Font size
S
M
L
XL
WorksheetsAWS Cloud Practitioner Exam #2
Total questions: 65
Worksheet time: 33mins
Name
Class
Date
1.
Which AWS service helps users to collect, process, and analyze real-time streaming data from sources including operating logs, financial transactions, and social media feeds?
a)
Amazon Kinesis
b)
AWS Direct Connect
c)
Amazon Redshift
d)
Amazon Athena
2.
A company is running a production workload on AWS.
Which AWS Support plan will provide the company with technical support within 15 minutes of a user opening a case concerning a critical service interruption?
a)
Basic support
b)
Developer Support
c)
Business support
d)
Enterprise Support
3.
A company is developing a new application that will be hosted in the AWS Cloud. The company needs to make changes to the application and the AWS resources that it uses.
What is a characteristic of the AWS Cloud that would meet this requirement?
a)
Elasticity
b)
Reliability
c)
Performance
d)
Agility
4.
Which AWS service or feature can prevent SQL injection attacks?
a)
Security Groups
b)
Network ACLs
c)
AWS WAF
d)
IAM Policies
5.
How can a company isolate the costs of production and non-production workloads on AWS?
a)
Create AWS IAM roles for production and non-production workloads
b)
Use different accounts for produciton and non-poroduction expenses
c)
Use Amazon EC2 for non-production workloads and other services for production workloads
d)
Use Amazon CloudWatch to monitor the use of services
6.
Which AWS service or feature can be used to block traffic to a specific port on Amazon EC2 instances?
a)
Network ACL
b)
AWS Direct Connect
c)
Amazon Route 53
d)
Amazon VPC peering connections
7.
Which AWS service or feature will automatically scale with an expected increase in web traffic?
a)
AWS CodePipeline
b)
Elastic Load Balancing
c)
Amazon Elastic Block Store
d)
AWS DIrect COnnect
8.
A company wants to use Amazon EC2 to deploy a global commercial application. The deployment solution should be built with the highest redundancy and fault tolerance.
How should the EC2 instances be deployed?
a)
In a single Availability Zone in one AWS Region
b)
With multiple elastic network interfaces belonging to different subnets
c)
Across multiple Availability Zones in one AWS Region
d)
Across multiple Availability Zones in two AWS Regions
9.
Which controls or features are shared controls according to the AWS shared responsibility model? (Select TWO.)
a)
Physical security controls
b)
Environmental controls
c)
Patch management
d)
Zone Security
e)
Configuration Management
10.
Which AWS Cloud benefit gives users the ability to provision only the resources required and to instantly scale up or down as demand changes?
a)
High availability
b)
Cost savings
c)
security
d)
elasticity
11.
A company needs to perform a one-time migration of 40 TB of data from its on-premises storage servers to Amazon S3. The transfer must happen as quickly as possible while keeping costs to a minimum. The company has 100 Mbps internet connectivity.
Which AWS service will meet these requirements?
a)
AWS Snowball Edge
b)
AWS Direct Connect
c)
AWS Storage Gateway
d)
Amazon S3 Transfer Acceleration
12.
A company runs an application on an Amazon EC2 instance that needs to securely write data to an Amazon S3 bucket without the use of long-term credentials.
Which AWS service or feature will meet this requirement?
a)
Amazon Cognito
b)
AWS SHield
c)
IAM role
d)
IAM user access key
13.
A company that is migrating to the AWS Cloud wants guidance about operational risk management. The company wants to lower its overall risk profile.
Which perspective of the AWS Cloud Adoption Framework (AWS CAF) provides guidance on risk management?
a)
Busniess perspective
b)
Security perspective
c)
Governance perspective
d)
Operations perspective
14.
A company hosts a website on an Amazon EC2 instance. The company wants to reduce latency for global users of the website.
Which AWS service will meet this requirement?
a)
AWS Outposts
b)
AWS Snowball Edge
c)
Amazon CloudFront
d)
AWS CloudFormation
15.
A company needs to deploy an Amazon EC2 instance and attach a storage mount for the operating system and application files.
Which AWS service will meet these requirements?
a)
AWS backup
b)
Amazon Elastic File System (EFS)
c)
Amazon S3
d)
Amazon Elastic Block Store (EBS)
16.
Which AWS service helps users meet contractual and regulatory compliance requirements for data security by using dedicated hardware appliances within the AWS Cloud?
a)
AWS Secrets Manager
b)
AWS CloudHSM
c)
AWS Key Management Service (KMS)
d)
AWS DIrectory Service
17.
Which tasks will AWS perform according to the AWS shared responsibility model? (Select TWO.)
a)
Configure IAM ysers according to the principle of least privilege
b)
Determine which services are allowed to access an Amazon DynamoDB table
c)
Patch Elastic Load Balancing load balancers
d)
Configure an Amazon S3 bucket to allow public access
e)
Control physical access to a data center that contains a user's VPC
18.
A company wants assistance in creating a cloud environment for its business.
Which AWS service or feature can the company use to find a third party to assist with the deployment?
a)
AWS Cloud Development Kit
b)
AWS Partner Network
c)
AWS Support
d)
AWS Trusted Advisor
19.
Which AWS services can be used to provide network connectivity between an on-premises network and a VPC? (Select TWO.)
a)
Amazon Route 53
b)
AWS Direct Connect
c)
AWS Data Exchange
d)
AWS VPN
e)
Amazon Connect
20.
Which service's PRIMARY purpose is software version control?
a)
AWS CodeStar
b)
AWS Command Line Interface
c)
Amazon Cognito
d)
AWS CodeCommit
21.
A company wants to improve the overall availability and performance of its applications that are hosted on AWS.
Which AWS service should the company use?
a)
Amazon Connect
b)
Amazon Lightsail
c)
AWS Global Accelorator
d)
AWS Storage Gateway
22.
A company wants to increase its ability to recover its infrastructure in the case of a natural disaster.
Which pillar of the AWS Well-Architected Framework does this ability represent?
a)
Cost Optimization
b)
Performance efficiency
c)
Reliability
d)
Security
23.
Which AWS security mechanisms can be used to restrict or permit access to resources within a VPC? (Select TWO.)
a)
Network ACL
b)
Elastic network interface
c)
Route table
d)
Security group
e)
VPC Flow logs
24.
A company needs a relational database on AWS that records new customer orders from a website.
Which AWS service or feature will meet this requirement?
a)
Amazon Aurora
b)
Amazon Neptune
c)
Amazon DynamoDB
d)
Amazon Redshift
25.
A company does not own a physical data center but needs a network solution that connects employee laptops directly to the AWS Cloud.
Which AWS service will meet this requirement?
a)
Amazon Connect
b)
AWS Client VPN
c)
AWS Direct Connect
d)
AWS Site-to-Site VPN
26.
Which AWS service or feature gives a company the ability to analyze AWS costs and usage over time?
a)
AWS Budgets
b)
AWS Cost Explorer
c)
AWS Organizations
d)
Consolidated billing
27.
A user must encrypt data that is received, stored, and managed by AWS CloudTrail.
Which AWS service will provide this capability?
a)
AWS Secrets Manager
b)
AWS Systems Manager
c)
AWS Key Management Service (KMS)
d)
AWS Certificate Manager
28.
Which service gives customers the ability to audit and monitor changes in AWS resources?
a)
AWS Trusted advisor
b)
Amazon GuardDuty
c)
Amazon Inspector
d)
AWS Config
29.
A cloud practitioner needs an Amazon EC2 instance to launch and run for 7 hours without interruptions.
What is the MOST cost-effective option for this task?
a)
On-Demand Instance
b)
Reserved Instance
c)
Dedicated Instance
d)
Spot Instance
30.
Which AWS service enables the decoupling and scaling of applications?
a)
Amazon Simple Queue Service (Amazon SQS)
b)
AWS OUtposts
c)
Amazon S3
d)
Amazon SImple Email Service (SES)
31.
A company wants to deploy a stateless application where occasional downtime is acceptable.
What is the MOST affordable Amazon EC2 pricing option available for this use case?
a)
On-demand instances
b)
reserved instances
c)
on-demand capacity reservations
d)
spot instances
32.
Which AWS service adds speech-to-text capabilities to applications?
a)
Amazon POlly
b)
Amazon Textract
c)
Amazon Transcribe
d)
Amazon Comprehend
33.
Which service or feature should be used to limit Amazon S3 bucket access to specific users?
a)
AWS Key Management Service (KMS)`
b)
Netork ACL
c)
IAM plicies
d)
Security groups
34.
A company is going through a compliance inspection for ISO 20017.
Which AWS service or tool can the company use to download the ISO certifications?
a)
AWS Trusted Advisor
b)
AWS Artifact
c)
AWS Well-Architected Tool (WA Tool)
d)
AWS Shield
35.
Which AWS service or tool reduces latency for static websites running on AWS?
a)
AWS Lambda
b)
AMazon CloudFront
c)
AMazon S3 Transfer Acceleration
d)
AWS Data Exchange
36.
Which AWS service will help a company identify the user who deleted an Amazon EC2 instance yesterday?
a)
Amazon CloudWatch
b)
AWS Trusted Advisor
c)
AWS CLoudTrail
d)
Amazon Inspector
37.
A company wants to quickly deploy duplicate infrastructure in a different AWS Region to create global redundancy.
Which AWS service will meet this requirement?
a)
Amazon API Gateway
b)
AWS CloudFormation
c)
Amazon Route 53
d)
AWS Config
38.
A company is running a web application on Amazon EC2 instances. The company wants the application's compute capacity to automatically adjust to meet customer demand.
Which AWS service or capability should the company use to meet this requirement?
a)
AWS Compute Optimizer
b)
Amazon EC2 Auto Scaling
c)
AWS Launch Wizard
d)
AWS AppConfig
39.
Which solution describes a security best practice that can be implemented by using AWS Identity and Access Management (IAM)?
a)
Turn off AWS Management Console access for all user
b)
Generate secret keys for every IAM user
c)
Grant permissions to user who are required to perform a specific task only
d)
Store AWS credentials within Amazon EC2 instances
40.
Which AWS hybrid storage service enables a user's on-premises applications to seamlessly use AWS Cloud storage?
a)
AWS Backup
b)
Amazon Connect
c)
AWS Direct Connect
d)
AWS Storage Gateway
41.
Which perspective of the AWS Cloud Adoption Framework (AWS CAF) connects technology and business?
a)
Operations
b)
People
c)
Security
d)
Governance
42.
How should Reserved Instances be shared across multiple AWS accounts?
a)
AWS Cost Explorer activated on all AWS accounts
b)
AWS Organizations consolidated billing
c)
AWS Compute Optimizer activated on all AWS accounts
d)
IAM cross-account roles
43.
What are the benefits of using the AWS Cloud? (Select TWO.)
a)
Increased speed and agility
b)
No risk of security breaches
c)
Removes the need to patch user software
d)
All user data is backed up globally
e)
Ability to deploy globally in minutes
44.
A company wants to enhance security for AWS Identity and Access Management (IAM) users in an AWS account.
Which methods should be used to add security to IAM users? (Select TWO.)
a)
Implement Amazon Rekognition
b)
Use AWS Shield Protected resources
c)
Block access with security groups
d)
Use multi-factor autentication (MFA)
e)
enforce password strength and expiration
45.
A company needs to establish an AWS Site-to-Site VPN tunnel.
Which type of gateway should the company use?
a)
Internet gateway
b)
NAT gatewayr
c)
Virtual private gateway
d)
AWS Direct Connect gateway
46.
Which services can be used to deploy applications on AWS?
a)
AWS Elastic Beanstalk
b)
AWS Config
c)
AWS Application Discovery Service
d)
Amazon Kinesis Data Streams
47.
What is a benefit of the pay-as-you-go pricing model for AWS services?
a)
Reduces fixed costs
b)
Requires payment up front for AWS services
c)
Relevant only for Amazon EC2, Amazon S3, and Amazon RDS
d)
Reduces variable costs
48.
Which AWS services or features enable a user to establish a network connection from on premises to the AWS Cloud? (Select TWO.)
a)
AWS DIrect Connect
b)
AWS Snowball Edge
c)
Amazon S3
d)
AWS VPN
e)
Amazon Connect
49.
A company is developing a mobile app that needs a high-performance NoSQL database.
Which AWS services could the company use for this database? (Select TWO.)
a)
Amazon Aurora
b)
Amazon RDS
c)
Amazon Redshift
d)
Amazon DocumentDB (with MongoDB compatibility)
e)
Amazon DynamoDB
50.
Which recommendations are included in the AWS Trusted Advisor checks? (Select TWO.)
a)
Amazon S3 bucket permissions
b)
AWS service outages for services
c)
Multi-factor authentication use on the AWS account root user
d)
Available software patches for Amazon EC2 instances
e)
Number of users in the account
51.
Within the AWS shared responsibility model, which activities are the user's responsibility? (Select TWO.)
a)
Pathc operating sustem components for Amazon RDS
b)
Encrypt data on the client side
c)
Train the data center staff
d)
Configure network access conrol lists
e)
Maintain environmental controls within a data center
52.
A company requires physical isolation of its Amazon EC2 instances from the instances of other customers.
Which instance purchasing option meets this requirement?
a)
Dedicated Hosts
b)
Reserves Instances
c)
On-Demand instances
d)
Spot instances
53.
Which AWS service helps protect applications that run on AWS from DDoS attacks?
a)
AWS GuardDuty
b)
AWS auto scaling
c)
AWS Shield
d)
Amazon inspector
54.
Which AWS Cloud service should be used to run a self-managed relational database?
a)
Amazon EC2
b)
Amazon Route 53
c)
Amazon ElastiCache
d)
Amazon DynamoDB
55.
A company is planning to move to the AWS Cloud. The company wants guidance and best practices to guide key stakeholders on the cloud migration process.
Which AWS service or guidance will meet this requirement?
a)
AWS Well-Architected Framework
b)
Amazon Connect
c)
AWS Support
d)
AWS Cloud Adoption Framework (AWS CAF)
56.
Which of the following are pillars of the AWS Well-Architected Framework? (Select TWO.)
a)
Multiple availability zones
b)
Performance efficiency
c)
Sustainability
d)
Encryption usage
e)
High availability
57.
Which AWS service runs containers without the need to provision and manage Amazon EC2 instances?
a)
AWS Elastic Beanstalk
b)
Amazon Lightsail
c)
AWS Batch
d)
AWS fargate
58.
Which AWS service allows users to provision infrastructure as code?
a)
AWS COdeBuild
b)
AWS CloudFormation
c)
AWS Organizations
d)
AWS CodeCommit
59.
A company plans to migrate an application workload to the AWS Cloud.
Which control is the responsibility of AWS after the migration is complete?
a)
Patch the guest operating system
b)
Maintain physical and environmental controls
c)
Identify and protect personally identifiable information
d)
Patch customer-owned applications and customer-created applications
60.
A company wants to run a workload on the AWS Cloud.
What is the customer's responsibility? (Select TWO).
a)
Configure an Amazon S3 bucket so that the bucket is restricted to certain IAM users
b)
Control the physical access to the AWS resources that contain a customer's VPC
c)
Configure permissions for IAM users for least-privilege access
d)
Patch the operating system used by AWS Lambda functions
e)
Patch the VPC network devices
61.
Which AWS service provides on-demand downloads of AWS security and compliance documentation?
a)
AWS Directory Service
b)
AWS Artifact
c)
AWS trusted Advisor
d)
Amazon inspector
62.
Management at a large company wants to avoid long-term contracts and is interested in AWS to move from fixed costs to variable costs.
What is the value proposition of AWS for this company?
a)
Economy of scale
b)
Pay-as-you-go pricing
c)
Volume discounts
d)
Cost optimization
63.
A company is reviewing the current costs of running its own infrastructure on premises. The company wants to compare these on-premises costs to the costs of running infrastructure in the AWS Cloud.
How should the company make this comparison?
a)
Review the AWS shared responsibility model
b)
Audit existing software and hardware licensing costs
c)
Analyze the AWS well-architected framework
d)
Use Migration Evaluator
64.
What is a responsibility of AWS in the shared responsibility model?
a)
Updating the netwokr ACLs to block traffic to vulnerable ports
b)
Patching operating sustems running Amazon EC2 instances
c)
Updating the firmware o nthe underlying Amazon EC2 hosts
d)
Updating the security group rules to block traffic to the vulnerable ports
65.
After a merger, a company inherits an AWS account with an existing infrastructure. The company needs to ensure that the infrastructure follows AWS best practices for cost optimization, security, and performance efficiency.
Which AWS service or tool should the company use to meet these requirements?
a)
AWS Cost Explorer
b)
AWS Config
c)
AWS Compute Optimizer
d)
AWS Well-Architected Tool
Reset
