Amazon

CLF-C02 Free Practice Questions — Page 3

Question 21

Which AWS service or feature provides a firewall at the subnet level within a VPC?

A. Security group
B. Network ACL
C. Elastic network interface
D. AWS WAF
Show Answer
Correct Answer: B
Explanation:
Network ACLs (NACLs) operate at the subnet level within a VPC and act as a stateless firewall controlling inbound and outbound traffic for subnets. Security groups apply at the instance/ENI level, Elastic Network Interfaces are network interfaces rather than firewalls, and AWS WAF protects web applications at the HTTP(S) layer.

Question 22

Which task is the customer's responsibility, according to the AWS shared responsibility model?

A. Patch a guest operating system that is deployed on an Amazon EC2 instance.
B. Control physical access to an AWS data center.
C. Control access to AWS underlying hardware.
D. Patch a host operating system that is deployed on Amazon S3.
Show Answer
Correct Answer: A
Explanation:
Under the AWS shared responsibility model, customers are responsible for security 'in' the cloud, including managing and patching the guest operating system on Amazon EC2 instances. AWS is responsible for security 'of' the cloud, including physical data center security, underlying hardware, and managed service host operating systems such as those supporting Amazon S3.

Question 23

Which of the following can the AWS Pricing Calculator do?

A. Project monthly AWS costs.
B. Calculate historical AWS costs.
C. Provide in-depth information about AWS pricing strategies.
D. Provide users with access to their monthly bills.
Show Answer
Correct Answer: A
Explanation:
The AWS Pricing Calculator is used to estimate and project the cost of AWS services for planned workloads, including projected monthly costs. It does not calculate historical costs (AWS Cost Explorer does that), does not primarily provide in-depth pricing strategy guidance, and does not provide access to monthly bills (the AWS Billing console does that).

Question 24

When designing AWS workloads to be operational even when there are component failures, what is an AWS best practice?

A. Perform quarterly disaster recovery tests.
B. Place the main component on the us-east-1 Region.
C. Design for automatic failover to healthy resources.
D. Design workloads to fit on a single Amazon EC2 instance.
Show Answer
Correct Answer: C
Explanation:
AWS Well-Architected reliability best practices emphasize designing workloads to tolerate component failures through automatic failover, redundancy, and recovery mechanisms. Automatic failover to healthy resources improves availability and fault tolerance. Quarterly disaster recovery tests are useful but do not by themselves make workloads operational during component failures. Placing the main component in a single Region (especially us-east-1) does not provide fault tolerance, and designing to fit on a single EC2 instance creates a single point of failure.

Question 25

Which AWS service provides DNS resolution?

A. Amazon CloudFront
B. Amazon VPC
C. Amazon Route 53
D. AWS Direct Connect
Show Answer
Correct Answer: C
Explanation:
Amazon Route 53 is AWS's managed Domain Name System (DNS) web service. It provides DNS resolution by translating domain names into IP addresses and supports authoritative DNS, health checks, and routing policies. CloudFront is a CDN, Amazon VPC provides networking, and AWS Direct Connect provides dedicated network connectivity.

Question 26

Which AWS service supports a company's ability to treat infrastructure as code?

A. AWS CodeDeploy
B. AWS Elastic Beanstalk
C. Amazon API Gateway
D. AWS CloudFormation
Show Answer
Correct Answer: D
Explanation:
AWS CloudFormation enables infrastructure as code (IaC) by allowing you to define and provision AWS infrastructure using declarative templates. CodeDeploy automates application deployments, Elastic Beanstalk simplifies application deployment and management, and API Gateway manages APIs rather than infrastructure.

Question 27

A company wants to migrate all of its on-premises infrastructure to the AWS Cloud. Before migration, the company wants estimate of costs for running its as-is infrastructure. Which AWS service or principle should the company use to meet this requirement?

A. AWS Pricing Calculator
B. AWS Well-Architected Framework
C. AWS shared responsibility model
D. AWS Cloud Adoption Framework (AWS CAF)
Show Answer
Correct Answer: A
Explanation:
AWS Pricing Calculator is the service designed to estimate the cost of running workloads on AWS, including modeling an existing on-premises environment before migration. The Well-Architected Framework provides architectural best practices, the shared responsibility model defines security responsibilities, and AWS CAF guides organizational cloud adoption rather than cost estimation.

Question 28

Which task is the responsibility of the customer, according to the AWS shared responsibility model?

A. Patch the Amazon DynamoDB operating system.
B. Secure Amazon CloudFront edge locations by allowing physical access according to the principle of least privilege.
C. Protect the hardware that runs AWS services.
D. Use AWS Identity and Access Management (IAM) according to the principle of least privilege.
Show Answer
Correct Answer: D
Explanation:
Under the AWS shared responsibility model, AWS is responsible for security of the cloud, including physical infrastructure, hardware, and managed service operating systems such as DynamoDB. Customers are responsible for security in the cloud, including configuring and using IAM with the principle of least privilege to control access to their resources.

Question 29

A company is learning about its responsibilities that are related to the management of Amazon EC2 instances. Which tasks for EC2 instances are the company’s responsibility, according to the AWS shared responsibility model? (Choose two.)

A. Install and patch the machine hypervisor.
B. Patch the guest operating system.
C. Encrypt data at rest on associated storage.
D. Install the physical hardware and cabling.
E. Provide physical security for the EC2 instances.
Show Answer
Correct Answer: B, C
Explanation:
Under the AWS shared responsibility model for Amazon EC2, AWS is responsible for the security of the cloud, including the physical facilities, hardware, networking, and the hypervisor. Customers are responsible for security in the cloud, including patching the guest operating system they install on EC2 instances and configuring protections such as encryption for data at rest on attached storage (for example, using EBS encryption).

Question 30

A cloud practitioner wants to use a highly available and scalable DNS service for its AWS workload. Which AWS service will meet this requirement?

A. Amazon Route 53
B. Amazon Lightsail
C. AWS Amplify Hosting
D. Amazon S3
Show Answer
Correct Answer: A
Explanation:
Amazon Route 53 is AWS's highly available and scalable Domain Name System (DNS) web service. It is designed to route end users to internet applications and supports DNS routing, health checks, and domain registration. The other options are not managed DNS services.

$19

Get all 713 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.