ExamGecko
Home Home / Amazon / PAS-C01

Amazon PAS-C01 Practice Test - Questions Answers, Page 4

Question list
Search
Search

List of questions

Search

Related questions











A company is running an SAP HANA database on AWS The company is running AWS Backint Agent for SAP HANA(AWS Backint agent) on an Amazon EC2 instance AWS Back agent is configured to back up to an Amazon S3 bucket The backups are failing with an AccessDeniod error m the AWS Backint agent log file.

What should an SAP basis administrator do to resolve this error?

A.
Assign execute permissions at the operating system level for the AWS Backint agent binary and for AWS Backint agent
A.
Assign execute permissions at the operating system level for the AWS Backint agent binary and for AWS Backint agent
Answers
B.
Assign an 1AM role to an EC2 instance Attach a policy to the IAM role to grant access to the target S3 bucket
B.
Assign an 1AM role to an EC2 instance Attach a policy to the IAM role to grant access to the target S3 bucket
Answers
C.
Assign the correct Region ID for the S3BucketAwsRegion parameter in AWS Backint agent for the SAP HANA configuration file
C.
Assign the correct Region ID for the S3BucketAwsRegion parameter in AWS Backint agent for the SAP HANA configuration file
Answers
D.
Assign the value for the Enable Tagging parameter in AWS Backint agent for the SAP HANA configuration file
D.
Assign the value for the Enable Tagging parameter in AWS Backint agent for the SAP HANA configuration file
Answers
Suggested answer: B

Explanation:


A company is using SAP NetWeaver with Java on AWS The company has updated its generation of Amazon EC2 instances to the most recent generation of EC2 instances When the company tries to start SAP the startup fails The tog indicates that the SAP license expired Of is not valid.

What is the reason for this issue?

A.
The instance ID changed as part of the EC2 generation change
A.
The instance ID changed as part of the EC2 generation change
Answers
B.
The instance's hypervisor changed from Xen to Nitro
B.
The instance's hypervisor changed from Xen to Nitro
Answers
C.
The SAP Java Virtual Machine (SAP JVM) is not compatible with the new instance type
C.
The SAP Java Virtual Machine (SAP JVM) is not compatible with the new instance type
Answers
D.
An EC2 generation change is not supported for SAP Java-based systems
D.
An EC2 generation change is not supported for SAP Java-based systems
Answers
Suggested answer: B

Explanation:

The change in hypervisor from Xen to Nitro may be the cause of the hardware ID change.https://docs.aws.amazon.com/sap/latest/general/overview-sap-on- aws.html#:~:text=SAP%20Note%202113263,AWS%20Hardware%20ID


A company's basis administrator is planning to deploy SAP on AWS m Linux. The basis administrator must set up the proper storage to store SAP HANAdata and log volumes. Which storage options should the basis administrator choose to meet these requirements? (Select TWO.)

A.
Amazon Elastic Block Store (Amazon EBS) Throughput Optimized HDD (st1)
A.
Amazon Elastic Block Store (Amazon EBS) Throughput Optimized HDD (st1)
Answers
B.
Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS SSD (io1, k>2)
B.
Amazon Elastic Block Store (Amazon EBS) Provisioned IOPS SSD (io1, k>2)
Answers
C.
Amazon S3
C.
Amazon S3
Answers
D.
Amazon Elastic File System (Amazon EFS>
D.
Amazon Elastic File System (Amazon EFS>
Answers
E.
Amazon Elastic Block Store (Amazon EBS) General Purpose SSD (gp2 gp3)
E.
Amazon Elastic Block Store (Amazon EBS) General Purpose SSD (gp2 gp3)
Answers
Suggested answer: B, E

Explanation:


A company has deployed a highly available SAP NetWeaver system on SAP HANA into a VPC The system is distributed across multiple Availability Zones within a single AWS Region SAP NetWeaver is running on SUSE Linux Enterprise Server for SAP SUSE Linux Enterprise High Availability Extension is configured to protect SAP ASCS and ERS instances and uses the overlay IP address concept The SAP shared dies sapmnt and . usrsap. trans are hosted on an Amazon Elastic File System (Amazon EFS) tile system The company needs a solution that uses already-existing private connectivity to the VPC. The SAP NetWeaver system must be accessible through the SAP GUI client tool. Which solutions will meet these requirements? (Select TWO)

A.
Deploy an Application Load Balancer Configure the overlay IP address as a target
A.
Deploy an Application Load Balancer Configure the overlay IP address as a target
Answers
B.
Deploy a Network Load Balancer Configure the overlay IP address as a target
B.
Deploy a Network Load Balancer Configure the overlay IP address as a target
Answers
C.
Use an Amazon Route 53 private zone Create an A record that has the overlay IP address as a target
C.
Use an Amazon Route 53 private zone Create an A record that has the overlay IP address as a target
Answers
D.
Use AWS Transit Gateway Configure the overlay IP address as a static route in the transit gateway route table Specify the VPC as a target
D.
Use AWS Transit Gateway Configure the overlay IP address as a static route in the transit gateway route table Specify the VPC as a target
Answers
E.
Use a NAT gateway Configure the overlay IP address as a target
E.
Use a NAT gateway Configure the overlay IP address as a target
Answers
Suggested answer: B, C

Explanation:

Option B is correct because it uses a Network Load Balancer to enable network access to the overlay IP address for the SAP NetWeaver system. A Network Load Balancer supports TCP protocol and can route traffic to targets using IP addresses. It also provides high availability and scalability for the network connection.Option C is correct because it uses Amazon Route 53 private zone to create an A record that has the overlay IP address as a target. This allows the SAP GUI client tool to resolve the overlay IP address to the SAP NetWeaver system. It also uses the existing private connectivity to the VPC without requiring any additional components or configuration.Option A is incorrect because it uses an Application Load Balancer, which does not support TCP protocol for the SAP NetWeaver system. It also uses an overlay IP address as a target, which is not necessary for the network access to the SAP NetWeaver system.Option D is incorrect because it uses AWS Transit Gateway, which is not a network configuration for data transfer. It also uses an overlay IP address as a static route in the transit gateway route table, which may cause routing conflicts or errors with the existing private connectivity to the VPC.Option E is incorrect because it uses a NAT gateway, which is not a network configuration for data transfer. It also uses an overlay IP address as a target, which may cause routing conflicts or errors with the existing private connectivity to the VPC.Reference: https://docs.aws.amazon.com/sap/latest/sap-hana/sap-ha-overlay-ip.html https://docs.aws.amazon.com/sap/latest/sap-netweaver/cluster-configuration-prereqs-sap- netweaver-ha.html https://docs.aws.amazon.com/sap/latest/sap-hana/sap-oip-overlay-ip-routing-using-aws-transit- gateway.html


A company is planning to move all its SAP applications to Amazon EC2 instances in a VPC Recently the company signed a multiyear contract with a payroll software-as-a-service (SaaS) provider integration with the payroll SaaS solution is available only through public web APIs.

Corporate security guidelines state that all outbound traffic must be validated against an allow list. The payroll SaaS provider provides only fully qualified domain name (FQDN) addresses and no IP addresses or IP address ranges Currently, an on-premises firewall appliance filters FQDNs. The company needs to connect an SAP Process Orchestration (SAP PO) system to the payroll SaaS provider.

What must the company do on AWS to meet these requirements?

A.
Add an outbound rule to the security group of the SAP PO system to allow the FODN of the payroll SaaS provider and deny all other outbound traffic
A.
Add an outbound rule to the security group of the SAP PO system to allow the FODN of the payroll SaaS provider and deny all other outbound traffic
Answers
B.
Add an outbound rule to the network ACL of the subnet that contains the SAP PO system to allow the FQDN of the payroll SaaS provider and deny all other outbound traffic
B.
Add an outbound rule to the network ACL of the subnet that contains the SAP PO system to allow the FQDN of the payroll SaaS provider and deny all other outbound traffic
Answers
C.
Add an AWS WAF web ACL to the VPC Add an outbound rule to allow the SAP PO system to connect to the FQDN of the payroll SaaS provider
C.
Add an AWS WAF web ACL to the VPC Add an outbound rule to allow the SAP PO system to connect to the FQDN of the payroll SaaS provider
Answers
D.
Add an AWS Network Firewall firewall to the VPC Add an outbound rule to allow the SAP PO system to connect to the FQDN of the payroll SaaS provider
D.
Add an AWS Network Firewall firewall to the VPC Add an outbound rule to allow the SAP PO system to connect to the FQDN of the payroll SaaS provider
Answers
Suggested answer: D

Explanation:


A company is planning to migrate its on-premises SAP application to AWS. The application runs on VMware vSphere The SAP ERP Central Component (SAP ECC) server runs on an IBM Db2 database that is 2 TB m size The company wants to migrate the database to SAP HANA Which migration strategy will meet these requirements'?

A.
Use AWS Application Migration Service (CloudEndure Migration)
A.
Use AWS Application Migration Service (CloudEndure Migration)
Answers
B.
Use SAP Software Update Manager (SUM) Database Migration Option (DMO) with System Move
B.
Use SAP Software Update Manager (SUM) Database Migration Option (DMO) with System Move
Answers
C.
Use AWS Server Migration Service (AWS SMS)
C.
Use AWS Server Migration Service (AWS SMS)
Answers
D.
Use AWS Database Migration Service (AWS DMS)
D.
Use AWS Database Migration Service (AWS DMS)
Answers
Suggested answer: B

Explanation:


A company hosts multiple SAP applications on Amazon EC2 instances in a VPC While monitoring the environment the company notices that multiple port scans are attempting to connect to SAP portals inside the VPC. These port scans are originating from the same IP address block. The company must deny access to the VPC from all the offending IP addresses for the next 24 hours. Which solution win meet this requirement?

A.
Modify network ACLs that are associated with all public subnets in the VPC to deny access from the IP address block
A.
Modify network ACLs that are associated with all public subnets in the VPC to deny access from the IP address block
Answers
B.
Add a rule in the security group of the EC2 instances to deny access from the IP address block
B.
Add a rule in the security group of the EC2 instances to deny access from the IP address block
Answers
C.
Create a policy in AWS identity and Access Management (1AM) to deny access from the IP address block
C.
Create a policy in AWS identity and Access Management (1AM) to deny access from the IP address block
Answers
D.
Configure the firewall m the operating system of the EC2 instances to deny access from the IP address block
D.
Configure the firewall m the operating system of the EC2 instances to deny access from the IP address block
Answers
Suggested answer: A

Explanation:


A company has deployed SAP workloads on AWS The AWS Data Provider for SAP is installed on the Amazon EC2 instance where the SAP application is running An SAP solutions architect has attached an IAM role to the EC2 instance with the following policy.

The AWS Data Provider for SAP is not returning any metrics to the SAP application. Which change should the SAP solutions architect make to the 1AM permissions to resolve this issued.

A.
Add the cloudwatch ListMetrics action to the policy statement with Sid AWSDataProvider1.
A.
Add the cloudwatch ListMetrics action to the policy statement with Sid AWSDataProvider1.
Answers
B.
Add the cloudwatch GetMetricStatrstics action to the policy statement with Sid AWSDataProvider1
B.
Add the cloudwatch GetMetricStatrstics action to the policy statement with Sid AWSDataProvider1
Answers
C.
Add the cloudwatch GetMetricStream action (o the policy statement with Sid AWSDataProvider
C.
Add the cloudwatch GetMetricStream action (o the policy statement with Sid AWSDataProvider
Answers
D.
Add the cloudwatch DescribeAlarmsForMetric action to the policy statement with Sid AWSDataProvider
D.
Add the cloudwatch DescribeAlarmsForMetric action to the policy statement with Sid AWSDataProvider
Answers
Suggested answer: B

Explanation:

The AWS Data Provider for SAP requires the ability to access metrics data in order to return metrics to the SAP application. The IAM policy statement with Sid "AWSDataProvider1" currently does not have the necessary permissions to access metrics data. The SAP solutions architect should add the cloudwatch:GetMetricStatistics action to the policy statement with Sid "AWSDataProvider1" to grant the necessary permissions for the Data Provider to access metrics data.The other actions such as "EC2:DescribeInstances" and "EC2:DescribeVolumes" are not related to CloudWatch metrics and only provide the ability to describe EC2 instances and volumes. Actions such as "s3:GetObject" are not related to CloudWatch metrics, it's used to get an object from an S3 bucket. Actions such as "cloudwatch:ListMetrics" and "cloudwatch:DescribeAlarmsForMetric" would not be necessary for the AWS Data Provider for SAP to return metrics to the SAP application and it's not related to the problem described.https://docs.aws.amazon.com/sap/latest/general/data-provider-troubleshooting.html


A company wants to deploy an SAP HANA database on AWS by using AWS Launch Wizard for SAP An SAP solutions architect needs to run a custom post-deployment script on the Amazon EC2 instance that Launch Wizard provisions. Which actions can the SAP solutions architect take to provide the post-deployment script m the Launch Wizard console? (Select TWO.)

A.
Provide the FTP URL of the script
A.
Provide the FTP URL of the script
Answers
B.
Provide the HTTPS URL of the script on a web server
B.
Provide the HTTPS URL of the script on a web server
Answers
C.
Provide the Amazon S3 URL of the script
C.
Provide the Amazon S3 URL of the script
Answers
D.
Write the script inline
D.
Write the script inline
Answers
E.
Upload the script
E.
Upload the script
Answers
Suggested answer: C, E

Explanation:

https://catalog.us-east-1.prod.workshops.aws/workshops/754ba343-2704-404a-8abe- be7b21c4d9d5/en-US/800-other/802-prepostscript


A company has an SAP environment that runs on AWS. The company wants to enhance security by restricting Amazon EC2 Instance Metadata Service (IMDS) to IMDSv2 only. The company's current configuration option supports both iMDSvi and iM0Sv2. The security enhancement must not create an SAP outage.

What should the company do before it applies the security enhancement on EC2 instances that are running the SAP environment?

A.
Ensure that the SAP kernel versions are 7 45 or later
A.
Ensure that the SAP kernel versions are 7 45 or later
Answers
B.
Ensure that the EC2 instances are Nitro based
B.
Ensure that the EC2 instances are Nitro based
Answers
C.
Ensure that the AWS Data Provider for SAP is installed on each EC2 instance
C.
Ensure that the AWS Data Provider for SAP is installed on each EC2 instance
Answers
D.
Stop the EC2 instances
D.
Stop the EC2 instances
Answers
Suggested answer: A

Explanation:


Total 65 questions
Go to page: of 7