Random questions Flashcards

1
Q

Which of the following allows you to Watch a single metric over a time period that you specify, and perform one or more actions based on the value of the metric relative to a given threshold over a number of time periods.

a. Amazon Managed Grafana
b. Amazon CloudTrail
c. Amazon Cloudwatch
d. Amazon Redshift

A

Ans C

Amazon Managed Grafana does allow for you to watch metrics in a dashboard, but cloudwatch
allows you to set given thresholds for selected metrics and have an alert message your or do something when the alert triggers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which of the following is not a design principles for operational excellence in the cloud according to the well architected framework pillars:

a. Perform operations as code
b. Make frequent, small, reversible changes
c. Refine operations procedures frequently
d. Anticipate and adopt new, more efficient hardware and software offerings
e. Learn from all operational failures

A

Answer d is actually one of the six design principles for sustainability in the cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which one of the following is not a feature or benefit
of the AWS budgets?

a. monitor your aggregate utilization and coverage metrics for your Reserved Instances (RIs) or Savings Plans
b. enable simple-to-complex cost and usage tracking
c. set up optional notifications that warn you if you exceed, or are forecasted to exceed, your budgeted amount for cost or usage
d. Allows you to share the budgets by using a url link provided

A

Ans: d
This is actually something you can do with cost explorer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which one of the following is not a feature or benefit
of the AWS pricing calculator?

a. Allows you to share the estimates by using a url link provided
b. Allows you to compare actual vs. budgeted use
c. You can use it to model your solutions before building them
d. Allows you to view prices of AWS services
e. It is a web-based planning tool

A

Ans. b
this is actually something you can do with AWS budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which one of the following is not included in the business
support plan?

a. Response time for Production system down: < 1 hour
b. access to a technical account manager with expertise in all AWS services
c. Response time for System impaired: < 12 hours
d. All TrustedAdvisor checks

A

Ans. b
Only the enterprise level support plans have access to a TAM.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which one of the following is not a pillar of the Well architected
architecture?

a. cost optimization
b. sustainability
c. Reliability
d. monitoring and reporting

A

Ans. d

Pillar 1: Operational Excellence
Pillar 2: Security
Pillar 3: Reliability
Pillar 4: Performance Efficiency
Pillar 5: Cost Optimization
Pillar 6: Sustainability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which are the three elements of the AWS global infrastructure?

a. Availability Zones
b. Edge Locations
C. Regions
d. Hybrid locations

A

A, B and C
Availability Zones - discrete data centers each with their own power, servers, networking
Edge Locations - points of presence, located in various cities around the world. Cloudfront leverages these edge locations
Regions - physical geographical locations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which of the following are categories of recommedations
provided by AWS trusted Advisor? (choose three)

a. cost optimization
b. fault tolerance
c. performance
d. least privilege access
e. high availability

A

Ans. a, b and c

Know the categories of trusted advisor

Cost optimization
Performance
Security
Fault tolerance
Service limits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which of the following are categories of AWS Trusted Advisor? (Choose two.)
A. Fault Tolerance
B. Instance Usage
C. Infrastructure
D. Performance
E. Storage Capacity

A

AD
Like your customized cloud expert, AWS Trusted Advisor analyzes your AWS environment and provides best practice recommendations in five categories: cost optimization, performance, security, fault tolerance and service limits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AWS CAF groups its capabilities in six perspectives, which of the following is a perspective (choose three)

a. Business
b. People
c. cost
d. Governance
e. regions

A

A, b, and d

AWS CAF groups its capabilities in six perspectives: Business, People, Governance, Platform, Security, and Operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which one of the following is a set of capabilities that functionally related stakeholders own or manage in the cloud transformation journey?

A. AWS Config
B. AWS CAF
C. AWS Well architected framework
D. AWS Organizations
E. AWS pillars of excellence

A

B
AWS CAF groups its capabilities in six perspectives: Business, People, Governance, Platform, Security, and Operations. Each perspective comprises a set of capabilities that functionally related stakeholders own or manage in the cloud transformation journey.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False
You would use the AWS CAF to identify and prioritize transformation opportunities, evaluate and improve your cloud readiness, and iteratively evolve your transformation roadmap.

A

True
The AWS Cloud Adoption Framework (AWS CAF) leverages AWS experience and best practices to help you digitally transform and accelerate your business outcomes through innovative use of AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which of the follow AWS CAF perspectives serves as a bridge between technology and business, accelerating the cloud journey to help organizations more rapidly evolve to a culture of continuous growth, learning, and where change becomes business-as-normal, with focus on culture, organizational structure, leadership, and workforce.

A. Business
B. People
C. Governance
D. Platform
E. Operations

A

B People
The People perspective serves as a bridge between technology and business, accelerating the cloud journey to help organizations more rapidly evolve to a culture of continuous growth, learning, and where change becomes business-as-normal, with focus on culture, organizational structure, leadership, and workforce. Common stakeholders include CIO, COO, CTO, cloud director, and cross-functional and enterprise-wide leaders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which one of the follow AWS CAF perspective helps you orchestrate your cloud initiatives while maximizing organizational benefits and minimizing transformation-related risks.

A. Business
B. People
C. Governance
D. Platform
E. Operations
F. Security

A

C
The Governance perspective helps you orchestrate your cloud initiatives while maximizing organizational benefits and minimizing transformation-related risks. Common stakeholders include chief transformation officer, CIO, CTO, CFO, chief data officer (CDO), and chief risk officer (CRO).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which ONE of the following AWS CAF perspectives helps ensure that your cloud services are delivered at a level that meets the needs of your business.

A. Business
B. People
C. Governance
D. Platform
E. Operations
F. Security

A

E
The Operations perspective helps ensure that your cloud services are delivered at a level that meets the needs of your business. Common stakeholders include infrastructure and operations leaders, site reliability engineers, and information technology service managers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A company is planning to run a global marketing application in the AWS Cloud. The application will feature videos that can be viewed by users. The company must ensure that all users can view these videos with low latency.
Which AWS service should the company use to meet this requirement?
A. AWS Auto Scaling
B. Amazon Kinesis Video Streams
C. Elastic Load Balancing
D. Amazon CloudFront

A

D
Cloudfront used edge locations to ensure content is cached in locations close to the users to help with low latency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which pillar of the AWS Well-Architected Framework refers to the ability of a system to recover from infrastructure or service disruptions and dynamically acquire computing resources to meet demand?
A. Security
B. Reliability
C. Performance efficiency
D. Cost optimization

A

B
The reliability pillar focuses on workloads performing their intended functions and how to recover quickly from failure to meet demands. Key topics include distributed system design, recovery planning, and adapting to changing requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which of the following are benefits of migrating to the AWS Cloud? (Choose two.)
A. Operational resilience
B. Discounts for products on Amazon.com
C. Business agility
D. Business excellence
E. Increased staff retention

A

A and C
There are several benefits to migrating to the AWS Cloud, including:

A. Operational resilience: The AWS Cloud is designed to be highly available and scalable, which can help organizations improve their operational resilience and reduce the impact of failures or disruptions.

C. Business agility: Migrating to the AWS Cloud can help organizations to increase their business agility by allowing them to quickly and easily deploy new applications and services, scale their infrastructure up or down as needed, and experiment with new technologies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

A company is planning to replace its physical on-premises compute servers with AWS serverless compute services. The company wants to be able to take advantage of advanced technologies quickly after the migration.
Which pillar of the AWS Well-Architected Framework does this plan represent?
A. Security
B. Performance efficiency
C. Operational excellence
D. Reliability

A

B
Design Principles
There are five design principles for performance efficiency in the cloud:

Democratize advanced technologies
Go global in minutes
#####Use serverless architectures#####
Experiment more often
Consider mechanical sympathy

The performance efficiency pillar focuses on structured and streamlined allocation of IT and computing resources. Key topics include selecting resource types and sizes optimized for workload requirements, monitoring performance, and maintaining efficiency as business needs evolve.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

A large company has multiple departments. Each department has its own AWS account. Each department has purchased Amazon EC2 Reserved Instances.
Some departments do not use all the Reserved Instances that they purchased, and other departments need more Reserved Instances than they purchased.
The company needs to manage the AWS accounts for all the departments so that the departments can share the Reserved Instances.
Which AWS FEATURE should the company use to meet these requirements?
A. AWS Systems Manager
B. Cost Explorer
C. AWS Trusted Advisor
D. AWS Organizations

A

D organinzations - used to manage multiple accounts.
Centrally manage billing and costs
Organizations provides you with a single consolidated bill. In addition, you can view usage from resources across accounts and track costs using AWS Cost Explorer, and optimize your usage of compute resources using AWS Compute Optimizer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which AWS services or features provide disaster recovery solutions for Amazon EC2 instances? (Choose two.)
A. ׀*׀¡2 Reserved Instances
B. EC2 Amazon Machine Images (AMIs)
C. Amazon Elastic Block Store (Amazon EBS) snapshots
D. AWS Shield
E. Amazon GuardDuty

A

B and C
You can back up Amazon EC2 instances used by your workload as Amazon Machine Images (AMIs). The AMI is created from snapshots of your instance’s root volume and any other EBS volumes attached to your instance. You can use this AMI to launch a restored version of the EC2 instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

TRUE or FALSE
If you have a Basic Support and Developer Support plan, you can use the Trusted Advisor console to access checks in the following security category:

Amazon EBS Public Snapshots

Amazon RDS Public Snapshots

Amazon S3 Bucket Permissions

IAM Use

MFA on Root Account

Security Groups – Specific Ports Unrestricted

A

TRUE
If you have a Basic Support and Developer Support plan, you can use the Trusted Advisor console to access all checks in the Service limits category and ALL the following checks in the security category mentioned.

Amazon EBS Public Snapshots

Amazon RDS Public Snapshots

Amazon S3 Bucket Permissions

IAM Use

MFA on Root Account

Security Groups – Specific Ports Unrestricted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

A company is migrating to the AWS Cloud instead of running its infrastructure on premises.
Which of the following are advantages of this migration? (Choose two.)
A. Elimination of the need to perform security auditing
B. Increased global reach and agility
C. Ability to deploy globally in minutes
D. Elimination of the cost of IT staff members
E. Redundancy by default for all compute services

A

B and C

he six advantages of cloud computing are:
* Trade upfront expense for variable expense.
* Benefit from massive economies of scale.
* Stop guessing capacity.
* Increase speed and agility. Yes B
* Stop spending money running and maintaining data centers.
* Go global in minutes. YES C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

A user is comparing purchase options for an application that runs on Amazon EC2 and Amazon RDS. The application cannot sustain any interruption. The application experiences a predictable amount of usage, including some seasonal spikes that last only a few weeks at a time. It is not possible to modify the application.
Which purchase option meets these requirements MOST cost-effectively?
A. Review the AWS Marketplace and buy Partial Upfront Reserved Instances to cover the predicted and seasonal load.
B. Buy Reserved Instances for the predicted amount of usage throughout the year. Allow any seasonal usage to run on Spot Instances.
C. Buy Reserved Instances for the predicted amount of usage throughout the year. Allow any seasonal usage to run at an On-Demand rate.
D. Buy Reserved Instances to cover all potential usage that results from the seasonal usage.

A

C
C is the correct answer, the question explicitly mentioned that “The application cannot sustain any interruption” of which Spot Instances are ideal for workloads with flexible start and end times, or that can withstand interruptions. Ideally we want pricing that doesn’t allow interruption in this case it will be On-Demand.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Where can I get more exam questions

A

https://www.examtopics.com/exams/amazon/aws-certified-cloud-practitioner/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

When we mention AWS global content delivery network which service
are we talking about?

A. Region
B. Edge Location
C. Local Zone
D. Availability Zone

A

Ans. B

this is cloudfront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

A company wants to migrate a critical application to AWS. The application has a short runtime. The application is invoked by changes in data or by shifts in system state. The company needs a compute solution that maximizes operational efficiency and minimizes the cost of running the application.
Which AWS solution should the company use to meet these requirements?
A. Amazon EC2 On-Demand Instances
B. AWS Lambda
C. Amazon EC2 Reserved Instances
D. Amazon EC2 Spot Instances

A

b
From: https://aws.amazon.com/lambda/

  1. Run code without provisioning or managing infrastructure. Simply write and upload code as a .zip file or container image.
  2. Automatically respond to code execution requests at any scale, from a dozen events per day to hundreds of thousands per second.
  3. Save costs by paying only for the compute time you use—by per-millisecond—instead of provisioning infrastructure upfront for peak capacity.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Which AWS service or feature allows users to connect with and deploy AWS services programmatically?
A. AWS Management Console
B. AWS Cloud9
C. AWS CodePipeline
D. AWS software development kits (SDKs)

A

d

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

A company plans to create a data lake that uses Amazon S3.
Which factor will have the MOST effect on cost?
A. The selection of S3 storage tiers
B. Charges to transfer existing data into Amazon S3
C. The addition of S3 bucket policies
D. S3 ingest fees for each request

A

A
The most “effect” on cost. Transferring the data is going to be a set cost. There’s not really multiple options to effect the price of transferring. Which storage tier they pick out of all the options can largely effect the final cost.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Which AWS service or feature can a company use to determine which business unit is using specific AWS resources?
A. Cost allocation tags
B. Key pairs
C. Amazon Inspector
D. AWS Trusted Advisor

A

Cost allocation tags
https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/cost-alloc-tags.html

A tag is a label given to aws resources , each have key and values, each resources and key must be unique and each key have only one value .

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

TRUE or FALSE
You can use tags to organize your resources, and cost allocation tags to track your AWS costs on a detailed level. After you activate cost allocation tags, AWS uses the cost allocation tags to organize your resource costs on your cost allocation report, to make it easier for you to categorize and track your AWS costs.

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Which AWS hybrid storage service enables a user’s on-premises applications to seamlessly use AWS Cloud storage.

a. Internet Gateway
b. AWS Storage Gateway
c. S3 Standard IA
d. S3 Standard

A

B
AWS Storage Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

A user has limited knowledge of AWS services, but wants to quickly deploy a scalable Node.js application in an Amazon VPC.

Which service should be used to deploy the application?

a. AWS Lambda
b. AWS EBS
c. AWS Elastic Beanstalk
d. AWS code deploy

A

C
AWS Elastic Beanstalk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

A Service Control Policy (SCP) is used to manage the maximum available permissions and is associated with which of the following?

Service control policies (SCPs) manage permissions for which of the following?

a. Availability Zone
b. Regions
c. Organizational Unit
d. IAM

A

C
AWS SCP is a collection of permissions that can be applied at the root level of an AWS account or an Organizational Unit (OU) within an AWS Organization. These policies serve as guardrails for the accounts in the member account or OU, limiting the actions that users, groups, or roles within the account can take.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What can be used to allow an application running on an Amazon EC2 instance to securely store data in an Amazon S3 bucket without using long-term credentials?

a. groups
b. group policy
c. AWS config
d. roles

A

D
AWS IAM Role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Which AWS service should a Cloud Practitioner use to automate configuration management using Puppet?

a. AWS OpsWork
b. AWS config
c. AWS shield
d. AWS automat

A

A
AWS OpsWorks is a configuration management service that helps you configure and operate applications in a cloud enterprise by using Puppet or Chef. AWS OpsWorks Stacks and AWS OpsWorks for Chef Automate let you use Chef cookbooks and solutions for configuration management, while OpsWorks for Puppet Enterprise lets you configure a Puppet Enterprise master server in AWS. Puppet offers a set of tools for enforcing the desired state of your infrastructure, and automating on-demand tasks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Which Amazon EC2 pricing model should be avoided if a workload cannot accept interruption if capacity becomes temporarily unavailable?

a. spot instances
b. on-demand instances
c. RDS
d. EC2 standard IA

A

A
spot instances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Which AWS-managed service can be used to process vast amounts of data using a hosted Hadoop framework?

a. AWS Redshift
b. AWS Gateway
c. Amazon RDS
d. Amazon EMR

A

D
Amazon EMR; Amazon Elastic Map Reduce (EMR) is a web service that enables businesses, researchers, data analysts, and developers to easily and cost-effectively process vast amounts of data. EMR utilizes a hosted Hadoop framework running on Amazon EC2 and Amazon S3.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Which AWS Service that enables you to continually monitor your resources for adherence to best practices?

a. Amazon GuardDuty
b. AWS Artifact
c. Amazon Inspector
d. AWS config

A

D
AWS config
AWS Config is a config tool that helps you assess, audit, and evaluate the configurations and relationships of your resources.
You can use the service to automate the evaluation and remediation of recorded configurations against desired configurations. You also can review changes in configurations and relationships between AWS resources and dive into the history of a resource configuration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Which of the following is a security serivce that provides protection
against a type of attack that floods network traffic to you
application

a. Amazon Macie
b. Amazon Shield
c. Amazon GuardDuty
d. Amazon Inspector

A

Ans. B
Amazon Shield provides protection against DDoS threats
enables on-going threat detection
you keep it running
there is two - shield and advanced shield

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Which of the following security services utilizies machine
learning to analyze data stored in amazon S3, and provides
alerts if it detects anything unusual?

A. Amazon Inspector
b. Amazon CloudWatch
c. Amazon Macie
d. Amazon Shield

A

Ans. C
it uses ML to analyzed data stored in S3
provides dashboards that show how data is stored and accessed
allows you to have alerts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

The service proves a network reachability and host assessment,
which type is it?

A. Amazon Cloudwatch
b. Amazon Service Catalog
c. Amazon inspector
d. Amazon GuardDuty

A

ans. C
Amazon inspector is charged by instance per assessment
two types of rules packages network reachability and host assessment.
Amazon Inspector is a vulnerability management service that continuously scans your AWS workloads for software vulnerabilities and unintended network exposure. Amazon Inspector automatically discovers and scans running Amazon EC2 instances, container images in Amazon Elastic Container Registry (Amazon ECR), and AWS Lambda functions for known software vulnerabilities and unintended network exposure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

If you would like to use pre-defined solutions in AWS which two
would you choose?

a. AWS service catalog
b. AWS cloudformation
c. AWS marketplace
d. AWS config

A

Ans. a and c

aws service catalog - targetd to serve as an organization
service catalog in the cloud. Can include single server
image to multi tier custom applications
enables organizations to leverage services that meet
compliance
supports a lifecyle for services released in the catalog.

AWS marketplace - third party solutions for any aws
customer to run. SaaS solutions, cloud formation solutions.
provides different license types.
charges appear on your AWS bill - they will be an additional
charge.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Which aws developer service is like GIT?

a. aws codecommit
b. aws code build
c. aws codepipeline
d. aws codedeploy
e. aws codestar

A

Ans: a
Securely host highly scalable private Git repositories and collaborate on code
AWS CodeCommit is a secure, highly scalable, fully managed source control service that hosts private Git repositories.
codecommit is a utility git for repositories
you can control access with IAM policies
serves as an alternative to git hub

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Which of the following would you use if you needed a way
to manage the deployment of your customer applications?

a. aws CodeCommit
b. aws code build
c. aws codepipeline
d. aws CodeDeploy
e. aws codestar

A

Ans: D
AWS CodeDeploy is a managed deployement service for
deploying your custom applications
Deploys to amazon ec2, fargate, lambda and on-premise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Which of the following provides the capabilites to
automate building, testing and deploying your custom appliccation
in AWS?

a. aws CodeCommit
b. aws code build
c. aws codepipeline
d. aws CodeDeploy
e. aws codestar

A

ans: C
AWS codepipeline is a fully managed continous deliver service
on AWS
provides the capabilites to automate building, testing
and deploying
integrate with other developer tools as well as Github

AWS CodeStar is a workflow tool, that creates a complete
continous delivery toolchain for custom applications.
you only far charged for the other services uses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

They want to ensure your departments follow best practice
and are compliant. Which service tool should they use
so they can create compliant services that the department could use ?

a. AWS Marketplace
b. AWS service catalog
c. AWS Inspector
d. AWS CodeStar

A

B
Service catalogs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

They want to ensure your departments follow best practice
and are compliant. Which service should tool should they use to
so they can create compliant servies that the department could use ?

a. AWS Marketplace
b. AWS service catalog
c. AWS Inspector
d. AWS CodeStar

A

Ans. AWS service catalog
it is ‘just for use’ for your organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

Your company deals with sensitive information. You have
put reasonable policies in place to store this data in
S3. Which of the following aws services should you use
to ensure this?

a. Amazon Macie
b. Amazon Inspector
c. Amazon GuardDuty
d. Amazon Artifact

A

ans. A
Amazon Macie
gives your the ability to find sensitive data and monitor it
for anomalies, then alert you if it sees access control issues.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

If you are working with your data science team to move their processing work to the cloud, what service would enable them to continue to process data with Apache HBase without having to handle the configuration of the underlying instances?

a. Amazon Sagemaker

b. AWS Glue

c. Amazon DynamoDB

d. Amazon EMR

A

ans. D
Amazon EMR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

Jerry wants to create a custom application where users sign-in with their Google account. He wants each signed-in user to have access to an S3 bucket. What service would enable this functionality?

a. Amazon Cognito

a. AWS SSO

b. Amazon Guard Duty

c. Active Directory

A

ans. A
Amazon Cognito provides authentication, authorization, and user management for your web and mobile apps. Your users can sign in directly with a user name and password, or through a third party such as Facebook, Amazon, Google or Apple.

The two main components of Amazon Cognito are user pools and identity pools.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

Amazon Inspector automatically discovers and scans which of the following (choose two)?
a. Amazon EC2 instances
b. container images in Amazon Elastic Container Registry (Amazon ECR)
c. AWS S3
d. AWS RDS

A

Answers A and B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

Amazon Inspector automatically discovers and scans which of the following (choose two)?
a. container images in Amazon Elastic Container Registry (Amazon ECR)
b. AWS elastic beanstalk images
c. AWS S3
d. AWS Lambda functions

A

A and D

When activated, Amazon Inspector automatically discovers all eligible resources and begins continuous scans of those resources. Amazon Inspector scans for software vulnerabilities and unintended network exposure. Amazon Inspector also runs scans in response to events, such as the installation of a new application or patch.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

Which of the following services enables serverless querying of data stored within Amazon S3 using standard SQL queries?

A. Amazon Quicksight
B. Amazon Athena
C. Amazon CloudTrail
D. Amazon CloudSearch

A

B
Amazon Athena

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

Which one of the following services would you use for Managed search service for custom applications?

A. Amazon CloudSearch
B. Amazon Athena
C. Amazon CloudTrail
D. Amazon Quicksight

A

A
Amazon CloudSearch is a managed service in the AWS Cloud that makes it simple and cost-effective to set up, manage, and scale a search solution for your website or application.
Amazon CloudSearch supports 34 languages and popular search features such as highlighting, autocomplete, and geospatial search.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

Which on of the following is a Data workflow orchestration service that supports
multiple AWS services providing extract, transform, and
load (ETL) capabilities?

A. Amazon CloudSearch
B. Amazon Data Pipeline
C. Amazon EMR
D. Amazon Quicksight

A

B
AWS Data Pipeline is a web service that helps you reliably process and move data between different AWS compute and storage services, as well as on-premises data sources, at specified intervals. With AWS Data Pipeline, you can regularly access your data where it’s stored, transform and process it at scale, and efficiently transfer the results to AWS services such as Amazon S3, Amazon RDS, Amazon DynamoDB, and Amazon EMR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

Which AWS services can you transfer the results of ETL when using AWS Data Pipeline? (Pick two)

a. Amazon S3
b. Amazon EC2
c. Amazon RDS
d. Amazon Containers

A

A and C
With AWS Data Pipeline, you can regularly access your data where it’s stored, transform and process it at scale, and efficiently transfer the results to AWS services such as Amazon S3, Amazon RDS, Amazon DynamoDB, and Amazon EMR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

Which AWS services can you transfer the results of ETL when using AWS Data Pipeline?

a. Amazon EMR
b. Amazon EC2
c. Amazon Lambda
d. Amazon DynamoDB

A

a d With AWS Data Pipeline, you can regularly access your data where it’s stored, transform and process it at scale, and efficiently transfer the results to AWS services such as Amazon S3, Amazon RDS, Amazon DynamoDB, and Amazon EMR..

AWS Data Pipeline allows you to take advantage of a variety of features such as scheduling, dependency tracking, and error handling. You can use activities and preconditions that AWS provides and/or write your own custom ones. This means that you can configure an AWS Data Pipeline to take actions like run Amazon EMR jobs, execute SQL queries directly against databases, or execute custom applications running on Amazon EC2 or in your own datacenter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

Which of the following AWS tools and services allows you to run SQL queries ? (Pick two)

a. AWS Data Pipeline
b. AWS Athena
c. Amazon CloudSearch
d. Amazon Translate

A

A and B
AWS Data Pipeline create pipelines for a number of more complex use cases, such as regularly processing your log files, archiving data to Amazon S3, or running periodic SQL queries.
AWS Athena is a SQL service to pull that data out of S3 and push it into a relational structure. It’s great for inspecting buckets, transforming data through ETL processes, or cleaning data to send to services like Hadoop.
Amazon Athena is an interactive query service that makes it easy to analyze data directly in Amazon Simple Storage Service (Amazon S3) using standard SQL. With a few actions in the AWS Management Console, you can point Athena at your data stored in Amazon S3 and begin using standard SQL to run ad-hoc queries and get results in seconds.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

Which one of the following is a compliance service in AWS that is a Fully-managed service that continually monitors your AWS account and resources for potential malicious behavior and anomalies?

a. Amazon CloudTrail
b. Amazon Artifact
c. Amazon GuardDuty
d. Amazon config

A

C
GuardDuty is more tilted towards indications of actual compromise .
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts, workloads, and data stored in Amazon S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

Which of the following is AWS GuardDuty used for?

a. performs functions such as examining every single query on your application
b. protects web applications from DDoS attacks
c. monitor and analyze all activities for your Amazon Web Services account
d. Detects sensitive information and personal information and provides alerts to users

A

A and C
GuardDuty =This tool of AWS is from AWS basically to detect threats. Guardduty reads the logs throughout AWS and keeps the users posted in case of threats. AWS Guardduty is the best complete application protection service because of the coverage and the complete scope it can provide. No other service can.

Amazon Macie = Detects sensitive information and personal information and provides alerts to users.

Amazon Shield = Service from AWS that protects web applications from DDoS attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

Which of the following service does this describe?
Continuously monitor your AWS accounts, instances, serverless and container workloads, users, databases, and storage for potential threats.

a. Amazon GuardDuty
b. Amazon Inspector
c. Amazon Shield
d. Amazon detective

A

A
Amazon GuardDuty is a threat detection service that continuously monitors your AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation.
the different workload and resource types that you can continuously monitor for threats using Amazon GuardDuty. The items outlined are: Amazon S3, databases, container workloads, instance workloads, accounts and users, and serverless.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

Which of the 7 Rs in the Migration strategy does this use case describe: Enhanced modernization or upgrade of the application/service underlaying components such as OS and Databases.

a. replatform
b. rehost
c. rebuild
d. refactor

A

A
Replatform: Enhanced modernization or upgrade of the application/service underlaying components such as OS and Databases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

Which of the 7 Rs in the Migration strategy does this use case describe: Do nothing and keep running the application in the current location.

a. replatform
b. rehost
c. retain
d. refactor

A

Retain: Do nothing and keep running the application in the current location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

Which of the 7 Rs in the Migration strategy does this use case describe: Modernization of the application by applying changes to the code base in order to support a modernization pattern and/or changing its architecture (e.g., containerization, serverless)

a. replatform
b. rehost
c. retain
d. refactor

A

D
Refactor / Re-architect: Modernization of the application by applying changes to the code base in order to support a modernization pattern and/or changing its architecture (e.g., containerization, serverless)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

Which of the 7 Rs in the Migration strategy does this use case describe: Rapid migration of servers and applications without architectural, technology or functionality changes.

a. replatform
b. rehost
c. retain
d. refactor

A

B
Rehost: Rapid migration of servers and applications without architectural, technology or functionality changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

Which of the 7 Rs in the Migration strategy does this use case describe: Decommission the application without migrating or modernizing.

a. replatform
b. rehost
c. retire
d. refactor

A

C
Retire: Decommission the application without migrating or modernizing.

68
Q

Which of the 7 Rs in the Migration strategy does this use case describe: Rapid migration of servers and applications to vmware cloud on AWS

a. relocate
b. rehost
c. retire
d. refactor

A

A
Relocate: Rapid migration of servers and applications to vmware cloud on AWS.

69
Q

Which of the 7 Rs in the Migration strategy does this use case describe: Purchase, configure or customize a COTS (Commercial Of The Shelf) or SaaS (Software as a Service) product.

a. relocate
b. rehost
c. retire
d. repurchase

A

D
Repurchase: Purchase, configure or customize a COTS (Commercial Of The Shelf) or SaaS (Software as a Service) product.

70
Q

Which of the 7 Rs in the Migration strategy are you using when you decide to replace some of your on-premise applications with AWS containers and/or serverless services

a. refactor
b. rehost
c. retire
d. repurchase

A

A
Refactor - this is when you replace some systems with containers, microsystems, use devops, perform code refactoring, use managed services databases

71
Q

What are some Trusted advisor checks for the fault tolerance category? (pick 3)

a. Amazon ECS service using a single AZ
b. ELB Cross-Zone Load Balancing
c. Amazon S3 Bucket Permissions
d. Amazon RDS Backups

A

A, B and D

72
Q

What of the following trusted advisor checks falls in the performance category ? (pick two)

a. Large Number of Rules in an EC2 Security Group
b. Amazon EBS under-provisioned volumes
c. Amazon EBS over-provisioned volumes
d. IAM Use

A

A and B

Large Number of Rules in an EC2 Security Group
Description
Checks each Amazon Elastic Compute Cloud (Amazon EC2) security group for an excessive number of rules.

If a security group has a large number of rules, performance can be degraded.

Amazon EBS under-provisioned volumes
Description
Checks the Amazon Elastic Block Store (Amazon EBS) volumes that were running at any time during the lookback period. This check alerts you if any EBS volumes were under-provisioned for your workloads. Consistent high utilization can indicate optimized, steady performance, but can also indicate that an application does not have enough resources.

73
Q

TRUE or FALSE
AWS CloudFront
can create an alarm that sends a notification when billing threshold is exceeded?

A

FALSE

In the CloudFront console, you can set alarms to notify you by Amazon Simple Notification Service (Amazon SNS) based on specific CloudFront metrics.

BUT it is CloudWatch that does the alarms, you watch a single metric over a time period that you specify. If the metric exceeds a given threshold, a notification is sent to an Amazon SNS topic or AWS Auto Scaling policy. CloudWatch alarms do not invoke actions when a metric is in a particular state. Rather the state must have changed and been maintained for a specified number of periods.

74
Q

Which AWS support plans provide phone, email and chat access 24/7 to Cloud Support Associates?

a. Basic
B. Developer
c. Business
d. Enterprise on-ramp
e. Enterprise

A

C, D and E

The developer plan only has Business hours** web access to Cloud Support Associates

Business and all Enterprise plans offer 24/7 phone, web, and chat access to Cloud Support Engineers

75
Q

Which one of the support plans offers the lowest cost for Production system down: < 1 hour?

a. Basic
B. Developer
c. Business
d. Enterprise on-ramp
e. Enterprise

A

C
The business support plan provides a response time of less than 1 hour if a production system has a service interruption. The developer plan does not any production support response.

76
Q

TRUE or FALSE
To be able to start using AWS Service Control Policies you just need to attach it to a Account in the AWS Console

A

FALSE
To be able to start using AWS Service Control Policies you need to enable AWS Organizations first in the AWS Console

77
Q

Which AWS service will provide a good way to determine whether a specific AWS Service that you wish to block is being used in your target AWS account?

a. AWS CloudTrail
b. AWS CloudWatch
c. AWS Config
d. AWS Inspector

A

A
Tools like AWS CloudTrail and the service last accessed data in IAM are good ways to determine whether a specific AWS Service that you wish to block is being used in your target AWS account.

78
Q

Which support plans provide AWS Personal Health Dashboard provides a personalized view of the health of AWS services, and alerts when your resources are impacted. Also includes the AWS Health API for integration with your existing management systems. (pick all that apply)

a. Basic
b. Developer
c. Business
d. Enterprise on-ramp
e. Enterprise

A

a, b,c,d, and e

All of the plans get this dashboard

79
Q

Which support plans gets Access to Infrastructure Event Management with no fee?

a. Basic
b. Developer
c. Business
d. Enterprise on-ramp
e. Enterprise

A

D and E

AWS Infrastructure Event Management (IEM) offers architecture and scaling guidance and operational support during the preparation and execution of planned events, such as shopping holidays, product launches, and migrations. For these events, AWS Infrastructure Event Management will help you assess operational readiness, identify and mitigate risks, and execute your event confidently with AWS experts by your side. The program is included in the Enterprise Support plan and is available to Business Support customers for an additional fee.

80
Q

Which of the Pillars of the Well-architected Framework does this statement represent …
Minimizing environmental impacts for cloud workloads

a. Operational Excellence
b. realiability
c. security
d. performance efficiency
e. cost optimization
f. sustainability

A

F
sustainability

81
Q

Which of the Pillars of the Well-architected Framework does this statement represent …
Using resources efficiently to achieve business value

a. Operational Excellence
b. realiability
c. security
d. performance efficiency
e. cost optimization
f. sustainability

A

D
performance efficiency

82
Q

Which of the Pillars of the Well-architected Framework does this statement represent …
Running and monitoring systems for business value

a. Operational Excellence
b. realiability
c. security
d. performance efficiency
e. cost optimization
f. sustainability

A

ans A

Operational Excellence

83
Q

Which of the Pillars of the Well-architected Framework does this statement represent …
Enabling infrastructure to recover from disruptions

a. Operational Excellence
b. realiability
c. security
d. performance efficiency
e. cost optimization
f. Fault tolerance

A

b
Reliability

84
Q

Which of the Pillars of the Well-architected Framework does this statement represent …
Achieving minimal costs for the desired value

a. Operational Excellence
b. realiability
c. security
d. performance efficiency
e. cost optimization
f. sustainability

A

E
cost optimization

85
Q

Which of the following are services that support fault tolerance?
(pick two)

a. AWS config
b. Simple Queue Service (SQS)
c. Simple mail Service (SMS)
d. Route 53
e. AWS Storage Gateway

A

B and D

86
Q

Your company needs to ensure that you stay complianct in the AWS environment at all times,
which of the following services will help you ?

a. AWS config
b. AWS well architected framework
c. AWS CloudSearch
d. AWS Shield

A

A

AWS config - Continually monitor AWS resources and provides
conformance packs for specific compliance standards
The AWS Config service assesses how well your resource configurations comply with internal practices, industry guidelines, and regulations.

87
Q

Your company needs to ensure that you stay security compliant in the AWS environment at all times,
which of the following services will help you ?

a. Route 53
b. AWS well architected framework
c. AWS CloudSearch
d. AWS GuardDuty

A

D

Amazon GuardDuty
Provides intelligent threat detection.
configure GuardDuty to meet your security and compliance objectives.

88
Q

You need a AWS tool that will help you discovery any unusual patterns of login events on your database, which tool service would help perform this?

a. Route 53
b. AWS GuardDuty
c. AWS CloudSearch
d. AWS Inspector

A

B
RDS Protection in Amazon GuardDuty analyzes and profiles RDS login activity for potential access threats to your Amazon Aurora databases (Amazon Aurora MySQL-Compatible Edition and Aurora PostgreSQL-Compatible Edition). This feature allows you to identify potentially suspicious login behavior. RDS Protection doesn’t require additional infrastructure; it is designed so as not to affect the performance of your database instances.

89
Q

■ Jane’s company is building an application to process credit cards
■ They will be processing cards directly and not through a service
■ Their bank needs a PCI DSS compliance report for AWS
■ Where would Jane go to get the information?

a. AWS healthcheck dashboard
b. AWS security dashboard
c. AWS Artifact
d. AWS Cognito

A

C
AWS Artifact

90
Q

■ Ellen is a solutions architect at a startup
■ They are building a new tool for digital asset management
■ Ellen is curious how to best leverage the capabilities of AWS in this application
■ What resources would you recommend for Ellen and her team?

a. AWS well architected framework
b. AWS security dashboard
c. AWS Artifact
d. AWS Cognito

A

A
AWS well architected framework
The AWS Well-Architected Framework describes key concepts, design
principles, and architectural best practices for designing and running
workloads in the cloud. These principles are covered through six
different pillars.

91
Q

Is S3 region specific or Global?

A

Global
Does not require region selection
“S3 does not require region selection.” Also, you will notice that all the regions are greyed out and you actually can’t change the region.

92
Q

Which documentation does AWS Artifact provide?
A. Amazon EC2 terms and conditions
B. AWS ISO certifications
C. A history of a company’s AWS spending
D. A list of previous-generation Amazon EC2 instance types

A

B
According to AWS:
What is an AWS artifact?
AWS Artifact is a web service that enables you to download AWS security and compliance documents such as ISO certifications and SOC reports. User Guide.

93
Q

Which task requires using AWS account root user credentials?
A. Viewing billing information
B. Changing the AWS Support plan
C. Starting and stopping Amazon EC2 instances
D. Opening an AWS Support case

A

B
To access the AWS Support Center, sign in with either of the following steps:

Use your AWS account root user credentials

-or-

Use your AWS Identity and Access Management (IAM) user credentials with access permissions for AWS Support plans. For more information, see Manage access for AWS Support plans.

This is a tricky on because if root granted access permissions to a IAM user then they too can access support plans and change them.

94
Q

A company needs to simultaneously process hundreds of requests from different users.
Which combination of AWS services should the company use to build an operationally efficient solution?
A. Amazon Simple Queue Service (Amazon SQS) and AWS Lambda
B. AWS Data Pipeline and Amazon EC2
C. Amazon Kinesis and Amazon Athena
D. AWS Amplify and AWS AppSync

A

To efficiently handle concurrent requests from different users, the company can use a combination of Amazon Simple Queue Service (Amazon SQS) and AWS Lambda, which is option A.

95
Q

Which of the following are components of an AWS Site-to-Site VPN connection? (Choose two.)
A. AWS Storage Gateway
B. Virtual private gateway
C. NAT gateway
D. Customer gateway
E. Internet gateway

A

b and d

96
Q

A company needs to establish a connection between two VPCs. The VPCs are located in two different AWS Regions. The company wants to use the existing infrastructure of the VPCs for this connection.
Which AWS service or feature can be used to establish this connection?
A. AWS Client VPN
B. VPC peering
C. AWS Direct Connect
D. VPC endpoints

A

B

97
Q

A user needs to determine whether an Amazon EC2 instance’s security groups were modified in the last month.
How can the user see if a change was made?
A. Use Amazon EC2 to see if the security group was changed.
B. Use AWS Identity and Access Management (IAM) to see which user or role changed the security group.
C. Use AWS CloudTrail to see if the security group was changed.
D. Use Amazon CloudWatch to see if the security group was changed.

A

c

98
Q

How does the AWS Cloud pricing model differ from the traditional on-premises storage pricing model?
A. AWS resources do not incur costs
B. There are no infrastructure operating costs
C. There are no upfront cost commitments
D. There are no software licensing costs

A

C
Pay-as-you-go model
The AWS Cloud pricing model differs from traditional on-premises storage pricing in that it is based on a pay-as-you-go model with no upfront cost commitments. This means that customers only pay for the resources they consume and can easily scale up or down as needed.

99
Q

A company’s on-premises application deployment cycle was 3-4 weeks. After migrating to the AWS Cloud, the company can deploy the application in 2-3 days.
Which benefit has this company experienced by moving to the AWS Cloud?
A. Elasticity
B. Flexibility
C. Agility
D. Resilience

A

c

100
Q

Which of the following are included in AWS Enterprise Support? (Choose two.)
A. AWS technical account manager (TAM)
B. AWS partner-led support
C. AWS Professional Services
D. Support of third-party software integration to AWS
E. 5-minute response time for critical issues

A

a and d

101
Q

A global media company uses AWS Organizations to manage multiple AWS accounts.
Which AWS service or feature can the company use to limit the access to AWS services for member accounts?
A. AWS Identity and Access Management (IAM)
B. Service control policies (SCPs)
C. Organizational units (OUs)
D. Access control lists (ACLs)

A

B
service control policies are a feature of AWS organizations that allow the customer to define and enforce rules.

102
Q

A company wants to limit its employees’ AWS access to a portfolio of predefined AWS resources.
Which AWS solution should the company use to meet this requirement?
A. AWS Config
B. AWS software development kits (SDKs)
C. AWS Service Catalog
D. AWS AppSync

A

C. AWS Service Catalog
Apply access controls
Scale and control permissions so you can manage resource access in multi-account AWS environments.

How it works
AWS Service Catalog lets you centrally manage deployed IT services, applications, resources, and metadata to achieve consistent governance of your infrastructure as code (IaC) templates. With AWS Service Catalog, you can meet your compliance requirements while making sure your customers can quickly deploy the approved IT services they need.

103
Q

A company has a database server that is always running. The company hosts the server on Amazon EC2 instances. The instance sizes are suitable for the workload. The workload will run for 1 year.
Which EC2 instance purchasing option will meet these requirements MOST cost-effectively?
A. Standard Reserved Instances
B. On-Demand Instances
C. Spot Instances
D. Convertible Reserved Instances

A

A
Reserved instances are ideal for steady and predictable usage. They can help you save significantly on your Amazon EC2 costs compared to on-demand instance pricing because in exchange for your commitment to pay for all the hours in a one-year or three-year term, the hourly rate is lowered significantly.

104
Q

Which tasks are the responsibility of AWS, according to the AWS shared responsibility model? (Choose two.)
A. Patch the Amazon EC2 guest operating system.
B. Upgrade the firmware of the network infrastructure.
C. Apply password rotation for IAM users.
D. Maintain the physical security of edge locations.
E. Maintain least privilege access to the root user account.

A

B and D

105
Q

Which of the following are features of network ACLs as they are used in the AWS Cloud? (Choose two.)
A. They are stateless.
B. They are stateful.
C. They evaluate all rules before allowing traffic.
D. They process rules in order, starting with the lowest numbered rule, when deciding whether to allow traffic.
E. They operate at the instance level.

A

A and D
They evaluate each network packet independently and don’t track the state of the traffic flow. Therefore, any changes to the traffic flow require explicit rules for each direction of traffic.

They process rules in order, starting with the lowest numbered rule, when deciding whether to allow traffic: AWS Network ACLs process the rules in sequential order starting with the lowest numbered rule to the highest numbered rule to decide whether to allow traffic or not

106
Q

Which architecture design principle describes the need to isolate failures between dependent components in the AWS Cloud?
A. Use a monolithic design.
B. Design for automation.
C. Design for single points of failure.
D. Loosely couple components.

A

D
Loosely coupled is correct. In the cloud practitioner course states that in a microservices approach, application components are loosely coupled. In this case, if a single component fails, the other components continue to work because they are communicating with each other. The loose coupling prevents the entire application from failing.

107
Q

A company recently deployed an Amazon RDS instance in its VPC. The company needs to implement a stateful firewall to limit traffic to the private corporate network.
Which AWS service or feature should the company use to limit network traffic directly to its RDS instance?
A. Network ACLs
B. Security groups
C. AWS WAF
D. Amazon GuardDuty

A

B
Security groups act as a virtual firewall for the associated instances and control inbound and outbound traffic at the protocol and port level. By configuring the security group to allow only the necessary traffic from the corporate network to the RDS instance, the company can limit access to the instance.

AWS WAF is a web application firewall that lets you monitor the HTTP(S) requests that are forwarded to your protected web application resources. You can protect the following resource types:
Amazon CloudFront distribution
Amazon API Gateway REST API
Application Load Balancer

AWS AppSync GraphQL API
Amazon Cognito user pool

108
Q

Which AWS services should be used for read/write data constantly?

a. Amazon Glacier
b. snowball
c. Amazon RDS
d. Amazon EFS

A

C and D

109
Q

What is one of the advantages of the Amazon Relational database service (amazon rds)?

a. it simplifies relational database administraction tasks
b. if provides 99.9999999999% reliabilty and durability
c. it automatically scales databases for loads
d. it enables users to dynamically adjust CPU and RAM resources

A

A

b - is what S3 will do for you
c - is what Aurora will do for you

110
Q

Which storage option cost more ?
a. EBS
b. S3

A

a - EBS costs more than s3.

s3 has different cost plans
s3 is the right option to store backups

111
Q

Which service should a customer use to consolidate and centrally manage multiple AWS accounts?

a. AWS IAM
b. AWS organizations
c. AWS schema conversion tool
d. AWS config

A

B

112
Q

Which AWS service or feature identifies whether an Amazon S3 bucket or an IAM role has been shared with an external entity?
A. AWS Service Catalog
B. AWS Systems Manager
C. AWS IAM Access Analyzer
D. AWS Organizations

A

C
Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk.

113
Q

A large enterprise with multiple VPCs in several AWS Regions around the world needs to connect and centrally manage network connectivity between its VPCs.
Which AWS service or feature meets these requirements?
A. AWS Direct Connect
B. AWS Transit Gateway
C. AWS Site-to-Site VPN
D. VPC endpoints

A

B
a Transit Gateway will allow you to access those services with a simpler network configuration.
AWS Transit Gateway routes all traffic to and from each VPC or VPN, and you have one place to manage and monitor it all. It is a HUB like feature.

114
Q

A company needs to graphically visualize AWS billing and usage over time. The company also needs information about its AWS monthly costs.
Which AWS Billing and Cost Management tool provides this data in a graphical format?
A. AWS Bills
B. Cost Explorer
C. AWS Cost and Usage Report
D. AWS Budgets

A

B
Both Cost Explorer and Cost and Usage reports are for same purpose. The main difference is Cost Explorer gives graphically representation.

115
Q

A manufacturing company has a critical application that runs at a remote site that has a slow internet connection. The company wants to migrate the workload to
AWS. The application is sensitive to latency and interruptions in connectivity. The company wants a solution that can host this application with minimum latency.
Which AWS service or feature should the company use to meet these requirements?
A. Availability Zones
B. AWS Local Zones
C. AWS Wavelength
D. AWS Outpost

A

B

116
Q

A company wants to use the AWS Cloud to provide secure access to desktop applications that are running in a fully managed environment.
Which AWS service should the company use to meet this requirement?
A. Amazon S3
B. Amazon AppStream 2.0
C. AWS AppSync
D. AWS Outposts

A

B
Amazon AppStream 2.0 is a fully managed non-persistent desktop and application service for remotely accessing your work.

Amazon AppStream 2.0 is a fully managed, secure application streaming service that lets you stream desktop applications to users without rewriting applications. AppStream 2.0 provides users with instant access to the applications that they need with a responsive, fluid user experience on the device of their choice.

117
Q

A company needs to install an application in a Docker container.
Which AWS service eliminates the need to provision and manage the container hosts?
A. AWS Fargate
B. Amazon FSx for Windows File Server
C. Amazon Elastic Container Service (Amazon ECS)
D. Amazon EC2

A

A
The key here is ‘eliminate the need to provision container HOSTS’. ECS is an orchestrator management too. you still need to create ec2 hosts for the docker containers with ECS.

AWS Fargate is a serverless compute engine for containers that works with both Amazon Elastic Container Service (ECS) and Amazon Elastic Kubernetes Service (EKS). AWS Fargate makes it easy to focus on building your applications. Fargate eliminates the need to provision and manage servers, lets you specify and pay for resources per application, and improves security through application isolation by design.

118
Q

Which AWS service or feature checks access policies and offers actionable recommendations to help users set secure and functional policies?
A. AWS Systems Manager
B. AWS IAM Access Analyzer
C. AWS Trusted Advisor
D. Amazon GuardDuty

A

B

AWS IAM Access Analyzer helps identify resources in your organization and accounts that are shared with an external entity. IAM Access Analyzer validates IAM policies against policy grammar and best practices. IAM Access Analyzer generates IAM policies based on access activity in your AWS CloudTrail logs.

AWS IAM Access Analyzer helps identify any unintended access to AWS resources. It checks policies for resources such as Amazon S3 buckets and IAM roles to ensure that only authorized users and services have access to them. It offers actionable recommendations to help users set secure and functional policies.

119
Q

A company has a fleet of cargo ships. The cargo ships have sensors that collect data at sea, where there is intermittent or no internet connectivity. The company needs to collect, format, and process the data at sea and move the data to AWS later.
Which AWS service should the company use to meet these requirements?
A. AWS IoT Core
B. Amazon Lightsail
C. AWS Storage Gateway
D. AWS Snowball Edge

A

AWS Snowball Edge is a petabyte-scale data transfer and edge computing device that can be used to move large amounts of data in and out of AWS, as well as perform local processing and data storage. Snowball Edge can be used in environments where there is intermittent or no internet connectivity to collect, format, and process data at sea and then move the data to AWS when a connection is available.

120
Q

Which AWS services use cloud-native storage that provides replication across multiple Availability Zones by default? (Choose two.)
A. Amazon ElastiCache
B. Amazon RDS for Oracle
C. Amazon Neptune
D. Amazon DocumentDB (with MongoDB compatibility)
E. Amazon Waveshift

A

C. Amazon Neptune is a fast, reliable, fully managed graph database service that enables you to build and run applications that work with highly connected datasets. Neptune uses a distributed, fault-tolerant architecture that is designed to provide high availability and durability. Data is automatically replicated across multiple Availability Zones, which helps ensure that the database remains available even in the event of a failure.

D. Amazon DocumentDB (with MongoDB compatibility) is a fully managed document database service that is designed to be compatible with MongoDB workloads. DocumentDB uses a distributed, fault-tolerant architecture that is designed to provide high availability and durability. Data is automatically replicated across multiple Availability Zones, which helps ensure that the database remains available even in the event of a failure.

121
Q

A retail company needs to build a highly available architecture for a new ecommerce platform. The company is using only AWS services that replicate data across multiple Availability Zones.
Which AWS services should the company use to meet this requirement? (Choose two.)
A. Amazon EC2
B. Amazon Elastic Block Store (Amazon EBS)
C. Amazon Aurora
D. Amazon DynamoDB
E. Amazon Redshift

A

C and D

Amazon Aurora automatically maintains six copies of your data across three Availability Zones (AZs) and will automatically attempt to recover your database in a healthy AZ with no data loss.

By default AWS DynamoDB is a multi-AZ enabled service which means that your data is by default replicated across 3 data centers (minimum of 2 AZs)

EBS are replicated within the same AZ but not across AZ.

Amazon Redshift allows users to replicate their data across numerous regions by extracting data from their tables using the unload command and then loading the data in the target tables via Amazon S3. So, there is a process that has to be done it doesn’t occur by default.

122
Q

Service control policies (SCPs) manage permissions for which of the following?
A. Availability Zones
B. AWS Regions
C. AWS Organizations
D. Edge locations

A

c

123
Q

A user is storing objects in Amazon S3. The user needs to restrict access to the objects to meet compliance obligations.
What should the user do to meet this requirement?
A. Use AWS Secrets Manager.
B. Tag the objects in the S3 bucket.
C. Use security groups.
D. Use network ACLs.

A

B
Tagging the objects in the S3 bucket can help the user restrict access to the objects by implementing resource-level permissions. The user can create a policy that allows access to objects only if they have specific tags. This way, the user can ensure that only authorized users can access the objects that require compliance obligations.

if just ‘ACL’ was an option that that could be correct, be network ACLs is a virtual firewall on the subnet level. D is NOT correct in fact: Starting in April 2023, Amazon S3 will change the default settings for S3 Block Public Access and Object Ownership (ACLs disabled) for all new S3 buckets.

Suppose that an object contains protected health information (PHI) data. You might tag the object using the following key-value pair.

PHI=True

124
Q

If you are looking to orchestrate your data workflow for an ETL process that includes Amazon EMR, which service should you leverage?

a. AWS DataSync

b. Apache Spark

c. AWS Glue

d. AWS Data Pipeline

A

d. AWS Data Pipeline

AWS Data Pipeline is a web service that helps you reliably process and move data between different AWS compute and storage services, as well as on-premises data sources, at specified intervals. With AWS Data Pipeline, you can regularly access your data where it’s stored, transform and process it at scale, and efficiently transfer the results to AWS services such as Amazon S3, Amazon RDS, Amazon DynamoDB, and Amazon EMR.

AWS Data Pipeline helps you easily create complex data processing workloads that are fault tolerant, repeatable, and highly available. You don’t have to worry about ensuring resource availability, managing inter-task dependencies, retrying transient failures or timeouts in individual tasks, or creating a failure notification system. AWS Data Pipeline also allows you to move and process data that was previously locked up in on-premises data silos.

125
Q

You have a new employee joining your development team. For the foreseeable future, he will only be working on one of the three systems that the team maintains. How should his AWS access be handled:

a.
Create an IAM account with permissions only for the system he needs to access

b.
Create an IAM user and add him to the development team group since he will eventually need access to each system

c.
Create an IAM group for each system the development team needs to manage

d.
Create an IAM role for him to leverage that has access to the one system he needs to access

A

a.
Create an IAM account with permissions only for the system he needs to access

126
Q

If you are working with your data science team to move their processing work to the cloud, what service would enable them to continue to process data with Apache HBase without having to handle the configuration of the underlying instances?

a. Amazon DynamoDB

b. Amazon Sagemaker

c. AWS Glue

d. Amazon EMR

A

d. Amazon EMR

127
Q

If you have a files in your local data center that you need to daily sync to on an EFS volume in your AWS account, which service would best meet this need?

a. AWS Snowball

b. AWS Storage Gateway

c. AWS DataSync

d. AWS Snowmobile

A

c. AWS DataSync

128
Q

What are the five pillars of the Well-architected Framework?

a.
Cost optimization, Security, Fault tolerance, Performance improvement, Reliability

b.
Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization

c.
Operational Excellence, High-availability, Cost Optimization, Fault Tolerance, Reliability

d.
Compliance, Security, Reliability, Cost Optimization, Fault Tolerance, and High-availability

A

b.
Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization

and a sixth is sustainability

129
Q

Which disaster recovery approach keeps only key production systems running in the cloud?

a.
Pilot Light

b.
Backup and Restore

c.
Warm Standby

d.
Multi-site

A

a.
Pilot Light

130
Q

If you have a files in your local data center that you need to daily sync to on an EFS volume in your AWS account, which service would best meet this need?

a. AWS Storage Gateway

b. AWS Snowball

c. AWS DataSync

d. AWS CloudSync

A

c. AWS DataSync

131
Q

A manufacturing company has a critical application that runs at a remote site that has a slow internet connection. The company wants to migrate the workload to
AWS. The application is sensitive to latency and interruptions in connectivity. The company wants a solution that can host this application with minimum latency.
Which AWS service or feature should the company use to meet these requirements?
A. Availability Zones
B. AWS Local Zones
C. AWS Wavelength
D. AWS Outposts

A

b

132
Q

Which AWS service is used to provide encryption for Amazon EBS?
A. AWS Certificate Manager
B. AWS Systems Manager
C. AWS KMS
D. AWS Config

A

c

133
Q

Which AWS services make use of global edge locations? (Choose two.)
A. AWS Fargate
B. Amazon CloudFront
C. AWS Global Accelerator
D. AWS Wavelength
E. Amazon VPC

A

B and C

134
Q

A company is operating several factories where it builds products. The company needs the ability to process data, store data, and run applications with local system interdependencies that require low latency.
Which AWS service should the company use to meet these requirements?
A. AWS IoT Greengrass
B. AWS Lambda
C. AWS Outposts
D. AWS Snowball Edge

A

The AWS service that the company should use to meet these requirements is C. AWS Outposts.

AWS Outposts is a fully-managed service that extends AWS infrastructure, services, APIs, and tools to virtually any datacenter, co-location space, or on-premises facility for a truly consistent hybrid experience. With AWS Outposts, the company can run AWS services locally, including compute, storage, database, and analytics, while seamlessly connecting to AWS services in the cloud.

LAMBDA Does not offer low latency?
AWS IoT Greengrass (option A) is a service that enables you to run AWS Lambda functions and keep device data in sync with the cloud, even when the devices are offline.

135
Q

Which of the following is a recommended design principle for AWS Cloud architecture?
A. Design tightly coupled components.
B. Build a single application component that can handle all the application functionality.
C. Make large changes on fewer iterations to reduce chances of failure.
D. Avoid monolithic architecture by segmenting workloads.

A

d

136
Q

A company is designing its AWS workloads so that components can be updated regularly and so that changes can be made in small, reversible increments.
Which pillar of the AWS Well-Architected Framework does this design support?
A. Security
B. Performance efficiency
C. Operational excellence
D. Reliability

A

c

137
Q

Using AWS Config to record, audit, and evaluate changes to AWS resources to enable traceability is an example of which AWS Well-Architected Framework pillar?
A. Security
B. Operational excellence
C. Performance efficiency
D. Cost optimization

A

A

138
Q

Which AWS service can be used to decouple applications?
A. AWS Config
B. Amazon Simple Queue Service (Amazon SQS)
C. AWS Batch
D. Amazon Simple Email Service (Amazon SES)

A

B

139
Q

Which AWS service can be used to decouple applications?
A. AWS Config
B. Amazon Simple Queue Service (Amazon SQS)
C. AWS Batch
D. Amazon Simple Email Service (Amazon SES)

A

B

140
Q

A company hosts an application on an Amazon EC2 instance. The EC2 instance needs to access several AWS resources, including Amazon S3 and Amazon
DynamoDB.
What is the MOST operationally efficient solution to delegate permissions?
A. Create an IAM role with the required permissions. Attach the role to the EC2 instance.
B. Create an IAM user and use its access key and secret access key in the application.
C. Create an IAM user and use its access key and secret access key to create a CLI profile in the EC2 instance
D. Create an IAM role with the required permissions. Attach the role to the administrative IAM user.

A

A

141
Q

Which AWS service allows users to download security and compliance reports about the AWS infrastructure on demand?
A. Amazon GuardDuty
B. AWS Security Hub
C. AWS Artifact
D. AWS Shield

A

C

142
Q

A pharmaceutical company operates its infrastructure in a single AWS Region. The company has thousands of VPCs in a various AWS accounts that it wants to interconnect.
Which AWS service or feature should the company use to help simplify management and reduce operational costs?
A. VPC endpoint
B. AWS Direct Connect
C. AWS Transit Gateway
D. VPC peering

A

The answer is C - Transit Gateway. The more complicated topology is the more likely Transit Gateway will be the answer.

143
Q

A company is planning an infrastructure deployment to the AWS Cloud. Before the deployment, the company wants a cost estimate for running the infrastructure.
Which AWS service or feature can provide this information?
A. Cost Explorer
B. AWS Trusted Advisor
C. AWS Cost and Usage Report
D. AWS Pricing Calculator

A

d

144
Q

Which of the following are Amazon Virtual Private Cloud (Amazon VPC) resources?
A. Objects; access control lists (ACLs)
B. Subnets; internet gateways
C. Access policies; buckets
D. Groups; roles

A

b

145
Q

A company launched an Amazon EC2 instance with the latest Amazon Linux 2 Amazon Machine Image (AMI).
Which actions can a system administrator take to connect to the EC2 instance? (Choose two.)
A. Use Amazon EC2 Instance Connect.
B. Use a Remote Desktop Protocol (RDP) connection.
C. Use AWS Batch
D. Use AWS Systems Manager Session Manager.
E. Use Amazon Connect

A

D

146
Q

A company wants to perform sentiment analysis on customer service email messages that it receives. The company wants to identify whether the customer service engagement was positive or negative.
Which AWS service should the company use to perform this analysis?
A. Amazon Textract
B. Amazon Translate
C. Amazon Comprehend
D. Amazon Rekognition

A

The AWS service that should be used to perform sentiment analysis on customer service email messages is Amazon Comprehend. Amazon Comprehend is a natural language processing (NLP) service that uses machine learning to find insights and relationships in text. It can be used to perform sentiment analysis, entity recognition, topic modeling, and language detection.

Amazon Textract is a service that is used for extracting text and data from scanned documents, but it is not used for sentiment analysis.

Amazon Translate is a service that is used for translating text from one language to another, but it is not used for sentiment analysis.

Amazon Rekognition is a service that is used for image and video analysis, such as object and scene detection, facial analysis, and celebrity recognition, but it is not used for sentiment analysis of text.

147
Q

What is the total amount of storage offered by Amazon S3?
A. 100MB
B. 5 GB
C. 5 TB
D. Unlimited

A

D

148
Q

A company is migrating to Amazon S3. The company needs to transfer 60 TB of data from an on-premises data center to AWS within 10 days.
Which AWS service should the company use to accomplish this migration?
A. Amazon S3 Glacier
B. AWS Database Migration Service (AWS DMS)
C. AWS Snowball
D. AWS Direct Connect

A

c

149
Q

A large organization has a single AWS account.
What are the advantages of reconfiguring the single account into multiple AWS accounts? (Choose two.)
A. It allows for administrative isolation between different workloads.
B. Discounts can be applied on a quarterly basis by submitting cases in the AWS Management Console.
C. Transitioning objects from Amazon S3 to Amazon S3 Glacier in separate AWS accounts will be less expensive.
D. Having multiple accounts reduces the risks associated with malicious activity targeted at a single account.
E. Amazon QuickSight offers access to a cost tool that provides application-specific recommendations for environments running in multiple accounts.

A

A and D

150
Q

A retail company has recently migrated its website to AWS. The company wants to ensure that it is protected from SQL injection attacks. The website uses an
Application Load Balancer to distribute traffic to multiple Amazon EC2 instances.
Which AWS service or feature can be used to create a custom rule that blocks SQL injection attacks?
A. Security groups
B. AWS WAF
C. Network ACLs
D. AWS Shield

A

B
“You can also use AWS WAF to block or allow requests based on conditions that you specify, such as the IP addresses that requests originate from or values in the requests.”
Values in the requests can match sql injections

151
Q

Which AWS service provides a feature that can be used to proactively monitor and plan for the service quotas of AWS resources?
A. AWS CloudTrail
B. AWS Personal Health Dashboard
C. AWS Trusted Advisor
D. Amazon CloudWatch

A

C. AWS Trusted Advisor
How many service limits does AWS trusted advisor support?

One of the easiest ways to do this is via AWS Trusted Advisor’s Service Limit Dashboard, which currently covers 39 limits across 10 services. With the recent launch of Trusted Advisor metrics in Amazon CloudWatch, Business and Enterprise support customers can create customizable alarms for individual service limits.

NOTE: there is another service - Quota Monitor for AWS to does this too , Monitor resource usage and send notifications when approaching quotas by leveraging trusted avisor and service quotas.

152
Q

Which design principle is included in the operational excellence pillar of the AWS Well-Architected Framework?
A. Create annotated documentation.
B. Anticipate failure.
C. Ensure performance efficiency.
D. Optimize costs.

A

B

153
Q

Which AWS services offer gateway VPC endpoints that can be used to avoid sending traffic over the internet? (Choose two.)
A. Amazon Simple Notification Service (Amazon SNS)
B. Amazon Simple Queue Service (Amazon SQS)
C. AWS CodeBuild
D. Amazon S3
E. Amazon DynamoDB

A

D and E
The AWS services that offer gateway VPC endpoints that can be used to avoid sending traffic over the internet are:

D. Amazon S3
E. Amazon DynamoDB

Amazon S3 and Amazon DynamoDB both offer gateway VPC endpoints that allow you to access the services over a private network connection within your VPC, without the need to go over the internet. This can help improve security, reduce latency, and lower data transfer costs.

Amazon SNS, Amazon SQS, and AWS CodeBuild do not offer gateway VPC endpoints. However, you can still use these services securely within your VPC by using VPC endpoints for AWS services or by setting up a VPC peering connection.

154
Q

Which of the following is the customer responsible for updating and patching, according to the AWS shared responsibility model?
A. Amazon FSx for Windows File Server
B. Amazon WorkSpaces virtual Windows desktop
C. AWS Directory Service for Microsoft Active Directory
D. Amazon RDS for Microsoft SQL Server

A

B may be true … but you can have it automatically patch.
By default, your Amazon WorkSpaces are configured to install software updates. Amazon Linux and Ubuntu WorkSpaces will be updated to install the latest security and software patches, and Amazon WorkSpaces with Windows have Windows Updates turned on. You can customize these settings, or use an alternative patch management approach. Updates are installed at 2am each Sunday.

155
Q

A company is using an Amazon RDS DB instance for an application that is deployed in the AWS Cloud. The company needs regular patching of the operating system of the server where the DB instance runs.
What is the company’s responsibility in this situation, according to the AWS shared responsibility model?
A. Open a support case to obtain administrative access to the server so that the company can patch the DB instance operating system.
B. Open a support case and request that AWS patch the DB instance operating system.
C. Use administrative access to the server, and apply the operating system patches during the regular maintenance window that is defined for the DB instance.
D. Establish a regular maintenance window that tells AWS when to patch the DB instance operating system.

A

b

156
Q

Why is an AWS Well-Architected review a critical part of the cloud design process?
A. A Well-Architected review is mandatory before a workload can run on AWS.
B. A Well-Architected review helps identify design gaps and helps evaluate design decisions and related documents.
C. A Well-Architected review is an audit mechanism that is a part of requirements for service level agreements.
D. A Well-Architected review eliminates the need for ongoing auditing and compliance tests.

A

b
The review of architectures must be done in a consistent manner, with a blame-free approach that encourages diving deep. It should be a lightweight process (hours not days) that is a conversation and not an audit. The purpose of reviewing an architecture is to identify any critical issues that might need addressing or areas that could be improved. The outcome of the review is a set of actions that should improve the experience of a customer using the workload.

157
Q

A pharmaceutical company operates its infrastructure in a single AWS Region. The company has thousands of VPCs in a various AWS accounts that it wants to interconnect.
Which AWS service or feature should the company use to help simplify management and reduce operational costs?
A. VPC endpoint
B. AWS Direct Connect
C. AWS Transit Gateway
D. VPC peering

A

d VPC peering is free and if vpc’s are in the same az then free.

158
Q

A company launched an Amazon EC2 instance with the latest Amazon Linux 2 Amazon Machine Image (AMI).
Which actions can a system administrator take to connect to the EC2 instance? (Choose two.)
A. Use Amazon EC2 Instance Connect.
B. Use a Remote Desktop Protocol (RDP) connection.
C. Use AWS Batch
D. Use AWS Systems Manager Session Manager.
E. Use Amazon Connect

A

A and D
A. Use Amazon EC2 Instance Connect: This is a browser-based SSH connection method that allows you to connect to your EC2 instances using AWS Identity and Access Management (IAM) credentials, without the need to manage SSH keys. You can use Instance Connect to connect to an instance using the EC2 console, AWS CLI, or SDKs.

D. Use AWS Systems Manager Session Manager: This is a fully-managed, secure, and auditable way to access your instances using the AWS Systems Manager console or AWS CLI. With Session Manager, you can tunnel your SSH (Secure Shell) and SCP (Secure Copy) connections to your instances, without requiring inbound connections or the use of bastion hosts or VPNs.

159
Q

A large organization has a single AWS account.
What are the advantages of reconfiguring the single account into multiple AWS accounts? (Choose two.)
A. It allows for administrative isolation between different workloads.
B. Discounts can be applied on a quarterly basis by submitting cases in the AWS Management Console.
C. Transitioning objects from Amazon S3 to Amazon S3 Glacier in separate AWS accounts will be less expensive.
D. Having multiple accounts reduces the risks associated with malicious activity targeted at a single account.
E. Amazon QuickSight offers access to a cost tool that provides application-specific recommendations for environments running in multiple accounts.

A

A and D

160
Q

What AWS service will help you answer “Who did what, where, and when?” to your AWS resources?

a. AWS inspector
b. AWS CloudWatch
c. AWS CloudTrail
d. AWS config

A

c
AWS CloudTrail enables auditing, security monitoring, and operational troubleshooting. CloudTrail records user activity and API calls across AWS services as events. CloudTrail events help you answer the question of “Who did what, where, and when?”

161
Q

CloudTrail records two types CloudTrail of events, which of the following two are they?

a. Management events
b. auto-scaling launch event
c. Custom events
d. Data events

A

A and D
CloudTrail records two types CloudTrail of events:

Management events that capture control plane actions on resources, such as creating or deleting Amazon Simple Storage Service (S3) buckets.
Data events that capture data plane actions within a resource, such as reading or writing an Amazon S3 object.

162
Q

Which of the following (pick two) are action types of an Amazon CloudWatch alarm?

a. reboot an EC2 instance
b. scale an EC2 Auto Scaling group
c. trigger an AWS Lambda function
d. run scripts on your EC2 instances

A

the action types of an Amazon CloudWatch alarm are limited. You can send a message to an SNS topic, perform some EC2 actions such as stopping, terminating, rebooting, or recovering an EC2 instance, or scale an EC2 Auto Scaling group. Or you can use some Systems Manager features, such as creating OpsItems in Systems Manager Ops Center or incidents in AWS Systems Manager Incident Manager. Currently, CloudWatch alarm actions are only limited to these.

163
Q

TRUE or FALSE
You cannot validate the integrity of CloudTrail log files stored in your S3 bucket

A

FALSE

You can validate the integrity of CloudTrail log files stored in your S3 bucket and detect whether the log files were unchanged, modified, or deleted since CloudTrail delivered them to your S3 bucket.

164
Q

Which if the following migration strategies is a “ lift-and-shift” ?

a. Rehosting
b. Replatforming
c. Refactoring
d. Repurchasing

A

Rehosting is also called lift-and-shift.

It is a process of moving applications without making any changes to them.

This is a like for like migration

165
Q

Which of the migration stratgies is move your application as “ software-as-a-service (SaaS)”?

a. Rehosting
b. Replatforming
c. Refactoring
d. Repurchasing

A

D
Repurchasing is a process of changing business type.

It moves your application to a software-as-a-service (SaaS) model from a traditional model.