Practice Exam A Flashcards

1
Q

Which of the following statements is a valid reason for choosing a specific AWS Region to deploy your applications in? (Choose 2 answers)

A
  1. Selecting a specific AWS region enables you to ensure that your application is closer to your end-users and offers low latency connectivity.
  2. Selecting a specific AWS region ensures that you can comply with data sovereignty laws and compliance.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which AWS Service offers a complete cloud-powered Business Intelligence service that is charged on a pay-per-session pricing model?

A

AWS Quicksight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which of the following AWS Security tools can protect your web applications or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources?

A

AWS WAF
(*web application firewall)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

You are required to host a website across a fleet of web servers on the Amazon platform. In order to build a highly cost-effective solution, you want to automatically provision additional web servers configured with the necessary application stack when demand on those servers increases over a period and then terminate web servers when there is a decrease in CPU load. How would you configure your solution?

A

Configure Auto Scaling to manage your web servers. As part of the configuration, configure and launch additional servers when CPU Utilization goes above a threshold for a short period of time. Configure the Auto Scaling service to terminate web servers when the CPU Utilization levels drop below a certain threshold for a specified period of time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

One of the seven design principals of the Security Pillar in the Well-Architected Framework refers to the concept
of applying security at all layers. Which two firewall options can you configure to protect your EC2 Instances deployed in a VPC? (Choose 2 answers)

A
  1. NACLs
  2. Security Groups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following describes a benefit of cloud computing that relates to its ability to scale out and scale in resources based on demand?

A

Elasticity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which mode of Amazon ECS allows you to have control and manage your cluster of servers and schedule placement of containers on the servers?

A

EC2 Launch Type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which AWS database solution enables you to build a complete data warehousing solution, capable of handling complex analytic queries against petabytes of structured data using standard SQL and industry recognized Business Intelligence (BI) tools?

A

AWS Redshift

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which AWS Service enables you to test a new IAM Policy to ensure that it will only allow access from a specific IP Address before deploying the policy?

A

IAM. Policy Simulator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

You have been hired as a cloud consultant to design your clients’ web application architecture. A key requirement is to address a concern about building a second version of the web application so that if the primary site fails for any reason, customers can be redirected to the secondary site. You are also concerned about regional outages. How you would design this solution?

A

Build two versions of the site, primary site in your main region, and secondary site in another region. Configure Route53 with a Failover routing policy to switch to the secondary site if the primary site is down.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Each region consists of a minimum of two availability zones and many now have at least three availability zones. These availability zones are separated by a meaningful distance, many kilometers, from any other AZ, although all are within 100 km (60 miles) of each other. What is the primary benefit of having multiple AZs configured as above in each region?

A

To enable customers to deploy applications across these availability zones in a manner that would achieve high availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Your organization hosts multiple AWS Accounts with multiple VPCs. You would like to connect these VPCs together and centrally manage connectivity policies. Which AWS service enables you to connect multiple VPCs configured as a hub that controls how traffic is routed among all the connected networks which act like spokes?

A

AWS Transit Gateway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which type of EBS volume would you recommend for a high-performance application that is particularly sensitive to high latency?

A

EBS Provisioned IOPS SSD (io1)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

You are building a multi-tier architecture with web servers placed in the public subnet and application servers placed in the private subnet of your VPC. You need to deploy Elastic Load Balancers to distribute traffic to both the web-server farm and the application server farm. Which type of load balancer would you choose to distribute traffic to your application servers?

A

Internal load balancers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which service of the AWS Global Infrastructure enables you to distribute your content (videos, images, documents) such that they are cached locally for low latency access when your users try to download them?

A

Edge Locations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In applying the principals of the Reliability Pillar for Failure Management, what strategy should you adopt for production workloads, when you encounter a failure?

A

Replaced the failed component with a new one and carry out the analysis on the failed resource out of the band.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

A company plans to migrate its on-premises MySQL database to Amazon RDS. Which AWS service should they use for this task?

A

AWS Database Migration Service (AWS DMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which AWS Service helps you to review the state of your workloads and compares them to the latest AWS architectural best practices?

A

AWS Well-Architected Tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What best practice strategy should you follow when assigning permissions to IAM Users and Groups?

A

The principal of least privileges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

When retrieving data from Amazon Glacier, what is the typical time taken to make a Standard archive available?

A

3 to 5 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which of the following types of EBS volumes can be used as boot volumes for your EC2 Instances? (Select 2 answers)

A
  1. General Purposes SSD (gp2)
  2. Provisioned IOPS SSD (io1)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which AWS Service enables developers to analyze and debug applications, identifying the root cause of performance issues and errors?

A

AWS X-Ray

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which feature of the AWS EC2 Services helps to prevent the accidental termination of an EC2 Instance by preventing the user from issuing a termination command either from the console or CLI?

A

Enable ‘Termination Protection’

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Your company hosts various workloads across multiple AWS Accounts. Which AWS service can help you maximize on your total spend across all accounts by combining your accounts in a group and thus benefiting from volume discounts?

A

AWS Organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Which VPC Component enables to you grant Internet access to servers in the public subnet deployed in the VPC?

A

Internet Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Which AWS service can be used to monitor your company’s fleet of EC2 Instances which can be used to identify performance issues related to CPU utilization or memory consumption?

A

AWS CloudWatch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

You have launched a VPC in your AWS Account. You have been asked if it is possible to establish connectivity from your on-premise network to the VPC enabling your Developers with seamless access to production workloads deployed in the VPC from the on-premise network. Which connectivity strategy will enable you to establish this connection over the standard public Internet while keeping costs to a minimum?

A

Setup a Hardware VPC Connection between your on-premise network and your VPC.

28
Q

Which AWS service enables you to set custom budgets that alert you when your costs or usage exceed (or are forecasted to exceed) your budgeted amount?

A

AWS Budgets

29
Q

Which component of the AWS System Manager service can be used to automate common administrative tasks like remotely executing shell scripts or PowerShell commands, installing software updates?

A

Run Command

30
Q

Which type of cloud service model enables you to consume applications hosted by vendors in the cloud that do not require you to host any infrastructure or platform and which is generally accessible over the public Internet?

A

SaaS

31
Q

Which AWS services automatically provisions the necessary infrastructure (e.g. load balancing, auto-scaling, and health monitoring) and enables developers to automatically deploy applications built-in supported languages such as node.js, PHP and python?

A

AWS Elastic Beanstalk

32
Q

Which AWS Service enables companies looking to migrate to the AWS Cloud obtain copies of various compliance documents such as ISO certifications, Payment Card Industry (PCI), and Service Organization Control (SOC) reports?

A

AWS Artifact

33
Q

Which AWS service enables you to experience a truly hybrid solution by extending AWS Infrastructure such as EC2 and EBS services such that they can be hosted in your own on-premise datacentre?

A

AWS Outpost

34
Q

Which AWS service enables you to orchestrate and support the deployment of Docker Containers?

A

Amazon Elastic Container Services (ECS)

35
Q

Which storage solution enables you to share a common file system across multiple Linux based EC2 Instances that can be used to support applications which require access to data with very low latency connectivity?

A

EFS

36
Q

You have a fleet of on-premise servers that require access to a centrally managed cloud storage service. The application running on your servers need to be able to store and retrieve files as durable objects on Amazon S3 over standard NFS based access with local caching. Which AWS service can help you deliver a solution to meet the above required?

A

AWS Storage Gateway - File Gateway

37
Q

Which AWS EC2 pricing option enables you to take advantage of unused EC2 capacity in the AWS cloud and can offer up to a 90% discount compared to On-Demand prices?

A

Spot Instances

38
Q

AWS RDS supports six database engines. From the list below, choose three engines supported by Amazon RDS? (Choose 3 answers)

A
  1. Oracle
  2. MySQL
  3. Microsoft SQL
39
Q

Which Amazon S3 Storage Class enables you to optimize costs by automatically moving data to the most cost-effective access tier, while ensuring that frequently access data is made available immediately?

A

Amazon S3 Inteligent Tiering

40
Q

Which AWS Service enables you to compare those costs against on-premise capital expenditure with the on-demand costs associated with building your infrastructure on AWS?

A

AWS TOC

41
Q

Which AWS services enables you to track all API activity in your AWS account regardless of whether the activity was performed using the AWS Management Console of the Command Line Interface?

A

AWS CloudTrail

42
Q

Which of the following additional benefits come as part of signing up to the Enterprise Support Plan, when compared to the Business Support Plan? (Choose 2 answers)

A
  1. Access to a designated Technical Account Manager to proactively monitor your environment.
  2. Business-critical systems down with Responses Time of less than 15 minutes.
43
Q

You wish to configure an Amazon S3 Event, such that your legal team gets a notification if someone tries to delete an object from a sensitive S3 Bucket? Which AWS Service is used by Amazon S3 to send out notifications to your legal team?

A

Amazon SNS

44
Q

Which Amazon SQS queue type offers maximum throughput, best-effort ordering, and at-least-once delivery?

A

SQS Standard Queue

45
Q

Which AWS service can be used to run a piece of code which can create thumbnails of images uploaded to one Amazon S3 bucket and copy them copied to another S3 Bucket?

A

AWS Lambda

46
Q

Which AWS EC2 pricing option can help you reduce costs by allowing you to use your existing server-bound software licenses?

A

Dedicated Hosts

47
Q

Which AWS service enables you to perform heterogeneous migrations between different database platforms, such as Oracle to Amazon Aurora

A

AWS Database Migration Service

48
Q

You wish to deploy a Line of Business application which will use your on-premise identity and access management system (Active Directory) for login authentication. This will involve setting up network connectivity between your AWS architecture and your on-premise datacentre. What is this type of cloud deployment model known as?

A

Hybrid Cloud

49
Q

You wish to configure a bucket that will enforce a policy that enables anonymous to access its content if they connect to the data from the Corporate and branch offices as part of your security strategy. Which S3 configuration feature will enable you to define the IP Ranges from where you will allow access to the data?

A

Bucket Policy

50
Q

Which AWS Service provides you with static IP addresses that serve as a fixed entry point to your applications, thereby ensuring that you don’t need to make any client-facing changes or update DNS records as you modify or replace endpoints such as Application Load Balancers to connect to your application?

A

AWS Global Accelerator

51
Q

Which IAM service enables you to effectively manage users by creating a collection of them based on their job function and assigning them permissions according to their roles to the entire collective?

A

IAM Groups

52
Q

Which AWS Service can be used to analyze your data held in Amazon S3 using standard SQL queries, without having to set up and manage any servers or data warehouses?

A

Amazon Athena

53
Q

Which AWS Compliance program has AWS implemented to ensure that its healthcare customers can build applications to securely process, store, and maintain protected patient medical information?

A

HIPAA

54
Q

Your company is planning to host application workloads on AWS, and you wish to deploy a test environment. You wish to ensure that your developers can access your AWS account using a highly secure authentication process and follow best practices. Which of the following two configuration options will help ensure enhance security? (Choose 2 answers)

A
  1. Configure your IAM Password Policy with Complexity Rules.
  2. Configure your IAM accounts with MFA.
55
Q

Which of the following services offered by AWS are considered global services? (Choose 2 answers)

A
  1. Route53
  2. Identity and Access Management (IAM)
56
Q

Which AWS service enables you to monitor and have consistent visibility and network traffic controls for every microservice in an application, such that you can quickly pinpoint the exact location of errors and automatically re-route network traffic when there are failures or when code changes need to be deployed?

A

App Mesh

57
Q

Which of the following AWS services enables you to quickly launch a webserver with a pre-configured WordPress installation pack, offers predictable monthly pricing, comes with integrated certificate management, and provides free SSL/TLS certificates?

A

AWS LightSail

58
Q

Your administrators need to access your AWS environment using the command-line interface to perform certain specific functions. Which login method do you need to provide them to grant them access via the CLI?

A

Access Keys

59
Q

Which AWS Service enables you to centrally manage multiple AWS Accounts with service control policies (SCPs) to determine which services can be used in those individual AWS member Accounts?

A

AWS Organizations

60
Q

Which feature of IAM enables you to use your existing corporate Active Directory user credentials to log in to the AWS Management Console and therefore offer a single sign-on service?

A

Identity Federation

61
Q

Which of the following AWS Services is a better option to securely grant necessary permissions to a web application running on an EC2 Instance, that needs access to digital assets hosted on an S3 Bucket?

A

IAM Role

62
Q

Which AWS service enables you to perform search, analysis, and visualize data in real-time with features such as full-text search?

A

Amazon Elastisearch

63
Q

Your company uses Amazon RDS for certain databases it hosts on AWS. Amazon also offers you the ability to use the same RDS technology on-premise. Which AWS service enables you to deploy Amazon RDS services on-premise, bringing the same benefits of easy to set up, operate, and scale databases to your on-premises deployments?

A

Amazon RDS on VMware

64
Q

Which AWS service helps you identify potential unused resources such as Elastic IP Addresses that are not attached to a running instance, and thus highlight opportunities to save on costs?

A

AWS Trusted Advisor

65
Q

Which AWS Service can be used to capture, transform, and load streaming data into Amazon S3, Amazon Redshift, Amazon Elasticsearch Service, and Splunk, enabling near real-time analytics with existing business intelligence?

A

AWS Kinesis Firehose