AWS CCP 1 Flashcards
Which AWS service is primarily used for software version control?
- AWS CodeCommit
- AWS CodeStar
- AWS Cloud9
- AWS CodeDeploy
- AWS CodeCommit
Which AWS service can you use to install a third-party database?
- Amazon RDS
- Amazon DynamoDB
- Amazon EC2
- Amazon EMR
- Amazon EC2
Identify the services that have a global (rather than regional) scope? (choose 2)
- Amazon Route 53
- Amazon S3
- Amazon CloudFront
- AWS Lambda
- Amazon EC2
- Amazon Route 53
3. Amazon CloudFront
Which service can you use to provision a preconfigured server with little to no AWS experience?
- Amazon Elastic Beanstalk
- AWS Lambda
- Amazon EC2
- Amazon Lightsail
- Amazon Lightsail
Which AWS service allows you to connect to storage from on-premise servers using standard file protocols?
- Amazon S3
- Amazon EBS
- Amazon Glacier
- Amazon EFS
- Amazon EFS
Which pricing model should you use for EC2 instances that will be used in a lab environment for several hours on a weekend and must run uninterrupted?
- On-Demand
- Reserved
- Spot
- Dedicated Instance
- On-Demand
What is an availability zone composed of?
- One or more regions
- One or more DCs in a location
- A collection of edge locations
- A collection of VPCs
- One or more DCs in a location (Datacenter)
Which AWS services are used for analytics? (choose 2)
- Amazon RDS
- Amazon ElastiCache
- Amazon Athena
- Amazon S3
- Amazon EMR
- Amazon Athena
5. Amazon EMR
What advantages does deploying Amazon CloudFront provide? (choose 2)
- A private network link to the AWS cloud
- Reduced latency
- Automated deployment of resources
- Improved performance for end users
- Provides serverless compute services
- Reduced latency
4. Improved performance for end users
What considerations are there when choosing which region to use? (choose 2)
- Data sovereignty
- Available storage capacity
- Latency
- Pricing in local currency
- Available compute capacity
- Data sovereignty
3. Latency
Question 11 Which service can be used to track the CPU usage of an EC2 instance? 1. Amazon CloudTrail 2. Amazon CloudFront 3. Amazon CloudFormation 4. Amazon CloudWatch
- Amazon CloudWatch
Which feature of AWS allows you to deploy a new application for which the requirements may change over time?
- Elasticity
- Fault tolerance
- Disposable resources
- High availability
- Elasticity
Which items can be configured from within the VPC management console? (choose 2)
- Subnets
- Regions
- Load Balancing
- Auto Scaling
- Security Groups
- Subnets
5. Security Groups
Which services are integrated with KMS encryption? (choose 2)
- Amazon RDS
- Amazon EC2
- Amazon EBS
- Amazon SWF
- AWS CloudFormation
- Amazon RDS
3. Amazon EBS
Which service allows you to automatically expand and shrink your application in response to demand?
- AWS ElastiCache
- Amazon Elastic Load Balancing
- AWS Auto Scaling
- Amazon DynamoDB
- AWS Auto Scaling
The AWS global infrastructure is composed of? (choose 2)
- Regions
- Clusters
- Fault Zones
- Availability Zones
- IP subnets
- Regions
4. Availability Zones
Which of the statements below is accurate regarding Amazon S3 buckets? (choose 2)
- Bucket names must be unique regionally
- Buckets are replicated globally
- Bucket names must be unique globally
- Buckets are region-specific
- Buckets can contain other buckets
- Bucket names must be unique globally
4. Buckets are region-specific
Which AWS storage technology can be considered a “virtual hard disk in the cloud”?
- Amazon Elastic File Storage (EFS) filesystem
- Amazon Elastic Block Storage (EBS) volume
- Amazon S3 object
- Amazon Glacier archive
- Amazon Elastic Block Storage (EBS) volume
Question 19
Under the AWS shared responsibility model what is the customer responsible for? (choose 2)
1. Physical security of the data center
2. Replacement and disposal of disk drives
3. Configuration of security groups
4. Patch management of infrastructure
5. Encryption of customer data
- Configuration of security groups
5. Encryption of customer data
Which service records API activity on your account and delivers log files to an Amazon S3 bucket?
- Amazon CloudWatch
- Amazon S3 Event Notifications
- Amazon CloudTrail
- Amazon CloudWatch Logs
- Amazon CloudTrail
The IAM service can be used to manage which objects? (choose 2)
- Security groups
- Access policies
- Roles
- Network ACLs
- Key pairs
- Access policies
3. Roles
Which types of pricing policies does AWS offer? (choose 2)
- Pay-as-you-go
- Enterprise license agreement (ELA)
- Non-peak hour discounts
- Global usage discounts
- Save when you reserve
- Pay-as-you-go
5. Save when you reserve
Which tool enables you to visualize your usage patterns over time and to identify your underlying cost drivers?
- AWS Simple Monthly Calculator
- Total Cost of Ownership (TCO) Calculator
- AWS Cost Explorer
- AWS Budgets
- AWS Cost Explorer
What advantages do you get from using the AWS cloud? (choose 2)
- Trade capital expense for variable expense
- Stop guessing about capacity
- Increased capital expenditure
- Gain greater control of the infrastructure layer
- Comply with all local security compliance programs
- Trade capital expense for variable expense
2. Stop guessing about capacity
A company plans to create a hybrid cloud architecture. What technology will allow them to create a hybrid cloud?
- VPC Peering
- Internet Gateway
- Direct Connect
- Elastic Network Interface
- Direct Connect
Which service supports the resolution of public domain names to IP addresses or AWS resources?
- Amazon Route 53
- Amazon CloudFront
- Amazon SNS
- Hosted Zones
- Amazon Route 53
What can you use to quickly connect your office securely to your Amazon VPC?
- Route Table
- Internet Gateway
- Direct Connect
- AWS managed VPN
- AWS managed VPN
What is the scope of a VPC within a region?
- Spans all Availability Zones within the region
- Spans all Availability Zones globally
- At least 2 subnets per region
- At least 2 data centers per region
- Spans all Availability Zones within the region
Which service can be used for building and integrating loosely-coupled, distributed applications?
- Amazon EBS
- Amazon SNS
- Amazon EFS
- Amazon RDS
- Amazon SNS
Which type of Amazon Elastic Load Balancer operates at layer 7 of the OSI model?
- Application Load Balancer
- Network Load Balancer
- Classic Load Balancer
- F5 Load Balancer
- Application Load Balancer
Which services can help to automate a company’s IT infrastructure? (choose 2)
- Amazon CloudWatch Alarms
- Amazon Route 53
- AWS Lambda Scheduled Events
- Virtual Private Cloud
- Elastic Network Interface
- Amazon CloudWatch Alarms
3. AWS Lambda Scheduled Events
Which database service is a NoSQL type of database that is fully managed?
- Amazon RDS
- Amazon DynamoDB
- Amazon RedShift
- Amazon ElastiCache
- Amazon DynamoDB
Which storage service allows you to connect multiple EC2 instances concurrently using file-level protocols?
- Amazon S3
- Amazon EBS
- Amazon EFS
- Amazon Glacier
- Amazon EFS
For which services does Amazon not charge customers? (choose 2)
- Amazon VPC
- Amazon EBS
- Amazon CloudFormation
- Amazon S3
- Amazon SNS
- Amazon VPC
3. Amazon CloudFormation
What architectural best practice aims to reduce the interdependencies between services?
- Services, Not Servers
- Removing Single Points of Failure
- Automation
- Loose Coupling
- Loose Coupling
What is the most cost-effective support plan that should be selected to provide at least a 1-hour response time for a production system failure?
- Basic
- Developer
- Business
- Enterprise
- Business
Which AWS database service supports complex queries and joins and is suitable for a transactional database deployment?
- Amazon RDS
- Amazon DynamoDB
- Amazon RedShift
- Amazon EMR
- Amazon RDS
Under the shared responsibility model, what are examples of shared controls? (choose 2)
- Patch management
- Storage system patching
- Physical and environmental
- Configuration management
- Service and Communications Protection
- Patch management
4. Configuration management
How can an organization compare the cost of running applications in an on- premise or colocation environment against the AWS cloud?
- AWS Budgets
- AWS Simple Monthly Calculator
- TCO Calculator
- AWS Cost Explorer
- TCO Calculator
What is the most cost-effective EC2 pricing option to use for a non-critical overnight workload?
- On-Demand
- Spot
- Reserved Instance
- Dedicated Host
- Spot
Which service allows you to run code as functions without needing to provision or manage servers?
- Amazon EC2
- Amazon CodeDeploy
- AWS Lambda
- Amazon EKS
- AWS Lambda
What benefits does Amazon EC2 provide over using non-cloud servers? (choose 2)
- Complete control of the hypervisor layer
- Elastic web-scale computing
- Inexpensive
- Fault tolerance
- High-availability with an SLA of 99.99%
- Elastic web-scale computing
3. Inexpensive
Which type of Elastic Load Balancer operates at the connection layer (layer 4) and supports IP addresses as targets?
- Application Load Balancer
- Network Load Balancer
- Classic Load Balancer
- ELBs do not support IP addresses as targets
- Network Load Balancer
Which of the following are features of Amazon CloudWatch? (choose 2)
- Used to gain system-wide visibility into resource utilization
- Records account activity and service events from most AWS services
- Used for auditing of API calls
- Can be accessed via API, command-line interface, AWS SDKs, and the AWS Management Console
- Provides visibility into user activity by recording actions taken on your account
- Used to gain system-wide visibility into resource utilization
- Can be accessed via API, command-line interface, AWS SDKs, and the AWS Management Console
Amazon S3 bucket names must follow as set of rules. Which of the rules below apply to Amazon S3 bucket names? (choose 2)
- Names must be unique across all of AWS
- Names must be 3 to 63 characters in length
- Names must contain uppercase letters
- Names must be unique within a region
- Names must be formatted as a DNS domain name
- Names must be unique across all of AWS
2. Names must be 3 to 63 characters in length
Which of the following statements are correct about Elastic Block Store (EBS) volumes? (choose 2)
- Root EBS volumes are retained on termination by default
- EBS volumes must be in the same AZ as the instances they are attached to
- You can attach multiple EBS volumes to an instance
- You can attach an EBS volume to multiple instances
- EBS volumes cannot be backed up
- EBS volumes must be in the same AZ as the instances they are attached to
- You can attach multiple EBS volumes to an instance
Which statement below is incorrect in relation to Security Groups?
- Operate at the instance level
- Support allow rules only
- Stateless
- Evaluate all rules
- Stateless
What constraints apply to customers when performing penetration testing? (choose 2)
- Permission is required for all penetration tests
- You can perform penetration testing on your own systems at any time without prior authorization
- You must complete and submit the AWS Vulnerability / Penetration Testing Request Form to request authorization
- Penetration testing can be performed against any AWS resources
- Penetration testing must be performed by a certified security consultant
- Permission is required for all penetration tests
3. You must complete and submit the AWS Vulnerability / Penetration Testing Request Form to request authorization
Which statement below is incorrect in relation to Network ACLs?
- Operate at the Availability Zone level
- Support allow and deny rules
- Stateless
- Process rules in order
- Operate at the Availability Zone level
What benefits are provided by Amazon CloudFront? (choose 2)
- Allows you to register domain names
- Built-in Distributed Denial of Service (DDoS) attack protection
- Used to enable private subnet instances to access the Internet
- Content is cached at Edge Locations for fast distribution to customers
- Provides a worldwide distributed DNS service
- Built-in Distributed Denial of Service (DDoS) attack protection
- Content is cached at Edge Locations for fast distribution to customers
Which service can be used to help you to migrate databases to AWS quickly and securely?
- AWS KMS
- AWS SMS
- AWS DMS
- AWS Migration Hub
- AWS DMS
Which feature can you use to grant read/write access to an Amazon S3 bucket?
- IAM Role
- IAM Policy
- IAM Group
- IAM User
- IAM Policy
Which AWS support plan should you use if you need a response time of < 15 minutes for a business-critical system failure?
- Basic
- Developer
- Business
- Enterprise
- Enterprise
Which AWS service is used to enable multi-factor authentication?
- Amazon STS
- AWS IAM
- Amazon EC2
- AWS KMS
- AWS IAM
Which AWS service can be used to convert video and audio files from their source format into versions that will playback on devices like smartphones, tablets and PC?
- Elastic Transcoder
- Elastic Beanstalk
- Elastic Load Balancer
- Auto Scaling
- Elastic Transcoder
What method can you use to take a backup of an Amazon EC2 instance using AWS tools?
- Take full and incremental file-level backups using the backup console
- Take application-consistent backups using the EC2 API
- Use Cross Region Replication (CRR) to copy the instance to another region
- Take a snapshot to capture the point-in-time state of the instance
- Take a snapshot to capture the point-in-time state of the instance
What are two ways that moving to an AWS cloud can benefit an organization? (choose 2)
- Switch to a CAPEX model
- Increase speed and agility
- Stop guessing about capacity
- Depreciate assets over a longer timeframe
- Gain greater control of data center security
- Increase speed and agility
3. Stop guessing about capacity
Which of the following statements is correct in relation to consolidated billing? (choose 2)
- Paying accounts are independent and cannot access resources of other accounts
- Used to consolidate billing across organizations
- One bill is provided per AWS organization
- Volume pricing discounts cannot be applied to resources
- Only available to Enterprise customers
- Paying accounts are independent and cannot access resources of other accounts
- One bill is provided per AWS organization
Which AWS service allows you to use block-based volumes on-premise that are then asynchronously backed up to Amazon S3?
- AWS Storage Gateway File Gateway
- AWS Storage Gateway Volume Gateway
- Amazon S3 Multi-Part upload
- Amazon S3 Transfer Acceleration
- AWS Storage Gateway Volume Gateway
When instantiating compute resources, what are two techniques for using automated, repeatable processes that are fast and avoid human error? (choose 2)
- Snapshotting
- Bootstrapping
- Fault tolerance
- Infrastructure as code
- Performance monitoring
- Bootstrapping
4. Infrastructure as code
A company would like to maximize their potential volume and RI discounts across multiple accounts and also apply service control policies on member accounts. What can they use gain these benefits?
- AWS Budgets
- AWS Cost Explorer
- AWS IAM
- AWS Organizations
- AWS Organizations
Which AWS service can an organization use to automate operational tasks on EC2 instances using existing Chef cookbooks?
- AWS OpsWorks
- AWS Service Catalog
- AWS Config
- AWS CodeDeploy
- AWS OpsWorks
Which AWS service can be used to process a large amount of data using the Hadoop framework?
- Amazon Athena
- Amazon Kinesis
- AWS Glue
- Amazon EMR
- Amazon EMR
Which feature of Amazon Rekognition can assist with saving time?
- Identification of objects in images and videos
- Identification of the language of text in a document
- Adds automatic speech recognitions (ASR) to applications
- Provides on-demand access to compliance-related information
- Identification of objects in images and videos
Which type of cloud deployment enables customers to leverage the benefits of the public cloud and co-existing with on-premises infrastructure?
- Public Cloud
- Private Cloud
- Hybrid Cloud
- Legacy IT Infrastructure
- Hybrid Cloud