Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Associate Architecting & SysOps on AWS (Day 2)

Total questions: 10

Worksheet time: 9mins

Name
Class
Date
1.

What database engines are compatible with Amazon Aurora? (Select TWO.)

a)

DocumentDB

b)

MySQL

c)

MariaDB

d)

Neptune

e)

PostgreSQL

2.
You are performing an update to all of your application servers, however some of your applications are failing following the upgrade and you notice that this seems to only be affecting servers with a specific application profile. How can you assess, audit and evaluate the configurations of your AWS resources so that you can easily identify which of your systems are likely to be affected?
a)
CloudTrail
b)
CloudFormation
c)
Systems Manager
d)
AWS Config
3.
Which strategy can be used to create a highly available application using EC2 Auto Scaling?
a)
Do nothing, as Auto Scaling is highly available by default.
b)
Define multiple Regions in your Auto Scaling group
c)
Check the "do not fail" box in the configuration page
d)
Define multiple AZs in your Auto Scaling group
4.
The application is hosted on groups of EC2 instances in Auto Scaling Groups in multiple AWS Regions. There are also load balancers routing traffic to these instances. In two countries, Ireland and Australia, there are compliance rules in place that dictate users connect to the application in eu-west-1 and ap-southeast-1. Which service can you use to meet this requirement?
a)
Use Route 53 geolocation routing
b)
Configure CloudFront and the users will be routed to the nearest edge location
c)
Use Route 53 weighted routing
d)
Configure the load balancers to route users to the proper region
5.
An insurance company is creating an application which will perform analytics in near real-time on huge datasets in the terabyte range and potentially even petabyte. The company is evaluating an AWS data storage option. Which AWS service will allow storage of petabyte scale data and also allow fast querying of this data?
a)
DynamoDB
b)
Redshift
c)
ElastiCache
d)
RDS
6.

Consider the following scenario:

- Rule 100 in a NACL associated with subnets A and B denies HTTP traffic from 0.0.0.0/0.

- Rule 105 in the same NACL allows HTTP traffic from 0.0.0.0/0.

- EC2 instances in subnet A are associated with a security group that allows HTTP traffic from 192.168.0.0/24.

- EC2 instances in subnet B are associated with a security group that denies HTTP traffic from 128.168.0.0/24. Based on this information, which of the following statements are true?

a)
HTTP traffic from 192.168.0.0/24 will be denied to EC2 instances in subnet A because of the NACL rules.
b)
HTTP traffic from the internet will be denied to EC2 instances in both subnets due to the NACL rules
c)
HTTP traffic from the internet will be allowed to EC2 instances in subnet B
d)
HTTP traffic from 192.168.0.0/24 will be allowed to EC2 instances in subnet A
7.

What happens when RDS multi-AZ fails over from one Availability Zone to another?

a)
Failover is handled by AWS, and the failover mechanism automatically changes the DNS record of the DB instance to point to the standby DB instance
b)
You need to contact AWS for advice as to how to set up your application in the new Availability Zone
c)
You need to update the connection string in your application to point to the new RDS IP address
d)
You don't need to do anything: applications hosted on EC2 instances will failover automatically to the same AZ to which your RDS instances have failed over
8.
According to the AWS shared responsibility model for abstracted services such as Amazon S3 and Amazon DynamoDB, what is the customer responsible for
a)
Operating system patches
b)
Managing the data (including encryption options)
c)
Security of the data center
d)
Using IAM to apply the appropriate permissions
e)
Provisioning the underlying infrastructure
9.

What are TRUE about AWS Transit Gateway

a)

Create a secured tunnel between on-prem & AWS environment

b)

Attach to VPCs and VPNs

c)

Transit Gateway can be shared with other account

d)

It's configured as full-mesh topology

10.

You are evaluating the security setting within the main company VPC. There are several NACLs and security groups to evaluate and possibly edit. What is true regarding NACLs and security groups?

a)

Network ACLs and security groups are both stateful

b)

Network ACLs and security groups are both stateless

c)

Network ACLs are stateless, and security groups are stateful

d)

Network ACLs are stateful, and security groups are stateless