Q231. A company runs many Amazon EC2 instances in its VPC. The company wants to use a native AWS security resource to control network traffic between certain EC2 instances. Which AWS service or feature will meet this requirement?
A. Network ACLs
B. AWS WAF
C. Amazon GuardDuty
D. Security groups
Answer
D
Q232. Which of the following can be components of a VPC in the AWS Cloud? (Choose two.)
A. Amazon API Gateway
B. Amazon S3 buckets and objects
C. AWS Storage Gateway
D. Internet gateway
E. Subnet
Answer
D, E
Q233. A company is building a new application on AWS. The company needs the application to remain available if an individual application component fails. Which design principle should the company use to meet this requirement?
A. Disposable resources
B. Automation
C. Rightsizing
D. Loose coupling
Answer
D
Q234. A company wants to use a managed service to identify and protect sensitive data that is stored in Amazon S3. Which AWS service will meet these requirements?
A. AWS IAM Access Analyzer
B. Amazon GuardDuty
C. Amazon Inspector
D. Amazon Macie
Answer
D
Q235. Which AWS service or feature can a user configure to limit network access at the subnet level?
A. AWS Shield
B. AWS WAF
C. Network ACL
D. Security group
Answer
C
Q236. A company wants to enhance security by launching a third-party ISP intrusion detection system from its AWS account. Which AWS service or resource should the company use to meet this requirement?
A. AWS Security Hub
B. AWS Marketplace
C. AWS Quick Starts
D. AWS Security Center
Answer
B
Q237. How does the AWS Cloud help companies build agility into their processes and cloud infrastructure?
A. Companies can avoid provisioning too much capacity when they do not know how much capacity is required.
B. Companies can expand into new geographic regions.
C. Companies can access a range of technologies to experiment and innovate quickly.
D. Companies can pay for IT resources only when they use the resources.
Answer
C
Q238. Which AWS service or tool gives a company the ability to release application changes in an automated way?
A. Amazon AppFlow
B. AWS CodeDeploy
C. AWS PrivateLink
D. Amazon EKS Distro
Answer
B
Q239. Which AWS service or feature allows users to securely store encrypted credentials and retrieve these credentials when required?
A. AWS Encryption SDK
B. AWS Security Hub
C. AWS Secrets Manager
D. AWS Artifact
Answer
C
Q240. Which AWS service or resource can a company use to deploy AWS WAF rules?
A. Amazon EC2
B. Application Load Balancer
C. AWS Trusted Advisor
D. Network Load Balancer
Answer
B