Which AWS service can be used to send alerts when a specific Amazon CloudWatch alarm is invoked?
A. AWS CloudTrail
B. Amazon Simple Notification Service (Amazon SNS)
C. Amazon Simple Queue Service (Amazon SQS)
D. Amazon EventBridge
Show Answer
Correct Answer: B
Explanation: Amazon CloudWatch alarms can be configured to publish notifications to an Amazon SNS topic when they enter a specified state (such as ALARM). SNS then delivers alerts via email, SMS, HTTP endpoints, Lambda, and other supported subscribers. CloudTrail records API activity, SQS queues messages rather than sending notifications, and EventBridge can react to alarm state changes but the standard service used to send alerts from CloudWatch alarms is Amazon SNS.
Question 32
A company runs an application on AWS that performs batch jobs. The application is fault-tolerant and can handle interruptions. The company wants to optimize the cost to run the application.
Which AWS offering will meet these requirements?
A. Amazon Macie
B. Amazon Neptune
C. Amazon EC2 Spot Instances
D. Amazon EC2 On-Demand Instances
Show Answer
Correct Answer: C
Explanation: Amazon EC2 Spot Instances are designed for fault-tolerant, interruption-tolerant workloads such as batch processing. They use spare EC2 capacity at significant discounts compared to On-Demand Instances, making them the most cost-effective choice for this scenario. Amazon Macie is a data security service, Neptune is a graph database, and On-Demand Instances do not optimize cost for interruptible batch jobs.
Question 33
Which AWS tool or feature acts as a VPC firewall at the subnet level?
A. Security group
B. Network ACL
C. Traffic Mirroring
D. Internet gateway
Show Answer
Correct Answer: B
Explanation: Network ACLs act as stateless firewalls at the subnet level in a VPC. They control inbound and outbound traffic for subnets using allow and deny rules. Security groups operate at the instance/ENI level, Traffic Mirroring is for packet capture, and an Internet gateway provides internet connectivity rather than firewalling.
Question 35
Which AWS service provides machine learning capability to detect and analyze content in images and videos?
A. Amazon Connect
B. Amazon Lightsail
C. Amazon Personalize
D. Amazon Rekognition
Show Answer
Correct Answer: D
Explanation: Amazon Rekognition is the AWS computer vision service that uses machine learning to analyze images and videos, including object and scene detection, facial analysis, text detection, moderation, and celebrity recognition. Amazon Connect is a contact center service, Lightsail is a simplified VPS offering, and Personalize provides recommendation capabilities rather than image/video analysis.
Question 36
Which of the following are AWS best practice recommendations for the use of AWS Identity and Access Management (IAM)? (Choose two.)
A. Use the AWS account root user for daily access.
B. Use access keys and secret access keys on Amazon EC2.
C. Rotate credentials on a regular basis.
D. Create a shared set of access keys for system administrators.
E. Configure multi-factor authentication (MFA).
Show Answer
Correct Answer: C, E
Explanation: AWS IAM best practices include rotating credentials regularly and enabling multi-factor authentication (MFA) for additional account protection. AWS also recommends avoiding use of the root user for daily tasks, avoiding long-term access keys on EC2 in favor of IAM roles, and not sharing access keys among administrators.
Question 37
Which AWS service gives users on-demand, self-service access to AWS compliance control reports?
A. AWS Config
B. Amazon GuardDuty
C. AWS Trusted Advisor
D. AWS Artifact
Show Answer
Correct Answer: D
Explanation: AWS Artifact provides on-demand, self-service access to AWS compliance reports (such as SOC reports, ISO certifications, and PCI documents) and agreements. AWS Config assesses resource configurations, GuardDuty detects threats, and Trusted Advisor provides best-practice recommendations.
Question 38
Which combination of AWS services can be used to move a commercial relational database to an Amazon-managed open-source database? (Choose two.)
A. AWS Database Migration Service (AWS DMS)
B. AWS software development kits (SDKs)
C. AWS Schema Conversion Tool
D. AWS Systems Manager
E. Amazon EMR
Show Answer
Correct Answer: A, C
Explanation: AWS Database Migration Service (AWS DMS) migrates data from the source database to the target. AWS Schema Conversion Tool (AWS SCT) converts database schemas and code objects from commercial database engines to compatible open-source engines such as PostgreSQL or MySQL, making them the standard combination for heterogeneous database migration.
Question 39
A company uses Amazon WorkSpaces.
Which task is the responsibility of AWS, according to the AWS shared responsibility model?
A. Set up multi-factor authentication (MFA) for each WorkSpaces user account.
B. Ensure the environmental safety and security of the AWS infrastructure that hosts WorkSpaces.
C. Provide security for WorkSpaces user accounts through AWS Identity and Access Management (IAM).
D. Configure AWS CloudTrail to log API calls and user activity.
Show Answer
Correct Answer: B
Explanation: Under the AWS shared responsibility model for managed services like Amazon WorkSpaces, AWS is responsible for the security 'of' the cloud, including the physical facilities, environmental controls, and infrastructure hosting the service. Customers are responsible for security 'in' the cloud, such as configuring MFA, managing IAM access, and enabling services like CloudTrail for their accounts.
Question 40
A company is building AWS architecture to deliver real-time data feeds from an on-premises data center into an application that runs on AWS. The company needs a consistent network connection with minimal latency.
What should the company use to connect the application and the data center to meet these requirements?
A. AWS Direct Connect
B. Public internet
C. AWS VPN
D. Amazon Connect
Show Answer
Correct Answer: A
Explanation: AWS Direct Connect provides a dedicated private network connection between an on-premises data center and AWS, offering more consistent performance, lower latency, and higher reliability than internet-based connections. AWS VPN traverses the public internet and cannot guarantee minimal latency. Amazon Connect is a contact center service, and the public internet does not provide the required consistency.
Question 41
A company wants to use Amazon EC2 instances for a stable production workload that will run for 1 year.
Which instance purchasing option meets these requirements MOST cost-effectively?
A. Dedicated Hosts
B. Reserved Instances
C. On-Demand Instances
D. Spot Instances
Show Answer
Correct Answer: B
Explanation: Reserved Instances are the most cost-effective choice for a stable, predictable EC2 workload that will run continuously for a 1-year term. They provide significant discounts compared to On-Demand pricing in exchange for a 1- or 3-year commitment. Dedicated Hosts are for licensing/compliance needs, Spot Instances are interruptible and unsuitable for stable production workloads, and On-Demand is more expensive for long-running predictable usage.
$19
Get all 713 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.