Weekend Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Amazon Web Services CLF-C02 AWS Certified Cloud Practitioner Exam Practice Test

Page: 1 / 88
Total 881 questions

AWS Certified Cloud Practitioner Questions and Answers

Question 1

A company wants to automatically patch its Windows instances that are deployed on Amazon EC2.

Which AWS service will meet these requirements?

Options:

A.

AWS Systems Manager

B.

AWS Organizations

C.

AWS Control Tower

D.

Elastic Load Balancing (ELB)

Question 2

A company wants to centrally manage Its employee's access to multiple AWS accounts.

Which AWS service or feature should the company use to meet this requirement?

Options:

A.

AWS Identity and Access Management Access Analyzer

B.

AWS Secrets Manager

C.

AWS IAM Identity Center

D.

AWS Security Token Service (AWS STS)

Question 3

A company is moving Us development and test environments to AWS to increase agility and reduce cost. Because these are not production workloads and the servers are not fully utilized, occasional unavailability is acceptable.

What is the MOST cost-effective Amazon EC2 pricing model that will meet these requirements?

Options:

A.

Reserved instances

B.

On-Demand Instances

C.

Spot Instances

D.

Dedicated Hosts

Question 4

A company wants to migrate a virtual server that runs Windows Server from an on-premises data center to AWS. The company wants to automatically convert the existing server to run natively on AWS infrastructure.

Which AWS service will meet this requirement?

Options:

A.

AWS Application Discovery Service

B.

AWS Application Migration Service

C.

AWS Config

D.

AWS DataSync

Question 5

Which AWS service can generate information that can be used by external auditors?

Options:

A.

Amazon Cognito

B.

Amazon FSx

C.

AWS Config

D.

Amazon Inspector

Question 6

Which AWS service can a company use to manage encryption keys in the cloud?

Options:

A.

AWS License Manager

B.

AWS Certificate Manager (ACM)

C.

AWS CloudHSM

D.

AWS Directory Service

Question 7

A company wants to know more about the benefits offered by cloud computing. The company wants to understand the operational advantage of agility.

How does AWS provide agility for users?

Options:

A.

The ability the ensure high availability by deploying workloads to multiple regions.

B.

A pay-as-you-go model for many services and resources

C.

The ability to transfer infrastructure management to the AWS Cloud

D.

The ability to provision and deprovision resources quickly with minimal effort

Question 8

Which design principle aligns with performance efficiency pillar of the AWS Well-Architected Framework?

Options:

A.

Using serverless architectures

B.

Scaling horizontally

C.

Measuring the cost of workloads

D.

Using managed services

Question 9

Which task is the shared responsibility of the customer and AWS under the AWS shared responsibility model?

Options:

A.

Installing hardware infrastructure

B.

Managing security

C.

Managing guest operating systems

D.

Protecting the physical infrastructure that runs all services

Question 10

A company is learning about its responsibilities that are related to the management of Amazon EC2 instances.

Which tasks for EC2 instances are the company's responsibility, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Install and patch the machine hypervisor.

B.

Patch the guest operating system.

C.

Encrypt data at rest on associated storage.

D.

Install the physical hardware and cabling.

E.

Provide physical security for the EC2 instances.

Question 11

A company is building a business intelligence solution that uses Amazon Redshift. The company wants to use an AWS service to create interactive dashboards and not pay any upfront costs for it.

Which service should the company use?

Options:

A.

Amazon CloudWatch

B.

AWS Health Dashboard

C.

AWS Service Catalog

D.

Amazon QuickSight

Question 12

A company's workload can recover with minimal downtime when failures occur. Which AWS Cloud benefit does this scenario represent?

Options:

A.

Agility

B.

Elasticity

C.

Resiliency

D.

Scalability

Question 13

Which design principle is related to the reliability pillar according to the AWS Well-Architected Framework?

Options:

A.

Test recovery procedures

B.

Experiment more often

C.

Go global in minutes

D.

Analyze and attribute to expenditure

Question 14

A company is running a reporting web server application on Amazon EC2 instances. The application runs once every week and once again at the end of the month. The EC2 instances can be shut down when they are not in use.

What is the MOST cost-effective billing model for this use case?

Options:

A.

Standard Reserved Instances

B.

Convertible Reserved Instances

C.

On-Demand Capacity Reservations

D.

On-Demand Instances

Question 15

A company is creating a web application that requires a relational database to store customer data. Which AWS service should the company use to host the database?

Options:

A.

Amazon Aurora

B.

Amazon DynamoDB

C.

Amazon ElastiCache

D.

Amazon Redshift

Question 16

Which AWS service or feature provides information about governance monitoring and risk auditing of AWS accounts?

Options:

A.

AWS CloudTrail

B.

VPC Flow Logs

C.

Amazon CloudWatch

D.

AWS Trusted Advisor

Question 17

A company is moving its on-premises IT services to the AWS Cloud. The company wants to set spending limits and to receive notifications if the limits are exceeded.

Which AWS service or resource will meet these requirements?

Options:

A.

AWS Budgets

B.

AWS Cost and Usage Reports

C.

AWS Cost Explorer

D.

AWS Organizations consolidated billing

Question 18

A developer needs to use a standardized template to create copies of a company's AWS architecture for development test, and production environments. Which AWS service should the developer use to meet this requirement?

Options:

A.

AWS Cloud Map

B.

AWS Cloud Formation

C.

Amazon CloudFront

D.

AWS CloudTrail

Question 19

A company wants to migrate its on-premises SQL Server database to the AWS Cloud. The company wants AWS to handle the day-to-day administration of the database. Which AWS service will meet the company's requirements?

Options:

A.

Amazon EC2 foe Microsoft SQL Server

B.

Amazon DynamoDB

C.

Amazon RDS

D.

Amazon Aurora

Question 20

Which AWS design principle emphasizes the reduction of interdependencies between components of an application?

Options:

A.

Scalability

B.

Loose coupling

C.

Automation

D.

Caching

Question 21

Which AWS service can be used to encrypt data at rest?

Options:

A.

Amazon GuardDuty

B.

AWS Shield

C.

AWS Security Hub

D.

AWS Key Management Service (AWS KMS)

Question 22

A company is using Amazon EC2 instances.

Which tasks are the company's responsibility, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Maintain the network infrastructure.

B.

Patch the guest operating system.

C.

Configure a security group on deployed EC2 instances.

D.

Provide physical security for the underlying hardware of the EC2 instances.

E.

Manage the underlying hypervisor.

Question 23

A company wants to securely rehost databases to AWS with minimal downtime. Which AWS service will meet these requirements?

Options:

A.

AWS Database Migration Service (AWS DMS)

B.

AWS Snow Family

C.

AWSDataSync

D.

AWS Mainframe Modernization

Question 24

A company notices suspicious network activity against an application that is running on a fleet of Amazon EC2 instances. The suspicious activity is coming from a single IP address.

Which AWS service should the company use to block access from this IP address?

Options:

A.

AWS Shield

B.

AWS Config

C.

Amazon GuardDuty

D.

AWS WAF

Question 25

A company wants to securely log in to Linux Amazon EC2 instances.

Options:

A.

Use end-to-end encryption.

B.

Use multi-factor authentication (MFA).

C.

Use AWS Systems Manager Session Manager.

D.

Use AWS Systems Manager State Manager.

Question 26

An ecommerce company plans to move its data center workload to the AWS Cloud to support highly dynamic usage patterns. Which benefits make the AWS Cloud cost-effective for the migration of this type of workload? (Select TWO.)

Options:

A.

Reliability

B.

Security

C.

Elasticity

D.

Pay-as-you-go resource pricing

E.

High availability

Question 27

A company needs to manage multiple logins across AWS accounts within the same organization in AWS Organizations.

Which AWS service should the company use to meet this requirement?

Options:

A.

Amazon VPC

B.

Amazon GuardDuty

C.

Amazon Cognito

D.

AWS IAM Identity Center

Question 28

A company needs to ensure that users around the world can access the company's application with low latency. Which advantage of the AWS Cloud will meet this requirement?

Options:

A.

Avoid data center costs

B.

Global infrastructure

C.

Larger application leads to cost savings

D.

Pay as-you-go pricing

Question 29

Which AWS service or feature should a company use between two microservices to ensure that messages are sent and received in exact order?

Options:

A.

Amazon Simple Email Service (Amazon SES)

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon S3 Event Notifications

D.

Amazon Simple Queue Service (Amazon SQS) FIFO queues

Question 30

Which option is a shared responsibility between AWS and its customers under the AWS shared responsibility model?

Options:

A.

Configuration of Amazon EC2 instance operating systems

B.

Application file system server-side encryption

C.

Patch management

D.

Security of the physical infrastructure

Question 31

A company is moving some of its on-premises IT services to the AWS Cloud. The finance department wants to see the entire bill so it can forecast spending limits.

Which AWS service can the company use to set spending limits and receive notifications if those limits are exceeded?

Options:

A.

AWS Cost and Usage Reports

B.

AWS Budgets

C.

AWS Organizations consolidated billing

D.

Cost Explorer

Question 32

A company needs to provide users with a list of company-generated products that are based on AWS services. The company also needs to control access to these products by provisioning a personalized portal for specific users.

Which AWS service will meet these requirements?

Options:

A.

AWS AppSync

B.

Amazon Connect

C.

AWS Organizations

D.

AWS Service Catalog

Question 33

A company wants to securely access an Amazon S3 bucket from an Amazon EC2 instance without accessing the internet.

What should the company use to accomplish this goal?

Options:

A.

VPN connection

B.

Internet gateway

C.

VPC endpoint

D.

NAT gateway

Question 34

A company has multiple AWS accounts. The company needs to receive a consolidated bill from AWS and must centrally manage security and compliance. Which AWS service or feature should the company use to meet these requirements?

Options:

A.

AWS Cost and Usage Report

B.

AWS Organizations

C.

AWS Config

D.

AWS Security Hub

Question 35

Which AWS service or feature can a company use to create a private, secured, and scalable network environment in the AWS Cloud?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon S3

C.

Amazon VPC

D.

Route tables

Question 36

Which AWS service gives companies the ability to create graph applications that can analyze billions of relationships between data points in milliseconds?

Options:

A.

Amazon Redshift

B.

Amazon Neptune

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon ElastiCache

Question 37

Which AWS service provides access to AWS security and compliance reports for audits?

Options:

A.

Amazon Inspector

B.

Amazon GuardDuty

C.

AWS Artifact

D.

Amazon Detective

Question 38

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

Which action is the company's responsibility?

Options:

A.

Managing the infrastructure that runs the S3 bucket

B.

Managing the data in transit

C.

Managing the encryption options on the S3 bucket

D.

Managing the operating system updates on the S3 bucket

Question 39

A company plans to migrate to the AWS Cloud. The company wants to gather information about its on-premises data center.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Application Discovery Service

B.

AWS DataSync

C.

AWS Storage Gateway

D.

AWS Database Migration Service (AWS DMS)

Question 40

For which use case are Amazon EC2 On-Demand Instances MOST cost-effective?

Options:

A.

Compute-intensive video transcoding that can be restarted it necessary

B.

An instance in continual use for 1 month to conduct quality assurance tests

C.

An instance that runs a web server that will run for 1 year

D.

An instance that runs a database that will run for 3 years

Question 41

Which AWS service can a company use to directly query and analyze AWS Cost and Usage Reports?

Options:

A.

Amazon OpenSearch Service

B.

Amazon Athena

C.

Amazon Aurora

D.

AWS Glue

Question 42

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on organizing an inventory of data products in a data catalog?

Options:

A.

Operations

B.

Governance

C.

Business

D.

Platform

Question 43

Which AWS service or feature can a company use to determine which business unit is using specific AWS resources?

Options:

A.

Cost allocation tags

B.

Key pairs

C.

Amazon Inspector

D.

AWS Trusted Advisor

Question 44

A company that has an AWS Enterprise Support plan needs to protect its applications from DDoS attacks. The company requires access to the AWS DDoS Response Team (DRT) 24 hours a day. 7 days a week.

Which AWS service will meet these requirements?

Options:

A.

AWS Shield Standard

B.

AWS Shield Advanced

C.

AWS Firewall Manager

D.

AWS WAF

Question 45

A company wants to visualize and manage AWS Cloud costs and usage for a specific period of time.

Which AWS service or feature will meet these requirements?

Options:

A.

Cost Explorer

B.

Consolidated billing

C.

AWS Organizations

D.

AWS Budgets

Question 46

What is the total volume of data that can be stored in Amazon S3?

Options:

A.

10 PB

B.

50 PB

C.

100 PB

D.

Virtually unlimited

Question 47

Which AWS services are serverless? (Select TWO.)

Options:

A.

AWS Fargate

B.

Amazon Managed Streaming for Apache Kafka

C.

Amazon EMR

D.

Amazon S3

E.

Amazon EC2

Question 48

A company wants to build, train, and deploy machine learning (ML) models.

Which AWS service will meet these requirements?

Options:

A.

Amazon Athena

B.

Amazon Comprehend

C.

Amazon Polly

D.

Amazon SageMaker AI

Question 49

Which AWS service is a fully managed NoSQL database service?

Options:

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon DynamoDB

D.

Amazon Aurora

Question 50

A company wants to migrate its on-premises PostgreSQL database to a managed PostgreSQL database on AWS. Which AWS service will meet this requirement?

Options:

A.

Amazon DynamoDB

B.

Amazon Neptune

C.

Amazon RDS

D.

Amazon Redshift

Question 51

Which of the following is an architectural design principle of the AWS Well-Architected Framework?

Options:

A.

Loosely couple components

B.

Build monolithic systems

C.

Scale vertically, not horizontally

D.

Use third-party software

Question 52

Where can AWS users review answers to frequently asked questions about security in the AWS Cloud?

Options:

A.

AWS Trusted Advisor

B.

AWS Knowledge Center

C.

AWS Support Center

D.

AWS Artifact

Question 53

Treating infrastructure as code in the AWS Cloud allows users to:

Options:

A.

automate migration of on-premises hardware to AWS data centers.

B.

let a third party automate an audit of the AWS infrastructure.

C.

turn over application code to AWS so it can run on the AWS infrastructure.

D.

automate the infrastructure provisioning process.

Question 54

Which AWS service or resource can a company use to deploy AWS WAF rules?

Options:

A.

Amazon EC2

B.

Application Load Balancer

C.

AWS Trusted Advisor

D.

Network Load Balancer

Question 55

Which AWS service provides machine learning capability to detect and analyze content in images and videos?

Options:

A.

Amazon Connect

B.

Amazon Lightsail

C.

Amazon Personalize

D.

Amazon Rekognition

Question 56

A company needs a file-sharing service that supports SMB protocol.

Options:

A.

Amazon Aurora

B.

AWS Config

C.

AWS DataSync

D.

Amazon FSx for Windows File Server

Question 57

Which AWS service or tool can be used to capture information about inbound and outbound traffic in an Amazon VPC?

Options:

A.

Amazon Inspector

B.

VPC endpoint services

C.

VPC Flow Logs

D.

NAT gateway

Question 58

A company needs to request temporary, limited-privilege credentials for IAM users and for the federated users that the company authenticates.

Which AWS service will provide these credentials?

Options:

A.

Amazon GuardDuty

B.

AWS Key Management Service (AWS KMS)

C.

AWS Security Token Service (AWS STS)

D.

AWS Identity and Access Management Access Analyzer

Question 59

Which AWS service or tool can a company use to set up consolidated billing?

Options:

A.

AWS Billing and Cost Management console

B.

AWS Organizations

C.

AWS Cost and Usage Report

D.

AWS Systems Manager

Question 60

A company needs to reserve a certain amount of Amazon EC2 compute resources in a specific Availability Zone within an AWS Region. Which purchasing option should the company use to meet this requirement?

Options:

A.

EC2 Instance Savings Plans

B.

Compute Savings Plans

C.

Regional Reserved Instances

D.

Zonal Reserved Instances

Question 61

A company is building a web application using AWS.

Which AWS service will help prevent network layer DDoS attacks against the web application?

Options:

A.

AWS WAF

B.

AWS Firewall Manager

C.

Amazon GuardDuty

D.

AWS Shield

Question 62

A company has a client that uses an Amazon RDS database. The client requests Information about operating system-level upgrades on the AWS resources that host the RDS database. The company employs a third-party provider to monitor the RDS database.

Who is responsible for upgrading the operating systems for Amazon RDS under the AWS shared responsibility model?

Options:

A.

The client

B.

The company

C.

AWS

D.

The third-party provider

Question 63

A company wants to run its application's code without having to provision and manage servers. Which AWS service will meet this requirement?

Options:

A.

AWS Glue

B.

AWS Lambda

C.

AWS CodeDeploy

D.

Amazon CodeGuru

Question 64

A company wants to develop applications that run on AWS. The company's developers need a set of libraries and development tools that are available in multiple programming languages.

Which AWS solution provides these libraries and tools?

Options:

A.

AWS CodePipeline

B.

AWS SDKs

C.

Amazon CloudWatch

D.

AWS CodeDeploy

Question 65

A company that uses AWS needs to transfer 2 TB of data.

Which type of transfer of that data would result in no cost for the company?

Options:

A.

Inbound data transfer from the internet

B.

Outbound data transfer to the internet

C.

Data transfer between AWS Regions

D.

Data transfer between Availability Zones

Question 66

A company wants to use an AWS networking solution that can act as a centralized gateway between multiple VPCs and on-premises networks. Which AWS service or feature will meet this requirement?

Options:

A.

Gateway VPC endpoint

B.

AWS Direct Connect

C.

AWS Transit Gateway

D.

AWS PrivateLink

Question 67

Which AWS service provides command line access to AWS tools and resources directly (torn a web browser?

Options:

A.

AWS CIoudHSM

B.

AWS CloudShell

C.

Amazon Workspaces

D.

AWS Cloud Map

Question 68

Which Amazon S3 storage class is MOST cost-effective for unknown access patterns?

Options:

A.

S3 Standard

B.

S3 Standard-Infrequent Access (S3 Standard-IA)

C.

S3 One Zone-Infrequent Access (S3 One Zone-IA)

D.

S3 Intelligent-Tiering

Question 69

Which AWS service can a company use to visually design and build serverless applications?

Options:

A.

AWS Lambda

B.

AWS Batch

C.

AWS Application Composer

D.

AWS App Runner

Question 70

Which AWS service or tool provides a visualization of historical AWS spending patterns and projections of future AWS costs?

Options:

A.

AWS Cos! and Usage Report

B.

AWS Budgets

C.

Cost Explorer

D.

Amazon CloudWatch

Question 71

Which AWS compute service gives users the ability to securely and reliably run containers at scale?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon Aurora

C.

Amazon Athena

D.

Amazon Polly

Question 72

A company runs an application on AWS that performs batch jobs. The application is fault-tolerant and can handle interruptions. The company wants to optimize the cost to run the application.

Which AWS offering will meet these requirements?

Options:

A.

Amazon Macie

B.

Amazon Neptune

C.

Amazon EC2 Spot Instances

D.

Amazon EC2 On-Demand Instances

Question 73

A company wants to establish a schedule for rotating database user credentials.

Which AWS service will support this requirement with the LEAST amount of operational overhead?

Options:

A.

AWS Systems Manager

B.

AWS Secrets Manager

C.

AWS License Manager

D.

AWS Managed Services

Question 74

A cloud practitioner needs to obtain AWS compliance reports before migrating an environment to the AWS Cloud How can these reports be generated?

Options:

A.

Contact the AWS Compliance team

B.

Download the reports from AWS Artifact

C.

Open a case with AWS Support

D.

Generate the reports with Amazon Macie.

Question 75

Which option is a benefit of the economies of scale based on the advantages of cloud computing?

Options:

A.

The ability to trade variable expense for fixed expense

B.

Increased speed and agility

C.

Lower variable costs over fixed costs

D.

Increased operational costs across data centers

Question 76

A company has a workload that will run continuously for 1 year. The workload cannot tolerate service interruptions.

Which Amazon EC2 purchasing option will be MOST cost-effective?

Options:

A.

All Upfront Reserved Instances

B.

Partial Upfront Reserved Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 77

A company operates a petabyte-scale data warehouse to analyze its data. The company wants a solution that will not require manual hardware and software management. Which AWS service will meet these requirements?

Options:

A.

Amazon DocumentDB (with MongoDB compatibility)

B.

Amazon Redshift

C.

Amazon Neptune

D.

Amazon ElastiCache

Question 78

A company is planning to migrate applications to the AWS Cloud. During a system audit, the company finds that its content management system (CMS) application is incompatible with cloud environments.

Which migration strategies will help the company to migrate the CMS application with the LEAST effort? (Select TWO.)

Options:

A.

Retire

B.

Rehost

C.

Repurchase

D.

Replatform

E.

Refactor

Question 79

Which of the following is a customer responsibility according to the AWS shared responsibility model?

Options:

A.

Apply security patches for Amazon S3 infrastructure devices.

B.

Provide physical security for AWS datacenters.

C.

Install operating system updates on Lambda@Edge.

D.

Implement multi-factor authentication (MFA) for 1AM user accounts.

Question 80

A company has deployed a web application to Amazon EC2 instances. The EC2 instances have low usage. Which AWS service or feature should lite company use in rightsized the FC? instances?

Options:

A.

AWS Config

B.

AWS Cost Anomaly Detection

C.

AWS Budgets

D.

AWS Compute Optimizer

Question 81

Which AWS service or feature requires an Internet service provider (ISP) and a colocation facility to be Implemented?

Options:

A.

AWS VPN

B.

Amazon Conned

C.

AWS Direct Connect

D.

Internet gateway

Question 82

Which AWS service or feature allows users to create new AWS accounts, group multiple accounts to organize workflows, and apply policies to groups of accounts?

Options:

A.

AWS Identity and Access Management (1AM)

B.

AWS Trusted Advisor

C.

AWS CloudFormation

D.

AWS Organizations

Question 83

A company needs to create and publish interactive business intelligence dashboards. The dashboards require insights that are powered by machine learning.

Which AWS service or tool will meet these requirements?

Options:

A.

AWS Glue Studio

B.

Amazon QuickSight

C.

Amazon Redshift

D.

Amazon Athena

Question 84

Which AWS service supports user sign-up functionality and authentication to mobile and web applications?

Options:

A.

Amazon Cognito

B.

AWS Config

C.

Amazon GuardDuty

D.

AWS Systems Manager

Question 85

How does AWS Cloud computing help businesses reduce costs? (Select TWO.)

Options:

A.

AWS changes the name prices for servicers in every AWS Region.

B.

AWS enables capacity in be adjusted un demand.

C.

AWS offers discounts tor Amazon LC2 instances that remain Idle tor more man 1 week.

D.

AWS does not charge for data sent from the AWS Cloud to the internet.

E.

AWS eliminates many of the costs of building and maintaining on-premises data centers.

Question 86

What is a customer responsibility when using AWS Lambda according to the AWS shared responsibility model?

Options:

A.

Managing the code within the Lambda function

B.

Confirming that the hardware is working in the data center

C.

Patching the operating system

D.

Shutting down Lambda functions when they are no longer in use

Question 87

Which maintenance task is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Physical connectivity among Availability Zones

B.

Network switch maintenance

C.

Hardware updates and firmware patches

D.

Amazon EC2 updates and security patches

Question 88

A social media company wants to protect its web application from common web exploits such as SQL injections and cross-site scripting. Which AWS service will meet these requirements?

Options:

A.

Amazon Inspector

B.

AWS WAF

C.

Amazon GuardDuty

D.

Amazon CloudWatch

Question 89

An administrator observed that multiple AWS resources were deleted yesterday.

Which AWS service will help identify the cause and determine which user deleted the resources?

Options:

A.

AWS CtoudTrail

B.

Amazon Inspector

C.

Amazon GuardDuty

D.

AWS Trusted Advisor

Question 90

Which AWS Support plan provides the full set of AWS Trusted Advisor checks at the LOWEST cost?

Options:

A.

AWS Developer Support

B.

AWS Business Support

C.

AWS Enterprise On-Ramp Support

D.

AWS Enterprise Support

Question 91

Which of the following are advantages of moving to the AWS Cloud? (Select TWO.)

Options:

A.

Users can implement all AWS services in seconds.

B.

AWS assumes all responsibility for the security of infrastructure and applications.

C.

Users experience increased speed and agility.

D.

Users benefit from massive economies of scale.

E.

Users can move hardware from their data center to the AWS Cloud.

Question 92

A company's application is running on Amazon EC2 instances. The company is planning a partial migration to a serverless architecture in the next year and wants to pay for resources up front.

Which AWS purchasing option will optimize the company's costs?

Options:

A.

Convertible Reserved Instances

B.

Spot Instances

C.

EC2 Instance Savings Plans

D.

Compute Savings Plan

Question 93

Which AWS Support plan provides the full set to AWS Trusted Advisor checks at the LOWEST cost?

Options:

A.

AWS Developer Support

B.

AWS Business Support

C.

AWS Enterprise On-Ramp Support

D.

AWS Enterprise Support

Question 94

Which tasks are responsibilities of the customer, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Secure the virilization layer.

B.

Encrypt data and maintain data integrity.

C.

Patch the Amazon RDS operating system.

D.

Maintain identity and access management controls.

E.

Secure Availability Zones.

Question 95

A company wants a cost-effective option when running its applications in an Amazon EC2 instance for short time periods. The applications can be interrupted.

Which EC2 instance type will meet these requirements?

Options:

A.

Spot Instances

B.

On-Demand Instances

C.

Reserved Instances

D.

Dedicated Instances

Question 96

Which AWS service or tool gives a company the ability to release application changes in an automated way?

Options:

A.

Amazon AppFlow

B.

AWS CodeDeploy

C.

AWS PrivateLink

D.

Amazon EKS Distro

Question 97

A company Is designing its AWS workloads so that components can be updated regularly and so that changes can be made in small, reversible increments.

Which pillar of the AWS Well-Architected Framework does this design support?

Options:

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Question 98

Which AWS service enables companies to deploy an application dose to end users?

Options:

A.

Amazon CloudFront

B.

AWS Auto Scaling

C.

AWS AppSync

D.

Amazon Route S3

Question 99

Which benefits does a company gain when the company moves from on-premises IT architecture to the AWS Cloud? (Select TWO.)

Options:

A.

Reduced or eliminated tasks for hardware troubleshooting, capacity planning, and procurement

B.

Elimination of the need for trained IT staff

C.

Automatic security configuration of all applications that are migrated to the cloud

D.

Elimination of the need for disaster recovery planning

E.

Faster deployment of new features and applications

Question 100

A company wants to build graph queries for real-time fraud pattern detection.

Which AWS service will meet this requirement?

Options:

A.

Amazon Neptune

B.

Amazon DynamoDB

C.

Amazon Timestream

D.

Amazon Forecast

Question 101

A company needs a managed NFS file system that the company can use with its AWS compute....

Which AWS service or feature will meet these requirements?

Options:

A.

Amazon Elastic Block Store (Amazon EBS)

B.

AWS Storage Gateway Tape Gateway

C.

Amazon S3 Glacier Flexible Retrieval

D.

Amazon Elastic Pile System (Amazon EFS)

Question 102

A company is requesting Payment Card Industry (PCI) reports that validate the operating effectiveness of AWS security controls.

How should the company obtain these reports?

Options:

A.

Contact AWS Support

B.

Download reports from AWS Artifact.

C.

Download reports from AWS Security Hub.

D.

Contact an AWS technical account manager (TAM).

Question 103

Which AWS service or feature gives users the ability to connect VPCs and on-premises networks to a central hub?

Options:

A.

Virtual private gateway

B.

AWS Transit Gateway

C.

Internet gateway

D.

Customer gateway

Question 104

A company is using Amazon DynamoDB for its application database.

Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Classify data.

B.

Configure access permissions.

C.

Manage encryption options.

D.

Provide public endpoints to store and retrieve data.

E.

Manage the infrastructure layer and the operating system.

Question 105

What is the recommended use case for Amazon EC2 On-Demand Instances?

Options:

A.

A steady-state workload that requires a particular EC2 instance configuration for a long period of time

B.

A workload that can be interrupted for a project that requires the lowest possible cost

C.

An unpredictable workload that does not require a long-term commitment

D.

A workload that is expected to run for longer than 1 year

Question 106

An independent software vendor wants to deliver and share its custom Amazon Machine images (AMIs) to prospective customers.

Which AWS service will meet these requirements?

Options:

A.

AWS Marketplace

B.

AWS Data Exchange

C.

Amazon EC2

D.

AWS Organizations

Question 107

Which of the following is a fully managed graph database service on AWS?

Options:

A.

Amazon Aurora

B.

Amazon FSx

C.

Amazon DynamoDB

D.

Amazon Neptune

Question 108

A company has batch workloads that need to run for short periods of time on Amazon EC2. The workloads can handle interruptions and can start again from where they ended.

What is the MOST cost-effective EC2 instance purchasing option to meet these requirements?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 109

A company wants to migrate its on-premises infrastructure to the AWS Cloud.

Which advantage of cloud computing will help the company reduce upfront costs?

Options:

A.

Go global in minutes

B.

Increase speed and agility

C.

Benefit from massive economies of scale

D.

Trade fixed expense for variable expense

Question 110

Which complimentary AWS service or tool creates data-driven business cases for cloud planning?

Options:

A.

Migration Evaluator

B.

AWS Billing Conductor

C.

AWS Billing Console

D.

Amazon Forecast

Question 111

A company is migrating its applications from on-premises to the AWS Cloud. The company wants to ensure that the applications are assigned only the minimum permissions that are needed to perform all operations.

Which AWS service will meet these requirements'?

Options:

A.

AWS Identity and Access Management (IAM)

B.

Amazon CloudWatch

C.

Amazon Macie

D.

Amazon GuardDuty

Question 112

Elasticity in the AWS Cloud refers to which of the following? (Select TWO.)

Options:

A.

How quickly an Amazon EC2 instance can be restarted

B.

The ability to rightsized resources as demand shifts

C.

The maximum amount of RAM an Amazon EC2 instance can use

D.

The pay-as-you-go billing model

E.

How easily resources can be procured when they are needed

Question 113

A network engineer needs to build a hybrid cloud architecture connecting on-premises networks to the AWS Cloud using AWS Direct Connect. The company has a few VPCs in a single AWS Region and expects to increase the number of VPCs to hundreds over time.

Which AWS service or feature should the engineer use to simplify and scale this connectivity as the VPCs increase in number?

Options:

A.

VPC endpoints

B.

AWS Transit Gateway

C.

Amazon Route 53

D.

AWS Secrets Manager

Question 114

Which AWS service can run a managed PostgreSQL database that provides online transaction processing (OLTP)?

Options:

A.

Amazon DynamoDB

B.

Amazon Athena

C.

Amazon RDS

D.

Amazon EMR

Question 115

A company wants to design its cloud architecture so that it can support development innovations, and continuously improve processes and procedures.

This is an example of which pillar of the AWS Well-Architected Framework?

Options:

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Question 116

A company wants to implement detailed tracking of its cloud costs by department and project.

Which AWS feature or service should the company use?

Options:

A.

Consolidated billing

B.

Cost allocation tags

C.

AWS Marketplace

D.

AWS Budgets

Question 117

Which AWS resource can help a company reduce Its costs in exchange for a usage commitment when using Amazon EC2 instances?

Options:

A.

Compute Savings Plans

B.

Auto Stalling group

C.

On-Demand Instance

D.

EC2 instance store

Question 118

Which AWS service could an administrator use to provide desktop environments for several employees?

Options:

A.

AWS Organizations

B.

AWS Fargate

C.

AWS WAF

D.

AWS Workspaces

Question 119

Which Amazon EC2 pricing model is the MOST cost efficient for an uninterruptible workload that runs once a year for 24 hours?

Options:

A.

On-Demand Instances

B.

Reserved Instances

C.

Spot Instances

D.

Dedicated Instances

Question 120

Which AWS service or feature identifies whether an Amazon S3 bucket or an IAM role has been shared with an external entity?

Options:

A.

AWS Service Catalog

B.

AWS Systems Manager

C.

AWS IAM Access Analyzer

D.

AWS Organizations

Question 121

Which options are AWS Cloud Adoption Framework (AWS CAF) security perspective capabilities? (Select TWO.)

Options:

A.

Observability

B.

Incident and problem management

C.

Incident response

D.

Infrastructure protection

E.

Availability and continuity

Question 122

A team of researchers is going to collect data at remote locations around the world Many locations do not have internet connectivity. The team needs to capture the data in the field, and transfer it to the AWS Cloud later

Which AWS service will support these requirements?

Options:

A.

AWS Outposts

B.

AWS Transfer Family

C.

AWS Snow Family

D.

AWS Migration Hub

Question 123

Which AWS service is designed to help users handle large amounts of data in a data warehouse environment?

Options:

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon Aurora

Question 124

Which guidelines are best practices for using AWS Identity and Access Management (1AM)? (Select TWO.)

Options:

A.

Share access keys.

B.

Create individual 1AM users.

C.

Use inline policies instead of customer managed policies.

D.

Grant maximum privileges to 1AM users.

E.

Use groups to assign permissions to 1AM users.

Question 125

A company wants to migrate its on_premises workloads to the AWS Cloud. The company wants to separate workloads for chargeback to different departments.

Which AWS services or features will meet these requirements? (Select TWO.)

Options:

A.

Placement groups

B.

Consolidated billing

C.

Edge locations

D.

AWS Config

E.

Multiple AWS accounts

Question 126

A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify infrastructure deployments that do not meet best practices. Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWSConfig

D.

Amazon GuardDuty

Question 127

Which top-level key performance indicator (KPI) is available in AWS rightsizing recommendations of Cost Optimization?

Options:

A.

Container modernization opportunities

B.

Estimated monthly saving

C.

Reserved instances savings

D.

Compute savings recommendations

Question 128

A company needs a fully managed file server that natively supports Microsoft workloads and file systems The file server must also support the SMB protocol.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Elastic File System (Amazon EFS)

B.

Amazon FSx for Lustre

C.

Amazon FSx for Windows File Server

D.

Amazon Elastic Block Store (Amazon EBS)

Question 129

A company wants to manage its AWS Cloud resources through a web interface.

Which AWS service will meet this requirement?

Options:

A.

AWS Management Console

B.

AWS CLI

C.

AWS SDK

D.

AWS Cloud

Question 130

A company migrated its systems to the AWS Cloud. The systems are rightsized, and a security review did not reveal any issues. The company must ensure that additional developments, integrations, changes, and system usage growth do not jeopardize this optimized AWS infrastructure.

Which AWS service should the company use to report ongoing optimization and security?

Options:

A.

AWS Trusted Advisor

B.

AWS Health Dashboard

C.

Amazon Connect

D.

AWS Systems Manager

Question 131

Which AWS service or feature provides log information of the inbound and outbound traffic on network interfaces in a VPC?

Options:

A.

Amazon CloudWatch Logs

B.

AWS CloudTrail

C.

VPC Flow Logs

D.

AWS Identity and Access Management (IAM)

Question 132

A company plans to use an Amazon Snowball Edge device la transfer files to the AWS Cloud.

Which activities related in a Snowball device are available to the company at no cost?

Options:

A.

Use of the Snowball Edge appliance for a 10-day period

B.

The transfer of data out of Amazon S3 and 10 the Snowball Edge appliance

C.

The transfer of data from the Snowball Edge appliance into Amazon S3

D.

Daily use of the Snowball Edge appliance after 10 days

Question 133

A company wants to run its production workloads on AWS. The company needs concierge service, a designated AWS technical account manager (TAM), and technical support that is available 24 hours a day, 7 days a week.

Which AWS Support plan will meet these requirements?

Options:

A.

AWS Basic Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Developer Support

Question 134

Which AWS service converts text to lifelike voices?

Options:

A.

Amazon Transcribe

B.

Amazon Rekognition

C.

Amazon Polly

D.

Amazon Textract

Question 135

Which aspect of security is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Patch and configuration management

B.

Service and communications protection or zone security

C.

Physical and environmental controls

D.

Awareness and training

Question 136

A company simulates workflows to review and validate that all processes are effective and that staff are familiar with the processes.

Which design principle of the AWS Well-Architected Framework is the company following with this practice?

Options:

A.

Perform operations as code.

B.

Refine operation procedures frequently.

C.

Make frequent, small, reversible changes.

D.

Structure the company to support business outcomes.

Question 137

Which AWS service is an in-memory data store service?

Options:

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DynamoDB

D.

Amazon ElastiCache

Question 138

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

Options:

A.

Sustainability

B.

Security

C.

Performance efficiency

D.

Reliability

Question 139

A company's headquarters is located on a different continent from where the majority of the company's customers live. The company wants an AWS Cloud environment setup that will provide the lowest latency to the customers.

A company wants to automate the creation of new AWS accounts and automatically prevent all users from creating Amazon EC2

instances.

Which AWS service provides this functionality?

Options:

A.

AWS Service Catalog

B.

AWS Organizations

C.

EC2 Image Builder

D.

AWS Systems Manager

Question 140

What can a cloud practitioner use to retrieve AWS security and compliance documents and submit them as evidence to an auditor or regulator?

Options:

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS Artifact

D.

Amazon Inspector

Question 141

A company wants to design a reliable web application that is hosted on Amazon EC2.

Which approach will achieve this goal?

Options:

A.

Launch large EC2 instances in the same Availability Zone.

B.

Spread EC2 instances across more than one security group.

C.

Spread EC2 instances across more than one Availability Zone.

D.

Use an Amazon Machine Image (AMI) from AWS Marketplace.

Question 142

An ecommerce company has migrated its IT infrastructure from an on-premises data center to the AWS Cloud. Which cost is the company's direct responsibility?

Options:

A.

Cost of application software licenses

B.

Cost of the hardware infrastructure on AWS

C.

Cost of power for the AWS servers

D.

Cost of physical security for the AWS data center

Question 143

A company is running its application in the AWS Cloud. The company wants to periodically review its AWS account for cost optimization opportunities.

Which AWS service or tool can the company use to meet these requirements?

Options:

A.

AWS Cost Explorer

B.

AWS Trusted Advisor

C.

AWS Pricing

D.

AWS Budgets

Question 144

Which AWS service or feature is an example of a relational database management system?

Options:

A.

Amazon Athena

B.

Amazon Redshift

C.

Amazon S3 Select

D.

Amazon Kinesis Data Streams

Question 145

Which AWS service provides encryption at rest for Amazon RDS and for Amazon Elastic Block Store (Amazon EBS) volumes?

Options:

A.

AWS Lambda

B.

AWS Key Management Service (AWS KMS)

C.

AWSWAF

D.

Amazon Rekognition

Question 146

A company wants to use the AWS Cloud to deploy an application globally.

Which architecture deployment model should the company use to meet this requirement?

Options:

A.

Multi-Region

B.

Single-Region

C.

Multi-AZ

D.

Single-AZ

Question 147

Which tasks are customer responsibilities, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Configure the AWS provided security group firewall.

B.

Classify company assets in the AWS Cloud.

C.

Determine which Availability Zones to use for Amazon S3 buckets.

D.

Patch or upgrade Amazon DynamoDB.

E.

Select Amazon EC2 instances to run AWS Lambda on.

F.

AWS Config

Question 148

Which of the following is a benefit of using an AWS managed service?

Options:

A.

Reduced operational overhead for a company's IT staff

B.

Increased fixed costs that can be predicted by a finance team

C.

Removal of the need to have a backup strategy

D.

Removal of the need to follow compliance standards

Question 149

Which pillar of the AWS Well-Architected Framework includes the AWS shared responsibility model?

Options:

A.

Operational excellence

B.

Performance efficiency

C.

Reliability

D.

Security

Question 150

A company deployed an Amazon EC2 instance last week. A developer realizes that the EC2 instance is no longer running. The developer reviews a list of provisioned EC2 instances, and the EC2 instance is no longer on the list.

What can the developer do to generate a recent history of the EC2 instance?

Options:

A.

Run Cost Explorer to identify the start time and end time of the EC2 instance.

B.

Use Amazon Inspector to find out when the EC2 instance was stopped.

C.

Perform a search in AWS CloudTrail to find all EC2 instance-related events.

D.

Use AWS Secrets Manager to display hidden termination logs of the EC2 instance.

Question 151

A company is collecting user behavior patterns to identify how to meet goals for sustainability impact.

Which guidelines are best practices for the company to implement to meet these goals? (Select TWO.)

Options:

A.

Scale infrastructure with user load.

B.

Maximize the geographic distance between workloads and user locations.

C.

Eliminate creation and maintenance of unused assets.

D.

Scale resources with excess capacity and remove auto scaling.

E.

Scale infrastructure based on the number of users.

Question 152

A software engineer wants to launch a virtual machine (VM) and MySQL database on AWS.

Which AWS service will meet these requirements with the LEAST operational effort?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Elastic Beanstalk

C.

Amazon Lightsail

D.

Amazon EC2

Question 153

A company needs to engage third-party consultants to help maintain and support its AWS environment and the company's business needs.

Which AWS service or resource will meet these requirements?

Options:

A.

AWS Support

B.

AWS Organizations

C.

AWS Service Catalog

D.

AWS Partner Network (APN)

Question 154

In the AWS shared responsibility model, which tasks are the responsibility of AWS? (Select TWO.)

Options:

A.

Patch an Amazon EC2 instance operating system.

B.

Configure a security group.

C.

Monitor the health of an Availability Zone.

D.

Protect the infrastructure that runs Amazon EC2 instances.

E.

Manage access to the data in an Amazon S3 bucket

Question 155

Which of the following is a benefit of operating in the AWS Cloud?

Options:

A.

The ability to migrate on-premises network devices to the AWS Cloud

B.

The ability to expand compute, storage, and memory when needed

C.

The ability to host custom hardware in the AWS Cloud

D.

The ability to customize the underlying hypervisor layer for Amazon EC2

Question 156

Which AWS service should be used when a company needs to provide its remote employees with virtual desktops?

Options:

A.

Amazon Identity and Access Management (IAM)

B.

AWS Directory Service

C.

AWS IAM Identity Center (AWS Single Sign-On)

D.

Amazon Workspaces

Question 157

A company plans to migrate to the AWS Cloud. The company wants to use the AWS Cloud Adoption Framework (AWS CAF) to define and track business outcomes as part of its cloud transformation journey.

Which AWS CAF governance perspective capability will meet these requirements?

Options:

A.

Benefits management

B.

Risk management

C.

Application portfolio management

D.

Cloud financial management

Question 158

A company wants a time-series database service that makes it easier to store and analyze trillions of events each day.

Which AWS service will meet this requirement?

Options:

A.

Amazon Neptune

B.

Amazon Timestream

C.

Amazon Forecast

D.

Amazon DocumentDB (with MongoDB compatibility)

Question 159

A company wants to migrate its high-performance computing (HPC) application to Amazon EC2 instances. The application has multiple components. The application must have fault tolerance and must have the ability to fail over automatically.

Which AWS infrastructure solution will meet these requirements with the LEAST latency between components?

Options:

A.

Multiple AWS Regions

B.

Multiple edge locations

C.

Multiple Availability Zones

D.

Regional edge caches

Question 160

Which of the following is a benefit that AWS Professional Services provides?

Options:

A.

Management of the ongoing security of user data

B.

Advisory solutions for AWS adoption

C.

Technical support 24 hours a day, 7 days a week

D.

Monitoring of monthly billing costs in AWS accounts

Question 161

A company has a single Amazon EC2 instance. The company wants to adopt a highly available architecture.

What can the company do to meet this requirement?

Options:

A.

Scale vertically to a larger EC2 instance size.

B.

Scale horizontally across multiple Availability Zones.

C.

Purchase an EC2 Dedicated Instance.

D.

Change the EC2 instance family to a compute optimized instance.

Question 162

A company is hosting an application in the AWS Cloud. The company wants to verify that underlying AWS services and general AWS infrastructure are operating normally.

Which combination of AWS services can the company use to gather the required information? (Select TWO.)

Options:

A.

AWS Personal Health Dashboard

B.

AWS Systems Manager

C.

AWS Trusted Advisor

D.

AWS Service Health Dashboard

E.

AWS Service Catalog

Question 163

A company wants to move its iOS application development and build activities to AWS.

Which AWS service or resource should the company use for these activities?

Options:

A.

AWS CodeCommit

B.

Amazon EC2 M1 Mac instances

C.

AWS Amplify

D.

AWS App Runner

Question 164

A company wants high levels of detection and near-real-time (NRT) mitigation against large and sophisticated distributed denial of service (DDoS) attacks on applications running on AWS.

Which AWS service should the company use?

Options:

A.

Amazon GuardDuty

B.

Amazon Inspector

C.

AWS Shield Advanced

D.

Amazon Macie

Question 165

A company wants to ensure that all of its Amazon EC2 instances have compliant operating system patches.

Which AWS service will meet these requirements?

Options:

A.

AWS Compute Optimizer

B.

AWS Elastic Beanstalk

C.

AWS AppSync

D.

AWS Systems Manager

Question 166

A company is running an Amazon EC2 instance in a VPC.

An ecommerce company is using Amazon EC2 Auto Scaling groups to manage a fleet of web servers running on Amazon EC2.

This architecture follows which AWS Well-Architected Framework best practice?

Options:

A.

Secure the workload

B.

Decouple infrastructure components

C.

Design for failure

D.

Think parallel

Question 167

A company needs to control inbound and outbound traffic for an Amazon EC2 instance.

Which AWS service or feature can the company associate with the EC2 instance to meet this requirement?

Options:

A.

Network ACL

B.

Security group

C.

AWS WAF

D.

VPC route tables

Question 168

A company needs to migrate a PostgreSQL database from on-premises to Amazon RDS.

Which AWS service or tool should the company use to meet this requirement?

Options:

A.

Cloud Adoption Readiness Tool

B.

AWS Migration Hub

C.

AWS Database Migration Service (AWS DMS)

D.

AWS Application Migration Service

Question 169

A company wants to query its server logs to gain insights about its customers' experiences.

Which AWS service will store this data MOST cost-effectively?

Options:

A.

Amazon Aurora

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon S3

Question 170

A company wants an automated process to continuously scan its Amazon EC2 instances for software vulnerabilities.

Which AWS service will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

Amazon Inspector

C.

Amazon Detective

D.

Amazon Cognito

Question 171

A company wants to set up a high-speed connection between its data center and its applications that run on AWS. The company must not transfer data over the internet.

Which action should the company take to meet these requirements?

Options:

A.

Transfer data to AWS by using AWS Snowball.

B.

Transfer data to AWS by using AWS Storage Gateway.

C.

Set up a VPN connection between the data center and an AWS Region.

D.

Set up an AWS Direct Connect connection between the company network and AWS.

Question 172

A company deployed an application on an Amazon EC2 instance. The application ran as expected for 6 months. In the past week, users

have reported latency issues. A system administrator found that the CPU utilization was at 100% during business hours. The company

wants a scalable solution to meet demand.

Which AWS service or feature should the company use to handle the load for its application during periods of high demand?

Options:

A.

Auto Scaling groups

B.

AWS Global Accelerator

C.

Amazon Route 53

D.

An Elastic IP address

Question 173

A company has designed its AWS Cloud infrastructure to run its workloads effectively. The company also has protocols in place to

continuously improve supporting processes.

Which pillar of the AWS Well-Architected Framework does this scenario represent?

Options:

A.

Security

B.

Performance efficiency

C.

Cost optimization

D.

Operational excellence

Question 174

A company needs to apply security rules to specific Amazon EC2 instances.

Which AWS service or feature provides this functionality?

Options:

A.

AWS Shield

B.

Network ACLs

C.

Security groups

D.

AWS Firewall Manager

Question 175

A company needs to store infrequently used data for data archives and long-term backups.

A company needs a history report about how its Amazon EC2 instances were modified last month.

Which AWS service can be used to meet this requirement?

Options:

A.

AWS Service Catalog

B.

AWS Config

C.

Amazon CloudWatch

D.

AWS Artifact

Question 176

A company has a centralized group of users with large file storage requirements that have exceeded the space available on premises. The company wants to extend its file storage capabilities for this group while retaining the performance benefit of sharing content locally.

What is the MOST operationally efficient AWS solution for this scenario?

Options:

A.

Create an Amazon S3 bucket for each user. Mount each bucket by using an S3 file system mounting utility.

B.

Configure and deploy an AWS Storage Gateway file gateway. Connect each user's workstation to the file gateway.

C.

Move each user's working environment to Amazon Workspaces. Set up an Amazon WorkDocs account for each user.

D.

Deploy an Amazon EC2 instance and attach an Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS volume. Share the EBS volume directly with the users.

Question 177

A company wants to use Amazon EC2 instances for a stable production workload that will run for 1 year.

Which instance purchasing option meets these requirements MOST cost-effectively?

Options:

A.

Dedicated Hosts

B.

Reserved Instances

C.

On-Demand Instances

D.

Spot Instances

Question 178

A company wants to grant users in one AWS account access to resources in another AWS account. The users do not currently have permission to access the resources.

Which AWS service will meet this requirement?

Options:

A.

IAM group

B.

IAM role

C.

IAM tag

D.

IAM Access Analyzer

Question 179

A company wants an AWS service to provide product recommendations based on its customer data.

Which AWS service will meet this requirement?

Options:

A.

Amazon Polly

B.

Amazon Personalize

C.

Amazon Comprehend

D.

Amazon Rekognition

Question 180

A company is running an application on AWS. The company wants to identify and prevent the accidental

Which AWS service or feature will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

Network ACL

C.

AWS WAF

D.

AWS Network Firewall

Question 181

A company has all of its servers in the us-east-1 Region. The company is considering the deployment of additional servers different Region.

Which AWS tool should the company use to find pricing information for other Regions?

Options:

A.

Cost Explorer

B.

AWS Budgets

C.

AWS Purchase Order Management

D.

AWS Pricing Calculator

Question 182

A company is using a central data platform to manage multiple types of data for its customers. The company wants to use AWS services to discover, transform, and visualize the data.

Which combination of AWS services should the company use to meet these requirements? (Select TWO.)

Options:

A.

AWS Glue

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Redshift

D.

Amazon QuickSight

E.

Amazon Quantum Ledger Database (Amazon QLDB)

Question 183

A company needs to implement identity management for a fleet of mobile apps that are running in the AWS Cloud.

Which AWS service will meet this requirement?

Options:

A.

Amazon Cognito

B.

AWS Security Hub

C.

AWS Shield

D.

AWS WAF

Question 184

Which task must a user perform by using the AWS account root user credentials?

Options:

A.

Make changes to AWS production resources.

B.

Change AWS Support plans.

C.

Access AWS Cost and Usage Reports.

D.

Grant auditors’ access to an AWS account for a compliance audit.

Question 185

Which AWS service provides this functionality?

Options:

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Systems Manager

C.

AWS Config

D.

AWS Control Tower

Question 186

Which perspective in the AWS Cloud Adoption Framework (AWS CAF) includes a capability for well-designed data and analytics architecture?

Options:

A.

Security

B.

Governance

C.

Operations

D.

Platform

Question 187

Which AWS services are connectivity services for a VPC? (Select TWO.)

Options:

A.

AWS Site-to-Site VPN

B.

AWS Direct Connect

C.

Amazon Connect

D.

AWS Key Management Service (AWS KMS)

E.

AWS Identity and Access Management (IAM)

Question 188

Which AWS service requires the customer to be fully responsible for applying operating system patches?

Options:

A.

Amazon DynamoDB

B.

AWS Lambda

C.

AWS Fargate

D.

Amazon EC2

Question 189

Which task can only an AWS account root user perform?

Options:

A.

Changing the AWS Support plan

B.

Deleting AWS resources

C.

Creating an Amazon EC2 instance key pair

D.

Configuring AWS WAF

Question 190

Which of the following is a fully managed MySQL-compatible database?

Options:

A.

Amazon S3

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon Aurora

Question 191

Which benefit does AWS offer exclusively to users who have an AWS Enterprise Support plan?

Options:

A.

Access to a technical project manager

B.

Access to a technical account manager (TAM)

C.

Access to a cloud support engineer

D.

Access to a solutions architectA company wants to automatically set up and govern a multi-account AWS environment.

Question 192

A company is planning to host its workloads on AWS.

Which AWS service requires the company to update and patch the guest operating system?

Options:

A.

Amazon DynamoDB

B.

Amazon S3

C.

Amazon EC2

D.

Amazon Aurora

Question 193

Which AWS service can identify when an Amazon EC2 instance was terminated?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS CloudTrail

C.

AWS Compute Optimizer

D.

Amazon EventBridge

Question 194

A company wants its Amazon EC2 instances to share the same geographic area but use multiple independent underlying power sources.

Which solution achieves this goal?

Options:

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Question 195

According to the AWS shared responsibility model, who is responsible for the virtualization layer down to the

physical security of the facilities in which AWS services operate?

Options:

A.

It is the sole responsibility of the customer.

B.

It is the sole responsibility of AWS.

C.

It is a shared responsibility between AWS and the customer.

D.

The customer's AWS Support plan tier determines who manages the configuration.

Question 196

A company is running a workload in the AWS Cloud.

Which AWS best practice ensures the MOST cost-effective architecture for the workload?

Options:

A.

Loose coupling

B.

Rightsizing

C.

Caching

D.

Redundancy

Question 197

Which AWS service or feature offers security for a VPC by acting as a firewall to control traffic in and out of subnets?

Options:

A.

AWS Security Hub

B.

Security groups

C.

Network ACL

D.

AWSWAF

Question 198

A user is moving a workload from a local data center to an architecture that is distributed between the local data center and the AWS Cloud.

Which type of migration is this?

Options:

A.

On-premises to cloud native

B.

Hybrid to cloud native

C.

On-premises to hybrid

D.

Cloud native to hybrid

Question 199

Which of the following are advantages of the AWS Cloud? (Select TWO.)

Options:

A.

Trade variable expenses for capital expenses

B.

High economies of scale

C.

Launch globally in minutes

D.

Focus on managing hardware infrastructure

E.

Overprovision to ensure capacity

Question 200

A company's application stores data in an Amazon S3 bucket. The company has an AWS Lambda function that processes data in the S3

bucket. The company needs to invoke the function once a day at a specific time.

Which AWS service should the company use to meet this requirement?

Options:

A.

AWS Managed Services (AMS)

B.

AWS CodeStar

C.

Amazon EventBridge

D.

AWS Step Functions

Question 201

Which AWS service or feature captures information about the network traffic to and from an Amazon EC2 instance?

Options:

A.

VPC Reachability Analyzer

B.

Amazon Athena

C.

VPC Flow Logs

D.

AWS X-Ray

Question 202

Which credential allows programmatic access to AWS resources for use from the AWS CLI or the AWS API?

Options:

A.

User name and password

B.

Access keys

C.

SSH public keys

D.

AWS Key Management Service (AWS KMS) keys

Question 203

A company needs to identify the last time that a specific user accessed the AWS Management Console.

Which AWS service will provide this information?

Options:

A.

Amazon Cognito

B.

AWS CloudTrail

C.

Amazon Inspector

D.

Amazon GuardDuty

Question 204

Which tasks are customer responsibilities according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Determine application dependencies with operating systems.

B.

Provide user access with AWS Identity and Access Management (IAM).

C.

Secure the data center in an Availability Zone.

D.

Patch the hypervisor.

E.

Provide network availability in Availability Zones.

Question 205

Which pillar of the AWS Well-Architected Framework includes a design principle about measuring the overall efficiency of workloads in terms of business value?

Options:

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Question 206

A company runs a database on Amazon Aurora in the us-east-1 Region. The company has a disaster recovery requirement that the database be available in another Region.

Which solution meets this requirement with minimal disruption to the database operations?

Options:

A.

Perform an Aurora Multi-AZ deployment.

B.

Deploy Aurora cross-Region read replicas.

C.

Create Amazon Elastic Block Store (Amazon EBS) volume snapshots for Aurora and copy them to another Region.

D.

Deploy Aurora Replicas.

Question 207

A company wants to securely store Amazon RDS database credentials and automatically rotate user passwords periodically.

Which AWS service or capability will meet these requirements?

Options:

A.

Amazon S3

B.

AWS Systems Manager Parameter Store

C.

AWS Secrets Manager

D.

AWS CloudTrail

Question 208

Which AWS service offers a global content delivery network (CDN) that helps companies securely deliver websites, videos, applications,

and APIs at high speeds with low latency?

Options:

A.

Amazon EC2

B.

Amazon CloudFront

C.

Amazon CloudWatch

D.

AWS CloudFormation

Question 209

Which AWS solution gives companies the ability to use protocols such as NFS to store and retrieve objects in Amazon S3?

Options:

A.

Amazon FSx for Lustre

B.

AWS Storage Gateway volume gateway

C.

AWS Storage Gateway file gateway

D.

Amazon Elastic File System (Amazon EFS)

Question 210

Which task is a customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Management of the guest operating systems

B.

Maintenance of the configuration of infrastructure devices

C.

Management of the host operating systems and virtualization

D.

Maintenance of the software that powers Availability ZonesA company has refined its workload to use specific AWS services to improve efficiency and reduce cost.

Question 211

Which tasks are the responsibility of AWS according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Configure AWS Identity and Access Management (IAM).

B.

Configure security groups on Amazon EC2 instances.

C.

Secure the access of physical AWS facilities.

D.

Patch applications that run on Amazon EC2 instances.

E.

Perform infrastructure patching and maintenance.

Question 212

Which AWS service should a cloud engineer use to view API calls to AWS services?

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Config

D.

AWS Artifact

Question 213

A company is designing a web application that will run on Amazon EC2 instances.

Which AWS services and features will improve availability and reduce the impact of failures for this application?

(Select TWO.)

Options:

A.

Amazon EC2 Auto Scaling for the EC2 instances

B.

VPC subnet ACLs to check the health of a service

C.

Resources that are distributed across multiple Availability Zones

D.

Configuration of AWS Server Migration Service (AWS SMS) to move the EC2 instances to a differentAWS Region

E.

Resources that are distributed across multiple AWS points of presence

Question 214

A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a

natural disaster in a particular geographic area.

Which solution achieves this goal?

Options:

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple edge locations.

D.

Use Amazon CloudFront with the EC2 instances configured as the source.

Question 215

A company needs to centralize its operational data. The company also needs to automate tasks across all of its Amazon EC2 instances.

Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

AWS Systems Manager

C.

AWS CodeDeploy

D.

AWS Elastic Beanstalk

Question 216

company wants to protect its AWS Cloud information, systems, and assets while performing risk assessment and mitigation tasks.

Which pillar of the AWS Well-Architected Framework is supported by these goals?

Options:

A.

Reliability

B.

Security

C.

Operational excellence

D.

Performance efficiency

Question 217

A company needs to configure rules to identify threats and protect applications from malicious network access.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Identity and Access Management (IAM)

B.

Amazon QuickSight

C.

AWS WAF

D.

Amazon Detective

Question 218

A company recently migrated to the AWS Cloud. The company needs to determine whether its newly imported Amazon EC2 instances are the appropriate size and type.

Which AWS services can provide this information to the company? {Select TWO.)

Options:

A.

AWS Auto Scaling

B.

AWS Control Tower

C.

AWS Trusted Advisor

D.

AWS Compute Optimizer

E.

Amazon Forecast

Question 219

Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO.)

Options:

A.

Availability

B.

Reliability

C.

Scalability

D.

Responsive design

E.

Operational excellence

Question 220

A company has a social media platform in which users upload and share photos with other users. The company wants to identify and remove inappropriate photos. The company has no machine learning (ML) scientists and must build this detection capability with no ML expertise.

Which AWS service should the company use to build this capability?

Options:

A.

Amazon SageMaker

B.

Amazon Textract

C.

Amazon Rekognition

D.

Amazon Comprehend

Question 221

Which of the following are customer responsibilities under the AWS shared responsibility model? (Select TWO.)

Options:

A.

Physical security of AWS facilities

B.

Configuration of security groupsQ C. Encryption of customer data on AWS

C.

Management of AWS Lambda infrastructureQ E. Management of network throughput of each AWS Region

Question 222

A company wants to establish a security layer in its VPC that will act as a firewall to control subnet traffic.

Which AWS service or feature will meet this requirement?

Options:

A.

Routing tables

B.

Network access control lists (network ACLs)

C.

Security groups

D.

Amazon GuardDuty

Question 223

Which AWS service can a company use to securely store and encrypt passwords for a database?

Options:

A.

AWS Shield

B.

AWS Secrets Manager

C.

AWS Identity and Access Management (IAM)

D.

Amazon Cognito

Question 224

In which of the following AWS services should database credentials be stored for maximum security?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS Secrets Manager

C.

Amazon S3

D.

AWS Key Management Service (AWS KMS)

Question 225

A company has an environment that includes Amazon EC2 instances, Amazon Lightsail, and on-premises servers. The company wants to automate the security updates for its operating systems and applications.

Which solution will meet these requirements with the LEAST operational effort?

Options:

A.

Use AWS Shield to identify and manage security events.

B.

Connect to each server by using a remote desktop connection. Run an update script.

C.

Use the AWS Systems Manager Patch Manager capability.

D.

Schedule Amazon GuardDuty to run on a nightly basis.

Question 226

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

Options:

A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Question 227

Which options are perspectives that include foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)? (Select TWO.)

Options:

A.

Sustainability

B.

Security

C.

Operations

D.

Performance efficiency

E.

Reliability

Question 228

Which AWS Support plan provides customers with access to an AWS technical account manager (TAM)?

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Question 229

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances. The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 230

A company plans to migrate its on-premises workload to AWS. Before the migration, the company needs to estimate its future AWS service costs.

Which AWS service or tool should the company use to meet this requirement?

Options:

A.

AWS Trusted Advisor

B.

AWS Budgets

C.

AWS Pricing Calculator

D.

AWS Cost Explorer

Question 231

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

Options:

A.

Set up multi-factor authentication (MFA) for each Workspaces user account.

B.

Ensure the environmental safety and security of the AWS infrastructure that hosts Workspaces.

C.

Provide security for Workspaces user accounts through AWS Identity and Access Management(IAM).

D.

Configure AWS CloudTrail to log API calls and user activity.A company stores data in an Amazon S3 bucket. The company must control who has permission to read, write,or delete objects that the company stores in the S3 bucket.

Question 232

A company wants to implement controls (guardrails) in a newly created AWS Control Tower landing zone.

Which AWS services or features can the company use to create and define these controls (guardrails)? (Select TWO.)

Options:

A.

AWS Config

B.

Service control policies (SCPs)

C.

Amazon GuardDuty

D.

AWS Identity and Access Management (IAM)

E.

Security groups

Question 233

A company wants to create a chatbot and integrate the chatbot with its current web application.

Which AWS service will meet these requirements?

Options:

A.

AmazonKendra

B.

Amazon Lex

C.

AmazonTextract

D.

AmazonPolly

Question 234

A company has multiple AWS accounts that include compute workloads that cannot be interrupted. The company wants to obtain billing discounts that are based on the company's use of AWS services.

Which AWS feature or purchasing option will meet these requirements?

Options:

A.

Resource tagging

B.

Consolidated billing

C.

Pay-as-you-go pricing

D.

Spot Instances

Question 235

What can a user accomplish using AWS CloudTrail?

Options:

A.

Generate an IAM user credentials report.

B.

Record API calls made to AWS services.

C.

Assess the compliance of AWS resource configurations with policies and guidelines.

D.

Ensure that Amazon EC2 instances are patched with the latest security updates.A company uses Amazon Workspaces.

Question 236

A company needs to run its existing custom, nonproduction workloads in the AWS Cloud quickly and cost-effectively.

The workloads can recover from interruptions easily.

Which pricing model should the company use?

Options:

A.

Reserved Instances

B.

On-Demand Instances

C.

Spot Instances

D.

Dedicated Hosts

Question 237

A company is migrating a relational database server to the AWS Cloud. The company wants to minimize

administrative overhead of database maintenance tasks.

Which AWS service will meet these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon EC2

C.

Amazon Redshift

D.

Amazon RDS

Question 238

Which AWS database service provides in-memory data storage?

Options:

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon RDS

D.

Amazon Timestream

Question 239

A company is using Amazon RDS.

A company is launching a critical business application in an AWS Region.

How can the company increase resilience for this application?

Options:

A.

Deploy a copy of the application in another AWS account.

B.

Deploy the application by using multiple VPCs.

C.

Deploy the application by using multiple subnets.

D.

Deploy the application by using multiple Availability Zones.

Question 240

According to the AWS shared responsibility model, which of the following are AWS responsibilities? (Select TWO.)

Options:

A.

Network infrastructure and virtualization of infrastructure

B.

Security of application data

C.

Guest operating systems

D.

Physical security of hardware

E.

Credentials and policies

Question 241

A company is using a third-party service to back up 10 TB of data to a tape library. The on-premises backup server is running out of space. The company wants to use AWS services for the backups without changing its existing

backup workflows.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Elastic Block Store (Amazon EBS)

B.

AWS Storage Gateway

C.

Amazon Elastic Container Service (Amazon ECS)

D.

AWS Lambda

Question 242

A company needs to store data across multiple Availability Zones in an AWS Region. The data will not be

accessed regularly but must be immediately retrievable.

Which Amazon Elastic File System (Amazon EFS) storage class meets these requirements MOST cost effectively?

Options:

A.

EFS Standard

B.

EFS Standard-Infrequent Access(EFS Standard-IA)

C.

EFS One Zone

D.

EFS One Zone-Infrequent Access (EFS One Zone-IA)

Question 243

Which AWS services or features can control VPC traffic? (Select TWO.)

Options:

A.

Security groups

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

Network ACLs

E.

Amazon Connect

Question 244

Which activity is a customer responsibility in the AWS Cloud according to the AWS shared responsibility model?

Options:

A.

Ensuring network connectivity from AWS to the internet

B.

Patching and fixing flaws within the AWS Cloud infrastructure

C.

Ensuring the physical security of cloud data centers

D.

Ensuring Amazon EBS volumes are backed up

Question 245

A company wants its Amazon EC2 instances to share the same geographic area but use redundant underlying power sources.

Which solution will meet these requirements?

Options:

A.

Use EC2 instances across multiple Availability Zones in the same AWS Region.

B.

Use Amazon CloudFront as the database for the EC2 instances.

C.

Use EC2 instances in the same edge location and the same Availability Zone.

D.

Use EC2 instances in AWS OpsWorks stacks in different AWS Regions.

Question 246

A user wants to identify any security group that is allowing unrestricted incoming SSH traffic.

Which AWS service can be used to accomplish this goal?

Options:

A.

Amazon Cognito

B.

AWS Shield

C.

Amazon Macie

D.

AWS Trusted Advisor

Question 247

A company has an AWS-hosted website located behind an Application Load Balancer. The company wants to safeguard the website from SQL injection or cross-site scripting.

Which AWS service should the company use?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Trusted Advisor

D.

Amazon Inspector

Question 248

A company needs to host a web server on Amazon EC2 instances for at least 1 year. The web server cannot tolerate interruption.

Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

Options:

A.

On-Demand Instances

B.

Partial Upfront Reserved Instances

C.

Spot Instances

D.

No Upfront Reserved Instances

Question 249

A company wants an in-memory data store that is compatible with open source in the cloud.

Which AWS service should the company use?

Options:

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon Redshift

Question 250

A company needs to launch an Amazon EC2 instance.

Which of the following can the company use during the launch process to configure the root volume of the EC2 instance?

Options:

A.

Amazon EC2 Auto Scaling

B.

Amazon Data Lifecycle Manager (Amazon DLM)

C.

Amazon Machine Image (AMI)

D.

Amazon Elastic Block Store (Amazon EBS) volume

Question 251

A company is configuring its AWS Cloud environment. The company's administrators need to group users together and apply permissions to the group.

Which AWS service or feature can the company use to meet these requirements?

Options:

A.

AWS Organizations

B.

Resource groups

C.

Resource tagging

D.

AWS Identity and Access Management (IAM)

Question 252

A company is using AWS Lambda functions to build an application.

Which tasks are the company's responsibility, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Patch the servers where the Lambda functions are deployed.

B.

Establish the IAM permissions that define who can run the Lambda functions.

C.

Write the code for the Lambda functions to define the application logic.

D.

Deploy Amazon EC2 instances to support the Lambda functions.

E.

Scale out the Lambda functions when the load increases.

Question 253

Which of the following are advantages of moving to the AWS Cloud? (Select TWO.)

Options:

A.

The ability to turn over the responsibility for all security to AWS.

B.

The ability to use the pay-as-you-go model.

C.

The ability to have full control over the physical infrastructure.

D.

No longer having to guess what capacity will be required.

E.

No longer worrying about users access controls.

Question 254

A company does not want to rely on elaborate forecasting to determine its usage of compute resources. Instead, the company wants to pay only for the resources that it uses. The company also needs the ability to increase or decrease its resource usage to meet business requirements.

Which pillar of the AWS Well-Architected Framework aligns with these requirements?

Options:

A.

Operational excellence

B.

Security

C.

Reliability

D.

Cost optimization

Question 255

Which AWS service provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning (ML)?

Options:

A.

Amazon Kendra

B.

Amazon SageMaker

C.

Amazon Augmented Al (Amazon A2I)

D.

Amazon Polly

Question 256

Which AWS feature or resource is a deployable Amazon EC2 instance template that is prepackaged with

software and security requirements?

Options:

A.

Amazon Elastic Block Store (Amazon EBS) volume

B.

AWS CloudFormation template

C.

Amazon Elastic Block Store (Amazon EBS) snapshot

D.

Amazon Machine Image (AMI)

Question 257

A company is developing an application that uses multiple AWS services. The application needs to use

temporary, limited-privilege credentials for authentication with other AWS APIs.

Which AWS service or feature should the company use to meet these authentication requirements?

Options:

A.

Amazon API Gateway

B.

IAM users

C.

AWS Security Token Service (AWS STS)

D.

IAM instance profiles

Question 258

Which AWS Well-Architected Framework concept represents a system's ability to remain functional when the system encounters operational problems?

Options:

A.

Consistency

B.

Elasticity

C.

Durability

D.

Latency

Question 259

A company wants to use a managed service to simplify the setup, operation, and scaling of its MySQL database in the AWS Cloud.

Which AWS service will meet these requirements?

Options:

A.

Amazon EMR

B.

Amazon RDS

C.

Amazon Redshift

D.

Amazon DynamoDB

Question 260

Which of the following is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Identity and access management

B.

Hard drive initialization

C.

Protection of data center hardware

D.

Security of Availability Zones

Question 261

Which pillar of the AWS Well-Architected Framework focuses on the ability to run workloads effectively, gain insight into operations, and continuously improve supporting processes and procedures?

Options:

A.

Cost optimization

B.

Reliability

C.

Operational excellence

D.

Performance efficiency

Question 262

Which design principle should be considered when architecting in the AWS Cloud?

Options:

A.

Think of servers as non-disposable resources.

B.

Use synchronous integration of services.

C.

Design loosely coupled components.

D.

Implement the least permissive rules for security groups.

Question 263

A company's information security manager is supervising a move to AWS and wants to ensure that AWS best practices are followed. The manager has concerns about the potential misuse of AWS account root user credentials.

Which of the following is an AWS best practice for using the AWS account root user credentials?

Options:

A.

Allow only the manager to use the account root user credentials for normal activities.

B.

Use the account root user credentials only for Amazon EC2 instances from the AWS Free Tier.

C.

Use the account root user credentials only when they alone must be used to perform a requiredfunction.

D.

Use the account root user credentials only for the creation of private VPC subnets.

Page: 1 / 88
Total 881 questions