wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Cloud Practitioner

Total questions: 103

Worksheet time: 55mins

Name
Class
Date
1.

Under the AWS shared responsibility model, which of the following is an example of security in the AWS Cloud?

a)

Managing edge locations

b)

Global infrastructure

c)

Firewall configuration

d)

Physical Security

2.

How can an AWS user with an AWS Basic Support plan obtain technical assistance from AWS?

a)

AWS Senior Support Engineers

b)

AWS Technical Account Managers

c)

AWS Trusted Advisor

d)

AWS Discussion Forums

3.

Which of the following are pillars of the AWS Well-Architected Framework? (Choose two.)

a)

Multiple Availability Zones

b)

Performance efficiency

c)

Security

d)

Encryption usage

e)

High availability

4.

After selecting an Amazon EC2 Dedicated Host reservation, which pricing option would provide the largest discount?

a)

No upfront payment

b)

Hourly on-demand payment

c)

Partial upfront payment

d)

All upfront payment

5.

What is an advantage of deploying an application across multiple Availability Zones?

a)

There is a lower risk of service failure if a natural disaster causes a service disruption in a given AWS Region.

b)

The application will have higher availability because it can withstand a service disruption in one Availability Zone.

c)

There will be better coverage as Availability Zones are geographically distant and can serve a wider area.

d)

There will be decreased application latency that will improve the user experience.

6.

A Cloud Practitioner is asked how to estimate the cost of using a new application on AWS. What is the MOST appropriate response?

a)

Inform the user that AWS pricing allows for on-demand pricing.

b)

Direct the user to the AWS Simple Monthly Calculator for an estimate.

c)

Use Amazon QuickSight to analyze current spending on-premises.

d)

Use Amazon AppStream 2.0 for real-time pricing analytics.

7.

A company wants to migrate its applications to a VPC on AWS. These applications will need to access on-premises resources. What combination of actions will enable the company to accomplish this goal? (Choose two.)

a)

Use the AWS Service Catalog to identify a list of on-premises resources that can be migrated.

b)

Build a VPN connection between an on-premises device and a virtual private gateway in the new VPC.

c)

Use Amazon Athena to query data from the on-premises database servers.

d)

Connect the company's on-premises data center to AWS using AWS Direct Connect.

e)

Leverage Amazon CloudFront to restrict access to static web content provided through the company's on-premises web servers

8.

A web application running on AWS has been spammed with malicious requests from a recurring set of IP addresses. Which AWS service can help secure the application and block the malicious traffic?

a)

AWS IAM

b)

Amazon GuardDuty

c)

Amazon Simple Notification Service (Amazon SNS)

d)

AWS WAF

9.

Treating infrastructure as code in the AWS Cloud allows users to:

a)

automate migration of on-premises hardware to AWS data centers.

b)

let a third party automate an audit of the AWS infrastructure.

c)

turn over application code to AWS so it can run on the AWS infrastructure.

d)

automate the infrastructure provisioning process.

10.

A company requires a dedicated network connection between its on-premises servers and the AWS Cloud. Which AWS service should be used?

a)

AWS VPN

b)

AWS Direct Connect

c)

Amazon API Gateway

d)

Amazon Connect

11.

Which AWS service can be used to query stored datasets directly from Amazon S3 using standard SQL?

a)

AWS Glue

b)

AWS Data Pipeline

c)

Amazon CloudSearch

d)

Amazon Athena

12.

AWS CloudFormation is designed to help the user:

a)

model and provision resources.

b)

update application code.

c)

set up data lakes.

d)

create reports for billing.

13.

Which of the following is an AWS database service?

a)

Amazon Redshift

b)

Amazon Elastic Block Store (Amazon EBS)

c)

Amazon S3 Glacier

d)

AWS Snowball

14.

A Cloud Practitioner must determine if any security groups in an AWS account have been provisioned to allow unrestricted access for specific ports. What is the SIMPLEST way to do this?

a)

Review the inbound rules for each security group in the Amazon EC2 management console to check for port 0.0.0.0/0.

b)

Run AWS Trusted Advisor and review the findings.

c)

Open the AWS IAM console and check the inbound rule filters for open access.

d)

In AWS Config, create a custom rule that invokes an AWS Lambda function to review rules for inbound access.

15.

What are the benefits of developing and running a new application in the AWS Cloud compared to on-premises? (Choose two.)

a)

AWS automatically distributes the data globally for higher durability.

b)

AWS will take care of operating the application.

c)

AWS makes it easy to architect for high availability.

d)

AWS can easily accommodate application demand changes.

e)

AWS takes care application security patching.

16.

A user needs an automated security assessment report that will identify unintended network access to Amazon EC2 instances and vulnerabilities on those instances. Which AWS service will provide this assessment report?

a)

EC2 security groups

b)

AWS Config

c)

Amazon Macie

d)

Amazon Inspector

17.

How can a company isolate the costs of production and non-production workloads on AWS?

a)

Create Identity and Access Management (IAM) roles for production and non-production workloads.

b)

Use different accounts for production and non-production expenses.

c)

Use Amazon EC2 for non-production workloads and other services for production workloads.

d)

Use Amazon CloudWatch to monitor the use of services.

18.

Where can users find a catalog of AWS-recognized providers of third-party security solutions?

a)

AWS Service Catalog

b)

AWS Marketplace

c)

AWS Quick Start

d)

AWS CodeDeploy

19.

A Cloud Practitioner needs to store data for 7 years to meet regulatory requirements. Which AWS service will meet this requirement at the LOWEST cost?

a)

Amazon S3

b)

AWS Snowball

c)

Amazon Redshift

d)

Amazon S3 Glacier

20.

What are the immediate benefits of using the AWS Cloud? (Choose two.)

a)

Increased IT staff.

b)

Capital expenses are replaced with variable expenses.

c)

User control of infrastructure.

d)

Increased agility.

e)

E. AWS holds responsibility for security in the cloud.

21.

Which security service automatically recognizes and classifies sensitive data or intellectual property on AWS?

a)

Amazon GuardDuty

b)

Amazon Macie

c)

Amazon Inspector

d)

AWS Shield

22.

What is the purpose of AWS Storage Gateway?

a)

It ensures on-premises data storage is 99.999999999% durable.

b)

It transports petabytes of data to and from AWS.

c)

It connects to multiple Amazon EC2 instances.

d)

It connects on-premises data storage to the AWS Cloud.

23.

What should users do if they want to install an application in geographically isolated locations?

a)

Install the application using multiple internet gateways.

b)

Deploy the application to an Amazon VPC.

c)

Deploy the application to multiple AWS Regions.

d)

Configure the application using multiple NAT gateways.

24.

What does it mean if a user deploys a hybrid cloud architecture on AWS?

a)

All resources run using on-premises infrastructure.

b)

Some resources run on-premises and some run in a colocation center.

c)

All resources run in the AWS Cloud.

d)

Some resources run on-premises and some run in the AWS Cloud.

25.

Which AWS service allows users to identify the changes made to a resource over time?

a)

Amazon Inspector

b)

AWS Config

c)

AWS Service Catalog

d)

AWS IAM

26.

How can a company reduce its Total Cost of Ownership (TCO) using AWS?

a)

By minimizing large capital expenditures

b)

By having no responsibility for third-party license costs

c)

By having no operational expenditures

d)

By having AWS manage applications

27.

Which activity is a customer responsibility in the AWS Cloud according to the AWS shared responsibility model?

a)

Ensuring network connectivity from AWS to the internet

b)

Patching and fixing flaws within the AWS Cloud infrastructure

c)

Ensuring the physical security of cloud data centers

d)

Ensuring Amazon EBS volumes are backed up

28.

What are the advantages of the AWS Cloud? (Choose two.)

a)

Fixed rate monthly cost

b)

No need to guess capacity requirements

c)

Increased speed to market

d)

Increased upfront capital expenditure

e)

Physical access to cloud data centers

29.

When comparing the total cost of ownership (TCO) of an on-premises infrastructure to a cloud architecture, what costs should be considered? (Choose two.)

a)

The credit card processing fees for application transactions in the cloud.

b)

The cost of purchasing and installing server hardware in the on-premises data.

c)

The cost of administering the infrastructure, including operating system and software installations, patches, backups, and recovering from failures.

d)

The costs of third-party penetration testing.

e)

The advertising costs associated with an ongoing enterprise-wide campaign.

30.

Which AWS feature allows a company to take advantage of usage tiers for services across multiple member accounts?

a)

Service control policies (SCPs)

b)

Consolidated billing

c)

All Upfront Reserved Instances

d)

AWS Cost Explorer

31.

What is one of the customer's responsibilities according to the AWS shared responsibility model?

a)

Virtualization infrastructure

b)

Network infrastructure

c)

Application security

d)

Physical security of hardware

32.

What helps a company provide a lower latency experience to its users globally?

a)

Using an AWS Region that is central to all users

b)

Using a second Availability Zone in the AWS Region that is using used

c)

Enabling caching in the AWS Region that is being used

d)

Using edge locations to put content closer to all users

33.

How can the AWS Cloud increase user workforce productivity after migration from an on-premises data center?

a)

Users do not have to wait for infrastructure provisioning.

b)

The AWS Cloud infrastructure is much faster than an on-premises data center infrastructure.

c)

AWS takes over application configuration management on behalf of users.

d)

Users do not need to address security and compliance issues.

34.

Which AWS service provides a quick and automated way to create and manage AWS accounts?

a)

AWS QuickSight

b)

Amazon Lightsail

c)

AWS Organizations

d)

Amazon Connect

35.

Which Amazon RDS feature can be used to achieve high availability?

a)

Multiple Availability Zones

b)

Amazon Reserved Instances

c)

Provisioned IOPS storage

d)

Enhanced monitoring

36.

Where should users report that AWS resources are being used for malicious purposes?

a)

AWS Abuse team

b)

AWS Shield

c)

AWS Support

d)

AWS Developer Forums

37.

Which AWS service needs to be enabled to track all user account changes within the AWS Management Console?

a)

AWS CloudTrail

b)

Amazon Simple Notification Service (Amazon SNS)

c)

VPC Flow Logs

d)

AWS CloudHSM

38.

What is an AWS Cloud design best practice?

a)

Tight coupling of components

b)

Single point of failure

c)

High availability

d)

Overprovisioning of resources

39.

Why is AWS more economical than traditional data centers for applications with varying compute workloads?

a)

Amazon Elastic Compute Cloud (Amazon EC2) costs are billed on a monthly basis.

b)

Customers retain full administrative access to their Amazon EC2 instances.

c)

Amazon EC2 instances can be launched on-demand when needed.

d)

Customers can permanently run enough instances to handle peak workloads.

40.

Which AWS service would simplify migration of a database to AWS?

a)

AWS Storage Gateway

b)

AWS Database Migration Service (AWS DMS)

c)

Amazon Elastic Compute Cloud (Amazon EC2)

d)

Amazon AppStream 2.0

41.

A user is planning to migrate an application workload to the AWS Cloud. Which control becomes the responsibility of AWS once the migration is complete?

a)

Patching the guest operating system

b)

Maintaining physical and environmental controls

c)

Protecting communications and maintaining zone security

d)

Patching specific applications

42.

Which services can be used to deploy applications on AWS? (Choose two.)

a)

AWS Elastic Beanstalk

b)

AWS Config

c)

AWS OpsWorks

d)

AWS Application Discovery Service

e)

Amazon Kinesis

43.

Which AWS service can be used to provide an on-demand, cloud-based contact center?

a)

AWS Direct Connect

b)

Amazon Connect

c)

AWS Support Center

d)

AWS Managed Services

44.

What tool enables customers without an AWS account to estimate costs for almost all AWS services?

a)

Cost Explorer

b)

TCO Calculator

c)

AWS Budgets

d)

AWS Pricing Calculator

45.

Which component must be attached to a VPC to enable inbound Internet access?

a)

NAT gateway

b)

VPC endpoint

c)

VPN connection

d)

Internet gateway

46.

Which pricing model would result in maximum Amazon Elastic Compute Cloud (Amazon EC2) savings for a database server that must be online for one year?

a)

Spot Instance

b)

On-Demand Instance

c)

Partial Upfront Reserved Instance

d)

No Upfront Reserved Instance

47.

A company has a MySQL database running on a single Amazon EC2 instance. The company now requires higher availability in the event of an outage. Which set of tasks would meet this requirement?

a)

Add an Application Load Balancer in front of the EC2 instance

b)

Configure EC2 Auto Recovery to move the instance to another Availability Zone

c)

Migrate to Amazon RDS and enable Multi-AZ

d)

Enable termination protection for the EC2 instance to avoid outages

48.

A company wants to ensure that AWS Management Console users are meeting password complexity requirements. How can the company configure password complexity?

a)

Using an AWS IAM user policy

b)

Using an AWS Organizations service control policy (SCP)

c)

Using an AWS IAM account password policy

d)

Using an AWS Security Hub managed insight

49.

Under the AWS shared responsibility model, which of the following is the customer's responsibility?

a)

Patching guest OS and applications

b)

Patching and fixing flaws in the infrastructure

c)

Physical and environmental controls

d)

Configuration of AWS infrastructure devices

50.

Which of the following tasks is required to deploy a PCI-compliant workload on AWS?

a)

Use any AWS service and implement PCI controls at the application layer

b)

Use an AWS service that is in-scope for PCI compliance and raise an AWS support ticket to enable PCI compliance at the application layer

c)

Use any AWS service and raise an AWS support ticket to enable PCI compliance on that service

d)

Use an AWS service that is in scope for PCI compliance and apply PCI controls at the application layer

51.
A company is building an application that requires the ability to send, store, and receive messages between application components. The company has another requirement to process messages in first-in, first-out (FIFO) order. Which AWS service should the company use?
a)
AWS Step Functions
b)
Amazon Simple Notification Service (Amazon SNS)
c)
Amazon Kinesis Data Streams
d)
Amazon Simple Queue Service (Amazon SQS)
52.

AnyCompany recently purchased Example Corp. Both companies use AWS resources, and AnyCompany wants a single aggregated bill. Which option allows AnyCompany to receive a single bill?

a)

Example Corp. must submit a request to its AWS solutions architect or AWS technical account manager to link the accounts and consolidate billing.

b)

AnyCompany must create a new support case in the AWS Support Center requesting that both bills be combined.

c)

Send an invitation to join the organization from AnyCompany's AWS Organizations master account to Example Corp.

d)

Migrate the Example Corp. VPCs, Amazon EC2 instances, and other resources into the AnyCompany AWS account.

53.

Which tool can be used to create alerts when the actual or forecasted cost of AWS services exceeds a certain threshold?

a)

Cost Explorer

b)

AWS Budgets

c)

AWS Cost and Usage Report

d)

AWS CloudTrail

54.

A user has limited knowledge of AWS services, but wants to quickly deploy a scalable Node.js application in the AWS Cloud. Which service should be used to deploy the application?

a)

AWS CloudFormation

b)

AWS Elastic Beanstalk

c)

Amazon EC2

d)

AWS OpsWorks

55.

Which AWS Trusted Advisor check is available to all AWS users?

a)

Core checks

b)

All checks

c)

Cost optimization checks

d)

Fault tolerance checks

56.

A web developer is concerned that a DDoS attack could target an application. Which AWS services or features can help protect against such an attack? (Choose two.)

a)

AWS Shield

b)

AWS CloudTrail

c)

Amazon CloudFront

d)

AWS Support Center

e)

AWS Service Health Dashboard

57.

Which AWS service gives users on-demand, self-service access to AWS compliance control reports?

a)

AWS Config

b)

Amazon GuardDuty

c)

AWS Trusted Advisor

d)

AWS Artifact

58.

A company wants to provide one of its employees with access to Amazon RDS. The company also wants to limit the interaction to only the AWS CLI and AWS software development kits (SDKs). Which combination of actions should the company take to meet these requirements while following the principles of least privilege? (Choose two.)

a)

Create an IAM user and provide AWS Management Console access only.

b)

Create an IAM user and provide programmatic access only.

c)

Create an IAM role and provide AWS Management Console access only.

d)

Create an IAM policy with administrator access and attach it to the IAM user.

e)

Create an IAM policy with Amazon RDS access and attach it to the IAM user.

59.

A company has a compliance requirement to record and evaluate configuration changes, as well as perform remediation actions on AWS resources. Which AWS service should the company use?

a)

AWS Config

b)

AWS Secrets Manager

c)

AWS CloudTrail

d)

AWS Trusted Advisor

60.

What are the advantages of deploying an application with Amazon EC2 instances in multiple Availability Zones? (Choose two.)

a)

Preventing a single point of failure

b)

Reducing the operational costs of the application

c)

Allowing the application to serve cross-region users with low latency

d)

Increasing the availability of the application

e)

Increasing the load of the application

61.

A company wants to review its monthly costs of using Amazon EC2 and Amazon RDS for the past year.
Which AWS service or tool provides this information?

a)

AWS Trusted Advisor

b)

Cost Explorer

c)

Amazon Forecast

d)

Amazon CloudWatch

62.


A company wants to migrate a critical application to AWS. The application has a short runtime. The application is invoked by changes in data or by shifts in system state. The company needs a compute solution that maximizes operational efficiency and minimizes the cost of running the application.
Which AWS solution should the company use to meet these requirements?

a)

Amazon EC2 On-Demand Instances

b)

AWS Lambda

c)

Amazon EC2 Reserved Instances

d)

Amazon EC2 Spot Instances

63.

Which AWS service or feature allows users to connect with and deploy AWS services programmatically?

a)

AWS Management Console

b)

AWS Cloud9

c)

AWS CodePipeline

d)

AWS software development kits (SDKs)

64.


A company plans to create a data lake that uses Amazon S3.
Which factor will have the MOST effect on cost?

a)

The selection of S3 storage tiers

b)

Charges to transfer existing data into Amazon S3

c)

The addition of S3 bucket policies

d)

S3 ingest fees for each request

65.


A company is launching an ecommerce application that must always be available. The application will run on Amazon EC2 instances continuously for the next
12 months.
What is the MOST cost-effective instance purchasing option that meets these requirements?

a)

Spot Instances

b)

Savings Plans

c)

Dedicated Hosts

d)

On-Demand Instances

66.

Which AWS service or feature can a company use to determine which business unit is using specific AWS resources?

a)

Cost allocation tags

b)

Key pairs

c)

Amazon Inspector

d)

AWS Trusted Advisor

67.


A company wants to migrate its workloads to AWS, but it lacks expertise in AWS Cloud computing.
Which AWS services or features will help the company with its migration?

SELECT TWO

a)

AWS Trusted Advisor


b)

AWS Consulting Partners


c)

AWS Artifacts


d)

AWS Managed Services


68.

Which AWS service or tool should a company use to centrally request and track service limit increases?


a)

AWS Config


b)

Service Quotas


c)

AWS Service Catalog


d)

AWS Budgets

Add individual feedback


69.

Which documentation does AWS Artifact provide?

a)

Amazon EC2 terms and conditions


b)

AWS ISO certifications


c)

A history of a company's AWS spending


d)

A list of previous-generation Amazon EC2 instance types


70.

Which task requires using AWS account root user credentials?

a)

Viewing billing information


b)

Changing the AWS Support plan


c)

Starting and stopping Amazon EC2 instances


d)

Opening an AWS Support case


71.


A company needs to simultaneously process hundreds of requests from different users.
Which combination of AWS services should the company use to build an operationally efficient solution?

a)

Amazon Simple Queue Service (Amazon SQS) and AWS Lambda


b)

AWS Data Pipeline and Amazon EC2


c)

Amazon Kinesis and Amazon Athena


d)

AWS Amplify and AWS AppSync

Add individual feedback


72.

What is the scope of a VPC within the AWS network?

a)

A VPC can span all Availability Zones globally.


b)

A VPC must span at least two subnets in each AWS Region.


c)

A VPC must span at least two edge locations in each AWS Region


d)

A VPC can span all Availability Zones within an AWS Region.


73.

Which of the following are components of an AWS Site-to-Site VPN connection? (Choose two.)

a)

AWS Storage Gateway


b)

Virtual private gateway


c)

NAT gateway


d)

Customer gateway


e)

Internet gateway

Add individual feedback


74.

A company needs to establish a connection between two VPCs. The VPCs are located in two different AWS Regions. The company wants to use the existing infrastructure of the VPCs for this connection.
Which AWS service or feature can be used to establish this connection?

a)

AWS Client VPN

b)

VPC peering

c)

AWS Direct Connect

d)

VPC endpoints

75.

According to the AWS shared responsibility model, what responsibility does a customer have when using Amazon RDS to host a database?

a)

Manage connections to the database

b)

Install Microsoft SQL Server

c)

Design encryption-at-rest strategies

d)

Apply minor database patches

76.

What are some advantages of using Amazon EC2 instances to host applications in the AWS Cloud instead of on premises? (Choose two.)

a)

EC2 includes operating system patch management.


b)

EC2 integrates with Amazon VPC, AWS CloudTrail, and AWS Identity and Access Management (IAM).


c)

EC2 has a 100% service level agreement (SLA).


d)

EC2 has a flexible, pay-as-you-go pricing model.


e)

EC2 has automatic storage cost optimization.


77.

A user needs to determine whether an Amazon EC2 instance's security groups were modified in the last month.
How can the user see if a change was made?

a)

Use Amazon EC2 to see if the security group was changed.


b)

Use AWS Identity and Access Management (IAM) to see which user or role changed the security group.


c)

Use AWS CloudTrail to see if the security group was changed.


d)

Use Amazon CloudWatch to see if the security group was changed.


78.

Which AWS service will help protect applications running on AWS from DDoS attacks?

a)

Amazon GuardDuty


b)

AWS WAF

c)

AWS Shield


d)

Amazon Inspector


79.

Which AWS service or feature acts as a firewall for Amazon EC2 instances?

a)

Network ACL


b)

Elastic network interface


c)

Amazon VPC


d)

Security group


80.

How does the AWS Cloud pricing model differ from the traditional on-premises storage pricing model?

a)

AWS resources do not incur costs


b)

There are no infrastructure operating costs


c)

There are no upfront cost commitments


d)

There are no software licensing costs

Add individual feedback


81.


A company has a single Amazon EC2 instance. The company wants to adopt a highly available architecture.
What can the company do to meet this requirement?

a)

Scale vertically to a larger EC2 instance size.


b)

Scale horizontally across multiple Availability Zones.


c)

Purchase an EC2 Dedicated Instance.


d)

Change the EC2 instance family to a compute optimized instance.

Add individual feedback


82.

A company's on-premises application deployment cycle was 3-4 weeks. After migrating to the AWS Cloud, the company can deploy the application in 2-3 days.
Which benefit has this company experienced by moving to the AWS Cloud?

a)

Elasticity


b)

Flexibility

c)

Agility

d)

Resilience

83.

Which of the following are included in AWS Enterprise Support? (Choose two.)


a)

AWS technical account manager (TAM)


b)

AWS partner-led support


c)

AWS Professional Services


d)

Support of third-party software integration to AWS


e)

5-minute response time for critical issues


84.

A global media company uses AWS Organizations to manage multiple AWS accounts.
Which AWS service or feature can the company use to limit the access to AWS services for member accounts?

a)

AWS Identity and Access Management (IAM)

b)

Service control policies (SCPs)

c)

Organizational units (OUs)

d)

Access control lists (ACLs)

85.

A company wants to limit its employees' AWS access to a portfolio of predefined AWS resources.
Which AWS solution should the company use to meet this requirement?

a)

AWS Config


b)

AWS software development kits (SDKs)


c)

AWS Service Catalog


d)

AWS AppSync


86.

An online company was running a workload on premises and was struggling to launch new products and features. After migrating the workload to AWS, the company can quickly launch products and features and can scale its infrastructure as required.
Which AWS Cloud value proposition does this scenario describe?

a)

Business agility

b)

High availability

c)

Security

d)

Centralized auditing

87.

Which of the following are advantages of the AWS Cloud? (Choose two.)

a)

AWS management of user-owned infrastructure


b)

Ability to quickly change required capacity


c)

High economies of scale


d)

Increased deployment time to market


e)

Increased fixed expenses


88.

AWS has the ability to achieve lower pay-as-you-go pricing by aggregating usage across hundreds of thousands of users.
This describes which advantage of the AWS Cloud?

a)

Launch globally in minutes


b)

Increase speed and agility


c)

High economies of scale


d)

No guessing about compute capacity

Add individual feedback


89.


A company has a database server that is always running. The company hosts the server on Amazon EC2 instances. The instance sizes are suitable for the workload. The workload will run for 1 year.
Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?

a)

Standard Reserved Instances


b)

On-Demand Instances


c)

Spot Instances


d)

Convertible Reserved Instances


90.

A company is developing a mobile app that needs a high-performance NoSQL database.
Which AWS services could the company use for this database? (Choose two.)

a)

Amazon Aurora


b)

Amazon RDS


c)

Amazon Redshift


d)

Amazon DocumentDB (with MongoDB compatibility)


e)

Amazon DynamoDB


91.

A company plans to use an Amazon Snowball Edge device to transfer files to the AWS Cloud.
Which activities related to a Snowball Edge device are available to the company at no cost?

a)

Use of the Snowball Edge appliance for a 10-day period


b)

The transfer of data out of Amazon S3 and to the Snowball Edge appliance


c)

The transfer of data from the Snowball Edge appliance into Amazon S3


d)

Daily use of the Snowball Edge appliance after 10 days


92.

A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify infrastructure deployments that do not meet best practices.
Which AWS service can the company use to meet these requirements?

a)

AWS Trusted Advisor


b)

Amazon Inspector


c)

AWS Config


d)

Amazon GuardDuty


93.

A company has a centralized group of users with large file storage requirements that have exceeded the space available on premises. The company wants to extend its file storage capabilities for this group while retaining the performance benefit of sharing content locally.
What is the MOST operationally efficient AWS solution for this scenario?

a)

Create an Amazon S3 bucket for each user. Mount each bucket by using an S3 file system mounting utility.


b)

Configure and deploy an AWS Storage Gateway file gateway. Connect each user’s workstation to the file gateway.


c)

Move each user’s working environment to Amazon WorkSpaces. Set up an Amazon WorkDocs account for each user.


d)

Deploy an Amazon EC2 instance and attach an Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS volume. Share the EBS volume directly with the users.

Add individual feedback


94.

According to security best practices, how should an Amazon EC2 instance be given access to an Amazon S3 bucket?

a)

Hard code an IAM user’s secret key and access key directly in the application, and upload the file.


b)

Store the IAM user’s secret key and access key in a text file on the EC2 instance, read the keys, then upload the file.


c)

Have the EC2 instance assume a role to obtain the privileges to upload the file.


d)

Modify the S3 bucket policy so that any service can upload to it at any time.


95.

Which option is a customer responsibility when using Amazon DynamoDB under the AWS Shared Responsibility Model?

a)

Physical security of DynamoDB


b)

Patching of DynamoDB


c)

Access to DynamoDB tables


d)

Encryption of data at rest in DynamoDB


96.

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

a)

Sustainability

b)

Performance efficiency


c)

Governance


d)

Reliability

97.

A company is running and managing its own Docker environment on Amazon EC2 instances. The company wants an alternative to help manage cluster size, scheduling, and environment maintenance.
Which AWS service meets these requirements?

a)

AWS Lambda


b)

Amazon RDS


c)

AWS Fargate


d)

Amazon Athena


98.

A company wants to run a NoSQL database on Amazon EC2 instances.
Which task is the responsibility of AWS in this scenario?

a)

Update the guest operating system of the EC2 instances.


b)

Maintain high availability at the database layer.


c)

Patch the physical infrastructure that hosts the EC2 instances.


d)

Configure the security group firewall.


99.

Which AWS services or tools can identify rightsizing opportunities for Amazon EC2 instances? (Choose two.)

a)

AWS Cost Explorer

b)

AWS Billing Conductor

c)

Amazon CodeGuru

d)

Amazon SageMaker


e)

AWS Compute Optimizer


100.

Which of the following are benefits of using AWS Trusted Advisor? (Choose two.)

a)

Providing high-performance container orchestration


b)

Creating and rotating encryption keys


c)

Detecting underutilized resources to save costs


d)

Improving security by proactively monitoring the AWS environment


e)

Implementing enforced tagging across AWS resources


101.

Which pillar of the AWS Well-Architected Framework includes principles such as:

Use serverless architectures

Democratize advanced technologies

Go global in minutes

a)

Cost optimisation

b)

Sustainability

c)

Reliability

d)

Performance efficiency

102.

A company is designing a new a service that must align with the operational excellence pillar of the AWS Well-Architected Framework. Which design principles should the company follow? (Select TWO.)

a)

Anticipate failure.

b)

Make large-scale changes.

c)

Perform operations as code.

d)

Perform manual operations.

e)

Create static operational procedures.

103.

A national library is planning to store around 50 TB of data containing all their books, articles and other written materials in AWS. One of the requirements is to have a search feature to enable the users to look for their collection on their dynamic website.

 

As a Cloud Engineer, what is the most suitable solution that you should implement in AWS to satisfy the needed functionality?

a)

Use Elastic Beanstalk as the deployment service. Deploy the needed AWS resources such as the Multi-AZ RDS for storage and an EC2 instance to host their website

b)

Use CloudFormation as the deployment service to deploy the needed AWS resources such as an S3 bucket for storage; CloudSearch to provide the needed search functionality, and an EC2 instance to host their website

c)

Use CodeDeploy as the deployment service to deploy two S3 buckets in which the first one serves as the storage service and the second one for hosting their dynamic website. Use the native search functionality of S3 to satisfy the search feature requirement

d)

Use OpsWorks as the deployment service to deploy Kinesis as the storage service and an EC2 instance to serve their website