Worksheets3 Day Combined
Total questions: 20
Worksheet time: 10mins
Name
Class
Date
1.
True or False: Storage, including S3, is automatically globally duplicated, so it never needs to be replicated across regions.
a)
true
b)
false
2.
The AWS Global Infrastructure is divided up geographically, and then subdivided to provide fault-tolerance and reliability of AWS services. Within each _ there are mutliple _.
a)
Region, Availability Zones
b)
Availability Zone, Regions
c)
Country, Availability Zones
d)
Country, Regions
e)
Local Zone, Regions
3.
In order to prevent the accidental permanent deletion of an object in an S3 bucket, you can turn on which of the following features?
a)
Item Duplication
b)
Automatic Backups
c)
Logging
d)
Versioning
e)
Encryption
4.
True or False: All services are available in every AWS Region.
a)
true
b)
false
5.
_ is a service that allows you to set up, operate, and scale a relational database in the cloud with just a few clicks.
a)
Amazon DynamoDB
b)
Amazon Neptune
c)
Amazon Relational Database Service (RDS)
d)
Amazon ElastiCache
6.
True or False: A VPC (Virtual Private Cloud) can exist across mutliple regions in AWS.
a)
true
b)
false
7.
Which of the following best describes AWS Direct Connect (DX)?
a)
Dedicated network connection over private lines
b)
Fast network connection over public lines and the open internet.
c)
Dedicated submarine communications cables, available to customers to speed up connections between countries.
d)
100Gbps fiber connections which run between customers' datacenters.
8.
True or False: VPCs natively support transitive peering.
a)
true
b)
false
9.
Network Access Control Lists (NACLs) are _, meaning you must specify both ingoing and outgoing rules independently. In other words, they do not keep track of ingoing and outgoing requests.
a)
Stateful
b)
Unsupported
c)
Obfuscated
d)
Stateless
e)
Serverless
10.
When creating a new IAM user, a user has which of the following access by default?
a)
Full Access
b)
No Access
c)
Admin Access
d)
Account Access
e)
Organizational Unit Access
11.
True or False: Bucket Policies and User Policies can be used together for more restrictive access and control.
a)
true
b)
false
12.
True or False: When creating a new AWS Account, it is best pratice for an Admin to use the root user as their personal account for any and all admin actions.
a)
true
b)
false
13.
Which of the following does NOT describe a feature of Amazon CloudWatch?
a)
Collects metrics on your resources
b)
Records all API calls made in your account and saves the logs
14.
True or False: EC2 Auto Scaling works across Availability Zones.
a)
true
b)
false
15.
Which is not a feature of AWS CloudFormation?
a)
Describes your infrastructure as code
b)
Write templates in JSON
c)
Allows you to update your infrastructure once it has been deployed
d)
Provides an faster manual intervention for production environments
e)
Version Control
16.
When defining access for users, groups, and roles in IAM, it's best to follow the principle of:
a)
Least-privilege
b)
Maximum Control
c)
Max Privilege
d)
Greatest Consistency
e)
Least Latency
17.
A statement which ensures that principals cannot use any AWS actions or resources other than the specified table and bucket, is known as what?
a)
Implicit Allow
b)
Implicit Deny
c)
Explicit Allow
d)
Explicit Deny
18.
True or False: An explicit deny statement takes precedence over an allow statement
a)
true
b)
false
19.
Which of the following lets you define a set of permissions to access the resources that a user or service needs, and is assumed by the user?
a)
Federation
b)
IAM Roles
c)
KMS (Key Management Service)
d)
Private Keys
20.
A developer is considering options for fully managed authentication, authorization, and user management for web and mobile apps. Which service should she use?
a)
Amazon Aurora
b)
RDS (Relational Database Service)
c)
Amazon Cognito
d)
Amazon Sagemaker
e)
AS Trusted Advisor
100 %
