TD Exam 2 - Short Review Flashcards

1
Q

What Load Balancer should you use if you want unbroken encryption

A

NLB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which Load Balancer should you use if you want Static IP for whitelisting

A

NLB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which Load Balancer should you use if you want the fastest performance (millions of rps)

A

NLB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which Load Balancer should you use if you want to use a protocol other than HTTP or HTTPS

A

NLB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which Load Balancer should you use if you need Private Link

A

NLB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which Load Balancer should you use if you need to use Layer 7 information

A

ALB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which Load Balancer should you use for a gRPC app

A

ALB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can you assign an Elastic IP to an ALB

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Can you assign an Elastic IP to a NLB

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the protocol versions for ALB

A

HTTP1
HTTP2
gRPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Do NLBs support gRPC

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are some use cases for Lambda@Edge

A

A/B Testing
Migration between S3 origins
Different Objects Based on Device
Content by Country
Overriding a response header
Redirect unauthenticated users to a sign-in page
Normalize query string params for better cache hits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What should you used if you want to do A/B testing with CloudFront

A

Lambda@Edge on the viewer request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What should you used if you want to do migration between S3 origins with CloudFront

A

Lambda@Edge on the Origin request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What should you used if you want to do different objects based on device with CloudFront

A

Lambda@Edge on the Origin request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What should you use if you want to do different content by country with CloudFront

A

Lambda@Edge on the Origin request

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What do CloudFront Header Policies do

A

They tell which HTTP headers should be included or excluded in the responses sent by CloudFront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which service should you use for transferring large sets of data to aws?

A

DataSync, not storage gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

When should you use DataSync

A

When you need reliable transfer of large amounts of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is Amazon EMR

A

A managed cluster platform that simplifies running big data frameworks, like Apache Hadoop and Apache Spark

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What can you use Amazon EMR for

A

To process data, to transform and move large amounts of data in and out of AWS data stores and databases

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is Amazon Redshift

A

A cloud data warehouse

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What does Redshift do

A

It makes it fast, simple and cost-effective to analyze all your data using standard SQL and existing BI tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is AWS Network Firewall

A

A stateful, managed network firewall and intrusion detection and prevention service for VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Where do you create an AWS Network Firewall

A

In your VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Where do AWS Network Firewalls filter traffic

A

At the perimeter of the VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

At which level do Security Gorups provide protection

A

Instance level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

At what level do NACLs provide protection

A

Subnet level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

At what level foes WAF provide protection

A

Endpoint level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What is needed if you set up AWS Network Firewall

A

Reroute VPC network traffic through the firewall endpoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

How do you ensure 2 instances in different subnets can communicate

A

NACLs to allow traffic between subnets
SGs to allow instance to instance communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Do you launch Aurora in subnets

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What is the default value for ASGs cooldown

A

300

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

What does cooldown do in ASGs

A

It ensures that auto-0scaling does not terminate or launch instances before the previous scaling activity has taken effect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Are cooldowns in ASGs configurable

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

When would you use RDS Proxy

A

If you have a too many connections error
If you’re using Lambda
When you need long-running connections
When resilience to db failure is important

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What do you pay for in API Gateway

A

Per API call and for data transferred out

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Which APIs are supported by API Gateway

A

REST, HTTP, WebSockets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

What does AWS Config do

A

It enables you to assess, audit and evaluate the configurations of AWS resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What does AWS Inspector do

A

It scans EC2 instances and its OS (also containers) for vulnerabilities and deviations against best practices
Can do networking assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

What does GuardDuty do

A

It generates findings of suspicious activities using AI. It is used with data sources and can be cross-account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

How does failover occur in RDS multi-AZ

A

CNAME is switched from primary to standby instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

Can DMS work with DynamoDB

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Can you use S3 as a target for DMS

A

Yes, and it will write data as CSV by default
Can also use parquet format if you want something more compact with faster queries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

How can you encrypt DMS connections

A

Use SSL by assigning a certificate to a DMS endpoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Do you need to set up SSL for Redshift data transfer

A

No, it’s endpoint already uses SSL, no need to set it up in DMS

47
Q

What is Landing Zone

A

It allows you to set up a well-architected multi-account environment with rules for security, operations and internal compliance

48
Q

How can you allow Organizational Units to launch new accounts with preapproved configurations

A

Use AWS Control Tower with guardrails to enfore policies or detect violations

49
Q

What is Control Tower GuardRails

A

It provides governance controls by preventing the creation of resources that don<t conform

50
Q

What other AWS services are used by Control Tower Guardrails

A

CloudFormation to establish a baseline
AWS Organization Service Control POlicies to prevent configuration changes
AWS Config rules to continuously detect non-complicance

51
Q

How do you specify a role for an ECS task

A

Declare the IAM Role in the taskRoleArn section of the task definition

52
Q

What is a service that is very suitable for batch jobs

A

ECS

53
Q

How can you use an existing Directory for AWS sign in

A

Use IAM Identity center (Federation)

54
Q

What do SCPs do

A

They say what permissions can be granted to identities in accounts in an organization

55
Q

Is the directory service intended to be used for multi-account auth purposes

A

No, not directly from AWS Organization, you still need IAM Identity center

56
Q

How do you use an existing directory service for user authentication

A

Configure IAM Identity center and integrate it using the Active Directory Connector

57
Q

Is there an option to use an external authentication on AWS Organizations

A

No

58
Q

Can you create VPC peering between onprem network and VPC

A

No

59
Q

Do peered VPCs support edge-to-edge routing

A

No

60
Q

Can VPC peering transmit a VPN connection

A

No

61
Q

Can VPC peering transmit a Direct Connect connection

A

No

62
Q

Can VPC peering transmit an internet connection from an Internet Gateway

A

No

63
Q

What are some services you can use to create a decoupled architecture for apps onprem and in AWS

A

SQS and SWF (Simple Workflow Service)

64
Q

Where can workers from SWF be

A

On cloud or onprem

65
Q

What is Amazon SWF

A

A web service that makes it easy to coordinate work across distributed application components

66
Q

What are the 2 main concepts in SWF

A

Tasks: invocation of logical steps in applications
Workers: programs that interact with SWF to get tasks, process them and return their results

67
Q

Can subnets span AZs

A

No

68
Q

For VPCs, are IPv4 CIDR ranges required

A

Yes

69
Q

For VPCs, are IPv6 CIDR ranges required

A

No

70
Q

Can you disable IPv4 for a VPC

A

No

71
Q

What do you need to attach to your VPC to have a VPN

A

Virtual Provate Gateway

72
Q

What are the steps to implement a VPN to a VPC

A

Attach a virtual private gateway to the VPC
Create a custom route table
Update security group rules
Create an AWS-managed VPN connection

73
Q

What does a customer gateway resource fo in AWS

A

It provies information to AWS about your customer gateway device

74
Q

Do Customer Gateways need a publicly routable static IP

A

Yes

75
Q

Do you need to attach an elastic IP to a Virtual Private Gateway

A

No

76
Q

Do you need a NAT instance to create a VPN connection

A

No

77
Q

What does geoproximity routing do

A

It gives the CLOSEST record

78
Q

Is EBS off-instance

A

Yes

79
Q

Can EBS volumes be attached to any EC2 instance in any AZ

A

No, it is only in one AZ

80
Q

Do EBS volumes support live configuration changes while in production

A

Yes, you can modify volume type, volume size and IOPS capacity without service interuption

81
Q

Can you modify EBS volume size without interruption

A

Yes

82
Q

Can you modify EBS volume type without interruption

A

Yes

83
Q

Can you modify EBS IOPS capacity without interruption

A

Yes

84
Q

Does EBS automatically replicate to another AZ

A

No

85
Q

Does EBS do automatic replication

A

Yes, within an AZ

86
Q

What types of EBS and EC2 instance types allow multi-instance connection

A

Provisioned IOPS SSD (io1) attached to multiple Nitro-based instances using EBS Multi-Attach

87
Q

What kind of VPC endpoint can be used with DynamoDB

A

Gateway endpoint

88
Q

What do you specify when you create a DynamoDB Gateway endpoint

A

Specify the VPC where it will be deployed and the route table that will be associated with the endpoint

89
Q

How can you implement department-by-department cost-tracking

A

Tag resources with the department name and enable cost allocation tags

90
Q

What is a tag in AWS

A

A label you associate to an AWS resource
COnsists of a key and a value
Each tag key must be unique
Each tag key can only have one value

91
Q

What are tags used for in AWS

A

To organize resources

92
Q

What are cost allocation tags used for in AWS

A

to track costs on a detailed level

93
Q

What does AWS Budget do

A

It allows you to be alerted and run custom actions if budget thresholds are exceeded

94
Q

Where do you need to activate tags to enable cost-tracking

A

In Billing and Cost management console

95
Q

What is Amazon EMR

A

A managed cluster that simplifies running big data frameworks on AWS to process and analyze vast amounts of data. It can do ETL

96
Q

What service should you associate with the phrase “big data processing frameworks”

A

EMR

97
Q

What service should you associate with the phrase “access data using various business intelligence tools and standard SQL queries”

A

Amazon Redshift

98
Q

Can you use big data frameworks effectively with Glue

A

No, use EMR

99
Q

What service allows you to do SQL queries in S3

A

Athena

100
Q

What does S3 select feature do

A

Allows you to run simple SQL queries against a subset of data from a specific S3 object

101
Q

What does Amazon Managed Service for Apache Flink studio do

A

Process streaming data

102
Q

What should you do to convert csv files to Parquet

A

Scheduled ETL job in AWS Glue, use crawler to automatically discover raw data

103
Q

What is a fanout scenario

A

SNS topic used to push to multiple places (multiple SQS queues subscribed to the topic)

104
Q

How can you limit what an SNS subscriber gets

A

SNS message filtering; by default, they receive everything

105
Q

Can you specify failover for Route 53

A

Yes

106
Q

What happens when you enable failover in route 53

A

It points to secondary when primary is unhealthy

107
Q

What do you need to host a static website on S3

A

An S3 bucket with the same name as the domain or subdomain configured to host a static website
Registered domain name
Route 53 as the DNS service for the domain

108
Q

Does the S3 bucket need to be in the same region as the R53 hosted zone for a static website

A

No

109
Q

What is a Bastion host

A

EC2 in public subnet with public or elastic IP with sufficient RDP or SSH access. Users log into it to manage other hosts in private subnets

110
Q

What protocol do you use with a Windows Bastion host

A

RDP

111
Q

What is Amazon Data Lifecycle Manager used for

A

Can use it to automate the creation, retention and deletion of snapshots taken to back up EBS

112
Q

Is there such a thing as EBS lifecycle policy

A

No

113
Q
A