Amazon

CLF-C02 Free Practice Questions — Page 26

Question 252

A company wants to implement detailed tracking of its cloud costs by department and project. Which AWS feature or service should the company use?

A. Consolidated billing
B. Cost allocation tags
C. AWS Marketplace
D. AWS Budgets
Show Answer
Correct Answer: B
Explanation:
Cost allocation tags allow AWS costs to be labeled by department, project, or other dimensions and then tracked and reported in cost management tools. This enables detailed cost tracking and attribution, which is exactly what the company requires.

Question 253

A company wants its Amazon EC2 instances to operate in a highly available environment, even if there is a natural disaster in a particular geographic area. Which solution achieves this goal?

A. Use EC2 instances in multiple AWS Regions.
B. Use EC2 instances in multiple edge locations.
C. Use EC2 instances in the same Availability Zone but in different AWS Regions.
D. Use Amazon CloudFront with the EC2 instances configured as the source.
Show Answer
Correct Answer: A
Explanation:
To remain highly available during a natural disaster affecting a geographic area, EC2 instances must be deployed across multiple AWS Regions. Regions are geographically isolated, so a regional disaster will not impact others. Edge locations do not run EC2, Availability Zones are within a single Region, and CloudFront improves content delivery but does not provide regional fault tolerance for compute.

Question 254

A company is connecting multiple VPCs and on-premises networks. The company needs to use an AWS service as a cloud router to simplify peering relationships. Which AWS service can the company use to meet this requirement?

A. AWS Direct Connect
B. AWS Transit Gateway
C. Amazon Connect
D. Amazon Route 53
Show Answer
Correct Answer: B
Explanation:
The requirement is for a cloud router that connects multiple VPCs and on‑premises networks while simplifying peering relationships. AWS Transit Gateway provides a hub‑and‑spoke architecture that centralizes routing between VPCs, VPNs, and Direct Connect links, eliminating the need for many individual VPC peering connections. Other options do not serve this routing hub role.

Question 255

A company wants to maintain bandwidth throughput and provide a more consistent network experience than public internet-based connections. Which AWS service should the company choose?

A. AWS VPN
B. AWS Direct Connect
C. Amazon Connect
D. Amazon CloudFront
Show Answer
Correct Answer: B
Explanation:
The requirement is for consistent bandwidth throughput and a more predictable network experience than public internet connections. AWS Direct Connect provides a dedicated, private network connection between on-premises infrastructure and AWS, bypassing the public internet. This results in higher, more consistent bandwidth and lower, more predictable latency. The other options do not provide dedicated private connectivity.

Question 256

A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account. Which AWS service or resource should the company use to meet this requirement?

A. AWS Security Hub
B. AWS Marketplace
C. AWS Quick Starts
D. AWS Security Center
Show Answer
Correct Answer: B
Explanation:
The requirement is to launch a **third-party intrusion detection system** from the company’s AWS account. AWS Marketplace is specifically designed to discover, purchase, and deploy third-party security products, including IDS/IPS solutions, directly into AWS environments. Security Hub aggregates security findings, Quick Starts are deployment templates, and "AWS Security Center" is not an actual AWS service.

Question 257

Which AWS service or feature can a user configure to limit network access at the subnet level?

A. AWS Shield
B. AWS WAF
C. Network ACL
D. Security group
Show Answer
Correct Answer: C
Explanation:
Network ACLs operate at the subnet level in a VPC and allow you to control inbound and outbound traffic for all resources within that subnet. AWS Shield and AWS WAF protect against specific attack types, and security groups apply at the instance or ENI level, not the subnet level.

Question 258

A company needs to check for IAM access keys that have not been rotated recently. Which AWS service should the company use to meet this requirement?

A. AWS WAF
B. AWS Shield
C. Amazon Cognito
D. AWS Trusted Advisor
Show Answer
Correct Answer: D
Explanation:
AWS Trusted Advisor includes a security check for IAM Access Key Rotation. It identifies IAM users with access keys that have not been rotated within AWS-recommended timeframes, helping companies monitor and improve credential hygiene. The other services listed do not provide IAM access key rotation checks.

Question 259

A company needs to consolidate the billing for multiple AWS accounts. The company needs to use one account to pay on behalf of all the other accounts. Which AWS service or tool should the company use to meet this requirement?

A. AWS Trusted Advisor
B. AWS Organizations
C. AWS Budgets
D. AWS Service Catalog
Show Answer
Correct Answer: B
Explanation:
Consolidated billing, where one account pays for charges from multiple AWS accounts, is provided by AWS Organizations. It allows you to designate a management (payer) account that centrally manages billing and payments for all member accounts.

Question 260

Which AWS service provides users with AWS issued reports, certifications, accreditations, and third-party attestations?

A. AWS Artifact
B. AWS Trusted Advisor
C. AWS Health Dashboard
D. AWS Config
Show Answer
Correct Answer: A
Explanation:
AWS Artifact is the service that provides on-demand access to AWS-issued compliance reports, certifications, accreditations, and third-party attestations (e.g., PCI, ISO, SOC). The other options do not provide compliance documentation.

Question 261

Which of the following can be components of a VPC in the AWS Cloud? (Choose two.)

A. Amazon API Gateway
B. Amazon S3 buckets and objects
C. AWS Storage Gateway
D. Internet gateway
E. Subnet
Show Answer
Correct Answer: D, E
Explanation:
A Virtual Private Cloud (VPC) is a logically isolated network in AWS, and its native components include networking constructs. A subnet is a fundamental component that defines IP ranges within a VPC. An internet gateway is a VPC-attached component that enables communication between resources in the VPC and the public internet. Amazon API Gateway, Amazon S3, and AWS Storage Gateway are AWS services that are not components contained within a VPC.

$19

Get all 715 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.