ExamGecko
Home Home / Amazon / CLF-C01

Amazon CLF-C01 Practice Test - Questions Answers, Page 37

Question list
Search
Search

Related questions











A company is managing millions of documents in hundreds of Amazon S3 buckets that are located in multiple AWS Regions. The company needs to find out if the S3 buckets are hosting information (PII). What can the company do to meet this requirement with the LEAST amount of operational overhead?

A.
Use Amazon Detective to identify any PII that is stored in the S3 buckets
A.
Use Amazon Detective to identify any PII that is stored in the S3 buckets
Answers
B.
Use AWS Trusted Advisor to generate PII notifications
B.
Use AWS Trusted Advisor to generate PII notifications
Answers
C.
Use Amazon Macie to identify and provide alerts about PII
C.
Use Amazon Macie to identify and provide alerts about PII
Answers
D.
Use AWS Lambda functions to review each file in the S3 buckets to identify PII
D.
Use AWS Lambda functions to review each file in the S3 buckets to identify PII
Answers
Suggested answer: C

Explanation:

Explanation:

Macie automatically detects a large and growing list of sensitive data types, including personally identifiable information (PII) such as names, addresses, and credit card numbers. It also gives you constant visibility of the data security and data privacy of your data stored in Amazon S3.

Which statement describes a characteristic of the AWS global infrastructure?

A.
Edge locations contain multiple AWS Regions
A.
Edge locations contain multiple AWS Regions
Answers
B.
AWS Regions contain multiple Regional edge caches
B.
AWS Regions contain multiple Regional edge caches
Answers
C.
Availability Zones contain multiple data centers
C.
Availability Zones contain multiple data centers
Answers
D.
Each data center contains multiple edge locations
D.
Each data center contains multiple edge locations
Answers
Suggested answer: C

Which AWS services or features help protect Amazon EC2 instances from DDoS attacks by limiting network access to the instances? (Select TWO.)

A.
Network ACLs
A.
Network ACLs
Answers
B.
AWS Batch
B.
AWS Batch
Answers
C.
Security groups
C.
Security groups
Answers
D.
AWS Identity and Access Management (IAM)
D.
AWS Identity and Access Management (IAM)
Answers
E.
AWS CloudHSM
E.
AWS CloudHSM
Answers
Suggested answer: A, C

Which AWS services can a company use to transfer on-premises data to the AWS Cloud? (Select TWO.)

A.
AWS Snowcone
A.
AWS Snowcone
Answers
B.
AWS Transit Gateway
B.
AWS Transit Gateway
Answers
C.
AWS DataSync
C.
AWS DataSync
Answers
D.
AWS Backup
D.
AWS Backup
Answers
E.
Amazon Connect
E.
Amazon Connect
Answers
Suggested answer: B, C

Explanation:

Explanation:

AWS Snowcone is the smallest member of the AWS Snow Family of edge computing, edge storage, and data transfer devices, weighing in at 4.5 pounds (2.1 kg) with 8 terabytes of usable storage. ...

Snowcone is ruggedized, secure, and purpose-built for use outside of a traditional data center.

AWS Transit Gateway connects VPCs and on-premises networks through a central hub. This simplifies your network and puts an end to complex peering relationships. It acts as a cloud router - each new connection is only made once. AWS DataSync is an online data transfer service that simplifies, automates, and accelerates moving data between on-premises storage systems and AWS Storage services, as well as between AWS Storage services.

AWS Backup provides a centralized console to automate and manage backups across AWS services.

AWS Backup supports Amazon EBS, Amazon RDS, Amazon DynamoDB, Amazon EFS, Amazon FSx, Amazon EC2, and AWS Storage Gateway, to enable you to backup key data stores, such as your storage volumes, databases, and file systems.

Amazon Connect is an easy to use omnichannel cloud contact center that helps you provide superior customer service at a lower cost. Designed from the ground up to be omnichannel, Amazon Connect provides a seamless experience across voice and chat for your customers and agents.

A company wants to configure its AWS resources so that the resources can be easily deployed across different AWS Regions. The company wants the deployment to be as automated as. Which AWS service will meet these requirements?

A.
AWS CodeBuild
A.
AWS CodeBuild
Answers
B.
AWS CodePipeline
B.
AWS CodePipeline
Answers
C.
AWS CloudFormation
C.
AWS CloudFormation
Answers
D.
Amazon CloudWatch
D.
Amazon CloudWatch
Answers
Suggested answer: B

Explanation:

Using AWS CodePipeline and AWS CloudFormation, you can use continuous delivery to automatically build and test changes to your AWS CloudFormation stacks before promoting them to production stacks. This release process lets you rapidly and reliably make changes to your AWS infrastructure.

WS CloudFormation provides users with a simple way to create and manage a collection of Amazon Web Services (AWS) resources by provisioning and updating them in a predictable way. AWS CloudFormation enables you to manage your complete infrastructure or AWS resources in a text file.

What tasks should a customer perform when that customer suspects an AWS account has been compromised? (Choose two.)

A.
Rotate and delete all AWS access keys.
A.
Rotate and delete all AWS access keys.
Answers
B.
Remove any multi-factor authentication (MFA) tokens
B.
Remove any multi-factor authentication (MFA) tokens
Answers
C.
Move resources to a different AWS Region.
C.
Move resources to a different AWS Region.
Answers
D.
Delete AWS CloudTrail Resources.
D.
Delete AWS CloudTrail Resources.
Answers
E.
Contact AWS Support.
E.
Contact AWS Support.
Answers
Suggested answer: A, E

Which AWS service provides users with recommendations for improving the quality of an application's code, and identifies the most expensive lines of code?

A.
AWS CodeBuild
A.
AWS CodeBuild
Answers
B.
AWS CodeStar
B.
AWS CodeStar
Answers
C.
Amazon CodeGuru
C.
Amazon CodeGuru
Answers
D.
AWS CodeDeploy
D.
AWS CodeDeploy
Answers
Suggested answer: C

Explanation:

Explanation:

Amazon CodeGuru is a developer tool that provides intelligent recommendations to improve code quality and identifying an application's most expensive lines of code.

A company wants to secure its consumer web application by using SSL/TLS to encrypt traffic. Which AWS service can the company use to meet this goal?

A.
AWS WAF
A.
AWS WAF
Answers
B.
AWS Shield
B.
AWS Shield
Answers
C.
Amazon VPC
C.
Amazon VPC
Answers
D.
AWS Certificate Manager (ACM)
D.
AWS Certificate Manager (ACM)
Answers
Suggested answer: D

Explanation:

Explanation:

WS Certificate Manager is a service that lets you easily provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with AWS services and your internal connected resources. SSL/TLS certificates are used to secure network communications and establish the identity of websites over the Internet as well as resources on private networks. AWS Certificate Manager removes the time-consuming manual process of purchasing, uploading, and renewing SSL/TLS certificates.

With AWS Certificate Manager, you can quickly request a certificate, deploy it on ACM-integrated AWS resources, such as Elastic Load Balancers, Amazon CloudFront distributions, and APIs on API Gateway, and let AWS Certificate Manager handle certificate renewals. It also enables you to create private certificates for your internal resources and manage the certificate lifecycle centrally. Public and private certificates provisioned through AWS Certificate Manager for use with ACM-integrated services are free. You pay only for the AWS resources you create to run your application. With AWS Certificate Manager Private Certificate Authority, you pay monthly for the operation of the private CA and for the private certificates you issue.

Which AWS service supports a company's ability to treat infrastructure as code?

A.
AWS CodeDeploy
A.
AWS CodeDeploy
Answers
B.
AWS Elastic Beanstalk
B.
AWS Elastic Beanstalk
Answers
C.
Amazon API Gateway
C.
Amazon API Gateway
Answers
D.
AWS CloudFormation
D.
AWS CloudFormation
Answers
Suggested answer: D

Explanation:

Explanation:

AWS CloudFormation gives you an easy way to model a collection of related AWS and third-party resources, provision them quickly and consistently, and manage them throughout their lifecycles, by treating infrastructure as code.

Which AWS services can host PostgreSQL databases? (Select TWO.)

A.
Amazon S3
A.
Amazon S3
Answers
B.
Amazon Aurora
B.
Amazon Aurora
Answers
C.
Amazon EC2
C.
Amazon EC2
Answers
D.
Amazon Elasticsearch Service (Amazon ES)
D.
Amazon Elasticsearch Service (Amazon ES)
Answers
E.
Amazon Elastic File System (Amazon EFS)
E.
Amazon Elastic File System (Amazon EFS)
Answers
Suggested answer: B, C
Total 944 questions
Go to page: of 95