ExamGecko
Home Home / Amazon / SOA-C02

Amazon SOA-C02 Practice Test - Questions Answers, Page 22

Question list
Search
Search

List of questions

Search

Related questions











A company applies user-defined tags to resources that are associated with me company's AWS workloads Twenty days after applying the tags, the company notices that it cannot use re tags to filter views in the AWS Cost Explorer console. What is the reason for this issue?

A.
It lakes at least 30 days to be able to use tags to filter views in Cost Explorer.
A.
It lakes at least 30 days to be able to use tags to filter views in Cost Explorer.
Answers
B.
The company has not activated the user-defined tags for cost allocation.
B.
The company has not activated the user-defined tags for cost allocation.
Answers
C.
The company has not created an AWS Cost and Usage Report
C.
The company has not created an AWS Cost and Usage Report
Answers
D.
The company has not created a usage budget in AWS Budgets
D.
The company has not created a usage budget in AWS Budgets
Answers
Suggested answer: B

A company's SysOps administrator must ensure that all Amazon EC2 Windows instances that are launched in an AWS account have a third-party agent installed. The third-party agent has an msi package. The company uses AWS Systems Manager for patching, and the Windows instances are tagged appropriately. The third-party agent required periodic updates as new versions are released. The SysOps administrator must deploy these updates automatically

Which combination of steps will meet these requirements with the LEAST operational effort? (Seed TWO.) Create a Systems Manager Distributor package for the third-party agent.

A.
Make sure that Systems Manager Inventory Is configured. If Systems Manager Inventory is not configured, set up a new inventory tor instances that is based on the appropriate tag value for Windows.
A.
Make sure that Systems Manager Inventory Is configured. If Systems Manager Inventory is not configured, set up a new inventory tor instances that is based on the appropriate tag value for Windows.
Answers
B.
Create a Systems Manager State Manager association to run the AWS-RunRemoteScript document. Populate the details of the third-party agent package. Specify instance tags based on the appropriate tag value for Windows with a schedule of 1 day
B.
Create a Systems Manager State Manager association to run the AWS-RunRemoteScript document. Populate the details of the third-party agent package. Specify instance tags based on the appropriate tag value for Windows with a schedule of 1 day
Answers
C.
Create a Systems Manager State Manager- association to run the AWS-ConfigureAWSPackage document. Populate the details of the third-party agent package. Specify instance tags based on the appropriate tag value for Windows with a schedule of 1 day
C.
Create a Systems Manager State Manager- association to run the AWS-ConfigureAWSPackage document. Populate the details of the third-party agent package. Specify instance tags based on the appropriate tag value for Windows with a schedule of 1 day
Answers
D.
Create a Systems Manager Opsitem with the tag value for Windows Attach the Systems Manager Distributor package to the Opsitem. Create a maintenance window that is specific to the package deployment Configure the maintenance window to cover 24 hours a day.
D.
Create a Systems Manager Opsitem with the tag value for Windows Attach the Systems Manager Distributor package to the Opsitem. Create a maintenance window that is specific to the package deployment Configure the maintenance window to cover 24 hours a day.
Answers
Suggested answer: A, D

Explanation:

https://docs.aws.amazon.com/systems-manager/latest/userguide/distributor-working-with- packages-deploy.html

A global gaming company is preparing to launch a new game on AWS. The game runs in multiple AWS Regions on a fleet of Amazon EC2 instances. The instances are in an Auto Scaling group behind an Application Load Balancer (ALB) in each Region. The company plans to use Amazon Route 53 tor DNS services. The DNS configuration must direct users to the Region that is closest to mem and must provide automated failover. Which combination of steps should a SysOps administrator take to configure Route 53 to meet these requirements?{Select TWO.)

A.
Create Amazon CloudWatch alarms that monitor the health of the ALB in each Region. Configure Route 53 DNS failover by using a health check that monitors the alarms.
A.
Create Amazon CloudWatch alarms that monitor the health of the ALB in each Region. Configure Route 53 DNS failover by using a health check that monitors the alarms.
Answers
B.
Create Amazon CloudWatch alarms that monitor the hearth of the EC2 instances in each Region.Configure Route 53 DNS failover by using a health check that monitors the alarms.
B.
Create Amazon CloudWatch alarms that monitor the hearth of the EC2 instances in each Region.Configure Route 53 DNS failover by using a health check that monitors the alarms.
Answers
C.
Configure Route 53 DNS failover by using a health check that monitors the private address of an EC2 instance in each Region.
C.
Configure Route 53 DNS failover by using a health check that monitors the private address of an EC2 instance in each Region.
Answers
D.
Configure Route 53 geoproximity routing Specify the Regions that are used for the infrastructure
D.
Configure Route 53 geoproximity routing Specify the Regions that are used for the infrastructure
Answers
E.
Configure Route 53 simple routing Specify the continent, country, and state or province that are used for the infrastructure.
E.
Configure Route 53 simple routing Specify the continent, country, and state or province that are used for the infrastructure.
Answers
Suggested answer: A, D

A SysOps administrator is configuring an application on Amazon EC2 instances for a company Teams in other countries will use the application over the internet. The company requires the application endpoint to have a static pubic IP address.

How should the SysOps administrator deploy the application to meet this requirement?

A.
Behind an Amazon API Gateway API
A.
Behind an Amazon API Gateway API
Answers
B.
Behind an Application Load Balancer
B.
Behind an Application Load Balancer
Answers
C.
Behind an internet-facing Network Load Balancer
C.
Behind an internet-facing Network Load Balancer
Answers
D.
In an Amazon CloudFront distribution
D.
In an Amazon CloudFront distribution
Answers
Suggested answer: C

A SysOps administrator trust manage the security of An AWS account Recently an IAM users access key was mistakenly uploaded to a public code repository. The SysOps administrator must identity anything that was changed by using this access key.

A.
Create an Amazon EventBridge (Amazon CloudWatch Events) rule to send all IAM events lo an AWS Lambda function for analysis
A.
Create an Amazon EventBridge (Amazon CloudWatch Events) rule to send all IAM events lo an AWS Lambda function for analysis
Answers
B.
Query Amazon EC2 togs by using Amazon CloudWatch Logs Insights for all events Heated with the compromised access key within the suspected timeframe
B.
Query Amazon EC2 togs by using Amazon CloudWatch Logs Insights for all events Heated with the compromised access key within the suspected timeframe
Answers
C.
Search AWS CloudTrail event history tor all events initiated with the compromised access key within the suspected timeframe
C.
Search AWS CloudTrail event history tor all events initiated with the compromised access key within the suspected timeframe
Answers
D.
Search VPC Flow Logs foe all events initiated with the compromised access key within the suspected Timeframe.
D.
Search VPC Flow Logs foe all events initiated with the compromised access key within the suspected Timeframe.
Answers
Suggested answer: C

A company maintains a large set of sensitive data in an Amazon S3 bucket. The company's security team asks a SyeOps administrator to help verify that all current objects in the S3 bucket are encrypted. What is the MOST operationally efficient solution that meets these requirements?

A.
Create a script that runs against the S3 bucket and outputs the status of each object.
A.
Create a script that runs against the S3 bucket and outputs the status of each object.
Answers
B.
Create an S3 Inventory configuration on the S3 bucket Induce the appropriate status fields.
B.
Create an S3 Inventory configuration on the S3 bucket Induce the appropriate status fields.
Answers
C.
Provide the security team with an IAM user that has read access to the S3 bucket.
C.
Provide the security team with an IAM user that has read access to the S3 bucket.
Answers
D.
Use the AWS CLI to output a list of all objects in the S3 bucket.
D.
Use the AWS CLI to output a list of all objects in the S3 bucket.
Answers
Suggested answer: B

A company has a high-performance Windows workload. The workload requires a storage volume mat provides consistent performance of 10.000 KDPS. The company does not want to pay for additional unneeded capacity to achieve this performance.

Which solution will meet these requirements with the LEAST cost?

A.
Use a Provisioned IOPS SSD (lol) Amazon Elastic Block Store (Amazon EBS) volume that is configured with 10.000 provisioned IOPS
A.
Use a Provisioned IOPS SSD (lol) Amazon Elastic Block Store (Amazon EBS) volume that is configured with 10.000 provisioned IOPS
Answers
B.
Use a General Purpose SSD (gp3) Amazon Elastic Block Store (Amazon EBS) volume that is configured with 10.000 provisioned IOPS.
B.
Use a General Purpose SSD (gp3) Amazon Elastic Block Store (Amazon EBS) volume that is configured with 10.000 provisioned IOPS.
Answers
C.
Use an Amazon Elastic File System (Amazon EFS) file system w\ Max I/O mode.
C.
Use an Amazon Elastic File System (Amazon EFS) file system w\ Max I/O mode.
Answers
D.
Use an Amazon FSx for Windows Fife Server foe system that is configured with 10.000 IOPS
D.
Use an Amazon FSx for Windows Fife Server foe system that is configured with 10.000 IOPS
Answers
Suggested answer: A

A company has an application that is running on Amazon EC2 instances in a VPC. The application needs access to download software updates from the internet. The VPC has public subnets and private signets. The company's security policy requires all ECS instances to be deployed in private subnets What should a SysOps administrator do to meet those requirements?

A.
Add an internet gateway to the VPC In the route table for the private subnets, odd a route to the interne; gateway.
A.
Add an internet gateway to the VPC In the route table for the private subnets, odd a route to the interne; gateway.
Answers
B.
Add a NAT gateway to a private subnet. In the route table for the private subnets, add a route to the NAT gateway.
B.
Add a NAT gateway to a private subnet. In the route table for the private subnets, add a route to the NAT gateway.
Answers
C.
Add a NAT gateway to a public subnet in the route table for the private subnets, add a route to the NAT gateway.
C.
Add a NAT gateway to a public subnet in the route table for the private subnets, add a route to the NAT gateway.
Answers
D.
Add two internet gateways to the VPC. In The route tablet for the private subnets and public subnets, add a route to each internet gateway.
D.
Add two internet gateways to the VPC. In The route tablet for the private subnets and public subnets, add a route to each internet gateway.
Answers
Suggested answer: C

A SysOps administrator has successfully deployed a VPC with an AWS Cloud Formation template The SysOps administrator wants to deploy me same template across multiple accounts that are managed through AWS Organizations. Which solution will meet this requirement with the LEAST operational overhead?

A.
Assume the OrganizationAccountAcccssKolc IAM role from the management account. Deploy the template in each of the accounts
A.
Assume the OrganizationAccountAcccssKolc IAM role from the management account. Deploy the template in each of the accounts
Answers
B.
Create an AWS Lambda function to assume a role in each account Deploy the template by using the AWS CloudFormation CreateStack API call
B.
Create an AWS Lambda function to assume a role in each account Deploy the template by using the AWS CloudFormation CreateStack API call
Answers
C.
Create an AWS Lambda function to query fc a list of accounts Deploy the template by using the AWS Cloudformation
C.
Create an AWS Lambda function to query fc a list of accounts Deploy the template by using the AWS Cloudformation
Answers
D.
CreateStack API call. Use AWS CloudFormation StackSets from the management account to deploy the template in each of the accounts
D.
CreateStack API call. Use AWS CloudFormation StackSets from the management account to deploy the template in each of the accounts
Answers
Suggested answer: D

Explanation:

AWS CloudFormation StackSets extends the capability of stacks by enabling you to create, update, or delete stacks across multiple accounts and AWS Regions

A SysOps administrator must ensure that a company's Amazon EC2 instances auto scale as expected The SysOps administrator configures an Amazon EC2 Auto Scaling Lifecycle hook to send an event to Amazon EventBridge (Amazon CloudWatch Events), which then invokes an AWS Lambda function to configure the EC2 distances When the configuration is complete, the Lambda function calls the complete Lifecycle-action event to put the EC2 instances into service. In testing, the SysOps administrator discovers that the Lambda function is not invoked when the EC2 instances auto scale. What should the SysOps administrator do to reserve this issue?

A.
Add a permission to the Lambda function so that it can be invoked by the EventBridge (CloudWatch Events) rule.
A.
Add a permission to the Lambda function so that it can be invoked by the EventBridge (CloudWatch Events) rule.
Answers
B.
Change the lifecycle hook action to CONTINUE if the lifecycle hook experiences a fa* we or timeout.
B.
Change the lifecycle hook action to CONTINUE if the lifecycle hook experiences a fa* we or timeout.
Answers
C.
Configure a retry policy in the EventBridge (CloudWatch Events) rule to retry the Lambda function invocation upon failure.
C.
Configure a retry policy in the EventBridge (CloudWatch Events) rule to retry the Lambda function invocation upon failure.
Answers
D.
Update the Lambda function execution role so that it has permission to call the complete lifecycleaction event
D.
Update the Lambda function execution role so that it has permission to call the complete lifecycleaction event
Answers
Suggested answer: D
Total 425 questions
Go to page: of 43