TD Exam 5 - Review Flashcards

1
Q

What is the minimum billing duration for AWS Glue

A

1 minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can AWS Batch automatically provision capacity for your batch jobs

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Does step scaling use CloudWatch Alarms

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What deos step scaling vary depending on

A

Size of alarm breach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does simple scaling depend on

A

A SINGLE scaling adjustment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Is there such a thing as AWS Storage Gateway Hardware appliance

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What do you do if you want to use Storage gateway with an app that does not run on virtualized stuff

A

Storage Gateway Hardware appliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What kind of storage gateway do you need to use if you want SMB or NFS

A

File Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What protocol is used by Storage gateway volume mode

A

iSCSI, it’s block devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does AppSync Gateway do

A

It offers an elegant server-side solution to aggregate data from multiple databases

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is edge-optimized API Gateway used for

A

With CloudFront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What can Transit Gateway use to make VPN more scalable

A

Equal Cost Multipath Routing, to do routing over multiple VPN tunnels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the max throughput of a VPN tunnel

A

1.25 Gbps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How many Virtual Private Gateways can VPCs have

A

One

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can you have more than 2 tunnels for a VPN

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Will having a second Customer gateway device increase throughput of a VPN

A

No, only the redundancy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What does Aurora do during Failover if you have no standby and are not serverless

A

Attemps to create new instance in same AZ, best efforts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What happens during Aurora failover if you have a replica

A

CName flips to helathy relica. Around 30 s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What does Aurora do during Failover if you have no standby and are serverless

A

Aurora automatically recreate db in different AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What should you put in Route 53 to link an ALB

A

ALB DNS name

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Can you create CNAME records for you zone Apex

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Is data between EBS and EC2 encrypted if you use EBS encryption

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Are snapshots encrypted automatically if you use EBS encryption

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Are volumes created from encrypted EBS snapshots also encrypted

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What do you use to configure instances without SSH and RDP if Systems Manager is enabled

A

Run Command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Should you use NACLs to deny access from a country

A

No, there is a lot of IPs in a country

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What should you do to deny access from a Country

A

AWS WAF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What is Amazon Workspaces used for

A

Virtual Desktops

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Are cloudtrail files encrypted by default

A

Yes, using SSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Can EBS volumes be used when a snapshot is in progress

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

How does data load to a volume created from EBS snapshot

A

Lazily and in the background

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Can Network firewall be used to inspect traffic entering and exiting a VPC

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

is Network Firewall stateless

A

No, it is stateful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Can you set lifecycle policy for 0 days in S3

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Can you upload directly to Glacier

A

Yes, but not using the console
Using console, you can change storage class to glacier though

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Can you specify public IPs for ALB

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What do you need to point to onprem from ALB

A

PrivateLink or VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Does Network Load Balancer have weighted routing

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

What should you use if you need Real Time

A

Kinesis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What is AppSync

A

Serverless GraphQL and Pub/Sub API

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Does AWS Trusted Advisor have Service Limits checks

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What are CloudTrail Management events

A

Visibility into management events of AWS accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

What are data events in CloudTrail

A

Resource operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

What polling does SQS use by default

A

Short Polling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

How do you configure polling in SQS

A

ReceiveMessageWaitTimeSeconds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

What value for ReceiveMessageWaitTimeSeconds means short polling

A

0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

What value for ReceiveMessageWaitTimeSeconds means long polling

A

more than 0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What is false empty responses in SQS

A

You get an empty response when using short polling because not all servers are polled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

How does long polling diminish the number of empty responses

A

By allowing SQS to wait for a message before sending a response, until timeout

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

How to you ensure all servers are polled using SQS

A

Use long polling

51
Q

What is the max performance for S3

A

3500 writes per s, 5500 reads per s per S3 prefix

52
Q

Does EFA support Windows

A

No

53
Q

What is AWS ParallelCluster

A

AWS-supported open-source cluster management tool

54
Q

What is a useful metric when sclaing based on SQS

A

ApproximateAgeOfOldestMessage

55
Q

What is a limitation of SimpleDB

A

It has a limit on request capacity and storage size for a given table

56
Q

How do you delay termination of instance

A

Lifecycle hook in AutoScaling Group to use Terminating:Wait state

57
Q

What is instance warmup condition

A

Specifies how long before including instance in metric

58
Q

What is AWS Wavelength

A

Allows AWS deployments in telecom provider data centers at edge of 5g netwroks

59
Q

What is the point of Wavelength

A

Extend AWS to 5g edges

60
Q

How can you used IAM for kubernetes RBAC

A

aws-auth configmap

61
Q

What is default visibility timeout

A

30s

62
Q

Which is more scalable, RDS or Aurora

A

Aurora

63
Q

Can you use tags to limit access to ressources with IAM

A

Yes

64
Q

Would XRAY on an ECS cluster track IP

A

No

65
Q

What is CloudWatch application insights

A

Facilitates observability of apps and underlying AWS resources
Uses SageMaker

66
Q

What do Access Logs on ALB provide

A

Request time, latencies, paths, client IP, server response
Disabled by default

67
Q

CloudTrail vs Cloudwatch

A

CloudTrail: AWS console actions and api calls
Cloudwatch: systems monitoring

68
Q

How to use IAM with MySQL

A

AWSAuthenticationPlugin for MySQL

69
Q

What DB engines does IAM db auth work with

A

MySQL and PostgreSQL

70
Q

What is an advantage of IAM DB auth

A

SSL for traffic

71
Q

What are NS record types

A

Allow delegation to occur

72
Q

What are A and AAAA records

A

Map host to IP (A = IPv4, AAAA = IPv6)
Or AWS Resource with alias

73
Q

What is CNAME Records

A

Host to host (point to other names)

74
Q

What is MX records

A

Mail

75
Q

What is TXT record

A

Used to prove domain ownership
Add random text

76
Q

Can you use a CNAME for the apex of a domain

A

No

77
Q

Could you use a CNAME to point to an ALB with www.asd.com

A

Yes, ity is not the apex

78
Q

Could you use a CNAME to point to an ALB with asd.com

A

No, it is the apex

79
Q

What is an alias record

A

Usually, maps name to AWS resource

80
Q

What can alias record be used with

A

naked/apex and normal recors

81
Q

What is the difference between alias an CNAME record for non-apex domains

A

They work in the same way.
Alias is free for requests pointing at AWS resource

82
Q

What type of record should you pick when pointing to AWS Service

A

Alias

83
Q

What is the record type for an alias

A

Should be the same type as what it is pointing at; can be CNAME, A, etc

84
Q

What kind of record is the DNS fiven for an ELB

A

A record

85
Q

What kind of record do you need for DNS pointing to ALB

A

Alias A record

86
Q

Can you use alias elsewhere than R53

A

No, it is implemented by AWS, outside the DNS standard

87
Q

Is EBS encrypted by default

A

No

88
Q

Where is the key to decrypt EBS held in plaintext

A

Only in memory of EC2 host

89
Q

Can you configure encryption for EBS by deaulft

A

Yes, for an account

90
Q

Is KMS key used to encrypt EBS volume

A

No, it uses a DEK, one per volume

91
Q

What volumes uses the same DEK in EBS

A

Snapshots, future volumes and the volume itself. No other volume uses it.

92
Q

Can you remove encryption from an EBS volume or snapshot

A

No

93
Q

What does OS see in an encrypted EBS

A

Plaintext

94
Q

Is EC2 OS aware of encryption

A

No
No performance loss

95
Q

What encryption used for EBS

A

AES-256

96
Q

Can you detach secondary ENI

A

Yes, and attach it to other instance

97
Q

Can ENIs have source/destination checks

A

Yes

98
Q

What is RDS multiAZ instance mode

A

One standby in other AZ
Synchronous replication at storage level
Access via CNAME points to primary
Can do backup from standby
Failover: CNAME points to standby
60-120s, remove DNS caching for faster
Cannot use standby for read/writes
Same region only

99
Q

What is RDS multiAZ cluster mode

A

One writer, 2 readers replicas (only) different AZs
SYNCHRONOUS replication
Readers are usable
Data committed when one reader at least has it
Each instance has it’s storage
Cluster endpoint
Reader endpoint (can include writer)
Instance endpoints
Replication via transaction logs, more efficient
Failover is faster, 35s + transaction logs apply

100
Q

What is Aurora

A

Single primary + 0 or more replicas; failover and reads
No local storage, shared cluster volume
Max size of shared storage: 128 TiB, across AZs
Synchronous replication across storage nodes
Replication at storage level
All instances have access to all storage nodes
Default: only primary can write
Can have up to 15 replicas, any can be failover
Don’t allocate storage, billed on what is used, high water mark
Endpoints

101
Q

What is Aurora serverless

A

Billed as serverless, write min an max ACU
Same resilience as Aurora (6 copies across AZ)

102
Q

How many REad instances in Aurora Global DB

A

only one

103
Q

What is systems manager used for

A

Centralize operational data and automate tasks across resources

104
Q

What does run command do

A

Remotely and securely manage configuration of managed instances at scale

105
Q

What is WAF

A

L7 firewall

106
Q

What does WAF apply to

A

CF, ALB, AppSync, API Gateway and such

107
Q

What is logged in CloudTrail

A

Almost anything that can be done to an AWS account

108
Q

What is default storage for CloudTrail

A

90 days

109
Q

Is Cloudtrail RT

A

No

110
Q

How are EBS snapshots implemented

A

They are incremental

111
Q

How can you force a complete restore of EBWS snapshot

A

Force read data
Or FSR (Fast snapshot restore)

112
Q

When should you use datasync

A

Huge transfers
Schedule
Encryption
Throttling
Automatic retry

113
Q

What is max size of SQS message

A

256 KB

114
Q

Does SQS support encryption

A

Yes, using KMS, at rest

115
Q

What are ASG Lifecycle hooks

A

Allow you to set up custom actions during ASG actions

116
Q

What do ASG Lifecycle hooks do

A

Instances are paused within flow, until timeout or unpaused (CompleteLifecycleAction)

117
Q

What can be used with Lifecycle hooks

A

SNS and EventBridge

118
Q

What is a concept used in step scaling

A

Size of alarm breach

119
Q

Can ASG respond to additional alarms during scaling for simple scaling

A

No

120
Q

Can ASG respond to additional alarms during scaling for step scaling

A

Yes

121
Q

Can AWS Achema COnversion handle app code

A

Apparently, yes

122
Q

What are the 2 supported solutions to add nodes automatically to EKS

A

Karpenter
Cluster Autoscaler

123
Q
A