ExamGecko
Home Home / Amazon / CLF-C02

Amazon CLF-C02 Practice Test - Questions Answers, Page 45

Question list
Search
Search

List of questions

Search

Related questions











A company wants to implement controls (guardrails) in a newly created AWS Control Tower landing zone.

Which AWS services or features can the company use to create and define these controls (guardrails)? (Select TWO.)

A.
AWS Config
A.
AWS Config
Answers
B.
Service control policies (SCPs)
B.
Service control policies (SCPs)
Answers
C.
Amazon GuardDuty
C.
Amazon GuardDuty
Answers
D.
AWS Identity and Access Management (1AM)
D.
AWS Identity and Access Management (1AM)
Answers
E.
Security groups
E.
Security groups
Answers
Suggested answer: A, B

Explanation:

AWS Config and service control policies (SCPs) are AWS services or features that the company can use to create and define controls (guardrails) in a newly created AWS Control Tower landing zone.

AWS Config is a service that enables users to assess, audit, and evaluate the configurations of their AWS resources. It can be used to create rules that check for compliance with the desired configurations and report any deviations. AWS Control Tower provides a set of predefined AWS Config rules that can be enabled as guardrails to enforce compliance across the landing zone1.

Service control policies (SCPs) are a type of policy that can be used to manage permissions in AWS Organizations. They can be used to restrict the actions that the users and roles in the member accounts can perform on the AWS resources. AWS Control Tower provides a set of predefined SCPs that can be enabled as guardrails to prevent access to certain services or regions across the landing zone2. Amazon GuardDuty is a service that provides intelligent threat detection and continuous monitoring for AWS accounts and resources. It is not a feature that can be used to create and define controls (guardrails) in a landing zone. AWS Identity and Access Management (IAM) is a service that allows users to manage access to AWS resources and services. It can be used to create users, groups, roles, and policies that control who can do what in AWS. It is not a feature that can be used to create and define controls (guardrails) in a landing zone. Security groups are virtual firewalls that control the inbound and outbound traffic for Amazon EC2 instances. They can be used to allow or deny access to an EC2 instance based on the port, protocol, and source or destination. They are not a feature that can be used to create and define controls (guardrails) in a landing zone.

A developer wants to use an Amazon S3 bucket to store application logs that contain sensitive data.

Which AWS service or feature should the developer use to restrict read and write access to the S3 bucket?

A.
Security groups
A.
Security groups
Answers
B.
Amazon CloudWatch
B.
Amazon CloudWatch
Answers
C.
AWS CloudTrail
C.
AWS CloudTrail
Answers
D.
ACLs
D.
ACLs
Answers
Suggested answer: D

Explanation:

ACLs are an AWS service or feature that the developer can use to restrict read and write access to the S3 bucket. ACLs are access control lists that grant basic permissions to other AWS accounts or predefined groups. They can be used to grant read or write access to an S3 bucket or an object3.

Security groups are virtual firewalls that control the inbound and outbound traffic for Amazon EC2 instances. They are not a service or feature that can be used to restrict access to an S3 bucket.

Amazon CloudWatch is a service that provides monitoring and observability for AWS resources and applications. It can be used to collect and analyze metrics, logs, events, and alarms. It is not a service or feature that can be used to restrict access to an S3 bucket. AWS CloudTrail is a service that provides governance, compliance, and audit for AWS accounts and resources. It can be used to track and record the API calls and user activity in AWS. It is not a service or feature that can be used to restrict access to an S3 bucket.

Which AWS service or tool helps companies measure the environmental impact of their AWS usage?

A.
AWS customer carbon footprint tool
A.
AWS customer carbon footprint tool
Answers
B.
AWS Compute Optimizer
B.
AWS Compute Optimizer
Answers
C.
Sustainability pillar
C.
Sustainability pillar
Answers
D.
OS-Climate (Open Source Climate Data Commons)
D.
OS-Climate (Open Source Climate Data Commons)
Answers
Suggested answer: A

Explanation:

AWS customer carbon footprint tool is an AWS service or tool that helps companies measure the environmental impact of their AWS usage. It allows users to estimate the carbon emissions associated with their AWS resources and services, such as EC2, S3, and Lambda. It also provides recommendations and best practices to reduce the carbon footprint and improve the sustainability of their AWS workloads4. AWS Compute Optimizer is an AWS service that helps users optimize the performance and cost of their EC2 instances and Auto Scaling groups. It provides recommendations for optimal instance types, sizes, and configurations based on the workload characteristics and utilization metrics. It does not help users measure the environmental impact of their AWS usage.

Sustainability pillar is a concept that refers to the ability of a system to operate in an environmentally friendly and socially responsible manner. It is not an AWS service or tool that helps users measure the environmental impact of their AWS usage. OS-Climate (Open Source Climate Data Commons) is an initiative that aims to provide open source data, tools, and platforms to accelerate climate action and innovation. It is not an AWS service or tool that helps users measure the environmental impact of their AWS usage.

Which option is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF)?

A.
Sustainability
A.
Sustainability
Answers
B.
Operations
B.
Operations
Answers
C.
Performance efficiency
C.
Performance efficiency
Answers
D.
Reliability
D.
Reliability
Answers
Suggested answer: B

Explanation:

Operations is an option that is a perspective that includes foundational capabilities of the AWS Cloud Adoption Framework (AWS CAF). Operations is one of the six perspectives of the AWS CAF, along with business, people, governance, platform, and security. Operations focuses on the processes and procedures to support the ongoing management and maintenance of the cloud-based IT assets. It covers topics such as monitoring, backup and recovery, change management, incident management, and automation5. Sustainability is not a perspective of the AWS CAF, but a concept that refers to the ability of a system to operate in an environmentally friendly and socially responsible manner.

Performance efficiency is not a perspective of the AWS CAF, but a pillar of the AWS Well-Architected Framework. It focuses on using the right resources and services for the workload, monitoring performance, and continuously improving the efficiency of the solution. Reliability is not a perspective of the AWS CAF, but a pillar of the AWS Well-Architected Framework. It focuses on the ability of a system to recover from infrastructure or service disruptions, dynamically acquire computing resources to meet demand, and mitigate disruptions such as misconfigurations or transient network issues.

Which of the following is a benefit of decoupling an AWS Cloud architecture?

A.
Reduced latency
A.
Reduced latency
Answers
B.
Fewer components to manage
B.
Fewer components to manage
Answers
C.
Decreased costs
C.
Decreased costs
Answers
D.
Ability to upgrade components independently
D.
Ability to upgrade components independently
Answers
Suggested answer: D

Explanation:


Which AWS service uses AWS Compute Optimizer to provide sizing recommendations based on workload metrics?

A.
Amazon EC2
A.
Amazon EC2
Answers
B.
Amazon RDS
B.
Amazon RDS
Answers
C.
Amazon Lightsail
C.
Amazon Lightsail
Answers
D.
AWS Step Functions
D.
AWS Step Functions
Answers
Suggested answer: A

Explanation:

Amazon EC2 is a web service that provides secure, resizable compute capacity in the cloud. It allows you to launch virtual servers, called instances, with different configurations of CPU, memory, storage, and networking resources. AWS Compute Optimizer analyzes the specifications and utilization metrics of your Amazon EC2 instances and generates recommendations for optimal instance types that can reduce costs and improve performance.You can view the recommendations on the AWS Compute Optimizer console or the Amazon EC2 console12.

Amazon RDS, Amazon Lightsail, and AWS Step Functions are not supported by AWS Compute Optimizer. Amazon RDS is a managed relational database service that lets you set up, operate, and scale a relational database in the cloud. Amazon Lightsail is an easy-to-use cloud platform that offers everything you need to build an application or website, plus a cost-effective, monthly plan.AWS Step Functions lets you coordinate multiple AWS services into serverless workflows so you can build and update apps quickly3.

Which capabilities are in the platform perspective of the AWS Cloud Adoption Framework (AWS CAF)? (Select TWO.)

A.
Performance and capacity management
A.
Performance and capacity management
Answers
B.
Data engineering
B.
Data engineering
Answers
C.
Continuous integration and continuous delivery (CI/CD)
C.
Continuous integration and continuous delivery (CI/CD)
Answers
D.
Infrastructure protection
D.
Infrastructure protection
Answers
E.
Change and release management
E.
Change and release management
Answers
Suggested answer: B, C

Explanation:

These are two of the seven capabilities that are in the platform perspective of the AWS Cloud Adoption Framework (AWS CAF).The platform perspective helps you build an enterprise-grade, scalable, hybrid cloud platform, modernize existing workloads, and implement new cloud-native solutions1. The other five capabilities are:

Platform architecture -- Establish and maintain guidelines, principles, patterns, and guardrails for your cloud environment.

Platform engineering -- Build a compliant multi-account cloud environment with enhanced security features, and packaged, reusable cloud products.

Platform operations -- Manage and optimize your cloud environment with automation, monitoring, and incident response.

Application development -- Develop and deploy cloud-native applications using modern architectures and best practices.

Application migration -- Migrate your existing applications to the cloud using proven methodologies and tools.

Performance and capacity management, infrastructure protection, and change and release management are not capabilities of the platform perspective.They are part of the operations perspective, which helps you achieve operational excellence in the cloud2. The operations perspective comprises six capabilities:

Performance and capacity management -- Monitor and optimize the performance and capacity of your cloud workloads.

Infrastructure protection -- Protect your cloud infrastructure from unauthorized access, malicious attacks, and data breaches.

Change and release management -- Manage changes and releases to your cloud workloads using automation and governance.

Configuration management -- Manage the configuration of your cloud resources and applications using automation and version control.

Incident management -- Respond to incidents affecting your cloud workloads using best practices and tools.

Service continuity management -- Ensure the availability and resilience of your cloud workloads using backup, recovery, and disaster recovery strategies.

How does the AWS Enterprise Support Concierge team help users?

A.
Supporting application development
A.
Supporting application development
Answers
B.
Providing architecture guidance
B.
Providing architecture guidance
Answers
C.
Answering billing and account inquiries
C.
Answering billing and account inquiries
Answers
D.
Answering questions regarding technical support cases
D.
Answering questions regarding technical support cases
Answers
Suggested answer: C

Explanation:

The AWS Enterprise Support Concierge team is a group of billing and account experts who specialize in working with enterprise customers. They can help customers with questions about billing, account management, cost optimization, and other non-technical issues. They can also assist customers with navigating and optimizing their AWS environment, such as setting up consolidated billing, applying for service limit increases, or requesting refunds.

AWS Support Plan Comparison

AWS Enterprise Support Plan

Answer Explained: Which AWS Support plan provides access to AWS Concierge Support team for account assistance?

A company wants to make an upfront commitment for continued use of its production Amazon EC2 instances in exchange for a reduced overall cost.

Which pricing options meet these requirements with the LOWEST cost? (Select TWO.)

A.
Spot Instances
A.
Spot Instances
Answers
B.
On-Demand Instances
B.
On-Demand Instances
Answers
C.
Reserved Instances
C.
Reserved Instances
Answers
D.
Savings Plans
D.
Savings Plans
Answers
E.
Dedicated Hosts
E.
Dedicated Hosts
Answers
Suggested answer: C, D

Explanation:

Reserved Instances (RIs) are a pricing model that allows you to reserve EC2 instances for a specified period of time (one or three years) and receive a significant discount compared to On-Demand pricing. RIs are suitable for workloads that have predictable usage patterns and require a long-term commitment. You can choose between three payment options: All Upfront, Partial Upfront, or No Upfront.The more you pay upfront, the greater the discount1.

Savings Plans are a flexible pricing model that can help you reduce your EC2 costs by up to 72% compared to On-Demand pricing, in exchange for a commitment to a consistent amount of usage (measured in $/hour) for a one or three year term. Savings Plans apply to usage across EC2, AWS Lambda, and AWS Fargate. You can choose between two types of Savings Plans: Compute Savings Plans and EC2 Instance Savings Plans. Compute Savings Plans offer the most flexibility and apply to any instance family, size, OS, tenancy, or region.EC2 Instance Savings Plans offer the highest discount and apply to a specific instance family within a region2.

Spot Instances are a pricing model that allows you to bid for unused EC2 capacity in the AWS cloud and are available at a discount of up to 90% compared to On-Demand pricing. Spot Instances are suitable for fault-tolerant or stateless workloads that can run on heterogeneous hardware and have flexible start and end times.However, Spot Instances are not guaranteed and can be interrupted by AWS at any time if the demand for capacity increases or your bid price is lower than the current Spot price3.

On-Demand Instances are a pricing model that allows you to pay for compute capacity by the hour or second with no long-term commitments. On-Demand Instances are suitable for short-term, spiky, or unpredictable workloads that cannot be interrupted, or for applications that are being developed or tested on EC2 for the first time.However, On-Demand Instances are the most expensive option among the four pricing models4.

Dedicated Hosts are physical EC2 servers fully dedicated for your use. Dedicated Hosts can help you reduce costs by allowing you to use your existing server-bound software licenses, such as Windows Server, SQL Server, and SUSE Linux Enterprise Server. Dedicated Hosts can be purchased On-Demand or as part of Savings Plans. Dedicated Hosts are suitable for workloads that need to run on dedicated physical servers or have strict licensing requirements. However, Dedicated Hosts are not the lowest cost option among the four pricing models.

A company wants a time-series database service that makes it easier to store and analyze trillions of events each day.

Which AWS service will meet this requirement?

A.
Amazon Neptune
A.
Amazon Neptune
Answers
B.
Amazon Timestream
B.
Amazon Timestream
Answers
C.
Amazon Forecast
C.
Amazon Forecast
Answers
D.
Amazon DocumentDB (with MongoDB compatibility)
D.
Amazon DocumentDB (with MongoDB compatibility)
Answers
Suggested answer: B

Explanation:

Amazon Timestream is a fast, scalable, and serverless time-series database service for IoT and other operational applications that makes it easy to store and analyze trillions of events per day up to 1,000 times faster and at as little as 1/10th the cost of relational databases1.Amazon Timestream saves you time and cost in managing the lifecycle of time series data, and its purpose-built query engine lets you access and analyze recent and historical data together with a single query1.Amazon Timestream has built-in time series analytics functions, helping you identify trends and patterns in near real time1.

The other options are not suitable for storing and analyzing trillions of events per day. Amazon Neptune is a graph database service that supports highly connected data sets. Amazon Forecast is a machine learning service that generates accurate forecasts based on historical dat a. Amazon DocumentDB (with MongoDB compatibility) is a document database service that supports MongoDB workloads.

1: Time Series Database -- Amazon Timestream -- Amazon Web Services

Total 789 questions
Go to page: of 79