Cloud Practitioner Flashcards

1
Q

Amazon Inspector

A

Amazon Inspector can be used to analyze potential security threats for an Amazon EC2 instance against an assessment template with predefined rules. It does not provide historical data for configurational changes done to AWS resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AWS Config

A

AWS Config can be used to audit, evaluate configurations of AWS resources. If there are any operational issues, AWS Config can be used to retrieve configurational changes made to AWS resources that may have caused these issues. It can also keep multiple date-stamped versions in a reviewable history.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AWS Artifact

A

AWS Artifact is a comprehensive resource center to have (downloadable) access to the AWS auditor-issued reports and security and compliance documentation from several renowned independent standard organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AWS Resource Center

A

AWS Resource Center is a repository of tutorials, whitepapers, digital training, and project use cases that aid in learning the core concepts of AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS Service Catalog

A

AWS Service Catalog allows organizations to create and save their own IT service catalogs for further use, but they have to be approved by AWS. IT service catalogs can be multi-tiered applications architectures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which service to use to optimize performance for global users to transfer large-sized data objects to a centralized S3 bucket?

A

Enable S3 Transfer Acceleration on the Amazon S3 bucket.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When to use Multi-part upload?

A

For all data objects exceeding 100 megabytes. (For better performance, S3 transfer acceleration should be enabled.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

AWS X-Ray

A

AWS X-Ray is a service that collects data about requests that your application serves and provides tools that you can use to view, filter, and gain insights into that data to identify issues and opportunities for optimization. It helps developers analyze and debug production, distributed applications, such as those built using a microservices architecture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AWS Cloudwatch vs AWS X-Ray

A

X-Ray can help with debugging. Cloudwatch primarily monitors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Business vs Enterprise Support

A

Enterprise support adds 15 minute response time for business-critical system outages, as well as consultative guidance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which service can detect users’ personal credit card numbers from data stored in Amazon S3?

A

Amazon Macie

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which AWS managed database service provides processing power up to 5x faster than a traditional MySQL database?

A

Aurora

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AWS CodeStar

A

AWS CodeStar enables you to develop, build, and deploy applications on AWS quickly. AWS CodeStar provides a unified user interface, enabling you to manage your software development activities in one place easily.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

AWS CodeArtifact

A

AWS CodeArtifact is a fully managed artifact repository service that makes it easy for organizations of any size to securely store, publish, and share software packages used in their software development process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Amazon Athena

A

Amazon Athena queries data directly from S3, Athena is compatible with many formats such as CSV, JSON, ORC, AVRO, and Parquet, but Athena can only query in SQL.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

AWS Trusted Advisor

A

AWS Trusted Advisor checks for service usage for all the resources within AWS Cloud and provides notifications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Amazon Detective

A

Amazon Detective uses machine learning and graph theory capability on automatically collected log data to help you conduct faster and efficient security investigations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

EFS or S3 for Linux?

A

Storing files (even petabytes of data) in a Linux-based workload is best done with EFS. S3 is not suitable for deploying Linux-based workloads and uses objects not files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Cost Explorer compared to Pricing Calculator?

A

Cost Explorer helps users to view graph displays of cost of your billing data and analyze them & get a forecast for likely spends for the next 12 months. The scenario is more to do with clients getting a cost estimate of different AWS services before they move to AWS cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Cost Explorer compared to Pricing Calculator?

A

Through AWS Pricing Calculator a client can estimate costs that he will incur for various AWS services that he wishes to use. The pricing calculator guides the user through a set of well defined service parameters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Amazon Redshift

A

Automates infrastructure provisioning and admin tasks for an analytical data warehouse. Redshift is a fully managed, petabyte scale data warehouse. You can start with small data and scale up to large data, allowing you to acquire new insights for your business and customers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

AWS Audit Manager

A

Audit Manager is used for auditing AWS usage and building audit reports for risk & compliance. This will not generate AWS security & compliance documents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

AWS License Manager

A

AWS License Manager provisions & tracks license usage across multiple AWS accounts and also on-premises environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

AWS Cloud HSM

A

AWS Cloud HSM (Hardware Security Model) for generating and managing encryption keys on the AWS cloud. It can be used for offloading SSL processing for web servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

AWS Secrets Manager

A

AWS Secrets Manager can be used to implement password rotation policy for secrets stored. Not suitable for SSL processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

S3 Glacier vs Glacier Deep Archive

A

Standard is 3-5 Hrs vs < 12 Hrs. Expedited is 1-5 Mins vs Not available.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

AWS CodeCommit

A

Data store to store source code, scripts, etc., accessible over the internet, and encrypts at rest and in transit. Q about startup company wants to store their source code on open-source repository publicly accessible but secured…

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Acceptable use for penetration testing of EC2 instances..

A

Can be performed by the customer (without prior AWS approval), provided they work with the list of services mentioned by AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Trusted Advisor - what 5 categories does it provide insight for?

A

Cost Optimization, Performance, Security, Fault Tolerance, Service Limits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

AWS CodeDeploy

A

managed service that automates software deployment on a large scale to EC2 instances and on-premise services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

AWS Personal Health Dashboard

A

AWS Personal Health Dashboard is a tool that shows the status of AWS services running the user-specific resources. It is a graphical representation that sends alerts / notifications of any personal pending issues, planned changes, and scheduled activities.

32
Q

Savings Plans services

A

Flexible discount pricing models that offer reduced rates for 1 to 3 year commitments - confined to EC2, Fargate, and Lambda

33
Q

CloudFront vs Global Accelerator - Static IP

A

Global Accelerator provides static public IP addresses. CloudFront uses domain name and can resolve to dynamic public IP addresses.

34
Q

AWS Systems Manager

A

AWS Systems Manager allows users to control their AWS resources by unifying services into a user interface. They can view, automate, and monitor tasks - across AWS regions and by account.

35
Q

Which service can collect important metrics from AWS RDS and EC2 instances?

A

Amazon CloudWatch

36
Q

An application has been deployed to multiple regions to improve performance. How to best achieve the optimal regional endpoint to increase the availability of the application?

A

Use Global Accelerator

37
Q

What endpoints are available for standard Global Accelerator?

A

Network Load Balancers, Application Load Balancers, EC2 Instances, or Elastic IP Addresses.

38
Q

Which AWS service can be used to manage infrastructure as code?

A

AWS CloudFormation

39
Q

Which service can be used to create steps to automate build, test, and deployment for a web application?

A

AWS CodePipeline

40
Q

What is AWS CodeCommit used for?

A

CodeCommit is used to store deployment codes.

41
Q

What is AWS CodeDeploy used for?

A

CodeDeploy is used for deployment of code to resources.

42
Q

What is AWS CodeBuild used for?

A

CodeBuild is used to test and build application code.

43
Q

CloudWatch vs CloudTrails - re API calls

A

CloudTrails logs API calls; CloudWatch does not.

44
Q

Which service can be used to retreive configuration changes to an AWS resource causing operational issues?

A

AWS Config. (NOT Amazon Inspector)

45
Q

Amazon Workspaces

A

Allows users to log in remotely to access Windows or Linux desktops from any location.

46
Q

Which service can be used to create a customized portfolio that will help users for a quick deployment?

A

AWS Service Catalog. Portfolio is the key - Code Deploy automates code deployment, but is not used for creating a portfolio of resources.

47
Q

Which services are used by AWS Service Catalog to create a portfolio of products?

A

AWS IAM and AWS CloudFormation

48
Q

Which service provides location-based web personalization using geolocation headers?

A

Amazon CloudFront. (NOT Route 53)

49
Q

Route 53 - what routing policy to use when one location is experiencing degraded service?

A

Failover routing policy. (NOT latency-based or geo-location)

50
Q

What service to use to re-engineer the application by decoupling the components?

A

Amazon SQS. (NOT Load Balancing - this is for distributing workloads across EC2 instances but not for refactoring or re-engineering.)

51
Q

Kinesis Data Streams vs Kinesis Data Analytics?

A

Data Streams is an ingestion service that provides data streams to consumers. Data Analytics is a fully managed solution using SQL to process data from a data stream.

52
Q

AWS Elastic Beanstalk

A

Developers simply upload their application and Beanstalk automatically handles the deployment details of scaling, provisioning and health monitoring.

53
Q

What service to use for launching a quick simple application or website in AWS Cloud with pre-configured resources?

A

Amazon LightSail. (NOT Beanstalk, which uses more resources to support an application.) For quick and simple and preconfigured, use LightSail.

54
Q

What 3 actions can Amazon Macie perform on users’ data?

A

Discover, Monitor, Protect

55
Q

Facts about Cost Explorer

A

12 months back and forward / Provides trends to understand your costs / Usage-based forecasting

56
Q

Network ACLs - Default Count - How many?

A

200 Network ACLs per VPC spanning multiple AZs

57
Q

List 4 Support Plans

A

Basic, Developer, Business, Enterprise - - - that’s it, only 4.

58
Q

Subnets - Route Tables - Default Count - How many?

A

200 Route tables are supported per VPC - a soft limit which can be adjusted. Each Route Table supports 50 non-propagated routes and 100 BGP advertised propagated routes.

59
Q

Which tool can check service limits for resources launched in the aws cloud?

A

AWS Trusted Advisor

60
Q

Can user run Oracle DB and maintain full control?

A

Yes - Run Oracle SQL DBase using Amazon EC2.

61
Q

CodePipeline typical use case?

A

To orchestrate and automate the various phases involved int he release of application undates in-line with a predefined release model.

62
Q

Snow transfer limitations:

A

Snowcone (14 TB w/ ssd; 8 TB w/o) / Snowball Edge Compute Optimized (42 TB) / Snowball Edge Storage Optimized (100 TB; 80 TB usable, w/ 24 vCPUs and 32 GB memory for in-transit processing) / Snowmobile (100 Petabytes)

63
Q

AWS Budgets and utilization triggers

A

AWS Budgets allows you to set reservation utilization budgets that define a threshold and send alerts when utilization falls below that threshold

64
Q

What service provides a POSIX compliant, NFS file storage solution?

A

AWS Elastic File System (EFS)

65
Q

Aurora or Redshift - which one can utilize standard SQL queries and existing BI tools?

A

Redshift. / Aurora uses MySQL and PostgreSQL.

66
Q

Aurora or Redshift - which one uses OLAP?

A

Redshift. / Aurora uses OLTP

67
Q

Priority of the job queue is set by the Priority Parameter of the Job Queue

A

Not the Priority Parameter of the Job Definition.

68
Q

What resources can WAF integrate with?

A

Application Load Balancer / CloudFront / API Gateway / AppSync

69
Q

Are Savings Plans available in all regions?

A

No - Savings Plans are not available in China

70
Q

Examples of CloudTrail Events include?

A

Actions taken in the AWS Management Console, AWS Command Line Interface (CLI), AWS SDKs and AWS APIs.

71
Q

What does a VPC Security Group do?

A

A security group is a virtual firewall that controls inbound and outbound traffic for an Amazon EC2 instance. By default, a security group denies all inbound traffic and allows all outbound traffic.

72
Q

What does a VPC Subnet do?

A

A subnet is a section of a VPC in which you can group resources based on security or operational needs.

73
Q

What does a VPC Network Access Control List (NACL) do?

A

A network access control list (ACL) is a virtual firewall that controls inbound and outbound traffic at the subnet level.

74
Q

What does a VPC Internet Gateway do?

A

An internet gateway is a connection between a VPC and the internet. It allows public traffic from the internet to access a VPC.

75
Q
A