ExamGecko
Home Home / Amazon / SAP-C01

Amazon SAP-C01 Practice Test - Questions Answers, Page 69

Question list
Search
Search

List of questions

Search

Related questions











Your company policies require encryption of sensitive data at rest. You are considering the possible options for protecting data while storing it at rest on an EBS data volume, attached to an EC2 instance. Which of these options would allow you to encrypt your data at rest? (Choose three.)

A.
Implement third party volume encryption tools
A.
Implement third party volume encryption tools
Answers
B.
Implement SSL/TLS for all services running on the server
B.
Implement SSL/TLS for all services running on the server
Answers
C.
Encrypt data inside your applications before storing it on EBS
C.
Encrypt data inside your applications before storing it on EBS
Answers
D.
Encrypt data using native data encryption drivers at the file system level
D.
Encrypt data using native data encryption drivers at the file system level
Answers
E.
Do nothing as EBS volumes are encrypted by default
E.
Do nothing as EBS volumes are encrypted by default
Answers
Suggested answer: A, C, D

What does elasticity mean to AWS?

A.
The ability to scale computing resources up easily, with minimal friction and down with latency.
A.
The ability to scale computing resources up easily, with minimal friction and down with latency.
Answers
B.
The ability to scale computing resources up and down easily, with minimal friction.
B.
The ability to scale computing resources up and down easily, with minimal friction.
Answers
C.
The ability to provision cloud computing resources in expectation of future demand.
C.
The ability to provision cloud computing resources in expectation of future demand.
Answers
D.
The ability to recover from business continuity events with minimal friction.
D.
The ability to recover from business continuity events with minimal friction.
Answers
Suggested answer: B

A company has used infrastructure as code (IaC) to provision a set of two Amazon EC2 instances. The instances have remained the same for several years. The company’s business has grown rapidly in the past few months. In response the company’s operations team has implemented an Auto Scaling group to manage the sudden increases in traffic. Company policy requires a monthly installation of security updates on all operating systems that are running.

The most recent security update required a reboot. As a result, the Auto Scaling group terminated the instances and replaced them with new, unpatched instances. Which combination of steps should a solutions architect recommend to avoid a recurrence of this issue? (Choose two.)

A.
Modify the Auto Scaling group by setting the Update policy to target the oldest launch configuration for replacement.
A.
Modify the Auto Scaling group by setting the Update policy to target the oldest launch configuration for replacement.
Answers
B.
Create a new Auto Scaling group before the next patch maintenance. During the maintenance window, patch both groups and reboot the instances.
B.
Create a new Auto Scaling group before the next patch maintenance. During the maintenance window, patch both groups and reboot the instances.
Answers
C.
Create an Elastic Load Balancer in front of the Auto Scaling group. Configure monitoring to ensure that target group health checks return healthy after the Auto Scaling group replaces the terminated instances.
C.
Create an Elastic Load Balancer in front of the Auto Scaling group. Configure monitoring to ensure that target group health checks return healthy after the Auto Scaling group replaces the terminated instances.
Answers
D.
Create automation scripts to patch an AMI, update the launch configuration, and invoke an Auto Scaling instance refresh.
D.
Create automation scripts to patch an AMI, update the launch configuration, and invoke an Auto Scaling instance refresh.
Answers
E.
Create an Elastic Load Balancer in front of the Auto Scaling group. Configure termination protection on the instances.
E.
Create an Elastic Load Balancer in front of the Auto Scaling group. Configure termination protection on the instances.
Answers
Suggested answer: A, C

Explanation:

Reference: https://medium.com/@endofcake/using-terraform-for-zero-downtime-updates-of-an-auto-scaling-group-in-aws-60faca582664 https://docs.aws.amazon.com/autoscaling/ec2/userguide/as-add-elb-healthcheck.html

A solutions architect must analyze a company’s Amazon EC2 instances and Amazon Elastic Block Store (Amazon EBS) volumes to determine whether the company is using resources efficiently. The company is running several large, highmemory EC2 instances to host database clusters that are deployed in active/passive configurations. The utilization of these EC2 instances varies by the applications that use the databases, and the company has not identified a pattern. The solutions architect must analyze the environment and take action based on the findings.

Which solution meets these requirements MOST cost-effectively?

A.
Create a dashboard by using AWS Systems Manager OpsCenter. Configure visualizations for Amazon CloudWatch metrics that are associated with the EC2 instances and their EBS volumes. Review the dashboard periodically, and identify usage patterns. Rightsize the EC2 instances based on the peaks in the metrics.
A.
Create a dashboard by using AWS Systems Manager OpsCenter. Configure visualizations for Amazon CloudWatch metrics that are associated with the EC2 instances and their EBS volumes. Review the dashboard periodically, and identify usage patterns. Rightsize the EC2 instances based on the peaks in the metrics.
Answers
B.
Turn on Amazon CloudWatch detailed monitoring for the EC2 instances and their EBS volumes. Create and review a dashboard that is based on the metrics. Identify usage patterns. Rightsize the EC2 instances based on the peaks in the metrics.
B.
Turn on Amazon CloudWatch detailed monitoring for the EC2 instances and their EBS volumes. Create and review a dashboard that is based on the metrics. Identify usage patterns. Rightsize the EC2 instances based on the peaks in the metrics.
Answers
C.
Install the Amazon CloudWatch agent on each of the EC2 instances. Turn on AWS Compute Optimizer, and let it run for at least 12 hours. Review the recommendations from Compute Optimizer, and rightsize the EC2 instances as directed.
C.
Install the Amazon CloudWatch agent on each of the EC2 instances. Turn on AWS Compute Optimizer, and let it run for at least 12 hours. Review the recommendations from Compute Optimizer, and rightsize the EC2 instances as directed.
Answers
D.
Sign up for the AWS Enterprise Support plan. Turn on AWS Trusted Advisor. Wait 12 hours. Review the recommendations from Trusted Advisor, and rightsize the EC2 instances as directed.
D.
Sign up for the AWS Enterprise Support plan. Turn on AWS Trusted Advisor. Wait 12 hours. Review the recommendations from Trusted Advisor, and rightsize the EC2 instances as directed.
Answers
Suggested answer: A

A company is using an on-premises Active Directory service for user authentication. The company wants to use the same authentication service to sign in to the company’s AWS accounts, which are using AWS Organizations. AWS Site-to- Site VPN connectivity already exists between the on-premises environment and all the company’s AWS accounts. The company’s security policy requires conditional access to the accounts based on user groups and roles. User identities must be managed in a single location. Which solution will meet these requirements?

A.
Configure AWS Single Sign-On (AWS SSO) to connect to Active Directory by using SAML 2.0. Enable automatic provisioning by using the System for Cross-domain Identity Management (SCIM) v2.0 protocol. Grant access to the AWS accounts by using attribute-based access controls (ABACs).
A.
Configure AWS Single Sign-On (AWS SSO) to connect to Active Directory by using SAML 2.0. Enable automatic provisioning by using the System for Cross-domain Identity Management (SCIM) v2.0 protocol. Grant access to the AWS accounts by using attribute-based access controls (ABACs).
Answers
B.
Configure AWS Single Sign-On (AWS SSO) by using AWS SSO as an identity source. Enable automatic provisioning by using the System for Cross-domain Identity Management (SCIM) v2.0 protocol. Grant access to the AWS accounts by using AWS SSO permission sets.
B.
Configure AWS Single Sign-On (AWS SSO) by using AWS SSO as an identity source. Enable automatic provisioning by using the System for Cross-domain Identity Management (SCIM) v2.0 protocol. Grant access to the AWS accounts by using AWS SSO permission sets.
Answers
C.
In one of the company’s AWS accounts, configure AWS Identity and Access Management (IAM) to use a SAML 2.0 identity provider. Provision IAM users that are mapped to the federated users. Grant access that corresponds to appropriate groups in Active Directory. Grant access to the required AWS accounts by using cross-account IAM users.
C.
In one of the company’s AWS accounts, configure AWS Identity and Access Management (IAM) to use a SAML 2.0 identity provider. Provision IAM users that are mapped to the federated users. Grant access that corresponds to appropriate groups in Active Directory. Grant access to the required AWS accounts by using cross-account IAM users.
Answers
D.
In one of the company’s AWS accounts, configure AWS Identity and Access Management (IAM) to use an OpenID Connect (OIDC) identity provider. Provision IAM roles that grant access to the AWS account for the federated users that correspond to appropriate groups in Active Directory. Grant access to the required AWS accounts by using cross-account IAM roles.
D.
In one of the company’s AWS accounts, configure AWS Identity and Access Management (IAM) to use an OpenID Connect (OIDC) identity provider. Provision IAM roles that grant access to the AWS account for the federated users that correspond to appropriate groups in Active Directory. Grant access to the required AWS accounts by using cross-account IAM roles.
Answers
Suggested answer: B

Explanation:

Reference: https://docs.aws.amazon.com/singlesignon/latest/userguide/onelogin-idp.html

After your Lambda function has been running for some time, you need to look at some metrics to ascertain how your function is performing and decide to use the AWS CLI to do this. Which of the following commands must be used to access these metrics using the AWS CLI?

A.
mon-list-metrics and mon-get-stats
A.
mon-list-metrics and mon-get-stats
Answers
B.
list-metrics and get-metric-statistics
B.
list-metrics and get-metric-statistics
Answers
C.
ListMetrics and GetMetricStatistics
C.
ListMetrics and GetMetricStatistics
Answers
D.
list-metrics and mon-get-stats
D.
list-metrics and mon-get-stats
Answers
Suggested answer: B

Explanation:

AWS Lambda automatically monitors functions on your behalf, reporting metrics through Amazon CloudWatch. To access metrics using the AWS CLI

Use the list-metrics and get-metric-statistics commands.

Reference: http://docs.aws.amazon.com/lambda/latest/dg/monitoring-functions-access-metrics.html

A company built an ecommerce website on AWS using a three-tier web architecture. The application is Java-based and composed of an Amazon CloudFront distribution, an Apache web server layer of Amazon EC2 instances in an Auto Scaling group, and a backend Amazon Aurora MySQL database.

Last month, during a promotional sales event, users reported errors and timeouts while adding items to their shopping carts.

The operations team recovered the logs created by the web servers and reviewed Aurora DB cluster performance metrics.

Some of the web servers were terminated before logs could be collected and the Aurora metrics were not sufficient for query performance analysis. Which combination of steps must the solutions architect take to improve application performance visibility during peak traffic events? (Choose three.)

A.
Configure the Aurora MySQL DB cluster to publish slow query and error logs to Amazon CloudWatch Logs.
A.
Configure the Aurora MySQL DB cluster to publish slow query and error logs to Amazon CloudWatch Logs.
Answers
B.
Implement the AWS X-Ray SDK to trace incoming HTTP requests on the EC2 instances and implement tracing of SQLqueries with the X-Ray SDK for Java.
B.
Implement the AWS X-Ray SDK to trace incoming HTTP requests on the EC2 instances and implement tracing of SQLqueries with the X-Ray SDK for Java.
Answers
C.
Configure the Aurora MySQL DB cluster to stream slow query and error logs to Amazon Kinesis
C.
Configure the Aurora MySQL DB cluster to stream slow query and error logs to Amazon Kinesis
Answers
D.
Install and configure an Amazon CloudWatch Logs agent on the EC2 instances to send the Apache logs to CloudWatch Logs.
D.
Install and configure an Amazon CloudWatch Logs agent on the EC2 instances to send the Apache logs to CloudWatch Logs.
Answers
E.
Enable and configure AWS CloudTrail to collect and analyze application activity from Amazon EC2 and Aurora.
E.
Enable and configure AWS CloudTrail to collect and analyze application activity from Amazon EC2 and Aurora.
Answers
F.
Enable Aurora MySQL DB cluster performance benchmarking and publish the stream to AWS X-Ray.
F.
Enable Aurora MySQL DB cluster performance benchmarking and publish the stream to AWS X-Ray.
Answers
Suggested answer: B, C, E

When using Numeric Conditions within IAM, short versions of the available comparators can be used instead of the more verbose versions. Which of the following is the short version of the Numeric Condition "NumericLessThanEquals"?

A.
numlteq
A.
numlteq
Answers
B.
numlteql
B.
numlteql
Answers
C.
numltequals
C.
numltequals
Answers
D.
numeql
D.
numeql
Answers
Suggested answer: A

Explanation:

When using Numeric Conditions within IAM, short versions of the available comparators can be used instead of the more verbose versions. For instance, numIteq is the short version of NumericLessThanEquals.

Reference: http://awsdocs.s3.amazonaws.com/SQS/2011-10-01/sqs-dg-2011-10-01.pdf

A company wants to move a web application to AWS. The application stores session information locally on each web server, which will make auto scaling difficult. As part of the migration, the application will be rewritten to decouple the session data from the web servers. The company requires low latency, scalability, and availability.

Which service will meet the requirements for storing the session information in the MOST cost-effective way?

A.
Amazon ElastiCache with the Memcached engine
A.
Amazon ElastiCache with the Memcached engine
Answers
B.
Amazon S3
B.
Amazon S3
Answers
C.
Amazon RDS MySQL
C.
Amazon RDS MySQL
Answers
D.
Amazon ElastiCache with the Redis engine
D.
Amazon ElastiCache with the Redis engine
Answers
Suggested answer: D

Explanation:

Reference: https://aws.amazon.com/caching/session-management/ https://aws.amazon.com/elasticache/redis-vsmemcached/


A Solutions Architect must migrate an existing on-premises web application with 70 TB of static files supporting a public open-data initiative. The Architect wants to upgrade to the latest version of the host operating system as part of the migration effort.

Which is the FASTEST and MOST cost-effective way to perform the migration?

A.
Run a physical-to-virtual conversion on the application server. Transfer the server image over the internet, and transfer the static data to Amazon S3.
A.
Run a physical-to-virtual conversion on the application server. Transfer the server image over the internet, and transfer the static data to Amazon S3.
Answers
B.
Run a physical-to-virtual conversion on the application server. Transfer the server image over AWS Direct Connect, and transfer the static data to Amazon S3.
B.
Run a physical-to-virtual conversion on the application server. Transfer the server image over AWS Direct Connect, and transfer the static data to Amazon S3.
Answers
C.
Re-platform the server to Amazon EC2, and use AWS Snowball to transfer the static data to Amazon S3.
C.
Re-platform the server to Amazon EC2, and use AWS Snowball to transfer the static data to Amazon S3.
Answers
D.
Re-platform the server by using the AWS Server Migration Service to move the code and data to a new Amazon EC2 instance.
D.
Re-platform the server by using the AWS Server Migration Service to move the code and data to a new Amazon EC2 instance.
Answers
Suggested answer: C
Total 906 questions
Go to page: of 91