S3 Flashcards

1
Q

What is Snowball?

A

Snowball Is a secure portable device used to transfer huge amount of data in & out of AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is S3 Availability?

A

99.99%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How to securely store objects in a bucket?

A

To securely store objects in a S3 bucket we have to use “Encryption at rest”.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Governance Mode

A

In governance mode User cant overwrite or delete a version or alter lock settings without special permissions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How AWS implement Transfer Acceleration?

A

Transfer Acceleration is implemented using aws CloudFront service through edge locations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Cross Region Replication in S3

A

Cross region replication means transfer of s3 object from one region to another.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In what scenario we can use S3 Standard tire

A

In S3 Standard Tier Data stored will be frequently accessed.

Data is be stored redundant on multiple facility to withstand 2 facility loss.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is S3 object Lock

A

S3 Object Lock achieve WORM based storage model.

S3 Object Lock prevent objects from delete / overwrite for a fixed amount of time or indefinitely.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the two S3 Object Lock Modes:

A

Governance Mode

Compliance Mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Can we move one file version to another s3 tier?

A

Yes; S3 life cycle mgt support Versioning ; we can transfer certain files version to another s3 tier.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Storage Gateway?

A

Storage gateway connect on-premise IT application with AWS Storage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In what scenarios we can use S3-IA

A

In S3 IA Data stored will be infrequently accessed.

Data is be stored redundant on multiple facility to withstand 2 facility loss.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is the max size of s3 object

A

5 TB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is CloudFront - Distribution

A

Cloud front distribution is a CDN - Collection of Edge Location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can we see who accessed s3 objects?

A

yes s3 can maintain access log for who access the objects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is AWS Organizations?

A

AWS Organization is an Account Management service.

It helps us combine multiple AWS accounts into an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

if new bucket is created; does every one have access?

A

No; In new bucket Block public access will be enabled by default.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is S3 Byte range Fetches?

A

S3 Byte range Fetches allows you to download huge files from S3.
It downloads huge files parallelly by specifying byte range.
This improves download performance to a greater extent.
If there is any failure it would be only specific byte range.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is Compliance Mode

A

In compliance mode Even Root User cant overwrite or delete a version or alter lock settings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is min retrieval time for S3 Glacier?

A

For S3 glacier Min retrieval time is 1 min to 1 hr

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What are the S3 limitations on KMS?

A

We use AWS KMS service to encrypt S3 object at rest; We call AWS KMS service every time during upload/download.
AWS KMS service has max request limits per second at regional level.
Like 5500,10000 & 30000 etc.
You cant increase request limits.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

In what scenarios we can use S3 Glacier

A

S3 Glacier is Used for cheap data archive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is CloudFront - Origin

A

Cloud front origin is the Source location of file that CDN distribute;
Origin can be S3 Bucket, EC2, Elastic Load Balancer or Route 53”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

How to restrict public access for all objects in a bucket?

A

To restrict public access we have to use “Block Public Access” option at bucket level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What is Glacier Vault Lock

A

Glacier Vault Lock allows you to place compliance controls for individual Glacier object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is Management Account?

A

In AWS Organization Management Account manages billing & payment of multiple member accounts.
It does not have any access to any service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

In what scenarios we can use S3 Glacier Deep Archive

A

S3 Glacier Deep Archive is Used for much cheaper data archives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What is S3 Prefixes?

A

S3 Prefixes are similar to a directory names.
This enables you to group similar objects together in a bucket.
If you read from 2 folder; you can achieve 11000 request per second.
If you read from 4 folder; you can achieve 22000 request per second.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

In what scenarios we can use S3 Intelligent Tiering

A

S3 intelligent tier is used to optimize cost by moving data to cheaper tier according to usage.

30
Q

How to maintain all file modification for objects in a bucket?

A

To maintain all file modification of S3 objetcs we have to use “Versioning” option.

31
Q

What is snowmobile?

A

Snow mobile is a hexabyte scale data transfer.

32
Q

What is S3 Select?

A

“S3 select allows you to run sql query directly on S3 objects.
we can download specific set of object from S3.
Using S3 Select we can achieve 400% performance increase

33
Q

How Encryption at rest is achieved?

A

“S3 keys
AWS KMS
Customer keys
Client side encryption”

34
Q

3 ways to share S3 bucket across accounts?

A
  1. Bucket Policy & IAM - Programmatic Access
  2. ACL & IAM - Programmatic Access
  3. Cross Account IAM Roles - Programmatic Access & Console Access”
35
Q

What is CloudFront - RTMP

A

Cloud front RTMP is Used for media streaming

36
Q

What is a S3 bucket

A

S3 bucket is the place where objects are stored;

37
Q

In S3 how the objects are stored?

A

Objects are stored in buckets

38
Q

What is Athena?

A

Athena Allows you to query data using sql directly on S3

39
Q

if you upload a object in S3 what would be the response

A

HTTP 200 Status code

40
Q

How to improve S3 Upload performance?

A

“if you have a big file to upload in to S3;we have to split the file & upload parallelly; rather than single file upload.
This improves upload performance to a greater extent.
It is recommended for files >100 mb.
It is required for files > 5 gb.”

41
Q

Can we have common name across all S3 bucket

A

No; Every bucket name should be unique at global level

42
Q

What are S3 Tiers?

A
"S3 Standard
S3 IA
S3 ONCE ZONE IA
S3 INTELLIGENT TIER
S3 GLACIER
S3 GLACIER DEEP ARCHIVE"
43
Q

What is Legal Hold?

A

“S3 object lock allows you to place a legal hold on specific version; once placed object cant be modified or deleted until revoked.
There is no specific time period for legal hold like retention period.”

44
Q

How Encryption in transit is achieved?

A

SSL/TSL

45
Q

What are S3 object properties

A
Key
Value
Version ID
Metadata
Sub resources: Access control List & Torrent"
46
Q

what is min size of s3 object

A

0 bytes

47
Q

Bucket is blocked from public can we enable public access for a specific file?

A

No; you have to enable public access for bucket then only we can enable public access for individual files.

48
Q

In what scenarios we can use S3 One Zone IA

A

In S3 one zone AI Data stored will be infrequently accessed.
Data will not be stored redundant on multiple facility.”

49
Q

S3 abbreviation

A

Simple storage service

50
Q

Can we disable versioning?

A

no versioning can only be suspended.

51
Q

How’s to secure S3 object versions from delete?

A

we can enable MFA for version delete.

52
Q

What are S3 Features?

A
"Tiered Storage
Lifecycle Mgt
Versioning
Encryption
MFA Delete
Secure data using - Access Control List & Bucket Policy"
53
Q

What is S3 Life cycle rules?

A

S3 life cycle rules is a set of instructions using which we can move S3 objects between S3 tiers.

54
Q

On what basis AWS charge for S3 Service?

A
"Storage
No of Request
Data Transfer
Transfer Acceleration
Cross Region Replication"
55
Q

Does each version has different access rules?

A

yes each version has its own access policies. By default latest file rules does not apply to other versions.

56
Q

What is CloudFront - Signed URL

A

Cloud front signed URL IS Used for authentication & authorization of content
1 authentication URL 1 object”

57
Q

How to control S3 bucket access?

A
  1. Bucket policy

2. access control list

58
Q

What is S3 Data Consistence model?

A

S3 Data Consistence model is Read after write consistency

In case of any overwrite or delete of an existing object, any subsequent read request immediately receives the latest version of the object.”

59
Q

What is Consolidated Billing?

A

AWS Organization Consolidated Billing allows us to Combine billing & payment of multiple AWS accounts.

AWS Organization management account pays for all member accounts.

60
Q

What is Macie?

A

Macie Allows you to protect sensitive data stored in S3

61
Q

What is Retention period?

A

“Retention period protect an S3 object version for a fixed amount of time.
When you place a retention period on a object version;
S3 store a time stamp on version metadata to indicate the retention expiry; after that data version can be modified or deleted.”

62
Q

What is CloudFront - Cookie

A

Cloud front cookie are Used for authentication & authorization of content
1 authentication cookie can be used for many object”

63
Q

What is Glacier Select?

A

Glacier select allows you to run SQL query directly on Glacier objects.
You can download specific set of data from Glacier.

64
Q

What is S3

A

S3 is a object storage service.

65
Q

What is snowball Edge?

A

Snowball edge has compute capability in addition to Storage

66
Q

if we transfer files from one bucket to another do we maintain the same security details

A

Yes.

67
Q

What is CloudFront - Web Distribution

A

Cloud front web distribution is Used for website

68
Q

What is min retrieval time for S3 Glacier Deep Archive?

A

S3 Glacier Deep Archive retrieval time is 12 Hrs

69
Q

What is AWS Data Sync?

A

AWS Data Sync seamlessly sync data between on-premise server & AWS S3 / EFS / FSx

70
Q

What is CloudFront - Edge Location

A

AWS CloudFront - Edge Location is where data is cached & used for CDN;
This is separate from Region & AZ.