All practice questions
1473 questions
An agricultural technology company is migrating its crop monitoring analysis platform from an on-premises data center to the AWS Cloud. The company wants to focus its engineering resources on developing predictive soil algorithms rather than managing physical server racks and hardware cabling. Additionally, they want to pay only for the compute resources used during the active growing seasons, rather than purchasing physical servers that sit idle during winter. Which of the following AWS Cloud benefits directly align with this company's goals? (Select TWO.)
Select all that apply
A financial technology startup has deployed application microservices across multiple AWS accounts. To protect their workloads, the startup's security team needs to implement a solution that continuously scans their container images and virtual machines for software vulnerabilities, while also analyzing log sources (such as VPC Flow Logs and DNS query logs) to detect active threats and potential data exfiltration. Which of the following AWS services should the startup configure to address both of these requirements? (Select two.)
Select all that apply
A biotech startup is developing a genomic sequencing platform. To launch the product quickly, the startup wants its small team of software developers to focus on refining their proprietary analysis algorithms and user interface rather than managing server hardware, networking cables, and cooling systems.
Which benefit of the AWS Cloud is this startup demonstrating by choosing to deploy their platform on AWS?
A logistics company is migrating its package tracking application to AWS. To ensure the application remains operational even during a physical infrastructure outage, the architects configure the application to run on Amazon EC2 instances spread across three Availability Zones behind an Application Load Balancer. They also deploy a Multi-AZ Amazon RDS database instance that automatically replicates data and handles failover. Which AWS Cloud design principle is directly implemented by this architecture?
A software development firm manages a multi-account AWS environment. A developer in the development account needs temporary administrative access to perform emergency troubleshooting on resources in the production account. Which of the following options represents the most secure, AWS-recommended method to achieve this?
A logistics company is preparing for an external audit to verify that its cloud infrastructure meets international compliance standards. The company needs to retrieve AWS security reports and determine which security tasks are managed directly by AWS. Which two of the following actions should the company take to meet these requirements?
Select all that apply
A systems administrator is troubleshooting a connectivity issue for a web application deployed on Amazon EC2 instances within a custom VPC subnet. The instances are associated with a stateful Security Group that allows inbound HTTP (port 80) traffic from any source, and allows all outbound traffic. At the subnet level, the custom Network Access Control List (Network ACL) is configured with an inbound rule allowing HTTP (port 80) traffic from any source, but its outbound rule set only contains the default deny rule. Users report that they receive connection timeouts when trying to access the web application. Which of the following explains why the connection attempts are timing out?
A regional energy utility company is hosting its customer portal on AWS. In preparation for an upcoming regulatory audit, the company's compliance officer needs to retrieve the AWS Service Organization Control (SOC) reports to verify the security controls of the AWS physical infrastructure. Which AWS resource provides on-demand access to these compliance documents?
A media streaming company wants to improve its security posture on AWS. The company needs to implement continuous monitoring of its AWS accounts for malicious activity or unauthorized behavior. Additionally, it needs to automatically scan its Amazon EC2 instances for software vulnerabilities.
Which of the following AWS services should the company use to meet these requirements? (Select two.)
Select all that apply
A smart-agriculture IoT company runs containerized data processing applications on Amazon EC2 instances and stores container images in Amazon Elastic Container Registry (Amazon ECR). The security team wants to implement continuous, automated scans to identify software vulnerabilities in both the EC2 operating system packages and the ECR container images. According to the AWS Shared Responsibility Model, which AWS service performs these scans, and who is responsible for configuring the tool and remediating the findings?
A startup is establishing its cloud presence and needs to set up administrative access for its system administrator. The administrator will be responsible for creating resources, managing network settings, and monitoring logs on a daily basis. What is the AWS-recommended best practice to configure this administrative access?
Veridian Financial Services is conducting a comprehensive audit of its on-premises application portfolio in preparation for migrating to the AWS Cloud. During this discovery phase, the IT team identifies a legacy transactional logging tool. The team discovers that this tool's functionality has been fully replaced by a newer business intelligence platform, and no users or systems have accessed it for over 18 months. Which migration strategy should Veridian Financial Services apply to this legacy transactional logging tool?
A startup wants to establish operational visibility and security auditing. They need to log all API calls made by users and services across their AWS account, and they also need to collect and monitor performance metrics, such as CPU utilization, from their Amazon EC2 instances.
Which of the following AWS services should the startup use to meet these requirements? (Select TWO.)
Select all that apply
A software development company is setting up its testing environments on AWS. The team wants to deploy identical environments temporarily using templates, delete them when testing is complete to minimize costs, and ensure the system can recover automatically if a virtual server stops working. Which two AWS Cloud design principles should the team follow to meet these requirements?
Select all that apply
A digital real estate platform runs its database and web servers on Amazon Elastic Compute Cloud (Amazon EC2) instances. The platform's security team needs to implement a solution that automatically scans these EC2 instances for software vulnerabilities, package issues, and unintended network path exposures. Which AWS service should the real estate platform use to meet these requirements?
A startup is setting up its initial AWS environment and wants to secure the account. Which of the following are AWS Identity and Access Management (IAM) best practices that the startup should implement? (Select TWO.)
Select all that apply
A non-profit organization stores its public files in Amazon S3 and runs a web application on Amazon EC2 instances. Which two of the following tasks are the responsibility of AWS under the AWS Shared Responsibility Model?
Select all that apply
A company wants to automate vulnerability assessments for its Amazon EC2 instances to identify software vulnerabilities and unintended network exposure. Which AWS service should the company use?
A company is migrating its legacy application to the AWS Cloud. Currently, the application's user interface and database reside on the same server, meaning a database issue will crash the entire user interface. The team decides to split these components into independent tiers that communicate through well-defined APIs. Which design principle of the AWS Cloud does this separation directly demonstrate?
An IoT organization is designing a telemetry processing system on AWS to collect data from smart-home devices. The volume of incoming data fluctuates significantly throughout the day. To ensure high availability and efficiency, the architecture decouples the ingestion component from the database processing component so that ingestion is not disrupted if the database fails. Additionally, the backend compute resources adjust automatically to match the real-time rate of incoming sensor messages. Which two AWS Cloud design principles are directly applied in this architecture? (Select TWO.)
Select all that apply