WorksheetsSC-01.5
Total questions: 50
Worksheet time: 38mins
You are working for a shipping firm that has web applications running on their data center. Their servers have a dependency on non-x86 hardware, and they plan to use AWS to scale their on-premises data storage. However, your backup application is only able to write to POSIX-compatible block- based storage. There is a total of 1,000 TB of data files that need to be mounted to a single folder on your file server.
Existing users must also be able to access portions of this data while the backups are taking place. In this scenario, what backup solution would be most appropriate?
Use Amazon Glacier as the target for your data backups
Provision Gateway Stored Volumes from AWS Storage Gateway
Provision Gateway Cached Volumes from AWS Storage Gateway
Use Amazon S3 as the target for your data backups
As a best practice in your company, all the cloud-related deployments should not be done manually but using CloudFormation. All the CloudFormation templates should be treated as a code and hence, all of them are committed in a private GIT repository. A senior DevOps engineer has recently left your team and your manager asked you to take over his tasks and applications. One of the tasks that the outgoing DevOps engineer is handling is a distributed system in AWS, in which the architecture is declared in a template. The distributed system needs to be migrated to another VPC and you tried to read the template to understand the AWS resources that the template will generate. While analyzing the CloudFormation template, you stumbled upon this code below.
What does this code snippet do in CloudFormation?
"SNSTopic" : { "Type" : "AWS::SNS::Topic", "Properties" : { "Subscription" : [{
"Protocol" : "sqs", "Endpoint" : { "Fn::GetAtt" : [ "MyCompanyQueue", "Arn"
] } }] }
Creates an SNS topic and then adds a subscription using the ARN attribute name for the SQS resource, which is created under the logical name MyCompanyQueue
Creates an SNS topic which allows SQS subscription endpoints to be added as a parameter on the template
Creates an SNS topic and then invokes the call to create an SQS queue with a logical resource name of MyCompanyQueue
Creates an SNS topic which allows SQS subscription endpoints
You are managing a NodeJS application that needs a NGINX server for the front end, Elasticsearch and Logstash for log processing, as well as a MongoDB database instance for document management. In order to improve the process of updating the application stack, your manager instructed you to choose between In-place and Disposable method.
Which of the following is true about the In-place and Disposable method?
An in-place upgrade involves rolling out a new set of EC2 instances by terminating older instances. A disposable upgrade, on the other hand, involves performing application updates on live Amazon EC2 instances
An in-place upgrade involves performing application updates on live Amazon EC2 instances. A disposable upgrade, on the other hand, combines the simplicity of managing AWS infrastructure provided by Elastic Beanstalk and the automation of custom network segmentation provided by AWS CloudFormation
An in-place upgrade involves performing application updates on live Amazon EC2 instances. A disposable upgrade, on the other hand, involves rolling out a new set of EC2 instances by terminating older instances
An in-place upgrade combines the simplicity of managing AWS infrastructure provided by Elastic Beanstalk and the automation of custom network segmentation provided by AWS CloudFormation. A disposable upgrade, on the other hand, involves rolling out a new set of EC2 instances by terminating older instances
An online stock trading application is deployed to multiple Availability Zones in the us-east-1 region (N. Virginia) and uses RDS to host the database. Considering the massive financial transactions that the trading application handles, the company has hired you to be a consultant to make sure that the system is scalable, highly available, and disaster resilient. In the event of failure, the Recovery Time Objective (RTO) must be less than 2 hours and the Recovery Point Objective (RPO) must be 10 minutes to meet the compliance requirements set by the regulators.
In this scenario, which Disaster Recovery strategy can be used to achieve the RTO and RPO requirements in the event of system failure?
Take 15-minute database backups stored in Glacier with transaction logs stored in S3 every 5 minutes
Store hourly database backups to an EC2 instance store volume with transaction logs stored in an S3 bucket every 5 minutes
Take hourly database backups to an S3 bucket with transaction logs stored in S3 every 5 minutes. Set up a Cross-Region Replication (CRR) to another AWS Region
Configure your database to use synchronous master-slave replication between multiple Availability Zones
A hospital in New York has hosted its web-based medical records portal entirely in AWS using EC2 instances for its web-tier and an RDS database for its data tier. In compliance with HIPAA (Health Insurance Portability and Accountability Act of 1996), the hospital hired an IT security professional to check their systems. It was found that there are a lot of unauthorized requests coming from a set of IP addresses originating from a country in South East Asia.
What can you do to ensure that this type of attack is properly mitigated?
Enable enhanced networking to the EC2 instances that hosts the web portal and block the attacking IP addresses
Modify the main route table of the VPC and block the attacking IP addresses from the IGW (Internet Gateway)
Create an inbound Network Access Control list with deny rules to block the attacking IP addresses
Block the attacking IP addresses by creating a rule in the Security Group of the EC2 instances
You are working as a Network Engineer for an electronics and communications company in Japan where you are managing a NAT instance in your VPC. This allows multiple EC2 instances that are launched in a private subnet to initiate connections to the Internet but restrict any requests coming from any outside network.
However, there are numerous incidents where your NAT instance is notavailable, which affects the batch processing of your applications. In this scenario, which is the most suitable solution that provides better availability and bandwidth to your architecture with minimal administrative effort?
Create a NAT gateway then specify its corresponding subnet and Elastic IP address. Update your route tables of your private subnet to point the Internet traffic to the NAT gateway
Create an egress-only Internet gateway. Update the route tables of your private subnet to point the Internet traffic to the egress-only Internet gateway
Launch a larger NAT instance with the enhanced networking feature enabled to improve the availability and performance of your NAT device
Launch two large NAT instances in two separate public subnets and add a route from the private subnet to each NAT instance to make it more fault tolerant and highly available
A global enterprise web application is using a private S3 bucket, named MANILATECH-CONFIG, which has a Server-Side Encryption with Amazon S3- Managed Encryption Keys (SSE-S3) to store its configuration files for different regions in North America, Latin America, Europe, and Asia. There has been a lot of database changes and feature toggle switching for the past few weeks.
Your CTO assigned you the task of enabling versioning on this bucket to track any changes made to the configuration files and can use the old settings if needed. In the coming days ahead, a new region in Oceania will be supported by the web application and thus, a new configuration file will be added soon.
Currently, there are already four files in the bucket, namely: MNL-NA.config, MNL-LA.config, MNL-EUR.config and MNL-ASIA.config which are updated regularly. As instructed, you enabled the versioning in the bucket and after a few days, the new MNL-O.config configuration file for the Oceania region has been uploaded. A week after, a configuration has been done on MNL- NA.config, MNL-LA.config and MNL-O.config files.
Inthisscenario,whichofthefollowingiscorrectaboutfilesinsidetheMANILATECH-CONFIGS3bucket?(Choose2)
The MNL-EUR.config and MNL-ASIA.config files will have a Version ID of 1
The latest Version ID of MNL-NA.config and MNL-LA.config has a value of null
There would be two available versions for each of the MNL-NA.config, MNL-LA.config and MNL-O.config files. The first Version ID of MNL- NA.config and MNL-LA.config has a value of null
The MNL-EUR.config and MNL-ASIA.config files will have a Version ID of null
The first Version ID of MNL-NA.config and MNL-LA.config has a value of 1
You are designing a photo-sharing mobile app for an advertising company. The app will store all pictures directly uploaded by users in a single Amazon S3 bucket and users will also be able to view and download their own pictures directly from the Amazon S3 bucket.
You are to configure security on the application to handle potentially millions of users in the most secure manner possible.
How do you set up the user registration flow in AWS for this mobile app?
Generate long-term credentials using AWS STS and apply appropriate permissions. Store the credentials in the mobile app and use them to access Amazon S3
Create an IAM user, assign appropriate permissions to it, and generate an access key and a secret key which will be stored in the mobile app and used to access Amazon S3
Create an IAM user and generate an access key and a secret key to be stored in the mobile app for the IAM user. After applying the appropriate permissions to the S3 bucket policy, use the generated credentials to access S3
Store user information in Amazon RDS and create an IAM Role with appropriate permissions. Generate new temporary credentials using the AWS Security Token Service 'AssumeRole' function every time the user uses their mobile app and creates new temporary credentials. These credentials will be stored in the mobile app's memory and will be used to access Amazon S3
To ensure high availability of both the web servers and the database of your web application, you deployed your auto scaled EC2 instances to multiple
Availability Zones with an Application Load Balancer in front and used Multi- Availability Zone configuration to your RDS instance. There is a spike in incoming requests in the past few hours and the performance of the primary database is starting to go down.
What would happen to the database if the primary DB instance fails?
The RDS DB instance will automatically reboot
The IP address of the primary DB instance is switched to the standby DB instance
A new DB instance will be created and immediately replace the primary database
The canonical name record (CNAME) is changed from the primary database to standby database
You have an online video feed of your inventory warehouses in the Philippines. The web servers are hosted on a fleet of EC2 instances spread across 2 Availability Zones and are connected via an Elastic Load Balancer in your VPC. You observed that the incoming web traffic is not being evenly distributed across the Availability Zones.
What can be done to solve this issue?
Add additional EC2 web hosts in each AZ to absorb the imbalance
Your ELB might be malfunctioning. Remove the current ELB and create a new one
Lower the frequency of your health checks
Disable sticky sessions on the ELB
You are working as a Solutions Architect for a multinational software provider in Philadelphia and you are tasked to host both of your development and test environments in AWS. Your CTO decided to use separate AWS accounts in hosting each environment. You enabled Consolidated Billing to link each of the accounts' bill to a Master AWS account.
To make sure you keep within the budget, you are to provide a way for administrators in the master account to have access to stop, delete and/or terminate resources in both development and test environment accounts.
Which of the following is the best option to implement for this scenario?
By linking all accounts under Consolidated Billing, you will be able to provide IAM users in the master account access to Dev and Test account resources
In the master account, you are to create IAM users and a cross-account role that has full admin permissions to the Dev and Test accounts
First, create IAM users in the master account. Then in the Dev and Test accounts, generate cross-account roles that have full admin permissions while granting access for the master account
IAM users with full admin permissions will be created in the master account. In both Dev and Test accounts, generate cross-account roles that would grant the master account access to Dev and Test account resources through permissions inherited from the master account
A leading aerospace company wants to utilize AWS as its secondary storage. The project only has a limited funding hence, they are looking for the most cost-effective storage solution. The data being stored is rarely retrieved and in case it is requested, it is not required to have a fast retrieval time and the requestor can wait for 24 hours.
In this scenario, what is the best and most cost-effective storage option to use?
S3 One Zone-Infrequent Access
S3 Standard - Infrequent Access
S3 Standard Class
Glacier
The software development company that you are working for has two departments that want to use AWS Redshift. The engineering department uses a process that takes 3 hours to analyze the data whereas the accounting department just takes a few minutes.
What can you do to ensure that there is no performance impact on the accounting department's queries?
Start another Redshift cluster from snapshot for the accounting department if current Redshift cluster is busy processing long queries
Create two separate workload management groups and assign them to respective departments
Create a read replica of the Redshift instance and run the accounting department's queries on read replica
Pause long queries and resume the queries afterwards
A financial startup company offers flexible short-term loans of up to $5000 to its users. Their online portal is hosted in AWS which uses S3 for scalable storage, DynamoDB as a NoSQL database and a fleet of EC2 instances to host their web servers. To meet the financial regulation, the company is required to undergo a compliance audit.
In this scenario, how will you provide the auditor access to the logs of your AWS resources?
1. Contact AWS and inform them of the upcoming audit activities. 2. AWS will grant required access to the third-party auditor to see the logs
1. Create an SNS Topic. 2. Configure the SNS to send out an email with the attached CloudTrail log files to the auditor's email every time the CloudTrail delivers the logs to S3
1. Enable CloudTrail logging to the required AWS resources. 2. Create an IAM user with read-only permissions to the required AWS resources.
3. Provide the access credential to the auditor
1. Create an IAM role that has the required permissions for the auditor.
2. Attach the roles to the EC2, S3, and DynamoDB
There is a technical requirement in your team to build a distributed system that fetches workload from a queue. To implement the new architecture, you have deployed the Java web application on a fleet of Spot EC2 instances that accesses an SQS FIFO queue.
In this scenario, how should you configure the application to use AWS credentials to access the SQS queue securely?
1. Create an IAM user for the application with permissions that allows access to the SQS FIFO queue. 2. The application retrieves the IAM user credentials from a temporary directory in the EC2 instance
1. Create an IAM user for the application with permissions that allow access to the SQS FIFO queue. 2. Launch the EC2 instance as the IAM user. 3. Retrieve the IAM user's credentials from the EC2 instance user data
1. Create an IAM role for EC2 instances that allows access to the SQS queue. 2. Launch the EC2 instance with the IAM role. 3. Retrieve the role's credentials from the EC2 Instance metadata
1. Store the AWS account access and secret keys in a config file located in the home directory of the EC2 instances. 2. The application retrieves the credentials from the config file
You are working as a Solutions Architect for a global IT services company which has over a hundred data centers all around the globe. Due to financial constraints, one of its data centers located in Detroit will be decommissioned soon and require all their data to be moved to their cloud infrastructure in AWS. They need to migrate a total of 80 TB of data in approximately a week to avoid further system downtime. In addition, they only have a limited 25 Mbps Internet line in their data center to do the migration.
In this scenario, what is the fastest and most cost-effective solution to use to migrate all the data to AWS?
Use the Amazon S3 sync command in AWS CLI to migrate the data over the Internet
Use the Amazon Connect omnichannel to migrate the 80 TB of data to AWS
Use the AWS Snowball Edge service to migrate the 80 TB of data to AWS
Use AWS Snowmobile to migrate all the data to AWS
In a major investment bank at Wall Street, a developer requested for a temporary credential to access an S3 bucket. You generated the temporary credential from STS and gave it to the developer. However, your manager informed you that the credential you provided is too much and allows the developer to access all AWS resources.
What should you do to immediately revoke the access you have recently given to the developer?
Go to the STS Dashboard and select the specific role that you provided to the developer. Under the Revoke sessions tab, select "Revoke active sessions"
Go to the IAM Dashboard and select the specific role that you provided to the developer. Under the Revoke sessions tab, select "Revoke active sessions"
Delete the IAM user of the developer
It is currently impossible to revoke the credentials that you have already given
You are creating a CloudFormation script to deploy an online voting application for a Nature Photography Contest that accepts high-resolution images, stores them in an S3 bucket, and records 100-character summary about the image in RDS. As a Solutions Architect, you must ensure that the same online voting application can be deployed once again using the same CloudFormation template for the succeeding contests in the future.
The photography contest will run for just a month and once it has been concluded, there would be nobody using the online voting application anymore until the next contest. As a preparation for the upcoming events next year, the 100-character summaries should be kept and the S3 bucket which contains the high-resolution photos should remain.
In this scenario, which of the following is the best option to meet the above requirement?
1. Set the DeletionPolicy on the S3 resource to Snapshot. 2. Set the DeletionPolicy on the RDS resource to Snapshot
For both the RDS and S3 resource types on the CloudFormation template, set the DeletionPolicy to Retain
1. Set the DeletionPolicy on the S3 resource declaration in the CloudFormation template to Retain. 2. Set the RDS resource declaration DeletionPolicy to Snapshot
1. Enable Cross-Region Replication (CRR) in the S3 bucket to maintain a copy of all the S3 objects. 2. Set the DeletionPolicy for the RDS instance to Snapshot
You are working as a Solutions Architect for a cryptocurrency analytics website which uses a CloudFront distribution with a custom domain name (mycompany.com) to speed up the loading time of the site. Since the data being distributed are quite confidential, your manager instructed you to require HTTPS communication between the viewers (web visitors) and the CloudFront distribution. You are also instructed to improve the performance by increasing the proportion of your viewer requests that are served from CloudFront edge caches instead of going to your origin servers.
What should you do to accomplish the above requirement? (Choose 2)
Use an SSL/TLS certificate provided by AWS Certificate Manager (ACM)
Configure your origin to add a Cache-Control max-age directive to your objects and specify the longest practical value for max-age
Associate your CloudFront web distribution with Lambda@Edge which provides automatic scalability from a few requests per day to thousands of requests per second
Import an SSL/TLS certificate from a third-party certificate authority into a private S3 bucket with versioning and MFA enabled
Integrate your CloudFront web distribution with Amazon Elasticsearch (ES) and Kibana to improve the performance of your origin servers and to visualize the cache data in real time
You are looking to reduce the amount of time you spend managing database instances in your on-premises data center by migrating to a managed relational database service in AWS such as Amazon Relational Database Service (RDS). In addition, you are also planning to move your application hosted in your data center to a fully managed platform such as AWS Elastic Beanstalk.
As the Solutions Architect of the company, which of the following is the most cost-effective migration strategy that you should implement to meet the above requirement?
Replatform
Rehost
Refactor / Re-architect
Repurchase
You are working for a leading online media company that runs a popular sports news website. You are tasked to analyze each web visitor's clickstream data on the website to populate user analytics which gives you an insight on the sequence of pages and advertisements the visitor has clicked. The data will be processed real-time which will then transform the page layout as the visitors click through the web portal to increase user engagement and consequently, increase the revenue for the company.
Which option meets the requirements in this scenario?
Push web clicks by session to Amazon Kinesis and analyze behavior using Amazon Kinesis workers
Log clicks in weblogs by URL and store it in Amazon S3, and then analyze with Elastic MapReduce
Write click events directly to Amazon Redshift and then analyze with SQL
Publish web clicks by session to an Amazon SQS queue and periodically drain these events to Amazon RDS then analyze with SQL
A graphics design company is running an online portal in which users can upload their photos, videos, and other digital files. There is a new requirement that you must implement in which the online portal must share private content to certain users for only 24 hours by using an S3 bucket.
After the provided time limit has elapsed, the private content should not be accessible anymore.
In this scenario, which of the following is the most feasible option to fulfill this requirement?
Enable the Cross-Region Replication and Requester Pays option in the S3 bucket
Use Pre-Signed URLs to provide access to private content
Use SES to deliver content from the S3 bucket
Use Signed URLs to provide access to private content
A multinational insurance firm is running its web application on their corporate data center. They hired you to set up a disaster recovery infrastructure in AWS to ensure business continuity in the event of server failures in their on-premises network. You must run a minimal version of your environment by configuring and running the most critical core elements of your system only in another AWS region. When the time comes for recovery, you should be able to rapidly provision a full-scale production environment around the critical core.
Which is the MOST cost-effective disaster recovery option that provides a quick recovery time in a matter of minutes for the application?
Pilot Light
Backup & Restore
Warm Standby
Multisite
Your company is using Microsoft Active Directory to manage all employee accounts and devices. The IT department instructed you to implement a single sign-on feature to allow the employees to use their existing Windows account password to connect and use the various AWS resources.
Which of the following is the most suitable way to extend your Active Directory domain to AWS?
Use IAM Roles to set up cross-account access and delegate access to resources that are in your AWS account
Use AWS Directory Service to integrate your AWS resources with the existing Active Directory using trust relationship. Enable single sign-on using Managed Microsoft AD
Use AWS Cognito to authorize users to your applications using direct sign in or through third party apps and access your apps' backend resources in AWS
Create users and groups with AWS Single Sign-On along with AWS Organizations to help you manage SSO access and user permissions across all the AWS accounts
You are a Solutions Architect for a software development company, and you have been instructed to manage your AWS cloud infrastructure as code to automate the build and deploy process. The company would like to have the ability to easily deploy exact copies of different versions of your cloud infrastructure, stage changes into different environments, revert to previous versions, and identify the specific versions running in the VPC. Plus, all new public-facing applications should also have global content delivery network (CDN) service.
Which of the following can meet this requirement?
Use AWS CloudFormation to manage the cloud architecture and CloudFront as the CDN
Use CloudWatch as the CDN and CloudFormation to manage the cloud architecture
Use CloudWatch as the CDN and Elastic Beanstalk to deploy and manage the cloud architecture
Use CloudFront as the CDN and Elastic Beanstalk to deploy and manage the cloud architecture
You are a Cloud Engineer and currently managing an enterprise financial auditing system that generates regular analytics reports from your firm's application log files. All log data are collected in an Amazon S3 bucket which are then processed by a daily Amazon Elastic MapReduce job. It generates daily reports and aggregated tables in CSV format, which is stored in another S3 bucket and then transferred to an Amazon Redshift data warehouse. Your manager tasked you to optimize the cost structure for this system.
Which of the following options will lower costs without compromising performance or data integrity?
Launch Spot EC2 Instances for Amazon EMR jobs and then use Reserved Instances for Amazon Redshift. Choose the Amazon S3 One Zone- Infrequent Access storage class to store all data in S3
Launch a combination of Spot and Reserved EC2 Instances for Amazon EMR jobs then use Reserved instances for Amazon Redshift. Choose the Amazon S3 Intelligent-Tiering storage class to store all data in S3
Launch Spot EC2 Instances for Amazon EMR jobs as well as for Amazon Redshift. Choose the Amazon S3 Intelligent-Tiering storage class to store all data in S3
Launch On-Demand EC2 instances for both Amazon EMR jobs and Amazon Redshift. Choose the Amazon S3 Standard storage class to store all data in S3
You are working as the Lead Systems Architect for a government bank in which you are handling a web application that retrieves and displays highly sensitive information about the clients. The amount of traffic the site will receive is known and not expected to fluctuate. SSL will be used as part of the application's data security.
Your chief information security officer (CISO) is concerned about the security of your SSL private key and she wants to ensure that the key cannot be accidentally or intentionally moved outside the corporate environment. You are also concerned that the application logs might contain some sensitive information, although you have already configured an encrypted EBS volume to store the data. In this scenario, the application logs must be stored securely and durably so that they can only be decrypted by the authorized government employees.
Which of the following is the most suitable and highly available architecture that can meet all the requirements?
Distribute traffic to a set of web servers using an Elastic Load Balancer that performs TCP load balancing. Use an AWS CloudHSM to perform the SSL transactions and deliver your application logs to a private Amazon S3 bucket using server-side encryption
Distribute traffic to a set of web servers using an Elastic Load Balancer. To secure the SSL private key, upload the key to the load balancer and configure the load balancer to offload the SSL traffic. Lastly, write your application logs to an instance store volume that has been encrypted using a randomly generated AES key
Distribute traffic to a set of web servers using an Elastic Load Balancer that performs TCP load balancing. Use CloudHSM deployed to two Availability Zones to perform the SSL transactions and deliver your application logs to a private Amazon S3 bucket using server-side encryption
Distribute traffic to a set of web servers using an Elastic Load Balancer. Use TCP load balancing for the load balancer and configure your web servers to retrieve the SSL private key from a private Amazon S3 bucket on boot. Use another private Amazon S3 bucket to store your web server logs using Amazon S3 server-side encryption
A leading media company has a hybrid architecture where its on-premises data center is connected to AWS via a Direct Connect connection. They also have a repository of over 50-TB digital videos and media files. These files are stored on their on-premises tape library and are used by their Media Asset Management (MAM) system.
Due to the sheer size of their data, they want to implement an automated catalog system that will enable them to search their files using facial recognition. A catalog will store the faces of the people who are present in these videos including a still image of each person. Eventually, the media company would like to migrate these media files to AWS including the MAM video contents.
Which of the following options provides a solution which uses the LEAST amount of ongoing management overhead and will cause MINIMAL disruption to the existing system?
A. Integrate the file system of your local data center to AWS Storage Gateway by setting up a file gateway appliance on-premises. Utilize the MAM solution to extract the media files from the current data store and send them into the file gateway. Build a collection using Amazon
Rekognition by populating a catalog of faces from the processed mediafiles. Use an AWS Lambda function to invoke Amazon Rekognition by populating a catalog of faces from the processed media files. Use an AWS Lambda function to invoke Amazon Rekognition JavaScript SDK to have it fetch the media file from the S3 bucket, which is backing the file gateway, retrieve the needed metadata, and finally, persist the information into the MAM solution
Use Amazon Kinesis Video Streams to set up a video ingestion stream and with Amazon Rekognition, build a collection of faces. Stream the media files from the MAM solution into Kinesis Video Streams and configure the Amazon Rekognition to process the streamed files. Launch a stream consumer to retrieve the required metadata and push the metadata into the MAM solution. Finally, configure the stream to store the files in an S3 bucket
Set up a tape gateway appliance on-premises and connect it to your AWS Storage Gateway. Configure the MAM solution to fetch the media files from the current archive and push them into the tape gateway in the AWS Cloud. Using Amazon Rekognition, build a collection from the catalog of faces. Utilize a Lambda function which invokes the Rekognition JavaScript SDK to have Amazon Rekognition process the video directly from the tape gateway in real-time, retrieve the required metadata, and push the metadata into the MAM solution
Migrate all the media files from the on-premises library into an EBS volume mounted on a large EC2 instance. Install an open-source facial recognition tool in the instance like OpenFace or OpenCV. Process the media files to retrieve the metadata and push this information into the MAM solution. Lastly, copy the media files to an S3 bucket
The telecommunications company that you are working for will do a major public announcement for a new phone offer and it is expected that there would be millions of people who will access their website to get the new offer. Their e-commerce platform is running on an Auto Scaling group of On- Demand EC2 instances deployed across multiple Availability Zones. For the database tier, the platform is using an Amazon RDS database in a Multi-AZ deployments configuration.
Their e-commerce site performs a high number of small reads and writes per second to handle customer transactions and relies on an eventual consistency model. The Operations team identified that there is read contention on RDS MySQL database after conducting a series of performance tests.
Which combination of options should you implement to provide a fast, cost- efficient, and scalable solution? (Select TWO)
Modify the Amazon RDS Multi-AZ deployments configuration to launch multiple standby database instances. Distribute the incoming traffic to the standby instances to improve the database performance
Implement an in-memory cache using Amazon ElastiCache
Set up Read Replicas in each Availability Zone
Vertically scale your RDS MySQL Instance by upgrading its instance size with provisioned IOPS
Migrate the database to Amazon Redshift and use its massively parallel query execution capability to improve the read performance of the application
You are working as a Solutions Architect for a multinational tech company which has multiple VPCs for each of its IT departments. You are instructed to launch a new central database server which can be accessed by the other VPCs of the company using the database.mycompany.com domain name.
This server should only be accessible within the associated VPCs since only internal applications will be using the database.
Which of the following should you do to meet the above requirement?
A. Set up a public hosted zone with a domain name of mycompany.com and specify the VPCs that you want to associate with the hosted zone.
Create a CNAME record with a value of database.mycompany.com which maps to the IP address of the EC2 instance of your database server. Modify the enableDnsHostNames attribute of your VPC to false and the enableDnsSupport attribute to false
A. Set up a private hosted zone with a domain name of mycompany.com and specify the VPCs that you want to associate with the hosted zone. Create an A record with a value of database.mycompany.com which maps to the Elastic IP address of the EC2 instance of your database server. Modify the enableDnsHostNames attribute of your VPC to true and the enableDnsSupport attribute to false
Set up a public hosted zone with a domain name of mycompany.com and specify the VPCs that you want to associate with the hosted zone. Create an A record with a value of database.mycompany.com which maps to the IP address of the EC2 instance of your database server. Modify the enableDnsHostNames attribute of your VPC to true and the enableDnsSupport attribute to true
Set up a private hosted zone with a domain name of mycompany.com and specify the VPCs that you want to associate with the hosted zone. Create an A record with a value of database.mycompany.com which maps to the IP address of the EC2 instance of your database server. Modify the enableDnsHostNames attribute of your VPC to true and the enableDnsSupport attribute to true
You are working as a Solutions Architect for a leading IT consultancy company which has offices in San Francisco, Frankfurt, Tokyo, and Manila. They are using AWS Organizations to easily manage the multiple AWS accounts being used by their regional offices and subsidiaries. A new AWS account was recently added to a specific organizational unit (OU) which is responsible for the overall systems administration.
The administrator noticed that the account is using a root-created AWS ECS Cluster with an attached service-linked role. For regulatory purposes, you created a custom SCP that would deny the new account from performing certain actions in relation to using ECS. However, after applying the policy, the new account could still perform the actions that it was supposed to be restricted from doing.
What could be the most likely reason for this problem?
There is an SCP attached to a higher-level OU that permits the actions of the service-linked role. This permission would therefore be inherited by the current OU, and override the SCP placed by the administrator
SCPs do not affect any service-linked role. Service-linked roles enable other AWS services to integrate with AWS Organizations and can't be restricted by SCPs
The default SCP grants all permissions attached to every root, OU, and account. To apply stricter permissions, this policy is required to be modified
The ECS service is being run outside the jurisdiction of the organization. SCPs affect only the principals that are managed by accounts that are part of the organization
A multinational investment bank has a hybrid cloud architecture which uses a single 1 Gbps AWS Direct Connect connection to integrate their on- premises network to AWS Cloud. The bank has a total of 10 VPCs which are all connected to their on-premises data center via the same Direct Connect connection that you manage. Based on the recent IT audit, the existing network setup has a single point of failure which needs to be addressed immediately.
Which of the following is the MOST cost-effective solution that you should implement in order to improve the connection redundancy of your hybrid network?
Establish another 1 Gbps AWS Direct Connect connection using a public Virtual Interface (VIF). Prepare a VPN tunnel which will terminate on the virtual private gateway (VGW) of the respective VPC using the public VIF. Handle the failover to the VPN connection using BGP
Establish a new point-to-point Multiprotocol Label Switching (MPLS) connection to all your 10 VPCs. Configure BGP to use this new connection with an active/passive routing
Establish another 1 Gbps AWS Direct Connect connection with corresponding private Virtual Interfaces (VIFs) to connect all the 10 VPCs individually. Set up a Border Gateway Protocol (BGP) peering session for all the VIFs
Establish VPN tunnels from your on-premises data center to each of the 10 VPCs. Terminate each VPN tunnel connection at the virtual private gateway (VGW) of the respective VPC. Configure BGP for route management
A global financial company is launching their new trading platform in AWS which allows people to buy and sell their bitcoin, Ethereum, ripple and other cryptocurrencies as well as access to various financial reports. To meet the anti-money laundering and counter-terrorist financing (AML/CFT) measures compliance, all report files of the trading platform must not be accessible in certain countries which are listed in the Financial Action Task Force (FATF) list of non-cooperative countries or territories.
You were given a task to ensure that the company complies with this requirement to avoid hefty monetary penalties.
In this scenario, what is the best way to satisfy this security requirement in AWS while still delivering content to the users around the globe with lower latency?
Deploy the trading platform using Elastic Beanstalk and deny all incoming traffic from the IP addresses of the blacklisted countries in the Network Access Control List (ACL) of the VPC
Create a CloudFront distribution with Geo-Restriction enabled to block all the blacklisted countries from accessing the trading platform
Use Route53 with a Geolocation routing policy that blocks all traffic from the blacklisted countries
Use Route53 with a Geoproximity routing policy that blocks all traffic from the blacklisted countries
You currently operate a sports web portal that covers the latest cricket news in Australia. You manage the main AWS account which has multiple AWS regions. The online application is hosted on a fleet of on-demand EC2 instances and an RDS database which are also deployed to other AWS regions.
Your IT Security Compliance Officer has given you the task of developing a reliable and durable logging solution to track changes made to all your EC2, IAM, and RDS resources in all the AWS regions. The solution must ensure the integrity and confidentiality of your log data.
Which of the following solutions would be the best option to choose?
Create three new CloudTrail trails, each with its own S3 bucket to store the logs: one for the AWS Management console, one for AWS SDKs, and one for command line tools. Then create IAM roles and S3 bucket policies for the S3 buckets storing your logs
Create a new trail in CloudTrail and assign it a new S3 bucket to store the logs. Configure AWS SNS to send delivery notifications to your management system. Secure the S3 bucket that stores your logs using IAM roles and S3 bucket policies
Create a new trail in AWS CloudTrail with the global services option selected and assign it an existing S3 bucket to store the logs. Create S3 ACLs and enable Multi Factor Authentication (MFA) delete on the S3 bucket storing your logs
Create a new trail in AWS CloudTrail with the global services option selected and create one new Amazon S3 bucket to store the logs. Create IAM roles, S3 bucket policies, and enable Multi Factor Authentication (MFA) Delete on the S3 bucket storing your logs
A graphics design startup is using multiple Amazon S3 buckets to store high- resolution media files for their various digital artworks. After securing a partnership deal with a leading media company, the two parties shall be sharing digital resources with one another as part of the contract. The media company frequently performs multiple object retrievals from the S3 buckets every day, which increased the startup's data transfer costs.
As the Solutions Architect, what should you do to help the startup lower their operational costs?
Provide cross-account access for the media company, which has permissions to access contents in the S3 bucket. Cross-account retrieval of S3 objects are charged to the account that made the request
Enable the Requester Pays feature in all the startup's S3 buckets to make the media company pay the cost of the data transfer from the buckets
Advise the media company to create their own S3 bucket. Then run the aws s3 sync s3://sourcebucket s3://destinationbucket command to copy the objects from their S3 bucket to the other party's S3 bucket. In this way, future retrievals can be made on the media company's S3 bucket instead
Create a new billing account for the social media company by using AWS Organizations. Apply SCPs on the organization to ensure that each account has access only to its own resources and each other's S3 buckets
An online medical record system is using a fleet of Windows EC2 instances with several EBS volumes attached to it. Since the records that they are storing are confidential health files of their patients, there is a need to ensure that the latest security patches are installed to the EC2 instances. In addition, you also must implement a system in your cloud architecture which checks all your EC2 instances if they are using an approved Amazon Machine Image (AMI). The system that you will implement should not impede developers from launching instances using an unapproved AMI, but you still must be notified if there are non-compliant EC2 instances in your VPC.
Which of the following should you implement to protect and monitor all your instances as required above? (Choose 2)
Set up a patch baseline which defines which patches are approved for installation on your instances using AWS Systems Manager Patch Manager
Use AWS Shield Advanced to automatically patch all your EC2 instances and detect uncompliant EC2 instances which do not use approved AMIs
Create an IAM policy that will restrict the developers from launching EC2 instances with an unapproved AMI
Set up Amazon GuardDuty that continuously monitors your instances if the latest security patches are installed and if there is an instance that is using an unapproved AMI. Use CloudWatch Alarms to notify you if there are any non-compliant instances running in your VPC
Use the AWS Config Managed Rule which automatically checks whether your running EC2 instances are using approved AMIs. Set up CloudWatch Alarms to notify you if there are any non-compliant instances running in your VPC
An online immigration system is currently hosted on one large EC2 instance
with EBS volumes to store all the applicants' data. The registration system accepts the information from the user including documents and photos and then performs automated verification and processing to check if the applicant is eligible for immigration. The immigration system becomes unavailable at times when there is a surge of applicants using the system.
The existing architecture needs improvement as it takes a long time for the system to complete the processing and the attached EBS volumes are not enough to store the ever-growing data being uploaded by the users. Which of the following is the best option to achieve high availability and a more scalable data storage?
Use a SNS to distribute the tasks to a group of EC2 instances. Use Auto Scaling to dynamically increase or decrease the group of EC2 instances depending on the length of the SQS queue
Upgrade your architecture to use an S3 bucket with cross-region replication (CRR) enabled, as the storage service. Set up an SQS queue to distribute the tasks to a group of EC2 instances with Auto Scaling to dynamically increase or decrease the group of EC2 instances depending on the length of the SQS queue. Use CloudFormation to replicate your architecture to another region
Use EBS with Provisioned IOPS to store files, SNS to distribute tasks to a group of EC2 instances working in parallel, and Auto Scaling to dynamically size the group of EC2 instances depending on the number of SNS notifications. Use CloudFormation to replicate your architecture to another region
Upgrade to EBS with Provisioned IOPS as your main storage service and change your architecture to use an SQS queue to distribute the tasks to a group of EC2 instances. Use Auto Scaling to dynamically increase or decrease the group of EC2 instances depending on the length of the SQS queue
A print media company has a popular web application hosted on their on- premises network which allows anyone around the globe to search its back catalog and retrieve individual newspaper pages on their web portal. They have scanned the old newspapers into PNG image format and used Optical Character Recognition (OCR) software to automatically convert images to a text file. The license of their OCR software will expire soon, and the news organization decided to move to AWS and produce a scalable, durable, and highly available architecture.
Which is the best option to achieve this requirement?
Create a new S3 bucket to store and serve the scanned image files using a CloudFront web distribution. Launch a new Elastic Beanstalk environment to host the website across multiple Availability Zones and set up a CloudSearch for query processing, which the website can use. Use Amazon Rekognition to detect and recognize text from the scanned old newspapers
Store the images in an S3 bucket and prepare a separate bucket to host the static website. Utilize S3 Select for searching the images stored in S3. Set up a lifecycle policy to move the images to Glacier after 3 months and if needed, use Glacier Select to query the archives
Create a new CloudFormation template which has EBS-backed EC2 instances with an Application Load Balancer in front. Install and run a NGINX web server and an open source search application. Store the images to EBS volumes with Amazon Data Lifecycle Manager configured, and which automatically attach new volumes to the EC2 instances as required
Use S3 Intelligent-Tiering storage class to store and serve the scanned files. Migrate the commercial search application on an Auto Scaling group of Spot EC2 Instances across multiple Availability Zones with an Application Load Balancer to balance the incoming load. Use Amazon Rekognition to detect and recognize text from the scanned old newspapers
A Solutions Architect has been assigned to develop a workflow to ensure that the required patches of all their Windows EC2 instances are properly identified and applied automatically. To maintain their system uptime requirements, it is of utmost importance to ensure that the EC2 instance reboots do not occur at the same time on all their Windows instances. This is to avoid any loss of revenue that could be caused by any unavailability issues of their systems.
Which of the following will meet the above requirements?
Create two Patch Groups with unique tags that you will assign to all your EC2 Windows Instances. Associate the predefined AWS- DefaultPatchBaseline baseline on both patch groups. Set up two non- overlapping maintenance windows and associate each with a different patch group. Using Patch Group tags, register targets with specific maintenance windows and lastly, assign the AWS-RunPatchBaseline document as a task within each maintenance window which has a different processing start time
Create a Patch Group with unique tags that you will assign to all your EC2 Windows Instances. Associate the predefined AWS- DefaultPatchBaseline baseline on both patch groups. Create a CloudWatch Events rule configured to use a cron expression to automate the execution of patching in each schedule using the AWS Systems Manager Run command. Set up an AWS Systems Manager State Manager document to define custom commands which will be executed during patch execution
Create a Patch Group with unique tags that you will assign to all your EC2 Windows Instances. Associate the predefined AWS- DefaultPatchBaseline baseline on your patch group. Set up a maintenance window and associate it with your patch group. Assign the AWS-RunPatchBaseline document as a task within your maintenance window
Create two Patch Groups with unique tags that you will assign to all your EC2 Windows Instances. Associate the predefined AWS-DefaultPatchBaseline baseline on both patch groups. Create two CloudWatch Events rules which are configured to use a cron expression to automate the execution of patching for the two Patch Groups using the AWS Systems Manager Run command. Set up an AWS Systems Manager State Manager document to define custom commands which will be executed during patch executionManager Run command. Set up an AWS SystemsManager State Manager document to define custom commands whichwillbeexecutedduringpatchexecution
Your startup company is building a web app that lets users post photos of good deeds in their neighborhood with a 143-character caption/article. You decided to write the application in ReactJS, a popular JavaScript framework, so that it would run on the broadest range of browsers, mobile phones, and tablets. Your app should provide access to Amazon DynamoDB to store the caption. The initial prototype shows that there aren't large spikes in usage.
Which option provides the most cost-effective and scalable architecture for this application?
Register the web application with a Web Identity Provider such as Google, Facebook, Amazon or from any other popular social site. Create an IAM role for that web provider and set up permissions for the IAM role to allow PUT operations in DynamoDB. Serve your web application from a NGINX server hosted on a fleet of EC2 instances, with a load balancer and auto scaling. Add an IAM role to the EC2 instance to allow PUT operations to DynamoDB tables
Configure the ReactJS client with temporary credentials from the Security Token Service using a Token Vending Machine (TVM) on an EC2 instance. This will provide signed credentials to an IAM user allowing PUT operations in DynamoDB table and GET operations in the S3 bucket. You serve your mobile application out of an S3 bucket enabled as a web site
Register the web application with a Web Identity Provider such as Google, Facebook, Amazon or from any other popular social sites and use the AssumeRoleWithWebIdentity API of STS to generate temporary credentials. Create an IAM role for that web provider and set up permissions for the IAM role to allow GET operations in S3 and PUT operations in DynamoDB. Serve your web app out of an S3 bucket enabled as a website
Configure the ReactJS client with temporary credentials from the Security Token Service using a Token Vending Machine (TVM) to provide signed credentials to an IAM user. This will allow PUT operations to DynamoDB. Serve your web application from an NGINX server hosted in a fleet of EC2 instances that are load-balanced and auto scaled. Your EC2 instances are configured with an IAM role that allows PUT operations in DynamoDB
A multinational consumer goods corporation structured their AWS accounts to use AWS Organizations, which consolidates payment of their multiple AWS accounts for their various Business Units (BU’s) namely the Beauty products, Baby products, Health products and Home Care products unit.
One of their Solutions Architects for the Baby products business unit has purchased 10 Reserved Instances for their new Supply Chain application which will go live 3 months from now. However, they do not want their Reserved Instances to be shared by the other business units.
Which of the following options is the most suitable solution for this scenario?
Remove the AWS account of the Baby products business unit out of the AWS Organization
Set the Reserved Instance (RI) sharing to private on the AWS account of the Baby products business unit
Turn off the Reserved Instance (RI) sharing on the master account for the Baby products business unit
Since the Baby product business unit is part of an AWS Organization, the Reserved Instances will always be shared across other member accounts. There is no way to disable this setting
A fintech startup has developed a cloud-based payment processing system which accepts credit card payments as well as cryptocurrencies such as Bitcoin, Ripple and the likes. The system is deployed in AWS which uses EC2, DynamoDB, S3, and CloudFront to process the payments. Since they are accepting credit card information from the users, they are required to be compliant with the Payment Card Industry Data Security Standard (PCI DSS).
On the recent 3rd-party audit, it was found that the credit card numbers are not properly encrypted and hence, their system failed the PCI DSS compliance test. You were hired by the fintech startup to solve this issue so they can release the product in the market as soon as possible. In addition, you also must improve performance by increasing the proportion of your viewer requests that are served from CloudFront edge caches instead of going to your origin servers for content.
In this scenario, what is the best option to protect and encrypt the sensitive credit card information of the users and to improve the cache hit ratio of your CloudFront distribution?
Configure the CloudFront distribution to use Signed URLs. Configure your origin to add a Cache-Control max-age directive to your objects and specify the longest practical value for max-age to increase your cache hit ratio
Add a custom SSL in the CloudFront distribution. Configure your origin to add User-Agent and Host headers to your objects to increase your cache hit ratio
Create an origin access identity (OAI) and add it to the CloudFront distribution. Configure your origin to add User-Agent and Host headers to your objects to increase your cache hit ratio
Configure the CloudFront distribution to enforce secure end-to-end connections to origin servers by using HTTPS and field-level encryption. Configure your origin to add a Cache-Control max-age directive to your objects and specify the longest practical value for max-age to increase your cache hit ratio
You are migrating an interactive car registration web system hosted on your on-premises network to AWS Cloud. The current architecture of the system consists of a single NGINX web server and a MySQL database running on a Fedora server, which both reside in their on-premises data center.
In this scenario, what would be the most efficient way to transfer the web application to AWS?
1. Use the AWS Server Migration Service (SMS) to create an EC2 AMI of the NGINX web server. 2. Configure auto-scaling to launch in two Availability Zones. 3. Launch a multi-AZ MySQL Amazon RDS instance in one availability zone only. 4. Import the data into Amazon RDS from the latest MySQL backup. 5. Create an ELB to front your web servers. 6. Use Amazon Route 53 and create an A record pointing to the elastic load balancer
1. Export web files to an Amazon S3 bucket in one Availability Zone using AWS Migration Hub. 2. Run the website directly out of Amazon S3. 3. Migrate the database using the AWS Database Migration Service and AWS Schema Conversion Tool (AWS SCT). 4. Use Route 53 and create an alias record pointing to the ELB
1. Use the AWS Application Discovery Service to migrate the NGINX web server. 2. Configure Auto Scaling to launch two web servers in two Availability Zones. 3. Launch a Multi-AZ MySQL Amazon Relational Database Service (RDS) instance in one Availability Zone only. 4. Import the data into Amazon RDS from the latest MySQL backup. 5. Use Amazon Route 53 to create a private hosted zone and point a non-alias A record to the ELB
1. Launch two NGINX EC2 instances in two Availability Zones. 2. Copy the web files from the on-premises web server to each Amazon EC2 web server, using Amazon S3 as the repository. 3. Migrate the database using the AWS Database Migration Service. 4. Create an ELB to front your web servers. 5. Use Route 53 and create an alias A record pointing to the ELB
A serverless application is using a Lambda function which fetches data from a public REST API as part of its processing. There is a new requirement to configure the function to store the results to a database hosted in a virtual private cloud (VPC) in your account. You have provided the additional VPC- specific configuration information which includes the subnet IDs and security group IDs.
However, your function had stopped working and could not complete the processing after your change. Which of the following should you do to fix this issue? (Choose 2)
Manually set up elastic network interfaces (ENIs) to enable your function to connect securely to other resources within your private VPC
Submit a limit increase request for concurrent executions of your Lambda function
Add a NAT gateway to your VPC
Ensure that the associated security group of the Lambda function allows outbound connections
Configure Lambda to forward payloads that were not processed to a dead-letter queue (DLQ) using SQS
You are working as an AWS Developer for a mobile development company. They are currently developing new android and iOS mobile apps and are considering storing the customization data in AWS. This would provide a more uniform cross-platform experience to their users using multiple mobile devices to access the apps. The preference data for each user is estimated to be 50KB in size. Additionally, 3 million customers are expected to use the application on a regular basis, using their social login accounts for easier user authentication.
How would you design a highly available, cost-effective, scalable, and secure solution to meet the above requirements?
Launch an RDS MySQL instance in 2 availability zones to contain the user preference data. Deploy a public facing application on a server in front of the database which will manage authentication and access controls
Have the user preference data stored in S3 and set up a DynamoDB table with an item for each user and an item attribute referencing the user's S3 object. The mobile app will retrieve the S3 URL from DynamoDB and then access the S3 object directly utilizing STS, Web identity Federation, and S3 ACLs
Setup a table in DynamoDB containing an item for each user having the necessary attributes to hold the user preferences. The mobile app will query the user preferences directly from the table. Use STS, Web Identity Federation, and DynamoDB's Fine Grained Access Control for authentication and authorization
Create an RDS MySQL instance with multiple read replicas in 2 availability zones to store the user preference data. The mobile application will then query the user preferences from the read replicas. Finally, utilize MySQL's user management and access privilege system to handle security and access credentials of your users
You are working for a San Francisco-based company which provides digital transaction management services for facilitating electronic exchanges of contracts and signed documents. Using their online system, businessmen and contractors can digitally sign contracts anywhere and anytime, removing the hassle of signing them in paper and in person.
They are using AWS to host their multi-tier online portal in which the application tier is using a NGINX server hosted on an extra-large EC2 instance; the database tier is using an Oracle database which is regularly backed up to an S3 bucket using a custom backup utility and lastly, its static content is kept on a 512GB stored volume in AWS Storage Gateway which is attached to the application server via the iSCSI interface.
In this scenario, which AWS based disaster recovery strategy will give you the best RTO?
1. Deploy the Oracle database and the NGINX app server on an EC2 instance. 2. Restore the Recovery Manager (RMAN) Oracle backups from an Amazon S3 bucket. 3. Generate an EBS volume of static content from the Storage Gateway and attach it to the NGINX EC2 server
1. Deploy the Oracle database and the NGINX app server to an EC2 instance. 2. Restore the Recovery Manager (RMAN) Oracle backups from an S3 bucket. 3. Restore the static content by attaching an AWS Storage Gateway running on Amazon EC2 as an iSCSI volume to the NGINX EC2 server
1. Deploy the Oracle database on RDS. 2. Deploy the NGINX app server on an EC2 instance. 3. Restore the Recovery Manager (RMAN) Oracle backups from Amazon Glacier. 4. Generate an EBS volume of static content from the Storage Gateway and attach it to the NGINX EC2 server
1. Deploy the Oracle database and the NGINX app server on EC2. 2. Restore the Recovery Manager (RMAN) Oracle backups from an S3 bucket. 3. Restore the static content from an AWS Storage Gateway- VTL running on Amazon EC2
A well-funded startup company is building a mobile app that showcases their latest fashion accessories and gadgets. The marketing manager hired a famous model with millions of Instagram followers to promote their new products and hence, it is expected that the app will be a huge hit once it is launched in the market.
It must have the ability to automatically scale to handle millions of views of its static contents and to allow users to store their own photos of themselves wearing fashionable accessories with a maximum of 100- character caption. In this scenario, which of the following would fulfill this requirement?
1. Configure an on-premises Active Directory (AD) server utilizing SAML
2.0 to manage the application users inside of the on-premises ADserver. 2. Develop a custom code that authenticates against the LDAP server. 3. Use DynamoDB as the main database of the app and S3 as the scalable object storage. 4. Grant an IAM role assigned to the STS token to allow the end-user to access the required data in the DynamoDB table. 5. Distribute the static contents using CloudFront to improve scalability
1. Set up a SAML 2.0-based Federation that let the users sign into the app using a third-party identity provider such as Amazon, Google or Facebook. 2. Set up an RDS database and an S3 bucket to store the photos. 3. Use the AssumeRoleWithWebIdentity API call to assume the IAM role containing the proper permissions to communicate with the RDS database. 4. Distribute the static contents using S3 to improve scalability
1. Use Cognito to handle the user authentication and management. 2. Use an RDS database to store user data. 3. Create an S3 bucket to store all the user photos and other static files. 4. Distribute the static contents using CloudFront to improve scalability
1. Use Cognito to handle the user authentication and management. 2. Launch a DynamoDB table to store user data. 3. Create an S3 bucket to store all the user photos and other static files. 4. Distribute the static contents using CloudFront to improve scalability
You are working as a Solutions Architect in a leading commercial bank that is building a new online banking portal to replace their obsolete online system. Due to the volume of transactions that goes through the online portal every day, your job is to ensure that the portal is always available 24 hours a day, 7 days a week. The bank chose to deploy the portal in AWS using EC2 instances and a MySQL RDS instance for its database.
How can you ensure high availability of the online portal even in the event of application and database server failure?
Deploy the online portal to two auto scaled EC2 instances in two different Availability Zones with a load balancer in front using OpsWorks and then enable Auto Healing. Launch MySQL RDS in Multi- AZ deployments configuration
Deploy the online portal to two EC2 instances in two different Availability Zones with a load balancer in front using OpsWorks and CloudWatch for monitoring. Launch MySQL RDS in Multi-AZ deployments configuration
Deploy the online portal to an auto scaled EC2 instances in one Availability Zone using OpsWorks. Launch a MySQL RDS with Read Replica to two separate Availability Zones
Deploy the online portal to two auto scaled EC2 instances in two different Availability Zones with a load balancer in front using OpsWorks. Launch a MySQL RDS with Read Replica to two separate Availability Zones
A data analytics startup has been chosen to develop a data analytics system that will track all statistics in the Federation Internationale de Football Association (FIFA) World Cup which will also be used by other 3rd-party analytics sites. The system will record, store and provide statistical data reports about the top scorers, goal scores for each team, average goals, average passes and average yellow/red cards per match and many other details.
FIFA fans all over the world will frequently access the statistics reports every day and thus, it should be durably stored, highly available and highly scalable. In addition, the data analytics system will allow the users to vote for the best male and female FIFA player as well as the best male and female coach. Due to the popularity of the FIFA World Cup event, it is projected that there will be over 10 million queries on game day and could spike to 30 million queries over the course of time.
Which of the following is the most cost-effective solution that will meet these requirements?
1. Launch a MySQL database in Multi-AZ RDS deployments configuration. 2. Configure the application to generate reports from ElastiCache to improve the read performance of the system. 3. Utilize the default expire parameter for items in ElastiCache
1. Launch a MySQL database in Multi-AZ RDS deployments configuration with Read Replicas. 2. Generate the FIFA reports by querying the Read Replica. 3. Configure a daily job that performs a daily table cleanup
1. Generate the FIFA reports from MySQL database in Multi-AZ RDS deployments configuration with Read Replicas. 2. Set up a batch job that put reports in an S3 bucket. 3. Launch a CloudFront distribution to cache the content with a TTL set to expire objects daily
1. Launch a Multi-AZ MySQL RDS instance. 2. Query the RDS instance and store the results in a DynamoDB table. 3. Generate reports from DynamoDB table. 4. Delete the old DynamoDB tables every day
A leading financial company is planning to launch its MERN (MongoDB, Express, React, Node.js) application with an Amazon RDS MariaDB database to serve its clients worldwide. The application will run on both on-premises servers as well as Reserved EC2 instances. To comply with the company's strict security policy, the database credentials must be encrypted both at rest and in transit. These credentials will be used by the application servers to connect to the database.
The Solutions Architect is tasked to manage all the aspects of the application architecture and production deployment. How should the Architect automate the deployment process of the application in the MOST secure manner?
Upload the database credentials with key rotation in AWS Secrets Manager. Set up a new IAM role that enables access and decryption of the database credentials then attach this role to all on-premises servers and EC2 instances. Use AWS Elastic Beanstalk to host and manage the application on both on-premises servers and EC2 instances. Deploy the succeeding application revisions to AWS and on-premises servers using AWS Elastic Beanstalk
Upload the database credentials with a Secure String data type in AWS Systems Manager Parameter Store. Set up a new IAM role with an attached policy that enables access and decryption of the database credentials then attach this role to all on-premises servers and EC2 instances. Deploy the application packages to the EC2 instances and on- premises servers using AWS CodeDeploy
Upload the database credentials with a Secure String data type in AWS Systems Manager Parameter Store. Set up a new IAM policy that enables access and decryption of the database credentials then attach this IAM policy to the instance profile for CodeDeploy-managed instances. Attach the same policy as well to the on-premises instances. Using AWS CodeDeploy, launch the application packages to the Amazon EC2 instances and on-premises servers
Upload the database credentials with a Secure String data type in AWS Systems Manager Parameter Store. Set up a new IAM role that enables access and decryption of the database credentials then attach this role to all on-premises servers and EC2 instances. Use AWS Elastic Beanstalk to host and manage the application on both on-premises servers and EC2 instances. Deploy the succeeding application revisions to AWS and on-premises servers using AWS Elastic Beanstalk
