Exam1 Flashcards

1
Q

Which of the following is used to control network traffic in AWS? (Choose TWO)

A

Network Access Control Lists (ACLs)
Security Groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A company has an AWS Enterprise Support plan. They want quick and efficient guidance with their billing and account inquiries. Which of the following should the company use?

A

AWS Support Concierge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A company is concerned that they are spending money on underutilized compute resources in AWS. Which AWS feature will help ensure that their applications are automatically adding/removing EC2 compute capacity to closely match the required demand?

A

AWS Auto Scaling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the benefits of having infrastructure hosted in AWS? (Choose TWO)

A

All of the physical security and most of the data/network security are taken care of for you

Increasing speed and agility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which of the following are examples of AWS-Managed Services, where AWS is responsible for the operational and maintenance burdens of running the service? (Choose TWO)

A

Amazon DynamoDB
Amazon Elastic MapReduce

Other managed services include: AWS Lambda, Amazon RDS, Amazon Redshift, Amazon CloudFront, and several other services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following is NOT correct regarding Amazon EC2 On-demand instances?

A

You have to pay a start-up fee when launching a new instance for the first time

no startup or termination fees for EC2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A company is planning to host an educational website on AWS. Their video courses will be streamed all around the world. Which of the following AWS services will help achieve high transfer speeds?

A

Amazon CloudFront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which of the below options are related to the reliability of AWS? (Choose TWO)

A

Automatically provisioning new resources to meet demand
Ability to recover quickly from failures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In the AWS Shared responsibility Model, which of the following are the responsibility of the customer? (Choose TWO)

A

Setting password complexity rules
Configuring network access rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the AWS Personal Health Dashboard provide? (Choose TWO)

A
  • Personalized view of AWS service health
    Recommendations for Cost Optimization

AWS Personal Health Dashboard provides alerts and remediation guidance when AWS is experiencing events that may impact you. While the Service Health Dashboard displays the general status of AWS services, Personal Health Dashboard gives you a personalized view into the performance and availability of the AWS services underlying your AWS resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which service is used to ensure that messages between software components are not lost if one or more components fail?

A

Amazon SQS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A company has decided to migrate its Oracle database to AWS. Which AWS service can help achieve this without negatively impacting the functionality of the source database?

A

AWS Database Migration Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the advantage of the AWS-recommended practice of “decoupling” applications?
*

A

Reduces inter-dependencies so that failures do not impact other components of the application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does AWS Snowball provide?

A

Secure transfer of large amounts of data into and out of the AWS Cloud
Built-in computing capabilities that allow customers to process data locally

   With AWS Snowball, you have the choice of two devices, Snowball Edge Compute Optimized with more computing capabilities, suited for higher performance workloads, or Snowball Edge Storage Optimized with more storage, which is suited for large-scale data migrations and capacity-oriented workloads.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which of the following must an IAM user provide to interact with AWS services using the AWS Command Line Interface (AWS CLI)?

A

Access keys

Access keys consist of an access key ID and secret access key, which are used to sign programmatic requests to AWS using the CLI or the SDK.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the AWS service that provides a virtual network dedicated to your AWS account?

A

Amazon VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

AWS allows users to manage their resources using a web based user interface. What is the name of this interface?

A

AWS Management Console

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

You have AWS Basic support, and you have discovered that some AWS resources are being used maliciously, and those resources could potentially compromise your data. What should you do?

A

Contact the AWS Abuse team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Hundreds of thousands of DDoS attacks are recorded every month worldwide. What service does AWS provide to help protect AWS Customers from these attacks? (Choose TWO)

A

AWS WAF
AWS Shield

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Which of the following is not a benefit of Amazon S3? (Choose TWO)

A

Amazon S3 can be scaled manually to store and retrieve any amount of data from anywhere

Amazon S3 can run any type of application or backend system

Companies today need the ability to simply and securely collect, store, and analyze their data at a massive scale. Amazon S3 is object storage built to store and retrieve any amount of data from anywhere – web sites and mobile apps, corporate applications, and data from IoT sensors or devices. It’s a simple storage service that offers highly available, and infinitely scalable data storage infrastructure at very low costs. It is designed to deliver 99.999999999% durability, and stores data for millions of applications used by market leaders in every industry. S3 provides comprehensive security and compliance capabilities that meet even the most stringent regulatory requirements. It gives customers flexibility in the way they manage data for cost optimization, access control, and compliance. S3 provides query-in-place functionality, allowing you to run powerful analytics directly on your data at rest in S3. And Amazon S3 is the most supported cloud storage service available, with integration from the largest community of third-party solutions, systems integrator partners, and other AWS services.

   Amazon S3 stores any number of objects, but each object does have a size limitation. Individual Amazon S3 objects can range in size from a minimum of 0 bytes to a maximum of 5 terabytes.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which service provides DNS in the AWS cloud?

A

Route 53

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

As part of the Enterprise support plan, who is the primary point of contact for ongoing support needs?

A

Technical Account Manager (TAM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which of the below is a best-practice when designing solutions on AWS?

A

Automate wherever possible to make architectural experimentation easier

1- Stop guessing your capacity needs: Eliminate guessing about your infrastructure capacity needs. When you make a capacity decision before you deploy a system, you might end up sitting on expensive idle resources or dealing with the performance implications of limited capacity. With cloud computing, these problems can go away. You can use as much or as little capacity as you need, and scale up and down automatically.
2- Test systems at production scale: In the cloud, you can create a production-scale test environment on demand, complete your testing, and then decommission the resources. Because you only pay for the test environment when it’s running, you can simulate your live environment for a fraction of the cost of testing on premises.
3- Automate to make architectural experimentation easier: Automation allows you to create and replicate your systems at low cost and avoid the expense of manual effort. You can track changes to your automation, audit the impact, and revert to previous parameters when necessary.
4- Allow for evolutionary architectures: Allow for evolutionary architectures. In a traditional environment, architectural decisions are often implemented as static, one-time events, with a few major versions of a system during its lifetime. As a business and its context continue to change, these initial decisions might hinder the system’s ability to deliver changing business requirements. In the cloud, the capability to automate and test on demand lowers the risk of impact from design changes. This allows systems to evolve over time so that businesses can take advantage of innovations as a standard practice.
5- Drive architectures using data: In the cloud you can collect data on how your architectural choices affect the behavior of your workload. This lets you make fact-based decisions on how to improve your workload. Your cloud infrastructure is code, so you can use that data to inform your architecture choices and improvements over time.
6- Improve through game days: Test how your architecture and processes perform by regularly scheduling game days to simulate events in production. This will help you understand where improvements can be made and can help develop organizational experience in dealing with events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

You want to run a questionnaire application for only one day (without interruption), which Amazon EC2 purchase option should you use?

A
  • On-demand instances
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Which of the following can be described as a global content delivery network (CDN) service?

A

Amazon CloudFront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

In order to implement best practices when dealing with a “Single Point of Failure,” you should attempt to build as much automation as possible in both detecting and reacting to failure. Which of the following AWS services would help? (Choose TWO)
*

A

Auto Scaling*
ELB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What does the “Principle of Least Privilege” refer to

A

You should grant your users only the permissions they need when they need them and nothing more

28
Q

What is the AWS feature that provides an additional level of security above the default authentication mechanism of usernames and passwords?

A

AWS MFA
(Correct)

29
Q

What is the AWS database service that allows you to upload data structured in key-value format?

A

Amazon DynamoDB

30
Q

What does AWS provide to deploy popular technologies - such as IBM MQ - on AWS with the least amount of effort and time?

A

AWS Quick Start reference deployments

31
Q

Which S3 storage class is best for data with unpredictable access patterns?

A

Amazon S3 Intelligent-Tiering

32
Q

A company has moved to AWS recently. Which of the following AWS Services will help ensure that they have the proper security settings? (Choose TWO)

A

AWS Trusted Advisor
(Correct)
*
Amazon Inspector

33
Q

Which statement is true regarding the AWS Shared Responsibility Model?

A

Responsibilities vary depending on the services used

34
Q

A company is introducing a new product to their customers, and is expecting a surge in traffic to their web application. As part of their Enterprise Support plan, which of the following provides the company with architectural and scaling guidance?

A

Infrastructure Event Management

35
Q

You have set up consolidated billing for several AWS accounts. One of the accounts has purchased a number of reserved instances for 3 years. Which of the following is true regarding this scenario?

A

All accounts can receive the hourly cost benefit of the Reserved Instances

36
Q

Which of the following is an example of horizontal scaling in the AWS Cloud?

A

Adding more EC2 instances of the same size to handle an increase in traffic

37
Q

Which of the following services allows customers to manage their agreements with AWS?

A

AWS Artifact

38
Q

A global company with a large number of AWS accounts is seeking a way in which they can centrally manage billing and security policies across all accounts. Which AWS Service will assist them in meeting these goals?
*

A

AWS Organizations

AWS Organizations has five main benefits:
1) Centrally manage access polices across multiple AWS accounts.
2) Automate AWS account creation and management.
3) Control access to AWS services.
4) Consolidate billing across multiple AWS accounts.
5) Configure AWS services across multiple accounts.

39
Q

You have deployed your application on multiple Amazon EC2 instances. Your customers complain that sometimes they can’t reach your application. Which AWS service allows you to monitor the performance of your EC2 instances to assist in troubleshooting these issues?

A

Amazon CloudWatch

40
Q

According to the AWS Acceptable Use Policy, which of the following statements is true regarding penetration testing of EC2 instances?

A

Penetration testing can be performed by the customer on their own instances without prior authorization from AWS

      AWS customers are welcome to carry out security assessments and penetration tests against their AWS infrastructure without prior approval for 8 services: 1- Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers. 2- Amazon RDS. 3- Amazon CloudFront. 4- Amazon Aurora. 5- Amazon API Gateways. 6- AWS Lambda and Lambda Edge functions. 7- Amazon Lightsail resources. 8- Amazon Elastic Beanstalk environments.
41
Q

An organization has a large number of technical employees who operate their AWS Cloud infrastructure. What does AWS provide to help organize them into teams and then assign the appropriate permissions for each team?

A

IAM Groups

42
Q

A Japanese company hosts their applications on Amazon EC2 instances in the Tokyo Region. The company has opened new branches in the United States, and the US users are complaining of high latency. What can the company do to reduce latency for the users in the US while minimizing costs?

A

Deploying new Amazon EC2 instances in a Region located in the US
(Correct)

43
Q

What does Amazon CloudFront use to distribute content to global users with low latency?
*

A
  • AWS Edge Locations
44
Q

What do you gain from setting up consolidated billing for five different AWS accounts under another master account?

A

Each AWS account gets volume discounts

45
Q

A startup company is operating on limited funds and is extremely concerned about cost overruns. Which of the below options can be used to notify the company when their monthly AWS bill exceeds $2000? (Choose TWO)
*

A

Configure the AWS Budgets Service to alert the company when the threshold is exceeded
(Correct)
Setup a CloudWatch billing alarm that triggers an SNS notification when the threshold is exceeded
(Correct)

46
Q

Your company is developing a critical web application in AWS, and the security of the application is a top priority. Which of the following AWS services will provide infrastructure security optimization recommendations?

A

AWS Trusted Advisor
(Correct)

47
Q

Your company has a data store application that requires access to a NoSQL database. Which AWS database offering would meet this requirement?

A

Amazon DynamoDB

48
Q

The identification process of an online financial services company requires that new users must complete an online interview with their security team. The completed recorded interviews are only required in the event of a legal issue or a regulatory compliance breach. What is the most cost-effective service to store the recorded videos?
*

A
  • Amazon S3 Glacier Deep Archive
49
Q

The principle “design for failure and nothing will fail” is very important when designing your AWS Cloud architecture. Which of the following would help adhere to this principle? (Choose TWO)

A

Elastic Load Balancing
*
Availability Zones

“Vertical Scaling” is incorrect. A “vertically scalable” system is constrained to running its processes on only one computer; in such systems, the only way to increase performance is to add more resources into one computer in the form of faster (or more) CPUs, memory, or storage. Vertical scaling may improve performance, but not fault-tolerance; because if this “one computer” fails, the whole system will fail.

50
Q

One of the most important AWS best-practices to follow is the cloud architecture principle of elasticity. How does this principle improve your architecture’s design?

A

By automatically provisioning the required AWS resources based on changes in demand

51
Q

Under the shared responsibility model, which of the following is the responsibility of AWS?

A

Configuring infrastructure devices

52
Q

Which of the following does NOT belong to the AWS Cloud Computing models?

A

Networking as a Service (NaaS)

53
Q

You have noticed that several critical Amazon EC2 instances have been terminated. Which of the following AWS services would help you determine who took this action?

A

AWS CloudTrail

54
Q

You work as an on-premises MySQL DBA. The work of database configuration, backups, patching, and DR can be time-consuming and repetitive. Your company has decided to migrate to the AWS Cloud. Which of the following can help save time on database maintenance so you can focus on data architecture and performance?

A

Amazon RDS

Amazon RDS can be used to host Amazon Aurora, PostgreSQL, MySQL, MariaDB, Oracle, and Microsoft SQL Server databases.

55
Q

Skipped
A company has developed an eCommerce web application in AWS. What should they do to ensure that the application has the highest level of availability?

A
  • Deploy the application across multiple Regions and Availability Zones
56
Q

How can you view the distribution of AWS spending in one of your AWS accounts?

A

By using AWS Cost Explorer

57
Q

What should you do in order to keep the data on EBS volumes safe? (Choose TWO)

A

Create EBS snapshots
Ensure that EBS data is encrypted at rest

58
Q

Which service provides object-level storage in AWS?

A

Amazon S3

59
Q

Select TWO examples of the AWS shared controls.

A

Patch Management
*
Configuration Management

60
Q

Which of the following helps a customer view the Amazon EC2 billing activity for the past month?

A

AWS Cost & Usage Reports

61
Q

Adjusting compute capacity dynamically to reduce cost is an implementation of which AWS cloud best practice?

A

Implement elasticity

62
Q

You are working on a project that involves creating thumbnails of millions of images. Consistent uptime is not an issue, and continuous processing is not required. Which EC2 buying option would be the most cost-effective?

A

Spot Instances

63
Q

What is the AWS service that enables AWS architects to manage infrastructure as code?

A

AWS CloudFormation

64
Q

An organization has decided to purchase an Amazon EC2 Reserved Instance (RI) for three years in order to reduce costs. It is possible that the application workloads could change during the reservation period.
What is the EC2 Reserved Instance (RI) type that will allow the company to exchange the purchased reserved instance for another reserved instance with higher computing power if they need to?

A

Convertible RI
When your needs change, you can exchange your Convertible Reserved Instances and continue to benefit from the reservation’s pricing discount. With Convertible RIs, you can exchange one or more Reserved Instances for another Reserved Instance with a different configuration, including instance family, operating system, and tenancy. There are no limits to how many times you perform an exchange, as long as the new Convertible Reserved Instance is of an equal or higher value than the original Convertible Reserved Instances that you are exchanging.

“Standard RIs” is incorrect. You cannot exchange Standard Reserved Instances, but you can modify them. You can modify attributes such as the Availability Zone, instance size (within the same instance family), and scope of your Reserved Instance (regional or zonal). Standard RIs provide the most significant discount (up to 72% off On-Demand) and are best suited for steady-state usage.

65
Q

A company is deploying a new two-tier web application in AWS. Where should the most frequently accessed data be stored so that the application’s response time is optimal?
*

A
  • Amazon ElastiCache
    Amazon ElastiCache is a web service that makes it easy to deploy, operate, and scale an in-memory data store or cache in the cloud. The service improves the performance of web applications by allowing you to retrieve information from fast, managed, in-memory data stores, instead of relying entirely on slower disk-based databases.
66
Q

A developer is planning to build a two-tier web application that has a MySQL database layer. Which of the following AWS database services would provide automated backups for the application?

A

Amazon Aurora
Amazon Aurora is a MySQL and PostgreSQL-compatible relational database built for the cloud. Amazon Aurora combines the performance and availability of traditional enterprise databases with the simplicity and cost-effectiveness of open source databases. It delivers up to five times the throughput of standard MySQL and up to three times the throughput of standard PostgreSQL. Amazon Aurora is designed to be compatible with MySQL and with PostgreSQL, so that existing applications and tools can run without requiring modification. It is available through Amazon Relational Database Service (RDS), freeing you from time-consuming administrative tasks such as provisioning, patching, backup, recovery, failure detection, and repair.