Which tasks are the responsibility of AWS according to the AWS shared responsibility model? (Choose two.)
A. Configure AWS Identity and Access Management (IAM).
B. Configure security groups on Amazon EC2 instances.
C. Secure the access of physical AWS facilities.
D. Patch applications that run on Amazon EC2 instances.
E. Perform infrastructure patching and maintenance.
Show Answer
Correct Answer: C, E
Explanation: Under the AWS shared responsibility model, AWS is responsible for security 'of' the cloud, including physical security of data centers and the underlying infrastructure, as well as infrastructure patching and maintenance. Customers are responsible for security 'in' the cloud, including configuring IAM, security groups, and patching applications running on EC2 instances.
Question 173
What is a customer responsibility under the AWS shared responsibility model when using AWS Lambda?
A. Maintenance of the underlying Lambda hardware.
B. Maintenance of the Lambda networking infrastructure.
C. The code and libraries that run in the Lambda functions.
D. The Lambda server software.
Show Answer
Correct Answer: C
Explanation: Under the AWS shared responsibility model for AWS Lambda, AWS manages the underlying infrastructure, including the hardware, networking, and managed server environment. Customers are responsible for their function code, any libraries and dependencies they package, configuration, IAM permissions, and application data.
Question 174
A food delivery company needs to block users in certain countries from accessing its website.
Which AWS service should the company use to meet this requirement?
A. AWS WAF
B. AWS Control Tower
C. Amazon Fraud Detector
D. Amazon Pinpoint
Show Answer
Correct Answer: A
Explanation: AWS WAF supports geographic match rules that can allow or block web requests based on the originating country, making it the appropriate service for restricting website access by country. AWS Control Tower is for multi-account governance, Amazon Fraud Detector detects fraudulent activity, and Amazon Pinpoint is for customer engagement and messaging.
Question 175
A developer needs to interact with AWS by using the AWS CLI.
Which security feature or AWS service must be provisioned in the developer's account to meet this requirement?
A. User name and password
B. AWS Systems Manager
C. Root password access
D. AWS access key
Show Answer
Correct Answer: D
Explanation: The AWS CLI authenticates using programmatic credentials. An AWS access key (access key ID and secret access key), typically associated with an IAM user or obtained through temporary credentials via an IAM role, is required to make authenticated API calls. A username/password is for console sign-in, Systems Manager is unrelated, and root credentials should not be used for routine CLI access.
Question 176
Which VPC component can a company use to set up a virtual firewall at the Amazon EC2 instance level?
A. Network ACL
B. Security group
C. Route table
D. NAT gateway
Show Answer
Correct Answer: B
Explanation: Security groups act as virtual firewalls at the Amazon EC2 instance level, controlling inbound and outbound traffic. Network ACLs operate at the subnet level, route tables determine traffic routing, and NAT gateways provide outbound internet access for private subnets.
Question 177
What is the primary use case for Amazon GuardDuty?
A. Prevention of DDoS attacks
B. Protection against SQL injection attacks
C. Automatic monitoring for threats to AWS workloads
D. Automatic provisioning of AWS resources
Show Answer
Correct Answer: C
Explanation: Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts, workloads, and data sources for malicious activity and unauthorized behavior. It is not a DDoS prevention service (AWS Shield), not specifically an SQL injection protection service (AWS WAF), and not a resource provisioning service.
Question 178
A company has applications that control on-premises factory equipment.
Which AWS service should the company use to run these applications with the LEAST latency?
A. AWS Outposts
B. Amazon EC2
C. AWS Lambda
D. AWS Fargate
Show Answer
Correct Answer: A
Explanation: AWS Outposts extends AWS infrastructure and services into on-premises environments, allowing applications that control factory equipment to run locally with very low latency. Amazon EC2, AWS Lambda, and AWS Fargate typically run in AWS Regions and would introduce higher network latency for on-premises equipment.
Question 179
A company wants to add a conversational chatbot to its website.
Which AWS service can the company use to meet this requirement?
A. Amazon Textract
B. Amazon Lex
C. AWS Glue
D. Amazon Rekognition
Show Answer
Correct Answer: B
Explanation: Amazon Lex is the AWS service for building conversational interfaces (chatbots) using automatic speech recognition and natural language understanding. Amazon Textract extracts text from documents, AWS Glue is an ETL/data integration service, and Amazon Rekognition provides image and video analysis.
Question 180
Which AWS service or feature can be used to monitor for potential disk write spikes on a system that is running on Amazon EC2?
A. AWS CloudTrail
B. AWS Health Dashboard
C. AWS Trusted Advisor
D. Amazon CloudWatch
Show Answer
Correct Answer: D
Explanation: Amazon CloudWatch monitors Amazon EC2 instances and other AWS resources by collecting metrics and enabling alarms. It can monitor disk-related metrics (including disk I/O where applicable and via the CloudWatch agent for OS-level disk metrics), making it the appropriate service to detect and alert on potential disk write spikes.
Question 181
A developer who has no AWS Cloud experience wants to use AWS technology to build a web application.
Which AWS service should the developer use to start building the application?
A. Amazon SageMaker
B. AWS Lambda
C. Amazon Lightsail
D. Amazon Elastic Container Service (Amazon ECS)
Show Answer
Correct Answer: C
Explanation: Amazon Lightsail is designed for developers with little or no AWS cloud experience. It provides a simple way to launch and manage virtual private servers, databases, and networking for web applications with straightforward pricing and minimal setup. AWS Lambda and Amazon ECS require greater familiarity with serverless or container architectures, and Amazon SageMaker is for machine learning, not general web application development.
$19
Get all 713 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.