Practice Questions 2 Flashcards

1
Q
AWS offers the ability to download or export many reports within the Management Console that you can then use for local processing or importing into other tools. Which data format is offered to export the data from the Management Console?
A. CSV
B. JSON
C. XML
D. SQL
A

A. CSV

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
You suspect one of your employees has been violating company policy with the use of AWS services under your account for personal use. Which AWS service would be valuable to investigate their activities?
A. CloudTrail
B. CloudWatch
C. CloudAudit
D. CloudLog
A

A. CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
Rather than using your on-premises VDI solutions, which AWS service could be leveraged to provide your users the same functionality while removing your need to maintain and support a hardware infrastructure?
A. AppStream
B. WorkSpaces
C. WorkLink
D. AWS DaaS
A

B. WorkSpaces

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Your company wants to split budgets out in multiple ways in order to gain insight into costs by department and projects.
Which AWS tool under the Billing Dashboard will allow easy implementation of this?
A. Cost centers
B. Cost graphs
C. Cost categories
D. Cost codes

A

C. Cost categories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
AWS incorporates a variety of robust security services to counter common types of web attacks. Which type of attack is the AWS Shield service designed to protect against?
A. Cross-site scripting
B. SQL injection
C. Brute force
D. Distributed Denial of Service
A

D. Distributed Denial of Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
You need to provide application access to a subset of users to test and verify functionality but do not want them to see production data. What type of data deidentification process would you use for this?
A. Static masking
B. Dynamic masking
C. PII masking
D. Sensitivity masking
A

B. Dynamic masking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the easiest method to implement encryption at rest within S3 from the perspective of the user?
A. Client-side encryption using keys generated by AWS
B. Server-side encryption using your own keys
C. Server-side encryption using keys generated by AWS
D. Client-side encryption using your own keys

A

C. Server-side encryption using keys generated by AWS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
With consolidated billing you can merge multiple accounts into a single bill and leverage the combined resources for discounts on AWS services. Which of the following is not a cost that receives discounts under consolidated billing?
A. EC2
B. Support plans
C. Lambda
D. Fargate
A

B. Support plans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
The AWS Marketplace offers images from vendors that are full packages for their products that can be deployed within AWS. Costs for Marketplace offerings have two components. Which of the following are the price components? (Choose two.)
A. S3 costs
B. EC2 costs
C. Support costs
D. Licensing costs
E. Professional services costs
A

B. EC2 costs

D. Licensing costs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
Your company has decided to retire their on-premises data warehouse and move to a similar solution in AWS for increased capacity and lower costs. Which AWS service would you explore for this initiative?
A. Redshift
B. Aurora
C. DynamoDB
D. RDS
A

A. Redshift

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
Which type of service offerings pushes the responsibility for configuration and operations to AWS and leaves the customer only responsible for loading their data?
A. Unmanaged
B. Regulated
C. Managed
D. Offloaded
A

C. Managed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
When users are created via the IAM console, what can be used to assign granular levels of access within a service?
A. Groups
B. Roles
C. ACLs
D. Settings
A

B. Roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
A system is able to keep functioning when some portions of it experience an outage of resources. What concept refers to this ability?
A. Availability
B. Resiliency
C. Redundancy
D. Elasticity
A

B. Resiliency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
AWS allows for resources to be added to a system without any downtime or interruption to services. What is this concept called?
A. Elasticity
B. Scalability
C. Expandability
D. Portability
A

A. Elasticity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
Which component of AWS Systems Manager provides a consolidated view of data from sources such as CloudTrail and CloudWatch to help with the investigation of operational issues?
A. Explorer
B. AppConfig
C. Systems Manager
D. OpsCenter
A

D. OpsCenter

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Security groups and access control lists (ACLs) are two means of applying security rules within AWS. Which of the following statements is true?
A. Security groups and ACLs can both be applied to subnets and instances
B. Security groups apply to instances; ACLs apply to subnets
C. Security groups apply to subnets; ACLs apply to instances
D. Security groups and ACLs are only used on subnets

A

B. Security groups apply to instances; ACLs apply to subnets

17
Q
To help manage versioning in AWS S3, the service provides automation tools, called actions, to handle how versions are stored and when they are removed from the system. Which of the following are the types of actions available? (Choose two.)
A. Archive
B. Transition
C. Delete
D. Rotate
E. Expire
A

B. Transition

E. Expire

18
Q
Under the AWS Shared Responsibility Model and an IaaS implementation, which of the following areas of responsibility reside with the customer? (Choose two.)
A. Application code
B. Operating system
C. Virtualization
D. Storage
E. Networking
A

A. Application code

B. Operating system

19
Q
The use of multifactor authentication is imperative to protect accounts with administrative access, especially the root user for your AWS account. Along with a password, which of the following could be used to fulfill multifactor requirements?
A. PIN
B. Question/answer challenge
C. One-time use code
D. Date of birth
A

C. One-time use code

20
Q
Rather than creating accounts with passwords in AWS, your corporate policies require you to use your internal credentials via federation with AWS. Which technology could you use to establish federated authentication with AWS?
A. JSON
B. HTTPS
C. RADIUS
D. SAML
A

D. SAML

21
Q
When adding new users in IAM, you want to be able to assign a set of capabilities to them and keep them uniform between those users. Which feature of IAM would you use to accomplish this?
A. Groups
B. Labels
C. Roles
D. Sets
A

A. Groups

22
Q
Which core concept of cloud computing most relates to the cost-savings benefits you can realize through AWS offerings?
A. Broad network access
B. On-demand self-service
C. Metered service
D. Resource pooling
A

C. Metered service

23
Q
Which AWS support plan is the lowest level that gives 24/7 access to support?
A. Free
B. Business
C. Enterprise
D. Developer
A

B. Business

24
Q
Your company has decided for the first time to start using AWS services for storage. As a precondition, your CEO has demanded assurances that you can quickly remove data from AWS should the need arise. Which core concept of cloud computing would this pertain to?
A. Portability
B. Reversibility
C. Interoperability
D. Removability
A

B. Reversibility

25
Q
The Trust Advisor can flag AWS services that you have provisioned but are inactive or being used below the level for which they are configured. Which area of Trust Advisor would you explore to find this report?
A. Performance
B. Service limits
C. Cost optimization
D. Security
A

C. Cost optimization

26
Q
You want to do a compliance check with your configurations against best practices. Which AWS service would you use to accomplish this?
A. Trusted Advisor
B. IAM dashboard
C. AWS Management Console
D. AWS System Manager
A

A. Trusted Advisor

27
Q
You need to offer easy access to your AWS systems from anywhere, but you do not want to deal with many of the problems of BYOD and the security issues associated with it. Which AWS service would you investigate to accomplish this?
A. OpsWorks
B. Lambda
C. Aurora
D. WorkSpaces
A

D. WorkSpaces

28
Q
When using the AWS Virtual Private Cloud to span between AWS resources and your on-premises resources, what type of cloud deployment are you using?
A. Public
B. Community
C. Private
D. Hybrid
A

D. Hybrid

29
Q
Which concept of cloud computing refers to the ability of a system to easily move between different cloud providers?
A. Interoperability
B. Portability
C. Moveability
D. Transferability
A

B. Portability

30
Q
Which AWS database service does not use SQL and is highly optimized for key-value data storage?
A. DynamoDB
B. Aurora
C. Redshift
D. CloudFront
A

A. DynamoDB

31
Q
Which component of the AWS Management Console allows a user to access the shell and CLI for managing EC2 instances without the use of keys or exposing ports?
A. Run command
B. Distributor
C. Systems Manager
D. Automation
A

C. Systems Manager

32
Q
An academic institution has a suite of software packages that it wants to make available to students but does not want to distribute software or be responsible for the support of it on student devices. Which AWS service would be the easiest and most cost-effective means to accomplish this?
A. WorkSpaces
B. AppStream
C. WorkLink
D. VirtualApp
A

B. AppStream

33
Q
Which AWS security service would allow you to apply processing rules to web traffic based upon the contents or type of request?
A. AWS Shield
B. Route 53
C. AWS WAF
D. AWS Inspector
A

C. AWS WAF

34
Q
Which AWS storage service is used by EC2 instances for high-throughput data operations?
A. S3
B. AWS Storage Gateway
C. Elastic Block Storage
D. AWS Snow
A

C. Elastic Block Storage

35
Q
You want to use a set of configurations within your code that will use the same key value on all systems but have different values based upon the specific system. Which AWS tool allows you to do this?
A. Parameter store
B. State manager
C. Distributor
D. Automation
A

A. Parameter store