wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Cloud Practitioner Practice Questions (ND2)

Total questions: 65

Worksheet time: 1hrs 5mins

Name
Class
Date
1.

A company has a global user base and needs to deploy AWS services that can decrease network latency for their users. Which services may assist? (Select TWO.)

a)

Amazon CloudFront

b)

Amazon VPC

c)

Application Auto Scaling

d)

AWS Direct Connect

e)

AWS Global Accelerator

2.

Which on-premises costs must be included in a Total Cost of Ownership (TCO) calculation when comparing against the AWS Cloud? (Select TWO.)

a)

Physical compute hardware

b)

Operating system administration

c)

Network infrastructure in the data center

d)

Project management services

e)

Database schema development

3.

Which of the following tasks can a user perform to optimize Amazon EC2 costs? (Select TWO.)

a)

Implement Auto Scaling groups to add and remove instances based on demand.

b)

Create a policy to restrict IAM users from accessing the Amazon EC2 console.

c)

Set a budget to limit spending on Amazon EC2 instances using AWS Budgets.

d)

Purchase Amazon EC2 Reserved Instances.

e)

Create users in a single Region to reduce the spread of EC2 instances globally.

4.

A company plan to move the application development to AWS. Which benefits can they achieve when developing and running applications in the AWS Cloud compared to on-premises? (Select TWO.)

a)

AWS automatically replicates all data globally.

b)

AWS will fully manage the entire application.

c)

AWS makes it easy to implement high availability.

d)

AWS can accommodate large changes in application demand.

e)

AWS takes care of application security patching.

5.

A company recently migrated to AWS and wants to implement a solution to protect the traffic that flows in and out of the production VPC. The company had an inspection server in its on-premises data center. The inspection server performed specific operations such as traffic flow inspection and traffic filtering. The company wants to have the same functionalities in the AWS Cloud.
Which solution will meet these requirements?

a)

Use Amazon GuardDuty for traffic inspection and traffic filtering in the production VPC.

b)

Use Traffic Mirroring to mirror traffic from the production VPC for traffic inspection and filtering.

c)

Use AWS Network Firewall to create the required rules for traffic inspection and traffic filtering for the production VPC.

d)

Use AWS Firewall Manager to create the required rules for traffic inspection and traffic filtering for the production VPC.

6.

A Cloud Practitioner is re-architecting a monolithic application. Which design principles for cloud architecture do AWS recommend? (Select TWO.)

a)

Implement manual scalability.

b)

Implement loose coupling.

c)

Use self-managed servers.

d)

Rely on individual components.

e)

Design for scalability.

7.

Which of the following a valid best practices for using the AWS Identity and Access Management (IAM) service? (Select TWO.)

a)

Embed access keys in application code.

b)

Create individual IAM users.

c)

Use inline policies instead of customer managed policies.

d)

Use groups to assign permissions to IAM users.

e)

Grant maximum privileges to IAM users.

8.

Which of the following is an advantage for a company running workloads in the AWS Cloud vs on-premises? (Select TWO.)

a)

Less staff time is required to launch new workloads.

b)

Increased time to market for new application features.

c)

Higher acquisition costs to support elastic workloads.

d)

Lower overall utilization of server and storage systems.

e)

Increased productivity for application development teams.

9.

A Cloud Practitioner wants to configure the AWS CLI for programmatic access to AWS services. Which credential components are required? (Select TWO.)

a)

An access key ID

b)

A public key

c)

A secret access key

d)

An IAM Role

e)

A private key

10.

What can a Cloud Practitioner do with the AWS Cost Management tools? (Select TWO.)

a)

Visualize AWS costs by day, service, and linked AWS account.

b)

Terminate EC2 instances automatically if budget thresholds are exceeded.

c)

Automatically modify EC2 instances to use Spot pricing to reduce costs.

d)

Create budgets and receive notifications if current or forecasted usage exceeds the budgets.

e)

Archive data to Amazon Glacier if it is not acc

11.

Which of the following should be used to improve the security of access to the AWS Management Console? (Select TWO.)

a)

AWS Secrets Manager

b)

AWS Multi-Factor Authentication (AWS MFA)

c)

Security group rules

d)

Strong password policies

12.

An application has highly dynamic usage patterns. Which characteristics of the AWS Cloud make it cost-effective for this type of workload? (Select TWO.)

a)

High availability

b)

Strict security

c)

Elasticity

d)

Pay-as-you-go pricing

e)

Reliability

13.

Which benefits can a company immediately realize using the AWS Cloud? (Select TWO.)

a)

Variable expenses are replaced with capital expenses

b)

Capital expenses are replaced with variable expenses

c)

User control of physical infrastructure

d)

Increased agility

e)

No responsibility for security

14.

Which services are involved with security? (Select TWO.)

a)

AWS CloudHSM

b)

AWS DMS

c)

AWS KMS

d)

AWS SMS

e)

Amazon ELB

15.

What are the names of two types of AWS Storage Gateway? (Select TWO.)

a)

S3 Gateway

b)

File Gateway

c)

Block Gateway

d)

Tape Gateway

e)

Cached Gateway

16.

Which AWS support plans provide support via email, chat and phone? (Select TWO.)

a)

Basic

b)

Developer

c)

Business

d)

Enterprise

e)

Global

17.

Which of the following are AWS recommended best practices in relation to IAM? (Select TWO.)

a)

Assign permissions to users

b)

Create individual IAM users

c)

Embed access keys in application code

d)

Enable MFA for all users

e)

Grant greatest privilege

18.

Which of the following security operations tasks must be performed by AWS customers? (Select TWO.)

a)

Collecting syslog messages from physical firewalls

b)

Issuing data center access keycards

c)

Installing security updates on EC2 instances

d)

Enabling multi-factor authentication (MFA) for privileged users

e)

Installing security updates for server firmware

19.

Which of the statements below is correct in relation to Consolidated Billing? (Select TWO.)

a)

You receive one bill per AWS account

b)

You receive a single bill for multiple accounts

c)

You pay a fee per linked account

d)

You can combine usage and share volume pricing discounts

e)

You are charged a fee per user

20.

Amazon S3 is typically used for which of the following use cases? (Select TWO.)

a)

Host a static website

b)

Install an operating system

c)

Media hosting

d)

In-memory data cache

e)

Message queue

21.

A Service Control Policy (SCP) is used to manage the maximum available permissions and is associated with which of the following? Service control policies (SCPs) manage permissions for which of the following?

a)

AWS Global Infrastructure

b)

AWS Regions

c)

AWS Organizations

d)

Availability Zones

22.

Which AWS service is used to send both text and email messages from distributed applications?

a)

Amazon Simple Email Service (Amazon SES)

b)

Amazon Simple Workflow Service (Amazon SWF)

c)

Amazon Simple Queue Service (Amazon SQS)

d)

Amazon Simple Notification Service(SNS)

23.

Which AWS service can be used to run Docker containers?

a)

AWS Lambda

b)

Amazon ECR

c)

Amazon ECS

d)

Amazon AMI

24.

Which technology can automatically adjust compute capacity as demand for an application increases or decreases?

a)

Load balancing

b)

Auto Scaling

c)

Fault tolerance

d)

High availability

25.

How can an organization assess applications for vulnerabilities and deviations from best practice?

a)

Use AWS Artifact

b)

Use AWS Inspector

c)

Use AWS Shield

d)

Use AWS WAF

26.

Which cloud architecture design principle is supported by deploying workloads across multiple Availability Zones?

a)

Automate infrastructure.

b)

Design for agility.

c)

Enable elasticity.

d)

Design for failure.

27.

Which AWS service should a Cloud Practitioner use to establish a secure network connection between an on-premises network and AWS?

a)

AWS Mobile Hub

b)

AWS Web Application Firewall (WAF)

c)

Amazon Virtual Private Cloud (VPC)

d)

Virtual Private Network

28.

Which service can a Cloud Practitioner use to configure custom cost and usage limits and enable alerts for when defined thresholds are exceeded?

a)

Consolidated billing

b)

AWS Trusted Advisor

c)

Cost Explorer

d)

AWS Budgets

29.

According to the AWS shared responsibility model, which task is the customer's responsibility?

a)

Maintaining the infrastructure needed to run Amazon DynamoDB

b)

Updating the operating system of AWS Lambda instances

c)

Maintaining Amazon API Gateway infrastructure

d)

Updating the guest operating system on Amazon EC2 instances

30.

Which AWS service or feature allows a company to receive a single monthly AWS bill when using multiple AWS accounts?

a)

Consolidated billing

b)

Amazon Cloud Directory

c)

AWS Cost Explorer

d)

AWS Cost and Usage report

31.

AWS are able to continue to reduce their pricing due to:

a)

Pay-as-you go pricing

b)

The AWS global infrastructure

c)

Economies of scale

d)

Reserved instance pricing

32.

According to the shared responsibility model, which security-related task is the responsibility of the customer?

a)

Maintaining server-side encryption.

b)

Securing servers and racks at AWS data centers.

c)

Maintaining firewall configurations at a hardware level.

d)

Maintaining physical networking configuration.

33.

A company requires a dashboard for reporting when using a business intelligence solution. Which AWS service can a Cloud Practitioner use?

a)

Amazon Redshift

b)

Amazon Kinesis

c)

Amazon Athena

d)

Amazon QuickSight

34.

Which AWS dashboard displays relevant and timely information to help users manage events in progress, and provides proactive notifications to help plan for scheduled activities?

a)

AWS Service Health Dashboard

b)

AWS Personal Health Dashboard

c)

AWS Trusted Advisor dashboard

d)

Amazon CloudWatch dashboard

35.

Which AWS-managed service can be used to process vast amounts of data using a hosted Hadoop framework?

a)

Amazon DynamoDB

b)

Amazon Athena

c)

Amazon EMR

d)

Amazon Redshift

36.

Which AWS service helps customers meet corporate, contractual, and regulatory compliance requirements for data security by using dedicated hardware appliances within the AWS Cloud?

a)

AWS Secrets Manager

b)

AWS CloudHSM

c)

AWS Key Management Service (AWS KMS)

d)

AWS Directory Service

37.

Which of the following best describes an Availability Zone in the AWS Cloud?

a)

One or more physical data centers

b)

A completely isolated geographic location

c)

One or more edge locations based around the world

d)

A subnet for deploying resources into

38.

According to the shared responsibility mode, which security and compliance task is AWS responsible for?

a)

Granting permissions to users and services

b)

Updating Amazon EC2 host firmware

c)

Encrypting data at rest

d)

Updating operating systems

39.

Which benefit of AWS enables companies to replace upfront fixed expenses with variable expenses when using on-demand technology services?

a)

Pay-as-you-go pricing

b)

Economies of scale

c)

Global reach

d)

High availability

40.

Which Amazon EC2 pricing model should be avoided if a workload cannot accept interruption if capacity becomes temporarily unavailable?

a)

Spot Instances

b)

On-Demand Instances

c)

Standard ReservedInstances

d)

Convertible Reserved Instances

41.

What should a Cloud Practitioner ensure when designing a highly available architecture on AWS?

a)

Servers have low-latency and high throughput network connectivity.

b)

The failure of a single component should not affect the application.

c)

There are enough servers to run at peak load available at all times.

d)

A single monolithic application component handles all operations.

42.

Which of the following can be used to identify a specific user who terminated an Amazon RDS DB instance?

a)

AWS CloudTrail

b)

Amazon Inspector

c)

Amazon CloudWatch

d)

AWS Trusted Advisor

43.

Which AWS service is a fully-managed source control service that hosts secure Git-based repositories?

a)

AWS CodeBuild

b)

AWS CodeDeploy

c)

AWS CodeCommit

d)

AWS CodePipeline

44.

How should an organization deploy an application running on multiple EC2 instances to ensure that a power failure does not cause an application outage?

a)

Launch the EC2 instances in separate regions

b)

Launch the EC2 instances into different VPCs

c)

Launch the EC2 instances into different Availability Zones

d)

Launch the EC2 instances into Edge Locations

45.

Which of the following can be used to identify a specific user who terminated an Amazon RDS DB instance?

a)

AWS CloudTrail

b)

Amazon Inspector

c)

Amazon CloudWatch

d)

AWS Trusted Advisor

46.

What can be used to allow an application running on an Amazon EC2 instance to securely store data in an Amazon S3 bucket without using long-term credentials?

a)

AWS Systems Manager

b)

Amazon Connect

c)

AWS IAM role

d)

AWS IAM access key

47.

What can a Cloud Practitioner use the AWS Total Cost of Ownership (TCO) Calculator for?

a)

Generate reports that break down AWS Cloud compute costs by duration, resource, or tags

b)

Estimate savings when comparing the AWS Cloud to an on-premises environment

c)

Estimate a monthly bill for the AWS Cloud resources that will be used

d)

Enable billing alerts to monitor actual AWS costs compared to estimated costs

48.

An application stores images which will be retrieved infrequently, but must be available for retrieval immediately. Which is the most cost-effective storage option that meets these requirements?

a)

Amazon Glacier with expedited retrievals

b)

Amazon S3 Standard-Infrequent Access

c)

Amazon EFS

d)

Amazon S3 Standard

49.

Which AWS service can be used to perform data extract, transform, and load (ETL) operations so you can prepare data for analytics?

a)

Amazon QuickSight

b)

AWS Glue

c)

Amazon Athena

d)

Amazon S3 Select

50.

A user needs an automated security assessment report that will identify unintended network access to Amazon EC2 instances and vulnerabilities on those instances. Which AWS service will provide this assessment report?

a)

EC2 security groups

b)

AWS C

c)

Amazon Macie

d)

Amazon Inspector

51.

Which AWS service protects against common exploits that could compromise application availability, compromise security or consume excessive resources?

a)

AWS WAF

b)

AWS Shield

c)

Security Group

d)

Network ACL

52.

A new user is unable to access any AWS services, what is the most likely explanation?

a)

The user needs to login with a key pair

b)

The services are currently unavailable

c)

By default new users are created without access to any AWS services

d)

The default limit for user logons has been reached

53.

Which AWS service can be used to load data from Amazon S3, transform it, and move it to another destination?

a)

Amazon RedShift

b)

Amazon EMR

c)

Amazon Kinesis

d)

AWS Glue

54.

A cloud practitioner needs to migrate a 70 TB of data from an on-premises data center into the AWS Cloud. The company has a slow and unreliable internet connection. Which AWS service can the cloud practitioner leverage to transfer the data?

a)

Amazon S3 Glacier

b)

AWS Snowball

c)

AWS Storage Gateway

d)

AWS DataSync

55.

An eCommerce company plans to use the AWS Cloud to quickly deliver new functionality in an iterative manner, minimizing the time to market. Which feature of the AWS Cloud provides this functionality?

a)

Elasticity

b)

Agility

c)

Fault tolerance

d)

Cost effectiveness

56.

A company needs a consistent and dedicated connection between AWS resources and an on-premise system. Which service should be used?

a)

AWS Direct Connect

b)

AWS Managed VPN

c)

Amazon Connect

d)

AWS DataSync

57.

What is the function of Amazon EC2 Auto Scaling?

a)

Scales the size of EC2 instances up or down automatically, based on demand.

b)

Automatically updates the EC2 pricing model, based on demand.

c)

Scales the number of EC2 instances in or out automatically, based on demand.

d)

Automatically modifies the network throughput of EC2 instances, based on demand.

58.

Which AWS service can be used to host a static website?

a)

Amazon S3

b)

Amazon EBS

c)

AWS CloudFormation

d)

Amazon EFS

59.

Which AWS service should be used to create a billing alarm?

a)
S3
b)
EC2
c)
Lambda
d)
CloudWatch
60.

Which Amazon EC2 pricing model should be used to comply with per-core software license requirements?

a)
Spot Instances
b)
Reserved Instances
c)
On-Demand Instances
d)
Dedicated Hosts
61.

The ability to horizontally scale Amazon EC2 instances based on demand is an example of which concept?

a)
Vertical scaling
b)

Scalibility

c)

Elasticity

d)

Agility

62.

You would like to collect custom metrics from a production application every 1 minute. What type of monitoring should you

use?

a)

CloudTrail with detailed monitoring

b)

CloudWatch with basic monitoring

c)

CloudTrail with basic monitoring

d)

CloudWatch with detailed monitoring

63.

Which Amazon EC2 pricing option provides significant discounts for fixed term contracts?

a)
Reserved Instances
b)
Dedicated Hosts
c)
On-Demand Instances
d)
Spot Instances
64.

Which tool can be used to provide real time guidance on provisioning resources following AWS best practices?

a)

AWS Personal Health Dashboard

b)

AWS Inspector

c)

AWS Simple Monthly Calculator

d)
AWS Trusted Advisor
65.

Which AWS service uses a highly secure hardware storage device to store encryption keys?

a)
AWS Secure Storage Service (SSS)
b)

AWS CloudHSM

c)
AWS Key Management Service (KMS)
d)
AWS Protected Key Storage (PKS)