All practice questions
1473 questions
A healthcare organization hires a new compliance officer who needs permanent, individual access to log into the AWS Management Console to review compliance reports. Which AWS Identity and Access Management (IAM) entity should be created to grant this access?
A financial services firm wants to modernize its transaction auditing system. The technical lead recommends using separate microservices that communicate asynchronously and ensuring that test environments can be easily created and destroyed using automated scripts.
Which of the following AWS Cloud design principles do these recommendations demonstrate? (Select TWO.)
Select all that apply
An organization is configuring a secure network architecture on AWS with public-facing web servers and a private database tier. To meet strict compliance guidelines, the security team must implement a layered defense-in-depth strategy. They need to understand how Security Groups and Network Access Control Lists (Network ACLs) behave when filtering traffic across these tiers.
Which of the following statements accurately describe the behavior and configuration of Security Groups and Network ACLs in this scenario? (Select TWO.)
Select all that apply
A healthcare startup needs to verify its compliance posture by reviewing official security documentation and accepting a Business Associate Addendum (BAA) with AWS. Which of the following actions can the startup perform using AWS Artifact to meet these requirements? (Select TWO.)
Select all that apply
An organization hosts a multi-tier web application where Amazon EC2 instances in a private subnet receive traffic from a public-facing Application Load Balancer (ALB). The security team configures the EC2 instances' Security Group to allow inbound HTTP traffic on port 80 only from the ALB's Security Group, and allowed all outbound traffic. At the subnet level, the Network ACL (NACL) is modified to allow inbound HTTP traffic on port 80 from the ALB's private IP range, and allow outbound HTTP traffic on port 80 to the ALB's private IP range, with all other traffic blocked by default rules. Users report receiving 502 Bad Gateway errors from the ALB. Which configuration change is required to resolve this issue and allow successful traffic flow?
A retail company runs its e-commerce website on several Amazon Elastic Compute Cloud (Amazon EC2) instances. Under the AWS Shared Responsibility Model, which of the following security tasks is the sole responsibility of AWS?
A smart-vehicle manufacturer is launching an autonomous fleet management platform on AWS. To meet regional regulatory requirements, the manufacturer's legal department must execute a Business Associate Addendum (BAA) with AWS, and the risk assessment team must download the ISO/IEC 27001 certification report for the AWS physical infrastructure. Which AWS resource should the manufacturer use to accept this online agreement and retrieve the required certification?
A startup in the hospitality sector is launching a vacation rental booking application. The company wants to eliminate the need for upfront capital investments in physical servers and instead pay only for the compute resources they consume on a pay-as-you-go basis. Which AWS Cloud benefit is this startup leveraging, and what is its financial impact?
A financial services company is setting up its application environment on AWS. The environment will consist of developers who need to configure resources and applications running on Amazon EC2 instances that need to retrieve data from Amazon S3. Which two of the following actions align with AWS-recommended security best practices for managing identity and access in this scenario?
Select all that apply
A multiplayer gaming startup is redesigning its matchmaking and live tournament leaderboard system. The system experiences high, unpredictable spikes in traffic during weekend tournaments, but remains mostly idle during weekdays. The company wants to redesign the system to align with the AWS Cloud design principles of 'loose coupling' and 'services, not servers' to minimize operational overhead and handle failures gracefully. Which of the following architectural decisions best implement these design principles? (Select TWO.)
Select all that apply
A financial technology company wants to continuously monitor its AWS accounts for malicious activity and unauthorized behavior. The company needs a service that can analyze AWS CloudTrail event logs, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to detect issues like compromised EC2 instances or unauthorized API calls. Which AWS service should the company use to meet this requirement?
A logistics software provider is explaining the financial advantages of cloud migration to its stakeholders. The provider highlights that because AWS aggregates usage from hundreds of thousands of customers, it can achieve higher purchasing power and pass these savings back to customers in the form of lower pay-as-you-go prices. Which benefit of the AWS Cloud is the provider describing?
A financial services startup is planning to launch a new mobile application. The company wants to avoid purchasing physical servers and wants to focus its engineering resources on writing application code rather than managing data center infrastructure. Which of the following benefits of the AWS Cloud directly support this strategy? (Select TWO.)
Select all that apply
A company is migrating its relational database to Amazon RDS (Relational Database Service) to reduce operational overhead. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A logistics company is onboarding a new shipping partner that requires proof of AWS's ISO 9001 compliance. Which AWS service should the company use to download the required audit reports and certifications?
A smart-home IoT device manufacturer is preparing for a security audit of its database systems. The compliance team must review AWS physical infrastructure security controls via a SOC 2 report and verify who is responsible for patching the guest operating systems on their Amazon EC2 instances. Which of the following actions should the company take to meet these compliance and operational requirements? (Select TWO.)
Select all that apply
A logistics company wants to secure its cloud infrastructure. The development team needs a service to automatically scan their container images in Amazon Elastic Container Registry (ECR) for known software vulnerabilities. At the same time, the security team needs a service to continuously monitor their AWS accounts for malicious activity and unauthorized behavior. Which two AWS services should the company use to meet these requirements? (Select two.)
Select all that apply
BookHaven Networks, a public library system, plans to migrate its legacy catalog database to the AWS Cloud. The migration team wants to move the database as quickly as possible with minimal effort, without modifying the database code or its operational characteristics. Which of the following represents the correct migration strategy and a key benefit for this scenario? (Select TWO.)
Select all that apply
A financial technology company is launching a new international remittance application. The company must deploy its services in multiple geographic regions to provide a low-latency experience for users worldwide. Furthermore, transaction traffic is highly unpredictable, with extreme surges during holidays and minimal traffic during off-peak hours. The company wants to avoid both over-provisioning infrastructure and managing physical data centers. Which of the following benefits of the AWS Cloud directly align with the company's requirements? (Select TWO.)
Select all that apply
A logistics company is deploying a Redis cluster using Amazon ElastiCache to cache high-frequency tracking data. Under the AWS Shared Responsibility Model, which two of the following operational tasks are the responsibility of the customer?
Select all that apply