A company is designing workloads in the AWS Cloud. The company wants the workloads to perform their intended function correctly and consistently throughout their lifecycle.
Which pillar of the AWS Well-Architected Framework does this goal represent?
A. Operational excellence
B. Security
C. Reliability
D. Performance efficiency
Show Answer
Correct Answer: C
Explanation: The Reliability pillar of the AWS Well-Architected Framework focuses on ensuring a workload performs its intended function correctly and consistently throughout its lifecycle. It includes designing for failure, recovery, and consistent operation under expected conditions.
Question 163
Which AWS service is used to temporarily provide federated security credentials to access AWS resources?
A. Amazon GuardDuty
B. AWS Simple Token Service (AWS STS)
C. AWS Secrets Manager
D. AWS Certificate Manager
Show Answer
Correct Answer: B
Explanation: AWS Security Token Service (AWS STS) issues temporary security credentials for IAM users or federated identities to access AWS resources. It is specifically designed for federation and temporary, limited-privilege access. GuardDuty is for threat detection, Secrets Manager stores and rotates secrets, and Certificate Manager manages SSL/TLS certificates.
Question 164
A company wants to migrate its on-premises infrastructure to the AWS Cloud.
Which advantage of cloud computing will help the company reduce upfront costs?
A. Go global in minutes
B. Increase speed and agility
C. Benefit from massive economies of scale
D. Trade fixed expense for variable expense
Show Answer
Correct Answer: D
Explanation: Reducing upfront costs is achieved by replacing large capital expenditures (CapEx) for infrastructure with pay-as-you-go operational expenditures (OpEx). This is the AWS cloud advantage of trading fixed expense for variable expense. The other options are cloud benefits but do not specifically address reducing upfront costs.
Question 165
A company needs to use dashboards and charts to analyze insights from business data.
Which AWS service will provide the dashboards and charts for these insights?
A. Amazon Macie
B. Amazon Aurora
C. Amazon QuickSight
D. AWS CloudTrail
Show Answer
Correct Answer: C
Explanation: Amazon QuickSight is AWS's business intelligence (BI) service used to create interactive dashboards, visualizations, and charts from business data. Amazon Macie is for data security and discovery, Amazon Aurora is a relational database, and AWS CloudTrail records API activity for auditing.
Question 166
A company needs to set up dedicated network connectivity between its on-premises data center and the AWS Cloud. The network cannot use the public internet.
Which AWS service or feature will meet these requirements?
A. AWS Transit Gateway
B. AWS VPN
C. Amazon CloudFront
D. AWS Direct Connect
Show Answer
Correct Answer: D
Explanation: AWS Direct Connect provides a dedicated private network connection between an on-premises data center and AWS that does not traverse the public internet. AWS VPN uses encrypted tunnels over the public internet, Transit Gateway connects networks within AWS and attached networks but does not itself provide dedicated physical connectivity, and CloudFront is a content delivery network.
Question 167
A company wants to develop an accessibility application that will convert text into audible speech.
Which AWS service will meet this requirement?
A. Amazon MQ
B. Amazon Polly
C. Amazon Neptune
D. Amazon Timestream
Show Answer
Correct Answer: B
Explanation: Amazon Polly is the AWS text-to-speech service that converts written text into natural-sounding speech, making it suitable for accessibility applications. Amazon MQ is a managed message broker, Amazon Neptune is a graph database, and Amazon Timestream is a time series database.
Question 168
Which AWS network services or features allow CIDR block notation when providing an IP address range? (Choose two.)
A. Security groups
B. Amazon Machine Image (AMI)
C. Network access control list (network ACL)
D. AWS Budgets
E. Amazon Elastic Block Store (Amazon EBS)
Show Answer
Correct Answer: A, C
Explanation: Security groups and network ACLs both accept CIDR block notation (IPv4 and IPv6) when defining allowed or denied IP address ranges. AMIs, AWS Budgets, and Amazon EBS do not use CIDR ranges for this purpose.
Question 169
A company plans to perform a one-time migration of a large dataset with millions of files from its on-premises data center to the AWS Cloud.
Which AWS service should the company use for the migration?
A. AWS Database Migration Service (AWS DMS)
B. AWS DataSync
C. AWS Migration Hub
D. AWS Application Migration Service
Show Answer
Correct Answer: B
Explanation: AWS DataSync is designed to transfer large amounts of file or object data between on-premises storage and AWS efficiently, making it the appropriate choice for a one-time migration involving millions of files. AWS DMS is for database migrations, Migration Hub is for tracking migrations, and Application Migration Service is for migrating servers/applications rather than bulk file datasets.
Question 170
A company has a compliance requirement to record and evaluate configuration changes, as well as perform remediation actions on AWS resources.
Which AWS service should the company use?
A. AWS Config
B. AWS Secrets Manager
C. AWS CloudTrail
D. AWS Trusted Advisor
Show Answer
Correct Answer: A
Explanation: AWS Config records configuration changes to AWS resources, evaluates resource configurations against desired rules and compliance policies, and supports automated remediation through AWS Systems Manager Automation. CloudTrail records API activity but does not evaluate configurations or remediate them. Secrets Manager manages secrets, and Trusted Advisor provides best-practice recommendations rather than configuration change tracking and remediation.
Question 171
A company's compliance officer wants to review the AWS Service Organization Control (SOC) reports.
Which AWS service or feature should the compliance officer use to complete this task?
A. AWS Artifact
B. AWS Concierge Support
C. AWS Support
D. AWS Trusted Advisor
Show Answer
Correct Answer: A
Explanation: AWS Artifact is the AWS self-service portal that provides on-demand access to AWS compliance documentation and reports, including Service Organization Control (SOC) reports. AWS Support and Concierge are support services, while Trusted Advisor provides best practice recommendations rather than compliance reports.
$19
Get all 713 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.