91-120 Flashcards
QUESTION 91
A user has created a blank EBS volume in the US-East-1 region. The user is unable to attach the volume to a running instance in the same region. What could be the possible reason for this?
A. The instance must be in a running state. It is required to stop the instance to attach volume
B. The AZ for the instance and volume are different
C. The instance is from an instance store backed AMI
D. The instance has enabled the volume attach protection
B. The AZ for the instance and volume are different
QUESTION 92
In DynamoDB, could you use 1AM to grant access to Amazon DynamoDB resources and API actions?
A. Yes
B. Depended to the type of access
C. In DynamoDB there is no need to grant access
D. No
A. Yes
QUESTION 93 A user is planning to host a mobile game on EC2 which sends notifications to active users on either high score or the addition of new features. The user should get this notification when he is online on his mobile device. Which of the below mentioned AWS services can help achieve this functionality? A. AWS Simple Notification Service. B. AWS Simple Queue Service. C. AWS Mobile Communication Service. D. AWS Simple Email Service.
A. AWS Simple Notification Service.
QUESTION 94
An orgAMzation is setting up their website on AWS. The orgAMzation is working on various security measures to be performed on the AWS EC2 instances. Which of the below mentioned security mechAMsms will not help the orgAMzation to avoid future data leaks and identify security weaknesses?
A. Perform SQL injection for application testing.
B. Run penetration testing on AWS with prior approval from Amazon.
C. Perform a hardening test on the AWS instance.
D. Perform a Code Check for any memory leaks.
D. Perform a Code Check for any memory leaks.
QUESTION 95
A root account owner is trying to setup an additional level of security for all his 1AM users. Which of the below mentioned options is a recommended solution for the account owner?
A. Enable access key and secret access key for all the 1AM users
B. Enable MFA for all 1AM users
C. Enable the password for all the 1AM users
D. Enable MFA for the root account
B. Enable MFA for all 1AM users
QUESTION 96 Regarding Amazon SQS, what happens if there is no activity against a queue for more than 30 consecutive days? A. Your account will be suspended B. The queue may be deleted C. Nothing D. The queue will be deleted
B. The queue may be deleted
QUESTION 97 Which of the below mentioned options is a must to have an element as a part of the 1AM policy? A. Condition B. ID C. Statement D. Version
C. Statement
QUESTION 98 Which of the below mentioned commands allows the user to share the AMI with his peers using the AWS EC2 CLI? A. ec2-share-image-public B. ec2-share-image-account C. ec2-share-image D. ec2-modify-image-attribute
D. ec2-modify-image-attribute
QUESTION 99
ExamKiller (with AWS account ID H1122223333) has created 50 1AM users for its orgAMzation’s employees. ExamKil|er wants to make the AWS console login URL for all 1AM users like: https://examkiHer.signin.aws.amazon.com/console/. How can this be configured?
A. The user needs to use Route 53 to map the examkiller domain and 1AM URL
B. Create an 1AM AWS account alias with the name examkiller
C. It is not possible to have a personalized 1AM login URL
D. Create an 1AM hosted zone Identity for the domain examkiller
B. Create an 1AM AWS account alias with the name examkiller
QUESTION 100
A user has created a new EBS volume from an existing snapshot. The user mounts the volume on the instance to which it is attached. Which of the below mentioned options is a required step before the user can mount the volume?
A. Run a cyclic check on the device for data consistency
B. Create the file system of the volume
C. Resize the volume as per the original snapshot size
D. No step is required. The user can directly mount the device
D. No step is required. The user can directly mount the device
QUESTION 101
A user is creating multiple 1AM users. What advice should be given to him to enhance the security?
A. Grant least prMleges to the indMdual user
B. Grant all higher prMleges to the group
C. Grant less prMleges for user, but higher prMleges for the group
D. Grant more prMleges to the user, but least prMleges to the group
A. Grant least prMleges to the indMdual user
QUESTION 102 In regards to Amazon SQS how many times will you receive each message? A. At least twice B. Exactly once C. As many times as you want D. At least once
D. At least once
QUESTION 103
A user has set an 1AM policy where it allows all requests if a request from IP 10.10.10.1/32. Another policy allows all the requests between 5 PM to 7 PM. What will happen when a user is requesting access from IP 10.10.10.1/32 at 6 PM?
A. 1AM will throw an error for policy conflict
B. It is not possible to set a policy based on the time or IP
C. It will deny access
D. It will allow access
D. It will allow access
QUESTION 104
A user is enabling logging on a particular bucket. Which of the below mentioned options may be best suitable to allow access to the log bucket?
A. Create an 1AM policy and allow log access
B. It is not possible to enable logging on the S3 bucket
C. Create an 1AM Role which has access to the log bucket
D. Provide ACL for the logging group
D. Provide ACL for the logging group
QUESTION 105 A user is running a Webserver on EC2. The user wants to receive the SMS when the EC2 instance utilization is above the threshold limit. Which AWS services should the user configure in this case? A. AWS CloudWatch + AWS SES. B. AWS CloudWatch + AWS SNS. C. AWS CloudWatch + AWS SQS. D. AWS EC2 + AWS Cloudwatch.
B. AWS CloudWatch + AWS SNS.