All practice questions
1473 questions
A logistics company is modernizing its data tier on AWS. The company needs a database solution to handle two distinct requirements: first, storing live, highly structured transaction records for order processing that requires full ACID compliance and SQL joins; second, running complex analytical queries over petabytes of historical tracking data to generate business intelligence reports. Which two AWS database services should the company select to meet these requirements?
Select all that apply
A software development firm is deploying its microservices-based application using Amazon Elastic Container Service (Amazon ECS) with the AWS Fargate launch type. Under the AWS Shared Responsibility Model, which of the following tasks is the responsibility of the customer?
A logistics company suspects that credentials for one of its administrative accounts have been compromised, leading to unauthorized resource creation in multiple AWS Regions. The security team wants to implement a service that continuously monitors their AWS accounts for malicious activity and anomalies, such as unauthorized API calls or unusual network traffic, without needing to write custom detection rules. Which AWS service should the company use to meet this requirement?
A startup is designing a new microservices-based application and wants to minimize operational overhead by using serverless compute options. The architecture team needs to select services where they do not have to provision, manage, or patch the underlying virtual servers.
Which of the following AWS compute services meet these requirements? (Select TWO.)
Select all that apply
A small local bakery wants to launch a simple WordPress website to showcase their daily menu and take custom cake orders. The business has a very limited IT budget and no cloud engineering experience. They require a web hosting solution that bundles compute, SSD-based storage, a pre-configured database, and static IP addresses into a single package with a predictable monthly price. Which AWS compute service should the bakery use to meet these requirements?
A startup is setting up an application on AWS and must encrypt its customer data at rest. According to the AWS Shared Responsibility Model, which of the following is the customer's responsibility regarding data protection?
A logistics company is designing a package tracking system to monitor real-time location telemetry from a fleet of delivery vehicles. The telemetry data consists of rapid, high-volume key-value writes that require single-digit millisecond latency at any scale. Concurrently, the company's data analysts need to perform complex SQL queries on petabytes of historical delivery data to optimize routes. Which two AWS database services should the company choose to meet these requirements?
Select all that apply
A retail company hosts its core inventory management system on a fleet of Amazon EC2 instances. The company's security policy requires automated, continuous assessments of these instances to identify software package vulnerabilities and unintended network paths that could lead to exposure. Which AWS service should the company use to automate these security assessments?
A developer needs to write a shell script that runs on a local machine to automatically stop several Amazon EC2 instances every night. Which AWS tool is designed to support this type of command-line interaction and scripting?
A medical device manufacturer is deploying an application on AWS that handles sensitive patient health data. The company's compliance framework requires that all data at rest be encrypted using keys stored on dedicated, single-tenant hardware security modules that the customer directly manages. Additionally, the company must maintain responsibility for configuring access to these keys.
Which of the following actions are responsibilities of the customer to meet these requirements? (Select TWO.)
Select all that apply
A cloud architect needs to implement a network security control that operates at the subnet level to block traffic from a list of known malicious IP addresses before it reaches any EC2 instances. The control must evaluate traffic as it enters and leaves the subnet boundary, and any returned response traffic must be explicitly permitted by a rule because the control does not automatically remember connection states. Which AWS resource should the architect configure?
A company is deploying an application on Amazon EC2 instances that requires read and write access to an Amazon DynamoDB table. At the same time, the company needs to grant temporary access to external developers from a partner organization to collaborate on the project.
Which of the following actions align with AWS Identity and Access Management (IAM) best practices to meet these requirements? (Select TWO.)
Select all that apply
A software company is planning to migrate its database workload to the AWS Cloud. Currently, database administrators spend several hours each week configuring database replication, managing operating system updates, and executing manual backups on local servers. To eliminate these tasks, the company decides to migrate to Amazon Aurora, allowing AWS to manage these operational responsibilities automatically.
Which AWS Cloud design principle does this decision directly represent?
A systems administrator is configuring basic security boundaries for a new VPC deployment. To protect the environment, the administrator must understand the functional differences between Security Groups and Network Access Control Lists (Network ACLs). Which TWO statements accurately describe the characteristics of these two resources? (Select TWO.)
Select all that apply
An international digital news publisher wants to launch its content delivery application for readers across South America, Europe, and Asia to ensure low latency. Additionally, the publisher wants to focus its resources on developing software features rather than managing physical facilities, server racks, and utilities like cooling and electricity.
Which two benefits of the AWS Cloud directly support this publisher’s requirements? (Select TWO.)
Select all that apply
A cloud architect is mapping several application workloads to the most appropriate AWS compute services. Match each business workload requirement to the AWS compute service that best fits its deployment, cost, and management constraints.
Click a left item, then click its matching right item
Items
Matches
A media streaming company is designing a new platform on AWS. They require a fully managed database to store user profile preferences with single-digit millisecond latency at any scale. Additionally, they need a petabyte-scale data warehouse to run complex analytical queries on historical viewing habits. Which two AWS services should the company select to meet these requirements? (Select TWO.)
Select all that apply
A software engineering team is building a microservice-based application. The application code, written in Python, must dynamically read metadata from an Amazon DynamoDB table and write files to an Amazon S3 bucket at runtime. Concurrently, the DevOps team needs a declarative, version-controlled method to automatically provision and update the required DynamoDB tables, S3 buckets, and Amazon ECS resources in a repeatable manner.
Which two AWS deployment and operating methods or tools should be utilized to meet these requirements? (Select TWO.)
Select all that apply
A software development company is preparing to launch a new application. Instead of purchasing and setting up physical servers in a local facility, the company decides to deploy the application on AWS and pay for resources on a monthly basis based on active consumption. Which of the following best describes this financial change?
A telemedicine platform hosts its patient portal application on Amazon EC2 instances. The platform's security team needs to implement a solution that continuously monitors the AWS account for malicious activity and unauthorized access, while also automatically scanning the EC2 instances for known software vulnerabilities and unintended network exposure. Which two AWS services should the security team use to meet these requirements? (Select two.)
Select all that apply