Questions from exams Flashcards

1
Q

2 AWS Services with automatic data encryption

A

S3 and Storage Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which AWS service enables you to make it easy to centrally manage access to multiple AWS accounts and business applications and provide users with single sign-on?

A

SSO (Single Sign On)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Using AWS marketplace what two ways can sellers deliver software to customers?

A

AMIs and SaaSs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which AWS service lets you use Chef and Puppet to automate how servers are configured, deployed and managed across your EC2 instances or on-premises computer environments

A

AWS OpsWorks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True or False; you can use CloudWatch for on-premises servcers?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which AWS service has an easy-to-use interface that lets you visualise, understand and manage your AWS costs and usage over time?

A

AWS Cost Explorer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which AWS services is an online tool that provides real-time guidance to help provision your resources following AWS best practices?

A

AWS Trusted Advisor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which AWS service enables you to access, audit and evaluate the configurations of your AWS resources?

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which AWS service is an automated security assessment service that helps improve the security and compliance of applications deployed on your EC2 instances?

A

AWS Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which AWS service is a fully-managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in AWS?

A

AWS Macie

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which AWS service is a fully-managed extract, transform and load (ETL) service that makes it easy for customers to prepare and load their data for analytics?

A

AWS Glue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which AWS service turns text into life-like speech?

A

AWS Polly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

True or False; DynamoDB is schemaless?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or False; Redshift is schemaless?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which MFA device is a device that you can plug into a USB port on your computer?

A

U2F Security Key - Universal 2nd Factor Security Key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which AWS service allows marketers and developers to deliver customer-centric engagement experiences by capturing customer usage data to draw real-time insights

A

Amazon Pinpoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which AWS service automates code deployments to any instance, including EC2 instances and instances running on-premises?

A

AWS CodeDeploy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which AWS service is a fully-managed source control service that hosts secure Git-based repositories?

A

AWS CodeCommit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which AWS service is a continuous delivery service that enables you to model, visualise and automate the steps required to release your software?

A

AWS CodePipeline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Which AWS service gives the ability to set custom budgets that alert you when your costs or usage exceed (or are forecasted to exceed) your budgeted amount?

A

AWS Budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which AWS service allows you to centralise operational data from multiple AWS services and automate tasks across your AWS resources?

A

AWS Systems Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which AWS service helps you identify the optimal resource configurations and delivers recommendations for:
- EC2 instances
- EBS volumes
- EC2 Autoscaling groups
- Lambda functions
?

A

AWS Compute Optimizer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which AWS support level gives you access to online training and self-paced labs?

A

Enterprise support

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

True or False; DynamoDB global tables replicates data automatically across your choice of AWS regions?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

True or False; DynamoDB global tables automatically scales capacity to accommodate your workloads?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Which AWS service links your network directly to AWS?

A

AWs Direct Connect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

True or False; Foundations are part of the reliability pillar of the AWS Well-Architected Framework?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What 3 services are part of Foundations?

A
  • VPC
  • Trusted Advisor
  • Service Quotas
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which AWS service enables you to privately connect your VPC to supported AWS services and are powered by AWS PrivateLink without requiring an Internet Gateway, NAT device, VPN connection or Direct Connect connection?

A

VPC Endpoints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What are the six pillars of the Well-Architected Framework?

A
  • Operational Excellence
  • Security
  • Reliability
  • Performance Efficiency
  • Cost Optimisation
  • Sustainability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Main purpose of RDS Multi-AZ deployments?

A

High Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Main purpose of RDS Multi-region deployments?

A

Disaster recovery and local performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Main purpose of RDS Read replicas?

A

Scalability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

RDS Multi-AZ deployments non-Aurora uses synchronous or asynchronous replication?

A

Synchronous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

RDS Multi-AZ deployments Aurora uses synchronous or asynchronous replication?

A

Asynchronous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

RDS Multi-region deployments uses synchronous or asynchronous replication?

A

Asynchronous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

RDS Read replicas uses synchronous or asynchronous replication?

A

Asynchronous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What refers to new IT resources being only a click away?

A

Agility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Which AWS service are built by AWS Solutions Architects + Partners to help you deploy popular technologies on AWS, based on best practices for security and high availability. These accelerations reduce hundreds of manual procedures into just a few steps, so you can build your production environment quickly and start using it immediately?

A

AWS Quick Starts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Rule of thumb
- for resource performance monitoring, events and alerts, which service should you think of?

A

CloudWatch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Rule of thumb
- for account specific activity and audit, which service should you think of?

A

CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Rule of thumb
- for specific change history, audit and compliance, which service should you think of?

A

Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

A financial services company wants to ensure that its AWS account activity meets the governance, compliance and auditing norms. As a Cloud Practitioner, which AWS service would you recommend for this use-case?

A

CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Which AWS service checks your EC2 instances that were running at any time during the last 14 days and alerts you if the daily CPU utilization was 10% or less and network I/O was 5 MB or less on 4 or more days.

A

AWS Trusted Advisor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Which AWS service analyses your AWS environment and provides best practice recommendations in five categories: Cost Optimization, Performance, Security, Fault Tolerance, Service Limits.

A

AWS Trusted Advisor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

A corporation would like to have a central user portal to log in to third-party business applications as well as accounts managed under AWS Organizations. As a Cloud Practitioner, which AWS service would you use for this task?

A

AWS Single Sign On (SSO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

Which AWS service can check Amazon Elastic Block Store (Amazon EBS) volume configurations and warns when volumes appear to be underused?

A

AWS Trusted Advisor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What rules does a Security Group have?

A

allow only rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

What acts as a virtual firewall for your instance to control inbound and outbound traffic?

A

Security Groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

What is an optional layer of security for your VPC that acts as a firewall for controlling traffic in and out of one or more subnets?

A

Network Access Control List (NACL)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

What rules does a NACL (Network Access Control List) have?

A

A network ACL has separate inbound and outbound rules, and each rule can either allow or deny traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

True of False; NAT (Network Address Translation) Gateway is managed by AWS?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

True of False; NAT (Network Address Translation) Instance is managed by AWS?

A

False, it is managed by you

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

Which support plan provides architectural guidance that is contextual to your use-cases?

A

Business support plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

Which support plan provides architectural guidance that is a consultative review and guidance based on your applications

A

Enterprise and Enterprise-on-ramp

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

Which support plans have programmatic case management via the AWS Support API?

A

Business, Enterprise-on-ramp and Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

Which support plan have AWS Incident Detection and Response (for an additional fee)?

A

Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

Which support plan has access to a pool of Technical Account Managers?

A

Enterprise On-Ramp

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

Which support plan has access to a Designated Technical Account Manager?

A

Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

Which support plans have access to account assistance via the Concierge Support Team?

A

Enterprise On-Ramp and Enterprise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

AWS Shield Advanced provides expanded DDoS attack protection for web applications running on which five resources?

A
  • Route 53
  • AWS Global Accelerator
  • EC2
  • ELB
  • CloudFront
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

Which AWS service is a fully managed service that makes it easy for developers to create, publish, maintain, monitor, and secure APIs at any scale.

A

Amazon API Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

Five AWS Services that support reservations to optimise costs

A
  • EC2
  • RDS
  • DynamoDB
  • EastiCache
  • Redshift
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

What EC2 instance storage is a good option when you need storage with very low latency, but you don’t need the data to persist when the instance terminates or you can take advantage of fault-tolerant architectures?

A

Instance Store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

True or False; EFS file system can be mounted on instances across multiple Availability Zones

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

Each AWS Region consist of one or more Availability Zones?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

Each AWS Region consist of two or more Availability Zones?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

Each Availability Zone (AZ) consists of one or more discrete data centers?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

Each Availability Zone (AZ) consists of two or more discrete data centers?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
70
Q

True or False; for EC2 reserved instances a 3 years term would always be more cost-effective than a 1-year term?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
71
Q

Which AWS service creates a secure connection between your data center or branch office and your AWS cloud resources. This connection goes over the public internet.

A

Site-to-Site VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
72
Q

Which AWS service is the industry-leading cloud big data platform for processing vast amounts of data using open source tools such as Hadoop, Apache Spark, Apache Hive, Apache HBase, Apache Flink, Apache Hudi, and Presto.

A

AWS EMR (Elastic MapReduce)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
73
Q

EMR (Elastic MapReduce) is a serverless service?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
74
Q

True or False; data transfer between EC2 instances and S3 within the same region is not charged?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
75
Q

True or False; S3 has encryption enabled by default?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
76
Q

True or False; CloudTrail Logs has encryption enabled by default?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
77
Q

Which AWS service will help you receive alerts when the reservation utilization falls below the defined threshold?

A

AWS Budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
78
Q

True or False; you can use AWS Budgets to set reservation utilization or coverage targets and receive alerts when your utilization drops below the threshold you define?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
79
Q

A big data analytics company is moving its IT infrastructure from an on-premises data center to AWS Cloud. The company has some server-bound software licenses that it wants to use on AWS. As a Cloud Practitioner, which of the following EC2 instance types would you recommend to the company?

A

Dedicated Host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
80
Q

True or False; Amazon EC2 Dedicated Hosts allow you to use your eligible software licenses from vendors such as Microsoft and Oracle on Amazon EC2?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
81
Q

True or False; Dedicated Instances supports Bring Your Own License (BYOL)?

A

False, but Dedicated Hosts do

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
82
Q

Which of the AWS Support plans provides access to Infrastructure Event Management for an additional fee?

A

Business (Enterprise includes it as part of the plan)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
83
Q

Which S3 tier is for data that is accessed less frequently, but requires rapid access when needed?

A

Standard-Infrequent Access (S3 Standard IA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
84
Q

True or False; To remove an AWS account from an AWS Organisation the AWS account must not have any Service Control Policies (SCPs) attached to it. Only then can it be removed from AWS Organisations?

A

False; this is not a pre-requisite to remove the AWS account.

85
Q

True or False; To remove an AWS account from an AWS Organisation the AWS account must be able to operate as a standalone account. Only then it can be removed from AWS organizations

A

True

86
Q

True or False; encryption is enabled by default on S3?

A

False

87
Q

True or False; The AWS encryption SDK is a client-side encryption library that is separate from the language–specific SDKs?

A

True

88
Q

What are the three best practice areas for reliability in the cloud?

A
  • Foundations
  • Change Management
  • Failure Management
89
Q

True or False; Under the AWS Shared Responsibility Model, Configuration Management is a shared responsibility of both AWS and the customer?

A

True

90
Q

True or False; SQS cannot be used to monitor CPU utilization for EC2 instances or send emails?

A

True, use SNS instead

91
Q

What are the three fundamental drivers of cost with AWS?

A
  • compute
  • storage
  • outbound data transfer.
92
Q

True or False; A VPC spans all of the Availability Zones in the Region?

A

True

93
Q

True or False; A subnet is a range of IP addresses within your VPC?

A

True

94
Q

True or False; A subnet spans only one Availability Zone in the Region?

A

True

95
Q

An online gaming company wants to block users from certain geographies from accessing its content. Which TWO AWS services can be used to accomplish this task?

A
  • Route 53
  • AWS WAF
96
Q

True or False; You can use Route 53 geolocation routing policy to block certain geographies?

A

True

97
Q

Which AWS service is a managed message broker service for Apache ActiveMQ and RabbitMQ that makes it easy to set up and operate message brokers on AWS?

A

Amazon MQ

98
Q

True or False; Root account permissions cannot be restricted?

A

True

99
Q

Which AWS service can be used to store, manage, and deploy Docker container images?

A

Elastic Container Registry (ECR)

100
Q

S3 is a regional based or global service?

A

Regional, you specify an AWS Region when you create your Amazon S3 bucket

101
Q

Which AWS service helps protect your web applications or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources

A

AWS WAF (Web Application Firewall)

102
Q

Which AWS service is a threat detection service that monitors malicious activity and unauthorized behaviour to protect your AWS account. By analysing billions of events across your AWS accounts from:
- AWS CloudTrail
- VPC Flow Logs
- DNS Logs

A

AWS GuardDuty

103
Q

True or False; AWS GuardDuty can be used to protect from web exploits such as SQL injection and cross-site scripting?

A

False

104
Q

Which AWS service allows organizations to create and manage catalogues of IT services that are approved for use on AWS?

A

AWS Service Catalog

105
Q

An e-commerce company wants to assess its applications deployed on EC2 instances for vulnerabilities and deviations from AWS best practices. Which AWS service can be used to facilitate this?

A

AWS Inspector

106
Q

True or False; The AWS Developer Support plan allows one primary contact to open unlimited cases?

A

True

107
Q

A data analytics company has some data stored on Amazon S3 and wants to do SQL based analysis on this data with minimum effort. As a Cloud Practitioner, which AWS service will you suggest for this use case?

A

Amazon Athena

108
Q

Which AWS service is an interactive query service that makes it easy to analyse data in Amazon S3 using standard SQL.

A

Amazon Athena

109
Q

A startup is looking for 24x7 phone based technical support for his AWS account. What is the MOST cost-effective AWS support plan for this use-case?

A

Business

110
Q

Which AWS service provides a simple and secure way to connect to your Linux instances using Secure Shell (SSH)?

A

Amazon EC2 Instance Connect

111
Q

Which AWS service helps with global application availability and performance using the AWS global network?

A

AWS Global Accelerator

112
Q

Which AWS service improves the availability and performance of your applications with local or global users?

A

AWS Global Accelerator

113
Q

True or False; CloudFront can be used to improve application availability and performance using the AWS global network?

A

False, instead use Global Accelerator

114
Q

Which storage is ideal for the temporary storage of information that changes frequently, such as buffers, caches, scratch data, and other temporary content, or for data that is replicated across a fleet of instances, such as a load-balanced pool of web servers?

A

Instance storage

115
Q

What are the four different budget types you can create under AWS Budgets?

A
  • Cost budget
  • Usage budget
  • Reservation budget
  • Savings Plans budget
116
Q

True or False; With AWS Backup, you pay only for the amount of backup storage you use and the amount of backup data you restore in the month?

A

True

117
Q

True or False; Amazon EBS Snapshot storage pricing is based on the amount of space your data consumes in EBS?

A

False, Snapshot storage is based on the amount of space your data consumes in Amazon S3

118
Q

True or False; You will pay a fee each time you read from or write data stored on the EFS - Infrequent Access storage class?

A

True

119
Q

Amazon EBS Snapshots are stored incrementally, which means you are billed only for the changed blocks stored

A

True, Amazon EBS Snapshots are a point in time copy of your block data. For the first snapshot of a volume, Amazon EBS saves a full copy of your data to Amazon S3. EBS Snapshots are stored incrementally, which means you are billed only for the changed blocks stored.

120
Q

True or False; AWS Shield Advanced is a free service for AWS Enterprise Support plan?

A

False, AWS Shield Advanced is a paid service for all customers, irrespective of the Support plan.

121
Q

True or False; AWS Shield Advanced offers protection against higher fees that could result from a DDoS attack?

A

True

122
Q

A leading research firm needs to access information available in old patents and documents (such as PDFs, Text Files, Word documents, etc) present in its huge knowledge base. The firm is looking for a powerful search tool that can dig into these knowledge resources and return the most relevant files/documents. Which is the correct AWS service to address this requirement?

A

AWS Kendra

123
Q

Which AWS service is an intelligent search service powered by machine learning. It reimagines enterprise search for your websites and applications so your employees and customers can easily find the content they are looking for, even when it’s scattered across multiple locations and content repositories within your organization.

A

AWS Kendra

124
Q

Which AWS service is a natural-language processing (NLP) service that uses machine learning to uncover information in unstructured data?

A

AWs Comprehend

125
Q

Which AWS service is a service for building conversational interfaces into any application using voice and text?

A

AWS Lex

126
Q

True or False; Amazon Redshift only supports Single-AZ deployments?

A

True

127
Q

True or False; Amazon EFS is a regional service storing data within and across multiple Availability Zones (AZs) for high availability and durability?

A

True

128
Q

True or False; EC2 instances can access files on an EFS file system across many Availability Zones but not across VPCs and Regions?

A

False

129
Q

True or False; Amazon EC2 instances can access your EFS file system across AZs, regions, and VPCs, while on-premises servers can access using AWS Direct Connect or AWS VPN.

A

True

130
Q

True or False; AWS Organizations can create separate invoices for development and production environments?

A

False

131
Q

An e-commerce company uses AWS Cloud and would like to receive separate invoices for development and production environments. What solution would you recommend for this use-case?

A

Create separate AWS accounts for development and production environments to receive separate invoices

132
Q

Amazon CloudWatch billing metric data is stored in which AWS Region?

A

US East (N. Virginia) - us-east-1

133
Q

True or False; for Cost Allocation Tags in AWS Billing: For each resource, each tag key must be unique, and each tag key can have only one value?

A

True

134
Q

True or False; for Cost Allocation Tags in AWS Billing: You must activate both AWS generated tags and user-defined tags separately before they can appear in Cost Explorer or on a cost allocation report?

A

True

135
Q

True or False; for Cost Allocation Tags in AWS Billing: For each resource, each tag key must be unique, but can have multiple values

A

False, each tag key can have only one value

136
Q

True or False; for Cost Allocation Tags in AWS Billing: Only user-defined tags need to be activated before they can appear in Cost Explorer or on a cost allocation report?

A

False, both kinds of tags (user-defined and AWS generated) need to be activated separately before they can appear in report generation.

137
Q

An organization maintains separate VPCs for each of its departments. With expanding business, the organization now wants to connect all VPCs for better departmental collaboration. Which AWS service will help the organization tackle the issue effectively?

A

AWS Transit Gateway

138
Q

Which AWS service connects VPCs and on-premises networks through a central hub. This simplifies your network and puts an end to complex peering relationships?

A

AWS Transit Gateway

139
Q

True or False; with a growing number of VPCs, connecting them using VPC Peering becomes difficult to manage?

A

True, for connecting multiple VPC together use Transit Gateway

140
Q

True or False; Redshift has encryption automatically enabled?

A

False

141
Q

True or False; S3 Glacier has encryption automatically enabled?

A

True

142
Q

Two components of an AWS Site-to-Site VPN?

A

Customer Gateway and Virtual Private Gateway

143
Q

Two mandatory elements of AWS Identity and Access Management (IAM) policies?

A
  • Action
  • Effect
144
Q

Trusted Advisor analyses your AWS environment and provides best practice recommendations for which 5 categories?

A
  • Cost optimisation
  • Performance
  • Security
  • Fault tolerance
  • Service limits
145
Q

Which AWS Support plan provides general architectural guidance on how services can be used for various use-cases, workloads, or applications?

A

Business

146
Q

Which AWS service is a complimentary service to create data-driven business cases for AWS Cloud planning and migration?

A

AWS Migration Evaluator

147
Q

Security groups are stateful or stateless?

A

stateful, if you send a request from your instance, the response traffic for that request is allowed to flow in regardless of inbound security group rules

148
Q

NACL (Network Access Control Lists) are stateful or stateless?

A

Stateless - which means that responses to allowed inbound traffic are subject to the rules for outbound traffic (and vice versa)

149
Q

What is the difference between warm-standby and pilot-light disaster recovery strategies?

A

Warm standby can handle traffic at reduced levels immediately. Pilot light requires you to first deploy infrastructure and then scale out resources before the workload can handle requests.

150
Q

Which AWS services can be used together to send alerts whenever the AWS account root user signs in (two)?

A
  • CloudWatch
  • SNS
151
Q

True or False; using AWS organisations, users can receive cost benefits of other user’s reserved instances only if they are in the same Availability Zone?

A

True

152
Q

True or False; You can use RDS Read Replicas for both improved read performance as well as Disaster Recovery

A

True

153
Q

Which AWS storage service can be directly used with on-premises systems?

A

EFS

154
Q

True or False, S3 can be directly used with on-premises systems?

A

False, S3 can be accessed from on-premises only via AWS Storage Gateway.

155
Q

Which AWS service is a cloud service solution that makes it easy to establish a dedicated network connection from your premises to AWS?

A

AWS Direct Connect

156
Q

True or False; Global Accelerator is a good fit for non-HTTP use cases?

A

True

157
Q

Which AWS service is a networking service that helps you improve the availability and performance of the applications that you offer to your global users?

A

AWS Global Accelerator

158
Q

True or False; Global Accelerator provides static IP addresses that act as a fixed entry point to your applications?

A

True

159
Q

True or False; Global Accelerator cannot be configured with an Elastic Load Balancer (ELB)?

A

False. A regional ELB load balancer is an ideal target for AWS Global Accelerator.

160
Q

True or False; Global Accelerator uses the AWS global network and its edge locations. But the edge locations used by Global Accelerator are different from Amazon CloudFront edge locations?

A

False, AWS Global Accelerator and Amazon CloudFront use the same edge locations.

161
Q

Which AWS service enables fast, easy, and secure transfers of files over long distances between your client and your Amazon S3 bucket?

A

S3 Transfer Accelerator

162
Q

Which AWS entity enables you to privately connect your VPC to an Amazon SQS queue?

A

VPC Interface Endpoint, this is supported by all services. Only S3 and DynamoDB support VPC Gateway Endpoint

163
Q

Which two AWS services are supported by VPC Gateway Endpoint?

A

S3 and DynamoDB

164
Q

True or False; Billing alarms can be triggered via Cost Explorer?

A

False

165
Q

True or False; S3 Glacier has no data retrieval fee?

A

False

166
Q

True or False; S3 Intelligent-Tiering does not charge any data retrieval fee?

A

True

167
Q

Which AWS tool/service will help you define your cloud infrastructure using popular programming languages such as Python and JavaScript?

A

AWS CDK (Cloud Development Kit)

168
Q

True or False; you use the AWS CDK framework to author AWS CDK projects which are executed to generate CloudFormation templates?

A

True

169
Q

Which IAM Security Tool shows the service permissions granted to a user and when those services were last accessed?

A

IAM Access Advisor

170
Q

Using which IAM Security Tool can generate and download a credential report that lists all users in your account and the status of their various credentials, including passwords, access keys, and MFA devices?

A

IAM Credentials Report

171
Q

True or False; IAM credentials report can be used to review permissions granted to a user?

A

False

172
Q

True or False; EC2 Auto Scaling can detect when an instance is unhealthy, terminate it, and replace it with a new one?

A

True

173
Q

How much data can you transfer per Snowmobile?

A

You can transfer up to 100PB per Snowmobile

174
Q

Which AWS service is a secure online data transfer service that simplifies, automates, and accelerates copying terabytes of data to and from AWS storage services?

A

AWS DataSync

175
Q

True or False; AWS Trusted Advisor can be used to get operational insights of AWS resources?

A

False, use Systems Manager for operational insights, not Trusted Advisor

176
Q

A Cloud Practitioner would like to get operational insights of its resources to quickly identify any issues that might impact applications using those resources. Which AWS service can help with this task?

A

AWS Systems Manager

177
Q

Which AWS service lets you add user sign-up, sign-in, and access control to your web and mobile apps quickly and easily?

A

AWS Cognito

178
Q

Which AWS service can be used to generate, use, and manage encryption keys on the AWS Cloud?

A

CloudHSM

179
Q

With which AWS service can send, store, and receive messages between software components at any volume, without losing messages or requiring other services to be available?

A

SQS

180
Q

What billing timeframes is applied when running a Windows EC2 on-demand instance?

A

Pay per second

181
Q

True or False Total Cost of Ownership (TCO) refers to owning the infrastructure, I.e. on-premises, as opposed to via AWS

A

True

182
Q

True or False; Route 53 provides IP routing?

A

False

183
Q

True or False; Route 53 provides health checks and monitoring?

A

True

184
Q

Which AWS service lets you easily create and publish interactive BI dashboards that include Machine Learning-powered insights?

A

AWS Quicksight

185
Q

A company is looking at a service/tool to automate and minimize the time spent on keeping the server images up-to-date. These server images are used by EC2 instances as well as the on-premises systems.

Which AWS service will help achieve the company’s need?

A

Amazon EC2 Image Builder

186
Q

Which AWS service significantly reduces the effort of keeping EC2 images up-to-date and secure?

A

Amazon EC2 Image Builder

187
Q

What data sources are used by Amazon Detective to analyze events and identify potential security issues?

A
  • AWS CloudTrail logs
  • VPC Flow Logs
  • Amazon GuardDuty findings
188
Q

Which AWS service allows you to connect any number of IoT devices to the cloud without requiring you to provision or manage servers?

A

AWS IoT Core

189
Q

Which AWS service provides the easiest way to set up and govern a new, secure, multi-account AWS environment based on best practices?

A

AWS Control Tower

190
Q

True or False; S3 buckets are region-specific?

A

True

191
Q

Which AWS service is a fast, reliable, fully-managed graph database service that makes it easy to build and run applications that work with highly connected datasets?

A

AWS Neptune

192
Q

Which AWS service is a fully managed service that allows you to join public blockchain networks or set up and manage scalable private blockchain networks using popular open-source frameworks?

A

Amazon Managed Blockchain

193
Q

True or False; QLDB is not a blockchain technology?

A

True

194
Q

Which AWS service runs MongoDB in AWS?

A

DocumentDB

195
Q

Which AWS service is a graphical user interface you can use to manage your AWS Snowball devices?

A

OpsHub

196
Q

Which services/tools offers a user-friendly graphical user interface to manage AWS Snowball devices without a need for command-line interface or REST APIs?

A

AWS OpsHub

197
Q

True or False; With Elastic Beanstalk, you can quickly deploy and manage applications in the AWS Cloud without having to learn about the infrastructure that runs those applications?

A

True

198
Q

True or False; AWS Elastic Beanstalk supports web applications built on different languages. But, Elastic Beanstalk cannot be used for deploying non-web applications?

A

False, non-web applications can also be deployed using Elastic Beanstalk.

199
Q

True or False; You can use Resource Groups to organize your AWS resources. Resource groups make it easier to manage and automate tasks on large numbers of resources at a time?

A

True

200
Q

Which AWS service is a DynamoDB-compatible caching service that enables you to benefit from fast in-memory performance for demanding applications.

A

DynamoDB Accelerator

201
Q

True or False, there is a scope for message loss in SNS?

A

True, because it is a push system, the destination may not be available when the message is sent, so the message may be lost

202
Q

Which free tool helps to review the state of your workloads and compares them to the latest AWS architectural best practices after you have answered a series of questions about your workload?

A

AWS Well-Architected Tool

203
Q

True or False; AWS WAF can be deployed on Amazon EC2 instances directly?

A

False

204
Q

AWS offers two types of Savings Plans, name both

A
  • Compute Savings Plan
  • EC2 Instance Savings Plan
205
Q

True or False; AWS has the concept of a Region, which is a physical location around the world where AWS clusters the data centers?

A

True

206
Q

True or False; AWS calls each group of logical data centers as an Availability Zone?

A

True

207
Q

True or False; All traffic between AZ’s is encrypted?

A

True

208
Q

You can use AWS Pricing Calculator to get a forecast of your spending for the next 12 months?

A

False

209
Q

You can use AWS Cost Explorer to get a forecast of your spending for the next 12 months?

A

True