AWS Cloud Practitioner CLF Questions
AWS Cloud Practitioner CLF Questions
Forward monthly invoices for each account. Then create IAM roles to allow cross-account
access.
Create a new AWS account. Then configure AWS Organizations and invite all existing accounts
to join.
Configure AWS Organizations in each of the existing accounts. Then link all accounts together.
Use Cost Explorer to combine costs from all accounts. Then replicate IAM policies across
accounts.
2. The ability to horizontally scale Amazon EC2 instances based on demand is an
example of which concept in the AWS Cloud value proposition?
Economy of scale
Elasticity
High availability
Agility
3. An ecommerce company anticipates a huge increase in web traffic for two very
popular upcoming shopping holidays. Which AWS service or feature can be configured
to dynamically adjust resources to meet this change in demand?
AWS CloudTrail
Amazon Forecast
AWS Config
4. Which AWS service enables users to securely connect to AWS resources over the
public internet?
AWS VPN
Amazon Pinpoint
5. Which AWS service enables users to securely connect to AWS resources over the
public internet?
AWS VPN
Amazon Pinpoint
6. Which tool is used to forecast AWS spending?
AWS Organizations
Cost Explorer
Amazon Inspector
7. A company is running an ecommerce application hosted in Europe. To decrease
latency for users who access the website from other parts of the world, the company
would like to cache frequently accessed static content closer to the users.
Which AWS service will support these requirements?
Amazon ElastiCache
Amazon CloudFront
Amazon Alexa
AWS Regions
Amazon Lightsail
AWS Organizations
9. Which AWS service will help users determine if an application running on an Amazon
EC2 instance has sufficient CPU capacity?
Amazon CloudWatch
AWS Config
AWS CloudTrail
Amazon Inspector
10. Why is it beneficial to use Elastic Load Balancers with applications?
They allow for the conversion from Application Load Balancers to Classic Load Balancers.
Scalability
Loose coupling
Automation
Automatic scaling
13. Which AWS service or feature can enhance network security by blocking requests
from a particular network for a web application on AWS? (Choose two.)
AWS WAF
AWS Organizations
Network ACLs
14. An application runs on multiple Amazon EC2 instances that access a shared file
system simultaneously. Which AWS storage service should be used?
Amazon EBS
Amazon EFS
Amazon S3
AWS Artifact
15. A web application is hosted on AWS using an Elastic Load Balancer, multiple Amazon
EC2 instances, and Amazon RDS.
Which security measures fall under the responsibility of AWS? (Choose two.)
Encrypting communication between the EC2 instances and the Elastic Load Balancer
Configuring a security group and a network access control list (NACL) for EC2 instances
16. What is the benefit of elasticity in the AWS Cloud?
pay-as-you go pricing
economies of scale
Hold a team meeting to discuss the importance if only uploading private S3 objects.
Open a detailed case related to billing and submit it to AWS Support for help.
Upload data describing the issue to a new object in a private Amazon S3 bucket.
Create a pricing application and deploy it to a right-sized Amazon EC2 instance for
moreinformation.
Managed partners
AWS Support
22. Which AWS services may be scaled using AWS Auto Scaling? (Choose two.)
Amazon EC2
Amazon DynamoDB
Amazon S3
Amazon Route 53
Amazon Redshift
23. Which of the following are benefits of AWS Global Accelerator? (Choose two.)
AWS Abuse
AWS Support
26. Which AWS Cloud best practice uses the elasticity and agility of cloud computing?
Build the application and infrastructure in a data center that grants physical access
Break down AWS costs by day, service, and linked AWS account.
Create budgets and receive notifications if current of forecasted usage exceeds the budgets.
AWS Support
the customer
AWS Config
31. Which AWS service makes it easy to create and manage AWS users and groups, and
provide them with secure access to AWS resources at no charge?
Amazon Connect
AWS Artifact
Amazon Inspector
33. Which AWS service can be used to turn text into life-like speech?
Amazon Polly
Amazon Transcribe
Amazon Rekognition
Amazon Lex
34. What is one of the core principles to follow when designing a highly available
application in the AWS Cloud?
Dedicated Hosts
On-Demand Instances
Spot Instances
Reserved Instances
38. Which of the AWS global infrastructure is used to cache copies of content for faster
delivery to users across the globe?
AWS Regions
Availability Zones
Edge locations
Data centers
39. Which of the AWS global infrastructure is used to cache copies of content for faster
delivery to users across the globe?
AWS Regions
Availability Zones
Edge locations
Data centers
40. Using AWS Config to record, audit, and evaluate changes to AWS resources to
enable traceability is an example of which AWS Well-Architected Framework pillar?
Security
Operational excellence
Performance efficiency
Cost optimization
41. A user needs to quickly deploy a non-relational database on AWS. The user does not
want to manage the underlying hardware or the database software.
Which AWS service can be used to accomplish this?
Amazon RDS
Amazon DynamoDB
Amazon Aurora
Amazon Redshift
42. A Cloud Practitioner is developing a disaster recovery plan and intends to replicate
data between multiple geographic areas.
Which of the following meets these requirements?
AWS Accounts
AWS Regions
Availability Zones
Edge locations
43. Which features and benefits does the AWS Organizations service provide? (Choose
two.)
AWS Config
AWS OpsWorks
AWS CloudFormation
Consolidated billing
receive reports that break down AWS Cloud compute costs by duration, resource, or tags
estimate a monthly bill for the AWS Cloud resources that will be used
enable billing alerts to monitor actual AWS costs compared to estimated costs
47. Which AWS services can be used to provide network connectivity between an on-
premises network and a VPC? (Choose two.)
Amazon Route 53
AWS VPN
Amazon Connect
48. Under the AWS shared responsibility model, which of the following are customer
responsibilities? (Choose two.)
Developer
Enterprise
Business
Basic
50. A company has deployed several relational databases on Amazon EC2 instances.
Every month, the database software vendor releases new security patches that need to
be applied to the databases.
What is the MOST efficient way to apply the security patches?
Connect to each database instance on a monthly basis, and download and apply the necessary
security patches from the vendor.
Enable automatic patching for the instances using the Amazon RDS console.
In AWS Config, configure a rule for the instances and the required patch level.
Use AWS Transit Gateway to quickly route users from Brazil to the application
Use AWS Transit Gateway to quickly route users from Brazil to the application
Dedicated Instances
Spot Instances
On-Demand Instances
Reserved Instances
55. Which AWS dashboard displays relevant and timely information to help users
manage events in progress, and provides proactive notifications to help plan for
scheduled activities?
AWS Backup
Amazon Connect
Access keys
Security groups
Basic
Business
Developer
Enterprise
61. Which AWS service or feature helps restrict the AWS services, resources, and
individual API actions the users and roles in each member account can access?
Amazon Cognito
AWS Organizations
AWS Shield
AWS Artifact
AWS Marketplace
Amazon Inspector
AWS Support
63. Which Amazon S3 storage class is optimized to provide access to data with lower
resiliency requirements, but rapid access when needed such as duplicate backups?
Amazon S3 Standard
Amazon S3 Glacier
64. What is an Availability Zone in AWS?
AWS CloudFormation
Amazon CloudFront
AWS Batch
AWS OpsWorks
Amazon QuickSight
66. Which AWS service enables users to create copies of resources across AWS Regions?
Amazon ElastiCache
AWS CloudFormation
AWS CloudTrail
Amazon ElastiCache
AWS CloudFormation
AWS CloudTrail
Easy and fast deployment of applications in multiple Regions around the world
A primary key
A user ID
A secondary key
71. Which of the following are AWS compute services? (Choose two.)
Amazon Lightsail
AWS CloudFormation
AWS Batch
Amazon Inspector
72. How can a company separate costs for network traffic, Amazon EC2, Amazon S3, and
other AWS services by department?
AWS Organizations
AWS Budgets
Cost Explorer
AWS Trusted Advisor
75. Which AWS service provides the ability to detect inadvertent data leaks of
personally identifiable information (PII) and user credential data?
Amazon GuardDuty
Amazon Inspector
Amazon Macie
AWS Shield
76. Which tool can be used to monitor AWS service limits?
Hybrid cloud
Private cloud
78. Which of the following describes a security best practice that can be implemented
using AWS IAM?
Grant permissions to users who are required to perform a given task only
VPC peering
AWS WAF
Amazon GuardDuty
82. A company’s application has flexible start and end times.
Which Amazon EC2 pricing model will be the MOST cost-effective?
On-Demand Instances
Spot Instances
Reserved Instances
Dedicated Hosts
83. Under the AWS shared responsibility model, what are the customer’s
responsibilities? (Choose two.)
Reserved Instances
Spot Instances
Dedicated Hosts
85. Which AWS container service will help a user install, operate, and scale the cluster
management infrastructure?
Amazon Cognito
AWS Shield
To load balance traffic from the Internet across Amazon EC2 instances
89. A company must ensure that its endpoint for a database instance remains the same
after a single Availability Zone service interruption. The application needs to resume
database operations without the need for manual administrative intervention.
How can these requirements be met?
Use multiple Amazon Route 53 routes to the standby database instance endpoint hosted on
AWS Storage Gateway.
Configure Amazon RDS Multi-Availability Zone deployments with automatic failover to the
standby.
Add multiple Application Load Balancers and deploy the database instance with AWS Elastic
Beanstalk.
Deploy a single Network Load Balancer to distribute incoming traffic across multiple Amazon
CloudFront origins.
90. Which AWS managed service can be used to distribute traffic between one or more
Amazon EC2 instances?
NAT gateway
Amazon Athena
AWS PrivateLink
91. AWS Trusted Advisor provides recommendations on which of the following? (Choose
two.)
Cost optimization
Auditing
Serverless architecture
Performance
Scalability
92. Which of the following tasks can only be performed after signing in with AWS
account root user credentials? (Choose two.)
how well and how quickly an application’s environment can have lost data restored
AWS AppSync
AWS Batch
AWS CodePipeline
AWS DataSync
96. What can be used to reduce the cost of running Amazon EC2 instances? (Choose
two.)
AWS Config
AWS Artifact
AWS CloudTrail
98. Which AWS service or feature allows the user to manager cross-region application
traffic?
Amazon VPC
Amazon Route 53
99. Which AWS service can be used to track unauthorized API calls?
AWS Config
AWS CloudTrail
Amazon Inspector
100. A user needs to regularly audit and evaluate the setup of all AWS resources,
identify non-compliant accounts, and be notified when a resource changes.
Which AWS service can be used to meet these requirements?
AWS Config
Launch the instances across multiple Availability Zones in a single AWS Region.
Launch the instances as EC2 Reserved Instances in the same AWS Region and the same
Availability Zone.
Launch the instances in multiple AWS Regions, but in the same Availability Zone.
Launch the instances as EC2 Spot Instances in the same AWS Region, but in different
Availability Zones.
102. A company must store critical business data in Amazon S3 with a backup to another
AWS Region. How can this be achieved?
Use an Amazon CloudFront Content Delivery Network (CDN) to cache data globally
Configure the AWS Backup service to back up to the data to another AWS Region
Take Amazon S3 bucket snapshots and copy that data to another AWS Region
103. Which AWS Cloud service can send alerts to customers if custom spending
thresholds are exceeded?
AWS Budgets
AWS Organizations
104. What is the recommended method to request penetration testing on AWS
resources?
Amazon Inspector
Amazon Macie
Amazon GuardDuty
Internet gateway
NAT gateway
Customer gateway
Transit gateway
Virtual private gateway
107. Which Amazon EC2 pricing option is best suited for applications with short-term,
spiky, or unpredictable workloads that cannot be interrupted?
Spot Instances
Dedicated Hosts
On-Demand Instances
Reserved Instances
108. Which AWS cloud architecture principle states that systems should reduce
interdependencies?
Scalability
Loose coupling
109. What is the MOST effective resource for staying up to date on AWS security
announcements?
Amazon Inspector
110. Which AWS service offers persistent storage for a file system?
Amazon S3
Amazon ElastiCache
111. Which of the following allows AWS users to manage cost allocations for billing?
Tagging resources
Amazon GuardDuty
AWS Artifact
AWS Shield
113. Which of the following AWS services are serverless? (Choose two.)
AWS Lambda
Amazon DynamoDB
Amazon Redshift
114. Which AWS managed services can be used to extend an on-premises data center to
the AWS network? (Choose two.)
A. AWS VPN
B. NAT gateway
D. Amazon Connect
E. Amazon Route 53
115. Which requirement must be met for a member account to be unlinked from an AWS
Organizations account?
The linked account must be actively compliant with AWS System and Organization Controls
(SOC).
The payer and the linked account must both create AWS Support cases to request that the
member account be unlinked from the organization.
The payer account must be used to remove the linked account from the organization.
116. What AWS benefit refers to a customer’s ability to deploy applications that scale up
and down the meet variable demand?
Elasticity
Agility
Security
Scalability
117. During a compliance review, one of the auditors requires a copy of the AWS SOC 2
report. Which service should be used to submit this request?
AWS Artifact
Amazon S3
118. A company wants to set up a highly available workload in AWS with a disaster
recovery plan that will allow the company to recover in case of a regional service
interruption.
Which configuration will meet these requirements?
Run on two Availability Zones in one AWS Region, using the additional Availability Zones in the
AWS Region for the disaster recovery site.
Run on two Availability Zones in one AWS Region, using another AWS Region for the disaster
recovery site.
Run on two Availability Zones in one AWS Region, using a local AWS Region for the disaster
recovery site.
Run across two AWS Regions, using a third AWS Region for the disaster recovery site.
119. A company wants to set up a highly available workload in AWS with a disaster
recovery plan that will allow the company to recover in case of a regional service
interruption.
Which configuration will meet these requirements?
Run on two Availability Zones in one AWS Region, using the additional Availability Zones in the
AWS Region for the disaster recovery site.
Run on two Availability Zones in one AWS Region, using another AWS Region for the disaster
recovery site.
Run on two Availability Zones in one AWS Region, using a local AWS Region for the disaster
recovery site.
Run across two AWS Regions, using a third AWS Region for the disaster recovery site.
120. A company has a 500 TB image repository that needs to be transported to AWS for
processing. Which AWS service can import this data MOST cost-effectively?
A. AWS Snowball
B. AWS Direct Connect
C. AWS VPN
D. Amazon S3
121. A company has a 500 TB image repository that needs to be transported to AWS for
processing. Which AWS service can import this data MOST cost-effectively?
AWS Snowball
AWS VPN
Amazon S3
122. Which AWS service can run a managed PostgreSQL database that provides online
transaction processing (OLTP)?
Amazon DynamoDB
Amazon Athena
Amazon RDS
Amazon EMR
123. Which of the following assist in identifying costs by department? (Choose two.)
Principal
Action
Resource
Statement
125. Which AWS service allows for effective cost management of multiple AWS
accounts?
AWS Organizations
Amazon Connect
126. A company is piloting a new customer-facing application on Amazon Elastic
Compute Cloud (Amazon EC2) for one month.
What pricing model is appropriate?
Reserved Instances
Spot Instances
On-Demand Instances
Dedicated Hosts
127. Which AWS tools automatically forecast future AWS costs?
Cost Explorer
128. Under the AWS shared responsibility model, which of the following is a
responsibility of AWS?
AWS Budgets.
Amazon Macie.
Amazon QuickSight.
AWS Organizations.
130. Performing operations as code is a design principle that supports which pillar of
the AWS Well-Architected Framework?
Performance efficiency
Operational excellence
Reliability
Security
131. Which design principle is achieved by following the reliability pillar of the AWS
Well-Architected Framework?
Vertical scaling
Users can exchange Convertible RIs for other Convertible RIs from a different instance family.
Users can exchange Convertible RIs for other Convertible RIs in different AWS Regions.
Users can sell and buy Convertible RIs on the AWS Marketplace.
Users can shorten the term of their Convertible RIs by merging them with other Convertible
RIs.
133. The user is fully responsible for which action when running workloads on AWS?
Open an AWS Support case, provide the architecture proposal, and ask for a monthly cost
estimation.
Collect the published prices of the AWS services and calculate the monthly estimate.
Use the AWS Simple Monthly Calculator to estimate the monthly cost.
Use the AWS Total Cost of Ownership (TCO) Calculator to estimate the monthly cost.
135. Which are benefits of using Amazon RDS over Amazon EC2 when running relational
databases on AWS? (Choose two.)
Automated backups
Schema management
Indexing of tables
Software patching
Automated backups
Schema management
Indexing of tables
Software patching
137. What does the Amazon S3 Intelligent-Tiering storage class offer?
Long-term retention of data by copying the data to an encrypted Amazon Elastic Block Store
(Amazon EBS) volume
Automatic cost savings by moving objects between tiers based on access pattern changes
Amazon DynamoDB
Amazon Redshift
Amazon Athena
Amazon QuickSight
139. Which AWS service can be used to track resource changes and establish
compliance?
Amazon CloudWatch
AWS Config
AWS CloudTrail
High availability
Elasticity
Security
Loose coupling
141. A user has a stateful workload that will run on Amazon EC2 for the next 3 years.
What is the MOST cost-effective pricing model for this workload?
On-Demand Instances
Reserved Instances
Dedicated Instances
Spot Instances
142. A cloud practitioner needs an Amazon EC2 instance to launch and run for 7 hours
without interruptions. What is the most suitable and cost-effective option for this task?
A. On-Demand Instance
B. Reserved Instance
C. Dedicated Host
D. Spot Instance
143. Which of the following are benefits of using AWS Trusted Advisor? (Choose two.)
Grant the developer access to only the AWS resources needed to perform the job.
Share the AWS account root user credentials with the developer.
Configure a password policy that ensures the developer's password cannot be changed.
Amazon Lightsail
AWS Snowball
147. Which service provides a user the ability to warehouse data in the AWS Cloud?
Amazon EFS
Amazon Redshift
Amazon RDS
Amazon VPC
148. A user is planning to migrate an application workload to the AWS Cloud.
Which control becomes the responsibility of AWS once the migration is complete?
AWS Config
AWS OpsWorks
Amazon Kinesis
150. Which AWS service can be used to provide an on-demand, cloud-based contact
center?
Amazon Connect
Cost Explorer
TCO Calculator
AWS Budgets
NAT gateway
VPC endpoint
VPN connection
Internet gateway
153. Which pricing model would result in maximum Amazon Elastic Compute Cloud
(Amazon EC2) savings for a database server that must be online for one year?
Spot Instance
On-Demand Instance
Partial Upfront Reserved Instance
Configure EC2 Auto Recovery to move the instance to another Availability Zone
Use any AWS service and implement PCI controls at the application layer
Use an AWS service that is in-scope for PCI compliance and raise an AWS support ticket to
enable PCI compliance at the application layer
Use any AWS service and raise an AWS support ticket to enable PCI compliance on that service
Use an AWS service that is in scope for PCI compliance and apply PCI controls at the
application layer
158. A company is building an application that requires the ability to send, store, and
receive messages between application components. The company has another
requirement to process messages in first-in, first-out (FIFO) order.
Which AWS service should the company use?
Example Corp. must submit a request to its AWS solutions architect or AWS technical account
manager to link the accounts and consolidate billing.
AnyCompany must create a new support case in the AWS Support Center requesting that both
bills be combined.
Send an invitation to join the organization from AnyCompany’s AWS Organizations master
account to Example Corp.
Migrate the Example Corp. VPCs, Amazon EC2 instances, and other resources into the
AnyCompany AWS account.
160. Which tool can be used to create alerts when the actual or forecasted cost of AWS
services exceeds a certain threshold?
Cost Explorer
AWS Budgets
AWS CloudTrail
161. A user has limited knowledge of AWS services, but wants to quickly deploy a
scalable Node.js application in the AWS Cloud.
Which service should be used to deploy the application?
AWS CloudFormation
Amazon EC2
AWS OpsWorks
162. Which AWS Trusted Advisor check is available to all AWS users?
Core checks
All checks
AWS Shield
AWS CloudTrail
Amazon CloudFront
AWS Config
Amazon GuardDuty
AWS Artifact
165. A company wants to provide one of its employees with access to Amazon RDS. The
company also wants to limit the interaction to only the AWS CLI and AWS software
development kits (SDKs).
Which combination of actions should the company take to meet these requirements
while following the principles of least privilege? (Choose two.)
Create an IAM user and provide AWS Management Console access only.
Create an IAM role and provide AWS Management Console access only.
Create an IAM policy with administrator access and attach it to the IAM user.
Create an IAM policy with Amazon RDS access and attach it to the IAM user.
166. A company has a compliance requirement to record and evaluate configuration
changes, as well as perform remediation actions on AWS resources.
Which AWS service should the company use?
AWS Config
Dedicated Hosts
On-Demand Instances
Spot Instances
Reserved Instances
169. Which tool can be used to identify scheduled changes to the AWS infrastructure?
Billing Dashboard
AWS Config
170. Which of the following is the customer’s responsibility when using Amazon RDS?
Platform management
Code encryption
172. A company wants to be notified when its AWS Cloud costs or usage exceed defined
thresholds. Which AWS service will support these requirements?
AWS Budgets
Cost Explorer
AWS CloudTrail
Amazon Macie
173. Which AWS service provides the ability to host a NoSQL database in the AWS
Cloud?
Amazon Aurora
Amazon DynamoDB
Amazon RDS
Amazon Redshift
174. Which AWS service allows customers to purchase unused Amazon EC2 capacity at
an often discounted rate?
Reserved Instances
On-Demand Instances
Dedicated Instances
Spot Instances
175. Which AWS service or feature requires an internet service provider (ISP) and a
colocation facility to be implemented?
AWS VPN
Amazon Connect
Internet gateway
176. Which AWS services offer compute capabilities? (Choose two.)
Amazon EC2
Amazon S3
Amazon Cognito
AWS Lambda
177. Which AWS service can be used to privately store and manage versions of source
code?
AWS CodeBuild
AWS CodeCommit
AWS CodePipeline
AWS CodeStar
178. Which AWS service should a cloud practitioner use to identify security
vulnerabilities of an AWS account?
Amazon Cognito
Amazon Macie
Edge locations
Availability Zones
Regions
Amazon Route 53
180. Which AWS service or feature is used to send both text and email messages from
distributed applications?