Question #1 To install a PCI-compliant workload on AWS, which of the following tasks is required?• A. Use any AWS service and implement PCI controls at the application layer • B. Use an AWS service that is in-scope for PCI compliance and raise an AWS support ticket to enable PCI compliance at the application layer • C. Use any AWS service and raise an AWS support ticket to enable PCI compliance on that service • D. Use an AWS service that is in scope for PCI compliance and apply PCI controls at the application layer Question #2 According to the AWS shared responsibility model, who is responsible for managing IAM user access and secret keys?• A. IAM access and secret keys are static, so there is no need to rotate them.• B. The customer is responsible for rotating keys.• C. AWS will rotate the keys whenever required.• D. The AWS Support team will rotate keys when requested by the customer.Question #3 Which security-related duty is AWS accountable for under the AWS shared responsibility model?• A. Lifecycle management of IAM credentials • B. Physical security of global infrastructure • C. Encryption of Amazon EBS volumes • D. Firewall configuration Question #4 Which cloud architecture design concept is supported by distributing workloads across various Availability Zones?• A. Implement automation.• B. Design for agility.• C. Design for failure.• D. Implement elasticity.Question #5 What is one technique to provide unified billing if each department within a firm has its own AWS account? 1 / 4
• A. Use AWS Budgets on each account to pay only to budget.• B. Contact AWS Support for a monthly bill.• C. Create an AWS Organization from the payer account and invite the other accounts to join.• D. Put all invoices into one Amazon Simple Storage Service (Amazon S3) bucket, load data into Amazon Redshift, and then run a billing report.Question #6 Who is responsible for configuration management under the AWS shared responsibility model?• A. It is solely the responsibility of the customer.• B. It is solely the responsibility of AWS.• C. It is shared between AWS and the customer.• D. It is not part of the AWS shared responsibility model.Question #7 Who is the main point of contact for billing or account questions if a user has an AWS account with an Enterprise-level AWS Support plan?• A. Solutions architect • B. AWS Concierge Support team • C. An AWS Marketplace seller • D. AWS Partner Network (APN) partner Question #8 Which compute hosting model should be accounted for in the Total Cost of Ownership (TCO) when undertaking a cost analysis that allows physical isolation of a customer workload?• A. Dedicated Hosts • B. Reserved Instances • C. On-Demand Instances • D. No Upfront Reserved Instances Question #9 Which of the following is a suggestion made by an AWS Trusted Advisor? (Select two.) • A. Cost optimization • B. Auditing • C. Serverless architecture • D. Performance 2 / 4
• E. Scalability Question #10 Who is accountable for security and compliance under the AWS shared responsibility model?• A. The customer is responsible.• B. AWS is responsible.• C. AWS and the customer share responsibility.• D. AWS shares responsibility with the relevant governing body.Question #11 Which of the following is a critical design concept for architecting cloud applications?• A. Use the largest instance possible • B. Provision capacity for peak load • C. Use the Scrum development process • D. Implement elasticity Question #12 Which pillar of the AWS Well-Architected Framework is supported by the design philosophy of performing operations as code?• A. Performance efficiency • B. Operational excellence • C. Reliability • D. Security Question #13 What is the customer's responsibility while using Amazon RDS?• A. Patching and maintenance of the underlying operating system.• B. Managing automatic backups of the database.• C. Controlling network access through security groups.• D. Replacing failed instances in the event of a hardware failure.Question #14 Which of the following operational controls do users completely inherit from AWS as part of the AWS shared responsibility model?• A. Security management of data center 3 / 4
• B. Patch management • C. Configuration management • D. User and access management Question #15 What is the customer's obligation while using an AWS managed service under the AWS shared responsibility model?• A. Physical security of the data centers • B. Server-side encryption • C. Customer data • D. Operating system patching Question #16 Which pillar of the AWS Well-Architected Framework is designed on the idea of frequent, minor, reversible changes?• A. Reliability • B. Operational excellence • C. Performance efficiency • D. Cost optimization Question #17 Which AWS service can identify the person who made the API request when an Amazon EC2 instance is terminated?• A. Amazon CloudWatch • B. AWS CloudTrail • C. AWS X-Ray • D. AWS Identity and Access Management (IAM) Question #18 All AWS users have access to which AWS Trusted Advisor check?• A. Core checks • B. All checks • C. Cost optimization checks • D. Fault tolerance checks Question #19
- / 4