Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Certified Developer - Associate (DVA-C02) - Practice Exam 4

Total questions: 65

Worksheet time: 3hrs 15mins

Name
Class
Date
1.

An organization is hosting their static website on S3, using a custom domain name. Users have started reporting that their web browsers are alerting them to the fact that the organization's website is "not secure" because it is not served via a secure HTTPS connection.

What is the easiest way to start serving the website via HTTPS?

a)

Add a CloudFront distribution in front of the S3 static website, which supports HTTPS with a custom domain name.

b)

Enable AES 256-bit default encryption on the S3 bucket, which ensures all content is delivered via HTTPS.

c)

Add an Application Load Balancer in front of the S3 bucket and enable SSL termination.

d)

Enable AWS Shield on the S3 bucket. Browsers automatically detect that Shield is enabled and report that the website is secure.

2.

A three-tier application consists of a presentation and application tier deployed on EC2 instances in a public VPC subnet, and a data tier hosted on an RDS database in a private VPC subnet. When attempting to establish a connection to the RDS database, the application times out. What could be the source of this problem?

a)

The database credentials are incorrect.

b)

The public subnet does not have an internet gateway configured.

c)

The database VPC security group is not configured to allow traffic from EC2 instances.

d)

VPC peering is not configured properly.

3.

As a developer, you have built a WordPress site. Traffic to the site has increased, and you have improved the site's functionality to meet the demand of your viewers since launch. Changes are coming frequently, and you are considering using AWS CloudFormation to automate the process of building test stacks, creating a change set, and executing the change set. How would you streamline this process in AWS most efficiently?

a)

Build your test stack, create a change set, and then execute the change set by manually interacting with AWS CloudFormation.

b)

Create a CodePipeline separated by three stages. For each stage, organize actions in a pipeline. Have CodePipeline complete all actions in a stage before the stage processes new artifacts.

c)

Create a Config rule that will look for changes within your CloudFormation stack that will trigger Lambda functions to execute actions based on the pipeline.

d)

Use Amazon Inspector to monitor your CloudFormation environment that will send an SNS notification to Lambda when a pipeline stage is complete. Subscribe the Lambda function to the SNS topic.

4.

An application developer finds that performing a scan operation on a large DynamoDB table is taking a long time to execute. What can be used to improve the performance and decrease the execution time of the scan operation?

a)

Use of parallel scans

b)

Use of projection expression

c)

Use of a filter expression

d)

Use of pagination

5.

You are developing a gaming website that stores all players' scores in a DynamoDB table. You're thinking of using a partition key of user_ID and a sort key of game_ID, as well as storing the user_score, which is the user's highest score for the game, and also a timestamp. You need to find a way to get the game IDs for a specific user ID where the score is over 50,000 points. Which of the following will allow you to find this information in the most efficient way?

a)

Scan the table and order by score.

b)

Use a global secondary index with a partition key of game_ID and a sort key of user_ID.

c)

Use a local secondary index with a partition key of user_ID and a sort key of user_score.

d)

Query the table using a partition key of user_ID and sort by game_ID.

6.

You have developed an application that automatically tracks home deliveries for online orders from a number of different websites. You would like your application to send metrics to CloudWatch any time a critical error occurs, and you want CloudWatch to notify you if more than two critical errors occur within a time period of 15 minutes. Which of the following CloudWatch actions can you use to configure this?

a)

Use GetMetricData to fetch metrics relating to critical errors from the application. Use PutMetricAlarm to create an alarm and notify you if the threshold is reached.

b)


Use InputMetricData to publish metric data relating to critical errors to CloudWatch. Use CreateMetricAlarm to create an alarm and notify you if the threshold is reached.

c)

Use PutMetricAlarm to publish metric data relating to critical errors and alert you if the threshold is reached.

d)

Use PutMetricData to publish metric data relating to critical errors to CloudWatch. Use PutMetricAlarm to create an alarm and notify you if the threshold is reached.

7.

Your website is hosted in AWS, and you have recently configured CloudFront to help improve performance. The website includes some basic interactive functionality, including the ability to complete a form to submit product reviews. After configuring CloudFront, you discover that visitors to your site are no longer able to submit reviews. Which of the following CloudFront-allowed HTTP methods should you enable?

a)

GET, HEAD, OPTIONS, PUT, POST, PATCH, DELETE.

b)

GET, HEAD, OPTIONS, PUT, POST, PATCH.

c)

GET, HEAD, OPTIONS.

d)

GET, HEAD.

8.

You want to implement an HTTPS CloudFront distribution with a custom domain name for your web application hosting static content. The backend compute is hosted in us-east-2. You would like to use AWS Certificate Manager for the certificate management. Which of the following options is a requirement?

a)

You must deploy the ACM cert in the us-east-1 Region.

b)

CloudFront automatically issues and manages TLS certs for custom domain names.

c)

You must deploy the ACM cert in both the us-east-1 and us-east-2 Regions.

d)

You must deploy the ACM cert in the us-east-2 Region.

9.

You are working on a Lambda function that requires 150 MB of storage space to store temporary files containing computational data. The data is accessed, updated, and modified frequently by the function while it completes processing. Which of the following data storage options will meet this requirement?

a)

DynamoDB

b)

EFS

c)

S3

d)

/tmp

10.

You are leading a small team of DevOps engineers. The team requires a secure and scalable mechanism for centrally storing and sharing compiled code and software packages, as well as a source-control solution for collaborating on their source code. Which of the following do you recommend?

a)

Use CodeArtifact to store the compiled code and software packages. Use CodeCommit as a source-control system to store the source code.

b)

Use CodeDeploy to store the compiled code and software packages. Use CodePipeline as a source-control system to store the source code.

c)

Use CodeCommit to store the compiled code and software packages. Use CodeArtifact as a source-control system to store the source code.

d)

Use CodePipeline to store the compiled code and software packages. Use CodeDeploy as a source-control system to store the source code.

11.

A business-critical application is deployed using CloudFormation. The team would like to prevent accidental deletion of the stack. How can this be achieved most efficiently?

a)

Set the DeletionProtection to True in the CloudFormation template.

b)

Set the DeletionPolicy to Retain in the CloudFormation template.

c)

Set stack termination protection to Enable.

d)

Create IAM policy with Effect of Deny for cloudformation:DeleteStack action.

12.

You are developing an application in API Gateway and need to categorize your APIs based on their status as: sandbox, test, or prod. You want to use a name-value pair system to define configuration attributes associated with deployment stages of your APIs, and use it in your API setup and mapping templates. What feature of API Gateway would you use to accomplish this task?

a)

Use the API Gateway console to create a canary release deployment.

b)

Use stage variables based on the API deployment stage to interact with different backend endpoints.

c)

Use environment variables based on the API deployment stage to interact with different backend endpoints.

d)

Use tags based on stages. The tag can be set directly on the stage of the API.

13.

A document management application stores a catalogue of documents, each uniquely identified by its Document Number. Each document is also described by additional attributes: Document Title, Publication Date, Publisher Name, Country of Origin, and Length. Functional requirements specify that the application should be able to produce a listing of all documents for each country of origin. What would be the optimal DynamoDB data model for this application, using high cardinality partition keys, so that the required queries can be efficiently be performed?

a)

Table Partition Key=Document Number; Table Sort Key=Document Title; GSI Partition Key=Country of Origin; GSI Sort Key=Publisher Name

b)

Table Partition Key=Document Number; Table Sort Key=Document Title; GSI Partition Key=Publication Date; GSI Sort Key=Country of Origin

c)

Table Partition Key=Publication Date; Table Sort Key=Document Number; GSI Partition Key=Publisher Name; GSI Sort Key=Country of Origin

d)

Table Partition Key=Document Number; Table Sort Key=Document Title; GSI Partition Key=Random Prefix; GSI Sort Key=Country of Origin

14.

Your application runs in an Auto Scaling group to scale based on user demand. The Auto Scaling group runs behind an Elastic Load Balancer (ELB). When you check the ELB logs, you notice that a number of instances are failing the health check during periods of high demand. New instances are launching, but they periodically fail health checks and subsequent instances are being launched, which is increasing costs. What would you do to fix this issue?

a)

Increase the health check grace period.

b)

Increase the cooldown period of the Auto Scaling group.

c)

Create a new Auto Scaling group behind a new ELB. The current ELB is malfunctioning.

d)

Use AWS Config to monitor instances with failed health checks to terminate them.

15.

You are developing a batch process job on Amazon EMR. The EMR instances need to access data stored in Amazon RDS in order to initialize batch processing. The application code ran properly during testing in a test environment, but is not able to properly retrieve data from the RDS instance in the production environment, as there appears to be no connectivity. How would you remedy this situation in the most effective manner?

a)

Edit the security group rules associated with the RDS and EMR instances to allow inbound/outbound access.

b)

This an AWS issue. AWS manages the underlying RDS and EMR infrastructure; they should be able to communicate with each other. Open a support case to resolve the issue.

c)

Create a new key pair associated with the EMR instance. The current key pair is invalid.

d)

Migrate the application to run on Amazon EC2 instead. Create an Auto Scaling group to scale the batch process when it exceeds a CPU threshold.

16.

An organization receives documents from its users, which must be put into an SQS queue, ready for processing. The documents range in size from 3 MB to 20 MB, and must always be encrypted at rest. What is the best way to queue these documents?

a)

Store the document in DynamoDB. Include a reference to the item in a SQS message.

b)

Store the document in S3 Glacier. Include a reference to the object in an SQS message.

c)

Encode the document with Base64 and attach it to the SQS message as a MessageAttribute.

d)

Store the document in S3 using server-side encryption with Amazon S3 managed keys (SSE-S3). Include a reference to the object in an SQS message.

17.

You are developing a web application that runs on EC2 instances. During load testing, the web URL of your application is responding with the following HTTP status code: 503 service unavailable. Which of the following could be the reason for receiving this error?

a)

The requested page does not exist. 

b)

The application may be experiencing a performance issue.

c)

You typed the URL incorrectly. 

d)

You are not authorized to access the URL.

18.

Your application is running on EC2 and sending metrics to CloudWatch. You would like to create a single custom view to display the data relating to the production instances of your application so that you can view application health at a glance. How can you do this using CloudWatch?

a)

Create a dashboard to display the metrics that you would like to view. Use a dimension to filter the results to only show the EC2 instances that are in your production environment.

b)

Create a dashboard to display the metrics that you would like to view. Use a namespace to filter the results to only show the EC2 instances that are in your production environment.

c)

Create a namespace to display the metrics that you would like to view. Use a dimension to filter the results to only show the EC2 instances that are in your production environment.

d)

Create a namespace to display the metrics that you would like to view. Use a filter expression to filter the results to only show the EC2 instances that are in your production environment.

19.

You have a load balancer configuration that you use for most of your CloudFormation stacks. This load balancer always sits in front of your application running on EC2, as it has the important function of forwarding HTTPS requests on port 443 to HTTP requests on port 80 on the instance. As demand for the application grows, you need to reuse this load balancer configuration in multiple other deployments of the application, and you need to use CloudFormation to do this in an automated way. What is the most efficient way to deploy the load balancer configuration?

a)

Use AWS CloudFormation nested stacks by creating a dedicated template for the load balancer and refer to that template within other templates.

b)

Use AWS CloudFormation direct updates to quickly deploy the same load balancer configuration in multiple environments.


c)

Use AWS CloudFormation change sets to change the load balancer configuration based on Region/Availability Zone where you want to deploy a copy of the application.

d)

Instead of CloudFormation, use Lambda. Let the load balancer trigger a Lambda function that has the infrastructure code embedded to deploy the configuration when prompted.

20.

You are working on a new distributed application that will ingest large volumes of click data from various external sources and will process this data through multiple business rules and transformations. The solution requires the business rules to run in a very particular sequence and to handle reprocessing of data if errors occur. Your CTO has requested that the solution must be scalable, have the ability to handle errors, and require the least possible maintenance. Which service can you use to manage and automate the workflow of this application?

a)

Step Functions

b)

EventBridge

c)

SQS

d)

API Gateway

21.

A developer has written the following IAM policy to configure access to S3:

(See figure)

What access does the policy allow in relation to s3:GetObject and s3:PutObject actions?"

a)

All actions are denied for objects in the corporate_bucket bucket.

b)

GetObject and PutObject are allowed for all objects in the corporate_bucket bucket except for objects that start with sensitive.

c)

All actions are denied for all objects in the corporate_bucket bucket except objects that start with sensitive, which allow GetObject and PutObject actions.

d)

GetObject and PutObject are allowed for all objects in the corporate_bucket bucket.

22.

You are working on a project to migrate a legacy application that runs on virtual machines in your own data center. The application consists of a static website, business logic running on application servers, which store their data in a MySQL database. Additional requirements of the migration project are that you must ensure that the database is resilient to hardware failures, including data center failures, and you must recommend a cost-effective and scalable solution for the website. Which of the following architectures would you recommend for this application?

a)

Use Route 53 to host the static web content, use EC2 instances behind an Application Load Balancer for the application servers, and use an RDS for the database.

b)

Use S3 to host the static web content, use EC2 instances behind an Application Load Balancer for the application servers, and use an RDS multi-AZ deployment for the database.

c)


Use an RDS multi-AZ deployment for the database, and use EC2 instances behind an Application Load Balancer for the web and application servers.

d)

Use S3 to host the static web content, use EC2 instances behind an Application Load Balancer for the application servers, and use an RDS deployment for the database. Configure a read replica to provide resilience and failover for the database.

23.

A Lambda function needs to process item-level changes to items stored in a DynamoDB table. Which of the following options will enable the function to be triggered when an item in the table is updated or added?

a)


Enable DynamoDB Streams on the table. Configure the DynamoDB stream as a trigger for the Lambda function.

b)

Configure the Lambda function to periodically check the DynamoDB table for updates and changes.

c)

Use EventBridge to trigger the function based on item-level changes in the DynamoDB table.

d)

Attach a Kinesis stream to the DynamoDB table, and use the stream to stream the item-level changes to the Lambda function.

24.

A CustomerOrders DynamoDB table contains attributes, Customer Name (PK), Order Item, and Cost. What DynamoDB operation would be used to find all orders with cost greater than $10?

a)

Query operation with --filter-expression parameter

b)

Scan operation with --filter-expression parameter

c)

Scan operation with --projection-expression parameter

d)

Query operation with --key-condition-expression parameter

25.

You are responsible for developing an application that processes IoT data generated by car number plate recognition systems used in a number of large shopping mall parking lots. Visitors are charged a premium for parking, according to how long their vehicle remained in the parking lot. The application runs as a Lambda function that receives the IoT data through an exposed REST API. The IoT devices add a unique identification number to each data record that is included in the API call. It is important to ensure that no records are missed, because that could result in customers being billed incorrectly or not at all. During periods of peak activity, the IoT devices in the remote locations have been observed to send duplicate records to the API, causing records to be processed more than once, and resulting in some customers receiving multiple charges. Duplicate charges need to be avoided because customers have been complaining and asking for refunds. Which of the following would you implement to meet the requirements of this application?

a)

Before each record is processed, store the unique identifier in /tmp. Configure Lambda to check if the record has already been processed before completing processing.

b)

Create an RDS for PostgreSQL database instance. Store the unique identifier for each request in a database table. Modify the Lambda function to check the table for the identifier before processing the request.

c)

Create a DynamoDB table. Before processing each record, store its unique identifier in the table. Configure the Lambda function to check the table for the identifier after processing the next record.

d)

Create a DynamoDB table. Before processing a record, configure the Lambda function to do a ConditionalWrite check for the record's unique identifier. If it's not found, store the identifier in the table and then proceed with processing the record.

26.

A company security team wants to implement a solution for securely storing RDS database credentials. The solution should provide automatic rotation of database credentials. What AWS service can the team use to meet these requirements?

a)

AWS Resource Access Manager

b)

AWS Systems Manager Parameter Store

c)

AWS Secrets Manager

d)

AWS Key Management Service

AnswerFlag for Review

27.

A high-traffic news website is experiencing performance issues during peak times. Investigation reveals that the top news stories are impacting the database performance. Top news stories must be updated every 15 minutes. What would be an optimal and non-intrusive solution to fix this performance problem?

a)

Implement ElastiCache in front of the database.

b)

Create a CloudFront distribution. Configure TTL to 900 seconds.

c)

Create read replicas of the database. Distribute the read traffic to the read replicas.

d)

Upgrade the database instance to a more powerful instance type.

28.

You have developed an application to run on Amazon EC2. Users have increased, and you've found latency issues for users from various geographic locations. You decide to create a CloudFormation template of the application's environment in order to streamline application launch in other AWS Regions to improve performance for users. When creating the CloudFormation template, what is one thing you have to ensure for the resources to launch successfully?

a)

Ensure the tags of the resources are not the same in the new Region, as they are a universal namespace.

b)

This is not possible. CloudFormation templates can be launched only in a single Region.

c)

Create and validate the right IAM roles in the template in the desired Region.

d)

Ensure the AMIs referenced in the template correspond to the AMI IDs in the desired Region.

29.

You are developing an application that deals with sensitive financial data. The data is stored in RDS. Every month, a team of business analysts use the data to generate financial reports that are stored in S3. The security architect at your company has requested that the reports must be encrypted using an encryption key that is automatically rotated annually. Which of the following options is the best way to configure this?

a)

Configure SSE-KMS encryption for the S3 bucket. Enable automatic key rotation of the KMS key.

b)

Use S3 default encryption. Configure a Time to Live (TTL) parameter on the key to be one year from creation date. After the TTL has expired, create a new key.

c)

Configure SSE-KMS encryption for the S3 bucket. Create a Lambda function that automatically rotates the key material of your KMS key on an annual basis.

d)

Use S3 default encryption. Configure EventBridge to send an SNS notification on the anniversary of the key creation date to remind the team to rotate the key material.

30.

You have developed a CloudFormation stack in the AWS Management Console. You have a few CloudFormation stacks saved in the Region in which you are operating in. When you launch your stack that contains many EC2 resources, you receive the error Status=start_failed. How would you troubleshoot this issue?

a)

Save the template via the AWS CLI.

b)

Use the Support Center in the AWS Management Console to request an increase in the number of CloudFormation stacks.

c)

Verify that you didn't reach a resource limit, then use the Support Center in the AWS Management Console to request an increase in the number of EC2 instances.

d)

Wait a few minutes before saving the template and retry the process.

31.

You are reviewing an S3 bucket policy which includes the following statement:

(See figure)

Which of the following is correct in relation to this bucket policy?

a)

GetObject requests that use HTTPS will be denied.

b)

GetObject requests that do not use server-side encryption will be denied.

c)

GetObject requests that do not use KMS encryption will be denied.

d)

GetObject requests that do not use HTTPS will be denied.

32.

You are a developer working on a new online hotel booking application that allows users to search for hotels based on location and facilities. The application runs on EC2 instances, with persistent data stored in RDS. After searching for a hotel, customers have the ability to sort the results based on the distance from a particular town or city, by price, and rank the results by popularity. Customers are able to store their credit card details in their account for faster payment. You have noticed that certain destinations and hotels are more popular than others and certain searches are run repeatedly, as multiple customers run searches simultaneously. During performance testing, it was found that searches are taking up to 5 seconds to complete, which is significantly slower than your competitors. Your CTO has asked you to propose a solution that will speed up the searches, support sorting and ranking the search results, and provide encryption to protect sensitive customer data. Which of the following do you propose?

a)

Move the data to S3 with default encryption enabled. Use Athena to query, sort, and rank the data.

b)

Configure ElastiCache for Redis to cache the frequently accessed queries, sort and rank the data, and provide encryption for sensitive data. Update the application servers to query the ElastiCache cluster instead of the database.

c)

Configure multi-AZ for the RDS instance to increase database capacity, use Athena to sort and rank the data, and enable encryption on the database to protect sensitive customer data.

d)

Configure RDS Proxy for the RDS instance to increase database capacity, and update the application servers to query the RDS Proxy. Use Lambda to sort and rank the data, and enable default encryption on the database to protect sensitive customer data.

33.

A developer has just finished amending a Lambda function. Originally, the function ran outside of a VPC, but after the update, it now connects to a VPC. Since the change, part of the function that accesses a HTTPS endpoint on a third-party website has stopped working. What is the most likely cause of the Lambda function no longer being able to access the third-party endpoint?

a)

It is not possible to access external web services from a Lambda function that is connected to a VPC. The amend should be rolled back.

b)

The third-party web server does not support access from a Lambda function that is connected to a VPC. Contact the third party to request they create a VPC endpoint.

c)

The Lambda function no longer has any route out to the internet. A NAT Gateway and associated route should be added.

d)

The Lambda's execution role does not have the required permissions. Attach the AWS-managed AWSLambdaInternetAccess policy to the Lambda's execution role.

34.

You are designing a new product catalog application to support an e-commerce website that sells sporting equipment online. You need to create a solution for storing product details like product ID numbers, sizes, and specifications, as well as images showing the product in action. Customers visiting your site will need the ability to search for a product, read the specification information, and click on an image. The solution needs to be both cost effective and scalable. Which of the following solutions do you recommend?

a)

Store the images and product specification information in DynamoDB.

b)

Store the product images in EFS. Store the product specification information in RDS, including URLs for the relevant images stored in EFS.

c)

Store the images and product specification information in S3, with static website hosting enabled.

d)

Store the product images in S3. Store the product specification information in DynamoDB, including object keys for the relevant images stored in S3.

35.

While testing a new web application, the application endpoint URL that you are trying to connect to is responding with the following HTTP status code: 404 File not found. Which of the following options could be the reason for receiving this error? 

a)

The application is down. 

b)

You made a mistake when typing the URL.

c)

The server is experiencing performance issues. 

d)

The application is experiencing an internal failure. 

36.

You are responsible for configuring an API Gateway REST API. Customers call the API through a frontend UI, and the application uses Cognito to authenticate account holders. You now need to deploy a new version of the API, which includes new endpoints and changes to the back end integrations. The teams that are responsible for conducting testing in your organization have requested beta access to the new API, and you would like to provide this without affecting your customers, who need to continue using the current version. Which solution will meet these requirements with the least operational overhead?

a)

Define an environment variable that determines which version of the API to route traffic to based on the request header.

b)

Define a test stage on the API Gateway API. Instruct the test team to point to the test stage.

c)

Define a new API Gateway API that points to the new API application code. Instruct the test team to point to the new API.

d)

Define a new API Gateway API that points to the new API application code. Use Route 53 to route test team requests to the new API.

37.

Your website has been migrated to AWS, and you are using CloudFront to improve the performance for your users. However, when you try to access the website using the CloudFront URL, some of the functionality of your website, including the signup form, is broken. When you check the allowed HTTP methods in the CloudFront console, which of the following options should you select to try and fix the problem?

a)

GET, HEAD

b)

GET, HEAD, OPTIONS

c)

GET, HEAD, OPTIONS, PUT, POST, PATCH, DELETE

d)

GET, HEAD, OPTIONS, POST

38.

A developer is running an application on an Amazon EC2 instance that requires access to an Amazon S3 bucket. An administrator creates a role that includes policies that grant read permissions to the bucket. The developer then launches an Amazon EC2 instance with the role attached. What additional step is required for the application running on the instance to access the objects in the bucket?

a)

The developer must share their credentials with the bucket policy.

b)

No other steps are necessary. The application running on the instance will be able to access the bucket.

c)

Create an IAM policy that provides the developer permissions to access the bucket. Attach the policy to the developer's IAM user.

d)

The administrator must grant the developer permissions to access the bucket.

39.

You require a data storage solution for an application running on EC2. The data running on the application is not well-structured to fit into a defined schema. Even so, the schema would change very often, as data is dependent on users. Which choice of database solution would best support your application?

a)

Use AWS IoT-connected devices to interact easily and securely with AWS Lambda, Amazon Kinesis, and Amazon S3.

b)

Use an RDBMS solution, such as Amazon RDS, to implement a SQL-based relational database solution for your application.

c)

Use a NoSQL database, such as Amazon DynamoDB, that can be used as a data store for your application.

d)

Use Amazon Kinesis services to be able to collect, store, and process your users' data continuously.

40.

You are running an application on an EC2 instance that needs to create S3 objects and modify CloudWatch alarms. What is the best way to deploy this instance?

a)

Create an IAM role with the proper permissions to access S3 and CloudWatch. Store temporary credentials for the role in Secrets Manager. Configure the instance to execute tasks using the credentials stored in Secrets Manager.

b)

Assign an S3 policy to one IAM user and a CloudWatch policy to another IAM user. Have the instance execute tasks as the appropriate IAM user for the given task.

c)

Create an IAM role with the proper permissions to access S3 and CloudWatch. Assign the IAM role to the instance at launch time.

d)

Assign an S3 policy to one IAM role and a CloudWatch policy to another IAM role. Assign both IAM roles to the EC2 instance at deployment time.

41.

An application connects to an external third-party service with API keys being managed by AWS Secrets Manager. The development team uses CodeBuild for source code compilation activities in their CI/CD process. Where should the reference to the third-party service API keys be specified?

(Choose2)

a)

CodeBuild environment variable

b)

Buildspec file

c)

AppSpec file

d)

CloudFormation template

42.

You have created a DynamoDB table for your application with one partition key and no local secondary index. The table has the following attributes:

`AccountID` (partition key)

`AccountName`

`CustomerName`

`ReportingPeriod`

`TotalRevenue`

You have an application running on EC2 that displays revenue data as a dashboard for your sales organization. The dashboard requires a view of total revenue over multiple reporting periods by customer name as a readable format. What secondary index will you need to add to your table?

a)

Global secondary index with a partition key of CustomerName and sort key of ReportingPeriod; project the TotalRevenue attribute

b)

Local secondary index with a partition key of CustomerName and sort key of ReportingPeriod; project the TotalRevenue attribute

c)

Global secondary index with a partition key of ReportingPeriod and sort key of CustomerName; project the TotalRevenue attribute

d)


Local secondary index with a partition key of ReportingPeriod and sort key of CustomerName; project the TotalRevenue attribute

43.

Your Lambda compute intensive function is configured with the default memory allocation of 128 MB. During testing, you discover that the function does not respond as quickly as you expect, even thought the operations it is performing are not considered to be memory intensive. How can you improve the function performance?

a)

Increase the duration of the function timeout.

b)

Increase the function memory.

c)

Increase the function CPU count.

d)

Increase the concurrency limit.

44.

An enterprise company is migrating their ERP system from on-premises to AWS. The ERP system consists of a stateful web application operating over HTTP. Various components of the system are being implemented as microservices utilizing Docker. What load balancer configuration would be a suitable solution for the ERP system migration to AWS?

a)

Classic Load Balancer with sticky sessions

b)

Application Load Balancer with sticky sessions.

c)

Route53 with a CNAME and a CloudFront distribution.

d)

Network Load Balancer with an Elastic IP.

45.

You are a developer for a news, entertainment, lifestyle, and fashion website. User traffic has steadily increased month over month, and you are now tasked with cost optimizing the website. The website is currently served from an EC2 instance that is part of an Auto Scaling group behind an Elastic Load Balancer. Your manager and CTO have approved a complete re-structuring of the website's architecture in order to accommodate future growth. How would you optimize your application in the most cost-effective way?

a)

Edit the scale-in policy within Auto Scaling to terminate instances aggressively when demand is low.

b)

Move the website to a serverless application. Use S3 to host the website. Use a combination of Lambda and API Gateway to support dynamic API requests.

c)

Move the application on-premises. You'll be able to fully manage the application and purchase additional servers when appropriate.

d)

Implement CloudFront in front of the EC2 instance as the origin.

46.

You're part of a developer team building an application that requires access to S3. Everyone on your team requires the same IAM permissions. As your team grows, how would you manage IAM policies and provide access to the right AWS resources in the most efficient manner?

a)

Create an IAM group called Developers. Attach an IAM policy to the group with the appropriate permissions. Associate your IAM user and your team members' users to the group. Add new team members to the group as appropriate.

b)

Create an Amazon Cognito user pool for each user and a corresponding S3 bucket. Grant S3 bucket GET requests for each bucket to each Cognito user. Require users to log into the console using their Cognito credentials.

c)

Create one IAM role with the necessary permissions. Have all team members log into the AWS Management Console using that role. Rotate the password regularly.

d)

Create IAM users for each team member. Attach an IAM policy to each user. Edit the IAM policy for each user adhering to the principle of least privilege. Create new IAM policies for new team members as appropriate.

47.

You are working on a new application that will use Lambda, API Gateway, and DynamoDB. Your CTO has mandated that all AWS resources must be provisioned using an Infrastructure-as-Code approach. You have also been asked to store the code in a central repository for collaboration and source control. Which of the following should you do to meet this requirement?

a)

Use CloudFormation to define the AWS resources. Store the code in CodePipeline.

b)

Use AWS SAM to define the AWS resources. Store the code in CodeCommit.

c)

Use the Cloud Development Kit to define the AWS resources. Store the code in S3.

d)

Use Image Builder to define the AWS resources. Store the code in CodeDeploy.

48.

You have developed a Lambda function that is triggered by an application running on EC2. The Lambda function currently has an execution role that allows read/write access to EC2, and also has the AWSLambdaBasicExecutionRole managed policy attached. After some architectural changes in your environment, the Lambda now needs to access data stored in S3. What changes are required for your Lambda function to fulfill this new task of accessing data in S3?

a)

Attach a resource-based policy to the Lambda function that will allow it to access the S3 bucket resource.

b)


Create a new Lambda function with an execution role allowing read/write access to EC2 and S3.

c)

Add permissions to the function's execution role to grant it the necessary access to S3 in IAM.

d)

No changes are required. The function has all the permissions it needs to access S3.

49.

A developer is looking to implement a load balancing solution for a web-based, service-oriented application deployed in Amazon EC2. The solution must support path-based routing and traffic encryption between the load balancer, and the clients must be encrypted. What is the most performant method to achieve these requirements?

a)

Use a Network Load Balancer. Deploy SSL certificates on the Network Load Balancer.

b)

Use an Application Load Balancer. Deploy SSL certificates on the Application Load Balancer.

c)

Use an Application Load Balancer. Deploy SSL certificates on the EC2 instances.

d)

Use a Network Load Balancer. Deploy SSL certificates on the EC2 instances.

50.

You have several CloudWatch log groups, and Lambda functions send logs to them. You need to use a tool to quickly search and analyze the log data in the log streams. The tool should automatically discover information in the Lambda logs such as the timestamp, max memory used, and execution duration. It should also help you to perform the query using simple and prebuilt query languages. Which tool is the best one for you to choose?

a)

Stream the log data to an Amazon Kinesis stream, and perform real-time queries or analysis in the stream.

b)

Use Amazon Athena to run queries on the log streams. The query language of Athena is based on SQL.

c)

Use CloudWatch Logs Insights to select the log groups and perform queries.

d)

Export the log data to an Amazon Elasticsearch service. Use Elasticsearch to perform queries or analysis.

51.

You are designing an online auction application that runs on multiple EC2 instances that read and write data to an RDS multi-AZ database. You have recently added new application servers to cope with an increase in customer traffic. After a few weeks, you have noticed that the application is running slowly again. Upon investigation, you see that the application servers are constantly opening and closing database connections, which is adding latency and slowing down your application. In addition to this, the application servers are consistently operating at over 90% CPU utilization. The application support team has requested to double the number of application servers in preparation for the holiday period, which is expected to be the busiest time of the year. However, you are concerned that by adding additional applications servers, the RDS database will not be able to cope with the increased number of connections. Which of the following should you implement in order to scale this application?

a)

Add an additional host to the RDS cluster.

b)

Configure a read replica to handle the database reads.

c)

Scale the database by increasing the size of the underlying instance.

d)

Configure RDS Proxy to pool and share database connections.

52.

A developer has created an S3 bucket to store sensitive files. They would like to configure the S3 bucket to only serve content over HTTPS/SSL and explicitly deny all unencrypted HTTP access. They would also like to enforce that server-side encryption is always used. Which of the following should they include in the bucket policy in order to configure this?

(Choose2)

a)

The bucket policy should deny traffic that meets the following condition: "aws:SecureTransport": "false".

b)

The bucket policy should deny traffic that meets the following condition: "s3:x-amz-server-side-encryption": "true".

c)

The bucket policy should deny traffic that meets the following condition: "s3:x-amz-sse-encryption": "false".

d)

The bucket policy should deny traffic that meets the following condition: "aws:SSLTransport": "true".

e)

The bucket policy should deny traffic that meets the following condition: "s3:x-amz-server-side-encryption": "false".

53.

As a developer, you are working on adding new features to an existing Lambda function. However, you need to have the ability to return to the previous version of your function code with the least operational overhead. Which of the following should you implement in order to reference the previous version of the function, should you need to?

a)

Use an environment variable to reference the different versions of your code.

b)

Reference a different deployment package in the different versions of your code.

c)

Use a function alias to reference the different versions of your code.

d)

Create two Lambda layers and attach a different layer to each version of your code.

54.

You are working on two CloudFormation templates. The first, named mynetwork.yml, creates a new VPC with a public subnet and security group that allows traffic from port 443 from the internet. The second template, named myinstances.yml, will launch a number of EC2 instances into the VPC and public subnet created by the first template, and it will also associate the security group. How can you share the VPC, public subnet, and security group ID so that they can be used in your second template?. (Choose 2)

a)

Use the Fn:OutputValue function in myinstances.yml.

b)

Use the Export field in the Output section of mynetwork.yml.

c)

Use the Import field in the Input section of myinstances.yml.

d)

Use the Fn::ImportValue function in myinstances.yml.

55.

You are responsible for supporting a popular e-commerce website with an international customer base. You recently configured CloudFront to ensure good performance for all customers, however customers are now complaining that they are unable to contact the customer service team using the form that appears on your site. Which of the following CloudFront-allowed HTTP methods need to be enabled in order for the customer service form to operate correctly?

a)

GET, HEAD, OPTIONS

b)

GET, HEAD, OPTIONS, PUT, POST, PATCH, DELETE

c)

GET, HEAD, OPTIONS, PUT, POST, PATCH

d)

GET, HEAD

56.

As a developer, you have been asked to help to scale out an existing an application to run in multiple AWS Regions. The application runs on a fleet of EC2 instances located in us-east-1. The solutions architect has requested that you use the same Amazon Machine Image with the latest security updates and create a new application stack in us-east-2. The security architect has requested that all AMIs that are in use in the company must be encrypted. However, after checking which AMI was used in us-east-1, you discover that the AMI that was used was not encrypted. Which of the following should you implement in order to meet the requirements of the project?

a)

Delete the unencrypted AMIs. Copy the AMI to us-east-2. Enable KMS encryption on the unencrypted AMIs. Add the latest security updates to the AMI.

b)

Use CloudFormation to create a new AMI in us-east-2 with the security updates included. Specify that the new AMI will be encrypted. Delete the original unencrypted AMIs.

c)

Copy the unencrypted AMI to us-east-2. Add the latest security updates and check that the AMI boots successfully. Then, enable encryption on the new AMI.

d)

Use EC2 Image Builder to create new AMIs with the security updates included. Specify that the new AMI will be encrypted. Configure the new AMIs to be distributed to us-east-2. Delete the original unencrypted AMIs.

57.

You are deploying an application that connects to a third-party provider using API credentials that the provider has shared with you. You need to find a way to make the API credentials available to all of the application servers that connect to the third-party provider. Which of the following do you suggest so that the application servers can securely access the credentials?

a)

Store the API credentials in an S3 bucket.

b)

Store the API credentials in API Gateway.

c)

Store the API credentials in Secrets Manager.

d)

Store the API credentials in DynamoDB.

58.

A developer needs to replace an item that is stored in an existing DynamoDB table. Which of the following DynamoDB API calls will they need permissions for to enable them to successfully replace the item?

a)

UpdateItem

b)

UpdateTable

c)

DynamoDB full access

d)

PutItem

59.

You work on a busy DevOps team, and the team would like to find a solution for storing and sharing project artifacts (including compiled code, binaries, and software libraries) so that everybody on the team has access to the correct versions needed to build the applications the team helps support. Which of the following AWS services is the best choice?

a)

S3

b)

CodeCommit

c)

EFS

d)

CodeArtifact

60.

A developer is attempting to use the AWS CLI to get the attributes for an item stored in DynamoDB. The developer knows the primary key of the item and would like to retrieve the correct item from DynamoDB using the primary key. However, when they attempt to run the CLI command, they receive a "permission denied" message. What might the problem be?

a)

The developer does not have IAM permissions to run the AWS CLI.

b)

The developer does not have administrator access on their local machine.

c)

The developer does not have IAM permission to run ListTables.

d)

The developer does not have IAM permissions to run GetItem.

61.

Your organization wants you to lead a development project that will perform real-time processing. The application requires the analytics and field teams to respond promptly to emerging situations based on server activity, website clicks, geolocation of devices, people, and service usage. As the development lead, what combination of services would you recommend to build out this project most efficiently and cost effectively?

a)

Use Amazon Aurora to store data in real time. Aurora will automatically replicate the data in multiple Availability Zones. Build an application on EC2 that users can call using APIs to retrieve the relevant information they need.

b)

Store all data in an S3 bucket with the correct prefixes. Develop Lambda functions for each prefix that will routinely scan and extract necessary information to another S3 bucket that will be the source for an Amazon QuickSight dashboard.

c)

Use Amazon Kinesis to capture and store streaming data. Process streaming data with Lambda.

d)

Store the data on Amazon Redshift. Run queries on the Redshift cluster regularly to refresh a dashboard built on Amazon QuickSight.

62.

The GetItem operation reads data from DynamoDB tables. Amazon DynamoDB returns all the item attributes by default. What can you use to get only some, rather than all of the attributes?

a)

Use filter expression.

b)

Use projection expression.

c)

Use pagination.

d)

Use parallel scan.

63.

A developer is creating a CloudFormation template to deploy an application stack. The administrator password for the application needs to be configured at CloudFormation runtime. What CloudFormation section should be used for this requirement?

a)

Mappings

b)

Resources

c)

Metadata

d)

Parameters

64.

You are building an application that generates a new online word puzzle every day and allows players to share their scores on social media. You would like to configure your application to send custom metric data to CloudWatch. Which of the following CloudWatch actions could you use to achieve this?

a)

PutMetricData

b)

PutMetricAlarm

c)

ImportMetricData

d)

PutMetricStream

65.

Your application on EC2 must write to an Aurora cluster to store user and purchasing data. Your CISO implements a new company-wide policy that requires all AWS credentials to be encrypted and rotated monthly. How would you fulfill the new security policy with minimum administrative burden?

a)

Associate an IAM user with the application. Enroll that user with your Active Directory domain to use AD authorization.

b)

Attach an IAM role to the instance that allows your application to write to your Aurora cluster.

c)

Encrypt the Aurora clusters' credentials using SHA-256 hash function in the application code and schedule a cron job to rotate them monthly.

d)

Allow the application to fetch the credentials from an S3 bucket with SSE-S3. Upload new credentials monthly.