AWS Certified Cloud Practitioner CLF-C02 Exam
AWS Certified Cloud Practitioner CLF-C02 Exam
A company plans to use an Amazon Snowball Edge device to transfer files to the AWS Cloud.
Which activities related to a Snowball Edge device are available to the company at no cost?
B. The transfer of data out of Amazon S3 and to the Snowball Edge appliance
C. The transfer of data from the Snowball Edge appliance into Amazon S3
Correct Answer: C
Question #2 Topic 1
A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify
Which AWS service can the company use to meet these requirements?
B. Amazon Inspector
C. AWS Config
D. Amazon GuardDuty
Correct Answer: B
A company has a centralized group of users with large file storage requirements that have exceeded the space available on premises. The
company wants to extend its file storage capabilities for this group while retaining the performance benefit of sharing content locally.
What is the MOST operationally efficient AWS solution for this scenario?
A. Create an Amazon S3 bucket for each user. Mount each bucket by using an S3 file system mounting utility.
B. Configure and deploy an AWS Storage Gateway file gateway. Connect each user’s workstation to the file gateway.
C. Move each user’s working environment to Amazon WorkSpaces. Set up an Amazon WorkDocs account for each user.
D. Deploy an Amazon EC2 instance and attach an Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS volume. Share the EBS volume
Correct Answer: B
Question #4 Topic 1
According to security best practices, how should an Amazon EC2 instance be given access to an Amazon S3 bucket?
A. Hard code an IAM user’s secret key and access key directly in the application, and upload the file.
B. Store the IAM user’s secret key and access key in a text file on the EC2 instance, read the keys, then upload the file.
C. Have the EC2 instance assume a role to obtain the privileges to upload the file.
D. Modify the S3 bucket policy so that any service can upload to it at any time.
Correct Answer: C
Question #5 Topic 1
Which option is a customer responsibility when using Amazon DynamoDB under the AWS Shared Responsibility Model?
B. Patching of DynamoDB
Correct Answer: C
Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?
A. Sustainability
B. Performance efficiency
C. Governance
D. Reliability
Correct Answer: C
Question #7 Topic 1
A company is running and managing its own Docker environment on Amazon EC2 instances. The company wants an alternative to help manage
A. AWS Lambda
B. Amazon RDS
C. AWS Fargate
D. Amazon Athena
Correct Answer: C
Question #8 Topic 1
Correct Answer: C
Which AWS services or tools can identify rightsizing opportunities for Amazon EC2 instances? (Choose two.)
C. Amazon CodeGuru
D. Amazon SageMaker
Correct Answer: AE
Which of the following are benefits of using AWS Trusted Advisor? (Choose two.)
Correct Answer: CD
Which of the following is an advantage that users experience when they move on-premises workloads to the AWS Cloud?
Correct Answer: A
A company wants to manage deployed IT services and govern its infrastructure as code (IaC) templates.
C. AWS Organizations
Correct Answer: B
Which AWS service or tool helps users visualize, understand, and manage spending and usage over time?
A. AWS Organizations
Correct Answer: C
A company is using a central data platform to manage multiple types of data for its customers. The company wants to use AWS services to
Which combination of AWS services should the company use to meet these requirements? (Choose two.)
A. AWS Glue
C. Amazon Redshift
D. Amazon QuickSight
Correct Answer: AD
A global company wants to migrate its third-party applications to the AWS Cloud. The company wants help from a global team of experts to
complete the migration faster and more reliably in accordance with AWS internal best practices.
A. AWS Support
Correct Answer: B
An e-learning platform needs to run an application for 2 months each year. The application will be deployed on Amazon EC2 instances. Any
Which EC2 purchasing option will meet these requirements MOST cost-effectively?
A. Reserved Instances
B. Dedicated Hosts
C. Spot Instances
D. On-Demand Instances
Correct Answer: D
A developer wants to deploy an application quickly on AWS without manually creating the required resources.
A. Amazon EC2
C. AWS CodeBuild
D. Amazon Personalize
Correct Answer: B
A company is storing sensitive customer data in an Amazon S3 bucket. The company wants to protect the data from accidental deletion or
overwriting.
A. S3 Lifecycle rules
B. S3 Versioning
C. S3 bucket policies
D. S3 server-side encryption
Correct Answer: B
A. AWS CodePipeline
B. AWS CodeDeploy
D. AWS CloudFormation
Correct Answer: D
An online gaming company needs to choose a purchasing option to run its Amazon EC2 instances for 1 year. The web traffic is consistent, and any
increases in traffic are predictable. The EC2 instances must be online and available without any disruption.
Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Spot Fleet
Correct Answer: B
Which AWS service or feature allows a user to establish a dedicated network connection between a company’s on-premises data center and the
AWS Cloud?
B. VPC peering
C. AWS VPN
D. Amazon Route 53
Correct Answer: A
A. AWS DataSync
B. AWS Region
C. Amazon Connect
D. AWS Organizations
Correct Answer: B
A company wants to protect its AWS Cloud information, systems, and assets while performing risk assessment and mitigation tasks.
A. Reliability
B. Security
C. Operational excellence
D. Performance efficiency
Correct Answer: B
D. To load balance traffic from the internet across Amazon EC2 instances
Correct Answer: B
A company is running a monolithic on-premises application that does not scale and is difficult to maintain. The company has a plan to migrate the
Which best practice of the AWS Well-Architected Framework is the company following with this plan?
Correct Answer: D
A company has an AWS account. The company wants to audit its password and access key rotation details for compliance purposes.
B. AWS Artifact
Correct Answer: C
A company wants to receive a notification when a specific AWS cost threshold is reached.
Which AWS services or tools can the company use to meet this requirement? (Choose two.)
B. AWS Budgets
C. Cost Explorer
D. Amazon CloudWatch
Correct Answer: BD
Which AWS service or resource provides answers to the most frequently asked security-related questions that AWS receives from its users?
A. AWS Artifact
B. Amazon Connect
C. AWS Chatbot
Correct Answer: A
Which tasks are customer responsibilities, according to the AWS shared responsibility model? (Choose two.)
Correct Answer: AB
Which of the following are pillars of the AWS Well-Architected Framework? (Choose two.)
A. Availability
B. Reliability
C. Scalability
D. Responsive design
E. Operational excellence
Correct Answer: BE
Which AWS service or feature is used to send both text and email messages from distributed applications?
Correct Answer: A
A user needs programmatic access to AWS resources through the AWS CLI or the AWS API.
Which option will provide the user with the appropriate access?
A. Amazon Inspector
B. Access keys
Correct Answer: B
A company runs thousands of simultaneous simulations using AWS Batch. Each simulation is stateless, is fault tolerant, and runs for up to 3
hours.
Which pricing model enables the company to optimize costs and meet these requirements?
A. Reserved Instances
B. Spot Instances
C. On-Demand Instances
D. Dedicated Instances
Correct Answer: B
What does the concept of agility mean in AWS Cloud computing? (Choose two.)
Correct Answer: AC
A. AWS WAF
B. AWS Shield
C. Network ACLs
D. Security groups
Correct Answer: A
Which AWS service or feature identifies whether an Amazon S3 bucket or an IAM role has been shared with an external entity?
D. AWS Organizations
Correct Answer: C
A cloud practitioner needs to obtain AWS compliance reports before migrating an environment to the AWS Cloud.
Correct Answer: B
An ecommerce company has migrated its IT infrastructure from an on-premises data center to the AWS Cloud.
Correct Answer: A
A company is setting up AWS Identity and Access Management (IAM) on an AWS account.
A. Use the account root user access keys for administrative tasks.
B. Grant broad permissions so that all company employees can access the resources they need.
C. Turn on multi-factor authentication (MFA) for added security during the login process.
Correct Answer: C
Elasticity in the AWS Cloud refers to which of the following? (Choose two.)
Correct Answer: BE
Which service enables customers to audit API calls in their AWS accounts?
A. AWS CloudTrail
C. Amazon Inspector
D. AWS X-Ray
Correct Answer: A
What is a customer responsibility when using AWS Lambda according to the AWS shared responsibility model?
Correct Answer: A
A company has 5 TB of data stored in Amazon S3. The company plans to occasionally run queries on the data for analysis.
Which AWS service should the company use to run these queries in the MOST cost-effective manner?
A. Amazon Redshift
B. Amazon Athena
C. Amazon Kinesis
D. Amazon RDS
Correct Answer: B
A. Amazon SageMaker
B. AWS Config
C. AWS Organizations
D. Amazon CloudWatch
Correct Answer: C
Which AWS Cloud Adoption Framework (AWS CAF) capability belongs to the people perspective?
A. Data architecture
B. Event management
C. Cloud fluency
D. Strategic partnership
Correct Answer: C
A company wants to make an upfront commitment for continued use of its production Amazon EC2 instances in exchange for a reduced overall
cost.
Which pricing options meet these requirements with the LOWEST cost? (Choose two.)
A. Spot Instances
B. On-Demand Instances
C. Reserved Instances
D. Savings Plans
E. Dedicated Hosts
Correct Answer: CD
A company wants to migrate its on-premises relational databases to the AWS Cloud. The company wants to use infrastructure as close to its
Which AWS service or resource should the company use to select its Amazon RDS deployment area?
A. Amazon Connect
B. AWS Wavelength
C. AWS Regions
Correct Answer: C
A company is exploring the use of the AWS Cloud, and needs to create a cost estimate for a project before the infrastructure is provisioned.
Which AWS service or feature can be used to estimate costs before deployment?
Correct Answer: B
A company is building an application that needs to deliver images and videos globally with minimal latency.
Which approach can the company use to accomplish this in a cost effective manner?
Correct Answer: A
Which option is a benefit of the economies of scale based on the advantages of cloud computing?
Correct Answer: C
Which of the following is a software development framework that a company can use to define cloud resources as code and provision the
A. AWS CLI
D. AWS CodeStar
Correct Answer: C
A company is developing an application that uses multiple AWS services. The application needs to use temporary, limited-privilege credentials for
Which AWS service or feature should the company use to meet these authentication requirements?
B. IAM users
Correct Answer: C
Which AWS service is a cloud security posture management (CSPM) service that aggregates alerts from various AWS services and partner
C. Amazon EventBridge
D. Amazon GuardDuty
Correct Answer: A
A. Amazon S3
D. AWS WAF
Correct Answer: B
Which AWS service is fully managed and can automatically scale throughput capacity to meet database workload demands?
A. Amazon Redshift
B. Amazon Aurora
C. Amazon DynamoDB
D. Amazon RDS
Correct Answer: C
Which task is the company’s responsibility, according to the AWS shared responsibility model?
B. Provision hosts.
Correct Answer: C
A company has a test AWS environment. A company is planning on testing an application within AWS. The application testing can be interrupted
Which Amazon EC2 purchasing option will meet these requirements MOST cost-effectively?
A. On-Demand Instances
B. Dedicated Instances
C. Spot Instances
D. Reserved Instances
Correct Answer: C
Which AWS service gives users the ability to discover and protect sensitive data that is stored in Amazon S3 buckets?
A. Amazon Macie
B. Amazon Detective
C. Amazon GuardDuty
Correct Answer: A
Which of the following services can be used to block network traffic to an instance? (Choose two.)
A. Security groups
C. Network ACLs
D. Amazon CloudWatch
E. AWS CloudTrail
Correct Answer: AC
Which AWS service can identify when an Amazon EC2 instance was terminated?
B. AWS CloudTrail
D. Amazon EventBridge
Correct Answer: B
A. Amazon S3
B. Amazon DynamoDB
C. Amazon Redshift
D. Amazon Aurora
Correct Answer: D
Which AWS service supports a hybrid architecture that gives users the ability to extend AWS infrastructure, AWS services, APIs, and tools to data
A. AWS Snowmobile
C. AWS Outposts
D. AWS Fargate
Correct Answer: C
Which AWS service can run a managed PostgreSQL database that provides online transaction processing (OLTP)?
A. Amazon DynamoDB
B. Amazon Athena
C. Amazon RDS
D. Amazon EMR
Correct Answer: C
A company wants to provide managed Windows virtual desktops and applications to its remote employees over secure network connections.
Which AWS services can the company use to meet these requirements? (Choose two.)
A. Amazon Connect
C. Amazon WorkSpaces
Correct Answer: BC
A company wants to monitor for misconfigured security groups that are allowing unrestricted access to specific ports.
B. Amazon CloudWatch
C. Amazon GuardDuty
Correct Answer: A
Which AWS service is a key-value database that provides sub-millisecond latency on a large scale?
A. Amazon DynamoDB
B. Amazon Aurora
D. Amazon Neptune
Correct Answer: A
A company is deploying a machine learning (ML) research project that will require a lot of compute power over several months. The ML
Which Amazon EC2 instance purchasing option will meet these requirements at the lowest cost?
A. On-Demand Instances
B. Spot Instances
C. Reserved Instances
D. Dedicated Instances
Correct Answer: A
Which AWS services or features provide disaster recovery solutions for Amazon EC2 instances? (Choose two.)
D. AWS Shield
E. Amazon GuardDuty
Correct Answer: BC
Which AWS service provides command line access to AWS tools and resources directly from a web browser?
A. AWS CloudHSM
B. AWS CloudShell
C. Amazon WorkSpaces
Correct Answer: B
A network engineer needs to build a hybrid cloud architecture connecting on-premises networks to the AWS Cloud using AWS Direct Connect. The
company has a few VPCs in a single AWS Region and expects to increase the number of VPCs to hundreds over time.
Which AWS service or feature should the engineer use to simplify and scale this connectivity as the VPCs increase in number?
A. VPC endpoints
C. Amazon Route 53
Correct Answer: B
A company wants to assess its operational readiness. It also wants to identify and mitigate any operational risks ahead of a new product launch.
Which AWS Support plan offers guidance and support for this kind of event at no additional charge?
Correct Answer: A
Which AWS service will support this requirement with the LEAST amount of operational overhead?
Correct Answer: B
Which AWS service or feature can be used to create a private connection between an on-premises workload and an AWS Cloud workload?
A. Amazon Route 53
B. Amazon Macie
D. AWS PrivateLink
Correct Answer: D
C. AWS KMS
D. AWS Config
Correct Answer: C
A company wants to manage its AWS Cloud resources through a web interface.
B. AWS CLI
C. AWS SDK
D. AWS Cloud9
Correct Answer: A
Which of the following are advantages of the AWS Cloud? (Choose two.)
Correct Answer: BC
Which AWS Cloud benefit is shown by an architecture’s ability to withstand failures with minimal downtime?
A. Agility
B. Elasticity
C. Scalability
D. High availability
Correct Answer: C
A developer needs to maintain a development environment infrastructure and a production environment infrastructure in a repeatable fashion.
Which AWS service should the developer use to meet these requirements?
B. AWS Shield
D. AWS CloudFormation
Correct Answer: D
Which task is the customer’s responsibility, according to the AWS shared responsibility model?
Correct Answer: B
Which AWS service helps deliver highly available applications with fast failover for multi-Region and Multi-AZ architectures?
A. AWS WAF
C. AWS Shield
Correct Answer: B
A company has a set of ecommerce applications. The applications need to be able to send messages to each other.
Correct Answer: C
What are the benefits of consolidated billing for AWS Cloud services? (Choose two.)
A. Volume discounts
Correct Answer: AC
A user wants to review all Amazon S3 buckets with ACLs and S3 bucket policies in the S3 console.
B. S3 Storage Lens
Correct Answer: A
What is the best resource for a user to find compliance-related information and reports about AWS?
A. AWS Artifact
B. AWS Marketplace
C. Amazon Inspector
D. AWS Support
Correct Answer: A
Which AWS service enables companies to deploy an application close to end users?
A. Amazon CloudFront
C. AWS AppSync
D. Amazon Route 53
Correct Answer: A
Which AWS service or feature improves network performance by sending traffic through the AWS worldwide network infrastructure?
A. Route table
D. Amazon VPC
Correct Answer: C
A. Amazon S3
D. Amazon FSx
Correct Answer: A
Which responsibility belongs to AWS when a company hosts its databases on Amazon EC2 instances?
A. Database backups
Correct Answer: D
Which of the following are advantages of moving to the AWS Cloud? (Choose two.)
A. The ability to turn over the responsibility for all security to AWS.
Correct Answer: BD
Which AWS service is a hybrid cloud storage service that provides on-premises users access to virtually unlimited cloud storage?
A. AWS DataSync
B. Amazon S3 Glacier
Correct Answer: C
A company plans to migrate to AWS and wants to create cost estimates for its AWS use cases.
Which AWS service or tool can the company use to meet these requirements?
B. Amazon CloudWatch
D. AWS Budgets
Correct Answer: A
Which tool should a developer use to integrate AWS service features directly into an application?
B. AWS CodeDeploy
C. AWS Lambda
D. AWS Batch
Correct Answer: A
Which of the following is a recommended design principle of the AWS Well-Architected Framework?
Correct Answer: C
Using AWS Identity and Access Management (IAM) to grant access only to the resources needed to perform a task is a concept known as:
A. restricted access.
B. as-needed access.
D. token access.
Correct Answer: C
Which AWS service or tool can be used to set up a firewall to control traffic going into and coming out of an Amazon VPC subnet?
A. Security group
B. AWS WAF
D. Network ACL
Correct Answer: C
A company wants to operate a data warehouse to analyze data without managing the data warehouse infrastructure.
A. Amazon Aurora
C. AWS Lambda
D. Amazon RDS
Correct Answer: B
How does AWS Cloud computing help businesses reduce costs? (Choose two.)
A. AWS charges the same prices for services in every AWS Region.
C. AWS offers discounts for Amazon EC2 instances that remain idle for more than 1 week.
D. AWS does not charge for data sent from the AWS Cloud to the internet.
E. AWS eliminates many of the costs of building and maintaining on-premises data centers.
Correct Answer: BE
A company wants to grant users in one AWS account access to resources in another AWS account. The users do not currently have permission to
A. IAM group
B. IAM role
C. IAM tag
Correct Answer: B
Question #99 Topic 1
Correct Answer: A
A company wants to automate infrastructure deployment by using infrastructure as code (IaC). The company wants to scale production stacks so
A. Amazon CloudWatch
B. AWS Config
D. AWS CloudFormation
Correct Answer: D
Which option is an AWS Cloud Adoption Framework (AWS CAF) platform perspective capability?
A. Data architecture
B. Data protection
C. Data governance
D. Data science
Correct Answer: C
Which AWS best practice ensures the MOST cost-effective architecture for the workload?
A. Loose coupling
B. Rightsizing
C. Caching
D. Redundancy
Correct Answer: B
A company is using a third-party service to back up 10 TB of data to a tape library. The on-premises backup server is running out of space. The
company wants to use AWS services for the backups without changing its existing backup workflows.
Which AWS service should the company use to meet these requirements?
D. AWS Lambda
Correct Answer: B
Which AWS tool gives users the ability to plan their service usage, service costs, and instance reservations, and also allows them to set custom
A. Cost Explorer
B. AWS Budgets
Correct Answer: A
Which tasks are the customer’s responsibility, according to the AWS shared responsibility model? (Choose two.)
Correct Answer: BC
A developer has been hired by a large company and needs AWS credentials.
Which are security best practices that should be followed? (Choose two.)
A. Grant the developer access to only the AWS resources needed to perform the job.
B. Share the AWS account root user credentials with the developer.
D. Configure a password policy that ensures the developer’s password cannot be changed.
Correct Answer: AE
A company has multiple AWS accounts that include compute workloads that cannot be interrupted. The company wants to obtain billing discounts
A. Resource tagging
B. Consolidated billing
C. Pay-as-you-go pricing
D. Spot Instances
Correct Answer: C
A user wants to allow applications running on an Amazon EC2 instance to make calls to other AWS services. The access granted must be secure.
A. Security groups
C. IAM roles
Correct Answer: A
A company wants a fully managed Windows file server for its Windows-based applications.
A. Amazon FSx
D. Amazon EMR
Correct Answer: A
Which AWS Storage Gateway type should the company use to meet this requirement?
A. Tape Gateway
B. Volume Gateway
Correct Answer: D
A company needs to track the activity in its AWS accounts, and needs to know when an API call is made against its AWS resources.
A. Amazon CloudWatch
B. Amazon Inspector
C. AWS CloudTrail
D. AWS IAM
Correct Answer: C
A company has an uninterruptible application that runs on Amazon EC2 instances. The application constantly processes a backlog of files in an
Amazon Simple Queue Service (Amazon SQS) queue. This usage is expected to continue to grow for years.
What is the MOST cost-effective EC2 instance purchasing model to meet these requirements?
A. Spot Instances
B. On-Demand Instances
C. Savings Plans
D. Dedicated Hosts
Correct Answer: A
A company wants an AWS service to provide product recommendations based on its customer data.
A. Amazon Polly
B. Amazon Personalize
C. Amazon Comprehend
D. Amazon Rekognition
Correct Answer: B
A company is planning its migration to the AWS Cloud. The company is identifying its capability gaps by using the AWS Cloud Adoption
Which phase of the cloud transformation journey includes these identification activities?
A. Envision
B. Align
C. Scale
D. Launch
Correct Answer: B
A social media company wants to protect its web application from common web exploits such as SQL injections and cross-site scripting.
A. Amazon Inspector
B. AWS WAF
C. Amazon GuardDuty
D. Amazon CloudWatch
Correct Answer: B
Which fully managed AWS service assists with the creation, testing, and management of custom Amazon EC2 images?
Correct Answer: A
A company wants an automated process to continuously scan its Amazon EC2 instances for software vulnerabilities.
A. Amazon GuardDuty
B. Amazon Inspector
C. Amazon Detective
D. Amazon Cognito
Correct Answer: B
A company needs to perform data processing once a week that typically takes about 5 hours to complete.
Which AWS service should the company use for this workload?
A. AWS Lambda
B. Amazon EC2
C. AWS CodeDeploy
D. AWS Wavelength
Correct Answer: B
Which AWS service or feature provides log information of the inbound and outbound traffic on network interfaces in a VPC?
B. AWS CloudTrail
Correct Answer: C
A company wants to design a centralized storage system to manage the configuration data and passwords for its critical business applications.
Which AWS service or capability will meet these requirements MOST cost-effectively?
C. AWS Config
D. Amazon S3
Correct Answer: A
A company plans to deploy containers on AWS. The company wants full control of the compute resources that host the containers. Which AWS
B. AWS Fargate
C. Amazon EC2
Correct Answer: C
Which AWS service or feature allows users to create new AWS accounts, group multiple accounts to organize workflows, and apply policies to
groups of accounts?
C. AWS CloudFormation
D. AWS Organizations
Correct Answer: D
A company wants to store and retrieve files in Amazon S3 for its existing on-premises applications by using industry-standard file system
protocols.
A. AWS DataSync
Correct Answer: C
Which AWS service or feature should the company use to meet this requirement?
A. AWS WAF
B. Network ACLs
C. Security groups
Correct Answer: A
A company wants a unified tool to provide a consistent method to interact with AWS services.
A. AWS CLI
C. AWS Cloud9
Correct Answer: A
A company needs to evaluate its AWS environment and provide best practice recommendations in five categories: cost, performance, service
Which AWS service can the company use to meet these requirements?
A. AWS Shield
B. AWS WAF
Correct Answer: C
Which perspective in the AWS Cloud Adoption Framework (AWS CAF) includes capabilities for configuration management and patch
management?
A. Platform
B. Operations
C. Security
D. Governance
Correct Answer: B
Which Amazon EC2 instance purchasing options meet these requirements MOST cost-effectively? (Choose two.)
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Saving Plans
E. Dedicated Hosts
Correct Answer: BE
Which Amazon EC2 pricing model is the MOST cost efficient for an uninterruptible workload that runs once a year for 24 hours?
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Dedicated Instances
Correct Answer: C
Which option is a shared responsibility between AWS and its customers under the AWS shared responsibility model?
C. Patch management
Correct Answer: C
A company wants to migrate its on-premises workloads to the AWS Cloud. The company wants to separate workloads for chargeback to different
departments.
Which AWS services or features will meet these requirements? (Choose two.)
A. Placement groups
B. Consolidated billing
C. Edge locations
D. AWS Config
Correct Answer: BE
Which task is a responsibility of AWS, according to the AWS shared responsibility model?
A. Enable client-side encryption for objects that are stored in Amazon S3.
B. Configure IAM security policies to comply with the principle of least privilege.
Correct Answer: D
B. Pay-as-you-go pricing
Correct Answer: A
Which option is an AWS Cloud Adoption Framework (AWS CAF) business perspective capability?
A. Culture evolution
B. Event management
C. Data monetization
D. Platform architecture
Correct Answer: A
A company is assessing its AWS Business Support plan to determine if the plan still meets the company’s needs. The company is considering
Which additional benefit will the company receive with AWS Enterprise Support?
B. Phone, email, and chat access to cloud support engineers 24 hours a day, 7 days a week
Correct Answer: C
Which pricing model will interrupt a running Amazon EC2 instance if capacity becomes temporarily unavailable?
A. On-Demand Instances
C. Spot Instances
Correct Answer: C
Which options are AWS Cloud Adoption Framework (AWS CAF) security perspective capabilities? (Choose two.)
A. Observability
C. Incident response
D. Infrastructure protection
Correct Answer: CD
A company wants to run its workload on Amazon EC2 instances for more than 1 year. This workload will run continuously.
Which option offers a discounted hourly rate compared to the hourly rate of On-Demand Instances?
B. Dedicated Hosts
Correct Answer: C
Which characteristic of the AWS Cloud helps users eliminate underutilized CPU capacity?
A. Agility
B. Elasticity
C. Reliability
D. Durability
Correct Answer: B
Which AWS services can a company use to achieve a loosely coupled architecture? (Choose two.)
A. Amazon WorkSpaces
C. Amazon Connect
Correct Answer: BD
Which AWS Cloud service can send alerts to customers if custom spending thresholds are exceeded?
A. AWS Budgets
D. AWS Organizations
Correct Answer: A
A company plans to migrate to the AWS Cloud. The company wants to use the AWS Cloud Adoption Framework (AWS CAF) to define and track
Which AWS CAF governance perspective capability will meet these requirements?
A. Benefits management
B. Risk management
Correct Answer: A
A company needs to quickly and securely move files over long distances between its client and an Amazon S3 bucket.
A. S3 Versioning
B. S3 Transfer Acceleration
C. S3ACLs
D. S3 Intelligent-Tiering
Correct Answer: B
Question #144 Topic 1
A company needs to continuously run an experimental workload on an Amazon EC2 instance and stop the instance after 12 hours.
Which instance purchasing option will meet this requirement MOST cost-effectively?
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Dedicated Instances
Correct Answer: A
Which cloud transformation journey phase of the AWS Cloud Adoption Framework (AWS CAF) focuses on demonstrating how the cloud helps
A. Scale
B. Envision
C. Align
D. Launch
Correct Answer: B
Which option is a customer responsibility under the AWS shared responsibility model?
Correct Answer: B
Question #147 Topic 1
A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a natural disaster in a particular
geographic area.
Correct Answer: A
A company wants to modernize and convert a monolithic application into microservices. The company wants to move the application to AWS.
A. Rehost
B. Replatform
C. Repurchase
D. Refactor
Correct Answer: D
A systems administrator created a new IAM user for a developer and assigned the user an access key instead of a user name and password. What
Correct Answer: C
Question #150 Topic 1
A. Amazon CloudFront
B. Availability Zone
C. VPC
D. AWS Outposts
Correct Answer: B
A company is moving an on-premises data center to the AWS Cloud. The company must migrate 50 petabytes of file storage data to AWS with the
Which AWS service or resource should the company use to meet these requirements?
A. AWS Snowmobile
Correct Answer: A
A company has an application with robust hardware requirements. The application must be accessed by students who are using lightweight, low-
cost laptops.
Which AWS service will help the company deploy the application without investing in backend infrastructure or high-end client hardware?
B. AWS AppSync
C. Amazon WorkLink
Correct Answer: A
Question #153 Topic 1
A company wants to query its server logs to gain insights about its customers’ experiences.
A. Amazon Aurora
D. Amazon S3
Correct Answer: D
Which of the following is a recommended design principle for AWS Cloud architecture?
B. Build a single application component that can handle all the application functionality.
Correct Answer: D
Which AWS service helps users audit API activity across their AWS account?
A. AWS CloudTrail
B. Amazon Inspector
C. AWS WAF
D. AWS Config
Correct Answer: A
Which task is a customer’s responsibility, according to the AWS shared responsibility model?
Correct Answer: A
Question #157 Topic 1
A company wants to automatically add and remove Amazon EC2 instances. The company wants the EC2 instances to adjust to varying workloads
dynamically.
A. Amazon DynamoDB
Correct Answer: D
A user wants to securely automate the management and rotation of credentials that are shared between applications, while spending the least
A. AWS CloudHSM
D. Server-side encryption
Correct Answer: C
Which security service automatically recognizes and classifies sensitive data or intellectual property on AWS?
A. Amazon GuardDuty
B. Amazon Macie
C. Amazon Inspector
D. AWS Shield
Correct Answer: B
Question #160 Topic 1
Which actions are best practices for an AWS account root user? (Choose two.)
D. Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user.
Correct Answer: CD
A company is running a critical workload on an Amazon RDS DB instance. The company needs the DB instance to be highly available with a
C. Take frequent snapshots of the DB instance. Store the snapshots in Amazon S3.
Correct Answer: D
A company plans to migrate its application to AWS and run the application on Amazon EC2 instances. The application will have continuous usage
for 1 year.
Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?
A. Reserved Instances
B. Spot Instances
C. On-Demand Instances
D. Dedicated Hosts
Correct Answer: A
Question #163 Topic 1
A company needs to transfer data between an Amazon S3 bucket and an on-premises application.
Who is responsible for the security of this data, according to the AWS shared responsibility model?
A. The company
B. AWS
C. Firewall vendor
Correct Answer: A
Which pillar of the AWS Well-Architected Framework refers to the ability of a system to recover from infrastructure or service disruptions and
A. Security
B. Reliability
C. Performance efficiency
D. Cost optimization
Correct Answer: B
A company wants to identify Amazon S3 buckets that are shared with another AWS account.
C. Amazon CloudWatch
Correct Answer: D
Question #166 Topic 1
Which AWS service gives users the ability to build interactive business intelligence dashboards that include machine learning insights?
A. Amazon Athena
B. Amazon Kendra
C. Amazon QuickSight
D. Amazon Redshift
Correct Answer: C
Which of the following is an AWS value proposition that describes a user’s ability to scale infrastructure based on demand?
A. Speed of innovation
B. Resource elasticity
C. Decoupled architecture
D. Global deployment
Correct Answer: B
Which action is a security best practice for access to sensitive data that is stored in an Amazon S3 bucket?
B. Use IAM roles for applications that require access to the S3 bucket.
Correct Answer: B
A company wants to know more about the benefits offered by cloud computing. The company wants to understand the operational advantage of
A. The ability the ensure high availability by deploying workloads to multiple regions
D. The ability to provision and deprovision resources quickly with minimal effort
Correct Answer: D
Question #170 Topic 1
A company needs a central user portal so that users can log in to third-party business applications that support Security Assertion Markup
B. Amazon Cognito
D. AWS CLI
Correct Answer: C
Which AWS service should users use to learn about AWS service availability and operations?
A. Amazon EventBridge
Correct Answer: D
Which AWS service or tool can be used to capture information about inbound and outbound traffic in an Amazon VPC?
B. Amazon Inspector
D. NAT gateway
Correct Answer: A
What is the customer ALWAYS responsible for managing, according to the AWS shared responsibility model?
A. Software licenses
B. Networking
C. Customer data
D. Encryption keys
Correct Answer: C
Question #174 Topic 1
B. AWS Artifact
Correct Answer: B
Which AWS service enables users to check for vulnerabilities on Amazon EC2 instances by using predefined assessment templates?
A. AWS WAF
C. Amazon Inspector
D. AWS Shield
Correct Answer: C
A company plans to migrate to the AWS Cloud. The company is gathering information about its on-premises infrastructure and requires
A. AWS DataSync
Correct Answer: C
Correct Answer: C
Question #178 Topic 1
Which AWS tool or set of resources should the company use to analyze and assess its readiness for migration?
D. AWS Budgets
Correct Answer: A
Which of the following describes some of the core functionality of Amazon S3?
A. Amazon S3 is a high-performance block storage service that is designed for use with Amazon EC2.
B. Amazon S3 is an object storage service that provides high-level performance, security, scalability, and data availability.
C. Amazon S3 is a fully managed, highly reliable, and scalable file storage system that is accessible over the industry-standard SMB protocol.
D. Amazon S3 is a scalable, fully managed elastic NFS for use with AWS Cloud services and on-premises resources.
Correct Answer: B
Which AWS benefit is demonstrated by on-demand technology services that enable companies to replace upfront fixed expenses with variable
expenses?
A. High availability
B. Economies of scale
C. Pay-as-you-go pricing
D. Global reach
Correct Answer: C
Question #181 Topic 1
Which AWS services or features enable users to connect on-premises networks to a VPC? (Choose two.)
A. AWS VPN
D. VPC peering
E. Amazon CloudFront
Correct Answer: AC
A user needs to quickly deploy a nonrelational database on AWS. The user does not want to manage the underlying hardware or the database
software.
A. Amazon RDS
B. Amazon DynamoDB
C. Amazon Aurora
D. Amazon Redshift
Correct Answer: B
Which actions are examples of a company’s effort to rightsize its AWS resources to control cloud costs? (Choose two.)
B. Base the selection of Amazon EC2 instance types on past utilization patterns.
C. Use Amazon S3 Lifecycle policies to move objects that users access infrequently to lower-cost storage tiers.
Correct Answer: BC
Question #184 Topic 1
Which AWS service or feature can a company use to apply security rules to specific Amazon EC2 instances?
A. Network ACLs
B. Security groups
D. AWS WAF
Correct Answer: B
Which design principles support the reliability pillar of the AWS Well-Architected Framework? (Choose two.)
B. Enable traceability.
Correct Answer: CE
Which type of transfer of that data would result in no cost for the company?
Correct Answer: A
Question #187 Topic 1
A company wants to create templates that the company can reuse to deploy multiple AWS resources.
Which AWS service or feature can the company use to meet this requirement?
A. AWS Marketplace
C. AWS CloudFormation
D. AWS OpsWorks
Correct Answer: C
A company is building an application that requires the ability to send, store, and receive messages between application components. The
company has another requirement to process messages in first-in, first-out (FIFO) order.
Correct Answer: D
Which AWS service or feature is a browser-based, pre-authenticated service that can be launched directly from the AWS Management Console?
A. AWS API
B. AWS Lightsail
C. AWS Cloud9
D. AWS CloudShell
Correct Answer: D
Question #190 Topic 1
A company wants to migrate its database to a managed AWS service that is compatible with PostgreSQL.
A. Amazon Athena
B. Amazon RDS
C. Amazon EC2
D. Amazon DynamoDB
E. Amazon Aurora
Correct Answer: BE
A company has a fleet of cargo ships. The cargo ships have sensors that collect data at sea, where there is intermittent or no internet
connectivity. The company needs to collect, format, and process the data at sea and move the data to AWS later.
Which AWS service should the company use to meet these requirements?
B. Amazon Lightsail
Correct Answer: D
A company hosts an application on multiple Amazon EC2 instances. The application uses Amazon Simple Notification Service (Amazon SNS) to
send messages.
Which AWS service or feature will give the application permission to access required AWS services?
B. IAM roles
D. Amazon GuardDuty
Correct Answer: B
Question #193 Topic 1
A user has limited knowledge of AWS services, but wants to quickly deploy a scalable Node.js application in the AWS Cloud.
A. AWS CloudFormation
C. Amazon EC2
D. AWS OpsWorks
Correct Answer: B
A company needs a content delivery network that provides secure delivery of data, videos, applications, and APIs to users globally with low
A. Amazon CloudFront
C. Amazon S3
Correct Answer: A
Which AWS service or feature can the company use to purchase the software?
D. AWS Marketplace
Correct Answer: D
Question #196 Topic 1
A company needs fully managed, highly reliable, and scalable file storage that is accessible over the Server Message Block (SMB) protocol.
A. Amazon S3
Correct Answer: C
A company needs to centrally configure and manage Amazon VPC security groups across multiple AWS accounts within an organization in AWS
Organizations.
Which AWS service should the company use to meet these requirements?
B. Amazon GuardDuty
C. Amazon Detective
D. AWS WAF
Correct Answer: A
Which task is a responsibility of AWS, according to the AWS shared responsibility model?
Correct Answer: D
Question #199 Topic 1
A company has an Amazon EC2 instance in a private subnet. The company wants to initiate a connection to the internet to pull operating system
updates while preventing traffic from the internet from accessing the EC2 instance.
A. VPC endpoint
B. NAT gateway
C. Amazon PrivateLink
D. VPC peering
Correct Answer: B
Which actions are the responsibility of AWS, according to the AWS shared responsibility model? (Choose two.)
Correct Answer: AD
A company is storing data that will not be frequently accessed in the AWS Cloud. If the company needs to access the data, the data needs to be
retrieved within 12 hours. The company wants a solution that is cost-effective for storage costs for each gigabyte.
A. S3 Standard
Correct Answer: B
Question #202 Topic 1
Which AWS service or resource can be used to identify services that have been used by a user within a specified date range?
Correct Answer: D
A company needs to engage third-party consultants to help maintain and support its AWS environment and the company’s business needs.
A. AWS Support
B. AWS Organizations
Correct Answer: D
A company wants to create Amazon QuickSight dashboards every week by using its billing data.
Which AWS feature or tool can the company use to meet these requirements?
A. AWS Budgets
Correct Answer: C
Question #205 Topic 1
A company is planning to move data backups to the AWS Cloud. The company needs to replace on-premises storage with storage that is cloud-
B. AWS Snowcone
C. AWS Backup
Correct Answer: A
A company needs to organize its resources and track AWS costs on a detailed level. The company needs to categorize costs by business
A. Access the AWS Cost Management console to organize resources, set an AWS budget, and receive notifications of unintentional usage.
B. Use tags to organize the resources. Activate cost allocation tags to track AWS costs on a detailed level.
C. Create Amazon CloudWatch dashboards to visually organize and track costs individually.
D. Access the AWS Billing and Cost Management dashboard to organize and track resource consumption on a detailed level.
Correct Answer: B
A company needs to plan, schedule, and run hundreds of thousands of computing jobs on AWS.
Which AWS service can the company use to meet this requirement?
D. AWS Batch
Correct Answer: D
Question #208 Topic 1
Which AWS services or features provide high availability and low latency by enabling failover across different AWS Regions? (Choose two.)
A. Amazon Route 53
Correct Answer: AD
Which of the following is a way to use Amazon EC2 Auto Scaling groups to scale capacity in the AWS Cloud?
Correct Answer: A
Correct Answer: BD
Which AWS security service protects applications from distributed denial of service attacks with always-on detection and automatic inline
mitigations?
A. Amazon Inspector
D. AWS Shield
Correct Answer: D
Question #212 Topic 1
Which AWS service allows users to model and provision AWS resources using common programming languages?
A. AWS CloudFormation
B. AWS CodePipeline
Correct Answer: C
Which Amazon EC2 instance pricing model can provide discounts of up to 90%?
A. Reserved Instances
B. On-Demand
C. Dedicated Hosts
D. Spot Instances
Correct Answer: D
Which of the following acts as an instance-level firewall to control inbound and outbound access?
B. Security groups
Correct Answer: B
A company must be able to develop, test, and launch an application in the AWS Cloud quickly.
Correct Answer: D
Question #216 Topic 1
A company has teams that have different job roles and responsibilities. The company’s employees often change teams. The company needs to
manage permissions for the employees so that the permissions are appropriate for the job responsibilities.
Which IAM resource should the company use to meet this requirement with the LEAST operational overhead?
B. IAM roles
Correct Answer: B
Which AWS service can a company use to securely store and encrypt passwords for a database?
A. AWS Shield
D. Amazon Cognito
Correct Answer: B
What can a cloud practitioner use to retrieve AWS security and compliance documents and submit them as evidence to an auditor or regulator?
C. AWS Artifact
D. Amazon Inspector
Correct Answer: C
Question #219 Topic 1
Which encryption types can be used to protect objects at rest in Amazon S3? (Choose two.)
C. TLS
D. SSL
Correct Answer: AB
A company wants to integrate its online shopping website with social media login credentials.
Which AWS service can the company use to make this integration?
C. Amazon Cognito
Correct Answer: C
Which AWS service is used to track, record, and audit configuration changes made to AWS resources?
A. AWS Shield
B. AWS Config
C. AWS IAM
D. Amazon Inspector
Correct Answer: B
Question #222 Topic 1
A customer runs an On-Demand Amazon Linux EC2 instance for 3 hours, 5 minutes, and 6 seconds.
A. 3 hours, 5 minutes
C. 3 hours, 6 minutes
D. 4 hours
Correct Answer: C
Which AWS service can help protect the company website against these attacks?
B. AWS Amplify
C. AWS Shield
D. Amazon GuardDuty
Correct Answer: C
A company wants a customized assessment of its current on-premises environment. The company wants to understand its projected running
B. Amazon Inspector
D. Migration Evaluator
Correct Answer: D
Question #225 Topic 1
A company that has multiple business units wants to centrally manage and govern its AWS Cloud environments. The company wants to automate
the creation of AWS accounts, apply service control policies (SCPs), and simplify billing processes.
Which AWS service or tool should the company use to meet these requirements?
A. AWS Organizations
B. Cost Explorer
C. AWS Budgets
Correct Answer: A
A company is hosting an application in the AWS Cloud. The company wants to verify that underlying AWS services and general AWS infrastructure
Which combination of AWS services can the company use to gather the required information? (Choose two.)
Correct Answer: AD
Which AWS service or tool should the company use to meet this requirement?
Correct Answer: C
Question #228 Topic 1
A. Security validation
B. Rightsizing
C. Elasticity
D. Global reach
Correct Answer: B
A company hosts a large amount of data in AWS. The company wants to identify if any of the data should be considered sensitive.
A. Amazon Inspector
B. Amazon Macie
D. Amazon CloudWatch
Correct Answer: B
A user has a stateful workload that will run on Amazon EC2 for the next 3 years.
A. On-Demand Instances
B. Reserved Instances
C. Dedicated Instances
D. Spot Instances
Correct Answer: B
Question #231 Topic 1
Who enables encryption of data at rest for Amazon Elastic Block Store (Amazon EBS)?
A. AWS Support
B. AWS customers
Correct Answer: B
C. Assess the compliance of AWS resource configurations with policies and guidelines.
D. Ensure that Amazon EC2 instances are patched with the latest security updates.
Correct Answer: B
Which AWS service requires the company to update and patch the guest operating system?
A. Amazon DynamoDB
B. Amazon S3
C. Amazon EC2
D. Amazon Aurora
Correct Answer: C
Which AWS service or feature will search for and identify AWS resources that are shared externally?
D. AWS Fargate
Correct Answer: C
Question #235 Topic 1
A company is migrating its workloads to the AWS Cloud. The company must retain full control of patch management for the guest operating
Which AWS service should the company use to meet these requirements?
A. Amazon DynamoDB
B. Amazon EC2
C. AWS Lambda
D. Amazon RDS
Correct Answer: B
A. Basic Support
B. Developer Support
C. Business Support
D. Enterprise Support
Correct Answer: D
Which AWS service can a company use to visually design and build serverless applications?
A. AWS Lambda
B. AWS Batch
Correct Answer: C
Question #238 Topic 1
A company wants to migrate to AWS and use the same security software it uses on premises. The security software vendor offers its security
D. AWS Marketplace
Correct Answer: D
Which option is an AWS responsibility under the AWS shared responsibility model?
Correct Answer: C
A company wants to migrate its PostgreSQL database to AWS. The company does not use the database frequently.
Which AWS service or resource will meet these requirements with the LEAST management overhead?
Correct Answer: D
Question #241 Topic 1
Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Choose two.)
A. Classify data.
Correct Answer: DE
A company wants to create a globally accessible ecommerce platform for its customers. The company wants to use a highly available and
A. Amazon EC2
B. Amazon VPC
C. Amazon Route 53
D. Amazon RDS
Correct Answer: C
Which maintenance task is the customer’s responsibility, according to the AWS shared responsibility model?
Correct Answer: D
Question #244 Topic 1
A company wants to improve its security posture by reviewing user activity through API calls.
A. AWS WAF
B. Amazon Detective
C. Amazon CloudWatch
D. AWS CloudTrail
Correct Answer: D
A company is migrating to the AWS Cloud and plans to run experimental workloads for 3 to 6 months on AWS.
Correct Answer: D
A company that has AWS Enterprise Support is launching a new version of a popular product in 2 months. The company expects a large increase
Which action should the company take to assess its readiness to scale for this launch?
Correct Answer: B
Question #247 Topic 1
A company wants to launch multiple workloads on AWS. Each workload is related to a different business unit. The company wants to separate and
Which solution will meet these requirements with the LEAST operational overhead?
A. Use AWS Organizations and create one account for each business unit.
C. Use an Amazon DynamoDB table to record costs for each business unit.
D. Use the AWS Billing console to assign owners to resources and track costs.
Correct Answer: A
A company wants a time-series database service that makes it easier to store and analyze trillions of events each day.
A. Amazon Neptune
B. Amazon Timestream
C. Amazon Forecast
Correct Answer: B
Which option is a shared control between AWS and the customer, according to the AWS shared responsibility model?
A. Configuration management
Correct Answer: D
Question #250 Topic 1
A company often does not use all of its current Amazon EC2 capacity to run stateless workloads. The company wants to optimize its EC2 costs.
A. Spot Instances
B. Dedicated Instances
C. Reserved Instances
D. On-Demand Instances
Correct Answer: A
A company wants to store data in Amazon S3. The company rarely access the data, and the data can be regenerated if necessary. The company
A. S3 Standard
B. S3 Intelligent-Tiering
Correct Answer: D
A company has migrated its workloads to AWS. The company wants to adopt AWS at scale and operate more efficiently and securely. Which AWS
A. AWS Support
Correct Answer: D