Practice Exam B Flashcards

1
Q

Which AWS service makes it easy to deploy, manage, and scale containerized applications using Kubernetes on AWS

A

Amazon EKS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

You work for a web application development company and have been asked to design an infrastructure solution which can be repeatedly created using scripted templates to create individual sandbox environments for your developers to use. Some infrastructure components will include the setup and configuration of a VPC, EC2 Instances, S3 buckets etc. Which AWS service enables you to design an infrastructure template that can be deployed to create repeatable infrastructure for your developers to use as a sandbox environment?

A

AWS CloudFormation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which IAM feature enables you to grant secure access to other AWS accounts?

A

IAM Roles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which configuration feature of the AWS Auto Scaling service enables you to define a maximum number of EC2 Instances that can be launched in your fleet?

A

Auto Scaling Group.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which AWS Service can be used to analyze IoT telemetry data in real-time as it is streamed into your data storage services on AWS?

A

AWS Kinesis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following is true with regards to the benefits of purchasing a convertible EC2 Reserved Instance?

(Choose 2 answers)

A
  1. To benefit from better pricing, you can exchange a No Upfront Convertible Reserved Instance for an All Upfront or Partial Upfront Convertible Reserved Instance.
  2. You can exchange one or more Convertible Reserved Instances with a different configuration, including instance family, operating system, and tenancy.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which AWS S3 service can be used to help prevent accidental deletion of objects?

A

Versioning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Your CEO recently heard that a competitor who migrated to AWS suffered from an attack. The competitors’ AWS Account was used to mine cryptocurrency for an illegal concern. Which AWS security services offer threat detection capabilities using machine learning and behavior models to help detect such malicious activity?

A

AWS Guard Duty.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which AWS service uses machine-learning to classify sensitive information stored in your Amazon S3 buckets and monitor access patterns for anomalies that indicate risks or suspicious behavior, such as large quantities of source code being downloaded?

A

AWS Macie.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which AWS service is more cost-effective if you need to host static website content for an upcoming product launch?

A

Amazon S3.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which AWS support plans are suitable if you require telephone technical support? (Choose 2 Answers)

A
  1. Business
  2. Enterprise
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

You have been asked to design and deploy docker style containerized applications on the AWS platform. As part of the requirement, you have been asked to suggest a solution that will not require granular infrastructure management such as choosing server types or deciding when to scale your clusters. Which AWS Elastic Container Service (ECS) modes will enable you to focus on the application packaging rather and worry about provisioning, patching, and scaling of servers?

A

AWS Fargate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Your finance team would like to be alerted when the cost of using a new AWS test/dev account is about to reach the approved budget for an upcoming project. Which AWS tool can you use to help you achieve this need?

A

AWS Budgets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which of the following six advantages of cloud computing enables you to achieve massive savings by avoiding hidden costs when compared to an on-premise infrastructure design?

A

Stop spending money running and maintaining data centers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which of the following determines the price of S3?

(Choose 3 answers).

A
  1. Amount of Storage.
  2. Data Transfer Out.
  3. Storage Class.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

As part of designing for the Well-Architected Framework, you should enable traceability in order to meet best practices for the Security Pillar. Which of the following AWS tools can help you achieve this?

A

AWS CloudTrail.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which AWS service allows you to register any application resources, such as databases, queues, microservices, and other cloud resources, with custom names, that allows your applications to easily query the registry for the location of such resources?

A

CloudMap.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

As part of implementing change management, which AWS service can be used to assess, audit, and evaluate change configurations of your AWS resources, enabling you to identify if a change was the cause of an incident?

A

AWS Config.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which AWS service enables you to set custom cost and usage budgets to manage your AWS spend more easily?

A

AWS Budgets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Where can AWS customers to list their Reserved Instances for sale, if they signed up for a 1 or 3-year contract but now no longer need the instance?

A

Reversed Instance Marketplace.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

You are planning on developing a website in multiple languages such that you have one fleet of EC2 Instances which serves the English version of your site and another fleet that serves the Spanish version of your site. For each language version, you will be configuring URLs with different paths such that the English version of your site will contain /en/ in the path, and the Spanish version will contain /es/.

Which type of Load Balancer would you use to route traffic to ensure users connect to the site in their desired language?

A

Application Load Balancer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

You wish to automatically start your fleet of servers used to an Accounting application every morning at 6 am and then shut down the servers at night at 6 pm. This will help reduce overall costs. You plan to use Cloud Events and create cron/scheduled job for this. Which AWS service can enable you to run a node.js code to perform the actual start and stop request, triggered from the scheduled CloudWatch Events Rule?

A

AWS Lambda.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which AWS Report gives enables you to view line items for each unique combination of AWS product, usage type, and operation that your AWS account uses?

A

AWS Cost and Usage Report.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Which AWS Service can be used to automatically select and deploy operating system software patches automatically across large groups of instances?

A

AWS System Manager Patch Manager.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Which S3 storage class would you recommend for hosting data that is quickly accessible but infrequently accessed and can also be re-created if required hence offers even cheaper storage costs?

A

S3 One Zone IA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Which AWS services enable you to perform security assessment against your EC2 instance using pre-defined rules mapped to security best practices, thus enabling you to perform common checks such as access to your EC2 instances from the internet, remote root login being enabled, or vulnerable software versions installed?

A

AWS Inspector.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Which service in AWS protects your virtual network and resources from common Distributed Denial of Service (DDoS) attacks?

A

AWS Shield.

28
Q

You are building an application for a Wealth Asset Management company which will be used to store portfolio data and transactions of stocks. Mutual funds and Forex purchased. To that end you require a backend database solution that will ensure a ledger-like functionality because they want to maintain an accurate history of their applications’ data, for example, tracking the history of credits and debits for its customers. Which AWS Database Solution would you recommend for this business requirement?

A

Amazon QLBD.

29
Q

Which of the following is part of the customers’ responsibility regarding the Shared Responsibility Model?

(Choose 2 answers)

A
  1. Configure NACL to only allow inbound ports 80 and 443 to Linux web servers from the Internet.
  2. Patch Windows EC2 Instances with the latest security patches.
30
Q

Your eCommerce application is built following a monolith architecture which means that a single component failure often brings the entire app crashing to a halt. Modern software best practices recommend decoupling application components that offer a higher level of redundancy. A requirement for building a decouple microservices architecture is to have a process in place to handle messages between components so that if one component is held up in processing, newer requests/tasks are held in a queue and not lost. Then when that component becomes free, it will be able to poll for new requests/tasks from the queue. Which AWS Service enables you to design a microservices architecture for your eCommerce application?

A

Amazon SQS.

31
Q

Which feature of the Amazon S3 platform enables you to upload content to a centralized bucket from across any location, such that the data is uploaded via AWS Edge Locations ensuring faster transfer speeds and avoidance of general public Internet congestion?

A

Amazon S3 Transfer Acceleration.

32
Q

Which AWS Service enables you to purchase and register new domain names that can be used to publish your website on the Internet?

A

Route53.

33
Q

What is an Amazon Region?

A

A Geological region comprising Amazon Availability Zones.

34
Q

Which of the following are examples of Amazon AWS Certifications and Attestations for Compliance?

(Choose 3 answers)

A
  1. ISO 27001
  2. SOC 3
  3. PCI DSS Level1
35
Q

Which AWS service enables you to manage multiple AWS Accounts under a single Master Account where you can apply policies to restrict what services can be configured in each member account?

A

AWS Organization.

36
Q

You are setting an AWS CloudFront distribution for a new video sharing web application. Your CFO would like to know the costs associated with using CloudFront.

Which of the following is NOT required to estimate the cost of CloudFront?

A

Data Transfer In.

37
Q

Which of the following is true regarding the Amazon Simple Storage Service (Amazon S3)?

(Select 2 answers)

A
  1. Amazon S3 Standard Storage Class offers 99.999999999.
  2. Amazon S3 is Object-Based Storage.
38
Q

Which AWS Service enables you to distribute your digital assets such that it is cached locally to users who attempt to access this content for a time to live, and thus helps to reduce network latency?

A

AWS CloudFront.

39
Q

Which AWS Service can be used to track costs you have incurred so far in your AWS account with a graphical visualization?

A

AWS Cost Explorer.

40
Q

As part of ensuring operational excellence, you are required to monitor your EC2 service health in terms of load and traffic to and from those servers. Which AWS service will enable you to build dashboards to get a quick one pane health view of your EC2 farm?

A

AWS CloudWatch.

41
Q

One of the five design principals of the Performance Efficiency Pillar suggests using a serverless architecture. Which of the following use cases lends itself well to using serverless architecture?

(Choose 2 answers)

A
  1. Using Lambda Functions to start and stop test servers.
  2. Hosting a static website on an S3 Bucket.
42
Q

Which AWS Service enables you to analyze streaming data, gain actionable insights, and respond to your business and customer needs in real-time?

A

Amazon Kinesis Data Analytics.

43
Q

Which tool in Amazon IAM can you use to configure company-wide password rules such as complexity level, number of passwords to remember, and length of password?

A

Password Policy.

44
Q

What is the maximum file size that you can store in Amazon S3?

A

5TB.

45
Q

Which AWS services does Amazon CloudWatch use to send out email alerts to administrators when alarms are triggered and enter the ‘Alarm’ state?

A

Amazon SNS.

46
Q

Which AWS Database service is suitable for your company’s new Smart IoT product ranges, that can be used to manage trillions of events per day and be used to store a time series of events from those devices?

A

AWS Timestream.

47
Q

Which AWS Services enables developers to create, publish, maintain, monitor, and secure APIs for serverless applications that need to access data, business logic, or functionality from your backend services?

A

API Gateway.

48
Q

Which AWS service enables you to configure multiple Windows-based EC2 Instances to share and access a common storage solution that is based on using the industry-standard SMB protocol and eliminate the administrative overhead of managing Windows file servers?

A

Amazon FSx for Windows File Sever.

49
Q

Which AWS Service enables you to use Chef and Puppet to automate how servers are configured, deployed, and managed across your Amazon EC2 instances or on-premises compute environments?

A

AWS OpsWorks.

50
Q

Your company provides an Options market trading service. You wish to run the end of day analysis against the day’s transaction costs, perform execution reporting, and conduct market performance analysis. Which AWS service provides Managed Compute Environments that dynamically provisions and scale compute resources based on the volume and resource requirements of your submitted jobs?

A

AWS Batch.

51
Q

Which of the following is the primary key benefit of using an Amazon RDS Database instead of installing a MySQL compatible database on your EC2 Instance?

A

Managing of the database including patching and backup is take care of by Amazon.

52
Q

Which AWS Database engine offers up to five times faster than standard MySQL databases and three times faster than standard PostgreSQL databases?

A

Amazon Aurora.

53
Q

Which AWS Service can be attached to your EC2 Instances and used as a virtual disk?

A

EBS.

54
Q

Which AWS Service is used to ensure that only specific traffic on specific ports is allowed inbound to your EC2 Instances and act as a firewall at the Instance Level?

A

Security Groups.

55
Q

Your company manages a fleet of Windows EC2 instances in a VPC (Public/Private Subnet Configuration) for a client. Your team is connecting to the VPC over the Internet to manage the fleet of Amazon EC2 instances running in both the public and private subnets. You have not yet gotten the approval to configure a site-to-site VPN tunnel from your offices to the client’s VPC.
You have added a bastion host with Microsoft Remote Desktop Protocol (RDP) access to the application instance in the private subnet, but the client wants to further limit administrative access to all of the instances in the VPC.

Which of the following bastion host deployment options will meet this requirement?

A

Configure the Bastion Host in the Public Subnet with an Elastic IP and a Security Group to accept incoming RDP traffic from only your corporate IP address.

56
Q

Where can you set up Billing Alarms?

A

AWS CloudWatch.

57
Q

Your organization is looking to replace its old desktops and laptops with thin clients and virtual desktop infrastructure in the cloud. Which AWS service offers you the ability to host Windows desktops quickly and at a fraction of the costs of traditional VDI deployments?

A

AWS Workspaces.

58
Q

Are you allowed to run vulnerability testing against your AWS workloads?

A

Yes.

59
Q

When an Elastic Load Balancer detects an unhealthy EC2 Instance, what action does it perform in regards to distributing incoming traffic?

A

It only send traffic to the remaining healthy instances.

60
Q

Which of the following statements are true?

A

NACLS protect the entire subnets whereas Security Groups protect the individual instance.

61
Q

Which Elastic Load Balancer is ideal for handling volatile workloads and can scale to millions of requests per second?

A

Network Load Balancer.

62
Q

Which IP Addressing strategy enables you to increase the levels of High Availability for a public-facing EC2 Instance?

A

Elastic IP Address.

63
Q

Your company is planning on migrating to the AWS Cloud. As part of a one-time data migration effort migration, you need to transfer over 500TB of data to Amazon S3 is a couple of weeks. Which is the most cost-effective strategy to transfer this amount of data to the cloud?

A

Use the Amazon Snowball Service.

64
Q

Which Amazon S3 service can you use to automatically migrate data from one storage class to another after a set number of days as a means of reducing your costs, especially where frequent instant access may not be required to that subset of data?

A

Lifecycle Management.

65
Q

One of the five design principals for cost optimization as part of the Well-Architected Framework is to ‘Adopt a Consumption Model’. Which of the following statements in reference holds true for this statement?

A

For applications running in development and test environments, you should use On-Demend EC2 Instances.