ExamGecko
Home Home / Amazon / CLF-C02

Amazon CLF-C02 Practice Test - Questions Answers, Page 24

Question list
Search
Search

List of questions

Search

Related questions











A company wants to create a chatbot and integrate the chatbot with its current web application.

Which AWS service will meet these requirements?

A.
AmazonKendra
A.
AmazonKendra
Answers
B.
Amazon Lex
B.
Amazon Lex
Answers
C.
AmazonTextract
C.
AmazonTextract
Answers
D.
AmazonPolly
D.
AmazonPolly
Answers
Suggested answer: B

Explanation:

The AWS service that will meet the requirements of the company that wants to create a chatbot and integrate the chatbot with its current web application is Amazon Lex. Amazon Lex is a service that helps customers build conversational interfaces using voice and text. The company can use Amazon Lex to create a chatbot that can understand natural language and respond to user requests, using the same deep learning technologies that power Amazon Alexa. Amazon Lex also provides easy integration with other AWS services, such as Amazon Comprehend, Amazon Polly, and AWS Lambda, as well as popular platforms, such as Facebook Messenger, Slack, and Twilio. Amazon Lex helps customers create engaging and interactive chatbots for their web applications. Amazon Kendra, Amazon Textract, and Amazon Polly are not the best services to use for this purpose. Amazon Kendra is a service that helps customers provide accurate and natural answers to natural language queries using machine learning. Amazon Textract is a service that helps customers extract text and data from scanned documents using optical character recognition (OCR) and machine learning. Amazon Polly is a service that helps customers convert text into lifelike speech using deep learning. These services are more useful for different types of natural language processing and generation tasks, rather than creating and integrating chatbots.

Which AWS service is used to temporarily provide federated security credentials to a__________

A.
Amazon GuardDuty
A.
Amazon GuardDuty
Answers
B.
AWS Simple Token Service (AWS STS)
B.
AWS Simple Token Service (AWS STS)
Answers
C.
AWS Secrets Manager
C.
AWS Secrets Manager
Answers
D.
AWS Certificate Manager
D.
AWS Certificate Manager
Answers
Suggested answer: B

Explanation:

The AWS service that is used to temporarily provide federated security credentials to a user is AWS Security Token Service (AWS STS). AWS STS is a service that enables customers to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that they authenticate (federated users). The company can use AWS STS to grant federated users access to AWS resources without creating permanent IAM users or sharing long-term credentials. AWS STS helps customers manage and secure access to their AWS resources for federated users. Amazon GuardDuty, AWS Secrets Manager, and AWS Certificate Manager are not the best services to use for this purpose. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior across the AWS accounts and resources. AWS Secrets Manager is a service that helps customers manage and rotate secrets, such as database credentials, API keys, and passwords. AWS Certificate Manager is a service that helps customers provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with AWS services and internal connected resources. These services are more useful for different types of security and compliance tasks, rather than providing temporary federated security credentials to a user.

A company wants to securely store Amazon RDS database credentials and automatically rotate user passwords periodically.

Which AWS service or capability will meet these requirements?

A.
Amazon S3
A.
Amazon S3
Answers
B.
AWS Systems Manager Parameter Store
B.
AWS Systems Manager Parameter Store
Answers
C.
AWS Secrets Manager
C.
AWS Secrets Manager
Answers
D.
AWS CloudTrail
D.
AWS CloudTrail
Answers
Suggested answer: C

Explanation:

AWS Secrets Manager is a service that helps you protect access to your applications, services, and IT resources. This service enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle1. Amazon S3 is a storage service that does not offer automatic rotation of credentials. AWS Systems Manager Parameter Store is a service that provides secure, hierarchical storage for configuration data management and secrets management2, but it does not offer automatic rotation of credentials. AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account3, but it does not store or rotate credentials.

A company has an application that runs periodically in an on-premises environment. The application runs for a few hours most days, but runs for 8 hours a day for a week at the end of each month.

Which AWS service or feature should be used to host the application in the AWS Cloud?

A.
Amazon EC2 Standard Reserved Instances
A.
Amazon EC2 Standard Reserved Instances
Answers
B.
Amazon EC2 On-Demand Instances
B.
Amazon EC2 On-Demand Instances
Answers
C.
AWS Wavelength
C.
AWS Wavelength
Answers
D.
Application Load Balancer
D.
Application Load Balancer
Answers
Suggested answer: B

Explanation:

Amazon EC2 On-Demand Instances are instances that you pay for by the second, with no long-term commitments or upfront payments4. This option is suitable for applications that have unpredictable or intermittent workloads, such as the one described in the question. Amazon EC2 Standard Reserved Instances are instances that you purchase for a one-year or three-year term, and pay a lower hourly rate compared to On-Demand Instances. This option is suitable for applications that have steady state or predictable usage. AWS Wavelength is a service that enables developers to build applications that deliver ultra-low latency to mobile devices and users by deploying AWS compute and storage at the edge of the 5G network. This option is not relevant for the application described in the question. Application Load Balancer is a type of load balancer that operates at the application layer and distributes traffic based on the content of the request. This option is not a service or feature to host the application, but rather to balance the traffic among multiple instances.

A company is reviewing the design of an application that will be migrated from on premises to a single Amazon EC2 instance.

What should the company do to make the application highly available?

A.
Provision additional EC2 instances in other Availability Zones.
A.
Provision additional EC2 instances in other Availability Zones.
Answers
B.
Configure an Application Load Balancer (ALB). Assign the EC2 instance as the ALB's target.
B.
Configure an Application Load Balancer (ALB). Assign the EC2 instance as the ALB's target.
Answers
C.
Use an Amazon Machine Image (AMI) to create the EC2 instance.
C.
Use an Amazon Machine Image (AMI) to create the EC2 instance.
Answers
D.
Provision the application by using an EC2 Spot Instance.
D.
Provision the application by using an EC2 Spot Instance.
Answers
Suggested answer: A

Explanation:

Provisioning additional EC2 instances in other Availability Zones is a way to make the application highly available, as it reduces the impact of failures and increases fault tolerance. Configuring an Application Load Balancer and assigning the EC2 instance as the ALB's target is a way to distribute traffic among multiple instances, but it does not make the application highly available if there is only one instance. Using an Amazon Machine Image to create the EC2 instance is a way to launch a virtual server with a preconfigured operating system and software, but it does not make the application highly available by itself. Provisioning the application by using an EC2 Spot Instance is a way to use spare EC2 capacity at up to 90% off the On-Demand price, but it does not make the application highly available, as Spot Instances can be interrupted by EC2 with a two-minute notification.

Which AWS service provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning (ML)?

A.
Amazon Kendra
A.
Amazon Kendra
Answers
B.
Amazon SageMaker
B.
Amazon SageMaker
Answers
C.
Amazon Augmented Al (Amazon A2I)
C.
Amazon Augmented Al (Amazon A2I)
Answers
D.
Amazon Polly
D.
Amazon Polly
Answers
Suggested answer: A

Explanation:

Amazon Kendra is a service that provides a highly accurate and easy-to-use enterprise search service that is powered by machine learning. Kendra delivers powerful natural language search capabilities to your websites and applications so your end users can more easily find the information they need within the vast amount of content spread across your company. Amazon SageMaker is a service that provides a fully managed platform for data scientists and developers to quickly and easily build, train, and deploy machine learning models at any scale. Amazon Augmented AI (Amazon A2I) is a service that makes it easy to build the workflows required for human review of ML predictions.

Amazon A2I brings human review to all developers, removing the undifferentiated heavy lifting associated with building human review systems or managing large numbers of human reviewers.

Amazon Polly is a service that turns text into lifelike speech, allowing you to create applications that talk, and build entirely new categories of speech-enabled products. None of these services provide an enterprise search service that is powered by machine learning.

A company provides a software as a service (SaaS) application. The company has a new customer that is based in a different country.

The new customer's data needs to be hosted in that country.

Which AWS service or infrastructure component should the company use to meet this requirement?

A.
AWS Shield
A.
AWS Shield
Answers
B.
Amazon S3 Object Lock
B.
Amazon S3 Object Lock
Answers
C.
AWS Regions
C.
AWS Regions
Answers
D.
Placement groups
D.
Placement groups
Answers
Suggested answer: C

Explanation:

AWS Regions are geographic areas around the world where AWS has clusters of data centers. Each AWS Region consists of multiple, isolated, and physically separate AZ's within a geographic area. By hosting the customer's data in a specific AWS Region, the company can meet the requirement of hosting the data in the customer's country. AWS Shield is a service that provides always-on detection and automatic inline mitigations that minimize application downtime and latency, so there is no need to engage AWS Support to benefit from DDoS protection. Amazon S3 Object Lock is a feature that allows you to store objects using a write-once-read-many (WORM) model. You can use it to prevent an object from being deleted or overwritten for a fixed amount of time or indefinitely.

Placement groups are logical grouping of instances within a single Availability Zone. Placement groups enable applications to participate in a low-latency, 10 Gbps network. None of these services or infrastructure components can help the company host the customer's data in a different country.

Which credential allows programmatic access to AWS resources for use from the AWS CLI or the AWS API?

A.
User name and password
A.
User name and password
Answers
B.
Access keys
B.
Access keys
Answers
C.
SSH public keys
C.
SSH public keys
Answers
D.
AWS Key Management Service (AWS KMS) keys
D.
AWS Key Management Service (AWS KMS) keys
Answers
Suggested answer: B

Explanation:

Access keys are long-term credentials that consist of an access key ID and a secret access key. You use access keys to sign programmatic requests that you make to AWS using the AWS CLI or AWS API1. User name and password are credentials that you use to sign in to the AWS Management Console or the AWS Management Console mobile app2. SSH public keys are credentials that you use to authenticate with EC2 instances that are launched from certain Linux AMIs3. AWS Key Management Service (AWS KMS) keys are customer master keys (CMKs) that you use to encrypt and decrypt your data and to control access to your data across AWS services and in your applications4.

A company has developed a distributed application that recovers gracefully from interruptions. The application periodically processes large volumes of data by using multiple Amazon EC2 instances.

The application is sometimes idle for months.

Which EC2 instance purchasing option is MOST cost-effective for this use case?

A.
Reserved Instances
A.
Reserved Instances
Answers
B.
Spot Instances
B.
Spot Instances
Answers
C.
Dedicated Instances
C.
Dedicated Instances
Answers
D.
On-Demand Instances
D.
On-Demand Instances
Answers
Suggested answer: B

Explanation:

Spot Instances are instances that use spare EC2 capacity that is available for up to 90% off the On-Demand price. Because Spot Instances can be interrupted by EC2 with two minutes of notification when EC2 needs the capacity back, you can use them for applications that have flexible start and end times, or that can withstand interruptions5. This option is most cost-effective for the use case described in the question. Reserved Instances are instances that you purchase for a one-year or three-year term, and pay a lower hourly rate compared to On-Demand Instances. This option is suitable for applications that have steady state or predictable usage. Dedicated Instances are instances that run on hardware that's dedicated to a single customer within an Amazon VPC. This option is suitable for applications that have stringent regulatory or compliance requirements. On-Demand Instances are instances that you pay for by the second, with no long-term commitments or upfront payments. This option is suitable for applications that have unpredictable or intermittent workloads.

A company is running workloads for multiple departments within a single VPC. The company needs to be able to bill each department for its resource usage.

Which action should the company take to accomplish this goal with the LEAST operational overhead?

A.
Add a department tag to each resource and configure cost allocation tags.
A.
Add a department tag to each resource and configure cost allocation tags.
Answers
B.
Move each department resource to its own VPC.
B.
Move each department resource to its own VPC.
Answers
C.
Move each department resource to its own AWS account.
C.
Move each department resource to its own AWS account.
Answers
D.
Use AWS Organizations to get a billing report for each department.
D.
Use AWS Organizations to get a billing report for each department.
Answers
Suggested answer: A

Explanation:

Adding a department tag to each resource and configuring cost allocation tags is an action that can help you accomplish the goal of billing each department for its resource usage with the least operational overhead. Tags are simple labels consisting of a key and an optional value that you can assign to AWS resources. You can use tags to organize your resources and track your AWS costs on a detailed level. Cost allocation tags enable you to track your AWS costs on a detailed level. After you activate cost allocation tags, AWS uses the cost allocation tags to organize your resource costs on your cost allocation report, to make it easier for you to categorize and track your AWS costs2. Moving each department resource to its own VPC or its own AWS account is an action that can help you isolate and control the resources for each department, but it would incur more operational overhead than using tags. Using AWS Organizations to get a billing report for each department is an action that can help you consolidate billing and payment across multiple AWS accounts, but it would not help you bill each department for its resource usage within a single VPC.

Total 789 questions
Go to page: of 79