Amazon

CLF-C02 Free Practice Questions — Page 14

Question 132

A company wants to use an AWS networking solution that can act as a centralized gateway between multiple VPCs and on-premises networks. Which AWS service or feature will meet this requirement?

A. Gateway VPC endpoint
B. AWS Direct Connect
C. AWS Transit Gateway
D. AWS PrivateLink
Show Answer
Correct Answer: C
Explanation:
AWS Transit Gateway is designed to act as a centralized hub that connects multiple VPCs and on-premises networks using a hub-and-spoke architecture. Gateway VPC endpoints provide private access to specific AWS services, Direct Connect is a dedicated network connection rather than a central routing hub, and PrivateLink provides private access to services without serving as a transit gateway.

Question 133

What is the recommended use case for Amazon EC2 On-Demand Instances?

A. A steady-state workload that requires a particular EC2 instance configuration for a long period of time
B. A workload that can be interrupted for a project that requires the lowest possible cost
C. An unpredictable workload that does not require a long-term commitment
D. A workload that is expected to run for longer than 1 year
Show Answer
Correct Answer: C
Explanation:
Amazon EC2 On-Demand Instances are best suited for short-term, irregular, or unpredictable workloads where you want flexibility without making a long-term commitment. Steady long-running workloads are typically better served by Reserved Instances or Savings Plans, while interruptible, lowest-cost workloads are suited to Spot Instances.

Question 134

A company needs to run some of its workloads on premises to comply with regulatory guidelines. The company wants to use the AWS Cloud to run workloads that are not required to be on premises. The company also wants to be able to use the same API calls for the on-premises workloads and the cloud workloads. Which AWS service or feature should the company use to meet these requirements?

A. Dedicated Hosts
B. AWS Outposts
C. Availability Zones
D. AWS Wavelength
Show Answer
Correct Answer: B
Explanation:
AWS Outposts extends AWS infrastructure, services, APIs, and tools to an on-premises environment, allowing workloads to run on premises for regulatory requirements while using the same AWS APIs and management experience as workloads running in AWS Regions.

Question 135

Which AWS service is always available free of charge to users?

A. Amazon Athena
B. AWS Identity and Access Management (IAM)
C. AWS Secrets Manager
D. Amazon ElastiCache
Show Answer
Correct Answer: B
Explanation:
AWS Identity and Access Management (IAM) is provided at no additional charge. You pay only for the AWS resources accessed by your users. The other services listed (Amazon Athena, AWS Secrets Manager, and Amazon ElastiCache) incur usage-based charges, though some may have limited Free Tier offers.

Question 136

Which AWS service should a company use to organize, characterize, and search large numbers of images?

A. Amazon Transcribe
B. Amazon Rekognition
C. Amazon Aurora
D. Amazon QuickSight
Show Answer
Correct Answer: B
Explanation:
Amazon Rekognition is the AWS computer vision service designed to analyze images and videos. It can detect objects, scenes, faces, text, and labels, enabling organizations to organize, characterize, and search large image collections. Amazon Transcribe is for speech-to-text, Amazon Aurora is a relational database, and Amazon QuickSight is a business intelligence and visualization service.

Question 137

Which of the following is a customer responsibility according to the AWS shared responsibility model?

A. Apply security patches for Amazon S3 infrastructure devices.
B. Provide physical security for AWS datacenters.
C. Install operating system updates on Lambda@Edge.
D. Implement multi-factor authentication (MFA) for IAM user accounts.
Show Answer
Correct Answer: D
Explanation:
Under the AWS shared responsibility model, AWS is responsible for the security 'of' the cloud (including physical datacenters and the infrastructure supporting managed services like S3 and Lambda@Edge). Customers are responsible for security 'in' the cloud, including IAM configuration and enabling MFA for IAM users. Therefore, implementing MFA for IAM user accounts is the customer's responsibility.

Question 138

Which AWS services are serverless? (Choose two.)

A. AWS Fargate
B. Amazon Managed Streaming for Apache Kafka
C. Amazon EMR
D. Amazon S3
E. Amazon EC2
Show Answer
Correct Answer: A, D
Explanation:
AWS Fargate is a serverless compute engine for containers, eliminating server management. Amazon S3 is a fully managed object storage service where AWS manages the underlying infrastructure. Amazon MSK, EMR, and EC2 have serverless variants or modes, but the services listed are not inherently serverless in their standard form.

Question 139

A company wants an AWS service that can automate software deployment in Amazon EC2 instances and on-premises instances. Which AWS service will meet this requirement?

A. AWS CodeCommit
B. AWS CodeBuild
C. AWS CodeDeploy
D. AWS CodePipeline
Show Answer
Correct Answer: C
Explanation:
AWS CodeDeploy automates software deployments to Amazon EC2 instances as well as on-premises instances. CodeCommit is for source control, CodeBuild compiles and tests code, and CodePipeline orchestrates CI/CD workflows rather than performing deployments itself.

Question 140

A company wants to securely access an Amazon S3 bucket from an Amazon EC2 instance without accessing the internet. What should the company use to accomplish this goal?

A. VPN connection
B. Internet gateway
C. VPC endpoint
D. NAT gateway
Show Answer
Correct Answer: C
Explanation:
An Amazon VPC endpoint allows private connectivity between resources in a VPC and supported AWS services such as Amazon S3 without traversing the public internet. For S3, a Gateway VPC Endpoint is the standard solution. An Internet Gateway provides internet access, a NAT Gateway enables outbound internet access for private subnets, and a VPN connection is for connecting external networks to AWS, not for private access to S3 from EC2 within a VPC.

Question 141

Which AWS service uses edge locations to cache content?

A. Amazon Kinesis
B. Amazon Simple Queue Service (Amazon SQS)
C. Amazon CloudFront
D. Amazon Route 53
Show Answer
Correct Answer: C
Explanation:
Amazon CloudFront is AWS's content delivery network (CDN) that uses a global network of edge locations to cache and deliver content with low latency. Amazon Kinesis is for data streaming, Amazon SQS is a message queue service, and Amazon Route 53 is a DNS and routing service, not a content caching service.

$19

Get all 713 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.