Questions and Answers; certified for accuracy 2025/2026
Which type of volume should be used for an EC2 root with minimum latency correct
answer
Instance store
Which solution should be used to store application content that is accessed concurrently
by a fleet of Amazon EC2-based Linux hosts correct answer
Amazon EFS
A company is planning to move its on-premises Windows domain servers to the cloud.
As part of this move, the company needs a storage solution that can host shared file
systems for its Windows hosts. The file sharing will be done using Server Message
Block (SMB) and needs to support file system access control lists (ACLs), shadow
copies, and user quotas.
Which storage solution supports these requirements correct answer
Amazon FSx
A client has an on-premises data center and wants to establish a network link to an
Amazon Virtual Private Cloud (VPC). The solution must ensure the maximum
throughput and minimum latency. Which service provides these capabilities correct
answer
AWS Direct Connect
A client has an on-premises data center and needs to transfer large data sets to AWS
over the network without affecting the internet bandwidth available for its on-premises
workloads. Which service provides these capabilities correct answer
AWS Direct Connect
A company needs to connect its VPC to the EC2 API. Which solution meets this
requirement at the lowest cost and with the least configuration correct answer
Interface endpoint
,Data for an application is served from a single Amazon S3 bucket. Customers around
the world upload data to the bucket. Which Amazon S3 feature will reduce latency
correct answer
Transfer Acceleration
Which database solution allows the failover priority of each read replica to be configured
correct answer
Amazon Aurora
Which database scaling solution supports high-availability replication correct answer
Amazon ElastiCache for Redis
A company has a multi-tier application that is very read intensive at the database layer.
The company is looking to implement a caching strategy for the data, and its security
department requires it to be encrypted. Which solution fits this requirement correct
answer
Amazon ElastiCache for Redis
An administrator needs a relational database that can support online analytical
processing (OLAP) and provide fast performance despite many concurrent queries.
Which solution should this administrator choose correct answer
Amazon Redshift
An organization has signed up for an AWS account.
Which action should be performed to ensure the account is secured and used according
to the principle of least privilege correct answer
Delete the root access keys and secret
A company needs to configure an EC2 instance for delegate access to a DynamoDB
table.
, Which policy should this company use correct answer
Permissions
An application running in an EC2 instance needs to access an Amazon S3 bucket with
temporary credentials generated by AWS Security Token Service (AWS STS).
Credentials cannot be stored in the EC2 instance.
Which principal type should the client use to configure the application access to the
Amazon S3 bucket correct answer
IAM role
What is used in the IAM policy evaluation logic correct answer
An explicit allow in a resource-based policy overrides an implicit deny.
A client has an Amazon Virtual Private Cloud (VPC) containing 10 Amazon EC2
instances. The client plans to develop an application that will call Amazon EC2 API from
the EC2 instances. Which service should this client use to implement a private
connectivity for the Amazon EC2 API calls from the VPC correct answer
Interface endpoint
A company is building a new application, and as part of this new application, the
company will provision a multi-tiered EC2 infrastructure across multiple Availability
Zones and subnets. They will have an application server tier, a web server tier, and a
database tier. For their network security, the company is looking for a solution that will
enable them to create the rules once per tier type and apply the rules to all created
instances. They also want the solution to filter traffic between the instances in the same
tier. Which solution fits these requirements correct answer
Security group
An engineer designs a network that must have 512 IP addresses available for use by
the client.