SA Professional Exam Flashcards

1
Q

How long does it take to get data out of Glacier?

A

It can take AT LEAST 3 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What storage type provides the ability to create point-in-time snapshots of data volumes?

A

EBs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which three services have automated backups?

A

RDS
Elasticache (Redis only)
Redshift

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which service does not have automated backups?

A

EC2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In Read Replicas vs Multi-AZ;

Which is used for scaling?

A

Read Replicas

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In Read Replicas vs Multi-AZ;

Which is used for DR/MultiAZ?

A

Multi-AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many read replicas can you have?

A

Up to 5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can you have read replicas in different regions?

A

Yes - With the exception of SQL Server and Oracle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Are read replicas synchronous or asynchronous?

A

Asynchronous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

[T/F] Read Replicas can be made off of Multi-AZ’s database

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

[T/F] Read Replicas can be in Multi-AZ.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Can you have a read replica of a read replica? Will this increase latency?

A

Yes, but only for MySQL and this will increase latency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DB Snapshots and Automated backups [can/cannot] be taken of read replicas.

A

Can - but are not enabled by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

If you application does not require transaction support, Atomicity, Consistency, Isolation, Durability (ACID) compliance, joins & SQL… What should you consider using instead of RDS?

A

DynamoDB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the 4 different Storage Gateway Types?

A

File Gateway
Gateway-Cached Volumes
Gateway-Stored Volumes
Gateway-Virtual Tape Library

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How long does it take to access virtual tapes in your virtual tape library?

A

Instantaneous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How long does it take to access your virtual tapes from your virtual tape shelf?

A

It can take 24 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How is Storage Gateway encrypted?

A

Encrypted using SSL for transit

Encrypted at rest in S3 using AES-256

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

How are Gateway-Stored Volumes stored?

A

Stored data as Amazon EBS Snapshots in S3.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Gateway Storage snapshots [can/cannot] be scheduled.

A

Gateway Storage Volumes can be scheduled.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Gateway Storage bandwidth [can/cannot] be throttled.

A

Gateway storage can be throttled - which is great for remote sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

AWS Snowball _______ and _________ from S3.

A

Import; Export

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

AWS Import Export can only _______ to S3.

A

Import

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

_______ make it easy to group your resources using the tags that are assigned to them. You can group resources that share one or more tags.

A

Resource groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

_________ allows you to get volume discounts on all your accounts.

A

Consolidated billing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

With consolidated billing, _____ is on a per account and per region basis but can be aggregated into a single bucket in the paying account.

A

CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

The contract length for Reserved Instances is between __ and __ years.

A

1 & 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What are the 3 types of RIs?

A

Standard, Convertible, Scheduled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which of the RIs offers the largest discount?

A

All Upfront RIs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Standard RIs for EC2 can be modified, but only if they are in the same _______ and only if the ______ factors are equal and only for the Linux operating system.

A

Family; Normalization;

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

You can switch EC2 RIs between ______, but not between ______.

A

AZs; Regions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

EC2 RIs [can/cannot] be sold on the marketplace.

A

can

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Can you have reserved RDS instances?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

With RDS reserved instances, you can move ______ but not _______.

A

AZ’s but not regions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Elastic Beanstalk [can/cannot] provision RDS instances.

A

can

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Elastic Beanstalk [does/does not] support IAM.

A

does

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

You have ___ access to the resources under Elastic Beanstalk.

A

full

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Elastic Beanstalk code is stored in ___.

A

S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

With Elastic Beanstalk, ________ environments are allowed to support version control.

A

multiple

40
Q

Elastic Beanstalk [can/cannot] roll back changes.

A

can

41
Q

With Elastic Beanstalk, ______ the changes from ____ repositories are replicated.

A

Only the changes from Git repositories

42
Q

Amazon Elastic Beanstalk supports which AMIs?

A

Linux AMI & Windows 2012 R2

43
Q

OpsWork consists of ________ and ________.

A

Stacks; Layers

44
Q

OpsWorks runs on _____.

A

Chef

45
Q

In OpsWork, layers contain AWS resources such as…

A

EC2
ELB
RDS

46
Q

In OpsWork, layers are like _____, ______, and _______ layer.

A

Web; Application; Database

47
Q

In OpsWork, each stack will have how many layers?

A

1 or more

48
Q

What happens to any EC2 instance added outside of the OpsWork stack in ELB?

A

OpsWork will remove

49
Q

CloudFormation uses ________ to resolve dependency between resource creation.

A

wait condition

50
Q

What is mandatory for a CloudFormation template?

A

Resources

51
Q

With CloudFormation, you can create multiple ____ inside of one template.

A

VPCs

52
Q

If you wanted to connect VPCs in your CloudFormation template. You can enable _____________ using CloudFormation, but only within the same AWS account.

A

VPC Peering

53
Q

CloudFormation supports _____, ________, and _____ scripts.

A

Chef; Puppet; Bootstrap

54
Q

With CloudFormation, you can use ________ to output data.

A

Fn:GetAtt

55
Q

By default, the _______________ feature is enabled in CloudFormation.

A

“automatic rollback on error”

56
Q

CloudFormation itself costs what?

A

Nothing

57
Q

_______ is completely supported with CloudFormation. This includes creating new hosted zones or updating existing ones.

A

Route53

58
Q

If you are accessing services using HTTPs endpoints (think DynamoDB, S3) use public ____.

A

VIFs

59
Q

If you are accessing VPCs using private IP address ranges, use private ______.

A

VIFs

60
Q

In the US, you need ___ direct connect connection(s) to connect to all 4 US regions.

A

1

61
Q

Does data transferred between regions go over public internet?

A

No

62
Q

Layer 2 connections [are/are not] supported by direct connect.

A

Are not

63
Q

What is the difference between a Customer Gateway and a Virtual Private Gateway?

A

Customer Gateway - Customer side

Virtual Private Gateway - AWS Side

64
Q

Which ports does EC2-VPC ELB support?

A

1-65536

65
Q

What ports does the EC2-Class ELB support?

A
25
80/443
465
587
1024-65535
66
Q

Can you assign an Elastic IP to an Elastic Load Balancer?

A

No

67
Q

You can load balance to the _________ of your domain name with ELBs.

A

Zone Apex

68
Q

If you have multiple SSL certifications you should use ________ Elastic Load Balancers, unless you have a wildcard certificate.

A

Multiple

69
Q

A placement group [can/cannot] span availability zones but it [can/cannot] span subnets, provided that they are in the same VPC.

A

cannot; can

70
Q

You [can/cannot] move existing instances to placement groups.

A

cannot

71
Q

How can you reduce bottlenecks with NATs?

A

Scale up and Scale out;

If you scale out, add an additional NAT & subnet and migrate half your workload to the new subnet.

72
Q

Can you peer VPCs from different regions?

A

Nope

73
Q

If you peer two VPCs, what needs to be updated?

A

Security groups & make sure that a route table has been created in both VPCs to allow traffic.

74
Q

If your application is more oriented toward indexing and querying data, it may be better to use this Amazon DB for your needs.

A

DyanmoDB

75
Q

If your application has number BLOB data (binary large objects) then what would be a good choice for storage?

A

S3

76
Q

If you need fully automated scaling, which DB is best?

A

DynamoDB

77
Q

If you’re looking to scale your database up you should use ________, if you’re looking to scale out use ________.

A

RDS; DynamoDB

78
Q

Databases that require Joins and/or complex transactions should look to utilize what database options with AWS?

A

Amazon RDS or Amazon EC2 with self-managed database

79
Q

If you plan to store very large amounts of data that are infrequently accessed (Low I/O rates) where should you store that data?

A

S3

80
Q

Use _______ to optimize both GETs & PUTs with S3.

A

Parallelization

81
Q

S3 stores data in __________ order so you have to __________ the data.

A

Lexicographical; randomize

82
Q

You can secure S3 by doing what 3 things?

A
  • Using Bucket policies
  • Using MFA Delete
  • Backing your Bucket Up to Another S3 Bucket Owned by a separate account
83
Q

CloudHSM is _____ tenanted.

A

Single Tenanted (1 physical device, for you only)

84
Q

CloudHSM must be used in _____.

A

a VPC

85
Q

You can use ___________ to connect o a CloudHSM from another VPC.

A

VPC Peering

86
Q

IF you need fault tolerance with your CloudHSM, you need to build a ________.

A

Cluster

87
Q

CloudHSM can integrate with the following databases & warehouses:

A

RDS (Oracle & SQL)

Redshift

88
Q

You monitor CloudHSM via ______.

A

Syslog

89
Q

The two types of directory services are ____ and ________.

A

AD Connector; Simple AD

90
Q

By default, CloudWatch Logs will store your log data for how long?

A

Indefinitely

91
Q

The default CloudWatch Alarm History is only how many days?

A

14

92
Q

Step 1 of 3 for developing an Identity Broker is:

A

Develop an Identity Broker to communicate with LDAP & AWS STS

93
Q

Step 2 of 3 for developing an Identity Broker is:

A

Identity Broker always communicates with LDAP first, THEN with AWS STS

94
Q

Step 3 of 3 for developing an Identity Broker is:

A

Application then gets temporary access to AWS resources.

95
Q

AWS Security Token Service returns which four values upon request for a federated token?

A

A Token
A Secret Access Key
Access Key ID
A Duration

96
Q

True or False: To minimize the attack surface area, servers can be placed behind a bastion host, through which all traffic must pass.

A

False

97
Q

If you want Intrusion Prevention AND Intrusion Detection you should use what?

A

A IPS tool