Font size
WorksheetsSC-01.3
Total questions: 50
Worksheet time: 38mins
You are a Senior Solutions Architect in a world-renowned logistics company in which you handle the entire security of their global enterprise e- commerce platform. They built a multi-tier web application running in a VPC that uses an Elastic Load Balancer in front of both the web tier and the app tier, with static assets served directly from an Amazon S3 bucket. They use a combination of Amazon RDS and DynamoDB for their dynamic data and then archiving nightly into an Amazon S3 bucket for further processing with Amazon Elastic MapReduce.
After a routine audit, they found questionable log entries and suspected that someone is attempting to gain unauthorized access to the system. You must improve the security of your architecture from DDoS, SQL injection, and HTTP flood attacks as well as from bad bots (content scrapers).
Which approach provides the MOST suitable and scalable solution to protect your architecture from these kinds of security attacks?
Establish an AWS Direct Connect (DX) connection to the VPC through a Direct Connect partner. Configure Internet connectivity to filter the traffic in hardware Web Application Firewall (WAF) and then reroute the traffic through the DX connection into the application. Use the company's wide area network (WAN) to send traffic over the DX connection
Set up AWS WAF and AWS Shield Advanced on all web endpoints. Launch AWS WAF rules against SQL injection and other common web exploits
Insert the identified suspect's source IP as an explicit inbound deny to the network ACL rules of the web tier's subnet. Set up AWS Config to periodically audit the network ACLs and ensure that the blacklisted IP addresses are always in place
Create an identical application stack that acts as a standby environment in another AWS region by using an AWS CloudFormation template. Use AWS CloudFormation StackSets to deploy the new stack and configure the security groups as well as network ACLs of the EC2 instances. Use Amazon Macie to protect the data stored in the Amazon S3 bucket. Create a Route 53 failover routing policy and configure an active- passive failover
A company has a CRM application that uses a MySQL database hosted in Amazon RDS, and a central data warehouse that runs on Amazon Redshift. There is a batch analytics process that runs every day that reads data from RDS. During the execution of the batch analytics, the RDS utilization spikes up, which results in the CRM application being unresponsive. The top management dashboard must also be updated with new data right after the batch analytics processing completes.
However, the dashboard is on another system running on-premises and cannot be modified directly. The only way to update the dashboard is to send an email with the new data to the dashboard system via SMTP, which will then be parsed and processed to update the dashboard with the latest data.
How would you optimize this scenario to solve performance issues and automate the process as much as possible?
Add read replicas for the RDS database to speed up batch analytics and use Amazon SNS to notify the on-premises system to update the dashboard
Add read replicas for the RDS database to speed up batch analytics and use Amazon SQS to notify the on-premises system to update the dashboard
Consider using Amazon Redshift instead of Amazon RDS as the database for the CRM application. Use Amazon SQS to notify the on- premises system to update the dashboard
Consider using Amazon Redshift as the main OLTP transactional database instead of RDS for the batch analytics and use Redshift Spectrum to run SQL queries directly against Exabytes of structured or unstructured data in S3 without the need for unnecessary data movement. Utilize Amazon SNS to notify the on-premises system to update the dashboard
A leading telecommunications company is moving all their mission-critical, multi-tier applications to AWS. At present, their architecture is composed of desktop client applications and several servers that are all located in their on-premises data center. The application-tier is using a MySQL database which is hosted on a single VM while both the presentation and business logic layers are distributed across multiple VMs.
There has been a lot of reports that their users, who access the applications remotely, are experiencing increased connection latency and slow load times.
Which of the following is the MOST cost-effective solution to improve the uptime of the application with MINIMAL change and improve the overall user experience?
Set up a new CloudFront web distribution to improve the overall user experience of your desktop applications. Migrate the MySQL database from your VM to a Redshift cluster. Host the application and presentation layers in ECS containers behind a Network Load Balancer
Use Amazon ElastiCache to improve the overall user experience of your desktop applications. Directly migrate the MySQL database from your VM to a DynamoDB database. Host the application and presentation layers in AWS Fargate containers behind an Application Load Balancer
Use Amazon AppStream 2.0 to centrally manage your desktop applications and improve the overall user experience. Migrate the MySQL database from your VM to Amazon Aurora. Host the application and presentation layers in an Auto Scaling group on EC2 instances behind an Application Load Balancer
Using Amazon WorkSpaces, set up and allocate a workspace for each user to improve the overall user experience. Migrate the MySQL database from your VM to a self-hosted MySQL database in a large EC2 instance. Host the application and presentation layers in Amazon ECS containers behind an Application Load Balancer
An online sports betting company has multiple web applications hosted in their VPC. The security team has discovered multiple port scans which are coming in from a specific IP address block. To protect confidential and financial data hosted in your AWS Cloud, the offending IP addresses must be denied access to the network as soon as possible.
Which of the following is the best method to accomplish this task?
Modify the firewall settings of the EC2 instances to deny access from the IP address block
Add a rule to all the Security Groups to deny access from the IP Address block
Modify the IAM policy of each EC2 instance to deny access from the offending IP address block
Set the Network ACLs associated with all public subnets in the VPC to deny access from the offending IP address block
A company has several financial applications hosted in AWS that uses
Amazon S3 buckets to store static data. The Solutions Architect recently discovered that some employees store highly classified data into S3 buckets without proper approval. To mitigate any security risks, the Architect needs to determine all possible S3 objects that contain personally identifiable information (PII) and determine whether the data has been accessed.
Due to the sheer volume of data, the Architect must implement an automated solution to accomplish this important task.
Which of the following should the Architect do in this situation?
Enable Amazon Macie on the S3 buckets to automatically classify the data and detect any objects with personally identifiable information (PII). Determine if the objects with PII have been recently accessed by tracking the GET API calls in AWS CloudTrail
Use Amazon GuardDuty to detect personally identifiable information (PII) on the Amazon S3 buckets. Determine if the objects with PII have been recently accessed by tracking the GET API calls in AWS CloudTrail that are used to download these objects
Install the Amazon Inspector agent on the Amazon S3 buckets. Use AWS CloudTrail to determine if the objects with personally identifiable information (PII) have been recently accessed by tracking the GET API calls that are used to fetch these objects
Detect personally identifiable information (PII) on the specific S3 buckets using Amazon Athena. Set up Amazon CloudWatch to determine if the objects with PII have been recently accessed by tracking the GET API calls that are used to download these objects
A multinational manufacturing company has multiple AWS accounts in multiple AWS regions across North America, Europe, and Asia. You were instructed to set up AWS Organizations to centrally manage policies and have full administrative control across the multiple AWS accounts of the company, without requiring custom scripts and manual processes.
As the Solutions Architect, how can you achieve this requirement with the LEAST effort?
Set up AWS Organizations by sending an invitation to all member accounts of the company from the master account of your organization. Create an OrganizationAccountAccessRole IAM role in the member account and grant permission to the master account to assume the role
Set up AWS Organizations by sending an invitation to the master account of your organization from each of the member accounts of the company. Create an OrganizationAccountAccessRole IAM role in the member account and grant permission to the master account to assume the role
Set up AWS Organizations by establishing cross-account access from the master account to all member AWS accounts of the company. The master account will automatically have full administrative control across all member accounts
Set up AWS Organizations by enabling trusted access to all member AWS accounts of the company. The master account will automatically have full administrative control across all member accounts
A leading aerospace engineering company is experiencing high growth and demand on their highly available and fault-tolerant cloud services platform that is hosted in AWS. The technical lead of your team has asked you to virtually extend two existing on-premises data centers into AWS cloud to support an online flight-tracking service which is used by a lot of airline companies. The online service heavily depends on existing, on-premises resources located in multiple data centers and static content that is served from an S3 bucket.
To meet the requirement, you launched a dual-tunnel VPN connection between your CGW and VGW. In this scenario, which component of your cloud architecture represents a potential single point of failure, which you should consider changing to make the solution more highly available?
Set up a NAT Gateway in a different data center and set up another dual-tunnel VPN connection
Create another Customer Gateway in a different data center and set up another dual-tunnel VPN connection
Create another Virtual Gateway in a different AZ and create another dual-tunnel VPN connection
Create a second Virtual Gateway in a different AZ and a Customer Gateway in a different data center. Create another dual-tunnel connection to ensure high-availability and fault-tolerance
You have multiple database servers hosted on extra-large Reserved EC2 instances which are all deployed to a private subnet. A single NAT instance is in place to allow the servers to fetch data from the Internet. You noticed that whenever there is a new database patch update, the processing takes a lot of time which results in request time-outs. As a workaround, you just manually re-run the database patch update on the servers that failed to complete the process the first time.
What could be the possible root cause of the issue and what steps will you take to solve it?
There is no Virtual Private Gateway attached to the VPC that links up to the Customer Gateway of the database provider. Simply add the missing gateway and the issue will be resolved
The timeout behavior of a NAT instance is that, when there is a connection time out, it sends a FIN packet to resources behind the NAT instance to close the connection. It does not attempt to continue the connection which is why some database updates are failing. For better performance, use a NAT Gateway instead
There is no Internet Gateway (IGW) attached to the VPC. Simply add an IGW and the issue will be resolved
The database servers are not in a Placement Group, which means that the inter-instance communications are not optimal. This is causing the timeout issue. Place all the database servers on either a Spread or a Cluster type Placement group to fix the problem
You are the Lead Solutions Architect for an online booking system hosted on a dedicated EC2 instance. You are implementing a caching system, so you set the EC2 web server as the origin of CloudFront. The system must be able to handle both HTTP and HTTPS connection requests from a client.
What should be the Origin Protocol policy that must be configured to ensure that communication with the origin is done via HTTP or HTTPS?
Match Viewer
None of the above
HTTP
HTTPS
A national library is planning to store around 50 TB of data containing all their books, articles and other written materials in AWS. One of the requirements is to have a search feature to enable the users to look for their collection on their dynamic website.
As a Cloud Engineer, what is the most suitable solution that you should implement in AWS to satisfy the needed functionality?
Use Elastic Beanstalk as the deployment service. Deploy the needed AWS resources such as the Multi-AZ RDS for storage and an EC2 instance to host their website
Use CloudFormation as the deployment service to deploy the needed AWS resources such as an S3 bucket for storage; CloudSearch to provide the needed search functionality, and an EC2 instance to host their website
Use CodeDeploy as the deployment service to deploy two S3 buckets in which the first one serves as the storage service and the second one for hosting their dynamic website. Use the native search functionality of S3 to satisfy the search feature requirement
Use OpsWorks as the deployment service to deploy Kinesis as the storage service and an EC2 instance to serve their website
You are working as an IT Consultant for a FinTech startup based in Bonifacio Global City where you are tasked to properly set up an online analytical processing (OLAP) application. You have also launched and configured all the required AWS resources such as EC2, Security Groups, Redshift WLM Queues, S3, and IAM Roles. The development team has completed their coding and deployed the new application in AWS.
However, after a few days, the QA team noticed that queries stop responding at all in Redshift. In this scenario, which of the following can you do to solve this performance issue? (Choose 3)
Reduce the size of maximum transmission unit (MTU)
Increase the available memory by increasing the wlm_query_slot_count
View the STV_LOCKS and STL_TR_CONFLICT system tables to find conflicts involving updates to more than one table
Run the VACUUM command
Use the PG_CANCEL_BACKEND function to cancel one or more conflicting queries
You are managing a serverless auction application which uses API Gateway, AWS Lambda, and DynamoDB. The application sends and receives messages to and from individual users in real-time in the entire duration of the online auction. However, your customers are complaining that they are intermittently getting HTTP 504 errors in your application which ruins their user experience.
Which of the following is the most likely cause of this issue?
The API Gateway and the Lambda function encountered an authorization failure
Due to the increasing number of incoming requests, the API Gateway automatically enabled throttling which inadvertently caused the HTTP 504 errors
The usage plan quota for the Lambda function has been exceeded
The underlying Lambda function has been running for more than 29 seconds which causes the API Gateway request to timeout
You are instructed to perform a Total Cost of Ownership (TCO) analysis and prepare a cost optimized migration plan for the systems hosted in your on- premises network to AWS. It is required that you collect configuration, usage, and behavior data from your on-premises servers to help you better understand your workloads before doing the migration.
Which of the following is the most suitable solution that you should implement to meet this requirement?
Use the AWS SAM service to move your data to AWS which will also help you perform the TCO analysis
Use the AWS Migration Hub service to collect data from each server in your on-premises data center and perform the TCO analysis
Use the AWS Application Discovery Service to gather data about your on-premises data center and perform the TCO analysis
Use the AWS Server Migration Service (SMS) to migrate VM servers to AWS and collect data required to complete your TCO analysis
A suite of web applications is hosted in an Auto Scaling group of On-Demand EC2 instances behind an Application Load Balancer that handles traffic from various web domains.
You are responsible for securing the system by allowing multiple domains to serve SSL traffic without the need to re-authenticate and re-provision your certificate whenever you add a new domain name. This change of architecture from HTTP to HTTPS will help improve the SEO and Google search ranking of the web application.
Which of the following are valid solutions to meet the above requirement? (Choose 2)
Use a Classic Load Balancer instead of an Application Load Balancer. Upload all SSL certificates of the domains and use Server Name Indication (SNI)
Use a wildcard certificate to handle multiple sub-domains and different domains
Add a Subject Alternative Name (SAN) for each additional domain to your certificate
Upload all SSL certificates of the domains in the ALB using the console and bind multiple certificates to the same secure listener on your load balancer. ALB will automatically choose the optimal TLS certificate for each client using Server Name Indication (SNI)
Create a new CloudFront web distribution and configure it to serve HTTPS requests using dedicated IP addresses in order to associate your alternate domain names with a dedicated IP address in each CloudFront edge location
You are working as a Solutions Architect for a leading financial company. One of your applications is hosted in an Amazon ECS Cluster, which processes a large stream of intraday data and stores the generated result to a DynamoDB database.
To comply with the financial regulatory policy, you were tasked to design a system which will detect new entries in the DynamoDB table then automatically run tests to verify the results using a Lambda function.
Which of the following options can satisfy the requirement with minimal configuration?
Set up DynamoDB Streams to detect the new entries and automatically trigger the Lambda function
Detect the new entries in the DynamoDB table using Systems Manager Automation then automatically invoke the Lambda function for processing
Set up a CloudWatch Alarm to automatically trigger the Lambda function whenever a new entry is created in the DynamoDB table
Run the Lambda function using SNS each time the ECS Cluster successfully processes financial data
You are running a startup company in which you are building a mobile app and a custom GraphQL API that lets people post photos and videos of road potholes, faulty streetlights, bridge damages and other issues in the public infrastructure with 100-character summaries. The data gathered by the system will be used by the department of public works which will allow fast resolution. You decided to develop the app using a JavaScript-based React Native mobile framework so that it would run on various mobile and tablet devices. The app will also be connecting to a custom GraphQL API that you have built which will be responsible to store the photos and videos in an S3 bucket and will also need access to the DynamoDB database to store the summaries.
You have recently deployed the mobile app prototype, but you found out that there is an availability issue with the custom GraphQL API. To proceed with the project, your team decided to remove the API and instead, remodel the mobile app so that it will directly connect to both DynamoDB and S3 as well as handle user authentication.
Which option provides the most cost-effective and scalable architecture for this project?
1. Set up a web identity federation using the AssumeRole API of STS and register with social identity providers like Amazon, Google, Facebook or any other OpenID Connect (OIDC)-compatible IdP. 2. Create an IAM user for that provider and set up permissions for the IAM user to allow access to S3 and DynamoDB. 3. The mobile app will use the AWS access and secret keys to store the photos and videos to an S3 bucket and persist the summaries to the DynamoDB database
1. Set up a web identity federation using the AssumeRoleWithWebIdentity API of STS and register with social identity providers like Amazon, Google, Facebook or any other OpenID Connect (OIDC)-compatible IdP. 2. Create an IAM role for that provider and set up permissions for the IAM role to allow access to S3 and DynamoDB. 3. The mobile app will use the AWS access and secret keys to store the photos and videos to an S3 bucket and persist the summaries to the DynamoDB database
A. 1. Set up a web identity federation using the AssumeRoleWithSAML API of STS and register with social identity providers like Amazon, Google, Facebook or any other OpenID Connect (OIDC)-compatible IdP. 2. Create an IAM role for that provider and set up permissions for the IAM role to allow access to S3 and DynamoDB. 3. The mobile app will use the AWS temporary security credentials to store the photos and videos to an S3 bucket and persist the summaries to the DynamoDB database
1. Set up a web identity federation using Cognito and social identity providers like Amazon, Google, Facebook or any other OpenID Connect (OIDC)-compatible IdP. 2. Configure the IAM role in Cognito to allow access to S3 and DynamoDB. 3. The mobile app will use the AWS access and secret keys to store the photos and videos to an S3 bucket and persist the summaries to the DynamoDB database
1. Set up a web identity federation using the AssumeRoleWithWebIdentity API of STS and register with social identity providers like Amazon, Google, Facebook or any other OpenID Connect (OIDC)-compatible IdP. 2. Create an IAM role for that provider and set up permissions for the IAM role to allow access to S3 and DynamoDB. 3. The mobile app will use the AWS temporary security credentials to store the photos and videos to an S3 bucket and persist the summaries to the DynamoDB database
You are the CTO of your co-founded startup where you are building an innovative AI-powered traffic monitoring portal using AWS as its cloud infrastructure. As the system would be used in the entire city, it should be highly available and fault-tolerant to avoid unnecessary downtime.
Which of the following options is the MOST suitable architecture that you should implement?
Use DynamoDB as the database of the portal. Launch an Auto Scaling group of EC2 instances on four Availability Zones. Attach an application load balancer to the Auto Scaling Group. Use Route 53 and create an A record to point to the ELB
A. Launch an Auto Scaling group of EC2 instances on three Availability Zones. Attach an application load balancer to the Auto Scaling Group.
Use an Amazon Aurora Multi-Master as the database tier. Use Route 53 and create alias record to point to the ELB
Use ElastiCache for the database caching of the portal. Launch an Auto Scaling group of EC2 instances on four Availability Zones. Attach an application load balancer to the Auto Scaling Group. Use a MySQL RDS instance with Multi-AZ deployments configuration and Read Replicas. Use Route 53 and create a CNAME to point to the ELB
Launch an Auto Scaling group of EC2 instances on two Availability Zones. Attach an application load balancer to the Auto Scaling Group. Use a MySQL RDS instance with Multi-AZ deployments configuration. Use Route 53 and create an A record to point to the ELB
A leading commercial bank has recently hired you as a replacement for their outgoing Solutions Architect. The bank has a hybrid network architecture and is extensively using AWS for their day-to-day operations. The outgoing Solutions Architect told you that the S3 bucket that they are using to store sensitive bank records has versioning enabled and does not have any encryption. He handed over the task of implementing a Server-Side Encryption with Customer-Provided Encryption Keys (SSE-C) for the S3 bucket to ensure data security both at rest and in-transit.
Which of the following will you do to properly complete this task? (Choose 2)
Only use the S3 console to upload and update objects with SSE-C encryption
For Amazon S3 REST API calls, use the following HTTP Request Headers: x-amz-server-side-encryption-customer-algorithm x-amz-server-side- encryption-customer-key x-amz-server-side-encryption-customer-key- MD5
For presigned URLs, specify the algorithm using the x-amz-server-side- encryption-customer-key-MD5 request header
For presigned URLs, specify the algorithm using the x-amz-server-side- encryption-customer-algorithm request header
Use WSS (WebSocket Secure)
A French fashion design company which sells bags, clothes, and other luxury items has recently decided to move all their on-premises infrastructure entirely on AWS. They have an application which is hosted on a NGINX web server and a database which has an Oracle Real Application Clusters (RAC) configuration. Which is the best way to migrate their application to AWS and set up an automated back up?
Launch an EC2 instance for both the NGINX server as well as for the database. Attach EBS Volumes on the EC2 instance of the database and then write a shell script that runs the manual snapshot of the volumes
Launch an EC2 instance and run a NGINX server to host the application. Deploy an RDS instance and enable automated backups on the RDS RAC cluster
Launch an On-Demand EC2 instance and run a NGINX server to host the application. Deploy an RDS instance with a Multi-AZ deployment configuration and enable automated backups on the RDS RAC cluster
Launch an EC2 instance for both the NGINX server as well as for the database. Attach EBS volumes to the EC2 instance of the database and then use the Data Lifecycle Manager to automatically create scheduled snapshots against the EBS volumes
A financial company is building a new online document portal system that allows its employees and developers to upload yearly and bi-annual corporate earnings report files to a private S3 bucket in which other confidential corporate files will also be stored. You are working as a
Solutions Architect and you were instructed to create the private S3 bucket as well as the IAM users for the application developers to start their work. You assigned the required policies in IAM to the developers that allows them read and write access to the S3 bucket. After a few weeks, they have completed the new online portal and hosted it on a fleet of Spot EC2 instances. One of the application developers created a pre-signed URL that points to the correct S3 bucket and after a few tests, he has successfully uploaded the files from his laptop using the generated URL.
He then made the necessary code change to the online portal to generate the pre-signed URL to upload the files in S3. However, after a few days, the development team complained that they cannot upload the files anymore using the online portal. Which of the following options are valid reasons for this behavior? (Choose 2)
The application developers do not have access to either read or upload objects to the S3 bucket
The expiration date of the pre-signed URL is incorrectly set to expire too quickly and thus, may have already expired when they used it
The required AWS credentials in the ~/.aws/credentials configuration file located on the EC2 instances of the online portal is missing and hence, it does not generate the pre-signed URL properly
There was a recent change in the S3 bucket that allows object versioning which invalidates all presigned URLs
The ACL of the S3 bucket blocks the online portal and prevents the developers from uploading any files
The global investment bank that you are working for has an online trading platform in which you are assigned to manage. It is used by a lot of traders around the world to buy and sell stocks, bonds, ETFs, CFDs and REITs. There are times when the trading platform is unresponsive due to a lot of slow processing queries on its RDS database. In order to fix this issue, you decided to supplement your primary RDS database with an in-memory data caching using ElastiCache to speed up the processing for the frequently accessed read data.
You have asked the approval of your CTO that you will use ElastiCache with an open-source Apache Ignite in-memory datastore however, your request was denied because he confidently and positively said it was not possible. What is the reason behind this?
Your CTO is wrong. Your plan is valid, and you can implement it right away
Although it is possible to use ElastiCache on top of RDS as a distributed cache, you can only use Redis as your in-memory datastore and nothing else
It is not possible to use ElastiCache on top of RDS as a distributed cache
Although it is possible to use ElastiCache on top of RDS as a distributed cache, you can only use Memcached as your in-memory datastore and nothing else
Although it is possible to use ElastiCache on top of RDS distributed cache, you can only use either Redis or Memcached as your in-memory datastore and nothing else
A leading mobile game company has an application running on Elastic Beanstalk that continuously collects player-game interactions and player's behavior then feeds the data into an Amazon Kinesis stream. A second Elastic Beanstalk app generates key performance indicators (KPIs) into a DynamoDB table and powers the game leaderboard.
After a few weeks, there has been a technical problem in the Kinesis data stream which resulted in data loss for your application. Which of the following is the most efficient and most scalable option to prevent any data loss for this application?
Launch a second Amazon Kinesis stream in another Availability Zone then use Data Pipeline to replicate data across Kinesis streams
Use Data Pipeline to replicate your DynamoDB tables into another region
Launch a third Elastic Beanstalk app that uses the Amazon Kinesis S3 connector or Amazon Kinesis Data Firehose to archive the data from Kinesis into an S3 bucket
Use the second AWS Elastic Beanstalk app to store a backup of Kinesis data onto an EBS volume, and then create snapshots from your EBS volumes
You are the developer of a live flight tracker that gets updated every 10 minutes with the latest flight information on every airplane. The tracking website has a global audience and uses an Auto Scaling group behind an Elastic Load Balancer and an Amazon RDS database. A simple web interface is hosted as static content on your Amazon S3 bucket. The Auto Scaling group is set to trigger a scale up event at 90% CPU utilization.
The average load time of your web pages is around 7 seconds, but you want to bring it down to less than 3 seconds. In this scenario, which combination of options will make the page load time faster in the MOST cost-effective way? (Choose 2)
Have CloudFront enable caching of re-usable content from your website
Replace your existing Auto Scaling group with the AWS Systems Manager State Manager which provides a more effective way to manage and scale your EC2 instances
Create a second installation in another region and utilize Amazon Route 53's latency-based routing feature to direct requests to the appropriate region
Scale more frequently by setting the scale up trigger of the Auto Scaling group to 30%
Add a caching layer using Amazon ElastiCache Service to be used for storing sessions and frequent DB queries
There was a recent production incident in your company in which the confidential files that are stored in an S3 bucket were accidentally made public. This has caused data leakage in your company which is why you were instructed by your manager to come up with a solution to safeguard your S3 bucket. The solution should only allow private files to be uploaded in your S3 bucket and no file should have a public read nor public write access.
Which of the following options can you implement to meet the above requirements with MINIMAL effort?
Use the s3-bucket-public-read-prohibited and s3-bucket-public-write- prohibited managed rules in AWS Config to restrict all users from uploading publicly accessible and writable files to the S3 bucket
Enable Amazon S3 Block Public Access in the S3 bucket
Set up AWS Organizations and create a new Service Control Policy (SCP) that will deny public objects from being uploaded to the Amazon S3 bucket. Attach the SCP to the AWS account
Set up a policy that restricts all s3:PutObject actions of the user to have a private canned ACL only which prohibits any public access to the uploaded objects
An enterprise accounting application runs in your on-premises data center as well as on the AWS cloud to achieve the minimum recovery time objective (RTO) of your company's business continuity plan. In this hybrid setup, the users can connect to the on-premises server if the EC2 instance in AWS is down and vice versa.
In this scenario, which of the following will not meet the requirements of a disaster-resilient network infrastructure?
Set up weighted DNS service in Route53 to route traffic across sites
Set up a single DB instance in one availability zone
Run the accounting application both on-premises and in AWS with full capacity
Configure data replication to provide a durable storage
You are working for a supermarket chain that handles branded credit card transactions from major card schemes such as Mastercard, Visa, Discover, and AMEX. The chain requested an external auditor to audit your AWS environment as part of the Payment Card Industry Data Security Standard (PCI DSS) security compliance. The auditor has specified that he just needs read-only access to the AWS resources on all accounts to perform the checks.
Which of the following options would help the auditor get the required access?
Create an Active Directory account for the auditor and use identity federation for SSO to let the auditor log in to your AWS environment and conduct the audit
Provide the auditor an AWS account with an IAM role that has read- only permissions to your AWS services. Add a permissions policy that will allow the auditor to assume the ARN role for each AWS account that has an assigned role
Create a new IAM User which has an access key ID and a secret access key for API calls that can be used by the auditor
Give the auditor each of your AWS users' username and password in your VPC and let the auditor use those credentials to login to a specific account and conduct the audit
You are managing the cloud infrastructure of a highly available trip planner website which provides timetables, travel alerts, and other public transportation information for trains, buses, ferries, and trams. The front- end tier is composed of an ELB in front of an Auto Scaling group of EC2 instances deployed across 3 Availability Zones and a Multi-AZ RDS for its database tier. When there are sporting events and popular concerts to be held in the city, the usage of the trip planner application spikes which cause the application servers to reach utilization of over 95%.
As the Solutions Architect, you are responsible to ensure that the website can quickly recover if one of its Availability Zones failed during its peak usage. What is the most cost-effective architectural design that you should implement for this website to maintain high availability?
Deploy one On-Demand EC2 instance and two Spot EC2 Instances in each of the 3 Availability Zones. In case that one Availability Zone fails, the remaining two Availability Zones can handle the peak load
Deploy six Reserved and Spot EC2 Instances in each of the 3 Availability Zones. In this way, the remaining two Availability Zones can handle the load left behind by the Availability Zone that went down
To have the most cost-effective architecture, replace all the Reserved and On-Demand EC2 instances with Spot instances across all Availability Zones. Configure an Auto Scaling group in one of the AZs for scalability
Increase the capacity and scaling thresholds of the Auto Scaling group to allow the application servers to scale up across all Availability Zones, which will lower the aggregate utilization of the EC2 instances. Use Reserved Instances to handle the steady-state load and a combination of On-Demand and Spot Instances to process the peak load. When the peak usage is over, scale down the number of the On-Demand and Spot instances.
A company is running its enterprise resource planning application in AWS that handles supply chain, order management, and delivery tracking. The architecture has a set of RESTful web services that enable third-party companies to search for data that will be consumed by their respective applications. The public web services consist of several AWS Lambda functions. DynamoDB is used for its database-tier and is integrated with an Amazon ES domain, which stores the indexes and supports the search feature.
A Solutions Architect has been instructed to ensure that in the event of a failed deployment, there should be no downtime, and a system should be in place to prevent subsequent deployments. The service must strictly maintain full capacity during API deployment without any reduced compute capacity to avoid degradation of the service.
Among the options below, which can the Architect use to meet the requirements in the MOST efficient way?
Do a blue/green deployment on all upcoming changes using AWS CodeDeploy. Using AWS CloudFormation, launch the Amazon DynamoDB tables, AWS Lambda functions, and Amazon ES domain in your AWS VPC. Host the web application in AWS Elastic Beanstalk and set the deployment policy to Immutable
Do an in-place deployment on all upcoming changes using AWS CodeDeploy. Using AWS SAM, launch the Amazon DynamoDB tables, Lambda functions, and Amazon ES domain in your AWS VPC. Host the web application in AWS Elastic Beanstalk and set the deployment policy to Rolling
Do a blue/green deployment on all upcoming changes using AWS CodeDeploy. Using AWS SAM, launch the DynamoDB tables, Lambda functions, and Amazon ES domain in your AWS VPC. Host the web application in AWS Elastic Beanstalk and set the deployment policy to All at Once
Do a blue/green deployment on all upcoming changes using AWS CodeDeploy. Using AWS CloudFormation, launch the Amazon DynamoDB tables, AWS Lambda functions, and Amazon ES domain in your AWS VPC. Launch the application to an Amazon S3 static web hosting and enable cross-region replication
An online banking portal is using a GraphQL API hosted in AWS which uses Amazon API Gateway Lambda proxy integration. There were several API issues lately in which you need to trace and analyze user requests as they travel through your Amazon API Gateway APIs to the underlying services.
As the Solutions Architect, which of the following is the most suitable service that you must use to meet this requirement?
CloudTrail
AWS X-Ray
Amazon Inspector
CloudWatch Logs
A company wants to improve the security of their cloud resources by ensuring that all running EC2 instances were launched from pre-approved AMIs only, which are set by the Security team. Their Development team has an agile CI/CD process which should not be stalled by the new automated solution that they’ll implement. Any new application release must be deployed first before the solution could analyze if it is using a pre-approved AMI or not.
Which of the following options enforces the required controls with the LEAST impact on the development process? (Choose 2)
Set up AWS Config rules to determine any launches of EC2 instances based on non-approved AMIs and then trigger an AWS Lambda function to automatically terminate the instance. Afterwards, publish a message to an SNS topic to inform the Security team about the occurrence
Set up Amazon Inspector to do regular scans using a custom assessment template to determine if the EC2 instance is based upon a pre-approved AMI. Terminate the instances and inform the Security team by email about the security breach
Set up IAM policies to restrict the ability of users to launch EC2 instances based on a specific set of pre-approved AMIs which were tagged by the Security team
Set up the required policies, roles and permissions to a centralized IT Operations team, which will manually process the security approval steps to ensure that EC2 instances are only launched from pre- approved AMIs
Set up a scheduled Lambda function to search through the list of running EC2 instances within your VPC and determine if any of these are based on unauthorized AMIs. Afterwards, publish a new message to an SNS topic to inform the Security team that this occurred and then terminate the EC2 instance
A startup is working on a prototype of their cryptocurrency trading platform in AWS that allows the Internet traffic as well as the back-end connections from their VPC. They want to make sure that for the back-end connections, EC2 instance can receive SSH traffic only from a selected IP range, while the Internet facing web server will have an IP address which can receive traffic from all IPs.
How can you achieve this by running the web app on a single on-demand EC2 instance?
The organization should create 2 EC2 instances as this is not possible with one EC2 instance
Use a Dedicated EC2 instance rather than an On-demand instance to allow multiple IP addresses
It is not possible to have 2 IP addresses for a single EC2 instance
The startup should create 2 elastic network interfaces: one for the Internet traffic and the other for the backend traffic
An IT services and solutions firm support all the enterprise web applications of a Fortune 500 company, with an RTO of 3 hours and RPO of 5 hours as defined in the operational level agreement (OLA). As the Solutions Architect of the IT firm, you need to set up a Backup & Restore disaster recovery in AWS. If a disaster occurs at 7:00 AM, by what time should the disaster recovery process have completely restored the service to the acceptable level?
12:00 PM
10:00 AM
4:00 AM
2:00 AM
You are working as an IT consultant for a multinational investment bank where you manage various multi-tier applications hosted in their on- premises network. To leverage the power of cloud computing, the management decided to migrate all their systems to AWS. They also need to migrate their ActiveMQ messaging broker service which supports NMS and MQTT messaging protocol.
Which of the following is the most suitable service to use to migrate the messaging service with minimal configuration?
Use Amazon SNS as the messaging service of your multi-tier applications
Use Amazon MQ as the messaging service of your multi-tier applications
Use AWS Step Functions as the messaging service of your multi-tier applications
Use Amazon SQS as the messaging service of your multi-tier applications
A cryptocurrency trading platform uses a Lambda function which has recently been integrated with DynamoDB Streams as its event source. Whenever there is a new deployment, the incoming traffic to the function must be shifted in two increments using CodeDeploy.
Ten percent of the incoming traffic should be shifted to the new version and then the remaining 90 percent should be deployed five minutes later. You are also required to trace the event source that invoked your Lambda function including the downstream calls that your function made.
Which of the following should you implement to satisfy this requirement?
Configure a Rolling with additional batch deployment configuration for your Lambda function and use X-Ray to trace the event source and downstream calls
Configure a Linear deployment configuration for your Lambda function and use AWS Config to trace the event source and downstream calls
Configure an All-at-once deployment configuration for your Lambda function and use AWS Config to trace the event source and downstream calls
Configure a Canary deployment configuration for your Lambda function. Enable active tracing to integrate AWS X-Ray to your AWS Lambda function
You are running an Auto Scaling group of EC2 instances which uses ElastiCache with Append Only Files (AOF) enabled in multiple AWS regions. Recently, one of the regions experienced a power outage due to a storm which has affected your business.
Assuming that only a short recovery downtime period is allowed, how would you maintain site availability in case an event like this occurs again in the future?
Set up a DNS active-active failover using latency-based routing policy that resolves to an ELB. Configure the 'Evaluate Target Health' attribute to Yes
Consolidate all your VPCs across multiple regions into a single Private Hosted Zone using Route 53
Create a dedicated Transit VPC to directly route multi-VPC traffic over a VPN connection across multiple regions
Enable Domain Name System Security Extensions (DNSSEC) in your domain. Configure Route 53 to automatically failover the traffic to a secondary group of healthy resources on standby. Configure the 'Evaluate Target Health' attribute to No
The www.buzzpluz.com news website is using an EC2-hosted WordPress instance as its platform to deliver news around the globe. There are a lot of customers complaining about the slow loading time of the website.
You used CloudFront and set the website as origin to improve the read performance. After several days, the IT Security team told you that the setup is not secure, and you should enable end-to-end HTTPS connections from the user's browser to the origin via CloudFront.
What would you do to satisfy the above requirement?
Use a self-signed certificate in both the origin and CloudFront
Configure CloudFront to use its default certificate. For the origin, use a self-signed certificate
Configure CloudFront to use its default certificate by setting the Viewer Protocol Policy for one or more cache behaviors to require HTTPS communication. For the origin, also use the default certificate provided by ACM
Use third-party CA certificate on both the origin and CloudFront
You are the Technical Lead of a medical firm that has an image analysis application that extracts data from multiple images. The input stream analyzes a batch of images and for each file, it writes the result data to an output stream of files. The number of input files per day grows and peaks for a few hours in a day. You are already using an EC2 instance with a large EBS volume that hosts the input data, but the results still take almost 20 hours per day to be processed.
What services could be used to reduce the processing time and improve the availability of the solution?
Store I/O files in an EBS Provisioned IOPS volume and use SNS to facilitate a group of hosts working in parallel. Include the hosts in an auto scaling group that scales accordingly to the number of SNS notifications
Store I/O files in S3 instead and use SQS to facilitate a group of hosts working in parallel. Include the hosts in an auto scaling group that scales accordingly to the number of SNS notifications
Store I/O files in an EBS Provisioned IOPS volume and use SNS to facilitate a group of hosts working in parallel. Include the hosts in an auto scaling group that scales accordingly to the length of your SQS queue
Store I/O files in S3 instead and use SQS to facilitate a group of hosts working in parallel. Include the hosts in an auto scaling group that scales accordingly to the length of your SQS queue
As a Solutions Architect, you are responsible for the security of your AWS resources as well as securing your web applications from common web vulnerabilities and cyber-attacks. One example is a Distributed Denial of Service attack (DDoS) in which there are numerous incoming traffic coming from many different locations that simultaneously goes into your web application and floods your network.
Which of the following can be a part of your DDoS attack surface reduction strategy to minimize the blast radius in your cloud infrastructure? (Choose 2)
Strictly implement Multi-Factor Authentication (MFA) in AWS. Use a combination of AWS Systems Manager State Manager, AWS Config, and Trusted Advisor to fortify your AWS resources
Add Elastic Load Balancing and Auto Scaling to your EC2 instances to improve availability and scalability. Use extra-large EC2 instances to accommodate a surge of incoming traffic caused by a DDoS attack and utilize AWS Systems Manager Session Manager to filter all client-side web sessions to your instances
Always add a security group that only allows certain ports and authorized servers and protects your origin servers by putting it behind a CloudFront distribution. Enable AWS Shield Advanced which provides enhanced DDoS attack detection and monitoring for application-layer traffic to your AWS resources
Configure the Network Access Control Lists (ACLs) to only allow the required ports to your network. Identify and block common DDoS request patterns to effectively mitigate a DDoS attack by using AWS WAF
Allow versioning in your S3 bucket. Ensure that the OS of all your EC2 instances are properly patched using Systems Manager Patch Manager
You are working as a Solutions Architect at the European Organization for Nuclear Research, also known as CERN, which is a European research organization that operates the largest particle physics laboratory in the world. A group of data scientists are planning to use an Elastic MapReduce cluster for their testing, which will only be run once.
The cluster is designed to ingest 300 TB of data with a total of 200 EC2 instances and is expected to run for about 8 hours. The resulting data set must be stored temporarily until it is permanently stored in their AWS Redshift database.
What is the best and most cost-effective solution to satisfy this requirement?
Use Reserved EC2 instances for the master node; On-Demand instances for the core nodes; and use Spot EC2 instances for the task nodes
Use Reserved EC2 instances for both the master and core nodes and use Spot EC2 instances for the task nodes
Use On-Demand EC2 instances for both the master and core nodes and use Spot EC2 instances for the task nodes
Use a combination of On-Demand instance and Spot instance types for both the master and core nodes. Use Spot EC2 instances for the task nodes
You are a Cloud Consultant for a new startup, and they have a VPC with an IPv4 CIDR block 10.0.0.0/24. The Senior IT Manager wants to expand the VPC CIDR to host more resources in that VPC.
How can you implement this in AWS?
Delete all the subnets in the VPC and allocate a larger CIDR range
You can expand your existing VPC by adding four (4) secondary IPv4 IP ranges (CIDRs) to it
Create a new VPC with a greater IP range and link it with the old VPC
There is no method in changing your CIDR block size. You will have to create a new VPC
A photo sharing website uses a CloudFront distribution with a default name (dtut0r1al5doj0.cloudfront.net) to distribute its static contents. It uses an ELB in front of an Auto Scaling group of Spot EC2 instances deployed across two Availability Zones. The website has a poor search ranking in Google as it doesn't use a secure HTTPS/SSL on its site.
Which of the following are valid options in order to require HTTPS for communication between the viewers and CloudFront? (Choose 3)
Use a self-signed certificate in the ELB
Configure CloudFront to use its default SSL/TLS certificate by changing the Viewer Protocol Policy setting for one or more cache behaviors to require HTTPS communication
Set the Viewer Protocol Policy to use Redirect HTTP to HTTPS
Configure the ELB to use its default SSL/TLS certificate
Set the Viewer Protocol Policy to use HTTPS Only
An online brokerage firm used AWS Elastic Beanstalk in deploying their cryptocurrency trading platform. After one year, a new version of their trading platform is ready to be deployed.
Which of the following is not a valid deployment policy that you can use in Elastic Beanstalk?
Immutable
Rolling with additional batch
Rolling
Swap Environment URLs
A well-known business news portal is visited by thousands of readers each day to check on the latest hot topics in the world of business and technology. The news portal runs on a fleet of Spot EC2 instances behind an Application Load Balancer ELB.
Readers can also submit their comments in every article. Currently, the system's database is running on an on-premises data center, and the CTO is concerned that the content delivery time is not meeting company objectives. The portal's page load time is of utmost importance for the company to maintain their daily visitors.
How should you quickly and cost-effectively re-architect the system for the news portal to reduce latency for their customers?
Add an in-memory datastore using Amazon ElastiCache for Redis to reduce the burden on the database. Enable Redis replication to scale database reads and to have highly available clusters.
Create a CloudFront web distribution to speed up the delivery of data to their readers around the globe. Migrate the entire portal to an S3 bucket and then enable static web hosting. Set the S3 bucket as the origin of your CloudFront distribution
Migrate your database on-premises to Amazon Aurora using the AWS Database Migration Service (DMS) and AWS Schema Conversion Tool (SCT). Create Aurora Replicas across Availability Zones and reconfigure the web servers to query from the Aurora database instead
Replace the on-premises database of the news portal with a fast, scalable full-text search engine using Amazon ES by setting up an ELK stack (Elasticsearch, Logstash, and Kibana). Use a CloudFront web distribution to speed up the delivery of data to your users across the globe
Your company has a gaming store platform hosted in its on-premises data center for a whole variety of digital games. The application just experienced downtime last week due to a large burst in web traffic caused by a year-end sale on almost all the games. Due to the success of the previous promotion, the CEO has planned to do the same in a few weeks, which will drive similar unpredictable bursts in web traffic.
Your team is looking to find ways to quickly improve your infrastructure's ability to handle unexpected increases in traffic. The web application is currently made up of a 2-tier web tier which consists of a load balancer and several web app servers, as well as a database tier which hosts an Oracle database.
In this scenario, which of the following infrastructure changes will you implement to avoid any further incidences of downtime considering that the new announcement will be done in a few weeks?
Set up an Amazon S3 bucket for website hosting. Migrate your DNS to Route 53 using zone import and use DNS failover to failover to the hosted website in S3
Set up a CloudFront distribution to cache objects from a custom origin to offload traffic from your on-premises environment. Customize your object cache behavior and choose a time-to-live that will determine how long objects will reside in the cache
Migrate your environment to AWS by using AWS VM Import to quickly convert your web server into an AMI. Then set up an Auto Scaling group that uses the imported AMI. Also, create an RDS read replica and migrate the Oracle database to an RDS instance through replication
Create an AMI that can be used to launch new EC2 web servers. Then create an Auto Scaling group which will use the AMI to scale the web tier. Finally, place an Application Load Balancer to distribute traffic between your on-premises servers and servers running in AWS
You are working as a Solutions Architect for a leading insurance company in Hong Kong. As part of the audit process, an auditor has been called in to view all the logs of all API requests made to your AWS environment.
Which of the following options is the most suitable solution that you should implement?
Create an IAM Role with the required permissions for the auditor
Subscribe the auditor to an SNS topic that sends notifications via email whenever CloudTrail delivers log files to S3. Do not provide the auditor access to your AWS environment
The company will have to contact AWS first due to the shared responsibility model, before AWS can provide the necessary access to the auditor
Turn on CloudTrail logging and provide the auditor an IAM user with read-only permissions to the AWS resources that will be audited, including the S3 bucket containing the CloudTrail logs
A graphic design startup company has recently started using AWS and has hired you to set up their cloud infrastructure to multiple VPCs. They are looking to automate the deployment of their systems to one or more of their VPCs that require a MEAN (MongoDB, Express, AngularJS, and Node.js) stack, an Application Load Balancer, and an S3 bucket to host their graphic design files.
To ensure that there are no graphic design files that will be lost, the manager also said that the S3 bucket should never be deleted if they decided to bring down the architecture and transfer it to another VPC.
Which of the following services can meet this requirement?
AWS CloudFormation with a value of "Snapshot" for the S3 bucket's DeletionPolicy
AWS CloudFormation with a value of "Retain" for the S3 bucket's CreationPolicy
AWS CloudFormation with a value of "false" for the S3 bucket's DeletionPolicy
AWS CloudFormation with a value of "Retain" for the S3 bucket's DeletionPolicy
You have built a web application on an extra-large EC2 instance, which allows users to upload and download various pdf files from a private S3 bucket using a pre-signed URL. The web application checks if the file being requested exists in the S3 bucket before generating the URL.
In this scenario, how should you configure the web application to access the S3 bucket securely?
1. Create an IAM role with a policy that allows listing and uploading of the objects in the S3 bucket. Launch the EC2 instance with the IAM role. 2. Program your web application to retrieve the temporary security credentials from the EC2 instance metadata
1. Store your access keys inside the EC2 instance. 2. Program your web application to retrieve the AWS credentials from the instance to interact with the objects in the S3 bucket
1. Create an IAM user with the appropriate permissions allowing access and listing of all the objects of the S3 bucket. Associate the EC2 instance with the IAM user. 2. Program your web application to retrieve the user credentials from the EC2 instance metadata
1. Create an IAM role with a policy that allows listing of the objects in the S3 bucket. Launch the EC2 instance with the IAM role.2. Program your web application to retrieve the temporary security credentials from the EC2 instance user data
An online learning portal which provides educational video courses is deployed in AWS and is using CloudFront to distribute their images, videos, files, and other static contents to its users. Recently, they introduced a new member-only access to some of its top-rated courses.
They want to provide access to multiple private files of their online courses only to their paying subscribers without having to change their current URLs. What should you do to satisfy the given requirement?
Enable field-level encryption when serving your content
Set the Origin Protocol Policy of your CloudFront web distribution to Match Viewer
Configure your web distribution to serve the private content using Signed URLs
Configure your web distribution to serve the private content using Signed Cookies
You are working closely with a medical research team in a university, and the outcome is an intuitive mobile app that shows the user's overall health record and medications. The highly sensitive health records of your users are stored in an EC2 instance with an attached EBS data volume. As part of the security compliance, it is mandated that all the data stored in your cloud infrastructure are properly secured and encrypted.
Which of these options would allow you to encrypt your data at rest? (Choose 3)
All EBS volumes after provisioning are encrypted by default
Encrypt your data prior to storing them on EBS
Take advantage of third-party volume encryption software
Apply SSL/TLS for all your services running on the server
Use native data encryption drivers present at the file system level of encrypting your data
You are working as a Senior AWS Solutions Architect in a company in Silicon Valley. Your client has asked you to design a connectivity solution between on-premises infrastructure and their Amazon VPC. The goal is to allow communication of the on-premises servers with the EC2 instances running in the VPC. You considered establishing IPSec tunnels over the Internet using VPN gateways and terminating the IPsec tunnels on AWS-supported customer gateways.
Which of the following objectives would you achieve by implementing an IPSec tunnel as described above? (Choose 4)
You obtain peer identity authentication between VPN gateway and customer gateway
You receive end-to-end protection of data in transit
Your data is encrypted across the Internet
Your data in transit is protected over the Internet
You obtain data integrity protection across the Internet
