Amazon

CLF-C02 Free Practice Questions — Page 17

Question 162

A company is designing workloads in the AWS Cloud. The company wants the workloads to perform their intended function correctly and consistently throughout their lifecycle. Which pillar of the AWS Well-Architected Framework does this goal represent?

A. Operational excellence
B. Security
C. Reliability
D. Performance efficiency
Show Answer
Correct Answer: C
Explanation:
The Reliability pillar focuses on a workload’s ability to perform its intended function correctly and consistently throughout its lifecycle, including handling failures and meeting expected behavior. This directly matches the goal described in the question.

Question 163

Which AWS service is used to temporarily provide federated security credentials to access AWS resources?

A. Amazon GuardDuty
B. AWS Simple Token Service (AWS STS)
C. AWS Secrets Manager
D. AWS Certificate Manager
Show Answer
Correct Answer: B
Explanation:
AWS Security Token Service (AWS STS) provides temporary, limited-privilege security credentials, commonly used for federated access where identities are authenticated by external identity providers.

Question 164

A company wants to migrate its on-premises infrastructure to the AWS Cloud. Which advantage of cloud computing will help the company reduce upfront costs?

A. Go global in minutes
B. Increase speed and agility
C. Benefit from massive economies of scale
D. Trade fixed expense for variable expense
Show Answer
Correct Answer: D
Explanation:
Reducing upfront costs is achieved by shifting from large capital expenditures on on‑premises hardware to a pay‑as‑you‑go model. Cloud computing allows companies to trade fixed expenses for variable expenses, paying only for the resources they use instead of investing upfront.

Question 165

A company needs to use dashboards and charts to analyze insights from business data. Which AWS service will provide the dashboards and charts for these insights?

A. Amazon Macie
B. Amazon Aurora
C. Amazon QuickSight
D. AWS CloudTrail
Show Answer
Correct Answer: C
Explanation:
Amazon QuickSight is AWS’s business intelligence service designed specifically to create interactive dashboards, visualizations, and charts from business data. The other options serve different purposes: Amazon Macie focuses on data security and PII detection, Amazon Aurora is a relational database, and AWS CloudTrail is used for auditing and logging API activity.

Question 166

A company needs to set up dedicated network connectivity between its on-premises data center and the AWS Cloud. The network cannot use the public internet. Which AWS service or feature will meet these requirements?

A. AWS Transit Gateway
B. AWS VPN
C. Amazon CloudFront
D. AWS Direct Connect
Show Answer
Correct Answer: D
Explanation:
The requirement is for dedicated network connectivity between an on-premises data center and AWS that does not use the public internet. AWS Direct Connect provides a private, dedicated physical connection to AWS, meeting this requirement. The other options either rely on the public internet (AWS VPN), serve different purposes (Transit Gateway, CloudFront), or do not provide dedicated private connectivity on their own.

Question 167

A company wants to develop an accessibility application that will convert text into audible speech. Which AWS service will meet this requirement?

A. Amazon MQ
B. Amazon Polly
C. Amazon Neptune
D. Amazon Timestream
Show Answer
Correct Answer: B
Explanation:
Amazon Polly is a text-to-speech service that converts written text into natural-sounding audible speech, making it ideal for accessibility applications. The other options are messaging (Amazon MQ), graph database (Amazon Neptune), and time-series database (Amazon Timestream), none of which provide text-to-speech capabilities.

Question 168

Which AWS network services or features allow CIDR block notation when providing an IP address range? (Choose two.)

A. Security groups
B. Amazon Machine Image (AMI)
C. Network access control list (network ACL)
D. AWS Budgets
E. Amazon Elastic Block Store (Amazon EBS)
Show Answer
Correct Answer: A, C
Explanation:
Security groups allow you to specify allowed source or destination IP ranges using CIDR block notation (for example, 0.0.0.0/0). Network access control lists (network ACLs) also require CIDR blocks when defining inbound and outbound rules. The other options do not involve defining IP address ranges.

Question 169

A company plans to perform a one-time migration of a large dataset with millions of files from its on-premises data center to the AWS Cloud. Which AWS service should the company use for the migration?

A. AWS Database Migration Service (AWS DMS)
B. AWS DataSync
C. AWS Migration Hub
D. AWS Application Migration Service
Show Answer
Correct Answer: B
Explanation:
AWS DataSync is purpose-built for fast, secure transfer of large-scale datasets, including millions of files, between on-premises storage and AWS. It is ideal for one-time or periodic migrations. The other options focus on databases (AWS DMS), migration tracking (Migration Hub), or application lift-and-shift (Application Migration Service), not bulk file data transfer.

Question 170

A company has a compliance requirement to record and evaluate configuration changes, as well as perform remediation actions on AWS resources. Which AWS service should the company use?

A. AWS Config
B. AWS Secrets Manager
C. AWS CloudTrail
D. AWS Trusted Advisor
Show Answer
Correct Answer: A
Explanation:
AWS Config records and tracks configuration changes of AWS resources, evaluates them against compliance rules, and supports automated remediation for noncompliant resources. This directly meets the requirement to record, evaluate, and remediate configuration changes.

Question 171

A company's compliance officer wants to review the AWS Service Organization Control (SOC) reports. Which AWS service or feature should the compliance officer use to complete this task?

A. AWS Artifact
B. AWS Concierge Support
C. AWS Support
D. AWS Trusted Advisor
Show Answer
Correct Answer: A
Explanation:
AWS Artifact is the self-service portal that provides on-demand access to AWS compliance reports and documentation, including SOC reports, ISO certifications, and PCI DSS attestations. The other options do not provide direct access to these compliance reports.

$19

Get all 715 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.