CP Basic Concepts Flashcards
Cloud Concepts:
What are some key financial benefits of migrating on-prem to AWS?
- Replace upfront capital expenditures (capex) with low variable operational expenditures (opex)
- Reduce the total cost of ownership
Cloud Concepts:
What are the 4 Cloud Architecture Design Principles
- Implement Elasticity
- Think Parallel
- Decouple your components
- Design for failure
Cloud Concepts:
How would you design mission-critical workloads in AWS that must be highly available
Use multiple Availability Zones
Cloud Concepts:
How can you ensure that a change or failure in one component will not cascade to other components?
Loose coupling
Cloud Concepts:
How would you enable your Amazon EC2 instances in the public subnet to connect to the public internet?
Use the Internet Gateway
Cloud Concepts:
How would you enable your EC2 instances in the private subnet to connect to the public internet?
NAT Gateway
Security:
What security management tool would you use to configure your AWS WAF rules across accounts?
AWS Firewall Manager
Security:
If a company needs to download compliance-related documents in AWS like the Service Organization Controls (SOC) reports, where would they go?
AWS Artifact
Security:
How would you improve the security of IAM users?
- Enable multi factor authentication (MFA)
2. Configure a strong password policy
Security:
What is an IAM identity that uses access keys to manage cloud resources via the AWS CLI?
IAM User
Security:
How would you grant temporary access to your AWS resources?
IAM Role
Security:
How would you apply and easily manage common access permissions to a large number of IAM users in AWS?
IAM Group
Security:
How would you grant the required permissions to access your S3 resources?
Bucket Policy and/or User Policy
Security:
If you need to provide temporary AWS credentials for users who have authenticated via their social media logins as well as for guest users who don’t need any authentication, what would you use?
Amazon Cognito Identity Pool
Security:
How would a startup evaluate the newly created IAM policies?
IAM Policy Simulator
Security:
What is a service that discovers, classifies, and protects sensitive data such as personally identifiable information (PII) or intellectual property?
Amazon Macie
Security:
What is a threat detection service that continually monitors for malicious activity to protect your AWS account?
Amazon GuardDuty
Security:
What prevents unauthorized deletion of Amazon S3 objects?
Enabling Multi-Factor Authentication (MFA)
Security:
How would a company control the traffic going in and out of their VPC subnets?
Network Access Control Lists (NACL)
Security:
What acts as a virtual firewall in AWS that controls traffic at the EC2 instance level?
Security Group
Security:
Where would you set up an automated security assessment service to improve the security and compliance of your applications?
Amazon Inspector
Technology:
What would the company use if they need to use the AWS global network to improve availability of deployed applications on AWS using an anycast static IP address?
AWS Global Accelerator
Technology:
If you need to securely transfer hundreds of petabytes of data in/out of AWS cloud, what would you use?
AWS Snowball Edge
Technology:
What is a type of EC2 instance that allows you to use your existing server-bound software licenses?
Dedicated Host
Technology:
What is a service that allows you to continuously monitor and log account activities such as the user actions made from the AWS Management Console and AWS SDKs?
AWS CloudTrail
Technology:
What is a highly available and scalable cloud DNS web service in AWS?
Amazon Route 53
Technology:
How would you store the results of I/O intensive SQL database queries to improve application performance?
Amazon ElastiCache
Technology:
What is a combination of AWS services that allow you to serve static files with lowest possible latency?
Amazon S3
Amazon CloudFront
Technology:
How would you automatically scale the capacity of an AWS cloud resource based on the incoming traffic to improve availability and reduce failures?
AWS Auto Scaling
Technology:
What would a company use to migrate an on-prem MySQL database to Amazon RDS?
AWS Database Migration Service (DMS)
Technology:
How would you automatically transfer your infrequently accessed data in your S3 bucket to a more cost-effective storage class?
S3 Lifecycle Policy
Technology:
What would you use to upload a single object as a set of parts to improve throughput and have a quicker recovery from any network issues?
The Multipart Upload API
Technology:
What would a company use to establish a dedicated connection between their on-premise network and AWS VPC?
AWS Direct Connect
Technology:
What is a Machine Learning service that allows you to add a visual analysis feature to your applications?
Amazon Rekognition
Technology:
What is a source control service that allows you to host Git-based repositories?
AWS CodeCommit
Technology:
What is a service that can trace user requests in your application?
AWS X-Ray
Technology:
What would a company use to retrieve the Instance ID, public keys, and public IP address of their EC2 instance?
Instance Metadata
Technology:
If you need to speed up the content delivery of static assets to your customers around the globe, what would you use?
Amazon CloudFront
Technology:
How would you create and deploy infrastructure-as-code templates?
AWS Cloud Formation
Technology:
What would you use to encrypt the log data stored and managed by AWS CloudTrail?
AWS Key Management Service (AWS KMS)
Technology:
What is a database service that can be used to store JSON documents?
Amazon DynamoDB
Billing:
Who is the designated technical point of contact that will maintain an operationally healthy AWS environment?
Technical Account Manager (TAM)
Billing:
What is a tool that inspects your AWS environment and makes recommendations that follow AWS best practices?
AWS Trusted Advisor
Billing:
What would a startup use to estimate their cost of moving their application to AWS?
AWS Pricing Calculator
Billing:
How would you set coverage targets and receive alerts when your utilization drops?
AWS Budgets
Billing:
What is a type of Reserved Instance that allows you to change its instance family, instance type, platform, scope, or tenancy?
Convertible Reserved Instance
Billing:
What lets you take advantage of unused EC2 capacity in the AWS cloud and provide up to a 90% discount?
Spot Instances
Billing:
Where would you go to centrally manage policies and consolidate billing across multiple AWS accounts?
AWS Organizations
Billing:
What is the most cost-efficient storage option for retaining database backups that allow occasional data retrieval in minutes?
Amazon Glacier
Billing:
Where would you forecast future costs and usage of your AWS resources based on your past consumption?
AWS Cost Explorer
Billing:
How would you categorize and track AWS costs on a detailed level?
Cost Allocation tags
Billing:
If a company launched a new VPC that was way beyond the default service limit, what would they do?
Request a service limit decrease in the AWS Support Center
Billing:
What is the most cost-effective option when you purchase a Reserved Instance for a 1-year term?
All Upfront