Amazon

CLF-C02 Free Practice Questions — Page 8

Question 72

What is the MOST secure way to store passwords on AWS?

A. Store passwords in an Amazon S3 bucket.
B. Store passwords as AWS CloudFormation parameters.
C. Store passwords in AWS Storage Gateway.
D. Store passwords in AWS Secrets Manager.
Show Answer
Correct Answer: D
Explanation:
AWS Secrets Manager is the AWS service specifically designed for securely storing, managing, and rotating secrets such as passwords, database credentials, and API keys. Amazon S3, CloudFormation parameters, and Storage Gateway are not the recommended secure secret management solution for passwords.

Question 73

An AWS user wants to proactively detect when an instance or account might be compromised or if there are threats from attacks. Which AWS service should the user choose?

A. Amazon GuardDuty
B. AWS WAF
C. AWS Shield
D. Amazon Inspector
Show Answer
Correct Answer: A
Explanation:
Amazon GuardDuty is AWS's managed threat detection service. It continuously monitors AWS accounts, workloads, and data sources (such as CloudTrail, VPC Flow Logs, and DNS logs) to identify suspicious activity, compromised instances, credential misuse, and other potential threats. AWS WAF protects web applications, AWS Shield provides DDoS protection, and Amazon Inspector assesses vulnerabilities rather than providing continuous threat detection.

Question 74

A company is building an application that will receive millions of database queries each second. The company needs the data store for the application to scale to meet these needs. Which AWS service will meet this requirement?

A. Amazon DynamoDB
B. AWS Cloud9
C. Amazon ElastiCache for Memcached
D. Amazon Neptune
Show Answer
Correct Answer: A
Explanation:
Amazon DynamoDB is a fully managed NoSQL key-value and document database designed to scale horizontally and handle millions of requests per second with low latency. AWS Cloud9 is a development environment, ElastiCache for Memcached is an in-memory cache rather than the primary scalable database, and Amazon Neptune is a graph database optimized for graph workloads rather than general high-throughput key-value access.

Question 75

Which AWS service or feature supports governance, compliance, and risk auditing of AWS accounts?

A. Multi-factor authentication (MFA)
B. AWS Lambda
C. Amazon Simple Notification Service (Amazon SNS)
D. AWS CloudTrail
Show Answer
Correct Answer: D
Explanation:
AWS CloudTrail records API activity and account events to support governance, compliance, operational auditing, and risk auditing across AWS accounts. MFA enhances security, Lambda is a compute service, and Amazon SNS is a messaging service, not an auditing service.

Question 76

Which AWS service or feature requires an internet service provider (ISP) and a colocation facility to be implemented?

A. AWS VPN
B. Amazon Connect
C. AWS Direct Connect
D. Internet gateway
Show Answer
Correct Answer: C
Explanation:
AWS Direct Connect is the AWS service that establishes a dedicated private network connection from an on-premises environment to AWS through an AWS Direct Connect location, which is typically a colocation facility or via a Direct Connect Partner. This generally involves working with a network service provider/ISP. AWS VPN uses the public internet, Amazon Connect is a managed contact center service, and an Internet Gateway is a VPC networking component.

Question 77

A company wants a solution that will automatically adjust the number of Amazon EC2 instances that are being used based on the current load. Which AWS offering will meet these requirements?

A. Dedicated Hosts
B. Placement groups
C. Auto Scaling groups
D. Reserved Instances
Show Answer
Correct Answer: C
Explanation:
Amazon EC2 Auto Scaling groups automatically adjust the number of EC2 instances in response to demand or defined metrics, maintaining performance and optimizing cost. Dedicated Hosts provide dedicated physical servers, Placement Groups influence instance placement for networking/performance, and Reserved Instances are a pricing discount mechanism rather than an automatic scaling feature.

Question 78

A company that operates on-premises servers decides to start a new line of business. The company determines that additional servers are required for the new workloads. Which advantage of cloud computing can help the company to provision additional infrastructure as quickly as possible?

A. Benefit from massive economies of scale
B. Increase speed and agility
C. Trade fixed expense for variable expense
D. Go global in minutes
Show Answer
Correct Answer: B
Explanation:
The key requirement is provisioning additional infrastructure as quickly as possible. A core advantage of cloud computing is increased speed and agility, allowing resources to be provisioned in minutes rather than waiting for procurement and installation of on-premises hardware.

Question 79

Which AWS service can manage permissions for AWS resources by using policies?

A. Amazon Inspector
B. Amazon Detective
C. AWS Identity and Access Management (IAM)
D. Amazon GuardDuty
Show Answer
Correct Answer: C
Explanation:
AWS Identity and Access Management (IAM) manages permissions for AWS resources using identity-based and resource-based policies. Amazon Inspector assesses workloads for vulnerabilities, Amazon Detective helps investigate security findings, and Amazon GuardDuty detects threats; none of these services manage access permissions.

Question 80

A company needs to run some of its workload in the AWS Cloud. The company needs to keep some of the workload in its own on-site data center due to compliance reasons. Which AWS service will meet these requirements?

A. AWSConfig
B. AWS Outposts
C. Amazon Lightsail
D. Amazon Connect
Show Answer
Correct Answer: B
Explanation:
AWS Outposts extends AWS infrastructure and services to on-premises data centers, enabling a hybrid architecture where some workloads run locally for compliance while integrating with the AWS Cloud. AWS Config is a configuration auditing service, Amazon Lightsail is a simplified cloud hosting service, and Amazon Connect is a cloud contact center service.

Question 81

A company wants to connect its supported AWS services and VPCs. The company does not want to expose its internal traffic to the public internet. Which AWS service will meet these requirements?

A. Amazon Inspector
B. AWS PrivateLink
C. Amazon Connect
D. AWS Internet Gateway
Show Answer
Correct Answer: B
Explanation:
AWS PrivateLink enables private connectivity between VPCs and supported AWS services over the AWS network without exposing traffic to the public internet. Amazon Inspector is a security assessment service, Amazon Connect is a contact center service, and an Internet Gateway provides internet connectivity rather than private connectivity.

$19

Get all 713 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.