Amazon

CLF-C02 Free Practice Questions — Page 18

Question 172

Which tasks are the responsibility of AWS according to the AWS shared responsibility model? (Choose two.)

A. Configure AWS Identity and Access Management (IAM).
B. Configure security groups on Amazon EC2 instances.
C. Secure the access of physical AWS facilities.
D. Patch applications that run on Amazon EC2 instances.
E. Perform infrastructure patching and maintenance.
Show Answer
Correct Answer: C, E
Explanation:
Under the AWS shared responsibility model, AWS is responsible for security *of* the cloud. This includes securing physical data center facilities and performing infrastructure-level patching and maintenance (hardware, networking, and underlying virtualization). Customers are responsible for security *in* the cloud, such as IAM configuration, security groups, and patching applications.

Question 173

What is a customer responsibility under the AWS shared responsibility model when using AWS Lambda?

A. Maintenance of the underlying Lambda hardware.
B. Maintenance of the Lambda networking infrastructure.
C. The code and libraries that run in the Lambda functions.
D. The Lambda server software.
Show Answer
Correct Answer: C
Explanation:
Under the AWS shared responsibility model for AWS Lambda, AWS manages the underlying hardware, networking infrastructure, and server software. Customers are responsible for what they deploy and run in Lambda, including the function code and any libraries or dependencies it uses. Therefore, the correct answer is C.

Question 174

A food delivery company needs to block users in certain countries from accessing its website. Which AWS service should the company use to meet this requirement?

A. AWS WAF
B. AWS Control Tower
C. Amazon Fraud Detector
D. Amazon Pinpoint
Show Answer
Correct Answer: A
Explanation:
AWS WAF allows you to create web access control rules, including geographic (country-based) blocking, to prevent users from specific countries from accessing a website. The other services do not provide web request filtering or geo-blocking capabilities.

Question 175

A developer needs to interact with AWS by using the AWS CLI. Which security feature or AWS service must be provisioned in the developer's account to meet this requirement?

A. User name and password
B. AWS Systems Manager
C. Root password access
D. AWS access key
Show Answer
Correct Answer: D
Explanation:
The AWS CLI requires programmatic access to AWS APIs. This is provided through an AWS access key (access key ID and secret access key), which is generated for an IAM user or role. Usernames/passwords and root access are not used for CLI authentication, and AWS Systems Manager is not required for basic CLI access.

Question 176

Which VPC component can a company use to set up a virtual firewall at the Amazon EC2 instance level?

A. Network ACL
B. Security group
C. Route table
D. NAT gateway
Show Answer
Correct Answer: B
Explanation:
A security group acts as a virtual firewall at the Amazon EC2 instance level, controlling inbound and outbound traffic. Network ACLs operate at the subnet level, route tables handle routing, and NAT gateways provide outbound internet access.

Question 177

What is the primary use case for Amazon GuardDuty?

A. Prevention of DDoS attacks
B. Protection against SQL injection attacks
C. Automatic monitoring for threats to AWS workloads
D. Automatic provisioning of AWS resources
Show Answer
Correct Answer: C
Explanation:
Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts and workloads for malicious activity and unauthorized behavior. It analyzes logs such as CloudTrail, VPC Flow Logs, and DNS logs to identify threats, rather than preventing DDoS attacks, blocking SQL injection, or provisioning resources.

Question 178

A company has applications that control on-premises factory equipment. Which AWS service should the company use to run these applications with the LEAST latency?

A. AWS Outposts
B. Amazon EC2
C. AWS Lambda
D. AWS Fargate
Show Answer
Correct Answer: A
Explanation:
Applications that control on-premises factory equipment require extremely low and predictable latency to local systems. AWS Outposts runs AWS infrastructure and services directly in the company’s on-premises environment, eliminating network latency to a remote AWS Region. The other options (EC2, Lambda, Fargate) run in AWS Regions and would introduce higher network latency.

Question 179

A company wants to add a conversational chatbot to its website. Which AWS service can the company use to meet this requirement?

A. Amazon Textract
B. Amazon Lex
C. AWS Glue
D. Amazon Rekognition
Show Answer
Correct Answer: B
Explanation:
Amazon Lex is specifically designed for building conversational chatbots and voice assistants. It provides natural language understanding and automatic speech recognition to create and deploy chatbots for websites and applications. The other options serve different purposes (Textract for document text extraction, Glue for ETL, Rekognition for image/video analysis).

Question 180

Which AWS service or feature can be used to monitor for potential disk write spikes on a system that is running on Amazon EC2?

A. AWS CloudTrail
B. AWS Health Dashboard
C. AWS Trusted Advisor
D. Amazon CloudWatch
Show Answer
Correct Answer: D
Explanation:
Amazon CloudWatch provides built-in and custom metrics for Amazon EC2 instances, including disk read/write operations and throughput. It allows real-time monitoring and the creation of alarms to detect abnormal disk write spikes. The other options focus on auditing (CloudTrail), service health notifications (AWS Health Dashboard), or general optimization recommendations (Trusted Advisor), not detailed disk performance monitoring.

Question 181

A developer who has no AWS Cloud experience wants to use AWS technology to build a web application. Which AWS service should the developer use to start building the application?

A. Amazon SageMaker
B. AWS Lambda
C. Amazon Lightsail
D. Amazon Elastic Container Service (Amazon ECS)
Show Answer
Correct Answer: C
Explanation:
The developer has no AWS Cloud experience, so the best service is one that is simple, guided, and requires minimal setup. Amazon Lightsail is designed specifically for beginners and provides an easy way to launch and manage a web application using preconfigured virtual private servers, networking, and storage. The other options (SageMaker, Lambda, ECS) require more specialized knowledge and are not ideal starting points for someone new to AWS.

$19

Get all 715 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.