AWS Certified Cloud Practitioner: Test 2 Flashcards

1
Q
Which service provides visibility into user activity by recording actions taken on your account?    
A.Amazon CloudTrail
B.Amazon CloudHSM
C.Amazon CloudWatch
D.Amazon CloudFormation
A

A.Amazon CloudTrail

Explanation:
CloudTrail is a web service that records activity made on your account and delivers log files to an Amazon S3 bucket. CloudTrail records API activity. CloudTrail is used for auditing whereas CloudWatch is used for performance monitoring.

CORRECT: “Amazon CloudTrail” is the correct answer.

INCORRECT: “Amazon CloudWatch” is incorrect. CloudWatch is used for performance monitoring.

INCORRECT: “Amazon CloudFormation” is incorrect. CloudFormation is used for deploying infrastructure through code

INCORRECT: “Amazon CloudHSM” is incorrect. CloudHSM is a hardware security module for generating, managing and storing encryption keys.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
Which AWS-managed service can be used to process vast amounts of data using a hosted Hadoop framework?
A.Amazon Redshift
B.Amazon DynamoDB
C.Amazon Athena
D.Amazon EMR
A

D.Amazon EMR

Explanation:
Amazon Elastic Map Reduce (EMR) is a web service that enables businesses, researchers, data analysts, and developers to easily and cost-effectively process vast amounts of data. EMR utilizes a hosted Hadoop framework running on Amazon EC2 and Amazon S3.

CORRECT: “Amazon EMR” is the correct answer.

INCORRECT: “Amazon DynamoDB” is incorrect. DynamoDB is not a hosted Hadoop framework, it is a no-SQL database.

INCORRECT: “Amazon Athena” is incorrect. Amazon Athena is a serverless, interactive query service to query data and analyze big data in Amazon S3 using standard SQL

INCORRECT: “Amazon Redshift” is incorrect. Amazon Redshift is a fast, simple, cost-effective data warehousing service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
Which AWS service or feature allows a company to receive a single monthly AWS bill when using multiple AWS accounts?
A.Consolidating billing
B.AWS Cost and Usage Report
C.Amazon Cloud Directory
D.AWS Cost explorer
A

A.Consolidating billing

Explanation;
You can use the consolidated billing feature in AWS Organizations to consolidate billing and payment for multiple AWS accounts or multiple Amazon Internet Services Pvt. Ltd (AISPL) accounts. Every organization in AWS Organizations has a master (payer) account that pays the charges of all the member (linked) accounts.

Consolidated billing has the following benefits:

  • One bill – You get one bill for multiple accounts.
  • Easy tracking – You can track the charges across multiple accounts and download the combined cost and usage data.
  • Combined usage – You can combine the usage across all accounts in the organization to share the volume pricing discounts, Reserved Instance discounts, and Savings Plans. This can result in a lower charge for your project, department, or company than with individual standalone accounts.
  • No extra fee – Consolidated billing is offered at no additional cost.

CORRECT: “Consolidated billing” is the correct answer.

INCORRECT: “Amazon Cloud Directory” is incorrect. Cloud Directory is used for creating cloud-native directories. This is not related to billing.

INCORRECT: “AWS Cost Explorer” is incorrect. AWS Cost Explorer has an easy-to-use interface that lets you visualize, understand, and manage your AWS costs and usage over time. It does not centralize billing.

INCORRECT: “AWS Cost and Usage report” is incorrect. The AWS Cost & Usage Report lists AWS usage for each service category used by an account and its IAM users in hourly or daily line items, as well as any tags that you have activated for cost allocation purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following security operations tasks must be performed by AWS customers? (Select TWO.)
A.Installing security updates for server firmware
B.Issuing data center access keycards
C.Installing security updates on EC@ instances
D.Enabling multi-factor authentiucation (MFA) for privleged users

A

C.Installing security updates on EC@ instances
D.Enabling multi-factor authentiucation (MFA) for privleged users

Explanation

The customer is responsible for installing security updates on EC2 instances and enabling MFA. AWS is responsible for security of the physical data center and the infrastructure upon which customer services run.

CORRECT: “Installing security updates on EC2 instances” is a correct answer.

CORRECT: “Enabling multi-factor authentication (MFA) for privileged users” is also a correct answer.

INCORRECT: “Collecting syslog messages from physical firewalls” is incorrect as this is an AWS responsibility.

INCORRECT: “Issuing data center access keycards” is incorrect as this is an AWS responsibility.

INCORRECT: “Installing security updates for server firmware” is incorrect as this is an AWS responsibility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
Which AWS service should a Cloud Practitioner use to establish a secure network connection between an on-premises network and AWS?
A.Amazon Virtual Private Cloud (VPC)
B.Amazon Web Application Firewall (WAF)
C.Virtual Private Network
D.AWS Mobile Hub
A

C.Virtual Private Network

AWS Virtual Private Network solutions establish secure connections between your on-premises networks, remote offices, client devices, and the AWS global network.

CORRECT: “Virtual Private Network” is the correct answer.

INCORRECT: “AWS Mobile Hub” is incorrect. This service is used for building, testing, and monitoring mobile applications that make use of one or more AWS services.

INCORRECT: “AWS Web Application Firewall (WAF)” is incorrect. This service is used for protecting against common web exploits.

INCORRECT: “Amazon Virtual Private Cloud (VPC)” is incorrect. This is a virtual network in the cloud. You connect your AWS VPN to your Amazon VPC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following should be used to improve the security of access to the AWS Management Console? (Select TWO.)
A. Security group rules
B.Strong password policies
C.AWS multi-Factor Authentication(AWS MFA)
D.AWS Certificate Manager
E.AWS Secret Manager

A

B.Strong password policies
C.AWS multi-Factor Authentication(AWS MFA)

Epxplanation;
For extra security, AWS recommends that you require multi-factor authentication (MFA) for all users in your account. With MFA, users have a device that generates a response to an authentication challenge.

Both the user’s credentials (something you know) and the device-generated response (something you have) are required to complete the sign-in process. If a user’s password or access keys are compromised, your account resources are still secure because of the additional authentication requirement.
Additionally, strong password policies should be used to enforce measures including minimum password length, complexity, and password reuse restrictions.

CORRECT: “AWS Multi-Factor Authentication (AWS MFA)” is a correct answer.

CORRECT: “Strong password policies” is also a correct answer.

INCORRECT: “AWS Secrets Manager” is incorrect. This service enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

INCORRECT: “AWS Certificate Manager” is incorrect. This service is used for creating SSL/TLS certificates for use with HTTPS connections.

INCORRECT: “Security group rules” is incorrect as these are used to restrict traffic to/from your EC2 instances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

An eCommerce company plans to use the AWS Cloud to quickly deliver new functionality in an iterative manner, minimizing the time to market.
Which feature of the AWS Cloud provides this functionality?
A.Cost effectiveness
B.Fault tolerance
C.Elasticity
D.Agility

A

D.Agility

Explanation:
In a cloud computing environment, new IT resources are only a click away, which means that you reduce the time to make those resources available to your developers from weeks to just minutes.

This results in a dramatic increase in agility for the organization, since the cost and time it takes to experiment and develop is significantly lower.

CORRECT: “Agility” is the correct answer.

INCORRECT: “Elasticity” is incorrect. Elasticity enables infrastructure to scale based on demand and helps applications perform and be cost effective. It does not reduce time to market.

INCORRECT: “Fault tolerance” is incorrect as this is involved with ensuring applications stay available in the event of a fault.

INCORRECT: “Cost effectiveness” is incorrect. The AWS Cloud can be cost effective but this is not the benefit that allows faster time to market.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An application stores images which will be retrieved infrequently, but must be available for retrieval immediately. Which is the most cost-effective storage option that meets these requirements?
A.Amazon S3 Standard
B.Amazon Glacier with expedited retrievals
C.Amazon S3 Standard-Infrequent Access
D.Amazon EFS

A

C.Amazon S3 Standard-Infrequent Access

Explanation:
Amazon S3 Standard-Infrequent Access is the most cost-effective choice. It provides immediate access and is suitable for this use case as it is lower cost than S3 standard. Note that you must pay a fee for retrievals which is why you would only use this tier for infrequent access use cases.
CORRECT: “Amazon S3 Standard-Infrequent Access” is the correct answer.

INCORRECT: “Amazon Glacier with expedited retrievals” is incorrect. Amazon Glacier with expedited retrievals is fast (1-5 minutes) but not immediate.

INCORRECT: “Amazon EFS” is incorrect. Amazon EFS is a high-performance file system and not ideally suited to this scenario, it is also not the most cost-effective option.

INCORRECT: “Amazon S3 Standard” is incorrect. Amazon S3 Standard provides immediate retrieval but is not less cost-effective compared to Standard-Infrequent access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
Which AWS service helps customers meet corporate, contractual, and regulatory compliance requirements for data security by using dedicated hardware appliances within the AWS Cloud?
A.AWS Directory Service
B.AWS Key Management Service (AWS KMS)
C.AWS Secret manager
D.AWS CloudHSM
A

D.AWS CloudHSM

Explanation:
The AWS CloudHSM service helps you meet corporate, contractual, and regulatory compliance requirements for data security by using dedicated Hardware Security Module (HSM) instances within the AWS cloud. AWS CloudHSM enables you to easily generate and use your own encryption keys on the AWS Cloud.

CORRECT: “AWS CloudHSM” is the correct answer.

INCORRECT: “AWS Secrets Manager” is incorrect. AWS Secrets Manager enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

INCORRECT: “AWS Key Management Service (AWS KMS)” is incorrect. This service is also involved with creating and managing encryption keys but does not use dedicated hardware.

INCORRECT: “AWS Directory Service” is incorrect. AWS Directory Service for Microsoft Active Directory, also known as AWS Managed Microsoft AD, enables your directory-aware workloads and AWS resources to use managed Active Directory in the AWS Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A company is planning to migrate some resources into the cloud. What factors need to be considered when determining the cost of the AWS Cloud? (Select TWO.)
A. The amount of ingress data per month
B.The number of VPC’s created
C.The number of servers migrated into EC2
D.The number of IAM users created

A

C.The number of servers migrated into EC2

Explanation

There are three fundamental drivers of cost with AWS: compute, storage, and outbound data transfer. These characteristics vary somewhat, depending on the AWS product and pricing model you choose.

In most cases, there is no charge for inbound data transfer or for data transfer between other AWS services within the same region. However, there are some exceptions.

CORRECT: “The number of servers migrated into EC2” is a correct answer.

CORRECT: “The amount of egress data per month” is also a correct answer.

INCORRECT: “The number of VPCs created” is incorrect as you are not charged for VPCs.

INCORRECT: “The number of IAM users created” is incorrect as you are not charged for IAM.

INCORRECT: “The amount of ingress data per month” is incorrect as you are not charged for data ingress.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a Resource Group?
A.A collection of services within a category
B.A collection of services within a region
C.A collection for resources that share one or more tags
D. A collection of resources within a VPC

A

C.A collection for resources that share one or more tags

Explanation:
A resource group is a collection of resources that share one or more tags or portions of tags. To create a resource group, you simply identify the tags that contain the items that members of the group should have in common.

CORRECT: “A collection of resources that share one or more tags” is the correct answer.

INCORRECT: “A collection of resources within a VPC” is incorrect.

INCORRECT: “A collection of services within a category” is incorrect.

INCORRECT: “A collection of services within a region” is incorrect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What can a Cloud Practitioner do with the AWS Cost Management tools? (Select TWO.)
A.Automatically modify EC2 instances to use Spot pricing to reduce costs
B.Terminate EC2 instances automatically if budgeted thresholds are exceeded
C.Archive data to Amazon Glacier if it not accessed for a configured period of time
D.Create budgets and receive notifications if current or forecasted usage exceeds the budget

A

D.Create budgets and receive notifications if current or forecasted usage exceeds the budget

Explanation:
AWS Cost Explorer has an easy-to-use interface that lets you visualize, understand, and manage your AWS costs and usage over time. It can be used to visualize AWS costs by day, service, and linked AWS account.

AWS Budgets can be used to receive notifications if current or forecasted usage exceeds the budgets.

CORRECT: “Visualize AWS costs by day, service, and linked AWS account” is a correct answer.

CORRECT: “Create budgets and receive notifications if current or forecasted usage exceeds the budgets” is also a correct answer.

INCORRECT: “Terminate EC2 instances automatically if budget thresholds are exceeded” is incorrect. The cost management tools can alert on budget breaches but they do not directly terminate instances.

INCORRECT: “Automatically modify EC2 instances to use Spot pricing to reduce costs” is incorrect. The cost management tools cannot modify the pricing model of EC2 instances.

INCORRECT: “Archive data to Amazon Glacier if it is not accessed for a configured period of time” is incorrect. Use lifecycle rules in Amazon S3 to automatically move data between storage classes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
What features does Amazon RDS provide to deliver scalability, availability and durability? (Select TWO.)
A.DB Mirroring
B.Multi-AZ
C.Read Replicas
DD.Multi-Subnet
E.Clutstering
A

B.Multi-AZ
C.Read Replicas

Explanation:
Multi-AZ RDS creates a replica in another AZ and synchronously replicates to it (DR only). Read replicas are used for read heavy DBs and replication is asynchronous. With a read replica you direct your database queries to the read replica and this offloads pressure from the main database.
CORRECT: “Multi-AZ” is a correct answer.

CORRECT: “Read Replicas” is also a correct answer.

INCORRECT: “DB mirroring” is incorrect as it is not offered by RDS.

INCORRECT: “Clustering” is incorrect as this is not offered by RDS.

INCORRECT: “Multi-Subnet” is incorrect as this is not offered by RDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
Which Amazon EC2 pricing model should be avoided if a workload cannot accept interruption if capacity becomes temporarily unavailable?
A.Convertible Reserved Instances
B.Standard Reserved Instabnces
C.On-demand instances
D.Spot instances
A

D.Spot instances

Explanation;
Amazon EC2 Spot Instances let you take advantage of unused EC2 capacity in the AWS cloud. Spot Instances are available at up to a 90% discount compared to On-Demand prices.

The downside is that if capacity becomes temporarily unavailable, your instances may be terminated.

CORRECT: “Spot Instances” is the correct answer.

INCORRECT: “On-Demand Instances” is incorrect. On-demand instances are not subject to interruption if capacity becomes temporarily unavailable.

INCORRECT: “Standard Reserved Instances” is incorrect. Reserved instances are not subject to interruption if capacity becomes temporarily unavailable

INCORRECT: “Convertible Reserved Instances” is incorrect. Reserved instances are not subject to interruption if capacity becomes temporarily unavailable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which of the statements below is correct in relation to Consolidated Billing? (Select TWO.)
A. You are charged a fee per user
B.You can combine usage and share volume pricing discounts
C.You pay a fee per linked account
D.You receive one bill per AWS accoount
E.You receive single bill for multiple accounts

A

B.You can combine usage and share volume pricing discounts
E.You receive single bill for multiple accounts

Exaplantion:
Consolidated billing has the following benefits:

One bill – You get one bill for multiple accounts.

Easy tracking – You can track the charges across multiple accounts and download the combined cost and usage data.

Combined usage – You can combine the usage across all accounts in the organization to share the volume pricing discounts and Reserved Instance discounts. This can result in a lower charge for your project, department, or company than with individual standalone accounts.

CORRECT: “You receive a single bill for multiple accounts” is a correct answer.

CORRECT: “You can combine usage and share volume pricing discounts” is also a correct answer.

INCORRECT: “You receive one bill per AWS account” is incorrect as you receive a single bill for multiple accounts.

INCORRECT: “You pay a fee per linked account” is incorrect as you do not pay a fee.

INCORRECT: “You are charged a fee per user” is incorrect as you do not pay a fee.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which benefits can a company immediately realize using the AWS Cloud? (Select TWO.)
A.User control of physical infrastructure
B.Capital expenses are replaced with variable expenses
C.Increased agility
D.No responsibility for security
E.Variable expenses are replaced with capital expenses

A

B.Capital expenses are replaced with variable expenses
C.Increased agility

Explanation:
A couple of the benefits that companies will realize immediately when using the AWS Cloud are increased agility and a change from capital expenditure to variable operational expenditure.

Agility is enabled through the flexibility of cloud services and the ease with which applications can be deployed, scaled, and managed. When using cloud services you pay for what you use and this is a variable, operational expense which can be beneficial to company cashflow.

CORRECT: “Capital expenses are replaced with variable expenses” is a correct answer.

CORRECT: “Increased agility” is also a correct answer.

INCORRECT: “Variable expenses are replaced with capital expenses” is incorrect. This is the wrong way around, capital expenses are replaced with variable expenses.

INCORRECT: “User control of physical infrastructure” is incorrect. This is not true, you do not get control of the physical infrastructure.

INCORRECT: “No responsibility for security” is incorrect. This is not true, you are still responsible for “security in the cloud”.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the function of Amazon EC2 Auto Scaling?
A.Automatically updates the EC2 pricing model, based on demand
B.Automatically modifies the network throughput of the EC2 instances, based on demand
C.Scales the size of EC2 instances up or down automatically based on demand
D.Scales the number of EC2 instances in or out automatically, based on demand

A

D.Scales the number of EC2 instances in or out automatically, based on demand

Explanation;
Amazon EC2 Auto Scaling helps you maintain application availability and allows you to automatically add or remove EC2 instances according to conditions you define. You can use the fleet management features of EC2 Auto Scaling to maintain the health and availability of your fleet. You can also use the dynamic and predictive scaling features of EC2 Auto Scaling to add or remove EC2 instances.

CORRECT: “Scales the number of EC2 instances in or out automatically, based on demand.” is the correct answer.

INCORRECT: “Scales the size of EC2 instances up or down automatically, based on demand.” is incorrect. Auto Scaling adjusts the number of EC2 instances, not the size of EC2 instances.

INCORRECT: “Automatically updates the EC2 pricing model, based on demand.” is incorrect. Auto Scaling does not change pricing models

INCORRECT: “Automatically modifies the network throughput of EC2 instances, based on demand.” is incorrect. Auto Scaling does not modify network throughput for instances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q
Which AWS service can be used to run Docker containers?
A.AWS Lambda
B.Amazon ECR
C.Amazon ECS
D.Amazon AMI
A

C.Amazon ECS

Explanation:
Amazon Elastic Container Service (ECS) is a highly scalable, high performance container management service that supports Docker containers and allows you to easily run applications on a managed cluster of Amazon EC2 instances.

CORRECT: “Amazon ECS” is the correct answer.

INCORRECT: “AWS Lambda” is incorrect. AWS Lambda is a serverless technology that lets you run code in response to events as functions

INCORRECT: “Amazon ECR” is incorrect. Amazon Elastic Container Registry (ECR) is a fully-managed Docker container registry that makes it easy for developers to store, manage, and deploy Docker container images

INCORRECT: “Amazon AMI” is incorrect. Amazon Machine Images (AMI) store configuration information for Amazon EC2 instances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q
You need to implement a hosted queue for storing messages in transit between application servers. Which service should you use?
A.Amazon SQS
B.Amazon DynamoDB
C.Amazon SNS
D.Amazon SWF
A

A.Amazon SQS

Explanation:
Amazon Simple Queue Service (Amazon SQS) is a web service that gives you access to message queues that store messages waiting to be processed. SQS offers a reliable, highly-scalable, hosted queue for storing messages in transit between computers. SQS is used for distributed/decoupled application.
CORRECT: “Amazon SQS” is a correct answer.

INCORRECT: “Amazon SNS” is incorrect. Amazon Simple Notification Service (SNS) is a highly available, durable, secure, fully managed pub/sub messaging service that enables you to decouple microservices, distributed systems, and serverless applications.

INCORRECT: “Amazon DynamoDB” is incorrect. Amazon DynamoDB is a nonrelational database that delivers reliable performance at any scale.

INCORRECT: “Amazon SWF” is incorrect. Amazon SWF helps developers build, run, and scale background jobs that have parallel or sequential steps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

A user has limited knowledge of AWS services, but wants to quickly deploy a scalable Node.js application in an Amazon VPC.

Which service should be used to deploy the application?
A.Amazon LightSail
B.AWS Elastic Beanstalk
C.AWS CloudFormation
D.Amazon EC2
A

B.AWS Elastic Beanstalk

Explanation;
AWS Elastic Beanstalk is an easy-to-use service for deploying and scaling web applications and services developed with Java, .NET, PHP, Node.js, Python, Ruby, Go, and Docker on familiar servers such as Apache, Nginx, Passenger, and IIS.

You can simply upload your code and Elastic Beanstalk automatically handles the deployment, from capacity provisioning, load balancing, auto-scaling to application health monitoring. At the same time, you retain full control over the AWS resources powering your application and can access the underlying resources at any time.

CORRECT: “AWS Elastic Beanstalk” is the correct answer.

INCORRECT: “Amazon LightSail” is incorrect. LightSail is a good service to use when you don’t have good knowledge of AWS. However, you cannot deploy a scalable node.js application into a VPC.

INCORRECT: “AWS CloudFormation” is incorrect. CloudFormation is used for automating the deployment of infrastructure resources in AWS.

INCORRECT: “Amazon EC2” is incorrect. This would require more expertise that using Elastic Beanstalk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q
What type of database is fully managed and can be scaled without incurring downtime?
A. Amazon S3
B.Amazon ElastiCache
C.Amazon RDS
D.Amazon DynamoDB
A

D.Amazon DynamoDB

Explanation

Amazon DynamoDB is fully managed and can be scaled without incurring downtime. DynamoDB scales horizontally and it does so seamlessly.

Both RDS and ElastiCache use EC2 instances and therefore scaling (vertically) requires downtime.

CORRECT: “Amazon DynamoDB” is the correct answer.

INCORRECT: “Amazon RDS” is incorrect as it must be scaled vertically and this requires downtime.

INCORRECT: “Amazon S3” is incorrect. S3 is not a fully managed database, it is an object store.

INCORRECT: “Amazon ElastiCache” is incorrect as it must be scaled vertically and this requires downtime.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q
You need to ensure you have the right amount of compute available to service demand. Which AWS service can automatically scale the number of EC2 instances for your application?
A.Amazon RedShift
B.Amazon EC2 Auto Scaling
C.Amazon Elastic Load balancer
D.Amazon ElastiCache
A

B.Amazon EC2 Auto Scaling

Explanation:
Auto Scaling automates the process of adding (scaling up) OR removing (scaling down) EC2 instances based on the traffic demand for your application.

CORRECT: “Amazon EC2 Auto Scaling” is the correct answer.

INCORRECT: “Amazon Elastic Load Balancer” is incorrect. ELB automatically distributes incoming application traffic across multiple targets, such as Amazon EC2 instances, containers, and IP addresses.

INCORRECT: “Amazon ElastiCache” is incorrect. Amazon ElastiCache offers fully managed Redis and Memcached database services.

INCORRECT: “Amazon RedShift” is incorrect. Amazon Redshift is a fast, scalable data warehouse that makes it simple and cost-effective to analyze all your data across your data warehouse and data lake.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q
A Cloud Practitioner wants to configure the AWS CLI for programmatic access to AWS services. Which credential components are required? (Select TWO.)
A.An IAM Role
B.A public key
C.A private key
D.An access key ID
E.A secret access key
A

D.An access key ID
E.A secret access key

Explanation;
Access keys are long-term credentials for an IAM user or the AWS account root user. You can use access keys to sign programmatic requests to the AWS CLI or AWS API (directly or using the AWS SDK).

Access keys consist of two parts: an access key ID (for example, AKIAIOSFODNN7EXAMPLE) and a secret access key (for example, wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY).

Like a user name and password, you must use both the access key ID and secret access key together to authenticate your requests. Manage your access keys as securely as you do your user name and password.

CORRECT: “An access key ID” is a correct answer.

CORRECT: “A secret access key” is also a correct answer.

INCORRECT: “A public key” is incorrect. Public/private keys are used for encryption and are also associated with the key pairs used to authenticate to EC2 instances.

INCORRECT: “A private key” is incorrect. Public/private keys are used for encryption and are also associated with the key pairs used to authenticate to EC2 instances.

INCORRECT: “An IAM Role” is incorrect. IAM Roles are not used for configuring the CLI for programmatic access. They can be used for delegating access to AWS services and cross-account access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q
Which AWS support plans provide support via email, chat and phone? (Select TWO.)
A.basic
B.Global
C.Developer
D.Business
E.Enterprise
A

D.Business
E.Enterprise

Explanation:
Only the business and enterprise plans provide support via email, chat and phone.
CORRECT: “Business” is the correct answer.

CORRECT: “Enterprise” is the correct answer.

INCORRECT: “Basic” is incorrect does not provide support via email, chat and phone.

INCORRECT: “Developer” is incorrect only provides email support.

INCORRECT: “Global” is incorrect is not a support plan offered by AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q
An application has highly dynamic usage patterns. Which characteristics of the AWS Cloud make it cost-effective for this type of workload? (Select TWO.)
A.Elasticity
B.High availability
C.Strict security
D.Pay-as-you-go pricing
E.Reliability
A

A.Elasticity
D.Pay-as-you-go pricing

Explanation:
AWS is a cost-effective for dynamic workloads because it is elastic, meaning your workload can scale based on demand. And because you only pay for what you use (pay-as-you-go pricing).

CORRECT: “Elasticity” is the correct answer.

CORRECT: “Pay-as-you-go pricing” is the correct answer.

INCORRECT: “High availability” is incorrect. This is not a characteristic that results in cost-effectiveness.

INCORRECT: “Strict security” is incorrect. This is not a characteristic that results in cost-effectiveness.

INCORRECT: “Reliability” is incorrect. This is not a characteristic that results in cost-effectiveness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q
Which items should be included in a TCO analysis comparing on-premise to AWS Cloud? (Select TWO.)
A.Operating system patching
B.Application licensing
C.Data center security
D.Compute hardware
E.Firewall management
A

C.Data center security
D.Compute hardware

Explanation:
You need to identify the items that have a cost on-premise and that will be rolled into the service in the cloud. Compute hardware costs and data center security costs will be rolled in the service cost in the cloud so you need to include them in the model so you can really understand the true TCO on-premise vs. the cloud.

Firewall management, application licensing and operating system patching need to be paid for on-premise and in the cloud so there is little difference.

CORRECT: “Compute hardware” is a correct answer.

CORRECT: “Data center security” is also a correct answer.

INCORRECT: “Firewall management” is incorrect as explained above.

INCORRECT: “Application licensing” is incorrect as explained above.

INCORRECT: “Operating system patching” is incorrect as explained above.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q
What are two ways of connecting to an Amazon VPC from an on-premise data center? (Select TWO.)
A.AWS VPN CloudHub
B.VPC Peering
C.VPC Router
D.AWS Direct Connect
E.Internet Gateway
A

A.AWS VPN CloudHub
D.AWS Direct Connect

Explanation:
You can connect from your on-premise data center to a VPC via Direct Connect or VPN CloudHub.

AWS Direct Connect is a network service that provides an alternative to using the Internet to connect a customer’s on premise sites to AWS.

If you have multiple VPN connections, you can provide secure communication between sites using the AWS VPN CloudHub.

CORRECT: “AWS Direct Connect” is a correct answer.

CORRECT: “AWS VPN CloudHub” is also a correct answer.

INCORRECT: “VPC Peering” is incorrect as this is a way to connect VPCs to each other, not on-premises locations

INCORRECT: “Internet Gateway” is incorrect as this is used to provide internet connectivity to a VPC.

INCORRECT: “VPC Router” is incorrect as this is used for routing within a VPC.

28
Q
Which AWS service protects against common exploits that could compromise application availability, compromise security or consume excessive resources?    
A.Security Group
B.AWS WAF
C.Network ACL
D.AWS Shield
A

B.AWS WAF

Explanation:
AWS WAF is a web application firewall that protects against common exploits that could compromise application availability, compromise security or consume excessive resources.

CORRECT: “AWS WAF” is the correct answer.

INCORRECT: “AWS Shield” is incorrect. AWS Shield is a managed Distributed Denial of Service (DDoS) protection service.

INCORRECT: “Security Group” is incorrect. Security groups are firewalls applied at the instance level.

INCORRECT: “Network ACL” is incorrect. Network ACLs are firewalls applied at the subnet level.

29
Q

Which of the following best describes an Availability Zone in the AWS Cloud?
A.One or more edge locations based around the world
B.A completely isolated geographic location
C. A subnet for deploying resources into
D.One or more physical data centers

A

D.One or more physical data centers

Explanation:
An Availability Zone (AZ) is one or more discrete data centers with redundant power, networking, and connectivity in an AWS Region. AZ’s give customers the ability to operate production applications and databases that are more highly available, fault tolerant, and scalable than would be possible from a single data center.

CORRECT: “One or more physical data centers” is the correct answer.

INCORRECT: “A completely isolated geographic location” is incorrect. This is a description of an AWS Region.

INCORRECT: “One or more edge locations based around the world” is incorrect. Edge locations are used by Amazon CloudFront for caching content.

INCORRECT: “A subnet for deploying resources into” is incorrect. Subnets are created within AZs.

30
Q
Which AWS service can be used to host a static website?
A.Amazon EBS
B.Amazon EFS
C.Amazon S3
D.AWS CloudFormation
A

C.Amazon S3

Explanation:
You can use Amazon S3 to host a static website. On a static website, individual webpages include static content. They might also contain client-side scripts.

By contrast, a dynamic website relies on server-side processing, including server-side scripts such as PHP, JSP, or ASP.NET. Amazon S3 does not support server-side scripting, but AWS has other resources for hosting dynamic websites.

CORRECT: “Amazon S3” is the correct answer.

INCORRECT: “Amazon EBS” is incorrect as it cannot be used to host a static website.

INCORRECT: “AWS CloudFormation” is incorrect as it cannot be used to host a static website.

INCORRECT: “Amazon EFS” is incorrect as it cannot be used to host a static website.

31
Q
Amazon S3 is typically used for which of the following use cases? (Select TWO.)
A.Host a static website
B.Media hosting
C.Install an operating system
D.In-memory data cache
E.Messaging queue
A

A.Host a static website
B.Media hosting

Explanation:
Amazon S3 is an object storage system. Typical use cases include: Backup and storage, application hosting, media hosting, software delivery and hosting a static website.

CORRECT: “Host a static website” is the correct answer.

CORRECT: “Media hosting” is the correct answer.

INCORRECT: “Install an operating system” is incorrect. You cannot install an operating system on an object-based storage system. Instead, you need a block-based storage system such as Amazon EBS.

INCORRECT: “In-memory data cache” is incorrect. You cannot use Amazon S3 as an in-memory data cache; for this you need a service such as Amazon ElastiCache.

INCORRECT: “Message queue” is incorrect. You cannot use Amazon S3 as a message queue (or at least it is not a typical use case). You should use a services such as Amazon SQS or Amazon MQ.

32
Q
How can an organization assess application for vulnerabilities and deviations from best practice?    
A.Use AWS shield
B.Use AWS WAF
C.Use AWS Inspector
D.Use AWS Artifact
A

C.Use AWS Inspector

Explanation:
Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. Inspector automatically assesses applications for vulnerabilities or deviations from best practices.

CORRECT: “Use AWS Inspector” is the correct answer.

INCORRECT: “Use AWS Artifact” is incorrect. AWS Artifact is your go-to, central resource for compliance-related information that matters to you.

INCORRECT: “Use AWS Shield” is incorrect. AWS Shield is a managed Distributed Denial of Service (DDoS) protection service.

INCORRECT: “Use AWS WAF” is incorrect. AWS Web application Firewall (WAF) is a firewall service, it is not used for assessing best practice.

33
Q
Which of the following are valid types of Reserved Instance? (Select TWO.)
A.Convertible RI
B.Scheduled RI
C.Discounted RI
D.Long-Term RI
D.Special Ri
A

A.Convertible RI
B.Scheduled RI

Explanation:
Reserved Instances (RI) provide a significant discount (up to 72%) compared to On-Demand pricing and provide a capacity reservation when used in a specific Availability Zone. The following types of RI are available:

Standard RIs: These provide the most significant discount (up to 75% off On-Demand) and are best suited for steady-state usage.

Convertible RIs: These provide a discount (up to 54% off On-Demand) and the capability to change the attributes of the RI as long as the exchange results in the creation of Reserved Instances of equal or greater value. Like Standard RIs, Convertible RIs are best suited for steady-state usage.

Scheduled RIs: These are available to launch within the time windows you reserve. This option allows you to match your capacity reservation to a predictable recurring schedule that only requires a fraction of a day, a week, or a month.

CORRECT: “Convertible RI” is a correct answer.

CORRECT: “Scheduled RI” is also a correct answer.

INCORRECT: “Discounted RI” is incorrect as this is not a type of RI available.

INCORRECT: “Long-Term RI” is incorrect as this is not a type of RI available.

INCORRECT: “Special RI” is incorrect as this is not a type of RI available.

34
Q

What are two ways an AWS customer can reduce their monthly spend? (Select TWO.)
A.Turn off resources that are not being used
B.Be efficient with usage of security groups
C.Use more power efficient instance types
D.Reduce the amount of data ingress charges
E.Reserve capacity where suitable

A

A.Turn off resources that are not being used
E.Reserve capacity where suitable

Explanation:
Turning of resources that are not used can reduce spend. You can also use reserved capacity to reduce the monthly spend at the expense of having to lock into a 1 or 3-year contract – good for stable workloads.

CORRECT: “Turn off resources that are not being used” is a correct answer.

CORRECT: “Reserve capacity where suitable” is also a correct answer.

INCORRECT: “Use more power efficient instance types” is incorrect as you do not pay for power on AWS.

INCORRECT: “Be efficient with usage of Security Groups” is incorrect as you do not pay for security groups on AWS.

INCORRECT: “Reduce the amount of data ingress charges” is incorrect as in most cases you do not pay for data ingress.

35
Q

A user needs an automated security assessment report that will identify unintended network access to Amazon EC2 instances and vulnerabilities on those instances.

Which AWS service will provide this assessment report?
A.Amazon macie
B.Amazon Inspector
C.EC2 security groups
D.AWS Config
A

B.Amazon Inspector

Explanation:
Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices.

After performing an assessment, Amazon Inspector produces a detailed list of security findings prioritized by level of severity. These findings can be reviewed directly or as part of detailed assessment reports which are available via the Amazon Inspector console or API.

CORRECT: “Amazon Inspector” is the correct answer.

INCORRECT: “EC2 security groups” is incorrect. Security groups are instance-level firewalls used for controlling network traffic reaching and leaving EC2 instances.

INCORRECT: “AWS Config” is incorrect. AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources.

INCORRECT: “Amazon Macie” is incorrect. Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in AWS.

36
Q
Which services are managed at a regional (rather than global) level? (Select TWO.)
A.Amazon CloudFront
B.Amazon Route 53
C.Amazon EC2
D.AWS IAM
E.AMazon S3
A

C.Amazon EC2
E.AMazon S3

Explanation:
Both Amazon EC2 and Amazon S3 are managed at a regional level. Note: Amazon S3 is a global namespace but you still create your buckets within a region. Amazon CloudFront, Amazon Route 52 and AWS IAM are managed at a global level.

CORRECT: “Amazon S3” is a correct answer.

CORRECT: “Amazon EC2” is also a correct answer.

INCORRECT: “Amazon CloudFront” is incorrect as it is a global service.

INCORRECT: “Amazon Route 53” is incorrect as it is a global service.

INCORRECT: “AWS IAM” is incorrect as it is a global service.

37
Q
Which AWS service provides preconfigured virtual private servers (instances) that include everything required to deploy an application or create a database?
A.Amazon CloudFormation
B.AWS Lambda
C.Amazon ECS
D.Amazon LightSail
A

D.Amazon LightSail

Explanation:
LightSail provides preconfigured virtual private servers (instances) that include everything required to deploy and application or create a database.

LightSail includes everything you need to launch your project quickly – a virtual machine, SSD-based storage, data transfer, DNS management, and a static IP.

CORRECT: “Amazon LightSail” is the correct answer.

INCORRECT: “AWS CloudFormation” is incorrect. CloudFormation is used to deploy resources through code, as a service it does not include preconfigured servers.

INCORRECT: “Amazon ECS” is incorrect. Amazon Elastic Container Service (ECS) is a highly scalable, high performance container management service that supports Docker containers and allows you to easily run applications on a managed cluster of Amazon EC2 instances.

INCORRECT: “AWS Lambda” is incorrect. Lambda is a serverless computing technology that allows you to run code without provisioning or managing servers.

38
Q

A company needs a consistent and dedicated connection between AWS resources and an on-premise system.

Which AWS service can fulfil this requirement?
A.AWS DataSync
B.Amazon Managed VPN
C.AWS Direct Connect
D.Amazon Connect
A

C.AWS Direct Connect

Explanation:
An AWS Direct Connect connection is a private, dedicated link to AWS. As it does not use the internet, performance is consistent.

The following diagram shows how a corporate data center is connected to AWS using a Direct Connect link via an AWS Direct Connect location:
CORRECT: “AWS Direct Connect” is the correct answer.

INCORRECT: “AWS Managed VPN” is incorrect. This services uses the public internet so it is not a dedicated link and performance will not be consistent.

INCORRECT: “Amazon Connect” is incorrect. Amazon Connect is an easy to use omnichannel cloud contact center that helps companies provide superior customer service at a lower cost

INCORRECT: “AWS DataSync” is incorrect. AWS DataSync makes it simple and fast to move large amounts of data online between on-premises storage and Amazon S3, Amazon Elastic File System (Amazon EFS), or Amazon FSx for Windows File Server.

39
Q

How should an organization deploy an application running on multiple EC2 instances to ensure that a power failure does not cause an application outage?
A.Launch the EC2 instance into different VPCs
B.Launch the EC@ instances in seperate regions
C.Launch the EC2 instances into different Availabiltiy Zones
D.Launch the Ec2 instances into Edge Locations

A

C.Launch the EC2 instances into different Availabiltiy Zones

Explanation:
If you have multiple EC2 instances that are part of an application, you should deploy them into separate availability zones (AZs). Each AZ has redundant power and is also fed from a different grid. AZs also have low-latency network links which is often advantageous for most applications.

You do not need to deploy into separate regions to prevent a power outage bringing your application down. AZs have redundant power and grids so you are safe deploying your applications into multiple AZs. If you split your applications across regions you introduce latency which may impact your application. You may also run into data sovereignty issues in some cases.

Deploying your EC2 instances into different VPCs is not required and would complicate your application deployment. Also, bear in mind that VPCs within a region use the same underlying infrastructure so deploying into different VPCs may still result in your EC2 instances being deployed into the same AZs. It is a best practice to deploy into separate AZs.

CORRECT: “Launch the EC2 instances into different Availability Zones” is the correct answer.

INCORRECT: “Launch the EC2 instances in separate regions” is incorrect as described above.

INCORRECT: “Launch the EC2 instances into different VPCs” is incorrect as described above.

INCORRECT: “Launch the EC2 instances into Edge Locations” is incorrect. You cannot deploy EC2 instances into Edge Locations.

40
Q
Which AWS construct provides you with your own dedicated virtual network in the cloud?
A.Amazon Workspaces
B.Amazon Ec2
C.Amazon VPC
D.Amazon IAM
A

C.Amazon VPC

Explanation:
A virtual private cloud (VPC) is a virtual network dedicated to your AWS account. A VPC is analogous to having your own DC inside AWS. It is logically isolated from other virtual networks in the AWS Cloud.

CORRECT: “Amazon VPC” is the correct answer.

INCORRECT: “Amazon Workspaces” is incorrect. Amazon WorkSpaces is a managed desktop computing service running on the AWS cloud

INCORRECT: “Amazon EC2” is incorrect. Amazon Elastic Compute Cloud (Amazon EC2) is a web service that provides secure, resizable compute capacity in the cloud.

INCORRECT: “Amazon IAM” is incorrect. IAM is used to securely control individual and group access to AWS resources.

41
Q

Which configuration changes are associated with scaling horizontally? (Select TWO.)
A.Adding a larger capacity hard drive to a server
B.Adding additional EC2 instances through Auto Scaling
C.Changing an EC2 instance to a type that has more CPU and RAM
D>Changing the DB instances class on an RDS DB
E.Adding additional hard drives to a storage array

A

B.Adding additional EC2 instances through Auto Scaling
E.Adding additional hard drives to a storage array

Explanation:
Scaling horizontally takes place through an increase in the number of resources (e.g., adding more hard drives to a storage array or adding more servers to support an application)

Scaling vertically takes place through an increase in the specifications of an individual resource (e.g., upgrading a server with a larger hard drive or a faster CPU). On Amazon EC2, this can easily be achieved by stopping an instance and resizing it to an instance type that has more RAM, CPU, IO, or networking capabilities

CORRECT: “Adding additional EC2 instances through Auto Scaling” is the correct answer.

CORRECT: “Adding additional hard drives to a storage array” is the correct answer.

INCORRECT: “Adding a larger capacity hard drive to a server” is incorrect as this is scaling vertically.

INCORRECT: “Changing the DB instance class on an RDS DB” is incorrect as this is scaling vertically.

INCORRECT: “Changing an EC2 instance to a type that has more CPU and RAM” is incorrect as this is scaling vertically.

42
Q
Which of the following compliance programs allows the AWS environment to process, maintain, and store protected health information?    
A.ISO 2001
B.HIPAA
C.PCI DSS
D.SOC 1
A

B.HIPAA

Explanation:
AWS enables covered entities and their business associates subject to the U.S. Health Insurance Portability and Accountability Act of 1996 (HIPAA) to use the secure AWS environment to process, maintain, and store protected health information.

CORRECT: “HIPAA” is the correct answer.

INCORRECT: “ISO 27001” is incorrect as ISO/IEC 27001 is an information security standard.

INCORRECT: “PCI DSS” is incorrect as PCI DSS is related to the security of credit card payments.

INCORRECT: “SOC 1” is incorrect as this relates to financial reporting.

43
Q

Which of the facts below are accurate in relation to AWS Regions? (Select TWO.)
A.Each region is designed to be completely isolated from the other Amazon Regions
B.Regions are Content Delivery Network (CDN) endpoints for CloudFront
C.Regions have direct, low-latency, high throughput and redundant network connections between each other
D.Each region consists of 2 or more availability zones
E.Each region consist of a collection of VPCs

A

A.Each region is designed to be completely isolated from the other Amazon Regions
D.Each region consists of 2 or more availability zones

Explanation:
Availability Zones (not regions) have direct, low-latency, high throughput and redundant network connections between each other. Each AWS Region consist of 2 or more Availability Zones. AWS Regions are geographical areas and each AWS Region is designed to be completely isolated from other AWS Regions.

CORRECT: “Each region consists of 2 or more availability zones” is a correct answer.

CORRECT: “Each region is designed to be completely isolated from the other Amazon Regions” is also a correct answer.

INCORRECT: “Each region consists of a collection of VPCs” is incorrect. A region is not a collection of VPCs, it is composed of at least 2 AZs. VPCs exist within accounts on a per region basis.

INCORRECT: “Regions have direct, low-latency, high throughput and redundant network connections between each other” is incorrect. This is a description of an Availability Zone.

INCORRECT: “Regions are Content Delivery Network (CDN) endpoints for CloudFront” is incorrect. Edge locations are (not regions) are Content Delivery Network (CDN) endpoints for CloudFront

44
Q
A Cloud Practitioner requires a simple method to identify if unrestricted access to resources has been allowed by security groups. Which service can the Cloud Practitioner use?
A.Amazon CloudWatch
B.VPC Flow Logs
C.AWS CLudTrail
D.AWS Trusted Advisor
A

D.AWS Trusted Advisor

Explanation:
AWS Trusted Advisor checks security groups for rules that allow unrestricted access (0.0.0.0/0) to specific ports. Unrestricted access increases opportunities for malicious activity (hacking, denial-of-service attacks, loss of data). The ports with highest risk are flagged red, and those with less risk are flagged yellow. Ports flagged green are typically used by applications that require unrestricted access, such as HTTP and SMTP.

CORRECT: “AWS Trusted Advisor” is the correct answer.

INCORRECT: “Amazon CloudWatch” is incorrect. CloudWatch is used for performance monitoring.

INCORRECT: “VPC Flow Logs” is incorrect. VPC Flow Logs are used to capture network traffic information, they will not easily identify unrestricted security groups.

INCORRECT: “AWS CloudTrail” is incorrect. This service is used for auditing API actions

45
Q
Which AWS dashboard displays relevant and timely information to help users manage events in progress, and provides proactive notifications to help plan for scheduled activities?
A.AWS Personal Health Dashboard
B.AWS Service Health Dashboard
C.AWS Trusted Advisor Dashboard
D.Amazon CloudWatch dashboard
A

A.AWS Personal Health Dashboard

Explanation:
AWS Personal Health Dashboard provides alerts and remediation guidance when AWS is experiencing events that may impact you. While the Service Health Dashboard displays the general status of AWS services, Personal Health Dashboard gives you a personalized view into the performance and availability of the AWS services underlying your AWS resources.
The dashboard displays relevant and timely information to help you manage events in progress, and provides proactive notification to help you plan for scheduled activities. With Personal Health Dashboard, alerts are triggered by changes in the health of AWS resources, giving you event visibility, and guidance to help quickly diagnose and resolve issues.

CORRECT: “AWS Personal Health Dashboard” is the correct answer.

INCORRECT: “AWS Service Health Dashboard” is incorrect. This shows the current status of services across regions. However, it does not provide proactive notifications of scheduled activities or guidance of any kind.

INCORRECT: “AWS Trusted Advisor dashboard” is incorrect. AWS Trusted Advisor is an online tool that provides you real time guidance to help you provision your resources following AWS best practices.

INCORRECT: “Amazon CloudWatch dashboard” is incorrect as this service is used for monitoring performance related information for your infrastructure and resources, not the underlying AWS resources.

46
Q
Which service can a Cloud Practitioner use to configure custom cost and usage limits and enable alerts for when defined thresholds are exceeded?
A.COnsolidating billing
B.Cost Explorer
C.AWS Budgets
D.AWS Trusted Advisor
A

D.AWS Trusted Advisor

Explanation:
AWS Budgets allows you to set custom budgets to track your cost and usage. With AWS Budgets, you can choose to be alerted by email or SNS notification when actual or forecasted cost and usage exceed your budget threshold, or when your actual RI and Savings Plans’ utilization or coverage drops below your desired threshold.

CORRECT: “AWS Budgets” is the correct answer.

INCORRECT: “Consolidated billing” is incorrect. This is associated with AWS Organizations and provides a single bill across multiple member accounts.

INCORRECT: “AWS Trusted Advisor” is incorrect. This service provides guidance on AWS best practices.

INCORRECT: “Cost Explorer” is incorrect. This service is used for exploring the costs incurred within your account.

47
Q
A Cloud Practitioner wants to build an application stack that will be highly elastic. What AWS services can be used that don’t require you to make any capacity decisions upfront? (Select TWO.)
A.Amazon RDS
B.Amazon DynamoDB Provisioned mode
C.Amazon S3
D.Amazon EC2
E.AWS Lambda
A

C.Amazon S3
E.AWS Lambda

Explanation:
With Amazon S3 you don’t need to specify any capacity at any time, the service scales in both capacity and performance as required.

AWS Lambda lets you run code without provisioning or managing servers. You pay only for the compute time you consume – there is no charge when your code is not running.

CORRECT: “AWS Lambda” is a correct answer.

CORRECT: “Amazon S3” is also a correct answer.

INCORRECT: “Amazon EC2” is incorrect. With Amazon EC2 you need to select your instance sizes and number of instances.

INCORRECT: “Amazon RDS” is incorrect. With RDS you need to select the instance size for the DB.

INCORRECT: “Amazon DynamoDB” is incorrect. With DynamoDB provisioned mode you need to specify the read/write capacity of the DB. On-demand mode does allow elasticity, as does DynamoDB Auto Scaling but these are not offered as options.

48
Q
Which AWS service gives you centralized control over the encryption keys used to protect your data?
A.AWS STS
B.AWS KMS
C.Amazon EBS
D.AWS DSM
A

B.AWS KMS

Explanation:
AWS Key Management Service gives you centralized control over the encryption keys used to protect your data. You can create, import, rotate, disable, delete, define usage policies for, and audit the use of encryption keys used to encrypt your data.

Note: Make sure you know your abbreviations! Sometimes AWS will expand them and other times they won’t, it varies by question. Therefore, you must know the abbreviations for all services in scope for the exam.

CORRECT: “AWS KMS” is the correct answer.

INCORRECT: “AWS STS” is incorrect. The AWS Security Token Service (STS) is a web service that enables you to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users.

INCORRECT: “AWS DMS” is incorrect. AWS Database Migration Service (DMS) helps you migrate databases to AWS quickly and securely.

INCORRECT: “Amazon EBS” is incorrect. Amazon Elastic Block Store (Amazon EBS) provides persistent block storage volumes for use with Amazon EC2instances in the AWS Cloud.

49
Q
Which AWS services can be utilized at no cost? (Select TWO.)
A.Amazon RedShift
B .Identity and Access Management (IAM)
C.Amazon CLoudFront
D.Amazon S3
E.Amazon VPC
A

B .Identity and Access Management (IAM)
E.Amazon VPC

Explanation:
AWS offer many services without charge. These include the AWS IAM services for creating users, groups, roles and policies and the Amazon VPC service for creating virtual private clouds, subnets, route tables etc.

CORRECT: “Identity and Access Management (IAM)” is a correct answer.

CORRECT: “Amazon VPC” is also a correct answer.

INCORRECT: “Amazon S3” is incorrect as you must pay for this service.

INCORRECT: “Amazon CloudFront” is incorrect as you must pay for this service.

INCORRECT: “Amazon RedShift” is incorrect as you must pay for this service.

50
Q

A new user is unable to access any AWS services, what is the most likely explanation?
A.By default new users are created without access to any AWS services
B.The services are currently unavailable
C.The user needs to login with a key pair
D.The default limit for user logons has been reached

A

A.By default new users are created without access to any AWS services
Explanation

By default new users are created with NO access to any AWS services – they can only login to the AWS console. You must apply permissions to users to allow them to access services.

The recommended way to do this is to organize users into groups and then apply permissions policies to the group.

CORRECT: “By default new users are created without access to any AWS services” is the correct answer.

INCORRECT: “The user needs to login with a key pair” is incorrect. Key pairs are used for programmatic access using the API so they are required for API access only.

INCORRECT: “The services are currently unavailable” is incorrect as it is far more likely that the user just doesn’t have permissions.

INCORRECT: “The default limit for user logons has been reached” is incorrect as there is no limit for user logons.

51
Q
Which tool can be used to create and manage a selection of AWS services that are approved for use on AWS?
A.AWS Service Catalog
B.AWS oRganizations
C.AWS OpsWork
D.AMAzon CLoud Directory
A

A.AWS Service Catalog

Explanation:
AWS Service Catalog allows organizations to create and manage catalogs of IT services that are approved for use on AWS. These IT services can include everything from virtual machine images, servers, software, and databases to complete multi-tier application architectures

CORRECT: “AWS Service Catalog” is the correct answer.

INCORRECT: “AWS OpsWorks” is incorrect. AWS OpsWorks is a configuration management service that provides managed instances of Chef and Puppet.

INCORRECT: “Amazon Cloud Directory” is incorrect. Amazon Cloud Directory enables you to build flexible cloud-native directories for organizing hierarchies of data along multiple dimensions.

INCORRECT: “AWS Organizations” is incorrect. AWS Organizations offers policy-based management for multiple AWS accounts

52
Q
Which services are involved with security? (Select TWO.)
A.AWS CloudHSM
B.Amazon ELB
C.AWS DMS
D.AWS KMS
E.AWS SMS
A

A.AWS CloudHSM
D.AWS KMS

Explanation:
AWS Key Management Service (KMS) gives you centralized control over the encryption keys used to protect your data. AWS CloudHSM is a cloud-based hardware security module (HSM) that enables you to easily generate and use your own encryption keys on the AWS Cloud.

CORRECT: “AWS CloudHSM” is a correct answer.

CORRECT: “AWS KMS” is also a correct answer.

INCORRECT: “AWS DMS” is incorrect. AWS Database Migration Service is used for migration of databases.

INCORRECT: “AWS SMS” is incorrect. AWS Server Migration Service is used for migration of virtual machines.

INCORRECT: “Amazon ELB” is incorrect. Amazon Elastic Load Balancing is used for distributing incoming connections to pools of EC2 instances

53
Q
How can you apply metadata to an EC2 instance that categorizes it according to its purpose, owner or environment?    
A.Tags
B.Hostname
C.Stickers
D.Labels
A

A.Tags

Explanation:
A tag is a label that you assign to an AWS resource. Each tag consists of a key and an optional value, both of which you define. Tags enable you to categorize your AWS resources in different ways, for example, by purpose, owner, or environment

CORRECT: “Tags” is the correct answer.

INCORRECT: “Labels” is incorrect as this is not something you can assign to an AWS resource.

INCORRECT: “Hostname” is incorrect as you cannot use hostnames to categorize EC2 instances. Use tags instead.

INCORRECT: “Stickers” is incorrect as this is not something you can assign to an AWS resource.

54
Q

Which AWS service is used to send both text and email messages from distributed applications?
A.Amazon Simple Queue Service (Amazon SQS)
B.Amazon Simple Workflow Service (Amazon SWF)
C.Amazon Simple Email Service (Amazon SES)
D.Amazon Simple Notification Service (Amazon SNS)

A

D.Amazon Simple Notification Service (Amazon SNS)

Explanation:
Amazon Simple Notification Service (SNS) is a highly available, durable, secure, fully managed pub/sub messaging service that enables you to decouple microservices, distributed systems, and serverless applications.
Amazon SNS provides topics for high-throughput, push-based, many-to-many messaging. Using Amazon SNS topics, your publisher systems can fan out messages to a large number of subscriber endpoints for parallel processing, including Amazon SQS queues, AWS Lambda functions, and HTTP/S webhooks.

Additionally, SNS can be used to fan out notifications to end users using mobile push, SMS, and email.

CORRECT: “Amazon Simple Notification Service (Amazon SNS)” is the correct answer.

INCORRECT: “Amazon Simple Email Service (Amazon SES)” is incorrect. This service is used for sending email but not SMS text messages.

INCORRECT: “Amazon Simple Workflow Service (Amazon SWF)” is incorrect. Amazon SWF helps developers build, run, and scale background jobs that have parallel or sequential steps. You can think of Amazon SWF as a fully-managed state tracker and task coordinator in the Cloud.

INCORRECT: “Amazon Simple Queue Service (Amazon SQS)” is incorrect. Amazon Simple Queue Service (SQS) is a fully managed message queuing service that enables you to decouple and scale microservices, distributed systems, and serverless applications.

55
Q
Which AWS service should a Cloud Practitioner use to automate configuration management using Puppet?
A.AWS CLoudFormation
B.AWS COnfig
C.AWS OpsWorks
D.AWS Systems manager
A

C.AWS OpsWorks

Explanation

AWS OpsWorks is a configuration management service that provides managed instances of Chef and Puppet. Chef and Puppet are automation platforms that allow you to use code to automate the configurations of your servers.

OpsWorks lets you use Chef and Puppet to automate how servers are configured, deployed, and managed across your Amazon EC2 instances or on-premises compute environments,

CORRECT: “AWS OpsWorks” is the correct answer.

INCORRECT: “AWS Config” is incorrect. AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources.

INCORRECT: “AWS CloudFormation” is incorrect. AWS CloudFormation provides a common language for you to model and provision AWS and third party application resources in your cloud environment.

INCORRECT: “AWS Systems Manager” is incorrect. AWS Systems Manager gives you visibility and control of your infrastructure on AWS. Systems Manager provides a unified user interface so you can view operational data from multiple AWS services and allows you to automate operational tasks across your AWS resources.

56
Q
Which AWS hybrid storage service enables a user’s on-premises applications to seamlessly use AWS Cloud storage?
A.AWS Storage Gateway
B.Amazon Connect
C.AWS Backup
D.AWSDirect COnnect
A

A.AWS Storage Gateway

Explanation:
AWS Storage Gateway is a hybrid cloud storage service that gives you on-premises access to virtually unlimited cloud storage. Customers use Storage Gateway to simplify storage management and reduce costs for key hybrid cloud storage use cases.

These include moving tape backups to the cloud, reducing on-premises storage with cloud-backed file shares, providing low latency access to data in AWS for on-premises applications, as well as various migration, archiving, processing, and disaster recovery use cases.

CORRECT: “AWS Storage Gateway” is the correct answer.

INCORRECT: “AWS Backup” is incorrect. AWS Backup is a fully managed backup service that makes it easy to centralize and automate the backup of data across AWS services. It is not used for connecting on-premises storage to cloud storage.

INCORRECT: “Amazon Connect” is incorrect. Amazon Connect is an easy to use omnichannel cloud contact center that helps companies provide superior customer service at a lower cost. It has nothing to do with storing data.

INCORRECT: “AWS Direct Connect” is incorrect. AWS Direct Connect is a cloud service solution that makes it easy to establish a dedicated network connection from your premises to AWS. It is not related to storage of data.

57
Q
Which of the following services does Amazon Route 53 provide? (Select TWO.)
A.Auto scaling
B.DOmain Name Services (DNS)
C.Route Tables
D.Load balancing
E.Domain registration
A

B.DOmain Name Services (DNS)
E.Domain registration

Explanation:
Amazon Route 53 services include domain registration, DNS, health checking (availability monitoring) and traffic management.

CORRECT: “Domain registration” is a correct answer.

CORRECT: “Domain Name Service (DNS)” is also a correct answer.

INCORRECT: “Route tables” is incorrect as this is not provided by Route 53.

INCORRECT: “Auto Scaling” is incorrect as this is not provided by Route 53.

INCORRECT: “Load balancing” is incorrect as this is not provided by Route 53.

58
Q
A manager needs to keep a check on his AWS spend. How can the manager setup alarms that notify him when his bill reaches a certain amount?
A.Using CLoudWatch
B.USing AWS Trusted Advisor
C.By notifying AWS Support
D.Using AWS CloudTril
A

A.Using CLoudWatch

Explanation:
The best ways to do this is to use CloudWatch to configure alarms that deliver a notification when activated. The alarms can use cost metrics that trigger the alarm when a certain amount of spend has been reached

CORRECT: “Using Amazon CloudWatch” is the correct answer.

INCORRECT: “Using AWS Trusted Advisor” is incorrect as this service is focused on providing guidance for provisioning resources following AWS best practices.

INCORRECT: “Using AWS CloudTrail” is incorrect as this service is used for auditing API activity.

INCORRECT: “By notifying AWS support” is incorrect as you don’t need assistance from AWS support to do this.

59
Q
Which of the following are AWS recommended best practices in relation to IAM? (Select TWO.)
A.Create individual IAM Users
B.Enable MFA for all users
C.Assign permissions to users
D.Grant greatets privilege
E.Embed access keys in application code
A

A.Create individual IAM Users
B.Enable MFA for all users

Explanation:
AWS recommends that you create individual IAM users rather than sharing IAM user accounts.

For extra security, AWS recommends that you require multi-factor authentication (MFA) for all users in your account. For privileged IAM users who are allowed to access sensitive resources or API operations, AWS recommend using U2F or hardware MFA devices.

CORRECT: “Create individual IAM users” is the correct answer.

CORRECT: “Enable MFA for all users” is the correct answer.

INCORRECT: “Assign permissions to users” is incorrect. You should use groups to assign permissions to IAM users and should avoid embedding access keys in application code.

INCORRECT: “Embed access keys in application code” is incorrect as this is against best practice as it is highly insecure.

INCORRECT: “Grant greatest privilege” is incorrect. AWS recommend creating individual IAM users and assigning the least privilege necessary for them to perform their role.

60
Q

What are the benefits of using the AWS Managed Services? (Select TWO.)
A.Alignment with ITIL Processes
B.Designed for small businesses
C.baseline integration with ITSM tools
D.Managed applications so you can focus on infrastructure
E.Support for all AWS services

A

A.Alignment with ITIL Processes
C.baseline integration with ITSM tools

Explanation:
AWS Managed Services manages the daily operations of your AWS infrastructure in alignment with ITIL processes. AWS Managed Services provides a baseline integration with IT Service Management (ITSM) tools such as the ServiceNow platform.

AWS Managed Services provides ongoing management of your AWS infrastructure so you can focus on your applications. By implementing best practices to maintain your infrastructure, AWS Managed Services helps to reduce your operational overhead and risk.

AWS Managed Services currently supports the 20+ services most critical for Enterprises, and will continue to expand our list of integrated AWS services.

AWS Managed Services is designed to meet the needs of Enterprises that require stringent SLAs, adherence to corporate compliance, and integration with their systems and ITIL®-based processes.

CORRECT: “Alignment with ITIL processes” is a correct answer.

CORRECT: “Baseline integration with ITSM tools” is also a correct answer.

INCORRECT: “Managed applications so you can focus on infrastructure” is incorrect as this is not offered by AWS Managed Services.

INCORRECT: “Designed for small businesses” is incorrect as the service is designed for enterprises.

INCORRECT: “Support for all AWS services” is incorrect as the service does not support all AWS services.

61
Q

What can a Cloud Practitioner use the AWS Total Cost of Ownership (TCO) Calculator for?
A. Estimate a monthly bill for the AWS Cloud resources that will be used
B. Generate reports that break down AWS Cloud compute costs by duration, resource, tags
C. Estimate savings when comparing the AWS Cloud to an on-premises environment
D. Enable billing alerts to monitor actual AWS costs compared to estimated costs

A

C. Estimate savings when comparing the AWS Cloud to an on-premises environment

Explanation:
The TCO calculators allow you to estimate the cost savings when using AWS, compared to on-premises, and provide a detailed set of reports that can be used in executive presentations. The calculators also give you the option to modify assumptions that best meet your business needs.

CORRECT: “Estimate savings when comparing the AWS Cloud to an on-premises environment” is the correct answer.

INCORRECT: “Generate reports that break down AWS Cloud compute costs by duration, resource, or tags” is incorrect. This describes the AWS Cost & Usage Report.

INCORRECT: “Estimate a monthly bill for the AWS Cloud resources that will be used” is incorrect. This describes the AWS Pricing Calculator (or Simple Monthly Calculator).

INCORRECT: “Enable billing alerts to monitor actual AWS costs compared to estimated costs” is incorrect. Billing alerts can be enabled using Amazon CloudWatch.

62
Q
Which AWS service can be used to load data from Amazon S3, transform it, and move it to another destination?
A.Amazon Kinesis
B.Amazon EMR
C.AWS Glue
D>Amazon RedShift
A

C.AWS Glue

Explanation:
AWS Glue is an Extract, Transform, and Load (ETL) service. You can use AWS Glue with data sources on Amazon S3, RedShift and other databases. With AWS Glue you transform and move the data to various destinations. It is used to prepare and load data for analytics.
CORRECT: “AWS Glue” is the correct answer.

INCORRECT: “Amazon RedShift” is incorrect. Amazon RedShift is a data warehouse. With a data warehouse you load data from other databases such as transactional SQL databases and run analysis. You can analyze data using SQL and Business Intelligence tools.

INCORRECT: “Amazon EMR” is incorrect. Amazon EMR is a managed Hadoop framework running on EC2 and S3. It is used for analyzing data, not for ETL.

INCORRECT: “Amazon Kinesis” is incorrect. Amazon Kinesis is used for collecting, processing and analyzing real-time streaming data.

63
Q
What are the names of two types of AWS Storage Gateway? (Select TWO.)
A,S3 Gateway
B.Gateway Virtual Tape Library
C.Block Gateway
D.Cached Gateway
E.File Gateway
A

B.Gateway Virtual Tape Library
E.File Gateway

Explanation
The AWS Storage Gateway service enables hybrid storage between on-premises environments and the AWS Cloud. It provides low-latency performance by caching frequently accessed data on premises, while storing data securely and durably in Amazon cloud storage services. AWS Storage Gateway supports three storage interfaces: file, volume, and tape

File gateway provides a virtual on-premises file server, which enables you to store and retrieve files as objects in Amazon S3

The volume gateway represents the family of gateways that support block-based volumes, previously referred to as gateway-cached and gateway-stored modes

Tape Gateway (formerly known as Gateway Virtual Tape Library) is used for backup with popular backup software.|

All other answers are bogus and use terms that are associated with Storage Gateways (S3, block, cached)

CORRECT: “File Gateway” is a correct answer.

CORRECT: “Tape Gateway” is also a correct answer.

INCORRECT: “S3 Gateway” is incorrect as explained above.

INCORRECT: “Block Gateway” is incorrect as explained above.

INCORRECT: “Cached Gateway” is incorrect as explained above.

64
Q
Which AWS service provides elastic web-scale cloud computing allowing you to deploy operating system instances?    
A.Amazon EBS
B.Amazon RDS
C.AWS Lambda
D.Amazon EC2
A

D.Amazon EC2

Explanation:
The Amazon Elastic Compute Cloud (EC2) provides elastic web-scale computing in the cloud allowing you to deploy instances running the Windows and Linux operating systems.

CORRECT: “Amazon EC2” is the correct answer.

INCORRECT: “Amazon EBS” is incorrect. Amazon Elastic Block Store (Amazon EBS) provides persistent block storage volumes for use with Amazon EC2instances in the AWS Cloud.

INCORRECT: “AWS Lambda” is incorrect. AWS Lambda lets you run code without provisioning or managing server operating systems.

INCORRECT: “Amazon RDS” is incorrect. Amazon Relational Database Service (Amazon RDS) makes it easy to set up, operate, and scale a relational database in the cloud.

65
Q

How can a security compliance officer retrieve AWS compliance documentation such as a SOC 2 report?
A.Using AWS Inspector
B.Using AWS Trusted Advisor
C.Using the AWS Personal Health Dashboard
D.Using AWS Artifact

A

D.Using AWS Artifact

Explanation:
AWS Artifact, available in the console, is a self-service audit artifact retrieval portal that provides our customers with on-demand access to AWS’ compliance documentation and AWS agreements.

You can use AWS Artifact Reports to download AWS security and compliance documents, such as AWS ISO certifications, Payment Card Industry (PCI), and System and Organization Control (SOC) reports.

CORRECT: “Using AWS Artifact” is the correct answer.

INCORRECT: “Using AWS Trusted Advisor” is incorrect. AWS Trusted Advisor is an online resource to help you reduce cost, increase performance, and improve security by optimizing your AWS environment.

INCORRECT: “Using AWS Inspector” is incorrect. Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS.

INCORRECT: “Using the AWS Personal Health Dashboard” is incorrect. AWS Personal Health Dashboard provides alerts and remediation guidance when AWS is experiencing events that may impact you.