Amazon

CLF-C02 Free Practice Questions — Page 7

Question 62

A company is planning to migrate to the AWS Cloud. The company is conducting organizational transformation and wants to become more responsive to customer inquiries and feedback. Which task should the company perform to meet these requirements, according to the AWS Cloud Adoption Framework (AWS CAF)?

A. Realign teams to focus on products and value streams.
B. Create new value propositions with new products and services.
C. Use a new data and analytics platform to create actionable insights.
D. Migrate and modernize legacy infrastructure.
Show Answer
Correct Answer: A
Explanation:
According to the AWS Cloud Adoption Framework (AWS CAF), the Organization perspective emphasizes reorganizing around products and value streams and adopting agile ways of working to improve customer focus and responsiveness. This directly addresses the goal of becoming more responsive to customer inquiries and feedback during organizational transformation. The other options relate to business innovation, data platforms, or technology modernization rather than the organizational change described.

Question 63

Which AWS service gives users the ability to deploy highly repeatable infrastructure configurations?

A. AWS CloudFormation
B. AWS CodeDeploy
C. AWS CodeBuild
D. AWS Systems Manager
Show Answer
Correct Answer: A
Explanation:
AWS CloudFormation provides infrastructure as code (IaC) using templates to define and provision AWS resources in a consistent, automated, and highly repeatable way. CodeDeploy automates application deployments, CodeBuild compiles and tests code, and Systems Manager helps manage and operate infrastructure rather than define repeatable infrastructure configurations.

Question 64

Which AWS services can host PostgreSQL databases? (Choose two.)

A. Amazon S3
B. Amazon Aurora
C. Amazon EC2
D. Amazon OpenSearch Service
E. Amazon Elastic File System (Amazon EFS)
Show Answer
Correct Answer: B, C
Explanation:
Amazon Aurora offers a PostgreSQL-compatible managed database engine (Aurora PostgreSQL). Amazon EC2 can host a self-managed PostgreSQL installation. Amazon S3 is object storage, Amazon OpenSearch Service is for search/analytics, and Amazon EFS is a network file system rather than a database hosting service.

Question 65

A company wants to log in securely to Linux Amazon EC2 instances. How can the company accomplish this goal?

A. Use SSH keys.
B. Use a VPN.
C. Use end-to-end encryption.
D. Use Amazon Route 53.
Show Answer
Correct Answer: A
Explanation:
Linux Amazon EC2 instances are typically accessed securely using SSH with public/private key pairs. SSH keys provide strong authentication for remote login. A VPN can secure network transport but is not the primary authentication mechanism for logging into an EC2 instance. End-to-end encryption is a general concept, and Amazon Route 53 is a DNS service unrelated to instance authentication.

Question 66

A company needs to manage multiple logins across AWS accounts within the same organization in AWS Organizations. Which AWS service should the company use to meet this requirement?

A. Amazon VPC
B. Amazon GuardDuty
C. Amazon Cognito
D. AWS IAM Identity Center
Show Answer
Correct Answer: D
Explanation:
AWS IAM Identity Center (formerly AWS Single Sign-On) is the AWS service designed to centrally manage user identities and provide single sign-on access across multiple AWS accounts in an AWS Organization. Amazon Cognito is for application user authentication, GuardDuty is for threat detection, and Amazon VPC is for networking.

Question 67

A company wants to manage access and permissions for its third-party software as a service (SaaS) applications. The company wants to use a portal where end users can access assigned AWS accounts and AWS Cloud applications. Which AWS service should the company use to meet these requirements?

A. Amazon Cognito
B. AWS IAM Identity Center (AWS Single Sign-On)
C. AWS Identity and Access Management (IAM)
D. AWS Directory Service for Microsoft Active Directory
Show Answer
Correct Answer: B
Explanation:
AWS IAM Identity Center (formerly AWS Single Sign-On) provides a user portal for workforce users to access assigned AWS accounts and cloud applications, including third-party SaaS applications, with centralized identity and permission management.

Question 68

Which AWS service enables users to create copies of resources across AWS Regions?

A. Amazon ElastiCache
B. AWS CloudFormation
C. AWS CloudTrail
D. AWS Systems Manager
Show Answer
Correct Answer: B
Explanation:
AWS CloudFormation enables infrastructure as code using templates, which can be deployed in multiple AWS Regions to create copies of infrastructure resources across Regions. The other options do not provide cross-Region infrastructure replication capabilities.

Question 69

A company wants to update its online data processing application by implementing container-based services that run for 4 hours at a time. The company does not want to provision or manage server instances. Which AWS service will meet these requirements?

A. AWS Lambda
B. AWS Fargate
C. Amazon EC2
D. AWS Elastic Beanstalk
Show Answer
Correct Answer: B
Explanation:
AWS Fargate is the serverless compute engine for containers, allowing containerized applications to run without provisioning or managing server instances. Running containers for 4 hours is well within Fargate's use case. AWS Lambda is limited to a maximum execution time of 15 minutes, Amazon EC2 requires managing instances, and Elastic Beanstalk provisions and manages underlying EC2 infrastructure rather than providing serverless container execution.

Question 70

A company's cloud environment includes Amazon EC2 instances and Application Load Balancers. The company wants to improve protections for its cloud resources against DDoS attacks. The company also wants to have real-time visibility into any DDoS attacks. Which AWS service will meet these requirements?

A. AWS Shield Standard
B. AWS Firewall Manager
C. AWS Shield Advanced
D. Amazon GuardDuty
Show Answer
Correct Answer: C
Explanation:
AWS Shield Advanced provides enhanced DDoS protection for resources such as Amazon EC2 and Application Load Balancers, along with near real-time visibility into DDoS attacks through the AWS console, APIs, and Amazon CloudWatch metrics. Shield Standard provides baseline protection but does not include the advanced attack visibility and reporting required. AWS Firewall Manager centrally manages security policies, and Amazon GuardDuty detects threats but is not a DDoS protection service.

Question 71

An ecommerce company wants to distribute traffic between the Amazon EC2 instances that host its website. Which AWS service or resource will meet these requirements?

A. Application Load Balancer
B. AWS WAF
C. AWS CloudHSM
D. AWS Direct Connect
Show Answer
Correct Answer: A
Explanation:
An Application Load Balancer (ALB) distributes incoming HTTP/HTTPS traffic across multiple Amazon EC2 instances, improving availability and scalability. AWS WAF filters web requests, AWS CloudHSM provides hardware security modules for key management, and AWS Direct Connect provides dedicated network connectivity rather than traffic distribution.

$19

Get all 713 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.