Font size
WorksheetsAWS_IAM_Compute_Network_Storage
Total questions: 65
Worksheet time: 1hrs 5mins
Which of the following can be attached to EC2 Instances to store data?
Amazon Glacier
Amazon EBS Volumes
Amazon EBS Snapshots
Amazon SQS
Which of the following components of the Cloudfront service can be used to distribute contents to users across the globe.
Amazon VPC
Amazon Regions
Amazon Availability Zones
Amazon Edge locations
Your company is planning to move to the AWS Cloud. You need to give a presentation on the cost perspective when moving existing resources to the AWS Cloud. When it comes to Amazon EC2, which of the following is an advantage when it comes to the cost perspective.
Having the ability of automated backups of the EC2 instance, so that you don’t need to worry about the maintenance costs.
The ability to choose low cost AMI’s to prepare the EC2 Instances
The ability to only pay for what you use
Ability to tag instances to reduce the overall cost
Currently your organization has an operational team that takes care of ID management in their on-premise data center. They now also need to manage users and groups created in AWS. Which of the following AWS tools would they need to use for performing this management function.
AWS Config
AWS Cloud Trail
AWS Key Management Service (AWS KMS)
AWS Identity and Access Management (IAM)
Which of the following is the most secure way of giving access to AWS services to applications running on Ec2 instances?
Creating Service users
Creating service groups
Roles
Attaching policies to applications
TRUE or FALSE : By default a new user in IAM has permisiions to log in to the AWS Console.
TRUE
FLASE
Which of the following is not an IAM best practice?
Delete user accounts not in use
Attach policies to individual users
Manage permissions by adding users to groups
Enable MFA on user accounts
Wch of the following set of credentials are used to log in to AWS programmatically? (Choose two)
Username
Access Key
Password
Secret Key
Which of the following option describes the most common AWS billing model?
Daily Billing
Annual Billing
Pay as you go
Pay in advance
Availability Zones are
All together in one data centre
In geographically isolated data centers
In different data centres
None of the above
When a security group is created,what is the default behavior?
Allow all traffic inbound and allow all traffic outbound
Allow all traffic inbound and deny all traffic outbound
Deny all traffic inbound and allow all traffic outbound
Deny all traffic inbound and Deny all traffic outbound
All of these are IAM components except
Users
Organisations
Roles
Policies
Which parts of the AWS infrastructure support increased resilience?
Multiple Availability Zones within a region
Multiple AWS Direct Connect (DX) gateways within data center
Multiple regions distributed globally
Multiple edge locations within a region
You are getting a network timeout when trying to SSH into your EC2 instance
Your security group are misconfigured
Your key is missing permissions
The Linux instance is misconfigured
None of the above
Which component of the AWS global infrastructure supports the caching of content or faster access?
AWS Direct Connect locations
Edge locations
Regions
Availability Zones
A company has 70 employees divided into 10 departments. The IT administrator wants to customize each departments access to AWS. Which of the following option is most appropriate ?
Make each employee an AWS account root user
Create an IAM role for each department, and assign IAM users to the roles
Create a temporary role for each employee, and revise their access as needed
Create an IAM group for each department, and assign IAM users to the groups
An application you want to run on EC2 requires you to license it based on the number of physical CPU sockets and cores on the hardware you plan to run the application on. Which of the following tenancy models should you specify?
Dedicated host
Shared tenancy
Dedicated instance
Bring your own license
Which of the following commands will (when run from a shell session on an EC2 instance) display the instance ID?
curl http://169.254.169.254/latest/meta-data/instance-action
curl http://149.253.169.253/latest/meta-data/instanceaction
curl http://169.254.169.254/latest/meta/instance-action
curl http://169.254.169.254/meta-data/instance-action
Which three attributes of an incoming data packet are used by a security group to determine whether it should be allowed through? (Choose three.)
Network port
Source address
Datagram header size
Network protocol
What do you have to do to securely authenticate to the GUI console of a Windows EC2 session?
Use the private key of your key pair to initiate an SSH tunnel session.
Use the public key of your key pair to initiate an SSH tunnel session.
Use the public key of your key pair to retrieve the password you’ll use to log in.
Use the private key of your key pair to retrieve the password you’ll use to log in.
Which of the following is the greatest risk posed by using your AWS account root user for day-to-day operations?
There would be no easy way to control resource usage by project or class.
There would be no effective limits on the effect of an action, making it more likely for unintended and unwanted consequences to result.
Since root has full permissions over your account resources, an account compromise at the hands of hackers would be catastrophic
It would make it difficult to track which account user is responsible for specific actions.
An application you want to run on EC2 requires you to license it based on the number of physical CPU sockets and cores on the hardware you plan to run the application on. Which of the following tenancy models should you specify?
Dedicated host
Shared tenancy
Dedicated instance
Bring your own license
True/false: The EBS Lifecycle Manager can take snapshots of volumes that were once attached to terminated instances.
false
true
The sensitivity of the data your company works with means that the instances you run must be secured through complete physical isolation. What should you specify as you configure a new instance?
Dedicated Host Tenancy
Shared Tenancy
Dedicated Instance Tenancy
Isolated Tenancy
Which of the following EBS options will you need to keep your data-hungry application that requires up to 20,000 IOPS happy?
Cold HDD
General Purpose SSD
Provisioned-IOPS SSD
Throupth Optimized HDD
A database is running on an Amazon EC2 instance. The database software has a backup feature that requires block storage. What storage option would be the lowest cost option for the backup data?
Amazon Glacier
Amazon EBS Cold HDD Volume (sc1)
Amazon S3
Amazon EBS GP2
True/false: The EBS Lifecycle Manager can take snapshots of volumes that were once attached to terminated instances.
false
true
Which S3 encryption option does not require AWS persistently storing the encryption keys it uses to decrypt data?
SSE-CloudHSM
SSE-KMS
SSE-S3
SSE-C
True/false: Durability measures the percentage of likelihood that a given object will not be inadvertently lost by AWS over the course of a year.
true
false
You need a low-latency platform where you can store files to be mounted within multiple VPC-based instances. Which of the following AWS services is your best choice?
AWS Storage Gateway
AWS S3
Amazon Elastic File System
AWS Elastic Block Store
You want to encrypt the objects at rest in an S3 bucket using keys provided by AWS that also allows you to track related events. Which combination of tools should you use?
Server-side encryption with AWS KMS-Managed Keys
Service-side encryption with Amazon S3-Managed Keys
Client-side encryption with AWS KMS-Managed Keys
Client-side encryption with Amazon S3-Managed Keys
How can you apply transitions between storage classes for only certain objects within an S3 bucket?
By specifying particular prefixes when you define your lifecycle rules
This isn’t possible. Lifecycle rules must apply to all the objects in a bucket
By specifying particular prefixes when you create the bucket
By importing a predefined lifecycle rule template
Which of the following classes will usually make the most sense for long-term storage when included within a sequence of lifecycle rules?
Glacier
Reduced Redundancy
S3 One Zone-IA
S3 Standard-IA
Which of the following are the recommended methods for providing secure and controlled access to your buckets? (Choose two.)
S3 access control lists (ACLs)
S3 bucket policies
IAM policies
Security groups
Which of the following would be a good use case for Amazon Elastic File System?
You need to share files from a single host source among multiple EC2 instances within a VPC
You need an interface through which you can back up data archives from your local, on-premises infrastructure
You need a quick way to transfer large data archives to the cloud
You need a cost-effective place to store object data.
You are a solutions architect working for a large travel company that is migrating its existing server estate to AWS. You have recommended that they use a custom Amazon VPC, and they have agreed to proceed. They will need a public subnet for their web servers and a private subnet in which to place their databases. They also require that the web servers and database servers be highly available and that there be a minimum of two web servers and two database servers each. How many subnets should you have to maintain high availability?
2
3
4
6
You create a new subnet and then add a route to your route table that routes traffic out from that subnet to the Internet using an IGW. What type of subnet have you created?
Public Subnet
Private Subnet
What is the default limit for the number of Amazon VPCs that a customer may have in a region?
4
5
6
3
