AWS Certified Cloud Practitioner (CLF-C02) — Questions and Answers
Question 1: What is data transfer pricing for traffic moving WITHIN the same AWS Availability Zone?
- $0.02 per GB
- $0.01 per GB
- $0.09 per GB
- Free (Correct answer)
Correct answer: Free
Data transfer between EC2 instances within the same Availability Zone using private IP addresses is free.
Question 2: A business requires that all its AWS resources be tagged for cost allocation. Which AWS service helps enforce this requirement?
- Amazon Inspector
- AWS IAM
- AWS Systems Manager
- AWS Config (Correct answer)
Correct answer: AWS Config
AWS Config continuously monitors and records AWS resource configurations and can evaluate them against desired rules, including tagging policies.
Question 3: Which AWS support plan provides access to a Technical Account Manager (TAM)?
- Enterprise (Correct answer)
- Developer
- Basic
- Business
Correct answer: Enterprise
AWS Enterprise support plan includes a designated Technical Account Manager (TAM) who provides proactive guidance and advocacy.
Question 4: Which AWS service provides a managed message queuing service that decouples microservices and distributed systems?
- Amazon SNS
- AWS Step Functions
- Amazon EventBridge
- Amazon SQS (Correct answer)
Correct answer: Amazon SQS
Amazon SQS (Simple Queue Service) is a fully managed message queuing service used to decouple and scale microservices and distributed systems.
Question 5: What is the AWS Free Tier, and how long does the standard 12-month free tier last?
- Free for 6 months on new regions
- Free only for Enterprise Support customers
- Unlimited free usage forever
- Free usage for 12 months after account creation (Correct answer)
Correct answer: Free usage for 12 months after account creation
The AWS Free Tier offers new customers 12 months of limited free usage for many services, starting from account creation date.
Question 6: Which AWS service scans EC2 instances and container images for software vulnerabilities and unintended network exposure?
- AWS Shield
- AWS Security Hub
- Amazon Macie
- Amazon Inspector (Correct answer)
Correct answer: Amazon Inspector
Amazon Inspector automatically assesses EC2 instances and ECR container images for vulnerabilities and deviations from best practices.
Question 7: Which architectural pattern decouples application components so they can scale and fail independently?
- Hard coding
- Loose coupling (Correct answer)
- Tight coupling
- Monolithic architecture
Correct answer: Loose coupling
Loose coupling uses queues, APIs, or events to separate components, so failures or scaling needs in one part don't directly impact others.
Question 8: Which AWS service provides a fully managed message queuing service to decouple application components?
- Amazon MQ
- Amazon SNS
- AWS EventBridge
- Amazon SQS (Correct answer)
Correct answer: Amazon SQS
Amazon SQS (Simple Queue Service) is a fully managed message queuing service that enables decoupling of application components.
Question 9: Which AWS service provides DDoS protection at no additional cost for all AWS customers?
- AWS Shield Advanced
- Amazon CloudFront
- AWS WAF
- AWS Shield Standard (Correct answer)
Correct answer: AWS Shield Standard
AWS Shield Standard is automatically included for all AWS customers at no extra charge and protects against common DDoS attacks.
Question 10: Which AWS feature enables you to require a second form of authentication when logging into the AWS Management Console?
- AWS Cognito
- AWS SSO
- Multi-Factor Authentication (MFA) (Correct answer)
- IAM Password Policy
Correct answer: Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) adds an extra layer of protection by requiring a one-time code in addition to a password.
Question 11: Which AWS offering provides automatic protection against DDoS attacks for all AWS customers at no additional cost?
- Amazon GuardDuty
- AWS Shield Advanced
- AWS WAF
- AWS Shield Standard (Correct answer)
Correct answer: AWS Shield Standard
AWS Shield Standard is automatically enabled for all AWS customers at no extra cost and protects against common network and transport-layer DDoS attacks.
Question 12: Which AWS service helps implement loose coupling by allowing components to communicate asynchronously via message queues?
- Amazon SQS (Correct answer)
- AWS Step Functions
- Amazon SNS
- Amazon EventBridge
Correct answer: Amazon SQS
Amazon SQS (Simple Queue Service) provides a managed message queue that decouples producers and consumers, enabling asynchronous and fault-tolerant communication.
Question 13: What does AWS mean by 'pay-as-you-go' pricing?
- Pay annually in advance for reserved capacity
- Pay per user rather than per resource
- Pay only for the resources you actually consume, with no upfront cost (Correct answer)
- Pay a flat monthly fee regardless of usage
Correct answer: Pay only for the resources you actually consume, with no upfront cost
AWS's pay-as-you-go model means you pay only for what you use, with no minimum fees or upfront commitments required.
Question 14: What is Amazon S3 Glacier used for?
- Real-time data processing
- Caching frequently accessed data
- Hosting static websites
- Long-term archival storage at very low cost with infrequent access requirements (Correct answer)
Correct answer: Long-term archival storage at very low cost with infrequent access requirements
Amazon S3 Glacier is a low-cost storage class designed for data archiving with retrieval times ranging from minutes to hours.
Question 15: What is a key advantage of using AWS Spot Instances?
- Guaranteed capacity at any time
- Up to 90% cost savings over On-Demand pricing (Correct answer)
- Fixed pricing regardless of demand
- No interruptions to running workloads
Correct answer: Up to 90% cost savings over On-Demand pricing
Spot Instances use spare AWS capacity and can save up to 90% compared to On-Demand prices, though they can be interrupted with a 2-minute warning.
Question 16: Which AWS service enables you to model and provision infrastructure as code using templates?
- AWS CloudFormation (Correct answer)
- AWS Systems Manager
- AWS OpsWorks
- AWS Elastic Beanstalk
Correct answer: AWS CloudFormation
AWS CloudFormation lets you define your entire infrastructure in JSON or YAML templates and provision it consistently and repeatedly.
Question 17: Which AWS service provides a publish-subscribe messaging model to send notifications to multiple subscribers simultaneously?
- Amazon SQS
- Amazon SNS (Correct answer)
- AWS EventBridge
- Amazon Kinesis
Correct answer: Amazon SNS
Amazon SNS (Simple Notification Service) uses a pub-sub model to fan out messages to multiple subscribers including SQS queues, Lambda functions, and email endpoints.
Question 18: Which deployment strategy releases new application versions to a small subset of users before a full rollout?
- Rolling Deployment
- Canary Deployment (Correct answer)
- Immutable Deployment
- Blue/Green Deployment
Correct answer: Canary Deployment
A Canary deployment routes a small percentage of traffic to the new version first, allowing issues to be detected before affecting all users.
Question 19: What is the primary purpose of AWS CloudTrail?
- Scan code for security vulnerabilities
- Record API calls and account activity for auditing (Correct answer)
- Monitor infrastructure performance metrics
- Manage SSL/TLS certificates
Correct answer: Record API calls and account activity for auditing
AWS CloudTrail records API calls made in your AWS account, providing an audit trail of who did what, when, and from where.
Question 20: Which AWS migration strategy is most disruptive but results in the greatest long-term benefits by redesigning an application as cloud-native?
- Refactor/Re-architect (Correct answer)
- Replatform
- Rehost
- Retire
Correct answer: Refactor/Re-architect
Refactoring (re-architecting) involves redesigning an application to fully leverage cloud-native features like microservices and serverless, offering the highest long-term benefits but the most upfront effort.
Question 21: What is the benefit of using multiple AWS Regions for a global application?
- Lower storage costs
- Simplified IAM management
- Automatic Reserved Instance discounts
- Reduced latency for users in different geographic locations and improved disaster recovery (Correct answer)
Correct answer: Reduced latency for users in different geographic locations and improved disaster recovery
Deploying in multiple Regions reduces latency for globally distributed users and provides geographic redundancy for disaster recovery purposes.
Question 22: Which IAM best practice recommends avoiding the use of root account credentials for everyday tasks?
- Identity Federation
- Role-Based Access Control
- Root Account Protection (Correct answer)
- Principle of Least Privilege
Correct answer: Root Account Protection
AWS recommends locking away root account credentials and creating individual IAM users for day-to-day operations to minimize risk.
Question 23: How do Network Access Control Lists (NACLs) differ from Security Groups?
- NACLs apply at the subnet level and are stateless, while Security Groups apply at the instance level and are stateful (Correct answer)
- NACLs only allow traffic rules, while Security Groups can both allow and deny traffic
- NACLs require approval from AWS Support to modify, while Security Groups can be changed freely
- NACLs are only used for IPv6 traffic, while Security Groups handle IPv4 traffic
Correct answer: NACLs apply at the subnet level and are stateless, while Security Groups apply at the instance level and are stateful
NACLs act as a firewall at the subnet level and are stateless (must explicitly allow both inbound and outbound), while Security Groups operate at the instance level and are stateful (return traffic is automatically allowed).
Question 24: Which AWS feature allows you to define fine-grained permissions for AWS users and roles using JSON policy documents?
- AWS Config
- AWS Organizations
- AWS IAM Policies (Correct answer)
- Amazon Cognito
Correct answer: AWS IAM Policies
IAM (Identity and Access Management) policies are JSON documents that define what actions are allowed or denied on which AWS resources.
Question 25: The "Principle of Least Privilege" is best described by what? Out of the following alternatives, select the right response.
- Users should submit all access requests in written form so that there is a paper trail of who needs access to different AWS resources.
- All users should have the same baseline permissions granted to them to use basic AWS services.
- Users should always have a little more permission than they need.
- Users should be granted permission to access only resources they need to do their assigned job. (Correct answer)
Correct answer: Users should be granted permission to access only resources they need to do their assigned job.
According to this rule, a user account should only be granted the rights necessary for it to serve its stated purpose. For instance, it is not necessary to install the program for a user account that is just used to make backups. As a result, it is only permitted to execute backup and backup-related programs.
Question 26: Which AWS service automatically adjusts the number of EC2 instances based on demand?
- Elastic Load Balancing
- AWS Auto Scaling (Correct answer)
- Amazon CloudWatch
- AWS Elastic Beanstalk
Correct answer: AWS Auto Scaling
AWS Auto Scaling monitors your applications and automatically adds or removes EC2 instances to maintain performance and minimize cost.
Question 27: Which AWS Well-Architected pillar focuses on the ability of a system to recover from failures and meet demand?
- Reliability (Correct answer)
- Security
- Sustainability
- Operational Excellence
Correct answer: Reliability
The Reliability pillar addresses designing systems that can recover from infrastructure failures, scale to meet demand, and mitigate disruptions.
Question 28: Which service centralizes security findings from multiple AWS security services into a single dashboard?
- AWS CloudTrail
- AWS Config
- Amazon Detective
- AWS Security Hub (Correct answer)
Correct answer: AWS Security Hub
AWS Security Hub aggregates, organizes, and prioritizes security findings from services like GuardDuty, Inspector, and Macie in one place.
Question 29: Which AWS service provides recommendations to rightsize EC2 instances based on actual utilization data?
- Amazon CloudWatch
- AWS Cost Explorer
- AWS Compute Optimizer (Correct answer)
- AWS Trusted Advisor
Correct answer: AWS Compute Optimizer
AWS Compute Optimizer uses machine learning to analyze CloudWatch metrics and recommend the optimal instance type for your workloads.
Question 30: Which AWS service continuously monitors resource configurations and evaluates them against desired compliance rules?
- AWS Systems Manager
- AWS Config (Correct answer)
- AWS Inspector
- AWS CloudTrail
Correct answer: AWS Config
AWS Config records resource configuration changes over time and evaluates them against rules to identify non-compliant configurations.
Question 31: Which design principle recommends replacing failed components automatically rather than fixing them in place?
- Principle of Least Privilege
- Defense in Depth
- Treat servers as cattle, not pets (Correct answer)
- Infrastructure as Code
Correct answer: Treat servers as cattle, not pets
The 'cattle not pets' principle means servers are disposable and interchangeable — when one fails, it's replaced automatically rather than manually nursed back to health.
Question 32: What does 'high availability' mean in AWS architecture?
- Designing systems to remain operational despite component failures by eliminating single points of failure (Correct answer)
- Guaranteed zero downtime
- Using only the latest EC2 instance families
- Running instances with premium hardware
Correct answer: Designing systems to remain operational despite component failures by eliminating single points of failure
High availability means designing architectures with redundancy and automatic failover so systems remain accessible even when individual components fail.
Question 33: Which continuing component of operations will be scaled back if Sun Solar moves its servers to the AWS cloud?
- Software Licenses
- Software Patching
- Redundant Servers
- Idle Capacity (Correct answer)
Correct answer: Idle Capacity
Moving services to the AWS cloud is probably the best way to decrease idle capacity. Resources are provisioned in conventional data centers based on a demand model. The need for extra resources can be met by purchasing them. The likelihood of these resources being utilized to their full potential is low. Reduce the amount of idle resource capacity by using AWS services like Auto Scaling.
Question 34: Without allowing the traffic to pass across the open internet, Auto Car must deploy AWS resources on-premises. What should they configure to do this?
- NAT Gateway
- AWS Direct Connect (Correct answer)
- AWS Site-to-Site Virtual Private Network
- Virtual Private Cloud
Correct answer: AWS Direct Connect
Organizations should utilize Direct Connect to connect to the AWS cloud directly, avoiding the usage of the open internet. A connection to an AWS Direct Connect site must be purchased or rented by the organization in order to use this.
Question 35: Which AWS service is used to manage and automate the deployment of infrastructure using code templates?
- AWS CodeDeploy
- AWS Systems Manager
- AWS Config
- AWS CloudFormation (Correct answer)
Correct answer: AWS CloudFormation
AWS CloudFormation is the Infrastructure as Code (IaC) service that provisions and manages AWS resources using JSON or YAML templates.
Question 36: What is Amazon Route 53?
- A VPN gateway service
- A scalable Domain Name System (DNS) web service (Correct answer)
- A content delivery network
- A load balancing service
Correct answer: A scalable Domain Name System (DNS) web service
Amazon Route 53 is a highly available and scalable DNS web service that routes end users to applications running in AWS or anywhere on the internet.
Question 37: Which principle states that users should only be granted the permissions they need to perform their job?
- Zero trust
- Defense in depth
- Separation of duties
- Least privilege (Correct answer)
Correct answer: Least privilege
The principle of least privilege means granting only the minimum permissions required to perform a task, reducing the attack surface.
Question 38: What is the difference between Amazon SQS and Amazon SNS?
- They are identical services with different names
- SQS is for emails, SNS is for SMS only
- SQS is for storage, SNS is for networking
- SQS is a pull-based message queue for decoupling services; SNS is a push-based pub/sub notification service (Correct answer)
Correct answer: SQS is a pull-based message queue for decoupling services; SNS is a push-based pub/sub notification service
SQS is a message queue where consumers poll for messages (decoupling producers and consumers), while SNS pushes messages to multiple subscribers simultaneously.
Question 39: What is an IAM role used for in AWS?
- Granting temporary permissions to entities that need access to AWS resources (Correct answer)
- Defining password policies for AWS accounts
- Storing long-term access credentials for a user
- Creating groups of users with shared permissions
Correct answer: Granting temporary permissions to entities that need access to AWS resources
IAM roles are used to delegate access to AWS resources with temporary security credentials, without sharing long-term keys.
Question 40: What does 'designing for failure' mean in AWS cloud architecture?
- Reducing feature scope to avoid bugs
- Expecting systems to always fail
- Running systems in degraded mode permanently
- Building systems that assume component failures will happen and remain operational anyway (Correct answer)
Correct answer: Building systems that assume component failures will happen and remain operational anyway
Designing for failure means architecting systems with redundancy and auto-recovery so they remain available even when individual components fail.
Question 41: Which AWS service functions as a highly available and scalable Domain Name System (DNS) web service?
- AWS Global Accelerator
- Amazon CloudFront
- Amazon Route 53 (Correct answer)
- AWS Direct Connect
Correct answer: Amazon Route 53
Amazon Route 53 is a scalable and highly available DNS web service that routes end users to internet applications and also supports domain registration.
Question 42: What is the AWS service that enables you to manage encryption keys for your data?
- AWS CloudHSM
- AWS Secrets Manager
- AWS Key Management Service (KMS) (Correct answer)
- AWS Certificate Manager
Correct answer: AWS Key Management Service (KMS)
AWS Key Management Service (KMS) is a managed service that makes it easy to create and control encryption keys used to encrypt your data.
Question 43: Which AWS service distributes incoming application traffic across multiple EC2 instances, containers, or IP addresses?
- AWS Global Accelerator
- Amazon Route 53
- Elastic Load Balancing (Correct answer)
- AWS Auto Scaling
Correct answer: Elastic Load Balancing
Elastic Load Balancing automatically distributes incoming traffic across healthy targets in one or more Availability Zones to improve availability.
Question 44: Which AWS networking feature allows you to capture and inspect network traffic flowing to and from network interfaces in your VPC?
- AWS Config
- VPC Flow Logs (Correct answer)
- AWS CloudTrail
- Amazon GuardDuty
Correct answer: VPC Flow Logs
VPC Flow Logs capture information about IP traffic going to and from network interfaces in your VPC, enabling network monitoring, troubleshooting, and security analysis.
Question 45: Which AWS service helps you orchestrate multi-step workflows and coordinate distributed application components?
- AWS Step Functions (Correct answer)
- Amazon SNS
- Amazon SQS
- Amazon EventBridge
Correct answer: AWS Step Functions
AWS Step Functions is a serverless workflow orchestration service that coordinates multiple AWS services into visual, automated workflows using state machines.
Question 46: Which EC2 pricing option offers the largest discount (up to 90%) but can be interrupted by AWS when capacity is needed?
- Savings Plans
- Dedicated Hosts
- Reserved Instances
- Spot Instances (Correct answer)
Correct answer: Spot Instances
Spot Instances offer steep discounts because they use spare EC2 capacity, but AWS can reclaim them with a 2-minute warning.
Question 47: Which of the following, according to the AWS shared responsibility model, is an AWS responsibility?
- Securing application access and data
- Configuring third-party applications
- Maintaining physical hardware (Correct answer)
- Managing guest operating systems
Correct answer: Maintaining physical hardware
According to the AWS shared responsibility model, AWS is accountable for maintaining physical hardware.
Question 48: Which AWS pricing benefit consolidates billing for multiple accounts and applies volume discounts across the entire organization?
- Enterprise Discount Program
- Savings Plans
- Reserved Instance Sharing
- Consolidated Billing (Correct answer)
Correct answer: Consolidated Billing
Consolidated Billing through AWS Organizations combines usage across all member accounts, enabling volume pricing tiers and a single invoice.
Question 49: What is the primary function of AWS CloudTrail?
- Automate infrastructure provisioning
- Record API calls and account activity for auditing (Correct answer)
- Monitor application performance metrics
- Distribute traffic across multiple servers
Correct answer: Record API calls and account activity for auditing
AWS CloudTrail records API calls made in your AWS account, providing an audit trail of account activity for compliance and governance.
Question 50: Which AWS service enables multi-factor authentication (MFA) enforcement for IAM users?
- AWS Directory Service
- AWS SSO
- AWS IAM (Correct answer)
- Amazon Cognito
Correct answer: AWS IAM
AWS IAM allows administrators to require MFA for individual users or enforce it via IAM policies across the account.
Question 51: Which AWS service provides a managed relational database with automated backups, patching, and failover?
- Amazon Redshift
- Amazon RDS (Correct answer)
- Amazon ElastiCache
- Amazon DynamoDB
Correct answer: Amazon RDS
Amazon RDS (Relational Database Service) manages relational databases like MySQL, PostgreSQL, and Oracle, handling backups, patches, and Multi-AZ failover automatically.
Question 52: Which service continuously monitors AWS accounts and workloads for malicious activity using machine learning and threat intelligence?
- Amazon GuardDuty (Correct answer)
- Amazon Macie
- Amazon Inspector
- AWS Security Hub
Correct answer: Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously analyzes CloudTrail logs, VPC Flow Logs, and DNS logs to identify suspicious activity.
Question 53: Which AWS Savings Plan type offers the most flexibility by applying discounts across any EC2 instance family, region, OS, and tenancy?
- SageMaker Savings Plans
- Compute Savings Plans (Correct answer)
- Reserved Instance Plans
- EC2 Instance Savings Plans
Correct answer: Compute Savings Plans
Compute Savings Plans offer up to 66% savings and apply automatically to any EC2, Fargate, or Lambda usage regardless of instance type or region.
Question 54: Which AWS service would make the transfer of a database to AWS the easiest?
- AWS Storage Gateway
- Amazon AppStream 2.0
- AWS Database Migration Service (AWS DMS) (Correct answer)
- Amazon EC2
Correct answer: AWS Database Migration Service (AWS DMS)
Users may rapidly and securely move their databases to AWS using AWS DMS. Application downtime that depends on the source database is minimized since it stays fully functional throughout the migration. Data may be moved to and from the majority of popular commercial and open-source databases using AWS DMS.
Question 55: Which AWS service provides a managed firewall to filter malicious web traffic before it reaches your application?
- Amazon GuardDuty
- AWS WAF (Correct answer)
- AWS Shield
- AWS Firewall Manager
Correct answer: AWS WAF
AWS WAF (Web Application Firewall) filters HTTP/HTTPS traffic based on rules you define to block common exploits like SQL injection and XSS.
Question 56: A Cosmo Property AWS solution architect is outlining the advantages of transferring a data center to the cloud. What is the main advantage of this?
- Avoiding patch management and its associated costs
- Secured storage, retrieval and transmission of data
- Cost savings due to provisioning and decommissioning of resources based on varying traffic and workloads (Correct answer)
- Eliminating dependence on internet connections
Correct answer: Cost savings due to provisioning and decommissioning of resources based on varying traffic and workloads
A data center's ability to adapt to seasonal workload will enhance after moving to the AWS cloud. Since it has to do with IT infrastructure resources, elasticity can increase or decrease allotted resources in accordance with compute and storage needs. An e-commerce site could scale back its web server during peak buying seasons or hours.
Question 57: What is Amazon CloudFront's origin in the context of content delivery?
- The source server or S3 bucket from which CloudFront retrieves content to cache (Correct answer)
- The nearest edge location to the user
- The AWS Region where CloudFront is configured
- The DNS server that resolves domain names
Correct answer: The source server or S3 bucket from which CloudFront retrieves content to cache
The origin is the authoritative source of content (an S3 bucket, EC2 instance, or custom HTTP server) that CloudFront fetches from to populate its cache.
Question 58: Which pricing model is best for a predictable, steady-state workload running 24/7 all year?
- Reserved Instances (Correct answer)
- Spot Instances
- Savings Plans with no commitment
- On-Demand Instances
Correct answer: Reserved Instances
Reserved Instances offer the best pricing for workloads with predictable, continuous usage since you commit to a 1- or 3-year term.
Question 59: What AWS tool helps you identify S3 buckets that contain sensitive data such as PII?
- AWS Trusted Advisor
- Amazon GuardDuty
- Amazon Macie (Correct answer)
- AWS Inspector
Correct answer: Amazon Macie
Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data in Amazon S3.
Question 60: Which Well-Architected Framework pillar addresses reducing the environmental impact of your cloud workloads?
- Operational Excellence
- Sustainability (Correct answer)
- Cost Optimization
- Performance Efficiency
Correct answer: Sustainability
The Sustainability pillar, added in 2021, focuses on minimizing the environmental impact of running cloud workloads through efficient resource utilization.
Question 61: What is the key difference between a Security Group and a Network ACL in AWS?
- Both are stateless
- Both are stateful
- Security Groups are stateful; NACLs are stateless (Correct answer)
- Security Groups are stateless; NACLs are stateful
Correct answer: Security Groups are stateful; NACLs are stateless
Security Groups are stateful (return traffic is automatically allowed), while Network ACLs are stateless (you must explicitly allow both inbound and outbound traffic).
Question 62: What does AWS Config do?
- It monitors application performance metrics
- It manages EC2 instance fleets
- It provides centralized logging for applications
- It tracks and records configuration changes to AWS resources and evaluates compliance against desired configurations (Correct answer)
Correct answer: It tracks and records configuration changes to AWS resources and evaluates compliance against desired configurations
AWS Config continuously records AWS resource configurations and changes, enabling you to audit compliance, analyze changes, and troubleshoot issues.
Question 63: A company wants to run workloads without managing servers. Which AWS service is the best fit?
- Amazon ECS on EC2
- Amazon EC2
- AWS Lambda (Correct answer)
- AWS Elastic Beanstalk
Correct answer: AWS Lambda
AWS Lambda is a serverless compute service that runs code without provisioning or managing servers.
Question 64: Which AWS Well-Architected Framework pillar focuses on protecting data, systems, and assets through risk assessments and mitigation?
- Cost Optimization
- Security (Correct answer)
- Reliability
- Performance Efficiency
Correct answer: Security
The Security pillar of the Well-Architected Framework covers identity management, detecting incidents, protecting data, and automating security best practices.
Question 65: Which AWS service provides a managed NoSQL database that delivers single-digit millisecond performance?
- Amazon RDS
- Amazon Redshift
- Amazon DynamoDB (Correct answer)
- Amazon ElastiCache
Correct answer: Amazon DynamoDB
Amazon DynamoDB is a fully managed NoSQL database service that provides fast and predictable performance with seamless scalability.
AWS Certified Cloud Practitioner (CLF-C02)
The AWS Certified Cloud Practitioner validates foundational, high-level understanding of AWS Cloud concepts, services, security, and economics. It is intended for individuals seeking to demonstrate overall AWS knowledge independent of a specific job role.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds