AWSCP2
AWSCP2
(Correct)
Explanation
Correct option:
Incorrect options:
https://aws.amazon.com/rds/instance-types/
Question 2: Incorrect
A company needs a storage solution for a project wherein the data is
accessed less frequently but needs rapid access when required. Which S3
storage class is the MOST cost-effective for the given use-case?
Amazon S3 Standard
Amazon S3 Glacier (S3 Glacier)
Amazon S3 Intelligent-Tiering (S3 Intelligent-Tiering)
(Incorrect)
(Correct)
Explanation
Correct option:
Incorrect options:
Reference:
https://aws.amazon.com/s3/storage-classes/
Question 3: Incorrect
A cyber forensics team has detected that AWS owned IP-addresses are
being used to carry out malicious attacks. As this constitutes prohibited
use of AWS services, which of the following is the correct solution to
address this issue?
Contact AWS Support
(Incorrect)
(Correct)
Explanation
Correct option:
The AWS Abuse team can assist you when AWS resources are used to
engage in abusive behavior.
Please see details of the various scenarios that the AWS Abuse team can
address:
via - https://aws.amazon.com/premiumsupport/knowledge-center/report-
aws-abuse/
Incorrect options:
Contact AWS Support - You need to contact the AWS Abuse team for
prohibited use of AWS services.
Reference:
https://aws.amazon.com/premiumsupport/knowledge-center/report-aws-
abuse/
Question 4: Incorrect
Which of the following is CORRECT regarding removing an AWS account
from AWS Organizations?
Raise a support ticket with AWS Support to remove the
account
The AWS account must not have any Service Control Policies
(SCPs) attached to it. Only then it can be removed from AWS
organizations
(Incorrect)
The AWS account can be removed from AWS Systems
Manager
The AWS account must be able to operate as a standalone
account. Only then it can be removed from AWS
organizations
(Correct)
Explanation
Correct option:
You can remove an account from your organization only if the account has
the information that is required for it to operate as a standalone account.
For each account that you want to make standalone, you must accept the
AWS Customer Agreement, choose a support plan, provide and verify the
required contact information, and provide a current payment method.
AWS uses the payment method to charge for any billable (not AWS Free
Tier) AWS activity that occurs while the account isn't attached to an
organization.
Incorrect options:
The AWS account must not have any Service Control Policies
(SCPs) attached to it. Only then it can be removed from AWS
organizations - This is not a pre-requisite to remove the AWS account.
The principals in the AWS account are no longer affected by any service
control policies (SCPs) that were defined in the organization. This means
that restrictions imposed by those SCPs are gone, and the users and roles
in the account might have more permissions than they had before.
Reference:
https://docs.aws.amazon.com/organizations/latest/userguide/
orgs_manage_accounts_remove.html
Question 5: Incorrect
A startup wants to migrate its data and applications from the on-premises
data center to AWS Cloud. Which of the following options can be used by
the startup to help with this migration? (Select two)
Consult moderators on AWS Developer Forums
Leverage AWS Professional Services to accelerate the
infrastructure migration
(Correct)
(Incorrect)
(Correct)
Explanation
Correct options:
The AWS Partner Network (APN) is the global partner program for
technology and consulting businesses that leverage Amazon Web Services
to build solutions and services for customers. The startup can work with
experts from APN to build a custom solution for this infrastructure
migration.
Incorrect options:
Raise a support ticket with AWS Support for further assistance -
AWS Support cannot help with complex infrastructure migration of this
nature. Hence this option is incorrect.
References:
https://aws.amazon.com/partners/
https://aws.amazon.com/professional-services/
https://aws.amazon.com/solutions/implementations/aws-landing-zone/
Question 6: Incorrect
Which of the following is a recommended way to provide programmatic
access to AWS resources?
Use IAM user group to access AWS resources
programmatically
(Incorrect)
(Correct)
Access keys are long-term credentials for an IAM user or the AWS account
root user. You can use access keys to sign programmatic requests to the
AWS CLI or AWS API (directly or using the AWS SDK). Access keys consist
of two parts: an access key ID and a secret access key. As a user name
and password, you must use both the access key ID and secret access key
together to authenticate your requests. When you create an access key
pair, save the access key ID and secret access key in a secure location.
The secret access key is available only at the time you create it. If you
lose your secret access key, you must delete the access key and create a
new one.
Incorrect options:
Create a new IAM user and share the username and password -
This is not a viable option, IAM user credentials are not needed to access
resources programmatically.
Reference:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-
keys.html
Question 7: Correct
Which of the following are the storage services offered by the AWS Cloud?
(Select two)
Amazon Simple Notification Service (SNS)
Amazon Elastic File System (Amazon EFS)
(Correct)
(Correct)
Explanation
Correct options:
Incorrect options:
References:
https://aws.amazon.com/s3/
https://aws.amazon.com/efs/
Question 8: Incorrect
Which AWS Support plan provides architectural guidance contextual to
your specific use-cases?
AWS Developer Support
AWS Business Support
(Correct)
(Incorrect)
Explanation
Correct option:
You should use AWS Business Support if you have production workloads
on AWS and want 24x7 phone, email and chat access to technical support
and architectural guidance in the context of your specific use-cases. You
get full access to AWS Trusted Advisor Best Practice Checks. You also get
access to Infrastructure Event Management for an additional fee.
Incorrect options:
AWS Developer Support - You should use AWS Developer Support if you
are testing or doing early development on AWS and want the ability to get
email-based technical support during business hours as well as general
architectural guidance as you build and test. This plan only supports
general architectural guidance.
Reference:
https://aws.amazon.com/premiumsupport/plans/
Question 9: Correct
A research group wants to use EC2 instances to run a scientific
computation application that has a fault tolerant architecture. The
application needs high-performance hardware disks that provide fast I/O
performance. As a Cloud Practitioner, which of the following storage
options would you recommend as the MOST cost-effective solution?
Instance Store
(Correct)
Instance Store
As the Instance Store volumes are included as part of the instance's usage
cost, therefore this is the correct option.
Incorrect options:
Amazon Elastic Block Store (EBS) - Amazon Elastic Block Store (EBS) is
an easy to use, high-performance block storage service designed for use
with Amazon Elastic Compute Cloud (EC2) for both throughput and
transaction-intensive workloads at any scale. EBS is not available as a
hardware disk on the instance, so this option is not correct.
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/
InstanceStorage.html
(Correct)
(Correct)
Developer salary
SaaS application license fee
Project manager salary
Explanation
Correct options:
Exam Alert:
Please check out the following six advantages of Cloud Computing. You
would certainly be asked questions on the advantages of Cloud
Computing compared to a traditional on-premises
setup:
via - https://docs.aws.amazon.com/whitepapers/latest/aws-overview/six-
advantages-of-cloud-computing.html
Incorrect options:
Developer salary
Reference:
https://docs.aws.amazon.com/whitepapers/latest/aws-overview/six-
advantages-of-cloud-computing.html
(Correct)
(Incorrect)
Explanation
Correct option:
Amazon EFS is a file storage service for use with Amazon EC2. Amazon
EFS provides a file system interface, file system access semantics, and
concurrently-accessible storage for up to thousands of Amazon EC2
instances. Amazon EFS uses the Network File System protocol.
How EFS
works:
via - https://aws.amazon.com/efs/
Incorrect options:
Reference:
https://aws.amazon.com/efs/
(Incorrect)
(Correct)
(Incorrect)
(Correct)
Explanation
Correct option:
Engineer
Incorrect options:
References:
https://docs.aws.amazon.com/whitepapers/latest/overview-aws-cloud-
adoption-framework/platform-perspective.html
https://d1.awsstatic.com/whitepapers/aws-caf-ebook.pdf
(Correct)
Incorrect options:
AWS Secrets Manager - AWS Secrets Manager helps you protect secrets
needed to access your applications, services, and IT resources. The
service enables you to easily rotate, manage, and retrieve database
credentials, API keys, and other secrets throughout their lifecycle. With
Secrets Manager, you pay based on the number of secrets stored and API
calls made.
Reference:
https://docs.aws.amazon.com/waf/latest/developerguide/shield-
chapter.html
(Incorrect)
(Correct)
(Correct)
Provide lower latency to applications by maintaining servers
on-premises
Explanation
Correct options:
Incorrect options:
Reference:
https://docs.aws.amazon.com/whitepapers/latest/aws-overview/six-
advantages-of-cloud-computing.html
(Correct)
Explanation
Correct option:
Amazon Macie
Amazon Macie is a fully managed data security and data privacy service
that uses machine learning and pattern matching to discover and protect
your sensitive data in AWS. Macie automatically provides an inventory of
Amazon S3 buckets including a list of unencrypted buckets, publicly
accessible buckets, and buckets shared with AWS accounts outside those
you have defined in AWS Organizations. Then, Macie applies machine
learning and pattern matching techniques to the buckets you select to
identify and alert you to sensitive data, such as personally identifiable
information (PII).
How Macie
Works:
via - https://aws.amazon.com/macie/
Incorrect options:
AWS Glue - AWS Glue is a fully managed extract, transform, and load
(ETL) service that makes it easy for customers to prepare and load their
data for analytics. AWS Glue job is meant to be used for batch ETL data
processing. It cannot be used to discover and protect your sensitive data
in AWS.
Amazon Polly - Amazon Polly is a service that turns text into lifelike
speech, allowing you to create applications that talk, and build entirely
new categories of speech-enabled products. Polly's Text-to-Speech (TTS)
service uses advanced deep learning technologies to synthesize natural
sounding human speech. It cannot be used to discover and protect your
sensitive data in AWS.
AWS Secrets Manager - AWS Secrets Manager helps you protect secrets
needed to access your applications, services, and IT resources. The
service enables you to easily rotate, manage, and retrieve database
credentials, API keys, and other secrets throughout their lifecycle. Users
and applications retrieve secrets with a call to Secrets Manager APIs,
eliminating the need to hardcode sensitive information in plain text. It
cannot be used to discover and protect your sensitive data in AWS.
Reference:
https://aws.amazon.com/macie/
(Incorrect)
(Correct)
Incorrect options:
References:
https://aws.amazon.com/efs/faq/
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-attaching-
volume.html
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-volumes-
multi.html
(Incorrect)
(Correct)
(Correct)
Amazon DynamoDB
There are two types of VPC endpoints: interface endpoints and gateway
endpoints.
Amazon DynamoDB
Exam Alert:
You may see a question around this concept in the exam. Just remember
that only Amazon S3 and Amazon DynamoDB support VPC gateway
endpoint. All other services that support VPC Endpoints use a VPC
interface endpoint (note that Amazon S3 supports the VPC interface
endpoint as well).
Incorrect options:
Reference:
https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints.html
(Correct)
Explanation
Correct option:
Configuration Management
Controls that apply to both the infrastructure layer and customer layers,
but in completely separate contexts or perspectives are called shared
controls. In a shared control, AWS provides the requirements for the
infrastructure and the customer must provide their own control
implementation within their use of AWS services. Configuration
Management forms a part of shared controls - AWS maintains the
configuration of its infrastructure devices, but a customer is responsible
for configuring their own guest operating systems, databases, and
applications.
via - https://aws.amazon.com/compliance/shared-responsibility-model/
Incorrect options:
Reference:
https://docs.aws.amazon.com/kms/latest/developerguide/
concepts.html#master_keys
(Incorrect)
Amazon Route 53
(Correct)
AWS CloudFormation
(Incorrect)
(Correct)
Explanation
Correct options:
Amazon Route 53
AWS Shield Standard is activated for all AWS customers, by default. For
higher levels of protection against attacks, you can subscribe to AWS
Shield Advanced. With Shield Advanced, you also have exclusive access to
advanced, real-time metrics and reports for extensive visibility into
attacks on your AWS resources. With the assistance of the DRT (DDoS
response team), AWS Shield Advanced includes intelligent DDoS attack
detection and mitigation for not only for network layer (layer 3) and
transport layer (layer 4) attacks but also for application layer (layer 7)
attacks.
AWS Shield Advanced provides expanded DDoS attack protection for web
applications running on the following resources: Amazon Elastic Compute
Cloud, Elastic Load Balancing (ELB), Amazon CloudFront, Amazon Route
53, AWS Global Accelerator.
Incorrect options:
Reference: https://docs.aws.amazon.com/waf/latest/developerguide/ddos-
overview.html
(Incorrect)
(Correct)
Incorrect options:
AWS Management Console - The AWS Management Console is a web
application that comprises and refers to a broad collection of service
consoles for managing Amazon Web Services. When you first sign in, you
see the console home page. The home page provides access to each
service console as well as an intuitive user interface for exploring AWS
and getting helpful tips.
References:
https://aws.amazon.com/tools/
https://aws.amazon.com/cli/
(Correct)
(Correct)
(Correct)
(Incorrect)
Exam Alert:
Please check out the following six advantages of cloud computing. You
would certainly be asked questions on the advantages of cloud computing
compared to a traditional on-premises
setup:
via - https://docs.aws.amazon.com/whitepapers/latest/aws-overview/six-
advantages-of-cloud-computing.html
Incorrect options:
Reference:
https://docs.aws.amazon.com/whitepapers/latest/aws-overview/six-
advantages-of-cloud-computing.html
(Incorrect)
(Correct)
Explanation
Correct option:
AWS Budgets
AWS Budgets gives you the ability to set custom budgets that alert you
when your costs or usage exceed (or are forecasted to exceed) your
budgeted amount.
You can also use AWS Budgets to set reservation utilization or coverage
targets and receive alerts when your utilization drops below the threshold
you define. Reservation alerts are supported for Amazon EC2, Amazon
RDS, Amazon Redshift, Amazon ElastiCache, and Amazon Elasticsearch
reservations.
Incorrect options:
AWS Pricing Calculator - AWS Pricing Calculator lets you explore AWS
services and create an estimate for the cost of your use cases on AWS.
You can model your solutions before building them, explore the price
points and calculations behind your estimate, and find the available
instance types and contract terms that meet your needs. This enables you
to make informed decisions about using AWS. You cannot use this service
to receive alerts when the reservation utilization falls below the defined
threshold.
References:
https://aws.amazon.com/aws-cost-management/aws-budgets/
https://aws.amazon.com/premiumsupport/technology/trusted-advisor/
best-practice-checklist/
(Incorrect)
(Correct)
Explanation
Correct option:
Use Amazon Transcribe to convert speech to text for downstream
analysis. Then use Amazon Polly to convey the text results via
speech
via - https://aws.amazon.com/transcribe/
You can use Amazon Polly to turn text into lifelike speech thereby allowing
you to create applications that talk. Polly's Text-to-Speech (TTS) service
uses advanced deep learning technologies to synthesize natural sounding
human speech.
Amazon Polly
Benefits:
via - https://aws.amazon.com/polly/
Incorrect options:
Use Amazon Polly to convert speech to text for downstream
analysis. Then use Amazon Transcribe to convey the text results
via speech - Amazon Polly cannot be used to convert speech to text, so
this option is incorrect.
References:
https://aws.amazon.com/transcribe/
https://aws.amazon.com/polly/
(Correct)
Elasticity
(Incorrect)
Scalability
Explanation
Correct option:
Agility
Incorrect options:
Elasticity - This refers to the ability to acquire resources as you need and
release when they are no longer needed is termed as Elasticity of the
Cloud.
Reference:
https://docs.aws.amazon.com/whitepapers/latest/aws-overview/six-
advantages-of-cloud-computing.html
https://wa.aws.amazon.com/wat.concepts.wa-concepts.en.html
(Incorrect)
AWS Artifact
(Correct)
Explanation
Correct option:
AWS Artifact
Incorrect options:
AWS Secrets Manager - AWS Secrets Manager helps you protect secrets
needed to access your applications, services, and IT resources. The
service enables you to easily rotate, manage, and retrieve database
credentials, API keys, and other secrets throughout their lifecycle. Users
and applications retrieve secrets with a call to Secrets Manager APIs,
eliminating the need to hardcode sensitive information in plain text.
AWS Systems Manager - AWS Systems Manager gives you visibility and
control of your infrastructure on AWS. Systems Manager provides a unified
user interface so you can view operational data from multiple AWS
services and allows you to automate operational tasks across your AWS
resources. With Systems Manager, you can group resources, like Amazon
EC2 instances, Amazon S3 buckets, or Amazon RDS instances, by
application, view operational data for monitoring and troubleshooting, and
take action on your groups of resources.
Reference:
https://aws.amazon.com/artifact/
(Incorrect)
(Correct)
via - https://aws.amazon.com/compliance/shared-responsibility-model/
Incorrect options:
Patching guest OS
The customers must provide their own control implementation within their
use of AWS services. Therefore, the customers are responsible for
patching their guest OS as well as for configuring their applications.
Reference:
https://aws.amazon.com/compliance/shared-responsibility-model/
(Correct)
(Incorrect)
(Correct)
Explanation
Correct options:
Using the AWS Cloud Adoption Framework (AWS CAF), you can reimagine
how your business and technology teams create customer value and meet
your strategic intent. Organizing your teams around products and value
streams while leveraging agile methods to rapidly iterate and evolve will
help you become more responsive and customer centric.
Incorrect options:
These three options are not in agreement with the tasks outlined by the
AWS Cloud Adoption Framework (AWS CAF) to become more responsive to
customer inquiries and feedback, hence these options are incorrect.
Reference:
https://aws.amazon.com/cloud-adoption-framework/
(Incorrect)
(Correct)
Explanation
Correct option:
Incorrect options:
Deploy the database via AWS Elastic Beanstalk - You cannot deploy
only a database via Elastic Beanstalk as its meant for automatic
application deployment when you upload your code. Then Elastic
Beanstalk automatically handles the deployment, from capacity
provisioning, load balancing, auto-scaling to application health monitoring.
Hence this option is incorrect.
References:
https://aws.amazon.com/rds/features/multi-az/
(Correct)
Amazon Redshift
Amazon Redshift is a fully-managed petabyte-scale cloud-based data
warehouse product designed for large scale data set storage and analysis.
Incorrect options:
AWS Glue - AWS Glue is a fully managed extract, transform, and load
(ETL) service that makes it easy for customers to prepare and load their
data for analytics.
References:
https://aws.amazon.com/redshift/
https://aws.amazon.com/dms/
(Incorrect)
(Correct)
(Correct)
Explanation
Correct options:
AWS has the concept of a Region, which is a physical location around the
world where AWS clusters its data centers. AWS calls each group of logical
data centers an Availability Zone (AZ). Each AWS Region consists of a
minimum of three, isolated, and physically separate AZs within a
geographic area. Each AZ has independent power, cooling, and physical
security and is connected via redundant, ultra-low-latency networks.
Incorrect options:
Reference:
https://aws.amazon.com/about-aws/global-infrastructure/regions_az/
(Correct)
via - https://aws.amazon.com/compute-optimizer/
Incorrect options:
AWS Systems Manager - AWS Systems Manager is the operations hub
for AWS. Systems Manager provides a unified user interface so you can
track and resolve operational issues across your AWS applications and
resources from a central place. With Systems Manager, you can automate
operational tasks for Amazon EC2 instances or Amazon RDS instances.
You can also group resources by application, view operational data for
monitoring and troubleshooting, implement pre-approved change
workflows, and audit operational changes for your groups of resources.
Systems Manager simplifies resource and application management,
shortens the time to detect and resolve operational problems, and makes
it easier to operate and manage your infrastructure at scale. Systems
Manager cannot be used to identify the optimal resource configuration for
workloads running on AWS.
AWS Budgets - AWS Budgets allows you to set custom budgets to track
your cost and usage from the simplest to the most complex use cases.
With AWS Budgets, you can choose to be alerted by email or SNS
notification when actual or forecasted cost and usage exceed your budget
threshold, or when your actual RI and Savings Plans' utilization or
coverage drops below your desired threshold. With AWS Budget Actions,
you can also configure specific actions to respond to cost and usage
status in your accounts, so that if your cost or usage exceeds or is
forecasted to exceed your threshold, actions can be executed
automatically or with your approval to reduce unintentional over-
spending.
Reference:
https://aws.amazon.com/compute-optimizer/
(Incorrect)
Amazon DynamoDB
(Correct)
Amazon DocumentDB
AWS Lambda
(Incorrect)
(Correct)
Explanation
Correct options:
Amazon DynamoDB
Amazon EC2 Reserved Instances (RI): You can use Amazon EC2 Reserved
Instances (RI) to reserve capacity and receive a discount on your instance
usage compared to running On-Demand instances.
Amazon DynamoDB Reserved Capacity: If you can predict your need for
Amazon DynamoDB read-and-write throughput, Reserved Capacity offers
significant savings over the normal price of DynamoDB provisioned
throughput capacity.
Amazon RDS RIs: Like Amazon EC2 RIs, Amazon RDS RIs can be
purchased using No Upfront, Partial Upfront, or All Upfront terms. All
Reserved Instance types are available for Aurora, MySQL, MariaDB,
PostgreSQL, Oracle, and SQL Server database engines.
Amazon Redshift Reserved Nodes: If you intend to keep an Amazon
Redshift cluster running continuously for a prolonged period, you should
consider purchasing reserved-node offerings. These offerings provide
significant savings over on-demand pricing, but they require you to
reserve compute nodes and commit to paying for those nodes for either a
1- or 3-year duration.
Incorrect options:
AWS Lambda - AWS Lambda lets you run code without provisioning or
managing servers. You pay only for the compute time you consume.
Reference:
https://d0.awsstatic.com/whitepapers/aws_pricing_overview.pdf
(Correct)
(Correct)
Explanation
Correct options:
via - https://aws.amazon.com/compliance/shared-responsibility-model/
Incorrect options:
Reference:
https://aws.amazon.com/compliance/shared-responsibility-model/
(Incorrect)
(Correct)
(Correct)
via - https://aws.amazon.com/blogs/compute/building-loosely-coupled-
scalable-c-applications-with-amazon-sqs-and-amazon-sns/
Incorrect options:
AWS Lambda - AWS Lambda lets you run code without provisioning or
managing servers. You pay only for the compute time you consume.
Lambda cannot be used to decouple components of a microservices-
based application.
AWS Step Functions - AWS Step Functions lets you coordinate multiple
AWS services into serverless workflows. You can design and run workflows
that stitch together services such as AWS Lambda, AWS Glue and Amazon
SageMaker. AWS Step Functions cannot be used to decouple components
of a microservices-based application.
Reference:
https://aws.amazon.com/blogs/compute/building-loosely-coupled-scalable-
c-applications-with-amazon-sqs-and-amazon-sns/
https://aws.amazon.com/microservices/
(Incorrect)
Layer 4 and 7
Layer 4
Layer 7
(Correct)
Explanation
Correct option:
Layer 7
AWS WAF is a web application firewall that lets you monitor the HTTP and
HTTPS requests that are forwarded to an Amazon API Gateway API,
Amazon CloudFront or an Application Load Balancer. HTTP and HTTPS
requests are part of the Application layer, which is layer 7.
Incorrect options:
Layer 3 - Layer 3 is the Network layer and this layer decides which
physical path data will take when it moves on the network. AWS Shield
offers protection at this layer. WAF does not offer protection at this layer.
Layer 4 - Layer 4 is the Transport layer and this layer data transmission
occurs using TCP or UDP protocols. AWS Shield offers protection at this
layer. WAF does not offer protection at this layer.
Reference: https://docs.aws.amazon.com/waf/latest/developerguide/what-
is-aws-waf.html
(Incorrect)
(Correct)
Incorrect options:
References:
https://docs.aws.amazon.com/en_us/AmazonS3/latest/userguide/
UsingClientSideEncryption.html
https://docs.aws.amazon.com/en_us/AmazonS3/latest/userguide/serv-side-
encryption.html
(Correct)
Amazon S3 Intelligent-Tiering
Amazon S3 Standard
Amazon S3 Glacier Flexible Retrieval
Explanation
Correct option:
via - https://aws.amazon.com/s3/storage-classes/
Incorrect options:
Reference:
https://aws.amazon.com/s3/storage-classes/
(Correct)
(Incorrect)
Explanation
Correct option: Fault tolerance is achieved by a scale up operation
Incorrect options:
Reference:
https://wa.aws.amazon.com/wat.concept.horizontal-scaling.en.html
What will be the outcome on the overall bill once the credits are used?
(Select two)
(Correct)
Only one credit can be used in one billing cycle and the
customer has a choice to choose from the available ones
Then, credit two is applied to the remaining $900 of Amazon
EC2 usage
(Correct)
(Incorrect)
Soonest expiring
Oldest credit
For the given use case, credit one is applied, which expires in July, to the
Amazon EC2 charge which leaves you with a $900 Amazon EC2 charge
and a $500 Amazon S3 charge. Then, credit two is applied to the
remaining $900 of Amazon EC2 usage. You need to pay $850 for Amazon
EC2 and $500 for Amazon S3. All your credits are now exhausted.
Incorrect options:
Only one credit can be used in one billing cycle and the customer
has a choice to choose from the available ones
Reference:
https://www.amazonaws.cn/en/support/faqs/
(Correct)
(Incorrect)
via - https://aws.amazon.com/organizations/
Incorrect options:
Use AWS Cost Explorer to manage AWS accounts of all units and
then share the reserved EC2 instances amongst all units - AWS
Cost Explorer lets you explore your AWS costs and usage at both a high
level and at a detailed level of analysis, and empowering you to dive
deeper using several filtering dimensions (e.g., AWS Service, Region,
Linked Account). You cannot use Cost Explorer to share the reserved EC2
instances amongst multiple AWS accounts.
References:
https://aws.amazon.com/organizations/
https://aws.amazon.com/premiumsupport/technology/trusted-advisor/
https://aws.amazon.com/systems-manager/
(Correct)
(Correct)
The AWS Basic Support plan only provides access to the following:
You should use the AWS Developer Support plan if you are testing or
doing early development on AWS and want the ability to get email-based
technical support during business hours as well as general architectural
guidance as you build and test. This plan provides access to just the core
Trusted Advisor checks from the Service Quota and basic Security checks.
Exam Alert:
Please review the differences between the AWS Developer Support, AWS
Business Support, AWS Enterprise On-Ramp Support and AWS Enterprise
Support plans as you can expect at least a couple of questions on the
exam:
via - https://aws.amazon.com/premiumsupport/plans/
Incorrect options:
AWS Business Support - You should use the AWS Business Support plan
if you have production workloads on AWS and want 24x7 phone, email
and chat access to technical support and architectural guidance in the
context of your specific use-cases. You also get full access to AWS Trusted
Advisor Best Practice Checks.
https://aws.amazon.com/premiumsupport/plans/
(Incorrect)
Dedicated Host
(Correct)
Dedicated Host
Amazon EC2 Dedicated Hosts allow you to use your eligible software
licenses from vendors such as Microsoft and Oracle on Amazon EC2. An
Amazon EC2 Dedicated Host is a physical server fully dedicated for your
use, so you can help address corporate compliance requirements.
Exam Alert:
Incorrect options:
Reference:
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-
overview.html
(Incorrect)
(Correct)
Explanation
Correct option:
Incorrect options:
The AWS customer by using AWS Systems Manager - AWS Systems
Manager gives you visibility and control of your infrastructure on AWS.
Systems Manager provides a unified user interface so you can view
operational data from multiple AWS services and allows you to automate
operational tasks such as running commands, managing patches and
configuring servers across AWS Cloud as well as on-premises
infrastructure. You can only use AWS Systems Manager to apply patches
to your EC2 instances or on-premises instances. You cannot use Systems
Manager to apply patches to the underlying OS for AWS Aurora.
Reference:
https://aws.amazon.com/rds/aurora/
(Incorrect)
Amazon CloudWatch
(Correct)
AWS Config
(Correct)
(Incorrect)
AWS CloudTrail
(Correct)
Explanation
Correct options:
There are three best practice areas for Reliability in the cloud -
Foundations, Change Management, Failure Management. Being aware of
how change affects a system (change management) allows you to plan
proactively, and monitoring allows you to quickly identify trends that
could lead to capacity issues or SLA breaches.
AWS Config
AWS Config is a service that enables you to assess, audit, and evaluate
the configurations of your AWS resources. Config continuously monitors
and records your AWS resource configurations and allows you to automate
the evaluation of recorded configurations against desired configurations.
via - https://aws.amazon.com/config/
AWS CloudTrail
How CloudTrail
Works:
via - https://aws.amazon.com/cloudtrail/
Amazon CloudWatch
Incorrect options:
References:
https://d1.awsstatic.com/whitepapers/architecture/AWS_Well-
Architected_Framework.pdf
https://aws.amazon.com/config/
https://aws.amazon.com/cloudtrail/
Question 45: Correct
Which AWS Service can be used to mitigate a Distributed Denial of Service
(DDoS) attack?
AWS Shield
(Correct)
AWS Shield
All AWS customers benefit from the automatic protections of AWS Shield
Standard, at no additional charge. AWS Shield Standard defends against
most common, frequently occurring network and transport layer DDoS
attacks that target your web site or applications. When you use AWS
Shield Standard with Amazon CloudFront and Amazon Route 53, you
receive comprehensive availability protection against all known
infrastructure (Layer 3 and 4) attacks.
Incorrect options:
Reference:
https://aws.amazon.com/shield/
(Correct)
Internet Gateway
(Incorrect)
VPC Endpoint
Explanation
Correct option:
Incorrect options:
References:
https://aws.amazon.com/directconnect/
https://aws.amazon.com/vpn/
(Correct)
Explanation
Correct option:
There are three fundamental drivers of cost with AWS: compute, storage,
and outbound data transfer. In most cases, there is no charge for inbound
data transfer or data transfer between other AWS services within the
same region. Outbound data transfer is aggregated across services and
then charged at the outbound data transfer rate.
Per AWS pricing, data transfer between S3 and EC2 instances within the
same region is not charged, so there would be no data transfer charge for
moving 500 GB of data from an EC2 instance to an S3 bucket in the same
region.
Incorrect options:
The company would only be charged for the inbound data transfer
into the S3 bucket
References:
https://aws.amazon.com/s3/pricing/
https://d0.awsstatic.com/whitepapers/aws_pricing_overview.pdf
(Correct)
(Incorrect)
(Correct)
Explanation
Correct options:
You should use AWS Business Support if you have production workloads
on AWS and want 24x7 phone, email and chat access to technical support
and architectural guidance in the context of your specific use-cases. You
get full access to AWS Trusted Advisor Best Practice Checks. You get
access to guidance, configuration, and troubleshooting of AWS
interoperability with many common operating systems, platforms, and
application stack components.
Exam Alert:
Please review the differences between the AWS Developer Support, AWS
Business Support, AWS Enterprise On-Ramp Support and AWS Enterprise
Support plans as you can expect at least a couple of questions on the
exam:
via - https://aws.amazon.com/premiumsupport/plans/
Incorrect options:
AWS Basic Support - The AWS Basic Support only provides access to the
following:
AWS Developer Support - You should use AWS Developer Support plan
if you are testing or doing early development on AWS and want the ability
to get email-based technical support during business hours. This plan also
supports general guidance on how services can be used for various use
cases, workloads, or applications. You do not get access to Infrastructure
Event Management with this plan.
Reference:
https://aws.amazon.com/premiumsupport/plans/
(Incorrect)
(Correct)
Explanation
Correct option:
The KMS keys that you create are customer managed keys. Customer
managed keys are KMS keys in your AWS account that you create, own,
and manage. You have full control over these KMS keys, including
establishing and maintaining their key policies, IAM policies, and grants,
enabling and disabling them, rotating their cryptographic material, adding
tags, creating aliases that refer to the KMS keys, and scheduling the KMS
keys for deletion.
Incorrect options:
AWS Secrets Manager - AWS Secrets Manager helps you protect secrets
needed to access your applications, services, and IT resources. The
service enables you to easily rotate, manage, and retrieve database
credentials, API keys, and other secrets throughout their lifecycle. You
cannot use AWS Secrets Manager for creating and using your own keys for
encryption on AWS services.
AWS managed key - AWS managed keys are KMS keys in your account
that are created, managed, and used on your behalf by an AWS service
integrated with AWS KMS.
AWS owned key - AWS owned keys are a collection of KMS keys that an
AWS service owns and manages for use in multiple AWS accounts.
Although AWS owned keys are not in your AWS account, an AWS service
can use an AWS owned key to protect the resources in your account.
Reference:
https://docs.aws.amazon.com/kms/latest/developerguide/
concepts.html#master_keys
Which AWS database service is the right fit for this requirement?
(Incorrect)
(Correct)
Explanation
Correct option:
Incorrect options:
References:
https://aws.amazon.com/dynamodb/features/
https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-
multi-master.html
(Correct)
EC2 On-Demand Instance
EC2 Dedicated Host
(Incorrect)
Explanation
Correct option:
An EC2 Reserved Instance (RI) provides you with significant savings (up to
75%) on your Amazon EC2 costs compared to On-Demand Instance
pricing. A Reserved Instance (RI) is not a physical instance, but rather a
billing discount applied to the use of On-Demand Instances in your
account. You can purchase a Reserved Instance (RI) for a one-year or
three-year commitment, with the three-year commitment offering a
bigger discount. A reserved instance (RI) cannot be interrupted. So this is
the correct option.
via - https://aws.amazon.com/ec2/pricing/
Incorrect options:
EC2 On-Demand Instance - An EC2 On-Demand Instance is an instance
that you use on-demand. You have full control over its lifecycle — you
decide when to launch, stop, hibernate, start, reboot, or terminate it.
There is no long-term commitment required when you purchase On-
Demand Instances. There is no upfront payment and you pay only for the
seconds that your On-Demand Instances are running. The price per
second for running an On-Demand Instance is fixed. On-demand instances
cannot be interrupted. However, On-demand instances are not as cost-
effective as Reserved instances, so this option is not correct.
EC2 Dedicated Host - An Amazon EC2 Dedicated Host allows you to use
your eligible software licenses from vendors such as Microsoft and Oracle
on Amazon EC2 so that you get the flexibility and cost-effectiveness of
using your licenses, but with the resiliency, simplicity, and elasticity of
AWS. An Amazon EC2 Dedicated Host is a physical server fully dedicated
for your use, so you can help address corporate compliance requirement.
It is not cost-efficient compared to an On-Demand instance. So this option
is not correct.
Reference:
https://aws.amazon.com/ec2/pricing/
(Correct)
via - https://aws.amazon.com/partners/
Incorrect options:
Concierge Support Team - The Concierge Support Team are AWS billing
and account experts that specialize in working with enterprise accounts.
They will quickly and efficiently assist you with your billing and account
inquiries. The Concierge Support Team is only available for the Enterprise
Support plan. Concierge Support Team cannot help in migrating to AWS
and managing applications on AWS Cloud.
Reference:
https://aws.amazon.com/partners/
(Correct)
75
10
50
Explanation
Correct option:
90
Amazon EC2 spot instances let you take advantage of unused EC2
capacity in the AWS cloud. Spot instances are available at up to a 90%
discount compared to the on-demand instance prices. You can use spot
instances for various stateless, fault-tolerant, or flexible applications such
as big data, containerized workloads, CI/CD, web servers, high-
performance computing (HPC), and other test & development workloads.
Incorrect options:
75
10
50
Reference:
https://aws.amazon.com/ec2/spot/
(Correct)
600 seconds
30 seconds
Explanation
Correct option:
60 seconds
Incorrect options:
30 seconds
300 seconds
600 seconds
Reference:
https://aws.amazon.com/blogs/aws/new-per-second-billing-for-ec2-
instances-and-ebs-volumes/
(Incorrect)
(Correct)
AWS Pricing Calculator lets you explore AWS services and create an
estimate for the cost of your use cases on AWS. You can model your
solutions before building them, explore the price points and calculations
behind your estimate, and find the available instance types and contract
terms that meet your needs. This enables you to make informed decisions
about using AWS. You can plan your AWS costs and usage or price out
setting up a new set of instances and services. AWS Pricing Calculator can
provide the estimate of the AWS service usage based on the list of AWS
services.
via - https://calculator.aws/#/
You should also note AWS is in the process of deprecating a similar tool
called the Simple Monthly Calculator. This calculator provides an estimate
of usage charges for AWS services based on certain information you
provide. It helps customers and prospects estimate their monthly AWS bill
more efficiently. This tool can be accessed
on : https://calculator.s3.amazonaws.com/index.html
Incorrect options:
AWS Cost & Usage Report (AWS CUR) - The AWS Cost & Usage Report
(AWS CUR) contains the most comprehensive set of AWS cost and usage
data available, including additional metadata about AWS services, pricing,
credit, fees, taxes, discounts, cost categories, Reserved Instances, and
Savings Plans. The AWS Cost & Usage Report (AWS CUR) itemizes usage
at the account or Organization level by product code, usage type and
operation. These costs can be further organized by Cost Allocation tags
and Cost Categories. The AWS Cost & Usage Report (AWS CUR) is
available at an hourly, daily, or monthly level of granularity, as well as at
the management or member account level. The AWS Cost & Usage Report
(AWS CUR) cannot provide the estimate of the monthly AWS bill based on
the list of AWS services.
AWS Cost Explorer - AWS Cost Explorer has an easy-to-use interface
that lets you visualize, understand, and manage your AWS costs and
usage over time. AWS Cost Explorer includes a default report that helps
you visualize the costs and usage associated with your top five cost-
accruing AWS services, and gives you a detailed breakdown of all services
in the table view. The reports let you adjust the time range to view
historical data going back up to twelve months to gain an understanding
of your cost trends. AWS Cost Explorer cannot provide the estimate of the
monthly AWS bill based on the list of AWS services.
AWS Budgets - AWS Budgets gives the ability to set custom budgets that
alert you when your costs or usage exceed (or are forecasted to exceed)
your budgeted amount. You can also use AWS Budgets to set reservation
utilization or coverage targets and receive alerts when your utilization
drops below the threshold you define. Budgets can be created at the
monthly, quarterly, or yearly level, and you can customize the start and
end dates. You can further refine your budget to track costs associated
with multiple dimensions, such as AWS service, linked account, tag, and
others. AWS Budgets cannot provide the estimate of the monthly AWS bill
based on the list of AWS services.
Reference:
https://calculator.aws/#/
(Correct)
AWS CloudFormation
Amazon Pinpoint
Explanation
Correct option:
AWS X-Ray
You can use AWS X-Ray to analyze and debug serverless and distributed
applications such as those built using a microservices architecture. With
X-Ray, you can understand how your application and its underlying
services are performing to identify and troubleshoot the root cause of
performance issues and errors.
How AWS X-Ray
Works:
via - https://aws.amazon.com/xray/
Incorrect options:
Reference:
https://aws.amazon.com/xray/
(Correct)
(Correct)
via
- https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.
html
Please see this comparison table for differences between Network Address
Translation gateway (NAT gateway) and Network Address Translation
instance (NAT
instance):
via - https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-
comparison.html
Incorrect options:
A network access control list (network ACL) can have allow rules
only
References:
https://docs.aws.amazon.com/vpc/latest/userguide/
VPC_SecurityGroups.html
https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html
Amazon GuardDuty
(Incorrect)
Amazon Macie
AWS Shield
Explanation
Correct option:
Amazon Inspector
Incorrect options:
Amazon Macie - Amazon Macie is a fully managed data security and data
privacy service that uses machine learning and pattern matching to
discover and protect your sensitive data in AWS. Macie helps identify and
alert you to sensitive data, such as personally identifiable information
(PII). This service is for securing data and has nothing to do with an EC2
security assessment. Macie cannot be used to check OS vulnerabilities.
https://aws.amazon.com/inspector/
(Correct)
AWS Config
Explanation
Correct option:
AWS CloudTrail
You can use CloudTrail to log, monitor and retain account activity related
to actions across your AWS infrastructure. CloudTrail provides an event
history of your AWS account activity, including actions taken through the
AWS Management Console, AWS SDKs, command-line tools, and other
AWS services.
How CloudTrail
Works:
via - https://aws.amazon.com/cloudtrail/
Incorrect options:
AWS Config - AWS Config is a service that enables you to assess, audit,
and evaluate the configurations of your AWS resources. Config
continuously monitors and records your AWS resource configurations and
allows you to automate the evaluation of recorded configurations against
desired configurations.
Exam Alert:
Reference:
https://aws.amazon.com/cloudtrail/
(Correct)
Reference:
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/encrypting-
cloudtrail-log-files-with-aws-kms.html
(Correct)
(Incorrect)
Incorrect options:
AWS Auto Scaling - AWS Auto Scaling monitors your applications and
automatically adjusts capacity to maintain steady, predictable
performance at the lowest possible cost. Using AWS Auto Scaling, it’s easy
to setup application scaling for multiple resources across multiple services
in minutes. This is a scaling service that helps you spin up resources as
and when you need them and scale down when the high demand reduces.
Auto Scaling can be used with Elastic Load Balacing to build high
performance applications.
Reference:
https://aws.amazon.com/elasticloadbalancing/
(Correct)
AWS Lambda
AWS Lambda lets you run code without provisioning or managing servers.
You pay only for the compute time you consume. With Lambda, you can
run code for virtually any type of application or backend service - all with
zero administration. Just upload your code and Lambda takes care of
everything required to run and scale your code with high availability.
How Lambda
Works:
via - https://aws.amazon.com/lambda/
Incorrect options:
Reference:
https://aws.amazon.com/lambda/
(Correct)
Explanation
Correct option:
IaaS contains the basic building blocks for cloud IT. It typically provides
access to networking features, computers (virtual or on dedicated
hardware), and data storage space. IaaS gives the highest level of
flexibility and management control over IT resources.
EC2 gives you full control over managing the underlying OS, virtual
network configurations, storage, data and applications. So EC2 is an
example of an IaaS service.
via - https://aws.amazon.com/types-of-cloud-computing/
Incorrect options:
Reference:
https://aws.amazon.com/types-of-cloud-computing/
(Correct)
latency-based routing
Failover routing
Explanation
Correct option:
Weighted routing
via
- https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-
policy.html
Incorrect options:
Failover routing - This routing policy is used when you want to configure
active-passive failover.
Reference:
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-
policy.html
(Correct)
(Incorrect)
You can use Amazon EC2 Reserved Instances (RI) to reserve capacity and
receive a discount on your instance usage compared to running On-
Demand instances. The discounted usage price is reserved for the
duration of your contract, allowing you to predict compute costs over the
term of the Reserved Instance (RI).
"No upfront payment option with the standard 1-year term" - 36%
"All upfront payment option with the standard 1-year term" - 40%
"No upfront payment option with the standard 3-years term" - 56%
"Partial upfront payment option with the standard 3-years term" - 59%
Exam Alert:
For the exam, there is no need to memorize these savings numbers. All
you need to remember is that a 3 years term would always be more cost-
effective than a 1-year term. Then within a term, "all upfront" is better
than "partial upfront" which in turn is better than "no upfront" from a cost
savings perspective.
Incorrect options: