Untitled Quiz

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson
Download our mobile app to listen on the go
Get App

Questions and Answers

What is the most cost-effective method to host a website that contains HTML, CSS, client-side JavaScript, and images?

  • Containerize the website and host it in AWS Fargate.
  • Configure an Application Load Balancer with an AWS Lambda target that uses the Express.js framework.
  • Deploy a web server on an Amazon EC2 instance to host the website.
  • Create an Amazon S3 bucket and host the website there. (correct)

Which AWS service can be used to periodically run API calls for checking resource tag allocations?

  • Amazon S3
  • Amazon CloudWatch (correct)
  • Amazon EC2
  • AWS CodePipeline

What is the best solution for sharing millions of financial transactions while ensuring sensitive data is removed before storage?

  • Stream the transactions data into Amazon Kinesis Data Firehose and use Lambda.
  • Store batched transactions data in Amazon S3 and process with AWS Lambda.
  • Stream the transactions data into Amazon Kinesis Data Streams and use AWS Lambda. (correct)
  • Store the transactions data into Amazon DynamoDB and use DynamoDB Streams.

Which service is NOT suitable for hosting a static website made up of HTML, CSS, and images?

<p>AWS Lambda (A)</p> Signup and view all the answers

When processing financial transactions for sensitive data, which AWS service combination is most efficient?

<p>Amazon Kinesis Data Streams with Lambda and DynamoDB. (D)</p> Signup and view all the answers

Which method will NOT effectively enable the removal of sensitive data during transaction processing?

<p>Directly writing to Amazon S3. (D)</p> Signup and view all the answers

Which of the following is a key advantage of using Amazon S3 for hosting a website over an EC2 instance?

<p>Simplified deployment with no server management. (C)</p> Signup and view all the answers

What is a requirement for the solution architect regarding the marketplace web application?

<p>Transactions need to be processed for real-time latency. (C)</p> Signup and view all the answers

Which solution allows secure remote access to EC2 instances with the least operational overhead?

<p>Attach an IAM role and use AWS Systems Manager Session Manager for SSH access. (A)</p> Signup and view all the answers

To reduce latency for users accessing a static website hosted on S3, which option is the most cost-effective?

<p>Add an Amazon CloudFront distribution in front of the bucket. (B)</p> Signup and view all the answers

What is the primary purpose of configuring server-side encryption with AWS KMS keys for S3 buckets?

<p>To enhance data security by encrypting content at rest. (C)</p> Signup and view all the answers

When maintaining a searchable repository in Amazon RDS for MySQL, what is important for managing over 10 million rows effectively?

<p>Partitioning the database to simplify data retrieval. (A)</p> Signup and view all the answers

What must be configured to allow cross-region replication for S3 buckets?

<p>Enable versioning on the source and destination buckets. (B)</p> Signup and view all the answers

Which approach for SSH access to EC2 instances involves higher management overhead?

<p>Deploying a bastion host for secure access through a public subnet. (C)</p> Signup and view all the answers

Which solution is NOT a valid way to improve the performance of an S3-hosted static website?

<p>Use Elastic Load Balancing to distribute traffic to the S3 bucket. (D)</p> Signup and view all the answers

Which AWS service provides an efficient way to manage application secrets in a secure manner?

<p>AWS Secrets Manager. (D)</p> Signup and view all the answers

What is the primary benefit of using AWS Secrets Manager for credential rotation in this scenario?

<p>It provides secure storage and automatic rotation of secrets. (A)</p> Signup and view all the answers

Which option correctly utilizes multi-Region capabilities for credential management?

<p>Using multi-Region secret replication in AWS Secrets Manager. (D)</p> Signup and view all the answers

What is the first step needed to share dashboard access with the product manager?

<p>Create an IAM user for the company's employees. (A)</p> Signup and view all the answers

How does using Amazon Aurora with Multi-AZ deployment ensure high availability?

<p>By automatically failing over to a standby instance if the primary fails. (A)</p> Signup and view all the answers

What action should the product manager take to access the CloudWatch dashboard after receiving the login credentials?

<p>Locate the dashboard by name in the Dashboards section. (D)</p> Signup and view all the answers

What kind of scaling is necessary for the e-commerce application's database based on its workload?

<p>Read scaling to accommodate an increase in read requests. (B)</p> Signup and view all the answers

Which Amazon RDS configuration addresses both high availability and read workload demands effectively?

<p>Multi-AZ deployment with read replicas. (C)</p> Signup and view all the answers

Which trust relationship is required for connecting on-premises Microsoft Active Directory with AWS SSO to meet user management needs?

<p>A two-way forest trust. (C)</p> Signup and view all the answers

What AWS service can be used for a single sign-on solution while managing users in an on-premises directory?

<p>AWS Directory Service. (D)</p> Signup and view all the answers

What action is necessary to maintain the database performance amidst unpredictable workload changes?

<p>Automatically scale with Aurora Auto Scaling for read replicas. (A)</p> Signup and view all the answers

To achieve automated failover between Regions for a VoIP service, what is the recommended solution?

<p>Deploy a Network Load Balancer and use Global Accelerator. (B)</p> Signup and view all the answers

Why is utilizing Amazon ElastiCache for Memcached not an ideal solution for the database's performance issues?

<p>It does not improve the underlying database performance. (B)</p> Signup and view all the answers

Which Amazon service helps improve the caching of read-heavy workloads efficiently?

<p>Amazon ElastiCache for caching frequently accessed data. (C)</p> Signup and view all the answers

What is the main benefit of using AWS Organizations for managing multiple accounts?

<p>Centralized management of accounts and policies. (C)</p> Signup and view all the answers

When deploying a bastion server, what is critical to ensure regarding the browser on the server?

<p>It should use cached AWS credentials with appropriate permissions. (C)</p> Signup and view all the answers

Which component is essential for routing VoIP users to the Region with lowest latency?

<p>AWS Global Accelerator for optimizing performance. (A)</p> Signup and view all the answers

What is the primary purpose of using Amazon Macie in the context of file uploads containing PII?

<p>To scan and identify personally identifiable information (PII) in the uploaded files. (C)</p> Signup and view all the answers

Which option can automate the removal of files identified to contain PII with minimal development effort?

<p>Use Amazon Inspector for scanning and Amazon S3 Lifecycle policy for removal. (C)</p> Signup and view all the answers

What happens if an uploaded file is scanned and determined to contain PII when using Amazon Macie?

<p>Amazon SNS sends notifications to administrators to initiate manual removal. (C)</p> Signup and view all the answers

Which of the following tasks does not directly relate to the use of an Amazon S3 bucket as a secure transfer point?

<p>Triggering emails based on file content analysis. (C)</p> Signup and view all the answers

What is a key benefit of using Amazon S3 Lifecycle policies in managing files containing PII?

<p>They automate the deletion or transition of files based on predefined rules. (B)</p> Signup and view all the answers

What is the role of Amazon Inspector in the context described?

<p>To analyze the contents of each uploaded file for potential threats. (C)</p> Signup and view all the answers

Why might a company prefer using Amazon SNS for notifications rather than an email solution like Amazon SES?

<p>Amazon SNS can send notifications to multiple subscribers at once. (D)</p> Signup and view all the answers

What is the main function of an AWS Lambda function in the given scenario?

<p>Scanning uploaded files and triggering notifications as needed. (D)</p> Signup and view all the answers

What is the first step required when setting up an Auto Scaling group to manage nodes based on the number of items in an Amazon SQS queue?

<p>Create an Amazon SQS queue to hold the jobs. (A)</p> Signup and view all the answers

Which scaling policy is appropriate for an Auto Scaling group that is configured to use an Amazon SQS queue?

<p>Add and remove nodes based on the number of items in the SQS queue. (D)</p> Signup and view all the answers

How can the security team be notified about certificate expirations 30 days in advance?

<p>Use AWS Config along with EventBridge to monitor and alert on certificate expirations. (A)</p> Signup and view all the answers

What is a key step for an Auto Scaling group creation using a launch template?

<p>Create an Amazon Machine Image (AMI) first. (A)</p> Signup and view all the answers

Which AWS service is recommended to send alerts for expiring certificates 30 days before they expire?

<p>Amazon Simple Notification Service (SNS). (C)</p> Signup and view all the answers

What is NOT required when creating an Auto Scaling group using a launch template?

<p>An Amazon SNS topic for processing jobs. (A)</p> Signup and view all the answers

To improve the performance of a dynamic website for European users launched from the U.S., what technique could be effective?

<p>Use a global load balancer to distribute traffic. (C)</p> Signup and view all the answers

Which service should be configured to monitor certificates and alert on expiring ones?

<p>AWS Config. (D)</p> Signup and view all the answers

Flashcards

AWS Single Sign-On (SSO)

A solution allowing single sign-on across AWS accounts.

AWS Organizations

A service that lets you manage multiple AWS accounts as a group.

Microsoft Active Directory

A directory service that manages users and groups.

Two-way forest trust

Connects two separate Active Directory forests allowing users to authenticate in either forest.

Signup and view all the flashcards

Network Load Balancer (NLB)

Distributes traffic to multiple targets based on routing rules.

Signup and view all the flashcards

Target Group

A collection of resources (like EC2 instances), defining rules on how traffic should be routed to them

Signup and view all the flashcards

Auto Scaling Group

Manages a group of EC2 instances, dynamically adjusting the available capacity based on demand.

Signup and view all the flashcards

Global Accelerator

A service that can improve the performance of applications by routing your users to the closest AWS Region.

Signup and view all the flashcards

AWS Secrets Manager for credential rotation

Storing credentials as secrets in AWS Secrets Manager, utilizing multi-region replication and scheduled rotation for efficient credential management.

Signup and view all the flashcards

Database performance degradation

A decrease in the speed or responsiveness of a database, often due to high volume of read requests and limitations of the database architecture, impacting application performance.

Signup and view all the flashcards

Scaling database read workloads

Automatically increasing the database's processing capacity to handle a surging number of read requests without impacting the availability and performance of the database.

Signup and view all the flashcards

Amazon Aurora Auto Scaling with Aurora Replicas

Utilizing Amazon Aurora's automatic scaling of read replicas to handle increasing read requests, maintaining high availability and performance.

Signup and view all the flashcards

Multi-AZ Deployment

A database deployment approach that ensures high availability by replicating the database across multiple Availability Zones.

Signup and view all the flashcards

Amazon Aurora

A fully managed, MySQL and PostgreSQL-compatible database service that offers high availability and scalability.

Signup and view all the flashcards

Amazon RDS

A fully managed relational database service that allows for high availability and ease of management.

Signup and view all the flashcards

Application Load Balancer

A load balancing service that distributes traffic across multiple Amazon EC2 instances behind it to improve application responsiveness and high availability

Signup and view all the flashcards

Amazon SQS Queue

A service for storing messages as they are received from applications, enabling decoupled communication and asynchronous processing.

Signup and view all the flashcards

SNS Topic

A publish/subscribe messaging system used to distribute messages to multiple subscribers.

Signup and view all the flashcards

Lambda Function

A serverless compute service that allows running code without managing servers.

Signup and view all the flashcards

PII (Personally Identifiable Information)

Information that can be used to identify a specific individual.

Signup and view all the flashcards

SFTP

Secure File Transfer Protocol for transferring files securely over a network.

Signup and view all the flashcards

AWS Lambda function for PII detection

A method where custom scanning by a Lambda function detects PII in uploaded files.

Signup and view all the flashcards

Amazon Macie

A service for automatically classifying and protecting data, allowing for easy detection of PII.

Signup and view all the flashcards

Amazon S3 Bucket

A scalable storage service that is used to store files securely, which in this case, is a secure transfer point for files.

Signup and view all the flashcards

Cost-effective website hosting

Storing a website in an Amazon S3 bucket is the most cost-effective option for hosting a website with HTML, CSS, JavaScript, and images.

Signup and view all the flashcards

Scalable transaction data sharing

A near real-time solution that needs to share transaction details with other applications while removing sensitive data before storage.

Signup and view all the flashcards

High volume transactions

Transactions that need to be processed at a high rate (hundreds of thousands of users during peak hours).

Signup and view all the flashcards

Sensitive data removal

Removing sensitive data from transactions before storing them to meet compliance requirements.

Signup and view all the flashcards

Near-real time data sharing

A data sharing method with near real-time requirements for data updates.

Signup and view all the flashcards

API calls for tag allocation

Calls to verify the correct allocation of tags across all resources.

Signup and view all the flashcards

AWS Lambda Function Scheduling

Scheduling AWS Lambda functions for periodic executions using CloudWatch.

Signup and view all the flashcards

Document database retrieval

Storing pre-processed transaction data in a document database for low-latency retrieval.

Signup and view all the flashcards

Remote EC2 Instance Administration

A repeatable method to access and manage EC2 instances securely and with least operational overhead.

Signup and view all the flashcards

Static website latency

Reducing the time it takes for users around the world to access a static website hosted on S3 and routed via Route 53.

Signup and view all the flashcards

S3 Bucket Replication

Creating multiple copies of an S3 bucket in various AWS regions for faster access by users.

Signup and view all the flashcards

S3 Transfer Acceleration

A service accelerating data transfer between S3 and clients.

Signup and view all the flashcards

AWS KMS SSE Encryption

Server-side encryption of S3 buckets using keys managed by AWS Key Management Service (KMS).

Signup and view all the flashcards

IAM role for EC2 instance

Security credentials attached to an EC2 instance to define permissions and access control.

Signup and view all the flashcards

Scalable Database

Databases that can handle growing amounts of data, as needed.

Signup and view all the flashcards

CloudFront Distribution

A content delivery network service used to deliver static content, such as websites, more quickly to end users.

Signup and view all the flashcards

Scaling policy

Set of rules for Auto Scaling to decide when to add or remove instances.

Signup and view all the flashcards

Amazon Machine Image (AMI)

A template of an operating system with applications preinstalled.

Signup and view all the flashcards

Launch Template

Allows you to define the settings for EC2 instances to use for launching instances while using the same configurations, in order to ensure uniformity.

Signup and view all the flashcards

AWS Certificate Manager (ACM)

Manages TLS/SSL certificates used to secure web traffic.

Signup and view all the flashcards

Amazon Simple Notification Service (Amazon SNS)

Publishes messages to multiple subscribers. A messaging service used for notifications across different systems.

Signup and view all the flashcards

AWS Config

A service to record changes made to AWS resources.

Signup and view all the flashcards

Study Notes

AWS Solutions for Various Use Cases

  • Credential Rotation (Question #13): Store credentials as secrets in AWS Secrets Manager, utilize multi-region secret replication, and configure Secrets Manager for scheduled rotation. This method minimizes operational overhead.

  • Database Scaling (Question #14): Use Amazon Aurora with Multi-AZ deployment and Aurora Auto Scaling with Aurora Replicas for automatic scaling of read workloads and high availability.

  • Product Manager Access (Question #27): Create an IAM user with the ViewOnlyAccess managed policy, share login credentials, and direct the product manager to locate the CloudWatch dashboard by name.

  • SSO Across Accounts (Question #28): Use AWS Single Sign-On (AWS SSO) and create a one-way forest trust or a one-way domain trust to connect the on-premises Microsoft Active Directory with AWS SSO using AWS Directory Service for Microsoft Active Directory.

  • VoIP Service with Failover (Question #29): Deploy a Network Load Balancer (NLB) with an associated target group, associating the target group with the Auto Scaling group, and employing the NLB as an AWS Global Accelerator endpoint in each region. This provides low latency routing and automated failover to the region with the lowest latency.

  • Least Cost Effective Website Hosting (Question #32): Hosting a static website in an Amazon S3 bucket is the most cost-effective method.

  • Scalable Transaction Processing (Question #33): Stream transactions to Amazon Kinesis Data Firehose, storing data in Amazon DynamoDB and S3, and use Lambda integration with Kinesis Data Firehose to remove sensitive data. This lets other applications consume the data stored in Amazon S3.

  • Remote Instance Administration (Question #37): Utilize AWS Systems Manager Session Manager to create an SSH session; this method adheres to the AWS Well-Architected Framework and minimizes operational overhead

  • Static Website Latency Optimization (Question #38): Deploy an Amazon CloudFront distribution in front of the S3 bucket. This solution addresses latency issues and optimizes cost-effectively.

  • Searchable Repository (Question #39): To improve the performance of a repository with 10 million rows and 2 TB of data in an Amazon RDS for MySQL database, consider additional actions like indexing, query optimization, or using a more appropriate database for analytical purposes. This question lacks a clearly optimal solution.

  • PII Detection and Remediation (Question #46): Use Amazon Macie to scan objects in an Amazon S3 bucket for personally identifiable information (PII). If PII is detected, Amazon SNS triggers a notification and directs administrators to remove the data or implement further remediation steps.

  • Scalable Job Processing (Question #81): Utilize an Amazon SQS queue to hold jobs that need processing. Using an Auto Scaling group scales based on the queue length.

  • Certificate Expiration Notifications (Question #82): Configure an Amazon EventBridge (Amazon CloudWatch Events) rule that detects certificates expiring in 30 days. This rule invokes an AWS Lambda function, sending a notification via Amazon Simple Notification Service (Amazon SNS).

Key Concepts for AWS Solutions

  • IAM Roles: Attaching appropriate IAM roles to instances for secure administration.
  • Secrets Manager: Securely storing and managing sensitive credentials.
  • Multi-AZ Deployments: Enhanced availability via multiple Availability Zones.
  • Scalability: Architecting for increasing workloads, such as with Auto Scaling.
  • Monitoring: Utilizing services for collecting and analyzing data (e.g., CloudWatch).
  • Security: Procedures for protecting sensitive data (e.g., encryption of data).
  • Cost optimization: Strategies to make the system cost-effective and efficient.
  • High Availability: Setting up systems to continue functioning even with failures.
  • Fault tolerance: Restoring a failing system, ensuring business continuity.

Studying That Suits You

Use AI to generate personalized quizzes and flashcards to suit your learning preferences.

Quiz Team

Related Documents

More Like This

Untitled Quiz
37 questions

Untitled Quiz

WellReceivedSquirrel7948 avatar
WellReceivedSquirrel7948
Untitled Quiz
18 questions

Untitled Quiz

RighteousIguana avatar
RighteousIguana
Untitled Quiz
50 questions

Untitled Quiz

JoyousSulfur avatar
JoyousSulfur
Untitled Quiz
48 questions

Untitled Quiz

StraightforwardStatueOfLiberty avatar
StraightforwardStatueOfLiberty
Use Quizgecko on...
Browser
Browser