Amazon

CLF-C02 Free Practice Questions — Page 13

Question 122

Which option is an advantage of AWS Cloud computing that minimizes variable costs?

A. High availability
B. Economies of scale
C. Global reach
D. Agility
Show Answer
Correct Answer: B
Explanation:
AWS minimizes variable costs through economies of scale: by aggregating demand across many customers, AWS can offer lower pay‑as‑you‑go pricing, reducing per‑unit costs compared to operating individual infrastructure. The other options describe different benefits, not cost minimization.

Question 123

A company needs stateless network filtering for its VPC. Which AWS service, tool, or feature will meet this requirement?

A. AWS PrivateLink
B. Security group
C. Network access control list (ACL)
D. AWS WAF
Show Answer
Correct Answer: C
Explanation:
Stateless network filtering at the VPC level is provided by Network Access Control Lists (NACLs). NACLs evaluate inbound and outbound rules independently and require explicit rules for return traffic, unlike security groups which are stateful. AWS PrivateLink and AWS WAF do not provide VPC-level stateless packet filtering.

Question 124

A company wants to migrate its on-premises SQL Server database to the AWS Cloud. The company wants AWS to handle the day-to-day administration of the database. Which AWS service will meet the company's requirements?

A. Amazon EC2 for Microsoft SQL Server
B. Amazon DynamoDB
C. Amazon RDS
D. Amazon Aurora
Show Answer
Correct Answer: C
Explanation:
The company wants to migrate an existing SQL Server database and have AWS handle day-to-day administration, which points to a managed database service. Amazon RDS supports Microsoft SQL Server and provides managed features such as automated backups, patching, monitoring, and maintenance. Amazon EC2 would require the company to manage the database themselves, DynamoDB is not a relational SQL database, and Amazon Aurora does not support SQL Server.

Question 125

A company deployed an application in multiple AWS Regions around the world. The company wants to improve the application’s performance and availability. Which AWS service will meet these requirements?

A. AWS Global Accelerator
B. Amazon DataZone
C. AWS Cloud Map
D. AWS Auto Scaling
Show Answer
Correct Answer: A
Explanation:
AWS Global Accelerator improves both performance and availability for globally distributed applications by using the AWS global network to route user traffic to the closest healthy regional endpoint, providing faster response times and automatic failover. The other options do not address global traffic acceleration and availability.

Question 126

Which AWS service is a fully managed NoSQL database service?

A. Amazon RDS
B. Amazon Redshift
C. Amazon DynamoDB
D. Amazon Aurora
Show Answer
Correct Answer: C
Explanation:
Amazon DynamoDB is AWS’s fully managed NoSQL database service. Amazon RDS and Amazon Aurora are managed relational databases, and Amazon Redshift is a data warehouse, not a NoSQL service.

Question 127

A company stores data in an Amazon S3 bucket. Which task is the responsibility of AWS?

A. Configure an S3 Lifecycle policy.
B. Activate S3 Versioning.
C. Configure S3 bucket policies.
D. Protect the infrastructure that supports S3 storage.
Show Answer
Correct Answer: D
Explanation:
Under the AWS Shared Responsibility Model, AWS is responsible for the security *of* the cloud, including protecting and maintaining the physical data centers, hardware, and infrastructure that support services like Amazon S3. Tasks such as lifecycle policies, versioning, and bucket policies are customer responsibilities.

Question 128

Which design principle is related to the reliability pillar according to the AWS Well-Architected Framework?

A. Test recovery procedures
B. Experiment more often
C. Go global in minutes
D. Analyze and attribute to expenditure
Show Answer
Correct Answer: A
Explanation:
In the AWS Well-Architected Framework, the Reliability pillar includes design principles such as automatically recovering from failure, scaling horizontally, stopping guessing capacity, and testing recovery procedures. Among the options, only 'Test recovery procedures' is explicitly a Reliability pillar principle.

Question 129

What is the total volume of data that can be stored in Amazon S3?

A. 10 PB
B. 50 PB
C. 100 PB
D. Virtually unlimited
Show Answer
Correct Answer: D
Explanation:
Amazon S3 is designed to scale automatically and does not impose a fixed upper limit on total storage. Customers can store virtually unlimited amounts of data, constrained only by practical considerations such as cost and service quotas, not by an absolute capacity limit.

Question 130

In which situations should a company create an IAM user instead of an IAM role?

A. When an application that runs on Amazon EC2 instances requires access to other AWS services
B. When the company creates AWS access credentials for individuals
C. When the company creates an application that runs on a mobile phone that makes requests to AWS
D. When the company needs to add users to IAM groups
E. When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time
Show Answer
Correct Answer: B
Explanation:
IAM users are intended for long-term identities with permanent credentials, typically for individual people who need direct access via the console, CLI, or SDKs. The other options describe scenarios where IAM roles are recommended: EC2 applications (A), mobile applications using temporary credentials (C), and federated or SSO access (E). Option D is not a reason to choose a user over a role; IAM groups are simply a way to manage permissions for users once they exist.

Question 131

To assist companies with Payment Card Industry Data Security Standard (PCI DSS) compliance in the cloud, AWS provides:

A. physical Inspections of data centers by appointment.
B. required PCI compliance certifications for any application running on AWS.
C. an AWS Attestation of Compliance (AOC) report for specific AWS services.
D. professional PCI compliance services.
Show Answer
Correct Answer: C
Explanation:
AWS helps customers with PCI DSS compliance by providing an Attestation of Compliance (AOC) for in-scope AWS services via AWS Artifact. This documentation allows customers to leverage AWS’s validated controls as part of their own PCI DSS compliance efforts. AWS does not inspect data centers by appointment, require all applications to be PCI certified, or provide direct professional PCI compliance services.

$19

Get all 715 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.