AWS Cloud Practioner Flashcards

1
Q

When storing sensitive company data in Amazon S3, which security best practices should customers follow?

A

Enable S3 server-side encryption on S3 bucket.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What benefits does Amazon EC2 provide overusing non-cloud servers? (Select TWO.)

A
  • Inexpensive

- Elastic web-scale computing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which tool enables you to visualize your usage patterns over time and to identify your underlying cost drivers?

A
  • AWS Cost Explorer
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AWS Trusted Advisor provides real-time guidance on what characteristics of an AWS account? (Select TWO.)

A
  • Security best practices

- Cost optimization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which of the following statements is correct in relation to consolidated billing? (Select TWO.) #2

A
  • The paying account is independent and cannot access resources of other accounts.
  • One bill is provided per AWS organization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which types of pricing policies does AWS offer? (Select TWO.)

A
  • Save when you reserve

- Pay-as-you-go

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which Amazon S3 storage classes should be used for storing data for long time periods when immediate access is not required at the LOWEST cost? (Select TWO.)

A
  • Amazon S3 Glacier

- Amazon S3 Glacier Deep Archive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What method can you use to take a backup of an Amazon EC2 instance using AWS tools?

A
  • Take a snapshot to capture the point-in-time state of the instance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which benefit of the AWS Cloud eliminates the need for users to try estimating future infrastructure usage?

A
  • Elasticity of the AWS Cloud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which service allows you to automatically expand and shrink your application in response to demand?

A
  • Amazon EC2 Auto Scaling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which AWS service is primarily used for software version control?

A
  • AWS CodeCommit
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What benefits are provided by Amazon CloudFront? (Select TWO.) #2

A
  • Content is cached at Edge Locations for fast distribution to customers
  • Built-in Distributed Denial of Service (DDoS) attack protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which service can be used to help you to migrate databases to AWS quickly and securely?

A
  • AWS Database Migration Service (DMS)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

A company recently took up an Enterprise-level AWS Support plan and has a question relating to their AWS account. Who is the primary point of contact they should direct the question to?

A
  • AWS Concierge Support team
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which AWS service can be used to convert video and audio files from their source format into versions that will playback on devices like smartphones, tablets and PC?

A
  • Elastic Transcoder
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A company would like to maximize their potential volume and Reserved Instance discounts across multiple accounts and also apply service control policies on member accounts. Which service or tool can they use to gain these benefits?

A
  • AWS Organizations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which feature of Amazon Rekognition can assist with saving time?

A
  • Identification of objects in images and videos
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the most cost-effective support plan that should be selected to provide at most a 1-hour response time for a production system failure?

A
  • Business
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which benefits can an organization achieve by deploying AWS Global Accelerator? (Select TWO.)

A
  • Improves the availability of applications on AWS

- Decreased latency to reach applications deployed on AWS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What advantages do you get from using the AWS cloud? (Select TWO.) #2

A
  • Stop guessing about capacity

- Trade capital expense for variable expense

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What can you use to quickly connect your office securely to your Amazon VPC?

A
  • AWS managed VPN
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which of the following is a principle of good AWS Cloud architecture design?

A
  • Implement loose coupling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Under the AWS shared responsibility model what is the customer responsible for? (Select TWO.)

A
  • Configuration of security groups

- Encryption of customer data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Which feature of AWS allows you to deploy a new application for which the requirements may change over time?

A
  • Elasticity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

A company plans to deploy a global commercial application on Amazon EC2 instances. The deployment solution should be designed with the highest redundancy and fault tolerance. Based on this situation, how should the EC2 instances be deployed?

A
  • Across multiple Availability Zones in two AWS Regions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Which services can be used for asynchronous integration between application components? (Select TWO.)

A
  • Amazon SQS

- AWS Step Functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Which services are involved in reducing application latency and increasing performance for end users? (Select TWO.)

A
  • Amazon CloudFront

- Amazon ElastiCache

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Which AWS service is used to enable multi-factor authentication?

A
  • AWS IAM
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which AWS service can an organization use to automate operational tasks on EC2 instances using existing Chef cookbooks?

A
  • AWS OpsWorks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What are two ways that moving to an AWS cloud can benefit an organization? (Select TWO.)

A
  • Stop guessing about capacity

- Increase speed and agility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

When a customer deploys a database on Amazon RDS, what is the customer responsible for?

A
  • Controlling network access through security groups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Under the AWS shared responsibility model, what are the customer’s responsibilities? (Select TWO.) #2

A
  • Data integrity Authentication

- Security of data in transit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Which service allows you to run code as functions without needing to provision or manage servers?

A
  • AWS Lambda
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Which of the following types of recommendation does AWS Trusted Advisor provide? (Select TWO.)

A
  • Cost optimization

- Performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Which items can be configured from within the VPC management console? (Select TWO.)

A
  • Subnets

- Security Groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What strategy can assist with allocating metadata to AWS resources for cost tracking and visibility?

A
  • Tagging
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Which service can be used to track the CPU usage of an EC2 instance?

A
  • Amazon Cloudwatch
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Which AWS services can be used to connect the AWS Cloud and on-premises resources? (Select TWO.)

A
  • AWS Direct Connect

- AWS Managed VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

An AWS customer wishes to purchase unused Amazon EC2 capacity at a discounted rate. Which pricing plan should they choose?

A
  • Spot Instances
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Under the shared responsibility model, what are examples of shared controls? (Select TWO.)

A
  • Configuration Management

- Patch Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Which service supports the resolution of public domain names to IP addresses or AWS resources?

A
  • Amazon Route 53
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Which AWS storage technology can be considered a “virtual hard disk in the cloud”?

A
  • Amazon Elastic Block Storage (EBS) volume
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

Which service can be used for building and integrating loosely-coupled, distributed applications?

A
  • Amazon SNS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Which service records API activity on your account and delivers log files to an Amazon S3 bucket?

A
  • AWS CloudTrail
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Which AWS service allows you to connect to storage from on-premise servers using standard file protocols?

A
  • Amazon EFS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

What advantages does deploying Amazon CloudFront provide? (Select TWO.)

A
  • Reduced latency

- Improved performance for end users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

A company stores copies of backups on Amazon S3 and requires rapid access but low resiliency. Which storage class is optimized for these requirements?

A
  • Amazon S3 One Zone-Infrequent Access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What is the scope of a VPC within a region?

A
  • Spans all Availability Zones within the region
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

For which services does Amazon not charge customers? (Select TWO.)

theres two of these

A
  • AWS CloudFormation

- Amazon VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

Which AWS service can be used to generate encryption keys that can be used to encrypt data? (Select TWO.)

A
  • AWS CloudHSM

- AWS Key Management Service (AWS KMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

Which AWS service can you use to install a third-party database?

A
  • Amazon EC2
52
Q

Which feature can you use to grant read/write access to an Amazon S3 bucket?

A
  • IAM Policy
53
Q

Which service can you use to provision a preconfigured server with little to no AWS experience?

A
  • Amazon LightSail
54
Q

Which storage service allows you to connect multiple EC2 instances concurrently using file-level protocols?

A
  • Amazon EFS
55
Q

What considerations are there when choosing which region to use? (Select TWO.)

A
  • Data Sovereignty

- Latency

56
Q

How does AWS assist organizations’ with their capacity requirements?

A
  • You don’t need to guess capacity needs
57
Q

Which pricing model should you use for EC2 instances that will be used in a lab environment for several hours on a weekend and must run uninterrupted?

A
  • On-Demand
58
Q

What is the most cost-effective EC2 pricing option to use for a non-critical overnight workload?

A
  • Spot
59
Q

The AWS global infrastructure is composed of? (Select TWO.)

A
  • Regions

- Availability Zones

60
Q

A Cloud Practitioner needs to decide which Amazon S3 storage class to use for storing copies of backup data. The storage must provide rapid access when needed but resiliency can be low. Which storage class is most suitable?

A
  • Amazon S3 One Zone-IA
61
Q

Which AWS support plan should you use if you need a response time of < 15 minutes for a business-critical system failure?

A
  • Enterprise
62
Q

What architectural best practice aims to reduce the interdependencies between services?

A
  • Loose Coupling
63
Q

What can you use to quickly connect your office securely to your Amazon VPC?

A
  • AWS managed VPN
64
Q

Which benefits can an organization achieve by deploying AWS Global Accelerator? (Select TWO.)

A
  • Improves the availability of applications on AWS

- Decreased latency to reach applications deployed on AWS

65
Q

Which service supports the resolution of public domain names to IP addresses or AWS resources?

A
  • Amazon Route 53
66
Q

A new user is unable to access any AWS services, what is the most likely explanation?

A
  • By default, new users are created without access to any AWS services
67
Q

What features does Amazon RDS provide to deliver scalability, availability and durability? (Select TWO.)

A
  • Read Replicas

- Multi-AZ

68
Q

Which of the following are AWS recommended best practices in relation to IAM? (Select TWO.)

A
  • Create individual IAM users

- Enable MFA for all users

69
Q

Which AWS support plans provide support via email, chat and phone? (Select TWO.)

A
  • Business

- Enterprise

70
Q

Which services are managed at a regional (rather than global) level? (Select TWO.)

A
  • Amazon EC2

- Amazon S3

71
Q

Which AWS service should a Cloud Practitioner use to automate configuration management using Puppet?

A
  • AWS OpsWorks
72
Q

A manager needs to keep a check on his AWS spend. How can the manager setup alarms that notify him when his bill reaches a certain amount?

A
  • Using Amazon CloudWatch
73
Q

How can an organization assess application for vulnerabilities and deviations from best practice?

A
  • Use AWS Inspector
74
Q

Which service can a Cloud Practitioner use to configure custom cost and usage limits and enable alerts for when defined thresholds are exceeded?

A
  • AWS Budgets
75
Q

Which AWS service can be used to host a static website?

A
  • Amazon S3
76
Q

Which AWS service can be used to load data from Amazon S3, transform it, and move it to another destination?

A
  • AWS Glue
77
Q

What are two ways of connecting to an Amazon VPC from an on-premise data center? (Select TWO.)

A
  • AWS VPN CloudHub
78
Q

Which AWS services can be utilized at no cost? (Select TWO.)

A
  • Identity and Access Management

- AmazonVPC

79
Q

Which of the following security operations tasks must be performed by AWS customers? (Select TWO.)

A
  • Installing security updates on EC2 instances

- Enabling MFA for privileged users

80
Q

Which AWS dashboard displays relevant and timely information to help users manage events in progress, and provides proactive notifications to help plan for scheduled activities?

A
  • AWS Personal Health Dashboard
81
Q

Which of the following compliance programs allows the AWS environment to process, maintain, and store protected health information?

A
  • HIPPA
82
Q

Which AWS service protects against common exploits that could compromise application availability, compromise security or consume excessive resources?

A
  • AWS WAF
83
Q

Which AWS service provides elastic web-scale cloud computing allowing you to deploy operating system instances?

A
  • Amazon EC2
84
Q

Which Amazon EC2 pricing model should be avoided if a workload cannot accept interruption if capacity becomes temporarily unavailable?

A
  • Spot Instances
85
Q

Which of the following are valid types of Reserved Instance? (Select TWO.)

A
  • Convertible RI

- Scheduled RI

86
Q

Which AWS-managed service can be used to process vast amounts of data using a hosted Hadoop framework?

A
  • Amazon EMR
87
Q

How should an organization deploy an application running on multiple EC2 instances to ensure that a power failure does not cause an application outage?

A
  • Launch the EC2 instances into different Availability Zones
88
Q

A Cloud Practitioner wants to configure the AWS CLI for programmatic access to AWS services. Which credential components are required? (Select TWO.)

A
  • An access key ID

- A secret access key

89
Q

What can a Cloud Practitioner do with the AWS Cost Management tools? (Select TWO.)

A
  • Visualize AWS cost by day, service and linked AWS account

- Create budgets and receive notification if current of forecasted

90
Q

An application stores images which will be retrieved infrequently, but must be available for retrieval immediately. Which is the most cost-effective storage option that meets these requirements?

A
  • Amazon S3 Standard-Infrequent Access
91
Q

Which of the statements below is correct in relation to Consolidated Billing? (Select TWO.)

A
  • receive a single bill for multiple accounts

- combine usage and share volume pricing discounts

92
Q

What are the names of two types of AWS Storage Gateway? (Select TWO.)

A
  • File Gateway

- Gateway Virtual Tape Library

93
Q

Amazon S3 is typically used for which of the following use cases? (Select TWO.)

A
  • Host a static website

- Media hosting

94
Q

What type of database is fully managed and can be scaled without incurring downtime?

A
  • Amazon Dynamo DB
95
Q

Which configuration changes are associated with scaling horizontally? (Select TWO.)

A
  • Adding additional hard drives to a storage array

- Adding additional EC2 instances through Auto Scaling

96
Q

Which AWS service gives you centralized control over the encryption keys used to protect your data?

A
  • AWS KMS (Key Management Service)
97
Q

A user needs an automated security assessment report that will identify unintended network access to Amazon EC2 instances and vulnerabilities on those instances. Which AWS service will provide this assessment report?

A
  • Amazon Inspector
98
Q

How can a security compliance officer retrieve AWS compliance documentation such as a SOC 2 report?

A
  • Using AWS Artifact
99
Q

Which AWS service helps customers meet corporate, contractual, and regulatory compliance requirements for data security by using dedicated hardware appliances within the AWS Cloud?

A
  • AWS CloudHSM
100
Q

Which services are involved with security? (Select TWO.)

A
  • AWS Cloud HSM

- AWS KMS

101
Q

Which tool can be used to create and manage a selection of AWS services that are approved for use on AWS?

A
  • AWS Service Catalog
102
Q

Which benefits can a company immediately realize using the AWS Cloud? (Select TWO.)

A
  • Capital expenses are replaced with variable expenses

- Increased agility

103
Q

A company needs a consistent and dedicated connection between AWS resources and an on-premise system. Which AWS service can fulfil this requirement?

A
  • AWS Direct Connect
104
Q

A Cloud Practitioner wants to build an application stack that will be highly elastic. What AWS services can be used that don’t require you to make any capacity decisions upfront? (Select TWO.)

A
  • Amazon S3

- AWS Lamda

105
Q

A user has limited knowledge of AWS services, but wants to quickly deploy a scalable Node.js application in an Amazon VPC. Which service should be used to deploy the application?

A
  • AWS Elastic Beanstalk
106
Q

What can a Cloud Practitioner use the AWS Total Cost of Ownership (TCO) Calculator for?

A
  • Estimate savings when comparing the AWS Cloud to an on-premises environment
107
Q

A company is planning to migrate some resources into the cloud. What factors need to be considered when determining the cost of the AWS Cloud? (Select TWO.)

A
  • The number of servers migrated into EC2

- The amount of egress data per month

108
Q

Which AWS service is used to send both text and email messages from distributed applications?

A
  • Amazon Simple Notification Service (Amazon SNS)
109
Q

Which AWS service should a Cloud Practitioner use to establish a secure network connection between an on-premises network and AWS?

A
  • Virtual Private Network
110
Q

You need to ensure you have the right amount of compute available to service demand. Which AWS service can automatically scale the number of EC2 instances for your application?

A
  • Amazon EC2 Auto Scaling
111
Q

Which AWS service provides preconfigured virtual private servers (instances) that include everything required to deploy an application or create a database?

A
  • Amazon Lightsail
112
Q

What are two ways an AWS customer can reduce their monthly spend? (Select TWO.)

A
  • Reserve capacity where suitable

- Turn off resources that are not being used

113
Q

Which AWS service or feature allows a company to receive a single monthly AWS bill when using multiple AWS accounts?

A
  • Consolidated billing
114
Q

A Cloud Practitioner requires a simple method to identify if unrestricted access to resources has been allowed by security groups. Which service can the Cloud Practitioner use?

A
  • AWS Trusted Advisor
115
Q

What are the benefits of using the AWS Managed Services? (Select TWO.)

A
  • Baseline integration with ITSM tools

- Alignment with ITIL processes

116
Q

Which AWS construct provides you with your own dedicated virtual network in the cloud?

A
  • AmazonVPC
117
Q

You need to implement a hosted queue for storing messages in transit between application servers. Which service should you use?

A
  • Amazon SQS
118
Q

Which items should be included in a TCO analysis comparing on-premise to AWS Cloud? (Select TWO.)

A
  • Compute hardware

- Data center security

119
Q

Which AWS service can be used to run Docker containers?

A
  • Amazon ECS
120
Q

What is a Resource Group?

A
  • A collection of resources that share one or more tags
121
Q

Which AWS hybrid storage service enables a user’s on-premises applications to seamlessly use AWS Cloud storage?

A
  • AWS Storage Gateway
122
Q

An application has highly dynamic usage patterns. Which characteristics of the AWS Cloud make it cost-effective for this type of workload? (Select TWO.)

A
  • Pay-as-you-go pricing

- Elasticity

123
Q

An eCommerce company plans to use the AWS Cloud to quickly deliver new functionality in an iterative manner, minimizing the time to market. Which feature of the AWS Cloud provides this functionality?

A
  • Agility
124
Q

Which service provides visibility into user activity by recording actions taken on your account?

A
  • Amazon CloudTrail
125
Q

Which of the following services does Amazon Route 53 provide? (Select TWO.)

A
  • Domain registration

- Domain Name Service (DNS)