Cloud Practitioner - PRACTICE 3 Flashcards
Which AWS service or feature can be used to restrict the individual API actions that users and roles in each member account can access?
- Amazon Macie
- AWS Organizations
- AWS Shield
- AWS IAM
AWS Organizations
AWS Organizations offers Service control policies (SCPs) which are a type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions (API actions) for all accounts in your organization.
Which AWS service can be used to track the activity of users on AWS?
- AWS CloudTrail
- AWS Directory Service
- Amazon Inspector
- Amazon CloudWatch
AWS CloudTrail
AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. With CloudTrail, you can log, continuously monitor, and retain account activity related to actions across your AWS infrastructure.
A user needs a quick way to determine if any Amazon EC2 instances have ports that allow unrestricted access. Which AWS service will support this requirement?
- VPC Flow Logs
- AWS Shield
- AWS Trusted Advisor
- AWS CloudWatch Logs
AWS Trusted Advisor
Access to the ports on an Amazon EC2 instance is controlled through security groups. AWS Trusted Advisor scans the security groups in your account to see if any security groups allow unrestricted access to any ports.
A company has a website that delivers static content from an Amazon S3 bucket to users from around the world. Which AWS service will deliver the content with low latency?
- AWS Lambda
- Amazon CloudFront
- AWS Elastic Beanstalk
- AWS Global Accelerator
Amazon CloudFront
Amazon CloudFront is a content delivery network (CDN) and can use an Amazon S3 bucket configured as a static website as an origin for the content is caches globally. CloudFront reduces latency for global users by serving the requested content from a local cache.
Which AWS service or component allows inbound traffic from the internet to access a VPC?
- NAT Gateway
- Internet gateway
- VPC Route Table
- Virtual Private Gateway
Internet Gateway
An Internet gateway is attached to a VPC and allows inbound traffic from the internet to access the VPC. It is also used as a target in route tables for outbound internet traffic.
A company plans to connect their on-premises data center to the AWS Cloud and requires consistent bandwidth and performance. Which AWS service should the company choose?
- AWS VPN
- Amazon Connect
- AWS Direct Connect
- Amazon CloudFront
AWS Direct Connect
AWS Direct Connect is a cloud service solution that makes it easv to establish a dedicated network connection from your premises to AWS.
A manager is planning to migrate applications to the AWS Cloud and needs to obtain AWS compliance reports. How can these reports be generated?
- Download the reports from AWS Secrets Manager.
- Contact the AWS Compliance team.
- Create a support ticket with AWS Support.
- Download the reports from AWS Artifact.
AWS Artifact
AWS Artifact is your go-to, central resource for compliance-related
information that matters to you. It provides on-demand access to AWS’ security and compliance reports and select online agreements.
A company has been using an AWS managed IAM policy for granting permissions to users but needs to add some permissions. How can this be achieved?
- Create a rule in AWS WAF.
- Create a custom IAM policy.
- Edit the AWS managed policy.
- Create a Service Control Policy.
Create a custom IAM policy
AWS managed policies cannot be edited so if you need to add permissions to users that are not granted in the policy you must create your own custom IAM policy.
Which AWS service or feature can be used to capture information about inbound and outbound IP traffic on network interfaces in a VPC?
- Internet Gateway
- AWS CloudTrail
- VPC Endpoint
- VPC Flow Logs
VPC Flow Logs
VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC. Flow log data can be published to Amazon Cloud Watch Logs or Amazon S3. After you’ve created
Which AWS services can be used as infrastructure automation tools? (Select TWO.)
- AWS CloudFormation
- Amazon CloudFront
- AWS Batch
- AWS Ops Works
- Amazon QuickSight
CloudFormation & OpsWorks
AWS CloudFormation provides a common language for you to model and provision AWS and third party application resources in your cloud environment. AWS OpsWorks is a configuration management service that provides managed instances of Chef and Puppet. Chef and Puppet are automation platforms that allow you to use code to automate the configurations of your servers.
What technology enables compute capacity to adjust as loads change?
- Load balancing
- Automatic failover
- Round robin
- Auto Scaling
Auto Scaling
Auto Scaling allows the dynamic adjustment of provisioned resources based on demand. For instance, you can use Amazon EC2 Auto Scaling to launch additional EC2 instances when CloudWatch metrics report the CPU utilization has reached a certain threshold.
How can a company separate costs for storage, Amazon EC2, Amazon S3, and other AWS services by department?
- Add department-specific tags to each resource
- Create a separate VPC for each department
- Create a separate AWS account for each department
- Use AWS Organizations
Add department-specific tags to each resource
A tag is a label that you or AWS assigns to an AWS resource. Each tag consists of a key and a value. For each resource, each tag key must be unique, and each tag key can have only one value.
Which AWS Support plan provides access to architectural and operational reviews, as well as 24/7 access to Cloud Support Engineers through email, online chat, and phone?
- Basic
- Business
- Developer
- Enterprise
Enterprise
Only the enterprise plan provides Well-Architected Reviews and Operational Reviews. 24/7 access to Cloud Support Engineers through email, online chat,
and phone is offered on the business and enterprise plans.
Under the AWS shared responsibility model, which of the following is an example of security in the AWS Cloud?
- Managing edge locations
- Physical security
- Firewall configuration
- Global infrastructure
Firewall Configuration
Firewall configuration is an example of “security in the cloud”. This is the customer’s responsibility, not an AWS responsibility.
Which AWS service provides on-demand downloads of AWS security and compliance reports?
- AWS Directory Service
- AWS Artifact
- AWS Trusted Advisor
- Amazon Inspector
AWS Artifact
AWS Artifact is the go-to, central resource for compliance-related
information that matters to you. It provides on-demand access to AWS’ security amd compliance reports and select online agreements
Which Amazon EC2 pricing model is the most cost-effective for an always-up, right-sized database server running a project that will last 1 year?
- On-Demand Instances
- Convertible Reserved Instances
- Spot Instances
- Standard Reserved Instances
Standard Reserved Instances
Reserved Instances (RIs) provide you with a significant discount (up to 72%) compared to On-Demand instance pricing. Standard reserved instances offer the most cost savings. RIs are based on a 1 or 3 year contract so they are suitable for workloads that will run for the duration of the contract period.
Which feature enables fast, easy, and secure transfers of files over long distances between a client and an Amazon S3 bucket?
- S3 Static Websites
- S3 Copy
- Multipart Upload
- S3 Transfer Acceleration
Amazon S3 Transfer Acceleration
Amazon S3 Transfer Acceleration enables fast, easy, and secure transfers of files over long distances between your client and your Amazon S3 bucket.
S3 Transfer Acceleration leverages Amazon CloudFront’s globally distributed AWS Edge Locations.
Under the AWS shared responsibility model what is AWS responsible for? (Select TWO.)
- Physical security of the data center
- Replacement and disposal of disk drives
- Configuration of security groups
- Patch management of operating systems
- Encryption of customer data
Physical security of the data center & Replacement and disposal of disk drives
AWS are responsible for “Security of the Cloud” and customers are responsible for “Security in the Cloud”.
Which AWS service is known as a “serverless” service and runs code as functions triggered by events?
- Amazon ECS
- AWS Lambda
- Amazon CodeDeploy
- Amazon Cognito
AWS Lambda
AWS Lambda lets you run code as functions without provisioning or managing servers. Lambda-based applications (also referred to as serverless applications) are composed of functions triggered by events. With serverless computing, your application still runs on servers, but all the server management is done by AWS.
Which statement best describes Amazon Route 53?
- Amazon Route 53 is a service that enables routing within VPCs in an account
- Amazon Route 53 is a highly available and scalable Domain Name System (DNS) service
- Amazon Route 53 enables hybrid cloud models by extending an organization’s on-premise networks into the AWS cloud
- Amazon Route 53 is a service for distributing incoming connections between a fleet of registered EC2 instances
Amazon Route 53 is a highly available and scalable Domain Name System (DNS) service
Amazon Route 53 is a highly available and scalable cloud Domain Name System (DNS) web service. It is designed to give developers and businesses an extremely reliable and cost effective way to route end users to Internet applications by translating names like www.example.com into the numeric IP addresses like 192.0.2.1
A company needs to optimize costs and resource usage through monitoring of operational health for all resources running on AWS. Which AWS service will meet these requirements?
- AWS Control Tower
- Amazon CloudWatch
- AWS CloudTrail
- AWS Config
Amazon CloudWatch
Amazon CloudWatch is a performance monitoring tool that receives metrics from AWS services. This data can be used for monitoring the operational
health of resources as well as being used to optimize costs through ensuring systems are right-sized and just enough capacity is provisioned.
Which service provides a way to convert video and audio files from their source format into versions that will playback on devices like smartphones, tablets and PCs?
- Amazon Elastic Transcoder
- AWS Glue
- Amazon Rekognition
- Amazon Comprehend
Amazon Elastic Transcoder
Amazon Elastic Transcoder is a highly scalable, easy to use and cost-effective way for developers and businesses to convert (or “transcode”) video and audio
files from their source format into versions that will playback on devices like smartphones, tablets and PCs.
When using AWS Organizations with consolidated billing what are two valid best practices? (Select TWO.)
- Always enable multi-factor authentication (MFA) on the root account
- Always use a straightforward password on the root account
- The paying account should be used for billing purposes only
- Use the paying account for deploying resources
- Never exceed the limit of 20 linked accounts
Enable MFA & The Paying account should be used for billing purposes only
When using AWS Organizations with consolidated billing, best practices include:
- Always enable multi-factor authentication (MA) on the root account.
-The Paying account should be used for billing purposes only.
Which AWS support plan comes with a Technical Account Manager (TAM)?
- Basic
- Developer
- Business
- Enterprise
Enterprise
Only the Enterprise plan comes with a TAM.
Which service provides the ability to simply upload applications and have AWS handle the deployment details of capacity provisioning, load balancing, auto-scaling, and application health monitoring?
- Amazon EC2
- AWS Elastic Beanstalk
- Amazon EC2 Auto Scaling
- AWS OpsWorks
AWS Elastic Beanstalk
AWS Elastic Beanstalk can be used to quickly deploy and manage applications in the AWS Cloud.
You are concerned that you may be getting close to some of the default service limits for several AWS services. What AWS tool can be used to display current usage and limits?
- AWS Cloud Watch
- AWS Personal Health Dashboard
- AWS Trusted Advisor
- AWS Systems Manager
Trusted Advisor
Trusted Advisor provides real time guidance to help you provision your resources following AWS best practices. Offers a Service Limits check (in the Performance category) that displays your usage and limits for some aspects of some services.