All practice questions
1473 questions
A logistics company is integrating its on-premises inventory server with AWS. The server must automatically upload daily reports to an Amazon S3 bucket. To comply with strict security standards, the company prohibits storing long-term AWS access keys on the physical on-premises server. Which configuration represents the most secure AWS-recommended best practice to grant this access?
A satellite imagery analytics company processes massive volumes of earth observation data. The processing workload is highly variable, spiking dramatically after major weather events when customers request urgent assessments, while remaining idle during normal operations. Historically, the company maintained a large on-premises server cluster to handle peak demands, resulting in low average resource utilization. Which of the following AWS Cloud benefits directly address this organization's challenges? (Select TWO.)
Select all that apply
A company stores its financial documents in an Amazon Simple Storage Service (Amazon S3) bucket. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A global pharmaceutical firm is validating its drug development systems on Amazon EC2 for GxP (Good Practice) regulatory compliance. The auditors require the firm to provide official documentation of AWS's physical security certifications and verify who is responsible for patching the virtualization hypervisor host operating system. Which combination of actions correctly addresses these requirements?
A pharmaceutical company deploys an AWS Outpost in its on-premises data center to comply with local data residency regulations. The IT team is establishing the operational security procedures for this hybrid deployment. Under the AWS Shared Responsibility Model, which two duties remain the responsibility of the customer? (Select TWO.)
Select all that apply
A startup is designing a collaborative document editing platform on AWS. The development team wants to minimize the operational effort required to manage database infrastructure. They also want to ensure that testing environments can be spun up quickly for developers and completely destroyed when no longer needed to optimize costs.
Which of the following architectural decisions align with the AWS Cloud design principles of 'services not servers' and 'disposable resources'? (Select TWO.)
Select all that apply
A developer needs to configure a script running on their local workstation to upload log files to an Amazon S3 bucket. Which of the following is the AWS-recommended method to securely authenticate this script?
A retail company wants to continuously monitor its AWS accounts, Amazon EC2 instances, and container workloads for potential security threats, such as instances communicating with known malicious IP addresses or performing unauthorized API calls. The solution must use threat intelligence and machine learning to identify these anomalies. Which AWS service should the company use to meet these requirements?
A financial company is preparing for an external audit of its application running on Amazon EC2 instances. The company needs to restrict network access to the servers and collect compliance reports showing that the underlying AWS physical infrastructure meets industry security standards. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
A company is migrating its legacy customer booking application to the AWS Cloud. During this process, the development team wants to ensure that a failure in the email notification service does not halt the entire booking system. In addition, the developers want to automatically build temporary staging environments for testing and terminate them as soon as testing is complete. Which of the following AWS Cloud design principles are demonstrated in this scenario? (Select TWO)
Select all that apply
A mobile game studio based in London is launching a new multiplayer game. The studio needs to deploy its game backend servers in multiple locations worldwide, specifically near players in North America, Europe, and Asia, to ensure low-latency gameplay. Which AWS Cloud benefit is this studio utilizing by deploying their application across multiple AWS Regions with just a few clicks?
NovaPeak Manufacturing is planning to migrate two of its IT workloads to the AWS Cloud. First, they want to migrate a legacy inventory database to Amazon EC2 without making any architectural or code changes. Second, they plan to replace their on-premises customer relationship management (CRM) software with a cloud-based Software-as-a-Service (SaaS) subscription. Which two cloud migration strategies should NovaPeak Manufacturing select for these workloads? (Select TWO.)
Select all that apply
An online gaming company hosting its multiplayer game servers on Amazon EC2 wants to continuously monitor its AWS accounts for security threats like cryptocurrency mining, unauthorized API calls, and unusual data access patterns. The security team needs an intelligent service that automatically analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS query logs to detect these anomalies. Which AWS service should the company use to meet this objective?
SwiftCargo Logistics is planning to migrate its application portfolio to the AWS Cloud. During the analysis, the migration team identifies an old, duplicate database application that is no longer used by any business unit. The team decides to shut down and decommission this application completely before the migration begins. Which migration strategy is the company applying to this specific application?
An organization hosts a web application on Amazon EC2 instances in a public subnet. The security team wants to allow web clients to access the instances over HTTP (port 80) and HTTPS (port 443). However, to prevent data exfiltration, the EC2 instances must be restricted from initiating any outbound connections to the internet, while still allowing them to return responses to client requests. Which of the following configurations are required to achieve this goal? (Select TWO.)
Select all that apply
A retail company is migrating its e-commerce platform to AWS. The finance department wants to eliminate high upfront capital expenditures for data centers and instead pay for resources only as they are consumed. Simultaneously, the IT operations team wants to avoid the risk of either underprovisioning servers during peak sales events or paying for idle capacity during low-traffic periods. Which of the following benefits of the AWS Cloud directly address these requirements? (Select TWO)
Select all that apply
A company is migrating its monolithic on-premises order-processing application to AWS. To handle unpredictable traffic spikes, they need to ensure the system is highly resilient to failures, can scale dynamically without human intervention, and prevents database performance bottlenecks from crashing the web frontend. Which of the following architectural strategies on AWS best implements these requirements while avoiding common cloud design anti-patterns?
A company is building an online food delivery application on AWS. They want to ensure that if the payment service fails, the restaurant browsing and ordering service remains fully operational. Which AWS Cloud design principle is best demonstrated by this architectural choice?
A digital publishing company is planning to migrate its content archive and seasonal traffic analytics systems from an on-premises data center to the AWS Cloud. The systems experience predictable, low baseline activity throughout the month, except for a -hour window at the end of each month when monthly reports are generated and traffic spikes by . The company's goal is to minimize total cost of ownership (TCO) while ensuring performance during peak periods.
Which of the following strategies represent direct applications of AWS cloud economics to achieve these goals? (Select TWO.)
Select all that apply
A financial company hosts a transaction processing application on Amazon EC2 instances and stores historical data archives in Amazon S3. The security team must implement a security strategy that achieves two goals: first, automatically identifying software package vulnerabilities and unintended network accessibility on the EC2 instances; second, continuously monitoring the AWS accounts and network traffic for active malicious activity, such as brute-force attacks or communication with known malicious command-and-control servers. Which of the following AWS services should be implemented to address these specific security requirements? (Select two.)
Select all that apply