A company is planning to migrate to the AWS Cloud. The company is conducting organizational transformation and wants to become more responsive to customer inquiries and feedback.
Which task should the company perform to meet these requirements, according to the AWS Cloud Adoption Framework (AWS CAF)?
A. Realign teams to focus on products and value streams.
B. Create new value propositions with new products and services.
C. Use a new data and analytics platform to create actionable insights.
D. Migrate and modernize legacy infrastructure.
Show Answer
Correct Answer: A
Explanation: According to the AWS Cloud Adoption Framework, the Organization/People perspectives emphasize organizational transformation to improve agility and customer responsiveness. Realigning teams around products and value streams enables faster feedback loops, better ownership, and quicker responses to customer inquiries, directly meeting the stated requirement.
Question 63
Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?
A. AWS CloudFormation
B. AWS CodeDeploy
C. AWS CodeBuild
D. AWS Systems Manager
Show Answer
Correct Answer: A
Explanation: AWS CloudFormation enables infrastructure as code by defining resources in templates, allowing automated, consistent, and highly repeatable deployment of AWS infrastructure.
Question 64
Which AWS services can host PostgreSQL databases? (Choose two.)
A. Amazon S3
B. Amazon Aurora
C. Amazon EC2
D. Amazon OpenSearch Service
E. Amazon Elastic File System (Amazon EFS)
Show Answer
Correct Answer: B, C
Explanation: Amazon Aurora offers a PostgreSQL‑compatible managed database engine, allowing you to run PostgreSQL workloads without managing the underlying infrastructure. Amazon EC2 can host PostgreSQL by installing and managing the database software on virtual servers. The other options are storage or search services and do not host PostgreSQL databases.
Question 65
A company wants to log in securely to Linux Amazon EC2 instances.
How can the company accomplish this goal?
A. Use SSH keys.
B. Use a VPN.
C. Use end-to-end encryption.
D. Use Amazon Route 53.
Show Answer
Correct Answer: A
Explanation: Secure login to Linux Amazon EC2 instances is typically done using SSH with key pairs. SSH keys provide strong, asymmetric authentication without transmitting passwords, and are the standard, AWS-recommended method for securely accessing Linux EC2 instances. The other options do not directly provide instance login authentication.
Question 66
A company needs to manage multiple logins across AWS accounts within the same organization in AWS Organizations.
Which AWS service should the company use to meet this requirement?
A. Amazon VPC
B. Amazon GuardDuty
C. Amazon Cognito
D. AWS IAM Identity Center
Show Answer
Correct Answer: D
Explanation: AWS IAM Identity Center (formerly AWS Single Sign-On) is designed to manage centralized access and single sign-on across multiple AWS accounts within an AWS Organizations setup. It allows users to log in once and access multiple accounts and applications. The other options do not provide cross-account identity and access management for users.
Question 67
A company wants to manage access and permissions for its third-party software as a service (SaaS) applications. The company wants to use a portal where end users can access assigned AWS accounts and AWS Cloud applications.
Which AWS service should the company use to meet these requirements?
A. Amazon Cognito
B. AWS IAM Identity Center (AWS Single Sign-On)
C. AWS Identity and Access Management (IAM)
D. AWS Directory Service for Microsoft Active Directory
Show Answer
Correct Answer: B
Explanation: AWS IAM Identity Center (formerly AWS Single Sign-On) provides a centralized portal for end users to access assigned AWS accounts and integrated third-party SaaS applications, while allowing administrators to manage identities, permissions, and access across AWS and cloud applications. The other options do not provide a unified end-user access portal for SaaS and multiple AWS accounts.
Question 68
Which AWS service enables users to create copies of resources across AWS Regions?
A. Amazon ElastiCache
B. AWS CloudFormation
C. AWS CloudTrail
D. AWS Systems Manager
Show Answer
Correct Answer: B
Explanation: AWS CloudFormation enables users to define infrastructure as code and deploy the same set of resources repeatedly. Using the same template (and features like StackSets), resources can be created consistently across multiple AWS Regions. The other options do not provide cross-region resource provisioning capabilities.
Question 69
A company wants to update its online data processing application by implementing container-based services that run for 4 hours at a time. The company does not want to provision or manage server instances.
Which AWS service will meet these requirements?
A. AWS Lambda
B. AWS Fargate
C. Amazon EC2
D. AWS Elastic Beanstalk
Show Answer
Correct Answer: B
Explanation: The application requires container-based services that can run for up to 4 hours without managing servers. AWS Fargate is a serverless compute engine for containers that supports long-running container tasks and removes the need to provision or manage EC2 instances. AWS Lambda is limited to a maximum execution time of 15 minutes, Amazon EC2 requires server management, and Elastic Beanstalk still involves managing underlying instances.
Question 70
A company's cloud environment includes Amazon EC2 instances and Application Load Balancers. The company wants to improve protections for its cloud resources against DDoS attacks. The company also wants to have real-time visibility into any DDoS attacks.
Which AWS service will meet these requirements?
A. AWS Shield Standard
B. AWS Firewall Manager
C. AWS Shield Advanced
D. Amazon GuardDuty
Show Answer
Correct Answer: C
Explanation: AWS Shield Advanced provides enhanced DDoS protection for EC2 instances and Application Load Balancers, along with real-time visibility into attacks through detailed metrics, dashboards, and alerts. It offers advanced detection, mitigation, and reporting capabilities that go beyond the automatic protections of Shield Standard, meeting both the protection and real-time monitoring requirements.
Question 71
An ecommerce company wants to distribute traffic between the Amazon EC2 instances that host its website.
Which AWS service or resource will meet these requirements?
A. Application Load Balancer
B. AWS WAF
C. AWS CloudHSM
D. AWS Direct Connect
Show Answer
Correct Answer: A
Explanation: To distribute incoming web traffic across multiple Amazon EC2 instances, a load balancer is required. An Application Load Balancer (ALB) is designed to route HTTP and HTTPS traffic and balance it across EC2 instances, improving availability and scalability. AWS WAF is for web application firewall protection, CloudHSM is for hardware-based key management, and Direct Connect provides dedicated network connectivity, none of which distribute traffic.
$19
Get all 715 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.