A company wants to implement detailed tracking of its cloud costs by department and project.
Which AWS feature or service should the company use?
A. Consolidated billing
B. Cost allocation tags
C. AWS Marketplace
D. AWS Budgets
Show Answer
Correct Answer: B
Explanation: Cost allocation tags let you assign metadata such as department, project, or cost center to AWS resources so costs can be tracked and reported by those categories in AWS Cost Management. Consolidated billing aggregates charges across accounts, AWS Budgets monitors spending, and AWS Marketplace is for purchasing software.
Question 253
A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a natural disaster in a particular geographic area.
Which solution achieves this goal?
A. Use EC2 instances in multiple AWS Regions.
B. Use EC2 instances in multiple edge locations.
C. Use EC2 instances in the same Availability Zone but in different AWS Regions.
D. Use Amazon CloudFront with the EC2 instances configured as the source.
Show Answer
Correct Answer: A
Explanation: Using EC2 instances in multiple AWS Regions provides geographic redundancy. If a natural disaster affects an entire region, workloads can continue running in another region. Edge locations are for content delivery, not hosting EC2 instances. An Availability Zone cannot belong to different Regions, so option C is invalid. CloudFront improves content distribution but does not provide cross-region EC2 disaster resilience.
Question 254
A company is connecting multiple VPCs and on-premises networks. The company needs to use an AWS service as a cloud router to simplify peering relationships.
Which AWS service can the company use to meet this requirement?
A. AWS Direct Connect
B. AWS Transit Gateway
C. Amazon Connect
D. Amazon Route 53
Show Answer
Correct Answer: B
Explanation: AWS Transit Gateway is the managed AWS service that acts as a central cloud router, connecting multiple VPCs and on-premises networks through a hub-and-spoke architecture. It simplifies network connectivity by eliminating the need for numerous VPC peering relationships. AWS Direct Connect provides dedicated connectivity from on premises to AWS but is not a cloud router. Amazon Connect is a contact center service, and Route 53 is a DNS service.
Question 255
A company wants to maintain bandwidth throughput and provide a more consistent network experience than public internet-based connections.
Which AWS service should the company choose?
A. AWS VPN
B. AWS Direct Connect
C. Amazon Connect
D. Amazon CloudFront
Show Answer
Correct Answer: B
Explanation: AWS Direct Connect provides a dedicated private network connection between on-premises infrastructure and AWS. It is designed to increase bandwidth throughput and deliver a more consistent network experience than public internet-based connections. AWS VPN uses the public internet, Amazon Connect is a contact center service, and Amazon CloudFront is a content delivery network.
Question 256
A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account.
Which AWS service or resource should the company use to meet this requirement?
A. AWS Security Hub
B. AWS Marketplace
C. AWS Quick Starts
D. AWS Security Center
Show Answer
Correct Answer: B
Explanation: AWS Marketplace is the AWS catalog for discovering, purchasing, and launching third-party software, including partner security solutions such as intrusion detection systems. Security Hub aggregates security findings, Quick Starts are deployment guides/templates, and 'AWS Security Center' is not an AWS service.
Question 257
Which AWS service or feature can a user configure to limit network access at the subnet level?
A. AWS Shield
B. AWS WAF
C. Network ACL
D. Security group
Show Answer
Correct Answer: C
Explanation: Network ACLs (NACLs) are stateless packet filtering rules that are applied at the subnet level to control inbound and outbound traffic. Security groups operate at the instance/ENI level, while AWS Shield provides DDoS protection and AWS WAF filters web application traffic.
Question 258
A company needs to check for IAM access keys that have not been rotated recently.
Which AWS service should the company use to meet this requirement?
A. AWS WAF
B. AWS Shield
C. Amazon Cognito
D. AWS Trusted Advisor
Show Answer
Correct Answer: D
Explanation: AWS Trusted Advisor includes an IAM Access Key Rotation check that identifies IAM access keys that have not been rotated within the recommended time frame. AWS WAF protects web applications, AWS Shield provides DDoS protection, and Amazon Cognito handles user identity and authentication, not IAM key rotation monitoring.
Question 259
A company needs to consolidate the billing for multiple AWS accounts. The company needs to use one account to pay on behalf of all the other accounts.
Which AWS service or tool should the company use to meet this requirement?
A. AWS Trusted Advisor
B. AWS Organizations
C. AWS Budgets
D. AWS Service Catalog
Show Answer
Correct Answer: B
Explanation: AWS Organizations provides consolidated billing, allowing a management account to pay for charges incurred by multiple member AWS accounts. Trusted Advisor offers recommendations, AWS Budgets helps track spending, and Service Catalog manages approved IT services.
Question 260
Which AWS service provides users with AWS issued reports, certifications, accreditations, and third-party attestations?
A. AWS Artifact
B. AWS Trusted Advisor
C. AWS Health Dashboard
D. AWS Config
Show Answer
Correct Answer: A
Explanation: AWS Artifact is the service that provides on-demand access to AWS-issued compliance reports, certifications, accreditations, and third-party attestations (such as ISO, SOC, and PCI reports). Trusted Advisor provides best practice recommendations, AWS Health Dashboard reports service health and account events, and AWS Config tracks and evaluates resource configurations.
Question 261
Which of the following can be components of a VPC in the AWS Cloud? (Choose two.)
A. Amazon API Gateway
B. Amazon S3 buckets and objects
C. AWS Storage Gateway
D. Internet gateway
E. Subnet
Show Answer
Correct Answer: D, E
Explanation: A VPC includes networking components such as subnets and internet gateways. An Internet Gateway enables communication between resources in the VPC and the internet, and subnets are logical partitions of the VPC's IP address range. Amazon API Gateway, Amazon S3 buckets/objects, and AWS Storage Gateway are separate AWS services, not VPC components.
$19
Get all 713 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.