Practice exam 2 Flashcards
A global company with a large number of AWS accounts is seeking a way in which they can centrally manage billing and security policies across all accounts. Which AWS Service will assist them in meeting these goals?
A. AWS Organizations.
B. AWS Trusted Advisor.
C. IAM User Groups.
D. AWS Config.
A. AWS Organizations.
Which service provides object-level storage in AWS?
A. Amazon EBS.
B. Amazon Instance Store.
C. Amazon EFS.
D. Amazon S3.
D. Amazon S3.
A company is concerned that they are spending money on underutilized compute resources in AWS. Which AWS feature will help ensure that their applications are automatically adding/removing EC2 compute capacity to closely match the required demand?
A. AWS Elastic Load Balancer.
B. AWS Budgets.
C. AWS Auto Scaling.
D. AWS Cost Explorer
C. AWS Auto Scaling.
Which S3 storage class is best for data with unpredictable access patterns?
A. Amazon S3 Intelligent-Tiering.
B. Amazon S3 Glacier Flexible Retrieval.
C. Amazon S3 Standard.
D. Amazon S3 Standard-Infrequent Access.
A. Amazon S3 Intelligent-Tiering.
What is the AWS database service that allows you to upload data structured in key-value format?
A. Amazon DynamoDB.
B. Amazon Aurora.
C. Amazon Redshift.
D. Amazon RDS.
A. Amazon DynamoDB.
Which of the following is NOT correct regarding Amazon EC2 On-demand instances?
A. You have to pay a start-up fee when launching a new instance for the first time.
B. The on-demand instances follow the AWS pay-as-you-go pricing model.
C. With on-demand instances, no longer-term commitments or upfront payments are needed.
D. When using on-demand Linux instances, you are charged per second based on an hourly rate.
A. You have to pay a start-up fee when launching a new instance for the first time.
A company has moved to AWS recently. Which of the following AWS Services will help ensure that they have the proper security settings? (Choose TWO)
A. AWS Trusted Advisor.
B. Amazon Inspector.
C. Amazon SNS.
D. Amazon CloudWatch.
E. Concierge Support Team.
A. AWS Trusted Advisor.
B. Amazon Inspector.
What is the AWS feature that provides an additional level of security above the default authentication mechanism of usernames and passwords?
A. Encrypted keys.
B. Email verification.
C. AWS KMS.
D. AWS MFA.
D. AWS MFA.
A company is introducing a new product to their customers, and is expecting a surge in traffic to their web application. As part of their Enterprise Support plan, which of the following provides the company with architectural and scaling guidance?
A. AWS Knowledge Center.
B. AWS Health Dashboard.
C. Infrastructure Event Management.
D. AWS Support Concierge Service.
C. Infrastructure Event Management.
You work as an on-premises MySQL DBA. The work of database configuration, backups, patching, and DR can be time-consuming and repetitive. Your company has decided to migrate to the AWS Cloud. Which of the following can help save time on database maintenance so you can focus on data architecture and performance?
A. Amazon RDS.
B. Amazon Redshift.
C. Amazon DynamoDB.
D. Amazon CloudWatch.
A. Amazon RDS.
Which of the below is a best-practice when designing solutions on AWS?
A. Invest heavily in architecting your environment, as it is not easy to change your design later.
B. Use AWS reservations to reduce costs when testing your production environment.
C. Automate wherever possible to make architectural (© ) experimentation easier.
D. Provision a large compute capacity to handle any spikes in load
C. Automate wherever possible to make architectural (© ) experimentation easier.
According to the AWS Acceptable Use Policy, which of the following statements is true regarding penetration testing of EC2 instances?
A. Penetration testing is not allowed in AWS.
B. Penetration testing is performed automatically by AWS to determine vulnerabilities in your AWS infrastructure.
C. Penetration testing can be performed by the customer on their own instances without prior authorization from AWS.
D. The AWS customers are only allowed to perform penetration testing on services managed by AWS.
C. Penetration testing can be performed by the customer on their own instances without prior authorization from AWS.
Which service is used to ensure that messages between software components are not lost if one or more components fail?
A. Amazon SQS.
B. Amazon SES.
C. AWS Direct Connect.
D. Amazon Connect.
A. Amazon SQS.
The principle “design for failure and nothing will fail” is very important when designing your AWS Cloud architecture. Which of the following would help adhere to this principle? (Choose TWO)
A. Multi-factor authentication.
B. Availability Zones.
C. Elastic Load Balancing.
D. Penetration testing.
E. Vertical Scaling.
B. Availability Zones.
C. Elastic Load Balancing.
What is the AWS service that provides a virtual network dedicated to your AWS account?
A. AWS VPN.
B. AWS Subnets.
C. AWS Dedicated Hosts.
D. Amazon VPC.
D. Amazon VPC.
According to the AWS Shared responsibility model, which of the following are the responsibility of the customer? (Choose TWO)
A. Managing environmental events of AWS data centers.
B. Protecting the confidentiality of data in transit in Amazon S3.
C. Controlling physical access to AWS Regions.
D. Ensuring that the underlying EC2 host is configured properly.
E. Patching applications installed on Amazon EC2.
B. Protecting the confidentiality of data in transit in Amazon S3.
E. Patching applications installed on Amazon EC2.
Which of the following AWS services can be used as a compute resource? (Choose TWO)
A. Amazon VPC.
B. Amazon CloudWatch.
C. Amazon S3.
D. Amazon EC2.
E. AWS Lambda.
D. Amazon EC2.
E. AWS Lambda.
Your company is designing a new application that will store and retrieve photos and videos. Which of the following services should you recommend as the underlying storage mechanism?
A. Amazon EBS.
B. Amazon SQS.
C. Amazon S3.
D. Amazon Instance store.
C. Amazon S3.
Which of the following is equivalent to a user name and password and is used to authenticate your programmatic access to AWS services and APIs?
A. Instance Password.
B. Key pairs.
C. Access Keys.
D. MFA.
C. Access Keys.
What does Amazon ElastiCache provide?
A. In-memory caching for read-heavy applications.
B. An Ehcache compatible in-memory data store.
C. An online software store that allows Customers to launch pre-configured software with just few clicks.
D. A domain name system in the cloud.
A. In-memory caching for read-heavy applications.