Udemy Practice Exam 5 Flashcards

1
Q

Which AWS tool/service will help you define your cloud infrastructure using popular programming languages such as Python and JavaScript?

A

AWS Cloud Development Kit (CDK)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A data science team would like to build Machine Learning models for its projects. Which AWS service can it use?

A

Amazon SageMaker

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

An e-commerce company would like to build a chatbot for its customer service using Natural Language Understand (NLU). As a Cloud Practitioner, which AWS service would you use?

A

Amazon Lex

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Natural language processing (NLP) service that uses machine learning to find meaning and insights in text.

A

Amazon Comprehend

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A company needs to keep sensitive data in its own data center due to compliance but would still like to deploy resources using AWS. Which Cloud deployment model does this refer to?

A

Hybrid Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following statements is an AWS best practice when architecting for the Cloud?
-Automation
-Servers, not services
-Close coupling
-Security comes last

A

-Automation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which AWS service can be used to send, store, and receive messages between software components at any volume to decouple application tiers?

A

-Amazon SQS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

According to the Well-Architected Framework, which of the following action is recommended in the Security pillar?
-Use AWS Cost Explorer to view and track your usage in detail
-Use Amazon CloudWatch to measure overall efficiency
-Use AWS CloudFormation to automate security best practices
-Use AWS KMS to encrypt data

A

Use AWS KMS to encrypt data
“Protect data in transit and at rest”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which AWS service can be used to view the most comprehensive billing details for the past month?

A

AWS Cost & Usage Reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A production company would like to establish an AWS managed VPN service between its on-premises network and AWS. Which item needs to be set up on the company’s side?

A

A customer gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which types of monitoring can be provided by Amazon CloudWatch? (Select TWO)
-Performance and availability of AWS services
-API Access
-Application performance
-Account management
-Resource utilization

A

-Application performance
-Resource utilization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A Cloud Practitioner would like to get operational insights of its resources to quickly identify any issues that might impact applications using those resources. Which AWS service can help with this task?

A

-AWS Systems Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

-You can create logical groups of resources such as applications, different layers of an application stack, or production versus development environments.
-Central place to view and manage your AWS resources,

A

-AWS Systems Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which of the following AWS Support plans is the MOST cost-effective when getting enhanced technical support by Cloud Support Engineers?

A

-Business

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

It provides enhanced technical support, but by Cloud Support Associates.

A

-Developer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A company would like to separate cost for AWS services by the department for cost allocation. Which of the following is the simplest way to achieve this task?

A

-Create tags for each department

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

A media company wants to enable customized content suggestions for the users of its movies streaming platform. Which AWS service can provide these personalized recommendations based on the historic data?

A

-Amazon Personalize

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

A developer would like to automate operations on his on-premises environment using Chef and Puppet. Which AWS service can help with this task?

A

AWS OpsWorks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which of the following IAM Security Tools allows you to review permissions granted to a user?

A

IAM access advisor
service permissions granted to a user and when those services were last accessed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Lists all users in your account and the status of their various credentials, including passwords, access keys, and MFA devices.

A

IAM credentials report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

A start-up would like to monitor its cost on the AWS Cloud and would like to choose an optimal Savings Plan. As a Cloud Practitioner, which AWS service would you use?

A

AWS Cost Explorer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

According to the Shared Responsibility Model, which of the following is both the responsibility of AWS and the customer? (Select two)
-Configuration management
-Data center security
-Customer data
-Disposal of disk drives
-Operating system (OS) configuration

A

-Configuration management
-Operating system (OS) configuration (host OS-AWS / guest OS-Customer)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which AWS service can inspect CloudFront distributions running on any HTTP web-server?

A

AWS WAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Allowing you to configure rules that allow, block, or monitor (count) web requests based on conditions that you define.

A

AWS WAF (web application firewall )

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Is a threat detection service that continuously monitors for malicious or unauthorized behavior to help you protect your AWS accounts and workloads.

A

AWS GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Automated security assessment service that helps improve the security and compliance of applications deployed on AWS.

A

Amazon Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

A company is planning to implement Chaos Engineering to expose any blind spots that can disrupt the resiliency of the application.

Which AWS service will help implement this requirement with the least effort?

A

AWS Fault Injection Simulator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Which of the following are the best practices when using AWS Organizations? (Select TWO)
-Create accounts per department
-Never use tags for billing
-Restrict account privileges using Service Control Policies (SCP)
-Disable CloudTrail on several accounts
-Do not use AWS Organizations to automate AWS account creation

A

-Create accounts per department
-Restrict account privileges using Service Control Policies (SCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

A research lab needs to be notified in case of a configuration change for security and compliance reasons. Which AWS service can assist with this task?

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Helps you protect secrets needed to access your applications, services, and IT resources. The service enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

A

AWS Secrets Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

A company using a hybrid cloud would like to store secondary backup copies of the on-premises data. Which S3 Storage Class would you use for a cost-optimal yet rapid access solution?

A

S3 One Zone - Infrequent Access
costs 20% less

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

S3 categories that don’t charge retrieval charge (2)

A

-S3 Standard
-S3 Intelligent-Tiering`

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

A company would like to audit requests made to an S3 bucket. As a Cloud Practitioner, which S3 feature would you recommend addressing this use-case?

A

S3 Access Logs

34
Q

Provides detailed records for the requests that are made to a bucket.

A

S3 Access Logs

35
Q

A company would like to move 50 petabytes (PBs) of data from its on-premises data centers to AWS in the MOST cost-effective way. As a Cloud Practitioner, which of the following solutions would you choose?

A

AWS Snowmobile
(up to 100PB)

36
Q

-computing and data transfer device
-on-board storage and compute power that provides select AWS services for use in edge locations.
-up to 100 TB of capacity.

A

AWS Snowball Edge

37
Q

up to 80 TB of capacity.

A

AWS Snowball

38
Q

8 TB capacity

A

AWS Snowcone

39
Q

Which AWS serverless service allows you to prepare data for analytics?

A

AWS Glue
(ETL)

40
Q

According to the Shared Responsibility Model, which of the following is a responsibility of the customer?
-Managing DynamoDB
-Firewall & networking configuration in EC2
-Protecting hardware infrastructure
-Edge locations security

A

-Firewall & networking configuration in EC2

41
Q

A company based in Sydney hosts its application on EC2 instances in ap-southeast-2. They would like to deploy the same EC2 instances in eu-south-1. Which of the following AWS entities can address this use-case?

A

Amazon Machine Image (AMI)

42
Q

A corporation would like to have a central user portal to log in to third-party business applications as well as accounts managed under AWS Organizations. As a Cloud Practitioner, which AWS service would you use for this task?

A

AWS Single Sign-On (SSO)

43
Q

A Cloud Practitioner would like to deploy identical resources across all regions and accounts using templates while estimating costs. Which AWS service can assist with this task?

A

AWS CloudFormation

44
Q

Which of the following services are provided by Amazon Route 53? (Select TWO)

-Transfer acceleration
-Domain registration
-IP routing
-Health checks and monitoring
-Load balancing

A

-Domain registration
-Health checks and monitoring

45
Q

Which security control tool can be used to deny traffic from a specific IP address?

A

Network ACL

46
Q

Which of the following statements is the MOST accurate when describing AWS Elastic Beanstalk?

A

It is a Platform as a Service (PaaS) which allows you to deploy and scale web applications and services
DEPLOY
SCALE

47
Q

Developers simply upload their application, and Elastic Beanstalk automatically handles the deployment details of capacity provisioning, load balancing, auto-scaling, and application health monitoring.

A

AWS Elastic Beanstalk

48
Q

An engineering team would like to cost-effectively run hundreds of thousands of batch computing workloads on AWS. As a Cloud Practitioner, which AWS service would you use for this task?

A

AWS Batch

49
Q

to plan, schedule, and execute your batch computing workloads across the full range of AWS compute services.

A

AWS Batch

50
Q

An organization would like to copy data across different Availability Zones (AZs) using EBS snapshots. Where are EBS snapshots stored in the AWS Cloud?

A

Amazon S3

51
Q

A company would like to define a set of rules to manage objects cost-effectively between storage classes. As a Cloud Practitioner, which Amazon S3 feature would you use?

A

S3 Lifecycle management

52
Q

Which AWS tool can provide best practice recommendations for performance, service limits, and cost optimization?

A

AWS Trusted Advisor

53
Q

A production company with predictable usage would like to reduce the cost of its Amazon EC2 instances by using reserved instances. Which of the following length terms are available for Amazon EC2 reserved instances? (Select TWO)

A

1 year

3 years

54
Q

Which of the following statements is INCORRECT regarding EBS Volumes?
-EBS Volumes are bound to a specific Availability Zone (AZ)
-EBS Volumes can be mounted to one instance at a time
-EBS Volumes can be bound to several Availability Zones (AZs)
-EBS Volumes can persist data after their termination

A

-EBS Volumes can be bound to several Availability Zones (AZs)

55
Q

Which of the following criteria are used to charge for Elastic Block Store (EBS) volumes? (Select TWO)

A

-Provisioned IOPS (input/output operations)
-Volume Type

56
Q

A multinational company has just moved its infrastructure to AWS Cloud and has employees traveling to different offices around the world. How should the company set the AWS accounts?

A

There is nothing to do, IAM is a global service

57
Q

Which service/tool will you use to create and provide trusted users with temporary security credentials that can control access to your AWS resources?

A

AWS Security Token Service (AWS STS)

58
Q

a web service that enables you to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that you authenticate (federated users).

A

AWS Security Token Service (AWS STS)

59
Q

A growing start-up has trouble identifying and protecting sensitive data at scale. Which AWS fully managed service can assist with this task?

A

Amazon Macie

60
Q

According to the Well-Architected Framework, which of the following statements are recommendations in the Operational Excellence pillar? (Select two)

-Automatically recover from failure
-Anticipate failure
-Enable traceability
-Make frequent, small, reversible changes
-Use serverless architectures

A

-Anticipate failure
-Make frequent, small, reversible changes

61
Q

An engineering team is new to the AWS Cloud and it would like to launch a dev/test environment with low monthly pricing. Which AWS service can address this use-case?

A

Amazon Lightsail

62
Q

A start-up would like to quickly deploy a popular technology on AWS. As a Cloud Practitioner, which AWS tool would you use for this task?

A

AWS Quick Starts references

63
Q

Which AWS service allows you to quickly and easily add user sign-up, sign-in, and access control to web and mobile applications?

A

Amazon Cognito

64
Q

authenticate users through social identity providers such as Facebook, Twitter, or Amazon, with SAML identity solutions, or by using your own identity system.

A

Amazon Cognito

65
Q

A company would like to reserve EC2 compute capacity for three years to reduce costs. The company also plans to increase their workloads during this period. As a Cloud Practitioner, which EC2 Reserved Instance type would you recommend?

A

Convertible Reserved Instances

66
Q

A company would like to create a private, high bandwidth network connection between its on-premises data centers and AWS Cloud. As a Cloud Practitioner, which of the following options would you recommend?

A

Direct Connect

67
Q

A brand new startup would like to remove its need to manage the underlying infrastructure and focus on the deployment and management of its applications. Which type of Cloud Computing does this refer to?

A

Platform as a Service (PaaS)

68
Q

A company would like to move its infrastructure to AWS Cloud. Which of the following should be included in the Total Cost of Ownership (TCO) estimate? (Select TWO)

A

Server administration

Power/Cooling

69
Q

A company needs to use a secure online data transfer tool/service that can automate the ongoing transfers from on-premises systems into AWS while providing support for incremental data backups.

Which AWS tool/service is an optimal fit for this requirement?

A

AWS DataSync

70
Q

secure online data transfer service that simplifies, automates, and accelerates copying terabytes of data to and from AWS storage services.

A

AWS DataSync

71
Q

Which of the following options is NOT a feature of Amazon Inspector?

-Automate security assessments
-Track configuration changes
-Analyze against unintended network accessibility
-Inspect running operating systems (OS) against known vulnerabilities

A

-Track configuration changes

72
Q

According to the Shared Responsibility Model, which of the following are responsibilities of AWS? (Select two)

-Data center security
-Encrypting application data
-Network operability
-Configuring IAM Roles

A

-Data center security
-Network operability

73
Q

The IT infrastructure at a university is deployed on AWS Cloud and it’s experiencing a read-intensive workload. As a Cloud Practitioner, which AWS service would you use to take the load off databases?

A

Amazon ElastiCache

74
Q

Which of the following options are the benefits of using AWS Elastic Load Balancing (ELB)? (Select TWO)

A

-High availability
-Fault tolerance

75
Q

The development team at a company manages 300 microservices and it is now trying to automate the code reviews to improve the code quality. Which tool/service is the right fit for this requirement?

A

Amazon CodeGuru
CodeGuru Reviewer
CodeGuru Profiler

76
Q

pinpoints an application’s most expensive lines of code by helping developers understand the runtime behavior of their applications, identify and remove code inefficiencies, improve performance, and significantly decrease compute costs.

A

CodeGuru Profiler

77
Q

Which AWS service can be used to subscribe to an RSS feed to be notified of the status of all AWS service interruptions?

A

AWS Service Health Dashboard

78
Q

Which of the following billing timeframes is applied when running a Windows EC2 on-demand instance?

A

Pay per second

79
Q

Which of the following AWS services can be used to generate, use, and manage encryption keys on the AWS Cloud?

A

AWS CloudHSM

80
Q

Which of the following statements is CORRECT regarding the scope of an Amazon Virtual Private Cloud (VPC)?

-A VPC spans all Availability Zones (AZs) within a region
-A VPC spans all subnets in all regions
-A VPC spans all Availability Zones (AZs) in all regions
-A VPC spans all regions within an Availability Zone (AZ)

A

-A VPC spans all Availability Zones (AZs) within a region

81
Q

Which AWS service would you use to create a logically isolated section of the AWS Cloud where you can launch AWS resources in your virtual network?

A

Virtual Private Cloud (VPC)

82
Q

Which AWS entity enables you to privately connect your VPC to an Amazon SQS queue?

A

VPC Interface Endpoint