AWS SA Professional Exam Flashcards

1
Q

How long does it take to get data out of Glacier?

A

It can take AT LEAST 3 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What storage type provides the ability to create point-in-time snapshots of data volumes?

A

EBS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which three services have automated backups?

A

RDS

Elasticache (Redis only)

Redshift

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which service does not have automated backups?

A

EC2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In Read Replicas vs Multi-AZ; Which is used for scaling?

A

Read Replicas

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In Read Replicas vs Multi-AZ; Which is used for DR?

A

Multi-AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many read replicas can you have?

A

Up to 5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can you have read replicas in different regions?

A

Yes - With the exception of SQL Server and Oracle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Are read replicas synchronous or asynchronous?

A

Asynchronous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

[T/F] Read Replicas can be made off of Multi-AZ’s database

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

[T/F] Read Replicas can be in Multi-AZ.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Can you have a read replica of a read replica? Will this increase latency?

A

Yes, but only for MySQL and this will increase latency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DB Snapshots and Automated backups [can/cannot] be taken of read replicas.

A

Can - but are not enabled by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

If you application does not require transaction support, Atomicity, Consistency, Isolation, Durability (ACID) compliance, joins & SQL… What should you consider using instead of RDS?

A

DynamoDB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the 4 different Storage Gateway Types?

A

File Gateway
Gateway-Cached Volumes
Gateway-Stored Volumes
Gateway-Virtual Tape Library

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How long does it take to access virtual tapes in your virtual tape library?

A

Instantaneous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How long does it take to access your virtual tapes from your virtual tape shelf?

A

It can take 24 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How is Storage Gateway encrypted?

A

Encrypted using SSL for transit
Encrypted at rest in S3 using AES-256

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

How are Gateway-Stored Volumes stored?

A

Stored data as Amazon EBS Snapshots in S3.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Gateway Storage snapshots [can/cannot] be scheduled.

A

Gateway Storage Volumes can be scheduled.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Gateway Storage bandwidth [can/cannot] be throttled.

A

Gateway storage can be throttled - which is great for remote sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

_______ make it easy to group your resources using the tags that are assigned to them. You can group resources that share one or more tags.

A

Resource groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

_________ allows you to get volume discounts on all your accounts.

A

Consolidated billing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

With consolidated billing, _____ is on a per account and per region basis but can be aggregated into a single bucket in the paying account.

A

CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

The contract length for Reserved Instances is between __ and __ years.

A

1 & 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What are the 3 types of RIs?

A

-Standard
- Convertible
- Scheduled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Which of the RIs offers the largest discount?

A

All Upfront RIs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Standard RIs for EC2 can be modified, but only if they are in the same _______ and only if the ______ factors are equal and only for the Linux operating system.

A

Family; Normalization;

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

You can switch EC2 RIs between ______, but not between ______.

A

AZs; Regions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

EC2 RIs [can/cannot] be sold on the marketplace.

A

can

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Can you have reserved RDS instances?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

With RDS reserved instances, you can move ______ but not _______.

A

AZ’s but not regions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Elastic Beanstalk [can/cannot] provision RDS instances.

A

can

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Elastic Beanstalk [does/does not] support IAM.

A

does

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

You have ___ access to the resources under Elastic Beanstalk.

A

full

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Elastic Beanstalk code is stored in ___.

A

S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

With Elastic Beanstalk, ________ environments are allowed to support version control.

A

multiple

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Elastic Beanstalk [can/cannot] roll back changes.

A

can

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

With Elastic Beanstalk, ______ the changes from ____ repositories are replicated.

A

Only the changes from Git repositories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Amazon Elastic Beanstalk supports which AMIs?

A

Linux AMI & Windows 2012 R2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

OpsWork consists of ________ and ________.

A

Stacks; Layers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

OpsWorks runs on _____.

A

Chef

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

In OpsWork, layers contain AWS resources such as…

A

EC2 ELB RDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

In OpsWork, layers are like _____, ______, and _______ layer.

A

Web; Application; Database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

In OpsWork, each stack will have how many layers?

A

1 or more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

What happens to any EC2 instance added outside of the OpsWork stack in ELB?

A

OpsWork will remove

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

CloudFormation uses ________ to resolve dependency between resource creation.

A

wait condition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What is mandatory for a CloudFormation template?

A

Resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

With CloudFormation, you can create multiple ____ inside of one template.

A

VPCs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

If you wanted to connect VPCs in your CloudFormation template. You can enable _____________ using CloudFormation.

A

VPC Peering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

CloudFormation supports _____, ________, and _____ scripts.

A

Chef; Puppet; Bootstrap

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

With CloudFormation, you can use ________ to output data.

A

Fn:GetAtt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

By default, the _______________ feature is enabled in CloudFormation.

A

“automatic rollback on error”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

CloudFormation itself costs what?

55
Q

_______ is completely supported with CloudFormation. This includes creating new hosted zones or updating existing ones.

56
Q

If you are accessing services using HTTPs endpoints (think DynamoDB, S3) use public ____.

57
Q

Direct Connect. If you are accessing VPCs using private IP address ranges, use private ______.

58
Q

In the US, you need ___ direct connect connection(s) to connect to all 4 US regions.

59
Q

Does data transferred between regions go over public internet?

60
Q

Layer 2 connections [are/are not] supported by direct connect.

61
Q

What is the difference between a Customer Gateway and a Virtual Private Gateway?

A

Customer Gateway - Customer side Virtual Private Gateway - AWS Side

62
Q

Which ports does EC2-VPC ELB support?

63
Q

Can you assign an Elastic IP to an Elastic Load Balancer?

64
Q

You can load balance to the _________ of your domain name with ELBs.

65
Q

If you have multiple SSL certifications you should use ________ Elastic Load Balancers, unless you have a wildcard certificate.

66
Q

A placement group [can/cannot] span availability zones but it [can/cannot] span subnets, provided that they are in the same VPC.

A

cannot; can

67
Q

You [can/cannot] move existing instances to placement groups.

68
Q

How can you reduce bottlenecks with NATs?

A

Scale up and Scale out; If you scale out, add an additional NAT & subnet and migrate half your workload to the new subnet.

69
Q

Can you peer VPCs from different regions?

70
Q

If you peer two VPCs, what needs to be updated?

A

Security groups & make sure that a route table has been created in both VPCs to allow traffic.

71
Q

If your application is more oriented toward indexing and querying data, it may be better to use this Amazon DB for your needs.

72
Q

If your application has number BLOB data (binary large objects) then what would be a good choice for storage?

73
Q

If you need fully automated scaling, which DB is best?

74
Q

If you’re looking to scale your database up you should use ________, if you’re looking to scale out use ________.

A

RDS; DynamoDB

75
Q

Databases that require Joins and/or complex transactions should look to utilize what database options with AWS?

A

Amazon RDS or Amazon EC2 with self-managed database

76
Q

If you plan to store very large amounts of data that are infrequently accessed (Low I/O rates) where should you store that data?

77
Q

Use _______ to optimize both GETs & PUTs with S3.

A

Parallelization

78
Q

S3 stores data in __________ order so you have to __________ the data.

A

Lexicographical; randomize

79
Q

You can secure S3 by doing what 3 things?

A
  • Using Bucket policies
  • Using MFA Delete
  • Backing your Bucket Up to Another S3 Bucket Owned by a separate account
80
Q

CloudHSM is _____ tenanted.

A

Single Tenanted (1 physical device, for you only)

81
Q

CloudHSM must be used in _____.

82
Q

You can use ___________ to connect o a CloudHSM from another VPC.

A

VPC Peering

83
Q

IF you need fault tolerance with your CloudHSM, you need to build a ________.

84
Q

Which databases & warehouses CloudHSM can integrate with:

A
  • RDS (Oracle & SQL)
  • Redshift
85
Q

You monitor CloudHSM via ______.

86
Q

The two types of directory services are ____ and ________.

A

AD Connector; Simple AD

87
Q

By default, CloudWatch Logs will store your log data for how long?

A

Indefinitely

88
Q

The default CloudWatch Alarm History is only how many days?

89
Q

Step 1 of 3 for developing an Identity Broker is:

A

Develop an Identity Broker to communicate with LDAP & AWS STS

90
Q

Step 2 of 3 for developing an Identity Broker is:

A

Identity Broker always communicates with LDAP first, THEN with AWS STS

91
Q

Step 3 of 3 for developing an Identity Broker is:

A

Application then gets temporary access to AWS resources.

92
Q

AWS Security Token Service returns which four values upon request for a federated token?

A

A Token
A Secret Access Key
Access Key ID
A Duration

93
Q

True or False: To minimize the attack surface area, servers can be placed behind a bastion host, through which all traffic must pass.

94
Q

If you want Intrusion Prevention AND Intrusion Detection you should use what?

A

A IPS tool

95
Q

SNS Can SNS push notification to mobile devices (“Mobile Push”)?

96
Q

What elements of a CloudFormation template are required?

97
Q

How can I configure a CloudFormation template to pause while an application is configured on a template-created EC2 instance?

A

Using wait conditions
Using creation policies
cfn-signal CreationPolicies are the preferred mechanism

98
Q

Can you copy EBS snapshots across regions?

99
Q

ElasticBeanstalk rolling update types

A
  • based on health
  • based on time
  • Immutable
100
Q

ElasticBeanstalk environment types

A
  • single-instance
  • load-balancing
  • autoscaling
101
Q

How to preserve/backup CloudFormation resource when the stack is deleted

A

DeletionPolicy attribute

102
Q

In which parts of CloudFormation template can intristic function be used?

A

resource properties,
outputs,
metadata attributes
update policy attributes

103
Q

Simple, automated way to back up data stored on Amazon EBS volumes

A

Amazon Data Lifecycle Manager (DLM) for EBS Snapshots

104
Q

Two ways to install security update on the running OpsWorks instances

A
  • Create and start new instances to replace your current online instances. Then delete the current instances. - On Linux-based instances in Chef 11.10 or older stacks, run the Update Dependencies stack command
105
Q

What is CFN Hup?

A

The cfn-hup helper is a daemon that detects changes in resource metadata and runs user-specified actions when a change is detected.

106
Q

Three CI/CD stages

A
  • Source
  • Build/test
  • Deploy
107
Q

ElasticBeanstalk source bundle requirements

A
  • Consist of a single ZIP file or TAR file
  • Not exceed 512 MB
  • Not include a parent folder or top-level directory
108
Q

Describe durability in Kinesis

A

Kinesis synchronously replicates the streaming data across three data centres within single AWS region and preserves the data for up to 24H

109
Q

How do you scale Kinesis?

A

Adding more shards

110
Q

What’s the processing rate of 1 shard in Kinesis

A

1MB/sec data input and 2MB/sec data output

111
Q

Which CloudFormation resource is used to create nested stacks?

A

AWS::CloudFormation::Stack

112
Q

Three source repositories of CodeDeploy

A
  • Github
  • S3
  • Bitbucket
113
Q

Two types of deployments in CodeDeploy

A
  • in-place
  • blue/green
114
Q

Directory for awslogs service

A

/etc/awslogs/

115
Q

What is the maximum amount of data that can be stored in a Gateway-Stored volume?

116
Q

How to ensure Redshift is capable of parallel processing?

A

By configuring workload management (WLM) in Amazon Redshift

117
Q

What is HLS?

A

HTTP Live Streaming - protocol that segments media files for optimization during streaming. HLS enables media players to play segments with the highest quality resolution that is supported by their network connection during playback

118
Q

What is WOWZA Streaming Engine

A

Wowza Streaming Engine is the gold standard of customizable streaming server software for building and delivering professional-grade streaming at any scale

119
Q

Can you modify DHCP options in VPC?

A

If you want your VPC to use a different set of DHCP options, you must create a new set and associate them with your VPC.

120
Q

What to do when you receive a capacity error when launching an instance in a placement group

A

stop and start all of the instances in the placement group, and try the launch again

121
Q

Can read replica of RDS on VMware be assigned ty any region?

122
Q

Two use cases for HLS

A

view an Amazon Kinesis video stream for: - live playback - view archived video

123
Q

Is retention schedule carried over to the snapshot copy?

124
Q

When can you enable EFS encryption at rest?

A

When creating EFS file system

125
Q

When can you enable encryption in transit on EFS

A

When mounting the EFS volume

126
Q

Can you snapshot instance-store volume?

A

NO. Other method need to be used (backing up to EBS)

127
Q

What is TLS?

A

Transport Layer Security

128
Q

What is ETL shortcut form?

A

Extract, transform, load

129
Q

Where you can put policy variables in CF?

A
  • in the Resource element
  • in string comparisons in the Condition element
130
Q

Default maximum number of customer managed policies in an AWS account

131
Q

Default maximum number of Groups in AWS account

132
Q

Default maximum number of roles in AWS account

133
Q

Maximum number of users in AWS account

A

5000 (and cannot be changed)

134
Q

3 Support plans in AWS

A
  • Developer
  • Business
  • Enterprise