T15may2024 Examm
T15may2024 Examm
T15may2024 Examm
- By JD
Note : Real exam question does not mean this questions will be asked 100% in exams but it means
there is high probability that you get SAME or SIMILAR questions.
1. Which AWS services should be used for read/write of constantly changing data? Choose two.
Answer : Amazon RDS & Amazon EFS
2. What is one of the advantages of the Amazon Relational Database Service (Amazon RDS) ?
Answer : It simplifies relational database administration tasks
3. A customer needs to run a MySQL database that easily scales. Which AWS service should they use?
Answer : Amazon Aurora
4. Which of the following components of the AWS Global infrastructure consist of one or more
discrete data centers interconnected through low latency links?
Answer : Availability Zone.
5. Which of the following is a shared control between the customer and AWS?
Answer : Awareness and training.
6. How many Availability zones should compute resources be provisioned across to achieve high
availability?
Answer : A minimum of Two
7. One of the advantages to moving infrastructure from an on-premises data center to AWS cloud is?
Answer : It allows the business to focus on business activities.
8. What is the lowest cost, durable storage option for retaining database backups for immediate
retrieval?
Answer : Amazon S3
9. Which of the following is a fast and reliable NoSQL Database service?
Answer : Amazon DynamoDB
10. What is an example of agility in the AWS?
Answer : Decreased acquisition time for new compute resources.
11. Which service should a customer use to consolidate and centrally manage multiple AWS accounts?
Answer : AWS Organizations
12. What approach to transcoding a large number of individual video files adheres to AWS architecture
principle?
Answer : Using many instances in parallel
13. For which auditing process does AWS have sole responsibility?
Answer : Physical Security
14. Which feature of the AWS cloud will support an international company’s requirement for low
latency to all of its customers?
Answer : Global reach
15. Which of the following is the customer’s responsibility under the AWS Shared Responsibility
Model?
Answer : Patching Amazon EC2 instances
16. A customer is using multiple AWS account with separate billing. How can the customer take
advantage of volume discounts with minimal impact to the AWS resources?
Answer : Use the Consolidated billing feature from AWS Organizations.
17. Which of the following are the features of amazon Cloudwatch Logs? (Choose Two)
Answer : Real time monitoring & adjustable retention
18. Which of the following is an AWS managed Domain Name System (DNS) web service?
Answer : Amazon Route53
19. A customer is deploying a new application and needs to choose an AWS region. Which of the
following factors could influence the customers decision? (Choose Two)
Answer : Reduced latency & Data sovereignty compliance
20. Which storage service can be used as a low cost option for hosting static websites?
Answer : Amazon Simple Storage Service (Amazon S3)
21. Which Amazon EC2 instance pricing model can provide discounts upto 90% ?
Answer : Spot instances
22. Webservers running on Amazon EC2 access a legacy application running in a corporate data center.
What term would describe this model?
Answer : Hybrid Architecture
23. What is the benefit of using AWS managed services, such as Amazon ElastiCache and Amazon
Relational Database Service (Amazon RDS)?
Answer : They have better performance than customer-managed services.
24. Which service provides a virtually unlimited amount of online highly durable object storage?
Answer : Amazon S3
25. Which of the following identity and Access Management entities is associated with an access key ID
and secret access key when using AWS command line interface (AWS CLI)?
Answer : IAM user
26. Which of the following security related services does AWS offer? (Choose Two)
Answer : AWS Trusted Advisor security checks & Data encryption
27. Which AWS managed service is used to host databases?
Answer : Amazon RDS
28. Which AWS service provides a simple and scalable shared file storage solution for use with linux
based AWS and on premises servers?
Answer : Amazon EFS
29. When architecting cloud applications, which of the following are a key design principle?
Answer : Implementing Elasticity
30. Which AWS service should be used for long term, low cost storage of data backups?
Answer : Amazon Glacier
31. Under the shared responsibility model, which of the following is a shared control between a
customer and AWS?
Answer : Patch Management
32. Which AWS service allows companies to connect an Amazon VPC to an on premises data center?
Answer : Amazon DirectConnect
33. A company wants to reduce the physical compute footprint that developers use to run code. Which
service would meet that need by enabling serverless architecture?
Answer : AWS Lambda
34. Which task is AWS responsible for in the shared responsibility model for security and compliance?
Answer : Updating Amazon EC2 host firmware
35. Where should a company go to search software listings from independent software vendors to find,
test, buy and deploy software that runs on AWS?
Answer : Amazon MarketPlace
36. Which of the following is a benefit of using the AWS cloud?
Answer : Ability to focus on revenue-generating activities
37. When performing a cost analysis that supports physical isolation of a customer workload, which
compute hosting model should be accounted for in the Total Cost of Ownership (TCO)?
Answer : Dedicated Hosts
38. Which AWS service provides the ability to manage infrastructure as code?
Answer : AWS Cloudformation
39. If a customer needs to audit the change management of AWS resources, which of the following
AWS services should the customer use?
Answer : AWS Config
40. Which service allows a company with multiple AWS accounts to combine its usage to obtain volume
discounts?
Answer : AWS Organizations
41. Which of the following services could be used to deploy an application to servers running on
premises? (Choose two)
Answer : AWS Opswork & AWS CodeDeploy
42. Which Amazon EC2 pricing model adjusts based on supply and demand of EC2 instances?
Answer : Spot Instances
43. Which design principles for cloud architecture are recommended when re-architecting a large
monolithic application? (Choose two)
Answer : Implement Loose Coupling & Design for scalability
44. Which is the minimum AWS support plan that allows for one hour target response time for support
cases?
Answer : Business
45. Where can AWS compliance and certification reports be downloaded?
Answer : AWS Artifacts
46. Which of the following is an advantage of consolidated billing on AWS?
Answer : Volume pricing qualification
47. Which of the following AWS features enables a user to launch a pre-configured Amazon Elastic
Compute cloud (Amazon EC2 instance?
Answer: Amazon machine Image
48. How would an AWS customer easily apply common access controls to a alarge set of users?
Answer : Apply an IAM policy to an IAM group
49. What technology enables compute capacity to adjust as loads change?
Answer : Auto Scaling
50. Which AWS services are defined as global instead of regional? (Choose Two)
Answer : Amazon Route53 & Amazon Cloudfront
51. Which AWS service would you use to obtain compliance report and certificates?
Answer : AWS Artifact
52. Under the shared responsibility model, which of the following tasks are responsibility of the AWS
customer? (Choose two)
Answer : Ensuring that application data is encrypted at rest & Ensuring that users have received
security training in the use of AWS services.
53. Which AWS service can be used to manually launch instances based on resource requirements?
Answer : Amazon EC2
54. A company Is migrating an application that is running non interruptible workloads for a three year
time frame. Which pricing construct would provide the most cost effective solutions?
Answer : Amazon EC2 Reserved instances
55. The financial benefits of using AWS are : (Choose Two)
Answer : Reduced Total Cost of Ownership (TCO) & Rduced Operational Expenditure (Opex)
56. Which AWS Cost Management Tool allows you to view the most granular data about your AWS bill?
Answer : AWS Cost and Usage Report
57. Which of the following can an AWS customer use to launch a new Amazon Relational databse
service (Amazon RDS) cluster (Choose Two)
Answer : AWS Cloudformation & AWS Management Console
58. Which of the following is an AWS Cloud architecture design principle?
Answer : Implement Loose coupling
59. Which of the following security measures protect access to an AWS account? (Choose Two)
Answer : Grant least privilege access to IAM users & Activate multi factor authentication (MFA for
privileged users.
60. Which service provides a hybrid storage service that enables on premises applications to seamlessly
use cloud storage?
Answer : AWS Storage Gateway
61. Which of the following services falls under the responsibility of the customer to maintain operating
system configuration, security patching and networking?
Answer : Amazon EC2
62. Which of the following is an important architectural design principle when designing cloud
applications?
Answer : Use multiple Availability Zones.
63. Which AWS support plan includes a dedicated Technical Account Manager?
Answer : Enterprise
64. Amazon Relational Database Service (Amazon RDS) offers which of the following benefits over
traditional database management?
Answer : AWS manages the maintenance of the operating system
65. Which service is best for storing common database query results, which helps to alleviate database
access load?
Answer : Amazon ElastiCache
66. Which of the following is a component of the shared responsibility model managed entirely by
AWS?
Answer : Auditing physical data center assets
67. If each department within a company has its own AWS account, what is one way to enable
consolidated billing?
Answer : create an AWS Organization from the payer account and invite the other accounts to join.
68. Which AWS services can be used to gather information about AWS account activity? (Choose Two.)
Answer : AWS Cloudtrail & AWS Cloudwatch
69. In which Scenerio should amazon EC2 spot instances be used?
Answer : A company has a number of infrequent, interruptible jobs that are currently using On-
Demand instances.
70. Which AWS feature should a customer leverage to achieve high availability of an application?
Answer : Availability Zones
71. Which is the minimum AWS support plan that includes infrastructure Event management without
additional costs?
Answer : Business
72. Which AWS service can serve a static website?
Answer : Amazon S3
73. How does AWS shorten the time to provision IT resources?
Answer : It provides the ability to programmatically provision existing resources.
74. What can AWS edge locations be used for? (Choose Two)
Answer : Delivering content closer to users & Reducing traffic on the server by caching resources
75. Which of the following can limit Amazon Simple Storage service (Amazon S3) bucket access to
specific users?
Answer : AWS Identity and Access Management (IAM) Policies
76. A solution that is able to support growth in users, traffic or data size with no drop in performance
aligns with cloud architecture principle?
Answer : Implement elasticity
77. A company will be moving from an on premises data center to the AWS Cloud. What would be on
financial difference after the move?
Answer : moving from upfront capital expense (capex) to variable operational expense (opex)
78. How should a customer forecast the future costs for running a new web application?
Answer : AWS simple monthly calculator
79. Which is the minimum AWS support plan that provides technical support through phone calls?
Answer : Business
80. Which of the following tasks is the responsibility of AWS?
Answer : Securing the EC2 hypervisor
81. One benefit of on-demand Amazon Elastic Compute Cloud (Amazon EC2) pricing is :
Answer : paying only for time used.
82. An administrator needs to rapidly deploy a popular IT solution and start using it immediately.
Where can the administrator find assistance?
Answer : AWS Quick Start reference deployments.
83. A start-up organization is using the cost explorer tool to view and analyze its costs and usage.
Which of the below statements are correct with regards to the cost explorer tool? (Select TWO)
Answer : Provides Usage-Based Forecating & Provides trends that you can use to understand your
costs
84. The project team requires an AWS service that provides a filesystem simultaneously mounted from
different instances of EC2. Which AWS service will satisfy this requirement?
Answer : Amazon EFS
85. Which of the below statements is incorrect with regards to the advantages of moving to cloud?
Answer : Trade variable expense for capital expense
86. Project team enhancing the security features of a banking application, requires implementing a
threat detection service that continuously monitors malicious activities and unauthorized behaviors
to protect AWS accounts, workloads, and data stored in Amazon S3. Which AWS services should
the project team select?
Answer : Amazon GuardDuty
87. Which of the following support plans offer 24*7 technical support via phone, email, and chat access
to Cloud Support Engineers? (Select TWO.)
Answer : Business & Enterprise
88. Which AWS product provides a unified user interface, enabling easy management of software
development activities in one place, along with, quick development, build, and deployment of
applications on AWS?
Answer : AWS CodeStar
89. __________________ automates the discovery of sensitive data at scale and lowers the cost of
protecting your data using machine learning and pattern matching techniques.
Answer : Amazon Macie.
90. Security and Compliance is a shared responsibility between AWS and the customer. Which
amongst the below-listed options are AWS responsibilities? (Select TWO.)
Answer : Security of the cloud & Patch management within the infrastructure.
91. Based on the AWS Well-Architected Framework, how should a start-up company with a dynamic
AWS environment manage its users and resources securely without affecting the cost? Select
(TWO)
Answer : Create multiple unique IAM users with administrator access for each functional group of
the company & use of AWS Cloudfront template versions and revision controls to kee p track of the
dynamic configuration changes.
92. Which pillar of the AWS Well-Architected Framework places emphasis on making informed
decisions on the backdrop of processed data?
Answer : Operational excellence pillar
93. In the AWS environment using an EC2 instance, what is the difference between metadata and user
data?
Answer : Instance metadata are the defined parameters and attributes specified in instance
configuration, whilst user data is the information passed to the instance’s operating system to
automatically execute while launching the instance.
94. An administrator would like to install and run the same CloudWatch Agent configuration on ten
Amazon EC2 instances to collect custom metrics from them. What is the most efficient method to
achieve this objective?
Answer : Install and configure the CloudWatch Agent on one of the EC2 instances, then write the
CloudWatch Agent configuration to the parameter store of AWS Systems Manager (SSM). Install the
CloudWatch Agent configuration from SSM onto the other nine EC2 instances.
95. A group of non-tech savvy friends are looking to set up a website for an upcoming event at a cost -
effective price, with a novice-friendly interface. Which AWS service is the most appropriate to use?
Answer : Use AWS Marketplace to install a ready-made WordPress AMI.
96. Which of the following accurately describes a typical use case in which the AWS CodePipeline
service can be utilized?
Answer : to orchestrate and automate the various phases involved in the releas e of application
updates in-line with a predefined release model.
97.
NEW QUESTION 1
A company wants to run a gaming application on Amazon EC2 instances that are part of an Auto Scaling group in the AWS
Cloud. The application will transmit data by using UDP packets. The company wants to ensure that the application can
scale out and in as traffic increases and decreases.
What should a solutions architect do to meet these requirements?
Answer: B
NEW QUESTION 2
A company is developing a file-sharing application that will use an Amazon S3 bucket for storage. The company wants to
serve all the files through an Amazon CloudFront distribution. The company does not want the files to be accessible through
direct navigation to the S3 URL.
What should a solutions architect do to meet these requirements?
A. Write individual policies for each S3 bucket to grant read permission for only CloudFront access.
B. Create an IAM use
C. Grant the user read permission to objects in the S3 bucke
D. Assign the user to CloudFront.
E. Write an S3 bucket policy that assigns the CloudFront distribution ID as the Principal and assigns the target S3 bucket as
the Amazon Resource Name (ARN).
F. Create an origin access identity (OAI). Assign the OAI to the CloudFront distributio
G. Configure the S3 bucket permissions so that only the OAI has read permission.
Answer: D
Explanation:
Explanation
https://aws.amazon.com/premiumsupport/knowledge-
center/cloudfront-access-to-amazon-s3/
https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperG
uide/private-content-restricting-access-to-s3
NEW QUESTION 3
A company has two applications: a sender application that sends messages with payloads to be processed and a
processing application intended to receive the messages with payloads. The company wants to implement an AWS service
to handle messages between the two applications. The sender application can send about 1.000 messages each hour. The
messages may take up to 2 days to be processed. If the messages fail to process, they must be retained so that they do
not impact the processing of any remaining messages.
Which solution meets these requirements and is the MOST operationally efficient?
Answer: C
Explanation:
Explanation
https://aws.amazon.com/blogs/compute/building-loosely-coupled-
scalable-c-applications-with-amazon-sqs-and-
https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSD
eveloperGuide/sqs-dead-letter-queues.htm
NEW QUESTION 4
A company has created an image analysis application in which users can upload photos and add photo frames to their
images. The users upload images and metadata to indicate which photo frames they want to add to their images. The
application uses a single Amazon EC2 instance and Amazon DynamoDB to store the metadata.
The application is becoming more popular, and the number of users is increasing. The company expects the number of
concurrent users to vary significantly depending on the time of day and day of week. The company must ensure that the
application can scale to meet the needs of the growing user base.
Which solution meats these requirements?
Answer: A
NEW QUESTION 5
A company runs its two-tier ecommerce website on AWS. The web tier consists of a load balancer that sends traffic to
Amazon EC2 instances. The database tier uses an Amazon RDS DB instance. The EC2 instances and the RDS DB instance
should not be exposed to the public internet. The EC2 instances require internet
access to complete payment processing of orders through a third-party web service.
The application must be highly available. Which combination of configuration
options will meet these requirements? (Choose two.)
A. Use an Auto Scaling group to launch the EC2 instances in private subnet
B. Deploy an RDS Multi-AZ DB instance in private subnets.
C. Configure a VPC with two private subnets and two NAT gateways across two Availability Zones.Deploy an Application
Load Balancer in the private subnets.
D. Use an Auto Scaling group to launch the EC2 instances in public subnets across two Availability Zones.Deploy an RDS
Multi-AZ DB instance in private subnets.
E. Configure a VPC with one public subnet, one private subnet, and two NAT gateways across two Availability Zone
F. Deploy an Application Load Balancer in the public subnet.
G. Configure a VPC with two public subnets, two private subnets, and two NAT gateways across two Availability Zone
H. Deploy an Application Load Balancer in the public subnets.
Answer: AE
Explanation:
Explanation
Before you begin: Decide which two Availability Zones you will use for your EC2 instances. Configure your
virtual private cloud (VPC) with at least one public subnet in each of these Availability Zones. These public subnets are used
to configure the load balancer. You can launch your EC2 instances in other subnets of these Availability Zones instead.
NEW QUESTION 6
A company wants to migrate its on-premises data center to AWS. According to the company's compliance
requirements, the company can use only the ap- northeast-3 Region. Company administrators are not permitted
to connect VPCs to the internet.
Which solutions will meet these requirements? (Choose two.)
A. Use AWS Control Tower to implement data residency guardrails to deny internet access and deny access to all AWS
Regions except ap-northeast-3.
B. Use rules in AWS WAF to prevent internet acces
C. Deny access to all AWS Regions except ap-northeast-3 in the AWS account settings.
D. Use AWS Organizations to configure service control policies (SCPS) that prevent VPCs from gaining internet acces
E. Deny access to all AWS Regions except ap-northeast-3.
F. Create an outbound rule for the network ACL in each VPC to deny all traffic from 0.0.0.0/0. Create an IAM policy for
each user to prevent the use of any AWS Region other than ap-northeast-3.
G. Use AWS Config to activate managed rules to detect and alert for internet gateways and to detect and alert
for new resources deployed outside of ap- northeast-3.
Answer: AC
NEW QUESTION 7
A company wants to manage Amazon Machine Images (AMIs). The company currently copies AMIs to the same AWS Region
where the AMIs were created. The company needs to design an application that captures AWS API calls and sends alerts
whenever the Amazon EC2 Createlmage API operation is called within the company's account.
Which solution will meet these requirements with the LEAST operational overhead?
A. Create an AWS Lambda function to query AWS CloudTrail logs and to send an alert when a Createlmage API call is
detected.
B. Configure AWS CloudTrail with an Amazon Simple Notification Service {Amazon SNS) notification that occurs when
updated logs are sent to Amazon S3. Use Amazon Athena to create a new table and to query on Createlmage when an
API call is detected.
C. Create an Amazon EventBridge (Amazon CloudWatch Events) rule for the Createlmage API call.Configure the target as
an Amazon Simple Notification Service (Amazon SNS) topic to send an alert when a Createlmage API call is detected.
D. Configure an Amazon Simple Queue Service (Amazon SQS) FIFO queue as a target for AWS CloudTrail log
E. Create an AWS Lambda function to send an alert to an Amazon Simple NotificationService (Amazon SNS) topic when a
Createlmage API call is detected.
Answer: B
NEW QUESTION 8
A company hosts an application on multiple Amazon EC2 instances The application processes messages from an Amazon
SQS queue writes to an Amazon RDS table and deletes the message from the queue Occasional duplicate records are
found in the RDS table. The SQS queue does not contain any duplicate messages.
What should a solutions architect do to ensure messages are being processed once only?
Answer: D
Explanation:
Explanation
The visibility timeout begins when Amazon SQS returns a message. During this time, the consumer processes and deletes
the message. However, if the consumer fails before deleting the message and your system doesn't call the DeleteMessage
action for that message before the visibility timeout expires, the message becomes visible to other consumers and the
message is received again. If a message must be received only once, your consumer should delete it within the duration of
the visibility timeout. https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-visibility-
timeout.html
Keyword: SQS queue writes to an Amazon RDS From this, Option D best suite & other Options ruled out [Option A -
You can't intruduce one more Queue in the existing one; Option B - only Permission & Option C - Only Retrieves
Messages] FIF O queues are designed to never introduce duplicate messages.
However, your message producer might introduce duplicates in certain scenarios: for example, if the producer sends a
message, does not receive a response, and then resends the same message. Amazon SQS APIs provide deduplication
functionality that prevents your message producer from sending duplicates. Any duplicates introduced by the message
producer are removed within a 5-minute deduplication interval. For standard queues, you might occasionally receive a
duplicate copy of a message (at-least- once delivery). If you use a standard queue, you must design your applications to be
idempotent (that is, they must not be affected adversely when processing the same message more than once).
NEW QUESTION 9
A company collects temperature, humidity, and atmospheric
pressure data in cities across multiple continents. The average
volume of data collected per site each day is 500 GB. Each site
has a highspeed
internet connection. The company's weather forecasting applications are based in a
single Region and analyze the data daily. What is the FASTEST way to aggregate
data from all of these global sites?
Answer: A
Explanation:
Explanation
You might want to use Transfer Acceleration on a bucket for various reasons, including the following:
You have customers that upload
to a centralized bucket from all
over the world. You transfer
gigabytes to terabytes of data on
a regular basis across continents.
You are unable to utilize all of your available bandwidth
over the Internet when uploading to Amazon S3.
https://docs.aws.amazon.com/AmazonS3/latest/dev/transfer-acceleration.html
https://aws.amazon.com/s3/transferacceleration/#:~:text=S3%20Transfer%20Acceleration%20(S3TA)%20reduces,to%20S3%2
0for%20remote%20applications: "Amazon S3 Transfer Acceleration can speed up content transfers to and from Amazon S3
by as much
as 50-500% for long-distance transfer of larger objects. Customers who have either web or mobile
applications with widespread users or applications hosted far away from their S3 bucket can experience long and variable
upload and download speeds over the Internet"
https://docs.aws.amazon.com/Am
azonS3/latest/userguide/mpuover
view.html "Improved throughput
- You can upload parts in parallel
to improve throughput."
NEW QUESTION 10
A company is designing an application. The application uses an AWS Lambda function to receive information through
Amazon API Gateway and to store the information in an Amazon Aurora PostgreSQL database.
During the proof-of-concept stage, the company has to increase the Lambda quotas significantly to handle the high
volumes of data that the company needs to load into the database. A solutions architect must recommend a new design
to improve scalability and minimize the configuration effort.
Which solution will meet these requirements?
A. Refactor the Lambda function code to Apache Tomcat code that runs on Amazon EC2 instances.Connect the
database by using native Java Database Connectivity (JDBC) drivers.
B. Change the platform from Aurora to Amazon DynamoD
C. Provision a DynamoDB Accelerator (DAX) cluste
D. Use the DAX client SDK to point the existing DynamoDB API calls at the DAX cluster.
E. Set up two Lambda function
F. Configure one function to receive the informatio
G. Configure the other function to load the information into the databas
H. Integrate the Lambda functions by using Amazon Simple Notification Service (Amazon SNS).
I. Set up two Lambda function
J. Configure one function to receive the informatio
K. Configure the other function to load the information into the databas
L. Integrate the Lambda functions by using an Amazon Simple Queue Service (Amazon SQS) queue.
Answer: D
Explanation:
Explanation
bottlenecks can be avoided with queues (SQS).
NEW QUESTION 10
A company needs to review its AWS Cloud deployment to ensure that its Amazon S3 buckets do not have
unauthorized configuration changes. What should a solutions architect do to accomplish this goal?
Answer: A
NEW QUESTION 14
A company is launching a new application and will display application metrics on an Amazon CloudWatch dashboard. The
company’s product manager needs to access this dashboard periodically. The product manager does not have an AWS
account. A solution architect must provide access to the product manager by following the principle of least privilege.
Which solution will meet these requirements?
A. Share the dashboard from the CloudWatch consol
B. Enter the product manager’s email address, and complete the sharing step
C. Provide a shareable link for the dashboard to the product manager.
D. Create an IAM user specifically for the product manage
E. Attach the CloudWatch Read Only Access managed policy to the use
F. Share the new login credential with the product manage
G. Share the browser URL of the correct dashboard with the product manager.
H. Create an IAM user for the company’s employees, Attach the View Only Access AWS managed policy to the IAM use
I. Share the new login credentials with the product manage
J. Ask the product manager to navigate to the CloudWatch console and locate the dashboard by name in the Dashboards
section.
K. Deploy a bastion server in a public subne
L. When the product manager requires access to the dashboard, start the server and share the RDP credential
M. On the bastion server, ensure that the browser is configured to open the dashboard URL with cached AWS
credentials that have appropriate permissions to view the dashboard.
Answer: A
NEW QUESTION 16
A company that hosts its web application on AWS wants to ensure all Amazon EC2 instances. Amazon RDS DB instances. and
Amazon Redshift clusters are configured with tags. The company wants to minimize the effort of configuring and operating
this check.
What should a solutions architect do to accomplish this?
A. Use AWS Config rules to define and detect resources that are not properly tagged.
B. Use Cost Explorer to display resources that are not properly tagge
C. Tag those resources manually.
D. Write API calls to check all resources for proper tag allocatio
E. Periodically run the code on an EC2 instance.
F. Write API calls to check all resources for proper tag allocatio
G. Schedule an AWS Lambda function through Amazon CloudWatch to periodically run the code.
Answer: A
NEW QUESTION 21
A development team needs to host a website that will be accessed by other teams. The website contents consist of HTML,
CSS, client-side JavaScript, and images Which method is the MOST costeffective for hosting the website?
Answer: B
Explanation:
Explanation
In Static Websites, Web pages are
returned by the server which are
prebuilt. They use simple
languages such as HTML, CSS, or
JavaScript.
There is no processing of content on the server (according to the user) in Static Websites. Web pages are returned by the
server with no change therefore, static Websites are fast.
There is no interaction with databases.
Also, they are less costly as the host does not need to support server-side processing with different languages.
============
In Dynamic Websites, Web pages are returned by the server which are processed during runtime means they are not prebuilt
web pages but they are built during runtime according to the user’s demand.
These use server-side scripting languages such as PHP, Node.js, ASP.NET and
many more supported by the server. So, they are slower than static
websites but updates and interaction with databases are possible.
NEW QUESTION 26
A company hosts its multi-tier applications on AWS. For compliance, governance, auditing, and security, the company
must track configuration changes on its AWS resources and record a history of API calls made to these resources.
What should a solutions architect do to meet these requirements?
A. Use AWS CloudTrail to track configuration changes and AWS Config to record API calls
B. Use AWS Config to track configuration changes and AWS CloudTrail to record API calls
C. Use AWS Config to track configuration changes and Amazon CloudWatch to record API calls
D. Use AWS CloudTrail to track configuration changes and Amazon CloudWatch to record API calls
Answer: B
NEW QUESTION 31
A company is preparing to launch a public-facing web application in the AWS Cloud. The architecture consists of Amazon
EC2 instances within a VPC behind an Elastic Load Balancer (ELB). A third-party service is used for the DNS. The company's
solutions architect must recommend a solution to detect and protect against large-scale DDoS attacks.
Which solution meets these requirements?
NEW QUESTION 33
A company is hosting a static website on Amazon S3 and is using Amazon Route 53 for DNS. The website is experiencing
increased demand from around the world. The company must decrease latency for users who access the website.
Which solution meets these requirements MOST cost-effectively?
A. Replicate the S3 bucket that contains the website to all AWS Region
B. Add Route 53 geolocation routing entries.
C. Provision accelerators in AWS Global Accelerato
D. Associate the supplied IP addresses with the S3 bucke
E. Edit the Route 53 entries to point to the IP addresses of the accelerators.
F. Add an Amazon CloudFront distribution in front of the S3 bucke
G. Edit the Route 53 entries to point to the CloudFront distribution.
H. Enable S3 Transfer Acceleration on the bucke
I. Edit the Route 53 entries to point to the new endpoint.
Answer: C
NEW QUESTION 35
A company has thousands of edge devices that collectively generate 1 TB of status alerts each day.
Each alert is approximately 2 KB in size. A solutions architect needs to implement a solution to ingest and store the alerts for
future analysis.
The company wants a highly available solution. However, the company needs to minimize costs and does not want to
manage additional infrastructure. Additionally, the company wants to keep 14 days of data available for immediate
analysis and archive any data older than 14 days.
What is the MOST operationally efficient solution that meets these requirements?
A. Create an Amazon Kinesis Data Firehose delivery stream to ingest the alerts Configure the Kinesis Data Firehose stream
to deliver the alerts to an Amazon S3 bucket Set up an S3 Lifecycle configuration to transition data to Amazon S3 Glacier
after 14 days
B. Launch Amazon EC2 instances across two Availability Zones and place them behind an Elastic Load Balancer to ingest
the alerts Create a script on the EC2 instances that will store tne alerts m an Amazon S3 bucket Set up an S3 Lifecycle
configuration to transition data to Amazon S3 Glacier after 14 days
C. Create an Amazon Kinesis Data Firehose delivery stream to ingest the alerts Configure the Kinesis Data Firehose stream
to deliver the alerts to an Amazon Elasticsearch Service (Amazon ES) duster Set up the Amazon ES cluster to take manual
snapshots every day and delete data from the duster that is older than 14 days
D. Create an Amazon Simple Queue Service (Amazon SQS i standard queue to ingest the alerts and set the message
retention period to 14 days Configure consumers to poll the SQS queue check the age of the message and analyze the
message data as needed If the message is 14 days old the consumer should copy the message to an Amazon S3 bucket
and delete the message from the SQS queue
Answer: A
Explanation:
Explanation
https://aws.amazon.com/kinesis/datafirehose/features/?nc=sn&loc=2#:~:text=into%20Amazon%20S3%2C%20Amazon%20Red
shift%2C%20Amazon%20OpenSe arch%20Service%2C%20Kinesis,Delivery%20streams
NEW QUESTION 39
A company's application integrates with multiple software-as-a-service (SaaS) sources for data collection. The company
runs Amazon EC2 instances to receive the data and to upload the data to an Amazon S3 bucket for analysis. The same EC2
instance that receives and uploads the data also sends a notification to the user when an upload is complete. The
company has noticed slow application performance and wants to improve the performance as much as possible.
Which solution will meet these requirements with the LEAST operational overhead?
Answer: B
NEW QUESTION 43
A company runs a highly available image-processing application on Amazon EC2 instances in a single VPC The EC2
instances run inside several subnets across multiple Availability Zones. The EC2 instances do not communicate with each
other However, the EC2 instances download images from Amazon S3 and upload images to Amazon S3 through a single
NAT gateway The company is concerned about data transfer charges What is the MOST cost-effective way for the
company to avoid Regional data transfer charges?
Answer: C
NEW QUESTION 47
A company has an on-premises application that generates a large amount of time-sensitive data that is backed up to Amazon
S3. The application has grown and there are user complaints about internet bandwidth limitations. A solutions architect
needs to design a long-term solution that allows for both timely backups to Amazon S3 and with minimal impact on internet
connectivity for internal users.
Which solution meets these requirements?
A. Establish AWS VPN connections and proxy all traffic through a VPC gateway endpoint
B. Establish a new AWS Direct Connect connection and direct backup traffic through this new connection.
C. Order daily AWS Snowball devices Load the data onto the Snowball devices and return the devices to AWS each day.
D. Submit a support ticket through the AWS Management Console Request the removal of S3 service limits from the
account.
Answer: B
NEW QUESTION 49
A company has an application that provides marketing services to stores. The services are based on previous purchases by
store customers. The stores upload transaction data to the company through SFTP, and the data is processed and analyzed
to generate new marketing offers. Some of the files can exceed 200 GB in size.
Recently, the company discovered that some of the stores have uploaded files that contain personally identifiable
information (PII) that should not have been included. The company wants administrators to be alerted if PII is shared again.
The company also wants to automate remediation.
What should a solutions architect do to meet these requirements with the LEAST development effort?
Answer: B
NEW QUESTION 54
A company wants to migrate its on-premises application to AWS. The application produces output files that vary in size from
tens of gigabytes to hundreds of terabytes The application data must be stored in a standard file system structure
The company wants a solution that scales automatically, is highly available, and
requires minimum operational overhead. Which solution will meet these
requirements?
A. Migrate the application to run as containers on Amazon Elastic Container Service (Amazon ECS) Use Amazon S3 for
storage
B. Migrate the application to run as containers on Amazon Elastic Kubernetes Service (Amazon EKS) Use Amazon Elastic
Block Store (Amazon EBS) for storage
C. Migrate the application to Amazon EC2 instances in a Multi-AZ Auto Scaling grou
D. Use Amazon Elastic File System (Amazon EFS) for storage.
E. Migrate the application to Amazon EC2 instances in a Multi-AZ Auto Scaling grou
F. Use Amazon Elastic Block Store (Amazon EBS) for storage.
Answer: C
NEW QUESTION 55
A company needs to keep user transaction data in an Amazon DynamoDB table. The
company must retain the data for 7 years. What is the MOST operationally efficient
solution that meets these requirements?
Answer: C
NEW QUESTION 58
A company has more than 5 TB of file data on Windows file servers that run on premises Users and applications interact with
the data each day
The company is moving its Windows workloads to AWS. As the company continues this process, the company requires
access to AWS and on-premises file storage with minimum latency The company needs a solution that minimizes
operational overhead and requires no significant changes to the existing file access patterns. The company uses an AWS
Site-to-Site VPN connection for connectivity to AWS
What should a solutions architect do to meet these requirements?
Answer: D
NEW QUESTION 60
A company is running a high performance computing (HPC) workload on AWS across many Linux based Amazon EC2
instances. The company needs a shared storage system that is capable of sub-millisecond latencies, hundreds of Gbps of
throughput and millions of IOPS. Users will store millions of small files.
Which solution meets these requirements?
A. Create an Amazon Elastic File System (Amazon EFS) file system Mount me file system on each of the EC2 instances
B. Create an Amazon S3 bucket Mount the S3 bucket on each of the EC2 instances
C. Ensure that the EC2 instances ate Amazon Elastic Block Store (Amazon EBS) optimized Mount Provisioned lOPS SSD
(io2) EBS volumes with Multi-Attach on each instance
D. Create an Amazon FSx for Lustre file syste
E. Mount the file system on each of the EC2 instances
Answer: D
NEW QUESTION 62
A company collects data from thousands of remote devices by using a RESTful web services application that runs on an
Amazon EC2 instance. The EC2 instance receives the raw data, transforms the raw data, and stores all the data in an Amazon
S3 bucket. The number of remote devices will increase into the millions soon. The company needs a highly scalable solution
that minimizes operational overhead.
Which combination of steps should a solutions architect take to meet these requirements9 (Select TWO.)
Answer: BE
NEW QUESTION 65
A company is expecting rapid growth in the near future. A solutions architect needs to configure existing users and grant
permissions to new users on AWS The solutions architect has decided to create IAM groups The solutions architect will add
the new users to IAM groups based on department
Which additional action is the MOST secure way to grant permissions to the new users?
Answer: C
NEW QUESTION 67
A company hosts a serverless application on AWS. The application uses Amazon API Gateway. AWS Lambda, and an
Amazon RDS for PostgreSQL database. The company notices an increase in application errors that result from database
connection timeouts during times of peak traffic or unpredictable traffic. The company needs a solution that reduces the
application failures with the least amount of change to the code.
What should a solutions architect do to meet these requirements?
Answer: B
NEW QUESTION 72
A company hosts its product information webpages on AWS The existing solution uses multiple Amazon EC2 instances behind
an Application Load Balancer in an Auto Scaling group. The website also uses a custom DNS name and communicates with
HTTPS only using a dedicated SSL certificate The company is planning a new product launch and wants to be sure that users
from around the world have the best possible experience on the new website
What should a solutions architect do to meet these requirements?
Answer: A
Explanation:
as CloudFront can help provide the best experience for global users. CloudFront integrates seamlessly with ALB and provides
and option to use custom DNS and SSL certs.
NEW QUESTION 77
A company is planning to build a high performance computing (HPC) workload as a service solution that Is hosted on AWS A
group of 16 AmazonEC2Ltnux Instances requires the lowest possible latency for
node-to-node communication. The instances also need a shared
block device volume for high-performing storage.
Which solution will meet these requirements?
Answer: A
NEW QUESTION 78
A company wants to use the AWS Cloud to make an existing application highly available and resilient. The current version
of the application resides in the company's data center. The application recently experienced data loss after a database
server crashed because of an unexpected power outage.
The company needs a solution that avoids any single points of failure. The solution must give the application the
ability to scale to meet user demand. Which solution will meet these requirements?
A. Deploy the application servers by using Amazon EC2 instances in an Auto Scaling group across multiple Availability Zone
B. Use an Amazon RDS DB instance in a Multi-AZ configuration.
C. Deploy the application servers by using Amazon EC2 instances in an Auto Scaling group in a single Availability Zon
D. Deploy the database on an EC2 instanc
E. Enable EC2 Auto Recovery.
F. Deploy the application servers by using Amazon EC2 instances in an Auto Scaling group across multiple Availability Zone
G. Use an Amazon RDS DB instance with a read replica in a single Availability Zon
H. Promote the read replica to replace the primary DB instance if the primary DB instance fails.
I. Deploy the application servers by using Amazon EC2 instances in an Auto Scaling group across multiple Availability
Zones Deploy the primary and secondary database servers on EC2 instances across multiple Availability Zones Use
Amazon Elastic Block Store (Amazon EBS) Multi-Attach to create shared storage between the instances.
Answer: A
NEW QUESTION 82
A company is implementing a new business application The application runs on two Amazon EC2 instances and uses an
Amazon S3 bucket for document storage A solutions architect needs to ensure that the EC? instances can access the S3
bucket
What should the solutions architect do to moot this requirement?
Answer: C
NEW QUESTION 83
A solution architect is creating a new Amazon CloudFront distribution for an application Some of Ine information
submitted by users is sensitive. The application uses HTTPS but needs another layer" of security The sensitive information
should be protected throughout the entire application stack end access to the information should be restricted to certain
applications
Which action should the solutions architect take?
Answer: C
NEW QUESTION 88
A company wants to build a scalable key management Infrastructure to support developers who
need to encrypt data in their applications. What should a solutions architect do to reduce the
operational burden?
Answer: B
NEW QUESTION 92
A company has migrated a two-tier application from its on-premises data center to the AWS Cloud The data tier is a Multi-
AZ deployment of Amazon RDS for Oracle with 12 TB of General Purpose SSD Amazon Elastic Block Store (Amazon EBS)
storage The application is designed to process and store documents in the database as binary large objects (blobs) with an
average document size of 6 MB
The database size has grown over time reducing the performance and increasing the cost of storage. The company must
improve the database performance and needs a solution that is highly available and resilient
Which solution will meet these requirements MOST cost-effectively?
A. Reduce the RDS DB instance size Increase the storage capacity to 24 TiB Change the storage type to Magnetic
B. Increase the RDS DB instance siz
C. Increase the storage capacity to 24 TiB Change the storage type to Provisioned IOPS
D. Create an Amazon S3 bucke
E. Update the application to store documents in the S3 bucket Store theobject metadata m the existing database
F. Create an Amazon DynamoDB tabl
G. Update the application to use DynamoD
H. Use AWS Database Migration Service (AWS DMS) to migrate data from the Oracle database to DynamoDB
Answer: C
NEW QUESTION 93
A company's website handles millions of requests each day and the number of requests continues to increase. A solutions
architect needs to improve the response time of the web application. The solutions architect determines that the application
needs to decrease latency when retrieving product details from the Amazon DynamoDB table
Which solution will meet these requirements with the LEAST amount of operational overhead?
A. Set up a DynamoDB Accelerator (DAX) cluster Route all read requests through DAX.
B. Set up Amazon ElastiCache for Redis between the DynamoDB table and the web application Route all read requests
through Redis.
C. Set up Amazon ElastrCachertor Memcached between the DynamoDB table and the web application Route all read
requests through Memcached.
D. Set up Amazon DynamoDB streams on the table and have AWS Lambda read from the table andpopulate Amazon
ElastiCache Route all read requests through ElastiCache
Answer: A
NEW QUESTION 96
A company is building a containerized application on premises and decides to move the application to AWS. The
application will have thousands of users soon after li is deployed. The company Is unsure how to manage the deployment
of containers at scale. The company needs to deploy the containerized application in a highly available architecture that
minimizes operational overhead.
Which solution will meet these requirements?
A. Store container images In an Amazon Elastic Container Registry (Amazon ECR) repositor
B. Use an Amazon Elastic Container Service (Amazon ECS) cluster with the AWS Fargate launch type to run the container
C. Use target tracking to scale automatically based on demand.
D. Store container images in an Amazon Elastic Container Registry (Amazon ECR) repositor
E. Use an Amazon Elastic Container Service (Amazon ECS) cluster with the Amazon EC2 launch type to run the container
F. Use target tracking to scale automatically based on demand.
G. Store container images in a repository that runs on an Amazon EC2 instanc
H. Run the containers on EC2 instances that are spread across multiple Availability Zone
I. Monitor the average CPU utilization in Amazon CloudWatc
J. Launch new EC2 instances as needed
K. Create an Amazon EC2 Amazon Machine Image (AMI) that contains the container image Launch EC2 Instances in
an Auto Scaling group across multiple Availability Zone
L. Use an Amazon CloudWatch alarm to scale out EC2 instances when the average CPU utilization threshold is breached.
Answer: A
A. Have the R&D AWS account be part of both organizations during the transition.
B. Invite the R&D AWS account to be part of the new organization after the R&D AWS account has left the prior
organization.
C. Create a new R&D AWS account in the new organizatio
D. Migrate resources from the period R&D AWS account to thee new R&D AWS account
E. Have the R&D AWS account into the now organisatio
F. Make the now management account a member of the prior organisation
Answer: B
A. Create an S3 Glacier vault Apply a write-once, read-many (WORM) vault lock policy to the objects
B. Create an S3 bucket with S3 Object Lock enabled Enable versioning Set a retention period of 100 years Use
governance mode as the S3 bucket's default retention mode for new objects
C. Create an S3 bucket Use AWS CloudTrail to (rack any S3 API events that modify the objects Upon notification, restore the
modified objects from any backup
versions that the company has
D. Create an S3 bucket with S3 Object Lock enabled Enable versioning Add a legal hold to the objects Add the s3
PutObjectLegalHold permission to the 1AM policies of users who need to delete the objects
Answer: D
A. Use zonal Reserved Instances for the master nodes and the ewe nodes Use a Spot Fleet lor tire task nodes
B. Use zonal Reserved Instances for the master nodes Use Spot instances for the core nodes and the task nodes
C. Use regional Reserved Instances for the master nodes Use a Spot Fleer for the core nodes and the task nodes
D. Use regional Reserved Instances for the master node
E. Use On-Demand Capacity Reservations for the core nodes and the task nodes.
Answer: A
A. Use a database in Amazon RDS with Multi-AZ and at least one read replica.
B. Use a database in Amazon RDS with Multi-AZ and at least one standby replica.
C. Use databases that are hosted on multiple Amazon EC2 instances in different AWS Regions.
D. Use databases that are hosted on Amazon EC2 instances behind an Application Load Balancer in different Availability
Zones
Answer: A
Explanation:
https://aws.amazon.com/blogs/database/implementing-a-disaster-recovery-strategy-with-amazon-rds/
Explanation:
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-ec2-placementgroup.html "A cluster
placement group is a logical grouping of instances within a single Availability Zone that benefit from low network latency,
high network throughput"
Answer: C
A. Create a read replica in us-west-1 Set the DB cluster to automaKaliy fail over to the read replica if the primary instance is
not responding
B. Create an Aurora global database Sel us-west-1 as the secondary Region update connections to use the writer and reader
endpomis as appropriate
C. Set up a second Aurora DB cluster in us-west-1 Use logical replication to keep the databases synchronized
Create an Amazon EvontBridgc (Amazon CloudWatch Events) rule to change thedatabase endpoint rf the
primary DB cluster does not respond.
D. Use Aurora automated snapshots to store data in an Amazon S3 bucket Enable S3 Verswnm
E. Configure S3 Cross-Region Replication to us-west-1 Create a second Aurora DB cluster in us-west-1 Create an
Amazon EventBndge (Amazon CloudWatch Events) rule to restore the snapshot il the primary D8 cluster does not
respond
Answer: B
A. Enable S3 Versioning on the publisher account's S3 bucket Configure S3 Same-Region Replication of the objects to the
subscriber account's S3 bucket
B. Create an AWS Lambda function that is invoked when objects are published in the publisher account's S3 bucke
C. Configure the Lambda function to copy the objects to the subscriber accounts S3 bucket
D. Configure Amazon EventBridge (Amazon CloudWatch Events) to invoke an AWS Lambda function when objects are
published in the publisher account's S3 bucket Configure the Lambda function to copy the objects to the subscriber
account's S3 bucket
E. Configure Amazon EventBridge (Amazon CloudWatch Events) to publish Amazon Simple Notification Service
(Amazon SNS) notifications when objects are published in the publisher account's S3 bucket When notifications are
received use the S3 console to copy the objects to the subscriber accounts S3 bucket
Answer: B
Answer: A
Explanation:
- Scheduled scaling is the solution here, while "using the least amount of settings possible" - Beanstalk vs moving to ECS -
ECS requires MORE CONFIGURATION / SETTINGS (task and service definitions, configuring ECS container agent) than
Beanstalk (upload application code) https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/environments-cfg-
autoscaling-scheduledactions.html Elastic Beanstalk supports time based scaling, since we are aware that the application
performance slows down during the lunch hours.
https://aws.amazon.com/about-aws/whats-new/2015/05/aws-elastic-beanstalk-supports-time-based-scaling/
A. Write the document information to an Amazon EC2 instance that runs a MySQL database
B. Write the document information to an Amazon S3 bucket Use Amazon Athena to query the data
C. Create an Auto Scaling group of Amazon EC2 instances to run a custom application that processes the scanned files and
extracts the medical information.
D. Create an AWS Lambda function that runs when new documents are uploaded Use Amazon Rekognition to convert
the documents to raw text Use Amazon Transcribe Medical to detect and extract relevant medical Information from
the text.
E. Create an AWS Lambda function that runs when new documents are uploaded Use Amazon Textract to convert
the documents to raw text Use Amazon Comprehend Medical to detect and extract relevant medical information
from the text
Answer: AE
Answer: BE
NEW QUESTION 132
An ecommerce company has an order-processing application that uses Amazon API Gateway and an AWS Lambda
function. The application stores data in an Amazon Aurora PostgreSQL database. During a recent sales event, a sudden
surge in customer orders occurred. Some customers experienced timeouts and the application did not process the orders
of those customers A solutions architect determined that the CPU utilization and memory utilization were high on the
database because of a large number of open connections The solutions architect needs to prevent the timeout errors
while making the least possible changes to the application.
Which solution will meet these requirements?
A. Configure provisioned concurrency for the Lambda function Modify the database to be a global database in multiple AWS
Regions
B. Use Amazon RDS Proxy to create a proxy for the database Modify the Lambda function to use the RDS Proxy endpoint
instead of the database endpoint
C. Create a read replica for the database in a different AWS Region Use query string parameters in API Gateway to route
traffic to the read replica
D. Migrate the data from Aurora PostgreSQL to Amazon DynamoDB by using AWS Database Migration Service (AWS
DMS| Modify the Lambda function to use the OynamoDB table
Answer: C
A. Deploy EC2 instances In an additional Region Create a DB instance with the Multi-AZ option activated
B. Deploy all EC2 instances in the same Region and the same Availability Zon
C. Create a DB instance with the Multi-AZ option activated.
D. Deploy the fcC2 instances across at least two Availability Zones within the some Regio
E. Create a DB instance in a single Availability Zone
F. Deploy the EC2 instances across at least Two Availability Zones within the same Regio
G. Create a DB instance with the Multi-AZ option activated
Answer: D
Answer: D
NEW QUESTION 142
A company has a business system that generates hundreds of reports each day. The business system saves the reports to a
network share in CSV format The company needs to store this data in the AWS Cloud in near-real time for analysis. Which
solution will meet these requirements with the LEAST administrative overhead?
A. Use AWS DataSync to transfer the files to Amazon S3 Create a scheduled task that runs at the end of each day.
B. Create an Amazon S3 File Gateway Update the business system to use a new network share from the S3 File Gateway.
C. Use AWS DataSync to transfer the files to Amazon S3 Create an application that uses the DataSync API in the automation
workflow.
D. Deploy an AWS Transfer for SFTP endpoint Create a script that checks for new files on the network share and uploads the
new files by using SFTP.
Answer: B
A. Update the Kinesis Data Streams default settings by modifying the data retention period.
B. Update the application to use the Kinesis Producer Library (KPL) lo send the data to Kinesis Data Streams.
C. Update the number of Kinesis shards lo handle the throughput of me data that is sent to Kinesis Data Streams.
D. Turn on S3 Versioning within the S3 bucket to preserve every version of every object that is ingested in the S3 bucket.
Answer: A
Answer: C
A. group in the private subnets and associate it with an Application Load Balancer Configure a Network Load Balancer in the
public subnet
B. Configure the Auto Scaling
C. group in the public subnets and associate it with an Application Load Balancer.
D. Configure an Application Load Balancer in the public subnet
E. Configure the Auto Scaling group in the private subnets and associate it with the Application Load
F. Balancer, Configure an Application Load Balancer in the private subnet
G. Configure the Auto Scaling group in the private subnets and associate it with the Application Load Balancer.
Answer: C
Answer: B
A. Set up long polling in the SQS queue by increasing the ReceiveMessage wait time to 30 seconds.
B. Change the SQS standard queue to an SQS FIFO queu
C. Use the message deduplication ID to discard duplicate messages.
D. Increase the visibility timeout in the SQS queue to a value that is greater than the total of the function timeout and the
batch window timeout.
E. Modify the Lambda function to delete each message from the SQS queue immediately after the message is read before
processing.
Answer: B
A. Create an interlace VPC endpoinl for Amazon S3 in the subnet where the EC2 instance is located Attach a resource
policy to the S3 bucket to only allow the EC2 instance's 1AM rote for access
B. Create a gateway VPC endpoinl for Amazon S3 in the Availability Zone where the EC2 instance is located Attach
appropriate security groups to the endpoint Attach a resource policy to the S3 bucket to only allow the EC2 instance's
lAM tote for access
C. Run the nslookup toot from inside the EC2 instance to obtain the private IP address of the S3 bucket's service API
endpoint Create a route in the VPC route table to provide the EC2 instance with access to the S3 bucket Attach a
resource policy to the S3 bucket to only allow the EC2 instance's AM role for access
D. Use the AWS provided publicly available ip-ranges |son file to obtam the pnvate IP address of the S3 bucket's service
API endpoint Create a route in the VPC route table to provide the EC2 instance with access to the S3 bucket Attach a
resource policy to the S3 bucket to only allow the EC2 instance's 1AM role for access
Answer: B
Answer: C
Explanation:
https://aws.amazon.com/premiumsupport/knowledge-center/multivalue-versus-simple-policies/
"Use a multivalue answer routing policy to help distribute DNS responses across multiple resources. For example, use
multivalue answer routing when you want to associate your routing records with a Route 53 health check."
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-policy.html#routing-policy-multivalue
A. Create a database server security group with inbound and outbound rules for MySQL port 3306 traffic to and from
anywhere (0.0.0.0/0).
B. Create a database server security group with an inbound rule for MySQL port 3300 and specify the source as a web server
security group.
C. Create a web server security group within an inbound allow rule for HTTPS port 443 traffic from anywbere (0.0.0.0/0) and
an inbound deny rule for IP range
182. 20.0.0/16
D. Create a web server security group with an inbound rule for HTTPS port 443 traffic from anywhere (0.0.0.0/0). Create
network ACL inbound and outbound deny rules for IP range 182. 20.0.0/16
E. Create a web server security group with an inbound and outbound rules for HTTPS port 443 traffic to and from
anywbere (0.0.0.0/0). Create a network ACL inbound deny rule for IP range 182. 20.0.0/16.
Answer: BD
Answer: A
A. Use AWS DataSync to transfer the data to Amazon S3. Use AWS Glue to transform the data and integrate the data into a
data lake.
B. Use AWS Snowball to transfer the data to Amazon S3. Use AWS Batch to transform the data and integrate the data into a
data lake.
C. Use AWS Database Migration Service (AWS DMS) to transfer the data to Amazon S3 Use AWS Glue to transform the
data and integrate the data into a data lake.
D. Use an Amazon EC2 instance to transfer the data to Amazon S3. Configure the EC2 instance to transform the data and
integrate the data into a data lake.
Answer: C
A. Use Amazon DynamoDB with auto scaling Use on-demand backups and Amazon DynamoDB Streams
B. Use Amazon Redshif
C. Configure concurrency scalin
D. Activate audit loggin
E. Perform database snapshots every 4 hours.
F. Use Amazon RDS with Provisioned IOPS Activate the database auditing parameter Perform database snapshots every 5
hours
G. Use Amazon Aurora MySQL with auto scalin
H. Activate the database auditing parameter
Answer: B
A. Host the application on AWS Lambda Integrate the application with Amazon API Gateway.
B. Host the application with AWS Amplif
C. Connect the application to an Amazon API Gateway API that is integrated with AWS Lambda.
D. Host the application on Amazon EC2 instance
E. Set up an Application Load Balancer with EC2 instances in an Auto Scaling group as targets.
F. Host the application on Amazon Elastic Container Service (Amazon ECS) Set up an Application Load Balancer with Amazon
ECS as the target.
Answer: C
A. Create internal Network Load Balancers in front of the application in each Region
B. Create external Application Load Balancers in front of the application in each Region
C. Create an AWS Global Accelerator accelerator to route traffic to the load balancers in each Region
D. Configure Amazon Route 53 to use a geolocation routing policy to distribute the traffic
E. Configure Amazon CloudFront to handle the traffic and route requests to the application in each Region
Answer: AC
A. Use one SQS FIFO queue Assign a higher priority to the paid photos so they are processed first
B. Use two SQS FIFO queues: one for paid and one for free Set the free queue to use short polling and the paid queue to use
long polling
C. Use two SQS standard queues one for paid and one for free Configure Amazon EC2 instances to prioritize polling for the
paid queue over the free queue.
D. Use one SQS standard queu
E. Set the visibility timeout of the paid photos to zero Configure Amazon EC2 instances to prioritize visibility settings so paid
photos are processed first
Answer: C
Explanation:
https://acloud.guru/forums/guru-of-the-week/discussion/-
L7Be8rOao3InQxdQcXj/ https://aws.amazon.com/sqs/features/ Priority:
Use separate queues to provide prioritization of work.
https://aws.amazon.com/sqs/features/
https://aws.amazon.com/sqs/features/#:~:text=Priority%3A%20Use%20sepa
rate%20queues%20to%20provide%
https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDevelope
rGuide/sqs-short-and-long-polling.
A. S3 Standard
B. S3 Intelligent-Tiering
C. S3 Standard-Infrequent Access (S3 Standard-IA)
D. S3 One Zone-Infrequent Access (S3 One Zone-IA)
Answer: C
A. Use an Auto Scaling group to launch the EC2 Instances in private subnets Deploy an RDS Mulli-AZ DB instance in private
subnets
B. Configure a VPC with two private subnets and two NAT gateways across two Availability Zones Deploy an Application
Load Balancer in the private subnets
C. Use an Auto Scaling group to launch the EC2 instances in public subnets across two Availability Zones Deploy an RDS
Multi-AZ DB instance in private subnets
D. Configure a VPC with one public subnet, one private subnet, and two NAT gateways across two Availability Zones
Deploy an Application Load Balancer in the public subnet
E. Configure a VPC with two public subnets, two private subnets, and two NAT gateways across two Availability Zones
Deploy an Application Load Balancer in the public subnets
Answer: AE
Answer: B
A. Use AWS DataSync to move the data Create a custom transformation job by using AWS Glue
B. Order an AWS Snowcone device to move the data Deploy the transformation application to the device
C. Order an AWS Snowball Edge Storage Optimized devic
D. Copy the data to the devic
E. Create a customtransformation job by using AWS Glue
F. Order an AWS
G. Snowball Edge Storage Optimized device that includes Amazon EC2 compute Copy the data to the device Create a
new EC2 instance on AWS to run the transformation application
Answer: D
Answer: D
Answer: C
Answer: A
Answer: C
NEW QUESTION 204
A company has an application that processes customer of tiers. The company hosts the application on an Amazon EC2
instance that saves the orders to an Amazon Aurora database. Occasionally when traffic Is high, the workload does not
process orders fast enough.
What should a solutions architect do to write the orders reliably to the database as quickly as possible?
A. Increase the instance size of the EC2 instance when baffle Is hig
B. Write orders to Amazon Simple Notification Service (Amazon SNS) Subscribe the database endpoint to the SNS topic
C. Write orders to an Amazon Simple Queue Service (Amazon SOS) queue Use EC2 instances in an Auto Scaling group
behind an Application Load Balancer to read born the SQS queue and process orders into the database
D. Write orders to Amazon Simple Notification Service (Amazon SNS). Subscribe the database endpoint to the SNS topi
E. Use EC2 ^stances in an Auto Scaling group behind an Application Load Balancer to read from the SNS topic.
F. Write orders to an Amazon Simple Queue Service (Amazon SQS) queue when the EC2 instance reaches CPU threshold
limit
G. Use scheduled scaling of EC2 instances in an Auto Scaling group behind an Application Load Balancer to read from
the SQS queue and process orders into the database
Answer: B
Answer: C
Explanation:
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.Encryption.html#Overview.Encryption.
NEW QUESTION 209
A company maintains a searchable repository of items on its website. The data is stored in an Amazon RDS for MySQL
database table that contains more than 10 million rows The database has 2 TB of General Purpose SSD storage There are
millions of updates against this data every day through the company's website The company has noticed that some insert
operations are taking 10 seconds or longer The company has determined that the database storage performance is the
problem
Which solution addresses this performance issue?
Answer: A
Explanation:
https://aws.amazon.com/ebs/features/
"Provisioned IOPS volumes are backed by solid-state drives (SSDs) and are the highest performance EBS volumes designed
for your critical, I/O intensive database applications. These volumes are ideal for both IOPS-intensive and throughput-
intensive workloads that require extremely low latency."
Answer: C
Answer: B
A. Create an Amazon CloudWatch alarm to scale up the EC2 instances when CPU utilization exceeds 90%.
B. Create a recurring scheduled action to scale up the Auto Scaling group before the expected period of peak demand.
C. increase the minimum and maximum number of EC2 instances in the Auto Scaling group during the peak demand period
D. Configure an Amazon Simple Notification Service (Amazon SNS) notification to send alerts when there are autoscaling
EC2_INSTANCE_LAUNCH events
Answer: B
Answer: C
Explanation:
using AWS ECS on AWS Fargate since they requirements are for scalability and availability without having to provision and
manage the underlying infrastructure to run the containerized workload.
https://docs.aws.amazon.com/AmazonECS/latest/userguide/what-is-fargate.html
A. Store the Iogs in Amazon S3 Use AWS Backup lo move logs more than 1 month old to S3 Glacier Deep Archive
B. Store the logs in Amazon S3 Use S3 Lifecycle policies to move logs more than 1 month old to S3 Glacier Deep Archive
C. Store the logs in Amazon CloudWatch Logs Use AWS Backup to move logs more then 1 month old to S3 Glacier Deep
Archive
D. Store the logs in Amazon CloudWatch Logs Use Amazon S3 Lifecycle policies to move logs more than 1 month old to S3
Glacier Deep Archive
Answer: B
A. Create an AWS Lambda function to query AWS CloudTrail logs and to send an alert when a Createlmage API call is
detected
B. Configure AWS CloudTrail with an Amazon Simple Notification Sen/ice (Amazon SNS) notification that occurs when
updated logs are sent to Amazon S3 Use Amazon Athena to create a new table and to query on Createlmage when an
API call is detected
C. Create an Amazon EventBndge (Amazon CloudWatch Events) rule for the Createlmage API call Configure the target as
an Amazon Simple Notification Service (Amazon SNS) topic to send an alert when a Createlmage API call is detected
D. Configure an Amazon Simple Queue Service (Amazon SQS) FIFO queue as a target for AWS CloudTrail logs Create an
AWS Lambda function to send an alert to an Amazon Simple Notification Service (Amazon SNS) topic when a Createlmage
API call is detected
Answer: B
Answer: B
Answer: B
A. Create an Amazon CloudFront distribution that has the S3 bucket and the ALB as origins Configure Route 53 to route
traffic to the CloudFront distribution.
B. Create an Amazon CloudFront distribution that has the ALB as an origin Create an AWS Global Accelerator standard
accelerator that has the S3 bucket as an endpoin
C. Configure Route 53 to route traffic to the CloudFront distribution.
D. Create an Amazon CloudFront distribution that has the S3 bucket as an origin Create an AWS Global Accelerator standard
accelerator that has the ALB and the
CloudFront distribution as endpoints Create a custom domain name that points to the accelerator DNS name Use the custom
domain name as an endpoint for the web application.
E. Create an Amazon CloudFront distribution that has the ALB as an origin
F. Create an AWS Global Accelerator standard accelerator that has the S3 bucket as an endpoint Create two domain name
G. Point one domain name to the CloudFront DNS name for dynamic content, Point the other domain name to the
accelerator DNS name for static content Use the domain names as endpoints for the web application.
Answer: D
A. Add a rule m ACM to publish a custom message to an Amazon Simple Notification Service (Amazon SNS) topic
every day beginning 30 days before any certificate will expire.
B. Create an AWS Config rule that checks for certificates that will expire within 30 day
C. Configure Amazon EventBridge (Amazon CloudWatch Events) to invoke a custom alert by way of Amazon Simple
Notification Service (Amazon SNS) when AWS Config reports a noncompliant resource
D. Use AWS trusted Advisor to check for certificates that will expire within to day
E. Create an Amazon CloudWatch alarm that is based on Trusted Advisor metrics for check status changes Configure the
alarm to send a custom alert by way of Amazon Simple rectification Service (Amazon SNS)
F. Create an Amazon EventBridge (Amazon CloudWatch Events) rule to detect any certificates that will expire within 30 day
G. Configure the rule to invoke an AWS Lambda functio
H. Configure the Lambda function to send a custom alert by way of Amazon Simple Notification Service (Amazon SNS).
Answer: B
A. S3 Standard
B. S3 Intelligent-Tiering
C. S3 Standard-Infrequent Access {S3 Standard-IA)
D. S3 One Zone-Infrequent Access (S3 One Zone-IA)
Answer: B
Answer: D
Answer: AD
A. Create Amazon Elastic Block Store (Amazon EBS) volumes In the same Availability Zones where EKS worker nodes are
place
B. Register the volumes In a StorageClass object on an EKS cluster Use EBS Multi-Attach to share the data between
containers
C. Create an Amazon Elastic File System (Amazon EFS) tile system Register the tile system in a StorageClass object on an EKS
cluster Use the same file system
for all containers
D. Create an Amazon Elastic Block Store (Amazon EBS) volume Register the volume In a StorageClass object on an EKS
cluster Use the same volume for all containers.
E. Create Amazon Elastic File System (Amazon EFS) file systems In the same Availability Zones where EKS worker nodes
are placed Register the file systems in a StorageClass obied on an EKS duster Create an AWS Lambda function to
synchronize the data between file systems
Answer: B
A. Place the instances in a public subnet Use Amazon S3 for storage Access S3 objects by using URLs
B. Place the instances in a private subnet use Amazon S3 for storage Use a VPC endpoint to access S3 objects
C. Use the instances with a Provisioned IOPS SSD (io2) Amazon Elastic Block Store (Amazon EBS) volume.
D. Use Amazon Elastic File System (Amazon EPS) Standard-Infrequent Access (Standard-IA) to store data and provide shared
access to the instances
Answer: B
Actual Exam
Questions 2nd -
Questons and
Answers in PDF
Format