Big Black Friday Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Amazon Web Services CLF-C02 Dumps

Page: 1 / 88
Total 877 questions

AWS Certified Cloud Practitioner Questions and Answers

Question 1

Which AWS service or tool gives a company the ability to release application changes in an automated way?

Options:

A.

Amazon AppFlow

B.

AWS CodeDeploy

C.

AWS PrivateLink

D.

Amazon EKS Distro

Question 2

A company wants to deploy a web application as a containerized application. The company wants to use a managed service that can automatically create container images from source code and deploy the containerized application.

Which AWS service will meet these requirements?

Options:

A.

AWS Elastic Beanstalk

B.

Amazon Elastic Container Service (Amazon ECS)

C.

AWS App Runner

D.

Amazon EC2

Question 3

A company is using Amazon DynamoDB for its application database.

Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Classify data.

B.

Configure access permissions.

C.

Manage encryption options.

D.

Provide public endpoints to store and retrieve data.

E.

Manage the infrastructure layer and the operating system.

Question 4

A company wants to migrate to AWS and use the same security software it uses on premises. The security software vendor offers its security software as a service on AWS.

Where can the company purchase the security solution?

Options:

A.

AWS Partner Solutions Finder

B.

AWS Support Center

C.

AWS Management Console

D.

AWS Marketplace

Question 5

A company wants to set up its workloads to perform their intended functions and recover quickly from failure. Which pillar of the AWS Well-Architected Framework aligns with these goals?

Options:

A.

Performance efficiency

B.

Sustainability

C.

Reliability

D.

Security

Question 6

A company Is designing its AWS workloads so that components can be updated regularly and so that changes can be made in small, reversible increments.

Which pillar of the AWS Well-Architected Framework does this design support?

Options:

A.

Security

B.

Performance efficiency

C.

Operational excellence

D.

Reliability

Question 7

A company has a physical tape library to store data backups. The tape library is running out of space. The company needs to extend the tape library's capacity to the AWS Cloud.

Which AWS service should the company use to meet this requirement?

Options:

A.

Amazon Elastic File System (Amazon EFS)

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon S3

D.

AWS Storage Gateway

Question 8

Which AWS service is used to provide encryption for Amazon EBS?

Options:

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS KMS

D.

AWS Config

Question 9

A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify infrastructure deployments that do not meet best practices. Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWSConfig

D.

Amazon GuardDuty

Question 10

Which action is a security best practice for access to sensitive data that is stored in an Amazon S3 bucket?

Options:

A.

Enable S3 Cross-Region Replication (CRR) on the S3 bucket.

B.

Use IAM roles for applications that require access to the S3 bucket.

C.

Configure AWS WAF to prevent unauthorized access to the S3 bucket.

D.

Configure Amazon GuardDuty to prevent unauthorized access to the S3 bucket.

Question 11

Which of the following is a customer responsibility according to the AWS shared responsibility model?

Options:

A.

Apply security patches for Amazon S3 infrastructure devices.

B.

Provide physical security for AWS datacenters.

C.

Install operating system updates on Lambda@Edge.

D.

Implement multi-factor authentication (MFA) for 1AM user accounts.

Question 12

Which AWS feature provides a no-cost platform for AWS users to join community groups, ask questions, find answers, and read community-generated articles about best practices?

Options:

A.

AWS Knowledge Center

B.

AWS re:Post

C.

AWS 10

D.

AWS Enterprise Support

Question 13

A company is requesting Payment Card Industry (PCI) reports that validate the operating effectiveness of AWS security controls.

How should the company obtain these reports?

Options:

A.

Contact AWS Support

B.

Download reports from AWS Artifact.

C.

Download reports from AWS Security Hub.

D.

Contact an AWS technical account manager (TAM).

Question 14

Which AWS service or feature allows users to create new AWS accounts, group multiple accounts to organize workflows, and apply policies to groups of accounts?

Options:

A.

AWS Identity and Access Management (1AM)

B.

AWS Trusted Advisor

C.

AWS CloudFormation

D.

AWS Organizations

Question 15

Which AWS service can be used at no additional cost?

Options:

A.

Amazon SageMaker

B.

AWS Config

C.

AWS Organizations

D.

Amazon CloudWatch

Question 16

Using AWS Identity and Access Management (IAM) to grant access only to the resources needed to perform a task is a concept known as:

Options:

A.

restricted access.

B.

as-needed access.

C.

least privilege access.

D.

token access.

Question 17

Which complimentary AWS service or tool creates data-driven business cases for cloud planning?

Options:

A.

Migration Evaluator

B.

AWS Billing Conductor

C.

AWS Billing Console

D.

Amazon Forecast

Question 18

A company needs to block SQL injection attacks.

Which AWS service or feature can meet this requirement?

Options:

A.

AWS WAF

B.

AWS Shield

C.

Network ACLs

D.

Security groups

Question 19

Which tasks are responsibilities of the customer, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Secure the virilization layer.

B.

Encrypt data and maintain data integrity.

C.

Patch the Amazon RDS operating system.

D.

Maintain identity and access management controls.

E.

Secure Availability Zones.

Question 20

A company wants to establish a private network connection between AWS and its corporate network.

Which AWS service or feature will meet this requirement?

Options:

A.

Amazon Connect

B.

Amazon Route 53

C.

AWS Direct Connect

D.

VPC peering

Question 21

Which AWS Support plans provide access to an AWS technical account manager (TAM)? (Select)

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise On-Ramp Support

E.

AWS Enterprise Support

Question 22

A company has a set of ecommerce applications. The applications need to be able to send messages to each other. Which AWS service meets this requirement?

Options:

A.

AWS Auto Scaling

B.

Elastic Load Balancing

C.

Amazon Simple Queue Service (Amazon SOS)

D.

Amazon Kinesis Data Streams

Question 23

Which top-level key performance indicator (KPI) is available in AWS rightsizing recommendations of Cost Optimization?

Options:

A.

Container modernization opportunities

B.

Estimated monthly saving

C.

Reserved instances savings

D.

Compute savings recommendations

Question 24

Which AWS service can a company use to visually design and build serverless applications?

Options:

A.

AWS Lambda

B.

AWS Batch

C.

AWS Application Composer

D.

AWS App Runner

Question 25

Which fully managed AWS service assists with the creation, testing, and management of custom Amazon EC? images?

Options:

A.

EC2 Image Builder

B.

Amazon Machine Image (AMI)

C.

AWS Launch Wizard

D.

AWS Elastic Beanstalk

Question 26

A company is planning to migrate applications to the AWS Cloud. During a system audit, the company finds that its content management system (CMS) application is incompatible with cloud environments.

Which migration strategies will help the company to migrate the CMS application with the LEAST effort? (Select TWO.)

Options:

A.

Retire

B.

Rehost

C.

Repurchase

D.

Replatform

E.

Refactor

Question 27

A company has deployed an Amazon EC2 instance.

Which option is an AWS responsibility under the AWS shared responsibility model?

Options:

A.

Managing and encrypting application data

B.

Installing updates and security patches of guest operating system

C.

Configuration of infrastructure devices

D.

Configuration of security groups on each instance

Question 28

Which task is the customer's responsibility, according to the AWS shared responsibility model?

Options:

A.

Patch a guest operating system that is deployed on an Amazon EC2 instance.

B.

Control physical access to an AWS data center

C.

Control access to AWS underlying hardware.

D.

Patch a host operating system that is deployed on Amazon S3.

Question 29

Which guidelines are best practices for using AWS Identity and Access Management (1AM)? (Select TWO.)

Options:

A.

Share access keys.

B.

Create individual 1AM users.

C.

Use inline policies instead of customer managed policies.

D.

Grant maximum privileges to 1AM users.

E.

Use groups to assign permissions to 1AM users.

Question 30

A company wants to migrate its PostgreSQL database to AWS. The company does not use the database frequently.

Which AWS service or resource will meet these requirements with the LEAST management overhead?

Options:

A.

PostgreSQL on Amazon EC2

B.

Amazon RDS for PostgreSQL

C.

Amazon Aurora PostgreSQL-Compatible Edition

D.

Amazon Aurora Serverless

Question 31

Which AWS service integrates with other AWS services to provide the ability to encrypt data at rest?

Options:

A.

AWS Key Management Service (AWS KMS)

B.

AWS Certificate Manager (ACM)

C.

AWS Identity and Access Management (1AM)

D.

AWS Security Hub

Question 32

What is a benefit of using AWS serverless computing?

Options:

A.

Application deployment and management are not required

B.

Application security will be fully managed by AWS

C.

Monitoring and logging are not needed

D.

Management of infrastructure is offloaded to AWS

Question 33

What is the recommended use case for Amazon EC2 On-Demand Instances?

Options:

A.

A steady-state workload that requires a particular EC2 instance configuration for a long period of time

B.

A workload that can be interrupted for a project that requires the lowest possible cost

C.

An unpredictable workload that does not require a long-term commitment

D.

A workload that is expected to run for longer than 1 year

Question 34

Which AWS service or feature gives users the ability to capture information about network traffic in a VPC?

Options:

A.

VPC Flow Logs

B.

Amazon Inspector

C.

VPC route tables

D.

AWS CloudTrail

Question 35

A company is using AWS for all its IT Infrastructure. The company's developers are allowed to deploy applications on their own. The developers want to deploy their applications without having to provision the infrastructure themselves.

Which AWS service should the developers use to meet these requirements?

Options:

A.

AWS Cloud Formation

B.

AWS CodeBuild

C.

AWS Elastic Beanstalk

D.

AWS CodeDeploy

Question 36

A company has deployed a web application to Amazon EC2 instances. The EC2 instances have low usage. Which AWS service or feature should lite company use in rightsized the FC? instances?

Options:

A.

AWS Config

B.

AWS Cost Anomaly Detection

C.

AWS Budgets

D.

AWS Compute Optimizer

Question 37

Which characteristic of the AWS Cloud helps users eliminate underutilized CPU capacity'?

Options:

A.

Agility

B.

Elasticity

C.

Reliability

D.

Durability

Question 38

Which AWS Cloud Adoption Framework (AWS CAF) perspective focuses on real-time insights and answers questions about strategy?

Options:

A.

Operations

B.

People

C.

Business

D.

Platform

Question 39

A company is building a new application on AWS. The company needs the application to remain available if an individual application component fails.

Which design principle should the company use to meet this requirement?

Options:

A.

Disposable resources

B.

Automation

C.

Rightsizing

D.

Loose coupling

Question 40

Which benefits does a company gain when the company moves from on-premises IT architecture to the AWS Cloud? (Select TWO.)

Options:

A.

Reduced or eliminated tasks for hardware troubleshooting, capacity planning, and procurement

B.

Elimination of the need for trained IT staff

C.

Automatic security configuration of all applications that are migrated to the cloud

D.

Elimination of the need for disaster recovery planning

E.

Faster deployment of new features and applications

Question 41

Which of the following is an AWS Well-Architected Framework design principle for operational excellence in the AWS Cloud?

Options:

A.

Go global in minutes

B.

Make frequent, small, reversible changes

C.

Implement a strong foundation of identity and access management

D.

Stop spending money on hardware infrastructure for data center operations

Question 42

A company has a workload that will run continuously for 1 year. The workload cannot tolerate service interruptions.

Which Amazon EC2 purchasing option will be MOST cost-effective?

Options:

A.

All Upfront Reserved Instances

B.

Partial Upfront Reserved Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 43

Which of the following services can be used to block network traffic to an instance? (Select TWO.)

Options:

A.

Security groups

B.

Amazon Virtual Private Cloud (Amazon VPC) flow logs

C.

Network ACLs

D.

Amazon CloudWatch

E.

AWS CloudTrail

Question 44

An independent software vendor wants to deliver and share its custom Amazon Machine images (AMIs) to prospective customers.

Which AWS service will meet these requirements?

Options:

A.

AWS Marketplace

B.

AWS Data Exchange

C.

Amazon EC2

D.

AWS Organizations

Question 45

An ecommerce company has deployed a new web application on Amazon EC2 Instances. The company wants to distribute incoming HTTP traffic evenly across all running instances.

Which AWS service or resource will meet this requirement?

Options:

A.

Amazon EC2 Auto Scaling

B.

Application Load Balancer

C.

Gateway Load Balancer

D.

Network Load Balancer

Question 46

A user has been granted permission to change their own IAM user password.

Which AWS services can the user use to change the password? (Select TWO.)

Options:

A.

AWS Command Line Interface (AWS CLI)

B.

AWS Key Management Service (AWS KMS)

C.

AWS Management Console

D.

AWS Resource Access Manager (AWS RAM)

E.

AWS Secrets Manager

Question 47

Which AWS resource can help a company reduce Its costs in exchange for a usage commitment when using Amazon EC2 instances?

Options:

A.

Compute Savings Plans

B.

Auto Stalling group

C.

On-Demand Instance

D.

EC2 instance store

Question 48

In which situations should a company create an 1AM user instead of an 1AM role? (Select TWO.)

Options:

A.

When an application that runs on Amazon EC2 instances requires access to other AWS services

B.

When the company creates AWS access credentials for individuals

C.

When the company creates an application that runs on a mobile phone that makes requests to AWS

D.

When the company needs to add users to 1AM groups

E.

When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time

Question 49

Which AWS service or feature improves network performance by sending traffic through the AWS worldwide network infrastructure?

Options:

A.

Route table

B.

AWS Transit Gateway

C.

AWS Global Accelerator

D.

Amazon VPC

Question 50

Which AWS service or tool can be used to set up a firewall to control traffic going into and coming out of an Amazon VPC subnet?

Options:

A.

Security group

B.

AWS WAF

C.

AWS Firewall Manager

D.

Network ACL

Question 51

Which of the following is a managed AWS service that is used specifically for extract, transform, and load (ETL) data?

Options:

A.

Amazon Athena

B.

AWS Glue

C.

Amazon S3

D.

AWS Snowball Edge

Question 52

Which AWS service or feature provides a firewall at the subnet level within a VPC?

Options:

A.

Security group

B.

Network ACL

C.

Elastic network interface

D.

AWS WAF

Question 53

A company plans to launch an ecommerce website that contains many images for a product catalog. The company wants to keep the cost of running the website within a specific budget.

Which AWS service or tool should the company use to monitor the ongoing costs of the website?

Options:

A.

AWS Cost Explorer

B.

AWS SDKs

C.

EC2 Image Builder

D.

AWS CloudFormation

Question 54

A company has batch workloads that need to run for short periods of time on Amazon EC2. The workloads can handle interruptions and can start again from where they ended.

What is the MOST cost-effective EC2 instance purchasing option to meet these requirements?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

Dedicated Instances

D.

On-Demand Instances

Question 55

Which responsibility belongs to AWS when a company hosts its databases on Amazon EC2 instances?

Options:

A.

Database backups

B.

Database software patches

C.

Operating system patches

D.

Operating system installations

Question 56

A company wants to generate a list of IAM users. The company also wants to view the status of various credentials that are associated with the users, such as password, access keys: and multi-factor authentication (MFA) devices

Which AWS service or feature will meet these requirements?

Options:

A.

IAM credential report

B.

AWS IAM Identity Center (AWS Single Sign-On)

C.

AWS Identity and Access Management Access Analyzer

D.

AWS Cost and Usage Report

Question 57

A company migrated its systems to the AWS Cloud. The systems are rightsized, and a security review did not reveal any issues. The company must ensure that additional developments, integrations, changes, and system usage growth do not jeopardize this optimized AWS infrastructure.

Which AWS service should the company use to report ongoing optimization and security?

Options:

A.

AWS Trusted Advisor

B.

AWS Health Dashboard

C.

Amazon Connect

D.

AWS Systems Manager

Question 58

A company wants to migrate its on-premises infrastructure to the AWS Cloud.

Which advantage of cloud computing will help the company reduce upfront costs?

Options:

A.

Go global in minutes

B.

Increase speed and agility

C.

Benefit from massive economies of scale

D.

Trade fixed expense for variable expense

Question 59

A company wants to manage its cloud resources by using infrastructure as code (laC) template…..

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Artifact

B.

AWS Resource Explorer

C.

AWS License Manager

D.

AWS Service Catalog

Question 60

Which of the following is an advantage that the AWS Cloud provides to users?

Options:

A.

Users eliminate the need to guess about infrastructure capacity requirements.

B.

Users decrease their variable costs by maintaining sole ownership of IT hardware.

C.

Users maintain control of underlying IT infrastructure hardware.

D.

Users maintain control of operating systems for managed services.

Question 61

Which AWS Cloud deployment model uses AWS Outposts as part of the application deployment infrastructure?

Options:

A.

On-premises

B.

Serverless

C.

Cloud-native

D.

Hybrid

Question 62

Which mechanism allows developers to access AWS services from application code?

Options:

A.

AWS Software Development Kit

B.

AWS Management Console

C.

AWS CodePipeline

D.

AWS Config

Question 63

Which cloud computing advantage is a company applying when it uses AWS Regions to increase application availability to users in different countries?

Options:

A.

Pay-as-you-go pricing

B.

Capacity forecasting

C.

Economies of scale

D.

Global reach

Question 64

Which AWS services or features give users the ability to create a network connection between two VPCs? (Select TWO.)

Options:

A.

VPC endpoints

B.

Amazon Route 53

C.

VPC peering

D.

AWS Direct Connect

E.

AWS Transit Gateway

Question 65

Which tool should a developer use lo integrate AWS service features directly into an application?

Options:

A.

AWS Software Development Kit

B.

AWS CodeDeploy

C.

AWS Lambda

D.

AWS Batch

Question 66

What is the best resource for a user to find compliance-related information and reports about AWS?

Options:

A.

AWS Artifact

B.

AWS Marketplace

C.

Amazon Inspector

D.

Increase operational costs across data centers.

Question 67

Which AWS service is always free of charge for users?

Options:

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

AWS Identity and Access Management (IAM)

Question 68

Which of the following are customer responsibilities under the AWS shared responsibility model? (Select TWO.)

Options:

A.

Physical security of AWS facilities

B.

Configuration of security groupsQ C. Encryption of customer data on AWS

C.

Management of AWS Lambda infrastructureQ E. Management of network throughput of each AWS Region

Question 69

A company wants to create multiple isolated networks in the same AWS account.

Which AWS service or component will provide this functionality?

Options:

A.

AWS Transit Gateway

B.

Internet gateway

C.

Amazon VPC

D.

Amazon EC2

Question 70

A company needs to run code in response to an event notification that occurs when objects are uploaded to an Amazon S3 bucket.

Which AWS service will integrate directly with the event notification?

Options:

A.

AWS Lambda

B.

Amazon EC2

C.

Amazon Elastic Container Registry (Amazon ECR)

D.

AWS Elastic Beanstalk

Question 71

A company is configuring its AWS Cloud environment. The company's administrators need to group users together and apply permissions to the group.

Which AWS service or feature can the company use to meet these requirements?

Options:

A.

AWS Organizations

B.

Resource groups

C.

Resource tagging

D.

AWS Identity and Access Management (IAM)

Question 72

A company needs help managing multiple AWS linked accounts that are reported on a consolidated bill.

Which AWS Support plan includes an AWS concierge whom the company can ask for assistance?

Options:

A.

AWS Developer Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Basic Support

Question 73

A company has an environment that includes Amazon EC2 instances, Amazon Lightsail, and on-premises servers. The company wants to automate the security updates for its operating systems and applications.

Which solution will meet these requirements with the LEAST operational effort?

Options:

A.

Use AWS Shield to identify and manage security events.

B.

Connect to each server by using a remote desktop connection. Run an update script.

C.

Use the AWS Systems Manager Patch Manager capability.

D.

Schedule Amazon GuardDuty to run on a nightly basis.

Question 74

Which of the following is a benefit of decoupling an AWS Cloud architecture?

Options:

A.

Reduced latency

B.

Ability to upgrade components independently

C.

Decreased costs

D.

Fewer components to manage

Question 75

A company suspects that its AWS resources are being used for illegal activities.

Which AWS group or team should the company notify?

Options:

A.

AWS Abuse team

B.

AWS Support team

C.

AWS technical account managers

D.

AWS Professional Services team

Question 76

Which AWS service provides highly durable object storage?

Options:

A.

Amazon S3

B.

Amazon Elastic File System (Amazon EFS)

C.

Amazon Elastic Block Store (Amazon EBS)

D.

Amazon FSx

Question 77

A company wants to access a report about the estimated environmental impact of the company's AWS usage.

Which AWS service or feature should the company use to meet this requirement?

Options:

A.

AWS Organizations

B.

IAM policy

C.

AWS Billing console

D.

Amazon Simple Notification Service (Amazon SNS)

Question 78

Which of the following are components of an AWS Site-to-Site VPN connection? (Select TWO.)

Options:

A.

AWS Storage Gateway

B.

Virtual private gateway

C.

NAT gateway

D.

Customer gateway

E.

Internet gateway

Question 79

A company is using a third-party service to back up 10 TB of data to a tape library. The on-premises backup server is running out of space. The company wants to use AWS services for the backups without changing its existing

backup workflows.

Which AWS service should the company use to meet these requirements?

Options:

A.

Amazon Elastic Block Store (Amazon EBS)

B.

AWS Storage Gateway

C.

Amazon Elastic Container Service (Amazon ECS)

D.

AWS Lambda

Question 80

A company wants to securely store Amazon RDS database credentials and automatically rotate user passwords periodically.

Which AWS service or capability will meet these requirements?

Options:

A.

Amazon S3

B.

AWS Systems Manager Parameter Store

C.

AWS Secrets Manager

D.

AWS CloudTrail

Question 81

A company moves its infrastructure from on premises to the AWS Cloud. The company can now provision additional Amazon EC2 instances whenever the instances are required. With this ability, the company can launch new marketing campaigns in 3 days instead of 3 weeks.

Which benefit of the AWS Cloud does this scenario demonstrate?

Options:

A.

Cost savings

B.

Improved operational resilience

C.

Increased business agility

D.

Enhanced security

Question 82

What does "security of the cloud" refer to in the AWS shared responsibility model?

Options:

A.

Availability of AWS services such as Amazon EC2

B.

Security of the cloud infrastructure that runs all the AWS services

C.

Implementation of password policies for IAM users

D.

Security of customer environments by using AWS Network Firewall partners

Question 83

A user wants to identify any security group that is allowing unrestricted incoming SSH traffic.

Which AWS service can be used to accomplish this goal?

Options:

A.

Amazon Cognito

B.

AWS Shield

C.

Amazon Macie

D.

AWS Trusted Advisor

Question 84

Which AWS service or tool does AWS Control Tower use to create resources?

Options:

A.

AWS CloudFormation

B.

AWS Trusted Advisor

C.

AWS Directory Service

D.

AWS Cost Explorer

Question 85

What are the characteristics of Availability Zones? (Select TWO.)

Options:

A.

All Availability Zones in an AWS Region are interconnected with high-bandwidth, low-latency networking

B.

Availability Zones are physically separated by a minimum of distance of 150 km (100 miles).

C.

All traffic between Availability Zones is encrypted.

D.

Availability Zones within an AWS Region share redundant power, networking, and connectivity.

E.

Every Availability Zone contains a single data center.

Question 86

Which AWS service can defend against DDoS attacks?

Options:

A.

AWS Firewall Manager

B.

AWS Shield Standard

C.

AWS WAF

D.

Amazon Inspector

Question 87

Which of the following is available to a company that has an AWS Business Support plan?

Options:

A.

AWS Support concierge

B.

AWS DDoS Response Team (DRT)

C.

AWS technical account manager (TAM)

D.

AWS Health API

Question 88

What are some advantages of using Amazon EC2 instances lo host applications in the AWS Cloud instead of on premises? (Select TWO.)

Options:

A.

EC2 includes operating system patch management

B.

EC2 integrates with Amazon VPC. AWS CloudTrail, and AWS Identity and Access Management (IAM)

C.

EC2 has a 100% service level agreement (SLA).

D.

EC2 has a flexible, pay-as-you-go pricing model.

E.

EC2 has automatic storage cost optimization.

Question 89

A company wants to migrate its applications to the AWS Cloud. The company plans to identify and prioritize any business transformation opportunities and evaluate its AWS Cloud readiness.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

AWS Cloud Adoption Framework (AWS CAF)

B.

AWS Managed Services (AMS)

C.

AWS Well-Architected Framework

D.

AWS Migration Hub

Question 90

Which AWS Well-Architected Framework concept represents a system's ability to remain functional when the system encounters operational problems?

Options:

A.

Consistency

B.

Elasticity

C.

Durability

D.

Latency

Question 91

A company has an application with robust hardware requirements. The application must be accessed by students who are using lightweight, low-cost laptops.

Which AWS service will help the company deploy the application without investing in backend infrastructure or high end client hardware?

Options:

A.

Amazon AppStream 2.0

B.

AWS AppSync

C.

Amazon WorkLink

D.

AWS Elastic Beanstalk

Question 92

A company wants to move its data warehouse application to the AWS Cloud. The company wants to run and scale its analytics services without needing to provision and manage data warehouse clusters.

Which AWS service will meet these requirements?

Options:

A.

Amazon Redshift provisioned data warehouse

B.

Amazon Redshift Serverless

C.

Amazon Athena

D.

Amazon S3

Question 93

Which task requires the use of AWS account root user credentials?

Options:

A.

The deletion of IAM users

B.

The change to a different AWS Support plan

C.

The creation of an organization in AWS Organizations

D.

The deletion of Amazon EC2 instances

Question 94

A company runs a database on Amazon Aurora in the us-east-1 Region. The company has a disaster recovery requirement that the database be available in another Region.

Which solution meets this requirement with minimal disruption to the database operations?

Options:

A.

Perform an Aurora Multi-AZ deployment.

B.

Deploy Aurora cross-Region read replicas.

C.

Create Amazon Elastic Block Store (Amazon EBS) volume snapshots for Aurora and copy them to another Region.

D.

Deploy Aurora Replicas.

Question 95

A company needs to use standard SQL to query and combine exabytes of structured and semi-structured data across a data warehouse, operational database, and data lake.

Which AWS service meets these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon Athena

D.

Amazon Redshift

Question 96

Which controls are the responsibility of both AWS and AWS customers, according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Physical and environmental controls

B.

Patch management

C.

Configuration management

D.

Account structures

E.

Choice of the AWS Region where data is stored

Question 97

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

Options:

A.

Sustainability

B.

Operations

C.

Performance efficiency

D.

Reliability

Question 98

Which duties are the responsibility of a company that is using AWS Lambda? (Select TWO.)

Options:

A.

Security inside of code

B.

Selection of CPU resources

C.

Patching of operating system

D.

Writing and updating of code

E.

Security of underlying infrastructure

Question 99

Which pillar of the AWS Well-Architected Framework focuses on the return on investment of moving into the AWS Cloud?

Options:

A.

Sustainability

B.

Cost optimization

C.

Operational excellence

D.

Reliability

Question 100

A newly created IAM user has no IAM policy attached.

What will happen when the user logs in and attempts to view the AWS resources in the account?

Options:

A.

All AWS services will be read-only access by default.

B.

Access to all AWS resources will be denied.

C.

Access to the AWS billing services will be allowed.

D.

Access to AWS resources will be allowed through the AWS CLL

Question 101

Which AWS service or feature is used to Troubleshoot network connectivity issues between Amazon EC2 instances?

Options:

A.

AWS Certificate Manager (ACM)

B.

Internet gateway

C.

VPC Flow Logs

D.

AWS CloudHSM

Question 102

According to the AWS shared responsibility model, which of the following are AWS responsibilities? (Select TWO.)

Options:

A.

Network infrastructure and virtualization of infrastructure

B.

Security of application data

C.

Guest operating systems

D.

Physical security of hardware

E.

Credentials and policies

Question 103

Which of the following are user authentication services managed by AWS? (Select TWO.)

Options:

A.

Amazon Cognito

B.

AWS Lambda

C.

AWS License Manager

D.

AWS Identity and Access Management (IAM)

E.

AWS CodeStar

Question 104

A company needs to host a web server on Amazon EC2 instances for at least 1 year. The web server cannot tolerate interruption.

Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

Options:

A.

On-Demand Instances

B.

Partial Upfront Reserved Instances

C.

Spot Instances

D.

No Upfront Reserved Instances

Question 105

Which AWS service provides the ability to host a NoSQL database in the AWS Cloud?

Options:

A.

Amazon Aurora

B.

Amazon DynamoDB

C.

Amazon RDS

D.

Amazon Redshift

Question 106

An application runs on multiple Amazon EC2 instances that access a shared file system simultaneously.

Which AWS storage service should be used?

Options:

A.

Amazon EBS

B.

Amazon EFS

C.

Amazon S3

D.

AWS Artifact

Question 107

A company wants to migrate its on-premises data warehouse to AWS. The information in the data warehouse is

used to populate analytics dashboards.

Which AWS service should the company use for the data warehouse?

Options:

A.

Amazon ElastiCache

B.

Amazon Aurora

C.

Amazon RDS

D.

Amazon Redshift

Question 108

A company provides a software as a service (SaaS) application. The company has a new customer that is based in a different country.

The new customer's data needs to be hosted in that country.

Which AWS service or infrastructure component should the company use to meet this requirement?

Options:

A.

AWS Shield

B.

Amazon S3 Object Lock

C.

AWS Regions

D.

Placement groups

Question 109

A company needs to centralize its operational data. The company also needs to automate tasks across all of its Amazon EC2 instances.

Which AWS service can the company use to meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

AWS Systems Manager

C.

AWS CodeDeploy

D.

AWS Elastic Beanstalk

Question 110

A company wants to ensure that two Amazon EC2 instances are in separate data centers with minimal

communication latency between the data centers.

How can the company meet this requirement?

Options:

A.

Place the EC2 instances in two separate AWS Regions connected with a VPC peering connection.

B.

Place the EC2 instances in two separate Availability Zones within the same AWS Region.

C.

Place one EC2 instance on premises and the other in an AWS Region. Then connect them by using anAWS VPN connection.

D.

Place both EC2 instances in a placement group for dedicated bandwidth.

Question 111

Which design principles should a company apply to AWS Cloud workloads to maximize sustainability and minimize environmental impact? (Select TWO.)

Options:

A.

Maximize utilization of Amazon EC2 instances.

B.

Minimize utilization of Amazon EC2 instances.

C.

Minimize usage of managed services.

D.

Force frequent application reinstallations by users.

E.

Reduce the need for users to reinstall applications.

Question 112

A developer wants to use an Amazon S3 bucket to store application logs that contain sensitive data.

Which AWS service or feature should the developer use to restrict read and write access to the S3 bucket?

Options:

A.

Security groups

B.

Amazon CloudWatch

C.

AWS CloudTrail

D.

ACLs

Question 113

What is a benefit of moving to the AWS Cloud in terms of improving time to market?

Options:

A.

Decreased deployment speed

B.

Increased application security

C.

Increased business agility

D.

Increased backup capabilities

Question 114

A company wants to migrate its Microsoft SQL Server database management system from on premises to the AWS Cloud.

Which AWS service should the company use to reduce management overhead for this environment?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

Amazon SageMaker

C.

Amazon RDS

D.

Amazon Athena

Question 115

Which AWS service or feature offers HTTP attack protection to users running public-facing web applications?

Options:

A.

Security groups

B.

Network ACLs

C.

AWS Shield Standard

D.

AWS WAF

Question 116

Which AWS service gives users the ability to provision a dedicated and private network connection from their internal

network to AWS?

Options:

A.

AWS CloudHSM

B.

AWS Direct Connect

C.

AWS VPN

D.

Amazon Connect

Question 117

Which AWS Support plan assigns an AWS concierge agent to a company's account?

Options:

A.

AWS Basic Support

B.

AWS Developer Support

C.

AWS Business Support

D.

AWS Enterprise Support

Question 118

A company has two AWS accounts in an organization in AWS Organizations for consolidated billing. All of the company's AWS resources are hosted in one AWS Region.

Account A has purchased five Amazon EC2 Standard Reserved Instances (RIs) and has four EC2 instances

running. Account B has not purchased any RIs and also has four EC2 instances running.

Which statement is true regarding pricing for these eight instances?

Options:

A.

The eight instances will be charged as regular instances.

B.

Four instances will be charged as RIs, and four will be charged as regular instances.

C.

Five instances will be charged as RIs, and three will be charged as regular instances.

D.

The eight instances will be charged as RIs.

Question 119

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

Options:

A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Question 120

Which benefit of AWS Cloud computing provides lower latency between users and applications?

Options:

A.

Agility

B.

Economies of scale

C.

Global reach

D.

Pay-as-you-go pricing

Question 121

Which of the following are benefits that a company receives when it moves an on-premises production workload to AWS? (Select TWO.)

Options:

A.

AWS trains the company's staff on the use of all the AWS services.

B.

AWS manages all security in the cloud.

C.

AWS offers free support from technical account managers (TAMs).

D.

AWS offers high availability.

E.

AWS provides economies of scale.

Question 122

A company is running an order processing system on Amazon EC2 instances. The company wants to migrate microservices-based application.

Which combination of AWS services can the application use to meet these requirements? (Select TWO.)

Options:

A.

Amazon Simple Queue Service (Amazon SQS)

B.

AWS Lambda

C.

AWS Migration Hub

D.

AWS AppSync

E.

AWS Application Migration Service

Question 123

Which AWS service is a key-value database that provides sub-millisecond latency on a large scale?

Options:

A.

Amazon DynamoDB

B.

Amazon Aurora

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon Neptune

Question 124

Which design principle is included in the operational excellence pillar of the AWS Well-Architected Framework?

Options:

A.

Create annotated documentation.

B.

Anticipate failure.

C.

Ensure performance efficiency.

D.

Optimize costs.

Question 125

Which tasks are the responsibility of AWS according to the AWS shared responsibility model? (Select TWO.)

Options:

A.

Configure AWS Identity and Access Management (IAM).

B.

Configure security groups on Amazon EC2 instances.

C.

Secure the access of physical AWS facilities.

D.

Patch applications that run on Amazon EC2 instances.

E.

Perform infrastructure patching and maintenance.

Question 126

A company recently migrated to the AWS Cloud. The company needs to determine whether its newly imported Amazon EC2 instances are the appropriate size and type.

Which AWS services can provide this information to the company? {Select TWO.)

Options:

A.

AWS Auto Scaling

B.

AWS Control Tower

C.

AWS Trusted Advisor

D.

AWS Compute Optimizer

E.

Amazon Forecast

Question 127

A company deploys its application to multiple AWS Regions and configures automatic failover between those Regions.

Which cloud concept does this architecture represent?

Options:

A.

Security

B.

Reliability

C.

Scalability

D.

Cost optimization

Question 128

Which AWS features will meet these requirements? (Select TWO.)

Options:

A.

Security groups

B.

Network ACLs

C.

S3 bucket policies

D.

IAM user policies

E.

S3 bucket versioning

Question 129

Which AWS service or tool helps to centrally manage billing and allow controlled access to resources across AWS accounts?

Options:

A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Cost Explorer

D.

AWS Budgets

Question 130

Using Amazon Elastic Container Service (Amazon ECS) to break down a monolithic architecture into microservices is an example of:

Options:

A.

a loosely coupled architecture.

B.

a tightly coupled architecture.

C.

a stateless architecture.

D.

a stateful architecture.

Question 131

A company is preparing to launch a redesigned website on AWS. Users from around the world will download digital handbooks from the website.

Which AWS solution should the company use to provide these static files securely?

Options:

A.

Amazon Kinesis Data Streams

B.

Amazon CloudFront with Amazon S3

C.

Amazon EC2 instances with an Application Load Balancer

D.

Amazon Elastic File System (Amazon EFS)

Question 132

Which options are common stakeholders for the AWS Cloud Adoption Framework (AWS CAF) platform perspective? (Select TWO.)

Options:

A.

Chief financial officers (CFOs)

B.

IT architects

C.

Chief information officers (CIOs)

D.

Chief data officers (CDOs)

E.

Engineers

Question 133

Which AWS service provides this functionality?

Options:

A.

AWS IAM Identity Center (AWS Single Sign-On)

B.

AWS Systems Manager

C.

AWS Config

D.

AWS Control Tower

Question 134

An ecommerce company wants to distribute traffic between the Amazon EC2 instances that host its website.

Which AWS service or resource will meet these requirements?

Options:

A.

Application Load Balancer

B.

AWS WAF

C.

AWS CloudHSM

D.

AWS Direct Connect

Question 135

A company wants to grant users in one AWS account access to resources in another AWS account. The users do not currently have permission to access the resources.

Which AWS service will meet this requirement?

Options:

A.

IAM group

B.

IAM role

C.

IAM tag

D.

IAM Access Analyzer

Question 136

Which AWS service provides storage that can be mounted across multiple Amazon EC2 instances?

Options:

A.

Amazon Workspaces

B.

Amazon Elastic File System (Amazon EFS)

C.

AWS Database Migration Service (AWS DMS)

D.

AWS Snowball Edge

Question 137

A company wants a customized assessment of its current on-premises environment. The company wants to understand its projected running costs in the AWS Cloud.

Which AWS service or tool will meet these requirements?

Options:

A.

AWS Trusted Advisor

B.

Amazon Inspector

C.

AWS Control Tower

D.

Migration Evaluator

Question 138

For which AWS service is the customer responsible for maintaining the underlying operating system?

Options:

A.

Amazon DynamoDB

B.

Amazon S3

C.

Amazon EC2

D.

AWS Lambda

Question 139

Which of the following is a benefit that AWS Professional Services provides?

Options:

A.

Management of the ongoing security of user data

B.

Advisory solutions for AWS adoption

C.

Technical support 24 hours a day, 7 days a week

D.

Monitoring of monthly billing costs in AWS accounts

Question 140

A company has teams that have different job roles and responsibilities. The company's employees often change teams. The company needs to manage permissions for the employees so that the permissions are appropriate for the job responsibilities.

Which IAM resource should the company use to meet this requirement with the LEAST operational overhead?

Options:

A.

IAM user groups

B.

IAM roles

C.

IAM instance profiles

D.

IAM policies for individual users

Question 141

A company is considering migration to the AWS Cloud. The company wants a fully managed service or feature that can transfer streaming data from multiple sources to an Amazon S3 bucket.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

AWS DataSync

B.

Amazon Kinesis Data Firehose

C.

S3 Select

D.

AWS Transfer Family

Question 142

A company is operating several factories where it builds products. The company needs the ability to process data, store data, and run applications with local system interdependencies that require low latency.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS loT Greengrass

B.

AWS Lambda

C.

AWS Outposts

D.

AWS Snowball Edge

Question 143

A company wants to launch multiple workloads on AWS. Each workload is related to a different business unit. The company wants to separate and track costs for each business unit.

Which solution will meet these requirements with the LEAST operational overhead?

Options:

A.

Use AWS Organizations and create one account for each business unit.

B.

Use a spreadsheet to control the owners and cost of each resource.

C.

Use an Amazon DynamoDB table to record costs for each business unit.

D.

Use the AWS Billing console to assign owners to resources and track costs.

Question 144

A company wants to define a central data protection policy that works across AWS services for compute, storage, and database resources.

Which AWS service will meet this requirement?

Options:

A.

AWS Batch

B.

AWS Elastic Disaster Recovery

C.

AWS Backup

D.

Amazon FSx

Question 145

Which VPC component provides a layer of security at the subnet level?

Options:

A.

Security groups

B.

Network ACLs

C.

NAT gateways

D.

Route tables

Question 146

A company plans to migrate to the AWS Cloud. The company wants to use the AWS Cloud Adoption Framework (AWS CAF) to define and track business outcomes as part of its cloud transformation journey.

Which AWS CAF governance perspective capability will meet these requirements?

Options:

A.

Benefits management

B.

Risk management

C.

Application portfolio management

D.

Cloud financial management

Question 147

A company wants to design a reliable web application that is hosted on Amazon EC2.

Which approach will achieve this goal?

Options:

A.

Launch large EC2 instances in the same Availability Zone.

B.

Spread EC2 instances across more than one security group.

C.

Spread EC2 instances across more than one Availability Zone.

D.

Use an Amazon Machine Image (AMI) from AWS Marketplace.

Question 148

A company has a MySQL database running on a single Amazon EC2 instance. The company now requires higher availability in the event of an outage.

Which set of tasks would meet this requirement?

Options:

A.

Add an Application Load Balancer in front of the EC2 instance.

B.

Configure EC2 Auto Recovery to move the instance to another Availability Zone.

C.

Migrate to Amazon RDS and enable Multi-AZ.

D.

Enable termination protection for the EC2 instance to avoid outages.

Question 149

A company needs to run a workload for several batch image rendering applications. It is acceptable for the workload to experience downtime.

Which Amazon EC2 pricing model would be MOST cost-effective in this situation?

Options:

A.

On-Demand Instances

B.

Reserved Instances

C.

Dedicated Instances

D.

Spot Instances

Question 150

Which of the following actions are controlled with AWS Identity and Access Management (IAM)? (Select TWO.)

Options:

A.

Control access to AWS service APIs and to other specific resources.

B.

Provide intelligent threat detection and continuous monitoring.

C.

Protect the AWS environment using multi-factor authentication (MFA).

D.

Grant users access to AWS data centers.

E.

Provide firewall protection for applications from common web attacks.

Question 151

A company wants a key-value NoSQL database that is fully managed and serverless.

Which AWS service will meet these requirements?

Options:

A.

Amazon DynamoDB

B.

Amazon RDS

C.

Amazon Aurora

D.

Amazon Memory DB for Redis

Question 152

A company needs to control inbound and outbound traffic for an Amazon EC2 instance.

Which AWS service or feature can the company associate with the EC2 instance to meet this requirement?

Options:

A.

Network ACL

B.

Security group

C.

AWS WAF

D.

VPC route tables

Question 153

A company is planning to migrate to the AWS Cloud and wants to become more responsive to customer inquiries and feedback. The company wants to focus on organizational transformation.

A company wants to give its customers the ability to view specific data that is hosted in Amazon S3 buckets. The company wants to keep control over the full datasets that the company shares with the customers.

Which S3 feature will meet these requirements?

Options:

A.

S3 Storage Lens

B.

S3 Cross-Region Replication (CRR)

C.

S3 Versioning

D.

S3 Access Points

Question 154

Which AWS service is always available free of charge to users?

Options:

A.

Amazon Athena

B.

AWS Identity and Access Management (IAM)

C.

AWS Secrets Manager

D.

Amazon ElastiCache

Question 155

Which AWS service provides the SIMPLEST way for the company to establish a website on AWS?

Options:

A.

Amazon Elastic File System (Amazon EFS)

B.

AWS Elastic Beanstalk

C.

AWS Lambda

D.

Amazon Lightsail

Question 156

Which AWS services can limit manual errors by consistently provisioning AWS resources in multiple envirom

Options:

A.

AWS Config

B.

AWS CodeStar

C.

AWS CloudFormation

D.

AWS Cloud Development Kit (AWS CDK)

E.

AWS CodeBuild

Question 157

Which statements explain the business value of migration to the AWS Cloud? (Select TWO.)

Options:

A.

The migration of enterprise applications to the AWS Cloud makes these applications automatically available on mobile devices.S B. AWS availability and security provide the ability to improve service level agreements (SLAs) while reducing risk and unplanned downtime.

B.

Companies that migrate to the AWS Cloud eliminate the need to plan for high availability and disaster recovery.

C.

Companies that migrate to the AWS Cloud reduce IT costs related to infrastructure, freeing budget for reinvestment in otherareas.

D.

Applications are modernized because migration to the AWS Cloud requires companies to rearchitect and rewrite allenterprise applications.

Question 158

A company is running its application in the AWS Cloud and wants to protect against a DDoS attack. The company's security team wants near real-time visibility into DDoS attacks.

Which AWS service or traffic filter will meet these requirements with the MOST features for DDoS protection?

Options:

A.

AWS Shield Advanced

B.

AWS Shield

C.

Amazon GuardDuty

D.

Network ACLs

Question 159

A company migrated its core application onto multiple workloads in the AWS Cloud. The company wants to improve the application's reliability.

Which cloud design principle should the company implement to achieve this goal?

Options:

A.

Maximize utilization.

B.

Decouple the components.

C.

Rightsize the resources.

D.

Adopt a consumption model.

Question 160

Which actions are examples of a company's effort to right size its AWS resources to control cloud costs? (Select TWO.)

Options:

A.

Switch from Amazon RDS to Amazon DynamoDB to accommodate NoSQL datasets.Q B. Base the selection of Amazon EC2 instance types on past utilization patterns.

B.

Use Amazon S3 Lifecycle policies to move objects that users access infrequently to lower-cost storage tiers.

C.

Use Multi-AZ deployments for Amazon RDS.

D.

Replace existing Amazon EC2 instances with AWS Elastic Beanstalk.

Question 161

A company wants to use the latest technologies and wants to minimize its capital investment. Instead of upgrading on-premises infrastructure, the company wants to move to the AWS Cloud.

Which AWS Cloud benefit does this scenario describe?

Options:

A.

Increased speed to market

B.

The trade of infrastructure expenses for operating expenses

C.

Massive economies of scale

D.

The ability to go global in minutes

Question 162

Which task can only an AWS account root user perform?

Options:

A.

Changing the AWS Support plan

B.

Deleting AWS resources

C.

Creating an Amazon EC2 instance key pair

D.

Configuring AWS WAF

Question 163

A company is building an application that needs to deliver images and videos globally with minimal latency.

Which approach can the company use to accomplish this in a cost effective manner?

Options:

A.

Deliver the content through Amazon CloudFront.

B.

Store the content on Amazon S3 and enable S3 cross-region replication.

C.

Implement a VPN across multiple AWS Regions.

D.

Deliver the content through AWS PrivateLink.

Question 164

Which AWS service or feature is an example of a relational database management system?

Options:

A.

Amazon Athena

B.

Amazon Redshift

C.

Amazon S3 Select

D.

Amazon Kinesis Data Streams

Question 165

What is the LEAST expensive AWS Support plan that provides the full set of AWS Trusted Advisor best practice checks for cost optimization?

Options:

A.

AWS Enterprise Support

B.

AWS Business Support

C.

AWS Developer Support

D.

AWS Basic Support

Question 166

Which options are AWS Cloud Adoption Framework (AWS CAF) people perspective capabilities? (Select TWO.)

Options:

A.

Organizational alignment

B.

Portfolio management

C.

Organization design

D.

Risk management

E.

Modern application development

Question 167

A company wants to migrate its application to AWS. The company wants to replace upfront expenses with variable payment that is based on usage.

What should the company do to meet these requirements?

Options:

A.

Use pay-as-you-go pricing.

B.

Purchase Reserved Instances.

C.

Pay less by using more.

D.

Rightsize instances.

Question 168

Which option is an AWS Cloud Adoption Framework (AWS CAF) foundational capability for the operations perspective?

Options:

A.

Performance and capacity management

B.

Application portfolio management

C.

Identity and access management

D.

Product management

Question 169

A company hosts a large amount of data in AWS. The company wants to identify if any of the data should be considered sensitive.

Which AWS service will meet the requirement?

Options:

A.

Amazon Inspector

B.

Amazon Macie

C.

AWS Identity and Access Management (IAM)

D.

Amazon CloudWatch

Question 170

A company needs to run some of its workloads on premises to comply with regulatory guidelines. The company wants to use the AWS Cloud to run workloads that are not required to be on premises. The company also wants to be able to use the same API calls for the on-premises workloads and the cloud workloads.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

Dedicated Hosts

B.

AWS Outposts

C.

Availability Zones

D.

AWS Wavelength

Question 171

A company needs to categorize and track AWS usage cost based on business categories.

Which AWS service or feature should the company use to meet these requirements?

Options:

A.

Cost allocation tags

B.

AWS Organizations

C.

AWS Security Hub

D.

AWS Cost and Usage Report

Question 172

A company wants to monitor for misconfigured security groups that are allowing unrestricted access to specific ports.

Which AWS service will meet this requirement?

Options:

A.

AWS Trusted Advisor

B.

Amazon CloudWatch

C.

Amazon GuardDuty

D.

AWS Health Dashboard

Question 173

Which AWS service or feature will search for and identify AWS resources that are shared externally?

Options:

A.

Amazon OpenSearch Service

B.

AWS Control Tower

C.

AWS IAM Access Analyzer

D.

AWS Fargate

Question 174

Which pillar of the AWS Well-Architected Framework includes the AWS shared responsibility model?

Options:

A.

Operational excellence

B.

Performance efficiency

C.

Reliability

D.

Security

Question 175

Which perspective in the AWS Cloud Adoption Framework (AWS CAF) includes a capability for well-designed data and analytics architecture?

Options:

A.

Security

B.

Governance

C.

Operations

D.

Platform

Question 176

A company is planning to host its workloads on AWS.

Which AWS service requires the company to update and patch the guest operating system?

Options:

A.

Amazon DynamoDB

B.

Amazon S3

C.

Amazon EC2

D.

Amazon Aurora

Question 177

Which database engines does Amazon Aurora support? (Select TWO.)

Options:

A.

Oracle

B.

Microsoft SQL Server

C.

MySQL

D.

PostgreSQL

E.

MongoDB

Question 178

What can a cloud practitioner use to retrieve AWS security and compliance documents and submit them as evidence to an auditor or regulator?

Options:

A.

AWS Certificate Manager

B.

AWS Systems Manager

C.

AWS Artifact

D.

Amazon Inspector

Question 179

A company wants to migrate a database from an on-premises environment to Amazon RDS.

After the migration is complete, which management task will the company still be responsible for?

Options:

A.

Hardware lifecycle management

B.

Application optimization

C.

Server maintenance

D.

Power, network, and cooling provisioning

Question 180

A company provides a web-based ecommerce service that runs in two Availability Zones within a single AWS Region. The web service distributes content that is stored in the Amazon S3 Standard storage class. The company wants to improve the web service's performance globally.

What should the company do to meet this requirement?

Options:

A.

Change the S3 storage class to S3 Intelligent-Tiering.

B.

Deploy an Amazon CloudFront distribution to cache web server content in edge locations.

C.

Use Amazon API Gateway for the web service.

D.

Migrate the website ecommerce servers to Amazon EC2 with enhanced networking.

Question 181

A company needs to migrate a PostgreSQL database from on-premises to Amazon RDS.

Which AWS service or tool should the company use to meet this requirement?

Options:

A.

Cloud Adoption Readiness Tool

B.

AWS Migration Hub

C.

AWS Database Migration Service (AWS DMS)

D.

AWS Application Migration Service

Question 182

According to security best practices, how should an Amazon EC2 instance be given access to an Amazon S3 bucket?

Options:

A.

Hard code an IAM user's secret key and access key directly in the application, and upload the file.

B.

Store the IAM user's secret key and access key in a text file on the EC2 instance, read the keys, then upload the file.

C.

Have the EC2 instance assume a role to obtain the privileges to upload the file.

D.

Modify the S3 bucket policy so that any service can upload to it at any time.

Question 183

A company is setting up AWS Identity and Access Management (IAM) on an AWS account.

Which recommendation complies with IAM security best practices?

Options:

A.

Use the account root user access keys for administrative tasks.

B.

Grant broad permissions so that all company employees can access the resources they need.

C.

Turn on multi-factor authentication (MFA) for added security during the login process.

D.

Avoid rotating credentials to prevent issues in production applications.

Question 184

A company is running a monolithic on-premises application that does not scale and is difficult to maintain. The company has a plan to migrate the application to AWS and divide the application into microservices.

Which best practice of the AWS Well-Architected Framework is the company following with this plan?

Options:

A.

Integrate functional testing as part of AWS deployment.

B.

Use automation to deploy changes.

C.

Deploy the application to multiple locations.

D.

Implement loosely coupled dependencies.

Question 185

A company is planning to migrate to the AWS Cloud. The company is conducting organizational transformation and wants to become more responsive to customer inquiries and feedback.

Which tasks should the company perform to meet these requirements, according to the AWS Cloud Adoption

Framework (AWS CAF)? (Select TWO.)

Options:

A.

Realign teams to focus on products and value streams.

B.

Create new value propositions with new products and services.

C.

Use agile methods to rapidly iterate and evolve.

D.

Use a new data and analytics platform to create actionable insights.

E.

Migrate and modernize legacy infrastructure.

Question 186

A customer runs an On-Demand Amazon Linux EC2 instance for 3 hours, 5 minutes, and 6 seconds.

For how much time will the customer be billed?

Options:

A.

3 hours, 5 minutes

B.

3 hours, 5 minutes, and 6 seconds

C.

3 hours, 6 minutes

D.

4 hours

Question 187

Which AWS solution provides the ability for a company to run AWS services in the company's on-premises data center?

Options:

A.

AWS Direct Connect

B.

AWS Outposts

C.

AWS Systems Manager hybrid activations

D.

AWS Storage Gateway

Question 188

Which AWS Support plan is the minimum recommended tier for users who have production workloads on AWS?

Options:

A.

AWS Developer Support

B.

AWS Enterprise Support

C.

AWS Business Support

D.

AWS Enterprise On-Ramp Support

Question 189

A company has 5 TB of data stored in Amazon S3. The company plans to occasionally run queries on the data for analysis.

Which AWS service should the company use to run these queries in the MOST cost-effective manner?

Options:

A.

Amazon Redshift

B.

Amazon Athena

C.

Amazon Kinesis

D.

Amazon RDS

Question 190

Which AWS service is deployed to VPCs and provides protection from common network threats?

Options:

A.

AWSShield

B.

AWSWAF

C.

AWS Network Firewall

D.

AWS FirewallManager

Question 191

Which AWS service or feature enables users to encrypt data at rest in Amazon S3?

Options:

A.

IAM policies

B.

Server-side encryption

C.

Amazon GuardDuty

D.

Client-side encryption

Question 192

A company is building an application in the AWS Cloud. The company wants to use temporary credentials for the application to access other AWS resources.

Which AWS service will meet these requirements?

Options:

A.

AWS Key Management Service (Aws KMS)

B.

AWS CloudHSM

C.

Amazon Cognito

D.

AWS Security Token Service (Aws STS)

Question 193

A company needs to set a maximum spending limit on AWS services each month. The company also needs to set up alerts for when the company reaches its spending limit.

Which AWS service or tool should the company use to meet these requirements?

Options:

A.

Cost Explorer

B.

AWS Trusted Advisor

C.

Service Quotas

D.

AWS Budgets

Question 194

Which AWS service or tool helps users visualize, understand, and manage spending and usage over time?

Options:

A.

AWS Organizations

B.

AWS Pricing Calculator

C.

AWS Cost Explorer

D.

AWS Service Catalog

Question 195

Which cloud concept is demonstrated by using AWS Compute Optimizer?

Options:

A.

Security validation

B.

Rightsizing

C.

Elasticity

D.

Global reach

Question 196

A company website is experiencing DDoS attacks.

Which AWS service can help protect the company website against these attacks?

Options:

A.

AWS Resource Access Manager

B.

AWS Amplify

C.

AWS Shield

D.

Amazon GuardDuty

Question 197

Which AWS service provides the ability to manage infrastructure as code?

Options:

A.

AWS CodePipeline

B.

AWS CodeDeploy

C.

AWS Direct Connect

D.

AWS CloudFormation

Question 198

A company's application has high customer usage during certain times of the day. The company wants to reduce the number of Amazon EC2 instances that run when application usage is low.

Which AWS service or instance purchasing option should the company use to meet this requirement?

Options:

A.

EC2 Instance Savings Plans

B.

Spot Instances

C.

Reserved Instances

D.

Amazon EC2 Auto Scaling

Question 199

A company wants to centrally manage Its employee's access to multiple AWS accounts.

Which AWS service or feature should the company use to meet this requirement?

Options:

A.

AWS Identity and Access Management Access Analyzer

B.

AWS Secrets Manager

C.

AWS IAM Identity Center

D.

AWS Security Token Service (AWS STS)

Question 200

Which AWS service can a company use to directly query and analyze AWS Cost and Usage Reports?

Options:

A.

Amazon OpenSearch Service

B.

Amazon Athena

C.

Amazon Aurora

D.

AWS Glue

Question 201

A company will run a predictable compute workload on Amazon EC2 Instances for the next 3 years. The workload is critical for the company. The company wants to optimize costs to run the workload.

Which solution will meet these requirements?

Options:

A.

Spot Instances

B.

Dedicated Hosts

C.

Savings Plans

D.

On-Demand Instances

Question 202

Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?

Options:

A.

AWS CloudFormation

B.

AWS CodeDeploy

C.

AWS CodeBuild

D.

AWS Systems Manager

Question 203

A cloud practitioner wants a repeatable way to deploy identical AWS resources by using infrastructure templates. Which AWS service will meet these requirements?

Options:

A.

AWS CloudFormation

B.

AWS Directory Service

C.

Amazon Lightsail

D.

AWS CodeDeploy

Question 204

A company that has an AWS Enterprise Support plan needs to protect its applications from DDoS attacks. The company requires access to the AWS DDoS Response Team (DRT) 24 hours a day. 7 days a week.

Which AWS service will meet these requirements?

Options:

A.

AWS Shield Standard

B.

AWS Shield Advanced

C.

AWS Firewall Manager

D.

AWS WAF

Question 205

Which AWS service should a company use to organize characterize, and search large numbers of images?

Options:

A.

Amazon Transcribe

B.

Amazon Rekognition

C.

Amazon Aurora

D.

Amazon QuickSight

Question 206

Which AWS service is a fully managed service for machine learning?

Options:

A.

AWS Lambda

B.

Amazon Kinesis

C.

Amazon Athena

D.

Amazon SageMaker

Question 207

Which AWS service provides machine learning capability to detect and analyze content in images and videos?

Options:

A.

Amazon Connect

B.

Amazon Lightsail

C.

Amazon Personalize

D.

Amazon Rekognition

Question 208

A company wants to use an AWS networking solution that can act as a centralized gateway between multiple VPCs and on-premises networks. Which AWS service or feature will meet this requirement?

Options:

A.

Gateway VPC endpoint

B.

AWS Direct Connect

C.

AWS Transit Gateway

D.

AWS PrivateLink

Question 209

A company wants to migrate its on-premises SQL Server database to the AWS Cloud. The company wants AWS to handle the day-to-day administration of the database. Which AWS service will meet the company's requirements?

Options:

A.

Amazon EC2 foe Microsoft SQL Server

B.

Amazon DynamoDB

C.

Amazon RDS

D.

Amazon Aurora

Question 210

A company runs a legacy workload in an on-premises data center. The company wants to migrate the workload to AWS. The company does not want to make any changes to the workload.

Which migration strategy should the company use?

Options:

A.

Repurchase

B.

Replatform

C.

Rehost

D.

Refactor

Question 211

Which AWS service is a fully managed NoSQL database service?

Options:

A.

Amazon RDS

B.

Amazon Redshift

C.

Amazon DynamoDB

D.

Amazon Aurora

Question 212

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance state changes to RUNNING.

Which AWS service can the company use to meet this requirement?

Options:

A.

Amazon SageMaker

B.

Amazon Connect

C.

Amazon EventBridge

D.

AWS Fargate

Question 213

A user wants to review all Amazon S3 buckets with ACLs and S3 bucket policies in the S3 console. Which AWS service or resource will meet this requirement?

Options:

A.

S3 Multi-Region Access Points

B.

S3 Storage Lens

C.

AWS IAM Identity Center

D.

Access Analyzer for S3

Question 214

A company is creating a web application that requires a relational database to store customer data. Which AWS service should the company use to host the database?

Options:

A.

Amazon Aurora

B.

Amazon DynamoDB

C.

Amazon ElastiCache

D.

Amazon Redshift

Question 215

Which AWS service or resource can a company use to deploy AWS WAF rules?

Options:

A.

Amazon EC2

B.

Application Load Balancer

C.

AWS Trusted Advisor

D.

Network Load Balancer

Question 216

A company plans to host its data warehouse application on AWS. The company has a machine learning (ML) model and wants to use that model within its data warehouse for data forecasting.

Options:

A.

Amazon DynamoDB

B.

Amazon Redshift ML

C.

Amazon Aurora ML

D.

Amazon MemoryDB

Question 217

A company uploads audio and video files to a centralized Amazon S3 bucket from different geographic locations. Which AWS solution will optimize transfer speeds for these files?

Options:

A.

AWS Global Accelerator

B.

S3 Transfer Acceleration

C.

AWS Direct Connect

D.

Amazon CloudFront

Question 218

A company wants to minimize network latency between its Amazon EC2 instances. The EC2 instances do not need to be highly available. Which solution meets these requirements?

Options:

A.

Use EC2 instances in a single Availability Zone.

B.

Use EC2 instances in multiple edge locations.

C.

Use EC2 instances in the same Availability Zone but in different AWS Regions.

D.

Use EC2 instances in the same edge location and the same AWS Region.

Question 219

Which AWS service or feature gives users the ability to run containers and Kubernetes applications without the need to manage scaling?

Options:

A.

Amazon Elastic Container Registry (Amazon ECR)

B.

Elastic network interface

C.

AWS Fargate

D.

Amazon EC2

Question 220

A company notices suspicious network activity against an application that is running on a fleet of Amazon EC2 instances. The suspicious activity is coming from a single IP address.

Which AWS service should the company use to block access from this IP address?

Options:

A.

AWS Shield

B.

AWS Config

C.

Amazon GuardDuty

D.

AWS WAF

Question 221

A company wants to use an AWS networking solution to connect multiple VPCs.

Which AWS service will meet this requirement?

Options:

A.

AWS Config

B.

AWS Direct Connect

C.

Amazon GuardDuty

D.

AWS Transit Gateway

Question 222

A company is designing AWS architecture that will add compute resources when the company needs them. The architecture also includes a disaster recovery plan with automatic failover.

Options:

A.

Reliability

B.

Operational excellence

C.

Security

D.

Performance efficiency

Question 223

Which AWS service gives users on-demand, sell-service access to AWS compliance control reports?

Options:

A.

AWS Config

B.

Amazon GuardDuty

C.

AWS Trusted Advisor

D.

AWS Artifact

Question 224

A company is migrating its public website to AWS. The company wants to host the domain name for the website on AWS.

Which AWS service should the company use to meet this requirement?

Options:

A.

AWS Lambda

B.

Amazon Route 53

C.

Amazon CloudFront

D.

AWS Direct Connect

Question 225

A company needs to block SOL injection attacks.

Which AWS service or feature provides this functionality?

Options:

A.

AWS WAF

B.

Network ACLs

C.

Security groups

D.

AWS Trusted Advisor

Question 226

A company is moving its on-premises IT services to the AWS Cloud. The company wants to set spending limits and to receive notifications if the limits are exceeded.

Which AWS service or resource will meet these requirements?

Options:

A.

AWS Budgets

B.

AWS Cost and Usage Reports

C.

AWS Cost Explorer

D.

AWS Organizations consolidated billing

Question 227

Which AWS service or tool provides users with a graphical interface that they can use to manage AWS services?

Options:

A.

AWS Copilot

B.

AWS CLI

C.

AWS Management Console

D.

AWS software development kits (SDKs)

Question 228

Which AWS services can host PostgreSQL databases? (Select TWO.)

Options:

A.

Amazon S3

B.

Amazon Aurora

C.

Amazon EC2

D.

Amazon OpenSearch Service

E.

Amazon Elastic File System (Amazon EFS)

Question 229

Which AWS service provides on-premises applications with low-latency access to data that is stored in the AWS Cloud?

Options:

A.

Amazon CloudFront

B.

AWS Storage Gateway

C.

AWS Backup

D.

AWS DataSync

Question 230

A company is running Amazon EC2 instances in a private subnet in a VPC.

Which AWS service or feature can provide the EC2 instances with network connections to the internet?

Options:

A.

Gateway endpoint

B.

NAT gateway

C.

Network Load Balancer

D.

Amazon Route 53

Question 231

Which action should a company take to improve security in its AWS account?

Options:

A.

Require multi-factor authentication (MFA) for privileged users.

B.

Remove the root user account.

C.

Create an access key for the AWS account root user.

D.

Create an access key for each privileged user.

Question 232

A company is releasing a business-critical application. Before the release, the company needs strategic planning assistance from AWS. During the release, the company needs AWS infrastructure event management and real-time support.

What should the company do to meet these requirement?

Options:

A.

Access AWS Trusted Advisor.

B.

Contact the AWS Partner Network (APN).

C.

Sign up for AWS Enterprise Support.

D.

Contact AWS Professional Services.

Question 233

A company wants to track tags, buckets, and prefixes for its Amazon S3 objects.

Which S3 feature will meet this requirement?

Options:

A.

S3 Inventory report

B.

S3 Lifecycle

C.

S3 Versioning

D.

S3 ACLs

Question 234

A company wants its Amazon EC2 instances to be in different locations but share the same geographic area. The company also wants to use multiple power grids and independent networking connectivity for the EC2 instances.

Which solution meets these requirements?

Options:

A.

Use EC2 instances in multiple edge locations in the same AWS Region.

B.

Use EC2 instances in multiple Availability Zones in the same AWS Region.

C.

Use EC2 instances in multiple Amazon Connect locations in the same AWS Region

D.

Use EC2 instances in multiple AWS Artifact locations in the same AWS Region.

Question 235

A company wants to migrate its on-premises PostgreSQL database to a managed PostgreSQL database on AWS. Which AWS service will meet this requirement?

Options:

A.

Amazon DynamoDB

B.

Amazon Neptune

C.

Amazon RDS

D.

Amazon Redshift

Question 236

A company uses Amazon EC2 instances to run its application. The application needs to be available and running continuously for three or more years. What type of EC2 instance should the company purchase for a discount on the EC2 pricing?

Options:

A.

Reserved Instances

B.

Spot Instances

C.

On-Demand Instances

D.

EC2 Fleet

Question 237

A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account.

Which AWS service or resource should the company use to meet this requirement?

Options:

A.

AWS Security Hub

B.

AWS Marketplace

C.

AWS Quick Starts

D.

AWS Security Center

Question 238

An ecommerce company has been monitoring usage of its online store that is hosted on a fleet of Amazon EC2 instances. Surges in traffic occur every weekend day at the same time and last for approximately 4 hours.

Which AWS service should the company use to ensure that there are enough instances to meet the surges in demand?

Options:

A.

AWS Lambda

B.

Amazon EventBridge

C.

Elastic Load Balancing (ELB)

D.

Amazon EC2 Auto Scaling

Question 239

A company is planning to set up a new application in the AWS Cloud. The company needs a complete estimate of the AWS expenses that the application is likely to incur.

Options:

A.

AWS Trusted Advisor

B.

AWS Cost Explorer

C.

AWS Price List API

D.

AWS Pricing Calculator

Question 240

Which AWS service or feature provides information about governance monitoring and risk auditing of AWS accounts?

Options:

A.

AWS CloudTrail

B.

VPC Flow Logs

C.

Amazon CloudWatch

D.

AWS Trusted Advisor

Question 241

A company wants to run a graph query that provides credit card users' names, addresses, and transactions. The company wants the graph to show if the names, addresses, and transactions indicates possible fraud.

Which AWS database service will meet these requirements?

Options:

A.

Amazon DocumenlDB (with MongoDB compatibility)

B.

Amazon Timestream

C.

Amazon DynamoDB

D.

Amazon Neptune

Question 242

A company has an on-premises application. The application has processing times of less than 5 minutes and is invoked only a few times each day. The company wants to move the application to the AWS Cloud.

Which AWS service will support this application MOST cost-effectively?

Options:

A.

Amazon Elastic Container Service (Amazon ECS)

B.

AWS Lambda

C.

Amazon Elastic Kubernetes Service (Amazon EKS)

D.

Amazon EC2

Question 243

A company needs to store infrequently used data for data archives and long-term backups.

Which AWS service or storage class will meet these requirements MOST cost-effectively?

Options:

A.

Amazon FSx for Lustre

B.

Amazon Elastic Block Store (Amazon EBS)

C.

Amazon Elastic File System (Amazon EFS)

D.

Amazon S3 Glacier Flexible Retrieval

Question 244

Which AWS service gives companies the ability to create graph applications that can analyze billions of relationships between data points in milliseconds?

Options:

A.

Amazon Redshift

B.

Amazon Neptune

C.

Amazon DocumentDB (with MongoDB compatibility)

D.

Amazon ElastiCache

Question 245

A company has a client that uses an Amazon RDS database. The client requests Information about operating system-level upgrades on the AWS resources that host the RDS database. The company employs a third-party provider to monitor the RDS database.

Who is responsible for upgrading the operating systems for Amazon RDS under the AWS shared responsibility model?

Options:

A.

The client

B.

The company

C.

AWS

D.

The third-party provider

Question 246

A company needs access to checks and recommendations that help the company follow AWS best practices for cost optimization, security, fault tolerance, performance, and service quotas.

Which combination of an AWS service and AWS Support plan on the AWS account will meet these requirements?

Options:

A.

AWS Trusted Advisor with AWS Developer Support

B.

AWS Health Dashboard with AWS Enterprise Support

C.

AWS Trusted Advisor with AWS Business Support

D.

AWS Health Dashboard with AWS Enterprise On-Ramp Support

Question 247

A company wants to control the protection of its AWS resources. The company wants to block SQL injection attacks and cross-site scripting.

Which AWS service or feature meets these requirements?

Options:

A.

Amazon GuardDuty

B.

AWSWAF

C.

Security groups

D.

AWS Shield

Question 248

A company uses AWS and has a VPC that includes two public subnets. The company needs to allow and deny specific inbound and outbound traffic for each public subnet.

Which AWS service or tool can the company use to meet this requirement?

Options:

A.

Network ACL

B.

AWSWAF

C.

VPC route table entry

D.

Security group

Question 249

Treating infrastructure as code in the AWS Cloud allows users to:

Options:

A.

automate migration of on-premises hardware to AWS data centers.

B.

let a third party automate an audit of the AWS infrastructure.

C.

turn over application code to AWS so it can run on the AWS infrastructure.

D.

automate the infrastructure provisioning process.

Question 250

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

Which action is the company's responsibility?

Options:

A.

Managing the infrastructure that runs the S3 bucket

B.

Managing the data in transit

C.

Managing the encryption options on the S3 bucket

D.

Managing the operating system updates on the S3 bucket

Question 251

An Amazon EC2 instance previously used for development is inaccessible and no longer appears in the AWS Management Console.

Which AWS service should be used to determine what action made this EC2 instance inaccessible?

Options:

A.

Amazon CloudWatch Logs

B.

AWS Security Hub

C.

Amazon Inspector

D.

AWS CloudTrail

Question 252

Which AWS service can a company use to manage encryption keys in the cloud?

Options:

A.

AWS License Manager

B.

AWS Certificate Manager (ACM)

C.

AWS CloudHSM

D.

AWS Directory Service

Question 253

Which options are benefits of using third-party software from AWS Marketplace? (Select TWO.)

Options:

A.

The software's data encryption is managed by a third-party vendor.

B.

The software has been evaluated by vendors to ensure that it will run on AWS.

C.

Users do not need to upgrade to newer software versions.

D.

Users do not need to conduct security testing on the software.

E.

Users can launch preconfigured software in only a few steps.

Question 254

Which AWS service or feature should a company use between two microservices to ensure that messages are sent and received in exact order?

Options:

A.

Amazon Simple Email Service (Amazon SES)

B.

Amazon Simple Notification Service (Amazon SNS)

C.

Amazon S3 Event Notifications

D.

Amazon Simple Queue Service (Amazon SQS) FIFO queues

Question 255

A company plans to migrate to the AWS Cloud. The company wants to gather information about its on-premises data center.

Which AWS service should the company use to meet these requirements?

Options:

A.

AWS Application Discovery Service

B.

AWS DataSync

C.

AWS Storage Gateway

D.

AWS Database Migration Service (AWS DMS)

Question 256

A company needs to establish a dedicated network connection from on premises to AWS. The connection must provide consistent, low-latency network performance.

Which AWS service should the company use to meet this requirement?

Options:

A.

AWS Direct Connect

B.

AWS Site-to-Site VPN

C.

AWS Directory Service

D.

AWS Transit Gateway

Question 257

A company wants to log in securely to Linux Amazon EC2 instances.

How can the company accomplish this goal?

Options:

A.

Use SSH keys.

B.

Use a VPN.

C.

Use end-to-end encryption.

D.

Use Amazon Route 53.

Question 258

Which task is the shared responsibility of the customer and AWS under the AWS shared responsibility model?

Options:

A.

Installing hardware infrastructure

B.

Managing security

C.

Managing guest operating systems

D.

Protecting the physical infrastructure that runs all services

Question 259

A company wants to rightsize its Amazon EC2 instances.

Which configuration change will meet this requirement with the LEAST operational overhead?

Options:

A.

Add EC2 instances in another Availability Zone.

B.

Change the size and type of the EC2 instances based on utilization.

C.

Convert the payment method from On-Demand to Savings Plans.

D.

Reprovision the EC2 instances with a larger instance type.

Question 260

A company wants to run its application's code without having to provision and manage servers. Which AWS service will meet this requirement?

Options:

A.

AWS Glue

B.

AWS Lambda

C.

AWS CodeDeploy

D.

Amazon CodeGuru

Question 261

What is the total volume of data that can be stored in Amazon S3?

Options:

A.

10 PB

B.

50 PB

C.

100 PB

D.

Virtually unlimited

Question 262

Which AWS service provides storage-optimized and compute-optimized device configurations?

Options:

A.

AWS Snowcone

B.

AWS Storage Gateway

C.

AWS Snowball Edge

D.

AWS DataSync

Question 263

A company needs to automatically protect its Amazon EC2 instances from distributed denial of service (DDoS) attacks.

Options:

A.

Network access control list (ACL)

B.

AWS Shield

C.

Security group

D.

Amazon GuardDuty

Page: 1 / 88
Total 877 questions