ExamGecko
Home Home / Amazon / CLF-C02

Amazon CLF-C02 Practice Test - Questions Answers, Page 8

Question list
Search
Search

List of questions

Search

Related questions











A company is designing an identity access management solution for an application. The company wants users to be able to use their social media, email, or online shopping accounts to access the application.

Which AWS service provides this functionality?

A.
AWS 1AM Identity Center (AWS Single Sign-On)
A.
AWS 1AM Identity Center (AWS Single Sign-On)
Answers
B.
AWS Config
B.
AWS Config
Answers
C.
Amazon Cognito
C.
Amazon Cognito
Answers
D.
AWS Identity and Access Management (1AM)
D.
AWS Identity and Access Management (1AM)
Answers
Suggested answer: C

Explanation:

The correct answer is C because Amazon Cognito provides identity federation and user authentication for web and mobile applications. Amazon Cognito allows users to sign in with their social media, email, or online shopping accounts. The other options are incorrect because they do not provide identity federation or user authentication. AWS 1AM Identity Center (AWS Single Sign-On) is a service that enables users to access multiple AWS accounts and applications with a single sign-on experience. AWS Config is a service that enables users to assess, audit, and evaluate the configurations of their AWS resources. AWS Identity and Access Management (1AM) is a service that enables users to manage access to AWS resources using users, groups, roles, and policies.

Reference: Amazon Cognito FAQs

Which AWS service aggregates, organizes, and prioritizes security alerts and findings from multiple AWS services?

A.
Amazon Detective
A.
Amazon Detective
Answers
B.
Amazon Inspector
B.
Amazon Inspector
Answers
C.
Amazon Macie
C.
Amazon Macie
Answers
D.
AWS Security Hub
D.
AWS Security Hub
Answers
Suggested answer: D

Explanation:

The correct answer is D because AWS Security Hub is a service that aggregates, organizes, and prioritizes security alerts and findings from multiple AWS services, such as Amazon GuardDuty, Amazon Inspector, Amazon Macie, AWS Firewall Manager, and AWS IAM Access Analyzer. The other options are incorrect because they are not services that aggregate security alerts and findings from multiple AWS services. Amazon Detective is a service that helps users analyze and visualize security data to investigate and remediate potential issues. Amazon Inspector is a service that helps users find security vulnerabilities and deviations from best practices in their Amazon EC2 instances.

Amazon Macie is a service that helps users discover, classify, and protect sensitive data stored in Amazon S3. Reference: AWS Security Hub FAQs

Which of the following are advantages of the AWS Cloud? (Select TWO.)

A.
Trade variable expenses for capital expenses
A.
Trade variable expenses for capital expenses
Answers
B.
High economies of scale
B.
High economies of scale
Answers
C.
Launch globally in minutes
C.
Launch globally in minutes
Answers
D.
Focus on managing hardware infrastructure
D.
Focus on managing hardware infrastructure
Answers
E.
Overprovision to ensure capacity
E.
Overprovision to ensure capacity
Answers
Suggested answer: B, C

Explanation:

The correct answers are B and C because they are advantages of the AWS Cloud. High economies of scale means that AWS can achieve lower variable costs than customers can get on their own. Launch globally in minutes means that AWS has a global infrastructure that allows customers to deploy their applications and data across multiple regions and availability zones. The other options are incorrect because they are not advantages of the AWS Cloud. Trade variable expenses for capital expenses means that customers have to invest heavily in data centers and servers before they know how they will use them. Focus on managing hardware infrastructure means that customers have to spend time and money on maintaining and upgrading their physical resources. Overprovision to ensure capacity means that customers have to pay for more resources than they actually need to avoid performance issues. Reference: What is Cloud Computing?

Which AWS service is a key-value database that provides sub-millisecond latency on a large scale?

A.
Amazon DynamoDB
A.
Amazon DynamoDB
Answers
B.
Amazon Aurora
B.
Amazon Aurora
Answers
C.
Amazon DocumentDB (with MongoDB compatibility)
C.
Amazon DocumentDB (with MongoDB compatibility)
Answers
D.
Amazon Neptune
D.
Amazon Neptune
Answers
Suggested answer: A

Explanation:

The correct answer is A because Amazon DynamoDB is a key-value database that provides submillisecond latency on a large scale. Amazon DynamoDB is a fully managed, serverless, and scalable NoSQL database service that supports both key-value and document data models. The other options are incorrect because they are not key-value databases. Amazon Aurora is a relational database that is compatible with MySQL and PostgreSQL. Amazon DocumentDB (with MongoDB compatibility) is a document database that is compatible with MongoDB. Amazon Neptune is a graph database that supports property graph and RDF models. Reference: Amazon DynamoDB FAQs

Which AWS service or tool provides users with the ability to monitor AWS service quotas?

A.
AWS CloudTrail
A.
AWS CloudTrail
Answers
B.
AWS Cost and Usage Reports
B.
AWS Cost and Usage Reports
Answers
C.
AWS Trusted Advisor
C.
AWS Trusted Advisor
Answers
D.
AWS Budgets
D.
AWS Budgets
Answers
Suggested answer: C

Explanation:

The correct answer is C because AWS Trusted Advisor is an AWS service or tool that provides users with the ability to monitor AWS service quotas. AWS Trusted Advisor is an online tool that provides users with real-time guidance to help them provision their resources following AWS best practices.

One of the categories of checks that AWS Trusted Advisor performs is service limits, which monitors the usage of each AWS service and alerts users when they are close to reaching the default limit. The other options are incorrect because they are not AWS services or tools that provide users with the ability to monitor AWS service quotas. AWS CloudTrail is a service that enables users to track user activity and API usage across their AWS account. AWS Cost and Usage Reports is a tool that enables users to access comprehensive information about their AWS costs and usage. AWS Budgets is a tool that enables users to plan their service usage, costs, and reservations. Reference: [AWS Trusted Advisor FAQs]

Which of the following is an advantage of AWS Cloud computing?

A.
Trade security for elasticity.
A.
Trade security for elasticity.
Answers
B.
Trade operational excellence for agility.
B.
Trade operational excellence for agility.
Answers
C.
Trade fixed expenses for variable expenses.
C.
Trade fixed expenses for variable expenses.
Answers
D.
Trade elasticity for performance.
D.
Trade elasticity for performance.
Answers
Suggested answer: C

Explanation:

The correct answer is C because AWS Cloud computing allows customers to trade fixed expenses for variable expenses. This means that customers only pay for the resources they use, and can scale up or down as needed. The other options are incorrect because they are not advantages of AWS Cloud computing. Trade security for elasticity means that customers have to compromise on the protection of their data and applications in order to adjust their capacity quickly. Trade operational excellence for agility means that customers have to sacrifice the quality and reliability of their operations in order to respond to changing needs faster. Trade elasticity for performance means that customers have to limit their ability to scale up or down in order to achieve higher speed and efficiency.

Reference: What is Cloud Computing?

A company is running applications on Amazon EC2 instances in the same AWS account for several different projects. The company wants to track the infrastructure costs for each of the projects separately. The company must conduct this tracking with the least possible impact to the existing infrastructure and with no additional cost.

What should the company do to meet these requirements?

A.
Use a different EC2 instance type for each project.
A.
Use a different EC2 instance type for each project.
Answers
B.
Publish project-specific custom Amazon CloudWatch metrics for each application.
B.
Publish project-specific custom Amazon CloudWatch metrics for each application.
Answers
C.
Deploy EC2 instances for each project in a separate AWS account.
C.
Deploy EC2 instances for each project in a separate AWS account.
Answers
D.
Use cost allocation tags with values that are specific to each project.
D.
Use cost allocation tags with values that are specific to each project.
Answers
Suggested answer: D

Explanation:

The correct answer is D because cost allocation tags are a way to track the infrastructure costs for each of the projects separately. Cost allocation tags are key-value pairs that can be attached to AWS resources, such as EC2 instances, and used to categorize and group them for billing purposes. The other options are incorrect because they do not meet the requirements of the question. Use a different EC2 instance type for each project does not help to track the costs for each project, and may impact the performance and compatibility of the applications. Publish project-specific custom Amazon CloudWatch metrics for each application does not help to track the costs for each project, and may incur additional charges for using CloudWatch. Deploy EC2 instances for each project in a separate AWS account does help to track the costs for each project, but it impacts the existing infrastructure and incurs additional charges for using multiple accounts. Reference: Using Cost Allocation Tags

A company has an online shopping website and wants to store customers' credit card dat a. The company must meet Payment Card Industry (PCI) standards.

Which service can the company use to access AWS compliance documentation?

A.
Amazon Cloud Directory
A.
Amazon Cloud Directory
Answers
B.
AWS Artifact
B.
AWS Artifact
Answers
C.
AWS Trusted Advisor
C.
AWS Trusted Advisor
Answers
D.
Amazon Inspector
D.
Amazon Inspector
Answers
Suggested answer: B

Explanation:

The correct answer is B because AWS Artifact is a service that provides access to AWS compliance documentation, such as audit reports, security certifications, and agreements. AWS Artifact allows customers to download, review, and accept the documents that are relevant to their use of AWS services. The other options are incorrect because they are not services that provide access to AWS compliance documentation. Amazon Cloud Directory is a service that enables customers to create flexible cloud-native directories for organizing hierarchies of data. AWS Trusted Advisor is a service that provides real-time guidance to help customers follow AWS best practices for security, performance, cost optimization, and fault tolerance. Amazon Inspector is a service that helps customers find security vulnerabilities and deviations from best practices in their Amazon EC2 instances. Reference: [AWS Artifact FAQs]

Which of the following are components of an AWS Site-to-Site VPN connection? (Select TWO.)

A.
AWS Storage Gateway
A.
AWS Storage Gateway
Answers
B.
Virtual private gateway
B.
Virtual private gateway
Answers
C.
NAT gateway
C.
NAT gateway
Answers
D.
Customer gateway
D.
Customer gateway
Answers
E.
Internet gateway
E.
Internet gateway
Answers
Suggested answer: B, D

Explanation:

The correct answers are B and D because a virtual private gateway and a customer gateway are components of an AWS Site-to-Site VPN connection. A virtual private gateway is the AWS side of the VPN connection that attaches to the customer's VPC. A customer gateway is the customer side of the VPN connection that resides in the customer's network. The other options are incorrect because they are not components of an AWS Site-to-Site VPN connection. AWS Storage Gateway is a service that connects on-premises software applications with cloud-based storage. NAT gateway is a service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances. Internet gateway is a service that enables communication between instances in a VPC and the internet. Reference: [What is AWS Siteto-Site VPN?]

A company runs thousands of simultaneous simulations using AWS Batch. Each simulation is stateless, is fault tolerant, and runs for up to 3 hours.

Which pricing model enables the company to optimize costs and meet these requirements?

A.
Reserved Instances
A.
Reserved Instances
Answers
B.
Spot Instances
B.
Spot Instances
Answers
C.
On-Demand Instances
C.
On-Demand Instances
Answers
D.
Dedicated Instances
D.
Dedicated Instances
Answers
Suggested answer: B

Explanation:

The correct answer is B because Spot Instances enable the company to optimize costs and meet the requirements. Spot Instances are spare EC2 instances that are available at up to 90% discount compared to On-Demand prices. Spot Instances are suitable for stateless, fault-tolerant, and flexible applications that can run for any duration. The other options are incorrect because they do not enable the company to optimize costs and meet the requirements. Reserved Instances are EC2 instances that are reserved for a specific period of time (one or three years) in exchange for a lower hourly rate. Reserved Instances are suitable for steady-state or predictable workloads that run for a long duration. On-Demand Instances are EC2 instances that are launched and billed at a fixed hourly rate. On-Demand Instances are suitable for short-term, irregular, or unpredictable workloads that cannot be interrupted. Dedicated Instances are EC2 instances that run on hardware that is dedicated to a single customer. Dedicated Instances are suitable for workloads that require regulatory compliance or data isolation. Reference: [Amazon EC2 Instance Purchasing Options]

Total 789 questions
Go to page: of 79