Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

awss

Total questions: 390

Worksheet time: 4hrs 33mins

Name
Class
Date
1.

A geological research agency maintains the seismological data for the last 100 years. The data has a velocity of 1GB per minute. You would like to store the data with only the most relevant attributes to build a predictive model for earthquakes.

What AWS services would you use to build the most cost-effective solution with the LEAST amount of infrastructure maintenance?

a)

Ingest the data in Amazon Kinesis Data Streams and use an intermediary AWS Lambda function to filter and transform the incoming stream before the output is dumped on Amazon S3

b)

Ingest the data in a Spark Streaming Cluster on Amazon EMR and use Spark Streaming transformations before writing to Amazon S3

c)

Ingest the data in Amazon Kinesis Data Analytics and use SQL queries to filter and transform the data before writing to Amazon S3

d)

Ingest the data in Amazon Kinesis Data Firehose and use an intermediary AWS Lambda function to filter and transform the incoming stream before the output is dumped on Amazon S3

2.

A media agency stores its re-creatable assets on Amazon Simple Storage Service (Amazon S3) buckets. The assets are accessed by a large number of users for the first few days and the frequency of access falls down drastically after a week. Although the assets would be accessed occasionally after the first week, but they must continue to be immediately accessible when required. The cost of maintaining all the assets on Amazon S3 storage is turning out to be very expensive and the agency is looking at reducing costs as much as possible.

As an AWS Certified Solutions Architect – Associate, can you suggest a way to lower the storage costs while fulfilling the business requirements?

a)

Configure a lifecycle policy to transition the objects to Amazon S3 Standard-Infrequent Access (S3 Standard-IA) after 7 days

b)

Configure a lifecycle policy to transition the objects to Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA) after 30 days

c)

Configure a lifecycle policy to transition the objects to Amazon S3 Standard-Infrequent Access (S3 Standard-IA) after 30 days

d)

Configure a lifecycle policy to transition the objects to Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA) after 7 days

3.

A healthcare startup needs to enforce compliance and regulatory guidelines for objects stored in Amazon S3. One of the key requirements is to provide adequate protection against accidental deletion of objects.

As a solutions architect, what are your recommendations to address these guidelines? (Select two) ?

a)

Establish a process to get managerial approval for deleting Amazon S3 objects

b)

Change the configuration on Amazon S3 console so that the user needs to provide additional confirmation while deleting any Amazon S3 object

c)

Create an event trigger on deleting any Amazon S3 object. The event invokes an Amazon Simple Notification Service (Amazon SNS) notification via email to the IT manager

d)

Enable multi-factor authentication (MFA) delete on the Amazon S3 bucket

e)

Enable versioning on the Amazon S3 bucket

4.

A development team requires permissions to list an Amazon S3 bucket and delete objects from that bucket. A systems administrator has created the following IAM policy to provide access to the bucket and applied that policy to the group. The group is not able to delete objects in the bucket. The company follows the principle of least privilege."Version": "2021-10-17", "Statement": [ { "Action": [ "s3:ListBucket", "s3:DeleteObject" ], "Resource": [ "arn:aws:s3:::example-bucket" ], "Effect": "Allow" } ]

a)

{ "Action": [ "s3:DeleteObject" ], "Resource": [ "arn:aws:s3:::example-bucket*" ], "Effect": "Allow" }

b)

{ "Action": [ "s3:*" ], "Resource": [ "arn:aws:s3:::example-bucket/*" ], "Effect": "Allow" }

c)

{ "Action": [ "s3:DeleteObject" ], "Resource": [ "arn:aws:s3:::example-bucket/*" ], "Effect": "Allow" }

d)

{ "Action": [ "s3:*Object" ], "Resource": [ "arn:aws:s3:::example-bucket/*" ], "Effect": "Allow" }

5.

A telecom company operates thousands of hardware devices like switches, routers, cables, etc. The real-time status data for these devices must be fed into a communications application for notifications. Simultaneously, another analytics application needs to read the same real-time status data and analyze all the connecting lines that may go down because of any device failures.

As an AWS Certified Solutions Architect – Associate, which of the following solutions would you suggest, so that both the applications can consume the real-time status data concurrently?

a)

Amazon Simple Notification Service (SNS)

b)

Amazon Simple Queue Service (SQS) with Amazon Simple Notification Service (SNS)

c)

Amazon Kinesis Data Streams

d)

Amazon Simple Queue Service (SQS) with Amazon Simple Email Service (Amazon SES)

6.

An IT company wants to review its security best-practices after an incident was reported where a new developer on the team was assigned full access to Amazon DynamoDB. The developer accidentally deleted a couple of tables from the production environment while building out a new feature.

Which is the MOST effective way to address this issue so that such incidents do not recur?

a)

Only root user should have full database access in the organization

b)

The CTO should review the permissions for each new developer's IAM user so that such incidents don't recur

c)

Remove full database access for all IAM users in the organization

d)

Use permissions boundary to control the maximum permissions employees can grant to the IAM principals

7.

A company uses Amazon DynamoDB as a data store for various kinds of customer data, such as user profiles, user events, clicks, and visited links. Some of these use-cases require a high request rate (millions of requests per second), low predictable latency, and reliability. The company now wants to add a caching layer to support high read volumes.

As a solutions architect, which of the following AWS services would you recommend as a caching layer for this use-case? (Select two)

a)

Amazon Relational Database Service (Amazon RDS)

b)

Amazon OpenSearch Service

c)

Amazon Redshift

d)

Amazon ElastiCache

e)

Amazon DynamoDB Accelerator (DAX)

8.

The product team at a startup has figured out a market need to support both stateful and stateless client-server communications via the application programming interface (APIs) developed using its platform. You have been hired by the startup as a solutions architect to build a solution to fulfill this market need using Amazon API Gateway.

Which of the following would you identify as correct?

a)

Amazon API Gateway creates RESTful APIs that enable stateful client-server communication and Amazon API Gateway also creates WebSocket APIs that adhere to the WebSocket protocol, which enables stateful, full-duplex communication between client and server

b)

Amazon API Gateway creates RESTful APIs that enable stateless client-server communication and Amazon API Gateway also creates WebSocket APIs that adhere to the WebSocket protocol, which enables stateless, full-duplex communication between client and server

c)

Amazon API Gateway creates RESTful APIs that enable stateless client-server communication and Amazon API Gateway also creates WebSocket APIs that adhere to the WebSocket protocol, which enables stateful, full-duplex communication between client and server

d)

Amazon API Gateway creates RESTful APIs that enable stateful client-server communication and Amazon API Gateway also creates WebSocket APIs that adhere to the WebSocket protocol, which enables stateless, full-duplex communication between client and server

9.

A new DevOps engineer has joined a large financial services company recently. As part of his onboarding, the IT department is conducting a review of the checklist for tasks related to AWS Identity and Access Management (AWS IAM).

As an AWS Certified Solutions Architect – Associate, which best practices would you recommend (Select two)?

a)

Configure AWS CloudTrail to log all AWS Identity and Access Management (AWS IAM) actions

b)

Create a minimum number of accounts and share these account credentials among employees

c)

Grant maximum privileges to avoid assigning privileges again

d)

Use user credentials to provide access specific permissions for Amazon EC2 instances

e)

Enable AWS Multi-Factor Authentication (AWS MFA) for privileged users

10.

Question 10Skipped

A company has a web application that runs 24*7 in the production environment. The development team at the company runs a clone of the same application in the dev environment for up to 8 hours every day. The company wants to build the MOST cost-optimal solution by deploying these applications using the best-fit pricing options for Amazon Elastic Compute Cloud (Amazon EC2) instances.

What would you recommend?

a)

Use Amazon EC2 reserved instance (RI) for the production application and on-demand instances for the dev application

b)

Use Amazon EC2 reserved instance (RI) for the production application and spot block instances for the dev application

c)

Use Amazon EC2 reserved instance (RI) for the production application and spot instances for the dev application

d)

Use on-demand Amazon EC2 instances for the production application and spot instances for the dev application

11.

A gaming company uses Amazon Aurora as its primary database service. The company has now deployed 5 multi-AZ read replicas to increase the read throughput and for use as failover target. The replicas have been assigned the following failover priority tiers and corresponding instance sizes are given in parentheses: tier-1 (16 terabytes), tier-1 (32 terabytes), tier-10 (16 terabytes), tier-15 (16 terabytes), tier-15 (32 terabytes).

In the event of a failover, Amazon Aurora will promote which of the following read replicas?

a)

Tier-1 (16 terabytes)

b)

Tier-10 (16 terabytes)

c)

Tier-15 (32 terabytes)

d)

Tier-1 (32 terabytes)

12.

A retail company's dynamic website is hosted using on-premises servers in its data center in the United States. The company is launching its website in Asia, and it wants to optimize the website loading times for new users in Asia. The website's backend must remain in the United States. The website is being launched in a few days, and an immediate solution is needed.

What would you recommend?

a)

Migrate the website to Amazon S3. Use S3 cross-region replication (S3 CRR) between AWS Regions in the US and Asia

b)

Leverage a Amazon Route 53 geo-proximity routing policy pointing to on-premises servers

c)

Use Amazon CloudFront with a custom origin pointing to the DNS record of the website on Amazon Route 53

d)

Use Amazon CloudFront with a custom origin pointing to the on-premises servers

13.

A major bank is using Amazon Simple Queue Service (Amazon SQS) to migrate several core banking applications to the cloud to ensure high availability and cost efficiency while simplifying administrative complexity and overhead. The development team at the bank expects a peak rate of about 1000 messages per second to be processed via SQS. It is important that the messages are processed in order.

Which of the following options can be used to implement this system?

a)

Use Amazon SQS FIFO (First-In-First-Out) queue in batch mode of 2 messages per operation to process the messages at the peak rate

b)

Use Amazon SQS FIFO (First-In-First-Out) queue to process the messages

c)

Use Amazon SQS FIFO (First-In-First-Out) queue in batch mode of 4 messages per operation to process the messages at the peak rate

d)

Use Amazon SQS standard queue to process the messages

14.

An IT security consultancy is working on a solution to protect data stored in Amazon S3 from any malicious activity as well as check for any vulnerabilities on Amazon EC2 instances.

As a solutions architect, which of the following solutions would you suggest to help address the given requirement?

a)

Use Amazon Inspector to monitor any malicious activity on data stored in Amazon S3. Use security assessments provided by Amazon GuardDuty to check for vulnerabilities on Amazon EC2 instances

b)

Use Amazon Inspector to monitor any malicious activity on data stored in Amazon S3. Use security assessments provided by Amazon Inspector to check for vulnerabilities on Amazon EC2 instances

c)

Use Amazon GuardDuty to monitor any malicious activity on data stored in Amazon S3. Use security assessments provided by Amazon Inspector to check for vulnerabilities on Amazon EC2 instances

d)

Use Amazon GuardDuty to monitor any malicious activity on data stored in Amazon S3. Use security assessments provided by Amazon GuardDuty to check for vulnerabilities on Amazon EC2 instances

15.

The DevOps team at an e-commerce company wants to perform some maintenance work on a specific Amazon EC2 instance that is part of an Auto Scaling group using a step scaling policy. The team is facing a maintenance challenge - every time the team deploys a maintenance patch, the instance health check status shows as out of service for a few minutes. This causes the Auto Scaling group to provision another replacement instance immediately.

As a solutions architect, which are the MOST time/resource efficient steps that you would recommend so that the maintenance work can be completed at the earliest? (Select two)

a)

Put the instance into the Standby state and then update the instance by applying the maintenance patch. Once the instance is ready, you can exit the Standby state and then return the instance to service

b)

Delete the Auto Scaling group and apply the maintenance fix to the given instance. Create a new Auto Scaling group and add all the instances again using the manual scaling policy

c)

Suspend the ReplaceUnhealthy process type for the Auto Scaling group and apply the maintenance patch to the instance. Once the instance is ready, you can manually set the instance's health status back to healthy and activate the ReplaceUnhealthy process type again

d)

Suspend the ScheduledActions process type for the Auto Scaling group and apply the maintenance patch to the instance. Once the instance is ready, you can you can manually set the instance's health status back to healthy and activate the ScheduledActions process type again

e)

Take a snapshot of the instance, create a new Amazon Machine Image (AMI) and then launch a new instance using this AMI. Apply the maintenance patch to this new instance and then add it back to the Auto Scaling Group by using the manual scaling policy. Terminate the earlier instance that had the maintenance issue

16.

A data analytics company measures what the consumers watch and what advertising they’re exposed to. This real-time data is ingested into its on-premises data center and subsequently, the daily data feed is compressed into a single file and uploaded on Amazon S3 for backup. The typical compressed file size is around 2 gigabytes.

Which of the following is the fastest way to upload the daily compressed file into Amazon S3?

a)

Upload the compressed file in a single operation

b)

Upload the compressed file using multipart upload with Amazon S3 Transfer Acceleration (Amazon S3TA)

c)

Upload the compressed file using multipart upload

d)

FTP the compressed file into an Amazon EC2 instance that runs in the same region as the Amazon S3 bucket. Then transfer the file from the Amazon EC2 instance into the Amazon S3 bucket

17.

The engineering team at a data analytics company has observed that its flagship application functions at its peak performance when the underlying Amazon Elastic Compute Cloud (Amazon EC2) instances have a CPU utilization of about 50%. The application is built on a fleet of Amazon EC2 instances managed under an Auto Scaling group. The workflow requests are handled by an internal Application Load Balancer that routes the requests to the instances.

As a solutions architect, what would you recommend so that the application runs near its peak performance state?

a)

Configure the Auto Scaling group to use a Amazon Cloudwatch alarm triggered on a CPU utilization threshold of 50%

b)

Configure the Auto Scaling group to use step scaling policy and set the CPU utilization as the target metric with a target value of 50%

c)

Configure the Auto Scaling group to use target tracking policy and set the CPU utilization as the target metric with a target value of 50%

d)

Configure the Auto Scaling group to use simple scaling policy and set the CPU utilization as the target metric with a target value of 50%

18.

A financial services company recently launched an initiative to improve the security of its AWS resources and it had enabled AWS Shield Advanced across multiple AWS accounts owned by the company. Upon analysis, the company has found that the costs incurred are much higher than expected.

Which of the following would you attribute as the underlying reason for the unexpectedly high costs for AWS Shield Advanced service?

a)

AWS Shield Advanced is being used for custom servers, that are not part of AWS Cloud, thereby resulting in increased costs

b)

Savings Plans has not been enabled for the AWS Shield Advanced service across all the AWS accounts

c)

AWS Shield Advanced also covers AWS Shield Standard plan, thereby resulting in increased costs

d)

Consolidated billing has not been enabled. All the AWS accounts should fall under a single consolidated billing for the monthly fee to be charged only once

19.

An organization wants to delegate access to a set of users from the development environment so that they can access some resources in the production environment which is managed under another AWS account.

As a solutions architect, which of the following steps would you recommend?

a)

It is not possible to access cross-account resources

b)

Create new IAM user credentials for the production environment and share these credentials with the set of users from the development environment

c)

Both IAM roles and IAM users can be used interchangeably for cross-account access

d)

Create a new IAM role with the required permissions to access the resources in the production environment. The users can then assume this IAM role while accessing the resources from the production environment

20.

A gaming company is looking at improving the availability and performance of its global flagship application which utilizes User Datagram Protocol and needs to support fast regional failover in case an AWS Region goes down. The company wants to continue using its own custom Domain Name System (DNS) service.

Which of the following AWS services represents the best solution for this use-case?

a)

Amazon CloudFront

b)

AWS Global Accelerator

c)

AWS Elastic Load Balancing (ELB)

d)

Amazon Route 53

21.

The IT department at a consulting firm is conducting a training workshop for new developers. As part of an evaluation exercise on Amazon S3, the new developers were asked to identify the invalid storage class lifecycle transitions for objects stored on Amazon S3.

Can you spot the INVALID lifecycle transitions from the options below? (Select two)

a)

Amazon S3 Standard => Amazon S3 Intelligent-Tiering

b)

Amazon S3 Intelligent-Tiering => Amazon S3 Standard

c)

Amazon S3 Standard-IA => Amazon S3 Intelligent-Tiering

d)

Amazon S3 Standard-IA => Amazon S3 One Zone-IA

e)

Amazon S3 One Zone-IA => Amazon S3 Standard-IA

22.

A gaming company is developing a mobile game that streams score updates to a backend processor and then publishes results on a leaderboard. The company has hired you as an AWS Certified Solutions Architect Associate to design a solution that can handle major traffic spikes, process the mobile game updates in the order of receipt, and store the processed updates in a highly available database. The company wants to minimize the management overhead required to maintain the solution.

Which of the following will you recommend to meet these requirements?

a)

Push score updates to Amazon Kinesis Data Streams which uses a fleet of Amazon EC2 instances (with Auto Scaling) to process the updates in Amazon Kinesis Data Streams and then store these processed updates in Amazon DynamoDB

b)

Push score updates to Amazon Kinesis Data Streams which uses an AWS Lambda function to process these updates and then store these processed updates in Amazon DynamoDB

c)

Push score updates to an Amazon Simple Notification Service (Amazon SNS) topic, subscribe an AWS Lambda function to this Amazon SNS topic to process the updates and then store these processed updates in a SQL database running on Amazon EC2 instance

d)

Push score updates to an Amazon Simple Queue Service (Amazon SQS) queue which uses a fleet of Amazon EC2 instances (with Auto Scaling) to process these updates in the Amazon SQS queue and then store these processed updates in an Amazon RDS MySQL database

23.

A leading carmaker would like to build a new car-as-a-sensor service by leveraging fully serverless components that are provisioned and managed automatically by AWS. The development team at the carmaker does not want an option that requires the capacity to be manually provisioned, as it does not want to respond manually to changing volumes of sensor data.

Given these constraints, which of the following solutions is the BEST fit to develop this car-as-a-sensor service?

a)

Ingest the sensor data in an Amazon Simple Queue Service (Amazon SQS) standard queue, which is polled by an application running on an Amazon EC2 instance and the data is written into an auto-scaled Amazon DynamoDB table for downstream processing

b)

Ingest the sensor data in an Amazon Simple Queue Service (Amazon SQS) standard queue, which is polled by an AWS Lambda function in batches and the data is written into an auto-scaled Amazon DynamoDB table for downstream processing

c)

Ingest the sensor data in Amazon Kinesis Data Streams, which is polled by an application running on an Amazon EC2 instance and the data is written into an auto-scaled Amazon DynamoDB table for downstream processing

d)

Ingest the sensor data in Amazon Kinesis Data Firehose, which directly writes the data into an auto-scaled Amazon DynamoDB table for downstream processing

24.

The engineering team at an in-home fitness company is evaluating multiple in-memory data stores with the ability to power its on-demand, live leaderboard. The company's leaderboard requires high availability, low latency, and real-time processing to deliver customizable user data for the community of users working out together virtually from the comfort of their home.

As a solutions architect, which of the following solutions would you recommend? (Select two)

a)

Power the on-demand, live leaderboard using Amazon DynamoDB with DynamoDB Accelerator (DAX) as it meets the in-memory, high availability, low latency requirements

b)

Power the on-demand, live leaderboard using Amazon Neptune as it meets the in-memory, high availability, low latency requirements

c)

Power the on-demand, live leaderboard using Amazon DynamoDB as it meets the in-memory, high availability, low latency requirements

d)

Power the on-demand, live leaderboard using Amazon ElastiCache for Redis as it meets the in-memory, high availability, low latency requirements

e)

Power the on-demand, live leaderboard using Amazon RDS for Aurora as it meets the in-memory, high availability, low latency requirements

25.

A junior scientist working with the Deep Space Research Laboratory at NASA is trying to upload a high-resolution image of a nebula into Amazon S3. The image size is approximately 3 gigabytes. The junior scientist is using Amazon S3 Transfer Acceleration (Amazon S3TA) for faster image upload. It turns out that Amazon S3TA did not result in an accelerated transfer.

Given this scenario, which of the following is correct regarding the charges for this image transfer?

a)

The junior scientist does not need to pay any transfer charges for the image upload

b)

The junior scientist needs to pay both S3 transfer charges and S3TA transfer charges for the image upload

c)

The junior scientist only needs to pay Amazon S3 transfer charges for the image upload

d)

The junior scientist only needs to pay S3TA transfer charges for the image upload

26.

The development team at an e-commerce startup has set up multiple microservices running on Amazon EC2 instances under an Application Load Balancer. The team wants to route traffic to multiple back-end services based on the URL path of the HTTP header. So it wants requests for https://www.example.com/orders to go to a specific microservice and requests for https://www.example.com/products to go to another microservice.

Which of the following features of Application Load Balancers can be used for this use-case?

a)

Path-based Routing

b)

HTTP header-based routing

c)

Query string parameter-based routing

d)

Host-based Routing

27.

A file-hosting service uses Amazon Simple Storage Service (Amazon S3) under the hood to power its storage offerings. Currently all the customer files are uploaded directly under a single Amazon S3 bucket. The engineering team has started seeing scalability issues where customer file uploads have started failing during the peak access hours with more than 5000 requests per second.

Which of the following is the MOST resource efficient and cost-optimal way of addressing this issue?

a)

Change the application architecture to create customer-specific custom prefixes within the single Amazon S3 bucket and then upload the daily files into those prefixed locations

b)

Change the application architecture to create a new Amazon S3 bucket for each customer and then upload each customer's files directly under the respective buckets

c)

Change the application architecture to use Amazon Elastic File System (Amazon EFS) instead of Amazon S3 for storing the customers' uploaded files

d)

Change the application architecture to create a new Amazon S3 bucket for each day's data and then upload the daily files directly under that day's bucket

28.

A company manages a multi-tier social media application that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances behind an Application Load Balancer. The instances run in an Amazon EC2 Auto Scaling group across multiple Availability Zones (AZs) and use an Amazon Aurora database. As an AWS Certified Solutions Architect – Associate, you have been tasked to make the application more resilient to periodic spikes in request rates.

Which of the following solutions would you recommend for the given use-case? (Select two)

a)

Use Amazon Aurora Replica

b)

Use AWS Direct Connect

c)

Use AWS Shield

d)

Use AWS Global Accelerator

e)

Use Amazon CloudFront distribution in front of the Application Load Balancer

29.

A social photo-sharing company uses Amazon Simple Storage Service (Amazon S3) to store the images uploaded by the users. These images are kept encrypted in Amazon S3 by using AWS Key Management Service (AWS KMS) and the company manages its own AWS KMS keys for encryption. A member of the DevOps team accidentally deleted the AWS KMS key a day ago, thereby rendering the user's photo data unrecoverable. You have been contacted by the company to consult them on possible solutions to this crisis.

As a solutions architect, which of the following steps would you recommend to solve this issue?

a)

As the AWS KMS key was deleted a day ago, it must be in the 'pending deletion' status and hence you can just cancel the KMS key deletion and recover the key

b)

The company should issue a notification on its web application informing the users about the loss of their data

c)

The AWS KMS key can be recovered by the AWS root account use

d)

Contact AWS support to retrieve the AWS KMS key from their backup

30.

An audit department generates and accesses the audit reports only twice in a financial year. The department uses AWS Step Functions to orchestrate the report creating process that has failover and retry scenarios built into the solution. The underlying data to create these audit reports is stored on Amazon S3, runs into hundreds of Terabytes and should be available with millisecond latency.

As an AWS Certified Solutions Architect – Associate, which is the MOST cost-effective storage class that you would recommend to be used for this use-case?

a)

Amazon S3 Standard-Infrequent Access (S3 Standard-IA)

b)

Amazon S3 Intelligent-Tiering (S3 Intelligent-Tiering)

c)

Amazon S3 Standard

d)

Amazon S3 Glacier Deep Archive

31.

A news network uses Amazon Simple Storage Service (Amazon S3) to aggregate the raw video footage from its reporting teams across the US. The news network has recently expanded into new geographies in Europe and Asia. The technical teams at the overseas branch offices have reported huge delays in uploading large video files to the destination Amazon S3 bucket.

Which of the following are the MOST cost-effective options to improve the file upload speed into Amazon S3 (Select two)

a)

Use AWS Global Accelerator for faster file uploads into the destination Amazon S3 bucket

b)

Use multipart uploads for faster file uploads into the destination Amazon S3 bucket

c)

Create multiple AWS Direct Connect connections between the AWS Cloud and branch offices in Europe and Asia. Use the direct connect connections for faster file uploads into Amazon S3

d)

Create multiple AWS Site-to-Site VPN connections between the AWS Cloud and branch offices in Europe and Asia. Use these VPN connections for faster file uploads into Amazon S3

e)

Use Amazon S3 Transfer Acceleration (Amazon S3TA) to enable faster file uploads into the destination S3 bucket

32.

An ivy-league university is assisting NASA to find potential landing sites for exploration vehicles of unmanned missions to our neighboring planets. The university uses High Performance Computing (HPC) driven application architecture to identify these landing sites.

Which of the following Amazon EC2 instance topologies should this application be deployed on?

a)

The Amazon EC2 instances should be deployed in a partition placement group so that distributed workloads can be handled effectively

b)

The Amazon EC2 instances should be deployed in a spread placement group so that there are no correlated failures

c)

The Amazon EC2 instances should be deployed in an Auto Scaling group so that application meets high availability requirements

d)

The Amazon EC2 instances should be deployed in a cluster placement group so that the underlying workload can benefit from low network latency and high network throughput

33.

A company uses Amazon S3 buckets for storing sensitive customer data. The company has defined different retention periods for different objects present in the Amazon S3 buckets, based on the compliance requirements. But, the retention rules do not seem to work as expected.

Which of the following options represent a valid configuration for setting up retention periods for objects in Amazon S3 buckets? (Select two)

a)

You cannot place a retention period on an object version through a bucket default setting

b)

When you apply a retention period to an object version explicitly, you specify a Retain Until Date for the object version

c)

When you use bucket default settings, you specify a Retain Until Date for the object version

d)

The bucket default settings will override any explicit retention mode or period you request on an object version

e)

Different versions of a single object can have different retention modes and periods

34.

The engineering team at a Spanish professional football club has built a notification system for its website using Amazon Simple Notification Service (Amazon SNS) notifications which are then handled by an AWS Lambda function for end-user delivery. During the off-season, the notification systems need to handle about 100 requests per second. During the peak football season, the rate touches about 5000 requests per second and it is noticed that a significant number of the notifications are not being delivered to the end-users on the website.

As a solutions architect, which of the following would you suggest as the BEST possible solution to this issue?

a)

Amazon SNS has hit a scalability limit, so the team needs to contact AWS support to raise the account limit

b)

The engineering team needs to provision more servers running the Amazon SNS service

c)

Amazon SNS message deliveries to AWS Lambda have crossed the account concurrency quota for AWS Lambda, so the team needs to contact AWS support to raise the account limit

d)

The engineering team needs to provision more servers running the AWS Lambda service

35.

A retail company has developed a REST API which is deployed in an Auto Scaling group behind an Application Load Balancer. The REST API stores the user data in Amazon DynamoDB and any static content, such as images, are served via Amazon Simple Storage Service (Amazon S3). On analyzing the usage trends, it is found that 90% of the read requests are for commonly accessed data across all users.

As a Solutions Architect, which of the following would you suggest as the MOST efficient solution to improve the application performance?

a)

Enable Amazon DynamoDB Accelerator (DAX) for Amazon DynamoDB and Amazon CloudFront for Amazon S3

b)

Enable ElastiCache Redis for DynamoDB and Amazon CloudFront for Amazon S3

c)

Enable Amazon DynamoDB Accelerator (DAX) for Amazon DynamoDB and ElastiCache Memcached for Amazon S3

d)

Enable ElastiCache Redis for DynamoDB and ElastiCache Memcached for Amazon S3

36.

Amazon CloudFront offers a multi-tier cache in the form of regional edge caches that improve latency. However, there are certain content types that bypass the regional edge cache, and go directly to the origin.

Which of the following content types skip the regional edge cache? (Select two)

a)

Static content such as style sheets, JavaScript files

b)

Proxy methods PUT/POST/PATCH/OPTIONS/DELETE go directly to the origin

c)

E-commerce assets such as product photos

d)

User-generated videos

e)

Dynamic content, as determined at request time (cache-behavior configured to forward all headers)

37.

An Electronic Design Automation (EDA) application produces massive volumes of data that can be divided into two categories. The 'hot data' needs to be both processed and stored quickly in a parallel and distributed fashion. The 'cold data' needs to be kept for reference with quick access for reads and updates at a low cost.

Which of the following AWS services is BEST suited to accelerate the aforementioned chip design process?

a)

Amazon FSx for Windows File Server

b)

Amazon EMR

c)

Amazon FSx for Lustre

d)

AWS Glue

38.

A financial services company uses Amazon GuardDuty for analyzing its AWS account metadata to meet the compliance guidelines. However, the company has now decided to stop using Amazon GuardDuty service. All the existing findings have to be deleted and cannot persist anywhere on AWS Cloud.

Which of the following techniques will help the company meet this requirement?

a)

Suspend the service in the general settings

b)

De-register the service under services tab

c)

Raise a service request with Amazon to completely delete the data from all their backups

d)

Disable the service in the general settings

39.

Which of the following feature of an Amazon S3 bucket can only be suspended and not disabled once it have been enabled?

a)

Versioning

b)

Server Access Logging

c)

Static Website Hosting

d)

Requester Pays

40.

The engineering team at an e-commerce company wants to establish a dedicated, encrypted, low latency, and high throughput connection between its data center and AWS Cloud. The engineering team has set aside sufficient time to account for the operational overhead of establishing this connection.

As a solutions architect, which of the following solutions would you recommend to the company?

a)

Use AWS Direct Connect plus virtual private network (VPN) to establish a connection between the data center and AWS Cloud

b)

Use AWS Direct Connect to establish a connection between the data center and AWS Cloud

c)

Use AWS Transit Gateway to establish a connection between the data center and AWS Cloud

d)

Use AWS site-to-site VPN to establish a connection between the data center and AWS Cloud

41.

While consolidating logs for the weekly reporting, a development team at an e-commerce company noticed that an unusually large number of illegal AWS application programming interface (API) queries were made sometime during the week. Due to the off-season, there was no visible impact on the systems. However, this event led the management team to seek an automated solution that can trigger near-real-time warnings in case such an event recurs.

Which of the following represents the best solution for the given scenario?

a)

Run Amazon Athena SQL queries against AWS CloudTrail log files stored in Amazon S3 buckets. Use Amazon QuickSight to generate reports for managerial dashboards

b)

Create an Amazon CloudWatch metric filter that processes AWS CloudTrail logs having API call details and looks at any errors by factoring in all the error codes that need to be tracked. Create an alarm based on this metric's rate to send an Amazon SNS notification to the required team

c)

AWS Trusted Advisor publishes metrics about check results to Amazon CloudWatch. Create an alarm to track status changes for checks in the Service Limits category for the APIs. The alarm will then notify when the service quota is reached or exceeded

d)

Configure AWS CloudTrail to stream event data to Amazon Kinesis. Use Amazon Kinesis stream-level metrics in the Amazon CloudWatch to trigger an AWS Lambda function that will trigger an error workflow

42.

A technology blogger wants to write a review on the comparative pricing for various storage types available on AWS Cloud. The blogger has created a test file of size 1 gigabytes with some random data. Next he copies this test file into AWS S3 Standard storage class, provisions an Amazon EBS volume (General Purpose SSD (gp2)) with 100 gigabytes of provisioned storage and copies the test file into the Amazon EBS volume, and lastly copies the test file into an Amazon EFS Standard Storage filesystem. At the end of the month, he analyses the bill for costs incurred on the respective storage types for the test file.

What is the correct order of the storage charges incurred for the test file on these three storage types?

a)

Cost of test file storage on Amazon EFS < Cost of test file storage on Amazon S3 Standard < Cost of test file storage on Amazon EBS

b)

Cost of test file storage on Amazon EBS < Cost of test file storage on Amazon S3 Standard < Cost of test file storage on Amazon EFS

c)

Cost of test file storage on Amazon S3 Standard < Cost of test file storage on Amazon EFS < Cost of test file storage on Amazon EBS

d)

Cost of test file storage on Amazon S3 Standard < Cost of test file storage on Amazon EBS < Cost of test file storage on Amazon EFS

43.

An IT consultant is helping the owner of a medium-sized business set up an AWS account. What are the security recommendations he must follow while creating the AWS account root user? (Select two)

a)

Enable Multi Factor Authentication (MFA) for the AWS account root user account

b)

Create AWS account root user access keys and share those keys only with the business owner

c)

Encrypt the access keys and save them on Amazon S3

d)

Send an email to the business owner with details of the login username and password for the AWS root user. This will help the business owner to troubleshoot any login issues in future

e)

Create a strong password for the AWS account root user

44.

A company runs a data processing workflow that takes about 60 minutes to complete. The workflow can withstand disruptions and it can be started and stopped multiple times.

Which is the most cost-effective solution to build a solution for the workflow?

a)

Use Amazon EC2 spot instances to run the workflow processes

b)

Use Amazon EC2 on-demand instances to run the workflow processes

c)

Use AWS Lambda function to run the workflow processes

d)

Use Amazon EC2 reserved instances to run the workflow processes

45.

A US-based healthcare startup is building an interactive diagnostic tool for COVID-19 related assessments. The users would be required to capture their personal health records via this tool. As this is sensitive health information, the backup of the user data must be kept encrypted in Amazon Simple Storage Service (Amazon S3). The startup does not want to provide its own encryption keys but still wants to maintain an audit trail of when an encryption key was used and by whom.

Which of the following is the BEST solution for this use-case?

a)

Use server-side encryption with customer-provided keys (SSE-C) to encrypt the user data on Amazon S3

b)

Use server-side encryption with AWS Key Management Service keys (SSE-KMS) to encrypt the user data on Amazon S3

c)

Use client-side encryption with client provided keys and then upload the encrypted user data to Amazon S3

d)

Use server-side encryption with Amazon S3 managed keys (SSE-S3) to encrypt the user data on Amazon S3

46.

A video analytics organization has been acquired by a leading media company. The analytics organization has 10 independent applications with an on-premises data footprint of about 70 Terabytes for each application. The CTO of the media company has set a timeline of two weeks to carry out the data migration from on-premises data center to AWS Cloud and establish connectivity.

Which of the following are the MOST cost-effective options for completing the data transfer and establishing connectivity? (Select two)

a)

Setup AWS Site-to-Site VPN to establish on-going connectivity between the on-premises data center and AWS Cloud

b)

Setup AWS Direct Connect to establish connectivity between the on-premises data center and AWS Cloud

c)

Order 1 AWS Snowmobile to complete the one-time data transfer

d)

Order 70 AWS Snowball Edge Storage Optimized devices to complete the one-time data transfer

e)

Order 10 AWS Snowball Edge Storage Optimized devices to complete the one-time data transfer

47.

A software engineering intern at an e-commerce company is documenting the process flow to provision Amazon EC2 instances via the Amazon EC2 API. These instances are to be used for an internal application that processes Human Resources payroll data. He wants to highlight those volume types that cannot be used as a boot volume.

Can you help the intern by identifying those storage volume types that CANNOT be used as boot volumes while creating the instances? (Select two)

a)

Throughput Optimized Hard disk drive (st1)

b)

Instance Store

c)

Cold Hard disk drive (sc1)

d)

General Purpose Solid State Drive (gp2)

e)

Provisioned IOPS Solid state drive (io1)

48.

A healthcare company uses its on-premises infrastructure to run legacy applications that require specialized customizations to the underlying Oracle database as well as its host operating system (OS). The company also wants to improve the availability of the Oracle database layer. The company has hired you as an AWS Certified Solutions Architect – Associate to build a solution on AWS that meets these requirements while minimizing the underlying infrastructure maintenance effort.

Which of the following options represents the best solution for this use case?

a)

Deploy the Oracle database layer on multiple Amazon EC2 instances spread across two Availability Zones (AZs). This deployment configuration guarantees high availability and also allows the Database Administrator (DBA) to access and customize the database environment and the underlying operating system

b)

Leverage multi-AZ configuration of Amazon RDS for Oracle that allows the Database Administrator (DBA) to access and customize the database environment and the underlying operating system

c)

Leverage multi-AZ configuration of Amazon RDS Custom for Oracle that allows the Database Administrator (DBA) to access and customize the database environment and the underlying operating system

d)

Leverage cross AZ read-replica configuration of Amazon RDS for Oracle that allows the Database Administrator (DBA) to access and customize the database environment and the underlying operating system

49.

A Big Data analytics company wants to set up an AWS cloud architecture that throttles requests in case of sudden traffic spikes. The company is looking for AWS services that can be used for buffering or throttling to handle such traffic variations.

Which of the following services can be used to support this requirement?

a)

Amazon API Gateway, Amazon Simple Queue Service (Amazon SQS) and Amazon Kinesis

b)

Elastic Load Balancer, Amazon Simple Queue Service (Amazon SQS), AWS Lambda

c)

Amazon Gateway Endpoints, Amazon Simple Queue Service (Amazon SQS) and Amazon Kinesis

d)

Amazon Simple Queue Service (Amazon SQS), Amazon Simple Notification Service (Amazon SNS) and AWS Lambda

50.

A media company runs a photo-sharing web application that is accessed across three different countries. The application is deployed on several Amazon Elastic Compute Cloud (Amazon EC2) instances running behind an Application Load Balancer. With new government regulations, the company has been asked to block access from two countries and allow access only from the home country of the company.

Which configuration should be used to meet this changed requirement?

a)

Use Geo Restriction feature of Amazon CloudFront in a Amazon Virtual Private Cloud (Amazon VPC)

b)

Configure the security group for the Amazon EC2 instances

c)

Configure the security group on the Application Load Balancer

d)

Configure AWS Web Application Firewall (AWS WAF) on the Application Load Balancer in a Amazon Virtual Private Cloud (Amazon VPC)

51.

A retail company uses Amazon Elastic Compute Cloud (Amazon EC2) instances, Amazon API Gateway, Amazon RDS, Elastic Load Balancer and Amazon CloudFront services. To improve the security of these services, the Risk Advisory group has suggested a feasibility check for using the Amazon GuardDuty service.

Which of the following would you identify as data sources supported by Amazon GuardDuty?

a)

Elastic Load Balancing logs, Domain Name System (DNS) logs, AWS CloudTrail events

b)

VPC Flow Logs, Amazon API Gateway logs, Amazon S3 access logs

c)

VPC Flow Logs, Domain Name System (DNS) logs, AWS CloudTrail events

d)

Amazon CloudFront logs, Amazon API Gateway logs, AWS CloudTrail events

52.

A new DevOps engineer has just joined a development team and wants to understand the replication capabilities for Amazon RDS Multi-AZ deployment as well as Amazon RDS Read-replicas.

Which of the following correctly summarizes these capabilities for the given database?

a)

Multi-AZ follows asynchronous replication and spans one Availability Zone (AZ) within a single region. Read replicas follow synchronous replication and can be within an Availability Zone (AZ), Cross-AZ, or Cross-Region

b)

Multi-AZ follows synchronous replication and spans at least two Availability Zones (AZs) within a single region. Read replicas follow asynchronous replication and can be within an Availability Zone (AZ), Cross-AZ, or Cross-Region

c)

Multi-AZ follows asynchronous replication and spans at least two Availability Zones (AZs) within a single region. Read replicas follow synchronous replication and can be within an Availability Zone (AZ), Cross-AZ, or Cross-Region

d)

Multi-AZ follows asynchronous replication and spans at least two Availability Zones (AZs) within a single region. Read replicas follow asynchronous replication and can be within an Availability Zone (AZ), Cross-AZ, or Cross-Region

53.

A leading video streaming service delivers billions of hours of content from Amazon Simple Storage Service (Amazon S3) to customers around the world. Amazon S3 also serves as the data lake for its big data analytics solution. The data lake has a staging zone where intermediary query results are kept only for 24 hours. These results are also heavily referenced by other parts of the analytics pipeline.

Which of the following is the MOST cost-effective strategy for storing this intermediary query data?

a)

Store the intermediary query results in Amazon S3 Glacier Instant Retrieval storage class

b)

Store the intermediary query results in Amazon S3 One Zone-Infrequent Access storage class

c)

Store the intermediary query results in Amazon S3 Standard storage class

d)

Store the intermediary query results in Amazon S3 Standard-Infrequent Access storage class

54.

A research group runs its flagship application on a fleet of Amazon EC2 instances for a specialized task that must deliver high random I/O performance. Each instance in the fleet would have access to a dataset that is replicated across the instances by the application itself. Because of the resilient application architecture, the specialized task would continue to be processed even if any instance goes down, as the underlying application would ensure the replacement instance has access to the required dataset.

Which of the following options is the MOST cost-optimal and resource-efficient solution to build this fleet of Amazon EC2 instances?

a)

Use Amazon Elastic Block Store (Amazon EBS) based EC2 instances

b)

Use Amazon EC2 instances with access to Amazon S3 based storage

c)

Use Instance Store based Amazon EC2 instances

d)

Use Amazon EC2 instances with Amazon EFS mount points

55.

The solo founder at a tech startup has just created a brand new AWS account. The founder has provisioned an Amazon EC2 instance 1A which is running in AWS Region A. Later, he takes a snapshot of the instance 1A and then creates a new Amazon Machine Image (AMI) in Region A from this snapshot. This AMI is then copied into another Region B. The founder provisions an instance 1B in Region B using this new AMI in Region B.

At this point in time, what entities exist in Region B?

a)

1 Amazon EC2 instance and 1 snapshot exist in Region B

b)

1 Amazon EC2 instance and 1 AMI exist in Region B

c)

1 Amazon EC2 instance and 2 AMIs exist in Region B

d)

1 Amazon EC2 instance, 1 AMI and 1 snapshot exist in Region B

56.

A company is in the process of migrating its on-premises SMB file shares to AWS so the company can get out of the business of managing multiple file servers across dozens of offices. The company has 200 terabytes of data in its file servers. The existing on-premises applications and native Windows workloads should continue to have low latency access to this data which needs to be stored on a file system service without any disruptions after the migration. The company also wants any new applications deployed on AWS to have access to this migrated data.

Which of the following is the best solution to meet this requirement?

a)

Use Amazon Storage Gateway’s File Gateway to provide low-latency, on-premises access to fully managed file shares in Amazon FSx for Windows File Server. The applications deployed on AWS can access this data directly from Amazon FSx in AWS

b)

Use Amazon FSx File Gateway to provide low-latency, on-premises access to fully managed file shares in Amazon FSx for Windows File Server. The applications deployed on AWS can access this data directly from Amazon FSx in AWS

c)

Use Amazon FSx File Gateway to provide low-latency, on-premises access to fully managed file shares in Amazon EFS. The applications deployed on AWS can access this data directly from Amazon EFS

d)

Use AWS Storage Gateway’s File Gateway to provide low-latency, on-premises access to fully managed file shares in Amazon S3. The applications deployed on AWS can access this data directly from Amazon S3

57.

A logistics company is building a multi-tier application to track the location of its trucks during peak operating hours. The company wants these data points to be accessible in real-time in its analytics platform via a REST API. The company has hired you as an AWS Certified Solutions Architect Associate to build a multi-tier solution to store and retrieve this location data for analysis.

Which of the following options addresses the given use case?

a)

Leverage Amazon Athena with Amazon S3

b)

Leverage Amazon QuickSight with Amazon Redshift

c)

Leverage Amazon API Gateway with Amazon Kinesis Data Analytics

d)

Leverage Amazon API Gateway with AWS Lambda

58.

An e-commerce company is looking for a solution with high availability, as it plans to migrate its flagship application to a fleet of Amazon Elastic Compute Cloud (Amazon EC2) instances. The solution should allow for content-based routing as part of the architecture.

As a Solutions Architect, which of the following will you suggest for the company?

a)

Use a Network Load Balancer for distributing traffic to the Amazon EC2 instances spread across different Availability Zones (AZs). Configure a Private IP address to mask any failure of an instance

b)

Use an Auto Scaling group for distributing traffic to the Amazon EC2 instances spread across different Availability Zones (AZs). Configure a Public IP address to mask any failure of an instance

c)

Use an Auto Scaling group for distributing traffic to the Amazon EC2 instances spread across different Availability Zones (AZs). Configure an elastic IP address (EIP) to mask any failure of an instance

d)

Use an Application Load Balancer for distributing traffic to the Amazon EC2 instances spread across different Availability Zones (AZs). Configure Auto Scaling group to mask any failure of an instance

59.

As part of a pilot program, a biotechnology company wants to integrate data files from its on-premises analytical application with AWS Cloud via an NFS interface.

Which of the following AWS service is the MOST efficient solution for the given use-case

a)

AWS Storage Gateway - File Gateway

b)

AWS Site-to-Site VPN

c)

WS Storage Gateway - Volume Gateway

d)

AWS Storage Gateway - Tape Gateway

60.

A large financial institution operates an on-premises data center with hundreds of petabytes of data managed on Microsoft’s Distributed File System (DFS). The CTO wants the organization to transition into a hybrid cloud environment and run data-intensive analytics workloads that support DFS.

Which of the following AWS services can facilitate the migration of these workloads?

a)

Amazon FSx for Windows File Server

b)

AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD)

c)

Microsoft SQL Server on AWS

d)

Amazon FSx for Lustre

61.

The sourcing team at the US headquarters of a global e-commerce company is preparing a spreadsheet of the new product catalog. The spreadsheet is saved on an Amazon Elastic File System (Amazon EFS) created in us-east-1 region. The sourcing team counterparts from other AWS regions such as Asia Pacific and Europe also want to collaborate on this spreadsheet.

As a solutions architect, what is your recommendation to enable this collaboration with the LEAST amount of operational overhead?

a)

The spreadsheet will have to be copied in Amazon S3 which can then be accessed from any AWS region

b)

The spreadsheet on the Amazon Elastic File System (Amazon EFS) can be accessed in other AWS regions by using an inter-region VPC peering connection

c)

The spreadsheet will have to be copied into Amazon EFS file systems of other AWS regions as Amazon EFS is a regional service and it does not allow access from other AWS regions

d)

The spreadsheet data will have to be moved into an Amazon RDS for MySQL database which can then be accessed from any AWS region

62.

The flagship application for a gaming company connects to an Amazon Aurora database and the entire technology stack is currently deployed in the United States. Now, the company has plans to expand to Europe and Asia for its operations. It needs the games table to be accessible globally but needs the users and games_played tables to be regional only.

How would you implement this with minimal application refactoring?

a)

Use a Amazon DynamoDB global table for the games table and use Amazon DynamoDB tables for the users and games_played tables

b)

Use an Amazon Aurora Global Database for the games table and use Amazon Aurora for the users and games_played tables

c)

Use an Amazon Aurora Global Database for the games table and use Amazon DynamoDB tables for the users and games_played tables

d)

Use a Amazon DynamoDB global table for the games table and use Amazon Aurora for the users and games_played tables

63.

The payroll department at a company initiates several computationally intensive workloads on Amazon EC2 instances at a designated hour on the last day of every month. The payroll department has noticed a trend of severe performance lag during this hour. The engineering team has figured out a solution by using Auto Scaling Group for these Amazon EC2 instances and making sure that 10 Amazon EC2 instances are available during this peak usage hour. For normal operations only 2 Amazon EC2 instances are enough to cater to the workload.

As a solutions architect, which of the following steps would you recommend to implement the solution?

a)

Configure your Auto Scaling group by creating a scheduled action that kicks-off at the designated hour on the last day of the month. Set the desired capacity of instances to 10. This causes the scale-out to happen before peak traffic kicks in at the designated hour

b)

Configure your Auto Scaling group by creating a simple tracking policy and setting the instance count to 10 at the designated hour. This causes the scale-out to happen before peak traffic kicks in at the designated hour

c)

Configure your Auto Scaling group by creating a scheduled action that kicks-off at the designated hour on the last day of the month. Set the min count as well as the max count of instances to 10. This causes the scale-out to happen before peak traffic kicks in at the designated hour

d)

Configure your Auto Scaling group by creating a target tracking policy and setting the instance count to 10 at the designated hour. This causes the scale-out to happen before peak traffic kicks in at the designated hour

64.

A leading social media analytics company is contemplating moving its dockerized application stack into AWS Cloud. The company is not sure about the pricing for using Amazon Elastic Container Service (Amazon ECS) with the EC2 launch type compared to the Amazon Elastic Container Service (Amazon ECS) with the Fargate launch type.

Which of the following is correct regarding the pricing for these two services?

a)

Both Amazon ECS with EC2 launch type and Amazon ECS with Fargate launch type are charged based on Amazon EC2 instances and Amazon EBS Elastic Volumes used

b)

Both Amazon ECS with EC2 launch type and Amazon ECS with Fargate launch type are charged based on vCPU and memory resources that the containerized application requests

c)

Both Amazon ECS with EC2 launch type and Amazon ECS with Fargate launch type are just charged based on Elastic Container Service used per hour

d)

Amazon ECS with EC2 launch type is charged based on EC2 instances and EBS volumes used. Amazon ECS with Fargate launch type is charged based on vCPU and memory resources that the containerized application requests

65.

One of the biggest football leagues in Europe has granted the distribution rights for live streaming its matches in the USA to a silicon valley based streaming services company. As per the terms of distribution, the company must make sure that only users from the USA are able to live stream the matches on their platform. Users from other countries in the world must be denied access to these live-streamed matches.

Which of the following options would allow the company to enforce these streaming restrictions? (Select two)

a)

Use georestriction to prevent users in specific geographic locations from accessing content that you're distributing through a Amazon CloudFront web distribution

b)

Use Amazon Route 53 based geolocation routing policy to restrict distribution of content to only the locations in which you have distribution rights

c)

Use Amazon Route 53 based failover routing policy to restrict distribution of content to only the locations in which you have distribution rights

d)

Use Amazon Route 53 based weighted routing policy to restrict distribution of content to only the locations in which you have distribution rights

e)

Use Amazon Route 53 based latency-based routing policy to restrict distribution of content to only the locations in which you have distribution rights

66.

A big data consulting firm needs to set up a data lake on Amazon S3 for a Health-Care client. The data lake is split in raw and refined zones. For compliance reasons, the source data needs to be kept for a minimum of 5 years. The source data arrives in the raw zone and is then processed via an AWS Glue based extract, transform, and load (ETL) job into the refined zone. The business analysts run ad-hoc queries only on the data in the refined zone using Amazon Athena. The team is concerned about the cost of data storage in both the raw and refined zones as the data is increasing at a rate of 1 terabyte daily in each zone.

As a solutions architect, which of the following would you recommend as the MOST cost-optimal solution? (Select two)

a)

Setup a lifecycle policy to transition the refined zone data into Amazon S3 Glacier Deep Archive after 1 day of object creation

b)

Use AWS Glue ETL job to write the transformed data in the refined zone using a compressed file format

c)

Setup a lifecycle policy to transition the raw zone data into Amazon S3 Glacier Deep Archive after 1 day of object creation

d)

Use AWS Glue ETL job to write the transformed data in the refined zone using CSV format

e)

Create an AWS Lambda function based job to delete the raw zone data after 1 day

67.

A systems administrator has created a private hosted zone and associated it with a Virtual Private Cloud (VPC). However, the Domain Name System (DNS) queries for the private hosted zone remain unresolved.

As a Solutions Architect, can you identify the Amazon Virtual Private Cloud (Amazon VPC) options to be configured in order to get the private hosted zone to work?

a)

Fix conflicts between your private hosted zone and any Resolver rule that routes traffic to your network for the same domain name, as it results in ambiguity over the route to be taken

b)

Remove any overlapping namespaces for the private and public hosted zones

c)

Enable DNS hostnames and DNS resolution for private hosted zones

d)

Fix the Name server (NS) record and Start Of Authority (SOA) records that may have been created with wrong configurations

68.

A developer needs to implement an AWS Lambda function in AWS account A that accesses an Amazon Simple Storage Service (Amazon S3) bucket in AWS account B.

As a Solutions Architect, which of the following will you recommend to meet this requirement?

a)

AWS Lambda cannot access resources across AWS accounts. Use Identity federation to work around this limitation of Lambda

b)

Create an IAM role for the AWS Lambda function that grants access to the Amazon S3 bucket. Set the IAM role as the AWS Lambda function's execution role. Make sure that the bucket policy also grants access to the AWS Lambda function's execution role

c)

Create an IAM role for the AWS Lambda function that grants access to the Amazon S3 bucket. Set the IAM role as the Lambda function's execution role and that would give the AWS Lambda function cross-account access to the Amazon S3 bucket

d)

The Amazon S3 bucket owner should make the bucket public so that it can be accessed by the AWS Lambda function in the other AWS account

69.

A weather forecast agency collects key weather metrics across multiple cities in the US and sends this data in the form of key-value pairs to AWS Cloud at a one-minute frequency.

As a solutions architect, which of the following AWS services would you use to build a solution for processing and then reliably storing this data with high availability? (Select two)

a)

Amazon Redshift

b)

Amazon DynamoDB

c)

Amazon RDS

d)

Amazon ElastiCache

e)

AWS Lambda

70.

An IT company is working on client engagement to build a real-time data analytics tool for the Internet of Things (IoT) data. The IoT data is funneled into Amazon Kinesis Data Streams which further acts as the source of a delivery stream for Amazon Kinesis Firehose. The engineering team has now configured a Kinesis Agent to send IoT data from another set of devices to the same Amazon Kinesis Firehose delivery stream. They noticed that data is not reaching Kinesis Firehose as expected. As a solutions architect, which of the following options would you attribute as the MOST plausible root cause behind this issue?

a)

Kinesis Agent can only write to Amazon Kinesis Data Streams, not to Amazon Kinesis Firehose

b)

Amazon Kinesis Firehose delivery stream has reached its limit and needs to be scaled manually

c)

The data sent by Kinesis Agent is lost because of a configuration error

d)

Kinesis Agent cannot write to Amazon Kinesis Firehose for which the delivery stream source is already set as Amazon Kinesis Data Streams

71.

A big-data consulting firm is working on a client engagement where the extract, transform, and load (ETL) workloads are currently handled via a Hadoop cluster deployed in the on-premises data center. The client wants to migrate their ETL workloads to AWS Cloud. The AWS Cloud solution needs to be highly available with about 50 Amazon Elastic Compute Cloud (Amazon EC2) instances per Availability Zone (AZ).

As a solutions architect, which of the following Amazon EC2 placement groups would you recommend for handling the distributed ETL workload?

a)

Partition placement group

b)

Both Spread placement group and Partition placement group

c)

Spread placement group

d)

Cluster placement group

72.

Question 7Skipped

An engineering team wants to examine the feasibility of the user data feature of Amazon EC2 for an upcoming project.

Which of the following are true about the Amazon EC2 user data configuration? (Select two)

a)

When an instance is running, you can update user data by using root user credentials

b)

By default, user data runs only during the boot cycle when you first launch an instance

c)

By default, scripts entered as user data do not have root user privileges for executing

d)

By default, scripts entered as user data are executed with root user privileges

e)

By default, user data is executed every time an Amazon EC2 instance is re-started

73.

An e-commerce application uses an Amazon Aurora Multi-AZ deployment for its database. While analyzing the performance metrics, the engineering team has found that the database reads are causing high input/output (I/O) and adding latency to the write requests against the database.

As an AWS Certified Solutions Architect Associate, what would you recommend to separate the read requests from the write requests?

a)

Configure the application to read from the Multi-AZ standby instance

b)

Set up a read replica and modify the application to use the appropriate endpoint

c)

Provision another Amazon Aurora database and link it to the primary database as a read replica

d)

Activate read-through caching on the Amazon Aurora database

74.

An IT company is working on a client project to build a Supply Chain Management application. The web-tier of the application runs on an Amazon EC2 instance and the database tier is on Amazon RDS MySQL. For beta testing, all the resources are currently deployed in a single Availability Zone (AZ). The development team wants to improve application availability before the go-live.

Given that all end users of the web application would be located in the US, which of the following would be the MOST resource-efficient solution?

a)

Deploy the web-tier Amazon EC2 instances in two regions, behind an Elastic Load Balancer. Deploy the Amazon RDS MySQL database in read replica configuration

b)

Deploy the web-tier Amazon EC2 instances in two regions, behind an Elastic Load Balancer. Deploy the Amazon RDS MySQL database in Multi-AZ configuration

c)

Deploy the web-tier Amazon EC2 instances in two Availability Zones (AZs), behind an Elastic Load Balancer. Deploy the Amazon RDS MySQL database in read replica configuration

d)

Deploy the web-tier Amazon EC2 instances in two Availability Zones (AZs), behind an Elastic Load Balancer. Deploy the Amazon RDS MySQL database in Multi-AZ configuration

75.

A Hollywood studio is planning a series of promotional events leading up to the launch of the trailer of its next sci-fi thriller. The executives at the studio want to create a static website with lots of animations in line with the theme of the movie. The studio has hired you as a solutions architect to build a scalable serverless solution.

Which of the following represents the MOST cost-optimal and high-performance solution?

a)

Host the website on an Amazon EC2 instance. Create a Amazon CloudFront distribution with the Amazon EC2 instance as the custom origin

b)

Build the website as a static website hosted on Amazon S3. Create an Amazon CloudFront distribution with Amazon S3 as the origin. Use Amazon Route 53 to create an alias record that points to your Amazon CloudFront distribution

c)

Host the website on an instance in the studio's on-premises data center. Create an Amazon CloudFront distribution with this instance as the custom origin

d)

Host the website on AWS Lambda. Create an Amazon CloudFront distribution with Lambda as the origin

76.

A financial services company has developed its flagship application on AWS Cloud with data security requirements such that the encryption key must be stored in a custom application running on-premises. The company wants to offload the data storage as well as the encryption process to Amazon S3 but continue to use the existing encryption key.

Which of the following Amazon S3 encryption options allows the company to leverage Amazon S3 for storing data with given constraints?

a)

Server-Side Encryption with Customer-Provided Keys (SSE-C)

b)

Server-Side Encryption with Amazon S3 managed keys (SSE-S3)

c)

Client-Side Encryption with data encryption is done on the client-side before sending it to Amazon S3

d)

Server-Side Encryption with AWS Key Management Service (AWS KMS) keys (SSE-KMS)

77.

A financial services company has deployed its flagship application on Amazon EC2 instances. Since the application handles sensitive customer data, the security team at the company wants to ensure that any third-party Secure Sockets Layer certificate (SSL certificate) SSL/Transport Layer Security (TLS) certificates configured on Amazon EC2 instances via the AWS Certificate Manager (ACM) are renewed before their expiry date. The company has hired you as an AWS Certified Solutions Architect Associate to build a solution that notifies the security team 30 days before the certificate expiration. The solution should require the least amount of scripting and maintenance effort.

What will you recommend?

a)

Leverage AWS Config managed rule to check if any third-party SSL/TLS certificates imported into ACM are marked for expiration within 30 days. Configure the rule to trigger an Amazon SNS notification to the security team if any certificate expires within 30 days

b)

Leverage AWS Config managed rule to check if any SSL/TLS certificates created via ACM are marked for expiration within 30 days. Configure the rule to trigger an Amazon SNS notification to the security team if any certificate expires within 30 days

c)

Monitor the days to expiry Amazon CloudWatch metric for certificates created via ACM. Create a CloudWatch alarm to monitor such certificates based on the days to expiry metric and then trigger a custom action of notifying the security team

d)

Monitor the days to expiry Amazon CloudWatch metric for certificates imported into ACM. Create a CloudWatch alarm to monitor such certificates based on the days to expiry metric and then trigger a custom action of notifying the security team

78.

An IT company wants to optimize the costs incurred on its fleet of 100 Amazon EC2 instances for the next year. Based on historical analyses, the engineering team observed that 70 of these instances handle the compute services of its flagship application and need to be always available. The other 30 instances are used to handle batch jobs that can afford a delay in processing.

As a solutions architect, which of the following would you recommend as the MOST cost-optimal solution?

a)

Purchase 70 on-demand instances and 30 reserved instances

b)

Purchase 70 reserved instances and 30 on-demand instances

c)

Purchase 70 on-demand instances and 30 spot instances

d)

Purchase 70 reserved instances (RIs) and 30 spot instances

79.

You have multiple AWS accounts within a single AWS Region managed by AWS Organizations and you would like to ensure all Amazon EC2 instances in all these accounts can communicate privately. Which of the following solutions provides the capability at the CHEAPEST cost?

a)

Create a Private Link between all the Amazon EC2 instances

b)

Create an AWS Transit Gateway and link all the virtual private cloud (VPCs) in all the accounts together

c)

Create a virtual private cloud (VPC) in an account and share one or more of its subnets with the other accounts using Resource Access Manager

d)

Create a VPC peering connection between all virtual private cloud (VPCs)

80.

You would like to migrate an AWS account from an AWS Organization A to an AWS Organization B. What are the steps do to it?

a)

Send an invite to the new organization. Remove the member account from the old organization. Accept the invite to the new organization from the member account

b)

Open an AWS Support ticket to ask them to migrate the account

c)

Send an invite to the new organization. Accept the invite to the new organization from the member account. Remove the member account from the old organization

d)

Remove the member account from the old organization. Send an invite to the member account from the new Organization. Accept the invite to the new organization from the member account

81.

A social media application is hosted on an Amazon EC2 fleet running behind an Application Load Balancer. The application traffic is fronted by an Amazon CloudFront distribution. The engineering team wants to decouple the user authentication process for the application, so that the application servers can just focus on the business logic.

As a Solutions Architect, which of the following solutions would you recommend to the development team so that it requires minimal development effort?

a)

Use Amazon Cognito Authentication via Cognito Identity Pools for your Amazon CloudFront distribution

b)

Use Amazon Cognito Authentication via Cognito User Pools for your Application Load Balancer

c)

Use Amazon Cognito Authentication via Cognito Identity Pools for your Application Load Balancer

d)

Use Amazon Cognito Authentication via Cognito User Pools for your Amazon CloudFront distribution

82.

A silicon valley based startup has a content management application with the web-tier running on Amazon EC2 instances and the database tier running on Amazon Aurora. Currently, the entire infrastructure is located in us-east-1 region. The startup has 90% of its customers in the US and Europe. The engineering team is getting reports of deteriorated application performance from customers in Europe with high application load time.

As a solutions architect, which of the following would you recommend addressing these performance issues? (Select two)

a)

Setup another fleet of Amazon EC2 instances for the web tier in the eu-west-1 region. Enable failover routing policy in Amazon Route 53

b)

Setup another fleet of Amazon EC2 instances for the web tier in the eu-west-1 region. Enable latency routing policy in Amazon Route 53

c)

Create Amazon Aurora Multi-AZ standby instance in the eu-west-1 region

d)

Create Amazon Aurora read replicas in the eu-west-1 region

e)

Setup another fleet of Amazon EC2 instances for the web tier in the eu-west-1 region. Enable geolocation routing policy in Amazon Route 53

83.

A company has many Amazon Virtual Private Cloud (Amazon VPC) in various accounts, that need to be connected in a star network with one another and connected with on-premises networks through AWS Direct Connect.

What do you recommend?

a)

VPC Peering Connection

b)

AWS PrivateLink

c)

AWS Transit Gateway

d)

Virtual private gateway (VGW)

84.

Your company has deployed an application that will perform a lot of overwrites and deletes on data and require the latest information to be available anytime data is read via queries on database tables.

As a Solutions Architect, which database technology will you recommend?

a)

Amazon Relational Database Service (Amazon RDS)

b)

Amazon Simple Storage Service (Amazon S3)

c)

Amazon ElastiCache

d)

Amazon Neptune

85.

You have been hired as a Solutions Architect to advise a company on the various authentication/authorization mechanisms that AWS offers to authorize an API call within the Amazon API Gateway. The company would prefer a solution that offers built-in user management.

Which of the following solutions would you suggest as the best fit for the given use-case?

a)

Use Amazon Cognito Identity Pools

b)

Use AWS Lambda authorizer for Amazon API Gateway

c)

Use AWS_IAM authorization

d)

Use Amazon Cognito User Pools

86.

A junior DevOps engineer wants to change the default configuration for Amazon EBS volume termination. By default, the root volume of an Amazon EC2 instance for an EBS-backed AMI is deleted when the instance terminates.

Which option below helps change this default behavior to ensure that the volume persists even after the instance terminates?

a)

Set the DeleteOnTermination attribute to true

b)

Set the DeleteOnTermination attribute to false

c)

Set the TerminateOnDelete attribute to false

d)

Set the TerminateOnDelete attribute to true

87.

A company is developing a global healthcare application that requires the least possible latency for database read/write operations from users in several geographies across the world. The company has hired you as an AWS Certified Solutions Architect Associate to build a solution using Amazon Aurora that offers an effective recovery point objective (RPO) of seconds and a recovery time objective (RTO) of a minute.

Which of the following options would you recommend?

a)

Set up an Amazon Aurora Global Database cluster

b)

Set up an Amazon Aurora serverless Database cluster

c)

Set up an Amazon Aurora provisioned Database cluster

d)

Set up an Amazon Aurora multi-master Database cluster

88.

What is true about Amazon RDS Read Replicas encryption?

a)

If the master database is encrypted, the read replicas can be either encrypted or unencrypted

b)

If the master database is unencrypted, the read replicas can be either encrypted or unencrypted

c)

If the master database is unencrypted, the read replicas are encrypted

d)

If the master database is encrypted, the read replicas are encrypted

89.

An HTTP application is deployed on an Auto Scaling Group, is accessible from an Application Load Balancer (ALB) that provides HTTPS termination, and accesses a PostgreSQL database managed by Amazon RDS.

How should you configure the security groups? (Select three)

a)

The security group of Amazon RDS should have an inbound rule from the security group of the Amazon EC2 instances in the Auto Scaling group on port 5432

b)

The security group of the Application Load Balancer should have an inbound rule from anywhere on port 443

c)

The security group of the Application Load Balancer should have an inbound rule from anywhere on port 80

d)

The security group of the Amazon EC2 instances should have an inbound rule from the security group of the Application Load Balancer on port 80

e)

The security group of Amazon RDS should have an inbound rule from the security group of the Amazon EC2 instances in the Auto Scaling group on port 80

90.

A company has historically operated only in the us-east-1 region and stores encrypted data in Amazon S3 using SSE-KMS. As part of enhancing its security posture as well as improving the backup and recovery architecture, the company wants to store the encrypted data in Amazon S3 that is replicated into the us-west-1 AWS region. The security policies mandate that the data must be encrypted and decrypted using the same key in both AWS regions.

Which of the following represents the best solution to address these requirements?

a)

Create an Amazon CloudWatch scheduled rule to invoke an AWS Lambda function to copy the daily data from the source bucket in us-east-1 region to the destination bucket in us-west-1 region. Provide AWS KMS key access to the AWS Lambda function for encryption and decryption operations on the data in the source and destination Amazon S3 buckets

b)

Enable replication for the current bucket in us-east-1 region into another bucket in us-west-1 region. Share the existing AWS KMS key from us-east-1 region to us-west-1 region

c)

Change the AWS KMS single region key used for the current Amazon S3 bucket into an AWS KMS multi-region key. Enable Amazon S3 batch replication for the existing data in the current bucket in us-east-1 region into another bucket in us-west-1 region

d)

Create a new Amazon S3 bucket in the us-east-1 region with replication enabled from this new bucket into another bucket in us-west-1 region. Enable SSE-KMS encryption on the new bucket in us-east-1 region by using an AWS KMS multi-region key. Copy the existing data from the current Amazon S3 bucket in us-east-1 region into this new Amazon S3 bucket in us-east-1 region

91.

A startup has just developed a video backup service hosted on a fleet of Amazon EC2 instances. The Amazon EC2 instances are behind an Application Load Balancer and the instances are using Amazon Elastic Block Store (Amazon EBS) Volumes for storage. The service provides authenticated users the ability to upload videos that are then saved on the EBS volume attached to a given instance. On the first day of the beta launch, users start complaining that they can see only some of the videos in their uploaded videos backup. Every time the users log into the website, they claim to see a different subset of their uploaded videos.

Which of the following is the MOST optimal solution to make sure that users can view all the uploaded videos? (Select two)

a)

Write a one time job to copy the videos from all Amazon EBS volumes to Amazon RDS and then modify the application to use Amazon RDS for storing the videos

b)

Write a one time job to copy the videos from all Amazon EBS volumes to Amazon S3 Glacier Deep Archive and then modify the application to use Amazon S3 Glacier Deep Archive for storing the videos

c)

Mount Amazon Elastic File System (Amazon EFS) on all Amazon EC2 instances. Write a one time job to copy the videos from all Amazon EBS volumes to Amazon EFS. Modify the application to use Amazon EFS for storing the videos

d)

Write a one time job to copy the videos from all Amazon EBS volumes to Amazon DynamoDB and then modify the application to use Amazon DynamoDB for storing the videos

e)

Write a one time job to copy the videos from all Amazon EBS volumes to Amazon S3 and then modify the application to use Amazon S3 standard for storing the videos

92.

A financial services company wants a single log processing model for all the log files (consisting of system logs, application logs, database logs, etc) that can be processed in a serverless fashion and then durably stored for downstream analytics. The company wants to use an AWS managed service that automatically scales to match the throughput of the log data and requires no ongoing administration.

As a solutions architect, which of the following AWS services would you recommend solving this problem?

a)

Amazon Kinesis Data Firehose

b)

AWS Lambda

c)

Amazon EMR

d)

Amazon Kinesis Data Streams

93.

What does this IAM policy do?

{ "Version": "2012-10-17", "Statement": [ { "Sid": "Mystery Policy", "Action": [ "ec2:RunInstances" ], "Effect": "Allow", "Resource": "*", "Condition": { "StringEquals": { "aws:RequestedRegion": "eu-west-1" } } } ] }

a)

It allows running Amazon EC2 instances only in the eu-west-1 region, and the API call can be made from anywhere in the world

b)

It allows running Amazon EC2 instances anywhere but in the eu-west-1 region

c)

It allows running Amazon EC2 instances in any region when the API call is originating from the eu-west-1 region

d)

It allows running Amazon EC2 instances in the eu-west-1 region, when the API call is made from the eu-west-1 region

94.

What does this IAM policy do?

{ "Version": "2012-10-17", "Statement": [ { "Sid": "Mystery Policy", "Action": [ "ec2:RunInstances" ], "Effect": "Allow", "Resource": "*", "Condition": { "IpAddress": { "aws:SourceIp": "34.50.31.0/24" } } } ] }

a)

It allows starting an Amazon EC2 instance only when they have a Public IP within the 34.50.31.0/24 CIDR block

b)

It allows starting an Amazon EC2 instance only when they have a Private IP within the 34.50.31.0/24 CIDR block

c)

It allows starting an Amazon EC2 instance only when they have an Elastic IP within the 34.50.31.0/24 CIDR block

d)

It allows starting an Amazon EC2 instance only when the IP where the call originates is within the 34.50.31.0/24 CIDR block

95.

A media company is migrating its flagship application from its on-premises data center to AWS for improving the application's read-scaling capability as well as its availability. The existing architecture leverages a Microsoft SQL Server database that sees a heavy read load. The engineering team does a full copy of the production database at the start of the business day to populate a dev database. During this period, application users face high latency leading to a bad user experience.

The company is looking at alternate database options and migrating database engines if required. What would you suggest?

a)

Leverage Amazon Aurora MySQL with Multi-AZ Aurora Replicas and create the dev database by restoring from the automated backups of Amazon Aurora

b)

Leverage Amazon RDS for MySQL with a Multi-AZ deployment and use the standby instance as the dev database

c)

Leverage Amazon Aurora MySQL with Multi-AZ Aurora Replicas and restore the dev database via mysqldump

d)

Leverage Amazon RDS for SQL server with a Multi-AZ deployment and read replicas. Use the read replica as the dev database

96.

A financial services company wants to store confidential data in Amazon S3 and it needs to meet the following data security and compliance norms:

  1. Encryption key usage must be logged for auditing purposes

  2. Encryption Keys must be rotated every year

  3. The data must be encrypted at rest

Which is the MOST operationally efficient solution?

a)

Server-side encryption with AWS Key Management Service (AWS KMS) keys (SSE-KMS) with automatic key rotation

b)

Server-side encryption (SSE-S3) with automatic key rotation

c)

Server-side encryption with AWS Key Management Service (AWS KMS) keys (SSE-KMS) with manual key rotation

d)

Server-side encryption with customer-provided keys (SSE-C) with automatic key rotation

97.

A manufacturing company receives unreliable service from its data center provider because the company is located in an area prone to natural disasters. The company is not ready to fully migrate to the AWS Cloud, but it wants a failover environment on AWS in case the on-premises data center fails. The company runs web servers that connect to external vendors. The data available on AWS and on-premises must be uniform.

Which of the following solutions would have the LEAST amount of downtime?

a)

Set up a Amazon Route 53 failover record. Set up an AWS Direct Connect connection between a VPC and the data center. Run application servers on Amazon EC2 in an Auto Scaling group. Run an AWS Lambda function to execute an AWS CloudFormation template to create an Application Load Balancer

b)

Set up a Amazon Route 53 failover record. Run an AWS Lambda function to execute an AWS CloudFormation template to launch two Amazon EC2 instances. Set up AWS Storage Gateway with stored volumes to back up data to Amazon S3. Set up an AWS Direct Connect connection between a VPC and the data center

c)

Set up a Amazon Route 53 failover record. Execute an AWS CloudFormation template from a script to provision Amazon EC2 instances behind an Application Load Balancer. Set up AWS Storage Gateway with stored volumes to back up data to Amazon S3

d)

Set up a Amazon Route 53 failover record. Run application servers on Amazon EC2 instances behind an Application Load Balancer in an Auto Scaling group. Set up AWS Storage Gateway with stored volumes to back up data to Amazon S3

98.

Upon a security review of your AWS account, an AWS consultant has found that a few Amazon RDS databases are unencrypted. As a Solutions Architect, what steps must be taken to encrypt the Amazon RDS databases?

a)

Enable Multi-AZ for the database, and make sure the standby instance is encrypted. Stop the main database to that the standby database kicks in, then disable Multi-AZ

b)

Take a snapshot of the database, copy it as an encrypted snapshot, and restore a database from the encrypted snapshot. Terminate the previous database

c)

Enable encryption on the Amazon RDS database using the AWS Console

d)

Create a Read Replica of the database, and encrypt the read replica. Promote the read replica as a standalone database, and terminate the previous database

99.

ou would like to store a database password in a secure place, and enable automatic rotation of that password every 90 days. What do you recommend?

a)

AWS Systems Manager Parameter Store

b)

AWS Key Management Service (AWS KMS)

c)

AWS Secrets Manager

d)

AWS CloudHSM

100.

The engineering team at an e-commerce company is working on cost optimizations for Amazon Elastic Compute Cloud (Amazon EC2) instances. The team wants to manage the workload using a mix of on-demand and spot instances across multiple instance types. They would like to create an Auto Scaling group with a mix of these instances.

Which of the following options would allow the engineering team to provision the instances for this use-case?

a)

You can use a launch configuration or a launch template to provision capacity across multiple instance types using both On-Demand Instances and Spot Instances to achieve the desired scale, performance, and cost

b)

You can only use a launch template to provision capacity across multiple instance types using both On-Demand Instances and Spot Instances to achieve the desired scale, performance, and cost

c)

You can neither use a launch configuration nor a launch template to provision capacity across multiple instance types using both On-Demand Instances and Spot Instances to achieve the desired scale, performance, and cost

d)

You can only use a launch configuration to provision capacity across multiple instance types using both On-Demand Instances and Spot Instances to achieve the desired scale, performance, and cost

101.

A company is looking at storing their less frequently accessed files on AWS that can be concurrently accessed by hundreds of Amazon EC2 instances. The company needs the most cost-effective file storage service that provides immediate access to data whenever needed.

Which of the following options represents the best solution for the given requirements?

a)

Amazon S3 Standard-Infrequent Access (S3 Standard-IA) storage class

b)

Amazon Elastic File System (EFS) Standard storage class

c)

Amazon Elastic File System (EFS) Standard–IA storage class

d)

Amazon Elastic File System (EFS) Standard–IA storage class

102.

Consider the following policy associated with an IAM group containing several users:

{ "Version":"2012-10-17", "Id":"EC2TerminationPolicy", "Statement":[ { "Effect":"Deny", "Action":"ec2:*", "Resource":"*", "Condition":{ "StringNotEquals":{ "ec2:Region":"us-west-1" } } }, { "Effect":"Allow", "Action":"ec2:TerminateInstances", "Resource":"*", "Condition":{ "IpAddress":{ "aws:SourceIp":"10.200.200.0/24" } } } ] }

a)

Users belonging to the IAM user group can terminate an Amazon EC2 instance belonging to any region except the us-west-1 region when the user's source IP is 10.200.200.200

b)

Users belonging to the IAM user group cannot terminate an Amazon EC2 instance in the us-west-1 region when the user's source IP is 10.200.200.200

c)

Users belonging to the IAM user group can terminate an Amazon EC2 instance in the us-west-1 region when the EC2 instance's IP address is 10.200.200.200

d)

Users belonging to the IAM user group can terminate an Amazon EC2 instance in the us-west-1 region when the user's source IP is 10.200.200.200

103.

An application runs big data workloads on Amazon Elastic Compute Cloud (Amazon EC2) instances. The application runs 24x7 all round the year and needs at least 20 instances to maintain a minimum acceptable performance threshold and the application needs 300 instances to handle spikes in the workload. Based on historical workloads processed by the application, it needs 80 instances 80% of the time.

As a solutions architect, which of the following would you recommend as the MOST cost-optimal solution so that it can meet the workload demand in a steady state?

a)

Purchase 20 on-demand instances. Use Auto Scaling Group to provision the remaining instances as spot instances per the workload demand

b)

Purchase 80 reserved instances (RIs). Provision additional on-demand and spot instances per the workload demand (Use Auto Scaling Group with launch template to provision the mix of on-demand and spot instances)

c)

Purchase 80 on-demand instances. Provision additional on-demand and spot instances per the workload demand (Use Auto Scaling Group with launch template to provision the mix of on-demand and spot instances)

d)

Purchase 80 spot instances. Use Auto Scaling Group to provision the remaining instances as on-demand instances per the workload demand

104.

A social photo-sharing web application is hosted on Amazon Elastic Compute Cloud (Amazon EC2) instances behind an Elastic Load Balancer. The app gives the users the ability to upload their photos and also shows a leaderboard on the homepage of the app. The uploaded photos are stored in Amazon Simple Storage Service (Amazon S3) and the leaderboard data is maintained in Amazon DynamoDB. The Amazon EC2 instances need to access both Amazon S3 and Amazon DynamoDB for these features.

As a solutions architect, which of the following solutions would you recommend as the MOST secure option?

a)

Attach the appropriate IAM role to the Amazon EC2 instance profile so that the instance can access Amazon S3 and Amazon DynamoDB

b)

Encrypt the AWS credentials via a custom encryption library and save it in a secret directory on the Amazon EC2 instances. The application code can then safely decrypt the AWS credentials to make the API calls to Amazon S3 and Amazon DynamoDB

c)

Configure AWS CLI on the Amazon EC2 instances using a valid IAM user's credentials. The application code can then invoke shell scripts to access Amazon S3 and Amazon DynamoDB via AWS CLI

d)

Save the AWS credentials (access key Id and secret access token) in a configuration file within the application code on the Amazon EC2 instances. Amazon EC2 instances can use these credentials to access Amazon S3 and Amazon DynamoDB

105.

Which of the following IAM policies provides read-only access to the Amazon S3 bucket mybucket and its content?

a)

{ "Version":"2012-10-17", "Statement":[ { "Effect":"Allow", "Action":[ "s3:ListBucket", "s3:GetObject" ], "Resource":"arn:aws:s3:::mybucket/*" } ] }

b)

{ "Version":"2012-10-17", "Statement":[ { "Effect":"Allow", "Action":[ "s3:ListBucket" ], "Resource":"arn:aws:s3:::mybucket" }, { "Effect":"Allow", "Action":[ "s3:GetObject" ], "Resource":"arn:aws:s3:::mybucket/*" } ] }

c)

{ "Version":"2012-10-17", "Statement":[ { "Effect":"Allow", "Action":[ "s3:ListBucket" ], "Resource":"arn:aws:s3:::mybucket/*" }, { "Effect":"Allow", "Action":[ "s3:GetObject" ], "Resource":"arn:aws:s3:::mybucket" } ] }

d)

{ "Version":"2012-10-17", "Statement":[ { "Effect":"Allow", "Action":[ "s3:ListBucket", "s3:GetObject" ], "Resource":"arn:aws:s3:::mybucket" } ] }

106.

A developer has configured inbound traffic for the relevant ports in both the Security Group of the Amazon EC2 instance as well as the network access control list (network ACL) of the subnet for the Amazon EC2 instance. The developer is, however, unable to connect to the service running on the Amazon EC2 instance.

As a solutions architect, how will you fix this issue?

a)

IAM Role defined in the Security Group is different from the IAM Role that is given access in the network access control list (network ACL)

b)

Security Groups are stateful, so allowing inbound traffic to the necessary ports enables the connection. Network access control list (network ACL) are stateless, so you must allow both inbound and outbound traffic

c)

Network access control list (network ACL) are stateful, so allowing inbound traffic to the necessary ports enables the connection. Security Groups are stateless, so you must allow both inbound and outbound traffic

d)

Rules associated with network access control list (network ACL) should never be modified from command line. An attempt to modify rules from command line blocks the rule and results in an erratic behavior

107.

A retail company wants to share sensitive accounting data that is stored in an Amazon RDS database instance with an external auditor. The auditor has its own AWS account and needs its own copy of the database.

Which of the following would you recommend to securely share the database with the auditor?

a)

Create a snapshot of the database in Amazon S3 and assign an IAM role to the auditor to grant access to the object in that bucket

b)

Set up a read replica of the database and configure IAM standard database authentication to grant the auditor access

c)

Export the database contents to text files, store the files in Amazon S3, and create a new IAM user for the auditor with access to that bucket

d)

Create an encrypted snapshot of the database, share the snapshot, and allow access to the AWS Key Management Service (AWS KMS) encryption key

108.

Your company has an on-premises Distributed File System Replication (DFSR) service to keep files synchronized on multiple Windows servers, and would like to migrate to AWS cloud.

What do you recommend as a replacement for the DFSR?

a)

Amazon FSx for Lustre

b)

Amazon Simple Storage Service (Amazon S3)

c)

Amazon FSx for Windows File Server

d)

Amazon Elastic File System (Amazon EFS)

109.

You have a team of developers in your company, and you would like to ensure they can quickly experiment with AWS Managed Policies by attaching them to their accounts, but you would like to prevent them from doing an escalation of privileges, by granting themselves the AdministratorAccess managed policy. How should you proceed?

a)

For each developer, define an IAM permission boundary that will restrict the managed policies they can attach to themselves

b)

Create a Service Control Policy (SCP) on your AWS account that restricts developers from attaching themselves the AdministratorAccess policy

c)

Put the developers into an IAM group, and then define an IAM permission boundary on the group that will restrict the managed policies they can attach to themselves

d)

Attach an IAM policy to your developers, that prevents them from attaching the AdministratorAccess policy

110.

A silicon valley based startup has a two-tier architecture using Amazon EC2 instances for its flagship application. The web servers (listening on port 443), which have been assigned security group A, are in public subnets across two Availability Zones (AZs) and the MSSQL based database instances (listening on port 1433), which have been assigned security group B, are in two private subnets across two Availability Zones (AZs). The DevOps team wants to review the security configurations of the application architecture.

As a solutions architect, which of the following options would you select as the MOST secure configuration? (Select two)

a)

For security group B: Add an inbound rule that allows traffic only from security group A on port 443

b)

For security group A: Add an inbound rule that allows traffic from all sources on port 443. Add an outbound rule with the destination as security group B on port 443

c)

For security group B: Add an inbound rule that allows traffic only from security group A on port 1433

d)

For security group B: Add an inbound rule that allows traffic only from all sources on port 1433

e)

For security group A: Add an inbound rule that allows traffic from all sources on port 443. Add an outbound rule with the destination as security group B on port 1433

111.

You would like to mount a network file system on Linux instances, where files will be stored and accessed frequently at first, and then infrequently. What solution is the MOST cost-effective?

a)

Amazon S3 Glacier Deep Archive

b)

Amazon S3 Intelligent Tiering

c)

Amazon FSx for Lustre

d)

Amazon EFS Infrequent Access

112.

The engineering team at a logistics company has noticed that the Auto Scaling group (ASG) is not terminating an unhealthy Amazon EC2 instance.

As a Solutions Architect, which of the following options would you suggest to troubleshoot the issue? (Select three)

a)

The instance maybe in Impaired status

b)

The Amazon EC2 instance could be a spot instance type, which cannot be terminated by the Auto Scaling group (ASG)

c)

A user might have updated the configuration of the Auto Scaling group (ASG) and increased the minimum number of instances forcing ASG to keep all instances alive

d)

The instance has failed the Elastic Load Balancing (ELB) health check status

e)

The health check grace period for the instance has not expired

113.

A retail company wants to rollout and test a blue-green deployment for its global application in the next 48 hours. Most of the customers use mobile phones which are prone to Domain Name System (DNS) caching. The company has only two days left for the annual Thanksgiving sale to commence.

As a Solutions Architect, which of the following options would you recommend to test the deployment on as many users as possible in the given time frame?

a)

Use AWS Global Accelerator to distribute a portion of traffic to a particular deployment

b)

Use Elastic Load Balancing (ELB) to distribute traffic across deployments

c)

Use Amazon Route 53 weighted routing to spread traffic across different deployments

d)

Use AWS CodeDeploy deployment options to choose the right deployment

114.

An IT company has an Access Control Management (ACM) application that uses Amazon RDS for MySQL but is running into performance issues despite using Read Replicas. The company has hired you as a solutions architect to address these performance-related challenges without moving away from the underlying relational database schema. The company has branch offices across the world, and it needs the solution to work on a global scale.

Which of the following will you recommend as the MOST cost-effective and high-performance solution?

a)

Spin up a Amazon Redshift cluster in each AWS region. Migrate the existing data into Redshift clusters

b)

Spin up Amazon EC2 instances in each AWS region, install MySQL databases and migrate the existing data into these new databases

c)

Use Amazon DynamoDB Global Tables to provide fast, local, read and write performance in each region

d)

Use Amazon Aurora Global Database to enable fast local reads with low latency in each region

115.

Your company has a monthly big data workload, running for about 2 hours, which can be efficiently distributed across multiple servers of various sizes, with a variable number of CPUs. The solution for the workload should be able to withstand server failures.

Which is the MOST cost-optimal solution for this workload?

a)

Run the workload on a Spot Fleet

b)

Run the workload on Reserved Instances (RI)

c)

Run the workload on Spot Instances

d)

Run the workload on Dedicated Hosts

116.

A cybersecurity company uses a fleet of Amazon EC2 instances to run a proprietary application. The infrastructure maintenance group at the company wants to be notified via an email whenever the CPU utilization for any of the Amazon EC2 instances breaches a certain threshold.

Which of the following services would you use for building a solution with the LEAST amount of development effort? (Select two)

a)

AWS Lambda

b)

Amazon Simple Notification Service (Amazon SNS)

c)

AWS Step Functions

d)

Amazon CloudWatch

e)

Amazon Simple Queue Service (Amazon SQS)

117.

An IT company provides Amazon Simple Storage Service (Amazon S3) bucket access to specific users within the same account for completing project specific work. With changing business requirements, cross-account S3 access requests are also growing every month. The company is looking for a solution that can offer user level as well as account-level access permissions for the data stored in Amazon S3 buckets.

As a Solutions Architect, which of the following would you suggest as the MOST optimized way of controlling access for this use-case?

a)

Use Access Control Lists (ACLs)

b)

Use Amazon S3 Bucket Policies

c)

Use Identity and Access Management (IAM) policies

d)

Use Security Groups

118.

The engineering manager for a content management application wants to set up Amazon RDS read replicas to provide enhanced performance and read scalability. The manager wants to understand the data transfer charges while setting up Amazon RDS read replicas.

Which of the following would you identify as correct regarding the data transfer charges for Amazon RDS read replicas?

a)

There are data transfer charges for replicating data across AWS Regions

b)

There are data transfer charges for replicating data within the same AWS Region

c)

There are no data transfer charges for replicating data across AWS Regions

d)

There are data transfer charges for replicating data within the same Availability Zone (AZ)

119.

An e-commerce company operates multiple AWS accounts and has interconnected these accounts in a hub-and-spoke style using the AWS Transit Gateway. Amazon Virtual Private Cloud (Amazon VPCs) have been provisioned across these AWS accounts to facilitate network isolation.

Which of the following solutions would reduce both the administrative overhead and the costs while providing shared access to services required by workloads in each of the VPCs?

a)

Use VPCs connected with AWS Direct Connect

b)

Build a shared services Amazon Virtual Private Cloud (Amazon VPC)

c)

Use Transit VPC to reduce cost and share the resources across Amazon Virtual Private Cloud (Amazon VPCs)

d)

Use Fully meshed VPC Peering connection

120.

A company has recently launched a new mobile gaming application that the users are adopting rapidly. The company uses Amazon RDS MySQL as the database. The engineering team wants an urgent solution to this issue where the rapidly increasing workload might exceed the available database storage.

As a solutions architect, which of the following solutions would you recommend so that it requires minimum development and systems administration effort to address this requirement?

a)

Enable storage auto-scaling for Amazon RDS MySQL

b)

Create read replica for Amazon RDS MySQL

c)

Migrate RDS MySQL database to Amazon Aurora which offers storage auto-scaling

d)

Migrate Amazon RDS MySQL database to Amazon DynamoDB which automatically allocates storage space when required

121.

A health-care solutions company wants to run their applications on single-tenant hardware to meet regulatory guidelines.

Which of the following is the MOST cost-effective way of isolating their Amazon Elastic Compute Cloud (Amazon EC2)instances to a single tenant?

a)

Dedicated Instances

b)

On-Demand Instances

c)

Spot Instances

d)

Dedicated Hosts

122.

An analytics company wants to improve the performance of its big data processing workflows running on Amazon Elastic File System (Amazon EFS). Which of the following performance modes should be used for Amazon EFS to address this requirement?

a)

Bursting Throughput

b)

Max I/O

c)

General Purpose

d)

Provisioned Throughput

123.

A media company has created an AWS Direct Connect connection for migrating its flagship application to the AWS Cloud. The on-premises application writes hundreds of video files into a mounted NFS file system daily. Post-migration, the company will host the application on an Amazon EC2 instance with a mounted Amazon Elastic File System (Amazon EFS) file system. Before the migration cutover, the company must build a process that will replicate the newly created on-premises video files to the Amazon EFS file system.

Which of the following represents the MOST operationally efficient way to meet this requirement?

a)

Configure an AWS DataSync agent on the on-premises server that has access to the NFS file system. Transfer data over the AWS Direct Connect connection to an AWS PrivateLink interface VPC endpoint for Amazon EFS by using a private VIF. Set up an AWS DataSync scheduled task to send the video files to the Amazon EFS file system every 24 hours

b)

Configure an AWS DataSync agent on the on-premises server that has access to the NFS file system. Transfer data over the AWS Direct Connect connection to an AWS VPC peering endpoint for Amazon EFS by using a private VIF. Set up an AWS DataSync scheduled task to send the video files to the Amazon EFS file system every 24 hours

c)

Configure an AWS DataSync agent on the on-premises server that has access to the NFS file system. Transfer data over the AWS Direct Connect connection to an Amazon S3 bucket by using a VPC gateway endpoint for Amazon S3. Set up an AWS Lambda function to process event notifications from Amazon S3 and copy the video files from Amazon S3 to the Amazon EFS file system

d)

Configure an AWS DataSync agent on the on-premises server that has access to the NFS file system. Transfer data over the AWS Direct Connect connection to an Amazon S3 bucket by using public VIF. Set up an AWS Lambda function to process event notifications from Amazon S3 and copy the video files from Amazon S3 to the Amazon EFS file system

124.

You would like to use AWS Snowball to move on-premises backups into a long term archival tier on AWS. Which solution provides the MOST cost savings?

a)

Create an AWS Snowball job and target an Amazon S3 bucket. Create a lifecycle policy to transition this data to Amazon S3 Glacier on the same day

b)

Create an AWS Snowball job and target a Amazon S3 Glacier Vault

c)

Create a AWS Snowball job and target an Amazon S3 Glacier Deep Archive Vault

d)

Create an AWS Snowball job and target an Amazon S3 bucket. Create a lifecycle policy to transition this data to Amazon S3 Glacier Deep Archive on the same day

125.

An application is currently hosted on four Amazon EC2 instances (behind Application Load Balancer) deployed in a single Availability Zone (AZ). To maintain an acceptable level of end-user experience, the application needs at least 4 instances to be always available.

As a solutions architect, which of the following would you recommend so that the application achieves high availability with MINIMUM cost?

a)

Deploy the instances in three Availability Zones (AZs). Launch two instances in each Availability Zone (AZ)

b)

Deploy the instances in two Availability Zones (AZs). Launch four instances in each Availability Zone (AZ)

c)

Deploy the instances in two Availability Zones (AZs). Launch two instances in each Availability Zone (AZ)

d)

Deploy the instances in one Availability Zones. Launch two instances in the Availability Zone (AZ)

126.

To improve the performance and security of the application, the engineering team at a company has created an Amazon CloudFront distribution with an Application Load Balancer as the custom origin. The team has also set up an AWS Web Application Firewall (AWS WAF) with Amazon CloudFront distribution. The security team at the company has noticed a surge in malicious attacks from a specific IP address to steal sensitive data stored on the Amazon EC2 instances.

As a solutions architect, which of the following actions would you recommend to stop the attacks?

a)

Create a deny rule for the malicious IP in the network access control list (network ACL) associated with each of the instances

b)

Create a ticket with AWS support to take action against the malicious IP

c)

Create an IP match condition in the AWS WAF to block the malicious IP address

d)

Create a deny rule for the malicious IP in the Security Groups associated with each of the instances

127.

Amazon EC2 Auto Scaling needs to terminate an instance from Availability Zone (AZ) us-east-1a as it has the most number of instances amongst the Availability Zone (AZs) being used currently. There are 4 instances in the Availability Zone (AZ) us-east-1a like so: Instance A has the oldest launch template, Instance B has the oldest launch configuration, Instance C has the newest launch configuration and Instance D is closest to the next billing hour.

Which of the following instances would be terminated per the default termination policy?

a)

Instance A

b)

Instance B

c)

Instance D

d)

Instance C

128.

An IT company has built a solution wherein an Amazon Redshift cluster writes data to an Amazon S3 bucket belonging to a different AWS account. However, it is found that the files created in the Amazon S3 bucket using the UNLOAD command from the Amazon Redshift cluster are not even accessible to the Amazon S3 bucket owner.

What could be the reason for this denial of permission for the bucket owner?

a)

When objects are uploaded to Amazon S3 bucket from a different AWS account, the S3 bucket owner will get implicit permissions to access these objects. This issue seems to be due to an upload error that can be fixed by providing manual access from AWS console

b)

By default, an Amazon S3 object is owned by the AWS account that uploaded it. So the Amazon S3 bucket owner will not implicitly have access to the objects written by the Amazon Redshift cluster

c)

The owner of an Amazon S3 bucket has implicit access to all objects in his bucket. Permissions are set on objects after they are completely copied to the target location. Since the owner is unable to access the uploaded files, the write operation may be still in progress

d)

When two different AWS accounts are accessing an Amazon S3 bucket, both the accounts must share the bucket policies. An erroneous policy can lead to such permission failures

129.

A Machine Learning research group uses a proprietary computer vision application hosted on an Amazon EC2 instance. Every time the instance needs to be stopped and started again, the application takes about 3 minutes to start as some auxiliary software programs need to be executed so that the application can function. The research group would like to minimize the application boostrap time whenever the system needs to be stopped and then started at a later point in time.

As a solutions architect, which of the following solutions would you recommend for this use-case?

a)

Use Amazon EC2 User-Data

b)

Create an Amazon Machine Image (AMI) and launch your Amazon EC2 instances from that

c)

Use Amazon EC2 Instance Hibernate

d)

Use Amazon EC2 Meta-Data

130.

You are establishing a monitoring solution for desktop systems, that will be sending telemetry data into AWS every 1 minute. Data for each system must be processed in order, independently, and you would like to scale the number of consumers to be possibly equal to the number of desktop systems that are being monitored.

What do you recommend?

a)

Use an Amazon Simple Queue Service (Amazon SQS) standard queue, and send the telemetry data as is

b)

Use an Amazon Simple Queue Service (Amazon SQS) FIFO (First-In-First-Out) queue, and make sure the telemetry data is sent with a Group ID attribute representing the value of the Desktop ID

c)

Use an Amazon Kinesis Data Stream, and send the telemetry data with a Partition ID that uses the value of the Desktop ID

d)

Use an Amazon Simple Queue Service (Amazon SQS) FIFO (First-In-First-Out) queue, and send the telemetry data as is

131.

A media startup is looking at hosting their web application on AWS Cloud. The application will be accessed by users from different geographic regions of the world to upload and download video files that can reach a maximum size of 10 gigabytes. The startup wants the solution to be cost-effective and scalable with the lowest possible latency for a great user experience.

As a Solutions Architect, which of the following will you suggest as an optimal solution to meet the given requirements?

a)

Use Amazon S3 for hosting the web application and use Amazon CloudFront for faster distribution of content to geographically dispersed users

b)

Use Amazon EC2 with AWS Global Accelerator for faster distribution of content, while using Amazon S3 as storage service

c)

Use Amazon S3 for hosting the web application and use Amazon S3 Transfer Acceleration (Amazon S3TA) to reduce the latency that geographically dispersed users might face

d)

Use Amazon EC2 with Amazon ElastiCache for faster distribution of content, while Amazon S3 can be used as a storage service

132.

A global manufacturing company with facilities in the US, Europe, and Asia is designing a new distributed application to optimize its procurement workflow. The orders booked in one AWS Region should be visible to all AWS Regions in a second or less. The database should be able to facilitate failover with a short Recovery Time Objective (RTO). The uptime of the application is critical to ensure that the manufacturing processes are not impacted.

As a solutions architect, which of the following will you recommend as the MOST cost-effective solution?

a)

Provision Amazon RDS for MySQL with a cross-Region read replica

b)

Provision Amazon DynamoDB global tables

c)

Provision Amazon RDS for PostgreSQL with a cross-Region read replica

d)

Provision Amazon Aurora Global Database

133.

A developer has configured inbound traffic for the relevant ports in both the Security Group of the Amazon EC2 instance as well as the Network Access Control List (Network ACL) of the subnet for the Amazon EC2 instance. The developer is, however, unable to connect to the service running on the Amazon EC2 instance.

As a solutions architect, how will you fix this issue?

a)

IAM Role defined in the Security Group is different from the IAM Role that is given access in the Network ACLs

b)

Rules associated with Network ACLs should never be modified from command line. An attempt to modify rules from command line blocks the rule and results in an erratic behavior

c)

Network ACLs are stateful, so allowing inbound traffic to the necessary ports enables the connection. Security Groups are stateless, so you must allow both inbound and outbound traffic

d)

Security Groups are stateful, so allowing inbound traffic to the necessary ports enables the connection. Network ACLs are stateless, so you must allow both inbound and outbound traffic

134.

The DevOps team at a multi-national company is helping its subsidiaries standardize Amazon EC2 instances by using the same Amazon Machine Image (AMI). Some of these subsidiaries are in the same AWS region but use different AWS accounts whereas others are in different AWS regions but use the same AWS account as the parent company. The DevOps team has hired you as a solutions architect for this project.

Which of the following would you identify as CORRECT regarding the capabilities of an Amazon Machine Image (AMI)? (Select three)

a)

You can share an Amazon Machine Image (AMI) with another AWS account

b)

You can copy an Amazon Machine Image (AMI) across AWS Regions

c)

Copying an Amazon Machine Image (AMI) backed by an encrypted snapshot cannot result in an unencrypted target snapshot

d)

You cannot copy an Amazon Machine Image (AMI) across AWS Regions

e)

Copying an Amazon Machine Image (AMI) backed by an encrypted snapshot results in an unencrypted target snapshot

135.

Question 5Skipped

A company recently experienced a database outage in its on-premises data center. The company now wants to migrate to a reliable database solution on AWS that minimizes data loss and stores every transaction on at least two nodes.

Which of the following solutions meets these requirements?

a)

Set up an Amazon RDS MySQL DB instance and then create a read replica in another Availability Zone that synchronously replicates the data

b)

Set up an Amazon RDS MySQL DB instance and then create a read replica in a separate AWS Region that synchronously replicates the data

c)

Set up an Amazon RDS MySQL DB instance with Multi-AZ functionality enabled to synchronously replicate the data

d)

Set up an Amazon EC2 instance with a MySQL DB engine installed that triggers an AWS Lambda function to synchronously replicate the data to an Amazon RDS MySQL DB instance

136.

A leading news aggregation company offers hundreds of digital products and services for customers ranging from law firms to banks to consumers. The company bills its clients based on per unit of clickstream data provided to the clients. As the company operates in a regulated industry, it needs to have the same ordered clickstream data available for auditing within a window of 7 days.

As a solutions architect, which of the following AWS services provides the ability to run the billing process and auditing process on the given clickstream data in the same order?

a)

Amazon Kinesis Data Firehose

b)

Amazon Kinesis Data Streams

c)

Amazon Kinesis Data Analytics

d)

Amazon Simple Queue Service (SQS)

137.

The DevOps team at an IT company has created a custom VPC (V1) and attached an Internet Gateway (I1) to the VPC. The team has also created a subnet (S1) in this custom VPC and added a route to this subnet's route table (R1) that directs internet-bound traffic to the Internet Gateway. Now the team launches an Amazon EC2 instance (E1) in the subnet S1 and assigns a public IPv4 address to this instance. Next the team also launches a Network Address Translation (NAT) instance (N1) in the subnet S1.

Under the given infrastructure setup, which of the following entities is doing the Network Address Translation for the Amazon EC2 instance E1?

a)

Subnet (S1)

b)

Internet Gateway (I1)

c)

Network Address Translation (NAT) instance (N1)

d)

Route Table (R1)

138.

A gaming company uses Application Load Balancers in front of Amazon EC2 instances for different services and microservices. The architecture has now become complex with too many Application Load Balancers in multiple AWS Regions. Security updates, firewall configurations, and traffic routing logic have become complex with too many IP addresses and configurations.

The company is looking at an easy and effective way to bring down the number of IP addresses allowed by the firewall and easily manage the entire network infrastructure. Which of these options represents an appropriate solution for this requirement?

a)

Assign an Elastic IP to an Auto Scaling Group (ASG), and set up multiple Amazon EC2 instances to run behind the Auto Scaling Groups, for each of the Regions

b)

Configure Elastic IPs for each of the Application Load Balancers in each Region

c)

Set up a Network Load Balancer with elastic IP address. Register the private IPs of all the Application Load Balancers as targets of this Network Load Balancer

d)

Launch AWS Global Accelerator and create endpoints for all the Regions. Register the Application Load Balancers of each Region to the corresponding endpoints

139.

A financial services company is migrating their messaging queues from self-managed message-oriented middleware systems to Amazon Simple Queue Service (Amazon SQS). The development team at the company wants to minimize the costs of using Amazon SQS.

As a solutions architect, which of the following options would you recommend for the given use-case?

a)

Use SQS message timer to retrieve messages from your Amazon SQS queues

b)

Use SQS short polling to retrieve messages from your Amazon SQS queues

c)

Use SQS visibility timeout to retrieve messages from your Amazon SQS queues

d)

Use SQS long polling to retrieve messages from your Amazon SQS queues

140.

An IT consultant is helping a small business revamp their technology infrastructure on the AWS Cloud. The business has two AWS accounts and all resources are provisioned in the us-west-2 region. The IT consultant is trying to launch an Amazon EC2 instance in each of the two AWS accounts such that the instances are in the same Availability Zone (AZ) of the us-west-2 region. Even after selecting the same default subnet (us-west-2a) while launching the instances in each of the AWS accounts, the IT consultant notices that the Availability Zones (AZs) are still different.

As a solutions architect, which of the following would you suggest resolving this issue?

a)

Use Availability Zone (AZ) ID to uniquely identify the Availability Zones across the two AWS Accounts

b)

Use the default subnet to uniquely identify the Availability Zones across the two AWS Accounts

c)

Reach out to AWS Support for creating the Amazon EC2 instances in the same Availability Zone (AZ) across the two AWS accounts

d)

Use the default VPC to uniquely identify the Availability Zones across the two AWS Accounts

141.

An e-commerce company runs its web application on Amazon EC2 instances in an Auto Scaling group and it's configured to handle consumer orders in an Amazon Simple Queue Service (Amazon SQS) queue for downstream processing. The DevOps team has observed that the performance of the application goes down in case of a sudden spike in orders received.

As a solutions architect, which of the following solutions would you recommend to address this use-case?

a)

Use a step scaling policy based on a custom Amazon SQS queue metric

b)

Use a target tracking scaling policy based on a custom Amazon SQS queue metric

c)

Use a simple scaling policy based on a custom Amazon SQS queue metric

d)

Use a scheduled scaling policy based on a custom Amazon SQS queue metric

142.

A company has set up AWS Organizations to manage several departments running their own AWS accounts. The departments operate from different countries and are spread across various AWS Regions. The company wants to set up a consistent resource provisioning process across departments so that each resource follows pre-defined configurations such as using a specific type of Amazon EC2 instances, specific IAM roles for AWS Lambda functions, etc.

As a solutions architect, which of the following options would you recommend for this use-case?

a)

Use AWS CloudFormation stacks to deploy the same template across AWS accounts and regions

b)

Use AWS Resource Access Manager (AWS RAM) to deploy the same template across AWS accounts and regions

c)

Use AWS CloudFormation StackSets to deploy the same template across AWS accounts and regions

d)

Use AWS CloudFormation templates to deploy the same template across AWS accounts and regions

143.

A big data analytics company is working on a real-time vehicle tracking solution. The data processing workflow involves both I/O intensive and throughput intensive database workloads. The development team needs to store this real-time data in a NoSQL database hosted on an Amazon EC2 instance and needs to support up to 25,000 IOPS per volume.

As a solutions architect, which of the following Amazon Elastic Block Store (Amazon EBS) volume types would you recommend for this use-case?

a)

Throughput Optimized HDD (st1)

b)

Provisioned IOPS SSD (io1)

c)

Cold HDD (sc1)

d)

General Purpose SSD (gp2)

144.

A video conferencing application is hosted on a fleet of EC2 instances which are part of an Auto Scaling group. The Auto Scaling group uses a Launch Template (LT1) with "dedicated" instance tenancy but the VPC (V1) used by the Launch Template LT1 has the instance tenancy set to default. Later the DevOps team creates a new Launch Template (LT2) with shared (default) instance tenancy but the VPC (V2) used by the Launch Template LT2 has the instance tenancy set to dedicated.

Which of the following is correct regarding the instances launched via Launch Template LT1 and Launch Template LT2?

a)

The instances launched by both Launch Template LT1 and Launch Template LT2 will have dedicated instance tenancy

b)

The instances launched by both Launch Template LT1 and Launch Template LT2 will have default instance tenancy

c)

The instances launched by Launch Template LT1 will have dedicated instance tenancy while the instances launched by the Launch Template LT2 will have shared (default) instance tenancy

d)

The instances launched by Launch Template LT1 will have default instance tenancy while the instances launched by the Launch Template LT2 will have dedicated instance tenancy

145.

A financial services company has recently migrated from on-premises infrastructure to AWS Cloud. The DevOps team wants to implement a solution that allows all resource configurations to be reviewed and make sure that they meet compliance guidelines. Also, the solution should be able to offer the capability to look into the resource configuration history across the application stack.

As a solutions architect, which of the following solutions would you recommend to the team?

a)

Use AWS Systems Manager to review resource configurations to meet compliance guidelines and maintain a history of resource configuration changes

b)

Use AWS CloudTrail to review resource configurations to meet compliance guidelines and maintain a history of resource configuration changes

c)

Use AWS Config to review resource configurations to meet compliance guidelines and maintain a history of resource configuration changes

d)

Use Amazon CloudWatch to review resource configurations to meet compliance guidelines and maintain a history of resource configuration changes

146.

An IT company is looking to move its on-premises infrastructure to AWS Cloud. The company has a portfolio of applications with a few of them using server bound licenses that are valid for the next year. To utilize the licenses, the CTO wants to use dedicated hosts for a one year term and then migrate the given instances to default tenancy thereafter.

As a solutions architect, which of the following options would you identify as CORRECT for changing the tenancy of an instance after you have launched it? (Select two)

a)

You can change the tenancy of an instance from dedicated to host

b)

You can change the tenancy of an instance from host to dedicated

c)

You can change the tenancy of an instance from default to dedicated

d)

You can change the tenancy of an instance from default to host

e)

You can change the tenancy of an instance from dedicated to default

147.

Your application is hosted by a provider on yourapp.provider.com. You would like to have your users access your application using www.your-domain.com, which you own and manage under Amazon Route 53.

Which Amazon Route 53 record should you create?

a)

Create an A record

b)

Create a PTR record

c)

Create an Alias Record

d)

Create a CNAME record

148.

A company has its application servers in the public subnet that connect to the Amazon RDS instances in the private subnet. For regular maintenance, the Amazon RDS instances need patch fixes that need to be downloaded from the internet.

Considering the company uses only IPv4 addressing and is looking for a fully managed service, which of the following would you suggest as an optimal solution?

a)

Configure a Network Address Translation instance (NAT instance) in the public subnet of the VPC

b)

Configure a Network Address Translation gateway (NAT gateway) in the public subnet of the VPC

c)

Configure the Internet Gateway of the VPC to be accessible to the private subnet resources by changing the route tables

d)

Configure an Egress-only internet gateway for the resources in the private subnet of the VPC

149.

A media company wants a low-latency way to distribute live sports results which are delivered via a proprietary application using UDP protocol.

As a solutions architect, which of the following solutions would you recommend such that it offers the BEST performance for this use case?

a)

Use Elastic Load Balancing (ELB) to provide a low latency way to distribute live sports results

b)

Use AWS Global Accelerator to provide a low latency way to distribute live sports results

c)

Use Auto Scaling group to provide a low latency way to distribute live sports results

d)

Use Amazon CloudFront to provide a low latency way to distribute live sports results

150.

A DevOps engineer at an IT company just upgraded an Amazon EC2 instance type from t2.nano (0.5G of RAM, 1 vCPU) to u-12tb1.metal (12.3 TB of RAM, 448 vCPUs). How would you categorize this upgrade?

a)

This is an example of high availability

b)

This is a scale up example of horizontal scalability

c)

This is a scale up example of vertical scalability

d)

This is a scale out example of vertical scalability

151.

An e-commerce company is using Elastic Load Balancing (ELB) for its fleet of Amazon EC2 instances spread across two Availability Zones (AZs), with one instance as a target in Availability Zone A and four instances as targets in Availability Zone B. The company is doing benchmarking for server performance when cross-zone load balancing is enabled compared to the case when cross-zone load balancing is disabled.

As a solutions architect, which of the following traffic distribution outcomes would you identify as correct?

a)

With cross-zone load balancing enabled, one instance in Availability Zone A receives 20% traffic and four instances in Availability Zone B receive 20% traffic each. With cross-zone load balancing disabled, one instance in Availability Zone A receives no traffic and four instances in Availability Zone B receive 25% traffic each

b)

With cross-zone load balancing enabled, one instance in Availability Zone A receives 20% traffic and four instances in Availability Zone B receive 20% traffic each. With cross-zone load balancing disabled, one instance in Availability Zone A receives 50% traffic and four instances in Availability Zone B receive 12.5% traffic each

c)

With cross-zone load balancing enabled, one instance in Availability Zone A receives 50% traffic and four instances in Availability Zone B receive 12.5% traffic each. With cross-zone load balancing disabled, one instance in Availability Zone A receives 20% traffic and four instances in Availability Zone B receive 20% traffic each

d)

With cross-zone load balancing enabled, one instance in Availability Zone A receives no traffic and four instances in Availability Zone B receive 25% traffic each. With cross-zone load balancing disabled, one instance in Availability Zone A receives 50% traffic and four instances in Availability Zone B receive 12.5% traffic each

152.

A company wants to improve its gaming application by adding a leaderboard that uses a complex proprietary algorithm based on the participating user's performance metrics to identify the top users on a real-time basis. The technical requirements mandate high elasticity, low latency, and real-time processing to deliver customizable user data for the community of users. The leaderboard would be accessed by millions of users simultaneously.

Which of the following options support the case for using Amazon ElastiCache to meet the given requirements? (Select two)

a)

Use Amazon ElastiCache to improve the performance of compute-intensive workloads

b)

Use Amazon ElastiCache to improve latency and throughput for read-heavy application workloads

c)

Use Amazon ElastiCache to improve the performance of Extract-Transform-Load (ETL) workloads

d)

Use Amazon ElastiCache to improve latency and throughput for write-heavy application workloads

e)

Use Amazon ElastiCache to run highly complex JOIN queries

153.

A small business has been running its IT systems on the on-premises infrastructure but the business now plans to migrate to AWS Cloud for operational efficiencies.

As a Solutions Architect, can you suggest a cost-effective serverless solution for its flagship application that has both static and dynamic content?

a)

Host the static content on Amazon S3 and use Amazon EC2 with Amazon RDS for generating the dynamic content. Amazon CloudFront can be configured in front of Amazon EC2 instance, to make global distribution easy

b)

Host both the static and dynamic content of the web application on Amazon S3 and use Amazon CloudFront for distribution across diverse regions/countries

c)

Host both the static and dynamic content of the web application on Amazon EC2 with Amazon RDS as database. Amazon CloudFront should be configured to distribute the content across geographically disperse regions

d)

Host the static content on Amazon S3 and use AWS Lambda with Amazon DynamoDB for the serverless web application that handles dynamic content. Amazon CloudFront will sit in front of AWS Lambda for distribution across diverse regions

154.

A financial services company wants to identify any sensitive data stored on its Amazon S3 buckets. The company also wants to monitor and protect all data stored on Amazon S3 against any malicious activity.

As a solutions architect, which of the following solutions would you recommend to help address the given requirements?

a)

Use Amazon Macie to monitor any malicious activity on data stored in Amazon S3. Use Amazon GuardDuty to identify any sensitive data stored on Amazon S3

b)

Use Amazon GuardDuty to monitor any malicious activity on data stored in Amazon S3 as well as to identify any sensitive data stored on Amazon S3

c)

Use Amazon Macie to monitor any malicious activity on data stored in Amazon S3 as well as to identify any sensitive data stored on Amazon S3

d)

Use Amazon GuardDuty to monitor any malicious activity on data stored in Amazon S3. Use Amazon Macie to identify any sensitive data stored on Amazon S3

155.

The engineering team at a social media company wants to use Amazon CloudWatch alarms to automatically recover Amazon EC2 instances if they become impaired. The team has hired you as a solutions architect to provide subject matter expertise.

As a solutions architect, which of the following statements would you identify as CORRECT regarding this automatic recovery process? (Select two)

a)

During instance recovery, the instance is migrated during an instance reboot, and any data that is in-memory is retained

b)

Terminated Amazon EC2 instances can be recovered if they are configured at the launch of instance

c)

A recovered instance is identical to the original instance, including the instance ID, private IP addresses, Elastic IP addresses, and all instance metadata

d)

If your instance has a public IPv4 address, it does not retain the public IPv4 address after recovery

e)

If your instance has a public IPv4 address, it retains the public IPv4 address after recovery

156.

The business analytics team at a company has been running ad-hoc queries on Oracle and PostgreSQL services on Amazon RDS to prepare daily reports for senior management. To facilitate the business analytics reporting, the engineering team now wants to continuously replicate this data and consolidate these databases into a petabyte-scale data warehouse by streaming data to Amazon Redshift.

As a solutions architect, which of the following would you recommend as the MOST resource-efficient solution that requires the LEAST amount of development time without the need to manage the underlying infrastructure?

a)

Use AWS Glue to replicate the data from the databases into Amazon Redshift

b)

Use AWS EMR to replicate the data from the databases into Amazon Redshift

c)

Use AWS Database Migration Service (AWS DMS) to replicate the data from the databases into Amazon Redshift

d)

Use Amazon Kinesis Data Streams to replicate the data from the databases into Amazon Redshift

157.

A company has a license-based, expensive, legacy commercial database solution deployed at its on-premises data center. The company wants to migrate this database to a more efficient, open-source, and cost-effective option on AWS Cloud. The CTO at the company wants a solution that can handle complex database configurations such as secondary indexes, foreign keys, and stored procedures.

As a solutions architect, which of the following AWS services should be combined to handle this use-case? (Select two)

a)

AWS Database Migration Service (AWS DMS)

b)

AWS Schema Conversion Tool (AWS SCT)

c)

Basic Schema Copy

d)

AWS Glue

e)

AWS Snowball Edge

158.

A data analytics company manages an application that stores user data in a Amazon DynamoDB table. The development team has observed that once in a while, the application writes corrupted data in the Amazon DynamoDB table. As soon as the issue is detected, the team needs to remove the corrupted data at the earliest.

What do you recommend?

a)

Configure the Amazon DynamoDB table as a global table and point the application to use the table from another AWS region that has no corrupted data

b)

Use Amazon DynamoDB on-demand backup to restore the table to the state just before corrupted data was written

c)

Use Amazon DynamoDB Streams to restore the table to the state just before corrupted data was written

d)

Use Amazon DynamoDB point in time recovery to restore the table to the state just before corrupted data was written

159.

An IT training company hosted its website on Amazon S3 a couple of years ago. Due to COVID-19 related travel restrictions, the training website has suddenly gained traction. With an almost 300% increase in the requests served per day, the company's AWS costs have sky-rocketed for just the Amazon S3 outbound data costs.

As a Solutions Architect, can you suggest an alternate method to reduce costs while keeping the latency low?

a)

To reduce Amazon S3 cost, the data can be saved on an Amazon EBS volume connected to an Amazon EC2 instance that can host the application

b)

Configure Amazon S3 Batch Operations to read data in bulk at one go, to reduce the number of calls made to Amazon S3 buckets

c)

Use Amazon EFS service, as it provides a shared, scalable, fully managed elastic NFS file system for storing AWS Cloud or on-premises data

d)

Configure Amazon CloudFront to distribute the data hosted on Amazon S3 cost-effectively

160.

A media streaming company is looking to migrate its on-premises infrastructure into the AWS Cloud. The engineering team is looking for a fully managed NoSQL persistent data store with in-memory caching to maintain low latency that is critical for real-time scenarios such as video streaming and interactive content. The team expects the number of concurrent users to touch up to a million so the database should be able to scale elastically.

As a solutions architect, which of the following AWS services would you recommend for this use-case?

a)

Amazon ElastiCache

b)

Amazon DocumentDB

c)

Amazon RDS

d)

Amazon DynamoDB

161.

The DevOps team at an IT company has recently migrated to AWS and they are configuring security groups for their two-tier application with public web servers and private database servers. The team wants to understand the allowed configuration options for an inbound rule for a security group.

As a solutions architect, which of the following would you identify as an INVALID option for setting up such a configuration?

a)

You can use an IP address as the custom source for the inbound rule

b)

You can use a range of IP addresses in CIDR block notation as the custom source for the inbound rule

c)

You can use an Internet Gateway ID as the custom source for the inbound rule

d)

You can use a security group as the custom source for the inbound rule

162.

A startup has created a new web application for users to complete a risk assessment survey for COVID-19 symptoms via a self-administered questionnaire. The startup has purchased the domain covid19survey.com using Amazon Route 53. The web development team would like to create Amazon Route 53 record so that all traffic for covid19survey.com is routed to www.covid19survey.com.

As a solutions architect, which of the following is the MOST cost-effective solution that you would recommend to the web development team?

a)

Create an MX record for covid19survey.com that routes traffic to www.covid19survey.com

b)

Create an NS record for covid19survey.com that routes traffic to www.covid19survey.com

c)

Create a CNAME record for covid19survey.com that routes traffic to www.covid19survey.com

d)

Create an alias record for covid19survey.com that routes traffic to www.covid19survey.com

163.

An engineering lead is designing a VPC with public and private subnets. The VPC and subnets use IPv4 CIDR blocks. There is one public subnet and one private subnet in each of three Availability Zones (AZs) for high availability. An internet gateway is used to provide internet access for the public subnets. The private subnets require access to the internet to allow Amazon EC2 instances to download software updates.

Which of the following options represents the correct solution to set up internet access for the private subnets?

a)

Set up three NAT gateways, one in each public subnet in each AZ. Create a custom route table for each AZ that forwards non-local traffic to the NAT gateway in its AZ

b)

Set up three egress-only internet gateways, one in each public subnet in each AZ. Create a custom route table for each AZ that forwards non-local traffic to the egress-only internet gateway in its AZ

c)

Set up three Internet gateways, one in each private subnet in each AZ. Create a custom route table for each AZ that forwards non-local traffic to the Internet gateway in its AZ

d)

Set up three NAT gateways, one in each private subnet in each AZ. Create a custom route table for each AZ that forwards non-local traffic to the NAT gateway in its AZ

164.

A global pharmaceutical company wants to move most of the on-premises data into Amazon S3, Amazon Elastic File System (Amazon EFS), and Amazon FSx for Windows File Server easily, quickly, and cost-effectively.

As a solutions architect, which of the following solutions would you recommend as the BEST fit to automate and accelerate online data transfers to these AWS storage services?

a)

Use AWS DataSync to automate and accelerate online data transfers to the given AWS storage services

b)

Use File Gateway to automate and accelerate online data transfers to the given AWS storage services

c)

Use AWS Transfer Family to automate and accelerate online data transfers to the given AWS storage services

d)

Use AWS Snowball Edge Storage Optimized device to automate and accelerate online data transfers to the given AWS storage services

165.

A financial services company is looking to move its on-premises IT infrastructure to AWS Cloud. The company has multiple long-term server bound licenses across the application stack and the CTO wants to continue to utilize those licenses while moving to AWS.

As a solutions architect, which of the following would you recommend as the MOST cost-effective solution?

a)

Use Amazon EC2 dedicated hosts

b)

Use Amazon EC2 on-demand instances

c)

Use Amazon EC2 reserved instances (RI)

d)

Use Amazon EC2 dedicated instances

166.

An online gaming application has a large chunk of its traffic coming from users who download static assets such as historic leaderboard reports and the game tactics for various games. The current infrastructure and design are unable to cope up with the traffic and application freezes on most of the pages.

Which of the following is a cost-optimal solution that does not need provisioning of infrastructure?

a)

Use AWS Lambda with Amazon ElastiCache and Amazon RDS for serving static assets at high speed and low latency

b)

Use Amazon CloudFront with Amazon DynamoDB for greater speed and low latency access to static assets

c)

Use Amazon CloudFront with Amazon S3 as the storage solution for the static assets

d)

Configure AWS Lambda with an Amazon RDS database to provide a serverless architecture

167.

A healthcare company has deployed its web application on Amazon Elastic Container Service (Amazon ECS) container instances running behind an Application Load Balancer. The website slows down when the traffic spikes and the website availability is also reduced. The development team has configured Amazon CloudWatch alarms to receive notifications whenever there is an availability constraint so the team can scale out resources. The company wants an automated solution to respond to such events.

Which of the following addresses the given use case?

a)

Configure AWS Auto Scaling to scale out the Amazon ECS cluster when the CloudWatch alarm's CPU utilization rises above a threshold

b)

Configure AWS Auto Scaling to scale out the Amazon ECS cluster when the Application Load Balancer's target group's CPU utilization rises above a threshold

c)

Configure AWS Auto Scaling to scale out the Amazon ECS cluster when the ECS service's CPU utilization rises above a threshold

d)

Configure AWS Auto Scaling to scale out the Amazon ECS cluster when the Application Load Balancer's CPU utilization rises above a threshold

168.

A company has a hybrid cloud structure for its on-premises data center and AWS Cloud infrastructure. The company wants to build a web log archival solution such that only the most frequently accessed logs are available as cached data locally while backing up all logs on Amazon S3.

As a solutions architect, which of the following solutions would you recommend for this use-case?

a)

Use AWS Direct Connect to store the most frequently accessed logs locally for low-latency access while storing the full backup of logs in an Amazon S3 bucket

b)

Use AWS Volume Gateway - Cached Volume - to store the most frequently accessed logs locally for low-latency access while storing the full volume with all logs in its Amazon S3 service bucket

c)

Use AWS Snowball Edge Storage Optimized device to store the most frequently accessed logs locally for low-latency access while storing the full backup of logs in an Amazon S3 bucket

d)

Use AWS Volume Gateway - Stored Volume - to store the most frequently accessed logs locally for low-latency access while storing the full volume with all logs in its Amazon S3 service bucket

169.

The development team at a retail company wants to optimize the cost of Amazon EC2 instances. The team wants to move certain nightly batch jobs to spot instances. The team has hired you as a solutions architect to provide the initial guidance.

Which of the following would you identify as CORRECT regarding the capabilities of spot instances? (Select three)

a)

Spot Fleets cannot maintain target capacity by launching replacement instances after Spot Instances in the fleet are terminated

b)

Spot Fleets can maintain target capacity by launching replacement instances after Spot Instances in the fleet are terminated

c)

When you cancel an active spot request, it terminates the associated instance as well

d)

If a spot request is persistent, then it is opened again after your Spot Instance is interrupted

e)

When you cancel an active spot request, it does not terminate the associated instance

170.

A startup has recently moved their monolithic web application to AWS Cloud. The application runs on a single Amazon EC2 instance. Currently, the user base is small and the startup does not want to spend effort on elaborate disaster recovery strategies or Auto Scaling Group. The application can afford a maximum downtime of 10 minutes.

In case of a failure, which of these options would you suggest as a cost-effective and automatic recovery procedure for the instance?

a)

Configure an Amazon CloudWatch alarm that triggers the recovery of the Amazon EC2 instance, in case the instance fails. The instance can be configured with Amazon Elastic Block Store (Amazon EBS) or with instance store volumes

b)

Configure an Amazon CloudWatch alarm that triggers the recovery of the Amazon EC2 instance, in case the instance fails. The instance, however, should only be configured with an Amazon EBS volume

c)

Configure AWS Trusted Advisor to monitor the health check of Amazon EC2 instance and provide a remedial action in case an unhealthy flag is detected

d)

Configure Amazon EventBridge events that can trigger the recovery of the Amazon EC2 instance, in case the instance or the application fails

171.

The database backend for a retail company's website is hosted on Amazon RDS for MySQL having a primary instance and three read replicas to support read scalability. The company has mandated that the read replicas should lag no more than 1 second behind the primary instance to provide the best possible user experience. The read replicas are falling further behind during periods of peak traffic spikes, resulting in a bad user experience as the searches produce inconsistent results.

You have been hired as an AWS Certified Solutions Architect - Associate to reduce the replication lag as much as possible with minimal changes to the application code or the effort required to manage the underlying resources.

Which of the following will you recommend?

a)

Set up an Amazon ElastiCache for Redis cluster in front of the MySQL database. Update the website to check the cache before querying the read replicas

b)

Host the MySQL primary database on a memory-optimized Amazon EC2 instance. Spin up additional compute-optimized Amazon EC2 instances to host the read replicas

c)

Set up database migration from Amazon RDS MySQL to Amazon DynamoDB. Provision a large number of read capacity units (RCUs) to support the required throughput and enable Auto-Scaling

d)

Set up database migration from Amazon RDS MySQL to Amazon Aurora MySQL. Swap out the MySQL read replicas with Aurora Replicas. Configure Aurora Auto Scaling

172.

A company has hired you as an AWS Certified Solutions Architect – Associate to help with redesigning a real-time data processor. The company wants to build custom applications that process and analyze the streaming data for its specialized needs.

Which solution will you recommend to address this use-case?

a)

Use Amazon Kinesis Data Streams to process the data streams as well as decouple the producers and consumers for the real-time data processor

b)

Use Amazon Simple Queue Service (Amazon SQS) to process the data streams as well as decouple the producers and consumers for the real-time data processor

c)

Use Amazon Simple Notification Service (Amazon SNS) to process the data streams as well as decouple the producers and consumers for the real-time data processor

d)

Use Amazon Kinesis Data Firehose to process the data streams as well as decouple the producers and consumers for the real-time data processor

173.

Which of the following AWS services provides a highly available and fault-tolerant solution to capture the clickstream events from the source and then provide a concurrent feed of the data stream to the downstream applications?

a)

Amazon Kinesis Data Analytics

b)

Amazon Kinesis Data Firehose

c)

Amazon Simple Queue Service (Amazon SQS)

d)

Amazon Kinesis Data Streams

174.

A financial services company wants to move the Windows file server clusters out of their datacenters. They are looking for cloud file storage offerings that provide full Windows compatibility. Can you identify the AWS storage services that provide highly reliable file storage that is accessible over the industry-standard Server Message Block (SMB) protocol compatible with Windows systems? (Select two)

a)

Amazon Simple Storage Service (Amazon S3)

b)

File Gateway Configuration of AWS Storage Gateway

c)

Amazon FSx for Windows File Server

d)

Amazon Elastic File System (Amazon EFS)

e)

Amazon Elastic Block Store (Amazon EBS)

175.

The engineering team at a company is moving the static content from the company's logistics website hosted on Amazon EC2 instances to an Amazon S3 bucket. The team wants to use an Amazon CloudFront distribution to deliver the static content. The security group used by the Amazon EC2 instances allows the website to be accessed by a limited set of IP ranges from the company's suppliers. Post-migration to Amazon CloudFront, access to the static content should only be allowed from the aforementioned IP addresses.

Which options would you combine to build a solution to meet these requirements? (Select two)

a)

Create an AWS WAF ACL and use an IP match condition to allow traffic only from those IPs that are allowed in the Amazon EC2 security group. Associate this new AWS WAF ACL with the Amazon CloudFront distribution

b)

Configure an origin access identity (OAI) and associate it with the Amazon CloudFront distribution. Set up the permissions in the Amazon S3 bucket policy so that only the OAI can read the objects

c)

Create a new NACL that allows traffic from the same IPs as specified in the current Amazon EC2 security group. Associate this new NACL with the Amazon CloudFront distribution

d)

Create an AWS Web Application Firewall (AWS WAF) ACL and use an IP match condition to allow traffic only from those IPs that are allowed in the Amazon EC2 security group. Associate this new AWS WAF ACL with the Amazon S3 bucket policy

e)

Create a new security group that allows traffic from the same IPs as specified in the current Amazon EC2 security group. Associate this new security group with the Amazon CloudFront distribution

176.

The application maintenance team at a company has noticed that the production application is very slow when the business reports are run on the Amazon RDS database. These reports fetch a large amount of data and have complex queries with multiple joins, spanning across multiple business-critical core tables. CPU, memory, and storage metrics are around 50% of the total capacity.

Can you recommend an improved and cost-effective way of generating the business reports while keeping the production application unaffected?

a)

Migrate from General Purpose SSD to magnetic storage to enhance IOPS

b)

Create a read replica and connect the report generation tool/application to it

c)

Configure the Amazon RDS instance to be Multi-AZ DB instance, and connect the report generation tool to the DB instance in a different AZ

d)

Increase the size of Amazon RDS instance

177.

An IT company hosts windows based applications on its on-premises data center. The company is looking at moving the business to the AWS Cloud. The cloud solution should offer shared storage space that multiple applications can access without a need for replication. Also, the solution should integrate with the company's self-managed Active Directory domain.

Which of the following solutions addresses these requirements with the minimal integration effort?

a)

Use File Gateway of AWS Storage Gateway to create a hybrid storage solution

b)

Use Amazon Elastic File System (Amazon EFS) as a shared storage solution

c)

Use Amazon FSx for Lustre as a shared storage solution with millisecond latencies

d)

Use Amazon FSx for Windows File Server as a shared storage solution

178.

A social media startup uses AWS Cloud to manage its IT infrastructure. The engineering team at the startup wants to perform weekly database rollovers for a MySQL database server using a serverless cron job that typically takes about 5 minutes to execute the database rollover script written in Python. The database rollover will archive the past week’s data from the production database to keep the database small while still keeping its data accessible.

As a solutions architect, which of the following would you recommend as the MOST cost-efficient and reliable solution?

a)

Schedule a weekly Amazon EventBridge event cron expression to invoke an AWS Lambda function that runs the database rollover job

b)

Provision an Amazon EC2 scheduled reserved instance to run the database rollover script to be run via an OS-based weekly cron expression

c)

Create a time-based schedule option within an AWS Glue job to invoke itself every week and run the database rollover script

d)

Provision an Amazon EC2 spot instance to run the database rollover script to be run via an OS-based weekly cron expression

179.

The engineering team at a company wants to use Amazon Simple Queue Service (Amazon SQS) to decouple components of the underlying application architecture. However, the team is concerned about the VPC-bound components accessing Amazon Simple Queue Service (Amazon SQS) over the public internet.

As a solutions architect, which of the following solutions would you recommend to address this use-case?

a)

Use VPN connection to access Amazon SQS

b)

Use Internet Gateway to access Amazon SQS

c)

Use Network Address Translation (NAT) instance to access Amazon SQS

d)

Use VPC endpoint to access Amazon SQS

180.

A retail company has connected its on-premises data center to the AWS Cloud via AWS Direct Connect. The company wants to be able to resolve Domain Name System (DNS) queries for any resources in the on-premises network from the AWS VPC and also resolve any DNS queries for resources in the AWS VPC from the on-premises network.

As a solutions architect, which of the following solutions can be combined to address the given use case? (Select two)

a)

Create an outbound endpoint on Amazon Route 53 Resolver and then DNS resolvers on the on-premises network can forward DNS queries to Amazon Route 53 Resolver via this endpoint

b)

Create an inbound endpoint on Amazon Route 53 Resolver and then DNS resolvers on the on-premises network can forward DNS queries to Amazon Route 53 Resolver via this endpoint

c)

Create an outbound endpoint on Amazon Route 53 Resolver and then Amazon Route 53 Resolver can conditionally forward queries to resolvers on the on-premises network via this endpoint

d)

Create an inbound endpoint on Amazon Route 53 Resolver and then Amazon Route 53 Resolver can conditionally forward queries to resolvers on the on-premises network via this endpoint

e)

Create a universal endpoint on Amazon Route 53 Resolver and then Amazon Route 53 Resolver can receive and forward queries to resolvers on the on-premises network via this endpoint

181.

The engineering team at an e-commerce company wants to migrate from Amazon Simple Queue Service (Amazon SQS) Standard queues to FIFO (First-In-First-Out) queues with batching.

As a solutions architect, which of the following steps would you have in the migration checklist? (Select three)

a)

Make sure that the throughput for the target FIFO (First-In-First-Out) queue does not exceed 3,000 messages per second

b)

Delete the existing standard queue and recreate it as a FIFO (First-In-First-Out) queue

c)

Make sure that the throughput for the target FIFO (First-In-First-Out) queue does not exceed 300 messages per second

d)

Convert the existing standard queue into a FIFO (First-In-First-Out) queue

e)

Make sure that the name of the FIFO (First-In-First-Out) queue ends with the .fifo suffix

182.

An e-commerce company has deployed its application on several Amazon EC2 instances that are configured in a private subnet using IPv4. These Amazon EC2 instances read and write a huge volume of data to and from Amazon S3 in the same AWS region. The company has set up subnet routing to direct all the internet-bound traffic through a Network Address Translation gateway (NAT gateway). The company wants to build the most cost-optimal solution without impacting the application's ability to communicate with Amazon S3 or the internet.

As an AWS Certified Solutions Architect Associate, which of the following would you recommend?

a)

Provision an internet gateway. Update the route table in the private subnet to route traffic to the internet gateway. Update the network ACL (NACL) to allow the S3-bound traffic

b)

Set up a VPC gateway endpoint for Amazon S3. Attach an endpoint policy to the endpoint. Update the route table to direct the S3-bound traffic to the VPC endpoint

c)

Set up an egress-only internet gateway in the public subnet. Update the route table in the private subnet to route traffic to the internet gateway. Update the network ACL to allow the S3-bound traffic

d)

Set up a Gateway Load Balancer (GWLB) endpoint for Amazon S3. Update the route table in the private subnet to direct the S3-bound traffic via the Gateway Load Balancer (GWLB) endpoint

183.

An AWS Organization is using Service Control Policies (SCPs) for central control over the maximum available permissions for all accounts in their organization. This allows the organization to ensure that all accounts stay within the organization’s access control guidelines.

Which of the given scenarios are correct regarding the permissions described below? (Select three)

a)

If a user or role has an IAM permission policy that grants access to an action that is either not allowed or explicitly denied by the applicable service control policy (SCP), the user or role can't perform that action

b)

Service control policy (SCP) affects all users and roles in the member accounts, including root user of the member accounts

c)

Service control policy (SCP) does not affect service-linked role

d)

If a user or role has an IAM permission policy that grants access to an action that is either not allowed or explicitly denied by the applicable service control policy (SCP), the user or role can still perform that action

e)

Service control policy (SCP) affects service-linked roles

184.

A biotechnology company has multiple High Performance Computing (HPC) workflows that quickly and accurately process and analyze genomes for hereditary diseases. The company is looking to migrate these workflows from their on-premises infrastructure to AWS Cloud.

As a solutions architect, which of the following networking components would you recommend on the Amazon EC2 instances running these HPC workflows?

a)

Elastic Network Adapter (ENA)

b)

Elastic Network Interface (ENI)

c)

Elastic Fabric Adapter (EFA)

d)

Elastic IP Address (EIP)

185.

A health care application processes the real-time health data of the patients into an analytics workflow. With a sharp increase in the number of users, the system has become slow and sometimes even unresponsive as it does not have a retry mechanism. The startup is looking at a scalable solution that has minimal implementation overhead.

Which of the following would you recommend as a scalable alternative to the current solution?

a)

Use Amazon Simple Queue Service (Amazon SQS) for data ingestion and configure AWS Lambda to trigger logic for downstream processing

b)

Use Amazon Kinesis Data Streams to ingest the data, process it using AWS Lambda or run analytics using Amazon Kinesis Data Analytics

c)

Use Amazon API Gateway with the existing REST-based interface to create a high performing architecture

d)

Use Amazon Simple Notification Service (Amazon SNS) for data ingestion and configure AWS Lambda to trigger logic for downstream processing

186.

An e-commerce company uses Microsoft Active Directory to provide users and groups with access to resources on the on-premises infrastructure. The company has extended its IT infrastructure to AWS in the form of a hybrid cloud. The engineering team at the company wants to run directory-aware workloads on AWS for a SQL Server-based application. The team also wants to configure a trust relationship to enable single sign-on (SSO) for its users to access resources in either domain.

As a solutions architect, which of the following AWS services would you recommend for this use-case?

a)

AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD)

b)

Active Directory Connector

c)

Amazon Cloud Directory

d)

Simple Active Directory (Simple AD)

187.

A retail company has its flagship application running on a fleet of Amazon EC2 instances behind Elastic Load Balancing (ELB). The engineering team has been seeing recurrent issues wherein the in-flight requests from the ELB to the Amazon EC2 instances are getting dropped when an instance becomes unhealthy.

Which of the following features can be used to address this issue?

a)

Connection Draining

b)

Cross Zone load balancing

c)

Sticky Sessions

d)

Idle Timeout

188.

An IT company is using Amazon Simple Queue Service (Amazon SQS) queues for decoupling the various components of application architecture. As the consuming components need additional time to process Amazon Simple Queue Service (Amazon SQS) messages, the company wants to postpone the delivery of new messages to the queue for a few seconds.

As a solutions architect, which of the following solutions would you suggest to the company?

a)

Use visibility timeout to postpone the delivery of new messages to the queue for a few seconds

b)

Use Amazon SQS FIFO queues to postpone the delivery of new messages to the queue for a few seconds

c)

Use delay queues to postpone the delivery of new messages to the queue for a few seconds

d)

Use dead-letter queues to postpone the delivery of new messages to the queue for a few seconds

189.

A leading bank has moved its IT infrastructure to AWS Cloud and they have been using Amazon EC2 Auto Scaling for their web servers. This has helped them deal with traffic spikes effectively. But, their MySQL relational database has now become a bottleneck and they urgently need a fully managed auto scaling solution for their relational database to address any unpredictable changes in the traffic.

Can you identify the AWS service that is best suited for this use-case?

a)

Amazon DynamoDB

b)

Amazon Aurora Serverless

c)

Amazon Aurora

d)

Amazon ElastiCache

190.

A media company has its corporate headquarters in Los Angeles with an on-premises data center using an AWS Direct Connect connection to the AWS VPC. The branch offices in San Francisco and Miami use AWS Site-to-Site VPN connections to connect to the AWS VPC. The company is looking for a solution to have the branch offices send and receive data with each other as well as with their corporate headquarters.

As a solutions architect, which of the following AWS services would you recommend addressing this use-case?

a)

AWS VPN CloudHub

b)

Software VPN

c)

VPC Peering connection

d)

VPC Endpoint

191.

A leading online gaming company is migrating its flagship application to AWS Cloud for delivering its online games to users across the world. The company would like to use a Network Load Balancer to handle millions of requests per second. The engineering team has provisioned multiple instances in a public subnet and specified these instance IDs as the targets for the NLB.

As a solutions architect, can you help the engineering team understand the correct routing mechanism for these target instances?

a)

Traffic is routed to instances using the primary elastic IP address specified in the primary network interface for the instance

b)

Traffic is routed to instances using the primary private IP address specified in the primary network interface for the instance

c)

Traffic is routed to instances using the primary public IP address specified in the primary network interface for the instance

d)

Traffic is routed to instances using the instance ID specified in the primary network interface for the instance

192.

A retail organization is moving some of its on-premises data to AWS Cloud. The DevOps team at the organization has set up an AWS Managed IPSec VPN Connection between their remote on-premises network and their Amazon VPC over the internet.

Which of the following represents the correct configuration for the IPSec VPN Connection?

a)

Create a virtual private gateway (VGW) on the on-premises side of the VPN and a Customer Gateway on the AWS side of the VPN

b)

Create a Customer Gateway on both the AWS side of the VPN as well as the on-premises side of the VPN

c)

Create a virtual private gateway (VGW) on the AWS side of the VPN and a Customer Gateway on the on-premises side of the VPN

d)

Create a virtual private gateway (VGW) on both the AWS side of the VPN as well as the on-premises side of the VPN

193.

A legacy application is built using a tightly-coupled monolithic architecture. Due to a sharp increase in the number of users, the application performance has degraded. The company now wants to decouple the architecture and adopt AWS microservices architecture. Some of these microservices need to handle fast running processes whereas other microservices need to handle slower processes.

Which of these options would you identify as the right way of connecting these microservices?

a)

Configure Amazon Simple Queue Service (Amazon SQS) queue to decouple microservices running faster processes from the microservices running slower ones

b)

Use Amazon Simple Notification Service (Amazon SNS) to decouple microservices running faster processes from the microservices running slower ones

c)

Configure Amazon Kinesis Data Streams to decouple microservices running faster processes from the microservices running slower ones

d)

Add Amazon EventBridge to decouple the complex architecture

194.

A retail company uses AWS Cloud to manage its IT infrastructure. The company has set up AWS Organizations to manage several departments running their AWS accounts and using resources such as Amazon EC2 instances and Amazon RDS databases. The company wants to provide shared and centrally-managed VPCs to all departments using applications that need a high degree of interconnectivity.

As a solutions architect, which of the following options would you choose to facilitate this use-case?

a)

Use VPC peering to share a VPC with other AWS accounts belonging to the same parent organization from AWS Organizations

b)

Use VPC peering to share one or more subnets with other AWS accounts belonging to the same parent organization from AWS Organizations

c)

Use VPC sharing to share one or more subnets with other AWS accounts belonging to the same parent organization from AWS Organizations

d)

Use VPC sharing to share a VPC with other AWS accounts belonging to the same parent organization from AWS Organizations

195.

The DevOps team at an IT company is provisioning a two-tier application in a VPC with a public subnet and a private subnet. The team wants to use either a Network Address Translation (NAT) instance or a Network Address Translation (NAT) gateway in the public subnet to enable instances in the private subnet to initiate outbound IPv4 traffic to the internet but needs some technical assistance in terms of the configuration options available for the Network Address Translation (NAT) instance and the Network Address Translation (NAT) gateway.

As a solutions architect, which of the following options would you identify as CORRECT? (Select three)

a)

Security Groups can be associated with a NAT instance

b)

NAT instance can be used as a bastion server

c)

NAT instance supports port forwarding

d)

Security Groups can be associated with a NAT gateway

e)

NAT gateway supports port forwarding

196.

The engineering team at a leading e-commerce company is anticipating a surge in the traffic because of a flash sale planned for the weekend. You have estimated the web traffic to be 10x. The content of your website is highly dynamic and changes very often.

As a Solutions Architect, which of the following options would you recommend to make sure your infrastructure scales for that day?

a)

Use an Auto Scaling Group

b)

Use an Amazon Route 53 Multi Value record

c)

Use an Amazon CloudFront distribution in front of your website

d)

Deploy the website on Amazon S3

197.

A ride-sharing company wants to use an Amazon DynamoDB table for data storage. The table will not be used during the night hours whereas the read and write traffic will often be unpredictable during day hours. When traffic spikes occur they will happen very quickly.

Which of the following will you recommend as the best-fit solution?

a)

Set up Amazon DynamoDB table with a global secondary index

b)

Set up Amazon DynamoDB global table in the provisioned capacity mode

c)

Set up Amazon DynamoDB table in the on-demand capacity mode

d)

Set up Amazon DynamoDB table in the provisioned capacity mode with auto-scaling enabled

198.

You are working as an AWS architect for a weather tracking facility. You are asked to set up a Disaster Recovery (DR) mechanism with minimum costs. In case of failure, the facility can only bear data loss of approximately 15 minutes without jeopardizing the forecasting models.

As a Solutions Architect, which DR method will you suggest?

a)

Warm Standby

b)

Pilot Light

c)

Multi-Site

d)

Backup and Restore

199.

An e-commerce company tracks user clicks on its flagship website and performs analytics to provide near-real-time product recommendations. An Amazon EC2 instance receives data from the website and sends the data to an Amazon Aurora Database instance. Another Amazon EC2 instance continuously checks the changes in the database and executes SQL queries to provide recommendations. Now, the company wants a redesign to decouple and scale the infrastructure. The solution must ensure that data can be analyzed in real-time without any data loss even when the company sees huge traffic spikes.

What would you recommend as an AWS Certified Solutions Architect - Associate?

a)

Leverage Amazon Kinesis Data Streams to capture the data from the website and feed it into Amazon Kinesis Data Firehose to persist the data on Amazon S3. Lastly, use Amazon Athena to analyze the data in real time

b)

Leverage Amazon SQS to capture the data from the website. Configure a fleet of Amazon EC2 instances under an Auto scaling group to process messages from the Amazon SQS queue and trigger the scaling policy based on the number of pending messages in the queue. Perform real-time analytics using a third-party library on the Amazon EC2 instances

c)

Leverage Amazon Kinesis Data Streams to capture the data from the website and feed it into Amazon QuickSight which can query the data in real time. Lastly, the analyzed feed is output into Kinesis Data Firehose to persist the data on Amazon S3

d)

Leverage Amazon Kinesis Data Streams to capture the data from the website and feed it into Amazon Kinesis Data Analytics which can query the data in real time. Lastly, the analyzed feed is output into Amazon Kinesis Data Firehose to persist the data on Amazon S3

200.

As an e-sport tournament hosting company, you have servers that need to scale and be highly available. Therefore you have deployed an Elastic Load Balancing (ELB) with an Auto Scaling group (ASG) across 3 Availability Zones (AZs). When e-sport tournaments are running, the servers need to scale quickly. And when tournaments are done, the servers can be idle. As a general rule, you would like to be highly available, have the capacity to scale and optimize your costs

a)

Set the minimum capacity to 3

b)

Use Dedicated hosts for the minimum capacity

c)

Use Reserved Instances (RIs) for the minimum capacity

d)

Set the minimum capacity to 1

e)

Set the minimum capacity to 2

201.

A social media company wants the capability to dynamically alter the size of a geographic area from which traffic is routed to a specific server resource.

Which feature of Amazon Route 53 can help achieve this functionality?

a)

Weighted routing

b)

Geolocation routing

c)

Geoproximity routing

d)

Latency-based routing

202.

A company has grown from a small startup to an enterprise employing over 1000 people. As the team size has grown, the company has recently observed some strange behavior, with Amazon S3 buckets settings being changed regularly.

How can you figure out what's happening without restricting the rights of the users?

a)

Implement a bucket policy requiring AWS Multi-Factor Authentication (AWS MFA) for all operations

b)

Use AWS CloudTrail to analyze API calls

c)

Implement an IAM policy to forbid users to change Amazon S3 bucket settings

d)

Use Amazon S3 access logs to analyze user access using Athena

203.

A company wants to grant access to an Amazon S3 bucket to users in its own AWS account as well as to users in another AWS account. Which of the following options can be used to meet this requirement?

a)

Use either a bucket policy or a user policy to grant permission to users in its account as well as to users in another account

b)

Use a user policy to grant permission to users in its account as well as to users in another account

c)

Use a bucket policy to grant permission to users in its account as well as to users in another account

d)

Use permissions boundary to grant permission to users in its account as well as to users in another account

204.

The engineering team at a company is running batch workloads on AWS Cloud. The team has embedded Amazon RDS database connection strings within each web server hosting the flagship application. After failing a security audit, the team is looking at a different approach to store the database secrets securely and automatically rotate the database credentials.

Which of the following solutions would you recommend to meet this requirement?

a)

AWS Secrets Manager

b)

AWS Systems Manager Parameter Store

c)

AWS Key Management Service (KMS)

d)

AWS Systems Manager

205.

An e-commerce company has copied 1 petabyte of data from its on-premises data center to an Amazon S3 bucket in the us-west-1 Region using an AWS Direct Connect link. The company now wants to set up a one-time copy of the data to another Amazon S3 bucket in the us-east-1 Region. The on-premises data center does not allow the use of AWS Snowball.

As a Solutions Architect, which of the following options can be used to accomplish this goal? (Select two)

a)

Use AWS Snowball Edge device to copy the data from one Region to another Region

b)

Set up Amazon S3 batch replication to copy objects across Amazon S3 buckets in another Region using S3 console and then delete the replication configuration

c)

Copy data from the source bucket to the destination bucket using the aws S3 sync command

d)

Copy data from the source Amazon S3 bucket to a target Amazon S3 bucket using the S3 console

e)

Set up Amazon S3 Transfer Acceleration (Amazon S3TA) to copy objects across Amazon S3 buckets in different Regions using S3 console

206.

A financial services firm has traditionally operated with an on-premise data center and would like to create a disaster recovery strategy leveraging the AWS Cloud.

As a Solutions Architect, you would like to ensure that a scaled-down version of a fully functional environment is always running in the AWS cloud, and in case of a disaster, the recovery time is kept to a minimum. Which disaster recovery strategy is that?

a)

Warm Standby

b)

Multi Site

c)

Backup and Restore

d)

Pilot Light

207.

For security purposes, a development team has decided to deploy the Amazon EC2 instances in a private subnet. The team plans to use VPC endpoints so that the instances can access some AWS services securely. The members of the team would like to know about the two AWS services that support Gateway Endpoints.

As a solutions architect, which of the following services would you suggest for this requirement? (Select two)

a)

Amazon S3

b)

Amazon Simple Notification Service (Amazon SNS)

c)

Amazon DynamoDB

d)

Amazon Kinesis

e)

Amazon Simple Queue Service (Amazon SQS)

208.

The engineering team at a social media company has recently migrated to AWS Cloud from its on-premises data center. The team is evaluating Amazon CloudFront to be used as a CDN for its flagship application. The team has hired you as an AWS Certified Solutions Architect – Associate to advise on Amazon CloudFront capabilities on routing, security, and high availability.

Which of the following would you identify as correct regarding Amazon CloudFront? (Select three)

a)

Use an origin group with primary and secondary origins to configure Amazon CloudFront for high-availability and failover

b)

Amazon CloudFront can route to multiple origins based on the price class

c)

Use field level encryption in Amazon CloudFront to protect sensitive data for specific content

d)

Use AWS Key Management Service (AWS KMS) encryption in Amazon CloudFront to protect sensitive data for specific content

e)

Amazon CloudFront can route to multiple origins based on the content type

209.

A small rental company had 5 employees, all working under the same AWS cloud account. These employees deployed their applications built for various functions- including billing, operations, finance, etc. Each of these employees has been operating in their own VPC. Now, there is a need to connect these VPCs so that the applications can communicate with each other.

Which of the following is the MOST cost-effective solution for this use-case?

a)

Use a VPC peering connection

b)

Use an Internet Gateway

c)

Use an AWS Direct Connect connection

d)

Use a Network Address Translation gateway (NAT gateway)

210.

You started a new job as a solutions architect at a company that has both AWS experts and people learning AWS. Recently, a developer misconfigured a newly created Amazon RDS database which resulted in a production outage.

How can you ensure that Amazon RDS specific best practices are incorporated into a reusable infrastructure template to be used by all your AWS users?

a)

Use AWS CloudFormation to manage Amazon RDS databases

b)

Attach an IAM policy to interns preventing them from creating an Amazon RDS database

c)

Store your recommendations in a custom AWS Trusted Advisor rule

d)

Create an AWS Lambda function which sends emails when it finds misconfigured Amazon RDS databases

211.

You have developed a new REST API leveraging the Amazon API Gateway, AWS Lambda and Amazon Aurora database services. Most of the workload on the website is read-heavy. The data rarely changes and it is acceptable to serve users outdated data for about 24 hours. Recently, the website has been experiencing high load and the costs incurred on the Aurora database have been very high.

How can you easily reduce the costs while improving performance, with minimal changes?

a)

Enable AWS Lambda In Memory Caching

b)

Switch to using an Application Load Balancer

c)

Enable Amazon API Gateway Caching

d)

Add Amazon Aurora Read Replicas

212.

An Internet of Things (IoT) company would like to have a streaming system that performs real-time analytics on the ingested IoT data. Once the analytics is done, the company would like to send notifications back to the mobile applications of the IoT device owners.

As a solutions architect, which of the following AWS technologies would you recommend to send these notifications to the mobile applications?

a)

Amazon Kinesis with Amazon Simple Email Service (Amazon SES)

b)

Amazon Kinesis with Amazon Simple Queue Service (Amazon SQS)

c)

Amazon Kinesis with Amazon Simple Notification Service (Amazon SNS)

d)

Amazon Simple Queue Service (Amazon SQS) with Amazon Simple Notification Service (Amazon SNS)

213.

You are working as a Solutions Architect for a photo processing company that has a proprietary algorithm to compress an image without any loss in quality. Because of the efficiency of the algorithm, your clients are willing to wait for a response that carries their compressed images back. You also want to process these jobs asynchronously and scale quickly, to cater to the high demand. Additionally, you also want the job to be retried in case of failures.

Which combination of choices do you recommend to minimize cost and comply with the requirements? (Select two)

a)

Amazon EC2 Spot Instances

b)

Amazon Simple Queue Service (Amazon SQS)

c)

Amazon Simple Notification Service (Amazon SNS)

d)

Amazon EC2 On-Demand Instances

e)

Amazon EC2 Reserved Instances (RIs)

214.

A photo hosting service publishes a collection of beautiful mountain images, every month, that aggregate over 50 gigabytes in size and downloaded all around the world. The content is currently hosted on Amazon EFS and distributed by Elastic Load Balancing (ELB) and Amazon EC2 instances. The website is experiencing high load each month and very high network costs.

As a Solutions Architect, what can you recommend that won't force an application refactor and reduce network costs and Amazon EC2 load drastically?

a)

Upgrade the Amazon EC2 instances

b)

Enable Elastic Load Balancing (ELB) caching

c)

Host the master pack onto Amazon S3 for faster access

d)

Create an Amazon CloudFront distribution

215.

A Big Data processing company has created a distributed data processing framework that performs best if the network performance between the processing machines is high. The application has to be deployed on AWS, and the company is only looking at performance as the key measure.

As a Solutions Architect, which deployment do you recommend?

a)

Optimize the Amazon EC2 kernel using EC2 User Data

b)

Use a Spread placement group

c)

Use a Cluster placement group

d)

Use Spot Instances

216.

A company's business logic is built on several microservices that are running in the on-premises data center. They currently communicate using a message broker that supports the MQTT protocol. The company is looking at migrating these applications and the message broker to AWS Cloud without changing the application logic.

Which technology allows you to get a managed message broker that supports the MQTT protocol?

a)

Amazon Simple Notification Service (Amazon SNS)

b)

Amazon Simple Queue Service (Amazon SQS)

c)

Amazon MQ

d)

Amazon Kinesis Data Streams

217.

The development team at a social media company wants to handle some complicated queries such as "What are the number of likes on the videos that have been posted by friends of a user A?".

As a solutions architect, which of the following AWS database services would you suggest as the BEST fit to handle such use cases?

a)

Amazon Aurora

b)

Amazon Neptune

c)

Amazon OpenSearch Service

d)

Amazon Redshift

218.

A CRM web application was written as a monolith in PHP and is facing scaling issues because of performance bottlenecks. The CTO wants to re-engineer towards microservices architecture and expose their application from the same load balancer, linked to different target groups with different URLs: checkout.mycorp.com, www.mycorp.com, yourcorp.com/profile and yourcorp.com/search. The CTO would like to expose all these URLs as HTTPS endpoints for security purposes.

As a solutions architect, which of the following would you recommend as a solution that requires MINIMAL configuration effort?

a)

Use Secure Sockets Layer certificate (SSL certificate) with SNI

b)

Change the Elastic Load Balancing (ELB) SSL Security Policy

c)

Use a wildcard Secure Sockets Layer certificate (SSL certificate)

d)

Use an HTTP to HTTPS redirect

219.

You are working for a software as a service (SaaS) company as a solutions architect and help design solutions for the company's customers. One of the customers is a bank and has a requirement to whitelist a public IP when the bank is accessing external services across the internet.

Which architectural choice do you recommend to maintain high availability, support scaling-up to 10 instances and comply with the bank's requirements?

a)

Use a Classic Load Balancer with an Auto Scaling Group

b)

Use an Application Load Balancer with an Auto Scaling Group

c)

Use a Network Load Balancer with an Auto Scaling Group

d)

Use an Auto Scaling Group with Dynamic Elastic IPs attachment

220.

A digital media company needs to manage uploads of around 1 terabyte each from an application being used by a partner company.

As a Solutions Architect, how will you handle the upload of these files to Amazon S3?

a)

Use AWS Snowball

b)

Use AWS Direct Connect to provide extra bandwidth

c)

Use multi-part upload feature of Amazon S3

d)

Use Amazon S3 Versioning

221.

As a solutions architect, you have created a solution that utilizes an Application Load Balancer with stickiness and an Auto Scaling Group (ASG). The Auto Scaling Group spans across 2 Availability Zones (AZs). AZ-A has 3 Amazon EC2 instances and AZ-B has 4 Amazon EC2 instances. The Auto Scaling Group is about to go into a scale-in event due to the triggering of a Amazon CloudWatch alarm.

What will happen under the default Auto Scaling Group configuration?

a)

The instance with the oldest launch template or launch configuration will be terminated in AZ-B

b)

A random instance in the AZ-A will be terminated

c)

A random instance will be terminated in AZ-B

d)

An instance in the AZ-A will be created

222.

An e-commerce company wants to migrate its on-premises application to AWS. The application consists of application servers and a Microsoft SQL Server database. The solution should result in the maximum possible availability for the database layer while minimizing operational and management overhead.

As a solutions architect, which of the following would you recommend to meet the given requirements?

a)

Migrate the data to Amazon RDS for SQL Server database in a Multi-AZ deployment

b)

Migrate the data to Amazon EC2 instance hosted SQL Server database. Deploy the Amazon EC2 instances in a Multi-AZ configuration

c)

Migrate the data to Amazon RDS for SQL Server database in a cross-region Multi-AZ deployment

d)

Migrate the data to Amazon RDS for SQL Server database in a cross-region read-replica configuration

223.

A ride-sharing company wants to improve the ride-tracking system that stores GPS coordinates for all rides. The engineering team at the company is looking for a NoSQL database that has single-digit millisecond latency, can scale horizontally, and is serverless, so that they can perform high-frequency lookups reliably.

As a Solutions Architect, which database do you recommend for their requirements?

a)

Amazon Neptune

b)

Amazon DynamoDB

c)

Amazon Relational Database Service (Amazon RDS)

d)

Amazon ElastiCache

224.

A company has migrated its application from a monolith architecture to a microservices based architecture. The development team has updated the Amazon Route 53 simple record to point "myapp.mydomain.com" from the old Load Balancer to the new one.

The users are still not redirected to the new Load Balancer. What has gone wrong in the configuration?

a)

The health checks are failing

b)

The CNAME Record is misconfigured

c)

The Time To Live (TTL) is still in effect

d)

The Alias Record is misconfigured

225.

A company has noticed that its Amazon EBS Elastic Volume (io1) accounts for 90% of the cost and the remaining 10% cost can be attributed to the Amazon EC2 instance. The Amazon CloudWatch metrics report that both the Amazon EC2 instance and the Amazon EBS volume are under-utilized. The Amazon CloudWatch metrics also show that the Amazon EBS volume has occasional I/O bursts. The entire infrastructure is managed by AWS CloudFormation.

As a Solutions Architect, what do you propose to reduce the costs?

a)

Keep the Amazon EBS volume to io1 and reduce the IOPS

b)

Convert the Amazon EC2 instance EBS volume to gp2

c)

Change the Amazon EC2 instance type to something much smaller

d)

Don't use a AWS CloudFormation template to create the database as the AWS CloudFormation service incurs greater service charges

226.

A development team has configured Elastic Load Balancing for host-based routing. The idea is to support multiple subdomains and different top-level domains.

The rule *.example.com matches which of the following?

227.

A retail company is using AWS Site-to-Site VPN connections for secure connectivity to its AWS cloud resources from its on-premises data center. Due to a surge in traffic across the VPN connections to the AWS cloud, users are experiencing slower VPN connectivity.

Which of the following options will maximize the VPN throughput?

a)

Create a virtual private gateway with equal cost multipath routing and multiple channels

b)

Create an AWS Transit Gateway with equal cost multipath routing and add additional VPN tunnels

c)

Use AWS Global Accelerator for the VPN connection to maximize the throughput

d)

Use Transfer Acceleration for the VPN connection to maximize the throughput

228.

An enterprise has decided to move its secondary workloads such as backups and archives to AWS cloud. The CTO wishes to move the data stored on physical tapes to Cloud, without changing their current tape backup workflows. The company holds petabytes of data on tapes and needs a cost-optimized solution to move this data to cloud.

What is an optimal solution that meets these requirements while keeping the costs to a minimum?

a)

Use Tape Gateway, which can be used to move on-premises tape data onto AWS Cloud. Then, Amazon S3 archiving storage classes can be used to store data cost-effectively for years

b)

Use AWS VPN connection between the on-premises datacenter and your Amazon VPC. Once this is established, you can use Amazon Elastic File System (Amazon EFS) to get a scalable, fully managed elastic NFS file system for use with AWS Cloud services and on-premises resources

c)

Use AWS DataSync, which makes it simple and fast to move large amounts of data online between on-premises storage and AWS Cloud. Data moved to Cloud can then be stored cost-effectively in Amazon S3 archiving storage classes

d)

Use AWS Direct Connect, a cloud service solution that makes it easy to establish a dedicated network connection from on-premises to AWS to transfer data. Once this is done, Amazon S3 can be used to store data at lesser costs

229.

Amazon Route 53 is configured to route traffic to two Network Load Balancer nodes belonging to two Availability Zones (AZs): AZ-A and AZ-B. Cross-zone load balancing is disabled. AZ-A has four targets and AZ-B has six targets.

Which of the below statements is true about traffic distribution to the target instances from Amazon Route 53?

a)

Each of the six targets in AZ-B receives 10% of the traffic

b)

Each of the four targets in AZ-A receives 12.5% of the traffic

c)

Each of the four targets in AZ-A receives 10% of the traffic

d)

Each of the four targets in AZ-A receives 8% of the traffic

230.

Your company runs a web portal to match developers to clients who need their help. As a solutions architect, you've designed the architecture of the website to be fully serverless with Amazon API Gateway and AWS Lambda. The backend uses Amazon DynamoDB table. You would like to automatically congratulate your developers on important milestones, such as - their first paid contract. All the contracts are stored in Amazon DynamoDB.

Which Amazon DynamoDB feature can you use to implement this functionality such that there is LEAST delay in sending automatic notifications?

a)

Amazon EventBridge events + AWS Lambda

b)

Amazon DynamoDB DAX + Amazon API Gateway

c)

Amazon DynamoDB Streams + AWS Lambda

d)

Amazon Simple Queue Service (Amazon SQS) + AWS Lambda

231.

A company runs a popular dating website on the AWS Cloud. As a Solutions Architect, you've designed the architecture of the website to follow a serverless pattern on the AWS Cloud using Amazon API Gateway and AWS Lambda. The backend uses an Amazon RDS PostgreSQL database. Currently, the application uses a username and password combination to connect the AWS Lambda function to the Amazon RDS database.

You would like to improve the security at the authentication level by leveraging short-lived credentials. What will you choose? (Select two)

a)

Use IAM authentication from AWS Lambda to Amazon RDS PostgreSQL

b)

Restrict the Amazon RDS database security group to the AWS Lambda's security group


c)

Deploy AWS Lambda in a VPC

d)

Embed a credential rotation logic in the AWS Lambda, retrieving them from SSM

e)

Attach an AWS Identity and Access Management (IAM) role to AWS Lambda

232.

A Big Data analytics company writes data and log files in Amazon S3 buckets. The company now wants to stream the existing data files as well as any ongoing file updates from Amazon S3 to Amazon Kinesis Data Streams.

As a Solutions Architect, which of the following would you suggest as the fastest possible way of building a solution for this requirement?

a)

Leverage Amazon S3 event notification to trigger an AWS Lambda function for the file create event. The AWS Lambda function will then send the necessary data to Amazon Kinesis Data Streams

b)

Configure Amazon EventBridge events for the bucket actions on Amazon S3. An AWS Lambda function can then be triggered from the Amazon EventBridge event that will send the necessary data to Amazon Kinesis Data Streams

c)

Amazon S3 bucket actions can be directly configured to write data into Amazon Simple Notification Service (Amazon SNS). Amazon SNS can then be used to send the updates to Amazon Kinesis Data Streams

d)

Leverage AWS Database Migration Service (AWS DMS) as a bridge between Amazon S3 and Amazon Kinesis Data Streams

233.

A company wants to adopt a hybrid cloud infrastructure where it uses some AWS services such as Amazon S3 alongside its on-premises data center. The company wants a dedicated private connection between the on-premise data center and AWS. In case of failures though, the company needs to guarantee uptime and is willing to use the public internet for an encrypted connection.

What do you recommend? (Select two)

a)

Use Egress Only Internet Gateway as a backup connection

b)

Use AWS Direct Connect connection as a backup connection

c)

Use AWS Site-to-Site VPN as a primary connection

d)

Use AWS Site-to-Site VPN as a backup connection

e)

Use AWS Direct Connect connection as a primary connection

234.

A company has developed a popular photo-sharing website using a serverless pattern on the AWS Cloud using Amazon API Gateway and AWS Lambda. The backend uses an Amazon RDS PostgreSQL database. The website is experiencing high read traffic and the AWS Lambda functions are putting an increased read load on the Amazon RDS database.

The architecture team is planning to increase the read throughput of the database, without changing the application's core logic. As a Solutions Architect, what do you recommend?

a)

Use Amazon ElastiCache

b)

Use Amazon RDS Read Replicas

c)

Use Amazon RDS Multi-AZ feature

d)

Use Amazon DynamoDB

235.

A Pharmaceuticals company is looking for a simple solution to connect its VPCs and on-premises networks through a central hub.

As a Solutions Architect, which of the following would you suggest as the solution that requires the LEAST operational overhead?

a)

Partially meshed VPC peering can be used to connect the Amazon VPCs to the on-premises networks

b)

Fully meshed VPC peering can be used to connect the Amazon VPCs to the on-premises networks

c)

Use Transit VPC Solution to connect the Amazon VPCs to the on-premises networks

d)

Use AWS Transit Gateway to connect the Amazon VPCs to the on-premises networks

236.

A CRM company has a software as a service (SaaS) application that feeds updates to other in-house and third-party applications. The SaaS application and the in-house applications are being migrated to use AWS services for this inter-application communication.

As a Solutions Architect, which of the following would you suggest to asynchronously decouple the architecture?

a)

Use Amazon Simple Queue Service (Amazon SQS) to decouple the architecture

b)

Use Amazon Simple Notification Service (Amazon SNS) to communicate between systems and decouple the architecture

c)

Use Elastic Load Balancing (ELB) for effective decoupling of system architecture

d)

Use Amazon EventBridge to decouple the system architecture

237.

Your company is deploying a website running on AWS Elastic Beanstalk. The website takes over 45 minutes for the installation and contains both static as well as dynamic files that must be generated during the installation process.

As a Solutions Architect, you would like to bring the time to create a new instance in your AWS Elastic Beanstalk deployment to be less than 2 minutes. Which of the following options should be combined to build a solution for this requirement? (Select two)

a)

Use AWS Elastic Beanstalk deployment caching feature

b)

Store the installation files in Amazon S3 so they can be quickly retrieved

c)

Use Amazon EC2 user data to install the application at boot time

d)

Create a Golden Amazon Machine Image (AMI) with the static installation components already setup

e)

Use Amazon EC2 user data to customize the dynamic installation parts at boot time

238.

A developer in your company has set up a classic 2 tier architecture consisting of an Application Load Balancer and an Auto Scaling group (ASG) managing a fleet of Amazon EC2 instances. The Application Load Balancer is deployed in a subnet of size 10.0.1.0/24 and the Auto Scaling group is deployed in a subnet of size 10.0.4.0/22.

As a solutions architect, you would like to adhere to the security pillar of the well-architected framework. How do you configure the security group of the Amazon EC2 instances to only allow traffic coming from the Application Load Balancer?

a)

Add a rule to authorize the security group of the Auto Scaling group

b)

Add a rule to authorize the security group of the Application Load Balancer

c)

Add a rule to authorize the CIDR 10.0.1.0/24

d)

Add a rule to authorize the CIDR 10.0.4.0/22

239.

A leading e-commerce company runs its IT infrastructure on AWS Cloud. The company has a batch job running at 7AM daily on an Amazon RDS database. It processes shipping orders for the past day, and usually gets around 2000 records that need to be processed sequentially in a batch job via a shell script. The processing of each record takes about 3 seconds.

What platform do you recommend to run this batch job?

a)

AWS Glue

b)

AWS Lambda

c)

Amazon Elastic Compute Cloud (Amazon EC2)

d)

Amazon Kinesis Data Streams

240.

A music-sharing company uses a Network Load Balancer to direct traffic to 5 Amazon EC2 instances managed by an Auto Scaling group. When a very popular song is released, the Auto Scaling Group scales to 100 instances and the company incurs high network and compute fees.

The company wants a solution to reduce the costs without changing any of the application code. What do you recommend?

a)

Leverage AWS Storage Gateway

b)

Move the songs to Amazon S3 Glacier

c)

Use an Amazon CloudFront distribution

d)

Move the songs to Amazon S3

241.

A junior developer has downloaded a sample Amazon S3 bucket policy to make changes to it based on new company-wide access policies. He has requested your help in understanding this bucket policy.

As a Solutions Architect, which of the following would you identify as the correct description for the given policy?

{ "Version": "2012-10-17", "Id": "S3PolicyId1", "Statement": [ { "Sid": "IPAllow", "Effect": "Allow", "Principal": "*", "Action": "s3:*", "Resource": "arn:aws:s3:::examplebucket/*", "Condition": { "IpAddress": {"aws:SourceIp": "54.240.143.0/24"}, "NotIpAddress": {"aws:SourceIp": "54.240.143.188/32"} } } ] }

a)

It ensures Amazon EC2 instances that have inherited a security group can access the bucket

b)

It authorizes an IP address and a Classless Inter-Domain Routing (CIDR) to access the S3 bucket

c)

It authorizes an entire Classless Inter-Domain Routing (CIDR) except one IP address to access the Amazon S3 bucket

d)

It ensures the Amazon S3 bucket is exposing an external IP within the Classless Inter-Domain Routing (CIDR) range specified, except one IP

242.

A retail company uses AWS Cloud to manage its technology infrastructure. The company has deployed its consumer-focused web application on Amazon EC2-based web servers and uses Amazon RDS PostgreSQL database as the data store. The PostgreSQL database is set up in a private subnet that allows inbound traffic from selected Amazon EC2 instances. The database also uses AWS Key Management Service (AWS KMS) for encrypting data at rest.

Which of the following steps would you recommend to facilitate end-to-end security for the data-in-transit while accessing the database?

a)

Create a new network access control list (network ACL) that blocks SSH from the entire Amazon EC2 subnet into the database

b)

Configure Amazon RDS to use SSL for data in transit

c)

Use IAM authentication to access the database instead of the database user's access credentials

d)

Create a new security group that blocks SSH from the selected Amazon EC2 instances into the database

243.

The engineering team at a global e-commerce company is currently reviewing their disaster recovery strategy. The team has outlined that they need to be able to quickly recover their application stack with a Recovery Time Objective (RTO) of 5 minutes, in all of the AWS Regions that the application runs. The application stack currently takes over 45 minutes to install on a Linux system.

As a Solutions architect, which of the following options would you recommend as the disaster recovery strategy?

a)

Store the installation files in Amazon S3 for quicker retrieval

b)

Create an Amazon Machine Image (AMI) after installing the software and copy the AMI across all Regions. Use this Region-specific AMI to run the recovery process in the respective Regions

c)

Create an Amazon Machine Image (AMI) after installing the software and use this AMI to run the recovery process in other Regions

d)

Use Amazon EC2 user data to speed up the installation process

244.

As a Solutions Architect, you are tasked to design a distributed application that will run on various Amazon EC2 instances. This application needs to have the highest performance local disk to cache data. Also, data is copied through an Amazon EC2 to EC2 replication mechanism. It is acceptable if the instance loses its data when stopped or terminated.

Which storage solution do you recommend?

a)

Amazon Elastic Block Store (EBS)

b)

Amazon Elastic File System (Amazon EFS)

c)

Instance Store

d)

Amazon Simple Storage Service (Amazon S3)

245.

A niche social media application allows users to connect with sports athletes. As a solutions architect, you've designed the architecture of the application to be fully serverless using Amazon API Gateway and AWS Lambda. The backend uses an Amazon DynamoDB table. Some of the star athletes using the application are highly popular, and therefore Amazon DynamoDB has increased the read capacity units (RCUs). Still, the application is experiencing a hot partition problem.

What can you do to improve the performance of Amazon DynamoDB and eliminate the hot partition problem without a lot of application refactoring?

a)

Use Amazon ElastiCache

b)

Use Amazon DynamoDB Streams

c)

Use Amazon DynamoDB Global Tables

d)

Use Amazon DynamoDB DAX

246.

A company uses Application Load Balancers in multiple AWS Regions. The Application Load Balancers receive inconsistent traffic that varies throughout the year. The engineering team at the company needs to allow the IP addresses of the Application Load Balancers in the on-premises firewall to enable connectivity.

Which of the following represents the MOST scalable solution with minimal configuration changes?

a)

Migrate all Application Load Balancers in different Regions to the Network Load Balancers. Configure the on-premises firewall's rule to allow the Elastic IP addresses of all the Network Load Balancers

b)

Develop an AWS Lambda script to get the IP addresses of the Application Load Balancers in different Regions. Configure the on-premises firewall's rule to allow the IP addresses of the Application Load Balancers

c)

Set up a Network Load Balancer in one Region. Register the private IP addresses of the Application Load Balancers in different Regions with the Network Load Balancer. Configure the on-premises firewall's rule to allow the Elastic IP address attached to the Network Load Balancer

d)

Set up AWS Global Accelerator. Register the Application Load Balancers in different Regions to the AWS Global Accelerator. Configure the on-premises firewall's rule to allow static IP addresses associated with the AWS Global Accelerator

247.

A media company uses Amazon ElastiCache Redis to enhance the performance of its Amazon RDS database layer. The company wants a robust disaster recovery strategy for its caching layer that guarantees minimal downtime as well as minimal data loss while ensuring good application performance.

Which of the following solutions will you recommend to address the given use-case?

a)

Add read-replicas across multiple availability zones (AZs) to reduce the risk of potential data loss because of failure

b)

Opt for Multi-AZ configuration with automatic failover functionality to help mitigate failure

c)

Schedule daily automatic backups at a time when you expect low resource utilization for your cluster

d)

Schedule manual backups using Redis append-only file (AOF)

248.

A mobile gaming company is experiencing heavy read traffic to its Amazon Relational Database Service (Amazon RDS) database that retrieves player’s scores and stats. The company is using an Amazon RDS database instance type that is not cost-effective for their budget. The company would like to implement a strategy to deal with the high volume of read traffic, reduce latency, and also downsize the instance size to cut costs.

Which of the following solutions do you recommend?

a)

Move to Amazon Redshift

b)

Setup Amazon ElastiCache in front of Amazon RDS

c)

Switch application code to AWS Lambda for better performance

d)

Setup Amazon RDS Read Replicas

249.

An Elastic Load Balancer has marked all the Amazon EC2 instances in the target group as unhealthy. Surprisingly, when a developer enters the IP address of the Amazon EC2 instances in the web browser, he can access the website.

What could be the reason the instances are being marked as unhealthy? (Select two)

a)

The Amazon Elastic Block Store (Amazon EBS) volumes have been improperly mounted

b)

The route for the health check is misconfigured

c)

You need to attach elastic IP address (EIP) to the Amazon EC2 instances

d)

The security group of the Amazon EC2 instance does not allow for traffic from the security group of the Application Load Balancer

e)

Your web-app has a runtime that is not supported by the Application Load Balancer

250.

A startup's cloud infrastructure consists of a few Amazon EC2 instances, Amazon RDS instances and Amazon S3 storage. A year into their business operations, the startup is incurring costs that seem too high for their business requirements.

Which of the following options represents a valid cost-optimization solution?

a)

Use AWS Trusted Advisor checks on Amazon EC2 Reserved Instances to automatically renew reserved instances (RI). AWS Trusted advisor also suggests Amazon RDS idle database instances

b)

Use AWS Compute Optimizer recommendations to help you choose the optimal Amazon EC2 purchasing options and help reserve your instance capacities at reduced costs

c)

Use AWS Cost Explorer Resource Optimization to get a report of Amazon EC2 instances that are either idle or have low utilization and use AWS Compute Optimizer to look at instance type recommendations

d)

Use Amazon S3 Storage class analysis to get recommendations for transitions of objects to Amazon S3 Glacier storage classes to reduce storage costs. You can also automate moving these objects into lower-cost storage tier using Lifecycle Policies

251.

A company has recently created a new department to handle their services workload. An IT team has been asked to create a custom VPC to isolate the resources created in this new department. They have set up the public subnet and internet gateway (IGW). However, they are not able to ping the Amazon EC2 instances with elastic IP address (EIP) launched in the newly created VPC.

As a Solutions Architect, the team has requested your help. How will you troubleshoot this scenario? (Select two)

a)

Check if the route table is configured with internet gateway

b)

Contact AWS support to map your VPC with subnet

c)

Disable Source / Destination check on the Amazon EC2 instance

d)

Create a secondary internet gateway to attach with public subnet and move the current internet gateway to private and write route tables

e)

Check if the security groups allow ping from the source

252.

The engineering team at an e-commerce company has been tasked with migrating to a serverless architecture. The team wants to focus on the key points of consideration when using AWS Lambda as a backbone for this architecture.

As a Solutions Architect, which of the following options would you identify as correct for the given requirement? (Select three)

a)

AWS Lambda allocates compute power in proportion to the memory you allocate to your function. AWS, thus recommends to over provision your function time out settings for the proper performance of AWS Lambda functions

b)

By default, AWS Lambda functions always operate from an AWS-owned VPC and hence have access to any public internet address or public AWS APIs. Once an AWS Lambda function is VPC-enabled, it will need a route through a Network Address Translation gateway (NAT gateway) in a public subnet to access public resources

c)

If you intend to reuse code in more than one AWS Lambda function, you should consider creating an AWS Lambda Layer for the reusable code

d)

Serverless architecture and containers complement each other but you cannot package and deploy AWS Lambda functions as container images

e)

Since AWS Lambda functions can scale extremely quickly, it's a good idea to deploy a Amazon CloudWatch Alarm that notifies your team when function metrics such as ConcurrentExecutions or Invocations exceeds the expected threshold

253.

As part of the on-premises data center migration to AWS Cloud, a company is looking at using multiple AWS Snow Family devices to move their on-premises data.

Which AWS Snow Family service offers the feature of storage clustering?

a)

AWS Snowcone

b)

AWS Snowmobile Storage Compute

c)

AWS Snowmobile

d)

AWS Snowball Edge Compute Optimized

254.

A company has built a serverless application using Amazon API Gateway and AWS Lambda. The backend is leveraging an Amazon Aurora MySQL database. The web application was initially launched in the Americas and the company would now like to expand it to Europe, where a read-only version will be available to improve latency. You plan on deploying the Amazon API Gateway and AWS Lambda using AWS CloudFormation, but would like to have a read-only copy of your data in Europe as well.

As a Solutions Architect, what do you recommend?

a)

Use Amazon Aurora Multi-AZ

b)

Use Amazon DynamoDB Streams

c)

Use Amazon Aurora Read Replicas

d)

Create an AWS Lambda function to periodically back up and restore the Amazon Aurora database in another region

255.

A systems administrator is creating IAM policies and attaching them to IAM identities. After creating the necessary identity-based policies, the administrator is now creating resource-based policies.

Which is the only resource-based policy that the IAM service supports?

a)

AWS Organizations Service Control Policies (SCP)

b)

Permissions boundary

c)

Trust policy

d)

Access control list (ACL)

256.

An IT company has a large number of clients opting to build their application programming interface (API) using Docker containers. To facilitate the hosting of these containers, the company is looking at various orchestration services available with AWS.

As a Solutions Architect, which of the following solutions will you suggest? (Select two

a)

Use Amazon Elastic Container Service (Amazon ECS) with Amazon EC2 for serverless orchestration of the containerized services

b)

Use Amazon EMR for serverless orchestration of the containerized services

c)

Use Amazon SageMaker for serverless orchestration of the containerized services

d)

Use Amazon Elastic Container Service (Amazon ECS) with AWS Fargate for serverless orchestration of the containerized services

e)

Use Amazon Elastic Kubernetes Service (Amazon EKS) with AWS Fargate for serverless orchestration of the containerized services

257.

.

a)

It prevents traffic from reaching on HTTP unless from the IP 192.168.1.1

b)

It configures a security group's outbound rules

c)

It lets traffic flow from one IP on port 22

d)

It configures a security group's inbound rules

e)

It allows any IP to pass through on the HTTP port

258.

An IT company runs a high-performance computing (HPC) workload on AWS. The workload requires high network throughput and low-latency network performance along with tightly coupled node-to-node communications. The Amazon EC2 instances are properly sized for compute and storage capacity and are launched using default options.

Which of the following solutions can be used to improve the performance of the workload?

a)

Select the appropriate capacity reservation while launching Amazon EC2 instances

b)

Select an Elastic Inference accelerator while launching Amazon EC2 instances

c)

Select dedicated instance tenancy while launching Amazon EC2 instances

d)

Select a cluster placement group while launching Amazon EC2 instances

259.

You have an Amazon S3 bucket that contains files in two different folders - s3://my-bucket/images and s3://my-bucket/thumbnails. When an image is first uploaded and new, it is viewed several times. But after 45 days, analytics prove that image files are on average rarely requested, but the thumbnails still are. After 180 days, you would like to archive the image files and the thumbnails. Overall you would like the solution to remain highly available to prevent disasters happening against a whole Availability Zone (AZ).

How can you implement an efficient cost strategy for your Amazon S3 bucket? (Select two)

a)

Create a Lifecycle Policy to transition objects to Amazon S3 Glacier using a prefix after 180 days

b)

Create a Lifecycle Policy to transition objects to Amazon S3 One Zone IA using a prefix after 45 days

c)

Create a Lifecycle Policy to transition all objects to Amazon S3 Glacier after 180 days

d)

Create a Lifecycle Policy to transition all objects to Amazon S3 Standard IA after 45 days

e)

Create a Lifecycle Policy to transition objects to Amazon S3 Standard IA using a prefix after 45 days

260.

A healthcare company is evaluating storage options on Amazon S3 to meet regulatory guidelines. The data should be stored in such a way on Amazon S3 that it cannot be deleted until the regulatory time period has expired.

As a solutions architect, which of the following would you recommend for the given requirement?

a)

Activate AWS Multi-Factor Authentication (AWS MFA) delete on the Amazon S3 bucket

b)

Use Amazon S3 Object Lock

c)

Use Amazon S3 Glacier Vault Lock

d)

Use Amazon S3 cross-region replication (S3 CRR)

261.

The infrastructure team at a company maintains 5 different VPCs (let's call these VPCs A, B, C, D, E) for resource isolation. Due to the changed organizational structure, the team wants to interconnect all VPCs together. To facilitate this, the team has set up VPC peering connection between VPC A and all other VPCs in a hub and spoke model with VPC A at the center. However, the team has still failed to establish connectivity between all VPCs.

As a solutions architect, which of the following would you recommend as the MOST resource-efficient and scalable solution?

a)

Use a VPC endpoint to interconnect the VPCs

b)

Use AWS transit gateway to interconnect the VPCs

c)

Establish VPC peering connections between all VPCs

d)

Use an internet gateway to interconnect the VPCs

262.

A gaming company is doing pre-launch testing for its new product. The company runs its production database on an Aurora MySQL DB cluster and the performance testing team wants access to multiple test databases that must be re-created from production data. The company has hired you as an AWS Certified Solutions Architect - Associate to deploy a solution to create these test databases quickly with the LEAST required effort.

What would you suggest to address this use case?

a)

Enable database Backtracking on the production database and let the testing team use the production database

b)

Take a backup of the Aurora MySQL database instance using the mysqldump utility, create multiple new test database instances and restore each test database from the backup

c)

Use database cloning to create multiple clones of the production database and use each clone as a test database

d)

Set up binlog replication in the Aurora MySQL database instance to create multiple new test database instances

263.

An IT company has built a custom data warehousing solution for a retail organization by using Amazon Redshift. As part of the cost optimizations, the company wants to move any historical data (any data older than a year) into Amazon S3, as the daily analytical reports consume data for just the last one year. However the analysts want to retain the ability to cross-reference this historical data along with the daily reports.

The company wants to develop a solution with the LEAST amount of effort and MINIMUM cost. As a solutions architect, which option would you recommend to facilitate this use-case?

a)

Use Amazon Redshift Spectrum to create Amazon Redshift cluster tables pointing to the underlying historical data in Amazon S3. The analytics team can then query this historical data to cross-reference with the daily reports from Redshift

b)

Use the Amazon Redshift COPY command to load the Amazon S3 based historical data into Amazon Redshift. Once the ad-hoc queries are run for the historic data, it can be removed from Amazon Redshift

c)

Setup access to the historical data via Amazon Athena. The analytics team can run historical data queries on Amazon Athena and continue the daily reporting on Amazon Redshift. In case the reports need to be cross-referenced, the analytics team need to export these in flat files and then do further analysis

d)

Use AWS Glue ETL job to load the Amazon S3 based historical data into Redshift. Once the ad-hoc queries are run for the historic data, it can be removed from Amazon Redshift

264.

An application with global users across AWS Regions had suffered an issue when the Elastic Load Balancing (ELB) in a Region malfunctioned thereby taking down the traffic with it. The manual intervention cost the company significant time and resulted in major revenue loss.

What should a solutions architect recommend to reduce internet latency and add automatic failover across AWS Regions?

a)

Set up an Amazon Route 53 geoproximity routing policy to route traffic

b)

Set up AWS Global Accelerator and add endpoints to cater to users in different geographic locations

c)

Create Amazon S3 buckets in different AWS Regions and configure Amazon CloudFront to pick the nearest edge location to the user

d)

Set up AWS Direct Connect as the backbone for each of the AWS Regions where the application is deployed

265.

As a Solutions Architect, you have been hired to work with the engineering team at a company to create a REST API using the serverless architecture.

Which of the following solutions will you recommend to move the company to the serverless architecture?

a)

Amazon Route 53 with Amazon EC2 as backend

b)

Public-facing Application Load Balancer with Amazon Elastic Container Service (Amazon ECS) on Amazon EC2

c)

Amazon API Gateway exposing AWS Lambda Functionality

d)

AWS Fargate with AWS Lambda at the front

266.

A silicon valley based startup helps its users legally sign highly confidential contracts. To meet the compliance guidelines, the startup must ensure that the signed contracts are encrypted using the AES-256 algorithm via an encryption key that is generated as well as managed internally. The startup is now migrating to AWS Cloud and would like the data to be encrypted on AWS. The startup wants to continue using their existing encryption key generation as well as key management mechanism.

What do you recommend?

a)

SSE-KMS

b)

SSE-S3

c)

SSE-C

d)

Client-Side Encryption

267.

A company wants to ensure high availability for its Amazon RDS database. The development team wants to opt for Multi-AZ deployment and they would like to understand what happens when the primary instance of the Multi-AZ configuration goes down.

As a Solutions Architect, which of the following will you identify as the outcome of the scenario?

a)

The application will be down until the primary database has recovered itself

b)

The CNAME record will be updated to point to the standby database

c)

An email will be sent to the System Administrator asking for manual intervention

d)

The URL to access the database will change to the standby database

268.

Your firm has implemented a multi-tiered networking structure within the VPC - with two public and two private subnets. The public subnets are used to deploy the Application Load Balancers, while the two private subnets are used to deploy the application on Amazon EC2 instances. The development team wants the Amazon EC2 instances to have access to the internet. The solution has to be fully managed by AWS and needs to work over IPv4.

What will you recommend?

a)

Egress-Only Internet Gateways deployed in your private subnet

b)

NAT Gateways deployed in your public subnet

c)

Internet Gateways deployed in your private subnet

d)

NAT Instances deployed in your public subnet

269.

A company wants to store business-critical data on Amazon Elastic Block Store (Amazon EBS) volumes which provide persistent storage independent of Amazon EC2 instances. During a test run, the development team found that on terminating an Amazon EC2 instance, the attached Amazon EBS volume was also lost, which was contrary to their assumptions.

As a solutions architect, could you explain this issue?

a)

The Amazon EBS volumes were not backed up on Amazon S3 storage, resulting in the loss of volume

b)

The Amazon EBS volume was configured as the root volume of Amazon EC2 instance. On termination of the instance, the default behavior is to also terminate the attached root volume

c)

On termination of an Amazon EC2 instance, all the attached Amazon EBS volumes are always terminated

d)

The Amazon EBS volumes were not backed up on Amazon EFS file system storage, resulting in the loss of volume

270.

A development team has deployed a microservice to the Amazon Elastic Container Service (Amazon ECS). The application layer is in a Docker container that provides both static and dynamic content through an Application Load Balancer. With increasing load, the Amazon ECS cluster is experiencing higher network usage. The development team has looked into the network usage and found that 90% of it is due to distributing static content of the application.

As a Solutions Architect, what do you recommend to improve the application's network usage and decrease costs?

a)

Distribute the static content through Amazon EFS

b)

Distribute the static content through Amazon S3

c)

Distribute the dynamic content through Amazon S3

d)

Distribute the dynamic content through Amazon EFS

271.

The data engineering team at an e-commerce company has set up a workflow to ingest the clickstream data into the raw zone of the Amazon S3 data lake. The team wants to run some SQL based data sanity checks on the raw zone of the data lake.

What AWS services would you recommend for this use-case such that the solution is cost-effective and easy to maintain?

a)

Use Amazon Athena to run SQL based analytics against Amazon S3 data

b)

Load the incremental raw zone data into Amazon Redshift on an hourly basis and run the SQL based sanity checks

c)

Load the incremental raw zone data into an Amazon EMR based Spark Cluster on an hourly basis and use SparkSQL to run the SQL based sanity checks

d)

Load the incremental raw zone data into Amazon RDS on an hourly basis and run the SQL based sanity checks

272.

The content division at a digital media agency has an application that generates a large number of files on Amazon S3, each approximately 10 megabytes in size. The agency mandates that the files be stored for 5 years before they can be deleted. The files are frequently accessed in the first 30 days of the object creation but are rarely accessed after the first 30 days. The files contain critical business data that is not easy to reproduce, therefore, immediate accessibility is always required.

Which solution is the MOST cost-effective for the given use case?

a)

Set up an Amazon S3 bucket lifecycle policy to move files from Amazon S3 Standard to Amazon S3 Glacier Flexible Retrieval 30 days after object creation. Delete the files 5 years after object creation

b)

Set up an Amazon S3 bucket lifecycle policy to move files from Amazon S3 Standard to Amazon S3 One Zone-IA 30 days after object creation. Delete the files 5 years after object creation

c)

Set up an Amazon S3 bucket lifecycle policy to move files from Amazon S3 Standard to Amazon S3 Standard-IA 30 days after object creation. Delete the files 5 years after object creation

d)

Set up an Amazon S3 bucket lifecycle policy to move files from Amazon S3 Standard to Amazon S3 Standard-IA 30 days after object creation. Archive the files to Amazon S3 Glacier Deep Archive 5 years after object creation

273.

An Internet-of-Things (IoT) company is looking for a database solution on AWS Cloud that has Auto Scaling capabilities and is highly available. The database should be able to handle any changes in data attributes over time, in case the company updates the data feed from its IoT devices. The database must provide the capability to output a continuous stream with details of any changes to the underlying data.

As a Solutions Architect, which database will you recommend?

a)

Amazon Redshift

b)

Amazon Aurora

c)

Amazon Relational Database Service (Amazon RDS)

d)

Amazon DynamoDB

274.

Which of the following is true regarding cross-zone load balancing as seen in Application Load Balancer versus Network Load Balancer?

a)

By default, cross-zone load balancing is disabled for both Application Load Balancer and Network Load Balancer

b)

By default, cross-zone load balancing is disabled for Application Load Balancer and enabled for Network Load Balancer

c)

By default, cross-zone load balancing is enabled for Application Load Balancer and disabled for Network Load Balancer

d)

By default, cross-zone load balancing is enabled for both Application Load Balancer and Network Load Balancer

275.

A silicon valley based healthcare startup uses AWS Cloud for its IT infrastructure. The startup stores patient health records on Amazon Simple Storage Service (Amazon S3). The engineering team needs to implement an archival solution based on Amazon S3 Glacier to enforce regulatory and compliance controls on data access.

As a solutions architect, which of the following solutions would you recommend?

a)

Use Amazon S3 Glacier vault to store the sensitive archived data and then use a vault lock policy to enforce compliance controls

b)

Use Amazon S3 Glacier to store the sensitive archived data and then use an Amazon S3 Access Control List to enforce compliance controls

c)

Use Amazon S3 Glacier to store the sensitive archived data and then use an Amazon S3 lifecycle policy to enforce compliance controls

d)

Use Amazon S3 Glacier vault to store the sensitive archived data and then use an Amazon S3 Access Control List to enforce compliance controls

276.

A junior developer is learning to build websites using HTML, CSS, and JavaScript. He has created a static website and then deployed it on Amazon S3. Now he can't seem to figure out the endpoint for his super cool website.

As a solutions architect, can you help him figure out the allowed formats for the Amazon S3 website endpoints? (Select two)

277.

You are a cloud architect at an IT company. The company has multiple enterprise customers that manage their own mobile applications that capture and send data to Amazon Kinesis Data Streams. They have been getting a ProvisionedThroughputExceededException exception. You have been contacted to help and upon analysis, you notice that messages are being sent one by one at a high rate.

Which of the following options will help with the exception while keeping costs at a minimum?

a)

Increase the number of shards

b)

Use batch messages

c)

Decrease the Stream retention duration

d)

Use Exponential Backoff

278.

The engineering team at an online fashion retailer uses AWS Cloud to manage its technology infrastructure. The Amazon EC2 server fleet is behind an Application Load Balancer and the fleet strength is managed by an Auto Scaling group. Based on the historical data, the team is anticipating a huge traffic spike during the upcoming Thanksgiving sale.

As an AWS solutions architect, what feature of the Auto Scaling group would you leverage so that the potential surge in traffic can be preemptively addressed?

a)

Auto Scaling group target tracking scaling policy

b)

Auto Scaling group scheduled action

c)

Auto Scaling group step scaling policy

d)

Auto Scaling group lifecycle hook

279.

A company is looking for a technology that allows its mobile app users to connect through a Google login and have the capability to turn on AWS Multi-Factor Authentication (AWS MFA) to have maximum security. Ideally, the solution should be fully managed by AWS.

Which technology do you recommend for managing the users' accounts?

a)

Write an AWS Lambda function with Auth0 3rd party integration

b)

Amazon Cognito

c)

AWS Identity and Access Management (AWS IAM)

d)

Enable the AWS Google Login Service

280.

A medical devices company uses Amazon S3 buckets to store critical data. Hundreds of buckets are used to keep the data segregated and well organized. Recently, the development team noticed that the lifecycle policies on the Amazon S3 buckets have not been applied optimally, resulting in higher costs.

As a Solutions Architect, can you recommend a solution to reduce storage costs on Amazon S3 while keeping the IT team's involvement to a minimum?

a)

Use Amazon S3 One Zone-Infrequent Access, to reduce the costs on Amazon S3 storage

b)

Use Amazon S3 Intelligent-Tiering storage class to optimize the Amazon S3 storage costs

c)

Use Amazon S3 Outposts storage class to reduce the costs on Amazon S3 storage by storing the data on-premises

d)

Configure Amazon EFS to provide a fast, cost-effective and sharable storage service

281.

A leading video streaming provider is migrating to AWS Cloud infrastructure for delivering its content to users across the world. The company wants to make sure that the solution supports at least a million requests per second for its Amazon EC2 server farm.

As a solutions architect, which type of Elastic Load Balancing would you recommend as part of the solution stack?

a)

Network Load Balancer

b)

Application Load Balancer

c)

Classic Load Balancer

d)

Infrastructure Load Balancer

282.

A company hires experienced specialists to analyze the customer service calls attended by its call center representatives. Now, the company wants to move to AWS Cloud and is looking at an automated solution to analyze customer service calls for sentiment analysis via ad-hoc SQL queries.

As a Solutions Architect, which of the following solutions would you recommend?

a)

Use Amazon Transcribe to convert audio files to text and Amazon Athena to perform SQL based analysis to understand the underlying customer sentiments

b)

Use Amazon Kinesis Data Streams to read the audio files and Amazon Alexa to convert them into text. Amazon Kinesis Data Analytics can be used to analyze these files and Amazon Quicksight can be used to visualize and display the output

c)

Use Amazon Kinesis Data Streams to read the audio files and machine learning (ML) algorithms to convert the audio files into text and run customer sentiment analysis

d)

Use Amazon Transcribe to convert audio files to text and Amazon Quicksight to perform SQL based analysis on these text files to understand the underlying patterns. Visualize and display them onto user Dashboards for reporting purposes

283.

A financial services company is moving its IT infrastructure to AWS Cloud and wants to enforce adequate data protection mechanisms on Amazon Simple Storage Service (Amazon S3) to meet compliance guidelines. The engineering team has hired you as a solutions architect to build a solution for this requirement.

Can you help the team identify the INCORRECT option from the choices below?

a)

Amazon S3 can encrypt object metadata by using Server-Side Encryption

b)

Amazon S3 can protect data at rest using Server-Side Encryption

c)

Amazon S3 can protect data at rest using Client-Side Encryption

d)

Amazon S3 can encrypt data in transit using HTTPS (TLS)

284.

A mobile chat application uses Amazon DynamoDB as its database service to provide low latency chat updates. A new developer has joined the team and is reviewing the configuration settings for Amazon DynamoDB which have been tweaked for certain technical requirements. AWS CloudTrail service has been enabled on all the resources used for the project. Yet, Amazon DynamoDB encryption details are nowhere to be found.

Which of the following options can explain the root cause for the given issue?

a)

By default, all Amazon DynamoDB tables are encrypted under Customer managed keys, which do not write to AWS CloudTrail logs

b)

By default, all Amazon DynamoDB tables are encrypted using AWS owned keys, which do not write to AWS CloudTrail logs

c)

By default, all Amazon DynamoDB tables are encrypted under AWS managed Keys, which do not write to AWS CloudTrail logs

d)

By default, all Amazon DynamoDB tables are encrypted using Data keys, which do not write to AWS CloudTrail logs

285.

A company's cloud architect has set up a solution that uses Amazon Route 53 to configure the DNS records for the primary website with the domain pointing to the Application Load Balancer (ALB). The company wants a solution where users will be directed to a static error page, configured as a backup, in case of unavailability of the primary website.

Which configuration will meet the company's requirements, while keeping the changes to a bare minimum?

a)

Set up Amazon Route 53 active-passive type of failover routing policy. If Amazon Route 53 health check determines the Application Load Balancer endpoint as unhealthy, the traffic will be diverted to a static error page, hosted on Amazon S3 bucket

b)

Use Amazon Route 53 Latency-based routing. Create a latency record to point to the Amazon S3 bucket that holds the error page to be displayed

c)

Use Amazon Route 53 Weighted routing to give minimum weight to Amazon S3 bucket that holds the error page to be displayed. In case of primary failure, the requests get routed to the error page

d)

Set up Amazon Route 53 active-active type of failover routing policy. If Amazon Route 53 health check determines the Application Load Balancer endpoint as unhealthy, the traffic will be diverted to a static error page, hosted on Amazon S3 bucket

286.

A Customer relationship management (CRM) application is facing user experience issues with users reporting frequent sign-in requests from the application. The application is currently hosted on multiple Amazon EC2 instances behind an Application Load Balancer. The engineering team has identified the root cause as unhealthy servers causing session data to be lost. The team would like to implement a distributed in-memory cache-based session management solution.

As a solutions architect, which of the following solutions would you recommend?

a)

Use Amazon Elasticache for distributed in-memory cache based session management

b)

Use Amazon RDS for distributed in-memory cache based session management

c)

Use Application Load Balancer sticky sessions

d)

Use Amazon DynamoDB for distributed in-memory cache based session management

287.

A medium-sized business has a taxi dispatch application deployed on an Amazon EC2 instance. Because of an unknown bug, the application causes the instance to freeze regularly. Then, the instance has to be manually restarted via the AWS management console.

Which of the following is the MOST cost-optimal and resource-efficient way to implement an automated solution until a permanent fix is delivered by the development team?

a)

Setup an Amazon CloudWatch alarm to monitor the health status of the instance. In case of an Instance Health Check failure, an EC2 Reboot CloudWatch Alarm Action can be used to reboot the instance

b)

Use Amazon EventBridge events to trigger an AWS Lambda function to check the instance status every 5 minutes. In the case of Instance Health Check failure, the AWS lambda function can use Amazon EC2 API to reboot the instance

c)

Setup an Amazon CloudWatch alarm to monitor the health status of the instance. In case of an Instance Health Check failure, Amazon CloudWatch Alarm can publish to an Amazon Simple Notification Service (Amazon SNS) event which can then trigger an AWS lambda function. The AWS lambda function can use Amazon EC2 API to reboot the instance

d)

Use Amazon EventBridge events to trigger an AWS Lambda function to reboot the instance status every 5 minutes

288.

A DevOps engineer at an IT company was recently added to the admin group of the company's AWS account. The AdministratorAccess managed policy is attached to this group.

Can you identify the AWS tasks that the DevOps engineer CANNOT perform even though he has full Administrator privileges (Select two)?

a)

Change the password for his own IAM user account

b)

Configure an Amazon S3 bucket to enable AWS Multi-Factor Authentication (AWS MFA) delete

c)

Close the company's AWS account

d)

Delete the IAM user for his manager

e)

Delete an Amazon S3 bucket from the production environment

289.

An Internet-of-Things (IoT) company is planning on distributing a master sensor in people's homes to measure the key metrics from its smart devices. In order to provide adjustment commands for these devices, the company would like to have a streaming system that supports ordered data based on the sensor's key, and also sustains high throughput messages (thousands of messages per second).

As a solutions architect, which of the following AWS services would you recommend for this use-case?

a)

Amazon Simple Notification Service (Amazon SNS)

b)

AWS Lambda

c)

Amazon Simple Queue Service (Amazon SQS)

d)

Amazon Kinesis Data Streams

290.

An online gaming company wants to block access to its application from specific countries; however, the company wants to allow its remote development team (from one of the blocked countries) to have access to the application. The application is deployed on Amazon EC2 instances running under an Application Load Balancer with AWS Web Application Firewall (AWS WAF).

As a solutions architect, which of the following solutions can be combined to address the given use-case? (Select two)

a)

Use Application Load Balancer geo match statement listing the countries that you want to block

b)

Use AWS WAF geo match statement listing the countries that you want to block

c)

Use AWS WAF IP set statement that specifies the IP addresses that you want to allow through

d)

Use Application Load Balancer IP set statement that specifies the IP addresses that you want to allow through

e)

Create a deny rule for the blocked countries in the network access control list (network ACL) associated with each of the Amazon EC2 instances

291.

A retail company wants to establish encrypted network connectivity between its on-premises data center and AWS Cloud. The company wants to get the solution up and running in the fastest possible time and it should also support encryption in transit.

As a solutions architect, which of the following solutions would you suggest to the company?

a)

Use AWS Direct Connect to establish encrypted network connectivity between the on-premises data center and AWS Cloud

b)

Use AWS Data Sync to establish encrypted network connectivity between the on-premises data center and AWS Cloud

c)

Use AWS Secrets Manager to establish encrypted network connectivity between the on-premises data center and AWS Cloud

d)

Use AWS Site-to-Site VPN to establish encrypted network connectivity between the on-premises data center and AWS Cloud

292.

A media company is evaluating the possibility of moving its IT infrastructure to the AWS Cloud. The company needs at least 10 terabytes of storage with the maximum possible I/O performance for processing certain files which are mostly large videos. The company also needs close to 450 terabytes of very durable storage for storing media content and almost double of it, i.e. 900 terabytes for archival of legacy data.

As a Solutions Architect, which set of services will you recommend to meet these requirements?

a)

Amazon EC2 instance store for maximum performance, AWS Storage Gateway for on-premises durable data access and Amazon S3 Glacier Deep Archive for archival storage

b)

Amazon EC2 instance store for maximum performance, Amazon S3 for durable data storage, and Amazon S3 Glacier for archival storage

c)

Amazon S3 standard storage for maximum performance, Amazon S3 Intelligent-Tiering for intelligent, durable storage, and Amazon S3 Glacier Deep Archive for archival storage

d)

Amazon EBS for maximum performance, Amazon S3 for durable data storage, and Amazon S3 Glacier for archival storage

293.

A media company wants to get out of the business of owning and maintaining its own IT infrastructure. As part of this digital transformation, the media company wants to archive about 5 petabytes of data in its on-premises data center to durable long term storage.

As a solutions architect, what is your recommendation to migrate this data in the MOST cost-optimal way?

a)

Transfer the on-premises data into multiple AWS Snowball Edge Storage Optimized devices. Copy the AWS Snowball Edge data into Amazon S3 Glacier

b)

Setup AWS Site-to-Site VPN connection between the on-premises data center and AWS Cloud. Use this connection to transfer the data into Amazon S3 Glacier

c)

Transfer the on-premises data into multiple AWS Snowball Edge Storage Optimized devices. Copy the AWS Snowball Edge data into Amazon S3 and create a lifecycle policy to transition the data into Amazon S3 Glacier

d)

Setup AWS direct connect between the on-premises data center and AWS Cloud. Use this connection to transfer the data into Amazon S3 Glacier

294.

A global media company uses a fleet of Amazon EC2 instances (behind an Application Load Balancer) to power its video streaming application. To improve the performance of the application, the engineering team has also created an Amazon CloudFront distribution with the Application Load Balancer as the custom origin. The security team at the company has noticed a spike in the number and types of SQL injection and cross-site scripting attack vectors on the application.

As a solutions architect, which of the following solutions would you recommend as the MOST effective in countering these malicious attacks?

a)

Use AWS Firewall Manager with CloudFront distribution

b)

Use AWS Security Hub with Amazon CloudFront distribution

c)

Use AWS Web Application Firewall (AWS WAF) with Amazon CloudFront distribution

d)

Use Amazon Route 53 with Amazon CloudFront distribution

295.

A company needs a massive PostgreSQL database and the engineering team would like to retain control over managing the patches, version upgrades for the database, and consistent performance with high IOPS. The team wants to install the database on an Amazon EC2 instance with the optimal storage type on the attached Amazon EBS volume.

As a solutions architect, which of the following configurations would you suggest to the engineering team?

a)

Amazon EC2 with Amazon EBS volume of Provisioned IOPS SSD (io1) type

b)

Amazon EC2 with Amazon EBS volume of Throughput Optimized HDD (st1) type

c)

Amazon EC2 with Amazon EBS volume of cold HDD (sc1) type

d)

Amazon EC2 with Amazon EBS volume of General Purpose SSD (gp2) type

296.

The engineering team at a weather tracking company wants to enhance the performance of its relational database and is looking for a caching solution that supports geospatial data.

As a solutions architect, which of the following solutions will you suggest?

a)

Use AWS Global Accelerator

b)

Use Amazon ElastiCache for Memcached

c)

Use Amazon DynamoDB Accelerator (DAX)

d)

Use Amazon ElastiCache for Redis

297.

A big data analytics company is using Amazon Kinesis Data Streams (KDS) to process IoT data from the field devices of an agricultural sciences company. Multiple consumer applications are using the incoming data streams and the engineers have noticed a performance lag for the data delivery speed between producers and consumers of the data streams.

As a solutions architect, which of the following would you recommend for improving the performance for the given use-case?

a)

Swap out Amazon Kinesis Data Streams with Amazon SQS Standard queues

b)

Use Enhanced Fanout feature of Amazon Kinesis Data Streams

c)

Swap out Amazon Kinesis Data Streams with Amazon Kinesis Data Firehose

d)

Swap out Amazon Kinesis Data Streams with Amazon SQS FIFO queues

298.

Reporters at a news agency upload/download video files (about 500 megabytes each) to/from an Amazon S3 bucket as part of their daily work. As the agency has started offices in remote locations, it has resulted in poor latency for uploading and accessing data to/from the given Amazon S3 bucket. The agency wants to continue using a serverless storage solution such as Amazon S3 but wants to improve the performance.

As a solutions architect, which of the following solutions do you propose to address this issue? (Select two)

a)

Use Amazon CloudFront distribution with origin as the Amazon S3 bucket. This would speed up uploads as well as downloads for the video files

b)

Enable Amazon S3 Transfer Acceleration (Amazon S3TA) for the Amazon S3 bucket. This would speed up uploads as well as downloads for the video files

c)

Spin up Amazon EC2 instances in each region where the agency has a remote office. Create a daily job to transfer Amazon S3 data into Amazon EBS volumes attached to the Amazon EC2 instances

d)

Move Amazon S3 data into Amazon Elastic File System (Amazon EFS) created in a US region, connect to Amazon EFS file system from Amazon EC2 instances in other AWS regions using an inter-region VPC peering connection

e)

Create new Amazon S3 buckets in every region where the agency has a remote office, so that each office can maintain its storage for the media assets

299.

The engineering team at an e-commerce company uses an AWS Lambda function to write the order data into a single DB instance Amazon Aurora cluster. The team has noticed that many order- writes to its Aurora cluster are getting missed during peak load times. The diagnostics data has revealed that the database is experiencing high CPU and memory consumption during traffic spikes. The team also wants to enhance the availability of the Aurora DB.

Which of the following steps would you combine to address the given scenario? (Select two)

a)

Create a standby Aurora instance in another Availability Zone to improve the availability as the standby can serve as a failover target

b)

Use Amazon EC2 instances behind an Application Load Balancer to write the order data into Amazon Aurora cluster

c)

Create a replica Aurora instance in another Availability Zone to improve the availability as the replica can serve as a failover target

d)

Handle all read operations for your application by connecting to the reader endpoint of the Amazon Aurora cluster so that Aurora can spread the load for read-only connections across the Aurora replica

e)

Increase the concurrency of the AWS Lambda function so that the order-writes do not get missed during traffic spikes

300.

You have built an application that is deployed with Elastic Load Balancing and an Auto Scaling Group. As a Solutions Architect, you have configured aggressive Amazon CloudWatch alarms, making your Auto Scaling Group (ASG) scale in and out very quickly, renewing your fleet of Amazon EC2 instances on a daily basis. A production bug appeared two days ago, but the team is unable to SSH into the instance to debug the issue, because the instance has already been terminated by the Auto Scaling Group. The log files are saved on the Amazon EC2 instance.

How will you resolve the issue and make sure it doesn't happen again?

a)

Make a snapshot of the Amazon EC2 instance just before it gets terminated

b)

Disable the Termination from the Auto Scaling Group any time a user reports an issue

c)

Use AWS Lambda to regularly SSH into the Amazon EC2 instances and copy the log files to Amazon S3

d)

Install an Amazon CloudWatch Logs agents on the Amazon EC2 instances to send logs to Amazon CloudWatch

301.

A retail company maintains an AWS Direct Connect connection to AWS and has recently migrated its data warehouse to AWS. The data analysts at the company query the data warehouse using a visualization tool. The average size of a query returned by the data warehouse is 60 megabytes and the query responses returned by the data warehouse are not cached in the visualization tool. Each webpage returned by the visualization tool is approximately 600 kilobytes.

Which of the following options offers the LOWEST data transfer egress cost for the company?

a)

Deploy the visualization tool on-premises. Query the data warehouse over the internet at a location in the same AWS region

b)

Deploy the visualization tool on-premises. Query the data warehouse directly over an AWS Direct Connect connection at a location in the same AWS region

c)

Deploy the visualization tool in the same AWS region as the data warehouse. Access the visualization tool over a Direct Connect connection at a location in the same region

d)

Deploy the visualization tool in the same AWS region as the data warehouse. Access the visualization tool over the internet at a location in the same region

302.

A financial services company runs its flagship web application on AWS. The application serves thousands of users during peak hours. The company needs a scalable near-real-time solution to share hundreds of thousands of financial transactions with multiple internal applications. The solution should also remove sensitive details from the transactions before storing the cleansed transactions in a document database for low-latency retrieval.

As an AWS Certified Solutions Architect Associate, which of the following would you recommend?

a)

Feed the streaming transactions into Amazon Kinesis Data Firehose. Leverage AWS Lambda integration to remove sensitive data from every transaction and then store the cleansed transactions in Amazon DynamoDB. The internal applications can consume the raw transactions off the Amazon Kinesis Data Firehose

b)

Persist the raw transactions into Amazon DynamoDB. Configure a rule in Amazon DynamoDB to update the transaction by removing sensitive data whenever any new raw transaction is written. Leverage Amazon DynamoDB Streams to share the transactions data with the internal applications

c)

Batch process the raw transactions data into Amazon S3 flat files. Use S3 events to trigger an AWS Lambda function to remove sensitive data from the raw transactions in the flat file and then store the cleansed transactions in Amazon DynamoDB. Leverage DynamoDB Streams to share the transactions data with the internal applications

d)

Feed the streaming transactions into Amazon Kinesis Data Streams. Leverage AWS Lambda integration to remove sensitive data from every transaction and then store the cleansed transactions in Amazon DynamoDB. The internal applications can consume the raw transactions off the Amazon Kinesis Data Stream

303.

A DevOps engineer at an organization is debugging issues related to an Amazon EC2 instance. The engineer has SSH'ed into the instance and he needs to retrieve the instance public IP from within a shell script running on the instance command line.

Can you identify the correct URL path to get the instance public IP?

304.

An e-commerce company uses Amazon Simple Queue Service (Amazon SQS) queues to decouple their application architecture. The engineering team has observed message processing failures for some customer orders.

As a solutions architect, which of the following solutions would you recommend for handling such message failures?

a)

Use a temporary queue to handle message processing failures

b)

Use long polling to handle message processing failures

c)

Use a dead-letter queue to handle message processing failures

d)

Use short polling to handle message processing failures

305.

A pharma company is working on developing a vaccine for the COVID-19 virus. The researchers at the company want to process the reference healthcare data in a highly available as well as HIPAA compliant in-memory database that supports caching results of SQL queries.

As a solutions architect, which of the following AWS services would you recommend for this task?

a)

Amazon DynamoDB Accelerator (DAX)

b)

Amazon DocumentDB

c)

Amazon ElastiCache for Redis/Memcached

d)

Amazon DynamoDB

306.

A financial services firm uses a high-frequency trading system and wants to write the log files into Amazon S3. The system will also read these log files in parallel on a near real-time basis. The engineering team wants to address any data discrepancies that might arise when the trading system overwrites an existing log file and then tries to read that specific log file.

Which of the following options BEST describes the capabilities of Amazon S3 relevant to this scenario?

a)

A process replaces an existing object and immediately tries to read it. Until the change is fully propagated, Amazon S3 might return the previous data

b)

A process replaces an existing object and immediately tries to read it. Amazon S3 always returns the latest version of the object

c)

A process replaces an existing object and immediately tries to read it. Until the change is fully propagated, Amazon S3 might return the new data

d)

A process replaces an existing object and immediately tries to read it. Until the change is fully propagated, Amazon S3 does not return any data

307.

A leading media company wants to do an accelerated online migration of hundreds of terabytes of files from their on-premises data center to Amazon S3 and then establish a mechanism to access the migrated data for ongoing updates from the on-premises applications.

As a solutions architect, which of the following would you select as the MOST performant solution for the given use-case?

a)

Use AWS DataSync to migrate existing data to Amazon S3 and then use File Gateway to retain access to the migrated data for ongoing updates from the on-premises applications

b)

Use File Gateway configuration of AWS Storage Gateway to migrate data to Amazon S3 and then use Amazon S3 Transfer Acceleration (Amazon S3TA) for ongoing updates from the on-premises applications

c)

Use Amazon S3 Transfer Acceleration (Amazon S3TA) to migrate existing data to Amazon S3 and then use AWS DataSync for ongoing updates from the on-premises applications

d)

Use AWS DataSync to migrate existing data to Amazon S3 as well as access the Amazon S3 data for ongoing updates

308.

A streaming solutions company is building a video streaming product by using an Application Load Balancer (ALB) that routes the requests to the underlying Amazon EC2 instances. The engineering team has noticed a peculiar pattern. The Application Load Balancer removes an instance from its pool of healthy instances whenever it is detected as unhealthy but the Auto Scaling group fails to kick-in and provision the replacement instance.

What could explain this anomaly?

a)

Both the Auto Scaling group and Application Load Balancer are using Amazon EC2 based health check

b)

The Auto Scaling group is using ALB based health check and the Application Load Balancer is using Amazon EC2 based health check

c)

The Auto Scaling group is using Amazon EC2 based health check and the Application Load Balancer is using ALB based health check

d)

Both the Auto Scaling group and Application Load Balancer are using ALB based health check

309.

While troubleshooting, a cloud architect realized that the Amazon EC2 instance is unable to connect to the internet using the Internet Gateway.

Which conditions should be met for internet connectivity to be established? (Select two)

a)

The network access control list (network ACL) associated with the subnet must have rules to allow inbound and outbound traffic

b)

The instance's subnet is not associated with any route table

c)

The subnet has been configured to be public and has no access to the internet

d)

The route table in the instance’s subnet should have a route to an Internet Gateway

e)

The instance's subnet is associated with multiple route tables with conflicting configurations

310.

Your company is evolving towards a microservice approach for their website. The company plans to expose the website from the same load balancer, linked to different target groups with different URLs, that are similar to these - checkout.mycorp.com, www.mycorp.com, mycorp.com/profile, and mycorp.com/search.

As a Solutions Architect, which Load Balancer type do you recommend to achieve this routing feature with MINIMUM configuration and development effort?

a)

Create a Classic Load Balancer

b)

Create a Network Load Balancer

c)

Create an Application Load Balancer

d)

Create an NGINX based load balancer on an Amazon EC2 instance to have advanced routing capabilities

311.

A health-care company manages its web application on Amazon EC2 instances running behind Auto Scaling group (ASG). The company provides ambulances for critical patients and needs the application to be reliable. The workload of the company can be managed on 2 Amazon EC2 instances and can peak up to 6 instances when traffic increases.

As a Solutions Architect, which of the following configurations would you select as the best fit for these requirements?

a)

The Auto Scaling group should be configured with the minimum capacity set to 4, with 2 instances each in two different AWS Regions. The maximum capacity of the Auto Scaling group should be set to 6

b)

The Auto Scaling group should be configured with the minimum capacity set to 4, with 2 instances each in two different Availability Zones. The maximum capacity of the Auto Scaling group should be set to 6

c)

The Auto Scaling group should be configured with the minimum capacity set to 2, with 1 instance each in two different Availability Zones. The maximum capacity of the Auto Scaling group should be set to 6

d)

The Auto Scaling group should be configured with the minimum capacity set to 2 and the maximum capacity set to 6 in a single Availability Zone

312.

A pharmaceutical company is considering moving to AWS Cloud to accelerate the research and development process. Most of the daily workflows would be centered around running batch jobs on Amazon EC2 instances with storage on Amazon Elastic Block Store (Amazon EBS) volumes. The CTO is concerned about meeting HIPAA compliance norms for sensitive data stored on Amazon EBS.

Which of the following options outline the correct capabilities of an encrypted Amazon EBS volume? (Select three)

a)

Data moving between the volume and the instance is NOT encrypted

b)

Data moving between the volume and the instance is encrypted

c)

Any snapshot created from the volume is encrypted

d)

Data at rest inside the volume is NOT encrypted

e)

Data at rest inside the volume is encrypted

313.

You have just terminated an instance in the us-west-1a Availability Zone (AZ). The attached Amazon EBS volume is now available for attachment to other instances. An intern launches a new Linux Amazon EC2 instance in the us-west-1b Availability Zone (AZ) and is attempting to attach the Amazon EBS volume. The intern informs you that it is not possible and needs your help.

Which of the following explanations would you provide to them?

a)

Amazon EBS volumes are region locked

b)

The required IAM permissions are missing

c)

The Amazon EBS volume is encrypted

d)

Amazon EBS volumes are Availability Zone (AZ) locked

314.

Computer vision researchers at a university are trying to optimize the I/O bound processes for a proprietary algorithm running on Amazon EC2 instances. The ideal storage would facilitate high-performance IOPS when doing file processing in a temporary storage space before uploading the results back into Amazon S3.

As a solutions architect, which of the following AWS storage options would you recommend as the MOST performant as well as cost-optimal?

a)

Use Amazon EC2 instances with Instance Store as the storage option

b)

Use Amazon EC2 instances with Amazon EBS General Purpose SSD (gp2) as the storage option

c)

Use Amazon EC2 instances with Amazon EBS Throughput Optimized HDD (st1) as the storage option

d)

Use Amazon EC2 instances with Amazon EBS Provisioned IOPS SSD (io1) as the storage option

315.

A company wants to publish an event into an Amazon Simple Queue Service (Amazon SQS) queue whenever a new object is uploaded on Amazon S3.

Which of the following statements are true regarding this functionality?

a)

Both Standard Amazon SQS queue and FIFO SQS queue are allowed as an Amazon S3 event notification destination

b)

Only FIFO Amazon SQS queue is allowed as an Amazon S3 event notification destination, whereas Standard SQS queue is not allowed

c)

Only Standard Amazon SQS queue is allowed as an Amazon S3 event notification destination, whereas FIFO SQS queue is not allowed

d)

Neither Standard Amazon SQS queue nor FIFO SQS queue are allowed as an Amazon S3 event notification destination

316.

A cyber security company is running a mission critical application using a single Spread placement group of Amazon EC2 instances. The company needs 15 Amazon EC2 instances for optimal performance.

How many Availability Zones (AZs) will the company need to deploy these Amazon EC2 instances per the given use-case?

a)

14

b)

3

c)

7

d)

15

317.

A developer in your team has set up a classic 3 tier architecture composed of an Application Load Balancer, an Auto Scaling group managing a fleet of Amazon EC2 instances, and an Amazon Aurora database. As a Solutions Architect, you would like to adhere to the security pillar of the well-architected framework.

How do you configure the security group of the Aurora database to only allow traffic coming from the Amazon EC2 instances?

a)

Add a rule authorizing the Elastic Load Balancing security group

b)

Add a rule authorizing the Auto Scaling group subnets CIDR

c)

Add a rule authorizing the Amazon Aurora security group

d)

Add a rule authorizing the Amazon EC2 security group

318.

An e-commerce company uses a two-tier architecture with application servers in the public subnet and an Amazon RDS MySQL DB in a private subnet. The development team can use a bastion host in the public subnet to access the MySQL database and run queries from the bastion host. However, end-users are reporting application errors. Upon inspecting application logs, the team notices several "could not connect to server: connection timed out" error messages.

Which of the following options represent the root cause for this issue?

a)

The database user credentials (username and password) configured for the application are incorrect

b)

The database user credentials (username and password) configured for the application do not have the required privilege for the given database

c)

The security group configuration for the database instance does not have the correct rules to allow inbound connections from the application servers

d)

The security group configuration for the application servers does not have the correct rules to allow inbound connections from the database instance

319.

A company has noticed that its application performance has deteriorated after a new Auto Scaling group was deployed a few days back. Upon investigation, the team found out that the Launch Configuration selected for the Auto Scaling group is using the incorrect instance type that is not optimized to handle the application workflow.

As a solutions architect, what would you recommend to provide a long term resolution for this issue?

a)

No need to modify the launch configuration. Just modify the Auto Scaling group to use more number of existing instance types. More instances may offset the loss of performance

b)

Modify the launch configuration to use the correct instance type and continue to use the existing Auto Scaling group

c)

Create a new launch configuration to use the correct instance type. Modify the Auto Scaling group to use this new launch configuration. Delete the old launch configuration as it is no longer needed

d)

No need to modify the launch configuration. Just modify the Auto Scaling group to use the correct instance type

320.

A multi-national company is looking at optimizing their AWS resources across various countries and regions. They want to understand the best practices on cost optimization, performance, and security for their system architecture spanning across multiple business units.

Which AWS service is the best fit for their requirements?

a)

AWS Management Console

b)

AWS Config

c)

AWS Trusted Advisor

d)

AWS Systems Manager

321.

The engineering team at a retail company manages 3 Amazon EC2 instances that make read-heavy database requests to the Amazon RDS for the PostgreSQL database instance. As an AWS Certified Solutions Architect - Associate, you have been tasked to make the database instance resilient from a disaster recovery perspective.

Which of the following features will help you in disaster recovery of the database? (Select two)

a)

Use the database cloning feature of the Amazon RDS Database cluster

b)

Enable the automated backup feature of Amazon RDS in a multi-AZ deployment that creates backups across multiple Regions

c)

Use cross-Region Read Replicas

d)

Enable the automated backup feature of Amazon RDS in a multi-AZ deployment that creates backups in a single AWS Region

e)

Use Amazon RDS Provisioned IOPS (SSD) Storage in place of General Purpose (SSD) Storage

322.

A startup has created a cost-effective backup solution in another AWS Region. The application is running in warm standby mode and has Application Load Balancer (ALB) to support it from the front. The current failover process is manual and requires updating the DNS alias record to point to the secondary Application Load Balancer in another Region in case of failure of the primary Application Load Balancer.

As a Solutions Architect, what will you recommend to automate the failover process?

a)

Configure AWS Trusted Advisor to check on unhealthy instances

b)

Enable an Amazon EC2 instance health check

c)

Enable an Amazon Route 53 health check

d)

Enable an ALB health check

323.

An application hosted on Amazon EC2 contains sensitive personal information about all its customers and needs to be protected from all types of cyber-attacks. The company is considering using the AWS Web Application Firewall (AWS WAF) to handle this requirement.

Can you identify the correct solution leveraging the capabilities of AWS WAF?

a)

Configure an Application Load Balancer (ALB) to balance the workload for all the Amazon EC2 instances. Configure Amazon CloudFront to distribute from an Application Load Balancer since AWS WAF cannot be directly configured on ALB. This configuration not only provides necessary safety but is scalable too

b)

AWS WAF can be directly configured only on an Application Load Balancer or an Amazon API Gateway. One of these two services can then be configured with Amazon EC2 to build the needed secure architecture

c)

AWS WAF can be directly configured on Amazon EC2 instances for ensuring the security of the underlying application data

d)

Create Amazon CloudFront distribution for the application on Amazon EC2 instances. Deploy AWS WAF on Amazon CloudFront to provide the necessary safety measures

324.

A solutions architect has been tasked to design a low-latency solution for a static, single-page application, accessed by users through a custom domain name. The solution must be serverless, provide in-transit data encryption and needs to be cost-effective.

Which AWS services can be combined to build the simplest possible solution for the company's requirement?

a)

Configure Amazon S3 to store the static data and use AWS Fargate for hosting the application

b)

Host the application on AWS Fargate and front it with Elastic Load Balancing for an improved performance

c)

Host the application on Amazon EC2 instance with instance store volume for high performance and low latency access to users

d)

Use Amazon S3 to host the static website and Amazon CloudFront to distribute the content for low latency access

325.

A financial services company has to retain the activity logs for each of their customers to meet compliance guidelines. Depending on the business line, the company wants to retain the logs for 5-10 years in highly available and durable storage on AWS. The overall data size is expected to be in Petabytes. In case of an audit, the data would need to be accessible within a timeframe of up to 48 hours.

Which AWS storage option is the MOST cost-effective for the given compliance requirements?

a)

Amazon S3 Glacier

b)

Amazon S3 Glacier Deep Archive

c)

Third party tape storage

d)

Amazon S3 Standard storage

326.

The CTO of an online home rental marketplace wants to re-engineer the caching layer of the current architecture for its relational database. The CTO wants the caching layer to have replication and archival support built into the architecture.

Which of the following AWS service offers the capabilities required for the re-engineering of the caching layer?

a)

Amazon DocumentDB

b)

Amazon ElastiCache for Redis

c)

Amazon ElastiCache for Memcached

d)

Amazon DynamoDB Accelerator (DAX)

327.

A Big Data company wants to optimize its daily Extract-Transform-Load (ETL) process that migrates and transforms data from its Amazon S3 based data lake to an Amazon Redshift cluster. The team wants to manage this daily job in a serverless environment.

Which AWS service is the best fit to manage this process without the need to configure or manage the underlying compute resources?

a)

AWS Database Migration Service (DMS)

b)

AWS Glue

c)

AWS Data Pipeline

d)

Amazon EMR

328.

An application running on an Amazon EC2 instance needs to access a Amazon DynamoDB table in the same AWS account.

Which of the following solutions should a solutions architect configure for the necessary permissions?

a)

Set up an IAM service role with the appropriate permissions to allow access to the Amazon DynamoDB table. Add the Amazon EC2 instance to the trust relationship policy document so that the instance can assume the role

b)

Set up an IAM user with the appropriate permissions to allow access to the Amazon DynamoDB table. Store the access credentials in an Amazon S3 bucket and read them from within the application code directly

c)

Set up an IAM service role with the appropriate permissions to allow access to the Amazon DynamoDB table. Configure an instance profile to assign this IAM role to the Amazon EC2 instance

d)

Set up an IAM user with the appropriate permissions to allow access to the Amazon DynamoDB table. Store the access credentials in the local storage and read them from within the application code directly

329.

The DevOps team at an e-commerce company has deployed a fleet of Amazon EC2 instances under an Auto Scaling group (ASG). The instances under the ASG span two Availability Zones (AZ) within the us-east-1 region. All the incoming requests are handled by an Application Load Balancer (ALB) that routes the requests to the Amazon EC2 instances under the Auto Scaling Group. As part of a test run, two instances (instance 1 and 2, belonging to AZ A) were manually terminated by the DevOps team causing the Availability Zones (AZ) to have unbalanced resources. Later that day, another instance (belonging to AZ B) was detected as unhealthy by the Application Load Balancer's health check.

Can you identify the correct outcomes for these events? (Select two)

a)

Amazon EC2 Auto Scaling creates a new scaling activity for terminating the unhealthy instance and then terminates it. Later, another scaling activity launches a new instance to replace the terminated instance

b)

Amazon EC2 Auto Scaling creates a new scaling activity to terminate the unhealthy instance and launch the new instance simultaneously

c)

Amazon EC2 Auto Scaling creates a new scaling activity for launching a new instance to replace the unhealthy instance. Later, Amazon EC2 Auto Scaling creates a new scaling activity for terminating the unhealthy instance and then terminates it

d)

As the resources are unbalanced in the Availability Zones, Amazon EC2 Auto Scaling will compensate by rebalancing the Availability Zones. When rebalancing, Amazon EC2 Auto Scaling terminates old instances before launching new instances, so that rebalancing does not cause extra instances to be launched

e)

As the resources are unbalanced in the Availability Zones, Amazon EC2 Auto Scaling will compensate by rebalancing the Availability Zones. When rebalancing, Amazon EC2 Auto Scaling launches new instances before terminating the old ones, so that rebalancing does not compromise the performance or availability of your application

330.

An engineering team wants to orchestrate multiple Amazon ECS task types running on Amazon EC2 instances that are part of the Amazon ECS cluster. The output and state data for all tasks need to be stored. The amount of data output by each task is approximately 20 megabytes and there could be hundreds of tasks running at a time. As old outputs are archived, the storage size is not expected to exceed 1 terabyte.

As a solutions architect, which of the following would you recommend as an optimized solution for high-frequency reading and writing?

a)

Use an Amazon EBS volume mounted to the Amazon ECS cluster instances

b)

Use Amazon DynamoDB table that is accessible by all ECS cluster instances

c)

Use Amazon EFS with Bursting Throughput mode

d)

Use Amazon EFS with Provisioned Throughput mode

331.

The engineering team at a startup is evaluating the most optimal block storage volume type for the Amazon EC2 instances hosting its flagship application. The storage volume should support very low latency but it does not need to persist the data when the instance terminates. As a solutions architect, you have proposed using Instance Store volumes to meet these requirements.

Which of the following would you identify as the key characteristics of the Instance Store volumes? (Select two)

a)

You can't detach an instance store volume from one instance and attach it to a different instance

b)

You can specify instance store volumes for an instance when you launch or restart it

c)

An instance store is a network storage type

d)

Instance store is reset when you stop or terminate an instance. Instance store data is preserved during hibernation

e)

If you create an Amazon Machine Image (AMI) from an instance, the data on its instance store volumes isn't preserved

332.

As a Solutions Architect, you would like to completely secure the communications between your Amazon CloudFront distribution and your Amazon S3 bucket which contains the static files for your website. Users should only be able to access the Amazon S3 bucket through Amazon CloudFront and not directly.

What do you recommend?

a)

Create a bucket policy to only authorize the IAM role attached to the Amazon CloudFront distribution

b)

Update the Amazon S3 bucket security groups to only allow traffic from the Amazon CloudFront security group

c)

Make the Amazon S3 bucket public

d)

Create an origin access identity (OAI) and update the Amazon S3 Bucket Policy

333.

The engineering team at a social media company has noticed that while some of the images stored in Amazon S3 are frequently accessed, others sit idle for a considerable span of time.

As a solutions architect, what is your recommendation to build the MOST cost-effective solution?

a)

Create a data monitoring application on an Amazon EC2 instance in the same region as the bucket storing the images. The application is triggered daily via Amazon CloudWatch and it changes the storage class of infrequently accessed objects to Amazon S3 One Zone-IA and the frequently accessed objects are migrated to Amazon S3 Standard class

b)

Create a data monitoring application on an Amazon EC2 instance in the same region as the bucket storing the images. The application is triggered daily via Amazon CloudWatch and it changes the storage class of infrequently accessed objects to Amazon S3 Standard-IA and the frequently accessed objects are migrated to Amazon S3 Standard class

c)

Store the images using the Amazon S3 Intelligent-Tiering storage class

d)

Store the images using the Amazon S3 Standard-IA storage class

334.

The development team at a company manages a Python based nightly process with a runtime of 30 minutes. The process can withstand any interruptions in its execution and start over again. The process currently runs on the on-premises infrastructure and it needs to be migrated to AWS.

Which of the following options do you recommend as the MOST cost-effective solution?

a)

Run on an Application Load Balancer

b)

Run on Amazon EMR

c)

Run on a Spot Instance with a persistent request type

d)

Run on AWS Lambda

335.

An e-commerce company uses Amazon RDS MySQL DB to store the data. The analytics department at the company runs its reports on the same database. The engineering team has noticed sluggish performance on the database when the analytics reporting process is in progress.

As an AWS Certified Solutions Architect - Associate, which of the following would you suggest as the MOST cost-optimal solution to improve the performance?

a)

Create a standby instance in a multi-AZ configuration with the same compute capacity and the same storage capacity as the primary. Point the reporting queries to run against the standby instance

b)

Create a read-replica with half compute capacity and half storage capacity as the primary. Point the reporting queries to run against the read replica

c)

Create a standby instance in a multi-AZ configuration with half compute capacity and half storage capacity as the primary. Point the reporting queries to run against the standby instance

d)

Create a read-replica with the same compute capacity and the same storage capacity as the primary. Point the reporting queries to run against the read replica

336.

As a Solutions Architect, you have set up a database on a single Amazon EC2 instance that has an Amazon EBS volume of type gp2. You currently have 300 gigabytes of space on the gp2 device. The Amazon EC2 instance is of type m5.large. The database performance has recently been poor and upon looking at Amazon CloudWatch, you realize the IOPS on the Amazon EBS volume is maxing out. The disk size of the database must not change because of a licensing issue.

How do you troubleshoot this issue?

a)

Stop the Amazon CloudWatch agent to improve performance

b)

Convert the gp2 volume to an io1

c)

Increase the IOPS on the gp2 volume

d)

Convert the Amazon EC2 instance to an i3.4xlarge

337.

A retail company's procurement application becomes slow when traffic spikes. The application has a three-tier architecture (web, application and database tier) that uses synchronous transactions. The engineering team at the company has identified certain bottlenecks in the application tier but it does not want to change the underlying application architecture.

As a solutions architect, which of the following solutions would you suggest to meet the required application response times while accounting for any traffic spikes?

a)

Leverage horizontal scaling for the application's persistence layer by adding Oracle RAC on AWS

b)

Leverage Amazon SQS with asynchronous AWS Lambda calls to decouple the application and data tiers

c)

Leverage horizontal scaling for the web and application tiers by using Auto Scaling groups and Application Load Balancer

d)

Leverage vertical scaling for the application instance by provisioning a larger Amazon EC2 instance size

338.

The data engineering team at a company wants to analyze Amazon S3 storage access patterns to decide when to transition the right data to the right storage class.

Which of the following represents a correct option regarding the capabilities of Amazon S3 Analytics storage class analysis?

a)

Storage class analysis only provides recommendations for Standard to Glacier Deep Archive classes

b)

Storage class analysis only provides recommendations for Standard to Glacier Flexible Retrieval classes

c)

Storage class analysis only provides recommendations for Standard to Standard IA classes

d)

Storage class analysis only provides recommendations for Standard to Standard One-Zone IA classes

339.

A systems administration team has a requirement to run certain custom scripts only once during the launch of the Amazon Elastic Compute Cloud (Amazon EC2) instances that host their application.

Which of the following represents the best way of configuring a solution for this requirement with minimal effort?

a)

Update Amazon EC2 instance configuration to ensure that the custom scripts, added as user data scripts, are run only during the boot process

b)

Run the custom scripts as instance metadata scripts on the Amazon EC2 instances

c)

Run the custom scripts as user data scripts on the Amazon EC2 instances

d)

Use AWS CLI to run the user data scripts only once while launching the instance

340.

A company has noticed several provisioned throughput exceptions on its Amazon DynamoDB database due to major spikes in the writes to the database. The development team wants to decouple the application layer from the database layer and dedicate a worker process to writing the data to Amazon DynamoDB.

Which middleware do you recommend on using that can scale infinitely and meet these requirements in the most cost effective way?

a)

Amazon Simple Queue Service (Amazon SQS)

b)

Amazon Simple Notification Service (Amazon SNS)

c)

Amazon DynamoDB DAX

d)

Amazon Kinesis Data Streams

341.

You are deploying a critical monolith application that must be deployed on a single web server, as it hasn't been created to work in distributed mode. Still, you want to make sure your setup can automatically recover from the failure of an Availability Zone (AZ).

Which of the following options should be combined to form the MOST cost-efficient solution? (Select three)

a)

Create an auto-scaling group that spans across 2 Availability Zones, which min=1, max=1, desired=1

b)

Create an elastic IP address (EIP) and use the Amazon EC2 user-data script to attach it

c)

Create an Application Load Balancer and a target group with the instance(s) of the Auto Scaling Group

d)

Create a Spot Fleet request

e)

Assign an Amazon EC2 Instance Role to perform the necessary API calls

342.

A company has media files that need to be shared internally. Users are first authenticated using Active Directory and then they access files on a Microsoft Windows platform. The engineering manager wants to keep the same user permissions but wants the company to migrate the storage layer to AWS Cloud as the company is reaching its storage capacity limit on the on-premises infrastructure.

What should a solutions architect recommend to meet this requirement?

a)

Set up Amazon FSx for Windows File Server and move all the media files

b)

Set up Amazon EFS and move all media files

c)

Provision Amazon EC2 with Windows OS, attach multiple Amazon EBS volumes, and move all media files

d)

Create a corporate Amazon S3 bucket and move all media files

343.

A company's real-time streaming application is running on AWS. As the data is ingested, a job runs on the data and takes 30 minutes to complete. The workload frequently experiences high latency due to large amounts of incoming data. A solutions architect needs to design a scalable and serverless solution to enhance performance.

Which combination of steps should the solutions architect take? (Select two)

a)

Set up AWS Database Migration Service (AWS DMS) to ingest the data

b)

Set up AWS Lambda with AWS Step Functions to process the data

c)

Provision Amazon EC2 instances in an Auto Scaling group to process the data

d)

Set up AWS Fargate with Amazon ECS to process the data

e)

Set up Amazon Kinesis Data Streams to ingest the data

344.

The engineering team at a company wants to create a daily big data analysis job leveraging Spark for analyzing online/offline sales and customer loyalty data to create customized reports on a client-by-client basis. The big data analysis job needs to read the data from Amazon S3 and output it back to Amazon S3.

Which technology do you recommend to run the Big Data analysis job? (Select two)

a)

Amazon EMR

b)

Amazon Redshift

c)

AWS Glue

d)

Amazon Athena

e)

AWS Batch

345.

A financial services company stores confidential data on an Amazon Simple Storage Service (S3) bucket. The compliance guidelines require that files be stored with server-side encryption. The encryption used must be Advanced Encryption Standard (AES-256) and the company does not want to manage the encryption keys.

Which of the following options represents the most cost-optimal solution for the given use case?

a)

Client Side Encryption

b)

Server-side encryption with Amazon S3 managed keys (SSE-S3)

c)

Server-side encryption with AWS KMS keys (SSE-KMS)

d)

Server-side encryption with customer-provided keys (SSE-C)

346.

An e-commerce website is migrating towards a microservices-based approach for their website and plans to expose their website from the same load balancer, linked to different target groups with different URLs: checkout.mycorp.com, www.mycorp.com, mycorp.com/products, and mycorp.com/orders. The website would like to use Amazon ECS on the backend to manage these microservices and possibly host the same container of the application multiple times on the same Amazon EC2 instance.

Which feature can help you achieve this with minimal effort?

a)

Network Load Balancer + dynamic port mapping

b)

Application Load Balancer + dynamic port mapping

c)

Classic Load Balancer + dynamic port mapping

d)

Application Load Balancer + Reverse Proxy running as a Docker daemon on each Amazon ECS host

347.

The DevOps team at a major financial services company uses Multi-Availability Zone (Multi-AZ) deployment for its MySQL Amazon RDS database in order to automate its database replication and augment data durability. The DevOps team has scheduled a maintenance window for a database engine level upgrade for the coming weekend.

Which of the following is the correct outcome during the maintenance window?

a)

Any database engine level upgrade for an Amazon RDS database instance with Multi-AZ deployment triggers the primary database instance to be upgraded which is then followed by the upgrade of the standby database instance. This does not cause any downtime for the duration of the upgrade

b)

Any database engine level upgrade for an Amazon RDS database instance with Multi-AZ deployment triggers the standby database instance to be upgraded which is then followed by the upgrade of the primary database instance. This does not cause any downtime for the duration of the upgrade

c)

Any database engine level upgrade for an Amazon RDS database instance with Multi-AZ deployment triggers both the primary and standby database instances to be upgraded at the same time. However, this does not cause any downtime until the upgrade is complete

d)

Any database engine level upgrade for an Amazon RDS database instance with Multi-AZ deployment triggers both the primary and standby database instances to be upgraded at the same time. This causes downtime until the upgrade is complete

348.

Your application is deployed on Amazon EC2 instances fronted by an Application Load Balancer. Recently, your infrastructure has come under attack. Attackers perform over 100 requests per second, while your normal users only make about 5 requests per second.

How can you efficiently prevent attackers from overwhelming your application?

a)

Define a network access control list (network ACL) on your Application Load Balancer

b)

Use an AWS Web Application Firewall (AWS WAF) and setup a rate-based rule

c)

Configure Sticky Sessions on the Application Load Balancer

d)

Use AWS Shield Advanced and setup a rate-based rule

349.

A healthcare company wants to run its applications on single-tenant hardware to meet compliance guidelines.

Which of the following is the MOST cost-effective way of isolating the Amazon EC2 instances to a single tenant?

a)

On-Demand Instances

b)

Dedicated Hosts

c)

Spot Instances

d)

Dedicated Instances

350.

A company is experiencing stability issues with their cluster of self-managed RabbitMQ message brokers and the company now wants to explore an alternate solution on AWS.

As a solutions architect, which of the following AWS services would you recommend that can provide support for quick and easy migration from RabbitMQ?

a)

Amazon MQ

b)

Amazon SQS FIFO (First-In-First-Out)

c)

Amazon Simple Queue Service (Amazon SQS) Standard

d)

Amazon Simple Notification Service (Amazon SNS)

351.

A development team has noticed that one of the Amazon EC2 instances has been incorrectly configured with the 'DeleteOnTermination' attribute set to True for its root EBS volume.

As a Solution's Architect, can you suggest a way to disable this flag while the instance is still running?

a)

Set the DisableApiTermination attribute of the instance using the API

b)

Set the DeleteOnTermination attribute to False using the command line

c)

The attribute cannot be updated when the instance is running. Stop the instance from Amazon EC2 console and then update the flag

d)

Update the attribute using AWS management console. Select the Amazon EC2 instance and then uncheck the DeleteOnTermination check box for the root EBS volume

352.

A healthcare company runs a fleet of Amazon EC2 instances in two private subnets (named PR1 and PR2) across two Availability Zones (AZs) named A1 and A2. The Amazon EC2 instances need access to the internet for operating system patch management and third-party software maintenance. To facilitate this, the engineering team at the company wants to set up two Network Address Translation gateways (NAT gateways) in a highly available configuration.

Which of the following options would you suggest?

a)

Set up a total of one NAT gateway. NAT gateway N1 should be set up in public subnet PU1 in any of the Availability Zones A1 or A2

b)

Set up a total of two NAT gateways. Both NAT gateways N1 and N2 should be set up in a single public subnet PU1 in any of the Availability Zones A1 or A2

c)

Set up a total of two NAT gateways. NAT gateway N1 should be set up in private subnet PR1 in Availability Zone A1. NAT gateway N2 should be set up in private subnet PR2 in Availability Zone A2

d)

Set up a total of two NAT gateways. NAT gateway N1 should be set up in public subnet PU1 in Availability Zone A1. NAT gateway N2 should be set up in public subnet PU2 in Availability Zone A2

353.

A Hollywood production studio is looking at transferring their existing digital media assets of around 20 petabytes to AWS Cloud in the shortest possible timeframe.

Which of the following is an optimal solution for this requirement, given that the studio's data centers are located at a remote location?

a)

AWS Snowmobile

b)

AWS Storage Gateway

c)

AWS Direct Connect

d)

AWS Snowball

354.

A company has moved its business critical data to Amazon Elastic File System (Amazon EFS) which will be accessed by multiple Amazon EC2 instances.

As an AWS Certified Solutions Architect - Associate, which of the following would you recommend to exercise access control such that only the permitted Amazon EC2 instances can read from the Amazon EFS file system? (Select two)

a)

Use an IAM policy to control access for clients who can mount your file system with the required permissions

b)

Use network access control list (network ACL) to control the network traffic to and from your Amazon EC2 instance

c)

Use VPC security groups to control the network traffic to and from your file system

d)

Set up the IAM policy root credentials to control and configure the clients accessing the Amazon EFS file system

e)

Use Amazon GuardDuty to curb unwanted access to Amazon EFS file system

355.

The engineering team at a multi-national company uses AWS Firewall Manager to centrally configure and manage firewall rules across its accounts and applications using AWS Organizations.

Which of the following AWS resources can the AWS Firewall Manager configure rules on? (Select three)

a)

Amazon Inspector

b)

AWS Shield Advanced

c)

AWS Web Application Firewall (AWS WAF)

d)

VPC Security Groups

e)

Amazon GuardDuty

356.

A company needs an Active Directory service to run directory-aware workloads in the AWS Cloud and it should also support configuring a trust relationship with any existing on-premises Microsoft Active Directory.

Which AWS Directory Service is the best fit for this requirement?

a)

Active Directory Connector

b)

AWS Transit Gateway

c)

Simple Active Directory (Simple AD)

d)

AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD)

357.

A company is deploying a publicly accessible web application. To accomplish this, the engineering team has designed the VPC with a public subnet and a private subnet. The application will be hosted on several Amazon EC2 instances in an Auto Scaling group. The team also wants Transport Layer Security (TLS) termination to be offloaded from the Amazon EC2 instances.

Which solution should a solutions architect implement to address these requirements in the most secure manner?

a)

Set up a Network Load Balancer in the public subnet. Create an Auto Scaling group in the public subnet and associate it with the Network Load Balancer

b)

Set up a Network Load Balancer in the private subnet. Create an Auto Scaling group in the private subnet and associate it with the Network Load Balancer

c)

Set up a Network Load Balancer in the private subnet. Create an Auto Scaling group in the public subnet and associate it with the Network Load Balancer

d)

Set up a Network Load Balancer in the public subnet. Create an Auto Scaling group in the private subnet and associate it with the Network Load Balancer

358.

A big data analytics company is looking to archive the on-premises data into a POSIX compliant file storage system on AWS Cloud. The archived data would be accessed for just about a week in a year.

As a solutions architect, which of the following AWS services would you recommend as the MOST cost-optimal solution?

a)

Amazon S3 Standard-IA

b)

Amazon S3 Standard

c)

Amazon EFS Infrequent Access

d)

Amazon EFS Standard

359.

A company uses a legacy on-premises reporting application that operates on gigabytes of .json files and represents years of data. The legacy application cannot handle the growing size of .json files. New .json files are added daily from various data sources to a central on-premises storage location. The company wants to continue to support the legacy application. The company has hired you as a solutions architect to build a solution that can manage ongoing data updates from your on-premises application to Amazon S3.

Which of the following solutions would you suggest to address the given requirement?

a)

Set up AWS DataSync on-premises. Configure AWS DataSync to continuously replicate the .json files between on-premises and Amazon Elastic File System (Amazon EFS). Enable replication from Amazon EFS to the company's Amazon S3 bucket

b)

Set up AWS DataSync on-premises. Configure AWS DataSync to continuously replicate the .json files between the company's on-premises storage and the company's Amazon S3 bucket

c)

Set up an on-premises file gateway. Configure data sources to write the .json files to the file gateway. Point the legacy analytics application to the file gateway. The file gateway should replicate the .json files to Amazon S3

d)

Set up an on-premises volume gateway. Configure data sources to write the .json files to the volume gateway. Point the legacy analytics application to the volume gateway. The volume gateway should replicate data to Amazon S3

360.

A Big Data consulting company runs large distributed and replicated workloads on the on-premises data center. The company now wants to move these workloads to Amazon EC2 instances by using the placement groups feature and it wants to minimize correlated hardware failures.

Which of the following represents the correct placement group configuration for the given requirement?

a)

Spread placement group

b)

Cluster placement groups

c)

Multi-AZ placement groups

d)

Partition placement groups

361.

A company maintains its business-critical customer data on an on-premises system in an encrypted format. Over the years, the company has transitioned from using a single encryption key to multiple encryption keys by dividing the data into logical chunks. With the decision to move all the data to an Amazon S3 bucket, the company is now looking for a technique to encrypt each file with a different encryption key to provide maximum security to the migrated on-premises data.

How will you implement this requirement without adding the overhead of splitting the data into logical groups?

a)

Configure a single Amazon S3 bucket to hold all data. Use server-side encryption with AWS KMS (SSE-KMS) and use encryption context to generate a different key for each file/object that you store in the S3 bucket

b)

Store the logically divided data into different Amazon S3 buckets. Use server-side encryption with Amazon S3 managed keys (SSE-S3) to encrypt the data

c)

Use Multi-Region keys for client-side encryption in the AWS S3 Encryption Client to generate unique keys for each file of data

d)

Configure a single Amazon S3 bucket to hold all data. Use server-side encryption with Amazon S3 managed keys (SSE-S3) to encrypt the data

362.

You are looking to build an index of your files in Amazon S3, using Amazon RDS PostgreSQL. To build this index, it is necessary to read the first 250 bytes of each object in Amazon S3, which contains some metadata about the content of the file itself. There are over 100,000 files in your S3 bucket, amounting to 50 terabytes of data.

How can you build this index efficiently?

a)

Create an application that will traverse the Amazon S3 bucket, read all the files one by one, extract the first 250 bytes, and store that information in Amazon RDS

b)

Use the Amazon RDS Import feature to load the data from Amazon S3 to PostgreSQL, and run a SQL query to build the index

c)

Create an application that will traverse the S3 bucket, issue a Byte Range Fetch for the first 250 bytes, and store that information in Amazon RDS

d)

Create an application that will traverse the Amazon S3 bucket, then use S3 Select Byte Range Fetch parameter to get the first 250 bytes, and store that information in Amazon RDS

363.

You are using AWS Lambda to implement a batch job for a big data analytics workflow. Based on historical trends, a similar job runs for 30 minutes on average. The AWS Lambda function pulls data from Amazon S3, processes it, and then writes the results back to Amazon S3. When you deployed your AWS Lambda function, you noticed an issue where the AWS Lambda function abruptly failed after 15 minutes of execution.

As a solutions architect, which of the following would you identify as the root cause of the issue?

a)

The AWS Lambda function is running out of memory

b)

The AWS Lambda function is timing out

c)

The AWS Lambda function is missing IAM permissions

d)

The AWS Lambda function chosen runtime is wrong

364.

The systems administrator at a company wants to set up a highly available architecture for a bastion host solution.

As a solutions architect, which of the following options would you recommend as the solution?

a)

Create an elastic IP address (EIP) and assign it to all Amazon EC2 instances that are bastion hosts managed by an Auto Scaling Group

b)

Create a public Application Load Balancer that links to Amazon EC2 instances that are bastion hosts managed by an Auto Scaling Group

c)

Create a VPC Endpoint for a fleet of Amazon EC2 instances that are bastion hosts managed by an Auto Scaling Group

d)

Create a public Network Load Balancer that links to Amazon EC2 instances that are bastion hosts managed by an Auto Scaling Group

365.

Your company has created a data warehouse using Amazon Redshift that is used to analyze data from Amazon S3. From the usage pattern, you have detected that after 30 days, the data is rarely queried in Amazon Redshift and it's not "hot data" anymore. You would like to preserve the SQL querying capability on your data and get the queries started immediately. Also, you want to adopt a pricing model that allows you to save the maximum amount of cost on Amazon Redshift.

What do you recommend? (Select two)

a)

Analyze the cold data with Amazon Athena

b)

Move the data to Amazon S3 Glacier Deep Archive after 30 days

c)

Migrate the Amazon Redshift underlying storage to Amazon S3 IA

d)

Create a smaller Amazon Redshift Cluster with the cold data

e)

Move the data to Amazon S3 Standard IA after 30 days

366.

A digital media streaming company wants to use Amazon CloudFront to distribute its content only to its service subscribers. As a solutions architect, which of the following solutions would you suggest to deliver restricted content to the bona fide end users? (Select two)

a)

Use Amazon CloudFront signed cookies

b)

Forward HTTPS requests to the origin server by using the ECDSA or RSA ciphers

c)

Require HTTPS for communication between Amazon CloudFront and your S3 origin

d)

Require HTTPS for communication between Amazon CloudFront and your custom origin

e)

Use Amazon CloudFront signed URLs

367.

A software engineering intern at a company is documenting the features offered by Amazon EC2 Spot instances and Spot fleets.

Can you help the intern by selecting the correct options that identify the key characteristics of these two types of Spot entities? (Select two)

a)

A Spot fleet can only consist of a set of Spot Instances that are launched to meet your target capacity

b)

Spot fleets are spare EC2 capacity that can save you up 90% off of On-Demand prices. Spot fleets are usually interrupted by Amazon EC2 for capacity requirements with a 2-minute notification

c)

Spot instances are spare Amazon EC2 capacity that can save you up 90% off of On-Demand prices. Spot instances can be interrupted by Amazon EC2 for capacity requirements with a 2-minute notification

d)

Spot fleets allow you to request Amazon EC2 Spot instances for 1 to 6 hours at a time to avoid being interrupted

e)

A Spot fleet can consist of a set of Spot Instances and optionally On-Demand Instances that are launched to meet your target capacity

368.

A social media application lets users upload photos and perform image editing operations. The application offers two classes of service: pro and lite. The product team wants the photos submitted by pro users to be processed before those submitted by lite users. Photos are uploaded to Amazon S3 and the job information is sent to Amazon SQS.

As a solutions architect, which of the following solutions would you recommend?

a)

Create two Amazon SQS FIFO queues: one for pro and one for lite. Set the lite queue to use short polling and the pro queue to use long polling

b)

Create one Amazon SQS standard queue. Set the visibility timeout of the pro photos to zero. Set up Amazon EC2 instances to prioritize visibility settings so pro photos are processed first

c)

Create two Amazon SQS standard queues: one for pro and one for lite. Set the lite queue to use short polling and the pro queue to use long polling

d)

Create two Amazon SQS standard queues: one for pro and one for lite. Set up Amazon EC2 instances to prioritize polling for the pro queue over the lite queue

369.

An e-commerce application uses a relational database that runs several queries that perform joins on multiple tables. The development team has found that these queries are slow and expensive, therefore these are a good candidate for caching. The application needs to use a caching service that supports multi-threading.

As a solutions architect, which of the following services would you recommend for the given use case?

a)

Amazon DynamoDB Accelerator (DAX)

b)

Amazon ElastiCache for Redis

c)

Amazon ElastiCache for Memcached

d)

AWS Global Accelerator

370.

The engineering team at an e-commerce company wants to set up a custom domain for internal usage such as internaldomainexample.com. The team wants to use the private hosted zones feature of Amazon Route 53 to accomplish this.

Which of the following settings of the VPC need to be enabled? (Select two)

a)

enableVpcHostnames

b)

enableDnsSupport

c)

enableDnsDomain

d)

enableVpcSupport

e)

enableDnsHostnames

371.

A photo-sharing company is storing user profile pictures in an Amazon S3 bucket and an image analysis application is deployed on four Amazon EC2 instances. A solutions architect would like to trigger an image analysis procedure only on one of the four Amazon EC2 instances for each photo uploaded.

What do you recommend?

a)

Create an Amazon S3 Event Notification that sends a message to an Amazon SQS queue. Make the Amazon EC2 instances read from the Amazon SQS queue

b)

Create an Amazon S3 Event Notification that sends a message to an Amazon SNS topic. Subscribe the Amazon EC2 instances to the Amazon SNS topic

c)

Subscribe the Amazon EC2 instances to the Amazon S3 Inventory stream

d)

Create an Amazon EventBridge event that reacts to objects uploads in Amazon S3 and invokes one of the Amazon EC2 instances

372.

The engineering team at a retail company is planning to migrate to AWS Cloud from the on-premises data center. The team is evaluating Amazon Relational Database Service (Amazon RDS) as the database tier for its flagship application. The team has hired you as an AWS Certified Solutions Architect Associate to advise on Amazon RDS Multi-AZ capabilities.

Which of the following would you identify as correct for Amazon RDS Multi-AZ? (Select two)

a)

To enhance read scalability, a Multi-AZ standby instance can be used to serve read requests

b)

Updates to your database Instance are asynchronously replicated across the Availability Zone to the standby in order to keep both in sync

c)

Amazon RDS applies operating system updates by performing maintenance on the standby, then promoting the standby to primary and finally performing maintenance on the old primary, which becomes the new standby

d)

For automated backups, I/O activity is suspended on your primary database since backups are not taken from standby database

e)

Amazon RDS automatically initiates a failover to the standby, in case primary database fails for any reason

373.

A team has around 200 users, each of these having an IAM user account in AWS. Currently, they all have read access to an Amazon S3 bucket. The team wants 50 among them to have write and read access to the buckets.

How can you provide these users access in the least possible time, with minimal changes?

a)

Create a group, attach the policy to the group and place the users in the group

b)

Update the Amazon S3 bucket policy

c)

Create a policy and assign it manually to the 50 users

d)

Create an AWS Multi-Factor Authentication (AWS MFA) user with read / write access and link 50 IAM with AWS MFA

374.

The engineering team at an IT company is deploying an Online Transactional Processing (OLTP) application that needs to support relational queries. The application will have unpredictable spikes of usage that the team does not know in advance.

Which database would you recommend using?

a)

Amazon DynamoDB with Provisioned Capacity and Auto Scaling

b)

Amazon ElastiCache

c)

Amazon DynamoDB with On-Demand Capacity

d)

Amazon Aurora Serverless

375.

Question 50Skipped

A company helps its customers legally sign highly confidential contracts. To meet the strong industry requirements, the company must ensure that the signed contracts are encrypted using the company's proprietary algorithm. The company is now migrating to AWS Cloud using Amazon Simple Storage Service (Amazon S3) and would like you, the solution architect, to advise them on the encryption scheme to adopt.

What do you recommend?

a)

Server-side encryption with AWS KMS keys (SSE-KMS)

b)

Server-side encryption with customer-provided keys (SSE-C)

c)

Client Side Encryption

d)

Server-side encryption with Amazon S3 managed keys (SSE-S3)

376.

A company manages a High Performance Computing (HPC) application that needs to be deployed on Amazon EC2 instances. The application requires high levels of inter-node communications and high network traffic between the instances.

As a solutions architect, which of the following options would you recommend to the engineering team at the company? (Select two)

a)

Deploy Amazon EC2 instances behind a Network Load Balancer

b)

Deploy Amazon EC2 instances with Elastic Fabric Adapter (EFA)

c)

Deploy Amazon EC2 instances in a partition placement group

d)

Deploy Amazon EC2 instances in a cluster placement group

e)

Deploy Amazon EC2 instances in a spread placement group

377.

A security consultant is designing a solution for a company that wants to provide developers with individual AWS accounts through AWS Organizations, while also maintaining standard security controls. Since the individual developers will have AWS account root user-level access to their own accounts, the consultant wants to ensure that the mandatory AWS CloudTrail configuration that is applied to new developer accounts is not modified.

Which of the following actions meets the given requirements?

a)

Configure a new trail in AWS CloudTrail from within the developer accounts with the organization trails option enabled

b)

Set up a service control policy (SCP) that prohibits changes to AWS CloudTrail, and attach it to the developer accounts

c)

Set up an IAM policy that prohibits changes to AWS CloudTrail and attach it to the root user

d)

Set up a service-linked role for AWS CloudTrail with a policy condition that allows changes only from an Amazon Resource Name (ARN) in the master account

378.

To support critical production workloads that require maximum resiliency, a company wants to configure network connections between its Amazon VPC and the on-premises infrastructure. The company needs AWS Direct Connect connections with speeds greater than 1 Gbps.

As a solutions architect, which of the following will you suggest as the best architecture for this requirement?

a)

Use AWS Managed VPN as a backup for AWS Direct Connect connections to ensure maximum resiliency

b)

Opt for two separate AWS Direct Connect connections terminating on separate devices in more than one Direct Connect location

c)

Opt for at least two AWS Direct Connect connections terminating on different devices at a single Direct Connect location

d)

Opt for one AWS Direct Connect connection at each of the multiple Direct Connect locations

379.

A retail company needs a secure connection between its on-premises data center and AWS Cloud. This connection does not need high bandwidth and will handle a small amount of traffic. The company wants a quick turnaround time to set up the connection.

What is the MOST cost-effective way to establish such a connection?

a)

Set up AWS Direct Connect

b)

Set up an Internet Gateway between the on-premises data center and AWS cloud

c)

Set up an AWS Site-to-Site VPN connection

d)

Set up a bastion host on Amazon EC2

380.

An application is hosted on multiple Amazon EC2 instances in the same Availability Zone (AZ). The engineering team wants to set up shared data access for these Amazon EC2 instances using Amazon EBS Multi-Attach volumes.

Which Amazon EBS volume type is the correct choice for these Amazon EC2 instances?

a)

General-purpose SSD-based Amazon EBS volumes

b)

Provisioned IOPS SSD Amazon EBS volumes

c)

Throughput Optimized HDD Amazon EBS volumes

d)

Cold HDD Amazon EBS volumes

381.

A company has multiple Amazon EC2 instances operating in a private subnet which is part of a custom VPC. These instances are running an image processing application that needs to access images stored on Amazon S3. Once each image is processed, the status of the corresponding record needs to be marked as completed in a Amazon DynamoDB table.

How would you go about providing private access to these AWS resources which are not part of this custom VPC?

a)

Create a separate gateway endpoint for Amazon S3 and Amazon DynamoDB each. Add two new target entries for these two gateway endpoints in the route table of the custom VPC

b)

Create a separate interface endpoint for Amazon S3 and Amazon DynamoDB each. Then connect to these services by adding these as targets in the route table of the custom VPC


c)

Create a gateway endpoint for Amazon S3 and add it as a target in the route table of the custom VPC. Create an interface endpoint for Amazon DynamoDB and then add it as a target in the route table of the custom VPC

d)

Create a gateway endpoint for Amazon DynamoDB and add it as a target in the route table of the custom VPC. Create an Origin Access Identity for Amazon S3 and then connect to the S3 service using the private IP address

382.

You have deployed a database technology that has a synchronous replication mode to survive disasters in data centers. The database is therefore deployed on two Amazon EC2 instances in two Availability Zones (AZs). The database must be publicly available so you have deployed the Amazon EC2 instances in public subnets. The replication protocol currently uses the Amazon EC2 public IP addresses.

What can you do to decrease the replication cost?

a)

Use an Elastic Fabric Adapter (EFA)

b)

Use the Amazon EC2 instances private IP for the replication

c)

Create a Private Link between the two Amazon EC2 instances

d)

Assign elastic IP address (EIP) to the Amazon EC2 instances and use them for the replication

383.

A startup uses a fleet of Amazon EC2 servers to manage its CRM application. These Amazon EC2 servers are behind Elastic Load Balancing (ELB). Which of the following configurations are NOT allowed for Elastic Load Balancing?

a)

Use the Elastic Load Balancing to distribute traffic for four Amazon EC2 instances. Two of these instances are deployed in Availability Zone A of us-east-1 region and the other two instances are deployed in Availability Zone B of us-west-1 region

b)

Use the Elastic Load Balancing to distribute traffic for four Amazon EC2 instances. All the four instances are deployed across two Availability Zones of us-east-1 region

c)

Use the Elastic Load Balancing to distribute traffic for four Amazon EC2 instances. All the four instances are deployed in Availability Zone A of us-east-1 region

d)

Use the Elastic Load Balancing to distribute traffic for four Amazon EC2 instances. All the four instances are deployed in Availability Zone B of us-west-1 region

384.

A development team is looking for a solution that saves development time and deployment costs for an application that uses a high-throughput request-response message pattern.

Which of the following Amazon SQS queue types is the best fit to meet this requirement?

a)

Amazon Simple Queue Service (Amazon SQS) temporary queues

b)

mazon Simple Queue Service (Amazon SQS) delay queues

c)

Amazon Simple Queue Service (Amazon SQS) FIFO queues

d)

Amazon Simple Queue Service (Amazon SQS) dead-letter queue

385.

A development team wants to ensure that all objects uploaded to an Amazon S3 bucket are encrypted?

Which of the following options represents the correct solution?

a)

Configure the bucket policy to deny if the PutObject does not have an aws:SecureTransport header set to true

b)

Configure the bucket policy to deny if the PutObject does not have an x-amz-server-side-encryption header set

c)

Configure the bucket policy to deny if the PutObject does not have an s3:x-amz-acl header set to private

d)

Configure the bucket policy to deny if the PutObject does not have an s3:x-amz-acl header set

386.

A company is developing a document management application on AWS. The application runs on Amazon EC2 instances in multiple Availability Zones (AZs). The company requires the document store to be highly available and the documents need to be returned immediately when requested. The engineering team has configured the application to use Amazon Elastic Block Store (Amazon EBS) to store the documents but the team is willing to consider other options to meet the availability requirement.

As a solutions architect, which of the following will you recommend?

a)

Provision at least three Provisioned IOPS Amazon Instance Store volumes for the Amazon EC2 instances and then mount these volumes to multiple Amazon EC2 instances

b)

Set up Amazon EBS as the Amazon EC2 instance root volume and then configure the application to use Amazon S3 as the document store

c)

Set up Amazon EBS as the Amazon EC2 instance root volume and then configure the application to use Amazon S3 Glacier as the document store

d)

Create snapshots for the Amazon EBS volumes regularly and then build new volumes using those snapshots in additional Availability Zones

387.

Your e-commerce application is using an Amazon RDS PostgreSQL database and an analytics workload also runs on the same database. When the analytics workload is run, your e-commerce application slows down which further affects your sales.

Which of the following is the MOST cost-optimal solution to fix this issue?

a)

Enable Multi-AZ for the Amazon RDS database and run the analytics workload on the standby database

b)

Create a Read Replica in the same Region as the Master database and point the analytics workload there

c)

Migrate the analytics application to AWS Lambda

d)

Create a Read Replica in another Region as the Master database and point the analytics workload there

388.

During a review, a security team has flagged concerns over an Amazon EC2 instance querying IP addresses used for cryptocurrency mining. The Amazon EC2 instance does not host any authorized application related to cryptocurrency mining.

Which AWS service can be used to protect the Amazon EC2 instances from such unauthorized behavior in the future?

a)

Amazon GuardDuty

b)

AWS Shield Advanced

c)

AWS Firewall Manager

d)

AWS Web Application Firewall (AWS WAF)

389.

A startup wants to create a highly available architecture for its multi-tier application. Currently, the startup manages a single Amazon EC2 instance along with a single Amazon RDS MySQL DB instance. The startup has hired you as an AWS Certified Solutions Architect - Associate to build a solution that meets these requirements while minimizing the underlying infrastructure maintenance effort.

What will you recommend?

a)

Create an Auto-Scaling group with a desired capacity of a total of two Amazon EC2 instances in a single Availability Zone. Configure an Application Load Balancer having a target group of these Amazon EC2 instances. Set up Amazon RDS MySQL DB in a multi-AZ configuration

b)

Provision a second Amazon EC2 instance in another Availability Zone. Provision a second Amazon RDS MySQL DB in another Availabililty Zone. Leverage Amazon Route 53 for equal distribution of incoming traffic to the Amazon EC2 instances. Use a custom script to sync data across the two MySQL DBs

c)

Create an Auto-Scaling group with a desired capacity of a total of two Amazon EC2 instances across two Availability Zones. Configure an Application Load Balancer having a target group of these Amazon EC2 instances. Set up a read replica of the Amazon RDS MySQL DB in another Availability Zone

d)

Create an Auto-Scaling group with a desired capacity of a total of two Amazon EC2 instances across two Availability Zones. Configure an Application Load Balancer having a target group of these Amazon EC2 instances. Set up Amazon RDS MySQL DB in a multi-AZ configuration

390.

A company is transferring a significant volume of data from on-site storage to AWS, where it will be accessed by Windows, Mac, and Linux-based Amazon EC2 instances within the same AWS region using both SMB and NFS protocols. Part of this data will be accessed regularly, while the rest will be accessed less frequently. The company requires a hosting solution for this data that minimizes operational overhead.

What solution would best meet these requirements?

a)

Set up an Amazon Elastic File System (Amazon EFS) volume that uses EFS Infrequent Access. Use AWS DataSync to migrate the data to the EFS volume

b)

Set up an Amazon FSx for ONTAP instance. Configure an FSx for ONTAP file system on the root volume and migrate the data to the FSx for ONTAP volume

c)

Set up an Amazon FSx for OpenZFS instance. Configure an FSx for OpenZFS file ystem on the root volume and migrate the data to the FSx for OpenZFS volume

d)

Set up an Amazon Elastic File System (Amazon EFS) volume that uses EFS Intelligent-Tiering. Use AWS DataSync to migrate the data to the EFS volume