100% de satisfacción garantizada Inmediatamente disponible después del pago Tanto en línea como en PDF No estas atado a nada 4,6 TrustPilot
logo-home
Examen

AWS CLOUD CERTIFICATION EXAM PRACTICE QUESTIONS WITH 100% CORRECT ANSWERS AND RATIONALES

Puntuación
-
Vendido
-
Páginas
65
Grado
A+
Subido en
14-05-2025
Escrito en
2024/2025

AWS CLOUD CERTIFICATION EXAM PRACTICE QUESTIONS WITH 100% CORRECT ANSWERS AND RATIONALES Which of the below are TRUE when running a database in an EC2 Instance? (choose 3) The customer is responsible for updating the operating system The customer is responsible for updating the database software The customer is responsible for managing access to the database AWS is responsible for managing access to the database AWS is responsible for updating the operating system AWS is responsible for updating the database software -ANSWER-- The customer is responsible for updating the operating system The customer is responsible for updating the database software The customer is responsible for managing access to the database In this case - as the database is being run in an EC2 instance, all aspects of database updates and access is the responsibility of the customer. Similarly as it is and EC2 instance, the customer is responsible for OS patching. Under the Shared Responsibility Model, AWS takes responsibility for managing all the hardware (including access, patching and other maintenance) and software required to deliver the service - which in this case is the EC2 instance - anything to do with the instance itself is the responsibility of the customer You want to streamline access management for your AWS administrators by assigning them a pre-defined set of permissions based on their job role - which of the below is the best way to approach this? Use IAM Groups Use Amazon Cognito Use AWS Organizations Use IAM Roles -ANSWER-- Use IAM Groups Using IAM Groups lets you create a list of pre-defined permissions that any user made a part of that group will be granted. Roles are primarily used to grant AWS resources permissions to other AWS resources and generally are not for end-users. Amazon Cognito is a service that help authenticate users to your apps, and not the AWS console itself A purchasing department staff member is setup as an AWS user in the company's procurement AWS account. At each month-end, the staff member needs access to an application running on EC2 in the company's accounts payable AWS account to reconcile reports. Which of the following provides the most secure and operationally efficient way to give the staff member access to the accounts payable application? Configure Active Directory integration so that you can federate the staff member's access to the accounts payable AWS account Create a user for the staff member in the accounts payable AWS account Invoke an AWS Lambda function to run the application in the accounts payable AWS account Have the user request temporary security credentials for the application by assuming a role -ANSWER-- Have the user request temporary security credentials for the application by assuming a role The staff member should be given the ability to assume a role programmatically with the permissions necessary to run the accounts payable application. Setting up another l AWS user for the staff member in the accounts payable account will require the presentation of hard credentials programmatically. Both federation and Lambda wil require the use of a role as well, but with the added overhead of maintaining Active Directory or the Lambda function Which of the following statements are true about who can use IAM roles? (choose 3) An IAM user in a different AWS account than the role An IAM user in the same AWS account as the role A web service offered by AWS A web service offered by providers other than AWS -ANSWER-- An IAM user in a different AWS account than the role An IAM user in the same AWS account as the role A web service offered by AWS A role can be used by either an IAM user in the same AWS account as the role or a user in a different AWS account. A role can also be used by a web service that AWS offers; a prime example is Amazon EC2 According to the Shared Responsibility Model, which of the following is AWS responsible for? (choose 2) Network Access Control Lists Elastic Cloud Compute (EC2) infrastructure Amazon Virtual Private Cloud Security Groups Subnets -ANSWER-- Elastic Cloud Compute (EC2) infrastructure Amazon Virtual Private Cloud Protecting the infrastructure that runs all of the services in the AWS Cloud is the responsibility of AWS. Such services include EC2 infrastructure - the hardware compute platform for running EC2 instances and Amazon Virtual Private Cloud, or VPC, which enables customers to provision a logically isolated section of the AWS Cloud to launch their resources. The subnets, security groups, and network access control lists configured in the VPC are the responsibility of the customer Which service might you use to provide Distributed Denial of Service (DDoS) protection to your applications running on AWS? AWS Shield AWS WAF DynamoDB AWS Inspector -ANSWER-- AWS Shield AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS Which of the below are TRUE statements when it comes to data security in AWS? (choose 3) The customer is responsible for managing who can access the data AWS is responsible for the security of the hardware the data resides on The customer is responsible for the security of the software that manages the data AWS is responsible for the security of the software that manages the data AWS is responsible for managing who can access the data The customer is responsible for the security of the hardware the data resides on ANSWER-- The customer is responsible for managing who can access the data AWS is responsible for the security of the hardware the data resides on AWS is responsible for the security of the software that manages the data Under the Shared Responsibility Model, AWS takes responsibility for managing all the hardware (including access, patching and other maintenance) and software required to deliver the service - which includes security. The customer is responsible for who can access the data itself Enabling Amazon GuardDuty automatically grants this service the permission to analyze which of the following data sources? (choose 3)

Mostrar más Leer menos
Institución
AWS CLOUD CERTIFICATION
Grado
AWS CLOUD CERTIFICATION











Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.

Escuela, estudio y materia

Institución
AWS CLOUD CERTIFICATION
Grado
AWS CLOUD CERTIFICATION

Información del documento

Subido en
14 de mayo de 2025
Número de páginas
65
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

Vista previa del contenido

AWS CLOUD CERTIFICATION EXAM PRACTICE
QUESTIONS WITH 100% CORRECT ANSWERS AND
RATIONALES


Which of the below are TRUE when running a database in an EC2 Instance?
(choose 3)

The customer is responsible for updating the operating system
The customer is responsible for updating the database software
The customer is responsible for managing access to the database
AWS is responsible for managing access to the database
AWS is responsible for updating the operating system
AWS is responsible for updating the database software -ANSWER-- The customer is
responsible for updating the operating system
The customer is responsible for updating the database software
The customer is responsible for managing access to the database

In this case - as the database is being run in an EC2 instance, all aspects of database
updates and access is the responsibility of the customer. Similarly as it is and EC2
instance, the customer is responsible for OS patching. Under the Shared Responsibility
Model, AWS takes responsibility for managing all the hardware (including access,
patching and other maintenance) and software required to deliver the service - which in
this case is the EC2 instance - anything to do with the instance itself is the
responsibility of the customer

You want to streamline access management for your AWS administrators by assigning
them a pre-defined set of permissions based on their job role - which of the below is the
best way to approach this?

Use IAM Groups
Use Amazon Cognito
Use AWS Organizations
Use IAM Roles -ANSWER-- Use IAM Groups

Using IAM Groups lets you create a list of pre-defined permissions that any user made
a part of that group will be granted. Roles are primarily used to grant AWS resources
permissions to other AWS resources and generally are not for end-users. Amazon
Cognito is a service that help authenticate users to your apps, and not the AWS
console itself

A purchasing department staff member is setup as an AWS user in the company's

,procurement AWS account. At each month-end, the staff member needs access to an
application running on EC2 in the company's accounts payable AWS account to
reconcile reports. Which of the following provides the most secure and operationally
efficient way to give the staff member access to the accounts payable application?

Configure Active Directory integration so that you can federate the staff member's
access to the accounts payable AWS account
Create a user for the staff member in the accounts payable AWS account
Invoke an AWS Lambda function to run the application in the accounts payable AWS
account
Have the user request temporary security credentials for the application by assuming a
role -ANSWER-- Have the user request temporary security credentials for the
application by assuming a role

The staff member should be given the ability to assume a role programmatically with the
permissions necessary to run the accounts payable application. Setting up another
AWS user for the staff member in the accounts payable account will require the
presentation of hard credentials programmatically. Both federation and Lambda will
require the use of a role as well, but with the added overhead of maintaining Active
Directory or the Lambda function

Which of the following statements are true about who can use IAM roles?
(choose 3)

An IAM user in a different AWS account than the role
An IAM user in the same AWS account as the role
A web service offered by AWS
A web service offered by providers other than AWS -ANSWER-- An IAM user in a
different AWS account than the role
An IAM user in the same AWS account as the role
A web service offered by AWS

A role can be used by either an IAM user in the same AWS account as the role or a
user in a different AWS account. A role can also be used by a web service that AWS
offers; a prime example is Amazon EC2

According to the Shared Responsibility Model, which of the following is AWS
responsible for?
(choose 2)

Network Access Control Lists
Elastic Cloud Compute (EC2) infrastructure
Amazon Virtual Private Cloud

,Security Groups
Subnets -ANSWER-- Elastic Cloud Compute (EC2) infrastructure
Amazon Virtual Private Cloud

Protecting the infrastructure that runs all of the services in the AWS Cloud is the
responsibility of AWS. Such services include EC2 infrastructure - the hardware
compute platform for running EC2 instances and Amazon Virtual Private Cloud, or
VPC, which enables customers to provision a logically isolated section of the AWS
Cloud to launch their resources. The subnets, security groups, and network access
control lists configured in the VPC are the responsibility of the customer

Which service might you use to provide Distributed Denial of Service (DDoS) protection
to your applications running on AWS?

AWS Shield
AWS WAF
DynamoDB
AWS Inspector -ANSWER-- AWS Shield

AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that
safeguards applications running on AWS

Which of the below are TRUE statements when it comes to data security in AWS?
(choose 3)

The customer is responsible for managing who can access the data
AWS is responsible for the security of the hardware the data resides on
The customer is responsible for the security of the software that manages the data
AWS is responsible for the security of the software that manages the data
AWS is responsible for managing who can access the data
The customer is responsible for the security of the hardware the data resides on
ANSWER-- The customer is responsible for managing who can access the data
AWS is responsible for the security of the hardware the data resides on
AWS is responsible for the security of the software that manages the data

Under the Shared Responsibility Model, AWS takes responsibility for managing all the
hardware (including access, patching and other maintenance) and software required to
deliver the service - which includes security. The customer is responsible for who can
access the data itself

Enabling Amazon GuardDuty automatically grants this service the permission to
analyze which of the following data sources?
(choose 3)

, DNS query logs
VPC Flow Logs
AWS CloudTrail logs
Amazon S3 buckets -ANSWER-- DNS query logs
VPC Flow Logs
AWS CloudTrail logs

Amazon GuardDuty monitors the security of your AWS environment by analyzing and
processing three data sources, which are VPC Flow Logs, AWS CloudTrail event logs,
and DNS logs

With AWS services, you can use as many resources as you need, as well as use them
when you need them. Which of the following terms can be applied to this concept?
(choose 2)

Disposable resources
Temporary resources
Dedicated resources
Fixed resources -ANSWER-- Disposable resources
Temporary resources

Working in a traditional infrastructure environment means that you have to deal with
fixed resources, which is comparatively costly and labor-intensive. By contrast, AWS
services are much more convenient; the services provide the ability to use as many
resources as you need and dispose of them when you no longer need them. That's why
such resources are both temporary and disposable

Which of the following is a Shared Control of the AWS Shared Responsibility Model?

Patch Management
Firmware Upgrades
Hardware Maintanence
Security Group Configuration -ANSWER-- Patch Management

Shared Controls are elements of the Shared Responsibility Model where both AWS and
the customer have shared responsibilities within their own contexts. Patch
Management is a Shared Control, since AWS is responsible for patching and fixing
flaws within the infrastructure, including managed services like RDS, but customers are
responsible for patching their guest OS and applications. Firmware Upgrades, and
other Hardware maintenance processes are solely the responsibility of AWS.
Configuration of Security Groups remain the responsibility of the customer

If you have a new application and you are not sure about future demand, which of the
$12.99
Accede al documento completo:

100% de satisfacción garantizada
Inmediatamente disponible después del pago
Tanto en línea como en PDF
No estas atado a nada

Conoce al vendedor
Seller avatar
TopGradeGuru
1.5
(2)

Documento también disponible en un lote

Conoce al vendedor

Seller avatar
TopGradeGuru Teachme2-tutor
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
11
Miembro desde
1 año
Número de seguidores
0
Documentos
2428
Última venta
1 semana hace
GRADEHUB

We provide access to a wide range of professionally curated exams for students and educators. It offers high-quality, up-to-date assessment materials tailored to various subjects and academic levels. With instant downloads and affordable pricing, it's the go-to resource for exam preparation and academic success.

1.5

2 reseñas

5
0
4
0
3
0
2
1
1
1

Recientemente visto por ti

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes