Question I Got Wrong Flashcards

1
Q

What can you use for dynamo DB Caching

A

DynamoDB Accelerator DAX

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

If you access data only twice a year but need rapid access what S3 Storage class should you use?

A

Standard-IA. Standard-IA storage class is for data that is accessed less frequently but requires rapid access when needed. Has lower cost per GB but 99.9% availability vs the Standard 99.99%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many TB of storage Does the snowball edge hold

A

80 TB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the downsides to Direct Connect

A

Direct Connect involves significant monetary investment and takes at least a month to set up

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is AWS Direct Connect

A

AWS Direct Connect is a networking service that provides an alternative to using the internet to connect to AWS. Using AWS Direct Connect, data that would have previously been transported over the internet is delivered through a private network connection between your facilities and AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

If you need to create secure connection between you on-prem data center and AWS what service should you use ?

A

AWS Site-to-Site VPN. It can be configure in minutes if you have an immediate need.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What file system should you use for “hot” and “cold” data

A

FSx for Lustre

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Do you need to pay for S3 Transfer Acceleration if did not result in accelerated transfer

A

No, you pay only for transfers that are accelerated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the destination for Amazon Data Firehose

A
  • S3
  • Redshift
  • OpenSearch
  • Splunk
  • Custom HTTP endpoints
  • 3rd Party service provider Enpoints
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

If you can a new version of object have a different retention period or mode?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What service should you use to migrate on-prem SMB file shares to AWS. The Company wants to stil use its native Windows workloads to have access to the data.

A

Fsx File Gateway. Amazon FSx File Gateway provides low-latency, on-premises access to fully managed file shares in Amazon FSx for Windows File Server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

If you have temporary storage that changes frequently such as buffers, caches, or data that is replicated across a fleet of instances what should you use. (EC2 context)

A

Instance Store.
Instance Store based volumes provide high random I/O performance at low cost (as the storage is part of the instance’s usage cost)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What cache service provides special commands for geospatial data

A

Amazon ElastiCache for Redis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What type of storage give maximum performance (EC2 context)

A

Instance Store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the format of the url for s3 buckets as a websiet

A

http://bucket-name.s3-website.Region.amazonaws.com

http://bucket-name.s3-website-Region.amazonaws.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A health-care company manages its web application on Amazon EC2 instances running behind Auto Scaling group (ASG). The company provides ambulances for critical patients and needs the application to be reliable. The workload of the company can be managed on 2 Amazon EC2 instances and can peak up to 6 instances when traffic increases.
What would you set for the min capacity? How many in each AZ? What would you set for the max capacity ?

A

Min: 4 / 2 per AZ
Max: 6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the retrieval time/Latency for S3 Glacier Flexible Retrieval ?

A

Minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the retrieval time/Latency for S3 - Standard - IA

A

Milliseconds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What can you do to increase the through put of your Kineses data stream while not increasing your cost ?

A

Using Batch Messages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is Amazon Redshift Spectrum?

A

A feature of Amazon Web Services’ (AWS) Redshift data warehousing service that allows users to run SQL queries against data stored in Amazon S3 without data loading or ETL.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the key use case for GuardDuty

A

Amazon GuardDuty offers threat detection that enables you to continuously monitor and protect your AWS accounts, workloads, and data stored in Amazon S3.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What Data does GuardDuty analyze?

A
  • CloudTrail Events
  • VPC Flow Logs
  • DNS Logs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

In what order are the cheapest for EBS, EFS, S3

A

Amazon S3 Standard < Amazon EFS < Amazon EBS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Can you suspend the ReplaceUnhealthy Process on an AutoScaling Group?

A

YES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What the use case for the “Standby” state in EC2 Instances ?

A

Update some software or troubleshoot the instance, and then return the instance to service. Instances that are on standby are still part of the Auto Scaling group, but they do not actively handle application traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is the make concurrent lambda executions per AWS account per region?

A

1000 but you ask support to raise the limit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Can CloudTrail be ingested into CloudWatch ?

A

YES, you can use all features such as Logs Insight, Contributor Insights, Metric filters, and CloudWatch Alarms.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What storage Volumes CANNOT be used as boot volumes

A

Throughput Optimized Hard disk drive (st1)
Cold Hard disk drive (sc1)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

How would you connect an EFS instance to multiple EC2 instances across multiple regions?

A

Inter-region VPC peering connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

How is a retention period for an object version set ?

A

You can place a retention period on an object version either explicitly using Retain Until Date or through a bucket default setting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What are the available Destinations for Kinesis Data Firehose ?

A
  • Amazon Simple Storage Service (Amazon S3)
  • Amazon Redshift
  • Amazon OpenSearch Service,
  • Splunk
  • any custom HTTP endpoint
  • HTTP endpoints owned by supported third-party service providers, including Datadog, Dynatrace, LogicMonitor, MongoDB, New Relic, and Sumo Logic.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What can Kinesis Data Analytics ingest data from?

A

Kinesis Data Streams
Kinesis Data Firehose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What Tier has the highest priority [1, 4, 5]

A

Amazon Aurora will promote the Read Replica that has the highest priority (the lowest numbered tier)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

If there is two Replicas with the same priority, how does RDS choose?

A

Promotes the replica that is largest in size (Storage SIze)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

You would like to mount a network file system on Linux instances, where files will be stored and accessed frequently at first, and then infrequently. What solution is the MOST cost-effective?

A

Amazon EFS Infrequent Access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What is the difference between a Spot Fleet and Spot Instance

A

Spot instance is a single EC2 Instance that is not being used where a Spot fleet is a collection Spot instances that are managed as a group.

37
Q

When can you use Service Control Policy (SCP) ?

A

When the account is under an organization.

38
Q

After upgrading an backend api using API Gateway the old response no longer works for the consumers what should you do to make it compatible?

A

Configure Mapping Template with API Gateway

39
Q

What are some of the benefits of using EventBridge in tandem with S3 Event Notifications

A
  • Enhanced Filtering: Helps match object a parameters which can be used to get only specific notification
  • Multiple Destination: You can forward event notification to multiple destination
  • Fast, Reliable Invocation: fast and reliable way to froward notification without additional custom codes
40
Q

What is a datashare in the context of RedShift? What are some of its integrations?

A

A unit of Sharing data that can be created for sharing data in Redshift with users in the same or different accounts

It integrates with AWS IAM which provides a way to share data with specific users in different accounts.

41
Q

What are termination Polices for Auto Scaling Groups ?

A

Default – Terminate instances according to the default termination policy.

AllocationStrategy – Terminate instances in the Auto Scaling group to align the remaining instances to the allocation strategy for the type of instance that is terminating (either a Spot Instance or an On-Demand Instance). This policy is useful when your preferred instance types have changed. If the Spot allocation strategy is lowest-price, you can gradually rebalance the distribution of Spot Instances across your N lowest priced Spot pools. If the Spot allocation strategy is capacity-optimized, you can gradually rebalance the distribution of Spot Instances across Spot pools where there is more available Spot capacity. You can also gradually replace On-Demand Instances of a lower priority type with On-Demand Instances of a higher priority type.

OldestLaunchTemplate – Terminate instances that have the oldest launch template. With this policy, instances that use the noncurrent launch template are terminated first, followed by instances that use the oldest version of the current launch template. This policy is useful when you’re updating a group and phasing out the instances from a previous configuration.

OldestLaunchConfiguration – Terminate instances that have the oldest launch configuration. This policy is useful when you’re updating a group and phasing out the instances from a previous configuration. With this policy, instances that use the noncurrent launch configuration are terminated first.

ClosestToNextInstanceHour – Terminate instances that are closest to the next billing hour. This policy helps you maximize the use of your instances that have an hourly charge.

NewestInstance – Terminate the newest instance in the group. This policy is useful when you’re testing a new launch configuration but don’t want to keep it in production.

OldestInstance – Terminate the oldest instance in the group. This option is useful when you’re upgrading the instances in the Auto Scaling group to a new EC2 instance type. You can gradually replace instances of the old type with instances of the new type.

42
Q

What Rate based rules does WAF have?

A

Blanket rate-based rule: to protect your application from large HTTP floods.
URI-specific rate-based rule: A rate-based rule to protect specific URIs at more restrictive rates than the blanket rate-based rule.
IP reputation rate-based rule: A rate-based rule to protect your application against known malicious source IPs.

43
Q

If you want to create a failover record how many do you need to for one primary and one secondary

A

Two Failover alias records

44
Q

What is the most cost effective way to transfer EFS data between regions without using the public networks

A

AWS DataSync

45
Q

Who is Not Effected by Service Control Polices

A

User or roles in the management account

46
Q

What is ECMP (in relation to Site-to-Site) VPN ?

A

Equal Cost multi path

47
Q

Which supports ECMP? AWS Transit Gateway or Virtual Private Gateway ?

A

AWS Transit gateway

48
Q

What is the maximum throughput of site-to-site VPN?

A

1.25 GPS

49
Q

How can yo in increase the through put of site-to-site VPN?

A

Using AWS Transit Gateway. It supports ECMP which can scale over the limit of 1.25 Gbps. You must have dynamic routing using BGP enable on you Transit Gateway for routing over multiple VPN tunnels.

50
Q

How can you route traffic between two VPCs that have over lapping subnets ?

A

Private NAT Gateway. All Traffic form overlapping subnets is mapped to the IP address assigned to NAT Gateway

51
Q

How can you can you track and categorize cost incurred by resources?

A

Using Cost Allocation Tags

52
Q

Who assigns cost allocation tags ?

A

Each member account

53
Q

If you have Direct Connection with VPC B and VPC B has a peering connection with VPC A can you connect to an EFS instance through the direct connect on-prem

A

No VPC peering is non-transitive

54
Q

Is VPC Peering Transitive ?

A

NO

55
Q

What is AWS PrivateLink?

A

AWS PrivateLink provides private connectivity between virtual private clouds (VPCs), supported AWS services, and your on-premises networks without exposing your traffic to the public internet. (Use in conjuction with VPC endpoints)

56
Q

What service can you use to connect EFS from one VPC to another

A

AWS PrivateLink

57
Q

What is AWS X-Ray

A

AWS X-RAY Provides a complete view of requests as they travel through your application and filters visual data across payloads, functions, traces, services, APIs, and more with no-code and low-code motions. It also integrates with SQS

58
Q

What is Parallel Query?

A

A Feature supported by Amazon Aurora For My SQL that makes it possible to perform analytical queries over the data stored in you transactional database with out copying that data to a separate system for analytics

59
Q

How do you establish a private connection between a VPC and Secrets Manager ?

A

Create an Interface VPC Endpoint

60
Q

How long are ACM certs valid for ?

A

13 months / 395 days

61
Q

If a ACM certificates is in pending validation stage what does that mean ?

A

You need to look for an email form ACM and then follow the link in that email to perform validation.

62
Q

What type of records can yo not create for a root domain like mysite.com

A

CNAME

63
Q

What AWS IAM Identity Center?

A

A Cloud based single sign on service that makes it easy to centrally managed single sgn on to different account
- Also provides built-in integrations with many cloud applications like SaleForce, Jenkins
- You have the User dastbase in IAM, AWS managed Microsoft AD, on-prem AD Services, and integration with an Identity Provider who is SAML 2.0 compliant.

64
Q

What is the delivery time of Amazon EventBridge

A

Near real-time

65
Q

What is CloudTrail Lake?

A

A fully managed solution for capturing, storing, storing any analyzing user & api related activity for 2 yeasrs .

66
Q

What is AWS Security Hub?

A

Provides a single a place that aggregates, organizes, and prioritizes alerts or finds form multiple AWS services.

67
Q

What is AWS Outpost ?

A

AWS Outposts is a family of fully managed solutions delivering AWS infrastructure and services to virtually any on-premises or edge location for a truly consistent hybrid experience. Outposts solutions allow you to extend and run native AWS services on premises, and is available in a variety of form factors, from 1U and 2U Outposts servers to 42U Outposts racks, and multiple rack deployments.

68
Q

What is AWS Lake Formation?

A

Easily set up Data Lakes in days. collects and catalogs data form databases and object storage, moves dasta into new S3 data lake, uses ML algos to clean and classify data, and secures access to the sensitive data using granular controls at the column, row, and cell-levels.

69
Q

What is the response time for S3 Glacier Instant Retrieval ?

A

Milliseconds

70
Q

What is Redshift AQUA

A

Advanced Query Accelerator. Accelerates certain types of queries, particularly those involed in large-scale data analytics and data lake queries. Integrates with s3

71
Q

What can AWS System manager Run Command be used for ?

A

Used to remotely run commands, like running package updates= on all EC2 Instances.

72
Q

What types of keys do you use for “signing”

A

Asymmetric Keys

73
Q

What is the conversational AI from Amazon?

A

Amazon Lex

74
Q

For Amazon Cloudfront where do certificates need to be imported ?

A

US-EAST-1

75
Q

What is AWS AppSync?

A

A way to create serverless GraphQL APIs

76
Q

Does EFS have lifecycle policies?

A

Yes, Based on that, the lifecycle policy will archive your file to the EFS Standard–Infrequent Access (Standard-IA) or One Zone–Infrequent Access (One Zone-IA) storage class, depending on your file system if the files haven’t been accessed for that defined period of time.

77
Q

What service would you use to back up you data for Amazon EFS ?

A

AWS Backup, it is natively integrated with EFS. You can enable automatic backups for your file systems.

78
Q

What is CloudWatch Execution Logging

A

Allows you to capture user request, response payloads, and error traces .

79
Q

Using what CloudFront Feature can you control access to multiple content files and not change the url

A

CloudFront Signed Cookies.

80
Q

If your RPO is 10s of Minutes what should you use ?

A

Pilot Light

81
Q

If your RPO is minutes what should you use ?

A

Warm Standby

82
Q

If your RPO is hours what should you use?

A

Backup and Restore

83
Q

What is EBS Snapshots Archive?

A

A storage tier for storing snapshots that are rarely accessed and stored for long periods of time

83
Q

What is Amazon Inspector?

A

A vulnerability Management Service that can identify software vunerabilities and network exposure.

It can be initiated on EC2 instances and Amazon ECR

84
Q

What type of data is Amazon Timestream good for?

A

Is the most suitable for timeseries dasta for IoT and Operational Services . It can store trillions of Events.

85
Q

What is the max storage for EBS volume

A

16TB / 16384 GB

86
Q

How would you move something from Glacier Deep Archive to S3 Intelligent Storage

A

First you need to restore them to their original locations using the S3 Console. Then use the lifecycle policy to move objects to the required S3 Intelligent Tiering Class

87
Q
A