Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Amazon AWS Certified Cloud Practitioner Exam CLF-C02 Exam Questions

Page: 1 / 64 Total 949 questions

Want more questions? Get Premium Access.

Question 1

Which controls are the responsibility of both AWS and AWS customers, according to the AWS shared responsibility model? (Select TWO.)

Correct Answer: B. Patch management; C. Configuration management
Explanation:

Patch management and configuration management are controls that are the responsibility of both AWS and AWS customers, according to the AWS shared responsibility model. Patch management is the process of applying updates to software and applications to fix vulnerabilities, bugs, or performance issues. Configuration management is the process of defining and maintaining the settings and parameters of systems and applications to ensure their consistency and reliability. AWS is responsible for patching and configuring the software and services that it manages, such as the AWS global infrastructure, the hypervisor, and the AWS managed services. The customer is responsible for patching and configuring the software and services that they manage, such as the guest operating system, the applications, and the AWS customer-managed services. Physical and environmental controls are the responsibility of AWS, according to the AWS shared responsibility model. Physical and environmental controls are the measures that protect the physical security and availability of the AWS global infrastructure, such as power, cooling, fire suppression, and access control. AWS is responsible for maintaining these controls and ensuring the resilience and reliability of the AWS Cloud. Account structures are the responsibility of the customer, according to the AWS shared responsibility model. Account structures are the ways that customers organize and manage their AWS accounts and resources, such as using AWS Organizations, IAM users and roles, resource tagging, and billing preferences. The customer is responsible for creating and configuring these structures and ensuring the security and governance of their AWS environment. Choice of the AWS Region where data is stored is the responsibility of the customer, according to the AWS sharedresponsibility model. AWS Regions are geographic areas that consist of multiple isolated Availability Zones. Customers can choose which AWS Region to store their data and run their applications, depending on their latency, compliance, and cost requirements. The customer is responsible for selecting the appropriate AWS Region and ensuring the data sovereignty and regulatory compliance of their data.


Question 2

Which task is the responsibility of AWS, according to the AWS shared responsibility model?

Correct Answer: B. Ensure the environmental safety and security of the AWS infrastructure that hosts Workspaces.
Explanation:

The correct answer is B because ensuring the environmental safety and security of the AWS infrastructure that hosts Workspaces is the responsibility of AWS, according to the AWS shared responsibility model. The AWS shared responsibility model is a framework that defines the division of responsibilities between AWS and the customer for security and compliance. AWS is responsible for the security of the cloud, which includes the global infrastructure, such as the regions, availability zones, and edge locations; the hardware, software, networking, and facilities that run the AWS services; and the virtualization layer that separates the customer instances and storage. The customer is responsible for the security in the cloud, which includes the customer data, the guest operating systems, the applications, the identity and access management, the firewall configuration, and the encryption. The other options are incorrect because they are the responsibility of the customer, according to the AWS shared responsibility model. Setting up multi-factor authentication (MFA) for each Workspaces user account, providing security for Workspaces user accounts through AWS Identity and Access Management (IAM), configuring AWS CloudTrail to log API calls and user activity, and encrypting data at rest and in transit are all tasks that the customer has to perform to secure their Workspaces environment. Reference:AWS Shared Responsibility Model,Amazon WorkSpaces Security


Question 3

A company needs to centralize its operational data. The company also needs to automate tasks across all of its Amazon EC2 instances.

Which AWS service can the company use to meet these requirements?

Correct Answer: B. AWS Systems Manager
Explanation:

AWS Systems Manager is a service that enables users to centralize and automate the management of their AWS resources. It provides a unified user interface to view operational data, such as inventory, patch compliance, and performance metrics.It also allows users to automate common and repetitive tasks, such as patching, backup, and configuration management, across all of their Amazon EC2 instances1.AWS Trusted Advisor is a service that provides best practices and recommendations to optimize the performance, security, and cost of AWS resources2.AWS CodeDeploy is a service that automates the deployment of code and applications to Amazon EC2 instances or other compute services3.AWS Elastic Beanstalk is a service that simplifies the deployment andmanagement of web applications using popular platforms, such as Java, PHP, and Node.js4.


Question 4

Which AWS service or tool provides recommendations to help users get rightsized Amazon EC2 instances based on historical workload usage data?

Correct Answer: B. AWS Compute Optimizer
Explanation:

The AWS service or tool that provides recommendations to help users get rightsized Amazon EC2 instances based on historical workload usage data is AWS Compute Optimizer. AWS Compute Optimizer is a service that analyzes the configuration and performance of the AWS resources, such as Amazon EC2 instances, and provides recommendations for optimal resource types and sizes based on the workload patterns and metrics. AWS Compute Optimizer helps users improve the performance, availability, and cost efficiency of their AWS resources. AWS Pricing Calculator, AWS App Runner, and AWS Systems Manager are not the best services or tools to use for this purpose. AWS Pricing Calculator is a tool that helps users estimate the cost of using AWS services based on their requirements and preferences. AWS App Runner is a service that helps users easily and quickly deploy web applications and APIs without managing any infrastructure.AWS Systems Manager is a service that helps users automate and manage the configuration and operation of their AWS resources and applications34


Question 5

An auditor is preparing for an annual security audit. The auditor requests certification details for a company's AWS hosted resources across multiple Availability Zones in the us-east-1 Region.

How should the company respond to the auditor's request?

Correct Answer: D. Use AWS Artifact to download the applicable report for AWS security controls. Provide the report to the auditor.
Explanation:

AWS Artifact is your go-to, central resource for compliance-related information that matters to you. It provides on-demand access to AWS' security and compliance reports and select online agreements. Reports available in AWS Artifact include our Service Organization Control (SOC) reports, Payment Card Industry (PCI) reports, and certifications from accreditation bodies across geographies and compliance verticals that validate the implementation and operating effectiveness of AWS security controls. Agreements available in AWS Artifact include the Business Associate Addendum (BAA) and the Nondisclosure Agreement (NDA). You can use AWS Artifact to download the applicable report for AWS security controls and provide it to the auditor.


Question 6

A company is in the process of finding correct Amazon EC2 instance types and sizes to meet its performance and capacity requirements. The company wants to find the lowest possible cost.

Which option accurately characterizes the company's actions?

Correct Answer: C. Rightsizing
Explanation:

The process of finding correct EC2 instance types and sizes to match performance and capacity requirements while minimizing cost is called 'right-sizing.' Right-sizing analyzes resource utilization to eliminate overprovisioning and ensures instances are appropriately matched to actual workload demands, directly resulting in cost optimization.

Question 7

Which AWS service provides a highly accurate enterprise search capability that is powered by machine learning?

Correct Answer: C. Amazon Kendra
Explanation:

Amazon Kendra is an intelligent enterprise search service that uses machine learning and natural language processing to help users find relevant information across organizational content. It can index unstructured documents from multiple repositories and return relevant answers, passages, and documents in response to natural-language questions. AWS describes Kendra as providing highly accurate enterprise search and retrieval capabilities, making option C correct. Amazon Augmented AI, abbreviated Amazon A2I, supports human review workflows for machine-learning predictions when human validation is required. It is not an enterprise search engine. Amazon Rekognition analyzes images and videos to identify objects, text, people, activities, and other visual information. Amazon Polly converts written text into lifelike speech. Neither service searches enterprise document repositories. The important exam association is that Kendra is used when an organization needs intelligent, natural-language search across sources such as document management systems, knowledge repositories, websites, and file collections. Kendra uses machine-learning techniques to understand the context and intent of a question instead of relying only on simple keyword matching.


Question 8

Which service enables customers to audit API calls in their AWS accounts'?

Correct Answer: A. AWS CloudTrail
Explanation:

AWS CloudTrail is a service that provides a record of actions taken by a user, role, or an AWS service in your AWS account. CloudTrail captures all API calls for AWS services as events, including calls from the AWS Management Console, AWS SDKs, command line tools, and higher-level AWS services.You can use CloudTrail to monitor, audit, and troubleshoot your AWS accountactivity34.AWS Trusted Advisor is a service that provides best practices recommendations for cost optimization, performance, security, and fault tolerance in your AWS account5.Amazon Inspector is a service that helps you improve the security and compliance of your applications deployed on AWS by automatically assessing them for vulnerabilities and deviations from best practices6.AWS X-Ray is a service that helps you analyze and debug your applications by collecting data about the requests that your application serves, and providing tools to view, filter, and gain insights into that data7.Reference:Logging AWS Audit Manager API calls with CloudTrail,Logging AWS Account Management API calls using AWS CloudTrail,Review API calls in your AWS account using CloudTrail,Monitor the usage of AWS API calls using Amazon CloudWatch,Which service enables customers to audit API calls in their AWS ...


Question 9

Which AWS services or tools are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks? (Select TWO.)

Correct Answer: C. AWS Config
Explanation:

AWS Shield Standard and AWS WAF are the AWS services or tools that are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks. According to the AWS Shield Developer Guide, 'AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS.AWS Shield provides always-on detection and automatic inline mitigations that minimize application downtime and latency, so there is no need to engage AWS Support to benefit from DDoS protection.'5According to the AWS WAF Developer Guide, ''AWS WAF is a web application firewall that helps protect your web applications or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources. AWS WAF gives you control over how traffic reaches your applications by enabling you to create security rules that block common attack patterns, such as SQL injection or cross-site scripting, and rules that filter out specific traffic patterns you define.'' VPC endpoint, virtual private gateway, and AWS Config are not designed to protect a workload from these types of attacks.


Question 10

What does the concept of agility mean in AWS Cloud computing? (Select TWO.)

Correct Answer: A. The speed at which AWS resources are implemented; C. The ability to experiment quickly
Explanation:

Agility in AWS Cloud computing means the ability to rapidly provision and deprovision AWS resources as needed, and the ability to experiment quickly with new ideas and solutions. Agility helps businesses to respond to changing customer demands, market opportunities, and competitive threats, and to innovate faster and cheaper. Agility also reduces the risk of failure, as businesses can test and validate their assumptions before committing to large-scale deployments. Some of the benefits of agility in AWS Cloud computing are:

The speed at which AWS resources are implemented: AWS provides a variety of services and tools that allow you to create, configure, and launch AWS resources in minutes, using the AWS Management Console, the AWS Command Line Interface (AWS CLI), the AWS Software Development Kits (AWS SDKs), or the AWS CloudFormation templates. You can also use the AWS Cloud Development Kit (AWS CDK) to define your AWS resources as code using familiar programming languages, and synthesize them into AWS CloudFormation templates. You can also use the AWS Service Catalog to create and manage standardized portfolios of AWS resources that meet your organizational policies and best practices.AWS also offers on-demand, pay-as-you-go pricing models, soyou only pay for the resources you use, and you can scale them up or down as your needs change12345

The ability to experiment quickly: AWS enables you to experiment quickly with new ideas and solutions, without having to invest in upfront capital or long-term commitments. You can use AWS to create and test multiple prototypes, hypotheses, and minimum viable products (MVPs) in parallel, and measure their performance and feedback. You can also use AWS to leverage existing services and solutions, such as AWS Marketplace, AWS Solutions, and AWS Quick Starts, that can help you accelerate your innovation process. AWS also supports a culture of experimentation and learning, by providing tools and resources for continuous integration and delivery (CI/CD), testing, monitoring, and analytics.

Six advantages of cloud computing - Overview of Amazon Web Services,AWS Cloud Development Kit (AWS CDK),AWS Service Catalog,AWS Pricing,AWS CloudFormation, [Experimentation and Testing - AWS Well-Architected Framework], [AWS Marketplace], [AWS Solutions], [AWS Quick Starts], [AWS Developer Tools]


Question 11

A company wants to push VPC Flow Logs to an Amazon S3 bucket.

Which action is the company's responsibility?

Correct Answer: C. Managing the encryption options on the S3 bucket
Explanation:

When pushing VPC Flow Logs to an Amazon S3 bucket, the company's responsibility is to configure the S3 bucket as the destination. This includes creating an S3 bucket, setting appropriate permissions/bucket policies to allow VPC Flow Logs service to write to it, and specifying this bucket in the VPC Flow Logs configuration. AWS manages the VPC Flow Logs service itself, but the customer must set up and manage the destination resources.

Question 12

For which use case are Amazon EC2 On-Demand Instances MOST cost-effective?

Correct Answer: B. An instance in continual use for 1 month to conduct quality assurance tests
Explanation:

On-Demand Instances are most cost-effective for short-term, steady, and unpredictable workloads. Using them for a one-month testing period allows flexibility without a long-term commitment. For long-term workloads (like a year or more), Reserved Instances or Savings Plans would be more cost-effective. Spot Instances are better for interruptible, flexible workloads.


Question 13

Which AWS service can provide a dedicated network connection with consistent low latency from on premises to the AWS Cloud?

Correct Answer: C. AWS Direct Connect
Explanation:

AWS Direct Connect is a service that provides a dedicated network connection from on premises to the AWS Cloud. It can reduce network costs, increase bandwidth throughput, and provide a more consistent network experience than internet-based connections.It can also provide low latency for applications that require real-time data transfer4. Amazon VPC is a service that provides a logically isolated section of the AWS Cloud where users can launch AWS resources in a virtual network that they define. Amazon Kinesis Data Streams is a service that provides a scalable and durable stream of data records for real-time data processing. Amazon OpenSearch Service is a service that provides a fully managed, scalable, and secure search and analytics solution that is compatible with Elasticsearch.


Question 14

Which AWS service can a company use to visually design and build serverless applications?

Correct Answer: C. AWS Application Composer
Explanation:

AWS Application Composer is a service that allows users to visually design and build serverless applications. Users can drag and drop components, such as AWS Lambda functions, Amazon API Gateway endpoints, Amazon DynamoDB tables, and Amazon S3 buckets, to create aserverless application architecture. Users can also configure the properties, permissions, and dependencies of each component, and deploy the application to their AWS account with a few clicks. AWS Application Composer simplifies the design and configuration of serverless applications, and reduces the need to write code or use AWS CloudFormation templates.Reference:AWS Application Composer,AWS releases Application Composer to make serverless 'easier' but initial scope is limited


Question 15

Which AWS tool or feature acts as a VPC firewall at the subnet level?

Correct Answer: B. Network ACL
Explanation:

Network ACLs (NACLs) are subnet-level firewalls in AWS, controlling inbound and outbound traffic for VPC subnets. They provide an additional layer of security by allowing or denying traffic based on IP protocol, source and destination IP, and port. Security groups operate at the instance level, while Traffic Mirroring and Internet Gateways do not function as firewalls at the subnet level.