AWS cloud practitioner prep
AWS cloud practitioner prep
QUESTION #2
QUESTION #3
A. Hard code an IAM user’s secret key and access key directly in the
application, and upload the file.
B. Store the IAM user’s secret key and access key in a text file on the
EC2 instance, read the keys, then upload the file.
C. Have the EC2 instance assume a role to obtain the privileges to
upload the file.
D. Modify the S3 bucket policy so that any service can upload to it at any
time.
QUESTION #5
QUESTION #6
A. Sustainability
B. Performance efficiency
C. Governance
D. Reliability
QUESTION #7
QUESTION #8
QUESTION #9
Which AWS services or tools can identify rightsizing opportunities for Amazon
EC2 instances? (Choose two.)
QUESTION #10
Which of the following are benefits of using AWS Trusted Advisor? (Choose
two.)
QUESTION #12
QUESTION #13
Which AWS service or tool helps users visualize, understand, and manage
spending and usage over time?
A. AWS Organizations
B. AWS Pricing Calculator
C. AWS Cost Explorer
D. AWS Service Catalog
QUESTION #14
QUESTION #15
A. AWS Support
B. AWS Professional Services
C. AWS Launch Wizard
D. AWS Managed Services (AMS)
QUESTION #16
A. Reserved Instances
B. Dedicated Hosts
C. Spot Instances
D. On-Demand Instances
QUESTION #17
A. Amazon EC2
B. AWS Elastic Beanstalk
C. AWS CodeBuild
D. Amazon Personalize
QUESTION #18
A. S3 Lifecycle rules
B. S3 Versioning
C. S3 bucket policies
D. S3 server-side encryption
QUESTION #19
A. AWS CodePipeline
B. AWS CodeDeploy
C. AWS Direct Connect
D. AWS CloudFormation
QUESTION #20
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Spot Fleet
QUESTION #21
QUESTION #22
A. AWS DataSync
B. AWS Region
C. Amazon Connect
D. AWS Organizations
QUESTION #23
A company wants to protect its AWS Cloud information, systems, and assets
while performing risk assessment and mitigation tasks.
Which pillar of the AWS Well-Architected Framework is supported by these
goals?
A. Reliability
B. Security
C. Operational excellence
D. Performance efficiency
QUESTION #24
QUESTION #26
A company has an AWS account. The company wants to audit its password
and access key rotation details for compliance purposes.
Which AWS service or tool will meet this requirement?
QUESTION #27
QUESTION #28
Which AWS service or resource provides answers to the most frequently
asked security-related questions that AWS receives from its users?
A. AWS Artifact
B. Amazon Connect
C. AWS Chatbot
D. AWS Knowledge Center
QUESTION #29
QUESTION #30
A. Availability
B. Reliability
C. Scalability
D. Responsive design
E. Operational excellence
QUESTION #31
Which AWS service or feature is used to send both text and email messages
from distributed applications?
A user needs programmatic access to AWS resources through the AWS CLI or
the AWS API.
Which option will provide the user with the appropriate access?
A. Amazon Inspector
B. Access keys
C. SSH public keys
D. AWS Key Management Service (AWS KMS) keys
QUESTION #33
A. Reserved Instances
B. Spot Instances
C. On-Demand Instances
D. Dedicated Instances
QUESTION #34
What does the concept of agility mean in AWS Cloud computing? (Choose
two.)
QUESTION #35
QUESTION #36
QUESTION #37
QUESTION #38
QUESTION #39
A company is setting up AWS Identity and Access Management (IAM) on an
AWS account.
Which recommendation complies with IAM security best practices?
A. Use the account root user access keys for administrative tasks.
B. Grant broad permissions so that all company employees can access
the resources they need.
C. Turn on multi-factor authentication (MFA) for added security during
the login process.
D. Avoid rotating credentials to prevent issues in production applications.
QUESTION #40
Elasticity in the AWS Cloud refers to which of the following? (Choose two.)
QUESTION #41
Which service enables customers to audit API calls in their AWS accounts?
A. AWS CloudTrail
B. AWS Trusted Advisor
C. Amazon Inspector
D. AWS X-Ray
QUESTION #42
A. Amazon Redshift
B. Amazon Athena
C. Amazon Kinesis
D. Amazon RDS
QUESTION #44
A. Amazon SageMaker
B. AWS Config
C. AWS Organizations
D. Amazon CloudWatch
QUESTION #45
Which AWS Cloud Adoption Framework (AWS CAF) capability belongs to the
people perspective?
A. Data architecture
B. Event management
C. Cloud fluency
D. Strategic partnership
QUESTION #46
QUESTION #47
A. Amazon Connect
B. AWS Wavelength
C. AWS Regions
D. AWS Direct Connect
QUESTION #48
A company is exploring the use of the AWS Cloud, and needs to create a cost
estimate for a project before the infrastructure is provisioned.
Which AWS service or feature can be used to estimate costs before
deployment?
QUESTION #49
QUESTION #50
QUESTION #51
A. AWS CLI
B. AWS Developer Center
C. AWS Cloud Development Kit (AWS CDK)
D. AWS CodeStar
QUESTION #52
QUESTION #54
A. Amazon S3
B. AWS Identity and Access Management (IAM)
C. Elastic Load Balancers
D. AWS WAF
QUESTION #55
A. Amazon Redshift
B. Amazon Aurora
C. Amazon DynamoDB
D. Amazon RDS
QUESTION #56
QUESTION #57
A. On-Demand Instances
B. Dedicated Instances
C. Spot Instances
D. Reserved Instances
QUESTION #58
Which AWS service gives users the ability to discover and protect sensitive
data that is stored in Amazon S3 buckets?
A. Amazon Macie
B. Amazon Detective
C. Amazon GuardDuty
D. AWS IAM Access Analyzer
QUESTION #59
A. Security groups
B. Amazon Virtual Private Cloud (Amazon VPC) flow logs
C. Network ACLs
D. Amazon CloudWatch
E. AWS CloudTrail
QUESTION #60
Which AWS service can identify when an Amazon EC2 instance was
terminated?
QUESTION #61
A. Amazon S3
B. Amazon DynamoDB
C. Amazon Redshift
D. Amazon Aurora
QUESTION #62
Which AWS service supports a hybrid architecture that gives users the ability
to extend AWS infrastructure, AWS services, APIs, and tools to data centers,
co-location environments, or on-premises facilities?
A. AWS Snowmobile
B. AWS Local Zones
C. AWS Outposts
D. AWS Fargate
QUESTION #63
Which AWS service can run a managed PostgreSQL database that provides
online transaction processing (OLTP)?
A. Amazon DynamoDB
B. Amazon Athena
C. Amazon RDS
D. Amazon EMR
QUESTION #64
A. Amazon Connect
B. Amazon AppStream 2.0
C. Amazon WorkSpaces
D. AWS Site-to-Site VPN
E. Amazon Elastic Container Service (Amazon ECS)
QUESTION #65
QUESTION #66
A. Amazon DynamoDB
B. Amazon Aurora
C. Amazon DocumentDB (with MongoDB compatibility)
D. Amazon Neptune
QUESTION #67
A. On-Demand Instances
B. Spot Instances
C. Reserved Instances
D. Dedicated Instances
QUESTION #68
QUESTION #69
Which AWS service provides command line access to AWS tools and
resources directly from a web browser?
A. AWS CloudHSM
B. AWS CloudShell
C. Amazon WorkSpaces
D. AWS Cloud Map
QUESTION #70
A. VPC endpoints
B. AWS Transit Gateway
C. Amazon Route 53
D. AWS Secrets Manager
QUESTION #71
QUESTION #72
QUESTION #73
A. Amazon Route 53
B. Amazon Macie
C. AWS Direct Connect
D. AWS PrivateLink
QUESTION #74
QUESTION #75
QUESTION #76
Which of the following are advantages of the AWS Cloud? (Choose two.)
QUESTION #77
A. Agility
B. Elasticity
C. Scalability
D. High availability
QUESTION #78
QUESTION #79
QUESTION #80
Which AWS service helps deliver highly available applications with fast
failover for multi-Region and Multi-AZ architectures?
A. AWS WAF
B. AWS Global Accelerator
C. AWS Shield
D. AWS Direct Connect
QUESTION #81
QUESTION #82
What are the benefits of consolidated billing for AWS Cloud services?
(Choose two.)
A. Volume discounts
B. A minimal additional fee for use
C. One bill for multiple accounts
D. Installment payment options
E. Custom cost and usage budget creation
QUESTION #83
A user wants to review all Amazon S3 buckets with ACLs and S3 bucket
policies in the S3 console.
Which AWS service or resource will meet this requirement?
QUESTION #84
A. AWS Artifact
B. AWS Marketplace
C. Amazon Inspector
D. AWS Support
QUESTION #85
Which AWS service enables companies to deploy an application close to end
users?
A. Amazon CloudFront
B. AWS Auto Scaling
C. AWS AppSync
D. Amazon Route 53
QUESTION #86
A. Route table
B. AWS Transit Gateway
C. AWS Global Accelerator
D. Amazon VPC
QUESTION #87
A. Amazon S3
B. Amazon Elastic File System (Amazon EFS)
C. Amazon Elastic Block Store (Amazon EBS)
D. Amazon FSx
QUESTION #88
A. Database backups
B. Database software patches
C. Operating system patches
D. Operating system installations
QUESTION #89
Which of the following are advantages of moving to the AWS Cloud? (Choose
two.)
A. The ability to turn over the responsibility for all security to AWS.
B. The ability to use the pay-as-you-go model.
C. The ability to have full control over the physical infrastructure.
D. No longer having to guess what capacity will be required.
E. No longer worrying about users access controls.
QUESTION #90
Which AWS service is a hybrid cloud storage service that provides on-
premises users access to virtually unlimited cloud storage?
A. AWS DataSync
B. Amazon S3 Glacier
C. AWS Storage Gateway
D. Amazon Elastic Block Store (Amazon EBS)
QUESTION #91
A company plans to migrate to AWS and wants to create cost estimates for
its AWS use cases.
Which AWS service or tool can the company use to meet these
requirements?
QUESTION #92
Which tool should a developer use to integrate AWS service features directly
into an application?
QUESTION #94
Using AWS Identity and Access Management (IAM) to grant access only to
the resources needed to perform a task is a concept known as:
A. restricted access.
B. as-needed access.
C. least privilege access.
D. token access.
QUESTION #95
Which AWS service or tool can be used to set up a firewall to control traffic
going into and coming out of an Amazon VPC subnet?
A. Security group
B. AWS WAF
C. AWS Firewall Manager
D. Network ACL
QUESTION #96
A. Amazon Aurora
B. Amazon Redshift Serverless
C. AWS Lambda
D. Amazon RDS
QUESTION #97
How does AWS Cloud computing help businesses reduce costs? (Choose
two.)
A. AWS charges the same prices for services in every AWS Region.
B. AWS enables capacity to be adjusted on demand.
C. AWS offers discounts for Amazon EC2 instances that remain idle for
more than 1 week.
D. AWS does not charge for data sent from the AWS Cloud to the
internet.
E. AWS eliminates many of the costs of building and maintaining on-
premises data centers.
QUESTION #98
A. IAM group
B. IAM role
C. IAM tag
D. IAM Access Analyzer
QUESTION #99
QUESTION #100
A company wants to automate infrastructure deployment by using
infrastructure as code (IaC). The company wants to scale production stacks
so the stacks can be deployed in multiple AWS Regions.
Which AWS service will meet these requirements?
A. Amazon CloudWatch
B. AWS Config
C. AWS Trusted Advisor
D. AWS CloudFormation
QUESTION #101
A. Data architecture
B. Data protection
C. Data governance
D. Data science
QUESTION #102
A. Loose coupling
B. Rightsizing
C. Caching
D. Redundancy
QUESTION #103
QUESTION #104
Which AWS tool gives users the ability to plan their service usage, service
costs, and instance reservations, and also allows them to set custom alerts
when their costs or usage exceed established thresholds?
A. Cost Explorer
B. AWS Budgets
C. AWS Cost and Usage Report
D. Reserved Instance reporting
QUESTION #105
Which tasks are the customer’s responsibility, according to the AWS shared
responsibility model? (Choose two.)
QUESTION #106
A developer has been hired by a large company and needs AWS credentials.
Which are security best practices that should be followed? (Choose two.)
A company has multiple AWS accounts that include compute workloads that
cannot be interrupted. The company wants to obtain billing discounts that
are based on the company’s use of AWS services.
Which AWS feature or purchasing option will meet these requirements?
A. Resource tagging
B. Consolidated billing
C. Pay-as-you-go pricing
D. Spot Instances
QUESTION #108
A. Security groups
B. AWS Firewall Manager
C. IAM roles
D. IAM user SSH keys
QUESTION #109
A company wants a fully managed Windows file server for its Windows-based
applications.
Which AWS service will meet this requirement?
A. Amazon FSx
B. Amazon Elastic Kubernetes Service (Amazon EKS)
C. Amazon Elastic Container Service (Amazon ECS)
D. Amazon EMR
QUESTION #110
QUESTION #111
A company needs to track the activity in its AWS accounts, and needs to
know when an API call is made against its AWS resources.
Which AWS tool or service can be used to meet these requirements?
A. Amazon CloudWatch
B. Amazon Inspector
C. AWS CloudTrail
D. AWS IAM
QUESTION #112
A. Spot Instances
B. On-Demand Instances
C. Savings Plans
D. Dedicated Hosts
QUESTION #113
A. Amazon Polly
B. Amazon Personalize
C. Amazon Comprehend
D. Amazon Rekognition
QUESTION #114
A. Envision
B. Align
C. Scale
D. Launch
QUESTION #115
A social media company wants to protect its web application from common
web exploits such as SQL injections and cross-site scripting.
Which AWS service will meet these requirements?
A. Amazon Inspector
B. AWS WAF
C. Amazon GuardDuty
D. Amazon CloudWatch
QUESTION #116
Which fully managed AWS service assists with the creation, testing, and
management of custom Amazon EC2 images?
QUESTION #117
QUESTION #118
A. AWS Lambda
B. Amazon EC2
C. AWS CodeDeploy
D. AWS Wavelength
QUESTION #119
Which AWS service or feature provides log information of the inbound and
outbound traffic on network interfaces in a VPC?
QUESTION #120
QUESTION #121
A company plans to deploy containers on AWS. The company wants full
control of the compute resources that host the containers. Which AWS
service will meet these requirements?
QUESTION #122
Which AWS service or feature allows users to create new AWS accounts,
group multiple accounts to organize workflows, and apply policies to groups
of accounts?
QUESTION #123
A company wants to store and retrieve files in Amazon S3 for its existing on-
premises applications by using industry-standard file system protocols.
Which AWS service will meet these requirements?
A. AWS DataSync
B. AWS Snowball Edge
C. Amazon S3 File Gateway
D. AWS Transfer Family
QUESTION #124
A. AWS WAF
B. Network ACLs
C. Security groups
D. AWS Certificate Manager (ACM)
QUESTION #125
A. AWS CLI
B. Amazon Elastic Container Service (Amazon ECS)
C. AWS Cloud9
D. AWS Virtual Private Network (AWS VPN)
QUESTION #126
A company needs to evaluate its AWS environment and provide best practice
recommendations in five categories: cost, performance, service limits, fault
tolerance and security.
Which AWS service can the company use to meet these requirements?
A. AWS Shield
B. AWS WAF
C. AWS Trusted Advisor
D. AWS Service Catalog
QUESTION #127
A. Platform
B. Operations
C. Security
D. Governance
QUESTION #128
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Saving Plans
E. Dedicated Hosts
QUESTION #129
Which Amazon EC2 pricing model is the MOST cost efficient for an
uninterruptible workload that runs once a year for 24 hours?
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Dedicated Instances
QUESTION #130
QUESTION #131
A. Placement groups
B. Consolidated billing
C. Edge locations
D. AWS Config
E. Multiple AWS accounts
QUESTION #132
A. Enable client-side encryption for objects that are stored in Amazon S3.
B. Configure IAM security policies to comply with the principle of least
privilege.
C. Patch the guest operating system on an Amazon EC2 instance.
D. Apply updates to the Nitro Hypervisor.
QUESTION #133
QUESTION #134
A. Culture evolution
B. Event management
C. Data monetization
D. Platform architecture
QUESTION #135
QUESTION #136
Which pricing model will interrupt a running Amazon EC2 instance if capacity
becomes temporarily unavailable?
A. On-Demand Instances
B. Standard Reserved Instances
C. Spot Instances
D. Convertible Reserved Instances
QUESTION #137
Which options are AWS Cloud Adoption Framework (AWS CAF) security
perspective capabilities? (Choose two.)
A. Observability
B. Incident and problem management
C. Incident response
D. Infrastructure protection
E. Availability and continuity
QUESTION #138
A company wants to run its workload on Amazon EC2 instances for more
than 1 year. This workload will run continuously.
Which option offers a discounted hourly rate compared to the hourly rate of
On-Demand Instances?
QUESTION #139
A. Agility
B. Elasticity
C. Reliability
D. Durability
QUESTION #140
A. Amazon WorkSpaces
B. Amazon Simple Queue Service (Amazon SQS)
C. Amazon Connect
D. AWS Trusted Advisor
E. AWS Step Functions
QUESTION #141
Which AWS Cloud service can send alerts to customers if custom spending
thresholds are exceeded?
A. AWS Budgets
B. AWS Cost Explorer
C. AWS Cost Allocation Tags
D. AWS Organizations
QUESTION #142
A company plans to migrate to the AWS Cloud. The company wants to use
the AWS Cloud Adoption Framework (AWS CAF) to define and track business
outcomes as part of its cloud transformation journey.
A. Benefits management
B. Risk management
C. Application portfolio management
D. Cloud financial management
QUESTION #143
A company needs to quickly and securely move files over long distances
between its client and an Amazon S3 bucket.
A. S3 Versioning
B. S3 Transfer Acceleration
C. S3ACLs
D. S3 Intelligent-Tiering
QUESTION #144
Which instance purchasing option will meet this requirement MOST cost-
effectively?
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Dedicated Instances
QUESTION #145
QUESTION #146
QUESTION #147
QUESTION #148
A. Rehost
B. Replatform
C. Repurchase
D. Refactor
QUESTION #149
QUESTION #150
A. Amazon CloudFront
B. Availability Zone
C. VPC
D. AWS Outposts
QUESTION #151
Which AWS service or resource should the company use to meet these
requirements?
A. AWS Snowmobile
B. AWS Snowball Edge
C. AWS Data Exchange
D. AWS Database Migration Service (AWS DMS)
QUESTION #152
A company has an application with robust hardware requirements. The
application must be accessed by students who are using lightweight, low-
cost laptops.
Which AWS service will help the company deploy the application without
investing in backend infrastructure or high-end client hardware?
QUESTION #153
A company wants to query its server logs to gain insights about its
customers’ experiences.
A. Amazon Aurora
B. Amazon Elastic File System (Amazon EFS)
C. Amazon Elastic Block Store (Amazon EBS)
D. Amazon S3
QUESTION #154
QUESTION #155
Which AWS service helps users audit API activity across their AWS account?
A. AWS CloudTrail
B. Amazon Inspector
C. AWS WAF
D. AWS Config
QUESTION #156
QUESTION #157
A COMPANY WANTS TO AUTOMATICALLY ADD AND REMOVE AMAZON EC2 INSTANCES. THE
COMPANY WANTS THE EC2 INSTANCES TO ADJUST TO VARYING WORKLOADS
DYNAMICALLY.
A. Amazon DynamoDB
B. Amazon EC2 Spot Instances
C. AWS Snow Family
D. Amazon EC2 Auto Scaling
QUESTION #158
A. AWS CloudHSM
B. AWS Key Management Service (AWS KMS)
C. AWS Secrets Manager
D. Server-side encryption
QUESTION #159
A. Amazon GuardDuty
B. Amazon Macie
C. Amazon Inspector
D. AWS Shield
QUESTION #160
Which actions are best practices for an AWS account root user? (Choose
two.)
QUESTION #161
QUESTION #162
A company plans to migrate its application to AWS and run the application
on Amazon EC2 instances. The application will have continuous usage for 1
year.
Which EC2 instance purchasing option will meet these requirements MOST
cost-effectively?
A. Reserved Instances
B. Spot Instances
C. On-Demand Instances
D. Dedicated Hosts
QUESTION #163
Who is responsible for the security of this data, according to the AWS shared
responsibility model?
A. The company
B. AWS
C. Firewall vendor
D. AWS Marketplace partner
QUESTION #164
A. Security
B. Reliability
C. Performance efficiency
D. Cost optimization
QUESTION #165
QUESTION #166
Which AWS service gives users the ability to build interactive business
intelligence dashboards that include machine learning insights?
A. Amazon Athena
B. Amazon Kendra
C. Amazon QuickSight
D. Amazon Redshift
QUESTION #167
A. Speed of innovation
B. Resource elasticity
C. Decoupled architecture
D. Global deployment
QUESTION #168
Which action is a security best practice for access to sensitive data that is
stored in an Amazon S3 bucket?
QUESTION #170
A company needs a central user portal so that users can log in to third-party
business applications that support Security Assertion Markup Language
(SAML) 2.0.
QUESTION #171
Which AWS service should users use to learn about AWS service availability
and operations?
A. Amazon EventBridge
B. AWS Service Catalog
C. AWS Control Tower
D. AWS Health Dashboard
QUESTION #172
Which AWS service or tool can be used to capture information about inbound
and outbound traffic in an Amazon VPC?
QUESTION #173
A. Software licenses
B. Networking
C. Customer data
D. Encryption keys
QUESTION #174
QUESTION #175
Which AWS service enables users to check for vulnerabilities on Amazon EC2
instances by using predefined assessment templates?
A. AWS WAF
B. AWS Trusted Advisor
C. Amazon Inspector
D. AWS Shield
QUESTION #176
A company plans to migrate to the AWS Cloud. The company is gathering
information about its on-premises infrastructure and requires information
such as the hostname, IP address, and MAC address.
A. AWS DataSync
B. AWS Application Migration Service
C. AWS Application Discovery Service
D. AWS Database Migration Service (AWS DMS)
QUESTION #177
QUESTION #178
Which AWS tool or set of resources should the company use to analyze and
assess its readiness for migration?
QUESTION #179
QUESTION #180
A. High availability
B. Economies of scale
C. Pay-as-you-go pricing
D. Global reach
QUESTION #171
Which AWS service should users use to learn about AWS service availability
and operations?
A. Amazon EventBridge
QUESTION #172
Which AWS service or tool can be used to capture information about inbound
and outbound traffic in an Amazon VPC?
D. NAT gateway
QUESTION #173
What is the customer ALWAYS responsible for managing, according to the
AWS shared responsibility model?
A. Software licenses
B. Networking
C. Customer data
D. Encryption keys
QUESTION #174
Which AWS service can be used to retrieve compliance reports on demand?
B. AWS Artifact
QUESTION #175
Which AWS service enables users to check for vulnerabilities on Amazon EC2
instances by using predefined assessment templates?
A. AWS WAF
C. Amazon Inspector
D. AWS Shield
QUESTION #176
A company plans to migrate to the AWS Cloud. The company is gathering
information about its on-premises infrastructure and requires information
such as the hostname, IP address, and MAC address.
A. AWS DataSync
QUESTION #177
Which action will help increase security in the AWS Cloud?
QUESTION #178
A company is planning to migrate its application to the AWS Cloud.
Which AWS tool or set of resources should the company use to analyze and
assess its readiness for migration?
D. AWS Budgets
QUESTION #179
Which of the following describes some of the core functionality of Amazon
S3?
D. Amazon S3 is a scalable, fully managed elastic NFS for use with AWS
Cloud services and on-premises resources.
QUESTION #180
Which AWS benefit is demonstrated by on-demand technology services that
enable companies to replace upfront fixed expenses with variable expenses?
A. High availability
B. Economies of scale
C. Pay-as-you-go pricing
D. Global reach