wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Cloud Practitioner - Practice Test I

Total questions: 65

Worksheet time: 34mins

Name
Class
Date
1.

Which AWS services can be used to store file? Choose 2 answers from the options given below.

a)

Amazon CloudWatch

b)

Amazon Simple Storage Service (Amazon S3)

c)

Amazon Elastic Block Store (Amazon EBS)

d)

Amazon Config

e)

Amazon Athena

2.

When an administrator is looking to deploy shared file access Linux-based workloads which will require up to petabytes of data stores, what is the best-suited file storage option to use?

a)

Amazon EFS

b)

Amazon S3

c)

AWS Snowball

d)

Amazon EBS

3.

Which Amazon Route 53 routing policy can be implemented to route traffic to multiple resources basec upon user location?

a)

Geolocation routing policy

b)

Geoproximity routing policy

c)

Simple routing policy

d)

Latency routing policy

4.

Which AWS service provides infrastructure security optimization recommendations?

a)

AWS Application Programming Interface(API)

b)

Reserved Instances

c)

AWS Trusted Advisor

d)

Amazon Elastic Compute Cloud (Amazon EC2) SpotFleet

5.

Which Amazon Route 53 routing policy will be best suited to divert traffic in proportions to multiple resources?

a)

Latency routing policy

b)

Weighted routing policy

c)

Failover routing policy

d)

Multivalue answer routing policy

6.

A company needs to know which user was responsible for terminating several critical Amazon Elastic Compute Cloud (EC2) Instances. Where can the customer find this information?

a)

AWS Trusted Advisor

b)

Amazon EC2 instance usage report

c)

Amazon CloudWatch

d)

AWS CloudTrail logs

7.

I Have a client who is moving their on premise workloads to AWS. Since they are very cost conscious, they would like to get first hand information on their expenses they will incur while using AWS services. Which of the following will help them do that?

a)

AWS Cost Explorer

b)

AWS Organizations

c)

AWS Budgets

d)

AWS Pricing Calculator

8.

What is the value of having AWS Cloud services accessible through an Application Programming Interface (API)?

a)

It allows developers to work with AWS resources programmatically

b)

AWS resources will always be cost-optimized

c)

All application testing can be managed by AWS.

d)

Customer-owned, on-premises infrastructure becomes programmable.

9.

Which is the correct statement for Spot Price with respect to Spot Instance?

a)

Spot Price is static & changes every 6 hours

b)

Spot Price is static & changes every 24 hours

c)

Spot Price varies based upon demand

d)

Spot Price is always less than Spot Instance request

10.

A file-sharing service uses Amazon S3 to store files uploaded by users. Files are accessed with random frequency. Popular ones are downloaded every day whilst others not so often and some rarely. What is the most-effective Amazon S3 object storage class to implement?

a)

Amazon S3 Standard

b)

Amazon S3 Glacier

c)

Amazon S3 One Zone-Infrequently

d)

Amazon S3 Intelligent-Tiering

11.

Which AWS service automates infrastructure provisioning and administrative tasks for an analytical data warehouse?

a)

Amazon Redshift

b)

Amazon DynamoDB

c)

Amazon ElastiCache

d)

Amazon Aurora

12.

An administrator would like to automate the creation of new AWS accounts for the organization's research and development department. New workloads need to be spun-up promptly and categorized into groups. How can this be achieved efficiently?

a)

Use of AWS CloudFormation would be sufficient.

b)

Use of AWS Organizations.

c)

Using the AWS API to programmatically create each account via command line interface.

d)

AWS Identity Access Management (IAM)

13.

Which service can be used to download AWS security & compliance documents?

a)

AWS Well-Architected Tool

b)

AWS Audit Manager

c)

AWS Trusted Advisor

d)

AWS Artifact

14.

Development team has purcharsed a new application with limited licences. Administrator wants to be alerted when usage of license is exceeded on Amazon EC2 instance. Which service can be used to meet this requirement?

a)

AWS Control Tower

b)

AWS Config

c)

AWS Service Catalog

d)

AWS License Manager

15.

Which service can be best suited to import third-party SSL/TLS certifiactes that can be used to deploy on Amazon Elastic Load Balancer?

a)

AWS Artifacts

b)

AWS Secrets Manager

c)

AWS Certificate Manager

d)

AWS Systems Manager Parameter Store

16.

Development team is looking to offload SSL processing from existing Web servers. Which service can be used for this purpose?

a)

AWS Certificate Manager

b)

AWS CloudHSM

c)

AWS KMS

d)

AWS Secrets Manager

17.

Developer Team is creating a new mobile app using AWS resources which will be accessed by thousands of users. Which of the following services can be used for creating a directory for managing sign-in for these users?

a)

AWS Secrets Manager

b)

Amazon Cognito Identity Pools

c)

AWS Single Sign-On

d)

AWS IAM

18.

According to the AWS, what is the benefit of Elasticity?

a)

Minimize storage requirements by reducing logging and auditing activities

b)

Create systems that scale to the required capacity based on changes in demand

c)

Enable AWS to automatically select the most cost-effective services.

d)

Accelerate the design process because recovery from failure is automated, reducing the need for testing

19.

For which of the following scenarios are the Amazon Elastic Compute Cloud (Amazon EC2) Spot instances most appropriate?

a)

Workloads that are only run in the morning and stopped at night

b)

Workloads where the availability of the Amazon EC2 instances can be flexible

c)

Workloads that need to run for long periods of time without interruption

d)

Workloads that are critical and need Amazon EC2 instances with termination protection

20.

A financial company with many resources running on AWS would like a machine learning-drive and proactive security solution that would promptly identify security vulnerabilities, particularly flagging suspicious or abnormal data patterns or activity between AWS services. Which AWS service would best meet this requirement?

a)

AWS Detective

b)

AWS Macie

c)

AWS Shield

d)

Amazon CloudWatch Anomaly Detection

21.

Which tool can you use to forecast your AWS spending?

a)

AWS Organizations

b)

Amazon Dev Pay

c)

AWS Trusted Advisor

d)

AWS Cost Explorer

22.

Which of the following is an optional Security layer attached to a subnet within a VPC for controlling traffic in & out of the VPC?

a)

VPC Flow Logs

b)

Web Application Firewall

c)

Security Group

d)

Network ACL

23.

A radio station compiles a list of the most popular songs each year. The songs are frequently fetched within 180 days. After that, the users will have a default retrieval time of 12 hours for downloading the files. The files should be stored for over 10 years. Which is the most cost-effective object storage after 180 days?

a)

Amazon S3 Glacier

b)

Amazon S3 One Zone - Infrequently Accessed

c)

Amazon S3 Glacier Deep Archive

d)

Amazon S3 Standard - Infrequently Accessed

24.

Which of the following is a customer responsibility under AWS Shared Responsibility Model?

a)

Patching of host OS deployed on Amazon S3.

b)

Logical Access controls for underlying infrastructure.

c)

Physical security of the facilities.

d)

Patching of guest OS deployed on Amazon EC2 instance.

25.

Which of the following is a factor when calculating Total Cost of Ownership (TCO) for the AWS Cloud?

a)

The number of servers migrated to AWS

b)

The number of users migrated to AWS

c)

The number of passwords migrated to AWS

d)

The number of keys migrated to AWS

26.

A group of developers for a startup company store their source code and binary files on a shared open-source repository platform which is publicly accessible over the internet. They have embarked on a new project in which their client requires high confidentiality and security on all development assets. Which AWS service can the developers use to store the source code?

a)

AWS CodeCommit

b)

AWS CodeDeploy

c)

AWS Lambda

d)

AWS CodeStar

27.

An organization has a persistently high amount of throughput. It requires connectivity with no jitter and very low latency between its on-premise infrastructure and its AWS cloud build to support live streaming and real-time services. What is the MOST appropriate solution to meet this requirement?

a)

AWS Data Streams

b)

AWS Kinesis

c)

Kinesis Data Firehose

d)

AWS Direct Connet

28.

A Professional Educational Institution maintains a dedicated web server and database cluster that hosts and exam result portal undertaken by its students. The resource is idle for most of the learning cycle and becomes excessively busy when exam result are released. How can this architecture with servers be improved to be cost-efficient?

a)

Configure AWS Elastic load-balancing between the webserver and database cluster.

b)

Configure RDS multi-availability zone for performance optimization.

c)

Configure serverless architecture leveraring AWS lambda functions.

d)

Migrate the web servers onto Amazon EC2 Spot Instances.

29.

A business analyst would like to move away from creating complex database queries and static spreadsheets when generating regular reports for high-level management. They would like to publish insightful, graphically appealing reports with interactive dashboards. Which service can they use to accomplish this?

a)

Amazon QuickSight

b)

Business intelligence on Amazon Redshift

c)

Amazon CloudWatch dashboards

d)

Amazon Athena integrated with Amazon Glue

30.

What is the AWS feature that enables fast, easy and secure transfers of files over long distances between your client and your Amazon S3 bucket?

a)

File Transfer

b)

HTTP Transfer

c)

Amazon S3 Transfer Acceleration

d)

Amazon S3 Transfer Acceleration

31.

Which of the following AWS services is not the permitted services for penetration testing?

a)

Amazon EC2 instances

b)

AWS Fargate

c)

Amazon Route 53

d)

AWS Lambda

32.

In which five categories does Trusted Advisor service provide insight for an AWS account?

a)

Security, fault tolerance, high availability, connectivity and Service Limits

b)

Security, access control, high availability, performance and Service Limits

c)

Performance, cost optimization, security, fault tolerance and Service Limits

d)

Performance, cost optimization, access control, connectivity and Service Limits

33.

Which of the following AWS services is suitable to be used as a fully managed data warehouse?

a)

Amazon Athena

b)

Amazon RedShift

c)

Amazon CloudWatch

d)

Amazon Warehouse

34.

What best describes the "Principle of Least Privilege"? Choose the correct answer from the options given below.

a)

All users should have the same baseline permissions granted to them to use basic AWS services.

b)

Users should be granted permission to access only resources they need to do their assined job.

c)

Users should submit all access requests in written form so that there is a paper trail of who needs access to diffetent AWS resources.

d)

Users should always have little more permission that they need.

35.

Which support plan can be chosen to get AWS Technical Account manager proactively monitor a business-critital application on AWS?

a)

Enterprise Plan

b)

Business Plan

c)

Developer Plan

d)

Enterprise On-Ramp Plan

36.

As per AWS global infrastructure, which of the following components within an AWS Region provides a low latency redundant connectivity?

a)

Data Centers

b)

Edge Location

c)

Availability Zones

d)

Regional Cache

37.

Which of the following routing policies can be used to provide the best performance to global users accessing a static website deployed on Amazon S3 buckets at multiple regions?

a)

Use Route 53 weighted routing policy.

b)

Use Route 53 latency routing policy.

c)

Use Route 53 Geoproximity routing policy.

d)

Use Route 53 Geolocation routing policy.

38.

Which of the following services can be used to optimize performance for global users to transfer large-sized data objects to a centralized Amazon S3 bucket in us-west-1 region?

a)

Enable S3 Transfer Acceleration on Amazon S3 Bucket.

b)

Use Amazon CloudFront Put/Post commands

c)

Use Multipart upload

d)

Use Amazon ElastiCache

39.

Which of the following is NOT an area of shared controls (Shared between AWS & Customer in different contexts) within the AWS Shared responsibility Model? (Select TWO.)

a)

Configuration Management

b)

Service & communication protection

c)

Patch Management

d)

IAM User Management

e)

Training & Awareness

40.

Which of the following services can be used to automate software deployments on a large number of Amazon EC2 instance and on-premise servers?

a)

AWS CodePipeline

b)

AWS CloudFormation

c)

AWS CodeDeploy

d)

AWS Config

41.

Which of the following statements best describe the AWS Personal Health Dashboard?

a)

A concise representation of the general status of AWS services

b)

A service that prompts the user with alerts and notifications on AWS scheduled activities, pending issues, and planned changes.

c)

A minute-by-minute update of system outages and service errors on the AWS global infrastructure.

d)

A rolling log of all service interruptions across the AWS network and records of incidents persistent for a year.

42.

A startup company that works on social media apps development would like to grant freelance developers temporary access to its Lambda functions setup on AWS. These developers would be signing-in via Facebook authentication. Which service is the most appropriate to grant secure access?

a)

Create user credentials using Identity Access Management (IAM).

b)

Use Amazon Cognito for web-identity federation.

c)

Create temporary access roles using IAM.

d)

Use a thrid-party Web ID, federated access provider.

43.

There is a requirement to store objects. The objects must be downloadable via a URL. Which storage option would you choose?

a)

Amazon S3

b)

Amazon Glacier

c)

Amazon Stotage Gateway

d)

Amazon EBS

44.

There is a requirement to host a database server for a minimum period of one year. Which of the following would result in the least cost?

a)

Spot Instances

b)

On-Demand

c)

No Upfront costs Reserved

d)

Partial Upfront costs Reserved

45.

During an organiozation's information systems audit, the administrator is requested to provide a dossier of security and compliance reports and online service agreements between the organization and AWS. Which service can they utilize to acquire this information?

a)

AWS Artifact

b)

AWS Resource Center

c)

AWS Service Catalog

d)

AWS Directory Service

46.

A new department has recentlly joined the organization and the administrator needs to compose access permissions for the group of users. Given that they have various roles and access needs, what is the best-practice approach when granting access?

a)

After gathering information on their access needs, the administrator should allow every user to access the most common resources and privileges on the system.

b)

The administrator should grant all users the same permissions and then grant more upon request.

c)

The administrator should grant all users the least privilege and add more privileges to only to those who need it.

d)

Users should have no access and be granted temporary access on the occacions that they need to execute a task.

47.

Which of the following are advantages of having infrastructure hosted on the AWS Cloud? (Select TWO)

a)

Having complete control over the physical infrastruture

b)

Having the pay as you go model

c)

No Upfront costs

d)

No need to worry about security

48.

There is an external audit being carried out on your company. The IT auditor needs to have a log of who made the requests to the AWS resources in the company's account. Which of the below services can assist in providing these details?

a)

AWS CloudWatch

b)

AWS CloudTrail

c)

AWS EC2

d)

AWS SNS

49.

A web administrator maintains several public and private web-based resources for an organisation. Which service can they use to keep track of the expery dates of SSL/TLS certificates as well as updating and renewal?

a)

AWS Data Lifecycle Manager

b)

AWS License Manager

c)

AWS Firewall Manager

d)

AWS Certificate Manager

50.

Which of the following statements regarding billing, cost optimization and cost management in AWS is accurate?

a)

When considering migrating to the cloud, the AWS Total Cost of Ownership (TCO) calculator is guaranteed to save up to 80% of the cost of running on-premise infrastruture.

b)

In AWS Budgets, utilizing Cost and Usage budgets will optimize and reduce the overwall spend by 79%.

c)

The AWS Pricing Calculator will workout a revised bill that can reduce the overwall spend by 60% if you commit to long-term usage plan.

d)

When using Saving Plans, 72% savings can be made on Amazon EC2, AWS Fargate, and AWS Lambda usage.

51.

Which of the following features can be used to preview changes to be made to an AWS resource which will be deployed using the AWS CloudFormation template?

a)

AWS CloudFormation Drift Detection

b)

AWS CloudFormation Change Sets

c)

AWS CloudFormation Stack Sets

d)

AWS CloudFormation Intrinsic Functions

52.

Which option best suits the implementation of an Amazon RDS database instance instead of a NoSQL/non-relational database?

a)

Where datasets are constantly evolving and cannot be confined to a static data schema.

b)

Where vertical scaling of the database's resources is not permissible and is seldom necessary.

c)

In an organisation whose dataset's are dynamic and document-based.

d)

In an organisation where only a finite number of processes query the database in predictable and well-structured Schemas.

53.

While making changes to AWS resources e.g. adding a new Security Group Ingress rule, I need to capture & record all these changes that will be helpful during an audit. Which of the following AWS service helps me do that?

a)

AWS Trusted Advisor

b)

AWS CloudWatch

c)

AWS Config

d)

AWS CloudFormation

54.

AWS Organizations help manage multiple accounts effectively in a large enterprise. Which of the following statements related to AWS Organizations are correct? (Select TWO.)

a)

An Organizational Unit (OU) can have only one parent.

b)

An account can be a member of multiple Organizational Units (OU).

c)

An SCP policy only impacts a particular AWS account even if it is applied at the root account.

d)

Organizational level policies are known as Service Control Policies.

e)

Service Control Policies (SCPs) can only allow actions instead of deny actions.

55.

Which of the following statements are incorrect regarding NoSQL databases?

a)

They are not realtional.

b)

They need to have a well defined schema.

c)

NoSQL databases are horizontally scalable.

d)

A patient's record in a hospital system with changing data for every visit a good candidate to be modeled using a NoSQL database.

56.

What is a valid difference between AWS Global Accelerator and Amazon CloudFront? Choose TWO responses.

a)

AWS Global Accelerator uses the Anycast techniques to accelerate latency-sensitive applications Amazon CloudFront uses Unicast.

b)

Amazon CloudFront makes use of Edge Locations and edge infrastructure, whilst AWS Global Accelerator does not.

c)

AWS Global Accelerator does not include the content caching capability that Amazon CloudFront does.

d)

AWS Global Accelerator is suitable for applications that are non-HTTP/S such as voIP, MTTQ and gaming where as Amazon CloudFront enhances the performance of HTTP-based content such as dymamic web applications, images and videos.

e)

For the resource endpoint, Amazon CloudFront offers static public IP addresses whilst AWS Global Accelerator does not.

57.

Which of the following is the responsibility of the customer to ensure the availability and backup of the EBS volumes?

a)

Delete the data and create a new EBS volume.

b)

Create EBS snapshots.

c)

Attach new volumes to EC2 Instances.

d)

Create copies of EBS Volumes.

58.

Which AWS service gives the user the ability to group AWS resources across different AWS Regions by application and then collectively view their operational data for monitoring purposes?

a)

Systems Manager

b)

Management Console

c)

Resource Groups

d)

Resource Access Manager (AWS RAM)

59.

Which of the following is a situation that would require using both Spot and Reserved EC2 Instances?

a)

A build that has sudden unpredictable workload spikes but for a short time horizon.

b)

One in which there is a predictable resource demand over a long time horizon.

c)

One that has unpredictable spikes for a long time.

d)

One that has a constantly predictable workload with brief unpredictable spikes.

60.

When designing a highly available architecture, what is the difference between vertical scaling (scaling-up) and horizontal scaling (scaling-out)?

a)

Scaling up provides for hign availability whilst scaling out brings fault-tolerance.

b)

Scaling up provides for high availability whilst scaling out brings fault-tolerance.

c)

Scaling up adds more resources to an instance, scaling out adds more instances.

d)

Autoscaling groups require scaling up whilst launch configurations use scaling out.

61.

A weather tracking system is designed to track weather conditions of any particular flight route. Flight travellers all over the world make use of this information prior to booking their flights. Travellers expect quick turnaround time in which the weather display & flight booking will happen which is critical to their business. You have designed this website and are using AWS Route 53 DNS. The routing policy that you will apply to this website is

a)

GeoLocation routing policy

b)

Failover routing policy

c)

Multivalue answer routing policy

d)

Latency based routing policy

62.

Which of the following services can be used as an application firewall in AWS?

a)

AWS Snowball

b)

AWS WAF

c)

AWS Firewall

d)

AWS Protection

63.

What can be termed as a user-defined label that has a key-value pair of variable character length? It is assigned to AWS resources as metadata for administration and management purposes.

a)

Resource Tag

b)

Resource Tag

c)

Resource Flag

d)

Tag key

64.

A financial Organization has an on-premises Data Center that holds large volumes of customer's financial transaction data on its legacy mainframe systems. While accessing transaction data, they have implemented a caching solution in the AWS cloud that will hold the customer's financial data due to performance issues. The transaction data is extremely confidential & is heavy in bandwidth while transferring to the cloud. What connectivity would you recommend for this data transfer? Select the best answer.

a)

Direct Connect with a VPN connection

b)

Virtual Private Network (VPN)

c)

AWS Storage Gateway

d)

AWS Snowball

65.

Which of the following services can be used by the Security team to investigate & analyze root cause of potential security threats on AWS resources?

a)

Amazon Detective

b)

AWS Shield

c)

Amazon GuardDuty

d)

AWS Security Hub