Extra Exam 4 Flashcards
Which of the following entities are part of an Amazon Virtual Private Cloud (Amazon VPC) in the AWS Cloud?
Subnet
Object
AWS Storage Gateway
Internet Gateway
API Gateway
Subnet, Internet Gateway
Reserved Instance (RI) pricing is available for which of the following AWS services?
S3
IAM
CloudFront
EC2
RDS
EC2, RDS
Which AWS Support plans provide programmatic access to AWS Support Center features to create, manage and close your support cases? (2)
Business and Enterprise
AWS Shield Advanced provides expanded DDoS attack protection for web applications running on which of the following resources? (2)
EC2, CloudFront
As per the AWS Shared Responsibility Model, which of the following is a responsibility of AWS from a security and compliance point of view?
Identity and Access Management
Service and Communications Protection
Patching networking infrastructure
Patching the guest OS
Patching networking infrastructure
Which (2) Amazon Simple Storage Service (Amazon S3) storage classes do not charge any data retrieval fee?
Standard-IA
Standard
Intelligent-Tiering
Glacier Flexible Retrieval
One Zone-IA
Standard and Intelligent Tiering
AWS Trusted Advisor can provide alerts on which of the following common security misconfigurations?
When you allow public access to S3 buckets and when you don’t turn on user activity logging (AWS CloudTrail)
Which entity can be used to connect to an EC2 server from a Mac OS, Windows or Linux based computer via a browser?
EC2 Instance Connect
Bob and Susan each have an AWS account in AWS Organizations. Susan has five Reserved Instances (RIs) of the same type and Bob has none. During one particular hour, Susan uses three instances and Bob uses six for a total of nine instances on the organization’s consolidated bill.
Which of the following statements are correct about consolidated billing in AWS Organizations?
Bob only receives the cost-benefit from Susan’s RI’s if he launches his instances in the same Availability Zone (AZ) that Susan purchased them
AWS bills 5 instances as reserved instances, the remaining 4 as regular instances
Which AWS service can help you analyze your infrastructure to identify unattached or underutilized Amazon EBS Elastic Volumes?
Trusted Advisor
CloudWatch
Config
Inspector
Trusted Advisor
Which of the following statements are CORRECT regarding AWS Global Accelerator?
AWS Global Accelerator uses the AWS global network and its edge locations. But the edge locations used by Global Accelerator are different from Amazon CloudFront edge locations
AWS Global Accelerator is a good fit for non-HTTP use cases
AWS Global Accelerator cannot be configured with an Elastic Load Balancer (ELB)
AWS Global Accelerator provides static IP addresses that act as a fixed entry point to your applications
AWS Global Accelerator can be used to host static websites
AWS Global Accelerator is a good fit for non-HTTP use cases
Global Accelerator provides static IP addresses that act as a fixed entry point to your applications
Which AWS services can be used together to send alerts whenever the AWS account root user signs in?
CloudWatch and SNS
Which of the following is correct regarding the Amazon Relational Database Service (Amazon RDS) service?
You can use both read replicas and multi-AZ deployment for disaster recovery
You can use read replicas for improved read performance only and multi-AZ deployment for disaster recovery only
You can use both read replicas and multi-AZ deployment having single standby for improved read performance
You can use read replicas for disaster recovery only and multi-AZ deployment for improved read performance only
You can use both read-replicas and multi-AZ deployment for disaster recovery
Which of the following are benefits of the AWS Web Application Firewall (AWS WAF)?
AWS Web Application Firewall (AWS WAF) can check for the presence of SQL code that is likely to be malicious (known as SQL injection)
AWS Web Application Firewall (AWS WAF) lets you monitor the HTTP and HTTPS requests that are forwarded to Amazon Route 53
AWS Web Application Firewall (AWS WAF) offers dedicated support from the DDoS Response Team (DRT) and advanced reporting
AWS Web Application Firewall (AWS WAF) can block all requests except the ones that you allow
WAF (firewall) can check for the presence of SQL code that is likely to be malicious (known as SQL injection)
WAF can block all requests except the ones that you allow
Which of the following entities should be used for an Amazon Elastic Compute Cloud (Amazon EC2) Instance to access a DynamoDB table?
Amazon Cognito
AWS Key Management Service (KMS)
IAM Role
AWS IAM user access keys
IAM Role