AWS 2 Flashcards

1
Q

A company wants to use the AWS Cloud to provide secure access to desktop applications that are running in a fully managed environment.Which AWS service should the company use to meet this requirement?
A. Amazon S3
B. Amazon AppStream 2.0
C. AWS AppSync
D. AWS Outposts

A

B. Amazon AppStream 2.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A company wants to implement threat detection on its AWS infrastructure. However, the company does not want to deploy additional software.Which AWS service should the company use to meet these requirements?
A. Amazon VPC
B. Amazon EC2
C. Amazon GuardDuty
D. AWS Direct Connect

A

C. Amazon GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which AWS service uses edge locations?
A. Amazon Aurora
B. AWS Global Accelerator
C. Amazon Connect
D. AWS Outposts

A

B. AWS Global Accelerator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A company needs to install an application in a Docker container.Which AWS service eliminates the need to provision and manage the container hosts?
A. AWS Fargate
B. Amazon FSx for Windows File Server
C. Amazon Elastic Container Service (Amazon ECS)
D. Amazon EC2

A

A. AWS Fargate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which AWS service or feature checks access policies and offers actionable recommendations to help users set secure and functional policies?
A. AWS Systems Manager
B. AWS IAM Access Analyzer
C. AWS Trusted Advisor
D. Amazon GuardDuty

A

B. AWS IAM Access Analyzer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A company has a fleet of cargo ships. The cargo ships have sensors that collect data at sea, where there is intermittent or no internet connectivity. The company needs to collect, format, and process the data at sea and move the data to AWS later.Which AWS service should the company use to meet these requirements?
A. AWS IoT Core
B. Amazon Lightsail
C. AWS Storage Gateway
D. AWS Snowball Edge

A

D. AWS Snowball Edge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A retail company needs to build a highly available architecture for a new ecommerce platform. The company is using only AWS services that replicate data across multiple Availability Zones.Which AWS services should the company use to meet this requirement? (Choose two.)
A. Amazon EC2
B. Amazon Elastic Block Store (Amazon EBS)
C. Amazon Aurora
D. Amazon DynamoDB
E. Amazon Redshift

A

A. Amazon EC2
B. Amazon Elastic Block Store (Amazon EBS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which characteristic of the AWS Cloud helps users eliminate underutilized CPU capacity?
A. Agility
B. Elasticity
C. Reliability
D. Durability

A

B. Elasticity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Service control policies (SCPs) manage permissions for which of the following?
A. Availability Zones
B. AWS Regions
C. AWS Organizations
D. Edge locations

A

C. AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which AWS service can be used to encrypt data at rest?
A. Amazon GuardDuty
B. AWS Shield
C. AWS Security Hub
D. AWS Key Management Service (AWS KMS)

A

D. AWS Key Management Service (AWS KMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which characteristics are advantages of using the AWS Cloud? (Choose two.)
A. A 100% service level agreement (SLA) for all AWS services
B. Compute capacity that is adjusted on demand
C. Availability of AWS Support for code development
D. Enhanced security
E. Increases in cost and complexity

A

B. Compute capacity that is adjusted on demand
D. Enhanced security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A user is storing objects in Amazon S3. The user needs to restrict access to the objects to meet compliance obligations.What should the user do to meet this requirement?
A. Use AWS Secrets Manager.
B. Tag the objects in the S3 bucket.
C. Use security groups.
D. Use network ACLs.

A

B. Tag the objects in the S3 bucket.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A company wants to convert video files and audio files from their source format into a format that will play on smartphones, tablets, and web browsers.Which AWS service will meet these requirements?
A. Amazon Elastic Transcoder
B. Amazon Comprehend
C. AWS Glue
D. Amazon Rekognition

A

A. Amazon Elastic Transcoder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which of the following are benefits of Amazon EC2 Auto Scaling? (Choose two.)
A. Improved health and availability of applications
B. Reduced network latency
C. Optimized performance and costs
D. Automated snapshots of data
E. Cross-Region Replication

A

A. Improved health and availability of applications
C. Optimized performance and costs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

A company has several departments. Each department has its own AWS accounts for its applications. The company wants all AWS costs on a single invoice to simplify payment, but the company wants to know the costs that each department is incurring.Which AWS tool or feature will provide this functionality?
A. AWS Cost and Usage Reports
B. Consolidated billing
C. Savings Plans
D. AWS Budgets

A

B. Consolidated billing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A company runs its workloads on premises. The company wants to forecast the cost of running a large application on AWS.Which AWS service or tool can the company use to obtain this information?
A. AWS Pricing Calculator
B. AWS Budgets
C. AWS Trusted Advisor
D. Cost Explorer

A

A. AWS Pricing Calculator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

A company wants to eliminate the need to guess infrastructure capacity before deployments. The company also wants to spend its budget on cloud resources only as the company uses the resources.Which advantage of the AWS Cloud matches the company’s requirements?
A. Reliability
B. Global reach
C. Economies of scale
D. Pay-as-you-go pricing

A

D. Pay-as-you-go pricing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which AWS service supports a hybrid architecture that gives users the ability to extend AWS infrastructure, AWS services, APIs, and tools to data centers, co- location environments, or on-premises facilities?
A. AWS Snowmobile
B. AWS Local Zones
C. AWS Outposts
D. AWS Fargate

A

C. AWS Outposts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

A company has a physical tape library to store data backups. The tape library is running out of space. The company needs to extend the tape library’s capacity to the AWS Cloud.Which AWS service should the company use to meet this requirement?
A. Amazon Elastic Block Store (Amazon EBS)
B. Amazon S3
C. Amazon Elastic File System (Amazon EFS)
D. AWS Storage Gateway

A

D. AWS Storage Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

An online retail company has seasonal sales spikes several times a year, primarily around holidays. Demand is lower at other times. The company finds it difficult to predict the increasing infrastructure demand for each season.Which advantages of moving to the AWS Cloud would MOST benefit the company? (Choose two.)
A. Global footprint
B. Elasticity
C. AWS service quotas
D. AWS shared responsibility model
E. Pay-as-you-go pricing

A

B. Elasticity
E. Pay-as-you-go pricing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which AWS service can be used to turn text into lifelike speech?
A. Amazon Polly
B. Amazon Kendra
C. Amazon Rekognition
D. Amazon Connect

A

A. Amazon Polly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which AWS service or tool can be used to capture information about inbound and outbound traffic in an Amazon VPC?
A. VPC Flow Logs
B. Amazon Inspector
C. VPC endpoint services
D. NAT gateway

A

A. VPC Flow Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

A company wants to ensure that two Amazon EC2 instances are in separate data centers with minimal communication latency between the data centers.How can the company meet this requirement?
A. Place the EC2 instances in two separate AWS Regions connected with a VPC peering connection.
B. Place the EC2 instances in two separate Availability Zones within the same AWS Region.
C. Place one EC2 instance on premises and the other in an AWS Region. Then connect them by using an AWS VPN connection.
D. Place both EC2 instances in a placement group for dedicated bandwidth.

A

B. Place the EC2 instances in two separate Availability Zones within the same AWS Region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

In which situations should a company create an IAM user instead of an IAM role? (Choose two.)
A. When an application that runs on Amazon EC2 instances requires access to other AWS services
B. When the company creates AWS access credentials for individuals
C. When the company creates an application that runs on a mobile phone that makes requests to AWS
D. When the company needs to add users to IAM groups
E. When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time

A

B. When the company creates AWS access credentials for individuals
D. When the company needs to add users to IAM groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Which AWS services should a company use to read and write data that changes frequently? (Choose two.)
A. Amazon S3 Glacier
B. Amazon RDS
C. AWS Snowball
D. Amazon Redshift
E. Amazon Elastic File System (Amazon EFS)

A

B. Amazon RDS
E. Amazon Elastic File System (Amazon EFS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Which AWS service is used to provide encryption for Amazon EBS?
A. AWS Certificate Manager
B. AWS Systems Manager
C. AWS KMS
D. AWS Config

A

C. AWS KMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Which AWS services make use of global edge locations? (Choose two.)
A. AWS Fargate
B. Amazon CloudFront
C. AWS Global Accelerator
D. AWS Wavelength
E. Amazon VPC

A

B. Amazon CloudFront
C. AWS Global Accelerator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

A company is operating several factories where it builds products. The company needs the ability to process data, store data, and run applications with local system interdependencies that require low latency.Which AWS service should the company use to meet these requirements?
A. AWS IoT Greengrass
B. AWS Lambda
C. AWS Outposts
D. AWS Snowball Edge

A

C. AWS Outposts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which of the following is a recommended design principle for AWS Cloud architecture?
A. Design tightly coupled components.
B. Build a single application component that can handle all the application functionality.
C. Make large changes on fewer iterations to reduce chances of failure.
D. Avoid monolithic architecture by segmenting workloads.

A

D. Avoid monolithic architecture by segmenting workloads.

30
Q

A company is designing its AWS workloads so that components can be updated regularly and so that changes can be made in small, reversible increments.Which pillar of the AWS Well-Architected Framework does this design support?
A. Security
B. Performance efficiency
C. Operational excellence
D. Reliability

A

C. Operational excellence

31
Q

Which of the following acts as an instance-level firewall to control inbound and outbound access?
A. Network access control list
B. Security groups
C. AWS Trusted Advisor
D. Virtual private gateways

A

B. Security groups

32
Q

A company has a workload that will run continuously for 1 year. The workload cannot tolerate service interruptions.Which Amazon EC2 purchasing option will be MOST cost-effective?
A. All Upfront Reserved Instances
B. Partial Upfront Reserved Instances
C. Dedicated Instances
D. On-Demand Instances

A

A. All Upfront Reserved Instances

33
Q

Which AWS service helps protect against DDoS attacks?
A. AWS Shield
B. Amazon Inspector
C. Amazon GuardDuty
D. Amazon Detective

A

A. AWS Shield

34
Q

Using AWS Config to record, audit, and evaluate changes to AWS resources to enable traceability is an example of which AWS Well-Architected Framework pillar?
A. Security
B. Operational excellence
C. Performance efficiency
D. Cost optimization

A

A. Security

35
Q

Which AWS tool or feature acts as a VPC firewall at the subnet level?
A. Security group
B. Network ACL
C. Traffic Mirroring
D. Internet gateway

A

B. Network ACL

36
Q

Which AWS service can be used to decouple applications?
A. AWS Config
B. Amazon Simple Queue Service (Amazon SQS)
C. AWS Batch
D. Amazon Simple Email Service (Amazon SES)

A

B. Amazon Simple Queue Service (Amazon SQS)

37
Q

Which disaster recovery option is the LEAST expensive?
A. Warm standby
B. Multisite
C. Backup and restore
D. Pilot light

A

C. Backup and restore

38
Q

Which type of AWS storage is ephemeral and is deleted when an Amazon EC2 instance is stopped or terminated?
A. Amazon Elastic Block Store (Amazon EBS)
B. Amazon EC2 instance store
C. Amazon Elastic File System (Amazon EFS)
D. Amazon S3

A

B. Amazon EC2 instance store

39
Q

Which of the following is a characteristic of the AWS account root user?
A. The root user is the only user that can be configured with multi-factor authentication (MFA).
B. The root user is the only user that can access the AWS Management Console.
C. The root user is the first sign-in identity that is available when an AWS account is created.
D. The root user has a password that cannot be changed.

A

C. The root user is the first sign-in identity that is available when an AWS account is created.

40
Q

A company hosts an application on an Amazon EC2 instance. The EC2 instance needs to access several AWS resources, including Amazon S3 and AmazonDynamoDB.What is the MOST operationally efficient solution to delegate permissions?
A. Create an IAM role with the required permissions. Attach the role to the EC2 instance.
B. Create an IAM user and use its access key and secret access key in the application.
C. Create an IAM user and use its access key and secret access key to create a CLI profile in the EC2 instance
D. Create an IAM role with the required permissions. Attach the role to the administrative IAM user.

A

A. Create an IAM role with the required permissions. Attach the role to the EC2 instance.

41
Q

Which of the following is a component of the AWS Global Infrastructure?
A. Amazon Alexa
B. AWS Regions
C. Amazon Lightsail
D. AWS Organizations

A

B. AWS Regions

42
Q

What is the purpose of having an internet gateway within a VPC?
A. To create a VPN connection to the VPC
B. To allow communication between the VPC and the internet
C. To impose bandwidth constraints on internet traffic
D. To load balance traffic from the internet across Amazon EC2 instances

A

B. To allow communication between the VPC and the internet

43
Q

Which AWS service allows users to download security and compliance reports about the AWS infrastructure on demand?
A. Amazon GuardDuty
B. AWS Security Hub
C. AWS Artifact
D. AWS Shield

A

C. AWS Artifact

44
Q

A pharmaceutical company operates its infrastructure in a single AWS Region. The company has thousands of VPCs in a various AWS accounts that it wants to interconnect.Which AWS service or feature should the company use to help simplify management and reduce operational costs?
A. VPC endpoint
B. AWS Direct Connect
C. AWS Transit Gateway
D. VPC peering

A

C. AWS Transit Gateway

45
Q

A company is planning an infrastructure deployment to the AWS Cloud. Before the deployment, the company wants a cost estimate for running the infrastructure.Which AWS service or feature can provide this information?
A. Cost Explorer
B. AWS Trusted Advisor
C. AWS Cost and Usage Report
D. AWS Pricing Calculator

A

D. AWS Pricing Calculator

46
Q

Which AWS service of tool helps to centrally manage billing and allow controlled access to resources across AWS accounts?
A. AWS Identity and Access Management (IAM)
B. AWS Organizations
C. Cost Explorer
D. AWS Budgets

A

B. AWS Organizations

47
Q

Which of the following are Amazon Virtual Private Cloud (Amazon VPC) resources?
A. Objects; access control lists (ACLs)
B. Subnets; internet gateways
C. Access policies; buckets
D. Groups; roles

A

B. Subnets; internet gateways

48
Q

A company needs to identify the last time that a specific user accessed the AWS Management Console.Which AWS service will provide this information?
A. Amazon Cognito
B. AWS CloudTrail
C. Amazon Inspector
D. Amazon GuardDuty

A

B. AWS CloudTrail

49
Q

A company launched an Amazon EC2 instance with the latest Amazon Linux 2 Amazon Machine Image (AMI).Which actions can a system administrator take to connect to the EC2 instance? (Choose two.)
A. Use Amazon EC2 Instance Connect.
B. Use a Remote Desktop Protocol (RDP) connection.
C. Use AWS Batch
D. Use AWS Systems Manager Session Manager.
E. Use Amazon Connect

A

A. Use Amazon EC2 Instance Connect.
D. Use AWS Systems Manager Session Manager.

50
Q

A company wants to perform sentiment analysis on customer service email messages that it receives. The company wants to identify whether the customer service engagement was positive or negative.Which AWS service should the company use to perform this analysis?
A. Amazon Textract
B. Amazon Translate
C. Amazon Comprehend
D. Amazon Rekognition

A

C. Amazon Comprehend

51
Q

What is the total amount of storage offered by Amazon S3?
A. 100MB
B. 5 GB
C. 5 TB
D. Unlimited

A

D. Unlimited

52
Q

A company is migrating to Amazon S3. The company needs to transfer 60 TB of data from an on-premises data center to AWS within 10 days.Which AWS service should the company use to accomplish this migration?
A. Amazon S3 Glacier
B. AWS Database Migration Service (AWS DMS)
C. AWS Snowball
D. AWS Direct Connect

A

C. AWS Snowball

53
Q

What type of database is Amazon DynamoDB?
A. In-memory
B. Relational
C. Key-value
D. Graph

A

C. Key-value

54
Q

A large organization has a single AWS account.What are the advantages of reconfiguring the single account into multiple AWS accounts? (Choose two.)
A. It allows for administrative isolation between different workloads.
B. Discounts can be applied on a quarterly basis by submitting cases in the AWS Management Console.
C. Transitioning objects from Amazon S3 to Amazon S3 Glacier in separate AWS accounts will be less expensive.
D. Having multiple accounts reduces the risks associated with malicious activity targeted at a single account.
E. Amazon QuickSight offers access to a cost tool that provides application-specific recommendations for environments running in multiple accounts.

A

A. It allows for administrative isolation between different workloads.
D. Having multiple accounts reduces the risks associated with malicious activity targeted at a single account.

55
Q

A retail company has recently migrated its website to AWS. The company wants to ensure that it is protected from SQL injection attacks. The website uses anApplication Load Balancer to distribute traffic to multiple Amazon EC2 instances.Which AWS service or feature can be used to create a custom rule that blocks SQL injection attacks?
A. Security groups
B. AWS WAF
C. Network ACLs
D. AWS Shield

A

B. AWS WAF

56
Q

Which AWS service provides a feature that can be used to proactively monitor and plan for the service quotas of AWS resources?
A. AWS CloudTrail
B. AWS Personal Health Dashboard
C. AWS Trusted Advisor
D. Amazon CloudWatch

A

D. Amazon CloudWatch

57
Q

Which of the following is an advantage that users experience when they move on-premises workloads to the AWS Cloud?
A. Elimination of expenses for running and maintaining data centers
B. Price discounts that are identical to discounts from hardware providers
C. Distribution of all operational controls to AWS
D. Elimination of operational expenses

A

A. Elimination of expenses for running and maintaining data centers

58
Q

Which design principle is included in the operational excellence pillar of the AWS Well-Architected Framework?
A. Create annotated documentation.
B. Anticipate failure.
C. Ensure performance efficiency.
D. Optimize costs.

A

B. Anticipate failure.

59
Q

Which AWS services offer gateway VPC endpoints that can be used to avoid sending traffic over the internet? (Choose two.)
A. Amazon Simple Notification Service (Amazon SNS)
B. Amazon Simple Queue Service (Amazon SQS)
C. AWS CodeBuild
D. Amazon S3
E. Amazon DynamoDB

A

D. Amazon S3
E. Amazon DynamoDB

60
Q

Which of the following is the customer responsible for updating and patching, according to the AWS shared responsibility model?
A. Amazon FSx for Windows File Server
B. Amazon WorkSpaces virtual Windows desktop
C. AWS Directory Service for Microsoft Active Directory
D. Amazon RDS for Microsoft SQL Server

A

B. Amazon WorkSpaces virtual Windows desktop

61
Q

Who has the responsibility to patch the host operating system of an Amazon EC2 instance, according to the AWS shared responsibility model?
A. Both AWS and the customer
B. The customer only
C. The EC2 hardware manufacturer
D. AWS only

A

D. AWS only

62
Q

A company is using an Amazon RDS DB instance for an application that is deployed in the AWS Cloud. The company needs regular patching of the operating system of the server where the DB instance runs.What is the company’s responsibility in this situation, according to the AWS shared responsibility model?
A. Open a support case to obtain administrative access to the server so that the company can patch the DB instance operating system.
B. Open a support case and request that AWS patch the DB instance operating system.
C. Use administrative access to the server, and apply the operating system patches during the regular maintenance window that is defined for the DB instance.
D. Establish a regular maintenance window that tells AWS when to patch the DB instance operating system.

A

D. Establish a regular maintenance window that tells AWS when to patch the DB instance operating system.

63
Q

Why is an AWS Well-Architected review a critical part of the cloud design process?
A. A Well-Architected review is mandatory before a workload can run on AWS.
B. A Well-Architected review helps identify design gaps and helps evaluate design decisions and related documents.
C. A Well-Architected review is an audit mechanism that is a part of requirements for service level agreements.
D. A Well-Architected review eliminates the need for ongoing auditing and compliance tests.

A

B. A Well-Architected review helps identify design gaps and helps evaluate design decisions and related documents.

64
Q

A company implements an Amazon EC2 Auto Scaling policy along with an Application Load Balancer to automatically recover unhealthy applications that run onAmazon EC2 instances.Which pillar of the AWS Well-Architected Framework does this action cover?
A. Security
B. Performance efficiency
C. Operational excellence
D. Reliability

A

D. Reliability

65
Q

Which AWS Cloud benefit is shown by an architecture’s ability to withstand failures with minimal downtime?
A. Agility
B. Elasticity
C. Scalability
D. High availability

A

D. High availability

66
Q

Under the AWS shared responsibility model, which task is the customer’s responsibility when managing AWS Lambda functions?
A. Creating versions of Lambda functions
B. Maintaining server and operating systems
C. Scaling Lambda resources according to demand
D. Updating the Lambda runtime environment

A

A. Creating versions of Lambda functions

67
Q

What does the AWS Concierge Support team provide?
A. A technical expert dedicated to the user
B. A primary point of contact for AWS Billing and AWS Support
C. A partner to help provide scaling guidance for an event launch
D. A dedicated AWS staff member who reviews the user’s application architecture

A

B. A primary point of contact for AWS Billing and AWS Support

68
Q

A company needs to generate reports that can break down cloud costs by product, by company-defined tags, and by hour, day, and month.Which AWS tool should the company use to meet these requirements?
A. Reserved Instance utilization and coverage reports
B. Savings Plans utilization reports
C. AWS Budgets reports
D. AWS Cost and Usage Reports

A

D. AWS Cost and Usage Reports

69
Q

A company has a serverless application that includes an Amazon API Gateway API, an AWS Lambda function, and an Amazon DynamoDB database.Which AWS service can the company use to trace user requests as they move through the application’s components?
A. AWS CloudTrail
B. Amazon CloudWatch
C. Amazon Inspector
D. AWS X-Ray

A

D. AWS X-Ray

70
Q

A company needs to set up a petabyte-scale data warehouse in the AWS Cloud.Which AWS service will meet this requirement?
A. Amazon DynamoDB
B. Amazon RDS
C. Amazon Redshift
D. Amazon ElastiCache

A

C. Amazon Redshift

71
Q

Which AWS service is always provided at no charge?
A. Amazon S3
B. AWS Identity and Access Management (IAM)
C. Elastic Load Balancers
D. AWS WAF

A

B. AWS Identity and Access Management (IAM)

72
Q

A company needs to design an AWS disaster recovery plan to cover multiple geographic areas.Which action will meet this requirement?
A. Configure multiple AWS accounts.
B. Configure the architecture across multiple Availability Zones in an AWS Region.
C. Configure the architecture across multiple AWS Regions.
D. Configure the architecture among many edge locations.

A

C. Configure the architecture across multiple AWS Regions.