wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Cloud Practitioner Q6

Total questions: 65

Worksheet time: 37mins

Name
Class
Date
1.

#1 The AWS Cost Management tools give users the ability to do which of the following? (Select TWO.)

a)

Terminate all AWS resources automatically if budget thresholds are exceeded

b)

Break down AWS costs by day, service, and linked AWS account

c)

Create budgets and receive notifications if current or forecasted usage exceeds the budgets

d)

Switch automatically to Reserved Instances or Spot Instances, whichever is most cost-effective

e)

Move data stored in Amazon S3 to a more cost-effective storage class

2.

#2 Which AWS service or feature helps restrict the AWS service, resources, and individual API actions the users and roles in each member account can access?

a)

Amazon Cognito

b)

AWS Organizations

c)

AWS Shield

d)

AWS Firewall Manager

3.

#3 Under the shared responsibility model, which of the following tasks are the responsibility of the AWS customer? (Select TWO.)

a)

Ensuring that application data is encrypted at rest

b)

Ensuring that AWS NTP servers are set to the correct time

c)

Ensuring that users have received security training in the use of AWS services

d)

Ensuring that access to data centers is restricted

e)

Ensuring that hardware is disposed of properly

4.

#4 Under the AWS shared responsibility model, which of the following are customer responsibilities? (Select TWO.)

a)

Setting up server-side encryption on an Amazon S3 bucket

b)

Amazon RDS instance patching

c)

Network and firewall configurations

d)

Physical security of data center facilities

e)

Compute capacity availability

5.

#5 A web application running on AWS has been received malicious requests from the same set of IP addresses. Which AWS service can help secure the application and block the malicious traffic?

a)

AWS IAM

b)

Amazon GuardDuty

c)

Amazon SNS

d)

AWS WAF

6.

#6 Which AWS service provides the ability to detect inadvertent data leaks of personally identifiable information (PII) and user credential data?

a)

Amazon GuardDuty

b)

Amazon Inspector

c)

Amazon Macie

d)

AWS Shield

7.

#7 According to the AWS Well-Architected Framework, what change management steps should be taken to achieve reliability in the AWS Cloud? (Select TWO.)

a)

Use AWS Config to generate an inventory of AWS resources

b)

Use service limits to prevent users from creating or making changes to AWS resources

c)

Use AWS CloudTrail to record AWS API calls into an auditable log file

d)

Use AWS Certificate Manager to create a catalog of approved services

e)

Use Amazon GuardDuty to record API activity to an S3 bucket

8.

#8 Which of the following acts as a virtual firewall at the Amazon EC2 instance level to control traffic for one or more instances?

a)

Route table

b)

Virtual private gateways (VPG)

c)

Security groups

d)

Network Access Control Lists (ACL)

9.

#9 Which AWS Cloud design principles can help increase reliability? (Select TWO.)

a)

Using monolithic architecture

b)

Measuring overall efficiency

c)

Testing recovery procedures

d)

Adopting a consumption mode

e)

Automatically recovering from failure

10.

#10 Which pricing model will interrupt a running Amazon EC2 instance if capacity becomes temporarily unavailable?

a)

On-Demand Instances

b)

Standard Reserved Instances

c)

Spot Instances

d)

Convertible Reserved Instances

11.

#11 Which of the following statements about AWS’s pay-as-you-go pricing model is correct?

a)

It results in reduced capital expenditures

b)

It requires payment up front for AWS services

c)

It is relevant only for Amazon EC2, Amazon S3, and Amazon DynamoDB

d)

It reduces operational expenditures

12.

#12 Which AWS service can serve a static website?

a)

Amazon S3

b)

Amazon Route 53

c)

Amazon QuickSight

d)

AWS X-Ray

13.

#13 A startup eCommerce company needs to quickly deliver new website features in an iterative manner, minimizing the time to market. Which AWS Cloud feature allows this?

a)

Elasticity

b)

High availability

c)

Agility

d)

Reliability

14.

What is the most efficient way to establish network connectivity from on-premises to multiple VPCs in different AWS Regions?

a)

. Use AWS Direct Connect

b)

Use AWS VPN

c)

Use AWS Client VPN

d)

Use an AWS Transit Gateway

15.

#15 A company is using the AWS CLI and programmatic access of AWS resources from its on-premises network. What is a mandatory requirement in this scenario?

a)

Using an AWS Direct Connect connection

b)

Using an AWS access key and a secret key

c)

Using Amazon API Gateway

d)

Using an Amazon EC2 key pair

16.

#16 Which AWS service is suitable for an event-driven workload?

a)

Amazon EC2

b)

AWS Elastic Beanstalk

c)

AWS Lambda

d)

Amazon Lumberyard

17.

#17 Based on the shared responsibility model, which of the following security and compliance tasks is AWS responsible for?

a)

Granting access to individuals and services

b)

Encrypting data in transit

c)

Updating Amazon EC2 host firmware

d)

Updating operating systems

18.

#18 Which AWS service can be used to run Docker containers?

a)

AWS Lambda

b)

Amazon ECR

c)

AWS Fargate

d)

Amazon AMI

19.

#19 Which type of Elastic Load Balancer operates at the TCP connection level?

a)

Application Load Balancer (ALB)

b)

Network Load Balancer (NLB)

c)

Classic Load Balancer (CLB)

d)

Amazon Route 53 Load Balancer

20.

#20 Which AWS technology can be referred to as a “virtual hard disk in the cloud”?

a)

Amazon EFS Filesystem

b)

Amazon S3 Bucket

c)

Amazon EBS volume

d)

Amazon ENI

21.

#21 In which ways does AWS’ pricing model benefit organizations?

a)

Eliminates licensing costs

b)

Focus spend on capital expenditure, rather than operational expenditure

c)

Reduce the cost of maintaining idle resources

d)

Reduces the people cost of application development

22.

#22 Which service allows you to monitor and troubleshoot systems using system and application log files generated by those systems?

a)

CloudTrail Logs

b)

CloudWatch Metrics

c)

CloudWatch Logs

d)

CloudTrail Metrics

23.

#23 According to the AWS Shared Responsibility Model, which of the following is a shared control?

a)

Operating system patching

b)

Awareness and training

c)

Protection of infrastructure

d)

Client-side data encryption

24.

#24 Where do Amazon Identity and Access Management (IAM) accounts need to be created for a global organization?

a)

In each region where the users are located

b)

just create them once, as IAM is a global service

c)

Create them globally, and then replicate them regionally

d)

In each geographical area where the users are located

25.

#25 What is the name for the top-level container used to hold objects within Amazon S3?

a)

Folder

b)

Directory

c)

Instance Store

d)

Bucket

26.

#26 Which of the following are examples of horizontal scaling?

a)

Add more CPU/RAM to existing instances as demand increases

b)

Add more instances as demand increases

c)

Requires a restart to scale up or down

d)

Automatic scaling using services such as AWS Auto Scaling

e)

Scalability is limited by maximum instance size

27.

#27 Which resource should you use to access AWS security and compliance reports?

a)

AWS Artifact

b)

AWS Business Associate Addendum (BAA)

c)

AWS IAM

d)

AWS Organizations

28.

#28 What methods are available for scaling an Amazon RDS database? (Select TWO.)

a)

You can scale up by moving to a larger instance size

b)

You can scale out automatically with EC2 Auto Scaling

c)

You can scale up by increasing storage capacity

d)

You can scale out by implementing Elastic Load Balancing

e)

You can scale up automatically using AWS Auto Scaling

29.

#29 Which type of scaling does Amazon EC2 Auto Scaling provide?

a)

Vertical

b)

Linear

c)

Horizontal

d)

Incremental

30.

#30 Which feature of Amazon S3 enables you to create rules to control the transfer of objects between different storage classes?

a)

Object sharing

b)

Versioning

c)

Lifecycle management

d)

Bucket policies

31.

#31 How can a database administrator reduce operational overhead for a MySQL database?

a)

Migrate the database onto an EC2 instance

b)

Migrate the database onto AWS Lambda

c)

Use AWS CloudFormation to manage operations

d)

Migrate the database onto an Amazon RDS instance

32.

#32 Which AWS database service is schema-less and can be scaled dynamically without incurring downtime?

a)

Amazon RDS

b)

Amazon Aurora

c)

Amazon RedShift

d)

Amazon DynamoDB

33.

#33 Which type of AWS database is ideally suited to analytics using SQL queries?

a)

Amazon DynamoDB

b)

Amazon RedShift

c)

Amazon RDS

d)

Amazon S3

34.

#34 Which AWS service is designed to be used for operational analytics?

a)

Amazon EMR

b)

Amazon Athena

c)

Amazon QuickSight

d)

Amazon Elasticsearch Service

35.

#35 You need to connect your company’s on-premise network into AWS and would like to establish an AWS managed VPN service. Which of the following configuration items needs to be setup on the Amazon VPC side of the connection?

a)

A Virtual Private Gateway

b)

A Customer Gateway

c)

A Network Address Translation device

d)

A Firewall

36.

#36 Where are Amazon EBS snapshots stored?

a)

On an Amazon EBS instance store

b)

On an Amazon EFS filesystem

c)

Within the EBS block store

d)

On Amazon S3

37.

#37 Which AWS service makes it easy to coordinate the components of distributed applications as a series of steps in a visual workflow?

a)

Amazon SWF

b)

AWS Step Functions

c)

Amazon SNS

d)

Amazon SES

38.

#38 A Cloud Practitioner is creating the business process workflows associated with an order fulfilment system. Which AWS service can assist with coordinating tasks across distributed application components?

a)

AWS STS

b)

Amazon SQS

c)

Amazon SWF

d)

Amazon SNS

39.

#39 Your manager has asked you to explain some of the security features available in the AWS cloud. How can you describe the function of Amazon CloudHSM?

a)

It provides server-side encryption for S3 objects

b)

It is a Public Key Infrastructure (PKI)

c)

It can be used to generate, use and manage encryption keys in the cloud

d)

It is a firewall for use with web applications

40.

#40 Which AWS Glacier data access option retrieves data from an archive in 1-5 minutes?

a)

Standard

b)

Express

c)

Accelerated

d)

Expedited

41.

#41 How can a systems administrator specify a script to be run on an EC2 instance during launch?

a)

Metadata

b)

User Data

c)

Run Command

d)

AWS Config

42.

#42 What advantages does the AWS cloud provide in relation to cost? (Select TWO.)

a)

Fine-grained billing

b)

One-off payments for on-demand resources

c)

Ability to turn off resources and not pay for them

d)

Enterprise licensing discounts

e)

Itemized power costs

43.

#43 Which of the authentication options below can be used to authenticate using AWS APIs? (Select TWO.)

a)

Key pairs

b)

Access keys

c)

Server passwords

d)

Security groups

e)

Server certificates

44.

Under the AWS Shared Responsibility Model, who is responsible for what? (Select TWO.)

a)

Customers are responsible for compute infrastructure

b)

AWS are responsible for network and firewall configuration

c)

Customers are responsible for networking traffic protection

d)

AWS are responsible for networking infrastructure

e)

Customers are responsible for edge locations

45.

#45 Which HTTP code indicates a successful upload of an object to Amazon S3?

a)

200

b)

300

c)

400

d)

500

46.

#46 Which AWS support plans provide 24×7 access to customer service?

a)

Basic

b)

Business

c)

Developer

d)

All plans

47.

#47 Which of the following are NOT features of AWS IAM? (Select TWO.)

a)

Shared access to your AWS account

b)

Logon using local user accounts

c)

Identity federation

d)

PCI DSS compliance

e)

Charged for what you use

48.

#48 How can a company facilitate the sharing of data over private connections between two accounts they own within a region?

a)

Create an internal ELB

b)

Create a subnet peering connection

c)

Create a VPC peering connection

d)

Configure matching CIDR address ranges

49.

#49 How can you deploy your EC2 instances so that if a single data center fails you still have instances available?

a)

Across regions

b)

Across subnets

c)

Across Availability Zones

d)

Across VPCs

50.

#50 Your manager has asked you to explain the benefits of using IAM groups. Which of the below statements are valid benefits? (Select TWO.)

a)

You can restrict access to the subnets in your VPC

b)

Groups let you specify permissions for multiple users, which can make it easier to manage the permissions for those users

c)

Provide the ability to create custom permission policies

d)

Enables you to attach IAM permission policies to more than one user at a time

e)

Provide the ability to nest groups to create an organizational hierarchy

51.

#51 Which of the following are pillars from the five pillars of the AWS Well-Architected Framework? (Select TWO.)

a)

Resilience

b)

Operational excellence

c)

Confidentiality

d)

Economics

e)

Performance efficiency

52.

#52 What do you need to log into the AWS console?

a)

User name and password

b)

Key pair

c)

Access key and secret ID

d)

Certificate

53.

#53 What are the advantages of running a database service such as Amazon RDS in the cloud versus deploying on-premise? (Select TWO.)

a)

You have full control of the operating system and can install your own operational tools

b)

Scalability is improved as it is quicker to implement and there is an abundance of capacity

c)

You can use any database software you like, allowing greater flexibility

d)

High availability is easier to implement due to built-in functionality for deploying read replicas and multi-AZ

e)

There are no costs for replicating data between DBs in different data centers or regions

54.

Which of the statements below does NOT characterize cloud computing?

a)

Cloud computing is the on-demand delivery of compute power

b)

With cloud computing you get to benefit from massive economies of scale

c)

Cloud computing allows you to swap variable expense for capital expense

d)

With cloud computing you can increase your speed and agility

55.

Which AWS technology enables you to group resources that share one or more tags?

a)

Tag groups

b)

Organization groups

c)

Resource groups

d)

Consolidation groups

56.

What is the easiest way to store a backup of an EBS volume on Amazon S3?

a)

Write a custom script to copy the data into a bucket

b)

Use S3 lifecycle actions to backup the volume

c)

Create a snapshot of the volume

d)

Use Amazon Kinesis to process the data and store the results in S3

57.

#57 Which AWS security tool uses an agent installed in EC2 instances and assesses applications for vulnerabilities and deviations from best practices?

a)

AWS Trusted Advisor

b)

AWS Personal Health Dashboard

c)

AWS TCO Calculator

d)

AWS Inspector

58.

#58 Which of the following is NOT a best practice for protecting the root user of an AWS account?

a)

Don’t share the root user credentials

b)

Enable MFA

c)

Remove administrative permissions

d)

Lock away the AWS root user access keys

59.

You are evaluating AWS services that can assist with creating scalable application environments. Which of the statements below best describes the Elastic Load Balancer service?

a)

Helps you ensure that you have the correct number of Amazon EC2 instances available to handle the load for your application

b)

A highly available and scalable Domain Name System (DNS) service

c)

Automatically distributes incoming application traffic across multiple targets, such as Amazon EC2 instances, containers, and IP addresses

d)

A network service that provides an alternative to using the Internet to connect customers’ on-premise sites to AWS

60.

#60 What is an example of scaling vertically?

a)

AWS Auto Scaling adding more EC2 instances

b)

AWS Lambda adding concurrently executing functions

c)

Increasing the instance size with Amazon RDS

d)

Adding read replicas to an Amazon RDS database

61.

#61 To reduce cost, which of the following services support reservations? (Select TWO.)

a)

Amazon ElastiCache

b)

Amazon CloudFormation

c)

Amazon RedShift

d)

AWS Elastic Beanstalk

e)

Amazon S3

62.

#62 What type of cloud computing service type do AWS Elastic Beanstalk and Amazon RDS correspond to?

a)

IaaS

b)

PaaS

c)

SaaS

d)

Hybrid

63.

#63 How can a company configure automatic, asynchronous copying of objects in Amazon S3 buckets across regions?

a)

This is done by default by AWS

b)

By configuring multi-master replication

c)

Using cross-region replication

d)

Using lifecycle actions

64.

#64 Your company has recently migrated to AWS. How can your CTO monitor the organization’s costs?

a)

AWS Cost Explorer

b)

AWS CloudTrail

c)

AWS Consolidated Billing

d)

AWS Simple Monthly calculator

65.

#65 Your organization has offices around the world and some employees travel between offices. How should their accounts be setup?

a)

IAM is a global service, just create the users in one place

b)

Create a separate account in IAM within each region in which they will travel

c)

Set the user account as a “global” account when created

d)

Enable MFA for the accounts