Skip to content
BytePatterns

CLF-C02 · Domain 3: Cloud Technology and Services · 34% of the exam

Task 3.1: Define methods of deploying and operating in the AWS Cloud.

Console, CLI, SDKs and infrastructure as code, when a one-off action is fine and when it should be a repeatable process, and the cloud, hybrid and on-premises deployment models.

Study it

  • Console, CLI, SDKs and infrastructure as code; deployment models

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

For every new customer, a team creates the same set of resources: a load balancer, an Auto Scaling group and a database. It wants every copy to be identical and the process to be repeatable. Which approach fits best?

  1. ACreate one stack per customer from an AWS CloudFormation template
  2. BCreate each copy by hand in the AWS Management Console, following a checklist
  3. CUse AWS Config to copy the first customer's resources
  4. DUse AWS CloudTrail to replay the API calls from the first customer's setup
Show the answer and why
  • ACreate one stack per customer from an AWS CloudFormation template

    Correct

    A CloudFormation template describes the resources once, and each stack created from it provisions them in a consistent, repeatable way.

  • BCreate each copy by hand in the AWS Management Console, following a checklist

    Incorrect

    Creating and configuring every resource individually is the manual work infrastructure as code removes, and a checklist cannot guarantee identical copies.

  • CUse AWS Config to copy the first customer's resources

    Incorrect

    AWS Config records and evaluates how resources are configured. It does not create resources.

  • DUse AWS CloudTrail to replay the API calls from the first customer's setup

    Incorrect

    CloudTrail records account activity as events for auditing and governance. It does not provision anything.

A repeatable process is code, not a checklist. Infrastructure as code turns "the same resources every time" into one template used many times.

Question 2 · choose 1

A developer is writing a Python application that must upload each new invoice to Amazon S3 from inside its own code, as part of its normal work. Which way of accessing AWS fits this best?

  1. AThe AWS Management Console
  2. BAn AWS SDK
  3. CAWS CloudFormation
  4. DAWS CloudShell
Show the answer and why
  • AThe AWS Management Console

    Incorrect

    The console is a web interface for people. An application cannot click through it as part of its own logic.

  • BAn AWS SDK

    Correct

    The AWS SDKs give programming languages such as Python an API for AWS services, and handle details such as signing requests and retries, so the application can call S3 directly from its code.

  • CAWS CloudFormation

    Incorrect

    CloudFormation provisions and configures resources from a template. It creates the bucket, not the uploads an application makes every day.

  • DAWS CloudShell

    Incorrect

    CloudShell is a browser-based shell for running commands by hand. It is not where an application's own code runs.

People use the console, scripts use the CLI, infrastructure is described in templates, and applications call AWS through an SDK.

Question 3 · choose 1

A bank keeps its core transaction system in its own data center but runs the backend of its new mobile app on AWS. The two are connected so the app can read account data from the core system. Which deployment model is the bank using?

  1. ACloud
  2. BOn-premises (private cloud)
  3. CHybrid
  4. DServerless
Show the answer and why
  • ACloud

    Incorrect

    In a cloud deployment, all parts of the application run in the cloud. Here the core system stays in the bank's data center.

  • BOn-premises (private cloud)

    Incorrect

    An on-premises deployment keeps resources in the company's own data center. The mobile backend runs on AWS.

  • CHybrid

    Correct

    A hybrid deployment connects infrastructure and applications in the cloud with existing resources that are not in the cloud, most commonly on-premises infrastructure.

  • DServerless

    Incorrect

    Serverless is a way to run code without managing servers, such as AWS Lambda. It is not one of the deployment models.

Part in the cloud, part on premises, connected: hybrid. It is the common shape of a migration that happens one system at a time.

Question 4 · choose 1

A manager asks an administrator a one-off question: is versioning turned on for one particular Amazon S3 bucket? The administrator will not need to repeat the check. Which way of working with AWS is the most sensible here?

  1. AWrite an AWS CloudFormation template
  2. BWrite an application with an AWS SDK
  3. CCheck the AWS Management Console
  4. DBuild a pipeline in AWS CodePipeline
Show the answer and why
  • AWrite an AWS CloudFormation template

    Incorrect

    Templates are for provisioning and configuring resources in a repeatable way. A single look at one setting does not need one.

  • BWrite an application with an AWS SDK

    Incorrect

    SDKs are for calling AWS from application code. Writing a program for a single question is more work than it saves.

  • CCheck the AWS Management Console

    Correct

    The console is a web interface for viewing and managing resources by hand — the natural fit for a one-time check.

  • DBuild a pipeline in AWS CodePipeline

    Incorrect

    CodePipeline automates the steps to release software. It is for repeated release processes, not a single look-up.

Match the tool to the frequency: one-time actions suit the console; anything you will repeat belongs in code, a script or a template.

Question 5 · choose 2

A team starts describing its infrastructure in AWS CloudFormation templates instead of creating resources by hand. Which benefits does this give the team? (Choose TWO.)

  1. AEvery API call in the account is recorded for auditing
  2. BTemplates are text files that can be kept in version control to track changes
  3. CInstances are scanned for software vulnerabilities
  4. DThe same template can create identical resources again, for example in another Region
  5. EAWS takes over patching the operating systems of the instances it creates
Show the answer and why
  • AEvery API call in the account is recorded for auditing

    Incorrect

    Recording API activity is what AWS CloudTrail does, whether resources come from a template or not.

  • BTemplates are text files that can be kept in version control to track changes

    Correct

    Because a template describes exactly what is provisioned, you can track differences between versions of it, like source code, and roll back to an earlier one.

  • CInstances are scanned for software vulnerabilities

    Incorrect

    Vulnerability scanning is Amazon Inspector's job.

  • DThe same template can create identical resources again, for example in another Region

    Correct

    You describe the resources once and can provision the same resources over and over, in a consistent and repeatable way.

  • EAWS takes over patching the operating systems of the instances it creates

    Incorrect

    How a resource is created does not change the shared responsibility model: the customer still patches the guest operating system on EC2.

Infrastructure as code makes environments repeatable and reviewable. It does not replace auditing, scanning or patching.

Practise domain 3 →Practise all domains →