Question Set 3
Question Set 3
1 Which AWS services can host a Microsoft SQL Server database? (choose two)
A. Amazon EC2.
B. Amazon Relational Database Service (Amazon RDS).
C. Amazon Aurora
D. Amazon Redshift
E. Amazon S3
2 Which of the following Amazon EC2 pricing models allow customers to use existing
server-bound software licenses?
A. Spot Instances
B. Reserved Instances
C. Dedicated Hosts.
D. On-Demand Instances
3 Which service enables risk auditing by continuously monitoring and logging account activity,
including user actions in the AWS Management Console and AWS SDKs?
A. Amazon CloudWatch
B. AWS CloudTrail.
C. AWS Config
D. AWS Health
4 Which services can be used across hybrid AWS Cloud architectures? (Choose two.)
A. Amazon Route 53.
B. Virtual Private Gateway.
C. Classic Load Balancer
D. Auto Scaling
E. Amazon CloudWatch default metrics
5 A company is considering using AWS for a self-hosted database that requires a nightly
shutdown for maintenance and cost-saving purposes. Which service should the company use?
A. Amazon Redshift
B. Amazon DynamoDB
C. Amazon Elastic Compute Cloud (Amazon EC2) with Amazon EC2 instance store
D. Amazon EC2 with Amazon Elastic Block Store (Amazon EBS).
6 Which AWS tools assist with estimating costs? (Choose three.)
A. Detailed billing report
B. Cost allocation tags.
C. AWS Pricing Calculator.
D. AWS Total Cost of Ownership (TCO) Calculator.
E. Cost Estimator
7 Which of the following Reserved Instance (RI) pricing models provides the highest average
savings compared to On-Demand pricing?
A. One-year, No Upfront, Standard RI pricing
B. One-year, All Upfront, Convertible RI pricing
C. Three-year, All Upfront, Standard RI pricing.
D. Three-year, No Upfront, Convertible RI pricing
10 Which AWS feature will reduce the customer's total cost of ownership (TCO)?
A. Shared responsibility security model
B. Single tenancy
C. Elastic computing.
D. Encryption
13 AWS supports which of the following methods to add security to Identity and Access
Management (IAM) users? (Choose two.)
A. Implementing Amazon Rekognition
B. Using AWS Shield-protected resources
C. Blocking access with Security Groups
D. Using Multi-Factor Authentication (MFA)
E. Enforcing password strength and expiration
14 What is one of the advantages of the Amazon Relational Database Service (Amazon
RDS)?(choose three)
A. It simplifies relational database administration tasks.
B. It provides 99.99999999999% reliability and durability.
C. It automatically scales databases for loads.
D. It enabled users to dynamically adjust CPU and RAM resources.
15 Which of the following components of the AWS Global Infrastructure consists of one or more
discrete data centers interconnected through low latency links?
A. Availability Zone
B. Edge location
C. Region
D. Private networking
16 How many Availability Zones should compute resources be provisioned across to achieve
high availability?
A. A minimum of one
B. A minimum of two
C. A minimum of three
D. A minimum of four or more
17 What is the lowest-cost, durable storage option for retaining database backups for
immediate retrieval?
A. Amazon S3
B. Amazon Glacier
C. Amazon EBS
D. Amazon EC2 Instance Store
19 Which service should a customer use to consolidate and centrally manage multiple AWS
accounts?
A. AWS IAM
B. AWS Organizations
C. AWS Schema Conversion Tool
D. AWS Config
21 Which of the following is the customer's responsibility under the AWS shared responsibility
model?
A. Patching underlying infrastructure
B. Physical security
C. Patching Amazon EC2 instances
D. Patching network infrastructure
22 Which of the following is an AWS managed Domain Name System (DNS) web service?
A. Amazon Route 53
B. Amazon Neptune
C. Amazon SageMaker
D. Amazon Lightsail
23 Which storage service can be used as a low-cost option for hosting static websites?
A. Amazon Glacier
B. Amazon DynamoDB
C. Amazon Elastic File System (Amazon EFS)
D. Amazon Simple Storage Service (Amazon S3)
24 What is the AWS customer responsible for according to the AWS shared responsibility model?
A. Physical access controls
B. Data encryption
C. Secure disposal of storage devices
D. Environmental risk management
25 A company is looking for a scalable data warehouse solution. Which of the following AWS
solutions would meet the company's needs?
A. Amazon Simple Storage Service (Amazon S3)
B. Amazon DynamoDB
C. Amazon Kinesis
D. Amazon Redshift
26 Which of the following are valid ways for a customer to interact with AWS services?
(Choose two.)
A. Command line interface
B. On-premises
C. Software Development Kits
D. Software-as-a-service
E. Hybrid
27 Which of the following AWS services can be used to serve large amounts of online video
content with the lowest possible latency? (Choose two.)
A. AWS Storage Gateway
B. Amazon S3
C. Amazon Elastic File System (EFS)
D. Amazon Glacier
E. Amazom CloudFront
28 What is the benefit of using AWS managed services, such as Amazon ElastiCache and
Amazon Relational Database Service (Amazon RDS)?
A. They require the customer to monitor and replace failing instances.
B. They have better performance than customer-managed services.
C. They simplify patching and updating underlying OSs.
D. They do not require the customer to optimize instance type or size selections
29 Which of the following Identity and Access Management (IAM) entities is associated with an
access key ID and secret access key when using AWS Command Line Interface (AWS CLI)?
A. IAM group
B. IAM user
C. IAM role
D. IAM policy
31 When architecting cloud applications, which of the following are a key design principle?
A. Use the largest instance possible
B. Provision capacity for peak load
C. Use the Scrum development process
D. Implement elasticity
32 Under the shared responsibility model, which of the following is a shared control
between a customer and AWS?
A. Physical controls
B. Patch management
C. Zone security
D. Data center auditing
33 A company wants to reduce the physical compute footprint that developers use to run code.
Which service would meet that need by enabling serverless architectures?
A. Amazon Elastic Compute Cloud (Amazon EC2)
B. AWS Lambda
C. Amazon DynamoDB
D. AWS CodeCommit
34 Which of the following are categories of AWS Trusted Advisor? (Choose two.)
A. Fault Tolerance
B. Instance Usage
C. Infrastructure
D. Performance
E. Storage Capacity
35 Where should a company go to search software listings from independent software vendors
to find, test, buy and deploy software that runs on AWS?
A. AWS Marketplace
B. Amazon Lumberyard
C. AWS Artifact
D. Amazon CloudSearch
36 When performing a cost analysis that supports physical isolation of a customer workload,
which compute hosting model should be accounted for in the Total Cost of Ownership
(TCO)?
A. Dedicated Hosts
B. Reserved Instances
C. On-Demand Instances
D. No Upfront Reserved Instances
37 If a customer needs to audit the change management of AWS resources, which of the
following AWS services should the customer use?
A. AWS Config
B. AWS Trusted Advisor
C. Amazon CloudWatch
D. Amazon Inspector
38 Which service allows a company with multiple AWS accounts to combine its usage to obtain
volume discounts?
A. AWS Server Migration Service
B. AWS Organizations
C. AWS Budgets
D. AWS Trusted Advisor
E. Amazon Quicksight
F. Amazon Forecast
39 Which Amazon EC2 pricing model adjusts based on supply and demand of EC2 instances?
A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Convertible Reserved Instances
40 Which is the MINIMUM AWS Support plan that allows for one-hour target response time for
support cases?
A. Enterprise
B. Business
C. Developer
D. Basic
41 Which AWS service provides a customized view of the health of specific AWS services that
power a customer's workloads running on AWS?
A. AWS Service Health Dashboard
B. AWS X-Ray
C. AWS Personal Health Dashboard
D. Amazon CloudWatch
42 Which of the following steps should be taken by a customer when conducting penetration
testing on an AWS ?
A. Conduct penetration testing using Amazon Inspector, and then notify AWS support.
B. Request and wait for approval from the customer's internal security team, and then
conduct testing.
C. Notify AWS support, and then conduct testing immediately.
D. Request and wait for approval from AWS support, and then conduct testing.
43 Which of the following steps should be taken by a customer when conducting penetration
testing on an AWS ?
A. Conduct penetration testing using Amazon Inspector, and then notify AWS support.
B. Request and wait for approval from the customer's internal security team, and then
conduct testing.
C. Notify AWS support, and then conduct testing immediately.
D. Request and wait for approval from AWS support, and then conduct testing.
44 How would an AWS customer easily apply common access controls to a large set of users?
A. Apply an IAM policy to an IAM group.
B. Apply an IAM policy to an IAM role.
C. Apply the same IAM policy to all IAM users with access to the same workload.
D. Apply an IAM policy to an Amazon Cognito user pool.
45 Which AWS services are defined as global instead of regional? (Choose two.)
A. Amazon Route 53
B. Amazon EC2
C. Amazon S3
D. Amazon CloudFront
E. Amazon DynamoDB
46 Which AWS service can be used to manually launch instances based on resource
requirements?
A. Amazon EBS
B. Amazon S3
C. Amazon EC2
D. Amazon ECS
49 Which of the following security measures protect access to an AWS account? (Choose two.)
A. Enable AWS CloudTrail.
B. Grant least privilege access to IAM users.
C. Create one IAM user and share with many developers and users.
D. Enable Amazon CloudFront.
E. Activate multi-factor authentication (MFA) for privileged users.
50 Which of the following services falls under the responsibility of the customer to
maintain operating system configuration, security patching, and networking?
A. Amazon RDS
B. Amazon EC2
C. Amazon ElastiCache
D. AWS Fargate
51 Amazon Relational Database Service (Amazon RDS) offers which of the following
benefits over traditional database management?
A. AWS manages the data stored in Amazon RDS tables.
B. AWS manages the maintenance of the operating system.
C. AWS automatically scales up instance types on demand.
D. AWS manages the database type.
52 Which of the following is a component of the shared responsibility model managed entirely
by AWS?
A. Patching operating system software
B. Encrypting data
C. Enforcing multi-factor authentication
D. Auditing physical data center assets
53 Which of the following features can be configured through the Amazon Virtual Private Cloud
(Amazon VPC) Dashboard? (Choose two.)
A. Amazon CloudFront distributions
B. Amazon Route 53
C. Security Groups
D. Subnets
E. Elastic Load Balancing
55 Which of the following common IT tasks can AWS cover to free up company IT resources?
(Choose two.)
A. Patching databases software
B. Testing application releases
C. Backing up databases
D. Creating database schema
E. Running penetration tests
59 A solution that is able to support growth in users, traffic, or data size with no drop in
performance aligns with which cloud architecture principle?
A. Think parallel
B. Implement elasticity
C. Decouple your components
D. Design for failure
60 How should a customer forecast the future costs for running a new web application?
A. Amazon Aurora Backtrack
B. Amazon CloudWatch Billing Alarms
C. AWS Pricing Calculator
D. AWS Cost and Usage report
64 Which AWS IAM feature is used to associate a set of permissions with multiple users?
A. Multi-factor authentication
B. Groups
C. Password policies
D. Access keys
65 Which of the following can a customer use to enable single sign-on (SSO) to the AWS
Console?
A. Amazon Connect
B. AWS Directory Service
C. Amazon Pinpoint
D. Amazon Rekognition