Free AWS CLF-C02 Practice Exam: Cloud Practitioner
Try 65 free AWS Certified Cloud Practitioner (AWS CLF-C02) questions across the exam domains, with explanations, then continue with IT Mastery practice.
This free full-length AWS CLF-C02 practice exam includes 65 original IT Mastery questions across the exam domains.
These are original IT Mastery practice questions. They are not official AWS questions, copied live-exam content, or exam dumps. Use them to preview question style and explanation depth before continuing with mixed sets, topic drills, and timed mocks in IT Mastery.
Count note: this page uses the full-length practice count maintained in the Mastery exam catalog. Some certification vendors publish total questions, scored questions, duration, or unscored/pretest-item rules differently; always confirm exam-day rules with the sponsor.
Try the IT Mastery web app for a richer interactive practice experience with mixed sets, timed mocks, topic drills, explanations, and progress tracking.
Exam snapshot
- Practice target: AWS CLF-C02
- Practice-set question count: 65
- Time limit: 90 minutes
- Practice style: mixed-domain diagnostic run with answer explanations
Full-length exam mix
| Domain | Weight |
|---|---|
| Cloud Concepts | 24% |
| Security and Compliance | 30% |
| Cloud Technology and Services | 34% |
| Billing, Pricing, and Support | 12% |
Use this as one diagnostic run. IT Mastery gives you timed mocks, topic drills, analytics, code-reading practice where relevant, and interactive practice.
Practice questions
Questions 1-25
Question 1
Topic: Billing, Pricing, and Support
A company is preparing its first AWS migration. The team wants curated, reusable strategies and implementation patterns for planning the migration. It also wants to post technical questions and receive responses from AWS experts and other AWS users.
Which TWO resource uses meet these needs? (Select TWO.)
Options:
A. Use AWS Knowledge Center to ask questions answered by AWS experts and the community.
B. Use AWS Prescriptive Guidance for migration strategies, patterns, and best practices.
C. Use AWS Knowledge Center for migration strategies, patterns, and best practices.
D. Use AWS re:Post to open private support cases involving account-specific information.
E. Use AWS re:Post to ask questions answered by AWS experts and the community.
Correct answers: B and E
Explanation: AWS Prescriptive Guidance provides curated strategies, guides, and reusable patterns for migration, modernization, and other cloud initiatives. AWS re:Post is an interactive community where users can post technical questions and receive responses from AWS experts and other customers. AWS Knowledge Center instead provides AWS-authored articles and videos that answer frequently asked technical and troubleshooting questions. It is useful when an existing curated answer may resolve a common issue, but it is not the primary resource for broad migration patterns or community discussion. Private, account-specific assistance requires an AWS Support case rather than a public re:Post discussion.
- Knowledge Center strategies confuses answers to common technical questions with the broader migration strategies and patterns in Prescriptive Guidance.
- Knowledge Center discussion treats curated AWS-authored content as an interactive community question-and-answer service.
- Private re:Post case confuses public community assistance with account-specific help provided through AWS Support.
Question 2
Topic: Security and Compliance
A company manages several AWS accounts with AWS Organizations. Employees already authenticate through a corporate SAML 2.0 identity provider. The company wants one access portal and centrally managed permissions while employees continue using their corporate credentials.
Which action best meets this need?
Options:
A. Configure SAML federation separately in each account and map groups to IAM roles
B. Create IAM users in one account and allow them to assume cross-account roles
C. Federate the corporate IdP through Amazon Cognito and assign users to account roles
D. Connect the corporate IdP to IAM Identity Center and assign permission sets to groups
Best answer: D
Explanation: AWS IAM Identity Center provides centralized workforce access to multiple AWS accounts. It can use an external SAML 2.0 identity provider for employee authentication, while permission sets define access that is assigned to users or groups for specific accounts. Employees can then access their authorized accounts through one portal using their existing corporate credentials.
Amazon Cognito primarily supports authentication for customer-facing applications. Direct federation configured separately in every account can provide access, but it does not centralize assignments. Central IAM users with cross-account roles introduce separate AWS identities instead of preserving corporate authentication.
- Per-account federation requires access mappings to be managed independently rather than through one central service.
- Amazon Cognito is intended primarily for application users, not centralized employee access to AWS accounts.
- Central IAM users create separate AWS credentials and do not use the existing corporate authentication experience.
Question 3
Topic: Cloud Concepts
An online retailer runs a fixed Amazon EC2 fleet sized for seasonal traffic peaks. Average utilization is 20%, but the application must retain capacity during bursts. The company specifically wants to reduce environmental impact by avoiding idle compute resources.
Which action best aligns with the sustainability pillar of the AWS Well-Architected Framework?
Options:
A. Replicate the fixed fleet across Regions for disaster recovery.
B. Move the fixed fleet to a current-generation EC2 instance family.
C. Purchase Compute Savings Plans covering the fleet’s peak capacity.
D. Right-size the instances and use Auto Scaling to match actual demand.
Best answer: D
Explanation: The sustainability pillar focuses on minimizing the environmental impact of running cloud workloads. Organizations should measure demand, maximize resource utilization, and remove or scale down idle resources. Here, the fleet operates at only 20% average utilization because it remains sized for occasional peaks. Right-sizing reduces unnecessary capacity, while Amazon EC2 Auto Scaling adjusts capacity as demand changes and can restore it during traffic bursts.
Current-generation hardware may be more efficient, but retaining fixed peak capacity leaves the stated idle-resource problem unresolved. Cost commitments reduce pricing, and multi-Region replication improves resilience; neither directly matches compute consumption to demand.
- Newer instance family may improve efficiency, but a fixed peak-sized fleet continues consuming excess resources during normal demand.
- Savings Plans reduce eligible compute costs but do not automatically change resource utilization or capacity.
- Regional replication supports disaster recovery but adds infrastructure rather than reducing idle compute consumption.
Question 4
Topic: Cloud Technology and Services
A company runs a critical application across three Availability Zones in one AWS Region. Business continuity requires service restoration in another geographic area if the entire Region becomes unavailable. Its disaster recovery policy also requires recoverable critical data outside the affected Region.
Which TWO measures directly address these requirements?
Options:
A. Replicate critical data and backups to a second AWS Region.
B. Place recovery resources in another account within the current Region.
C. Add application capacity across more Availability Zones in the current Region.
D. Distribute cached content through CloudFront edge locations worldwide.
E. Maintain a recovery environment in a second AWS Region.
Correct answers: A and E
Explanation: AWS Regions are separate geographic areas, while Availability Zones are isolated locations within a Region. A multi-AZ deployment improves availability during an Availability Zone failure, but it does not satisfy a requirement to recover from an entire regional disruption. Maintaining recovery resources and copies of critical data in another Region provides geographic separation for business continuity and disaster recovery.
CloudFront edge locations improve content delivery, and separate AWS accounts can provide administrative isolation, but neither substitutes for regional recovery capacity and data protection. The key distinction is that Region-level resilience requires resources outside the affected Region.
- Additional Availability Zones remain inside the current Region, so they address zonal rather than regional failures.
- CloudFront edge locations cache content but do not provide a complete application recovery environment or authoritative data copies.
- A separate account improves governance isolation, but resources in the same Region remain exposed to a regional outage.
Question 5
Topic: Cloud Concepts
A company wants to assess organizational readiness across business and technical functions, align stakeholders, and progress from cloud strategy to adoption at scale. Which TWO contributions does the AWS Cloud Adoption Framework (AWS CAF) provide? Select TWO.
Options:
A. Defines the division of security responsibilities between AWS and customers.
B. Provides automated server replication and cutover for each migration wave.
C. Evaluates workload designs against the six AWS Well-Architected pillars.
D. Organizes readiness capabilities into six business and technical perspectives.
E. Guides transformation through the envision, align, launch, and scale phases.
Correct answers: D and E
Explanation: AWS CAF connects organizational readiness to cloud transformation through six perspectives and four iterative phases. The Business, People, Governance, Platform, Security, and Operations perspectives help stakeholders assess capabilities and identify gaps across business and technical functions. The envision, align, launch, and scale phases then guide the organization from identifying transformation opportunities through planning, initial delivery, and broader adoption.
AWS CAF therefore focuses on organizational capabilities and transformation progress, rather than workload architecture assessment, migration automation, or the division of security responsibilities.
- Architecture assessment belongs to the AWS Well-Architected Framework, which evaluates workloads against architectural best practices.
- Server replication is provided by migration services such as AWS Application Migration Service, not AWS CAF.
- Security ownership is defined by the AWS shared responsibility model rather than the cloud adoption framework.
Question 6
Topic: Security and Compliance
A company runs Amazon EC2 instances and stores container images in Amazon ECR. Security leadership wants a managed AWS service that continually assesses these workloads for known software vulnerabilities and identifies unintended EC2 network exposure. Which AWS service best meets this requirement?
Options:
A. Amazon Macie
B. AWS Security Hub
C. Amazon Inspector
D. Amazon GuardDuty
Best answer: C
Explanation: Amazon Inspector is a vulnerability management service that continually assesses supported AWS workloads. It scans supported Amazon EC2 instances and Amazon ECR container images for known software vulnerabilities and can report network exposure affecting EC2 resources. This directly matches the company’s need for vulnerability and exposure assessment. The customer remains responsible for prioritizing and remediating the findings under the shared responsibility model. AWS Security Hub can centralize findings from Inspector and other services, but aggregation is not the same as performing the vulnerability assessment.
- Amazon GuardDuty analyzes AWS activity and logs for potential threats rather than scanning workloads for software vulnerabilities.
- AWS Security Hub centralizes security findings and evaluates security controls but does not perform Inspector’s workload scans.
- Amazon Macie discovers and protects sensitive data in Amazon S3 rather than assessing EC2 instances or container images.
Question 7
Topic: Cloud Technology and Services
An ecommerce company already uses Amazon SNS to fan out shipment notifications to multiple subscribers.
It is adding:
- Payment commands that workers pull from a backlog, with each command retained until processing succeeds and it is deleted.
- Business events from custom applications, AWS services, and SaaS applications that must be matched by event content and routed to different targets.
Which TWO service assignments meet these requirements? (Select TWO.)
Options:
A. Use Amazon SNS for the payment-command backlog.
B. Use Amazon SNS for the business-event routing.
C. Use Amazon SQS for the business-event routing.
D. Use Amazon EventBridge for the business-event routing.
E. Use Amazon SQS for the payment-command backlog.
Correct answers: D and E
Explanation: Amazon SQS provides durable message queues for decoupled processing. Consumers retrieve messages, and successfully processed messages are deleted from the queue. This matches the payment-command backlog.
Amazon EventBridge receives events from custom applications, AWS services, and supported SaaS sources. Event rules inspect event content and route matching events to designated targets. Amazon SNS instead provides publish-subscribe messaging that pushes notifications to multiple subscribers, as demonstrated by the existing shipment-notification flow.
The key distinction is queue-based workload processing versus content-based event routing and subscriber fan-out.
- Using Amazon SNS for payment commands confuses push-based subscriber notification with a worker-consumed, retained backlog.
- Using Amazon SQS for business events provides message retention but not event-bus rules for content-based routing.
- Using Amazon SNS for business events emphasizes subscriber fan-out rather than routing integrated events through event-pattern rules.
Question 8
Topic: Cloud Concepts
A ticketing company experiences unpredictable traffic spikes when new events are announced. It requires compute capacity to increase automatically during each spike and decrease when demand subsides, minimizing idle resources.
Which cloud capability best meets this requirement?
Options:
A. Agility, provisioning resources quickly for new business initiatives
B. Elasticity, dynamically matching capacity to current demand
C. Scalability, expanding capacity to support sustained business growth
D. High availability, distributing workloads across isolated locations
Best answer: B
Explanation: Elasticity is the ability to acquire resources when demand rises and release them when demand falls. It fits this case because the traffic spikes are unpredictable and temporary, capacity changes must be automatic, and unused resources should be removed afterward. Scalability also concerns handling increased demand, but it commonly describes the ability to expand capacity for workload growth and does not by itself require automatic contraction when demand declines.
The decisive requirement is dynamic adjustment in both directions, not merely supporting a larger workload.
- Scalability supports increasing workload capacity but does not necessarily include automatic reduction after temporary demand ends.
- High availability improves resilience to component or location failures rather than matching capacity to traffic fluctuations.
- Agility enables rapid resource provisioning and experimentation but does not specifically describe demand-driven capacity adjustment.
Question 9
Topic: Cloud Technology and Services
A company is moving an on-premises MySQL database to Amazon RDS for MySQL. The application must continue writing to the source database while changes are replicated to the target until a planned cutover. The schemas are compatible.
Which AWS capability best meets this requirement?
Options:
A. Use AWS SCT for schema conversion and ongoing data replication.
B. Use AWS DMS for full load and ongoing change replication.
C. Use AWS DataSync for scheduled copies of the database files.
D. Use AWS Application Migration Service to replicate the database server.
Best answer: B
Explanation: AWS Database Migration Service (AWS DMS) moves database data between supported sources and targets. It can perform an initial full load and then use change data capture to replicate ongoing source changes. This approach allows the application to keep using the source database while the target remains current for a later cutover. Because both databases use MySQL and their schemas are compatible, schema conversion is not the deciding need.
AWS DMS operates at the database-data level, unlike services focused on file transfer, schema conversion, or whole-server migration.
- Schema conversion addresses incompatible database schemas but does not provide the required ongoing data replication.
- Scheduled file copies transfer files rather than continuously capturing database changes for migration.
- Server replication migrates server workloads rather than moving data into a managed Amazon RDS database.
Question 10
Topic: Cloud Concepts
A development team repeatedly waits for test environments before trying new product ideas.
| Provisioning stage | Before AWS | After AWS |
|---|---|---|
| Request to ready environment | 10 business days | 20 minutes |
| Testing process and staffing | Unchanged | Unchanged |
Which AWS Cloud benefit best explains the team’s ability to experiment sooner?
Options:
A. Greater agility through rapid, on-demand resource provisioning
B. Greater elasticity through automatic capacity adjustment during tests
C. Higher availability through deployment across multiple Availability Zones
D. Lower costs through economies of scale in infrastructure pricing
Best answer: A
Explanation: Cloud agility is the ability to provision resources quickly, experiment, and respond to business needs faster. Reducing environment provisioning from 10 business days to 20 minutes lets the team start tests and evaluate ideas sooner. The cloud does not eliminate the testing process or the need for skilled staff; it removes much of the infrastructure waiting time.
Elasticity concerns adjusting capacity as demand changes, while availability concerns keeping workloads accessible despite failures. Economies of scale may reduce costs, but cost savings do not directly explain the shorter experimentation timeline.
- Elasticity addresses capacity changes during usage, not the initial reduction in environment provisioning time.
- Higher availability addresses workload resilience and uptime, neither of which is shown in the timeline.
- Economies of scale can affect pricing, but the exhibit provides no cost comparison.
Question 11
Topic: Security and Compliance
A company runs an application using AWS Lambda and stores customer records in Amazon DynamoDB. AWS manages the underlying servers. Which security work remains the company’s responsibility?
Options:
A. Patch host operating systems, protect application data, and configure IAM permissions
B. Review function code, protect application data, and configure IAM permissions
C. Review function code, replace failed hosts, and configure IAM permissions
D. Review function code, protect application data, and secure data center access
Best answer: B
Explanation: Under the AWS shared responsibility model, serverless services shift management of physical infrastructure, host operating systems, and failed servers to AWS. The customer still controls what the application does and who can access its resources. This includes reviewing Lambda function code, protecting data stored in DynamoDB, and configuring least-privilege IAM permissions.
Serverless reduces infrastructure administration, but it does not remove the customer’s security responsibilities for code, data, identities, or service configuration.
- Patching the host operating system is handled by AWS for Lambda’s underlying infrastructure.
- Replacing failed physical hosts is an AWS infrastructure responsibility.
- Physical security and data center access are controlled by AWS.
Question 12
Topic: Cloud Technology and Services
A retailer wants to consolidate years of structured sales data in AWS and run complex SQL queries for trend analysis. Which TWO statements explain why Amazon Redshift fits these requirements?
Options:
A. Creates interactive business dashboards for end-user visualization.
B. Provides an OLTP relational database for frequent application transactions.
C. Supports SQL analytical queries across large structured datasets.
D. Stores source objects for durable archival and file retrieval.
E. Provides a managed data warehouse for consolidated historical data.
Correct answers: C and E
Explanation: Amazon Redshift is an AWS managed data warehousing service designed for online analytical processing (OLAP). It can consolidate large volumes of structured historical data and support SQL queries that analyze trends, aggregate records, and produce reporting datasets. AWS manages much of the underlying data warehouse infrastructure, allowing customers to focus on their data and analysis.
An OLTP database instead supports frequent application transactions. Object storage provides durable file storage, while a business intelligence service such as Amazon QuickSight creates dashboards and visualizations that can use Redshift as a data source.
- Transaction processing describes an OLTP database workload rather than Redshift’s primary analytical warehousing purpose.
- Object archival describes storage such as Amazon S3 and its archive classes, not a data warehouse.
- Dashboard creation is a business intelligence capability associated with services such as Amazon QuickSight.
Question 13
Topic: Cloud Technology and Services
A media company wants to identify objects and scenes in uploaded images and detect potentially unsafe visual content in uploaded videos. Which TWO AWS service capabilities directly meet these requirements? (Select TWO.)
Options:
A. Use Amazon Rekognition to identify unsafe visual content in videos.
B. Use Amazon Textract to extract text and fields from images.
C. Use Amazon Transcribe to convert video speech into written text.
D. Use Amazon Comprehend to determine sentiment within video captions.
E. Use Amazon Rekognition to label objects and scenes in images.
Correct answers: A and E
Explanation: Amazon Rekognition is an AWS computer vision service for analyzing images and videos. It can detect and label objects, people, activities, and scenes in images. Its video analysis capabilities include detecting content moderation labels that indicate potentially unsafe or inappropriate visual material.
Amazon Textract extracts printed or handwritten text and structured data from documents. Amazon Transcribe converts speech to text, while Amazon Comprehend analyzes natural language. Those services can process information associated with media, but they do not perform the required visual analysis.
- Document extraction addresses text and form fields rather than recognizing general objects and scenes.
- Speech transcription processes the video’s audio track rather than its visual content.
- Sentiment analysis evaluates language in captions rather than detecting unsafe imagery.
Question 14
Topic: Cloud Concepts
A company wants to move existing on-premises physical and virtual servers to AWS quickly. It plans to replicate complete server workloads and make minimal application changes rather than redesign them. Which TWO choices identify the AWS service and migration strategy aligned with this goal? (Select TWO.)
Options:
A. Use refactoring to modernize the workloads during the migration.
B. Use AWS Application Migration Service to move the server workloads.
C. Use AWS Elastic Disaster Recovery to perform the planned migration.
D. Use AWS Database Migration Service to move the server workloads.
E. Use rehosting to preserve the workloads with minimal changes.
Correct answers: B and E
Explanation: AWS Application Migration Service supports rehosting existing servers on AWS. It continuously replicates source servers and enables them to be launched as Amazon EC2 instances for testing and cutover. This aligns with a rehosting, or lift-and-shift, strategy because the company wants to preserve its workloads while making minimal application changes.
AWS Database Migration Service focuses on databases rather than complete servers. AWS Elastic Disaster Recovery uses server replication for disaster recovery and recovery operations, not as the migration service for a planned move. Refactoring would require redesigning or significantly modifying the applications. The key distinction is migration with minimal change rather than database-only movement, disaster recovery, or modernization.
- Database migration moves database workloads, not complete servers containing operating systems and applications.
- Disaster recovery prepares replicated workloads for recovery after disruption rather than serving as the planned migration service.
- Refactoring redesigns applications for cloud-native capabilities, conflicting with the requirement for minimal changes.
Question 15
Topic: Billing, Pricing, and Support
A company has granted its cloud governance team access to AWS Trusted Advisor. The team wants to use its best-practice recommendations to review the current AWS environment.
Which TWO results can Trusted Advisor provide?
Options:
A. Software vulnerability findings for packages on supported workloads
B. Cost recommendations for idle or underutilized AWS resources
C. Monthly cost estimates for a proposed future architecture
D. Detailed usage and cost records for chargeback analysis
E. Security recommendations for potentially unrestricted network access
Correct answers: B and E
Explanation: AWS Trusted Advisor evaluates the current AWS environment against best practices and provides recommendations across categories including cost optimization, security, performance, fault tolerance, and service quotas. Its checks can identify potentially underutilized resources and risky configurations such as unrestricted network access.
Trusted Advisor is advisory; it does not replace specialized cost-planning, billing-record, or vulnerability-management services. AWS Pricing Calculator estimates proposed workloads, Cost and Usage Reports provide detailed billing data, and Amazon Inspector detects software vulnerabilities and unintended network exposure in supported workloads.
- Future cost estimates come from AWS Pricing Calculator rather than a review of current resource configurations.
- Chargeback records are provided through billing tools such as AWS Cost and Usage Reports.
- Package vulnerabilities are findings from Amazon Inspector rather than Trusted Advisor best-practice checks.
Question 16
Topic: Cloud Technology and Services
A company has an application that processes requests through several AWS components. The operations team needs to follow an individual request across those components and view the time spent at each step. Which AWS service best meets this requirement?
Options:
A. AWS CloudTrail
B. AWS X-Ray
C. Amazon CloudWatch metrics and alarms
D. Amazon Inspector
Best answer: B
Explanation: Distributed tracing follows an individual request as it moves through an application. AWS X-Ray collects trace data from supported application components and presents request paths, timing, errors, and service relationships. This helps teams identify which component contributes latency or failures to a specific request.
Amazon CloudWatch is primarily used for metrics, logs, alarms, and broader observability. Although it can integrate with trace data, the requirement to trace individual requests across components points specifically to AWS X-Ray.
- CloudWatch metrics and alarms measure aggregate observations and thresholds. CloudWatch also has integrated tracing experiences, but metrics and alarms alone do not trace individual requests.
- CloudTrail auditing records AWS API activity for governance and investigation, not application request paths and component timing.
- Inspector assessment evaluates supported workloads for vulnerabilities and exposure, not request flow across application components.
Question 17
Topic: Security and Compliance
A company uses a corporate identity provider for employee sign-in. Employees need AWS Management Console access across several AWS accounts.
Requirements:
- Enforce MFA through corporate sign-in.
- Apply job-based AWS permissions.
- End AWS access sessions after one hour.
- Avoid long-lived IAM user credentials.
Which action best meets these requirements?
Options:
A. Use Amazon Cognito groups for corporate users and issue one-hour authentication tokens.
B. Connect the corporate IdP to IAM Identity Center and assign permission sets with one-hour sessions.
C. Store IAM user credentials in Secrets Manager and rotate them after each shift.
D. Create IAM users in groups, require MFA, and rotate their passwords frequently.
Best answer: B
Explanation: AWS IAM Identity Center supports workforce federation with an existing corporate identity provider. Employees authenticate through the corporate system, where MFA can be enforced, and receive temporary AWS sessions for assigned accounts. Permission sets determine what each employee may do and can specify a one-hour session duration. Expiration reduces the exposure period if session credentials are compromised, but it does not replace least-privilege permissions or the need to protect active sessions.
IAM users retain long-lived credentials even when those credentials are rotated. Temporary sessions limit credential lifetime rather than merely changing stored credentials periodically.
- IAM users retain long-lived passwords, so frequent rotation does not meet the credential requirement.
- Amazon Cognito primarily provides identity services for application users, not centralized workforce access to AWS accounts.
- Secrets Manager rotation protects and replaces stored credentials but does not convert IAM user credentials into federated workforce sessions.
Question 18
Topic: Cloud Technology and Services
A company needs to:
- Route incoming customer calls to remote contact center agents.
- Use a conversational self-service bot to handle routine spoken requests before transferring customers.
Which TWO AWS services directly provide these capabilities?
Options:
A. Amazon Lex
B. Amazon Polly
C. Amazon WorkSpaces Personal
D. Amazon Transcribe
E. Amazon Connect
Correct answers: A and E
Explanation: Amazon Connect is a cloud-based contact center service that supports customer communications, call routing, and agent interactions. Amazon Lex builds conversational interfaces that understand voice or text input, making it suitable for the routine self-service bot described here. Lex can support automated conversations before a customer is transferred to an agent in Connect.
Speech synthesis and transcription are narrower AI capabilities; they do not independently provide conversational intent handling. A managed virtual desktop can support remote workers but does not supply contact center functionality.
- Speech synthesis generates spoken audio but does not recognize customer requests or manage conversational intent.
- Speech transcription converts audio into text but does not provide conversational bot logic or contact routing.
- Virtual desktops provide remote desktop environments rather than customer call routing or automated conversations.
Question 19
Topic: Cloud Concepts
A company runs commercially licensed database software on Amazon EC2 instances and on-premises servers. It wants to centrally track license consumption across environments and apply limits based on its existing license agreements to reduce compliance risk.
Which AWS service best meets this need?
Options:
A. AWS Systems Manager Inventory for installed software collection
B. AWS Cost Explorer for spending analysis and usage trends
C. AWS Config for configuration tracking and compliance evaluation
D. AWS License Manager for license tracking and rule enforcement
Best answer: D
Explanation: AWS License Manager helps organizations manage licenses obtained from software vendors. It can track license consumption across AWS and on-premises environments and apply licensing rules, such as limits on permitted usage. This helps control software licensing costs and reduce the risk of exceeding agreement terms.
AWS Systems Manager Inventory can identify installed software, but its primary purpose is inventory collection rather than managing license entitlements. AWS Config evaluates resource configurations, while Cost Explorer analyzes AWS costs and usage trends. The decisive requirement is managing consumption against software license agreements.
- AWS Config evaluates resource configurations but does not manage software license entitlements or consumption limits.
- Systems Manager Inventory collects software metadata but does not provide the required license-rule management.
- Cost Explorer analyzes AWS spending but does not track compliance with vendor license agreements.
Question 20
Topic: Billing, Pricing, and Support
A company with AWS Basic Support has two unrelated concerns:
- A security analyst discovers a suspected phishing page on an AWS resource that the company does not own.
- A billing contact finds an unrecognized charge on the company’s AWS invoice.
Which TWO actions use the appropriate AWS channels?
Options:
A. Open an account and billing case with AWS Support for the charge.
B. Submit the invoice issue to AWS Cost Explorer for billing resolution.
C. Submit the phishing evidence as an account case with AWS Support.
D. Submit the phishing evidence to AWS Security Hub for AWS investigation.
E. Submit the phishing evidence through the AWS Trust and Safety abuse channel.
Correct answers: A and E
Explanation: AWS separates reports of resource abuse from assistance with a customer’s own account. Suspected phishing hosted on an AWS resource should be reported through the AWS Trust and Safety abuse channel. The unrecognized invoice charge concerns the company’s account, so it belongs in an account and billing case with AWS Support; this assistance is included with Basic Support.
Cost Explorer analyzes historical costs and usage but does not resolve billing disputes. Security Hub manages security findings for a customer’s AWS environment rather than serving as an external abuse-reporting channel. The key distinction is suspected misuse of AWS resources versus assistance with the customer’s own bill.
- An account support case is not the designated reporting route for suspected abuse by an externally owned AWS resource.
- Cost Explorer provides cost analysis rather than AWS review or resolution of an invoice issue.
- Security Hub aggregates customer security findings; it does not send third-party abuse reports to AWS Trust and Safety.
Question 21
Topic: Cloud Technology and Services
A company is moving containerized applications to AWS. Its deployment manifests and operations tools depend on standard Kubernetes APIs. The company wants AWS to manage the availability and maintenance of the Kubernetes control plane.
Which approach best meets these requirements?
Options:
A. Use Amazon EKS with an AWS-managed Kubernetes control plane.
B. Run Kubernetes on Amazon EC2 with a customer-managed control plane.
C. Use Amazon ECS with an AWS-native container orchestration control plane.
D. Use AWS App Runner with its managed application deployment model.
Best answer: A
Explanation: Amazon EKS is the AWS managed service for Kubernetes orchestration. It supports Kubernetes APIs, manifests, and compatible operational tools while AWS manages the control plane. Amazon ECS also orchestrates containers, but it uses an AWS-native model rather than the Kubernetes API and resource model. Running Kubernetes directly on EC2 preserves Kubernetes compatibility but makes the customer responsible for operating the control plane. App Runner simplifies deployment of containerized web applications but does not provide a Kubernetes orchestration environment.
The decisive requirement is retaining the Kubernetes operating model while transferring control-plane management to AWS.
- AWS-native orchestration does not satisfy the requirement for standard Kubernetes APIs and manifests.
- Self-managed Kubernetes retains compatibility but leaves control-plane availability and maintenance with the customer.
- Managed application deployment abstracts container operations but does not expose a Kubernetes control plane.
Question 22
Topic: Security and Compliance
An administrator is documenting credentials for an IAM user. The user signs in to the AWS Management Console and runs an approved command-line tool that sends AWS API requests using the user’s long-term credentials. Company policy requires credentials to be protected from unauthorized disclosure.
Which TWO statements correctly describe the credentials?
Options:
A. Use the password for console sign-in and keep it in protected storage.
B. Use the access key pair for programmatic requests and keep it in protected storage.
C. Use the password for programmatic requests and keep it in protected storage.
D. Use the access key ID alone for programmatic requests and keep the secret key offline.
E. Use the access key pair for console sign-in and keep it in protected storage.
Correct answers: A and B
Explanation: An IAM user password supports interactive authentication through the AWS Management Console. Programmatic access through command-line tools and APIs uses an access key ID together with its secret access key to sign requests. Passwords and secret access keys must be protected from unauthorized disclosure and should not be shared or embedded in source code.
An access key ID identifies the credential but cannot authorize signed API requests by itself. Although temporary role credentials are generally preferable for workloads, the stated long-term credential mechanism requires the complete access key pair. The key distinction is the access method, while secure storage applies to both credential types.
- Assigning the password to programmatic access confuses interactive console authentication with signed API authentication.
- Assigning the access key pair to console sign-in reverses the purposes of the two credential types.
- Using the access key ID alone fails because the corresponding secret access key is required to sign API requests.
Question 23
Topic: Billing, Pricing, and Support
A company wants virtual firewall software from an independent vendor for workloads running on AWS. Procurement must review the product’s pricing and terms, subscribe through AWS, and receive eligible charges on the company’s AWS bill.
Which AWS resource best meets this need?
Options:
A. Use AWS Partner Network to find and subscribe to the virtual firewall.
B. Use AWS Service Catalog to find and subscribe to the virtual firewall.
C. Use AWS Marketplace to find and subscribe to the virtual firewall.
D. Use AWS Security Hub to find and subscribe to the virtual firewall.
Best answer: C
Explanation: AWS Marketplace is a digital catalog for third-party software, data, and professional services that run on or support AWS. Customers can review listings, pricing, and commercial terms, then purchase or subscribe with eligible charges included in AWS billing. Its listings include security products such as virtual firewalls.
AWS Service Catalog instead governs cloud products approved for organizational use. The deciding distinction is external product procurement through AWS Marketplace versus internal distribution and governance.
- Service Catalog distributes organization-approved cloud products but is not the public catalog for purchasing third-party listings.
- Partner Network helps customers identify AWS Partners and expertise but is not the transactional marketplace for AWS-billed software.
- Security Hub aggregates and prioritizes security findings but does not provide software procurement and subscription capabilities.
Question 24
Topic: Cloud Technology and Services
A company runs a web application on an Amazon EC2 fleet. Traffic is unpredictable, and the company wants the fleet to add instances when demand rises and remove them when demand falls, without manual intervention.
Which AWS capability best meets this requirement?
Options:
A. Use Elastic Load Balancing to distribute requests across healthy fleet instances.
B. Use EC2 Capacity Reservations to reserve fleet capacity in one Availability Zone.
C. Use Amazon EC2 Auto Scaling to adjust fleet size from demand metrics.
D. Use AWS Compute Optimizer to recommend suitable fleet instance types.
Best answer: C
Explanation: Amazon EC2 Auto Scaling supports elasticity by automatically increasing or decreasing the number of EC2 instances in a fleet. Scaling policies use metrics or defined conditions to adjust desired capacity within configured minimum and maximum limits. Adding instances helps the application respond to higher demand, while removing unnecessary instances after demand falls can reduce costs.
Elastic Load Balancing complements Auto Scaling by distributing traffic, but it does not change fleet size. The deciding requirement is automatic capacity adjustment, not traffic distribution, rightsizing advice, or capacity assurance.
- Traffic distribution spreads requests across available instances but does not add or remove them.
- Rightsizing recommendations help evaluate resource efficiency but do not dynamically change fleet capacity.
- Capacity reservation assures EC2 capacity availability in an Availability Zone but does not scale a running fleet.
Question 25
Topic: Security and Compliance
A company uses a standalone AWS account. Root authority is needed only for rare account-recovery tasks. Routine administration must use delegated identities, and only designated security custodians may access the emergency root credentials.
Which approach best meets these requirements?
Options:
A. Use delegated admin identities; enable root MFA, retain a rotated root access key, and secure root credentials with designated custodians.
B. Use delegated admin identities; enable root MFA, remove root access keys, and secure root credentials with designated custodians.
C. Use delegated admin identities; rotate the root password monthly, remove root access keys, and secure root credentials with designated custodians.
D. Use delegated admin identities; enable root MFA, remove root access keys, and share root credentials with all administrators.
Best answer: B
Explanation: The standalone account’s root user has unrestricted authority and should be protected as an emergency identity. Enable MFA, use a strong securely stored password, remove any root access keys, and restrict credential access to designated custodians. Administrators should perform routine work through their own delegated identities rather than root. This limits exposure of the most powerful credentials while preserving access for tasks that specifically require root authority.
Password rotation does not replace MFA, and retaining a root access key creates an unnecessary long-term credential.
- Retaining a root access key preserves an unnecessary highly privileged credential, even if it is rotated and stored securely.
- Monthly password rotation does not provide the additional authentication factor supplied by MFA.
- Sharing root credentials with every administrator violates the custodian restriction and unnecessarily broadens access.
Questions 26-50
Question 26
Topic: Cloud Technology and Services
A company has two temporary workforce access needs:
- Vendors need browser-only access to private web portals, with no VPN client or hosted desktop.
- Seasonal staff need two Windows applications streamed remotely, with no complete desktop.
Which TWO AWS service choices meet these requirements?
Options:
A. Use Amazon WorkSpaces Applications for seasonal application access.
B. Use Amazon WorkSpaces Secure Browser for vendor portal access.
C. Use Amazon WorkSpaces Personal for seasonal application access.
D. Use Amazon WorkSpaces Secure Browser for seasonal application access.
E. Use AWS Client VPN for vendor portal access.
Correct answers: A and B
Explanation: The Amazon WorkSpaces services differ by the scope of the user environment they deliver. WorkSpaces Secure Browser provides controlled, browser-based access to private websites and software-as-a-service applications without delivering a desktop. WorkSpaces Applications streams selected desktop applications, making it appropriate when users need specific Windows applications rather than an entire desktop.
Amazon WorkSpaces Personal provides a complete hosted virtual desktop, which exceeds the seasonal staff requirement. AWS Client VPN provides network connectivity rather than a managed browser session. The key distinction is whether users need websites, individual applications, or a complete desktop.
- Client VPN provides remote network connectivity and does not deliver the required managed browser-only environment.
- Complete WorkSpaces desktop delivers more than the seasonal staff require because they need only two streamed applications.
- Secure Browser for applications presents web content rather than streaming arbitrary Windows desktop applications.
Question 27
Topic: Security and Compliance
An application uploads confidential files from a company client to Amazon S3. The upload crosses a public network, and S3 then persists each object in a bucket.
Scroll sideways if needed. Open full-size diagram in a new tab
Text description
A company client uploads data over a public network to Amazon S3, which persists the object in a bucket.
Security requires encryption both during transfer and while stored. Which TWO controls directly meet these requirements? (Select TWO.)
Options:
A. Use Amazon Macie to classify objects in the destination bucket.
B. Enable S3 Block Public Access on the destination bucket.
C. Require HTTPS with TLS for each upload to Amazon S3.
D. Use S3 server-side encryption with AWS KMS keys (SSE-KMS).
E. Route the uploads through an AWS Direct Connect connection.
Correct answers: C and D
Explanation: Encryption in transit protects data while it moves between systems. HTTPS uses TLS to encrypt the upload between the client and Amazon S3. Encryption at rest protects the persisted object on storage media; S3 server-side encryption using AWS KMS keys provides this protection after the upload reaches S3.
Dedicated connectivity, access controls, and data discovery can strengthen security, but they address different risks. In particular, AWS Direct Connect provides a dedicated network connection and does not inherently encrypt data in transit.
- Dedicated connection does not inherently encrypt traffic, so Direct Connect does not replace HTTPS with TLS.
- Public access blocking limits unintended bucket exposure but does not provide encryption.
- Sensitive data discovery helps classify and monitor objects but does not encrypt them.
Question 28
Topic: Cloud Technology and Services
A company has two global workloads:
- A website serves cacheable images stored in Amazon S3 and must reduce latency and repeated origin requests.
- A multiplayer game uses TCP/UDP endpoints in two AWS Regions and needs static entry IP addresses plus routing to healthy endpoints over the AWS global network.
Which TWO actions match these requirements? (Select TWO.)
Options:
A. Use Global Accelerator for the game to provide static IPs and route TCP/UDP to healthy regional endpoints.
B. Use CloudFront for both workloads because edge caching also accelerates arbitrary TCP/UDP sessions.
C. Use Global Accelerator for the site to cache S3 objects near viewers and reduce origin requests.
D. Use CloudFront for the game to provide static IPs and route TCP/UDP to healthy regional endpoints.
E. Use CloudFront for the site to cache S3 objects near viewers and reduce origin requests.
Correct answers: A and E
Explanation: Amazon CloudFront is a content delivery network designed to cache HTTP(S) content, such as images from an Amazon S3 origin, at edge locations near viewers. This reduces latency and the number of requests reaching the origin.
AWS Global Accelerator does not cache content. It provides static anycast IP addresses and accepts TCP or UDP traffic at the AWS edge. The traffic then travels across the AWS global network to an appropriate healthy endpoint, such as a regional application endpoint.
The deciding distinction is content caching with CloudFront versus network-path acceleration and endpoint routing with Global Accelerator.
- Assigning caching to Global Accelerator confuses network traffic acceleration with edge content storage.
- Assigning TCP/UDP endpoint routing to CloudFront overlooks its focus on HTTP(S) content delivery.
- Extending CloudFront caching to arbitrary game sessions incorrectly treats network packets as cacheable web objects.
Question 29
Topic: Billing, Pricing, and Support
A retailer is moving custom order-management applications to AWS. It needs an external partner to assess dependencies, perform the migration, and integrate the workloads with existing identity and ERP systems. The retailer will operate the environment after handoff and is not seeking a packaged software product.
Which AWS Partner Network role best fits this need?
Options:
A. Engage an MSP to provide continuous operation of the migrated environment.
B. Engage a system integrator to deliver the tailored migration and integrations.
C. Engage an ISV to provide a licensed migration and integration product.
D. Engage an AWS Training Partner to prepare staff for post-migration operations.
Best answer: B
Explanation: System integrators provide professional services that help customers assess, plan, migrate, and connect systems. This retailer needs a tailored project involving custom applications and existing enterprise systems, followed by a handoff to its internal operations team. Independent software vendors primarily develop and license software products that run on or integrate with AWS. Managed service providers focus on ongoing operational management, while Training Partners develop customer skills. The required deliverable is migration and integration expertise rather than software licensing, continuing operations, or training.
- ISV software product does not match the retailer’s need for a tailored professional-services engagement rather than a software license.
- Continuous managed operations conflicts with the retailer’s plan to operate the environment after handoff.
- Staff training may support adoption but does not perform the required migration and systems integration.
Question 30
Topic: Security and Compliance
A company discovers that an Amazon S3 bucket policy was changed two days ago. An auditor must identify the IAM principal that made the change, the API operation used, and the time it occurred.
Which AWS service records should the company review?
Options:
A. AWS CloudTrail event history for the policy change
B. Amazon CloudWatch metrics for the bucket
C. AWS Config resource history for the bucket
D. Amazon Inspector findings for the account
Best answer: A
Explanation: AWS CloudTrail records account and API activity. For an S3 bucket policy change, its management event can show the IAM identity that initiated the request, the API operation, the affected resource, and the event time. CloudTrail event history includes recent management events, so a change from two days ago falls within its standard 90-day history.
AWS Config can show how a supported resource’s configuration changed, but CloudTrail supplies the API activity evidence needed to attribute the action to a principal. The key distinction is audit activity versus resource state, performance, or vulnerability evidence.
- Configuration history shows resource configuration changes but is not the primary record for identifying the API caller.
- Performance metrics describe resource activity and health, not the identity that performed a management action.
- Vulnerability findings report supported workload exposures and software vulnerabilities, not S3 policy-change activity.
Question 31
Topic: Security and Compliance
A company stores a sensitive dataset in Amazon S3. Another organization requests access. Company policy assigns external-disclosure approval to the designated data owner, while cloud administrators manage S3 permissions.
Under the AWS shared responsibility model, which TWO statements correctly describe how the request should be handled? (Select TWO.)
Options:
A. The company’s cloud administrator implements access matching the authorization.
B. AWS authorizes disclosure because it operates the underlying S3 infrastructure.
C. The designated data owner authorizes disclosure under company policy.
D. The requesting organization’s administrator authorizes release from the S3 bucket.
E. AWS Artifact authorizes disclosure when S3 has relevant compliance coverage.
Correct answers: A and C
Explanation: Under the shared responsibility model, AWS secures the infrastructure that operates Amazon S3, but the customer controls its data, access permissions, and disclosure decisions. The company’s policy therefore makes the designated data owner responsible for deciding whether sharing is permitted. After approval, the company’s cloud administrator implements appropriate S3 access.
AWS compliance coverage and AWS Artifact reports can provide evidence for a customer’s compliance assessment, but they do not authorize a particular disclosure. Similarly, the receiving organization can control how it accepts and uses data, but it cannot authorize the source company to release that data. Policy determines authorization; access controls enforce the decision.
- AWS operating S3 infrastructure does not give AWS authority over the customer’s disclosure decisions.
- AWS Artifact provides compliance documentation, not permission to share a specific dataset.
- The recipient can govern its own access and use, but cannot authorize the source company’s release.
Question 32
Topic: Cloud Concepts
A company is classifying applications before an AWS migration. Which TWO recommendations are appropriate? Select TWO.
| Application | Portfolio evidence |
|---|---|
| Payroll | Needed for 18 months; stable supported host; SaaS replacement underway |
| Reporting | Replacement accepted; no active users; required records archived |
| Customer portal | Actively used; seasonal demand; weekly releases |
| ERP | Actively used; hardware support ends in 6 months; AWS deployment supported |
| Test lab | Required for quarterly release certification; capacity is limited |
Options:
A. Retain ERP on premises because it is a packaged application.
B. Retire the test lab because it is used only quarterly.
C. Retain payroll on premises until the SaaS replacement is ready.
D. Retire the customer portal because its demand varies by season.
E. Retire reporting because its replacement and archival work are complete.
Correct answers: C and E
Explanation: Retain means leaving an application in its current environment, usually because migration provides little immediate value or the application will soon be replaced. Payroll fits this circumstance: it remains necessary, its host is supported, and a replacement is already underway. Retire means decommissioning an application that no longer delivers a needed capability. Reporting can be retired because its replacement is accepted, it has no active users, and required records are archived.
Seasonal demand, packaged software, and infrequent use do not independently justify retirement or retention. The continuing business need and migration value determine the appropriate disposition.
- Seasonal portal demand can favor cloud elasticity; it does not indicate that the actively used application is obsolete.
- Packaged software can be migrated when supported, while the approaching hardware-support deadline weakens the case for retention.
- Quarterly use does not justify retirement because the test lab remains required for release certification.
Question 33
Topic: Billing, Pricing, and Support
A company needs an AWS-maintained source for current, service-specific feature descriptions, prerequisites, and configuration reference information. Which resource should the company use as its primary source?
Options:
A. Consult AWS service documentation and user guides
B. Search AWS re:Post discussions and answers
C. Read AWS Architecture Blog solution posts
D. Review AWS whitepapers and technical guides
Best answer: A
Explanation: AWS service documentation and user guides are the primary references for current details about individual AWS services. They describe capabilities, prerequisites, supported configurations, and relevant operational concepts. AWS whitepapers generally explain broader cloud practices, security principles, and architectural approaches. AWS blogs provide examples, announcements, and solution patterns, but posts reflect their publication date. AWS re:Post is useful for questions and troubleshooting discussions, yet it is not the primary service reference.
Match the resource to the need: use documentation for service-specific reference details, whitepapers for broader guidance, and blogs for examples or updates.
- Whitepapers emphasize broader strategies and best practices rather than detailed service configuration references.
- Architecture Blog posts present patterns and examples that may reflect a specific publication date.
- AWS re:Post supports questions and troubleshooting but is not the authoritative primary service reference.
Question 34
Topic: Cloud Concepts
A team runs a customer-facing service on AWS and releases small changes weekly. It wants to improve continually by learning from observable operational outcomes. The team understands that monitoring reveals service behavior but does not guarantee outage prevention.
Which TWO statements correctly describe how the team should use operational evidence? (Select TWO.)
Options:
A. Operational event findings can guide updates to procedures and future changes.
B. Successful deployment status confirms that customer-facing outcomes improved.
C. AWS Health events can replace workload observations when evaluating changes.
D. Service metrics can reveal whether a change improved observed behavior.
E. CloudWatch alarms can ensure monitored service interruptions do not occur.
Correct answers: A and D
Explanation: Continual improvement uses observability as a feedback mechanism. Metrics such as latency, errors, and availability show how a service behaves after a change. Reviews of operational events then help the team learn from those results and refine procedures, priorities, and future changes.
Monitoring and alarms improve awareness and response, but they do not prevent every outage. Likewise, a successful deployment confirms that a change was delivered, not that users experienced a better outcome. Improvement requires evaluating measured service behavior and acting on what the team learns.
- Alarm coverage detects defined conditions but cannot ensure that service interruptions will not occur.
- AWS Health events report AWS service and account events, not the complete behavior of the team’s workload.
- Deployment success shows that delivery completed, but it does not establish improved customer-facing performance or reliability.
Question 35
Topic: Cloud Concepts
A company is testing a service with highly uncertain demand. The pilot may end after three months, and purchased servers cannot be returned or reassigned. The company compares a fixed server purchase with pay-as-you-go AWS resources that can be stopped when no longer needed.
Which explanation best describes the economic effect of choosing pay-as-you-go resources?
Options:
A. It reduces rates through a one-year commitment and provides the best flexibility before baseline demand is established.
B. It lowers unit cost at high utilization and therefore provides greater flexibility while demand remains uncertain.
C. It aligns spending with actual consumption and permits shutdown, but total cost still depends on realized demand.
D. It eliminates the financial effect of demand uncertainty and guarantees lower total cost at every usage level.
Best answer: C
Explanation: A fixed purchase commits money and capacity before actual demand is known. If demand is low or the pilot ends, the company still bears the cost of servers it cannot reuse. Pay-as-you-go AWS resources make spending more variable and allow the company to stop incurring resource charges when those resources are no longer needed.
This flexibility reduces the economic risk of unused capacity, but it does not guarantee savings. Actual usage, pricing, and the duration of the workload determine the final cost. Long-term commitments may become appropriate after a predictable usage baseline develops.
- High utilization can improve fixed-capacity economics, but it does not provide flexibility when demand may be low.
- A one-year commitment can reduce rates for predictable usage, but it recreates commitment risk before baseline demand is known.
- Variable spending limits unused-capacity exposure, but it cannot guarantee the lowest cost at every usage level.
Question 36
Topic: Cloud Technology and Services
A retailer uses this business-data flow:
- Amazon RDS records customer orders.
- Amazon S3 stores historical order files queried occasionally with Amazon Athena.
- Amazon Redshift supports analytical queries across consolidated sales data.
Executives now need interactive, browser-based KPI charts and scheduled dashboards without writing SQL. Which AWS service best adds this capability?
Options:
A. Use Amazon Redshift as the historical data warehouse layer.
B. Use Amazon RDS as the order-processing database layer.
C. Use Amazon Athena as the serverless S3 query layer.
D. Use Amazon Quick Sight as the business intelligence presentation layer.
Best answer: D
Explanation: Amazon Quick Sight is a business intelligence service for creating interactive visualizations, reports, and dashboards from AWS and other data sources. It can use the retailer’s analytical data in Amazon Redshift and present KPIs to executives through browser-based dashboards.
Amazon RDS serves the transactional workload that records orders. Amazon Athena performs serverless analytical queries directly against data in Amazon S3, while Amazon Redshift is a data warehouse for analyzing consolidated data. Those services can supply or query business data, but they do not provide the requested dashboard presentation layer.
- Athena supports ad hoc querying of S3 data rather than delivering interactive business dashboards.
- Redshift stores and analyzes consolidated historical data but is not the requested visualization layer.
- RDS supports transactional application data rather than executive KPI visualization.
Question 37
Topic: Cloud Concepts
A company wants to reduce AWS costs without violating its requirement that a production application continue serving customers if one Availability Zone becomes unavailable.
- Production uses active resources in one Availability Zone and a ready standby in another.
- Daily backups can restore service, but restoration may take two hours.
- Unattached development EBS volumes have no future use or retention requirement.
Which action best meets both goals?
Options:
A. Delete the unused volumes and retain the second-AZ production standby.
B. Retain the unused volumes and retain the second-AZ production standby.
C. Delete the unused volumes and replace the second-AZ standby with backups.
D. Retain the unused volumes and replace the second-AZ standby with backups.
Best answer: A
Explanation: Cost optimization removes resources that provide no required business value while preserving resources that support explicit workload requirements. The unattached development EBS volumes have no future or retention need, so deleting them removes waste. The ready production standby in a second Availability Zone supports continued service during a single-AZ disruption. Daily backups protect recoverability, but their two-hour restoration time means they cannot replace failover capacity for this availability requirement. Keeping every resource would preserve resilience but leave verified waste in place. Normal inactivity does not make a standby resource unnecessary when its purpose is resilience.
- Replacing the standby with backups fails because a two-hour restoration cannot provide continued service during an Availability Zone disruption.
- Keeping the unused volumes preserves resilience when the standby remains, but it fails to remove storage with no business value.
- Retaining unused storage while relying on backups preserves waste and also violates the availability requirement.
Question 38
Topic: Security and Compliance
A company currently runs a self-managed customer-records database on Amazon EC2. It plans to migrate the database to Amazon RDS to reduce operational security work while retaining control of data governance.
Which explanation best describes the resulting responsibility change? Select ONE.
Options:
A. AWS manages the host OS and database platform; the customer manages data classification and access.
B. AWS manages physical facilities; the customer manages the host OS, database platform, data classification, and access.
C. AWS manages the host OS; the customer manages database patching, data classification, and access.
D. AWS manages the host, database platform, and data classification; the customer manages user access.
Best answer: A
Explanation: The AWS shared responsibility boundary changes with the service model. For a self-managed database on Amazon EC2, the customer manages the guest operating system and database software. With Amazon RDS, AWS manages the underlying host and routine database-platform operations. The customer still governs its data, including classification, database users, permissions, and applicable service settings. Moving to a managed database reduces infrastructure and platform administration; it does not transfer ownership of customer data or access decisions to AWS.
- Retaining direct database patching responsibility reflects a self-managed database rather than the managed RDS platform.
- Assigning data classification to AWS incorrectly transfers a customer data-governance responsibility.
- Retaining host OS management describes the EC2 responsibility boundary, not the RDS boundary.
Question 39
Topic: Cloud Concepts
A company creates a steering committee led by its CIO, CFO, and chief risk officer. The committee must establish decision rights, prioritize cloud initiatives, track expected benefits, and oversee transformation risks.
Which AWS Cloud Adoption Framework (AWS CAF) perspective should primarily guide this work?
Options:
A. Governance perspective for portfolio oversight and decision rights
B. People perspective for workforce readiness and cultural change
C. Business perspective for strategy alignment and value outcomes
D. Platform perspective for cloud foundations and workload modernization
Best answer: A
Explanation: The AWS CAF governance perspective helps an organization coordinate cloud initiatives while maximizing benefits and managing transformation risks. Its concerns include decision rights, portfolio management, benefits realization, risk management, and cloud financial management. These responsibilities match the steering committee’s oversight mandate and the roles of the CIO, CFO, and chief risk officer.
The business perspective focuses on strategy and business outcomes, while the people perspective addresses culture, leadership, and skills. The platform perspective concerns the technical cloud foundation and workload modernization. Strategic value is relevant here, but formal oversight and decision authority make governance decisive.
- Business perspective defines strategic outcomes but does not primarily establish portfolio oversight and decision rights.
- People perspective addresses organizational readiness, skills, leadership, and cultural change rather than initiative governance.
- Platform perspective develops cloud architecture and technical foundations rather than overseeing benefits and transformation risks.
Question 40
Topic: Cloud Technology and Services
A retail company stores sales data in AWS. Business analysts need a managed service to create interactive business intelligence dashboards, visualize sales trends, and share reports with executives. Which AWS service best meets this need?
Options:
A. Amazon Kinesis Data Streams
B. AWS Glue
C. Amazon QuickSight
D. Amazon SageMaker AI
Best answer: C
Explanation: Amazon QuickSight is AWS’s managed business intelligence service for analyzing data and presenting insights through interactive visualizations and dashboards. It enables analysts to create and share reports with business users, matching the company’s requirement to communicate sales trends to executives. The other services support related analytics workflows, but their primary purposes are machine learning, data integration, or real-time data streaming rather than business intelligence dashboard creation.
The deciding requirement is presenting business data through shareable dashboards and visualizations.
- Machine learning development is the primary role of Amazon SageMaker AI, not business intelligence reporting.
- Data integration is handled by AWS Glue, which discovers, prepares, and transforms data rather than presenting executive dashboards.
- Real-time streaming is handled by Amazon Kinesis Data Streams, which collects and processes streaming records rather than creating BI reports.
Question 41
Topic: Security and Compliance
A company uses Amazon GuardDuty and Amazon Inspector across several AWS accounts. Its security team needs one service that consolidates findings from these services and summarizes compliance with security standards in a central view.
Which AWS service best meets this need?
Options:
A. Use Amazon GuardDuty.
B. Use Amazon Inspector.
C. Use AWS Security Hub.
D. Use Amazon Security Lake.
Best answer: C
Explanation: AWS Security Hub provides a centralized view of security findings from supported AWS services, products, and integrations. It also evaluates resources against security controls and standards, helping teams understand their overall security posture across accounts. GuardDuty and Inspector can supply findings to Security Hub, while Security Hub brings those findings and posture results together.
Security Lake centralizes security data for analysis, but it does not provide the same consolidated findings and security-standards posture view.
- Security Lake centralizes security data for analytics rather than presenting the required security findings and standards posture view.
- GuardDuty detects potential threats but does not consolidate findings and posture information from multiple security services.
- Inspector assesses supported workloads for vulnerabilities and exposure rather than providing the required central security posture view.
Question 42
Topic: Security and Compliance
A company finds that several administrators use the AWS account root user for routine work. Root access keys are active, although no workload requires them. The company needs person-level accountability while retaining secure root access for rare root-only tasks.
Which action best meets these requirements?
Options:
A. Enable root MFA, delete root access keys, secure root credentials, and use one shared least-privilege identity routinely.
B. Enable root MFA, retain encrypted root access keys, secure root credentials, and use named least-privilege identities routinely.
C. Enable root MFA, delete root access keys, secure root credentials, and use named least-privilege identities routinely.
D. Enable root MFA, delete root access keys, secure root credentials, and let one senior administrator use root routinely.
Best answer: C
Explanation: The AWS account root user has unrestricted authority and should be reserved for tasks that specifically require root credentials. Protect it with MFA, securely control its credentials, and delete root access keys when programmatic root access is unnecessary. Administrators should perform routine work through their own named or federated identities with only the permissions they need. Individual identities reduce exposure and provide attribution in audit records.
Encryption does not make unnecessary root access keys advisable, and replacing shared root access with another shared identity does not provide person-level accountability.
- Retaining encrypted root access keys preserves unnecessary long-term credentials with unrestricted account authority.
- Assigning routine root use to a senior administrator still exposes root credentials during ordinary operations.
- Using one shared workforce identity prevents actions from being reliably attributed to individual administrators.
Question 43
Topic: Cloud Concepts
A software company is evaluating cloud adoption. Its primary goal is to enter three new countries within one year and increase sales. The proposal also predicts faster server provisioning, fewer infrastructure administration hours, and lower energy use per transaction.
Which measure best shows whether the primary business outcome was achieved?
Options:
A. Energy consumed per completed customer transaction
B. Administrator hours spent on infrastructure maintenance
C. Average time required to provision server capacity
D. Sales generated in newly entered geographic markets
Best answer: D
Explanation: Cloud adoption can produce both business outcomes and technical outputs. The company’s primary objective is market expansion that increases sales, so revenue from the new geographic markets directly measures success. Faster provisioning is a technical output that may improve agility, while fewer administration hours indicate operational efficiency. Lower energy use per transaction can support environmental, social, and governance (ESG) performance. These benefits are valuable, but they do not directly demonstrate that the company reached new customers and increased revenue.
- Provisioning time measures technical agility rather than sales growth in new markets.
- Administration hours measures operational efficiency rather than customer reach or revenue.
- Energy per transaction measures an ESG-related improvement rather than market expansion.
Question 44
Topic: Security and Compliance
A company has AWS CloudTrail enabled, but several employees sign in through one shared IAM user. Security finds that:
- CloudTrail events cannot be attributed to a specific employee.
- A stolen password could be used by itself to sign in.
Which TWO safeguards most directly address these separate findings?
Options:
A. Restrict the shared IAM user’s permissions to required tasks
B. Increase the retention period for CloudTrail event records
C. Rotate the shared IAM user’s password more frequently
D. Require MFA for each employee’s sign-in
E. Assign each employee an individual workforce identity
Correct answers: D and E
Explanation: Individual identities and MFA are complementary safeguards addressing different risks. Individual identities give each employee a distinct principal, allowing CloudTrail events to provide meaningful attribution. MFA adds another authentication factor, so possession of a password alone is insufficient for sign-in.
Least privilege remains important for limiting permitted actions, but it does not identify which person used a shared identity. Similarly, longer log retention preserves evidence but cannot restore identity details that were never captured. Password rotation changes the shared secret but retains both the attribution weakness and reliance on one factor.
- Least privilege limits what the shared user can do but does not distinguish employees or add an authentication factor.
- Longer retention preserves CloudTrail records but cannot identify which employee used the shared identity.
- Password rotation reduces exposure time for an old password but retains shared access and single-factor authentication.
Question 45
Topic: Cloud Technology and Services
A company has 12 VPCs in one AWS Region and an on-premises data center. It wants to:
- Connect the VPCs and data center through a central network hub.
- Use a dedicated private network connection between the data center and AWS.
Which TWO AWS services provide these complementary capabilities?
Options:
A. AWS PrivateLink
B. VPC peering
C. AWS Site-to-Site VPN
D. AWS Direct Connect
E. AWS Transit Gateway
Correct answers: D and E
Explanation: AWS Transit Gateway acts as a regional network hub that can connect multiple VPCs and on-premises networks, avoiding a complex set of pairwise connections. AWS Direct Connect supplies the complementary dedicated private connection from the company’s data center to AWS. Direct Connect connectivity can reach a transit gateway through the appropriate Direct Connect gateway association.
A Site-to-Site VPN can provide encrypted on-premises connectivity, but it normally traverses the internet rather than supplying the required dedicated connection. The key distinction is centralized routing through Transit Gateway combined with dedicated connectivity through Direct Connect.
- Site-to-Site VPN provides encrypted connectivity over the internet, not the required dedicated private network connection.
- VPC peering creates direct, non-transitive VPC relationships rather than a centralized hub for many networks.
- AWS PrivateLink privately exposes services to consumers but does not provide general-purpose routing among entire networks.
Question 46
Topic: Cloud Technology and Services
A company will run containerized applications with Amazon ECS. The operations team will manage the container images and task definitions but does not want to provision, patch, or scale the servers that host the containers.
Which compute option best meets this requirement?
Options:
A. Run the Amazon ECS tasks using Amazon EC2 capacity.
B. Run the containers using Amazon EKS managed node groups.
C. Run the containers using Docker on Amazon Lightsail instances.
D. Run the Amazon ECS tasks using AWS Fargate capacity.
Best answer: D
Explanation: AWS Fargate is managed compute for containers that works with Amazon ECS and Amazon EKS. With ECS on Fargate, AWS provisions and manages the underlying compute infrastructure, including the container hosts. The customer remains responsible for container images, application code, task definitions, data, and access settings.
Using ECS with EC2 capacity instead requires the customer to manage the EC2 container instances. The decisive distinction is who manages the servers beneath the containers.
- EC2 capacity requires the company to manage the ECS container instances, including operating-system maintenance and capacity.
- EKS node groups use EC2 worker nodes and introduce Kubernetes rather than preserving the stated Amazon ECS environment.
- Lightsail instances remain customer-managed virtual servers even when Docker runs on them.
Question 47
Topic: Billing, Pricing, and Support
A startup created an eligible commercial AWS account on September 1, 2025, selected the free account plan, and received $100 in Free Tier credits. After three months, $60 remains. The startup now wants to join an AWS organization for consolidated billing.
What should the startup expect after joining? Select ONE.
Options:
A. It remains on the free plan until its credits are exhausted, then moves to paid under consolidated billing.
B. It moves to the paid plan, retains its credits for 12 months, and pays after those credits are exhausted.
C. It moves to the paid plan, its credits expire immediately, and usage beyond applicable allowances may incur charges.
D. It remains on the free plan through month six, retains its credits, and participates in consolidated billing.
Best answer: C
Explanation: For eligible accounts created on or after July 15, 2025, the free account plan normally ends after six months or when Free Tier credits are exhausted, whichever occurs first. However, joining an AWS organization is an immediate upgrade to the paid plan. That action expires all remaining Free Tier credits and prevents the account from earning more. Once paid, the account can incur charges for usage beyond any applicable service allowances. The credits’ ordinary 12-month expiration does not apply when an organization membership causes them to expire earlier.
- Retaining credits for 12 months overlooks the immediate expiration caused by joining an AWS organization.
- Remaining free through month six ignores that organization membership triggers an immediate paid-plan upgrade.
- Waiting for credit exhaustion uses the normal free-plan ending condition rather than the organization-specific upgrade rule.
Question 48
Topic: Security and Compliance
A company keeps analyst identities in AWS Account A. Analysts must read reports in an S3 bucket owned by Account B. The security team wants Account B to control read-only permissions without creating Account B users or distributing long-term access keys.
Which TWO statements explain how an IAM role can meet these requirements? (Select TWO.)
Options:
A. Assuming the role gives each authorized analyst temporary credentials for a limited session.
B. Placing both accounts in AWS Organizations automatically lets Account A analysts assume roles in Account B.
C. Account B can define a role with S3 read permissions and trust authorized principals from Account A.
D. The role stores long-term access keys that AWS rotates while analysts continue using the same credentials.
E. Account A can authorize bucket access without Account B granting trust or resource access.
Correct answers: A and C
Explanation: For cross-account role access, the resource-owning account defines both who may assume the role and what the role may do. Account B therefore controls the role’s trust policy and its read-only S3 permissions. An authorized analyst in Account A assumes the role, and AWS Security Token Service (AWS STS) returns temporary credentials containing an access key ID, secret access key, and session token. These credentials expire after the role session, avoiding separate IAM users and persistent keys in Account B.
AWS Organizations membership does not create role trust, and permissions granted only in Account A cannot independently authorize access to Account B’s resources.
- Organizations membership supports centralized governance but does not automatically grant cross-account role access.
- Account A authorization alone cannot replace the trust or resource permissions controlled by Account B.
- Rotated permanent keys misrepresents roles, which use temporary session credentials rather than stored long-term credentials.
Question 49
Topic: Cloud Technology and Services
A small development team wants to upload web application code to AWS. The team wants a service that coordinates application releases and supporting infrastructure rather than managing each resource separately. It is evaluating AWS Elastic Beanstalk.
Which TWO capabilities does Elastic Beanstalk provide? Select TWO.
Options:
A. Execute event-driven functions without managing application servers
B. Deploy supplied application versions to managed runtime environments
C. Provision and coordinate capacity, scaling, load balancing, and health monitoring
D. Store and distribute container images through a managed registry
E. Orchestrate Kubernetes clusters for containerized application workloads
Correct answers: B and C
Explanation: AWS Elastic Beanstalk is a managed service for deploying applications and coordinating their supporting environments. Developers upload application code and select a supported platform, while Elastic Beanstalk handles deployment and functions such as capacity provisioning, load balancing, automatic scaling, and health monitoring.
The customer still controls the application, data, and relevant configuration. Elastic Beanstalk does not replace specialized services for serverless functions, Kubernetes orchestration, or container image storage. Its distinguishing role is combining application deployment with management of the infrastructure that supports the application.
- Event-driven function execution describes AWS Lambda rather than Elastic Beanstalk environments.
- Kubernetes cluster orchestration describes Amazon EKS rather than application platform management.
- Container image storage and distribution describes Amazon ECR rather than application deployment management.
Question 50
Topic: Cloud Concepts
A retail company is migrating workloads from its data center to AWS. Operations staff currently spend significant time procuring, installing, and replacing servers. Leadership plans to reassign some staff to improving the customer portal.
Which TWO business effects should the company expect? Select TWO.
Options:
A. Increase staff capacity for customer-facing feature development and service improvements.
B. Shift data classification and IAM access approvals from staff to AWS.
C. Remove staff responsibility for patching guest operating systems on Amazon EC2.
D. Reduce staff effort devoted to procuring and replacing physical server hardware.
E. Convert infrastructure spending to a fixed cost independent of resource usage.
Correct answers: A and D
Explanation: AWS reduces undifferentiated operational work by operating data centers and maintaining the underlying physical infrastructure. The company therefore spends less staff time procuring, installing, and replacing servers. It can redirect that capacity toward portal features and other work that directly improves customer experiences.
Cloud adoption does not transfer every operational or security responsibility to AWS. Customers remain responsible for their data, identities, access decisions, and applications. For Amazon EC2, customers also manage the guest operating system. Cloud spending commonly varies with resource usage and still requires financial oversight. The key benefit is shifting effort from repetitive infrastructure maintenance to higher-value business work, not eliminating customer responsibilities.
- Guest operating system patching remains a customer responsibility for Amazon EC2 instances.
- Data classification and IAM access approvals remain customer governance responsibilities.
- AWS pricing is commonly usage-based, so infrastructure spending does not automatically become fixed.
Questions 51-65
Question 51
Topic: Security and Compliance
A company runs an application on Amazon EC2 and stores customer records on an attached Amazon EBS volume. Administrators access the guest operating system through SSH.
The security team proposes allowing inbound TCP port 22 only from the corporate network. Its memo states:
This control encrypts customer records and prevents unauthorized physical entry to AWS data centers.
Which TWO statements accurately assess the proposed control?
Options:
A. AWS secures the facilities; the company manages guest OS access and application data.
B. The rule replaces guest OS authentication for administrators using the approved network.
C. The rule reduces network exposure to SSH on the EC2 instances.
D. The company must secure AWS facilities because it administers the guest operating system.
E. The rule encrypts records on the EBS volume by filtering inbound connections.
Correct answers: A and C
Explanation: Security controls protect specific layers. An EC2 security group filters network traffic reaching an instance, so restricting port 22 reduces the network exposure of SSH. It does not encrypt data stored on an EBS volume, authenticate operating-system users, or control physical access to AWS facilities.
Under the shared responsibility model, AWS protects the physical data centers, hardware, and foundational infrastructure. The customer remains responsible for protecting application data, administering the EC2 guest operating system, and controlling user access. The memo therefore attributes data-encryption and physical-security outcomes to a network-layer control.
- EBS encryption is a data-protection mechanism; filtering inbound SSH traffic does not encrypt stored records.
- Facility security belongs to AWS even when the customer administers an EC2 guest operating system.
- OS authentication is still required because an approved source address does not establish an administrator’s identity.
Question 52
Topic: Cloud Technology and Services
A company is selecting AWS container orchestration services for two teams:
- One team wants AWS-native orchestration without requiring Kubernetes APIs.
- The other team must retain Kubernetes APIs and compatible tooling.
Which TWO service mappings meet these requirements?
Options:
A. Use Amazon EKS as the container image registry.
B. Use Amazon ECS only for serverless container workloads.
C. Use Amazon ECS for the AWS-native orchestration requirement.
D. Use Amazon ECS for a managed Kubernetes control plane.
E. Use Amazon EKS for the Kubernetes compatibility requirement.
Correct answers: C and E
Explanation: Amazon ECS is an AWS-native container orchestration service, while Amazon EKS is a managed Kubernetes service. ECS is appropriate when a team does not require the Kubernetes ecosystem. EKS is appropriate when Kubernetes APIs, tooling, and workload compatibility are required. Both services can run containers using Amazon EC2 capacity or AWS Fargate, so the distinction is the orchestration model rather than whether the workload is serverless.
Amazon ECR, not EKS, provides a managed container image registry.
- ECS does not provide a Kubernetes control plane; its orchestration model is AWS-native.
- EKS orchestrates Kubernetes workloads; Amazon ECR stores container images.
- ECS supports both AWS Fargate and Amazon EC2 capacity, not only serverless workloads.
Question 53
Topic: Security and Compliance
A company runs a public web application through an Application Load Balancer. It receives HTTP requests matching unwanted patterns, and the security team is concerned about DDoS attacks disrupting availability.
Which TWO statements describe complementary AWS security service contributions?
Options:
A. Amazon GuardDuty filters inbound requests before they reach the load balancer.
B. AWS WAF filters web requests by evaluating configured web rules.
C. AWS Shield provides managed protection against DDoS attacks affecting availability.
D. AWS Shield filters requested URLs by evaluating configured web rules.
E. AWS WAF provides AWS-wide mitigation of network-layer volumetric attacks.
Correct answers: B and C
Explanation: AWS WAF and AWS Shield address different but complementary threats. AWS WAF examines application-layer web requests and applies configured rules to allow, block, or count traffic based on characteristics such as request patterns. AWS Shield focuses on protecting AWS applications from DDoS attacks that attempt to exhaust resources or disrupt availability. AWS Shield Standard is automatically included with AWS accounts, while AWS Shield Advanced provides additional protections and response capabilities.
The key distinction is request-level filtering by AWS WAF versus managed DDoS protection by AWS Shield.
- Assigning web-rule evaluation to AWS Shield confuses DDoS protection with application-layer request filtering.
- Assigning AWS-wide network-layer volumetric mitigation to AWS WAF reverses the primary service roles.
- GuardDuty analyzes threat-related activity and findings; it does not serve as an inline web-request filter.
Question 54
Topic: Cloud Technology and Services
A company currently runs Amazon ECS tasks on self-managed EC2 container instances. It wants to reduce infrastructure administration while continuing to deploy its own container images through Amazon ECS.
Which TWO characteristics apply if the company uses AWS Fargate?
Options:
A. AWS manages the task infrastructure and host operating system.
B. Fargate replaces Amazon ECS as the service that schedules tasks.
C. AWS remediates vulnerabilities inside the company’s container images.
D. The company patches the EC2 host AMIs used by Fargate tasks.
E. The company manages its images, application code, and task definitions.
Correct answers: A and E
Explanation: AWS Fargate is managed compute for containers. With Amazon ECS on Fargate, AWS provisions the compute capacity and maintains the underlying servers and host operating system. The customer does not create, patch, or scale a fleet of EC2 container instances.
The shared responsibility model still applies above that infrastructure layer. The customer manages application code, container images, task definitions, permissions, and relevant application settings. Amazon ECS remains the container orchestration service that schedules and manages tasks, while Fargate provides the compute environment on which those tasks run.
- Patching EC2 host AMIs applies when the customer operates an EC2-backed container fleet, not when tasks use Fargate.
- Container-image vulnerabilities remain the customer’s responsibility because Fargate manages infrastructure rather than application contents.
- Replacing Amazon ECS confuses compute with orchestration; Fargate supplies capacity while ECS schedules the tasks.
Question 55
Topic: Security and Compliance
A financial company must keep encryption keys on dedicated, single-tenant cryptographic hardware hosted in AWS. Its security team must administer HSM users and control the keys throughout their lifecycle. Identity permissions will be governed separately.
Which AWS capability best meets these requirements?
Options:
A. Manage the keys directly in an AWS CloudHSM cluster.
B. Manage the keys as customer managed keys in AWS KMS.
C. Manage the keys through an AWS KMS external key store.
D. Manage imported key material as keys in AWS KMS.
Best answer: A
Explanation: AWS CloudHSM provides dedicated, single-tenant hardware security modules and gives the customer direct control over HSM users and cryptographic keys. AWS manages the underlying service infrastructure, while the customer manages the HSM cluster configuration, users, keys, and cryptographic operations. AWS KMS offers simpler managed key administration but does not provide direct customer administration of dedicated HSMs.
Control of cryptographic hardware and keys does not replace access authorization. The company must still govern which identities can create, manage, or use resources through appropriate permissions.
- Customer managed KMS keys provide lifecycle and policy controls, but AWS KMS operates the underlying HSM infrastructure.
- Imported key material controls the key’s origin, but it does not give the customer dedicated KMS hardware.
- An external key store relies on an external key-management system rather than dedicated AWS-hosted HSMs.
Question 56
Topic: Cloud Technology and Services
A company has recorded customer-support conversations and written follow-up messages. It must:
- Create searchable text transcripts from each recorded conversation.
- Generate spoken versions of written follow-up messages for phone playback.
Which TWO AWS services directly perform these required conversions? Select TWO.
Options:
A. Use Amazon Comprehend to convert recorded conversations into searchable text.
B. Use Amazon Translate to convert written follow-up messages into spoken audio.
C. Use Amazon Transcribe to convert recorded conversations into searchable text.
D. Use Amazon Polly to convert written follow-up messages into spoken audio.
E. Use Amazon Lex to convert recorded conversations into searchable text.
Correct answers: C and D
Explanation: Amazon Transcribe performs automatic speech recognition, converting spoken audio such as recorded customer conversations into text. Amazon Polly performs the complementary conversion: it uses text-to-speech technology to generate spoken audio from written content.
The conversion direction is the key distinction. Transcribe accepts speech and produces text, while Polly accepts text and produces speech. Amazon Comprehend analyzes text, Amazon Translate converts text between languages, and Amazon Lex supports conversational interfaces and intent recognition rather than transcription of complete recorded conversations.
- Comprehend confusion: Amazon Comprehend analyzes text for insights but does not convert recorded speech into text.
- Translate confusion: Amazon Translate converts text between languages rather than generating spoken audio.
- Lex confusion: Amazon Lex builds conversational interfaces and recognizes user intents rather than transcribing complete recorded conversations.
Question 57
Topic: Security and Compliance
A company wants a managed AWS service that continuously analyzes account activity and network telemetry to detect suspicious behavior, including unusual API calls and potentially compromised credentials. The service must generate threat findings rather than merely aggregate existing findings.
Which AWS service best meets this need?
Options:
A. Enable Amazon Inspector for automated vulnerability management.
B. Enable Amazon GuardDuty for managed threat detection.
C. Enable Amazon Detective for security investigation and visualization.
D. Enable AWS Security Hub for centralized findings management.
Best answer: B
Explanation: Amazon GuardDuty is a managed threat detection service that continuously analyzes supported AWS activity and data sources, such as AWS CloudTrail management events, VPC Flow Logs, and DNS logs. It uses threat intelligence and behavioral analysis to identify suspicious activity, including unusual API behavior, potentially compromised credentials, and communication with malicious destinations. GuardDuty then generates security findings for review and response.
The decisive requirement is generating threat detections from AWS activity. Centralizing findings, assessing vulnerabilities, and investigating incidents are related security capabilities, but they do not perform GuardDuty’s primary threat detection role.
- Vulnerability assessment identifies software vulnerabilities and unintended network exposure rather than suspicious account activity.
- Findings aggregation centralizes security findings and evaluates security posture but is not the required underlying threat detector.
- Security investigation helps analyze relationships around existing findings rather than continuously generating the requested threat findings.
Question 58
Topic: Cloud Concepts
A company wants to rehost existing on-premises server workloads on AWS with minimal application changes. It requires continuous block-level replication so that each server can be launched on AWS after a short cutover window.
Which AWS service best meets this requirement?
Options:
A. Use AWS Database Migration Service.
B. Use AWS Snowball Edge.
C. Use AWS DataSync.
D. Use AWS Application Migration Service.
Best answer: D
Explanation: AWS Application Migration Service is designed to move physical, virtual, or cloud-based servers to AWS using a rehosting approach. It continuously replicates source-server data at the block level into AWS, enabling testing before cutover and reducing downtime when the replicated server is launched. This fits a migration that requires minimal changes to existing applications.
Database Migration Service focuses on databases, while DataSync and Snowball Edge move data rather than rehost complete server workloads. The deciding requirement is replication and launch of existing servers, not merely transferring their data.
- Database replication applies to migrating database engines and data, not complete server workloads.
- Online file transfer moves data between storage systems but does not launch replicated servers.
- Offline data transfer transports large datasets using an edge device but does not provide continuous server replication.
Question 59
Topic: Cloud Technology and Services
A company has eight VPCs in one AWS Region and an on-premises data center connected through AWS Site-to-Site VPN. It wants each network to attach to a central hub that routes traffic among them, avoiding a full mesh of VPC peering connections.
Which AWS service best meets this need? Select ONE.
Options:
A. Use AWS Direct Connect gateway with virtual private gateways.
B. Use AWS PrivateLink endpoints for each VPC and application.
C. Use AWS Transit Gateway with VPC and VPN attachments.
D. Use VPC peering among the VPCs and retain the VPN.
Best answer: C
Explanation: AWS Transit Gateway acts as a network transit hub for connecting multiple VPCs and on-premises networks. Each VPC can use a transit gateway attachment, while the existing Site-to-Site VPN can attach the data center to the same hub. Transit Gateway then routes traffic according to its route tables, reducing the need for many pairwise connections.
VPC peering is non-transitive and would require a mesh for broad VPC-to-VPC connectivity. PrivateLink provides private access to specific services rather than general network routing. A Direct Connect gateway supports dedicated connectivity scenarios but is not a VPC-to-VPC transit hub.
- VPC peering requires separate pairwise connections because peering relationships do not provide transitive routing.
- AWS PrivateLink privately exposes specific services and does not connect entire networks through a routing hub.
- Direct Connect gateway supports Direct Connect connectivity to VPCs but does not provide general VPC-to-VPC transit routing.
Question 60
Topic: Cloud Concepts
An online retailer runs a stateless web tier on Amazon EC2. Traffic is unpredictable. The business requires the web tier to automatically adjust compute capacity as demand changes and remain available if one Availability Zone becomes unavailable.
Which approach best meets these requirements?
Options:
A. Use AWS Backup with a fixed standby EC2 fleet in another Region.
B. Use Elastic Load Balancing with EC2 Auto Scaling within one Availability Zone.
C. Use Elastic Load Balancing with a fixed EC2 fleet across multiple Availability Zones.
D. Use Elastic Load Balancing with EC2 Auto Scaling across multiple Availability Zones.
Best answer: D
Explanation: Reliability combines recovery from infrastructure disruption with sufficient capacity to meet changing demand. An EC2 Auto Scaling group can add, remove, and replace instances automatically. Spanning the group across multiple Availability Zones prevents one zone’s failure from eliminating the entire web tier. Elastic Load Balancing distributes requests among healthy instances in the available zones.
A fixed multi-zone fleet improves availability but does not automatically adjust capacity, while scaling within one zone leaves the workload exposed to a zone-level disruption.
- A fixed multi-zone fleet provides redundancy but cannot automatically scale with changing traffic.
- Auto Scaling in one Availability Zone addresses demand changes but not an outage of that zone.
- A standby fleet in another Region supports disaster recovery but does not directly provide automatic demand-based scaling.
Question 61
Topic: Security and Compliance
A company needs to store credentials for a supported Amazon RDS database securely. The application must retrieve the current credentials at runtime, and AWS must support scheduled credential rotation using an AWS-provided rotation integration.
Which AWS service best meets these requirements?
Options:
A. Use AWS KMS customer managed keys with key rotation
B. Use Parameter Store SecureString parameters with versioning
C. Use AWS AppConfig hosted configuration with deployment validation
D. Use AWS Secrets Manager with scheduled rotation
Best answer: D
Explanation: AWS Secrets Manager is designed to manage sensitive credentials throughout their lifecycle, including secure storage, application retrieval, and scheduled rotation. AWS Systems Manager Parameter Store can securely store configuration values and secrets as SecureString parameters, but it does not provide the same managed secret-rotation capability.
AWS KMS manages encryption keys rather than rotating the stored database credentials themselves. AWS AppConfig supports controlled deployment and validation of application configuration, not credential lifecycle management. The decisive requirement is managed rotation, which distinguishes Secrets Manager from protected parameter storage.
- Parameter Store can protect configuration and secret values, but versioning does not provide managed credential rotation.
- AWS KMS rotates cryptographic keys, not the database credential value required by the application.
- AWS AppConfig manages configuration deployments and validation rather than storing and rotating database credentials.
Question 62
Topic: Cloud Technology and Services
A company is selecting an AWS Region for a workload. The following requirements are mandatory:
- Customer content and backups must remain within the EU.
- User latency must be <= 40 ms.
- The required AWS service must be available in the Region.
| Region | EU location | Latency | Service available |
|---|---|---|---|
| Europe (Frankfurt) | Yes | 48 ms | Yes |
| Europe (Paris) | Yes | 24 ms | No |
| Europe (Ireland) | Yes | 32 ms | Yes |
| Europe (London) | No | 18 ms | Yes |
Which AWS Region should the company select?
Options:
A. Europe (Frankfurt) Region
B. Europe (Ireland) Region
C. Europe (Paris) Region
D. Europe (London) Region
Best answer: B
Explanation: AWS Region selection must account for every mandatory business constraint. Europe (Ireland) keeps the data within the required EU boundary, provides measured latency below 40 ms, and offers the required service. Selecting the Region with the lowest latency alone would not be sufficient because data sovereignty and regional service availability are also mandatory. A nearby Region can still be unsuitable if the required service is unavailable or its jurisdiction does not satisfy regulatory requirements.
- Frankfurt satisfies sovereignty and service availability, but its 48 ms latency exceeds the stated limit.
- Paris satisfies sovereignty and latency requirements, but the required service is unavailable there.
- London provides acceptable latency and service availability, but it is outside the required EU boundary.
Question 63
Topic: Cloud Concepts
A company needs temporary computing capacity today for a short business pilot. Its traditional data center procurement process takes several weeks to purchase, install, and configure new servers.
Which AWS Cloud capability best addresses this need? Select ONE.
Options:
A. Provision resources on demand instead of procuring and installing servers
B. Use provider economies of scale to reduce computing costs
C. Deploy resources across Regions to serve users closer to them
D. Adjust resources elastically as workload demand rises and falls
Best answer: A
Explanation: On-demand self-service allows customers to obtain AWS computing resources when needed through service requests rather than purchasing, installing, and configuring physical hardware. This can reduce capacity acquisition from weeks to minutes and requires much less upfront effort, enabling the company to begin its pilot quickly. Because the resources are temporary, the company can also release them when the pilot ends.
Elasticity concerns changing capacity as demand changes, while the decisive need here is obtaining the initial capacity quickly.
- Elastic scaling addresses changing existing capacity as demand varies, not shortening the initial hardware procurement process.
- Global deployment supports geographic reach and lower user latency, but location is not the stated constraint.
- Economies of scale can reduce prices, but the primary requirement concerns acquisition time and effort.
Question 64
Topic: Cloud Technology and Services
A company must give remote contractors access to a Windows accounting application from personal devices. The application is not browser-based, and contractors must see only the application rather than a complete virtual desktop.
Which AWS service best meets these requirements? Select ONE.
Options:
A. Amazon WorkSpaces Personal
B. Amazon WorkSpaces Secure Browser
C. Amazon WorkSpaces Pools
D. Amazon WorkSpaces Applications
Best answer: D
Explanation: Amazon WorkSpaces Applications, formerly Amazon AppStream 2.0, streams individual applications to users on their devices. It fits a requirement to deliver a non-browser-based Windows application without exposing a complete desktop.
Amazon WorkSpaces Personal and WorkSpaces Pools provide virtual desktop experiences. Personal desktops are persistent and assigned to individual users, while pooled desktops are nonpersistent and shared from a pool. WorkSpaces Secure Browser provides protected browser access to websites and browser-based applications, so it does not deliver the required Windows application.
- Personal desktop provides an individually assigned, persistent virtual desktop rather than only the accounting application.
- Pooled desktop provides a nonpersistent virtual desktop session rather than an application-only experience.
- Secure browser supports protected access to browser-based resources, but the accounting application is not browser-based.
Question 65
Topic: Billing, Pricing, and Support
A media company wants to minimize Amazon EC2 costs and will not make a one- or three-year usage commitment.
| Workload | Interruption tolerance | Timing |
|---|---|---|
| Checkout API | Cannot tolerate Spot interruptions | Traffic is unpredictable |
| Batch renderer | Can checkpoint and restart | Completion time is flexible |
Which TWO purchasing decisions best meet these requirements?
Options:
A. Use Spot Instances for the checkout API.
B. Use Spot Instances for the batch renderer.
C. Use On-Demand Instances for the checkout API.
D. Use Spot Instances for the renderer through a one-year term.
E. Use On-Demand Instances for the batch renderer.
Correct answers: B and C
Explanation: On-Demand and Spot Instances require no long-term usage commitment, but they differ in cost and interruption risk. On-Demand is appropriate for the checkout API because its unpredictable traffic does not justify accepting Spot interruptions. Spot Instances use discounted spare EC2 capacity that AWS may reclaim, making them suitable for interruption-tolerant workloads. The batch renderer can checkpoint, restart, and finish within a flexible timeframe, so it can benefit from Spot pricing while managing interruptions. On-Demand would run the renderer, but it would not best satisfy the cost-minimization goal given the workload’s flexibility.
- Using Spot for checkout overlooks that unpredictable demand does not make a workload tolerant of capacity interruptions.
- Using On-Demand for rendering avoids interruptions but misses the cost advantage available to this checkpointable, flexible workload.
- A one-year Spot term confuses Spot pricing with commitment-based discounts; Spot Instances do not require such a commitment.
Continue in the web app
Use IT Mastery for interactive AWS CLF-C02 practice with mixed sets, timed mocks, topic drills, explanations, and progress tracking.