Test 1 Flashcards

1
Q
  1. Under the shared responsibility model, which of the following is the customer responsible for?

A. Ensuring that disk drives are wiped after use.
B. Ensuring that firmware is updated on hardware devices.
C. Ensuring that data is encrypted at rest.
D. Ensuring that network cables are category six or higher.

A

C. Ensuring that data is encrypted at rest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
  1. The use of what AWS feature or service allows companies to track and categorize spending on a detailed level?

A. Cost allocation tags
B. Consolidated billing
C. AWS Budgets
D. AWS Marketplace

A

C. AWS Budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
  1. Which service stores objects, provides real-time access to those objects, and offers versioning and lifecycle capabilities?

A. Amazon Glacier
B. AWS Storage Gateway
C. Amazon S3
D. Amazon EBS

A

C. Amazon S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
  1. What AWS team assists customers with accelerating cloud adoption through paid engagements in any of several specialty practice areas?

A. AWS Enterprise Support
B. AWS Solutions Architects
C. AWS Professional Services
D. AWS Account Managers

A

C. AWS Professional Services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
  1. A customer would like to design and build a new workload on AWS Cloud but does not have the AWS-related software technical expertise in-house.
    Which of the following AWS programs can a customer take advantage of to achieve that outcome?

A. AWS Partner Network Technology Partners
B. AWS Marketplace
C. AWS Partner Network Consulting Partners
D. AWS Service Catalog

A

C. AWS Partner Network Consulting Partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  1. Distributing workloads across multiple Availability Zones supports which cloud architecture design principle?

A. Implement automation.
B. Design for agility.
C. Design for failure.
D. Implement elasticity.

A

C. Design for failure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
  1. Which AWS services can host a Microsoft SQL Server database? (Choose two.)
A. Amazon EC2
B. Amazon Relational Database Service (Amazon RDS)
C. Amazon Aurora
D. Amazon Redshift
E. Amazon S3
A

A. Amazon EC2

B. Amazon Relational Database Service (Amazon RDS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
  1. Which of the following inspects AWS environments to find opportunities that can save money for users and also improve system performance?

A. AWS Cost Explorer
B. AWS Trusted Advisor
C. Consolidated billing
D. Detailed billing

A

A. AWS Cost Explorer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
  1. Which of the following Amazon EC2 pricing models allow customers to use existing server-bound software licenses?

A. Spot Instances
B. Reserved Instances
C. Dedicated Hosts
D. On-Demand Instances

A

C. Dedicated Hosts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  1. Which AWS characteristics make AWS cost effective for a workload with dynamic user demand? (Choose two.)
A. High availability
B. Shared security model
C. Elasticity
D. Pay-as-you-go pricing
E. Reliability
A

C. Elasticity

D. Pay-as-you-go pricing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
  1. Which service enables risk auditing by continuously monitoring and logging account activity, including user actions in the AWS Management Console and AWS
    SDKs?

A. Amazon CloudWatch
B. AWS CloudTrail
C. AWS Config
D. AWS Health

A

B. AWS CloudTrail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
  1. Which of the following are characteristics of Amazon S3? (Choose two.)
A. A global file system
B. An object store
C. A local file store
D. A network file system
E. A durable storage system
A

B. An object store

E. A durable storage system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  1. Which services can be used across hybrid AWS Cloud architectures? (Choose two.)
A. Amazon Route 53
B. Virtual Private Gateway
C. Classic Load Balancer
D. Auto Scaling
E. Amazon CloudWatch default metrics
A

A. Amazon Route 53

B. Virtual Private Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
  1. What costs are included when comparing AWS Total Cost of Ownership (TCO) with on-premises TCO?

A. Project management
B. Antivirus software licensing
C. Data center security
D. Software development

A

C. Data center security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
  1. A company is considering using AWS for a self-hosted database that requires a nightly shutdown for maintenance and cost-saving purposes.
    Which service should the company use?

A. Amazon Redshift
B. Amazon DynamoDB
C. Amazon Elastic Compute Cloud (Amazon EC2) with Amazon EC2 instance store
D. Amazon EC2 with Amazon Elastic Block Store (Amazon EBS)

A

D. Amazon EC2 with Amazon Elastic Block Store (Amazon EBS)

Instance can be shutdown to save cost. When instance shutdown, the attached volume EBS will not be removed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q
  1. Which of the following is a correct relationship between regions, Availability Zones, and edge locations?

A. Data centers contain regions.
B. Regions contain Availability Zones.
C. Availability Zones contain edge locations.
D. Edge locations contain regions.

A

B. Regions contain Availability Zones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q
  1. Which AWS tools assist with estimating costs? (Choose three.)
A. Detailed billing report
B. Cost allocation tags
C. AWS Simple Monthly Calculator
D. AWS Total Cost of Ownership (TCO) Calculator
E. Cost Estimator
A

B. Cost allocation tags
C. AWS Simple Monthly Calculator
D. AWS Total Cost of Ownership (TCO) Calculator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q
  1. Which of the following are advantages of AWS consolidated billing? (Choose two.)

A. The ability to receive one bill for multiple accounts
B. Service limits increasing by default in all accounts
C. A fixed discount on the monthly bill
D. Potential volume discounts, as usage in all accounts is combined
E. The automatic extension of the master accounts AWS support plan to all accounts

A

A. The ability to receive one bill for multiple accounts

D. Potential volume discounts, as usage in all accounts is combined

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q
  1. Which of the following Reserved Instance (RI) pricing models provides the highest average savings compared to On-Demand pricing?

A. One-year, No Upfront, Standard RI pricing
B. One-year, All Upfront, Convertible RI pricing
C. Three-year, All Upfront, Standard RI pricing
D. Three-year, No Upfront, Convertible RI pricing

A

C. Three-year, All Upfront, Standard RI pricing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q
  1. Compared with costs in traditional and virtualized data centers, AWS has:

A. greater variable costs and greater upfront costs.
B. fixed usage costs and lower upfront costs.
C. lower variable costs and greater upfront costs.
D. lower variable costs and lower upfront costs.

A

D. lower variable costs and lower upfront costs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q
  1. A characteristic of edge locations is that they:

A. host Amazon EC2 instances closer to users.
B. help lower latency and improve performance for users.
C. cache frequently changing data without reaching the origin server.
D. refresh data changes daily.

A

B. help lower latency and improve performance for users.

An edge location is where end-users access services located at AWS. They are located in most of the major cities around the world and are specifically used by CloudFront (CDN) to distribute content to end-user to reduce latency.

AWS edge computing services provide infrastructure and software that move data processing and analysis as close to the end-point as necessary. This includes deploying AWS managed hardware and software to locations outside AWS data centers, and even onto customer-owned devices themselves.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q
  1. Which of the following can limit Amazon Storage Service (Amazon S3) bucket access to specific users?

A. A public and private key-pair
B. Amazon Inspector
C. AWS Identity and Access Management (IAM) policies
D. Security Groups

A

C. AWS Identity and Access Management (IAM) policies

Amazon Inspector - automated security assessment service that helps you test the network accessibility of your Amazon EC2 instances and the security state of your applications running on the instances.
https://aws.amazon.com/inspector/faqs/

Security Groups - A security group acts as a virtual firewall for your instance to control inbound and outbound traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q
  1. Which of the following security-related actions are available at no cost?

A. Calling AWS Support
B. Contacting AWS Professional Services to request a workshop
C. Accessing forums, blogs, and whitepapers
D. Attending AWS classes at a local university

A

C. Accessing forums, blogs, and whitepapers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q
  1. Which of the Reserved Instance (RI) pricing models can change the attributes of the RI as long as the exchange results in the creation of RIs of equal or greater value?

A. Dedicated RIs
B. Scheduled RIs
C. Convertible RIs
D. Standard RIs

A

C. Convertible RIs

Convertible RIs: These provide a discount (up to 54% off On-Demand) and the capability to change the attributes of the RI as long as the exchange results in the creation of Reserved Instances of equal or greater value. Like Standard RIs, Convertible RIs are best suited for steady-state usage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q
  1. Which AWS feature will reduce the customerג€™s total cost of ownership (TCO)?

A. Shared responsibility security model
B. Single tenancy
C. Elastic computing
D. Encryption

A

C. Elastic computing

A. Shared responsibility security model .- not related with cost
B. Single tenancy.- Related more with on premises infrastructure
C. Elastic computing .- Capacity to increase/decrease capacity with investment = 0, so these is related to cost
D. Encryption.- Is to protect data, no necessary to cost.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q
  1. Which of the following services will automatically scale with an expected increase in web traffic?

A. AWS CodePipeline
B. Elastic Load Balancing
C. Amazon EBS
D. AWS Direct Connect

A

B. Elastic Load Balancing

Automatically scale your applications
Elastic Load Balancing provides confidence that your applications will scale to the demands of your customers. With the ability to trigger Auto Scaling for your Amazon EC2 instance fleet when latency of any one of your EC2 instances exceeds a preconfigured threshold, your applications will always be ready to serve the next customer request.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q
  1. Where are AWS compliance documents, such as an SOC 1 report, located?

A. Amazon Inspector
B. AWS CloudTrail
C. AWS Artifact
D. AWS Certificate Manager

A

C. AWS Artifact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q
  1. Under the AWS shared responsibility model, which of the following activities are the customer’s responsibility? (Choose two.)

A. Patching operating system components for Amazon Relational Database Server (Amazon RDS)
B. Encrypting data on the client-side
C. Training the data center staff
D. Configuring Network Access Control Lists (ACL)
E. Maintaining environmental controls within a data center

A

B. Encrypting data on the client-side

D. Configuring Network Access Control Lists (ACL)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q
  1. Which is a recommended pattern for designing a highly available architecture on AWS?

A. Ensure that components have low-latency network connectivity.
B. Run enough Amazon EC2 instances to operate at peak load.
C. Ensure that the application is designed to accommodate failure of any single component.
D. Use a monolithic application that handles all operations.

A

C. Ensure that the application is designed to accommodate failure of any single component.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q
  1. According to best practices, how should an application be designed to run in the AWS Cloud?

A. Use tightly coupled components.
B. Use loosely coupled components.
C. Use infrequently coupled components.
D. Use frequently coupled components.

A

B. Use loosely coupled components.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q
  1. AWS supports which of the following methods to add security to Identity and Access Management (IAM) users? (Choose two.)

A. Implementing Amazon Rekognition
B. Using AWS Shield-protected resources
C. Blocking access with Security Groups
D. Using Multi-Factor Authentication (MFA)
E. Enforcing password strength and expiration

A

D. Using Multi-Factor Authentication (MFA)
E. Enforcing password strength and expiration

IAM Best Practices:

  • Configure a Strong Password Policy for Your Users
  • -If you allow users to change their own passwords, require that they create strong passwords and that they rotate their passwords periodically.
  • Enable MFA
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q
  1. Which AWS services should be used for read/write of constantly changing data? (Choose two.)
A. Amazon Glacier
B. Amazon RDS
C. AWS Snowball
D. Amazon Redshift
E. Amazon EFS
A

B. Amazon RDS
E. Amazon EFS

EFS is a shared file storage and it looks obvious that you will keep on editing or reading files from your NAS drive.
RDS is meant for transactional database which means its suited for frequent Read/write
Redshift is warehouse so its not suited for Write
Glacier is not a suited for any data which needs to frequently read and written.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q
  1. What is one of the advantages of the Amazon Relational Database Service (Amazon RDS)?

A. It simplifies relational database administration tasks.
B. It provides 99.99999999999% reliability and durability.
C. It automatically scales databases for loads.
D. It enables users to dynamically adjust CPU and RAM resources.

A

A. It simplifies relational database administration tasks.

RDS is a managed service, so A is the correct answer. B is not correct, the twelve 9 durability is an aspect of S3 storage. C is not correct, RDS does not scale automatically. D is not correct, the hardware resources are managed by AWS.

34
Q
  1. A customer needs to run a MySQL database that easily scales. Which AWS service should they use?

A. Amazon Aurora
B. Amazon Redshift
C. Amazon DynamoDB
D. Amazon ElastiCache

A

A. Amazon Aurora

Amazon Aurora is a MySQL and PostgreSQL-compatible relational database built for the cloud, that combines the performance and availability of traditional enterprise databases with the simplicity and cost-effectiveness of open source databases.

35
Q
  1. Which of the following components of the AWS Global Infrastructure consists of one or more discrete data centers interconnected through low latency links?

A. Availability Zone
B. Edge location
C. Region
D. Private networking

A

A. Availability Zone

An Availability Zone (AZ) is one or more discrete data centers with redundant power, networking, and connectivity in an AWS Region.

36
Q
  1. Which of the following is a shared control between the customer and AWS?

A. Providing a key for Amazon S3 client-side encryption
B. Configuration of an Amazon EC2 instance
C. Environmental controls of physical AWS data centers
D. Awareness and training

A

D. Awareness and training

Shared Controls – Controls which apply to both the infrastructure layer and customer layers, but in completely separate contexts or perspectives. In a shared control, AWS provides the requirements for the infrastructure and the customer must provide their own control implementation within their use of AWS services. Examples include:
Patch Management – AWS is responsible for patching and fixing flaws within the infrastructure, but customers are responsible for patching their guest OS and applications.
Configuration Management – AWS maintains the configuration of its infrastructure devices, but a customer is responsible for configuring their own guest operating systems, databases, and applications.
Awareness & Training - AWS trains AWS employees, but a customer must train their own employees.

37
Q
  1. How many Availability Zones should compute resources be provisioned across to achieve high availability?

A. A minimum of one
B. A minimum of two
C. A minimum of three
D. A minimum of four or more

A

B. A minimum of two

Werner Vogels (AWS CTO) said in a youtube video that AWS has change their policy and will now make new Regions to contains at least THREE Availability Zones (previously it was a min of 2) I selected option B cause it’s probably legacy but eventually it might become 3 AZ to achieve “HA”

38
Q
  1. One of the advantages to moving infrastructure from an on-premises data center to the AWS Cloud is:

A. it allows the business to eliminate IT bills.
B. it allows the business to put a server in each customers data center.
C. it allows the business to focus on business activities.
D. it allows the business to leave servers unpatched.

A

C. it allows the business to focus on business activities.

Focus on projects that differentiate your business, not the infrastructure. Cloud computing lets you focus on your own customers, rather than on the heavy lifting of racking, stacking, and powering servers.

39
Q
  1. What is the lowest-cost, durable storage option for retaining database backups for immediate retrieval?

A. Amazon S3
B. Amazon Glacier
C. Amazon EBS
D. Amazon EC2 Instance Store

A

A. Amazon S3

Amazon S3 have one important point - durable storage, which is one of main feature of S3

40
Q
  1. Which AWS IAM feature allows developers to access AWS services through the AWS CLI?

A. API keys
B. Access keys
C. User names/Passwords
D. SSH keys

A

B. Access keys

41
Q
  1. Which of the following is a fast and reliable NoSQL database service?

A. Amazon Redshift
B. Amazon RDS
C. Amazon DynamoDB
D. Amazon S3

A

C. Amazon DynamoDB

42
Q
  1. What is an example of agility in the AWS Cloud?

A. Access to multiple instance types
B. Access to managed services
C. Using Consolidated Billing to produce one bill
D. Decreased acquisition time for new compute resources

A

D. Decreased acquisition time for new compute resources

D. Decreased acquisition time for new compute resources

43
Q
  1. Which service should a customer use to consolidate and centrally manage multiple AWS accounts?

A. AWS IAM
B. AWS Organizations
C. AWS Schema Conversion Tool
D. AWS Config

A

B. AWS Organizations

44
Q
  1. What approach to transcoding a large number of individual video files adheres to AWS architecture principles?

A. Using many instances in parallel
B. Using a single large instance during off-peak hours
C. Using dedicated hardware
D. Using a large GPU instance type

A

A. Using many instances in parallel

A is correct because it is aligned with the design principal of scale horizontally.

45
Q
  1. For which auditing process does AWS have sole responsibility?

A. AWS IAM policies
B. Physical security
C. Amazon S3 bucket policies
D. AWS CloudTrail Logs

A

B. Physical security

AWS responsibility “Security of the Cloud” - AWS is responsible for protecting the infrastructure that runs all of the services offered in the AWS Cloud. This infrastructure is composed of the hardware, software, networking, and facilities that run AWS Cloud services.

46
Q
  1. Which feature of the AWS Cloud will support an international companys requirement for low latency to all of its customers?

A. Fault tolerance
B. Global reach
C. Pay-as-you-go pricing
D. High availability

A

B. Global reach

47
Q
  1. Which of the following is the customerג€™s responsibility under the AWS shared responsibility model?

A. Patching underlying infrastructure
B. Physical security
C. Patching Amazon EC2 instances
D. Patching network infrastructure

A

C. Patching Amazon EC2 instances

Patching EC2 instance is customer’s responsibility.
AWS is responsible for protecting the infrastructure that runs all of the services offered in the AWS Cloud.” => hence A, B, D are incorrect as they’re AWS’ responsibilities

48
Q
  1. A customer is using multiple AWS accounts with separate billing.

How can the customer take advantage of volume discounts with minimal impact to the AWS resources?
A. Create one global AWS acount and move all AWS resources to tha account.
B. Sign up for three years of Reserved Instance pricing up front.
C. Use the consolidated billing feature from AWS Organizations.
D. Sign up for the AWS Enterprise support plan to get volume discounts.

A

C. Use the consolidated billing feature from AWS Organizations.

49
Q
  1. Which of the following are features of Amazon CloudWatch Logs? (Choose two.)

A. Summaries by Amazon Simple Notification Service (Amazon SNS)
B. Free Amazon Elasticsearch Service analytics
C. Provided at no charge
D. Real-time monitoring
E. Adjustable retention

A

D. Real-time monitoring
E. Adjustable retention

You can adjust the retention policy for each log group, keeping the indefinite retention, or choosing a retention period between 10 years and one day.
You can use subscriptions to get access to a real-time feed of log events

50
Q
  1. Which of the following is an AWS managed Domain Name System (DNS) web service?

A. Amazon Route 53
B. Amazon Neptune
C. Amazon SageMaker
D. Amazon Lightsail

A

A. Amazon Route 53

DNS decoding done by Route 53

51
Q
  1. A customer is deploying a new application and needs to choose an AWS Region.
    Which of the following factors could influence the customers decision? (Choose two.)

A. Reduced latency to users
B. The applications presentation in the local language
C. Data sovereignty compliance
D. Cooling costs in hotter climates
E. Proximity to the customers office for on-site visits

A

A. Reduced latency to users
C. Data sovereignty compliance

U have to make sure in compliant with country and be able to get info quickly to customer

52
Q
  1. Which storage service can be used as a low-cost option for hosting static websites?

A. Amazon Glacier
B. Amazon DynamoDB
C. Amazon Elastic File System (Amazon EFS)
D. Amazon Simple Storage Service (Amazon S3)

A

D. Amazon Simple Storage Service (Amazon S3)

53
Q
  1. Which Amazon EC2 instance pricing model can provide discounts of up to 90%?

A. Reserved Instances
B. On-Demand
C. Dedicated Hosts
D. Spot Instances

A

D. Spot Instances

Spot - Up to 90%
Reserved - Up to 75%

54
Q
  1. What is the AWS customer responsible for according to the AWS shared responsibility model?

A. Physical access controls
B. Data encryption
C. Secure disposal of storage devices
D. Environmental risk management

A

B. Data encryption

Custer data belongs to the customer responsibility for security ‘IN’ the cloud.

55
Q
  1. Which of the following AWS Cloud services can be used to run a customer-managed relational database?

A. Amazon EC2
B. Amazon Route 53
C. Amazon ElastiCache
D. Amazon DynamoDB

A

A. Amazon EC2

Key is customer-managed relational database

56
Q
  1. A company is looking for a scalable data warehouse solution.
    Which of the following AWS solutions would meet the companys needs?

A. Amazon Simple Storage Service (Amazon S3)
B. Amazon DynamoDB
C. Amazon Kinesis
D. Amazon Redshift

A

D. Amazon Redshift

Amazon Redshift is for data warehouse

57
Q
  1. Which statement best describes Elastic Load Balancing?

A. It translates a domain name into an IP address using DNS.
B. It distributes incoming application traffic across one or more Amazon EC2 instances.
C. It collects metrics on connected Amazon EC2 instances.
D. It automatically adjusts the number of Amazon EC2 instances to support incoming traffic.

A

B. It distributes incoming application traffic across one or more Amazon EC2 instances.

Elastic Load Balancing (ELB)
automatically distributes incoming application traffic across multiple targets, such as Amazon EC2 instances, containers, and IP addresses.

A. Route53
B. Elastic Load Balancing - Correct Answer
C. CloudWatch
D. AutoScaling

58
Q
  1. Which of the following are valid ways for a customer to interact with AWS services? (Choose two.)
A. Command line interface
B. On-premises
C. Software Development Kits
D. Software-as-a-service
E. Hybrid
A

A. Command line interface
C. Software Development Kits

There are three forms to interact with AWS Services.

AWS MGMT CONSOLE
Graphical interface to access AWS features

COMMAND LINE INTERFACE (CLI)
Lets you control AWS services from command line

SOFTWARE DEVELOPMENT KITS (SDKs)
Enable you to access AWS using a variety of popular programming languages

59
Q
  1. The AWS Clouds multiple Regions are an example of:

A. agility.
B. global infrastructure.
C. elasticity.
D. pay-as-you-go pricing.

A

B. global infrastructure.

60
Q
  1. Which of the following AWS services can be used to serve large amounts of online video content with the lowest possible latency? (Choose two.)
A. AWS Storage Gateway
B. Amazon S3
C. Amazon Elastic File System (EFS)
D. Amazon Glacier
E. Amazom CloudFront
A

B. Amazon S3

E. Amazom CloudFront

61
Q
  1. Web servers running on Amazon EC2 access a legacy application running in a corporate data center.
    What term would describe this model?

A. Cloud-native
B. Partner network
C. Hybrid architecture
D. Infrastructure as a service

A

C. Hybrid architecture

AWS Hybrid Cloud services deliver a consistent AWS experience wherever you need it – from the cloud, to on premises, and at the edge. Select from the broadest set of compute, networking, storage, security, identity, data integration, management, monitoring, and operations services to build hybrid architectures that meet your specific requirements and use cases.

62
Q
  1. What is the benefit of using AWS managed services, such as Amazon ElastiCache and Amazon Relational Database Service (Amazon RDS)?

A. They require the customer to monitor and replace failing instances.
B. They have better performance than customer-managed services.
C. They simplify patching and updating underlying OSs.
D. They do not require the customer to optimize instance type or size selections.

A

C. They simplify patching and updating underlying OSs.

AWS Managed Services helps to reduce your operational overhead and risk. AWS Managed Services automates common activities, such as change requests, monitoring, patch management, security, and backup services, and provides full-lifecycle services to provision, run, and support your infrastructure. AWS Managed Services unburdens you from infrastructure operations so you can direct resources toward differentiating your business.

63
Q
  1. Which service provides a virtually unlimited amount of online highly durable object storage?

A. Amazon Redshift
B. Amazon Elastic File System (Amazon EFS)
C. Amazon Elastic Container Service (Amazon ECS)
D. Amazon S3

A

D. Amazon S3

Amazon S3 is object storage built to store and retrieve any amount of data from anywhere on the Internet. It’s a simple storage service that offers an extremely durable, highly available, and infinitely scalable data storage infrastructure at very low costs.

64
Q
  1. Which of the following Identity and Access Management (IAM) entities is associated with an access key ID and secret access key when using AWS Command Line Interface (AWS CLI)?

A. IAM group
B. IAM user
C. IAM role
D. IAM policy

A

B. IAM user

Access keys are long-term credentials for an IAM user or the AWS account root user. You can use access keys to sign programmatic requests to the AWS CLI or AWS API (directly or using the AWS SDK).

65
Q
  1. Which of the following security-related services does AWS offer? (Choose two.)

A. Multi-factor authentication physical tokens
B. AWS Trusted Advisor security checks
C. Data encryption
D. Automated penetration testing
E. Amazon S3 copyrighted content detection

A

B. AWS Trusted Advisor security checks
C. Data encryption

AWS Trusted Advisor can improve the security of your application by closing gaps, enabling various AWS security features, and examining your permissions.

AWS doesn’t offer tokens, Tokens are third party.

66
Q
  1. Which AWS managed service is used to host databases?

A. AWS Batch
B. AWS Artifact
C. AWS Data Pipeline
D. Amazon RDS

A

D. Amazon RDS

Amazon Relational Database Service (Amazon RDS) makes it easy to set up, operate, and scale a relational database in the cloud. It provides cost-efficient and resizable capacity while automating time-consuming administration tasks such as hardware provisioning, database setup, patching and backups. It frees you to focus on your applications so you can give them the fast performance, high availability, security and compatibility they need.

67
Q

67.Which AWS service provides a simple and scalable shared file storage solution for use with Linux-based AWS and on-premises servers?

A. Amazon S3
B. Amazon Glacier
C. Amazon Elastic Block Store (Amazon EBS)
D. Amazon Elastic File System (Amazon EFS)

A

D. Amazon Elastic File System (Amazon EFS)

Amazon Elastic File System (Amazon EFS) provides a simple, scalable, fully managed elastic NFS file system for use with AWS Cloud services and on-premises resources. It is built to scale on demand to petabytes without disrupting applications, growing and shrinking automatically as you add and remove files, eliminating the need to provision and manage capacity to accommodate growth.
Amazon EFS is designed to provide the throughput, IOPS, and low latency needed for Linux workloads. Throughput and IOPS scale as a file system grows and can burst to higher throughput levels for short periods of time to support the unpredictable performance needs of file workloads. For the most demanding workloads, Amazon EFS can support performance over 10 GB/sec and up to 500,000 IOPS.

68
Q
  1. When architecting cloud applications, which of the following are a key design principle?

A. Use the largest instance possible
B. Provision capacity for peak load
C. Use the Scrum development process
D. Implement elasticity

A

D. Implement elasticity

Cloud services main proposition is to provide elasticity through horizontal scaling. Itג€™s already there. As for using largest instance possible, it is not a design principle that helps cloud applications in anyway. Scrum development process is not related to architecting. Therefore, a key principle is to provision your application for on-demand capacity. Peak loads is something that cloud applications experience everyday. Peak load management should be a necessary part of cloud application design principle.

69
Q
  1. Which AWS service should be used for long-term, low-cost storage of data backups?

A. Amazon RDS
B. Amazon Glacier
C. AWS Snowball
D. AWS EBS

A

B. Amazon Glacier

Amazon S3 Glacier and S3 Glacier Deep Archive are a secure, durable, and extremely low-cost Amazon S3 cloud storage classes for data archiving and long-term backup.

70
Q
  1. Under the shared responsibility model, which of the following is a shared control between a customer and AWS?

A. Physical controls
B. Patch management
C. Zone security
D. Data center auditing

A

B. Patch management

Shared controls are: Patch Management, Configurations Management, Awareness & Training.
Shared Controls – Controls which apply to both the infrastructure layer and customer layers, but in completely separate contexts or perspectives. In a shared control, AWS provides the requirements for the infrastructure and the customer must provide their own control implementation within their use of AWS services. Examples include:

Patch Management – AWS is responsible for patching and fixing flaws within the infrastructure, but customers are responsible for patching their guest OS and applications.
Configuration Management – AWS maintains the configuration of its infrastructure devices, but a customer is responsible for configuring their own guest operating systems, databases, and applications.

71
Q
  1. Which AWS service allows companies to connect an Amazon VPC to an on-premises data center?

A. AWS VPN
B. Amazon Redshift
C. API Gateway
D. Amazon Connect

A

D. Amazon Connect

AWS Direct Connect enables you to securely connect your AWS environment to your on-premises data center or office location over a standard 1 gigabit or 10 gigabit Ethernet fiber-optic connection. AWS Direct Connect offers dedicated high speed, low latency connection, which bypasses internet service providers in your network path. An AWS Direct Connect location provides access to Amazon Web Services in the region it is associated with, as well as access to other US regions. AWS Direct Connect allows you to logically partition the fiber-optic connections into multiple logical connections called Virtual Local Area Networks
(VLAN). You can take advantage of these logical connections to improve security, differentiate traffic, and achieve compliance requirements.

72
Q
  1. A company wants to reduce the physical compute footprint that developers use to run code.
    Which service would meet that need by enabling serverless architectures?

A. Amazon Elastic Compute Cloud (Amazon EC2)
B. AWS Lambda
C. Amazon DynamoDB
D. AWS CodeCommit

A

B. AWS Lambda

AWS Lambda is an integral part of coding on AWS. It reduces physical compute footprint by utilizing aws cloud services to run code.

73
Q
  1. Which AWS service provides alerts when an AWS event may impact a companys AWS resources?

A. AWS Personal Health Dashboard
B. AWS Service Health Dashboard
C. AWS Trusted Advisor
D. AWS Infrastructure Event Management

A

A. AWS Personal Health Dashboard

AWS Personal Health Dashboard provides alerts and remediation guidance when AWS is experiencing events that may impact you. While the Service Health
Dashboard displays the general status of AWS services, Personal Health Dashboard gives you a personalized view into the performance and availability of the
AWS services underlying your AWS resources.

74
Q
  1. Which of the following are categories of AWS Trusted Advisor? (Choose two.)
A. Fault Tolerance
B. Instance Usage
C. Infrastructure
D. Performance
E. Storage Capacity
A

A. Fault Tolerance
D. Performance

Like your customized cloud expert, AWS Trusted Advisor analyzes your AWS environment and provides best practice recommendations in five categories: cost optimization, performance, security, fault tolerance and service limits.

75
Q
  1. Which task is AWS responsible for in the shared responsibility model for security and compliance?

A. Granting access to individuals and services
B. Encrypting data in transit
C. Updating Amazon EC2 host firmware
D. Updating operating systems

A

C. Updating Amazon EC2 host firmware

AWS Compliance enables customers to establish and operate in an AWS security control environment
✑ The shared responsibility model is part of AWS Compliance program
✑ The Security of the cloud is managed by Amazon AWS provider
✑ The Security in the cloud is responsibility of the customer
✑ The customer is responsible for their information and data, their secure transmission, integrity, and encryption
✑ Also, the customer is responsible for managing, support, patching and control of the guest operating system and AWS services provided like EC2
✑ AWS customers retain control and ownership of their data
✑ The AWS network provides significant protection against traditional network security issues and the customer can implement further protection

76
Q
  1. Where should a company go to search software listings from independent software vendors to find, test, buy and deploy software that runs on AWS?

A. AWS Marketplace
B. Amazon Lumberyard
C. AWS Artifact
D. Amazon CloudSearch

A

A. AWS Marketplace

AWS Marketplace is a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on AWS.

77
Q
  1. Which of the following is a benefit of using the AWS Cloud?

A. Permissive security removes the administrative burden.
B. Ability to focus on revenue-generating activities.
C. Control over cloud network hardware.
D. Choice of specific cloud hardware vendors.

A

B. Ability to focus on revenue-generating activities.

Amazon cloud infrastructure services, which make it easier to trial new business models, support revenue-generating applications, and provide more reliable services to end users.

78
Q
  1. When performing a cost analysis that supports physical isolation of a customer workload, which compute hosting model should be accounted for in the Total Cost of Ownership (TCO)?

A. Dedicated Hosts
B. Reserved Instances
C. On-Demand Instances
D. No Upfront Reserved Instances

A

A. Dedicated Hosts

se Dedicated Hosts to launch Amazon EC2 instances on physical servers that are dedicated for your use. Dedicated Hosts give you additional visibility and control over how instances are placed on a physical server, and you can reliably use the same physical server over time. As a result, Dedicated Hosts enable you to use your existing server-bound software licenses like Windows Server and address corporate compliance and regulatory requirements.

79
Q
  1. Which AWS service provides the ability to manage infrastructure as code?

A. AWS CodePipeline
B. AWS CodeDeploy
C. AWS Direct Connect
D. AWS CloudFormation

A

D. AWS CloudFormation

AWS CloudFormation provides a common language for you to describe and provision all the infrastructure resources in your cloud environment. CloudFormation allows you to use a simple text file to model and provision, in an automated and secure manner, all the resources needed for your applications across all regions and accounts. This file serves as the single source of truth for your cloud environment.

80
Q
  1. If a customer needs to audit the change management of AWS resources, which of the following AWS services should the customer use?

A. AWS Config
B. AWS Trusted Advisor
C. Amazon CloudWatch
D. Amazon Inspector

A

A. AWS Config
AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. Config continuously monitors and records your
AWS resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations. With Config, you can review changes in configurations and relationships between AWS resources, dive into detailed resource configuration histories, and determine your overall compliance against the configurations specified in your internal guidelines. This enables you to simplify compliance auditing, security analysis, change management, and operational troubleshooting.