ExamGecko
Home Home / Amazon / CLF-C02

Amazon CLF-C02 Practice Test - Questions Answers, Page 11

Question list
Search
Search

Related questions











What is the total amount of storage offered by Amazon S3?

A.
WOMB
A.
WOMB
Answers
B.
5 GB
B.
5 GB
Answers
C.
5 TB
C.
5 TB
Answers
D.
Unlimited
D.
Unlimited
Answers
Suggested answer: D

Explanation:

Amazon S3 offers unlimited storage for any amount of data. You can store as many objects as you want, and each object can be as large as 5 terabytes. You pay only for the storage space that you actually use, and there are no minimum commitments or upfront fees. Amazon S3 also provides high durability, availability, scalability, and security for your data.

Which AWS network services or features allow Cl DR block notation when providing an IP address range?

(Select TWO.)

A.
Security groups
A.
Security groups
Answers
B.
Amazon Machine Image (AMI)
B.
Amazon Machine Image (AMI)
Answers
C.
Network access control list (network ACL)
C.
Network access control list (network ACL)
Answers
D.
AWS Budgets
D.
AWS Budgets
Answers
E.
Amazon Elastic Block Store (Amazon EBS)
E.
Amazon Elastic Block Store (Amazon EBS)
Answers
Suggested answer: A, C

Explanation:

Security groups and network access control lists (network ACLs) are two AWS network services or features that allow CIDR block notation when providing an IP address range. Security groups act as a firewall for associated Amazon EC2 instances, controlling both inbound and outbound traffic at the instance level. Network ACLs act as a firewall for associated subnets, controlling both inbound and outbound traffic at the subnet level. Both security groups and network ACLs use CIDR block notation to specify the IP address ranges that are allowed or denied

A company has a workload that requires data to be collected, analyzed, and stored on premises. The company wants to extend the use of AWS services to run on premises with access to the company network and the company's VPC.

Which AWS service meets this requirement?

A.
AWS Outposts
A.
AWS Outposts
Answers
B.
AWS Storage Gateway
B.
AWS Storage Gateway
Answers
C.
AWS Direct Connect
C.
AWS Direct Connect
Answers
D.
AWS Snowball
D.
AWS Snowball
Answers
Suggested answer: A

Explanation:

AWS Outposts is an AWS service that meets the requirement of running AWS services on premises with access to the company network and the company's VPC. AWS Outposts is a fully managed service that extends AWS infrastructure, AWS services, APIs, and tools to virtually any datacenter, colocation space, or on-premises facility for a truly consistent hybrid experience. AWS Outposts is ideal for workloads that require low latency access to on-premises systems, local data processing, or local data storage2.

A company wants to deploy and manage a Docker-based application on AWS.

Which solution meets these requirements with the LEAST amount of operational overhead?

A.
An open-source Docker orchestrator on Amazon EC2 instances
A.
An open-source Docker orchestrator on Amazon EC2 instances
Answers
B.
AWS AppSync
B.
AWS AppSync
Answers
C.
Amazon Elastic Container Registry (Amazon ECR)
C.
Amazon Elastic Container Registry (Amazon ECR)
Answers
D.
Amazon Elastic Container Service (Amazon ECS)
D.
Amazon Elastic Container Service (Amazon ECS)
Answers
Suggested answer: D

Explanation:

Amazon Elastic Container Service (Amazon ECS) is a solution that meets the requirements of deploying and managing a Docker-based application on AWS with the least amount of operational overhead. Amazon ECS is a fully managed container orchestration service that makes it easy to run, scale, and secure Docker container applications on AWS. Amazon ECS eliminates the need for you to install, operate, and scale your own cluster management infrastructure. With simple API calls, you can launch and stop container-enabled applications, query the complete state of your cluster, and access many familiar features like security groups, Elastic Load Balancing, EBS volumes, and IAM roles3.

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

A.
Perform quarterly disaster recovery tests.
A.
Perform quarterly disaster recovery tests.
Answers
B.
Place the main component on the us-east-1 Region.
B.
Place the main component on the us-east-1 Region.
Answers
C.
Design for automatic failover to healthy resources.
C.
Design for automatic failover to healthy resources.
Answers
D.
Design workloads to fit on a single Amazon EC2 instance.
D.
Design workloads to fit on a single Amazon EC2 instance.
Answers
Suggested answer: C

Explanation:

Designing for automatic failover to healthy resources is an AWS best practice when designing AWS workloads to be operational even when there are component failures. This means that you should architect your system to handle the loss of one or more components without impacting the availability or performance of your application. You can use various AWS services and features to achieve this, such as Auto Scaling, Elastic Load Balancing, Amazon Route 53, Amazon CloudFormation, and AWS CloudFormation4.

Which AWS service provides highly durable object storage?

A.
Amazon S3
A.
Amazon S3
Answers
B.
Amazon Elastic File System (Amazon EFS)
B.
Amazon Elastic File System (Amazon EFS)
Answers
C.
Amazon Elastic Block Store (Amazon EBS)
C.
Amazon Elastic Block Store (Amazon EBS)
Answers
D.
Amazon FSx
D.
Amazon FSx
Answers
Suggested answer: A

Explanation:

Amazon S3 is the AWS service that provides highly durable object storage. Amazon S3 is designed to provide 99.999999999% durability of objects over a given year. This means that you can store your data with high confidence that it will not be lost. Amazon S3 also provides high availability, scalability, security, and performance for your data. You can use Amazon S3 to store and retrieve any amount of data, at any time, from anywhere on the web5.

Which pillar of the AWS Well-Architected Framework includes a design principle about measuring the overall efficiency of workloads in terms of business value?

A.
Operational excellence
A.
Operational excellence
Answers
B.
Security
B.
Security
Answers
C.
Reliability
C.
Reliability
Answers
D.
Cost optimization
D.
Cost optimization
Answers
Suggested answer: A

Explanation:

The operational excellence pillar of the AWS Well-Architected Framework includes a design principle about measuring the overall efficiency of workloads in terms of business value. This principle states that you should monitor and measure key performance indicators (KPIs) and set targets and thresholds that align with your business goals. You should also use feedback loops to continuously improve your processes and procedures1.

Who enables encryption of data at rest for Amazon Elastic Block Store (Amazon EBS)?

A.
AWS Support
A.
AWS Support
Answers
B.
AWS customers
B.
AWS customers
Answers
C.
AWS Key Management Service (AWS KMS)
C.
AWS Key Management Service (AWS KMS)
Answers
D.
AWS Trusted Advisor
D.
AWS Trusted Advisor
Answers
Suggested answer: B

Explanation:

AWS customers are responsible for enabling encryption of data at rest for Amazon Elastic Block Store (Amazon EBS). Amazon EBS encryption offers a simple encryption solution for your EBS volumes that does not require you to build, maintain, and secure your own key management infrastructure. You can encrypt both the boot and data volumes of your EC2 instances. You can use AWS Key Management Service (AWS KMS) customer master keys (CMKs) or your own CMKs to encrypt your volumes2.

Who is responsible for decommissioning end-of-life underlying storage devices that are used to host data on AWS?

A.
Customer
A.
Customer
Answers
B.
AWS
B.
AWS
Answers
C.
Account creator
C.
Account creator
Answers
D.
Auditing team
D.
Auditing team
Answers
Suggested answer: B

Explanation:

AWS is responsible for decommissioning end-of-life underlying storage devices that are used to host data on AWS. AWS follows strict and audited data destruction processes to ensure that customer data is not exposed to unauthorized individuals or devices when an AWS storage device reaches the end of its useful life. AWS uses techniques detailed in DoD 5220.22-M ("National Industrial Security Program Operating Manual") or NIST 800-88 ("Guidelines for Media Sanitization") to destroy data as part of the decommissioning process3.

A company wants to manage access and permissions for its third-party software as a service (SaaS) applications. The company wants to use a portal where end users can access assigned AWS accounts and AWS Cloud applications.

Which AWS service should the company use to meet these requirements?

A.
Amazon Cognito
A.
Amazon Cognito
Answers
B.
AWS 1AM Identity Center (AWS Single Sign-On)
B.
AWS 1AM Identity Center (AWS Single Sign-On)
Answers
C.
AWS Identity and Access Management (1AM)
C.
AWS Identity and Access Management (1AM)
Answers
D.
AWS Directory Service for Microsoft Active Directory
D.
AWS Directory Service for Microsoft Active Directory
Answers
Suggested answer: B

Explanation:

AWS IAM Identity Center (AWS Single Sign-On) is the AWS service that the company should use to meet the requirements of managing access and permissions for its third-party SaaS applications.

AWS Single Sign-On is a cloud-based service that makes it easy to centrally manage single sign-on (SSO) access to multiple AWS accounts and business applications. You can use AWS Single Sign-On to enable your users to sign in to a user portal with their existing corporate credentials and access all of their assigned accounts and applications from one place4.

Total 789 questions
Go to page: of 79