AWS CCP 2 Flashcards
Which AWS service gives you centralized control over the encryption keys used to protect your data?
- AWS STS
- AWS KMS
- AWS DMS
- Amazon EBS
- AWS KMS
How can a security compliance officer retrieve AWS compliance documentation such as a SOC 2 report?
- Using AWS Artifact
- Using AWS Trusted Advisor
- Using AWS Inspector
- Using the AWS Personal Health Dashboard
- Using AWS Artifact
Which items should be included in a TCO analysis comparing on-premise to AWS Cloud? (choose 2)
- Firewall management
- Application licensing
- Compute hardware
- Data center security
- Operating system patching
- Compute hardware
4. Data center security
Which service provides visibility into user activity by recording actions taken on your account?
- Amazon CloudWatch
- Amazon CloudFormation
- Amazon CloudTrail
- Amazon CloudHSM
- Amazon CloudTrail
Which of the facts below are accurate in relation to AWS Regions? (choose 2)
- Each region consists of 2 or more availability zones
- Each region consists of a collection of VPCs
- Each region is designed to be completely isolated from the other Amazon Regions
- Regions have direct, low-latency, high throughput and redundant network connections between each other
- Regions are Content Delivery Network (CDN) endpoints for CloudFront
- Each region consists of 2 or more availability zones
3. Each region is designed to be completely isolated from the other Amazon Regions
Which AWS service provides elastic web-scale cloud computing allowing you to deploy operating system instances?
- Amazon EBS
- AWS Lambda
- Amazon RDS
- Amazon EC2
- Amazon EC2
You need to ensure you have the right amount of compute available to service demand. Which AWS service can automatically scale the number of EC2 instances for your application?
- Amazon Elastic Load Balancer
- Amazon Elasticache
- AWS Auto Scaling
- AWS RedShift
- AWS Auto Scaling
Which configuration changes are associated with scaling vertically? (choose 2)
- Adding additional EC2 instances through Auto Scaling
- Adding additional hard drives to a storage array
- Adding a larger capacity hard drive to a server
- Distributed processing
- Changing an EC2 instance to a type that has more CPU and RAM
- Adding a larger capacity hard drive to a server
5. Changing an EC2 instance to a type that has more CPU and RAM
What are two ways an AWS customer can reduce their monthly spend? (choose 2)
- Turn off resources that are not being used
- Use more power efficient instance types
- Reserve capacity where suitable
- Be efficient with usage of Security Groups
- Reduce the amount of data ingress charges
- Turn off resources that are not being used
3. Reserve capacity where suitable
Which AWS services can be utilized at no cost? (choose 2)
- Identity and Access Management (IAM)
- Amazon VPC
- Amazon S3
- Amazon CloudFront 5. Amazon RedShift
- Identity and Access Management (IAM)
2. Amazon VPC
Which types of AWS resource can be launched from a Golden Image? (choose 2)
- Amazon DynamoDB tables
- Amazon EC2 instances
- AWS Lambda functions
- Amazon RDS instances
- Amazon S3 objects
- Amazon EC2 instances
4. Amazon RDS instances
Using AWS terminology, which items can be created in an Amazon S3 bucket? (choose 2)
- Folders
- Files
- Tables
- Objects
- Queues
- Folders
4. Objects
What are two ways of connecting to an Amazon VPC from an on-premise data center? (choose 2)
- VPC Peering
- Direct Connect
- VPN CloudHub
- Internet Gateway
- VPC Router
- Direct Connect
3. VPN CloudHub
Which of the below is Amazon’s proprietary RDS database?
- MariaDB
- MySQL
- DynamoDB
- Aurora
- Aurora
A new user is unable to access any AWS services, what is the most likely explanation?
- The user needs to login with a key pair
- The services are currently unavailable
- By default, new users are created without access to any AWS services
- The default limit for user logons has been reached
- By default, new users are created without access to any AWS services
Which of the following compliance programs allows the AWS environment to process, maintain, and store protected health information?
- ISO 27001
- PCI DSS
- HIPAA
- SOC 1
- HIPAA
Which of the following services does Amazon Route 53 provide? (choose 2)
- Domain registration
- Route tables
- Domain Name Service (DNS)
- Auto Scaling
- Load balancing
- Domain registration
3. Domain Name Service (DNS)
Which file format is used to write AWS Identity and Access Management (IAM) policies?
- DOC
- XML
- JBOD
- JSON
- JSON
Which of the following are valid types of Reserved Instance? (choose 2)
- Convertible RI
- Discounted RI
- Scheduled RI
- Long-Term RI
- Special RI
- Convertible RI
3. Scheduled RI
At what level is a Network ACL applied?
- Instance level
- Region level
- Availability Zone level
- Subnet level
- Subnet level
An architect needs to compare the cost of deploying an on-premise web server and an EC2 instance on the AWS cloud. Which tool can be used to assist the architect?
- AWS Cost Explorer
- AWS Budgets
- AWS TCO Calculator
- AWS Simple Monthly Calculator
- AWS TCO Calculator
Which AWS service provides preconfigured virtual private servers (instances) that include everything required to deploy an application or create a database?
- AWS CloudFormation
- Amazon Lightsail
- Amazon ECS
- AWS Lambda
- Amazon Lightsail
Which AWS service protects against common exploits that could compromise application availability, compromise security or consume excessive resources?
- AWS WAF
- AWS Shield
- Security Group
- Network ACL
- AWS WAF
A Solutions Architect is launching a new EC2 instance that will be a web- server. Which EBS volume type provides a good balancer of price and performance and can be used as a system boot volume?
- Cold HDD (sc1)
- Throughput Optimized (st1)
- General Purpose (gp2)
- Provisioned IOPS (io1)
- General Purpose (gp2)
Which Amazon S3 storage tier provides does not include a data retrieval fee and has an availability SLA of 99.99%?
- S3 Standard
- S3 Standard-IA
- S3 One Zone-IA
- Amazon Glacier
- S3 Standard
An organization would like to run managed desktops on the AWS cloud using the Windows 10 operating system. Which service can deliver these requirements?
- Amazon EC2
- Amazon Workspaces
- Amazon SWF
- Amazon does not provide desktop services
- Amazon Workspaces