ExamGecko
Home Home / Amazon / ANS-C00

Amazon ANS-C00 Practice Test - Questions Answers, Page 19

Question list
Search
Search

List of questions

Search

Related questions











You are the AWS cloud architect and have been tasked with designing an appropriate subnetting design for your production VPC. Your production VPC requires secure communications back to the corporate private network. Quality of Service (QoS) is very important 24 7 for this particular connection, as real-time data is passed continually backwards and forwards between your on-prem bioinformatics enterprise application, and the number crunching servers deployed in the cloud. Any potential latency incurred on this connection will have a direct impact on the company's ability to attract investors and expansion into new markets. Select the correct network configuration that best facilitates your company's continued growth plans.

A.
Provision a Direct Connect connection - between your service provider's data center and the AWS region that your cloud compute resources exist in. Configure just a Private Virtual Interface. As this is a Direct Connection, a Virtual Private Gateway is not required
A.
Provision a Direct Connect connection - between your service provider's data center and the AWS region that your cloud compute resources exist in. Configure just a Private Virtual Interface. As this is a Direct Connection, a Virtual Private Gateway is not required
Answers
B.
Configure a site-to-site layer 2 software router using OpenVPN within your VPC and ensure that QoS enabled - this is a secure and cheap option
B.
Configure a site-to-site layer 2 software router using OpenVPN within your VPC and ensure that QoS enabled - this is a secure and cheap option
Answers
C.
Configure a site-to-site layer 3 software router using OpenVPN within your VPC and ensure that QoS enabled - this is a secure and cheap option
C.
Configure a site-to-site layer 3 software router using OpenVPN within your VPC and ensure that QoS enabled - this is a secure and cheap option
Answers
D.
Provision a Direct Connect connection - between your existing service provider's data center and the AWS region that your cloud compute resources exist in. Configure a Virtual Private Gateway and Private Virtual InterfaceReference: https://aws.amazon.com/directconnect/faqs/
D.
Provision a Direct Connect connection - between your existing service provider's data center and the AWS region that your cloud compute resources exist in. Configure a Virtual Private Gateway and Private Virtual InterfaceReference: https://aws.amazon.com/directconnect/faqs/
Answers
Suggested answer: D

Explanation:

Explanation:

Answers A, B, and C all rely on an Internet connection. An Internet connection cannot guarantee QoS and will be subject to performance fluctuations - therefore they are all incorrect options. The only difference between these options is whether a Virtual Private Gateway is required - the answer is yes and therefore the correct answer is D. Reference: https://aws.amazon.com/directconnect/faqs/

What are 2 possible ALIAS records? (Choose two.)

A.
DynamoDB
A.
DynamoDB
Answers
B.
Elastic Beanstalk
B.
Elastic Beanstalk
Answers
C.
CloudFront
C.
CloudFront
Answers
D.
EC2 Instance
D.
EC2 Instance
Answers
Suggested answer: B, C

Explanation:

Explanation:

You cannot create an ALIAS record that points to an EC2 instance or DynamoDB.

The Web Application Development team is worried about malicious activity from 200 random IP addresses. Which action will ensure security and scalability from this type of threat?

A.
Use inbound security group rules to block the IP addresses.
A.
Use inbound security group rules to block the IP addresses.
Answers
B.
Use inbound network ACL rules to block the IP addresses.
B.
Use inbound network ACL rules to block the IP addresses.
Answers
C.
Use AWS WAF to block the IP addresses.
C.
Use AWS WAF to block the IP addresses.
Answers
D.
Write iptables rules on the instance to block the IP addresses.
D.
Write iptables rules on the instance to block the IP addresses.
Answers
Suggested answer: B

You have been asked to monitor traffic flows on your Amazon EC2 instance. You will be performing deep packet inspection, looking for atypical patterns. Which tool will enable you to look at this data?

A.
Wireshark
A.
Wireshark
Answers
B.
VPC Flow Logs
B.
VPC Flow Logs
Answers
C.
AWS CLI
C.
AWS CLI
Answers
D.
CloudWatch Logs
D.
CloudWatch Logs
Answers
Suggested answer: A

Explanation:

Explanation:

References: https://www.slideshare.net/TeriRadichel/packet-capture-on-aws

After setting an AWS Direct Connect, which of the following cannot be done with an AWS Direct Connect Virtual Interface?

A.
You can delete a virtual interface; if its connection has no other virtual interfaces, you can delete the connection.
A.
You can delete a virtual interface; if its connection has no other virtual interfaces, you can delete the connection.
Answers
B.
You can change the region of your virtual interface.
B.
You can change the region of your virtual interface.
Answers
C.
You can create a hosted virtual interface.
C.
You can create a hosted virtual interface.
Answers
D.
You can exchange traffic between the two ports in the same region connecting to different Virtual Private Gateways (VGWs) if you have more than one virtual interface.
D.
You can exchange traffic between the two ports in the same region connecting to different Virtual Private Gateways (VGWs) if you have more than one virtual interface.
Answers
Suggested answer: D

Explanation:

Explanation:

You must create a virtual interface to begin using your AWS Direct Connect connection. You can create a public virtual interface to connect to public resources or a private virtual interface to connect to your VPC. Also, it is possible to configure multiple virtual interfaces on a single AWS Direct Connect connection, and you'll need one private virtual interface for each VPC to connect to. Each virtual interface needs a VLAN ID, interface IP address, ASN, and BGP key. To use your AWS Direct Connect connection with another AWS account, you can create a hosted virtual interface for that account. These hosted virtual interfaces work the same as standard virtual interfaces and can connect to public resources or a VPC.

Reference: http://docs.aws.amazon.com/directconnect/latest/UserGuide/WorkingWithVirtualInterfaces.html

Which of the following does not configure Amazon CloudFront cache behaviors to forward cookies to an origin for web distributions?

A.
Origin server
A.
Origin server
Answers
B.
AWS CLI
B.
AWS CLI
Answers
C.
Amazon EMR
C.
Amazon EMR
Answers
D.
Amazon S3
D.
Amazon S3
Answers
Suggested answer: D

Explanation:

Explanation:

Amazon S3 and some HTTP servers do not process cookies. Do not configure Amazon CloudFront cache behaviors toforward cookies to an origin that doesn't process cookies or you'll adversely affect cache ability and consequentlyperformance.

Reference: http://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/Cookies.html

A global film production company uses the AWS Cloud to encode and store its video content before distribution. The company's three global offices are connected to the us-east-1 Region through AWS Site-to-Site VPN links that terminate on a transit gateway with BGP routing activated.

The company recently started to produce content at a higher resolution to support 8K streaming. The size of the content files has increased to three times the size of the content files from the previous format. Uploads of files to Amazon EC2 instances are taking 10 times longer than they did with the previous format.

Which actions should a network engineer recommend to reduce the upload times? (Choose two.)

A.
Create a second VPN tunnel from each office location to the transit gateway. Activate equal-cost multi-path (ECMP) routing.
A.
Create a second VPN tunnel from each office location to the transit gateway. Activate equal-cost multi-path (ECMP) routing.
Answers
B.
Modify the transit gateway to activate Jumbo MTU on the VPN tunnels to each office location.
B.
Modify the transit gateway to activate Jumbo MTU on the VPN tunnels to each office location.
Answers
C.
Replace the existing VPN tunnels with new tunnels that have acceleration activated.
C.
Replace the existing VPN tunnels with new tunnels that have acceleration activated.
Answers
D.
Upgrade each EC2 instance to a modern instance type. Activate Jumbo MTU in the operating system.
D.
Upgrade each EC2 instance to a modern instance type. Activate Jumbo MTU in the operating system.
Answers
E.
Replace the existing VPN tunnels with new tunnels that have IGMP activated.
E.
Replace the existing VPN tunnels with new tunnels that have IGMP activated.
Answers
Suggested answer: A, D

Explanation:

Explanation:

Reference: https://aws.amazon.com/premiumsupport/knowledge-center/transit-gateway-ecmp-multiple-tunnels/ https://tutorialsdojo.com/increasing-mtu-for-your-ec2-instance/

A company's IT Security team needs to ensure that all servers within an Amazon VPC can communicate with a list of five approved external IPs only. The team also wants to receive a notification every time any server tries to open a connection with a non-approved endpoint.

What is the MOST cost-effective solution that meets these requirements?

A.
Add allowed IPs to the network ACL for the application server subnets. Enable VPC Flow Logs with a filter set to ALL.Create an Amazon CloudWatch Logs filter on the VPC Flow Logs log group filtered by REJECT. Create an alarm for this metric to notify the security team.
A.
Add allowed IPs to the network ACL for the application server subnets. Enable VPC Flow Logs with a filter set to ALL.Create an Amazon CloudWatch Logs filter on the VPC Flow Logs log group filtered by REJECT. Create an alarm for this metric to notify the security team.
Answers
B.
Enable Amazon GuardDuty on the account and the specific Region. Upload a list of allowed IPs to Amazon S3 and link the S3 object to the GuardDuty trusted IP list. Configure an Amazon CloudWatch Events rule on all GuardDuty findings to trigger an Amazon SNS notification to the security team.
B.
Enable Amazon GuardDuty on the account and the specific Region. Upload a list of allowed IPs to Amazon S3 and link the S3 object to the GuardDuty trusted IP list. Configure an Amazon CloudWatch Events rule on all GuardDuty findings to trigger an Amazon SNS notification to the security team.
Answers
C.
Add allowed IPs to the network ACL for the application server subnets. Enable VPC Flow Logs with a filter set to REJECT. Set an Amazon CloudWatch Logs filter for the log group on every event. Create an alarm for this metric to notifythe security team.
C.
Add allowed IPs to the network ACL for the application server subnets. Enable VPC Flow Logs with a filter set to REJECT. Set an Amazon CloudWatch Logs filter for the log group on every event. Create an alarm for this metric to notifythe security team.
Answers
D.
Enable Amazon GuardDuty on the account and specific Region. Upload a list of allowed IPs to Amazon S3 and link the S3 object to the GuardDuty threat IP list. Integrate GuardDuty with a compatible SIEM to report on every alarm fromGuardDuty.
D.
Enable Amazon GuardDuty on the account and specific Region. Upload a list of allowed IPs to Amazon S3 and link the S3 object to the GuardDuty threat IP list. Integrate GuardDuty with a compatible SIEM to report on every alarm fromGuardDuty.
Answers
Suggested answer: A

You operate a production VPC with both a public and a private subnet. Your organization maintains a restricted Amazon S3 bucket to support this production workload. Only Amazon EC2 instances in the private subnet should access the bucket. You implement VPC endpoints (VPC-E) for Amazon S3 and remove the NAT that previously provided a network path to Amazon S3. The default VPC-E policy is applied. Neither EC2 instances in the public or private subnets are able to access the S3 bucket.

What should you do to enable Amazon S3 access from EC2 instances in the private subnet?

A.
Add the CIDR address range of the private subnet to the S3 bucket policy.
A.
Add the CIDR address range of the private subnet to the S3 bucket policy.
Answers
B.
Add the VPC-E identifier to the S3 bucket policy.
B.
Add the VPC-E identifier to the S3 bucket policy.
Answers
C.
Add the VPC identifier for the production VPC to the S3 bucket policy.
C.
Add the VPC identifier for the production VPC to the S3 bucket policy.
Answers
D.
Add the VPC-E identifier for the production VPC to endpoint policy.
D.
Add the VPC-E identifier for the production VPC to endpoint policy.
Answers
Suggested answer: A

To determine whether a log file was modified, deleted, or unchanged after CloudTrail delivered it, you can use ____.

A.
trusted signers
A.
trusted signers
Answers
B.
optimistic locking
B.
optimistic locking
Answers
C.
integrity validation
C.
integrity validation
Answers
D.
root credentialing
D.
root credentialing
Answers
Suggested answer: C

Explanation:

Explanation:

The AWS CloudTrail uses log file integrity validation to determine whether the log files were changed or modified since CloudTrail delivered them to an Amazon S3 bucket. Reference: https://aws.amazon.com/cloudtrail/

Total 414 questions
Go to page: of 42