ExamGecko
Home Home / Amazon / CLF-C02

Amazon CLF-C02 Practice Test - Questions Answers, Page 39

Question list
Search
Search

List of questions

Search

Related questions











Which option is an AWS Cloud Adoption Framework (AWS CAF) foundational capability for the operations perspective?

A.
Performance and capacity management
A.
Performance and capacity management
Answers
B.
Application portfolio management
B.
Application portfolio management
Answers
C.
Identity and access management
C.
Identity and access management
Answers
D.
Product management
D.
Product management
Answers
Suggested answer: C

Explanation:

Identity and access management is one of the foundational capabilities for the operations perspective of the AWS Cloud Adoption Framework (AWS CAF). It involves managing the identities, roles, permissions, and credentials of users and systems that interact with AWS resources.

Performance and capacity management is a capability for the platform perspective. Application portfolio management is a capability for the business perspective. Product management is a capability for the governance perspective.

A company needs to implement identity management for a fleet of mobile apps that are running in the AWS Cloud.

Which AWS service will meet this requirement?

A.
Amazon Cognito
A.
Amazon Cognito
Answers
B.
AWS Security Hub
B.
AWS Security Hub
Answers
C.
AWS Shield
C.
AWS Shield
Answers
D.
AWS WAF
D.
AWS WAF
Answers
Suggested answer: A

Explanation:

Amazon Cognito is a service that provides identity management for mobile and web applications, allowing users to sign up, sign in, and access AWS resources with different identity providers. AWS Security Hub is a service that provides a comprehensive view of the security posture of AWS accounts and resources. AWS Shield is a service that provides protection against distributed denial of service (DDoS) attacks. AWS WAF is a web application firewall that helps protect web applications from common web exploits.

Which AWS service or feature offers security for a VPC by acting as a firewall to control traffic in and out of subnets?

A.
AWS Security Hub
A.
AWS Security Hub
Answers
B.
Security groups
B.
Security groups
Answers
C.
Network ACL
C.
Network ACL
Answers
D.
AWSWAF
D.
AWSWAF
Answers
Suggested answer: C

Explanation:

A network access control list (network ACL) is a feature that acts as a firewall for controlling traffic in and out of one or more subnets in a virtual private cloud (VPC). AWS Security Hub is a service that provides a comprehensive view of the security posture of AWS accounts and resources. Security groups are features that act as firewalls for controlling traffic at the instance level. AWS WAF is a web application firewall that helps protect web applications from common web exploits.

An ecommerce company wants to provide relevant product recommendations to its customers. The recommendations will include products that are frequently purchased with other products that the customer already purchased. The recommendations also will include products of a specific color and products from the customer's favorite brand.

Which AWS service or feature should the company use to meet these requirements with the LEAST development effort?

A.
Amazon Comprehend
A.
Amazon Comprehend
Answers
B.
Amazon Forecast
B.
Amazon Forecast
Answers
C.
Amazon Personalize
C.
Amazon Personalize
Answers
D.
Amazon SageMaker Studio
D.
Amazon SageMaker Studio
Answers
Suggested answer: C

Explanation:

Amazon Personalize is a service that provides real-time personalized recommendations based on the user's behavior, preferences, and context. It can also incorporate metadata such as product color and brand to generate more relevant recommendations. Amazon Comprehend is a natural language processing (NLP) service that can analyze text for entities, sentiments, topics, and more. Amazon Forecast is a service that provides accurate time-series forecasting based on machine learning.

Amazon SageMaker Studio is a web-based integrated development environment (IDE) for machine learning.

Which AWS service or storage class provides low-cost, long-term data storage?

A.
Amazon S3 Glacier Deep Archive
A.
Amazon S3 Glacier Deep Archive
Answers
B.
AWS Snowball
B.
AWS Snowball
Answers
C.
Amazon MQ
C.
Amazon MQ
Answers
D.
AWS Storage Gateway
D.
AWS Storage Gateway
Answers
Suggested answer: A

Explanation:

Amazon S3 Glacier Deep Archive is a storage class within Amazon S3 that provides the lowest-cost, long-term data storage for data that is rarely accessed. AWS Snowball is a service that provides a physical device for transferring large amounts of data into and out of AWS. Amazon MQ is a service that provides managed message broker service for Apache ActiveMQ. AWS Storage Gateway is a service that provides hybrid cloud storage for on-premises applications.

Which AWS service or feature offers security for a VPC by acting as a firewall to control traffic in and out of subnets?

A.
AWS Security Hub
A.
AWS Security Hub
Answers
B.
Security groups
B.
Security groups
Answers
C.
Network ACL
C.
Network ACL
Answers
D.
AWSWAF
D.
AWSWAF
Answers
Suggested answer: C

Explanation:

A network access control list (network ACL) is a feature that acts as a firewall for controlling traffic in and out of one or more subnets in a virtual private cloud (VPC). Network ACLs can be configured with rules that allow or deny traffic based on the source and destination IP addresses, ports, and protocols1. AWS Security Hub is a service that provides a comprehensive view of the security posture of AWS accounts and resources2. Security groups are features that act as firewalls for controlling traffic at the instance level3. AWS WAF is a web application firewall that helps protect web applications from common web exploits4.

A company wants to create a set of custom dashboards to collect metrics to monitor its applications.

Which AWS service will meet these requirements?

A.
Amazon CloudWatch
A.
Amazon CloudWatch
Answers
B.
AWS X-Ray
B.
AWS X-Ray
Answers
C.
AWS Systems Manager
C.
AWS Systems Manager
Answers
D.
AWS CloudTrail
D.
AWS CloudTrail
Answers
Suggested answer: A

Explanation:

Amazon CloudWatch is a service that provides monitoring and observability for AWS resources and applications. Users can create custom dashboards to collect and visualize metrics, logs, alarms, and events from different sources5. AWS X-Ray is a service that provides distributed tracing and analysis for applications. AWS Systems Manager is a service that provides operational management for AWS resources and applications. AWS CloudTrail is a service that provides governance, compliance, and auditing for AWS account activity.

A company wants to migrate its workloads to AWS, but it lacks expertise in AWS Cloud computing.

Which AWS service or feature will help the company with its migration?

A.
AWS Trusted Advisor
A.
AWS Trusted Advisor
Answers
B.
AWS Consulting Partners
B.
AWS Consulting Partners
Answers
C.
AWS Artifacts
C.
AWS Artifacts
Answers
D.
AWS Managed Services
D.
AWS Managed Services
Answers
Suggested answer: D

Explanation:

AWS Managed Services is a service that provides operational management for AWS infrastructure and applications. It helps users migrate their workloads to AWS and provides ongoing support, security, compliance, and automation. AWS Trusted Advisor is a service that provides best practices and recommendations for cost optimization, performance, security, and fault tolerance. AWS Consulting Partners are professional services firms that help customers design, architect, build, migrate, and manage their workloads and applications on AWS. AWS Artifacts is a service that provides on-demand access to AWS compliance reports and select online agreements.

A company deployed an application on an Amazon EC2 instance. The application ran as expected for 6 months. In the past week, users have reported latency issues. A system administrator found that the CPU utilization was at 100%during business hours. The company wants a scalable solution to meet demand.

Which AWS service or feature should the company use to handle the load for its application during periods of high demand?

A.
Auto Scaling groups
A.
Auto Scaling groups
Answers
B.
AWS Global Accelerator
B.
AWS Global Accelerator
Answers
C.
Amazon Route 53
C.
Amazon Route 53
Answers
D.
An Elastic IP address
D.
An Elastic IP address
Answers
Suggested answer: A

Explanation:

Auto Scaling groups are a feature that allows users to automatically scale the number of Amazon EC2 instances up or down based on demand or a predefined schedule. Auto Scaling groups can help improve the performance and availability of applications by adjusting the capacity in response to traffic fluctuations1. AWS Global Accelerator is a service that improves the availability and performance of applications by routing traffic through AWS edge locations2. Amazon Route 53 is a service that provides scalable and reliable domain name system (DNS) service3. An Elastic IP address is a static IPv4 address that can be associated with an Amazon EC2 instance4.

Which VPC component provides a layer of security at the subnet level?

A.
Security groups
A.
Security groups
Answers
B.
Network ACLs
B.
Network ACLs
Answers
C.
NAT gateways
C.
NAT gateways
Answers
D.
Route tables
D.
Route tables
Answers
Suggested answer: B

Explanation:

Network ACLs are a feature that provide a layer of security at the subnet level by acting as a firewall to control traffic in and out of one or more subnets. Network ACLs can be configured with rules that allow or deny traffic based on the source and destination IP addresses, ports, and protocols5.

Security groups are a feature that provide a layer of security at the instance level by acting as a firewall to control traffic to and from one or more instances. Security groups can be configured with rules that allow or deny traffic based on the source and destination IP addresses, ports, protocols, and security groups. NAT gateways are a feature that enable instances in a private subnet to connect to the internet or other AWS services, but prevent the internet from initiating a connection with those instances. Route tables are a feature that determine where network traffic from a subnet or gateway is directed.

Total 789 questions
Go to page: of 79