Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Amazon Web Services CLF-C02 AWS Certified Cloud Practitioner Exam Practice Test

Demo: 263 questions
Total 881 questions

AWS Certified Cloud Practitioner Questions and Answers

Question 1

Which option is an AWS Cloud Adoption Framework (AWS CAF) foundational capability for the operations perspective?

Options:

A.

Performance and capacity management

B.

Application portfolio management

C.

Identity and access management

D.

Product management

Question 2

How should the company deploy the application to meet these requirements?

Options:

A.

Ina single Availability Zone

B.

On AWS Direct Connect

C.

On Reserved Instances

D.

In multiple Availability Zones

Question 3

Which Amazon EC2 instan ce pricing model can provide discounts of up to 90%?

Options:

A.

Reserved Instances

B.

On-Demand

C.

Dedicated Hosts

D.

Spot Instances

Question 4

A company has an application workload that is stateless by design and can sustain occasional downtime. The application performs massively parallel computations.

Which Amazon EC2 pricing model should the company choose for its application to reduce cost?

Options:

A.

On-Demand Instances

B.

Spot Instances

C.

Reserved Instances

D.

Dedicated Instances

Question 5

A company wants to ensure that all of its Amazon EC2 instances have compliant operating system patches.

Which AWS service will meet these requirements?

Options:

A.

AWS Compute Optimizer

B.

AWS Elastic Beanstalk

C.

AWS AppSync

D.

AWS Systems Manager

Question 6

Which AWS service offers object storage?

Options:

A.

Amazon RDS

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon S3

D.

Amazon DynamoDB

Question 7

A company is migrating its data center to AWS. The company needs an AWS Support plan that provides chat access to a cloud sup engineer 24 hours a day, 7 days a week. The company does not require access to infrastructure event management.

What is the MOST cost-effective AWS Support plan that meets these requirements?

Options:

A.

AWS Enterprise Support

B.

AWS Business Support

C.

AWS Developer Support

D.

AWS Basic Support

Question 8

Which AWS service is deployed to VPCs and provides protection from common network threats?

Options:

A.

AWSShield

B.

AWSWAF

C.

AWS Network Firewall

D.

AWS FirewallManager

Question 9

A company runs a MySQL database in its on-premises data center. The company wants to run a copy of this database in the AWS

Cloud.

Which AWS service would support this workload?

Options:

A.

Amazon RDS

B.

Amazon Neptune

C.

Amazon ElastiCache for Redis

D.

Amazon Quantum Ledger Database (Amazon QLDB)

Question 10

Which company needs to apply security rules to a subnet for Amazon EC2 instances.

Which AWS service or feature provides this functionality?

Options:

A.

Network ACLs

B.

Security groups

C.

AWS Certificate Manager (ACM)

D.

AWS Config

Question 11

What is a characteristic of Convertible Reserved Instances (RIs)?

Options:

A.

Users can exchange Convertible RIs for other Convertible RIs from a different instance family.

B.

Users can exchange Convertible RIs for other Convertible RIs in different AWS Regions.

C.

Users can sell and buy Convertible RIs on the AWS Marketplace.

D.

Users can shorten the term of their Convertible RIs by merging them with other Convertible RIs.

Question 12

A company hosts a large amount of data in AWS. The company wants to identify if any of the data should be considered sensitive.

Which AWS service will meet the requirement?

Options:

A.

Amazon Inspector

B.

Amazon Macie

C.

AWS Identity and Access Management (IAM)

D.

Amazon CloudWatch

Question 13

A company needs to control inbound and outbound traffic for an Amazon EC2 instance.

Which AWS service or feature can the company associate with the EC2 instance to meet this requirement?

Options:

A.

Network ACL

B.

Security group

C.

AWS WAF

D.

VPC route tables

Question 14

An ecommerce company has migrated its IT infrastructure from an on-premises data center to the AWS Cloud. Which cost is the company's direct responsibility?

Options:

A.

Cost of application software licenses

B.

Cost of the hardware infrastructure on AWS

C.

Cost of power for the AWS servers

D.

Cost of physical security for the AWS data center

Question 15

A company wants to query its server logs to gain insights about its customers' experiences.

Which AWS service will store this data MOST cost-effectively?

Options:

A.

Amazon Aurora

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon S3

Question 16

A company is building an application that needs to deliver images and videos globally with minimal latency.

Which approach can the company use to accomplish this in a cost effective manner?

Options:

A.

Deliver the content through Amazon CloudFront.

B.

Store the content on Amazon S3 and enable S3 cross-region replication.

C.

Implement a VPN across multiple AWS Regions.

D.

Deliver the content through AWS PrivateLink.

Question 17

Which AWS services or features can a company use to connect the network of its on-premises data center to AWS? (Select TWO.)

Options:

A.

AWS VPN

B.

AWS Directory Service

C.

AWS Data Pipeline

D.

AWS Direct Connect

E.

AWS CloudHSM

Question 18

What does the concept of agility mean in AWS Cloud computing? (Select TWO.)

Options:

A.

The speed at which AWS resources are implemented

B.

The speed at which AWS creates new AWS Regions

C.

The ability to experiment quickly

D.

The elimination of wasted capacity

E.

The low cost of entry into cloud computing

Question 19

A company wants to verify if multi-factor authentication (MFA) is enabled for all users within its AWS accounts.

Which AWS service or resource will meet this requirement?

Options:

A.

AWS Cost and Usage Report

B.

IAM credential reports

C.

AWS Artifact

D.

Amazon CloudFront reports

Question 20

A company wants to use the latest technologies and wants to minimize its capital investment. Instead of upgrading on-premises infrastructure, the company wants to move to the AWS Cloud.

Which AWS Cloud benefit does this scenario describe?

Options:

A.

Increased speed to market

B.

The trade of infrastructure expenses for operating expenses

C.

Massive economies of scale

D.

The ability to go global in minutes

Question 21

A company is running and managing its own Docker environment on Amazon EC2 instances. The company wants an alternative to help manage cluster size, scheduling, and environment maintenance.

Which AWS service meets these requirements?

Options:

A.

AWS Lambda

B.

Amazon RDS

C.

AWS Fargate

D.

Amazon Athena

Question 22

A company wants its Amazon EC2 instances to share the same geographic area but use multiple independent underlying power sources.

Which solution achieves this goal?

Options:

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple AWS Regions.

C.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Question 23

A company wants to migrate its on-premises relational databases to the AWS Cloud. The company wants to use infrastructure as close to its current geographical location as possible.

Which AWS service or resource should the company use to select its Amazon RDS deployment area?

Options:

A.

Amazon Connect

B.

AWS Wavelength

C.

AWS Regions

D.

AWS Direct Connect

Question 24

A company is running its application in the AWS Cloud and wants to protect against a DDoS attack. The company's security team wants near real-time visibility into DDoS attacks.

Which AWS service or traffic filter will meet these requirements with the MOST features for DDoS protection?

Options:

A.

AWS Shield Advanced

B.

AWS Shield

C.

Amazon GuardDuty

D.

Network ACLs

Question 25

A company is running a monolithic on-premises application that does not scale and is difficult to maintain. The company has a plan to migrate the application to AWS and divide the application into microservices.

Which best practice of the AWS Well-Architected Framework is the company following with this plan?

Options:

A.

Integrate functional testing as part of AWS deployment.

B.

Use automation to deploy changes.

C.

Deploy the application to multiple locations.

D.

Implement loosely coupled dependencies.

Question 26

A company is running an application on AWS. The company wants to identify and prevent the accidental

Which AWS service or feature will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

Network ACL

C.

AWS WAF

D.

AWS Network Firewall

Question 27

Which AWS service provides this functionality?

Options:

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Systems Manager

C.

AWS Config

D.

AWS Control Tower

Question 28

A company wants to create a set of custom dashboards to collect metrics to monitor its applications.

Which AWS service will meet these requirements?

Options:

A.

Amazon CloudWatch

B.

AWS X-Ray

C.

AWS Systems Manager

D.

AWS CloudTrail

Question 29

A company needs to set a maximum spending limit on AWS services each month. The company also needs to set up alerts for when the company reaches its spending limit.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

Cost Explorer

B.

AWS Trusted Advisor

C.

Service Quotas

D.

AWS Budgets

Question 30

A company is building a mobile app to provide shopping recommendations to its customers. The company wants to use a graph database as part of the shopping recommendation engine.

Which AWS database service should the company choose?

Options:

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon Neptune

D.

Amazon DocumentDB (with MongoDB compatibility)

Question 31

Which AWS services are connectivity services for a VPC? (Select TWO.)

Options:

A.

AWS Site-to-Site VPN

B.

AWS Direct Connect

C.

Amazon Connect

D.

AWS Key Management Service (AWS KMS)

E.

AWS Identity and Access Management (IAM)

Question 32

Which of the following are general AWS Cloud design principles described in the AWS Well-Architected Framework?

Options:

A.

Consolidate key components into monolithic architectures.

B.

Test systems at production scale.

C.

Provision more capacity than a workload is expected to need.

D.

Drive architecture design based on data collected about the workload behavior and requirements.

E.

Make AWS Cloud architectural decisions static, one-time events.

Question 33

A company needs to run some of its workloads on premises to comply with regulatory guidelines. The company wants to use the AWS Cloud to run workloads that are not required to be on premises. The company also wants to be able to use the same API calls for the on-premises workloads and the cloud workloads.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

Dedicated Hosts

B.

AWS Outposts

C.

Availability Zones

D.

AWS Wavelength

Question 34

A developer who has no AWS Cloud experience wants to use AWS technology to build a web application.

Which AWS service should the developer use to start building the application?

Options:

A.

Amazon SageMaker

B.

AWS Lambda

C.

Amazon Lightsail

D.

Amazon Elastic Container Service (Amazon ECS)

Question 35

A company wants to use Amazon EC2 instances for a stable production workload that will run for 1 year.

Which instance purchasing option meets these requirements MOST cost-effectively?

Options:

A.

Dedicated Hosts

B.

Reserved Instances

C.

On-Demand Instances

D.

Spot Instances

Question 36

A company encourages its teams to test failure scenarios regularly and to validate their understanding of the impact of potential failures.

Which pillar of the AWS Well-Architected Framework does this philosophy represent?

Options:

A.

Operational excellence

B.

Cost optimization

C.

Performance efficiency

D.

Security

Question 37

A company wants to grant users in one AWS account access to resources in another AWS account. The users do not currently have permission to access the resources.

Which AWS service will meet this requirement?

Options:

A.

IAM group

B.

IAM role

C.

IAM tag

D.

IAM Access Analyzer

Question 38

Which database engines does Amazon Aurora support? (Select TWO.)

Options:

A.

Oracle

B.

Microsoft SQL Server

C.

MySQL

D.

PostgreSQL

E.

MongoDB

Question 39

Which tasks are the responsibility of the customer, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Patch the Amazon RDS operating system.

B.

Upgrade the firmware of the network infrastructure.

C.

Manage data encryption.

D.

Maintain physical access control in an AWS Region.

E.

Grant least privilege access to IAM users.

Question 40

A software engineer wants to launch a virtual machine (VM) and MySQL database on AWS.

Which AWS service will meet these requirements with the LEAST operational effort?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Elastic Beanstalk

C.

Amazon Lightsail

D.

Amazon EC2

Question 41

A company wants to migrate its high-performance computing (HPC) application to Amazon EC2 instances. The application has multiple components. The application must have fault tolerance and must have the ability to fail over automatically.

Which AWS infrastructure solution will meet these requirements with the LEAST latency between components?

Options:

A.

Multiple AWS Regions

B.

Multiple edge locations

C.

Multiple Availability Zones

D.

Regional edge caches

Question 42

A company needs to categorize and track AWS usage cost based on business categories.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

Cost allocation tags

B.

AWS Organizations

C.

AWS Security Hub

D.

AWS Cost and Usage Report

Question 43

A company wants to launch its web application in a second AWS Region. The company needs to determine which services must be regionally configured for this launch.

Which AWS services can be configured at the Region level? (Select TWO.)

Options:

A.

Amazon EC2

B.

Amazon Route 53

C.

Amazon CloudFront

D.

AWS WAF

E.

Amazon DynamoDB

Question 44

Which of the following is a benefit of using an AWS managed service?

Options:

A.

Reduced operational overhead for a company's IT staff

B.

Increased fixed costs that can be predicted by a finance team

C.

Removal of the need to have a backup strategy

D.

Removal of the need to follow compliance standards

Question 45

An ecommerce company wants to distribute traffic between the Amazon EC2 instances that host its website.

Which AWS service or resource will meet these requirements?

Options:

A.

Application Load Balancer

B.

AWS WAF

C.

AWS CloudHSM

D.

AWS Direct Connect

Question 46

AWS has the ability to achieve lower pay-as-you-go pricing by aggregating usage across hundreds of thousands of users.

This describes which advantage of the AWS Cloud?

Options:

A.

Launch globally in minutes

B.

Increase speed and agility

C.

High economies of scale

D.

No guessing about compute capacity

Question 47

A company that has multiple business units wants to centrally manage and govern its AWS Cloud environments. The company wants to automate the creation of AWS accounts, apply service control policies (SCPs), and simplify billing processes.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

AWS Organizations

B.

Cost Explorer

C.

AWS Budgets

D.

AWS Trusted Advisor

Question 48

A developer wants to deploy an application quickly on AWS without manually creating the required resources. Which AWS service will meet these requirements?

Options:

A.

Amazon EC2

B.

AWS Elastic Beanstalk

C.

AWS CodeBuild

D.

Amazon Personalize

Question 49

A company uses AWS Organizations. The company wants to apply security best practices from the AWS Well-Architected Framework to all of its AWS accounts.

Which AWS service will meet these requirements?

Options:

A.

Amazon Macie

B.

Amazon Detective

C.

AWS Control Tower

D.

AWS Secrets Manager

Question 50

Which AWS service can identify when an Amazon EC2 instance was terminated?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS CloudTrail

C.

AWS Compute Optimizer

D.

Amazon EventBridge

Question 51

Which option is the default pricing model for Amazon EC2 instances?

Options:

A.

On-Demand Instances

B.

Savings Plans

C.

Spot Instances

D.

Reserved Instances

Question 52

Which AWS service is an in-memory data store service?

Options:

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DynamoDB

D.

Amazon ElastiCache

Question 53

Which AWS service or tool helps users visualize, understand, and manage spending and usage over time?

Options:

A.

AWS Organizations

B.

AWS Pricing Calculator

C.

AWS Cost Explorer

D.

AWS Service Catalog

Question 54

Which AWS service should be used when a company needs to provide its remote employees with virtual desktops?

Options:

A.

Amazon Identity and Access Management (IAM)

B.

AWS Directory Service

C.

AWS IAM Identity Center (AWS Single Sign-On)

D.

Amazon Workspaces

Question 55

A company wants to receive alerts to monitor its overall operating costs for its AWS public cloud infrastructure.

Which AWS offering will meet these requirements?

Options:

A.

Amazon EventBridge

B.

Compute Savings Plans

C.

AWS Budgets

D.

Migration Evaluator

Question 56

Which AWS Cloud Adoption Framework (AWS CAF) capability belongs to the people perspective?

Options:

A.

Data architecture

B.

Event management

C.

Cloud fluency

D.

Strategic partnership

Question 57

Which abilities are benefits of the AWS Cloud? (Select TWO.)

Options:

A.

Trade variable expenses for capital expenses.

B.

Deploy globally in minutes.

C.

Plan capacity in advance of deployments.

D.

Take advantage of economies of scale.

E.

Reduce dependencies on network connectivity.

Question 58

Which AWS services can be used to store files? (Select TWO.)

Options:

A.

Amazon S3

B.

AWS Lambda

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon SageMaker

E.

AWS Storage Gateway

Question 59

Which AWS service provides encryption at rest for Amazon RDS and for Amazon Elastic Block Store (Amazon EBS) volumes?

Options:

A.

AWS Lambda

B.

AWS Key Management Service (AWS KMS)

C.

AWSWAF

D.

Amazon Rekognition

Question 60

A company's headquarters is located on a different continent from where the majority of the company's customers live. The company wants an AWS Cloud environment setup that will provide the lowest latency to the customers.

A company wants to automate the creation of new AWS accounts and automatically prevent all users from creating Amazon EC2

instances.

Which AWS service provides this functionality?

Options:

A.

AWS Service Catalog

B.

AWS Organizations

C.

EC2 Image Builder

D.

AWS Systems Manager

Question 61

A company has set up a VPC in its AWS account and has created a subnet in the VPC. The company wants to make the subnet public.

Which AWS features should the company use to meet this requirement? (Select TWO.)

Options:

A.

Amazon VPC internet gateway

B.

Amazon VPC NAT gateway

C.

Amazon VPC route tables

D.

Amazon VPC network ACL

E.

Amazon EC2 security groups

Question 62

Which actions are examples of a company's effort to right size its AWS resources to control cloud costs? (Select TWO.)

Options:

A.

Switch from Amazon RDS to Amazon DynamoDB to accommodate NoSQL datasets.Q B. Base the selection of Amazon EC2 instance types on past utilization patterns.

B.

Use Amazon S3 Lifecycle policies to move objects that users access infrequently to lower-cost storage tiers.

C.

Use Multi-AZ deployments for Amazon RDS.

D.

Replace existing Amazon EC2 instances with AWS Elastic Beanstalk.

Question 63

Which scenarios represent the concept of elasticity on AWS? (Select TWO.)

Options:

A.

Scaling the number of Amazon EC2 instances based on traffic

B.

Resizing Amazon RDS instances as business needs change

C.

Automatically directing traffic to less-utilized Amazon EC2 instances

D.

Using AWS compliance documents to accelerate the compliance process

E.

Having the ability to create and govern environments using code

Question 64

A company's application has high customer usage during certain times of the day. The company wants to reduce the number of Amazon EC2 instances that run when application usage is low.

Which AWS service or instance purchasing option should the company use to meet this requirement?

Options:

A.

EC2 Instance Savings Plans

B.

Spot Instances

C.

Reserved Instances

D.

Amazon EC2 Auto Scaling

Question 65

Which task must a user perform by using the AWS account root user credentials?

Options:

A.

Make changes to AWS production resources.

B.

Change AWS Support plans.

C.

Access AWS Cost and Usage Reports.

D.

Grant auditors’ access to an AWS account for a compliance audit.

Question 66

How does the AWS Enterprise Support Concierge team help users?

Options:

A.

Supporting application development

B.

Providing architecture guidance

C.

Answering billing and account inquiries

D.

Answering questions regarding technical support cases

Question 67

Which task is the shared responsibility of the customer and AWS under the AWS shared responsibility model?

Options:

A.

Installing hardware infrastructure

B.

Managing security

C.

Managing guest operating systems

D.

Protecting the physical infrastructure that runs all services

Question 68

A company is learning about its responsibilities that are related to the management of Amazon EC2 instances.

Which tasks for EC2 instances are the company's responsibility, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Install and patch the machine hypervisor.

B.

Patch the guest operating system.

C.

Encrypt data at rest on associated storage.

D.

Install the physical hardware and cabling.

E.

Provide physical security for the EC2 instances.

Question 69

Which AWS service provides storage-optimized and compute-optimized device configurations?

Options:

A.

AWS Snowcone

B.

AWS Storage Gateway

C.

AWS Snowball Edge

D.

AWS DataSync

Question 70

A company wants to minimize network latency between its Amazon EC2 instances. The EC2 instances do not need to be highly available. Which solution meets these requirements?

Options:

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple edge locations.

C.

Use EC2 instances in the same Availability Zone but in different AWS Regions.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Question 71

A company is building AWS architecture to deliver real-time data feeds from an on-premises data center into an application that runs on AWS. The company needs a consistent network connection with minimal latency.

What should the company use to connect the application and the data center to meet these requirements?

Options:

A.

AWS Direct Connect

B.

Public internet

C.

AWS VPN

D.

Amazon Connect

Question 72

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance state changes to RUNNING.

Which AWS service can the company use to meet this requirement?

Options:

A.

Amazon SageMaker

B.

Amazon Connect

C.

Amazon EventBridge

D.

AWS Fargate

Question 73

A company wants to migrate its applications from its on-premises data center to a VPC in the AWS Cloud. These applications will need to access on-premises resources. Which actions will meet these requirements? (Select TWO.)

Options:

A.

Use AWS Service Catalog to identify a list of on-premises resources that can be migrated.

B.

Create a VPN connection between an on-premises device and a virtual private gateway in the VPC.

C.

Use an Amazon CloudFront distribution and configure it to accelerate content delivery close to the on-premises resources

D.

Set up an AWS Direct Connect connection between the on-premises data center and AWS.

E.

Use Amazon CloudFront to restrict access to static web content provided through the on-premises web servers.

Question 74

Which AWS design principle emphasizes the reduction of interdependencies between components of an application?

Options:

A.

Scalability

B.

Loose coupling

C.

Automation

D.

Caching

Question 75

Which task is a responsibility of AWS, according to the AWS shared responsibility model?

Options:

A.

Configure identity and access management for applications.

B.

Manage encryption options for data that is stored on AWS.

C.

Configure security groups for Amazon EC2 instances.

D.

Maintain the physical hardware of the infrastructure.

Question 76

A company wants to control the protection of its AWS resources. The company wants to block SQL injection attacks and cross-site scripting.

Which AWS service or feature meets these requirements?

Options:

A.

Amazon GuardDuty

B.

AWSWAF

C.

Security groups

D.

AWS Shield

Question 77

Which actions are the responsibility of AWS. according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Securing the virtualization layer

B.

Patching the operating system on Amazon EC2 instances

C.

Enforcing a strict password policy for 1AM users

D.

Patching the operating system on Amazon RDS instances

E.

Configuring security groups and network ACLs

Question 78

A company has an on-premises application. The application has processing times of less than 5 minutes and is invoked only a few times each day. The company wants to move the application to the AWS Cloud.

Which AWS service will support this application MOST cost-effectively?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Lambda

C.

Amazon Elastic Kubernetes Service (Amazon EKS)

D.

Amazon EC2

Question 79

A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account.

Which AWS service or resource should the company use to meet this requirement?

Options:

A.

AWS Security Hub

B.

AWS Marketplace

C.

AWS Quick Starts

D.

AWS Security Center

Question 80

A company wants to securely access an Amazon S3 bucket from an Amazon EC2 instance without accessing the internet.

What should the company use to accomplish this goal?

Options:

A.

VPN connection

B.

Internet gateway

C.

VPC endpoint

D.

NAT gateway

Question 81

A company is releasing a business-critical application. Before the release, the company needs strategic planning assistance from AWS. During the release, the company needs AWS infrastructure event management and real-time support.

What should the company do to meet these requirement?

Options:

A.

Access AWS Trusted Advisor.

B.

Contact the AWS Partner Network (APN).

C.

Sign up for AWS Enterprise Support.

D.

Contact AWS Professional Services.

Question 82

A company plans to host its data warehouse application on AWS. The company has a machine learning (ML) model and wants to use that model within its data warehouse for data forecasting.

Options:

A.

Amazon DynamoDB

B.

Amazon Redshift ML

C.

Amazon Aurora ML

D.

Amazon MemoryDB

Question 83

Which design principle is related to the reliability pillar according to the AWS Well-Architected Framework?

Options:

A.

Test recovery procedures

B.

Experiment more often

C.

Go global in minutes

D.

Analyze and attribute to expenditure

Question 84

A company notices suspicious network activity against an application that is running on a fleet of Amazon EC2 instances. The suspicious activity is coming from a single IP address.

Which AWS service should the company use to block access from this IP address?

Options:

A.

AWS Shield

B.

AWS Config

C.

Amazon GuardDuty

D.

AWS WAF

Question 85

Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?

Options:

A.

AWS CloudFormation

B.

AWS CodeDeploy

C.

AWS CodeBuild

D.

AWS Systems Manager

Question 86

A company is running a key-value NoSQL workload on Amazon EC2 instances. The company needs the workload to have scalability, failover protection, and backup capabilities.

What is the MOST operationally efficient way to meet these requirements?

Options:

A.

Add additional EC2 instances to the database cluster.

B.

Run an identical copy of the database in a second Availability Zone.

C.

Migrate the database to Amazon DynamoDB.

D.

Migrate the database to a relational database.

Question 87

Which cloud concept is demonstrated by using AWS Cost Explorer?

Options:

A.

Rightsizing

B.

Reliability

C.

Resilience

D.

Modernization

Question 88

Where can AWS users review answers to frequently asked questions about security in the AWS Cloud?

Options:

A.

AWS Trusted Advisor

B.

AWS Knowledge Center

C.

AWS Support Center

D.

AWS Artifact

Question 89

A company wants to visualize and manage AWS Cloud costs and usage for a specific period of time.

Which AWS service or feature will meet these requirements?

Options:

A.

Cost Explorer

B.

Consolidated billing

C.

AWS Organizations

D.

AWS Budgets

Question 90

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on organizing an inventory of data products in a data catalog?

Options:

A.

Operations

B.

Governance

C.

Business

D.

Platform

Question 91

An Amazon EC2 instance previously used for development is inaccessible and no longer appears in the AWS Management Console.

Which AWS service should be used to determine what action made this EC2 instance inaccessible?

Options:

A.

Amazon CloudWatch Logs

B.

AWS Security Hub

C.

Amazon Inspector

D.

AWS CloudTrail

Question 92

A company needs access to checks and recommendations that help the company follow AWS best practices for cost optimization, security, fault tolerance, performance, and service quotas.

Which combination of an AWS service and AWS Support plan on the AWS account will meet these requirements?

Options:

A.

AWS Trusted Advisor with AWS Developer Support

B.

AWS Health Dashboard with AWS Enterprise Support

C.

AWS Trusted Advisor with AWS Business Support

D.

AWS Health Dashboard with AWS Enterprise On-Ramp Support

Question 93

A company wants to host an application on Amazon EC2 instances. The company needs to bring its own license for its operating systems. To meet governance and compliance requirements, the application needs software licensing at the physical server level.

Which EC2 instance purchasing option will meet these requirements?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

Dedicated Hosts

Question 94

Which AWS service or tool can be used to capture information about inbound and outbound traffic in an Amazon VPC?

Options:

A.

Amazon Inspector

B.

VPC endpoint services

C.

VPC Flow Logs

D.

NAT gateway

Question 95

A company wants to centrally manage Its employee's access to multiple AWS accounts.

Which AWS service or feature should the company use to meet this requirement?

Options:

A.

AWS Identity and Access Management Access Analyzer

B.

AWS Secrets Manager

C.

AWS IAM Identity Center

D.

AWS Security Token Service (AWS STS)

Question 96

A company uploads audio and video files to a centralized Amazon S3 bucket from different geographic locations. Which AWS solution will optimize transfer speeds for these files?

Options:

A.

AWS Global Accelerator

B.

S3 Transfer Acceleration

C.

AWS Direct Connect

D.

Amazon CloudFront

Question 97

Which AWS service supports the deployment and management of applications in the AWS Cloud?

Options:

A.

Amazon CodeGuru

B.

AWS Fargate

C.

AWS CodeCommit

D.

AWS Elastic Beanstalk

Question 98

A company plans to perform a one-time migration of a large dataset with millions of files from its on-premises data center to the AWS Cloud.

Which AWS service should the company use for the migration?

Options:

A.

AWS Database Migration Service (AWS DMS)

B.

AWS DataSync

C.

AWS Migration Hub

D.

AWS Application Migration Service

Question 99

A company is considering a move to the AWS Cloud. The company wants to be able to scale its compute resources as needed to accommodate changing loads.

Which benefit of the AWS Cloud does this scenario describe?

Options:

A.

Global deployment in minutes

B.

Cost savings

C.

Agility

D.

Elasticity

Question 100

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

Which action is the company's responsibility?

Options:

A.

Managing the infrastructure that runs the S3 bucket

B.

Managing the data in transit

C.

Managing the encryption options on the S3 bucket

D.

Managing the operating system updates on the S3 bucket

Question 101

Which task can an IAM user perform without AWS account root user credentials?

Options:

A.

Change to a different AWS Support plan.

B.

Close an AWS account.

C.

View the AWS Billing console.

D.

Activate access to the AWS Billing console.

Question 102

Which options are benefits of using third-party software from AWS Marketplace? (Select TWO.)

Options:

A.

The software's data encryption is managed by a third-party vendor.

B.

The software has been evaluated by vendors to ensure that it will run on AWS.

C.

Users do not need to upgrade to newer software versions.

D.

Users do not need to conduct security testing on the software.

E.

Users can launch preconfigured software in only a few steps.

Question 103

Which AWS service helps assess the security and compliance of applications that are deployed on Amazon EC2 instances?

Options:

A.

AWS Security Hub

B.

Amazon Inspector

C.

Amazon GuardDuty

D.

AWS Shield

Question 104

A company wants to use AWS. The company has stringent requirements about low-latency access to on-premises systems and data residency.

Which AWS service should the company use to design a solution that meets these requirements?

Options:

A.

AWS Wavelength

B.

AWS Transit Gateway

C.

AWS Ground Station

D.

AWS Outposts

Question 105

A company that uses AWS needs to transfer 2 TB of data.

Which type of transfer of that data would result in no cost for the company?

Options:

A.

Inbound data transfer from the internet

B.

Outbound data transfer to the internet

C.

Data transfer between AWS Regions

D.

Data transfer between Availability Zones

Question 106

A company wants to build, train, and deploy machine learning (ML) models.

Which AWS service will meet these requirements?

Options:

A.

Amazon Athena

B.

Amazon Comprehend

C.

Amazon Polly

D.

Amazon SageMaker AI

Question 107

A company wants to use a template to reliably provision, manage, and update its infrastructure in the AWS Cloud.

Options:

A.

AWS Lambda

B.

AWS CloudFormation

C.

AWS Fargate

D.

AWS CodeDeploy

Question 108

A company is creating a web application that requires a relational database to store customer data. Which AWS service should the company use to host the database?

Options:

A.

Amazon Aurora

B.

Amazon DynamoDB

C.

Amazon ElastiCache

D.

Amazon Redshift

Question 109

An ecommerce company has been monitoring usage of its online store that is hosted on a fleet of Amazon EC2 instances. Surges in traffic occur every weekend day at the same time and last for approximately 4 hours.

Options:

A.

AWS Lambda

B.

Amazon EventBridge

C.

Elastic Load Balancing (ELB)

D.

Amazon EC2 Auto Scaling

Question 110

Which AWS service or resource can provide discounts on some AWS service costs in exchange for a spending commitment?

Options:

A.

Amazon Detective

B.

AWS Pricing

C.

Savings Plans

D.

Basic Support

Question 111

Which AWS service provides on-premises applications with low-latency access to data that is stored in the AWS Cloud?

Options:

A.

Amazon CloudFront

B.

AWS Storage Gateway

C.

AWS Backup

D.

AWS DataSync

Question 112

Which AWS tool or feature acts as a VPC firewall at the subnet level?

Options:

A.

Security group

B.

Network ACL

C.

Traffic Mirroring

D.

Internet gateway

Question 113

A company needs to mount a file share across multiple Amazon EC2 instances as a mapped drive by using the SMB protocol. Which AWS service will meet these requirements?

Options:

A.

Amazon FSx for Windows File Server

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon S3

D.

AWS DataSync

Question 114

Which AWS service is a fully managed service for machine learning?

Options:

A.

AWS Lambda

B.

Amazon Kinesis

C.

Amazon Athena

D.

Amazon SageMaker

Question 115

A company wants to use an AWS networking solution that can act as a centralized gateway between multiple VPCs and on-premises networks. Which AWS service or feature will meet this requirement?

Options:

A.

Gateway VPC endpoint

B.

AWS Direct Connect

C.

AWS Transit Gateway

D.

AWS PrivateLink

Question 116

A company is undergoing a security audit. The audit includes security validation and compliance validation of the AWS infrastructure and services that the company uses. The auditor needs to locate compliance-related information and must download AWS security and compliance documents. These documents include the System and Organization Control (SOC) reports.

Options:

A.

AWS Abuse team

B.

AWS Artifact

C.

AWS Support

D.

AWS Config

Question 117

Which of the following is an architectural design principle of the AWS Well-Architected Framework?

Options:

A.

Loosely couple components

B.

Build monolithic systems

C.

Scale vertically, not horizontally

D.

Use third-party software

Question 118

Which of the following are features of network ACLs as they are used in the AWS Cloud? (Select TWO.)

Options:

A.

They are stateless.

B.

They are stateful.

C.

They evaluate all rules before allowing traffic.

D.

They process rules in order, starting with the lowest numbered rule, when deciding whether to allow traffic.

E.

They operate at the instance level.

Question 119

A company's workload can recover with minimal downtime when failures occur. Which AWS Cloud benefit does this scenario represent?

Options:

A.

Agility

B.

Elasticity

C.

Resiliency

D.

Scalability

Question 120

A company wants to secure its consumer web application by using SSL/TLS to encrypt traffic.

Which AWS service can the company use to meet this goal?

Options:

A.

AWS WAF

B.

AWS Shield

C.

Amazon VPC

D.

AWS Certificate Manager (ACM)

Question 121

A company needs to organize its resources and track AWS costs on a detailed level. The company needs to categorize costs by business department, environment, and application. Which solution will meet these requirements'?

Options:

A.

Access the AWS Cost Management console to organize resources set an AWS budget, and receive notifications of unintentional usage.

B.

Use tags to organize the resources. Activate cost allocation tags to track AWS costs on a detailed level.

C.

Create Amazon CloudWatch dashboards to visually organize and track costs individually.

D.

Access the AWS Billing and Cost Management dashboard to organize and track resource consumption on a detailed level.

Question 122

A company is building a business intelligence solution that uses Amazon Redshift. The company wants to use an AWS service to create interactive dashboards and not pay any upfront costs for it.

Which service should the company use?

Options:

A.

Amazon CloudWatch

B.

AWS Health Dashboard

C.

AWS Service Catalog

D.

Amazon QuickSight

Question 123

A company needs a hybrid cloud storage service to connect its on-premises environment to scalable AWS Cloud storage. Which AWS service will meet these requirements?

Options:

A.

Amazon S3

B.

Amazon FSx

C.

AWS Storage Gateway

D.

AWS Fargate

Question 124

A company needs to store infrequently used data for data archives and long-term backups.

Which AWS service or storage class will meet these requirements MOST cost-effectively?

Options:

A.

Amazon FSx for Lustre

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3 Glacier Flexible Retrieval

Question 125

Which design principles are included in the reliability pillar of the AWS Well-Architected Framework? (Select TWO.)

Options:

A.

Automatically recover from failure.

B.

Grant everyone access to increase AWS service quotas.

C.

Stop guessing capacity.

D.

Design applications to run in a single Availability Zone.

E.

Plan to increase AWS service quotas first in a secondary AWS Region.

Question 126

Which design principle aligns with the performance efficiency pillar of the AWS Well-Architected Framework?

Options:

A.

Enable traceability

B.

Measure the cost of workloads

C.

Scale vertically

D.

Use serverless architectures

Question 127

A company plans to migrate to the AWS Cloud. The company wants to gather information about its on-premises data center.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Application Discovery Service

B.

AWS DataSync

C.

AWS Storage Gateway

D.

AWS Database Migration Service (AWS DMS)

Question 128

A user wants to invoke an AWS Lambda function when an Amazon EC2 instance enters the "stopping" state.

Which AWS service is appropriate for this use case?

Options:

A.

Amazon EventBridge

B.

AWS Config

C.

Amazon Simple Notification Service (Amazon SNS)

D.

AWS CloudFormation

Question 129

A company wants to transport 100 TB of data from its data center to AWS without using internet.

Which AWS service will meet this requirement?

Options:

A.

AWS Snowcone

B.

AWS Snowball Edge

C.

AWS Data Exchange

D.

AWS DataSync

Question 130

A company purchased Amazon EC2 Standard Reserved Instances (Rls) for a workload in the AWS Cloud. The company needs to move part of the workload to an instance family that does not match the instance family of these Standard RIs.

How can the company take advantage of the Standard RIs that it no longer needs?

Options:

A.

Contact the AWS Support team, and ask the team to sell the Standard RIs.

B.

Sell the Standard RIs on the Amazon EC2 Reserved Instance Marketplace.

C.

Sell the Standard RIs as a third-party seller on the AWS Marketplace.

D.

Convert the Standard RIs to Savings Plans.

Question 131

A developer needs to interact with AWS by using the AWS CLI.

Which security feature or AWS service must be provisioned in the developer's account to meet this requirement?

Options:

A.

User name and password

B.

AWS Systems Manager

C.

Root password access

D.

AWS access key

Question 132

A company wants to use an AWS networking solution to connect multiple VPCs.

Which AWS service will meet this requirement?

Options:

A.

AWS Config

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

AWS Transit Gateway

Question 133

Which AWS network services or features allow Cl DR block notation when providing an IP address range?

(Select TWO.)

Options:

A.

Security groups

B.

Amazon Machine Image (AMI)

C.

Network access control list (network ACL)

D.

AWS Budgets

E.

Amazon Elastic Block Store (Amazon EBS)

Question 134

Which tasks are the responsibility of AWS according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Configure AWS Identity and Access Management (IAM).

B.

Configure security groups on Amazon EC2 instances.

C.

Secure the access of physical AWS facilities.

D.

Patch applications that run on Amazon EC2 instances.

E.

Perform infrastructure patching and maintenance.

Question 135

Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Patch AWS network devices.

B.

Set user password rules.

C.

Provide physical security for compute resources.

D.

Configure security groups.

E.

Patch the operating system of an Amazon EC2 instance.

Question 136

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

Options:

A.

Third-party vendors

B.

Customers

C.

Reseller partners

D.

Internet providers

Question 137

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

Options:

A.

Perform quarterly disaster recovery tests.

B.

Place the main component on the us-east-1 Region.

C.

Design for automatic failover to healthy resources.

D.

Design workloads to fit on a single Amazon EC2 instance.

Question 138

Which AWS service should a cloud practitioner use to receive real-time guidance for provisioning resources, based on AWS best practices related to security, cost optimization, and service limits?

Options:

A.

AWS Trusted Advisor

B.

AWS Config

C.

AWS Security Hub

D.

AWS Systems Manager

Question 139

A company needs to run its existing custom, nonproduction workloads in the AWS Cloud quickly and cost-effectively.

The workloads can recover from interruptions easily.

Which pricing model should the company use?

Options:

A.

Reserved Instances

B.

On-Demand Instances

C.

Spot Instances

D.

Dedicated Hosts

Question 140

Which AWS services or features can control VPC traffic? (Select TWO.)

Options:

A.

Security groups

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

Network ACLs

E.

Amazon Connect

Question 141

Which AWS service provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning (ML)?

Options:

A.

Amazon Kendra

B.

Amazon SageMaker

C.

Amazon Augmented Al (Amazon A2I)

D.

Amazon Polly

Question 142

A company hosts an application on an Amazon EC2 instance. The EC2 instance needs to access several AWS resources, including Amazon S3 and Amazon DynamoDB.

What is the MOST operationally efficient solution to delegate permissions?

Options:

A.

Create an IAM role with the required permissions. Attach the role to the EC2 instance.

B.

Create an IAM user and use its access key and secret access key in the application.

C.

Create an IAM user and use its access key and secret access key to create a CLI profile in the EC2 instance.

D.

Create an IAM role with the required permissions. Attach the role to the administrativeIAM user.

Question 143

Which option is an advantage of AWS Cloud computing that minimizes variable costs?

Options:

A.

High availability

B.

Economies of scale

C.

Global reach

D.

Agility

Question 144

An auditor needs to find out whether a specific AWS service is compliant with specific compliance frameworks.

Which AWS service will provide this information?

Options:

A.

AWS Artifact

B.

AWS Trusted Advisor

C.

Amazon GuardDuty

D.

AWS Certificate Manager (ACM)

Question 145

A company wants to host its relational databases on AWS. The databases have predefined schemas that the company needs to replicate on AWS.

Which AWS services could the company use for the databases? (Select TWO.)

Options:

A.

Amazon Aurora

B.

Amazon RDS

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

E.

Amazon DynamoDB

Question 146

Which credential allows programmatic access to AWS resources for use from the AWS CLI or the AWS API?

Options:

A.

User name and password

B.

Access keys

C.

SSH public keys

D.

AWS Key Management Service (AWS KMS) keys

Question 147

What does the Amazon S3 Intelligent-Tiering storage class offer?

Options:

A.

Payment flexibility by reserving storage capacity

B.

Long-term retention of data by copying the data to an encrypted Amazon Elastic Block Store (AmazonEBS) volume

C.

Automatic cost savings by moving objects between tiers based on access pattern changes

D.

Secure, durable, and lowest cost storage for data archival

Question 148

An ecommerce company has migrated its IT infrastructure from an on-premises data center to the AWS Cloud.

Which AWS service is used to track, record, and audit configuration changes made to AWS resources?

Options:

A.

AWS Shield

B.

AWS Config

C.

AWS IAM

D.

Amazon Inspector

Question 149

Who is responsible for decommissioning end-of-life underlying storage devices that are used to host data on AWS?

Options:

A.

Customer

B.

AWS

C.

Account creator

D.

Auditing team

Question 150

Which AWS services can a company use to host and run a MySQL database? (Select TWO.)

Options:

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon S3

D.

Amazon EC2

E.

Amazon MQ

Question 151

A company wants to deploy and manage a Docker-based application on AWS.

Which solution meets these requirements with the LEAST amount of operational overhead?

Options:

A.

An open-source Docker orchestrator on Amazon EC2 instances

B.

AWS AppSync

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

Amazon Elastic Container Service (Amazon ECS)

Question 152

A company has an application with robust hardware requirements. The application must be accessed by students who are using lightweight, low-cost laptops.

Which AWS service will help the company deploy the application without investing in backend infrastructure or high end client hardware?

Options:

A.

Amazon AppStream 2.0

B.

AWS AppSync

C.

Amazon WorkLink

D.

AWS Elastic Beanstalk

Question 153

A company has an AWS-hosted website located behind an Application Load Balancer. The company wants to safeguard the website from SQL injection or cross-site scripting.

Which AWS service should the company use?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Trusted Advisor

D.

Amazon Inspector

Question 154

Which AWS service or tool offers consolidated billing?

Options:

A.

AWS Artifact

B.

AWS Budgets

C.

AWS Organizations

D.

AWS Trusted AdvisorA company wants to limit its employees' AWS access to a portfolio of predefined AWS resources.

Question 155

A company is designing a web application that will run on Amazon EC2 instances.

Which AWS services and features will improve availability and reduce the impact of failures for this application?

(Select TWO.)

Options:

A.

Amazon EC2 Auto Scaling for the EC2 instances

B.

VPC subnet ACLs to check the health of a service

C.

Resources that are distributed across multiple Availability Zones

D.

Configuration of AWS Server Migration Service (AWS SMS) to move the EC2 instances to a differentAWS Region

E.

Resources that are distributed across multiple AWS points of presence

Question 156

A large company has a workload that requires hardware to remain on premises. The company wants to use the same management and control plane services that it currently uses on AWS.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Device Farm

B.

AWS Fargate

C.

AWS Outposts

D.

AWS Ground Station

Question 157

Which AWS service should a cloud engineer use to view API calls to AWS services?

Options:

A.

Amazon CloudWatch

B.

AWS CloudTrail

C.

AWS Config

D.

AWS Artifact

Question 158

Which AWS benefit is demonstrated by on-demand technology services that enable companies to replace upfront fixed expenses with variable expenses?

Options:

A.

High availability

B.

Economies of scale

C.

Pay-as-you-go pricing

D.

Global reach

Question 159

Which of the following is an advantage that users experience when they move on-premises workloads to the AWS Cloud?

Options:

A.

Elimination of expenses for running and maintaining data centers

B.

Price discounts that are identical to discounts from hardware providers

C.

Distribution of all operational controls to AWS

D.

Elimination of operational expenses

Question 160

Which AWS service will help protect applications running on AWS from DDoS attacks?

Options:

A.

Amazon GuardDuty

B.

AWS WAF

C.

AWS Shield

D.

Amazon Inspector

Question 161

Which AWS service provides highly durable object storage?

Options:

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon FSx

Question 162

A company needs a content delivery network that provides secure delivery of data, videos, applications, and APIs to users globally with low latency and high transfer speeds.

Which AWS service meets these requirements?

Options:

A.

Amazon CloudFront

B.

Elastic Load Balancing

C.

Amazon S3

D.

Amazon Elastic Transcoder

Question 163

A company plans to migrate its on-premises workload to AWS. Before the migration, the company needs to estimate its future AWS service costs.

Which AWS service or tool should the company use to meet this requirement?

Options:

A.

AWS Trusted Advisor

B.

AWS Budgets

C.

AWS Pricing Calculator

D.

AWS Cost Explorer

Question 164

A large company wants to track the combined AWS usage costs of all of its linked accounts.

How can this be accomplished?

Options:

A.

Use AWS Trusted Advisor to generate customized summary reports.

B.

Use AWS Organizations to generate consolidated billing reports.

C.

Use AWS Budgets to set utilization targets and receive summary reports.

D.

Use the AWS Control Tower dashboard to get a summary report of all linked account costs.

Question 165

Which AWS service can a company use to perform complex analytical queries?

Options:

A.

Amazon RDS

B.

Amazon DynamoDB

C.

Amazon Redshift

D.

Amazon ElastiCache

Question 166

Which of the following is an advantage of AWS Cloud computing?

Options:

A.

Trade security for elasticity.

B.

Trade operational excellence for agility.

C.

Trade fixed expenses for variable expenses.

D.

Trade elasticity for performance.

Question 167

A company is hosting a web application on Amazon EC2 instances. The company wants to implement custom conditions to filter and control inbound web traffic.

Which AWS service will meet these requirements?

Options:

A.

Amazon GuardDuty

B.

AWSWAF

C.

Amazon Macie

D.

AWS Shield

Question 168

When a user wants to utilize their existing per-socket, per-core, or per-virtual machine software licenses for a Microsoft Windows server running on AWS, which Amazon EC2 instance type is required?

Options:

A.

Spot Instances

B.

Dedicated Instances

C.

Dedicated Hosts

D.

Reserved Instances

Question 169

A company is using a third-party service to back up 10 TB of data to a tape library. The on-premises backup server is running out of space. The company wants to use AWS services for the backups without changing its existing

backup workflows.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Elastic Block Store (Amazon EBS)

B.

AWS Storage Gateway

C.

Amazon Elastic Container Service (Amazon ECS)

D.

AWS Lambda

Question 170

According to the AWS shared responsibility model, which of the following are AWS responsibilities? (Select TWO.)

Options:

A.

Network infrastructure and virtualization of infrastructure

B.

Security of application data

C.

Guest operating systems

D.

Physical security of hardware

E.

Credentials and policies

Question 171

Which statements represent the cost-effectiveness of the AWS Cloud? (Select TWO.)

Options:

A.

Users can trade fixed expenses for variable expenses.

B.

Users can deploy all over the world in minutes.

C.

AWS offers increased speed and agility.

D.

AWS is responsible for patching the infrastructure.

E.

Users benefit from economies of scale.

Question 172

A company is migrating a relational database server to the AWS Cloud. The company wants to minimize

administrative overhead of database maintenance tasks.

Which AWS service will meet these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon EC2

C.

Amazon Redshift

D.

Amazon RDS

Question 173

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

Options:

A.

AWS CloudTrail

B.

AWS Cost and Usage Reports

C.

AWS Trusted Advisor

D.

AWS Budgets

Question 174

Which AWS service meets this requirement?

Options:

A.

AWS CloudFormation

B.

AWS Elastic Beanstalk

C.

AWS Cloud9

D.

AWS CloudShell

Question 175

Which AWS Cloud design principle does a company follow by using AWS CloudTrail?

Options:

A.

Recover automatically.

B.

Perform operations as code.

C.

Measure efficiency.

D.

Ensure traceability.

Question 176

A company wants to migrate its Microsoft SQL Server database management system from on premises to the AWS Cloud.

Which AWS service should the company use to reduce management overhead for this environment?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon SageMaker

C.

Amazon RDS

D.

Amazon Athena

Question 177

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances. The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 178

Which AWS service or tool does AWS Control Tower use to create resources?

Options:

A.

AWS CloudFormation

B.

AWS Trusted Advisor

C.

AWS Directory Service

D.

AWS Cost Explorer

Question 179

Which of the following is a benefit of decoupling an AWS Cloud architecture?

Options:

A.

Reduced latency

B.

Ability to upgrade components independently

C.

Decreased costs

D.

Fewer components to manage

Question 180

A company moves a workload to AWS to run on Amazon EC2 instances. The company needs to run the workload in the most cost-effective way.

What can the company do to meet this requirement?

Options:

A.

Use AWS Key Management Service (AWS KMS).

B.

Use multiple AWS accounts and consolidated billing.

C.

Use AWS CloudFormation to deploy the infrastructure.

D.

Rightsized all the EC2 instances that are used in the deployment.

Question 181

Which of the following are benefits that a company receives when it moves an on-premises production workload to AWS? (Select TWO.)

Options:

A.

AWS trains the company's staff on the use of all the AWS services.

B.

AWS manages all security in the cloud.

C.

AWS offers free support from technical account managers (TAMs).

D.

AWS offers high availability.

E.

AWS provides economies of scale.

Question 182

A company wants to move its data warehouse application to the AWS Cloud. The company wants to run and scale its analytics services without needing to provision and manage data warehouse clusters.

Which AWS service will meet these requirements?

Options:

A.

Amazon Redshift provisioned data warehouse

B.

Amazon Redshift Serverless

C.

Amazon Athena

D.

Amazon S3

Question 183

Which of the following are AWS Cloud design principles? (Select TWO.)

Options:

A.

Pay for compute resources in advance.

B.

Make data-driven decisions to determine cloud architectural design.

C.

Emphasize manual processes to allow for changes.

D.

Test systems at production scale.

E.

Refine operational procedures infrequently.

Question 184

Which of the following is entirely the responsibility of AWS, according to the AWS shared responsibility model?

Options:

A.

Security awareness and training

B.

Development of an IAM password policy

C.

Patching of the guest operating system

D.

Physical and environmental controls

Question 185

A company is building a serverless architecture that connects application data from multiple data sources. The company needs a solution that does not require additional code.

Which AWS service meets these requirements?

Options:

A.

AWS Lambda

B.

Amazon Simple Queue Service (Amazon SQS)

C.

Amazon CloudWatch

D.

Amazon EventBridge

Question 186

A company wants its workload to perform consistently and correctly.

Which benefit of AWS Cloud computing does this goal represent?

Options:

A.

Security

B.

Elasticity

C.

Pay-as-you-go pricing

D.

Reliability

Question 187

Which of the following is an AWS value proposition that describes a user's ability to scale infrastructure based on demand?

Options:

A.

Speed of innovation

B.

Resource elasticity

C.

Decoupled architecture

D.

Global deployment

Question 188

A company has two AWS accounts in an organization in AWS Organizations for consolidated billing. All of the company's AWS resources are hosted in one AWS Region.

Account A has purchased five Amazon EC2 Standard Reserved Instances (RIs) and has four EC2 instances

running. Account B has not purchased any RIs and also has four EC2 instances running.

Which statement is true regarding pricing for these eight instances?

Options:

A.

The eight instances will be charged as regular instances.

B.

Four instances will be charged as RIs, and four will be charged as regular instances.

C.

Five instances will be charged as RIs, and three will be charged as regular instances.

D.

The eight instances will be charged as RIs.

Question 189

A company wants guidance to optimize the cost and performance of its current AWS environment.

Which AWS service or tool should the company use to identify areas for optimization?

Options:

A.

Amazon QuickSight

B.

AWS Trusted Advisor

C.

AWS Organizations

D.

AWS Budgets

Question 190

Which services can be used to deploy applications on AWS? (Select TWO.)

Options:

A.

AWS Elastic Beanstalk

B.

AWS Config

C.

AWS OpsWorksQ D. AWS Application Discovery Service

D.

Amazon Kinesis

Question 191

Which AWS service or feature is used to send both text and email messages from distributed applications?

Options:

A.

Amazon Simple Notification Service (Amazon SNS)

B.

Amazon Simple Email Service (Amazon SES)

C.

Amazon CloudWatch alerts

D.

Amazon Simple Queue Service (Amazon SQS)

Question 192

What is a benefit of moving to the AWS Cloud in terms of improving time to market?

Options:

A.

Decreased deployment speed

B.

Increased application security

C.

Increased business agility

D.

Increased backup capabilities

Question 193

A company needs to host a web server on Amazon EC2 instances for at least 1 year. The web server cannot tolerate interruption.

Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

Options:

A.

On-Demand Instances

B.

Partial Upfront Reserved Instances

C.

Spot Instances

D.

No Upfront Reserved Instances

Question 194

Which of the following is a characteristic of the AWS account root user?

Options:

A.

The root user is the only user that can be configured with multi-factor authentication (MFA).

B.

The root user is the only user that can access the AWS Management Console.

C.

The root user is the first sign-in identity that is available when an AWS account is created.

D.

The root user has a password that cannot be changed.

Question 195

A company has been storing monthly reports in an Amazon S3 bucket. The company exports the report data into comma-separated values (.csv) files. A developer wants to write a simple query that can read all of these files and generate a summary report.

Which AWS service or feature should the developer use to meet these requirements with the LEAST amount of operational overhead?

Options:

A.

Amazon S3 Select

B.

Amazon Athena

C.

Amazon Redshift

D.

Amazon EC2

Question 196

Which AWS service can defend against DDoS attacks?

Options:

A.

AWS Firewall Manager

B.

AWS Shield Standard

C.

AWS WAF

D.

Amazon Inspector

Question 197

A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access.

According to the AWS shared responsibility model, which task is the responsibility of the customer?

Options:

A.

Protect the global infrastructure that runs all of the services offered in the AWS Cloud.

B.

Configure logical access controls for resources, and protect account credentials.

C.

Configure the security used by managed services.

D.

Patch and back up Amazon Aurora.

Question 198

Which AWS database service provides in-memory data storage?

Options:

A.

Amazon DynamoDB

B.

Amazon ElastiCache

C.

Amazon RDS

D.

Amazon Timestream

Question 199

Using AWS Identity and Access Management (IAM) to grant access only to the resources needed to perform a task is a concept known as:

Options:

A.

restricted access.

B.

as-needed access.

C.

least privilege access.

D.

token access.

Question 200

Which of the following is a fully managed graph database service on AWS?

Options:

A.

Amazon Aurora

B.

Amazon FSx

C.

Amazon DynamoDB

D.

Amazon Neptune

Question 201

Which AWS service can run a managed PostgreSQL database that provides online transaction processing (OLTP)?

Options:

A.

Amazon DynamoDB

B.

Amazon Athena

C.

Amazon RDS

D.

Amazon EMR

Question 202

A company needs a managed NFS file system that the company can use with its AWS compute....

Which AWS service or feature will meet these requirements?

Options:

A.

Amazon Elastic Block Store (Amazon EBS)

B.

AWS Storage Gateway Tape Gateway

C.

Amazon S3 Glacier Flexible Retrieval

D.

Amazon Elastic Pile System (Amazon EFS)

Question 203

Which benefit is always free of charge with AWS, regardless of a user's AWS Support plan?

Options:

A.

AWS Developer Support

B.

AWS Developer Forums

C.

Programmatic case management

D.

AWS technical account manager (TAM)

Question 204

Which pillar of the AWS Well-Architected Framework focuses on the ability to recover automatically from service Interruptions?

Options:

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Question 205

Which fully managed AWS service assists with the creation, testing, and management of custom Amazon EC? images?

Options:

A.

EC2 Image Builder

B.

Amazon Machine Image (AMI)

C.

AWS Launch Wizard

D.

AWS Elastic Beanstalk

Question 206

A company wants to build, tram, and deploy machine learning (ML) models.

Which AWS service can the company use to meet this requirement?

Options:

A.

Amazon Personalize

B.

Amazon Comprehend

C.

Amazon Forecast

D.

Amazon SageMaker

Question 207

Which AWS service allows for file sharing between multiple Amazon EC2 Instances?

Options:

A.

AWS Direct Connect

B.

AWS Snowball Edge

C.

AWS Backup

D.

Amazon Elastic File System (Amazon EFS)

Question 208

A company wants to establish a private network connection between AWS and its corporate network.

Which AWS service or feature will meet this requirement?

Options:

A.

Amazon Connect

B.

Amazon Route 53

C.

AWS Direct Connect

D.

VPC peering

Question 209

Which AWS Support plan provides the full set of AWS Trusted Advisor checks at the LOWEST cost?

Options:

A.

AWS Developer Support

B.

AWS Business Support

C.

AWS Enterprise On-Ramp Support

D.

AWS Enterprise Support

Question 210

Which guidelines are best practices for using AWS Identity and Access Management (1AM)? (Select TWO.)

Options:

A.

Share access keys.

B.

Create individual 1AM users.

C.

Use inline policies instead of customer managed policies.

D.

Grant maximum privileges to 1AM users.

E.

Use groups to assign permissions to 1AM users.

Question 211

A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify infrastructure deployments that do not meet best practices. Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWSConfig

D.

Amazon GuardDuty

Question 212

A company has deployed a web application to Amazon EC2 instances. The EC2 instances have low usage. Which AWS service or feature should lite company use in rightsized the FC? instances?

Options:

A.

AWS Config

B.

AWS Cost Anomaly Detection

C.

AWS Budgets

D.

AWS Compute Optimizer

Question 213

A company wants to run its application on Amazon EC2 instances. The company needs to keep the application on-premises to meet a compliance requirement. Which AWS offering will meet these requirements?

Options:

A.

Dedicated Instances

B.

Amazon CloudFront

C.

AWS Fargate

D.

AWS Outposts

Question 214

A company is using AWS for all its IT Infrastructure. The company's developers are allowed to deploy applications on their own. The developers want to deploy their applications without having to provision the infrastructure themselves.

Which AWS service should the developers use to meet these requirements?

Options:

A.

AWS Cloud Formation

B.

AWS CodeBuild

C.

AWS Elastic Beanstalk

D.

AWS CodeDeploy

Question 215

A company needs stateless network filtering for its VPC.

Which AWS service, tool, or feature will meet this requirement?

Options:

A.

AWS PrivateLink

B.

Security group

C.

Network access control list (ACL)

D.

AWS WAF

Question 216

A company wants to allow users to authenticate and authorize multiple AWS accounts by using a single set of credentials.

Which AWS service or resource will meet this requirement?

Options:

A.

AWS Organizations

B.

IAM user

C.

AWS IAM Identity Center (AWS Single Sign-On)

D.

AWS Control Tower

Question 217

Which AWS feature provides a no-cost platform for AWS users to join community groups, ask questions, find answers, and read community-generated articles about best practices?

Options:

A.

AWS Knowledge Center

B.

AWS re:Post

C.

AWS 10

D.

AWS Enterprise Support

Question 218

A company wants to migrate its on-premises infrastructure to the AWS Cloud.

Which advantage of cloud computing will help the company reduce upfront costs?

Options:

A.

Go global in minutes

B.

Increase speed and agility

C.

Benefit from massive economies of scale

D.

Trade fixed expense for variable expense

Question 219

Which AWS service can be used at no additional cost?

Options:

A.

Amazon SageMaker

B.

AWS Config

C.

AWS Organizations

D.

Amazon CloudWatch

Question 220

A company wants to migrate its PostgreSQL database to AWS. The company does not use the database frequently.

Which AWS service or resource will meet these requirements with the LEAST management overhead?

Options:

A.

PostgreSQL on Amazon EC2

B.

Amazon RDS for PostgreSQL

C.

Amazon Aurora PostgreSQL-Compatible Edition

D.

Amazon Aurora Serverless

Question 221

A company runs its production workload in the AWS Cloud. The company needs to choose one of the AWS Support Plans.

Which of the AWS Support Plans will meet these requirements at the LOWEST cost?

Options:

A.

Developer

B.

Enterprise On-Ramp

C.

Enterprise

D.

Business

Question 222

A company wants to migrate to AWS and use the same security software it uses on premises. The security software vendor offers its security software as a service on AWS.

Where can the company purchase the security solution?

Options:

A.

AWS Partner Solutions Finder

B.

AWS Support Center

C.

AWS Management Console

D.

AWS Marketplace

Question 223

Which responsibility belongs to AWS when a company hosts its databases on Amazon EC2 instances?

Options:

A.

Database backups

B.

Database software patches

C.

Operating system patches

D.

Operating system installations

Question 224

A company has an application that produces unstructured data continuously. The company needs to store the data so that the data is durable and easy to query.

Which AWS service can the company use to meet these requirements?

Options:

A.

Amazon RDS

B.

Amazon Aurora

C.

Amazon QuickSight

D.

Amazon DynamoDB

Question 225

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on real-time insights and answers questions about strategy?

Options:

A.

Operations

B.

People

C.

Business

D.

Platform

Question 226

Which task is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Patch a guest operating system that is deployed on an Amazon EC2 instance.

B.

Control physical access to an AWS data center

C.

Control access to AWS underlying hardware.

D.

Patch a host operating system that is deployed on Amazon S3.

Question 227

A company has data lakes designed for high performance computing (HPC) workloads. Which Amazon EC2 instance type should the company use to meet these requirements?

Options:

A.

General purpose instances

B.

Compute optimized instances

C.

Memory optimized instances

D.

Storage optimized instances

Question 228

What is the recommended use case for Amazon EC2 On-Demand Instances?

Options:

A.

A steady-state workload that requires a particular EC2 instance configuration for a long period of time

B.

A workload that can be interrupted for a project that requires the lowest possible cost

C.

An unpredictable workload that does not require a long-term commitment

D.

A workload that is expected to run for longer than 1 year

Question 229

A company is using Amazon DynamoDB for its application database.

Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Classify data.

B.

Configure access permissions.

C.

Manage encryption options.

D.

Provide public endpoints to store and retrieve data.

E.

Manage the infrastructure layer and the operating system.

Question 230

Which AWS service or feature provides a firewall at the subnet level within a VPC?

Options:

A.

Security group

B.

Network ACL

C.

Elastic network interface

D.

AWS WAF

Question 231

A company wants to deploy a web application as a containerized application. The company wants to use a managed service that can automatically create container images from source code and deploy the containerized application.

Which AWS service will meet these requirements?

Options:

A.

AWS Elastic Beanstalk

B.

Amazon Elastic Container Service (Amazon ECS)

C.

AWS App Runner

D.

Amazon EC2

Question 232

A company uses a third-party identity provider (IdP). The company wants to provide its employees with access to AWS accounts and services without requiring another set of login credentials.

Which AWS service will meet this requirement?

Options:

A.

AWS Directory Service

B.

Amazon Cognito

C.

AWS IAM Identity Center

D.

AWS Resource Access Manager (AWS RAM)

Question 233

An ecommerce company has deployed a new web application on Amazon EC2 Instances. The company wants to distribute incoming HTTP traffic evenly across all running instances.

Which AWS service or resource will meet this requirement?

Options:

A.

Amazon EC2 Auto Scaling

B.

Application Load Balancer

C.

Gateway Load Balancer

D.

Network Load Balancer

Question 234

What is a benefit of using AWS serverless computing?

Options:

A.

Application deployment and management are not required

B.

Application security will be fully managed by AWS

C.

Monitoring and logging are not needed

D.

Management of infrastructure is offloaded to AWS

Question 235

Which AWS service is a cloud security posture management (CSPM) service that aggregates alerts from various AWS services and partner products in a standardized format?

Options:

A.

AWS Security Hub

B.

AWS Trusted Advisor

C.

Amazon EventBndge

D.

Amazon GuardDuty

Question 236

Which AWS service integrates with other AWS services to provide the ability to encrypt data at rest?

Options:

A.

AWS Key Management Service (AWS KMS)

B.

AWS Certificate Manager (ACM)

C.

AWS Identity and Access Management (1AM)

D.

AWS Security Hub

Question 237

A company needs to create and publish interactive business intelligence dashboards. The dashboards require insights that are powered by machine learning.

Which AWS service or tool will meet these requirements?

Options:

A.

AWS Glue Studio

B.

Amazon QuickSight

C.

Amazon Redshift

D.

Amazon Athena

Question 238

A company hosts its website on Amazon EC2 instances. The company needs to ensure that the website reaches a global audience and provides minimum latency to users.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Route 53

B.

Amazon CloudFront

C.

Elastic Load Balancing

D.

AWS Lambda

Question 239

What is the MOST secure way to store passwords on AWS?

Options:

A.

Store passwords in an Amazon S3 bucket.

B.

Store passwords as AWS CloudFormation parameters

C.

Store passwords in AWS Storage Gateway.

D.

Store passwords in AWS Secrets Manager.

Question 240

A company operates a petabyte-scale data warehouse to analyze its data. The company wants a solution that will not require manual hardware and software management. Which AWS service will meet these requirements?

Options:

A.

Amazon DocumentDB (with MongoDB compatibility)

B.

Amazon Redshift

C.

Amazon Neptune

D.

Amazon ElastiCache

Question 241

A company wants to implement detailed tracking of its cloud costs by department and project.

Which AWS feature or service should the company use?

Options:

A.

Consolidated billing

B.

Cost allocation tags

C.

AWS Marketplace

D.

AWS Budgets

Question 242

A company runs an uninterruptible Amazon EC2 workload on AWS 24 hours a day. 7 days a week. The company will require the same instance family and instance type to run the workload for the next 12 months.

Which combination of purchasing options should the company choose to MOST optimize costs? (Select TWO.)

Options:

A.

Standard Reserved Instance

B.

Convertible Reserved Instance

C.

Compute Savings Plan

D.

Spot Instance

E.

All Upfront payment

Question 243

Which AWS service or resource provides answers to the most frequently askedsecurity-related questions that AWS receives from its users'?

Options:

A.

AWS Artifact

B.

Amazon Connect

C.

AWS Chatbot

D.

AWS Knowledge Center

Question 244

A company wants to run its workload on Amazon EC2 instances for more than 1 year. This workload will run continuously.

Which option offers a discounted hourly rate compared to the hourly rate of On-Demand Instances?

Options:

A.

AWS Graviton processor

B.

Dedicated Hosts

C.

EC2 Instance Savings Plans

D.

Amazon EC2 Auto Scaling instances

Question 245

A company wants to migrate its on_premises workloads to the AWS Cloud. The company wants to separate workloads for chargeback to different departments.

Which AWS services or features will meet these requirements? (Select TWO.)

Options:

A.

Placement groups

B.

Consolidated billing

C.

Edge locations

D.

AWS Config

E.

Multiple AWS accounts

Question 246

Which option is an environment that consists of one or more data centers?

Options:

A.

Amazon CloudFront

B.

Availability Zone

C.

VPC

D.

AWS Outposts

Question 247

A company is building a new application on AWS. The company needs the application to remain available if an individual application component fails.

Which design principle should the company use to meet this requirement?

Options:

A.

Disposable resources

B.

Automation

C.

Rightsizing

D.

Loose coupling

Question 248

Which AWS Cloud design principle is a company using when the company implements AWS CloudTrail?

Options:

A.

Activate traceability.

B.

Use serverless compute architectures.

C.

Perform operations as code.

D.

Go global in minutes.

Question 249

A company needs to convert video files and audio files to a format that will play on smartphones.

Which AWS service will meet this requirement?

Options:

A.

Amazon Comprehend

B.

Amazon Rekognition

C.

Amazon Elastic Transcoder

D.

Amazon Polly

Question 250

Which AWS compute service gives users the ability to securely and reliably run containers at scale?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon Aurora

C.

Amazon Athena

D.

Amazon Polly

Question 251

A company wants to move its on-premises databases to managed cloud database services by using a simplified migration process. Which AWS service or tool can help the company meet this requirement?

Options:

A.

AWS Storage Gateway

B.

AWS Application Migration Service

C.

AWS DataSync

D.

AWS Database Migration Service (AWS DMS)

Question 252

A company wants to discover, prepare, move, and integrate data from multiple sources for data analytics and machine learning.

Which AWS serverless data integration service should the company use to meet these requirements?

Options:

A.

AWS Glue

B.

AWS Data Exchange

C.

Amazon Athena

D.

Amazon EMR

Question 253

A company needs a fully managed file server that natively supports Microsoft workloads and file systems The file server must also support the SMB protocol.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Elastic File System (Amazon EFS)

B.

Amazon FSx for Lustre

C.

Amazon FSx for Windows File Server

D.

Amazon Elastic Block Store (Amazon EBS)

Question 254

A company needs to track the activity in its AWS accounts, and needs to know when an API call is made against its AWS resources. Which AWS tool or service can be used to meet these requirements?

Options:

A.

Amazon CloudWatch

B.

Amazon Inspector

C.

AWS CloudTrail

D.

AWS IAM

Question 255

A company is requesting Payment Card Industry (PCI) reports that validate the operating effectiveness of AWS security controls.

How should the company obtain these reports?

Options:

A.

Contact AWS Support

B.

Download reports from AWS Artifact.

C.

Download reports from AWS Security Hub.

D.

Contact an AWS technical account manager (TAM).

Question 256

A company needs to perform data processing once a week that typically takes about 5 hours to complete. Which AWS service should the company use for this workload?

Options:

A.

AWS Lambda

B.

Amazon EC2

C.

AWS CodeDeploy

D.

AWS Wavelength

Question 257

Which of the following is an AWS Well-Architected Framework design principle for operational excellence in the AWS Cloud?

Options:

A.

Go global in minutes

B.

Make frequent, small, reversible changes

C.

Implement a strong foundation of identity and access management

D.

Stop spending money on hardware infrastructure for data center operations

Question 258

Which AWS service gives users the ability to discover and protect sensitive data that is stored in Amazon S3 buckets?

Options:

A.

Amazon Macie

B.

Amazon Detective

C.

Amazon GuardDuty

D.

AWS I AM Access Analyzer

Question 259

A systems administrator created a new 1AM user for a developer and assigned the user an access key instead of a user name and password. What is the access key used for?

Options:

A.

To access the AWS account as the AWS account root user

B.

To access the AWS account through the AWS Management Console

C.

To access the AWS account through a CLI

D.

To access all of a company's AWS accounts

Question 260

Which AWS service or tool gives a company the ability to release application changes in an automated way?

Options:

A.

Amazon AppFlow

B.

AWS CodeDeploy

C.

AWS PrivateLink

D.

Amazon EKS Distro

Question 261

A company needs a firewall that will control network connections to and from a single Amazon EC2 instance. This firewall will not control network connections to and from other instances that are in the same subnet.

Which AWS service or feature can the company use to meet these requirements?

Options:

A.

Network ACL

B.

AWS WAF

C.

Route table

D.

Security group

Question 262

A company wants to generate a list of IAM users. The company also wants to view the status of various credentials that are associated with the users, such as password, access keys: and multi-factor authentication (MFA) devices

Which AWS service or feature will meet these requirements?

Options:

A.

IAM credential report

B.

AWS IAM Identity Center (AWS Single Sign-On)

C.

AWS Identity and Access Management Access Analyzer

D.

AWS Cost and Usage Report

Question 263

A company is planning to migrate applications to the AWS Cloud. During a system audit, the company finds that its content management system (CMS) application is incompatible with cloud environments.

Which migration strategies will help the company to migrate the CMS application with the LEAST effort? (Select TWO.)

Options:

A.

Retire

B.

Rehost

C.

Repurchase

D.

Replatform

E.

Refactor

Demo: 263 questions
Total 881 questions