A company uses Amazon Aurora as its database service. The company wants to encrypt its databases and database backups.
Which party manages the encryption of the database clusters and database snapshots, according to the AWS shared responsibility model?
A. AWS
B. The company
C. AWS Marketplace partners
D. Third-party partners
Show Answer
Correct Answer: B
Explanation: Under the AWS shared responsibility model, AWS secures and operates the underlying managed service infrastructure, but customers are responsible for protecting their data, including deciding to enable encryption and managing the encryption configuration and KMS keys for Amazon Aurora database clusters and snapshots. Therefore, the company is responsible for encryption of its databases and backups.
Question 315
A company runs MySQL database workloads on self-managed servers in an on-premises data center. The company wants to migrate the database workloads to an AWS managed service.
Which migration strategy should the company use?
A. Rehost
B. Repurchase
C. Refactor
D. Replatform
Show Answer
Correct Answer: D
Explanation: Moving MySQL workloads from self-managed on-premises servers to an AWS managed database service (such as Amazon RDS for MySQL or Amazon Aurora MySQL) is a replatform migration. Replatforming retains the core application but changes the underlying platform to a managed service to gain operational benefits. Rehosting would move the existing servers with minimal or no changes, repurchasing means replacing with a different commercial/SaaS product, and refactoring involves significant application redesign.
Question 316
Which AWS service or resource can a company use to deploy AWS WAF rules?
A. Amazon EC2
B. Application Load Balancer
C. AWS Trusted Advisor
D. Network Load Balancer
Show Answer
Correct Answer: B
Explanation: AWS WAF is associated with supported Layer 7 resources such as Application Load Balancers, Amazon CloudFront distributions, Amazon API Gateway REST APIs, AWS AppSync, Amazon Cognito user pools, and AWS Verified Access. It is not deployed directly to EC2 instances or Network Load Balancers, and AWS Trusted Advisor is unrelated to WAF rule deployment.
Question 317
Which AWS service can migrate data between AWS storage services?
A. AWS DataSync
B. AWS Direct Connect
C. AWS Lake Formation
D. Amazon S3
Show Answer
Correct Answer: A
Explanation: AWS DataSync is the managed data transfer service designed to migrate and synchronize data between AWS storage services (such as Amazon S3, Amazon EFS, and Amazon FSx), as well as between on-premises storage and AWS. AWS Direct Connect provides dedicated network connectivity, AWS Lake Formation is for building data lakes, and Amazon S3 is a storage service rather than a migration service.
Question 318
A company uses a third-party identity provider (IdP). The company wants to provide its employees with access to AWS accounts and services without requiring another set of login credentials.
Which AWS service will meet this requirement?
A. AWS Directory Service
B. Amazon Cognito
C. AWS IAM Identity Center
D. AWS Resource Access Manager (AWS RAM)
Show Answer
Correct Answer: C
Explanation: AWS IAM Identity Center is the correct service for workforce federation with a third-party identity provider. It enables employees to use existing corporate credentials via SAML/OIDC to access AWS accounts and services without separate AWS login credentials. Amazon Cognito is intended primarily for customer/application user authentication, AWS Directory Service provides managed directory integration rather than centralized workforce SSO to AWS accounts, and AWS RAM is for sharing AWS resources, not identity federation.
Question 319
Which cloud concept is demonstrated by using AWS Cost Explorer?
A. Rightsizing
B. Reliability
C. Resilience
D. Modernization
Show Answer
Correct Answer: A
Explanation: AWS Cost Explorer helps analyze AWS spending and usage, including identifying underutilized resources and providing rightsizing recommendations to optimize cost and resource allocation. This aligns with the cloud concept of rightsizing rather than reliability, resilience, or modernization.
Question 320
Which AWS service or resource can identify and provide reports on IAM resources in one AWS account that is shared with another AWS account?
A. IAM credential report
B. AWS IAM Identity Center (AWS Single Sign-On)
C. AWS Identity and Access Management Access Analyzer
D. Amazon Cognito user pool
Show Answer
Correct Answer: C
Explanation: AWS Identity and Access Management (IAM) Access Analyzer identifies resources shared with external entities, including other AWS accounts, and generates findings and reports about cross-account access. IAM credential reports only summarize IAM user credential status, IAM Identity Center provides workforce access management, and Amazon Cognito user pools manage application user identities.
Question 321
A company has deployed a web application to Amazon EC2 instances. The EC2 instances have low usage.
Which AWS service or feature should the company use to rightsize the EC2 instances?
A. AWS Config
B. AWS Cost Anomaly Detection
C. AWS Budgets
D. AWS Compute Optimizer
Show Answer
Correct Answer: D
Explanation: AWS Compute Optimizer analyzes historical utilization metrics for Amazon EC2 instances and provides rightsizing recommendations to reduce cost and improve performance. AWS Config assesses configuration compliance, AWS Cost Anomaly Detection identifies unusual spending patterns, and AWS Budgets tracks spending against budget thresholds.
Question 322
A company wants to manage sign-in security for workforce users. The company needs to create workforce users and centrally manage their access across all the company's AWS accounts and applications.
Which AWS service will meet these requirements?
A. AWS Audit Manager
B. Amazon Cognito
C. AWS Security Hub
D. AWS IAM Identity Center (AWS Single Sign-On)
Show Answer
Correct Answer: D
Explanation: AWS IAM Identity Center (formerly AWS Single Sign-On) is designed for workforce identities, allowing organizations to create or federate workforce users and centrally manage their access to multiple AWS accounts and supported applications. Amazon Cognito is primarily for customer/application user authentication rather than centralized workforce access management. Audit Manager and Security Hub do not provide identity and sign-in management.
Question 323
A company wants to define a central data protection policy that works across AWS services for compute, storage, and database resources.
Which AWS service will meet this requirement?
A. AWS Batch
B. AWS Elastic Disaster Recovery
C. AWS Backup
D. Amazon FSx
Show Answer
Correct Answer: C
Explanation: AWS Backup is the AWS service designed to centrally define and enforce data protection policies across supported AWS compute, storage, and database services. It provides centralized backup management, automated backup plans, lifecycle policies, and cross-account/cross-Region capabilities. AWS Batch is for batch computing, AWS Elastic Disaster Recovery focuses on disaster recovery, and Amazon FSx is a managed file system service.
$19
Get all 713 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.