2021-09-27

A company is looking for a way to encrypt data stored on Amazon S3. Which AWS managed service can be used to
help to accomplish this?
A. AWS Certificate Manager (ACM)
B. AWS Secrets Manager
C. AWS Resource Access Manager
D. AWS Key Management Service (AWS KMS)
Correct Answer: D
Reference: https://www.nakivo.com/blog/amazon-s3-encryption-configuration-overview/


Under the AWS shared responsibility model, which of the following is the customer\\’s responsibility?
A. Patching guest OS and applications
B. Patching and fixing flaws in the infrastructure
C. Physical and environmental controls
D. Configuration of AWS infrastructure devices
Correct Answer: B


Which AWS service or feature gives end users the ability to access AWS resources from any location by using an
encrypted connection?
A. Amazon CloudFront
B. AWS Client VPN
C. AWS Direct Connect
D. AWS PrivateLink
Correct Answer: A


Under the AWS shared responsibility model, the security and patching of the guest operating system is the responsibility
A. AWS Support
B. the customer
C. AWS Systems Manager
D. AWS Config
Correct Answer: B
Reference: https://aws.amazon.com/compliance/shared-responsibility-model/


A user wants to move legacy applications to the AWS Cloud to reduce the total cost. Which option is the MOST costeffective according to best practices?
A. Rewrite the legacy applications in an open-source language, such as Python.
B. Right-size the Amazon EC2 instances to prevent over-provisioning in terms of compute and memory.
C. Migrate relational databases to Amazon DynamoDB
D. Reserve a data center facility with an upfront payment, which provides an additional discount
Correct Answer: D


Which design principle is achieved by following the reliability pillar of the AWS Well-Architected Framework?
A. Vertical scaling
B. Manual failure recovery
C. Testing recovery procedures
D. Changing infrastructure manually
Correct Answer: C
Reference: https://aws.amazon.com/blogs/apn/the-5-pillars-of-the-aws-well-architected-framework/


Which AWS tool gives users the ability to plan their service usage, service costs, and instance reservations, and also
allows them to set custom alerts when their costs or usage exceed established thresholds?
A. Cost Explorer
B. AWS Budgets
C. AWS Cost and Usage Report
D. Reserved Instance reporting
Correct Answer: B


Which options does AWS make available for customers who want to learn about security in the cloud in an instructor-led
setting? (Choose two.)
A. AWS Trusted Advisor
B. AWS Online Tech Talks
C. AWS Blog
D. AWS Forums
E. AWS Classroom Training
Correct Answer: BE


A company uses Amazon EC2 Instances in its AWS account tor several different workloads. The company needs to
perform an analysis to understand the cost of each. workload. What is the MOST operationally efficient way to meet this
A. Move the EC2 instances for each workload into separate AWS accounts.
B. Use a different EC2 instance family for each of the workloads.
C. Add cost allocation tags to each EC2 instance, and activate the tags
D. Update the workload applications to publish usage data to a cost allocation database.
Correct Answer: D


Which AWS service can be used to provide an on-demand, cloud-based contact center?
A. AWS Direct Connect
B. Amazon Connect
C. AWS Support Center
D. AWS Managed Services
Correct Answer: C


Amazon Relational Database Service (Amazon RDS) offers which of the following benefits over traditional database
A. AWS manages the data stored in Amazon RDS tables.
B. AWS manages the maintenance of the operating system.
C. AWS automatically scales up instance types on demand.
D. AWS manages the database type.
Correct Answer: C


Which pricing model would result in maximum Amazon Elastic Compute Cloud (Amazon EC2) savings for a database
server that must be online for one year?
A. Spot Instance
B. On-Demand Instance
C. Partial Upfront Reserved Instance
D. No Upfront Reserved Instance
Correct Answer: C
Reference: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-reserved-instances.html


A company wants to improve its security and audit posture by limiting Amazon EC2 inbound access. What should the
company use to access instances remotely instead of opening inbound SSH ports and managing SSH keys?
A. EC2 key pairs
B. AWS Systems Manager Session Manager
C. AWS Identity and Access Management (1AM)
D. Network ACLs
Correct Answer: B

