AISS - AWS SA - AWS_Pillars

AISS - AWS SA - AWS_Pillars

KG - Professional Development

64 Qs

quiz-placeholder

Similar activities

Fun Ride

Fun Ride

University

65 Qs

Industrial Engineering

Industrial Engineering

University

60 Qs

Output devices and their uses

Output devices and their uses

9th - 11th Grade

60 Qs

HUT PERTAMINA 64 - FT. Tanjung Gerem

HUT PERTAMINA 64 - FT. Tanjung Gerem

5th Grade

64 Qs

APT STAAR Game

APT STAAR Game

6th - 10th Grade

69 Qs

papasa sa quiz ng earth science

papasa sa quiz ng earth science

11th Grade

61 Qs

ENTREP FINAL EXAM

ENTREP FINAL EXAM

University

62 Qs

mcyt(and other yt) god au

mcyt(and other yt) god au

7th Grade - Professional Development

68 Qs

AISS - AWS SA - AWS_Pillars

AISS - AWS SA - AWS_Pillars

Assessment

Quiz

Other

KG - Professional Development

Medium

Created by

Ian Banaag

Used 44+ times

FREE Resource

AI

Enhance your content in a minute

Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...

64 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

5 mins • 1 pt

(from linux academy - Operation Exellence Pillar)

You business operates in a very secure sensitive industry. You are looking at how to secure a small VPC. Your environment consists of a single S3 bucket, and an EC2 instance running in a internet connected VPC. What is the best way to lock down the environment, allowing access to S3 but keeping the environment as secure as possible?

Create an S3 VPC endpoint. Apply a policy restricting access to the S3 bucket from the VPC endpoint.

Create an S3 VPC endpoint. Apply a policy restricting access to the S3 bucket from the VPC endpoint, and remove the internet gateway. Setup a VPN Endpoint and client to securely SSH into the EC2 instance when needed.

Provision a privately addressable S3 bucket in your VPC. Migrate the contents of the public bucket and update the application. Remove the internet gateway to isolate the VPC.

Create a new security group, denying all IP's except the EC2 instance, and associate it with the S3 bucket.

2.

MULTIPLE CHOICE QUESTION

3 mins • 1 pt

(from linux academy - Operation Exellence Pillar)

Your existing custom NACL currently allows all Internet web traffic into the subnet. As part of a project implementation, you need to block IP traffic from a subnet to a specific internet IP address. How can this be accomplished?

Create a Security group, add a DENY rule to it, and attach to the subnet.

Attach a NACL to the subnet and add a DENY rule to it.

Attach a NACL to the VPC and add a DENY rule.

Create a Security group, add a DENY rule, and attach it to any resources in the subnet which need the DENY rule applied.

3.

MULTIPLE SELECT QUESTION

1 min • 1 pt

(from linux academy - Operation Exellence Pillar)

Which of the following events can be logged using CloudTrail. (Choose all that apply)

CLI Calls to the AWS Account

API Calls to the AWS Account

SSH Connections to EC2 Instances

Operations on S3 Objects

4.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

(from linux academy - Operation Exellence Pillar)

You need to migrate a legacy application into AWS. It currently runs on a Linux operating system and has a requirement for iSCSI based block storage. Which AWS Service would you utilise to meet this requirement?

EFS

S3

Storage Gateway

EBS

5.

MULTIPLE SELECT QUESTION

1 min • 1 pt

(from linux academy - Operation Exellence Pillar)

Which of the following are AWS managed services that can allow host access to instances running on the respective services? (Choose all that apply)

DynamoDB

Amazon EC2

Amazon RDS

Amazon EMR

ElastiCache

6.

MULTIPLE CHOICE QUESTION

3 mins • 1 pt

(from linux academy - Operation Exellence Pillar)

You are designing a VPC to host a small application. The VPC will be connected back to your on-premises network using a VPN. An EC2 instance runs the application, and will only need to connect to the internet for software updates. You have a list of the software update DNS names. How can you restrict this within the AWS VPC?

Place the EC2 instance in a public subnet and add an internet gateway.

This restriction isn't possible using an AWS VPC.

Add an internet gateway to the VPC, and a proxy service running on a EC2 instance in a public subnet with an elastic IP.

Use the DNS filtering option on a NAT gateway to restrict internet access to just the software updates.

7.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

(from linux academy - Operation Exellence Pillar)

You've been asked to host a docker container within your AWS environment. What is the most appropriate product to use for this task?

Lambda

EC2

Opsworks

ECS

Create a free account and access millions of resources

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

By signing up, you agree to our Terms of Service & Privacy Policy

Already have an account?