All Flashcards

1
Q

KMS multi region keys what limits on them?

A

Keys are not global related, not cloned but replicated
Cannot be converted from single region key.
make management of keys more complex

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does kinesis data streams offer for security features?

A

Control access via IAM.
Encryption in flight.
Encryption at rest with KMS.
VPC endpoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What two services support VPC Gateway Endpoints

A

S3.
Dynamo DB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define AWS firewall manager

A

Security management service to centrally, configure firewall rules across organizations includes

WAF rules.
Security groups.
Network firewall rules
R 53 resolver

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Define IAM ID Center

A

Allows for sign in for all accounts business cloud apps, like salesforce
Third-party app supporting SAML 2.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Aurora supports these databases

A

MYSQL
POSTGRES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many replicas in aurora cluster max?

A

15

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

RDS technology, which does not support IAM

A

Oracle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define cloud watch metric stream

A

Send cloud watch metrics in near real time to S3 via kinesis firehose or third-party destinations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Five tenants of AWS well architected application

A

Cost
Performance
Reliability
Security.
Operational excellence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

aws: principal org ID

A

For any resource policy to restrict to accounts that are member of an AWS Org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define comprehend medical is it HIPPA compliant

A

Detect extract analyze info from unstructured sources, such as doctors notes, radiology reports
Supports HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define Kendra

A

Document search service using machine learning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define Sagemaker

A

Fully manage service for deploying machine learning models quickly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Define AWS Polly

A

Text to speech service.
Uses lexicons for pronunciations.
Uses SSML = speech synthesis markup language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Define Transcribe

A

Auto convert speech to text
Auto remove PII.
Auto language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Define VPC sharing versus VPC peering

A

Sharing is for sharing subnets with other AWS accounts or to centrally manage VPCs for multiple accounts.

Peering is a peering connection between two VPCs in same or multiple accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are SCP’s?

A

Service control policies.
IAM policies applied to OU or accounts to restrict access.

Does not apply to management account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is S3 max object size

A

Five TB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is lambda max execution time?

A

15 minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What are RCU and WCU in Dynamo DB

A

Read capacity units and write capacity units.
Can be scaled independently

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is the purpose of increasing visibility timeout in SQS?

A

Gives consumers more time to process messages, resulting in less duplicates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Define SQS visibility timeout

A

Period of time where SQS prevents other consumers from receiving and processing messages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is a glacier vault lock?

A

Uses WORM.
Right once read many
Locks added for never delete

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What is S3 durability and availability?

A

99.99 or 53 minutes in one year

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What are the features of the application migration service or MGN?

A

Converts source servers to run an AWS physical VM or cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Key futures of Aurora global DB.
How many secondary regions?

How many read replicas

A

Replicas in other regions
Up to five secondary regions.
15 read replicas max per region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

kinesis data shard -
What are the max throughput?
Incoming and outgoing.

A

provisioned mode:
each shard = 1MB per second incoming
2 MB per second outgoing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Define kinesis partition key function

A

Used to order data in shards
truck one goes to shard one

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Can kinesis fire hose transform data

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

To create aurora read replica auto scaling do what

A

Create policy under actions
Can create auto scaling policy
Decide on target either by request or CPU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

EKS node types

A

manage node. AWS manage the node for you.

self manage node

Fargate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Describe Aurora global database with regard to regions

A

One primary region.
Up to five secondary regions.
With up to 16 read replicas per region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

What is the used case for Aurora serverless

A

In frequent intermittent or unpredictable workloads no capacity plan needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Why use EFS over EBS?

A

EFS is a shared file storage service offering high performance and can be connected to from many EC two instances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Define aurora reader endpoint

A

A reader endpoint connects to all replicas therefore application only needs to connect to reader endpoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Five things about Aurora high availability and read scaling

A

Storage replicated with Six copies of data
Instant takes rights the master
Auto fail over less than 30 seconds.
Master +15 read replicas.
Supports cross region replication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Why use Aurora global database feature?

A

Global means available in multiple regions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

What machine learning integrations does Aurora have?

A

Sage maker
Comprehend

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Aurora - list 6 features

A

Backup and recovery
Isolation and security.
Industry compliance.
Automated patching.
Advanced monitoring.
Backtrack is a way, restoring the database to appoint in time recovery must be enabled by database creation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

List features of Aurora
What databases does it support?
What is the performance increase?
What is the auto scale storage max?
How many replicas support?
What failover capabilities does it support?
What is the cost versus RDS?

A

Supports postgres and MYSQL.
Cloud optimize for 5X performance.
Auto scale storage to 128 TB.
Up to 15 read replicas
Failover instantaneous.
Cost is more than RDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What is an EC2 instance store what benefits and what drawbacks

A

Benefits.
Higher disk I/O as VM‘s have direct access to discs on server hardware

Instance store is an ephemeral volume. It does not persist across stop/start.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

List the EBS volume types

A

GP2
GP3
Io1/Io2
ST1
SC1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

What is the used case for EBS volume GP2 or GP3

A

General purpose, SSD, volume balances, price, and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

What is use case for EBS volume type
Io1/Io2?

A

Highest performance, SSD low latency high throughput

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

What is the used case for EBS volume type sT1

A

Lowest cost HDD volume design for frequently access throughput intensive workloads

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

What is the use case for EBS volume type SC1?

A

Lowest cost HDD volume design for less frequently accessed workloads

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What is the max CIDR size in AWS?

A

/16

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

API Gateway create what types of API

A

Restful APIs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

EFS backups are they enabled by default?

A

Yes, enabled by default for one zone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

API gateway websocket API -
state full or state less

A

Stateful – full duplex

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

What is the RDS feature which does not require connection string

A

Multi-AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

Define a stateless application

A

The application does not save session data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

Define a stateful application

A

Save session data user retain session data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

What can you say about SCP’s hierarchy?

A

SCPs are applied at OU level account example : cannot access lambda because SCP denies at OU level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

Define Neptune

A

Graphing Database
use case:
number of likes from one post from one user
Think social networking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

What kind of DB is dynamo DB

A

Key pair value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

What is SAML?

A

Security assertion, markup language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

What is the max size of dynamo DB table?

A

400 KB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

Define lambda at edge

A

Feature of cloud front which enables code to run near users which improves performance and latency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

Why use a volume gateway?

A

Provides block storage with ISCSI -
backed on S3 backed by EBS snapshots, which help restore on premises volumes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

What is the main reason to use FSX file gateway for window server

A

Creates a local cash for frequently access files. Can use SMB, NTFS, AD.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

With S3 file gateway, what protocol to use if you want to integrate with AD

A

SMB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

How is data and S3 file gateway handled?

A

Most recently used data is cashed in the gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

S3 file gateway, what protocols?

A

NTFS or SMB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

What is SNS message filtering

A

Jason policy to filter messages before they are sent to subscribers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

Define SNS to S3 through kinesis data fire hose.
What does this help you with?

A

This can allow you to persist your messages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

What are the four types of storage gateways?

A

S3 file
FSX file
Volume
Tape

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

What are the 4 use cases for storage gateway?

A

DR.
Back up and restore.
Tiered storage.
On premises, cashing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
70
Q

What function does storage gateway perform?

A

Expose S3 data to on premises

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
71
Q

What features does FSX NET ONTAP have with regard to cloning and storage?

A

Instant cloning of point in time.
Storage auto shrinks and grows

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
72
Q

What is SNS and SQS fan out

A

One SNS topic pushes to multiple SQS cues so each service can read from their own SQSQ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
73
Q

What security features for SNS

A

Encryption in flight.
Encryption at rest.
Client Certs if desired

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
74
Q

What is AWS global accelerator main benefits?

A

Provides regional failover
High availability
Static IPs
Improve performance via edge locations.
Find green control of regional deployments client affinity think blue Green deployments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
75
Q

What are two types of volume gateways that you can create?

A

Cashed: low latency access
Stored: entire data set on premises

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
76
Q

data sync - what aws services can it sync to?
Does it preserve file permissions?

A

S3
EFS
FSx
Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
77
Q

What does AWS data sync do which is important when sync between AWS storage services?

A

Preserves metadata, including file permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
78
Q

What is the main goal of a volume gateway?

A

Back up volumes from on premises servers to S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
79
Q

RDS database can have how many read replicas

A

15

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
80
Q

What is a storage gateway hardware app appliance

A

Use on premises in case there is no virtualization on premises

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
81
Q

What is the key use for Aurora cloning

A

Copy on right method
Quick access to production DB.
Initial clone created with minimum space.
Uses copy on right method which only allocate storage when changes are made to data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
82
Q

Why use IAM permission boundaries?

A

Provides a boundary of permissions for any user.
Helpful for developers to manage their own permissions, but not to elevate their own permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
83
Q

Name three on-premises configurations for storage gateway

A

file gateway. With nfs/smb
volume gateway with iscsi
tape gateway with iscsi VTL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
84
Q

What are the two types of file systems in FSX luster?

A

Scratch
Persistent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
85
Q

Where did the name luster come from used in FSX luster

A

Linux cluster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
86
Q

What file system to use for high-performance computing Linux clusters scales to millions of IOPS integrates with S3?

A

FSX for luster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
87
Q

Define symmetric KMS key

A

Symmetric key is used to decrypt and encrypt in a single key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
88
Q

How do you decouple with SQS between application tiers?

A

Use SQS between front-end web apps and back-end apps which can process data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
89
Q

How can you increase SQS throughput?

A

By scaling up the consumers.
Create ASG from cloud watch alarm Q length this alarm triggers ASG scale out

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
90
Q

Why use net app on tap?

A

Move workloads running NAS or ONTAPP
Supports NFS, SMB, ISCSI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
91
Q

What are SQS access policies

A

Similar to S3 bucket policies
Cross account access to SQS.
Other services write access to SQS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
92
Q

What is the only protocol in FSX for openZFS?

A

Only NFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
93
Q

List route 53 record types

A

A Maps host name to IP version four
AAAA -host name to IPv6
CNAME - maps hosting to another name cannot map on domain zone Apex.
NS – name servers
Alias – like CNAME points to AWS resources can be used on Apex

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
94
Q

Define dynamo DB DAX

A

Dynamo DB accelerator
10 times performance through caching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
95
Q

What is an edge optimized API gateway?

A

CloudFront feature for clients distributed, geographically. locations receive routed request, and API still lives in one region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
96
Q

What are AWS step functions?

A

Serverless workflow.
Human approval
Timeout.
Error handling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
97
Q

The export feature of dynamo DB does what

A

Exports to S3 with JSON format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
98
Q

What is glue data brew?

A

Used to clean and normalize data in preperation for ML

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
99
Q

What is the max throughput for SQSFIFO queue

A

3000 messages per second

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
100
Q

Does API gateway support caching?

A

 Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
101
Q

Does Dynamo DB supprt caching?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
102
Q

Define timestream
Does it include analytics?
What encryption?

A

Time series database
built in analytics
encryption at rest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
103
Q

Define Keyspaces

A

Apache open source noSQL.
Uses CQL Cassandra query language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
104
Q

What is the use case for dynamo DB streams?

A

Enables replication via changelog to other regions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
105
Q

What are the services the integrate with Quicksite?

A

Aurora.
S3
RDS
Open search
Athena
Red shift

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
106
Q

What are the key features of open search?

A

Search any field, including partial matches
Dashboards.
Manage or serverless.
Can support SQL
Analysis of logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
107
Q

What is enhanced VPC routing?

A

A feature of Redshift.
Forces a copy and unload traffic through your VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
108
Q

What type of DB is Redshift?

A

Relational DB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
109
Q

What are the valid subscribers for SNS?

A

HTTP and HTTPS
SQS
Lambda
Kinesis Firehose ONLY
Email
SMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
110
Q

EKS supports which storage

A

EBS
EFS
FSX luster,
FSX Net ONTAPP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
111
Q

Document DB
What is it based on?
Does it auto scale?
Is it serverless?
How does it store data?

A

MongoDB=NoSQL
Autoscales.
Not serverless.
Stores Json data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
112
Q

Define AWS XRAY

A

Provides user centric model to analyze and debug applications.
Provides end to end view of request as traveling through the application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
113
Q

What is the data rate for KinesisDataStreams producers sending into KinesisDataStreams service?

A

1MB per second or 1000 messages per second
Per shard per shard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
114
Q

What is the data rate for KenesisDataStreams outbound to consumers?

A

2MB per second per shard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
115
Q

What makes up a kinesis data stream record

A

Contains
Partition key.
Data blob

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
116
Q

DataLake
What is it built upon?
Major benefit
Where can the data be stored?
What sits on top?
What type of access control?

A

Built upon glue.
All data in one place.
Can be an S3, RDS, Aurora
Lake formation exists on top.
Column access control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
117
Q

Define MSK

A

Managed service for Kafka

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
118
Q

Define AWS Recognition what use case

A

Find objects text and people using machine language.
Used in content moderation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
119
Q

Define IAM conditions and what are the 4 categories

A

Source IP
Requested region.
Resource tags.
MFA present

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
120
Q

Supported databases in RDS

A

MySQL
Postgres
Maria DB
Oracle
Microsoft SQL server
Aurora

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
121
Q

key feature of S3 versioning

A

Enables rollbacks
Version key is updated.
Delete the delete marker will restore original version

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
122
Q

Aurora serverless-
Key Features
What DB’s supported

A

On demand
Auto scaling.
Auto start/stop
Supports MYSQL and POSTGRES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
123
Q

What are valid Route53 health checks?

A

Cloudwatch alarms
Endpoints.
Other health checks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
124
Q

List the S3 storage classes

A

Standard.
Standard infrequent.
One zone infrequent.
Glacier instant retrieval.
Glacier, flexible retrieval
Glacier, deep archive
Intelligent tiering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
125
Q

EventBridge supported Targets

A

Lambda
SNS
SQS
Cloudwatch
API destinations
API Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
126
Q

For event bridge security.
What two types of policies

A

Resource based
IAM role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
127
Q

Define AWS control tower

A

Govern and secure multi account AWS environment.
Automate setup of environment.
Automate policies.
Detect policy violations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
128
Q

What two types of guard rails are used in AWS control tower

A

Preventative – use SCP’s
Detective – ID noncompliant resources via config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
129
Q

What are the three services that guard duty scans?

A

Cloudtrail events
VPC flow logs.
DNS logs

130
Q

Define AWS Macie

A

Data and security privacy services.
Detects PII

131
Q

Data sync copies data to what storage providers

A

NFS
SMB
Hadoop
Google cloud
Snowcone
S3.
FS X – all.
EFS.

132
Q

What is the one service AWS data sync does not copy data to

A

EBS

133
Q

Which services support throttling

A

API gateway
SQS
Kinesis

134
Q

What is the minimum storage in days for S3 glacier instant retrieval

A

90 day minimum storage

135
Q

What is the retrieval time for S3 glacial instant retrieval

A

Millisecond retrieval

136
Q

What are the three retrieval modes for glacial flexible?

A

Expedited

Bulk.

Standard.

137
Q

S3 object lambda what is it used for?

A

Can change the object before retrieved by application to remove sensitive data.
Only one bucket needed.
Creates S3 access point and lambda access point

138
Q

What are the two types of snowball edge? What does it do?

A

Storage optimize : 80 TB.
Compute optimized: 42 TB.
Processes data

139
Q

What are the sizes available for a snowcone?

A

8TB AND 14 TB versions

140
Q

Define glue service

A

Extract, transform and load. ETL
– fully serverless
– pulls from S3 to transform and load to red shift

141
Q

What are the glacier, deep archive retrieval modes?

A

Standard.
Bulk.

142
Q

What is the retrieval time for glacier deep archive standard mode?

A

12 hours

143
Q

What is retrieval time for glacial deep archive bulk mode?

A

48 hours

144
Q

What is the minimum storage in days for glacial deep archive?

A

180 days

145
Q

Define comprehend

A

Natural language processing to determine key places, people and events

146
Q

List the S3 intelligent tiering categories

F I A A D

A

Frequent.
Infrequent
archive instant access.
Archive access.
Deep archive access

147
Q

What are the benefits of using organizations?

A

Use one account to manage multiple accounts.
Cloud watch logs can be sent through central account for logging.
Better security

148
Q

Define VMware Cloud

A

VSphere in AWS

149
Q

How many IP’s for cider 10.0.0.0/31

A

2

150
Q

List the number of IPs per cider.
/32
/31
/30
/29
/28
/27
/26

A

1
2
4
8
16
3 2
64

151
Q

What are the two types of direct connect gateway

A

Hosted
Dedicated

152
Q

What is a used case for direct connect gateway

A

Connect on premises to VPC using a direct connection location bypasses Internet

153
Q

Define AWS VPN cloud hub

A

Allows to securely communicate with multiple sites using AWS VPN

154
Q

How many IPs are reserved in AWS subnets by default

A

5

155
Q

Define AWS inspector

A

For EC2 and ECS
Analyze, running processes to report OS vulnerabilities.

156
Q

What is the purpose of SQS long polling?

A

Reduces API calls
agent weights for a time during the polling period in case message comes in

157
Q

What cookie names are not allowed on application load balancer

A

AWSALB
AWSALBAPP
AWSALBTG

158
Q

What is storage Gateway hardware appliance?

A

On premises in case there is no virtualization on premises

159
Q

What types of health checks do network load balancers support?

A

TCP.
HTTP
HTTPS

160
Q

What types of health checks do network load balancers support?

A

TCP.
HTTP
HTTPS

161
Q

RDS supports what databases

A

MYSQL
Maria DB
MS sequel server
Oracle

162
Q

List the difference between cloud front and global accelerator

A

Call front is a cashing at the edge locations performance improved via cashing

Global accelerator good for UDP or TCP no cashing good for gaming IOT - fast regional failover

163
Q

List EFS storage classes

A

Standard.
In frequent
Archive

164
Q

Define cross zone load balancing

A

Since traffic to all instances evenly across availability zones and instances

165
Q

Kinesis data streams list for features in regards to records

A

Routing records
Ordering of records.
Multiple applications consume same stream data.
Replay Consumer records up to 365 days later in the same order

166
Q

What is EFS regional versus one zone file systems?

A

One zone stores data redundantly across a single zone.
Regional stores data across AZs

167
Q

What is AWS Route 53 resolver

A

It is a DNS responds recursively to DNS queries from:
AWS resources for public records Amazon VPC specific DNS names
Amazon R53 private hosted zones
is available by default and all VPCs.

168
Q

For route 53 resolver what does an inbound resolver endpoint do?

A

Allows DNS queries TO your VPC FROM your on premises network or another VPC

169
Q

For route 53 outbound resolver endpoint does what

A

Allows DNS queries FROM your VPC TO your on premises network or another VPC

170
Q

A route 53 resolver automatically answers DNS queries for

A

VPC domain names for EC2 instances.
Records in private hosted zones.
Public domain names resolver performs recursive look ups against public name servers on the Internet

171
Q

Route 53 resolver what to do to resolve DNS queries for any resources in the on prime network from AWSVPC

A

Create an outbound, DNS resolver to resolve host names on prem from your VPC

172
Q

True or false
a recovered instance is identical to the original instance, including the instance ID private IP, elastic IP address and all incident data

A

True

173
Q

Simplified automatic recovery EC2 instance is supported if

A

It uses default or dedicated instance tenancy.
It does not use elastic fabric adapter.

174
Q

List differences between kinesis data, streams, and kinesis data fire hose

A

Kinesis data streams ingest data for streaming at scale
KDfirehose is a date of transfer service to load streaming data to S3, redshift,and others

Kinesis data streams needs shards configuration manually KDFireHose is fully managed service

Kinesis streams has manual scaling
Fire hose has automated scaling

Kinesis data streams, support replay capability fire hose does not

175
Q

Kinesis data of fire hose is the easiest way to do what

A

Load streaming data into data stores and analytics tools

176
Q

Name the two types of spot requests

A

One time
Persistent

177
Q

What defines a persistent spot request

A

Request is opened again after the spot instance is interrupted

178
Q

List the spot instance request states

A

Open
Active
Fail
Closed
Disabled.
Cancelled

179
Q

What is a dedicated spot instance?

A

Has a tenency of dedicated when you create the spot instance

180
Q

What is the default tenency for EC two instances?

A

Shared hardware

181
Q

What is a dedicated instance?

A

Instance that will run on hardware dedicated to a single AWS account

182
Q

Dedicated instances might share hardware with

A

Other instances from the same AWS account that are not dedicated instances

183
Q

List some differences between a dedicated host and a dedicated instance

A

Dedicated host as a physical server with instance capacity fully dedicated to your use.
Dedicated instance is a physical server that’s dedicated to a single customer account.
Billing for a dedicated host is per host billing per instance, billing for dedicated instance.
Visibility of sockets on dedicated host no visibility on dedicated instance

184
Q

You cannot request a spot instance with the tenency of default if

A

In a VPC with instance tenancy as dedicated

185
Q

You can only cancel spot instance request that are in what status

A

Open
Active
Disabled

186
Q

You can only stop a spot instance if

A

The spot instance was launched from a persistent spot instance request

187
Q

You can’t stop a spot instance if it is part of a fleet or a launch group true or false

A

True

188
Q

What is a spot capacity pool

A

Set of unused EC to instances with the same instance type operating system availability zone and network platform

189
Q

What can you do to control spending for spot fleet?

A

Specify the spot, max total price for spot instances and
on demand max total price for on-demand instances

190
Q

At what size data set would it be better to use S3 transfer acceleration over cloud front to distribute content

A

Objects smaller than one gigabyte size should use cloud front otherwise use S3 with transfer acceleration

191
Q

AWSWAF covers what end points?

A

Cloud front distributions
API Gateway.
Application load balancer
App sync graph CL
Cognito user pool
App runner.

192
Q

After you have launched an instance, what are the only two choices for changing it’s tenancy

A

You can change the tenancy of an instance from dedicated to host or from host to dedicated

193
Q

Scale out refers to what type of scaling

A

Horizontal

194
Q

Scale out refers to what type of scaling

A

Horizontal

195
Q

Scale up is used in conjunction with what type of scaling

A

Vertical

196
Q

Security groups are state full, true or false

A

True

197
Q

NACL’s are stateless true or false

A

True

198
Q

Because NACL‘s are stateless, you must do what?

A

You must allow both inbound and outbound traffic

199
Q

Why use SQS delay cues

A

They let you postpone the delivery of new messages to consumers for a number of seconds.
Makes messages unavailable to consumers for a period of time this helps consumers process all the messages

200
Q

True or false service control policies do not affect service linked roles

A

True

201
Q

Service control policy affects what

A

All users and roles in member accounts, including root user of the member accounts

202
Q

What are dynamo DB streams?

A

Allows you to capture time ordered sequence item level modifications in a table, integrated with lambda so you can create triggers that automatically respond to events

203
Q

What is dynamo db TTL ?

A

Feature of dynamo DB, which enables time to live on a table

204
Q

Define elastiCache

A

Fully managed in memory data store compatible with Redis or MEMCACHED

205
Q

Describe mongo DB

A

Mongo DB source available cross platform document oriented, database classified as no sequel. Uses json documents to store data

206
Q

What is QLDB?

A

Quantum ledger, database dedicated to financial transactions

207
Q

Describe HA options for Neptune

A

Available across 3AZ with 15 read replicas

208
Q

Name for features of timestream

A

Serverless
Auto scale
Thousands of times faster at 1/10 the cost of relational databases
Data storage tearing
Built-in analytics

209
Q

Describe Athena

A

Serverless query service for s3 stored data
Uses SQL language
Common with Quicksight

210
Q

How do you improve Athena performance?

A

Use columnar data - Apache Parquet
Compress data for smaller retrieval
Partition data sets in s3
Use larger files

211
Q

What is Athena Federated query?

A

Allows, SQL queries across data stored relational or non relational or Redis

212
Q

Redshift what underlying database based on ?
OLTP OR OLAP?

A

Based on post sequel
OLAP online and analytical processing

213
Q

List differences between red shift and Athena

A

Faster queries than Athena for joins aggregations
Redshift uses indexes

214
Q

What is the MEMCACHED evictions cloud watch metric?

A

When memory begins to fill up it deletes unused, cache keys to free up space

215
Q

What is the default behavior of AWS lambda in terms of network access?

A

Runs in a secure VPC with access to AWS services in the Internet lambda owns its own VPC, which is not connected to accounts default VPC

216
Q

What action to take to deploy new roles in each of the organizations accounts

A

Use cloud formation stack sets

217
Q

What can you use to validate the integrity of AWS cloud Trail log files

A

Enable cloud Trail, log file integrity, validation

218
Q

Define AWS data pipeline

A

Define data driven workflows, so that completed tasks can kick off the next task

219
Q

Define Amazon data, lifecycle manager or DLM

A

Automate creation, retention, and deletion of EBS snapshots

220
Q

What file systems does the data sync support?

A

NFS
SMB
HDFS
cloud storage providers
snowcone
S3
EFS
FSX
open OpenZFS
net app on tap 

221
Q

What type of billing method used when using AWS Linux, Ubuntu

A

Per second

222
Q

List default termination policy in ASG

A

In order:
Align with allocation strategy

If old launch template configuration

Next billing hour

223
Q

Can security groups have deny statements

A

No

224
Q

Are security groups stateful

A

Yes

225
Q

Which cluster placement strategy for large distributed workloads like Kafka Hadoop, and Cassandra and why

A

Partition placement group least likely to have hardware failure as each partition is its own dedicated rack

226
Q

What’s the difference between a launch configuration and a launch template

A

Template can contain different types of instances and can’t have versions.

Configuration contains one instant types used by ASG

227
Q

Static webpage definition

A

Static webpage delivers stored content with HTMLCSS or Java

228
Q

dynamic webpage definition

A

Dynamic is generated site at runtime by php node.js, asp.net

229
Q

What type of billing method used when using AWS Linux, Ubuntu

A

Per second

230
Q

List default termination policy in ASG

A

In order:
Align with allocation strategy

If old launch template configuration

Next billing hour

231
Q

Can security groups have deny statements

A

No

232
Q

Are security groups stateful

A

Yes

233
Q

Which cluster placement strategy for large distributed workloads like Kafka Hadoop, and Cassandra and why

A

Partition placement group least likely to have hardware failure as each partition is its own dedicated rack

234
Q

What’s the difference between a launch configuration and a launch template

A

Template can contain different types of instances and can’t have versions.

Configuration contains one instant types used by ASG

235
Q

Static webpage definition

A

Static webpage delivers stored content with HTMLCSS or Java

236
Q

dynamic webpage definition

A

Dynamic is generated site at runtime by php node.js, asp.net

237
Q

Any explicit deny in any policy results in

A

Overrides the allow

238
Q

What are the 5 policy types are available in a single AWS account

A

Identity-based
Resource-based
IAM permissions boundary
SCP’s
Session policies

239
Q

To help save S3 cost how can glue job help

A

Glue job can extract transform load and compressed data before it’s sent to S3

240
Q

What are the EFS performance modes?

A

General purpose
Max I/O

241
Q

What are EFS throughput modes

A

Elastic – auto scales
Provision – workload is known
Bursting - throughput scales with storage

242
Q

Why build a shared services VPC

A

Provides access across multiple accounts, which are shared reducing admin overhead

243
Q

How does global accelerator help with blue green deployments?

A

Global accelerator can shift traffic to green deployment from blue gradually or all at once

244
Q

What three types of virtual interface available for direct connect

A

Public – to connect for public AWS services

Private to connect to VPC using private ips

Transit – to connect to VPC using private IP and transit Gateway

245
Q

Define IAM policy evaluation
DORIBS

A

Is there an explicit deny?
Organization SCP
Resource SCP
ID based
IAM permissions boundary
Session policies

246
Q

Read replicas use asynchronous, or synchronous replication

A

Read replicas use asynchronous replication

247
Q

Read replicas in multi AZ set up use as synchronous or synchronous replication

A

Read replicas use synchronous in multi-AZ What?

248
Q

What is Amazon QuickSite?

A

Service machine, learning power business intelligence service creates interactive dashboards

249
Q

With regard to QuickSite, what is SPICE?

A

In memory computation engine if data is imported into QuickSight

250
Q

What are the data sources for quick site?

A

RDS
Aurora.
Red shift
Athena
S3
Open search.
Timestream

251
Q

When you define users in QuickSite, do the same users exist in IAM

A

No, these users exist only within quick sight

252
Q

What is Parquette file?

A

Open source column, oriented, data file format, designated for efficient, data storage and retrieval use with Apache Parquette

253
Q

What are glue job bookmarks?

A

Prevents reprocessing old data

254
Q

What is glue elastic views?

A

Combine and replicate data across multiple data stores using SQL

255
Q

What is lake formation?

A

Works on top of a data lake
centralize all your data for analytical purposes
fully managed service discover cleanse, transform ingest data

256
Q

What is a huge benefit of using AWS lake formations

A

Centralized permissions

257
Q

What other two types of kinesis data analytics

A

Sequel applications
Apache flink

258
Q

Why would you need to use kinesis data analytics for Apache Flink?

A

For more advanced Java or sequel data analytics

259
Q

Which version of kinesis data analytics would you use if you had kinesis fire hose as source?

A

You cannot use Flink must use kinesis analytics

260
Q

What DR options are available for red shift

A

Multi AZ mode for some cluster types
If single AZ, then snapshots are used

261
Q

With red shift, what can you do with snapshots?

A

Snapshots can be copied to another AWS region

262
Q

What is red shift spectrum

A

Query data that is already an S3 without loading it

263
Q

What service can convert JSON files to Apache Parquette

A

AWS glue

264
Q

What should you use to control access to your KMS CMKs?

A

KMS key policies

265
Q

What’s the difference between AWS secrets, manager and SSM parameter store

A

With AWS secrets manager, you can rotate the secrets automatically

266
Q

What’s the difference between dedicated instances and dedicated hosts?

A

Dedicated hosts are dedicated physical servers all your instances run on can use your own licensing

Dedicated instances are instances that run hardware that’s dedicated to a single customer. Other instances can run on the same hardware from other AWS accounts.

267
Q

What are Amazon cloud watch alarm actions

A

Create alarms, automatically stop terminate, reboot, or recover your EC2 instances

268
Q

Which is better for handling spikes of traffic cloud front or global accelerator

A

Cloud front

269
Q

Which is better for non-HTTPuse cases such as gaming UDP IOT VOIP

A

Global accelerator

270
Q

Can SNS buffer messages

A

No

271
Q

What three services can handle throttling

A

API Gateway
SQS
Kinesis

272
Q

What is a VIF and what are the two types?

A

VIF = virtual interface
Public and private

273
Q

What is the difference between a public VIF and a private VIF?

A

Public VIF enables access to public services such as S3

Private VIF enables access to your VPC

274
Q

What is the difference between AWS private link and AWS direct connection

A

Private link provides a private network connection between VPCs and AWS services.

AWS direct connect is dedicated private connection between on premises and AWS.

275
Q

What is the key difference between kinesis data streams and kinesis firehose

A

Kinesis data streams stream and process data runs real time metrics and analytics

Kinesis data firehose will load streaming data into data stores and analytics tools. It does not do any analytics by itself.

276
Q

What are the two types of VPC endpoint?

A

Interface.
Gateway

277
Q

What is the difference between a VPC interface endpoint and a gateway endpoint

A

An interface endpoint enables connectivity to AWS services over AWS private link. It consists of a collection of an elastic network interfaces private IP addresses services as an entry point for traffic to the AWS service.

GatewayEndpoints our supported by Amazon, S3 and dynamo DB. Gateway and points do not use AWS private link instead uses specific IP routes to connect to Dynamo DB or S3

278
Q

What is VPC traffic mirroring?

A

To replicate network traffic to and from an EC2 to instance and forward to an out of band security and monitoring appliance

279
Q

Which services are available for private link

A

EC2
ELB
Kinesis
EC2 systems manager
SNS
Data sink

280
Q

Amazon elastiCache is used for

A

Used as a cashing layer in front of relational databases

281
Q

What is spread placement group

A

Spreads instances across underlying hardware

282
Q

How many instances per group per AZ in a spread placement group

A

7

283
Q

True or false Amazon EFS file system can have Mount targets in only one VPC at a time

A

True

284
Q

What are some limits on EC2 Hibernate?

A

RAM must be less then 150GB
Root Volume must be EBS and encrypted
No bare metal
ON-Demand reserved and spot instances supported

285
Q

Is EFS compatible with Windows OS?

A

NO

286
Q

What are the EFS performance modes?

A

General and MAX I/O

287
Q

What are the EFS storage classes?

A

Standard.
Infrequent access
Archive

288
Q

Does Amazon RDS mySQL support storage auto scaling?

A

Yes

289
Q

How to migrate AWS account from an AWS organization a to organization B what are the steps?

A

Remove member from old organization
send invite to member the new organization
accept the invite to new organization

290
Q

What happens in the case of auto scaling group when an instance is in impaired status?

A

Auto scaling does not immediately terminate the instance, but waits for a few minutes for the instance to recover

291
Q

Can a single region KMS key be converted to a multi region

A

No!

292
Q

Route 53 what is created automatically for a public hosted zone only

A

NS and SOA records

293
Q

Can IAM permission boundaries be applied to groups

A

No. Roles or users only.

294
Q

Can IAM permission boundaries be applied to groups

A

No. Roles or users only.

295
Q

Can you host a website on lambda

A

No

296
Q

Can you put cloud front in front of lambda?

A

No

297
Q

List the default auto scaling group termination policy

A

Allocation strategy,
Old launch template
Old Launch configuration
Next billing hour

298
Q

Can you use S3 Gateway endpoint to transfer data over direct connection

A

No!

299
Q

To use EBS multi what type of EBS volume is needed

A

Io2 or io1

300
Q

For IAAS what components are responsibility of the customer?

A

Applications
Data
Runtime
Middleware
OS

301
Q

For PAAS what components are responsibility of the customer?

A

Applications
Data

302
Q

What database is in-memory, low latency, high performance?

A

ElastiCache

303
Q

What is EMR?

A

ETL service. Extract Transform and Load

304
Q

What does a DynamoDB Global table do for you?

A

Table will be accessible with low-latency in multiple regions

305
Q

What failover type is DynamoDB Global Table?

A

Active - Active

306
Q

What type of storage does RedShift store data?

A

Columnar

307
Q

What DB type of DB is RedShift based on?

A

Postgres

308
Q

What are the performance increase for Redshift?

A

10X increase

309
Q

Is RedShift OLTP or OLAP?

A

OLAP - Online Analytical processing

310
Q

What is MPP

A

Massive Parallel Processing - Used by Redshift

311
Q

Does Redshift have Serverless offering?

A

YES -

312
Q

What does EMR stand for?

A

Elastic Map Reduce

313
Q

What does EMR do?

A

Helps to create Hadoop clusters for vast amounts of data

314
Q

Is Athena Serverless?

A

YES

315
Q

What use cases for Athena?

A

Analyze and query
VPN flow logs
ELB logs
CloudTrails

316
Q

DocumentDB is based on….

A

MongoDB

317
Q

DocumentDB is SQL or NoSQL?

A

NoSQL

318
Q

What is TimeStream Database

A

Time Series database -
1000 times faster
1/10th the cost of relational databases

319
Q

What is QLDB

A

Quantum Ledger Database
Immutable - cannot be modified.
Journal behind the scene
cryptographically verifiable.

320
Q

AWS managed blockchain is a service to…

A

join public blockchain networks
build your own blockchain

321
Q

AWS Managed blockchain is compatible with what frameworks

A

HyperLedger Fabric
Ethereum