Unsure 1 Flashcards
A company wants to have control over creating and using its own keys for encryption on AWS services. Which of the following can be used for this use-case?
Customer managed key (CMK)
AWS owned key
AWS managed key
Customer managed key (CMK)
What is a benefit of using AWS managed services such as Amazon Relational Database Service (Amazon RDS) over an on-premises DB?
Better performance
T/F - One way to protect data in your RDS DB is to use RDS read replica mode with automatic failover to the standby
False, you can only use automatic failover with Multi-AZ deployment
T/F - An advantage of AWS is to trade variable expense for capital expense
False
T/F - DynamoDB supports reservations
True
T/F - An advantage of AWS is to trade capital expense for variable expense
True
T/F - S3 supports reservations
False
T/F - A Network Address Translation gateway (NAT gateway) is managed by AWS
True
T/F - Security groups have allow and deny rules
False, they only have allow rules
Security groups act at the ________ level, not the ______ level
instance; subnet
T/F - NACLs have allow and deny rules
True
You can use an ______ ___ __ and ______ ______ ___ to access AWS resources programmatically
Access Key ID; Secret Access Key
T/F - AWS Shield Advanced provides expanded DDoS attack protection for web applications running on the Global Accelerator
True
AWS Shield Advanced provides expanded DDoS attack protection for web applications running on Beanstalk
False
AWS Shield Advanced provides expanded DDoS attack protection for web applications running on Route 53
True