Amazon

CLF-C02 Free Practice Questions — Page 14

Question 132

A company wants to use an AWS networking solution that can act as a centralized gateway between multiple VPCs and on-premises networks. Which AWS service or feature will meet this requirement?

A. Gateway VPC endpoint
B. AWS Direct Connect
C. AWS Transit Gateway
D. AWS PrivateLink
Show Answer
Correct Answer: C
Explanation:
AWS Transit Gateway provides a centralized hub-and-spoke networking model that connects multiple VPCs and on‑premises networks through a single gateway. It is specifically designed to act as a central routing gateway, unlike VPC endpoints, Direct Connect alone, or PrivateLink.

Question 133

What is the recommended use case for Amazon EC2 On-Demand Instances?

A. A steady-state workload that requires a particular EC2 instance configuration for a long period of time
B. A workload that can be interrupted for a project that requires the lowest possible cost
C. An unpredictable workload that does not require a long-term commitment
D. A workload that is expected to run for longer than 1 year
Show Answer
Correct Answer: C
Explanation:
EC2 On-Demand Instances are best for workloads that are unpredictable or short-term and do not require a long-term commitment. They provide flexibility with no upfront cost and no interruption risk, unlike Spot (interruptible) or Reserved/Committed options meant for steady, long-running workloads.

Question 134

A company needs to run some of its workloads on premises to comply with regulatory guidelines. The company wants to use the AWS Cloud to run workloads that are not required to be on premises. The company also wants to be able to use the same API calls for the on-premises workloads and the cloud workloads. Which AWS service or feature should the company use to meet these requirements?

A. Dedicated Hosts
B. AWS Outposts
C. Availability Zones
D. AWS Wavelength
Show Answer
Correct Answer: B
Explanation:
AWS Outposts allows AWS infrastructure and services to be run on premises while using the same AWS APIs, tools, and management experience as in the AWS Cloud. This meets regulatory requirements for on‑premises workloads while enabling seamless operation of cloud workloads with identical API calls.

Question 135

Which AWS service is always available free of charge to users?

A. Amazon Athena
B. AWS Identity and Access Management (IAM)
C. AWS Secrets Manager
D. Amazon ElastiCache
Show Answer
Correct Answer: B
Explanation:
AWS Identity and Access Management (IAM) is an always-free AWS service. There is no charge for creating users, groups, roles, or managing permissions. The other options (Athena, Secrets Manager, ElastiCache) incur usage-based charges.

Question 136

Which AWS service should a company use to organize, characterize, and search large numbers of images?

A. Amazon Transcribe
B. Amazon Rekognition
C. Amazon Aurora
D. Amazon QuickSight
Show Answer
Correct Answer: B
Explanation:
Amazon Rekognition is designed to analyze images and videos, allowing organizations to organize, characterize, and search large image collections using features like object detection, facial recognition, and image labeling. The other options serve different purposes: Transcribe is for speech-to-text, Aurora is a database, and QuickSight is for business intelligence visualization.

Question 137

Which of the following is a customer responsibility according to the AWS shared responsibility model?

A. Apply security patches for Amazon S3 infrastructure devices.
B. Provide physical security for AWS datacenters.
C. Install operating system updates on Lambda@Edge.
D. Implement multi-factor authentication (MFA) for IAM user accounts.
Show Answer
Correct Answer: D
Explanation:
Under the AWS shared responsibility model, customers are responsible for security *in* the cloud, which includes managing identities and access. Implementing multi-factor authentication (MFA) for IAM user accounts is a customer responsibility. AWS, not customers, handles physical datacenter security, underlying infrastructure patching, and the operating system/runtime for managed services like Lambda@Edge.

Question 138

Which AWS services are serverless? (Choose two.)

A. AWS Fargate
B. Amazon Managed Streaming for Apache Kafka
C. Amazon EMR
D. Amazon S3
E. Amazon EC2
Show Answer
Correct Answer: A, D
Explanation:
Serverless services abstract away server management and infrastructure provisioning from the user. AWS Fargate is serverless because it allows you to run containers without managing EC2 instances or servers. Amazon S3 is serverless because it provides fully managed object storage with no server provisioning, scaling, or OS management required. The other options require managing clusters or instances, so they are not serverless.

Question 139

A company wants an AWS service that can automate software deployment in Amazon EC2 instances and on-premises instances. Which AWS service will meet this requirement?

A. AWS CodeCommit
B. AWS CodeBuild
C. AWS CodeDeploy
D. AWS CodePipeline
Show Answer
Correct Answer: C
Explanation:
AWS CodeDeploy automates application deployments to Amazon EC2 instances as well as on-premises servers. The other services handle source control (CodeCommit), build/compile (CodeBuild), or orchestrating CI/CD workflows (CodePipeline), not direct deployment to instances.

Question 140

A company wants to securely access an Amazon S3 bucket from an Amazon EC2 instance without accessing the internet. What should the company use to accomplish this goal?

A. VPN connection
B. Internet gateway
C. VPC endpoint
D. NAT gateway
Show Answer
Correct Answer: C
Explanation:
To access Amazon S3 from an EC2 instance without traversing the public internet, the correct solution is to use a VPC endpoint. Specifically, an S3 gateway VPC endpoint allows private connectivity between resources in a VPC and S3, keeping traffic within the AWS network and eliminating the need for an internet gateway, NAT gateway, or VPN.

Question 141

Which AWS service uses edge locations to cache content?

A. Amazon Kinesis
B. Amazon Simple Queue Service (Amazon SQS)
C. Amazon CloudFront
D. Amazon Route 53
Show Answer
Correct Answer: C
Explanation:
Amazon CloudFront is AWS’s content delivery network (CDN) that uses a global network of edge locations to cache and deliver content closer to users, reducing latency. The other services listed do not use edge locations for content caching.

$19

Get all 715 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.