AWS Cloud Practitioner (Pool 2/3) Flashcards
Which AWS services can be used to store files? Choose 2 answers from the options given below:
A) Amazon CloudWatch B) Amazon Simple Storage Service (S3) C) Amazon Elastic Block Store (Amazon EBS) D) AWS Config E) Amazon Athena
B) Amazon Simple Storage Service (S3)
C) Amazon Elastic Block Store (Amazon EBS)
Amazon S3 is object storage built to store and retrieve any amount of data from anywhere – web sites and mobile apps, corporate applications, and data from IoT sensors or devices. It is designed to deliver 99.999999999% durability, and stores data for millions of applications used by market leaders in every industry.
For more information on the Simple Storage Service, please refer to the below URL: https://aws.amazon.com/s3/
Amazon Elastic Block Store (Amazon EBS) provides persistent block storage volumes for use with Amazon EC2 instances in the AWS Cloud. Each Amazon EBS volume is automatically replicated within its Availability Zone to protect you from component failure, offering high availability and durability.
For more information on Amazon EBS, please refer to the below URL: https://aws.amazon.com/ebs/
Which of the following services uses AWS edge locations?
A) Amazon Virtual Private Cloud (Amazon VPC)
B) Amazon CloudFront
C) Amazon Elastic Cloud Compute (Amazon EC2)
D) AWS Storage Gateway
B) Amazon CloudFront
Amazon CloudFront is a web service that speeds up distribution of your static and dynamic web content, such as .html, .css, .js, and image files, to your users. CloudFront delivers your content through a worldwide network of data centers called edge locations.
For more information on Amazon CloudFront, please refer to the below URL: http://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/Introduction.html
Which of the following is a benefit of Amazon Elastic Compute Cloud (Amazon EC2) over physical servers?
A) Automated Backup
B) Paying for only what you use
C) The ability to chose hardware vendors
D) Root /administrator access
B) Paying for only what you use
One of the advantages of EC2 Instances is the per second billing concept. This is given in the AWS documentation also With per-second billing, you pay for only what you use. It takes cost of unused minutes and seconds in an hour off of the bill, so you can focus on improving your applications instead of maximizing usage to the hour. Especially, if you manage instances running for irregular periods of time, such as dev/testing, data processing, analytics, batch processing and gaming applications, can benefit.
For more information on EC2 Pricing, please refer to the below URL: https://aws.amazon.com/ec2/pricing/
Which AWS service provides infrastructure security optimization recommendations?
A) AWS Price List Application Programming Interface (API)
B) Reserved Instances
C) AWS Trusted Advisor
D) Amazon Elastic Compute Cloud (Amazon EC2) Spot Fleet
C) AWS Trusted Advisor
An online resource to help you reduce cost, increase performance, and improve security by optimizing your AWS environment, Trusted Advisor provides real time guidance to help you provision your resources following AWS best practices.
For more information on the AWS Trusted Advisor, please refer to the below URL: https://aws.amazon.com/premiumsupport/trustedadvisor/
Which service allows for the collection and tracking of metrics for AWS services?
A) Amazon CloudFront
B) Amazon CloudSearch
C) Amazon CloudWatch
D) Amazon Machine Learning (Amazon ML)
C) Amazon CloudWatch
Amazon CloudWatch is a monitoring service for AWS cloud resources and the applications you run on AWS. You can use Amazon CloudWatch to collect and track metrics, collect and monitor log files, set alarms, and automatically react to changes in your AWS resources.
For more information on AWS CloudWatch, please refer to the below URL: https://aws.amazon.com/cloudwatch/
A company needs to know which user was responsible for terminating several critical Amazon Elastic Compute Cloud (Amazon EC2) Instances. Where can the customer find this information?
A) AWS Trusted Advisor
B) Amazon EC2 instance usage report
C) Amazon CloudWatch
D) AWS CloudTrail logs
C) Amazon CloudWatch
Using CloudWatch trail , one can monitor all the API activity conducted on all AWS services. The AWS Documentation additionally mentions the following AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. With CloudTrail, you can log, continuously monitor, and retain account activity related to actions across your AWS infrastructure. CloudTrail provides event history of your AWS account activity, including actions taken through the AWS Management Console, AWS SDKs, command line tools, and other AWS services. This event history simplifies security analysis, resource change tracking, and troubleshooting.
For more information on AWS Cloudtrail, please refer to the below URL: https://aws.amazon.com/cloudtrail/
Which service should an administrator use to register a new domain name with AWS?
A) Amazon Route 53
B) Amazon CloudFront
C) Elastic Load Balancing
D) Amazon Virtual Private Cloud (Amazon VPC)
A) Amazon Route 53
Route53 allows for registration of new domain names in AWS The AWS Documentation additionally mentions the following Amazon Route 53 is a highly available and scalable cloud Domain Name System (DNS) web service. It is designed to give developers and businesses an extremely reliable and cost effective way to route end users to Internet applications by translating names like www.example.com into the numeric IP addresses like 192.0.2.1 that computers use to connect to each other. Amazon Route 53 is fully compliant with IPv6 as well.
For more information on AWS Route53, please refer to the below URL: https://aws.amazon.com/route53/
What is the value of having AWS Cloud services accessible through an Application Programming Interface (API)?
A) Cloud resources can be managed programmatically
B) AWS will always use be cost-optimized
C) All Application testing is managed by AWS
D) Customer-owned, On-premise infrastructure becomes programmable
A) Cloud resources can be managed programmatically
It allows developers to easily work with the various AWS resources programmatically.
For more information on the various programming tools available for AWS, please refer to the below URL: https://aws.amazon.com/tools/
Which of the following examples supports the cloud design principle “design for failure and nothing will fail’’?
A) Adding an Elastic Load Balancer in front of a Single Amazon Elastic Cloud Compute (Amazon EC2) instance
B) Creating and deploying the most cost-effective solution
C) Deploying an Application in multiple Availability Zones
D) Using Amazon CloudWatch alerts to monitor performance
C) Deploying an Application in multiple Availability Zones
Each AZ is a set of one or more data centers. By deploying your AWS resources to multiple Availability zones , you are designing with failure with mind. So if one AZ were to go down , the other AZ’s would still be up and running and hence your application would be more fault tolerant.
For more information on AWS Regions and AZ’s, please refer to the below URL: http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Concepts.RegionsAndAvailabilityZones.html
Which service allows an administrator to create and modify AWS user permissions?
A) AWS Config
B) AWS CloudTrail
C) AWS Key Management Service (AWS KMS)
D) AWS Identity and Access Management (IAM)
D) AWS Identity and Access Management (IAM)
AWS Identity and Access Management (IAM) is a web service that helps you securely control access to AWS resources. You use IAM to control who is authenticated (signed in) and authorized (has permissions) to use resources.
For more information on AWS IAM, please refer to the below URL: http://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html
Which AWS service automates infrastructure provisioning and administrative tasks for an analytical data warehouse?
A) Amazon Redshift
B) Amazon DynamoDB
C) Amazon ElastiCache
D) Amazon Aurora
A) Amazon Redshift
Amazon Redshift is a fully managed, petabyte-scale data warehouse service in the cloud. You can start with just a few hundred gigabytes of data and scale to a petabyte or more. This enables you to use your data to acquire new insights for your business and customers.
For more information on AWS Redshift, please refer to the below URL: http://docs.aws.amazon.com/redshift/latest/mgmt/welcome.html
Which tool can display the distribution of AWS spending?
A) AWS Organizations
B) Amazon Dev Pay
C) Amazon Trusted Advisor
D) AWS Cost Explorer
D) AWS Cost Explorer
Cost Explorer is a free tool that you can use to view your costs. You can view data up to the last 13 months, forecast how much you are likely to spend for the next three months, and get recommendations for what Reserved Instances to purchase. You can use Cost Explorer to see patterns in how much you spend on AWS resources over time, identify areas that need further inquiry, and see trends that you can use to understand your costs. You also can specify time ranges for the data, and view time data by day or by month.
For more information on the AWS Cost Explorer, please refer to the below URL: http://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/cost-explorer-what-is.html
How can the AWS Management Console be secured against unauthorized access?
A) Apply Multi-Factor Authentication (MFA)
B) Set up a Secondary Password
C) Request root access privileges
D) Disable AWS Console access
A) Apply Multi-Factor Authentication (MFA)
AWS Multi-Factor Authentication (MFA) is a simple best practice that adds an extra layer of protection on top of your user name and password.
For more information on the AWS MFA, please refer to the below URL: https://aws.amazon.com/iam/details/mfa/
Which AWS Cloud service is used to turn on Multi-Factor Authentication (MFA)?
A) AWS Identity and Access Management (IAM)
B) Amazon Elastic Compute Cloud (Amazon EC2)
C) AWS Config
D) Amazon Inspector
A) AWS Identity and Access Management (IAM)
You can use IAM in the AWS Management Console to enable a virtual MFA device for an IAM user in your account.
For more information on enabling AWS MFA, please refer to the below URL: http://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_enable_virtual.htm
A disaster recovery strategy on AWS should be based on launching infrastructure in a separate:
A) Subnet
B) AWS Region
C) AWS Edge location
D) Amazon Virtual Cloud (Amazon VPC)
B) AWS Region
Businesses are using the AWS cloud to enable faster disaster recovery of their critical IT systems without incurring the infrastructure expense of a second physical site. The AWS cloud supports many popular disaster recovery (DR) architectures from “pilot light” environments that may be suitable for small customer workload data center failures to “hot standby” environments that enable rapid failover at scale. With data centers in Regions all around the world, AWS provides a set of cloud-based disaster recovery services that enable rapid recovery of your IT infrastructure and data.
For more information on enabling AWS Disaster Recovery, please refer to the below URL: https://aws.amazon.com/disaster-recovery/
Which of the following is a factor when calculating Total Cost of Ownership (TCO) for the AWS Cloud?
A) The number of servers migrated to AWS
B) The number of users migrated to AWS
C) The number of passwords migrated to AWS
D) The number of keys migrated to AWS
A) The number of servers migrated to AWS
Since EC2 Instances carry a charge when they are running, you need to factor in the number of servers that need to be migrated to AWS.
For more information on AWS TCO, please refer to the below URL: https://aws.amazon.com/blogs/aws/the-new-aws-tco-calculator/
Which AWS service is used as a global content delivery network (CDN) service in AWS?
A) Amazon SES
B) Amazon CloudTrail
C) Amazon CloudFront
D) Amazon S3
C) Amazon CloudFront
Amazon CloudFront is a web service that gives businesses and web application developers an easy and cost effective way to distribute content with low latency and high data transfer speeds. Like other AWS services, Amazon CloudFront is a self-service, pay-per-use offering, requiring no long term commitments or minimum fees. With CloudFront, your files are delivered to end-users using a global network of edge locations.
For more information on CloudFront, please visit the Link: https://aws.amazon.com/cloudfront/
Which of the following is a fully managed NoSQL database service available with AWS?
A) Amazon RDS
B) Amazon DynamoDB
C) Amazon Redshift
D) Amazon MongoDB
B) Amazon DynamoDB
Amazon DynamoDB is a fast and flexible NoSQL database service for all applications that need consistent, single-digit millisecond latency at any scale. It is a fully managed cloud database and supports both document and key-value store models. Its flexible data model, reliable performance, and automatic scaling of throughput capacity, makes it a great fit for mobile, web, gaming, ad tech, IoT, and many other applications.
For more information on DynamoDB, please visit the Link: https://aws.amazon.com/dynamodb/
A company wants to store data that is not frequently accessed. What is the best and most cost efficient solution that should be considered?
A) Amazon Storage Gateway
B) Amazon Glacier
C) Amazon EBS
D) Amazon S3
B) Amazon Glacier
Amazon Glacier is a secure, durable, and extremely low-cost cloud storage service for data archiving and long-term backup. It is designed to deliver 99.999999999% durability, and provides comprehensive security and compliance capabilities that can help meet even the most stringent regulatory requirements.
For more information on Amazon Glacier, please visit the Link: https://aws.amazon.com/glacier/
You are currently hosting infrastructure and most of the EC2 instances are near 90 – 100% utilized. What type of EC2 instances would you utilize to ensure costs are minimized?
A) Reserved Instances
B) On-Demand Instances
C) Spot Instances
D) Regular Instances
A) Reserved Instances
When you have instances that will be used continuously and throughout the year, the best option is to buy reserved instances. By buying reserved instances, you are actually allocated an instance for the entire year or the duration you specify with a reduced cost.
For more information on Reserved Instances, please visit the Link: https://aws.amazon.com/ec2/pricing/reserved-instances/
What is the ability provided by AWS to enable fast, easy, and secure transfers of files over long distances between your client and your Amazon S3 bucket?
A) File Transfer
B) HTTP Transfer
C) Transfer Acceleration
D) Transfer S3
C) Transfer Acceleration
Amazon S3 Transfer Acceleration enables fast, easy, and secure transfers of files over long distances between your client and an S3 bucket. Transfer Acceleration takes advantage of Amazon CloudFront’s globally distributed edge locations. As the data arrives at an edge location, data is routed to Amazon S3 over an optimized network path.
For more information on Reserved Instances, please visit the Link: http://docs.aws.amazon.com/AmazonS3/latest/dev/transfer-acceleration.html
As per the AWS Acceptable Use Policy, penetration testing of EC2 instances:
A) May be performed by AWS, and will be performed by AWS upon customer request
B) May be performed by AWS, and is periodically performed by AWS
C) Are expressly prohibited under all circumstances
D) May be perfumed by the customer on their own instances with prior authorization from AWS
E) May be perfumed by the customer on their own instances only if performed by EC2 instances.
D) May be perfumed by the customer on their own instances with prior authorization from AWS
You need to take prior authorization from AWS before doing a penetration test on EC2 Instances.
Please refer to the below URL for more details. https://aws.amazon.com/security/penetration-testing/
The Trusted Advisor service provides insight regarding which four categories of an AWS account?
A) Security, Fault Tolerance, High Availability and Connectivity
B) Security, Access Control, High Availability and Performance
C) Performance, Cost Optimization, Security and Fault Tolerance
D) Performance, Cost Optimization, Access Control and Connectivity
C) Performance, Cost Optimization, Security and Fault Tolerance
Screenshot in below AWS Doc shows what services the Trusted Advisor Dashboard offers.
For more information on the AWS Trusted Advisor, please visit the Link: https://aws.amazon.com/premiumsupport/trustedadvisor/
A company is deploying a two-tier, highly available web application to AWS. Which service provides durable storage for static content while utilizing lower Overall CPU resources for the web tier?
A) Amazon EBS volume
B) Amazon S3
C) Amazon EC2 instance store
D) Amazon RDS instance.
B) Amazon S3
Amazon S3 is the default storage service that should be considered for companies. If provides durable storage for all static content.
For more information on AWS S3, please visit the Link: https://aws.amazon.com/s3/
What best describes the “Principal of Least Privilege”? Choose the correct answer from the options given below?
A) All users should have the same baseline permissions granted to them to use basic AWS services
B) Users should be granted permission to access only the resources they need to do their assigned job
C) Users should submit all access requests in written so that there is a paper trail of who needs access to different AWS resources
D) Users should always have a little more access granted to them than they need, just in case they end up needing it in the future
B) Users should be granted permission to access only the resources they need to do their assigned job
The principle means giving a user account only those privileges which are essential to perform its intended function. For example, a user account for the sole purpose of creating backups does not need to install software: hence, it has rights only to run backup and backup-related applications.
For more information on principle of least privilege, please refer to the following Link: https://en.wikipedia.org/wiki/Principle_of_least_privilege
Which of the below mentioned services can be used to host virtual servers in the AWS Cloud?
A) AWS IAM
B) AWS Server
C) AWS EC2
D) AWS Regions
C) AWS EC2
Amazon Elastic Compute Cloud (Amazon EC2) is a web service that provides secure, resizable compute capacity in the cloud. It is designed to make web-scale cloud computing easier for developers.
For more information on AWS EC2, please refer to the following Link: https://aws.amazon.com/ec2/