Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Amazon Web Services CLF-C02 Practice Exam with Questions & Answers | Set: 8

Questions 141

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

A company wants to optimize long-term compute costs of AWS Lambda functions and Amazon EC2 instances.

Which AWS purchasing option should the company choose to meet these requirements?

Options:
A.

Dedicated Hosts

B.

Compute Savings Plans

C.

Reserved Instances

D.

Spot Instances

Amazon Web Services CLF-C02 Premium Access
Questions 142

A company wants guidance to optimize the cost and performance of its current AWS environment.

Which AWS service or tool should the company use to identify areas for optimization?

Options:
A.

Amazon QuickSight

B.

AWS Trusted Advisor

C.

AWS Organizations

D.

AWS Budgets

Questions 143

Which AWS service can a company use to securely store and encrypt passwords for a database?

Options:
A.

AWS Shield

B.

AWS Secrets Manager

C.

AWS Identity and Access Management (IAM)

D.

Amazon Cognito

Questions 144

A user wants to invoke an AWS Lambda function when an Amazon EC2 instance enters the "stopping" state.

Which AWS service is appropriate for this use case?

Options:
A.

Amazon EventBridge

B.

AWS Config

C.

Amazon Simple Notification Service (Amazon SNS)

D.

AWS CloudFormation

Questions 145

Which AWS service can report how AWS resource configurations have changed over time?

Options:
A.

AWS CloudTrail

B.

Amazon CloudWatch

C.

AWS Config

D.

Amazon Inspector

Questions 146

A company needs to migrate all of its development teams to a cloud-based integrated development environment (IDE).

Which AWS service should the company use?

Options:
A.

AWS CodeBuild

B.

AWS Cloud9

C.

AWS OpsWorks

D.

AWS Cloud Development Kit (AWS CDK)

Questions 147

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

Options:
A.

Perform quarterly disaster recovery tests.

B.

Place the main component on the us-east-1 Region.

C.

Design for automatic failover to healthy resources.

D.

Design workloads to fit on a single Amazon EC2 instance.

Questions 148

What does "security of the cloud" refer to in the AWS shared responsibility model?

Options:
A.

Availability of AWS services such as Amazon EC2

B.

Security of the cloud infrastructure that runs all the AWS services

C.

Implementation of password policies for IAM users

D.

Security of customer environments by using AWS Network Firewall partners

Questions 149

A company has been storing monthly reports in an Amazon S3 bucket. The company exports the report data into comma-separated values (.csv) files. A developer wants to write a simple query that can read all of these files and generate a summary report.

Which AWS service or feature should the developer use to meet these requirements with the LEAST amount of operational overhead?

Options:
A.

Amazon S3 Select

B.

Amazon Athena

C.

Amazon Redshift

D.

Amazon EC2

Questions 150

How can an AWS user conduct security assessments of Amazon EC2 instances, NAT gateways, and Elastic

Load Balancers in a way that is approved by AWS?

Options:
A.

Flood a target with requests.

B.

Use Amazon Inspector.

C.

Perform penetration testing.

D.

Use the AWS Service Health Dashboard.

Questions 151

Which database engine is compatible with Amazon RDS?

Options:
A.

Apache Cassandra

B.

MongoDB

C.

Neo4j

D.

PostgreSQL

Questions 152

An ecommerce company has migrated its IT infrastructure from an on-premises data center to the AWS Cloud.

Which AWS service is used to track, record, and audit configuration changes made to AWS resources?

Options:
A.

AWS Shield

B.

AWS Config

C.

AWS IAM

D.

Amazon Inspector

Questions 153

A company is using AWS Lambda functions to build an application.

Which tasks are the company's responsibility, according to the AWS shared responsibility model? (Select TWO.)

Options:
A.

Patch the servers where the Lambda functions are deployed.

B.

Establish the IAM permissions that define who can run the Lambda functions.

C.

Write the code for the Lambda functions to define the application logic.

D.

Deploy Amazon EC2 instances to support the Lambda functions.

E.

Scale out the Lambda functions when the load increases.

Questions 154

A company is developing an application that uses multiple AWS services. The application needs to use

temporary, limited-privilege credentials for authentication with other AWS APIs.

Which AWS service or feature should the company use to meet these authentication requirements?

Options:
A.

Amazon API Gateway

B.

IAM users

C.

AWS Security Token Service (AWS STS)

D.

IAM instance profiles

Questions 155

Which factors affect costs in the AWS Cloud? (Select TWO.)

Options:
A.

The number of unused AWS Lambda functions

B.

The number of configured Amazon S3 buckets

C.

Inbound data transfers without acceleration

D.

Outbound data transfers without acceleration

E.

Compute resources that are currently in use

Questions 156

A company is planning a migration to the AWS Cloud and wants to examine the costs that are associated with different workloads.

Which AWS tool will meet these requirements?

Options:
A.

AWS Budgets

B.

AWS Cost Explorer

C.

AWS Pricing Calculator

D.

AWS Cost and Usage Report

Questions 157

A company wants to centrally manage security policies and billing services within a multi-account AWS environment. Which AWS service should the company use to meet these requirements?

Options:
A.

AWS Identity and Access Management (IAM)

B.

AWS Organizations

C.

AWS Resource Access Manager (AWS RAM)

D.

AWS Config

Questions 158

Which group shares responsibility with AWS for security and compliance of AWS accounts and resources?

Options:
A.

Third-party vendors

B.

Customers

C.

Reseller partners

D.

Internet providers

Questions 159

A security engineer wants a single-tenant AWS solution to create, control, and manage their own cryptographic keys to meet regulatory compliance requirements for data security.

Which AWS service should the engineer use?

Options:
A.

AWS Key Management Service (AWS KMS)

B.

AWS Certificate Manager (ACM)

C.

AWS CloudHSM

D.

AWS Systems Manager

Questions 160

A company needs to design a solution for the efficient use of compute resources for an enterprise workload. The company needs to make informed decisions as its technology needs evolve.

Which pillar of the AWS Well-Architected Framework do these requirements represent?

Options:
A.

Operational excellence

B.

Performance efficiency

C.

Cost optimization

D.

Reliability