wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Practice Questions Part 3

Total questions: 72

Worksheet time: 36mins

Name
Class
Date
1.

Which AWS support plans provide access to AWS Incident Detection and Response at an additional cost?

a)

AWS Developer Support

b)

AWS Business Support

c)

AWS Enterprise On-Ramp Support

d)

AWS Enterprise Support

2.

Which capabilities are in the security perspective of AWS Cloud Adoption Framework?

a)

Patch Management

b)

IAM

c)

Risk Management

d)

Strategy Management

3.

Which AWS support plans provide customers with annual consultative and architectural guidance?

a)

AWS Developer Support

b)

AWS Business Support

c)

AWS Enterprise On-Ramp Support

d)

AWS Enterprise Support

4.

A company needs to connect multiple VPCs and on-premises networks through a single network connection to the AWS cloud. Which solution meets this requirement?

a)

AWS Transit Gateway

b)

AWS Direct Connect

c)

AWS VPC Peering

d)

AWS Client VPN

5.

Which actions are the responsibility of AWS under the AWS Shared Responsibility Model? (Select Two)

a)

Scanning AWS Service Endpoints for Vulnerabilities

b)

Enabling Encryption on an Amazon S3 Bucket

c)

Configuring Security Group Rules

d)

Encrypting Traffic on the AWS Backbone between Global and Regional AWS Facilities

6.

Which AWS service helps protect applications against Distributed Denial of Service (DDoS) attacks?

a)

AWS Firewall Manager

b)

AWS Shield

c)

Amazon Inspector

d)

AWS Config

7.

Which of the following tasks are the responsibility of the customer under the AWS shared responsibility model? (Select TWO)

a)

Managing physical security of AWS data centers

b)

Patching the guest operating system

c)

Patching the network infrastructure

d)

Configuring security groups

e)

Maintaining hardware components

8.

Which AWS service allows users to run code without provisioning or managing servers?

a)

Amazon EC2

b)

AWS Fargate

c)

AWS Lambda

d)

AWS Elastic Beanstalk

9.

Which service provides a virtual firewall to control inbound and outbound traffic for Amazon EC2 instances?

a)

AWS WAF

b)

AWS Shield

c)

Security Groups

d)

Network ACLs

10.

What is the purpose of Amazon CloudWatch?

a)

Store log files

b)

Monitor AWS resources and applications

c)

Automatically scale resources

d)

Provision infrastructure as code

11.

Which AWS service enables you to manage users and their access to AWS services and resources?

a)

AWS Directory Service

b)

AWS IAM

c)

Amazon Cognito

d)

AWS KMS

12.

Which service lets you set up private network connectivity between your data center and AWS?

a)

AWS VPN

b)

Amazon VPC

c)

AWS Direct Connect

d)

AWS Transit Gateway

13.

Which service helps automate security assessments of applications deployed on AWS?

a)

AWS Shield

b)

Amazon GuardDuty

c)

Amazon Inspector

d)

AWS Config

14.

Which feature of Amazon VPC allows you to capture information about the IP traffic going to and from network interfaces?

a)

VPC Peering

b)

VPC Flow Logs

c)

NAT Gateway

d)

Subnet Route Tables

15.

Which service allows AWS customers to define a virtual network in their AWS account?

a)

Amazon EC2

b)

Amazon VPC

c)

AWS Direct Connect

d)

AWS Lambda

16.

Which service helps detect unauthorized and malicious activity in your AWS accounts?

a)

AWS CloudTrail

b)

AWS Config

c)

Amazon Inspector

d)

Amazon GuardDuty

17.

Which AWS service makes it easier to migrate databases to AWS quickly and securely?

a)

AWS Database Migration Service (DMS)

b)

AWS Snowball

c)

Amazon RDS

d)

AWS DataSync

18.

Which service helps you to define and enforce organizational units and service control policies (SCPs)?

a)

AWS IAM

b)

AWS Organizations

c)

AWS Shield

d)

AWS Config

19.

What are the AWS global infrastructure composed of?

a)

Availability Zones and Regions

b)

Regions and Edge Locations

c)

Availability Zones, Regions, and Edge Locations

d)

Data Centres and Servers

20.

Which AWS service allows developers to deploy and manage applications without dealing with the infrastructure?

a)

AWS CloudFormation

b)

AWS CodeDeploy

c)

AWS Lambda

d)

AWS Elastic Beanstalk

21.

Which AWS support plan provides a Technical Account Manager (TAM)?

a)

Developer Support

b)

Business Support

c)

Enterprise On-Ramp Support

d)

Enterprise Support

22.

Which tool helps you view and manage your AWS spending and usage?

a)

AWS Budgets

b)

AWS Cost Explorer

c)

AWS Trusted Advisor

d)

Amazon CloudWatch

23.

Which storage class is ideal for data that is accessed infrequently, but requires rapid access when needed?

a)

Amazon S3 Glacier

b)

Amazon S3 Intelligent-Tiering

c)

Amazon S3 Standard-IA

d)

Amazon EBS Cold HDD

24.

Which AWS service enables real-time monitoring and alarming based on custom metrics?

a)

Amazon CloudWatch

b)

AWS Config

c)

AWS CloudTrail

d)

Amazon Inspector

25.

Which tool provides real-time guidance to help provision your resources following AWS best practices?

a)

AWS Config

b)

AWS Trusted Advisor

c)

AWS Budgets

d)

AWS Cost Explorer

26.

A company has an AWS account. The company wants to audit its password and access key rotation details. For compliance purposes, which AWS service or tool will meet this requirement?

a)

IAM Access Analyzer

b)

AWS Artifact

c)

IAM Credential Report

d)

AWS Audit Manager

27.

The company is planning to host its workloads on AWS. Which service requires the company to update and patch the guest operating system?

a)

Amazon DynamoDB

b)

Amazon S3

c)

Amazon EC2

d)

Amazon Aurora

28.

A company needs to use an offline transfer strategy to move petabytes of databases, backups, and data records from on-premises to the AWS cloud. Which solution will meet this requirement with the most operational efficiency?

a)

AWS Snowball Edge Compute Optimization

b)

AWS Snowcone Devices

c)

AWS Storage Gateway

d)

AWS DataSync

29.

Which AWS Enterprise Framework capabilities are in the Business Perspective?

a)

Data Engineering

b)

Risk Management

c)

Cloud Fluency

d)

Strategic Partnership

30.

Which actions are the responsibility of AWS under the AWS Shared Responsibility Model? (Select two)

a)

Scanning AWS services, service endpoints for vulnerabilities

b)

Enabling encryption on an Amazon S3 bucket

c)

Configuring security group rules

d)

Encrypting traffic on the AWS backbone between global and regional AWS services

31.

A company plans to deploy its application globally. The company wants to cache content at edge locations and deliver the content to users with the lowest possible latency. Which AWS service will meet these requirements?

a)

AWS Global Accelerator

b)

AWS Outposts

c)

Amazon Route 53

d)

Amazon CloudFront

32.

Which AWS service blocks SQL injection attacks?

a)

AWS WAF

b)

Network ACLs

c)

Security Groups

d)

Trusted Advisor

33.

Which AWS service inspects a user's AWS environment and makes recommendations for cost savings and system performance improvements?

a)

Cloud Explorer

b)

AWS Trusted Advisor

c)

Amazon Inspector

d)

AWS Budgets

34.

Which of the following are design principles for reliability in AWS Cloud? (Select two)

a)

Build architectures with tightly coupled resources

b)

Use AWS Trusted Advisor to meet security best practices

c)

Use automation to recover immediately from failure

d)

Stimulate failures to test recovery process

35.

What actions represent best practices for using AWS IAM?

a)

Confirm a strong password policy

b)

Share security credentials among AWS users in the same region

c)

Use access keys to log in to the AWS Management Console

d)

Avoid using IAM roles to delegate permissions

36.

A company needs to identify personally identifiable information such as credit card numbers from data stored in Amazon S3. Which AWS service should the company use?

a)

Amazon Inspector

b)

AWS Shield

c)

Amazon GuardDuty

d)

Amazon Macie

37.

A company uses AWS Organizations. The company wants to apply security best practices from the AWS Well-Architected Framework to all of its AWS accounts. Which service will meet these requirements?

a)

Amazon Macie

b)

Amazon Detective

c)

AWS Control Tower

d)

AWS Secrets Manager

38.

Which AWS services or features enable users to connect an on-premises network to a VPC? (Select two)

a)

AWS VPN

b)

Elastic Load Balancer

c)

AWS Direct Connect

d)

Amazon CloudFront

39.

A company is designing an IAM solution for an application. The company wants users to use their social media, email, or online shopping accounts for access. Which AWS service provides this functionality?

a)

AWS IAM Identity Center

b)

AWS Config

c)

AWS Cognito

d)

AWS IAM

40.

A company is using Amazon EC2 instances to test an application. The company needs to run uninterrupted tests for one month. Which EC2 instance purchasing option will meet these requirements most efficiently?

a)

On-Demand Instances

b)

Spot Instances

c)

Reserved Instances

d)

Compute Savings Plan

41.

Which cloud concept is demonstrated by using AWS Compute Optimizer?

a)

Security Validation

b)

Rightsizing

c)

Elasticity

d)

Global Reach

42.

Which AWS service or resource provides discounts on some AWS service costs in exchange for a spending commitment?

a)

Amazon Detective

b)

AWS Pricing Calculator

c)

Savings Plan

d)

Basic Support

43.

A company is considering moving to the AWS cloud. The company wants to scale compute resources to accommodate changing loads. Which benefit of AWS cloud does this scenario describe?

a)

Global Deployment in Minutes

b)

Cost Savings

c)

Security

d)

Elasticity

44.

A company needs to invoke an AWS Step Functions workflow each time an Amazon EC2 instance changes to 'running'. Which AWS service can the company use to meet these requirements?

a)

Amazon SageMaker

b)

Amazon Connect

c)

Amazon EventBridge

d)

AWS Fargate

45.

A company needs a serverless data integration service to discover, prepare, and combine data for analytics. Which AWS service will meet these requirements?

a)

Amazon EMR

b)

Amazon Redshift

c)

AWS Glue

d)

AWS Step Functions

46.

Which option is an environment that contains one or more data centers?

a)

Amazon Cloud Workfront

b)

Availability Zone

c)

VPC

d)

AWS Outposts

47.

A company plans to move its test workloads to Amazon EC2. The test workloads can be interrupted and are not required to start at a particular time. Which EC2 instance purchase option is most cost-effective for this use case?

a)

On-Demand Instances

b)

Spot Instances

c)

Reserved Instances

d)

Dedicated Instances

48.

What is the benefit of using AWS serverless computing?

a)

Application deployment and management are not required.

b)

Application security will be fully managed by AWS.

c)

Monitoring and logging are not needed.

d)

Management of infrastructure is offloaded to AWS.

49.

A company needs to manage multiple AWS accounts in a single unit. A company must consolidate billing for all the accounts. Which AWS service should the company use to meet these requirements?

a)

AWS Organizations

b)

AWS Resource Access Manager

c)

AWS IAM

d)

AWS Control Tower

50.

A team of researchers is going to collect data at remote locations around the world. Many locations do not have internet connectivity. The team needs to capture the data in the field and transfer it to the cloud later. Which AWS service will support this requirement?

a)

AWS Outposts

b)

AWS Transfer Family

c)

AWS Snow Family

d)

AWS Migration Hub

51.

Which AWS service or tool does AWS Control Tower use to create resources?

a)

AWS CloudFormation

b)

AWS Trusted Advisor

c)

AWS Directory Service

d)

AWS Cost Explorer

52.

A company needs to set up a user-defined isolated environment in the AWS cloud. Which of the following can help the company meet this requirement?

a)

AWS VPN

b)

AWS VPC

c)

AWS Legions

d)

Availability Service

53.

Which AWS service provides a single location to track the progress of application migrations?

a)

AWS Application Discovery Service

b)

AWS Application Migration Service

c)

AWS Service Catalog

d)

AWS Migration Hub

54.

A company is migrating a traditional database server to the AWS cloud. A company wants to migrate administrative overhead to the database maintenance task. Which AWS service will meet these requirements?

a)

Amazon DynamoDB

b)

Amazon EC2

c)

Amazon Redshift

d)

Amazon RDS

55.

Which actions are AWS security best practices for using IAM to manage an AWS account root user? (Select two)

a)

Set up MFA for the root user.

b)

Remove all IAM policies from the root user.

c)

Delete the root user access keys.

d)

Use the root user for daily tasks.

56.

A company plans to deploy its application globally. Which AWS service or feature can a company use to determine which business unit has unit-specific AWS resources?

a)

Cost allocation tags

b)

Key pairs

c)

Amazon Inspector

d)

AWS Trusted Advisor

57.

A company wants to identify Amazon S3 buckets that are shared with another AWS account. Which AWS service or feature will meet these requirements?

a)

AWS Lake Formation

b)

IAM Credential Reports

c)

Amazon CloudWatch

d)

IAM Access Analyzer

58.

If the company needs to plan, schedule, and run hundreds of thousands of computing jobs on AWS, which service can the company use to meet this requirement?

a)

AWS Step Functions

b)

AWS Service Catalog

c)

Amazon Simple Queue Service

d)

AWS Batch

59.

Which task is the responsibility of the customer according to the AWS Shared Responsibility Model?

a)

Maintain the security of the hardware that runs Amazon EC2 instances

b)

Patch the guest operating system of Amazon EC2 instances

c)

Protect the security of the AWS global infrastructure

d)

Patch Amazon RDS software

60.

Which of the following is a pillar of the AWS Well-Architected Framework?

a)

Redundancy

b)

Operational Excellence

c)

Availability

d)

Multi-Region

61.

A company wants to know more about the benefits offered by cloud computing. The company wants to understand the operational advantage of agility. How does AWS provide agility for users?

a)

The ability to ensure high availability by deploying workloads to multiple regions

b)

Apply Azure Go model for many services and resources

c)

The ability to transfer infrastructure management to the AWS cloud

d)

The ability to provision and deprovision resources quickly with minimal effort

62.

A company needs to encrypt data at rest in the AWS cloud by using an encryption key that the company controls. Which AWS service should the company use to meet this requirement?

a)

AWS Certificate Manager

b)

AWS Cognito

c)

AWS Key Management Service

d)

AWS Trusted Advisor

63.

Which AWS service should a cloud engineer use to view API calls to AWS services?

a)

Amazon CloudWatch

b)

AWS CloudTrail

c)

AWS Config

d)

AWS Artifact

64.

A company needs an AWS Support plan that provides programmatic case management through AWS Support API. Which plan is the most cost-effective?

a)

AWS Business Support

b)

AWS Basic Support

c)

AWS Developer Support

d)

AWS Enterprise Support

65.

Which cloud concept is demonstrated by using AWS Cost Explorer?

a)

Rightsizing

b)

Reliability

c)

Resilience

d)

Modernization

66.

Which AWS service can a company use to create a private, secured, and scalable network environment in the AWS Cloud?

a)

Amazon ECS

b)

Amazon S3

c)

Amazon VPC

d)

Route Tables

67.

Which options are benefits of using third-party software from AWS Marketplace?

a)

The software's data encryption is managed by a third-party vendor.

b)

The software has been evaluated by vendors to ensure that it will run on AWS.

c)

Users do not need to upgrade to newer software versions.

d)

Users do not need to conduct security testing on the software.

68.

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

a)

Patch AWS network devices.

b)

Set user password rules.

c)

Provide physical security for compute resources.

d)

Configure security groups.

69.

Which AWS service requires customers to be fully responsible for applying OS patches?

a)

Amazon DynamoDB

b)

AWS Lambda

c)

AWS Fargate

d)

Amazon EC2

70.

Which action should a company take to improve security in AWS accounts?

a)

Require multi-factor authentication (MFA) for privileged users

b)

Remove the root user account

c)

Create an access key for the AWS account root user

d)

Create an access key for each privileged user

71.

Which AWS feature is a deployable EC2 instance template that is prepackaged with software and security requirements?

a)

Amazon EBS volume

b)

AWS CloudFormation template

c)

Amazon EBS snapshot

d)

Amazon Machine Image (AMI)

72.

Which AWS Cloud Adoption Framework (CAF) security perspective capability helps identify security misconfigurations?

a)

Identity and access management

b)

Threat detection

c)

Platform engineering

d)

Availability and continuity management