amazon EBS) data volume. The user wants to determine when the EBS volume was removed.

Which AWS service will provide this information?

A.

AWS Config

B.

AWS Trusted Advisor

C.

Amazon Timestream

D.

Amazon QuickSight

Full Access
Question # 82

A company needs to host a web server on Amazon EC2 instances for at least 1 year. The web server cannot tolerate interruption.

Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

A.

On-Demand Instances

B.

Partial Upfront Reserved Instances

C.

Spot Instances

D.

No Upfront Reserved Instances

Full Access
Question # 83

Which AWS service offers a global content delivery network (CDN) that helps companies securely deliver websites, videos, applications,

and APIs at high speeds with low latency?

A.

Amazon EC2

B.

Amazon CloudFront

C.

Amazon CloudWatch

D.

AWS CloudFormation

Full Access
Question # 84

Which credential allows programmatic access to AWS resources for use from the AWS CLI or the AWS API?

A.

User name and password

B.

Access keys

C.

SSH public keys

D.

AWS Key Management Service (AWS KMS) keys

Full Access
Question # 85

A new AWS user who has little cloud experience wants to build an application by using AWS services. The user wants to learn how to implement specific AWS services from other customer examples. The user also wants to ask questions to AWS experts.

Which AWS service or resource will meet these requirements?

A.

AWS Online Tech Talks

B.

AWS documentation

C.

AWS Marketplace

D.

AWS Health Dashboard

Full Access
Question # 86

A company wants to develop a shopping application that records customer orders. The application needs to use an AWS managed database service to store data.

Which AWS service should the company use to meet these requirements?

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon ElastiCache

D.

Amazon Neptune

Full Access
Question # 87

A company wants to migrate its application to AWS. The company wants to replace upfront expenses with variable payment that is based on usage.

What should the company do to meet these requirements?

A.

Use pay-as-you-go pricing.

B.

Purchase Reserved Instances.

C.

Pay less by using more.

D.

Rightsize instances.

Full Access
Question # 88

A company needs Amazon EC2 instances for a workload that can tolerate interruptions.

Which EC2 instance purchasing option meets this requirement with the LARGEST discount compared to On-Demand prices?

A.

Spot Instances

B.

Convertible Reserved Instances

C.

Standard Reserved Instances

D.

Dedicated Hosts

Full Access
Question # 89

An ecommerce company wants to design a highly available application that will be hosted on multiple Amazon EC2 instances.

How should the company deploy the EC2 instances to meet these requirements?

A.

Across multiple edge locations

B.

Across multiple VPCs

C.

Across multiple Availability Zones

D.

Across multiple AWS accounts

Full Access
Question # 90

Which of the following is entirely the responsibility of AWS, according to the AWS shared responsibility model?

A.

Security awareness and training

B.

Development of an IAM password policy

C.

Patching of the guest operating system

D.

Physical and environmental controls

Full Access
Question # 91

A company runs a database on Amazon Aurora in the us-east-1 Region. The company has a disaster recovery requirement that the database be available in another Region.

Which solution meets this requirement with minimal disruption to the database operations?

A.

Perform an Aurora Multi-AZ deployment.

B.

Deploy Aurora cross-Region read replicas.

C.

Create Amazon Elastic Block Store (Amazon EBS) volume snapshots for Aurora and copy them to another Region.

D.

Deploy Aurora Replicas.

Full Access
Question # 92

A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access.

According to the AWS shared responsibility model, which task is the responsibility of the customer?

A.

Protect the global infrastructure that runs all of the services offered in the AWS Cloud.

B.

Configure logical access controls for resources, and protect account credentials.

C.

Configure the security used by managed services.

D.

Patch and back up Amazon Aurora.

Full Access
Question # 93

In which categories does AWS Trusted Advisor provide recommended actions? (Select TWO.)

A.

Operating system patches

B.

Cost optimization

C.

Repetitive tasks

D.

Service quotas

E.

Account activity records

Full Access
Question # 94

What is an AWS responsibility under the AWS shared responsibility model?

A.

Configure the security group rules that determine which ports are open on an Amazon EC2 Linux instance.

B.

Ensure the security of the internal network in the AWS data centers.

C.

Patch the guest operating system with the latest security patches on Amazon EC2.

D.

Turn on server-side encryption for Amazon S3 buckets.

A company wants to deploy its critical application on AWS and maintain high availability.

Full Access
Question # 95

Which encryption types can be used to protect objects at rest in Amazon S3? (Select TWO.)

A.

Server-side encryption with AmazonS3 managed encryption keys (SSE-S3)

B.

Server-side encryption with AWS KMSmanaged keys (SSE-KMS)

C.

TLS

D.

SSL

E.

Transparent Data Encryption (TDE)

Full Access
Question # 96

Which options are common stakeholders for the AWS Cloud Adoption Framework (AWS CAF) platform perspective? (Select TWO.)

A.

Chief financial officers (CFOs)

B.

IT architects

C.

Chief information officers (CIOs)

D.

Chief data officers (CDOs)

E.

Engineers

Full Access
Question # 97

A company is running an application that is hosted on Amazon EC2 instances. The usage of the EC2 instances is higher during daytime hours than nighttime hours. The company wants to optimize the number of EC2 instances based on this usage pattern.

Which AWS service or instance purchasing option should the company use to meet these requirements?

A.

Spot Instances

B.

Reserved Instances

C.

AWS CloudFormation

D.

AWS Auto Scaling

Full Access
Question # 98

A company migrated its core application onto multiple workloads in the AWS Cloud. The company wants to improve the application's reliability.

Which cloud design principle should the company implement to achieve this goal?

A.

Maximize utilization.

B.

Decouple the components.

C.

Rightsize the resources.

D.

Adopt a consumption model.

Full Access
Question # 99

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

A.

Third-party vendors

B.

Customers

C.

Reseller partners

D.

Internet providers

Full Access
Question # 100

A company wants to migrate its Microsoft SQL Server database management system from on premises to the AWS Cloud.

Which AWS service should the company use to reduce management overhead for this environment?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon SageMaker

C.

Amazon RDS

D.

Amazon Athena

Full Access
Question # 101

Which AWS service provides the SIMPLEST way for the company to establish a website on AWS?

A.

Amazon Elastic File System (Amazon EFS)

B.

AWS Elastic Beanstalk

C.

AWS Lambda

D.

Amazon Lightsail

Full Access
Question # 102

Which AWS service can a company use to securely store and encrypt passwords for a database?

A.

AWS Shield

B.

AWS Secrets Manager

C.

AWS Identity and Access Management (IAM)

D.

Amazon Cognito

Full Access
Question # 103

Which AWS Cloud design principle does a company follow by using AWS CloudTrail?

A.

Recover automatically.

B.

Perform operations as code.

C.

Measure efficiency.

D.

Ensure traceability.

Full Access
Question # 104

A company is reviewing the design of an application that will be migrated from on premises to a single Amazon EC2 instance.

What should the company do to make the application highly available?

A.

Provision additional EC2 instances in other Availability Zones.

B.

Configure an Application Load Balancer (ALB). Assign the EC2 instance as the ALB's target.

C.

Use an Amazon Machine Image (AMI) to create the EC2 instance.

D.

Provision the application by using an EC2 Spot Instance.

Full Access
Question # 105

A company is using Amazon RDS.

A company is launching a critical business application in an AWS Region.

How can the company increase resilience for this application?

A.

Deploy a copy of the application in another AWS account.

B.

Deploy the application by using multiple VPCs.

C.

Deploy the application by using multiple subnets.

D.

Deploy the application by using multiple Availability Zones.

Full Access
Question # 106

A company wants its Amazon EC2 instances to share the same geographic area but use redundant underlying power sources.

Which solution will meet these requirements?

A.

Use EC2 instances across multiple Availability Zones in the same AWS Region.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in AWS OpsWorks stacks in different AWS Regions.

Full Access
Question # 107

Which AWS service or tool helps companies measure the environmental impact of their AWS usage?

A.

AWS customer carbon footprint tool

B.

AWS Compute Optimizer

C.

Sustainability pillar

D.

OS-Climate (Open Source Climate Data Commons)

Full Access
Question # 108

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Full Access
Question # 109

A company suspects that its AWS resources are being used for illegal activities.

Which AWS group or team should the company notify?

A.

AWS Abuse team

B.

AWS Support team

C.

AWS technical account managers

D.

AWS Professional Services team

Full Access
Question # 110

A developer wants to use an Amazon S3 bucket to store application logs that contain sensitive data.

Which AWS service or feature should the developer use to restrict read and write access to the S3 bucket?

A.

Security groups

B.

Amazon CloudWatch

C.

AWS CloudTrail

D.

ACLs

Full Access
Question # 111

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances. The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Full Access
Question # 112

Which AWS service requires the customer to patch the guest operating system?

A.

AWS Lambda

B.

Amazon OpenSearch Service

C.

Amazon EC2

D.

Amazon ElastiCache

Full Access
Question # 113

A company is hosting a web application on Amazon EC2 instances. The company wants to implement custom conditions to filter and control inbound web traffic.

Which AWS service will meet these requirements?

A.

Amazon GuardDuty

B.

AWSWAF

C.

Amazon Macie

D.

AWS Shield

Full Access
Question # 114

An application runs on multiple Amazon EC2 instances that access a shared file system simultaneously.

Which AWS storage service should be used?

A.

Amazon EBS

B.

Amazon EFS

C.

Amazon S3

D.

AWS Artifact

Full Access
Question # 115

A company has an application workload that is stateless by design and can sustain occasional downtime. The application performs massively parallel computations.

Which Amazon EC2 pricing model should the company choose for its application to reduce cost?

A.

On-Demand Instances

B.

Spot Instances

C.

Reserved Instances

D.

Dedicated Instances

Full Access
Question # 116

A company needs a repository that stores source code. The company needs a way to update the running software when the code changes.

Which combination of AWS services will meet these requirements? (Select TWO.)

A.

AWS CodeCommit

B.

AWS CodeDeploy

C.

Amazon DynamoDB

D.

Amazon S3

E.

Amazon Elastic Container Service (Amazon ECS)

Full Access
Question # 117

A company wants guidance to optimize the cost and performance of its current AWS environment.

Which AWS service or tool should the company use to identify areas for optimization?

A.

Amazon QuickSight

B.

AWS Trusted Advisor

C.

AWS Organizations

D.

AWS Budgets

Full Access
Question # 118

Which AWS service or tool provides recommendations to help users get rightsized Amazon EC2 instances based on historical workload usage data?

A.

AWS Pricing Calculator

B.

AWS Compute Optimizer

C.

AWS App Runner

D.

AWS Systems Manager

Full Access
Question # 119

A company wants to implement controls (guardrails) in a newly created AWS Control Tower landing zone.

Which AWS services or features can the company use to create and define these controls (guardrails)? (Select TWO.)

A.

AWS Config

B.

Service control policies (SCPs)

C.

Amazon GuardDuty

D.

AWS Identity and Access Management (IAM)

E.

Security groups

Full Access
Question # 120

A company has multiple AWS accounts that include compute workloads that cannot be interrupted. The company wants to obtain billing discounts that are based on the company's use of AWS services.

Which AWS feature or purchasing option will meet these requirements?

A.

Resource tagging

B.

Consolidated billing

C.

Pay-as-you-go pricing

D.

Spot Instances

Full Access
Question # 121

A user is moving a workload from a local data center to an architecture that is distributed between the local data center and the AWS Cloud.

Which type of migration is this?

A.

On-premises to cloud native

B.

Hybrid to cloud native

C.

On-premises to hybrid

D.

Cloud native to hybrid

Full Access
Question # 122

A retail company has recently migrated its website to AWS. The company wants to ensure that it is protected from SQL injection attacks. The website uses an Application Load Balancer to distribute traffic to multiple Amazon EC2 instances.

Which AWS service or feature can be used to create a custom rule that blocks SQL injection attacks?

A.

Security groups

B.

AWS WAF

C.

Network ACLs

D.

AWS Shield

Full Access
Question # 123

A company must store call recordings for 6 years. The storage system should be highly durable and cost-effective.

Which AWS service meets these requirements?

A.

AWS Snowball

B.

Amazon S3

C.

AWS Storage Gateway

D.

Amazon Kinesis

Full Access
Question # 124

Which AWS services or tools are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks? (Select TWO.)

A.

VPC endpoint

B.

Virtual private gateway

Q C. AWS Shield Standard

C.

AWS Config

D.

AWS WAF

Full Access
Question # 125

A company needs to launch an Amazon EC2 instance.

Which of the following can the company use during the launch process to configure the root volume of the EC2 instance?

A.

Amazon EC2 Auto Scaling

B.

Amazon Data Lifecycle Manager (Amazon DLM)

C.

Amazon Machine Image (AMI)

D.

Amazon Elastic Block Store (Amazon EBS) volume

Full Access
Question # 126

A company wants to move its data warehouse application to the AWS Cloud. The company wants to run and scale its analytics services without needing to provision and manage data warehouse clusters.

Which AWS service will meet these requirements?

A.

Amazon Redshift provisioned data warehouse

B.

Amazon Redshift Serverless

C.

Amazon Athena

D.

Amazon S3

Full Access
Question # 127

Which tasks are the responsibility of AWS according to the AWS shared responsibility model? (Select TWO.)

A.

Configure AWS Identity and Access Management (IAM).

B.

Configure security groups on Amazon EC2 instances.

C.

Secure the access of physical AWS facilities.

D.

Patch applications that run on Amazon EC2 instances.

E.

Perform infrastructure patching and maintenance.

Full Access
Question # 128

A company has set up a VPC in its AWS account and has created a subnet in the VPC. The company wants to make the subnet public.

Which AWS features should the company use to meet this requirement? (Select TWO.)

A.

Amazon VPC internet gateway

B.

Amazon VPC NAT gateway

C.

Amazon VPC route tables

D.

Amazon VPC network ACL

E.

Amazon EC2 security groups

Full Access
Question # 129

Which AWS service is always free of charge for users?

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

AWS Identity and Access Management (IAM)

Full Access
Question # 130

How should the company deploy the application to meet these requirements?

A.

Ina single Availability Zone

B.

On AWS Direct Connect

C.

On Reserved Instances

D.

In multiple Availability Zones

Full Access
Question # 131

Which AWS service or feature can be used to control inbound and outbound traffic on an Amazon EC2 instance?

A.

Internet gateways

B.

AWS Identity and Access Management (IAM)

C.

Network ACLs

D.

Security groups

Full Access
Question # 132

Which AWS service can defend against DDoS attacks?

A.

AWS Firewall Manager

B.

AWS Shield Standard

C.

AWS WAF

D.

Amazon Inspector

Full Access
Question # 133

A company is running workloads for multiple departments within a single VPC. The company needs to be able to bill each department for its resource usage.

Which action should the company take to accomplish this goal with the LEAST operational overhead?

A.

Add a department tag to each resource and configure cost allocation tags.

B.

Move each department resource to its own VPC.

C.

Move each department resource to its own AWS account.

D.

Use AWS Organizations to get a billing report for each department.

Full Access
Question # 134

A company does not want to rely on elaborate forecasting to determine its usage of compute resources. Instead, the company wants to pay only for the resources that it uses. The company also needs the ability to increase or decrease its resource usage to meet business requirements.

Which pillar of the AWS Well-Architected Framework aligns with these requirements?

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Full Access
Question # 135

Which perspective of the AWS Cloud Adoption Framework (AWS CAF) connects technology and business?

A.

Operations

B.

People

C.

Security

D.

Governance

Full Access
Question # 136

Which AWS services allow users to monitor and retain records of account activities that include governance, compliance, and auditing?

(Select TWO.)

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

Amazon GuardDuty

D.

AWS Shield

E.

AWS WAF

Full Access
Question # 137

Which task does AWS perform automatically?

A.

Encrypt data that is stored in Amazon DynamoDB.

B.

Patch Amazon EC2 instances.

C.

Encrypt user network traffic.

D.

Create TLS certificates for users' websites.

Full Access
Question # 138

A company is using AWS for all its IT Infrastructure. The company's developers are allowed to deploy applications on their own. The developers want to deploy their applications without having to provision the infrastructure themselves.

Which AWS service should the developers use to meet these requirements?

A.

AWS Cloud Formation

B.

AWS CodeBuild

C.

AWS Elastic Beanstalk

D.

AWS CodeDeploy

Full Access
Question # 139

A manufacturing company has a critical application that runs at a remote site that has a slow internet connection. The company wants to migrate the workload to AWS. The application is sensitive to latency and interruptions in connectivity. The company wants a solution that can host this application with minimum latency.

Which AWS service or feature should the company use to meet these requirements?

A.

Availability Zones

B.

AWS Local Zones

C.

AWS Wavelength

D.

AWS Outposts

Full Access
Question # 140

A company wants to migrate its on-premises application to the AWS Cloud. The company is legally obligated to retain certain data in its onpremises data center.

Which AWS service or feature will support this requirement?

A.

AWS Wavelength

B.

AWS Local Zones

C.

VMware Cloud on AWS

D.

AWS Outposts

Full Access
Question # 141

A company has a compliance requirement to record and evaluate configuration changes, as well as perform remediation actions on AWS resources.

Which AWS service should the company use?

A.

AWS Config

B.

AWS Secrets Manager

C.

AWS CloudTrail

D.

AWS Trusted Advisor

Full Access
Question # 142

Which AWS service provides protection against DDoS attacks for applications that run in the AWS Cloud?

A.

Amazon VPC

B.

AWS Shield

C.

AWS Audit Manager

D.

AWS Config

Full Access
Question # 143

A company wants to access a report about the estimated environmental impact of the company's AWS usage.

Which AWS service or feature should the company use to meet this requirement?

A.

AWS Organizations

B.

IAM policy

C.

AWS Billing console

D.

Amazon Simple Notification Service (Amazon SNS)

Full Access
Question # 144

Which aspect of security is the customer's responsibility, according to the AWS shared responsibility model?

A.

Patch and configuration management

B.

Service and communications protection or zone security

C.

Physical and environmental controls

D.

Awareness and training

Full Access
Question # 145

A company manages factory machines in real time. The company wants to use AWS technology to deploy its monitoring applications as close to the factory machines as possible.

Which AWS solution will meet these requirements with the LEAST latency?

A.

AWS Outposts

B.

Amazon EC2

C.

AWS App Runner

D.

AWS Batch

Full Access
Question # 146

Which design principle is included in the operational excellence pillar of the AWS Well-Architected Framework?

A.

Create annotated documentation.

B.

Anticipate failure.

C.

Ensure performance efficiency.

D.

Optimize costs.

Full Access
Question # 147

Which AWS service can create a private network connection from on premises to the AWS Cloud?

A.

AWS Config

B.

Virtual Private Cloud (Amazon VPC)

C.

AWS Direct Connect

D.

Amazon Route 53

Full Access
Question # 148

A company wants to migrate its database to a managed AWS service that is compatible with PostgreSQL.

Which AWS services will meet these requirements? (Select TWO)

A.

Amazon Athena

B.

Amazon RDS

C.

Amazon EC2

D.

Amazon DynamoDB

E.

Amazon Aurora

Full Access
Question # 149

Which AWS service or feature offers security for a VPC by acting as a firewall to control traffic in and out of subnets?

A.

AWS Security Hub

B.

Security groups

C.

Network ACL

D.

AWSWAF

Full Access
Question # 150

To assist companies with Payment Card Industry Data Security Standard (PCI DSS) compliance in the cloud. AWS provides:

A.

physical inspections of data centers by appointment.

B.

required PCI compliance certifications for any application running on AWS.

C.

an AWS Attestation of Compliance (AOC) report for specific AWS services.

D.

professional PCI compliance services.

Full Access
Question # 151

Using AWS Identity and Access Management (IAM) to grant access only to the resources needed to perform a task is a concept known as:

A.

restricted access.

B.

as-needed access.

C.

least privilege access.

D.

token access.

Full Access
Question # 152

An auditor is preparing for an annual security audit. The auditor requests certification details for a company's AWS hosted resources across multiple Availability Zones in the us-east-1 Region.

How should the company respond to the auditor's request?

A.

Open an AWS Support ticket to request that the AWS technical account manager (TAM) respond and help the auditor.

B.

Open an AWS Support ticket to request that the auditor receive approval to conduct an onsite assessment of the AWS data centers in

which the company operates.

C.

Explain to the auditor that AWS does not need to be audited because the company's application is hosted in multiple Availability

Zones.

D.

Use AWS Artifact to download the applicable report for AWS security controls. Provide the report to the auditor.

Full Access
Question # 153

A company wants to migrate its high-performance computing (HPC) application to Amazon EC2 instances. The application has multiple components. The application must have fault tolerance and must have the ability to fail over automatically.

Which AWS infrastructure solution will meet these requirements with the LEAST latency between components?

A.

Multiple AWS Regions

B.

Multiple edge locations

C.

Multiple Availability Zones

D.

Regional edge caches

Full Access
Question # 154

Which of the following is an advantage that the AWS Cloud provides to users?

A.

Users eliminate the need to guess about infrastructure capacity requirements.

B.

Users decrease their variable costs by maintaining sole ownership of IT hardware.

C.

Users maintain control of underlying IT infrastructure hardware.

D.

Users maintain control of operating systems for managed services.

Full Access
Question # 155

Which AWS service offers object storage?

A.

Amazon RDS

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon S3

D.

Amazon DynamoDB

Full Access
Question # 156

A cloud practitioner needs to obtain AWS compliance reports before migrating an environment to the AWS Cloud How can these reports be generated?

A.

Contact the AWS Compliance team

B.

Download the reports from AWS Artifact

C.

Open a case with AWS Support

D.

Generate the reports with Amazon Macie.

Full Access
Question # 157

A company wants to monitor for misconfigured security groups that are allowing unrestricted access to specific ports. Which AWS service will meet this requirement?

A.

AWS Trusted Advisor

B.

Amazon CloudWatch

C.

Amazon GuardDuty

D.

AWS Health Dashboard

Full Access
Question # 158

Which of the following can the AWS Pricing Calculator do?

A.

Project monthly AWS costs.

B.

Calculate historical AWS costs.

C.

Provide in-depth information about AWS pricing strategies.

D.

Provide users with access to their monthly bills.

Full Access
Question # 159

Which AWS compute service gives users the ability to securely and reliably run containers at scale?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon Aurora

C.

Amazon Athena

D.

Amazon Polly

Full Access
Question # 160

Which AWS service or tool can be used to consolidate payments for a company with multiple AWS accounts?

A.

AWS Cost and Usage Report

B.

AWS Organizations

C.

Cost Explorer

D.

AWS Budgets

Full Access
Question # 161

Which AWS service or feature can the company use to limit the access to AWS services for member accounts?

A.

AWS Identity and Access Management (IAM)

B.

Service control policies (SCPs)

C.

Organizational units (OUs)

D.

Access control lists (ACLs)

Full Access
Question # 162

A company needs to track the activity in its AWS accounts, and needs to know when an API call is made against its AWS resources. Which AWS tool or service can be used to meet these requirements?

A.

Amazon CloudWatch

B.

Amazon Inspector

C.

AWS CloudTrail

D.

AWS IAM

Full Access
Question # 163

A company wants to build, tram, and deploy machine learning (ML) models.

Which AWS service can the company use to meet this requirement?

A.

Amazon Personalize

B.

Amazon Comprehend

C.

Amazon Forecast

D.

Amazon SageMaker

Full Access
Question # 164

Which AWS service can provide a dedicated network connection with consistent low latency from on premises to the AWS Cloud?

A.

Amazon VPC

B.

Amazon Kinesis Data Streams

C.

AWS Direct Connect

D.

Amazon OpenSearch Service

Full Access
Question # 165

Which cloud computing advantage is a company applying when it uses AWS Regions to increase application availability to users in different countries?

A.

Pay-as-you-go pricing

B.

Capacity forecasting

C.

Economies of scale

D.

Global reach

Full Access
Question # 166

Which AWS service can run a managed PostgreSQL database that provides online transaction processing (OLTP)?

A.

Amazon DynamoDB

B.

Amazon Athena

C.

Amazon RDS

D.

Amazon EMR

Full Access
Question # 167

A company wants to migrate its on-premises infrastructure to the AWS Cloud.

Which advantage of cloud computing will help the company reduce upfront costs?

A.

Go global in minutes

B.

Increase speed and agility

C.

Benefit from massive economies of scale

D.

Trade fixed expense for variable expense

Full Access
Question # 168

Which AWS services or features provide disaster recovery solutions for Amazon EC2 instances? (Select TWO.)

A.

EC2 Reserved Instances

B.

EC2 Amazon Machine Images (AMIs)

C.

Amazon Elastic Block Store (Amazon EBS) snapshots

D.

AWS Shield

E.

Amazon GuardDuty

Full Access
Question # 169

Which of the following is a fully managed MySQL-compatible database?

A.

Amazon S3

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon Aurora

Full Access
Question # 170

Which AWS service helps users plan and track their server and application inventory migration data to AWS?

A.

Amazon CloudWatch

B.

AWS DataSync

C.

AWS Migration Hub

D.

AWS Application Migration Service

Full Access
Question # 171

Which task must a user perform by using the AWS account root user credentials?

A.

Make changes to AWS production resources.

B.

Change AWS Support plans.

C.

Access AWS Cost and Usage Reports.

D.

Grant auditors’ access to an AWS account for a compliance audit.

Full Access
Question # 172

Which task is the customer's responsibility, according to the AWS shared responsibility model?

A.

Maintain the security of the AWS Cloud.

B.

Configure firewalls and networks.

C.

Patch the operating system of Amazon RDS instances.

D.

Implement physical and environmental controls.

Full Access
Question # 173

A company wants to use guidelines from the AWS Well-Architected Framework to limit human error and facilitate consistent responses to events.

Which of the following is a Well-Architected design principle that will meet these requirements?

A.

Use AWS CodeDeploy.

B.

Perform operations as code.

C.

Migrate workloads to a Dedicated Host.

D.

Use AWS Compute Optimizer.

Full Access
Question # 174

A company wants its Amazon EC2 instances to be in different locations but share the same geographic area. The company also wants to use multiple power grids and independent networking connectivity for the EC2 instances.

Which solution meets these requirements?

A.

Use EC2 instances in multiple edge locations in the same AWS Region.

B.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

C.

Use EC2 instances in multiple Amazon Connect locations in the same AWS Region

D.

Use EC2 instances in multiple AWS Artifact locations in the same AWS Region.

Full Access
Question # 175

An ecommerce company plans to move its data center workload to the AWS Cloud to support highly dynamic usage patterns. Which benefits make the AWS Cloud cost-effective for the migration of this type of workload? (Select TWO.)

A.

Reliability

B.

Security

C.

Elasticity

D.

Pay-as-you-go resource pricing

E.

High availability

Full Access
Question # 176

A company that has multiple business units wants to centrally manage and govern its AWS Cloud environments. The company wants to automate the creation of AWS accounts, apply service control policies (SCPs), and simplify billing processes.

Which AWS service or tool should the company use to meet these requirements?

A.

AWS Organizations

B.

Cost Explorer

C.

AWS Budgets

D.

AWS Trusted Advisor

Full Access
Question # 177

A company wants to launch its web application in a second AWS Region. The company needs to determine which services must be regionally configured for this launch.

Which AWS services can be configured at the Region level? (Select TWO.)

A.

Amazon EC2

B.

Amazon Route 53

C.

Amazon CloudFront

D.

AWS WAF

E.

Amazon DynamoDB

Full Access
Question # 178

A company is releasing a business-critical application. Before the release, the company needs strategic planning assistance from AWS. During the release, the company needs AWS infrastructure event management and real-time support.

What should the company do to meet these requirement?

A.

Access AWS Trusted Advisor.

B.

Contact the AWS Partner Network (APN).

C.

Sign up for AWS Enterprise Support.

D.

Contact AWS Professional Services.

Full Access
Question # 179

A company is planning to migrate to the AWS Cloud. The company is conducting organizational transformation and wants to become more responsive to customer inquiries and feedback.

Which tasks should the company perform to meet these requirements, according to the AWS Cloud Adoption

Framework (AWS CAF)? (Select TWO.)

A.

Realign teams to focus on products and value streams.

B.

Create new value propositions with new products and services.

C.

Use agile methods to rapidly iterate and evolve.

D.

Use a new data and analytics platform to create actionable insights.

E.

Migrate and modernize legacy infrastructure.

Full Access
Question # 180

Elasticity in the AWS Cloud refers to which of the following? (Select TWO.)

A.

How quickly an Amazon EC2 instance can be restarted

B.

The ability to rightsized resources as demand shifts

C.

The maximum amount of RAM an Amazon EC2 instance can use

D.

The pay-as-you-go billing model

E.

How easily resources can be procured when they are needed

Full Access
Question # 181

Which AWS service allows for file sharing between multiple Amazon EC2 Instances?

A.

AWS Direct Connect

B.

AWS Snowball Edge

C.

AWS Backup

D.

Amazon Elastic File System (Amazon EFS)

Full Access
Question # 182

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO)

A.

High availability

B.

Performance efficiency

C.

Cost optimization

D.

Going global in minutes

E.

Continuous development

Full Access
Question # 183

Which AWS service or feature offers security for a VPC by acting as a firewall to control traffic in and out of subnets?

A.

AWS Security Hub

B.

Security groups

C.

Network ACL

D.

AWSWAF

Full Access
Question # 184

Which AWS Cloud design principle is a company using when the company implements AWS CloudTrail?

A.

Activate traceability.

B.

Use serverless compute architectures.

C.

Perform operations as code.

D.

Go global in minutes.

Full Access
Question # 185

Which AWS service or tool helps users visualize, understand, and manage spending and usage over time?

A.

AWS Organizations

B.

AWS Pricing Calculator

C.

AWS Cost Explorer

D.

AWS Service Catalog

Full Access
Question # 186

A company wants to design a reliable web application that is hosted on Amazon EC2.

Which approach will achieve this goal?

A.

Launch large EC2 instances in the same Availability Zone.

B.

Spread EC2 instances across more than one security group.

C.

Spread EC2 instances across more than one Availability Zone.

D.

Use an Amazon Machine Image (AMI) from AWS Marketplace.

Full Access
Question # 187

A company is moving an on-premises data center to the AWS Cloud. The company must migrate 50 petabytes of file storage data to AWS with the least possible operational overhead.

Which AWS service or resource should the company use to meet these requirements?

A.

AWS Snowmobile

B.

AWS Snowball Edge

C.

AWS Data Exchange

D.

AWS Database Migration Service (AWS DMS)

Full Access
Question # 188

A company is considering migration to the AWS Cloud. The company wants a fully managed service or feature that can transfer streaming data from multiple sources to an Amazon S3 bucket.

Which AWS service or feature should the company use to meet these requirements?

A.

AWS DataSync

B.

Amazon Kinesis Data Firehose

C.

S3 Select

D.

AWS Transfer Family

Full Access
Question # 189

What does the concept of agility mean in AWS Cloud computing? (Select TWO.)

A.

The speed at which AWS resources are implemented

B.

The speed at which AWS creates new AWS Regions

C.

The ability to experiment quickly

D.

The elimination of wasted capacity

E.

The low cost of entry into cloud computing

Full Access
Question # 190

Which AWS services or features give users the ability to create a network connection between two VPCs? (Select TWO.)

A.

VPC endpoints

B.

Amazon Route 53

C.

VPC peering

D.

AWS Direct Connect

E.

AWS Transit Gateway

Full Access
Question # 191

Which AWS services are supported by Savings Plans? (Select TWO.)

A.

Amazon EC2

B.

Amazon RDS

C.

Amazon SageMaker

D.

Amazon Redshift

E.

Amazon DynamoDB

Full Access
Question # 192

A company wants to run its workload on Amazon EC2 instances for more than 1 year. This workload will run continuously.

Which option offers a discounted hourly rate compared to the hourly rate of On-Demand Instances?

A.

AWS Graviton processor

B.

Dedicated Hosts

C.

EC2 Instance Savings Plans

D.

Amazon EC2 Auto Scaling instances

Full Access
Question # 193

A company needs to run some of its workloads on premises to comply with regulatory guidelines. The company wants to use the AWS Cloud to run workloads that are not required to be on premises. The company also wants to be able to use the same API calls for the on-premises workloads and the cloud workloads.

Which AWS service or feature should the company use to meet these requirements?

A.

Dedicated Hosts

B.

AWS Outposts

C.

Availability Zones

D.

AWS Wavelength

Full Access
Question # 194

A developer needs to use a standardized template to create copies of a company's AWS architecture for development test, and production environments. Which AWS service should the developer use to meet this requirement?

A.

AWS Cloud Map

B.

AWS Cloud Formation

C.

Amazon CloudFront

D.

AWS CloudTrail

Full Access
Question # 195

A company encourages its teams to test failure scenarios regularly and to validate their understanding of the impact of potential failures.

Which pillar of the AWS Well-Architected Framework does this philosophy represent?

A.

Operational excellence

B.

Cost optimization

C.

Performance efficiency

D.

Security

Full Access
Question # 196

A company runs a MySQL database in its on-premises data center. The company wants to run a copy of this database in the AWS

Cloud.

Which AWS service would support this workload?

A.

Amazon RDS

B.

Amazon Neptune

C.

Amazon ElastiCache for Redis

D.

Amazon Quantum Ledger Database (Amazon QLDB)

Full Access
Question # 197

Which AWS service helps developers use loose coupling and reliable messaging between microservices?

A.

Elastic Load Balancing

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon CloudFront

D.

Amazon Simple Queue Service (Amazon SQS)

Full Access
Question # 198

A company needs a managed NFS file system that the company can use with its AWS compute....

Which AWS service or feature will meet these requirements?

A.

Amazon Elastic Block Store (Amazon EBS)

B.

AWS Storage Gateway Tape Gateway

C.

Amazon S3 Glacier Flexible Retrieval

D.

Amazon Elastic Pile System (Amazon EFS)

Full Access
Question # 199

company wants to protect its AWS Cloud information, systems, and assets while performing risk assessment and mitigation tasks.

Which pillar of the AWS Well-Architected Framework is supported by these goals?

A.

Reliability

B.

Security

C.

Operational excellence

D.

Performance efficiency

Full Access
Question # 200

A company wants its Amazon EC2 instances to share the same geographic area but use multiple independent underlying power sources.

Which solution achieves this goal?

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Full Access
Question # 201

A company is building an application on AWS. The application needs to comply with credit card regulatory requirements. The company needs proof that the AWS services and deployment are in compliance.

Which actions should the company take to meet these requirements? (Select TWO.)

A.

Use Amazon Inspector to submit the application for certification.

B.

Ensure that the application's underlying hardware components comply with requirements.

C.

Use AWS Artifact to access AWS documents about the compliance of the services.

D.

Get the compliance of the application certified by a company assessor.

E.

Use AWS Security Hub to certify the compliance of the application.

Full Access
Question # 202

Which of the following is a fully managed graph database service on AWS?

A.

Amazon Aurora

B.

Amazon FSx

C.

Amazon DynamoDB

D.

Amazon Neptune

Full Access
Question # 203

A company is running its application in the AWS Cloud. The company wants to periodically review its AWS account for cost optimization opportunities.

Which AWS service or tool can the company use to meet these requirements?

A.

AWS Cost Explorer

B.

AWS Trusted Advisor

C.

AWS Pricing Calculator

D.

AWS Budgets

Full Access
Question # 204

A company has deployed an Amazon EC2 instance.

Which option is an AWS responsibility under the AWS shared responsibility model?

A.

Managing and encrypting application data

B.

Installing updates and security patches of guest operating system

C.

Configuration of infrastructure devices

D.

Configuration of security groups on each instance

Full Access
Question # 205

A company is planning to host its workloads on AWS.

Which AWS service requires the company to update and patch the guest operating system?

A.

Amazon DynamoDB

B.

Amazon S3

C.

Amazon EC2

D.

Amazon Aurora

Full Access
Question # 206

Which complimentary AWS service or tool creates data-driven business cases for cloud planning?

A.

Migration Evaluator

B.

AWS Billing Conductor

C.

AWS Billing Console

D.

Amazon Forecast

Full Access
Question # 207

A company wants a list of all users in its AWS account, the status of all of the users' access keys, and if multi-factor authentication (MFA) has been configured.

Which AWS service or feature will meet these requirements?

A.

AWS Key Management Service (AWS KMS)

B.

IAM Access Analyzer

C.

IAM credential report

D.

Amazon CloudWatch

Full Access
Question # 208

Which actions are best practices for an AWS account root user? (Select TWO.)

A.

Share root user credentials with team members.

B.

Create multiple root users for the account, separated by environment.

C.

Enable multi-factor authentication (MFA) on the root user.

D.

Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user.

E.

Use programmatic access instead of the root user and password.

Full Access
Question # 209

Which AWS service supports a hybrid architecture that gives users the ability to extend AWS infrastructure, AWS services, APIs, and tools to data centers, co-location environments, or on-premises facilities?

A.

AWS Snowmobile

B.

AWS Local Zones

C.

AWS Outposts

D.

AWS Fargate

Full Access
Question # 210

A company wants to provide managed Windows virtual desktops and applications to its remote employees over secure network connections. Which AWS services can the company use to meet these requirements? (Select TWO.)

A.

Amazon Connect

B.

Amazon AppStream 2.0

C.

Amazon Workspaces

D.

AWS Site-to-Site VPN

E.

Amazon Elastic Container Service (Amazon ECS)

Full Access
Question # 211

Which AWS service is a continuous delivery and deployment solution?

A.

AWSAppSync

B.

AWS CodePipeline

C.

AWS Cloud9

D.

AWS CodeCommit

Full Access
Question # 212

Which AWS services are connectivity services for a VPC? (Select TWO.)

A.

AWS Site-to-Site VPN

B.

AWS Direct Connect

C.

Amazon Connect

D.

AWS Key Management Service (AWS KMS)

E.

AWS Identity and Access Management (IAM)

Full Access
Question # 213

A software engineer wants to launch a virtual machine (VM) and MySQL database on AWS.

Which AWS service will meet these requirements with the LEAST operational effort?

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Elastic Beanstalk

C.

Amazon Lightsail

D.

Amazon EC2

Full Access
Question # 214

Which AWS service provides threat detection by monitoring for malicious activities and unauthorized actions to protect AWS accounts, workloads, and data that is stored in Amazon S3?

A.

AWS Shield

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

Amazon Inspector

Full Access
Question # 215

A company wants to run a NoSQL database on Amazon EC2 instances.

Which task is the responsibility of AWS in this scenario"?

A.

Update the guest operating system of the EC2 instances

B.

Maintain high availability at the database layer

C.

Patch the physical infrastructure that hosts the EC2 instances

D.

Configure the security group firewall

Full Access
Question # 216

What is the best resource for a user to find compliance-related information and reports about AWS?

A.

AWS Artifact

B.

AWS Marketplace

C.

Amazon Inspector

D.

Increase operational costs across data centers.

Full Access
Question # 217

Which AWS service or resource provides answers to the most frequently asked security-related questions that AWS receives from its users'?

A.

AWS Artifact

B.

Amazon Connect

C.

AWS Chatbot

D.

AWS Knowledge Center

Full Access
Question # 218

Which tool should a developer use lo integrate AWS service features directly into an application?

A.

AWS Software Development Kit

B.

AWS CodeDeploy

C.

AWS Lambda

D.

AWS Batch

Full Access
Question # 219

A company wants to migrate its on_premises workloads to the AWS Cloud. The company wants to separate workloads for chargeback to different departments.

Which AWS services or features will meet these requirements? (Select TWO.)

A.

Placement groups

B.

Consolidated billing

C.

Edge locations

D.

AWS Config

E.

Multiple AWS accounts

Full Access
Question # 220

Which AWS service aggregates, organizes, and prioritizes security alerts and findings from multiple AWS services?

A.

Amazon Detective

B.

Amazon Inspector

C.

Amazon Macie

D.

AWS Security Hub

Full Access
Question # 221

A company wants to migrate its on-premises data warehouse to AWS. The information in the data warehouse is

used to populate analytics dashboards.

Which AWS service should the company use for the data warehouse?

A.

Amazon ElastiCache

B.

Amazon Aurora

C.

Amazon RDS

D.

Amazon Redshift

Full Access
Question # 222

A company has two AWS accounts in an organization in AWS Organizations for consolidated billing. All of the company's AWS resources are hosted in one AWS Region.

Account A has purchased five Amazon EC2 Standard Reserved Instances (RIs) and has four EC2 instances

running. Account B has not purchased any RIs and also has four EC2 instances running.

Which statement is true regarding pricing for these eight instances?

A.

The eight instances will be charged as regular instances.

B.

Four instances will be charged as RIs, and four will be charged as regular instances.

C.

Five instances will be charged as RIs, and three will be charged as regular instances.

D.

The eight instances will be charged as RIs.

Full Access
Question # 223

Which statement describes a characteristic of the AWS global infrastructure?

A.

Edge locations contain multiple AWS Regions.

B.

AWS Regions contain multiple Regional edge caches.

C.

Availability Zones contain multiple data centers.

D.

Each data center contains multiple edge locations.

Full Access
Question # 224

A company is launching a new application in the AWS Cloud. The application will run on an Amazon EC2 instance. More EC2 instances will be needed when the workload increases.

Which AWS service or tool can the company use to launch the number of EC2 instances that will be needed to handle the workload?

A.

Elastic Load Balancing

B.

Amazon EC2 Auto Scaling

C.

AWS App2Container (A2C)

D.

AWS Systems Manager

Full Access
Question # 225

According to the AWS shared responsibility model, which of the following are AWS responsibilities? (Select TWO.)

A.

Network infrastructure and virtualization of infrastructure

B.

Security of application data

C.

Guest operating systems

D.

Physical security of hardware

E.

Credentials and policies

Full Access
Question # 226

A company is designing a web application that will run on Amazon EC2 instances.

Which AWS services and features will improve availability and reduce the impact of failures for this application?

(Select TWO.)

A.

Amazon EC2 Auto Scaling for the EC2 instances

B.

VPC subnet ACLs to check the health of a service

C.

Resources that are distributed across multiple Availability Zones

D.

Configuration of AWS Server Migration Service (AWS SMS) to move the EC2 instances to a different

AWS Region

E.

Resources that are distributed across multiple AWS points of presence

Full Access
Question # 227

A company is developing an application that uses multiple AWS services. The application needs to use

temporary, limited-privilege credentials for authentication with other AWS APIs.

Which AWS service or feature should the company use to meet these authentication requirements?

A.

Amazon API Gateway

B.

IAM users

C.

AWS Security Token Service (AWS STS)

D.

IAM instance profiles

Full Access
Question # 228

Which design principles support the reliability pillar of the AWS Well-Architected Framework? (Select TWO.)

A.

Perform operations as code.

B.

Enable traceability.

C.

Automatically scale to meet demand.

D.

Deploy resources globally to improve response time.

E.

Automatically recover from failure.

Full Access
Question # 229

Which AWS services and features are provided to all customers at no charge? (Select TWO.)

A.

Amazon Aurora

B.

VPC

C.

Amazon SageMaker

D.

AWS Identity and Access Management (IAM)

E.

Amazon Polly

Full Access
Question # 230

What are the characteristics of Availability Zones? (Select TWO.)

A.

All Availability Zones in an AWS Region are interconnected with high-bandwidth, low-latency networking

B.

Availability Zones are physically separated by a minimum of distance of 150 km (100 miles).

C.

All traffic between Availability Zones is encrypted.

D.

Availability Zones within an AWS Region share redundant power, networking, and connectivity.

E.

Every Availability Zone contains a single data center.

Full Access
Question # 231

A retail company is migrating its IT infrastructure applications from on premises to the AWS Cloud.

Which costs will the company eliminate with this migration? (Select TWO.)

A.

Cost of data center operations

B.

Cost of application licensing

C.

Cost of marketing campaigns

D.

Cost of physical server hardware

E.

Cost of network management

Full Access
Question # 232

Which AWS Well-Architected Framework concept represents a system's ability to remain functional when the system encounters operational problems?

A.

Consistency

B.

Elasticity

C.

Durability

D.

Latency

Full Access
Question # 233

A company needs a content delivery network that provides secure delivery of data, videos, applications, and APIs to users globally with low latency and high transfer speeds.

Which AWS service meets these requirements?

A.

Amazon CloudFront

B.

Elastic Load Balancing

C.

Amazon S3

D.

Amazon Elastic Transcoder

Full Access
Question # 234

Which design principle should be considered when architecting in the AWS Cloud?

A.

Think of servers as non-disposable resources.

B.

Use synchronous integration of services.

C.

Design loosely coupled components.

D.

Implement the least permissive rules for security groups.

Full Access
Question # 235

A company is migrating an application that includes an Oracle database to AWS. The company cannot rewrite the application.

To which AWS service could the company migrate the database?

A.

Amazon Athena

B.

Amazon DynamoDB

®C. Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

Full Access