CG - Practice Test 2 Flashcards
S3 encryption if you want to maintain full end to end control of the encryption/decryption of objects and assure that only encrypted objects are transimitted over the internet to Amazon S3
Client Side encryption - provide a client side master key to the Amazon S3 Encryption Client
One way to offload your Ec2 instances
installing SSL certificates on your ELBs
iptables
OS level logging tool that can log events to Cloud watch or S3 - is a command-line firewall utility that uses policy chains to allow or block traffic
Cluster Placement groups can span VPCs but not Azs- true or false
true
inter region vpc peering
creating a vpc connection between vps in different regions
You cannot have more thane one vpc peering connection between the same VPCs at the same time - t or f
true
Transfers between S3 buckets or from Amazon S3 to EC2 within the same AWS Region are free. T or F
true
All S3 costs are based on the volume of data regardless of how it is handled. - T or F
False
Data transfer into S3 from the Internet doesn’t incur any costs - T or F
true
The total costs for data transfer out from S3 to CloudFront depend on the monthly volume of data, i.e a tiered pricing applies: The more data goes out, the more you save. T or F
false
Transferring up to one GB of data per month out of S3 to end customers over the public internet is free. T or F
true
If your application requires more compute resources than the largest DB instance class or more storage than the maximum allocation, you can:
implement partitioning thereby spreading your data across multiple DB instances
Multi-AZ will help with performance - T or F
false, it will only help resiliency
RDS autoscaling is only available with which DB
Aurora
Z2 is a valid instance type - T or F
false