ExamGecko
Home Home / Amazon / CLF-C02

Amazon CLF-C02 Practice Test - Questions Answers, Page 61

Question list
Search
Search

List of questions

Search

Related questions











Which AWS service provides command line access to AWS tools and resources directly (torn a web browser?

A.
AWS CIoudHSM
A.
AWS CIoudHSM
Answers
B.
AWS CloudShell
B.
AWS CloudShell
Answers
C.
Amazon Workspaces
C.
Amazon Workspaces
Answers
D.
AWS Cloud Map
D.
AWS Cloud Map
Answers
Suggested answer: B

Explanation:

AWS CloudShell is the service that provides command line access to AWS tools and resources directly from a web browser. AWS CloudShell is a browser-based shell that makes it easy to securely manage, explore, and interact with your AWS resources. It comes pre-authenticated with your console credentials and common development and administration tools are pre-installed, so no local installation or configuration is required. You can open AWS CloudShell from the AWS Management Console with a single click and start running commands and scripts using the AWS Command Line Interface (AWS CLI), Git, or SDKs.AWS CloudShell also provides persistent home directories with 1 GB of storage per AWS Region12. The other services do not provide command line access to AWS tools and resources directly from a web browser.AWS CloudHSM is a service that helps you meet corporate, contractual and regulatory compliance requirements for data security by using dedicated Hardware Security Module (HSM) appliances within the AWS Cloud3.Amazon WorkSpaces is a service that provides a fully managed, secure Desktop-as-a-Service (DaaS) solution that runs on AWS4.AWS Cloud Map is a service that makes it easy for your applications to discover and connect to each other using logical names and attributes5.Reference:AWS CloudShell,AWS CloudShell -- Command-Line Access to AWS Resources,AWS CloudHSM,Amazon WorkSpaces,AWS Cloud Map

A developer needs to maintain a development environment infrastructure and a production environment infrastructure in a repeatable fashion Which AWS service should the developer use to meet these requirements?

A.
AWS Ground Station
A.
AWS Ground Station
Answers
B.
AWS Shield
B.
AWS Shield
Answers
C.
AWS loT Device Defender
C.
AWS loT Device Defender
Answers
D.
AWS CloudFormation
D.
AWS CloudFormation
Answers
Suggested answer: D

Explanation:

AWS CloudFormation is a service that allows developers to model and provision their AWS infrastructure in a repeatable and declarative way, using code and templates. AWS CloudFormation enables developers to define the resources they need for their development and production environments, such as compute, storage, network, and application services, and automate their creation and configuration.AWS CloudFormation also provides features such as change sets, nested stacks, and rollback triggers to help developers manage and update their infrastructure safely and efficiently12.Reference:

AWS CloudFormation

What is AWS CloudFormation?

A company wants to migrate its applications to the AWS Cloud. The company plans to identity and prioritize any business transformation opportunities and evaluate its AWS Cloud readiness. Which AWS service or tool should the company use to meet these requirements?

A.
AWS Cloud Adoption Framework (AWS CAF)
A.
AWS Cloud Adoption Framework (AWS CAF)
Answers
B.
AWS Managed Services (AMS)
B.
AWS Managed Services (AMS)
Answers
C.
AWS Well-Architected Framework
C.
AWS Well-Architected Framework
Answers
D.
AWS Migration Hub
D.
AWS Migration Hub
Answers
Suggested answer: A

Explanation:

AWS Cloud Adoption Framework (AWS CAF) is a set of best practices, tools, and guidance that helps organizations get started with cloud technologies. AWS CAF helps organizations identify and prioritize transformation opportunities, evaluate and improve their cloud readiness, and iteratively evolve their transformation roadmap. AWS CAF groups its capabilities in six perspectives: Business, People, Governance, Platform, Security, and Operations.Each perspective comprises a set of capabilities that functionally related stakeholders own or manage in the cloud transformation journey1

AWS Managed Services (AMS) is a service that operates AWS infrastructure on behalf of customers, providing a secure AWS Landing Zone, features that help meet various compliance program requirements, a proven enterprise operating model, on-going cost optimization, and day-to-day infrastructure management.AMS does not help customers identify and prioritize business transformation opportunities or evaluate their cloud readiness2

AWS Well-Architected Framework is a set of six pillars and lenses that help cloud architects design and run workloads in the cloud. It provides a consistent approach for customers and AWS Partners to evaluate and implement designs that scale with their needs.AWS Well-Architected Framework helps customers understand the pros and cons of decisions they make while building systems on AWS, but it does not help them identify and prioritize business transformation opportunities3

AWS Migration Hub is a tool that lets customers discover, plan, and track their existing servers and applications for migration to AWS. It offers journey templates, cross-team collaboration, application and server discovery, strategy recommendations, orchestration and simple dashboard.AWS Migration Hub simplifies the migration and modernization process, but it does not help customers identify and prioritize business transformation opportunities or evaluate their cloud readiness4

A social media company wants to protect its web application from common web exploits such as SQL injections and cross-site scripting. Which AWS service will meet these requirements?

A.
Amazon Inspector
A.
Amazon Inspector
Answers
B.
AWS WAF
B.
AWS WAF
Answers
C.
Amazon GuardDuty
C.
Amazon GuardDuty
Answers
D.
Amazon CloudWatch
D.
Amazon CloudWatch
Answers
Suggested answer: B

Explanation:

AWS WAF is a web application firewall service that helps protect web applications from common web exploits that could affect availability, compromise security, or consume excessive resources. AWS WAF gives you control over which traffic to allow or block to your web applications by defining customizable web security rules.You can use AWS WAF to create rules that block common attack patterns, such as SQL injection or cross-site scripting, and rules that filter out specific traffic patterns you define1.AWS WAF also integrates with other AWS services, such as Amazon CloudFront, Amazon API Gateway, AWS AppSync, and AWS Load Balancer, to provide a comprehensive defense against web attacks2. Therefore, AWS WAF meets the requirements of the social media company, compared to the other options.

The other options are not suitable for the social media company's requirements, because:

Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices.However, Amazon Inspector does not provide a web application firewall service that can block malicious web requests3.

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts, workloads, and data stored in Amazon S3. Amazon GuardDuty analyzes and processes the following data sources: VPC Flow Logs, AWS CloudTrail event logs, and DNS logs.However, Amazon GuardDuty does not provide a web application firewall service that can block malicious web requests4.

Amazon CloudWatch is a monitoring and observability service that provides data and actionable insights to monitor your applications, respond to system-wide performance changes, optimize resource utilization, and get a unified view of operational health. Amazon CloudWatch collects monitoring and operational data in the form of logs, metrics, and events, and visualizes it using automated dashboards, alarms, and notifications. However, Amazon CloudWatch does not provide a web application firewall service that can block malicious web requests.

What Is AWS WAF? - AWS WAF, AWS Firewall Manager, and AWS Shield Advanced

AWS WAF Features - AWS WAF, AWS Firewall Manager, and AWS Shield Advanced

What Is Amazon Inspector? - Amazon Inspector

What Is Amazon GuardDuty? - Amazon GuardDuty

[What Is Amazon CloudWatch? - Amazon CloudWatch]

Which AWS services or features provide disaster recovery solutions for Amazon EC2 instances? (Select TWO.)

A.
EC2 Reserved Instances
A.
EC2 Reserved Instances
Answers
B.
EC2 Amazon Machine Images (AMIs)
B.
EC2 Amazon Machine Images (AMIs)
Answers
C.
Amazon Elastic Block Store (Amazon EBS) snapshots
C.
Amazon Elastic Block Store (Amazon EBS) snapshots
Answers
D.
AWS Shield
D.
AWS Shield
Answers
E.
Amazon GuardDuty
E.
Amazon GuardDuty
Answers
Suggested answer: B, C

Explanation:

The correct answer isBandC. EC2 Amazon Machine Images (AMIs) and Amazon Elastic Block Store (Amazon EBS) snapshots are two AWS services that provide disaster recovery solutions for Amazon EC2 instances.

EC2 AMIsare preconfigured templates that contain the software configuration and data required to launch an EC2 instance. You can create AMIs from your running EC2 instances and use them to launch new instances in the same or different AWS Regions.This way, you can quickly recover your EC2 instances in case of a disaster that affects your primary Region or Availability Zone1.

Amazon EBS snapshotsare incremental backups of your Amazon EBS volumes. You can create snapshots of your volumes and store them in Amazon S3, which is a highly durable and scalable storage service. You can use snapshots to restore your volumes to a previous point in time or to create new volumes from snapshots.Snapshots can also be copied across AWS Regions, enabling you to recover your data in another Region in case of a disaster2.

The other options are not directly related to disaster recovery for EC2 instances:

EC2 Reserved Instancesare a pricing model that allows you to reserve EC2 capacity for a specific period of time and receive a discount on the hourly charge.Reserved Instances do not provide any disaster recovery benefits, as they are only a billing option3.

AWS Shieldis a managed service that protects your AWS resources from distributed denial-of-service (DDoS) attacks. AWS Shield provides basic protection for all AWS customers at no additional charge, and advanced protection for customers who need higher levels of detection and mitigation.AWS Shield does not provide any disaster recovery benefits, as it is only a security service4.

Amazon GuardDutyis a threat detection service that monitors your AWS account and workloads for malicious or unauthorized activity. Amazon GuardDuty analyzes various data sources, such as AWS CloudTrail, Amazon VPC Flow Logs, and DNS logs, to identify potential threats and alert you via Amazon CloudWatch Events or AWS Lambda.Amazon GuardDuty does not provide any disaster recovery benefits, as it is only a monitoring service5.

A user wants to allow applications running on an Amazon EC2 instance to make calls to other AWS services. The access granted must be secure. Which AWS service or feature should be used?

A.
Security groups
A.
Security groups
Answers
B.
AWS Firewall Manager
B.
AWS Firewall Manager
Answers
C.
IAM roles
C.
IAM roles
Answers
D.
IAM user SSH keys
D.
IAM user SSH keys
Answers
Suggested answer: C

Explanation:

IAM roles are a secure way to grant permissions to applications running on an Amazon EC2 instance to make calls to other AWS services. IAM roles are entities that have specific permissions policies attached to them. You can create an IAM role and associate it with an EC2 instance when you launch it or later. The applications on the instance can then use the temporary credentials provided by the role to access AWS resources that the role allows.This way, you do not have to store any long-term credentials or access keys on the instance, which reduces the risk of compromise or misuse12.

The other options are not correct, because:

Security groups are virtual firewalls that control the inbound and outbound traffic for your EC2 instances.Security groups do not grant permissions to access other AWS services, but rather filter the network traffic based on rules that you define3.

AWS Firewall Manager is a service that helps you centrally configure and manage firewall rules across your accounts and resources. AWS Firewall Manager works with AWS WAF, AWS Shield Advanced, and Amazon VPC security groups.AWS Firewall Manager does not grant permissions to access other AWS services, but rather helps you enforce consistent security policies across your AWS infrastructure4.

IAM user SSH keys are credentials that allow you to connect to your EC2 instance using SSH.SSH keys do not grant permissions to access other AWS services, but rather authenticate your identity when you log in to your instance5.

Using an IAM role to grant permissions to applications running on Amazon EC2 instances - AWS Identity and Access Management

IAM roles for Amazon EC2 - Amazon Elastic Compute Cloud

Security groups for your VPC - Amazon Virtual Private Cloud

What is AWS Firewall Manager? - AWS Firewall Manager

Connecting to your Linux instance using SSH - Amazon Elastic Compute Cloud

A company needs to track the activity in its AWS accounts, and needs to know when an API call is made against its AWS resources. Which AWS tool or service can be used to meet these requirements?

A.
Amazon CloudWatch
A.
Amazon CloudWatch
Answers
B.
Amazon Inspector
B.
Amazon Inspector
Answers
C.
AWS CloudTrail
C.
AWS CloudTrail
Answers
D.
AWS IAM
D.
AWS IAM
Answers
Suggested answer: C

Explanation:

AWS CloudTrail is the service that can be used to meet these requirements. AWS CloudTrail is a service that records AWS API calls for your account and delivers log files to you.The recorded information includes the identity of the API caller, the time of the API call, the source IP address of the API caller, the request parameters, and the response elements returned by the AWS service1. You can use CloudTrail to track the activity in your AWS accounts, such as who made an API call, when it was made, and what resources were affected.You can also use CloudTrail to monitor the compliance, security, and governance of your AWS environment2. The other services are not designed to track the activity and API calls in your AWS accounts. Amazon CloudWatch is a service that monitors and collects metrics, logs, and events from your AWS resources and applications.You can use CloudWatch to set alarms, visualize data, and automate actions based on predefined thresholds or rules3. Amazon Inspector is a service that helps you improve the security and compliance of your applications running on AWS.Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices4. AWS IAM is a service that enables you to manage access to AWS services and resources securely. IAM allows you to create and manage AWS users and groups, and use permissions to allow and deny their access to AWS resources.Reference:AWS CloudTrail,AWS CloudTrail -- Capture AWS API Activity,Amazon CloudWatch,Amazon Inspector, [AWS IAM]

A systems administrator created a new 1AM user for a developer and assigned the user an access key instead of a user name and password. What is the access key used for?

A.
To access the AWS account as the AWS account root user
A.
To access the AWS account as the AWS account root user
Answers
B.
To access the AWS account through the AWS Management Console
B.
To access the AWS account through the AWS Management Console
Answers
C.
To access the AWS account through a CLI
C.
To access the AWS account through a CLI
Answers
D.
To access all of a company's AWS accounts
D.
To access all of a company's AWS accounts
Answers
Suggested answer: C

Explanation:

An access key is a pair of long-term credentials that consists of an access key ID and a secret access key. An access key is used to sign programmatic requests to the AWS CLI or AWS API (directly or using the AWS SDK).An access key allows a user to access the AWS account through a CLI, which is a tool that enables users to interact with AWS services using commands in a terminal or a script12.

The other options are not correct, because:

To access the AWS account as the AWS account root user, a user needs the email address and password associated with the account. The root user has complete access to all AWS resources and services in the account.However, it is not recommended to use the root user for everyday tasks3.

To access the AWS account through the AWS Management Console, a user needs a user name and password.The console is a web-based interface that allows users to manage their AWS resources and services using a graphical user interface4.

To access all of a company's AWS accounts, a user needs to use AWS Organizations, which is a service that enables users to centrally manage and govern multiple AWS accounts.AWS Organizations allows users to create groups of accounts and apply policies to them5.

Managing access keys for IAM users - AWS Identity and Access Management

What Is the AWS Command Line Interface? - AWS Command Line Interface

AWS account root user - AWS Identity and Access Management

What Is the AWS Management Console? - AWS Management Console

What Is AWS Organizations? - AWS Organizations

Which AWS service or feature provides log information of the inbound and outbound traffic on network interfaces in a VPC?

A.
Amazon CloudWatch Logs
A.
Amazon CloudWatch Logs
Answers
B.
AWS CloudTrail
B.
AWS CloudTrail
Answers
C.
VPC Flow Logs
C.
VPC Flow Logs
Answers
D.
AWS Identity and Access Management (IAM)
D.
AWS Identity and Access Management (IAM)
Answers
Suggested answer: C

Explanation:

VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC. Flow log data can be published to the following locations: Amazon CloudWatch Logs, Amazon S3, or Amazon Kinesis Data Firehose.You can use VPC Flow Logs to monitor network traffic, diagnose security issues, troubleshoot connectivity problems, and perform network forensics1.Reference:

Logging IP traffic using VPC Flow Logs - Amazon Virtual Private Cloud

Which tool should a developer use lo integrate AWS service features directly into an application?

A.
AWS Software Development Kit
A.
AWS Software Development Kit
Answers
B.
AWS CodeDeploy
B.
AWS CodeDeploy
Answers
C.
AWS Lambda
C.
AWS Lambda
Answers
D.
AWS Batch
D.
AWS Batch
Answers
Suggested answer: A

Explanation:

AWS Software Development Kit (SDK) is a set of platform-specific tools for developers that let them integrate AWS service features directly into their applications. AWS SDKs provide libraries, code samples, documentation, and other resources to help developers write code that interacts with AWS APIs. AWS SDKs support various programming languages, such as Java, Python, Ruby, .NET, Node.js, Go, and more. AWS SDKs make it easier for developers to access AWS services, such as Amazon S3, Amazon EC2, Amazon DynamoDB, AWS Lambda, and more, from their applications.AWS SDKs also handle tasks such as authentication, error handling, retries, and data serialization, so developers can focus on their application logic.

Total 789 questions
Go to page: of 79