Exam style Questions Flashcards

1
Q

How does Direct Connect Work?

A

Direct Connect is a dedicated network connection between your on-premises network and AWS VPC via a private connection. (not over the public internet)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Site-to-Site VPN

connecting two sites

A

Site-to-Site VPN connects two sites (on-prem and AWS VPC) with a secure encrypted tunnel (VPN) over the public internet.

Connects 1 on-prem network to 1 AWS VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 3 main components of a Site-to-Site VPN connection?

A

Customer Gateway (CGW): Your on-premises router or software.

Virtual Private Gateway (VGW): AWS endpoint for one VPC.

Transit Gateway: Centralized hub connecting multiple VPCs and networks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does Database Migration service work?

A

AWS DMS can be used to migrate data from an on-premises database to a database in AWS. However, AWS DMS does not migrate the actual server to an EC2 instance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A company has an on-premises Linux-based server with an Oracle database that runs on it. The company wants to migrate the database server to run on an Amazon EC2 instance in AWS.

Which service should the company use to complete the migration?

A

Application Migration Service is an automated lift-and-shift solution. This solution can migrate physical servers and any databases or applications that run on them to EC2 instances in AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How does AWS charge for AWS Lambda usage once the free tier has been exceeded? (Select TWO.)

A

Charged based on the runtime of the code

and

number of requests for your Lambda functions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Polly?

A

Text to speech service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Transit Gateway?

Transit as data passing, Gateway a door connecting many netw + VPC

A

Hub that connects multiple VPCs and on-premises networks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the VPC Peering?

A

Direct, low-latency communication between two VPCs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What’s included in the basic support plan

A

Cost: Free for all AWS customers.

Features:
- Access to AWS documentation and whitepapers.
- Limited AWS Trusted Advisor core checks (e.g., service limits, security, fault tolerance and cost optimisation).
- AWS Personal Health Dashboard for service health updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What’s included in the Developer support plan

A

Features:
- 24/7 Access to Cloud Support Engineers
- Response time: <24 hours for general support issues.
- Access to some AWS Trusted Advisor core checks (service limits, security, cost optimisation and fault tolerance)
- Access to the Personal Health Dashboard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What’s included in the Business support plan

A

Features:
- 24/7 support via phone, chat, and email for production workloads.
Response time:
- <1 hour for urgent issues.
- <12 hours for non-urgent issues.
- Full AWS Trusted Advisor access with all checks
- Limited support for third-party software running on AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What’s included in the Enterprise support plan

A

Features:
- 24/7 access to senior AWS engineers.
- <15 minutes response time for critical issues.
- Dedicated Technical Account Manager (TAM) for proactive guidance.
- Full AWS Trusted Advisor access and AWS Infrastructure Event Management.
- Consultative architectural reviews and optimization planning.
- Support for third-party software and custom solutions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the 6 pillars of the Well-Architected Framework

CROPSS

A

CROPSS

C: Cost Optimization
R: Reliability
O: Operational Excellence
P: Performance Efficiency
S: Security
S: Sustainability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Summarise Cost Optimisation?

A

Focuses on managing your cloud spend efficiently by choosing the right pricing models and scaling resources as needed.

It involves right-sizing your infrastructure to eliminate waste and tracking costs to avoid overspending.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Summarise Reliability

A

systems can recover from failures and continue to operate at the desired performance level.

This includes using fault tolerance, redundancy, and monitoring to proactively detect and respond to issues.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Summarise Operational Excellence

A
  • automating operational processes
  • monitoring systems for performance
  • continuously improving operations.
  • making frequent, small changes
  • Infrastructure as code
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Summarise Performance efficiency

A

Ensures cloud resources are used effectively to meet evolving demands.

This includes selecting the right resources, scaling workloads dynamically, and continuously optimizing for performance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Summarise Security

A

Focuses on protecting systems, data, and assets from potential threats through robust identity management, encryption, and regular monitoring.

It ensures secure configurations and compliance with industry standards and regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Summarise Sustainability

A

Aims to reduce environmental impact by optimizing resource usage and minimizing carbon emissions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is a report that can break down cloud costs by product, by company defined tags ans by hour, day and month?

A

AWS Cost and Usage Report (CUR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What does Xray do ?

A

It provides a complete view of requests as they travel through your application good for debugging and generates a map of your application’s architecture, showing how different services interact with each other.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Differences between AWS Inspector and AWS GuardDuty?

A

AWS Inspector = Automated security assessments on EC2 and containerised applications (vulnerabilities, misconfigurations).

AWS GuardDuty = Continuous threat detection service for malicious or unauthorised behaviour.

Monitors AWS CloudTrail logs, VPC flow logs, and DNS logs for suspicious activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are Outposts

A

Outposts provide a hybrid solution by placing AWS infrastructure (like compute and storage) on the customer’s on-prem data centers.

Customers can run AWS services like EC2, EBS, and RDS on these Outposts, allowing for seamless integration between on-prem and AWS cloud environments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What are local zones?

A

Local Zones are extensions of AWS Regions, providing localized access to AWS compute, storage, and networking services in select metropolitan areas.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is direct connect?

A

A dedicated private connection from your on-premises data center to AWS.

  • a physical connection between your on-premises network and AWS, bypassing the public internet.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is Transit Gateway

A

A hub to connect multiple VPCs within AWS to your on-premises network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What does the “Effect” in an S3 bucket policy specify?

Effect = Outcome (allow or deny)

A

Whether access is allowed or denied

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which action would you use to allow users to upload objects to an S3 bucket?

A

s3:PutObject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

In an S3 bucket policy, how is the resource typically defined?

A

By the Amazon Resource Name (ARN) of the bucket or object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What does the “Principal” element in an S3 bucket policy define?

A

The entity (e.g., IAM user or account) the policy applies to

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What is the purpose of the “Condition” element in an S3 bucket policy?

“Conditions = When, Where, and How”

A

Conditions are rules or filters that specify when or under what circumstances a policy is applied.
- When: The condition specifies when a request should be allowed or denied (e.g., time of day, request origin).
- Where: It can specify where the request is coming from (e.g., a particular IP address or VPC).
- How: It can dictate how the request should be made (e.g., encrypted connections, MFA authentication).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What are the 6 perspectives of the Cloud Adoption Framework (CAF)?

“Big People Govern Platforms, Secure Operations.”

A
  • Business: Ensure cloud adoption drives value for the business by improving processes, reducing costs, and creating new opportunities.
  • People: Build and empower the right teams with the skills and culture necessary to succeed in a cloud environment.
  • Governance: Managing risk and ensuring compliance with policies.
  • Platform: Designing and building the cloud environment.
  • Security: Protecting data and applications from threats.
  • Operations: Managing and optimizing cloud resources.
34
Q

What is the Business Perspective in CAF, and who are the stakeholders?

A
  • Purpose: Aligns IT investments to business needs and outcomes.
  • Stakeholders: CEO, CFO, COO, CIO, CTO
35
Q

What is the People Perspective in CAF, and who are the stakeholders?

A
  • Purpose: Focuses on workforce, leadership, and continuous learning culture.
  • Stakeholders: CIO, COO, Cloud Director, enterprise-wide leaders
36
Q

What is the Governance Perspective in CAF, and who are the stakeholders?

A
  • Purpose: Orchestrates cloud initiatives.
  • Stakeholders: Chief Transformation Officer, Risk Officer, CIO, CFO
37
Q

What is the Platform Perspective in CAF, and who are the stakeholders?

A
  • Purpose: Ensures scalable, enterprise-grade platforms for cloud-native solutions.
  • Stakeholders: CTO, architects, tech leads, engineers
38
Q

What is the Security Perspective in CAF, and who are the stakeholders?

A
  • Purpose: Ensures data confidentiality, integrity, and availability.
  • Stakeholders: CSO, audit leads, security architects, engineers
39
Q

What is the Operations Perspective in CAF, and who are the stakeholders?

A
  • Purpose: Ensures cloud services meet delivery needs.
  • Stakeholders: SREs, IT managers, infrastructure teams
40
Q

What are the serverless servers in AWS?

A

AWS Lambda
AWS Fargate
Amazon Aurora Serverless
Amazon DynamoDB
Amazon S3
Amazon API Gateway
Amazon EventBridge
AWS Step Functions
Amazon SNS (Simple Notification Service)
Amazon SQS (Simple Queue Service)
Amazon Kinesis Data Streams
Amazon Kinesis Firehose

41
Q

What is the Systems Manager ?

A
  • Manage EC2 instances and on-premises servers from a centralized platform.
  • Automate tasks like patching, updates, and configuration management.
  • Securely access and control instances without traditional login methods.
  • Store and retrieve application settings securely.
42
Q

What is the difference between AWS Partner Network (APN) Technology vs Consulting Partner?

A
  • Consulting Partners: Offer professional services to implement and manage AWS solutions.
  • Technology Partners: Provide software products and tools that integrate with AWS services.
43
Q

Which AWS service providers automated backups of data by default?

A

Many AWS services like RDS, DynamoDB, and Aurora offer automated backups by default, others, such as EBS and EC2, require configuration for automation.

44
Q

What is AppStream ?

A

Amazon AppStream 2.0 enables organizations to stream applications securely to users, so users can access application without installing it on their device

45
Q

What are the 6 trusted advisor categories?

“Cloud Practices Secure Fast Scalable Solutions.”

A

Cost Optimization
Provides - recommendations to help reduce costs (e.g., identifying underutilized instances, recommending Reserved Instances).

Performance
- Suggests improvements to enhance performance (e.g., instance type changes).

Security
- Offers advice on improving security (e.g., reviewing open security groups, checking IAM permissions).

  • Fault Tolerance
    Helps ensure your environment is resilient by recommending actions like multi-AZ deployments.

Service Limits
- Alerts when your resources are approaching service limits, helping you avoid service disruptions.

Sustainability
- No information provided here, but would focus on practices to reduce environmental impact.

46
Q

How does an Elastic load balancer work?

A

ELB distributes traffic evenly across all healthy targets in each of the specified AZs.

Traffic between AZs is encrypted by default

47
Q

What is AWS Kinesis Data ?

A

Amazon Kinesis Data is a suite of managed services within AWS designed for real-time data streaming, ingestion, and processing at scale. It allows you to collect, process, and analyze streaming data in real time, enabling quick insights and actions.

48
Q

What is server-side encryption

A

Data is encrypted by the server after it is uploaded and before it is stored. Data is proctected while stored (At rest)

49
Q

What is client-side encryption

A

Data is encrypted by the client before it is uploaded to the server.

Data is protected during transfer using TLS/SSL (in transit)

50
Q

Which Pillar of the Well Architected Framework focuses on using computing resources efficiently to meet system requirements.

A

Performance efficiency

(Right-sizing resources to match workload requirements.)

51
Q

What Pillar focuses on Continuous improvement, monitoring and automation ?

A

Operational Excellence

52
Q

What pillar focuses on recovering from failures and maintaining availability

A

Reliability

53
Q

What Pillar focuses on avoiding unnecessary costs

A

Cost Optimization

54
Q

What is Control Tower?

A

A centralised account management app. You can create multiple AWS accounts within an organisation and govern it at scale.

You can automate setup, and apply governance and security policies across multiple accounts.

55
Q

What instance type is best for steady state workloads?

A

Reserved Instance?

56
Q

What do VPC flow logs show?

A

VPC Flow Logs provide detailed information about the network traffic going to and from network interfaces in your Amazon Virtual Private Cloud (VPC). They capture information about IP traffic and are valuable for monitoring and troubleshooting network performance and security issues.

57
Q

What does Xray do and how is it different to Trusted Advisor?

A

X-Ray focuses on tracing requests and debugging application performance in a distributed system, often at the application level.

Trusted Advisor provides best practice recommendations for optimizing your AWS environment across various dimensions like cost, security, and performance.

58
Q

What is Comprehend?

A

Comprehend is a specialized NLP service for analyzing and extracting insights from text data.
it helps you to comprehend insight from text data

59
Q

What is Sagemaker

A

SageMaker is a general-purpose machine learning platform for building, training, and deploying ML models,

60
Q

What is the Minimum credential for AWS CLI?

A

Access keys

61
Q

What are local zones?

A

AWS Local Zones are extensions of an AWS Region that place compute, storage, and other AWS services closer to users to reduce latency

62
Q

DIfference between CodeStar and Cloud9?

A

CodeStar is a development platform where you can manage the entire software development lifecycle (SDLC). It integrates various AWS developer tools (e.g., CodeCommit, CodeBuild, CodeDeploy, CodePipeline) for continuous integration and continuous delivery (CI/CD).

Cloud9 is a cloud-based integrated development environment (IDE) that allows developers to write, run, and debug code directly from the browser.

63
Q

What is AppSync?

A

AppSync is designed to simplify the development of GraphQL-based APIs, especially for real-time, serverless, and offline-capable applications, while integrating with various AWS data services.

64
Q

What is security hub ?

A

Security Hub shows findings from AWS services like Amazon GuardDuty, Amazon Inspector, AWS IAM Access Analyzer, AWS Firewall Manager, and others, as well as from third-party security tools.

65
Q

What are the ways to connect an on-premises network to an Amazon VPC (Virtual Private Cloud)?

A

Site-to-Site VPN - secure and encrypted connection between an on-premises network and an AWS VPC over the public internet

Direct Connect - dedicated connection between your on-premises network and AWS VPC via a private connection.

Transit Gateway - Connect multiple VPCs, on-prem networks via VPN Or Direct Connect

VPC Peering - Allows two VPCs to communicate with each other over private IP addresses.

66
Q

What tool enables customers without an AWS account to estimate costs for almost all services

A

Simple Monthly Calculator (now replaced by the AWS Pricing Calculator)

67
Q

What service helps to deploy, scale, and manage third-party virtual appliances like firewalls, intrusion detection/prevention systems (IDS/IPS)

A

Gateway Load Balancer (GWLB)

68
Q

How can a company consolidate billing with another company ?

A

The management account invites the other company’s AWS account(s) to join the organization.

Once accepted, Consolidated billing is automatically enabled in AWS Organizations.

69
Q

IAM Role vs Group vs Policy?

A

A Role is A set of permissions you can assign to entities (users, services, or applications) temporarily. Allows trusted entities to perform specific tasks without long-term credentials.

A Group is a collection of users with shared permissions.

A Policy is document (JSON) defining allow/deny permissions for AWS resources. Attached to Users, Groups, or Roles and controls who can do what on which resources.

70
Q

What does Device Farm do?

A

AWS Device Farm is a service that allows you to test your mobile and web applications across a wide range of real devices and browsers in the cloud.

71
Q

What is Storage Gateway?

A

AWS Storage Gateway is a hybrid cloud storage service that provides seamless integration between on-premises environments and AWS cloud storage.

72
Q

What service enables ultra-low-latency applications by bringing AWS compute and storage services closer to end-users through telecommunication providers’ 5G networks.

A

AWS Wavelength

73
Q

What is a Trusted Advisor feature exclusively for Business and Enterprise users?

A

AWS Support API

74
Q

VPC vs VPN?

A

VPC is a virtual network in the cloud, a container for your resources (like EC2 instances)
whereas VPN is a secure connection that links a network (such as an on-premises network) to another network (like a VPC)

75
Q

What Service supports the analysis, investigation and identifications of the root cause of security events and suspicious activity

A

Dectective

76
Q

AWS Detective vs Inspector

A

AWS Detective focuses on security investigations and helps with incident response by analyzing and visualizing logs, while AWS Inspector is about automated security assessments, scanning for vulnerabilities and misconfigurations in your resources.

77
Q

Which managed AWS Service assists with the creation, testing and management of Amazon EC2 images?

A

EC2 Image Builder

78
Q
A
79
Q
A
80
Q
A