Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 67 páginas
Examen

AWS Cloud Practitioner 65 Practice Exam 1 Full Certification Test (CLF-C02) With Well Elaborated Exam Questions and Answers

Document preview thumbnail
Vista previa 4 fuera de 67 páginas

AWS Cloud Practitioner 65 Practice Exam 1 Full Certification Test (CLF-C02) With Well Elaborated Exam Questions and Answers Question 1 An organization maintains separate Amazon Virtual Private Clouds (Amazon VPC) for each of its departments. With expanding business, the organization now wants to connect all Amazon Virtual Private Clouds (Amazon VPC) for better departmental collaboration. Which AWS service will help the organization tackle the issue effectively? AWS Transit Gateway AWS Direct Connect VPC peering connection AWS Site-to-Site VPN Correct option: AWS Transit Gateway AWS Transit Gateway connects Amazon Virtual Private Clouds (Amazon VPC) and onpremises networks through a central hub. This simplifies your network and puts an end to complex peering relationships. It acts as a cloud router – each new connection is only made once. As you expand globally, inter-Region peering connects AWS Transit Gateways using the AWS global network. Your data is automatically encrypted and never travels over the public internet. Incorrect options: VPC peering connection - A VPC peering connection is a networking connection between two Amazon Virtual Private Clouds (Amazon VPC) that enables you to route traffic between them privately. VPC peering connection is not transitive, a separate VPC peering connection has to be made between two VPCs that need to talk to each other. With growing VPCs, this gets difficult to manage. AWS Direct Connect - AWS Direct Connect creates a dedicated private connection from a remote network to your VPC. This is a private connection and does not use the public internet. Takes at least a month to establish this connection. AWS Direct Connect cannot be used to interconnect VPCs. AWS Site-to-Site VPN - AWS Site-to-Site VPN creates a secure connection between your data center or branch office and your AWS cloud resources. This connection goes over the public internet. AWS Site-to-Site VPN cannot be used to interconnect VPCs. Reference: Question 2 Which of the following Cloud Computing models does the 'gmail' service represent? Infrastructure as a service (IaaS) Software as a service (SaaS) Platform as a service (PaaS) Function as a service (Faas) Correct option: Software as a service (SaaS) Software as a Service (SaaS) provides you with a complete product that is run and managed by the service provider. With a Software as a Service (SaaS) offering, you don’t have to think about how the service is maintained or how the underlying infrastructure is managed. You only need to think about how you will use that particular software. Gmail is an example of Software as a Service (SaaS). Incorrect options: Infrastructure as a service (IaaS) - Infrastructure as a Service (IaaS) contains the basic building blocks for cloud IT. It typically provides access to networking features, computers (virtual or on dedicated hardware), and data storage space. IaaS gives the highest level of flexibility and management control over IT resources. Amazon EC2 is an example of Infrastructure as a Service (IaaS). Platform as a service (PaaS) - Platform as a Service (PaaS) removes the need to manage underlying infrastructure (usually hardware and operating systems), and allows you to focus on the deployment and management of your applications. You don’t need to worry about resource procurement, capacity planning, software maintenance, patching, or any of the other undifferentiated heavy lifting involved in running your application. AWS Elastic Beanstalk is an example of Platform as a Service (PaaS). Function as a service (FaaS) - Function as a service (FaaS) is a category of cloud computing services that provides a platform allowing customers to develop, run, and manage application functionalities without the complexity of building and maintaining the infrastructure typically associated with developing and launching an app. AWS Lambda is an example of Function as a service (FaaS). Reference: Question 3 Compared to the on-demand instance prices, what is the highest possible discount offered for reserved instances (RI)? 72 40 90 50 Correct option: 72 Reserved instances (RI) provide you with significant savings (up to 72%) on your Amazon Elastic Compute Cloud (Amazon EC2) costs compared to on-demand instance pricing. Reserved Instances (RI) are not physical instances, but rather a billing discount applied to the use of on-demand instances in your account. You can purchase a reserved instance (RI) for a one-year or three-year commitment, with the three-year commitment offering a bigger discount. Incorrect options: 90 50 40 These three options contradict the explanation provided above, so these options are incorrect. Reference: Question 4 Which budget types can be created under AWS Budgets (Select three)? Hardware budget Resource budget Software budget Cost budget Usage budget Reservation budget Correct options: AWS Budgets enable you to plan your service usage, service costs, and instance reservations. AWS Budgets information is updated up to three times a day. Updates typically occur between 8 to 12 hours after the previous update. Budgets track your unblended costs, subscriptions, refunds, and RIs. There are four different budget types you can create under AWS Budgets - Cost budget, Usage budget, Reservation budget and Savings Plans budget. Cost budget - Helps you plan how much you want to spend on a service. Usage budget - Helps you plan how much you want to use one or more services. Reservation budget - This helps you track the usage of your Reserved Instances (RI). Two ways of doing it - Reserved Instance (RI) utilization budgets (This lets you see if your Reserved Instances (RI) are unused or under-utilized), Reserved Instance (RI) coverage budgets (This lets you see how much of your instance usage is covered by a reservation). Incorrect options: Resource budget - This is a made-up option and has been added as a distractor. Software budget - This is a made-up option and has been added as a distractor. Hardware budget - This is a made-up option and has been added as a distractor. Reference: This is a made-up option and has been added as a distractor Question 5 A financial services enterprise plans to enable Multi-Factor Authentication (MFA) for its employees. For ease of travel, they prefer not to use any physical devices to implement Multi-Factor Authentication (MFA). Which of the below options is best suited for this use case? Soft Token Multi-Factor Authentication (MFA) device Virtual Multi-Factor Authentication (MFA) device U2F security key Hardware Multi-Factor Authentication (MFA) device Correct option: Virtual Multi-Factor Authentication (MFA) device A software app that runs on a phone or other device and emulates a physical device. The device generates a six-digit numeric code based upon a time-synchronized one-time password algorithm. The user must type a valid code from the device on a second webpage during sign-in. Each virtual Multi-Factor Authentication (MFA) device assigned to a user must be unique. A user cannot type a code from another user's virtual Multi-Factor Authentication (MFA) device to authenticate. Incorrect options: U2F security key - A device that you plug into a USB port on your computer. U2F is an open authentication standard hosted by the FIDO Alliance. When you enable a U2F security key, you sign in by entering your credentials and then tapping the device instead of manually entering a code. Hardware Multi-Factor Authentication (MFA) device - A hardware device that generates a six-digit numeric code based upon a time-synchronized one-time password algorithm. The user must type a valid code from the device on a second webpage during sign-in. Each Multi-Factor Authentication (MFA) device assigned to a user must be unique. A user cannot type a code from another user's device to be authenticated. Soft Token Multi-Factor Authentication (MFA) device - This is a made-up option and has been added as a distractor. Reference: Question 6 Which of the following is correct regarding the AWS Shield Advanced pricing? AWS Shield Advanced is a free service for all AWS Support plans AWS Shield Advanced is a free service for AWS Enterprise Support plan AWS Shield Advanced is a free service for AWS Business Support plan AWS Shield Advanced offers protection against higher fees that could result from a DDoS attack Correct option: AWS Shield Advanced offers protection against higher fees that could result from a DDoS attack AWS Shield Advanced offers some cost protection against spikes in your AWS bill that could result from a DDoS attack. This cost protection is provided for your Elastic Load Balancing load balancers, Amazon CloudFront distributions, Amazon Route 53 hosted zones, Amazon Elastic Compute Cloud instances, and your AWS Global Accelerator accelerators. AWS Shield Advanced is a paid service for all customers, irrespective of the Support plan. Incorrect options: AWS Shield Advanced is a free service for AWS Enterprise Support plan AWS Shield Advanced is a free service for AWS Business Support plan AWS Shield Advanced is a free service for all AWS Support plans These three options contradict the details provided earlier in the explanation, so these options are incorrect. Reference: Question 7 A research lab wants to optimize the caching capabilities for its scientific computations application running on Amazon Elastic Compute Cloud (Amazon EC2) instances. Which Amazon Elastic Compute Cloud (Amazon EC2) storage option is best suited for this use-case? Amazon Elastic Block Store (Amazon EBS) Amazon Elastic File System (Amazon EFS) Amazon Simple Storage Service (Amazon S3) Instance Store Correct option: Instance Store An Instance Store provides temporary block-level storage for your Amazon EC2 instance. This storage is located on disks that are physically attached to the host computer. Instance store is ideal for the temporary storage of information that changes frequently, such as buffers, caches, scratch data, and other temporary content, or for data that is replicated across a fleet of instances, such as a load-balanced pool of web servers. Instance storage is temporary, data is lost if instance experiences failure or is terminated. Incorrect options: Amazon Elastic Block Store (Amazon EBS) - Amazon Elastic Block Store (Amazon EBS) is an easy to use, high-performance block storage service designed for use with Amazon Elastic Compute Cloud (Amazon EC2) for both throughput and transaction-intensive workloads at any scale. A broad range of workloads, such as relational and non-relational databases, enterprise applications, containerized applications, big data analytics engines, file systems, and media workflows are widely deployed on Amazon EBS. Amazon EBS is not a good fit for caching information on Amazon EC2 instances. Amazon Elastic File System (Amazon EFS) - Amazon Elastic File System (Amazon EFS) provides a simple, scalable, fully managed, elastic NFS file system. It is built to scale ondemand to petabytes without disrupting applications, growing and shrinking automatically as you add and remove files, eliminating the need to provision and manage capacity to accommodate growth. Amazon EFS is designed to provide massively parallel shared access to thousands of Amazon EC2 instances, enabling your applications to achieve high levels of aggregate throughput and IOPS with consistent low latencies. Amazon EFS is not a good fit for caching information on Amazon EC2 instances. Amazon Simple Storage Service (Amazon S3) - Amazon Simple Storage Service (Amazon S3) is an object storage service that offers industry-leading scalability, data availability, security, and performance. Amazon S3 is not a good fit for caching information on Amazon EC2 instances. Reference: Question 8 An IT company has a hybrid cloud architecture and it wants to centralize the server logs for its Amazon Elastic Compute Cloud (Amazon EC2) instances and on-premises servers. Which of the following is the MOST effective for this use-case? Use AWS Lambda to send log data from Amazon Elastic Compute Cloud (Amazon EC2) instance as well as on-premises servers to Amazon CloudWatch Logs Use Amazon CloudWatch Logs for both the Amazon Elastic Compute Cloud (Amazon EC2) instance and the on-premises servers Use Amazon CloudWatch Logs for the Amazon Elastic Compute Cloud (Amazon EC2) instance and AWS CloudTrail for the on-premises servers Use AWS CloudTrail for the Amazon Elastic Compute Cloud (Amazon EC2) instance and Amazon CloudWatch Logs for the on-premises servers Correct option: Use Amazon CloudWatch Logs for both the Amazon Elastic Compute Cloud (Amazon EC2) instance and the on-premises servers You can use Amazon CloudWatch Logs to monitor, store, and access your log files from Amazon Elastic Compute Cloud (Amazon EC2) instances, AWS CloudTrail, Route 53, and other sources such as on-premises servers. Amazon CloudWatch Logs enables you to centralize the logs from all of your systems, applications, and AWS services that you use, in a single, highly scalable service. You can then easily view them, search them for specific error codes or patterns, filter them based on specific fields, or archive them securely for future analysis. Incorrect options: Use AWS Lambda to send log data from Amazon Elastic Compute Cloud (Amazon EC2) instance as well as on-premises servers to Amazon CloudWatch Logs AWS Lambda lets you run code without provisioning or managing servers. You pay only for the compute time you consume. Lambda cannot be used to centralize the logs from Amazon Elastic Compute Cloud (Amazon EC2) instances and on-premises servers. Use Amazon CloudWatch Logs for the Amazon Elastic Compute Cloud (Amazon EC2) instance and AWS CloudTrail for the on-premises servers Use AWS CloudTrail for the Amazon Elastic Compute Cloud (Amazon EC2) instance and Amazon CloudWatch Logs for the on-premises servers AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. With AWS CloudTrail, you can log, continuously monitor, and retain account activity related to actions across your AWS infrastructure. AWS CloudTrail provides event history of your AWS account activity, including actions taken through the AWS Management Console, AWS SDKs, command-line tools, and other AWS services. AWS CloudTrail cannot be used to centralize the server logs for Amazon Elastic Compute Cloud (Amazon EC2) instances or on-premises servers, so both these options are incorrect. References: Question 9 A customer is running a comparative study of pricing models of Amazon EFS and Amazon Elastic Block Store (Amazon EBS) that are used with the Amazon EC2 instances that host the application. Which of the following statements are correct regarding this use-case? (Select two) Amazon Elastic Block Store (Amazon EBS) Snapshot storage pricing is based on the amount of space your data consumes in Amazon Elastic Block Store (Amazon EBS) Amazon Elastic Block Store (Amazon EBS) Snapshots are stored incrementally, which means you are billed only for the changed blocks stored With AWS Backup, you pay only for the amount of Amazon Elastic File System (Amazon EFS) backup storage you use in a month, you need not pay for restoring this data You will pay a fee each time you read from or write data stored on the Amazon Elastic File System (Amazon EFS) - Infrequent Access storage class Amazon Elastic Compute Cloud (Amazon EC2) data transfer charges will apply for all Amazon Elastic Block Store (Amazon EBS) direct APIs for Snapshots Correct options: You will pay a fee each time you read from or write data stored on the Amazon Elastic File System (Amazon EFS) - Infrequent Access storage class Amazon Elastic File System (Amazon EFS) - Infrequent Access storage class is cost-optimized for files accessed less frequently. Data stored on the Amazon Elastic File System (Amazon EFS) - Infrequent Access storage class costs less than Standard and you will pay a fee each time you read from or write to a file. Amazon Elastic Block Store (Amazon EBS) Snapshots are stored incrementally, which means you are billed only for the changed blocks stored Amazon EBS Snapshots are a point in time copy of your block data. For the first snapshot of a volume, Amazon EBS saves a full copy of your data to Amazon S3. Amazon EBS Snapshots are stored incrementally, which means you are billed only for the changed blocks stored. Incorrect options: Amazon Elastic Compute Cloud (Amazon EC2) data transfer charges will apply for all Amazon Elastic Block Store (Amazon EBS) direct APIs for Snapshots - When using Amazon EBS direct APIs for Snapshots, additional Amazon EC2 data transfer charges will apply only when you use external or cross-region data transfers. Amazon Elastic Block Store (Amazon EBS) Snapshot storage pricing is based on the amount of space your data consumes in Amazon Elastic Block Store (Amazon EBS) Snapshot storage is based on the amount of space your data consumes in Amazon S3. Because Amazon EBS does not save empty blocks, it is likely that the snapshot size will be considerably less than your volume size. Copying Amazon EBS snapshots is charged for the data transferred across regions. After the snapshot is copied, standard Amazon EBS snapshot charges apply for storage in the destination region. With AWS Backup, you pay only for the amount of Amazon Elastic File System (Amazon EFS) backup storage you use in a month, you need not pay for restoring this data - To back up your Amazon EFS file data you can use AWS Backup, a fully-managed backup service that makes it easy to centralize and automate the back up of data across AWS services. With AWS Backup, you pay only for the amount of backup storage you use and the amount of backup data you restore in the month. There is no minimum fee and there are no set-up charges. References: Question 10 Which Amazon Simple Storage Service (Amazon S3) storage class offers the lowest availability? Amazon S3 Standard Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA) Amazon S3 Intelligent-Tiering Amazon S3 Glacier Flexible Retrieval Correct option: Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA) Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA) is for data that is accessed less frequently but requires rapid access when needed. Unlike other Amazon S3 Storage Classes which store data in a minimum of three Availability Zones (AZ), Amazon S3 One ZoneInfrequent Access (S3 One Zone-IA) stores data in a single Availability Zone (AZ). Incorrect options: Amazon S3 Standard - Amazon S3 Standard offers high durability, availability, and performance object storage for frequently accessed data. Amazon S3 Intelligent-Tiering - The Amazon S3 Intelligent-Tiering storage class is designed to optimize costs by automatically moving data to the most cost-effective access tier, without performance impact or operational overhead. It works by storing objects in two access tiers: one tier that is optimized for frequent access and another lower-cost tier that is optimized for infrequent access. Amazon S3 Glacier Flexible Retrieval - Amazon S3 Glacier Flexible Retrieval is a secure, durable, and extremely low-cost Amazon S3 cloud storage class for data archiving and longterm backup. It is designed to deliver 99.% durability, and provide comprehensive security and compliance capabilities that can help meet even the most stringent regulatory requirements. Reference: Question 11 Which of the following are components of an AWS Site-to-Site VPN? (Select two) Virtual private gateway (VGW) AWS storage gateway Network Address Translation gateway (NAT gateway) Internet gateway Customer gateway Correct option: Virtual private gateway (VGW) Customer gateway A virtual private gateway (VGW) is the VPN concentrator on the Amazon side of the AWS Site-to-Site VPN connection. A customer gateway is a resource in AWS that provides information to AWS about your Customer gateway device. Incorrect options: AWS storage gateway - AWS storage gateway is a hybrid cloud storage service that connects your existing on-premises environments with the AWS Cloud. Customers use storage gateway to simplify storage management and reduce costs for key hybrid cloud storage use cases. Network Address Translation gateway (NAT gateway) - A Network Address Translation gateway (NAT gateway) or a NAT Instance can be used in a public subnet in your VPC to enable instances in the private subnet to initiate outbound IPv4 traffic to the Internet. Network Address Translation gateway (NAT gateway) is managed by AWS but NAT Instance is managed by you. Internet gateway - An internet gateway is a horizontally scaled, redundant, and highly available VPC component that allows communication between instances in your VPC and the internet. It, therefore, imposes no availability risks or bandwidth constraints on your network traffic. Reference: Question 12 A startup has just moved its IT infrastructure to AWS Cloud. The CTO would like to receive detailed reports that break down the startup's AWS costs by the hour in an Amazon Simple Storage Service (Amazon S3) bucket. As a Cloud Practitioner, which AWS service would you recommend for this use-case? AWS Budgets AWS Cost Explorer AWS Cost & Usage Report (AWS CUR) AWS Pricing Calculator Correct option: AWS Cost & Usage Report (AWS CUR) AWS Cost & Usage Report (AWS CUR) contains the most comprehensive set of cost and usage data available. You can use AWS Cost & Usage Report (AWS CUR) to publish your AWS billing reports to an Amazon Simple Storage Service (Amazon S3) bucket that you own. You can receive reports that break down your costs by the hour or month, by product or product resource, or by tags that you define yourself. AWS updates the report in your bucket once a day in comma-separated value (CSV) format. Incorrect options: AWS Pricing Calculator - AWS Pricing Calculator lets you explore AWS services and create an estimate for the cost of your use cases on AWS. You can model your solutions before building them, explore the price points and calculations behind your estimate, and find the available instance types and contract terms that meet your needs. This enables you to make informed decisions about using AWS. You can plan your AWS costs and usage or price out setting up a new set of instances and services. AWS Cost Explorer - AWS Cost Explorer has an easy-to-use interface that lets you visualize, understand, and manage your AWS costs and usage over time. AWS Cost Explorer includes a default report that helps you visualize the costs and usage associated with your top five costaccruing AWS services, and gives you a detailed breakdown of all services in the table view. The reports let you adjust the time range to view historical data going back up to twelve months to gain an understanding of your cost trends. AWS Cost Explorer cannot provide a detailed report of your AWS costs by the hour into an Amazon S3 bucket. AWS Budgets - AWS Budgets gives the ability to set custom budgets that alert you when your costs or usage exceed (or are forecasted to exceed) your budgeted amount. You can also use AWS Budgets to set reservation utilization or coverage targets and receive alerts when your utilization drops below the threshold you define. AWS Budgets can be created at the monthly, quarterly, or yearly level, and you can customize the start and end dates. You can further refine your budget to track costs associated with multiple dimensions, such as AWS service, linked account, tag, and others. AWS Budgets cannot provide the estimate of the monthly AWS bill based on the list of AWS services. AWS Budgets cannot provide a detailed break down of your AWS costs by the hour. Exam Alert: Please review the differences between "AWS Cost & Usage Report (AWS CUR)" and "AWS Cost Explorer". Think of "AWS Cost & Usage Report (AWS CUR)" as a cost management tool providing the most detailed cost and usage data for your AWS account. It can provide reports that break down your costs by the hour into your Amazon S3 bucket. On the other hand, "AWS Cost Explorer" is more of a high-level cost management tool that helps you visualize the costs and usage associated with your AWS account. References: Question 13 Which feature of AWS Cloud offers the ability to innovate faster and rapidly develop, test and launch software applications? Elasticity Agility Ability to deploy globally in minutes Cost savings Correct option: Cloud computing is the on-demand delivery of IT resources over the Internet with pay-asyou-go pricing. Instead of buying, owning, and maintaining physical data centers and servers, you can access technology services, such as computing power, storage, and databases, on an as-needed basis from a cloud provider like Amazon Web Services (AWS). Agility - Agility refers to the ability of the cloud to give you easy access to a broad range of technologies so that you can innovate faster and build nearly anything that you can imagine. You can quickly spin up resources as you need them – from infrastructure services, such as compute, storage, and databases, to Internet of Things, machine learning, data lakes and analytics, and much more. Incorrect options: Elasticity - With cloud computing elasticity, you don’t have to over-provision resources upfront to handle peak levels of business activity in the future. Instead, you provision the number of resources that you actually need. You can scale these resources up or down instantly to grow and shrink capacity as your business needs change. Cost savings - The cloud allows you to trade capital expenses (such as data centers and physical servers) for variable expenses, and only pay for IT as you consume it. Plus, the variable expenses are much lower than what you would pay to do it yourself because of the economies of scale. Ability to deploy globally in minutes - With the cloud, you can expand to new geographic regions and deploy globally in minutes. For example, AWS has infrastructure all over the world, so you can deploy your application in multiple physical locations with just a few clicks. Putting applications in closer proximity to end users reduces latency and improves their experience. Exam Alert: Reference:

Vista previa del contenido

AWS Cloud Practitioner 65 Practice Exam 1 Full Certification Test (CLF-C02) With Well Elaborated Exam
Questions and Answers

Question 1

An organization maintains separate Amazon Virtual Private Clouds (Amazon VPC) for each of its
departments. With expanding business, the organization now wants to connect all Amazon Virtual Private
Clouds (Amazon VPC) for better departmental collaboration. Which AWS service will help the organization
tackle the issue effectively?

AWS Transit Gateway

AWS Direct Connect

VPC peering connection

AWS Site-to-Site VPN Correct

option:

AWS Transit Gateway

AWS Transit Gateway connects Amazon Virtual Private Clouds (Amazon VPC) and onpremises networks
through a central hub. This simplifies your network and puts an end to complex peering relationships. It acts
as a cloud router – each new connection is only made once. As you expand globally, inter-Region peering
connects AWS Transit Gateways using the AWS global network. Your data is automatically encrypted and
never travels over the public internet.

Incorrect options:

VPC peering connection - A VPC peering connection is a networking connection between two Amazon
Virtual Private Clouds (Amazon VPC) that enables you to route traffic between them privately. VPC peering
connection is not transitive, a separate VPC peering connection has to be made between two VPCs that
need to talk to each other. With growing VPCs, this gets difficult to manage.

AWS Direct Connect - AWS Direct Connect creates a dedicated private connection from a remote network to
your VPC. This is a private connection and does not use the public internet. Takes at least a month to
establish this connection. AWS Direct Connect cannot be used to interconnect VPCs.

AWS Site-to-Site VPN - AWS Site-to-Site VPN creates a secure connection between your data center or
branch office and your AWS cloud resources. This connection goes over the public internet. AWS Site-to-Site
VPN cannot be used to interconnect VPCs.

Reference:

https://aws.amazon.com/transit-gateway/

,Question 2

Which of the following Cloud Computing models does the 'gmail' service represent?

Infrastructure as a service (IaaS)

Software as a service (SaaS)

Platform as a service (PaaS)

Function as a service (Faas) Correct

option:

Software as a service (SaaS)

Software as a Service (SaaS) provides you with a complete product that is run and managed by the service
provider. With a Software as a Service (SaaS) offering, you don’t have to think about how the service is
maintained or how the underlying infrastructure is managed. You only need to think about how you will use
that particular software. Gmail is an example of Software as a Service (SaaS).

Incorrect options:

Infrastructure as a service (IaaS) - Infrastructure as a Service (IaaS) contains the basic building blocks for
cloud IT. It typically provides access to networking features, computers (virtual or on dedicated hardware),
and data storage space. IaaS gives the highest level of flexibility and management control over IT resources.
Amazon EC2 is an example of Infrastructure as a Service (IaaS).

Platform as a service (PaaS) - Platform as a Service (PaaS) removes the need to manage underlying
infrastructure (usually hardware and operating systems), and allows you to focus on the deployment and
management of your applications. You don’t need to worry about resource procurement, capacity planning,
software maintenance, patching, or any of the other undifferentiated heavy lifting involved in running your
application. AWS Elastic Beanstalk is an example of Platform as a Service (PaaS).

Function as a service (FaaS) - Function as a service (FaaS) is a category of cloud computing services that
provides a platform allowing customers to develop, run, and manage application functionalities without the
complexity of building and maintaining the infrastructure typically associated with developing and launching
an app. AWS Lambda is an example of Function as a service (FaaS).

Reference: https://aws.amazon.com/types-of-cloud-computing/


Question 3

Compared to the on-demand instance prices, what is the highest possible discount offered for reserved
instances (RI)?

,72

40

90

50

Correct option:

72

Reserved instances (RI) provide you with significant savings (up to 72%) on your Amazon Elastic Compute
Cloud (Amazon EC2) costs compared to on-demand instance pricing. Reserved Instances (RI) are not physical
instances, but rather a billing discount applied to the use of on-demand instances in your account. You can
purchase a reserved instance (RI) for a one-year or three-year commitment, with the three-year
commitment offering a bigger discount.

Incorrect options:

90

50

40

These three options contradict the explanation provided above, so these options are incorrect.

Reference: https://aws.amazon.com/ec2/pricing/


Question 4

Which budget types can be created under AWS Budgets (Select three)?

Hardware budget

Resource budget

Software budget

Cost budget

Usage budget Reservation

budget

Correct options:

, AWS Budgets enable you to plan your service usage, service costs, and instance reservations. AWS Budgets
information is updated up to three times a day. Updates typically occur between 8 to 12 hours after the
previous update. Budgets track your unblended costs, subscriptions, refunds, and RIs. There are four
different budget types you can create under AWS Budgets - Cost budget, Usage budget, Reservation budget
and Savings Plans budget.

Cost budget - Helps you plan how much you want to spend on a service.

Usage budget - Helps you plan how much you want to use one or more services.

Reservation budget - This helps you track the usage of your Reserved Instances (RI). Two ways of doing it -
Reserved Instance (RI) utilization budgets (This lets you see if your Reserved Instances (RI) are unused or
under-utilized), Reserved Instance (RI) coverage budgets (This lets you see how much of your instance usage
is covered by a reservation).

Incorrect options:

Resource budget - This is a made-up option and has been added as a distractor.

Software budget - This is a made-up option and has been added as a distractor.

Hardware budget - This is a made-up option and has been added as a distractor.

Reference:

This is a made-up option and has been added as a distractor



Question 5

A financial services enterprise plans to enable Multi-Factor Authentication (MFA) for its employees. For ease
of travel, they prefer not to use any physical devices to implement Multi-Factor Authentication (MFA).
Which of the below options is best suited for this use case?

Soft Token Multi-Factor Authentication (MFA) device

Virtual Multi-Factor Authentication (MFA) device

U2F security key

Hardware Multi-Factor Authentication (MFA) device Correct option:

Virtual Multi-Factor Authentication (MFA) device

A software app that runs on a phone or other device and emulates a physical device. The device generates a
six-digit numeric code based upon a time-synchronized one-time password algorithm. The user must type a
valid code from the device on a second webpage during sign-in. Each virtual Multi-Factor Authentication

Información del documento

Subido en
5 de diciembre de 2025
Número de páginas
67
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$8.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
NurseQueen1
4.7
(3)
Vendido
4
Seguidores
0
Artículos
196
Última venta
8 meses hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes