Amazon

CLF-C02 Free Practice Questions — Page 13

Question 122

Which option is an advantage of AWS Cloud computing that minimizes variable costs?

A. High availability
B. Economies of scale
C. Global reach
D. Agility
Show Answer
Correct Answer: B
Explanation:
Economies of scale are a core advantage of AWS Cloud. By aggregating usage across many customers, AWS achieves lower variable costs than individual organizations can typically achieve on their own, and passes many of those savings on through pricing.

Question 123

A company needs stateless network filtering for its VPC. Which AWS service, tool, or feature will meet this requirement?

A. AWS PrivateLink
B. Security group
C. Network access control list (ACL)
D. AWS WAF
Show Answer
Correct Answer: C
Explanation:
Network access control lists (NACLs) provide stateless filtering at the subnet level in a VPC. Because they are stateless, return traffic must be explicitly allowed. Security groups are stateful, AWS WAF filters HTTP/S web traffic, and AWS PrivateLink provides private connectivity rather than packet filtering.

Question 124

A company wants to migrate its on-premises SQL Server database to the AWS Cloud. The company wants AWS to handle the day-to-day administration of the database. Which AWS service will meet the company's requirements?

A. Amazon EC2 for Microsoft SQL Server
B. Amazon DynamoDB
C. Amazon RDS
D. Amazon Aurora
Show Answer
Correct Answer: C
Explanation:
Amazon RDS for SQL Server is a managed relational database service that supports Microsoft SQL Server and offloads routine administrative tasks such as provisioning, backups, patching, and monitoring. Running SQL Server on Amazon EC2 requires the customer to manage the database, DynamoDB is a NoSQL database, and Amazon Aurora does not support the SQL Server engine.

Question 125

A company deployed an application in multiple AWS Regions around the world. The company wants to improve the application’s performance and availability. Which AWS service will meet these requirements?

A. AWS Global Accelerator
B. Amazon DataZone
C. AWS Cloud Map
D. AWS Auto Scaling
Show Answer
Correct Answer: A
Explanation:
AWS Global Accelerator improves the performance and availability of applications deployed across multiple AWS Regions by routing users over the AWS global network to the optimal healthy endpoint, with automatic failover. Amazon DataZone is for data governance, AWS Cloud Map is for service discovery, and AWS Auto Scaling adjusts capacity but does not provide global traffic acceleration or cross-Region routing.

Question 126

Which AWS service is a fully managed NoSQL database service?

A. Amazon RDS
B. Amazon Redshift
C. Amazon DynamoDB
D. Amazon Aurora
Show Answer
Correct Answer: C
Explanation:
Amazon DynamoDB is AWS's fully managed NoSQL database service. Amazon RDS and Amazon Aurora are relational database services, and Amazon Redshift is a data warehouse service. Sources: https://docs.aws.amazon.com/whitepapers/latest/choosing-an-aws-nosql-database/amazon-dynamodb.html https://aws.amazon.com/nosql

Question 127

A company stores data in an Amazon S3 bucket. Which task is the responsibility of AWS?

A. Configure an S3 Lifecycle policy.
B. Activate S3 Versioning.
C. Configure S3 bucket policies.
D. Protect the infrastructure that supports S3 storage.
Show Answer
Correct Answer: D
Explanation:
Under the AWS Shared Responsibility Model, AWS is responsible for security 'of' the cloud, including the physical facilities, networking, hardware, and infrastructure that operates Amazon S3. Customers are responsible for security 'in' the cloud, including configuring S3 Lifecycle policies, enabling Versioning, and setting bucket policies. Sources: https://docs.aws.amazon.com/AmazonS3/latest/userguide/Welcome.html https://aws.amazon.com/s3

Question 128

Which design principle is related to the reliability pillar according to the AWS Well-Architected Framework?

A. Test recovery procedures
B. Experiment more often
C. Go global in minutes
D. Analyze and attribute to expenditure
Show Answer
Correct Answer: A
Explanation:
The Reliability pillar of the AWS Well-Architected Framework includes the design principle of testing recovery procedures to validate that systems can recover from failures and meet recovery objectives. The other options map to different pillars: experimenting more often (Performance Efficiency), going global in minutes (Operational Excellence/Cloud benefits, not a Reliability design principle), and analyzing and attributing expenditure (Cost Optimization).

Question 129

What is the total volume of data that can be stored in Amazon S3?

A. 10 PB
B. 50 PB
C. 100 PB
D. Virtually unlimited
Show Answer
Correct Answer: D
Explanation:
Amazon S3 is designed with virtually unlimited storage capacity. There is no fixed total storage limit such as 10 PB, 50 PB, or 100 PB; you can store as much data as needed, subject to service quotas and object-level limits.

Question 130

In which situations should a company create an IAM user instead of an IAM role?

A. When an application that runs on Amazon EC2 instances requires access to other AWS services
B. When the company creates AWS access credentials for individuals
C. When the company creates an application that runs on a mobile phone that makes requests to AWS
D. When the company needs to add users to IAM groups
E. When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time
Show Answer
Correct Answer: B
Explanation:
IAM users are appropriate when creating long-term AWS credentials for individual users (though AWS often recommends IAM Identity Center or federation where possible). EC2 applications, mobile apps, and federated corporate users should use IAM roles, not IAM users. IAM groups are a way to organize existing IAM users, not a reason by itself to create IAM users.

Question 131

To assist companies with Payment Card Industry Data Security Standard (PCI DSS) compliance in the cloud, AWS provides:

A. physical Inspections of data centers by appointment.
B. required PCI compliance certifications for any application running on AWS.
C. an AWS Attestation of Compliance (AOC) report for specific AWS services.
D. professional PCI compliance services.
Show Answer
Correct Answer: C
Explanation:
AWS helps customers with PCI DSS compliance by providing a PCI DSS Attestation of Compliance (AOC) and related compliance documentation for in-scope AWS services through AWS Artifact. AWS does not perform customer data center inspections, does not automatically certify every application running on AWS as PCI compliant, and does not provide required professional PCI compliance services as the primary offering.

$19

Get all 713 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.