General Flashcards

(109 cards)

1
Q

What does AWS CloudHSM stand for?

A

AWS managed dedicated hardware security model (HSM) in AWS Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the primary function of AWS CloudHSM?

A

Enables you to securely generate, store, and manage your own cryptographic keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which industry-standard APIs can integrate with AWS CloudHSM?

A
  • PKCS#11
  • Java Cryptography Extensions (JCE)
  • Microsoft CryptoNG (CNG) libraries
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Fill in the blank: AWS CloudHSM allows you to store _______ key material in a custom key store.

A

non-extractable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a use case for AWS CloudHSM?

A

Use KMS to create a CMKs in a custom key store and store non-extractable key material in AWS CloudHSM to get full control on encryption keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In AWS Systems Manager, was does Session Manager replace

A

The need for Bastions to access instances in private subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is AWS Shield?

A

Managed Distributed Denial of Service protection service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What type of attacks does AWS Shield protect against?

A

Layer 3 and 4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the tiers of service for AWS Shield

A
  • Standard - automatic and free for CloudFront and Route 53
  • Advanced - paid, enhanced DDoS protection for EC2, ELB, Cloudfront, and Route 53
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is AWS WAF

A

Web application firewall, protects web applications against common web exploits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What attacks does AWS WAF protect against

A

Layer 7, like SQL injection and Cross-site scripting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Where can you deploy AWS WAF

A
  • CloudFront
  • Application Load Balancer
  • API Gateway
  • AWS AppSync
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does AWS Firewall Manager do?

A

Centralizes configuration and management of AWS WAF rules, AWS Shield Advanced, Network Firewall rules, and Route 53 DNS firewall rules across accounts and resources in AWS Organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a use case for AWS Firewall Manager

A

Meet Gov regulations to deploy AWS WAF rule to block traffic from embargoed countries across acounts and resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is AWS Guard Duty

A
  • Read VPC Flow Logs, DNS Logs, and Cloudtrail Events, apply machine learning algorithms and anomaly detections to discover threats
  • Can protect against Crypto Currency Attacks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How is ECS with Fargate charged

A

On vCPU and memory resources that the container requests. Charged rounded up per the nearest second

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is Babelfish

A

Allows Aurora PostgreSQL to understand T-SQL and SQL Server wire protocol, enabling applications to communicate with Aurora using SQL Server-style queries with minimal code changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Using an autoscaling group, how can you make sure 10 instances are up at a specific time of day/month

A

Setup a scheduled action that kicks off at the designated time and set the desired capacity of the instances to 10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

With Amazon API Gateway and Websocket APIs, which is Stateful and which is stateless

A

Gateway - Stateless
Websocket - Stateful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

By default, FIFO queues (SQS) support how many messages per second

A

300

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

With SQS FIFO, what is the max number of messages you can batch per second

A

10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

How might you restrict traffic by country for an EC2

A

AWS web application firewall with ALB. Geo match Conditions in WAF can restrict traffic based on location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

T/F Cloudfront can have a custom origin pointing to the DNS record of a website on Route 53

A

False, It can have a custom origin pointing to on-premise servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

In S3, when you apply a retention period to an object version, what do you specify

A

Retain Until Date

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
You need to ensure exactly once message processing, what should you use
SQS FIFO
26
What is the min storage duration for an object in S3 before it can be transitioned away from S3 Stanadard
30 days
27
When using S3 Transfer Acceleration, if the upload occurred, but S3TA did not result in an accelerated transfer, what do you pay for in transfer charges
None. There is no transfer charges when data is transferred in from the internet, and you only pay for transfers that are accelerated
28
What is Amazon FSx for Lustre
Allows you work with files on S3 using the Lustre file system. It provides the ability to process 'hot data' in a parallel and distributed fashion as well as store the 'cold data' on Amazon s3
29
What is AWS Glue DataBrew
A way to build data workflows visually without code. It is fully managed by AWS and serverless
30
How is replication setup with a RDS Multi-AZ deployment
Synchronous replication and spans at least two AZs within a single region.
31
How is replication setup with a RDS Read Replica
Asynchronous replication and can be within a AZ, Cross AZ, or Cross-Region
32
What is AWS Outpost
It is an AWS physical rack that can be installed in the company's data center, bringing AWS services on-prem
33
What storage solutions cannot be used as a boot volume on an EC2
Throughput Optimized Hard disk drive (St1) Cold Hard disk drive (sc1)
34
What storage solutions can be used as a boot volume on EC2
Provisioned IOPS Solid State drive (io1,3) Instance Store General Purpose Solid State Drive (gp2,3)
35
What does a RDS Proxy do for Aurora
It helps manage connection pooling and throttling, which are a common cause of timeouts in high-load scenarios. It maintains a pool of database connections and reuses them across clients. This can be paired with a scaling group of EC2s
36
How can a EFS be access by another region
inter-region VPC peering connection
37
What is needed for a High Performance Computing driven application with EC2s
They need to be deployed in a cluster placement group so that the underlying workload can benefit from low network latency and high network throughput.
38
Does Amazon FsX for Luster support Microsoft's Distributed File System
No
39
What happens when a AMI is copied from Region A to Region B?
A snapshot is automatically created because AMIS are based on the underlying snapshot
40
What is the hierachy of S3 storage types
Standard > Standard IA > Intelligent-Tiering > One Zone IA > Glacier Instant Retrieval > Glacier Flexible Retrieval > Deep Archive Lifecycle transitions can only be made to go down, not up
41
If a company wants to continue to use its own custom DNS service, Is Route 53 an option
No
42
What is AWS Global Accelerator
AWS Global Accelerator uses the Amazon's network, improving performance by lowering first-byte latency and jitter, and increasing throughput compared to the public internet.
43
Can you hook up EFS to lambda
Yes by using the EFS mount target and access points
44
Using an autoscaling group, how would you trigger based on cpu utilization of 50%
Target tracking policy with CPU as target metric and target vakue of 50%
45
What is the soft limit of concurrent executions for lambda per AWS Account per region
1000
46
What is the order of operations when an instance has become unhealthy in a auto scaling group
A new scaling activty terminates the unhealthy instance and then a new scaling activity launches a new, replacement instance.
47
Can GuardDuty monitor S3 for malicious activity
Yes
48
What do you need to provide an encrypted connection between a data center and AWS cloud.
VPN usually paired with Direct Connect
49
S3 can achieve 3,500 PUT/COPY/POST/DELETE and 5500 GET/HEAD per what
prefix
50
On a EC2, what is the ideal storage for temporary information that changes frequently, such as buffers, caches, and scratch data
Instance Store
51
How can you run Oracle in AWS
AWS RDS Custom for Oracle
52
How can you hook up AWS to work with Active Directory
Use AWS Directory Service AD Connector to connect AWS to the on-premises Active Directory. Integrate AD Connector with AWS IAM Identity Center. Use permission sets to assign access to AWS accounts and resources based on Active Directory group membership
53
What does suspending ReplaceUnhealthy on an Auto Scaling group do
It will not replace any unhealthy instances. You can use this time to do maintenance on an instance. Just set it back
54
How long can you reserve an EC2 Reserved Instance
for 1 or 3 years only (NOT ANYTIME BETWEEN)
55
If running an OLTP on an EC@ and you need to do thousands of requests per second, what ec2 type should you choose
Storage Optimized
56
What are some examples of reasons you would use a compute optimized ec2 instance type
batch processing workloads media transcoding high performance web servers high performance computing scientific modeling and machine learning dedicated gaming servers
57
What is some examples of reasons why to use a memory optimized ec2 instance
High performance relational/non-relational dbs Distributed web scale cache stores in memory dbs optimized for bi applications performing real time processing for big unstructured data
58
What are some examples of reasons to use storage optimized ec2 instances
High Frequency OLTP systems Relational & NoSql dbs Cach for in memory dbs, redis Data warehouseing apps Distributed file systems
59
What are the different type of placement groups
Cluster Spread Partition
60
What is a cluster placement group
Clusters instances into a low latency group in a single az
61
what is a spread placement group
spreads instances across underlying hardware, max 7 instances per group per az (critical apps)
62
What is a partition placement group
Spreads instances across many different partitions (different sets of racks) within an AZ
63
What are some use cases for cluster placement groups
Big data jobs that need to complete fast apps that need extreme low latency and high network throughput
64
When would you use a partition placement group
Partition aware apps like HDFS, HBase, Cassandra, Kafka
65
Elastic Network Interface (ENI) can be attached to EC2 instances in another AZ. (T/F)
False, ENI are bounded to a specific AZ
66
For EC2 hibernate, what does the root volume need to be
an EBS volume
67
For EC2 hibernate, RAM must be less than what
150 GB
68
What EC2 types support hibernate
On Demand and Reserved
69
How many instances can an EBS volume be attached to at a time
1
70
What is the default behavior for delete on termination for the root ebs volume vs other ebs volumes
the root is deleted, others are kept
71
When moving an ebs snapshot to an archive, how long can it take to restore
24 to 72 hours
72
How long can you set the recycle bin for an EBS snapshot
1 day to 1 year
73
What is an EC2 Instance Store
High performance hardware disk attached to an ec2
74
What happens to an EC2 instance store if it they are stopped
they lose their storage
75
What type of EBS volume should you use for database workloads
Provisioned IOPS
76
What is EBS Multi Attach
Allows you attach ebs to multiple ec2s but it is only available for io1/io2 family volumes
77
What are the different throughput modes for EFS
Bursting Performance Mode Throughput Mode
78
What are the different Storage Tiers for EFS
Standard Infrequent Access Archive
79
With EBS gp2, what happens when IO increases
the disk size increases
80
With EBS gp3 and Io1, what happens when IO increases
nothing, the IO and disk are independent
81
EFS is only for Linux Systems (T/F)
true
82
AMIs are region specific (t/f)
True, but you can copy it to the other region
83
IAM User Groups can contain IAM Users and other User Groups. (t/f)
false
84
What traffic does a Network Load Balancer handle
TCP and UDP
85
A NLB is ultra low latency (t/f)
true
86
How many static ips per az does a nlb have
one, and supports assigning elastic ip
87
What type of health checks are supported by nlb
TCP, HTTP, and HTTPS
88
If you want to use the GENEVE protocol on port 6081, which load balancer do you need
Gateway load balancer
89
Which load balancer type only supplies a dns name
An elastic load balancer or application load balancer
90
Which load balancer supplies a DNS name and a static ip
A network load balancer
91
ALBs suppurt TCP (T/F)
False
92
ALBs can route traffic based on geography (t/f)
False
93
Network Load Balancer can be a registered target in an alb target group (t/f)
false
94
Lambda functions can be registered targets in an alb target group (t/f)
true
95
Can you attach an Elastic IP to an ALB
No
96
What are the RDS database that can be managed by AWS
Postgres MySql MariaDB Oracle (Custom) Microsoft SQL Server (Custom) IDM DB2 Aurora
97
Read Replicas can be within AZ, Cross AZ, or Cross Region (t/f)
True
98
Replication is SYNC (t/f)
false, they are sync, eventually consistent
99
Which manged dbs do you have access to the underlying os
Custom (oracle, msql)
100
Why would you use Global Aurora
When you need to support reads to other (multiple regions) and need to to recover to another region in less than a minute
101
What RDS supports RDS Proxy
MySql, Postges, Mariadb, MS Sql Server, Aurora
102
Which version of Elastic cache guarantees both uniqueness and element ordering
Redis (sorted sets)
103
Multi-AZ keeps the same connection string regardless of which database is up (t/f)
true
104
Which works for root doman and non root domain alias or cname
alias
105
EC2 DNS names can be the target if an alias record (t/f)
false
106
What are the routing policies supported by Route 53
simple weighted failover latency based geolocation multi value geoproximity
107
Can simple routing policies be associated with health checks
No
108
Can weighted routing polices be associated with health checks
Yes
109
With a weighted routing policy, what happens when all weights are set to 0?
All records are returned equally