Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Cloud Practitioner Q2

Total questions: 66

Worksheet time: 1hrs 6mins

Name
Class
Date
1.

#1 According to the shared responsibility mode, which security and compliance task is AWS responsible for?

a)

Granting permissions to users and services

b)

Updating Amazon EC2 host firmware

c)

Encrypting data at rest

d)

Updating operating systems

2.

#2 A Cloud Practitioner noticed that IP addresses that are owned by AWS are being used to attempt to flood ports on some of the company’s systems.

a)

AWS Professional Services

b)

AWS Partner Network (APN)

c)

AWS Trust & Safety team

d)

AWS Technical Account Manager (TAM)

3.

#3 What can be used to allow an application running on an Amazon EC2 instance to securely store data in an Amazon S3 bucket without using long-term credentials?

a)

AWS Systems Manager

b)

Amazon Connect

c)

AWS IAM role

d)

AWS IAM access key

4.

#4 Which AWS service does AWS Snowball Edge natively support?

a)

AWS Server Migration Service (AWS SMS)

b)

AWS Database Migration Service (AWS DMS)

c)

AWS Trusted Advisor

d)

Amazon EC2

5.

#5 AWS are able to continue to reduce their pricing due to:

a)

Pay-as-you go pricing

b)

The AWS global infrastructure

c)

Economies of scale

d)

Reserved instance pricing

6.

#6 According to the AWS shared responsibility model, which task is the customer's responsibility?

a)

Maintaining the infrastructure needed to run Amazon DynamoDB.

b)

Updating the operating system of AWS Lambda instances.

c)

Maintaining Amazon API Gateway infrastructure.

d)

Updating the guest operating system on Amazon EC2 instances.

7.

#7 A Cloud Practitioner noticed that IP addresses that are owned by AWS are being used to attempt to flood ports on some of the company’s systems. To whom should the issue be reported?

a)

AWS Professional Services

b)

AWS Partner Network (APN)

c)

AWS Trust & Safety team

d)

AWS Technical Account Manager (TAM)

8.

#8 Which on-premises costs must be included in a Total Cost of Ownership (TCO) calculation when comparing against the AWS Cloud? (Select TWO.)

a)

Physical compute hardware

b)

Operating system administration

c)

Network infrastructure in the data center

d)

Project management services

e)

Database schema development

9.

#9 Which of the following can be used to identify a specific user who terminated an Amazon RDS DB instance

a)

AWS CloudTrail

b)

Amazon Inspector

c)

Amazon CloudWatch

d)

AWS Trusted Advisor

10.

#10 Which AWS service can be used to perform data extract, transform, and load (ETL) operations so you can prepare data for analytics?

a)

Amazon QuickSight

b)

AWS Glue

c)

Amazon Athena

d)

Amazon S3 Select

11.

#11 Which of the following tasks can a user perform to optimize Amazon EC2 costs? (Select TWO.)

a)

Implement Auto Scaling groups to add and remove instances based on demand.

b)

Create a policy to restrict IAM users from accessing the Amazon EC2 console.

c)

Set a budget to limit spending on Amazon EC2 instances using AWS Budgets.

d)

Purchase Amazon EC2 Reserved Instances

e)

Create users in a single Region to reduce the spread of EC2 instances globally.

12.

# 12 According to the shared responsibility model, which security-related task is the responsibility of the customer?

a)

Maintaining server-side encryption

b)

Securing servers and racks at AWS data centers

c)

Maintaining firewall configurations at a hardware level.

d)

Maintaining physical networking configuration.

13.

#13 A company plan to move the application development to AWS. Which benefits can they achieve when developing and running applications in the AWS Cloud compared to on-premises? (Select TWO.)

a)

AWS automatically replicates all data globally

b)

AWS will fully manage the entire application.

c)

AWS makes it easy to implement high availability

d)

AWS can accommodate large changes in application demand.

e)

AWS takes care of application security patching.

14.

#14 Which AWS services offer compute capabilities? (Select TWO.)

a)

Amazon DynamoDB

b)

Amazon ECS

c)

Amazon EFS

d)

Amazon CloudHSM

e)

AWS Lambda

15.

#15 A cloud practitioner needs to migrate a 70 TB of data from an on-premises data center into the AWS Cloud. The company has a slow and unreliable internet connection. Which AWS service can the cloud practitioner leverage to transfer the data?

a)

Amazon S3 Glacier

b)

AWS Snowball

c)

AWS Storage Gateway

d)

AWS DataSync

16.

#16 Which AWS service is a fully-managed source control service that hosts secure Git-based repositories?

a)

AWS CodeBuild

b)

AWS CodeDeploy

c)

AWS CodeCommit

d)

AWS CodePipeline

17.

#17 A Cloud Practitioner is re-architecting a monolithic application. Which design principles for cloud architecture do AWS recommend? (Select TWO.)

a)

Implement manual scalability.

b)

Implement loose coupling.

c)

Use self-managed servers

d)

Rely on individual components

e)

Design for scalability.

18.

#18 Which of the following a valid best practices for using the AWS Identity and Access Management (IAM) service? (Select TWO.)

a)

Embed access keys in application code.

b)

Create individual IAM users

c)

Use inline policies instead of customer managed policies

d)

Use groups to assign permissions to IAM users.

e)

Grant maximum privileges to IAM users.

19.

#19 Which benefit of AWS enables companies to replace upfront fixed expenses with variable expenses when using on-demand technology services?

a)

Pay-as-you-go pricing

b)

Economies of scale

c)

Global reach

d)

High availability

20.

#20 A Service Control Policy (SCP) is used to manage the maximum available permissions and is associated with which of the following? Service control policies (SCPs) manage permissions for which of the following?

a)

AWS Global Infrastructure

b)

AWS Regions

c)

AWS Organizations

d)

Availability Zones

21.

#21 What should a Cloud Practitioner ensure when designing a highly available architecture on AWS?

a)

Servers have low-latency and high throughput network connectivity.

b)

The failure of a single component should not affect the application.

c)

There are enough servers to run at peak load available at all times.

d)

A single monolithic application component handles all operations.

22.

#22 Which technology can automatically adjust compute capacity as demand for an application increases or decreases?

a)

Load balancing

b)

Auto Scaling

c)

Fault tolerance

d)

High availability

23.

#23 Which of the following is an advantage for a company running workloads in the AWS Cloud vs on-premises? (Select TWO.)

a)

Less staff time is required to launch new workloads.

b)

Increased time to market for new application features

c)

Higher acquisition costs to support elastic workloads.

d)

Lower overall utilization of server and storage systems

e)

Increased productivity for application development teams.

24.

#24 Which cloud architecture design principle is supported by deploying workloads across multiple Availability Zones?

a)

Automate infrastructure

b)

Design for agility

c)

Enable elasticity

d)

Design for failure

25.

#25 A company requires a dashboard for reporting when using a business intelligence solution. Which AWS service can a Cloud Practitioner use?

a)

Amazon Redshift

b)

Amazon Kinesis

c)

Amazon Athena

d)

Amazon QuickSight

26.

#26 A Cloud Practitioner wants to configure the AWS CLI for programmatic access to AWS services. Which credential components are required? (Select TWO.)

a)

An access key ID

b)

A public key

c)

A secret access key

d)

An IAM Role

e)

A private key

27.

#27 Which service can a Cloud Practitioner use to configure custom cost and usage limits and enable alerts for when defined thresholds are exceeded?

a)

Consolidated billing

b)

AWS Trusted Advisor

c)

Cost Explorer

d)

AWS Budgets

28.

#28 What is the function of Amazon EC2 Auto Scaling?

a)

Scales the size of EC2 instances up or down automatically, based on demand

b)

Automatically updates the EC2 pricing model, based on demand

c)

Scales the number of EC2 instances in or out automatically, based on demand.

d)

Automatically modifies the network throughput of EC2 instances, based on demand.

29.

#29 Which AWS service should a Cloud Practitioner use to establish a secure network connection between an on-premises network and AWS

a)

AWS Mobile Hub

b)

AWS Web Application Firewall (WAF)

c)

Amazon Virtual Private Cloud (VPC)

d)

Virtual Private Network

30.

#30 Which AWS-managed service can be used to process vast amounts of data using a hosted Hadoop framework?

a)

Amazon DynamoDB

b)

Amazon Athena

c)

Amazon EMR

d)

Amazon Redshift

31.

#31 Which Amazon EC2 pricing model should be avoided if a workload cannot accept interruption if capacity becomes temporarily unavailable?

a)

Spot Instances

b)

On-Demand Instances

c)

Standard Reserved Instances

d)

Convertible Reserved Instances

32.

#32 A Cloud Practitioner requires a simple method to identify if unrestricted access to resources has been allowed by security groups. Which service can the Cloud Practitioner use?

a)

AWS Trusted Advisor

b)

Amazon CloudWatch

c)

VPC Flow Logs

d)

AWS CloudTrail

33.

#33 An eCommerce company plans to use the AWS Cloud to quickly deliver new functionality in an iterative manner, minimizing the time to market. Which feature of the AWS Cloud provides this functionality?

a)

Elasticity

b)

Agility

c)

Fault tolerance

d)

Cost effectiveness

34.

#34 What can a Cloud Practitioner do with the AWS Cost Management tools? (Select TWO.)

a)

Visualize AWS costs by day, service, and linked AWS account

b)

Terminate EC2 instances automatically if budget thresholds are exceeded.

c)

Automatically modify EC2 instances to use Spot pricing to reduce costs

d)

Create budgets and receive notifications if current or forecasted usage exceeds the budgets.

35.

#35 Which AWS dashboard displays relevant and timely information to help users manage events in progress, and provides proactive notifications to help plan for scheduled activities?

a)

AWS Service Health Dashboard

b)

AWS Personal Health Dashboard

c)

AWS Trusted Advisor dashboard

d)

Amazon CloudWatch dashboard

36.

#36 Which AWS service should a Cloud Practitioner use to automate configuration management using Puppet?

a)

AWS Config

b)

AWS OpsWorks

c)

AWS CloudFormation

d)

AWS Systems Manager

37.

#37 Which AWS service is used to send both text and email messages from distributed applications?

a)

Amazon Simple Notification Service (Amazon SNS)

b)

Amazon Simple Email Service (Amazon SES)

c)

Amazon Simple Workflow Service (Amazon SWF)

d)

Amazon Simple Queue Service (Amazon SQS)

38.

#38 Which AWS service or feature allows a company to receive a single monthly AWS bill when using multiple AWS accounts?

a)

Consolidated billing

b)

Amazon Cloud Directory

c)

AWS Cost Explorer

d)

AWS Cost and Usage report

39.

#39 A user needs an automated security assessment report that will identify unintended network access to Amazon EC2 instances and vulnerabilities on those instances. Which AWS service will provide this assessment report?

a)

EC2 security groups

b)

AWS Config

c)

Amazon Macie

d)

Amazon Inspector

40.

Which of the following best describes an Availability Zone in the AWS Cloud?

a)

One or more physical data centers

b)

A completely isolated geographic location

c)

One or more edge locations based around the world

d)

A subnet for deploying resources into

41.

#43 A company needs a consistent and dedicated connection between AWS resources and an on-premise system. Which AWS service can fulfil this requirement?

a)

AWS Direct Connect

b)

AWS Managed VPN

c)

Amazon Connect

d)

AWS DataSync

42.

#42 Which AWS service helps customers meet corporate, contractual, and regulatory compliance requirements for data security by using dedicated hardware appliances within the AWS Cloud?

a)

AWS Secrets Manager

b)

AWS CloudHSM

c)

AWS Key Management Service (AWS KMS)

d)

AWS Directory Service

43.

#43 What can a Cloud Practitioner use the AWS Total Cost of Ownership (TCO) Calculator for?

a)

Generate reports that break down AWS Cloud compute costs by duration, resource, or tags

b)

Estimate savings when comparing the AWS Cloud to an on-premises environment

c)

Estimate a monthly bill for the AWS Cloud resources that will be used

d)

Enable billing alerts to monitor actual AWS costs compared to estimated costs

44.

#44 Which of the following should be used to improve the security of access to the AWS Management Console? (Select TWO.)

a)

AWS Secrets Manager

b)

AWS Certificate Manager

c)

AWS Multi-Factor Authentication (AWS MFA)

d)

Security group rules

e)

Strong password policies

45.

#45 An application has highly dynamic usage patterns. Which characteristics of the AWS Cloud make it cost-effective for this type of workload? (Select TWO.)

a)

High availability

b)

Strict security

c)

Elasticity

d)

Pay-as-you-go pricing

e)

Reliability

46.

#46 Which benefits can a company immediately realize using the AWS Cloud? (Select TWO.)

a)

Variable expenses are replaced with capital expenses

b)

Capital expenses are replaced with variable expenses

c)

User control of physical infrastructure

d)

Increased agility

e)

No responsibility for security

47.

#47 Which AWS hybrid storage service enables a user’s on-premises applications to seamlessly use AWS Cloud storage?

a)

AWS Backup

b)

Amazon Connect

c)

AWS Direct Connect

d)

AWS Storage Gateway

48.

#48 A user has limited knowledge of AWS services, but wants to quickly deploy a scalable Node.js application in an Amazon VPC. Which service should be used to deploy the application?

a)

AWS CloudFormation

b)

AWS Elastic Beanstalk

c)

Amazon EC2

d)

Amazon LightSail

49.

#49 How can a security compliance officer retrieve AWS compliance documentation such as a SOC 2 report?

a)

Using AWS Artifact

b)

Using AWS Trusted Advisor

c)

Using AWS Inspector

d)

Using the AWS Personal Health Dashboard

50.

#50 Which AWS service can be used to run Docker containers?

a)

AWS Lambda

b)

Amazon ECR

c)

Amazon ECS

d)

Amazon AMI

51.

#51 What are the benefits of using the AWS Managed Services? (Select TWO.)

a)

Alignment with ITIL processes

b)

Managed applications so you can focus on infrastructure

c)

Baseline integration with ITSM tools

d)

Designed for small businesses

e)

Support for all AWS services

52.

#52 Which services are involved with security? (Select TWO.)

a)

AWS CloudHSM

b)

AWS DMS

c)

AWS KMS

d)

AWS SMS

e)

Amazon ELB

53.

#53 What are the names of two types of AWS Storage Gateway? (Select TWO.)

a)

S3 Gateway

b)

File Gateway

c)

Block Gateway

d)

Tape Gateway

e)

Cached Gateway

54.

#54 An application stores images which will be retrieved infrequently, but must be available for retrieval immediately. Which is the most cost-effective storage option that meets these requirements?

a)

Amazon Glacier with expedited retrievals

b)

Amazon S3 Standard-Infrequent Access

c)

Amazon EFS

d)

Amazon S3 Standard

55.

#55 Which AWS support plans provide support via email, chat and phone? (Select TWO.)

a)

Basic

b)

Developer

c)

Business

d)

Enterprise

e)

Global

56.

Which AWS service can be used to host a static website?

a)

Amazon S3

b)

Amazon EBS

c)

AWS CloudFormation

d)

Amazon EFS

57.

#57 Which of the following are AWS recommended best practices in relation to IAM? (Select TWO.)

a)

Assign permissions to users

b)

Create individual IAM users

c)

Embed access keys in application code

d)

Enable MFA for all users

e)

Grant greatest privilege

58.

#58 Which of the following security operations tasks must be performed by AWS customers? (Select TWO.)

a)

Collecting syslog messages from physical firewalls

b)

Issuing data center access keycards

c)

Installing security updates on EC2 instances

d)

Enabling multi-factor authentication (MFA) for privileged users

e)

Installing security updates for server firmware

59.

#59 How can an organization assess applications for vulnerabilities and deviations from best practice?

a)

Use AWS Artifact

b)

Use AWS Inspector

c)

Use AWS Shield

d)

Use AWS WAF

60.

#60 Which AWS service protects against common exploits that could compromise application availability, compromise security or consume excessive resources?

a)

AWS WAF

b)

AWS Shield

c)

Security Group

d)

Network ACL

61.

#61 A new user is unable to access any AWS services, what is the most likely explanation?

a)

The user needs to login with a key pair

b)

The services are currently unavailable

c)

By default new users are created without access to any AWS services

d)

The default limit for user logons has been reached

62.

#62 Which of the following compliance programs allows the AWS environment to process, maintain, and store protected health information?

a)

ISO 27001

b)

PCI DSS

c)

HIPAA

d)

SOC 1

63.

#63 Which AWS service can be used to load data from Amazon S3, transform it, and move it to another destination?

a)

Amazon RedShift

b)

Amazon EMR

c)

Amazon Kinesis

d)

AWS Glue

64.

#64 How should an organization deploy an application running on multiple EC2 instances to ensure that a power failure does not cause an application outage?

a)

Launch the EC2 instances in separate regions

b)

Launch the EC2 instances into different VPCs

c)

Launch the EC2 instances into different Availability Zones

d)

Launch the EC2 instances into Edge Locations

65.

Which of the statements below is correct in relation to Consolidated Billing? (Select TWO.)

a)

You receive one bill per AWS account

b)

You receive a single bill for multiple accounts

c)

You pay a fee per linked account

d)

You can combine usage and share volume pricing discounts

e)

You are charged a fee per user

66.

#66 Amazon S3 is typically used for which of the following use cases? (Select TWO.)

a)

Host a static website

b)

Install an operating system

c)

Media hosting

d)

In-memory data cache

e)

Message queue