What are the two required “items” to use AWS Inspector on the host?
- Instance must be tagged
What are the two types of assessments for inspector?
Network Assessment (checks for open ports) Host Assessment
What are the two runtime options for Inspector?
Run once and run weekly
What cannot be done with AWS managed CMKs?
Manage the keys yourself,
rotate them manually
change the key policies
use them in your own operations
How are AWS manages KMS keys priced?
No monthly fee
Free tier
Above that: usage of key
How often is a Customer managed CMK / AWS managed CMK automatically rotated?
Customer managed: 1 year (optional)
AWS managed: 3 years
What are the benefits of CloudHSM (in comparison to KMS)
Complete control of the keys, AWS has no access
Single Tenancy
Higher FIPS 140-2 rating
What are Web ACL?
Rules made by AWS WAF.
Can Count, Allow or Block if criteria is met
A company plans to expand its use of AWS services across its product portfolios. To ensure separation of business processes for billing, security, and compliance, the SysOps Administrator must provide each department with new AWS accounts having governance guardrails and a defined baseline in place. An efficient and scalable provisioning process is required to optimize the workflow and save time.
Which of the following options can satisfy the given requirement?
AWS Control Tower provides three methods for creating member accounts:
As part of the yearly AWS data cleanup, you need to delete all unused S3 buckets and their contents. The tutorialsdojo bucket, which contains several educational video files, has both the Versioning and MFA Delete features enabled. One of your Systems Engineers who has an Administrator account tried to delete an S3 bucket using the aws s3 rb s3://tutorialsdojo command. However, the operation fails even after repeated attempts.
Which of the following are valid options that you can implement to properly delete the bucket? (Select TWO.)
A company deployed a fleet of Linux-based EC2 instances to run an e-commerce website. The SysOps Administrator needs to monitor the CPU utilization of individual processes that are running in each server.
Which of the following options fulfills this requirement?
You are tasked to prepare a CloudFormation template which should automatically roll back in the event that the entire stack failed to launch. The application stack requires the pre-requisite packages to be installed first in order for it to run properly, which could take about an hour or so to complete.
What should you add in the template to accomplish this requirement?
1.In the ResourceSignal parameter of the CreationPolicyresource attribute, add a Timeout property with a value of 2 hours.
It is a requirement in your work that you produce regular reports and statistics on your EC2 resource consumption across different regions. In an upcoming meeting, you are asked to present these findings to your CTO and Data Analytics team. Aggregating these statistics would detail a lot of information on your resource consumption with ease.
What is the procedure for viewing aggregation statistics in CloudWatch?
You can also use CloudWatch metric math to aggregate and transform metrics from multiple accounts and Regions. Metric math enables you to query multiple CloudWatch metrics and use math expressions to create new time series based on these metrics. You can visualize the resulting time series on the CloudWatch console and add them to dashboards.
Why are Disk Read Operations and Disk Write Operations not correct metrics to check whether a EBS backed EC2 instance is slow?
the instances are being overloaded.
Disk Read Operations and Disk Write Operations are both incorrect because the Disk Read and Write Operations metrics are only applicable for instance store-backed AMI instances.
You work for a government agency as their Cloud Infrastructure Consultant and were given the task of automating the recurring tasks in their finance department such as data synchronizaton, infrastructure selection, and patch management, which will improve their current processes. You need to use a tool that can coordinate multiple AWS services into serverless workflows.
Which of these options is the most cost-effective service that you should use?
1´. AWS Batch
AWS Step Functions provides serverless orchestration for modern applications. Orchestration centrally manages a workflow by breaking it into multiple steps, adding flow logic, and tracking the inputs and outputs between the steps. As your applications execute, Step Functions maintains application state, tracking exactly which workflow step your application is in, and stores an event log of data that is passed between application components. That means that if networks fail or components hang, your application can pick up right where it left off.
A mobile development company has various AWS resources to support its various mobile products. To keep control of costs, they have requested for you to get the billing alerts for your AWS account once it reaches a certain limit.
Which of the following should you enable before you can receive billing alerts in AWS?
3 .Enable billing alerts in CloudWatch Console.
Before you can create an alarm for your estimated charges, you must enable billing alerts on your Accounts Preferences page first, so that you can monitor your estimated AWS charges and create an alarm using billing metric data. After you enable billing alerts, you cannot disable data collection, but you can delete any billing alarms that you created.
A popular online graphic design tool startup uses a standard S3 bucket that has versioning enabled to store the user-generated images on its platform. They have millions of users around the globe that store their logos, graphics, infographics, and other designs on their platform. Lately, there are a lot of users complaining that they receive a lot of HTTP 503 responses on the platform.
Which of the following options could be the reason why this issue exists?
When you have objects with millions of versions, Amazon S3 automatically throttles requests to the bucket to protect the customer from an excessive amount of request traffic, which could potentially impede other requests made to the same bucket.
What is the use case of AD Connector?
To connect to AWS using a self-managed Active Directory
A Company uses LDAP and needs to implement access control in AWS as part of an integration between internal and cloud
Need to configure SAM federation of IAM users and groups with the LDAP DB and map LDAP user and groups to IAM roles
What route53 queries are charged and which are not
CNAME: charged
ALIAS: free
What are the key facts to Cost-Explorer?
What are the key facts to Cost Allocation Tags?
What are the key facts to Cost and Usage Report?
- Lists all items that generate costs
What are the key facts to Cost Allocation Tags?