WorksheetsAWS Practitioner 12
Total questions: 48
Worksheet time: 12hrs 0mins
Name
Class
Date
1.
Which monitors performance in EC2
a)
CloudWatch
b)
CloudTrail
c)
both Answers
d)
neither answer
2.
Which audits API calls in the AWS platform
a)
CloudTrail
b)
CloudWatch
c)
both answers
d)
neither answer
3.
Cloud Trail is enabled
a)
per region
b)
globally
c)
.
d)
.
4.
For cloudtrail in an organization, cloudtrail in all the accounts write logs to the paying account's S3 bucket
a)
true
b)
false
c)
.
d)
.
5.
Which is a valid AWS Organization?
a)
both answers
b)
Neither anser
c)
Consolidated Billing
d)
Full Access
6.
In AWS Organizations, by default you can link _- accounts
a)
20
b)
10
c)
5
d)
50
7.
With AWS Organizations, can one root account be added to another root account?
a)
No
b)
Yes
c)
Maybe
d)
Only on Thursdays
8.
__ uses CloudFormation templates built by AWS Solution Architects
a)
quick start
b)
lambda
c)
consolidated billing
d)
DynamoDB
9.
AWS Landing Zone starts with __ accounts by default
a)
4
b)
2
c)
12
d)
8
10.
Which is am AWS calculator
a)
Both Answers
b)
Neither Answer
c)
Simple Monthly Calculator
d)
Total Cost of Ownership Calculator
11.
To compare on prem costs versus cloud costs, you would use
a)
Total Cost of Ownership
b)
Simply Monthly Calculator
c)
Consolidated Billing
d)
Cost Explorer
12.
You need to present a report to your CTO on the cloud savings. Which would be best to use?
a)
Total Cost of Ownership
b)
Simply Monthly Calculator
c)
Consolidated Billing
d)
Cost Explorer
13.
It addition to server costs, the Total Cost of Ownership calculator considers whch
a)
all of these
b)
Storage Costs
c)
Network Costs
d)
IT Labor Costs
14.
You need to stop all the EC2 instances in Stokholm region. What would you use?
a)
System Manager
b)
cloud trail
c)
Cloud Formation
d)
Elastic Beanstalk
15.
In AWS Organizations, it is OK to install resources into the billing root account
a)
false
b)
true
c)
.
d)
.
16.
The landing zone comes with a security account and what else
a)
all of these
b)
Org Account
c)
Shared Services Account
d)
Log Archive Account
17.
AWS manages security __ cloud, customers manage __ cloud
a)
of the, in the
b)
in the, of the
c)
in the, out of the
d)
out of the, in the
18.
Which of the following are customers responsible for securing
a)
all of these
b)
content
c)
applications
d)
platforms
19.
Who is responsible for security networks in AWS
a)
Customers
b)
Amazon
c)
.
d)
.
20.
AWS is responsible for securing which of the following
a)
all of these
b)
Regions
c)
Availability Zones
d)
Edge Locations
21.
Who is responsible for securing the AWS account databases
a)
Amazon
b)
Customers
c)
.
d)
.
22.
Who is responsible for securing the operating system of RDS
a)
Amazon
b)
Customers
c)
.
d)
.
23.
Who is responsible for securing the operating systems in EC2
a)
Customers
b)
Amazon
c)
.
d)
.
24.
Who is responsible for securing Security Groups?
a)
Customers
b)
Amazon
c)
.
d)
.
25.
__ is responsible for the S3 encription and __ is responsible for turning the encryption on
a)
Amazon, Customers
b)
Customer, Amazon
c)
Amazon, Amazon
d)
Customers, Customers
26.
For encrption, you are providing you own key. Who is responsible for the encryption?
a)
Customers
b)
Amazon
c)
.
d)
.
27.
This protects you from DDOS attacks
a)
AWS Shield
b)
WAF
c)
Cloud Formation
d)
AWS Firewall Manager
28.
Cost Protection is provided by
a)
AWS Shield Advanced
b)
AWS Shield Basic
c)
.
d)
.
29.
AWS Shield Advance is __ per month
a)
3000
b)
100
c)
10
d)
30
30.
You want to monitor the performance of the CPU in EC2. What would you use?
a)
CloudWatch
b)
AWS Config
c)
AWS Inspector
d)
AWS Trusted Advisor
31.
You would like to compare the configuration of two Wordpress sites in your AWS
a)
AWS Config
b)
CloudWatch
c)
AWS Inspector
d)
AWS Trusted Advisor
32.
You can queuery data in S3 using standard SQL
a)
Athena
b)
Macie
c)
AWS Config
d)
CloudWatch
33.
Security Service uses Machine Learning and LMP to discover, classify, and protect data stored in S3
a)
Macie
b)
Athena
c)
AWS Config
d)
CloudWatch
34.
You want to identify all the traffic across a VPC from the logs
a)
Athena
b)
Macie
c)
AWS Config
d)
CloudWatch
35.
You would like to analyze click-stream data. Which would you use
a)
Athena
b)
Macie
c)
AWS Config
d)
CloudWatch
36.
What protects against identiy fraud in AWS
a)
Macie
b)
Athena
c)
AWS Config
d)
CloudWatch
37.
This is used to retrieve compliance reports
a)
AWS Artifact
b)
Athena
c)
Macie
d)
CloudWatch
38.
AWS Shield is/is not turned on by default
a)
is
b)
is not
c)
.
d)
.
39.
You need to assess the security and compliance of your EC2 instances.
a)
AWS Inspector
b)
AWS Trusted Advisor
c)
AWS Config
d)
Athena
40.
T/F The standard version of AWS Shield offers automated application (layer 7) traffic monitoring
a)
false
b)
true
c)
.
d)
.
41.
Which service can help you assess the fault-tolerance of your AWS environmrent
a)
AWS Inspector
b)
AWS Trusted Advisor
c)
AWS Config
d)
Athena
42.
Which is NOT a feature of AWS Organizations
a)
Granualar config of security groups within a VPC
b)
Grouping all AWS accounts into Org Units (OU) as part of a hierachy
c)
Hierachicial based control over groups of IAM users and roles within multiple accounts
d)
AWS accounts in the org can have consolidated billing
43.
Which of the following AWS servies should you use to migrate an existing database to AWS
a)
DMS
b)
Storage Gateway
c)
SNS
d)
Route 53
44.
DMS is the Database Migration Service
a)
true
b)
false
c)
.
d)
.
45.
Which native AWS service will act as a file system mounted on an S3 bucket
a)
Storage Gateway
b)
Elastic File System
c)
S3
d)
Elastic Block Store
46.
Which allows you to run code without worry about underlying resources
a)
Lambda
b)
EC2 Container Service
c)
Dynamo DB
d)
EC2
47.
Under shared responsibilty, which is AWS NOT responsible for?
a)
Customer Data
b)
Networking
c)
Hypervisors
d)
Physical security of AWS Facilities
48.
The Elastic File System (EFS) mounts to
a)
EC2
b)
S3
c)
both answers
d)
neither answer
100 %
