25,99 €
NEW! We've added two new practice exams to the online test bank to cover concepts in the new certification Exam SAA-C02. To help you prepare for taking the exam, the updated test bank now includes THREE practice exams PLUS all the domain-by-domain questions. Over 1000 questions to test your knowledge! 1,000 practice questions with answers and explanations! With five unique practice tests, covering the five AWS Certified Solutions Architect Associate Exam objective domains, PLUS one additional practice exam, AWS Certified Solutions Architect Practice Tests provides over 1,000 practice test questions to make sure you are prepared for exam day. Coverage of all exam objective domains includes: Design Resilient Architectures, Define Performant Architectures, Specify Secure Applications and Architectures, Design Cost-Optimized Architectures, Define Operationally Excellent Architectures. This book will help you: * Gain confidence as you prepare for the SAA-C01 exam * Ensure you are set up for success with 1,000 practice questions * When you are ready, test your knowledge with the Sybex online interactive learning environment * Get that highly desired AWS certification Prepare smarter, not harder, with Sybex's superior study tools.
Sie lesen das E-Book in den Legimi-Apps auf:
Seitenzahl: 465
Veröffentlichungsjahr: 2019
Brett McLaughlin
Senior Acquisitions Editor: Kenyon Brown
Development Editor: David Clark
Technical Editor: Sara Perrot
Senior Production Editor: Christine O’Connor
Copy Editor: Judy Flynn
Content Enablement and Operations Manager: Pete Gaughan
Production Manager: Kathleen Wisor
Executive Editor: Jim Minatel
Book Designers: Judy Fung and Bill Gibson
Proofreader: Nancy Carrasco
Indexer: Johnna VanHoose Dinse
Project Coordinator, Cover: Brent Savage
Cover Designer: Wiley
Cover Image: Getty Images, Inc. / Jeremy Woodhouse
Copyright © 2019 by John Wiley & Sons, Inc., Indianapolis, Indiana
Published simultaneously in Canada
ISBN: 978-1-119-55843-9
ISBN: 978-1-119-55841-5 (ebk.)
ISBN: 978-1-119-55842-2 (ebk.)
Manufactured in the United States of America
No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning or otherwise, except as permitted under Sections 107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-copy fee to the Copyright Clearance Center, 222 Rosewood Drive, Danvers, MA 01923, (978) 750-8400, fax (978) 646-8600. Requests to the Publisher for permission should be addressed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030, (201) 748-6011, fax (201) 748-6008, or online at http://www.wiley.com/go/permissions.
Limit of Liability/Disclaimer of Warranty: The publisher and the author make no representations or warranties with respect to the accuracy or completeness of the contents of this work and specifically disclaim all warranties, including without limitation warranties of fitness for a particular purpose. No warranty may be created or extended by sales or promotional materials. The advice and strategies contained herein may not be suitable for every situation. This work is sold with the understanding that the publisher is not engaged in rendering legal, accounting, or other professional services. If professional assistance is required, the services of a competent professional person should be sought. Neither the publisher nor the author shall be liable for damages arising herefrom. The fact that an organization or Web site is referred to in this work as a citation and/or a potential source of further information does not mean that the author or the publisher endorses the information the organization or Web site may provide or recommendations it may make. Further, readers should be aware that Internet Web sites listed in this work may have changed or disappeared between when this work was written and when it is read.
For general information on our other products and services or to obtain technical support, please contact our Customer Care Department within the U.S. at (877) 762-2974, outside the U.S. at (317) 572-3993 or fax (317) 572-4002.
Wiley publishes in a variety of print and electronic formats and by print-on-demand. Some material included with standard print versions of this book may not be included in e-books or in print-on-demand. If this book refers to media such as a CD or DVD that is not included in the version you purchased, you may download this material at http://booksupport.wiley.com. For more information about Wiley products, visit www.wiley.com.
Library of Congress Control Number: 2019931614
TRADEMARKS: Wiley, the Wiley logo, and the Sybex logo are trademarks or registered trademarks of John Wiley & Sons, Inc. and/or its affiliates, in the United States and other countries, and may not be used without written permission. All other trademarks are the property of their respective owners. John Wiley & Sons, Inc. is not associated with any product or vendor mentioned in this book.
To Andrew Pawloski, easily the best AWS engineer I know. One of these days he’ll realize how good he is and will stop answering my random AWS questions over text. Until then, I’m immeasurably glad to have him on my side.
Writing books seems to require two things: solitude and a sort of rhythm (at least for me). For both of those, I owe my family a great debt. Many, many times I had to shoo away my daughter, Addie, or put off my wife, Leigh, because I was in that rhythm and needed to see a particular question or tricky answer through to its end. I’ve also yelled upstairs more than once to my sons, Dean and Robbie, because I was on a call discussing some arcane bit of AWS knowledge while they were screaming into their headsets about flanking someone (something?) in Call of Duty or laughing hysterically at subverting an intended mission in Red Dead Redemption 2.
In other words, lots of people had to bend so I could get this book completed. I’m grateful for that, especially since most of their reward is these few sentences in a book they’ll likely never crack open! (Well, Robbie might… he’s the budding engineer in the family.)
Another set of thanks goes to the numerous folks at and associated with Wiley who helped see this through: Ken Brown and Amy Sell, who got things started; David Clark, patient and forgiving; Sara Perrot, who was amazing as a technical editor; and several others on additional projects who waited while I finished this one (James Schultz and Adaobi Tulton come to mind).
My qualifications are informed by a lifetime of teaching, even when I didn’t realize it. I started reading at four, and by the time I was in elementary school, I was “writing” instruction manuals. I still recall the carefully illustrated guide to solving the Rubik’s Magic that I put together in fifth grade.
In high school, I taught myself to program. (Turbo Pascal was the first language beyond Basic I learned; anyone remember the book with the Porsche on the cover?) Shortly after, I began teaching the programming class to my peers. Before I graduated, I was teaching two different periods of computer classes’mostly because the actual teacher liked to drink at lunch and showed up loaded most afternoons!
Once I’d knocked out a bachelor of science degree in computer science, I worked in technology, primarily at telecoms. But I never could let go of what I loved most: I was not just a programmer and system administrator. I was the guy who could translate customer requirements into user stories. I was the guy who could talk... and I talked all the time. I also figured out you could talk through writing. I authored the bestselling technology book Java and XML, followed by a number of other books for O’Reilly Media, and eventually joined that company.
More recently, I returned to my developer roots and spent nearly eight years working with NASA’s Earth Science group. Never have I spent more time teaching, translating, and explaining what one group’s words meant to another, and ultimately telling the story of what NASA is doing through a flagship website and eventually a massive, organization-wide cloud platform. And no matter how much I learned about Amazon Web Services (AWS) or EC2 or Lambda, it was always the storytelling that was most interesting; even better, it was always the storytelling that seemed to interest most clients. I could speak to them, in a way that they understood, and that was a good thing (TM).
Now, I teach and tell stories full-time. I record AWS certification courses on video and write exam prep books in a way that’s actually more helpful for passing exams than rote memorization. I build websites and applications, small and large, most often for clients who have their own story to tell to their users. I write books on what I’ve learned and on how to tell stories the way I do.
Cover
Acknowledgments
About the Author
Introduction
Certification Pays
Steps to Getting Certified and Staying Certified
Taking the Exam
How to Use This Book and the Interactive Online Learning Environment and Test Bank
Exam Objectives
Objective Map
Chapter 1 Domain 1: Design Resilient Architectures
Review Questions
Chapter 2 Domain 2: Define Performant Architectures
Review Questions
Chapter 3 Domain 3: Specify Secure Applications and Architectures
Review Questions
Chapter 4 Domain 4: Design Cost-Optimized Architectures
Review Questions
Chapter 5 Domain 5: Define Operationally Excellent Architectures
Review Questions
Chapter 6 Practice Test
Appendix Answers to Review Questions
Domain 1: Design Resilient Architectures
Domain 2: Define Performant Architectures
Domain 3: Specify Secure Applications and Architectures
Domain 4: Design Cost-Optimized Architectures
Domain 5: Define Operationally Excellent Architectures
Practice Test
Index
WILEY END USER LICENSE AGREEMENT
iii
iv
v
vii
ix
xv
xvi
xvii
xviii
xix
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
Congratulations on your purchase of the AWS Certified Solutions Architect Practice Tests. This book will serve as a preparation tool for the Amazon Web Services (AWS) Certified Solutions Architect (CSA) – Associate exam as well as help you in the development of your career as an AWS Solutions Architect.
The objective of this book is to prepare you for the AWS Certified Solutions Architect – Associate exam by explaining the terminology and technology that will be tested on the exam. The main focus of this book is to help you pass the exam. Because of this focus, there are times when not every aspect of a piece of AWS technology is covered and other times when particularly unusual edge cases or details are emphasized. These are an effort to prepare you for the exam, which at times is not always perfectly aligned with the practicality of a real-world cloud architect.
That said, learning these odd details and edge cases will still come in handy in your career. The exam is largely use-case based, and often the answer bank has lots of “good” answers and one “best” answer. Additionally, these answers commonly have invalid or made-up terms. Learning the odd details about AWS will help you weed through these inaccuracies and throw out invalid answers.
AWS has become one of the most common requirements for job applicants. However, with many organizations moving to AWS for the first time or hiring their first AWS cloud engineers or solution architects, it’s not easy to figure out to whom it’s worth paying those large engineering salaries. A certification from AWS can often be the credential that helps your resume, application, and experience rise above competitors. This is particularly true when you are being interviewed and evaluated by management, where certification is an easy distinguisher.
Additionally, certification makes you more competitive and employable in general. Research has shown that people who study technology get hired. In the competition for entry-level jobs, applicants with high school diplomas or college degrees who included IT coursework in their academic load fared consistently better in job interviews and were hired in significantly higher numbers.
Review the candidate overview and exam goals. AWS provides a lot of detail on the exam, and in particular what qualifications a candidate for the exam should have:
https://aws.amazon.com/certification/certified-solutions-architect-associate/
Review the exam guide. AWS provides an exam guide with the domains covered by the exam and the question breakdown:
https://d1.awsstatic.com/training-and-certification/docs-sa-assoc/ AWS_Certified_Solutions_Architect_Associate_Feb_2018_%20Exam_Guide_v1.5.2.pdf
This URL changes at times. You can always visit the candidate overview (the URL is listed earlier) and find links to the latest exam guide.
Practice for the exam. After you have studied for the certification, review and answer as many sample questions as you can to prepare for the exam.
Schedule your voucher. When you’re ready, you can schedule and pay for your exam:
https://www.aws.training/certification?src=arc-assoc
Take the exam! You’ll take your exam at a testing center in a controlled environment.
Get an instant result. You’ll receive notification of whether you pass or fail immediately after completing the exam. You’ll only receive that level of detail, though: PASS or FAIL.
Wait for your official results. Within a few days, you’ll receive email confirmation of your results as well as a more detailed breakdown of your scores organized by domain. You will not receive details about which questions you missed, though.
Go get a job! (And stay certified too). Once you’ve passed, you’ll receive a certificate and digital badges and you can include your certification on your resume. You can also download certification transcripts from AWS. You’ll need to take the exam again every two years, but that should leave you plenty of time to add significant practical experience to your certification.
Once you are fully prepared to take the exam, you can visit the AWS certification site to schedule and pay for your exam:
https://www.aws.training/certification?src=arc-assoc
AWS partners with PSI Exams (https://candidate.psiexams.com), so when you schedule your exam, you’ll locate a testing center for taking the exam as well as a time block. Exams typically take two hours, so you’ll need to plan accordingly.
On the day of the test, make sure you arrive 10 minutes early in case there are any hiccups or a long line of folks waiting to take the exam. You’ll need two forms of identification too. Remember that you will not be able to take your notes, electronic devices (including smartphones and watches), or other materials in with you.
The testing center will provide you with some scratch paper, and most centers will supply headphones or earplugs if you find it helpful to block out the minimal noise of the testing center. The test itself is taken on a computer and is fairly straightforward.
Make sure you double-check that you complete the exam before leaving; as silly as it sounds, it’s rather easy to get nervous or anxious and not click through all the prompts at the end of the exam.
This book includes 1,000 practice test questions, which will help you get ready to pass the CSA Associate exam. The interactive online learning environment that accompanies the CSA Associate practice tests provides a large and varied test bank to help you prepare for the certification exam and increase your chances of passing the first time. There’s a tremendous value in taking practice questions as often as possible, even leading up to your actual test. Don’t worry if you start to recognize questions from earlier practice runs… that just means you’re learning the material and committing it to memory.
The test bank also includes a practice exam. Take the practice exams just as if you were taking the actual exam (without any reference material). As a general rule, you should be consistently making 85% or better before taking the exam.
You can access the AWS CSA Interactive Online Test Bank at www.wiley.com/go/sybextestprep.
The AWS Certified Solutions Architect – Associate exam validates your technical expertise in two key areas:
Taking customer requirements and defining an appropriate solution at the architecture level using AWS design principles
Providing guidance on implementation based on best practices that go beyond initial design and cover troubleshooting, optimization, and cost considerations
While the exam guide suggests a year of AWS experience, you’ll most benefit from working extensively with the AWS console and setting up new infrastructure, especially related to compute (EC2), storage (RDS, DynamoDB, and S3), and networking (VPCs).
The actual exam is organized into five different domains, each focusing on a specific objective, with each domain broken up further into subobjectives:
Chapter 1, Design Resilient Architectures (Domain 1) Choose reliable and resilient storage; determine how to design decoupling mechanisms using AWS services; determine how to design a multi-tier architecture solution; determine how to design high availability and/or fault tolerant architectures.
Chapter 2, Define Performant Architectures (Domain 2) Choose performance storage and databases; apply caching to improve performance; design solutions for elasticity and scalability.
Chapter 3, Specify Secure Applications and Architectures (Domain 3) Determine how to secure application tiers; determine how to secure data; define the networking infrastructure for a single VPC application.
Chapter 4, Design Cost-Optimized Architectures (Domain 4) Determine how to design cost-optimized storage; determine how to design cost-optimized compute.
Chapter 5, Define Operationally Excellent Architectures (Domain 5) Choose design features in solutions that enable operational excellence.
The following table lists each of the five domains and how much of the exam each domain affects. The subdomains are also listed for each domain. Because each chapter of this book focuses on a specific domain, the mapping is easy: for Domain 1, refer to Chapter 1. For Domain 2, flip to Chapter 2, and so on.
Domain
Percentage of Exam
Chapter
Domain 1. Design Resilient Architectures
34%
1
1.1 Choose reliable/resilient storage.
1.2 Determine how to design decoupling mechanisms using AWS services.
1.3 Determine how to design a multi-tier architecture solution.
1.4 Determine how to design high availability and/or fault tolerant architectures.
Domain 2. Define Performant Architectures
24%
2
2.1 Choose performant storage and databases.
2.2 Apply caching to improve performance.
2.3 Design solutions for elasticity and scalability.
Domain 3. Specify Secure Applications and Architectures
26%
3
3.1 Determine how to secure application tiers.
3.2 Determine how to secure data.
3.3 Define the networking infrastructure for a single VPC application.
Domain 4. Design Cost-Optimized Architectures
10%
4
4.1 Determine how to design cost-optimized storage.
4.2 Determine how to design cost-optimized compute.
Domain 5. Define Operationally Excellent Architectures
6%
5
5.1 Choose design features in solutions that enable operational excellence.
✓ Subdomain: 1.1 Choose reliable/resilient storage.
✓ Subdomain: 1.2 Determine how to design decoupling mechanisms using AWS services.
✓ Subdomain: 1.3 Determine how to design a multi-tier architecture solution.
✓ Subdomain: 1.4 Determine how to design high availability and/or fault tolerant architectures.
Which of the following statements regarding S3 storage classes is true?
The availability of S3 and S3-IA is the same.The durability of S3 and S3-IA is the same.The latency of S3 and Glacier is the same.The latency of S3 is greater than that of Glacier.A small business specializing in video processing wants to prototype cloud storage in order to lower its costs. However, management is wary of storing its client files in the cloud rather than on premises. They are focused on cost savings and experimenting with the cloud at this time. What is the best solution for their prototype?
Install a VPN, set up an S3 bucket for their files created within the last month, and set up an additional S3-IA bucket for older files. Create a lifecycle policy in S3 to move files older than 30 days into the S3-IA bucket nightly.Install an AWS storage gateway using stored volumes.Set up a Direct Connect and back all local hard drives up to S3 over the Direct Connect nightly.Install an AWS storage gateway using cached volumes.You have a group of web designers who frequently upload large zip files of images to S3, often in excess of 5 GB. Recently, team members have reported that they are receiving the error “Your proposed upload exceeds the maximum allowed object size.” What action should you take to resolve the upload problems?
Increase the maximum allowed object size in the target S3 bucket used by the web designers.Ensure that your web designers are using applications or clients that take advantage of the Multipart Upload API for all uploaded objects.Contact AWS and submit a ticket to have your default S3 bucket size raised; ensure that this is also applied to the target bucket for your web designers’ uploads.Log in to the AWS console, select the S3 service, and locate your bucket. Edit the bucket properties and increase the maximum object size to 50 GB.For which of the following HTTP methods does S3 have eventual consistency? (Choose two.)
PUTs of new objectsUPDATEsDELETEsPUTs that overwrite existing objectsWhat is the smallest file size that can be stored on standard class S3?
1 byte1 MB0 bytes1 KBYou’ve just created a new S3 bucket named ytmProfilePictures in the US East 2 region. You need the URL of the bucket for some programmatic access. What is the correct bucket URL?
https://s3-us-east-2.amazonaws.com/ytmProfilePictureshttps://s3-east-2.amazonaws.com/ytmProfilePictureshttps://s3-us-east-2-ytmProfilePictures.amazonaws.com/https://amazonaws.s3-us-east-2.com/ytmProfilePicturesYou’ve just created a new S3 bucket named ytmProfilePictures in the US East 2 region and created a folder at the root level of the bucket called images/. You’ve turned on website hosting and asked your content team to upload images into the images/ folder. At what URL will these images be available through a web browser?
https://s3-us-east-2.amazonaws.com/ytmProfilePictures/imageshttps://s3-website-us-east-2.amazonaws.com/ytmProfilePictures/imageshttps://ytmProfilePictures.s3-website-us-east-2.amazonaws.com/imageshttps://ytmProfilePictures.s3-website.us-east-2.amazonaws.com/imagesWhich of the following statements is true?
The durability of S3 and S3-IA is the same.The availability of S3 and S3-IA is the same.The durability of S3 is greater than that of Glacier.The durability of S3 is greater than that of S3-IA.Which of the following statements is not true?
Standard S3, S3-IA, and S3 One Zone-IA all are equally durable.The availability of S3-IA and S3 One Zone-IA are identical.Standard S3, S3-IA, and S3 One Zone-IA all have different availabilities.S3 One Zone-IA is as durable as standard S3.Which of the following AWS services appear in the AWS console across all regions? (Choose two.)
S3EC2IAMRDSAmazon’s EBS volumes are ____________. (Choose two.)
Block-based storageObject-based storageBased on magnetic disk by defaultAvailable in a variety of SSD and magnetic optionsYou have spent several days of your last DevOps sprint building an AMI upon which all instances of your development team’s application should reside. The application will be deployed into multiple regions and interact with multiple S3 buckets, and you now need the new AMI in us-east-2 and us-west-2, in addition to us-east-1, where you created the AMI. How can you make the new AMI available in us-east-2 and us-west-2?
Copy the AMI from us-east-1 to us-east-2 and us-west-2. Launch the new instances using the copied AMI.Ensure that all application instances share a security group. AMIs are available to all instances within a security group, regardless of the region in which the AMI was created.You can immediately launch the AMI, as all AMIs appear in all regions through the AWS console.Copy the AMI from us-east-1 to us-east-2 and us-west-2. Apply launch permissions and S3 bucket permissions and then launch new instances using the updated AMI.You have an S3 bucket and are working on cost estimates for your customer. She has asked you about pricing of objects stored in S3. There are currently objects in the buckets ranging from 0 bytes to over 1 GB. In this situation, what is the smallest file size that S3-IA will charge you for?
1 byte1 MB0 bytes128 KBYou have been tasked with ensuring that data stored in your organization’s RDS instance exists in a minimum of two geographically distributed locations. Which of the following solutions are valid approaches? (Choose two.)
Enable RDS in a Multi-AZ configuration.Enable RDS in a read replica configuration.Install a storage gateway with stored volumes.Enable RDS in a cross-region read replica configuration.Which of the following items are included in an Auto Scaling Launch Configuration? (Choose two.)
The AMI to use for creating new instancesThe EBS storage volume for the instances to createThe polling time for monitoring network latencyThe IAM role to associate with created instancesWhich of the following would you use for setting up AMIs from which new instances are created in an Auto Scaling policy?
The Auto Scaling policy itselfThe security group for the Auto Scaling policyThe Auto Scaling group used by the Auto Scaling policyThe launch configuration used by the Auto Scaling policyYou terminate an EC2 instance and find that the EBS root volume that was attached to the instance was also deleted. How can you correct this?
You can’t. A root volume is always deleted when the EC2 instance attached to that volume is deleted.Take a snapshot of the EBS volume while the EC2 instance is running. Then, when the EC2 instance is terminated, you can restore the EBS volume from the snapshot.Remove termination protection from the EC2 instance.Use the AWS CLS to change the DeleteOnTermination attribute for the EBS volume to “false.”In what manner are EBS snapshots backed up to S3?
Via full backup according to the backup policy set on the volumeIncrementallySynchronouslyEBS volumes are not stored on S3.Can you attach an EBS volume to more than one EC2 instance at the same time?
Yes, as long as the volume is not the root volume.No, EBS volumes cannot be attached to more than one instance at the same time.Yes, as long as the volume is one of the SSD classes and not magnetic storage.Yes, as long as at least one of the instances uses the volume as its root volume.How does AWS allow you to add metadata to your EC2 instances? (Choose two.)
CertificatesTagsPoliciesLabelsWhich of the following are valid criteria for determining which region to choose for your S3 buckets? (Choose two.)
The distance between the region and your user baseThe distance between the region and your on-premises operationsThe distance between the region and other regions in your AWS accountThe distance between the region and your development teamWhere are individual EC2 instances provisioned?
In a specific regionIn a specific availability zoneIn a random availability zone within a specified regionIt depends upon the region.Which of the following can be deployed across availability zones?
Cluster placement groupsPlacement groupsSpread placement groupsCross-region placement groupsWhich of the following services is used at an on-premises site to build a site-to-site VPN connection?
Storage gatewayVirtual private gatewayCustomer gatewayVirtual private networkWhat is the anchor on the AWS side of a site-to-site VPN connection between an on-premises site and AWS?
IPSec tunnelVirtual private gatewayCustomer gatewayVPCHow many tunnels for network traffic are involved when a customer gateway connects to an AWS VPC via an AWS-managed VPN connection?
OneTwoThreeIt depends on the settings in the AWS VPC.Choose the correct order in which traffic flows from an on-premises site to a VPC within AWS when a VPN connection is used.
Customer gateway to Amazon VPC to virtual private gatewayVirtual private gateway to customer gateway to Amazon VPCAmazon VPC to customer gateway to virtual private gatewayCustomer gateway to virtual private gateway to Amazon VPCYou are setting up a site-to-site VPN from an on-premises network into an AWS VPC. Which of the following are steps you may need to perform? (Choose two.)
Set up a public IP address for the customer gateway.Set up a public IP address for the AWS VPC.Set up a public IP address for the virtual private gateway.Set up a public IP address for the VPN tunnels.Which of the following services is used at an on-premises site to connect to cloud-based storage?
Storage gatewayVirtual private gatewayCustomer gatewayVirtual private networkWhich of the following are valid options for storage gateways? (Choose two.)
File gatewayVolume gatewayCached gatewayVirtual private gatewayYou are tasked with recommending a storage solution for a large company with a capital investment in an NFS-based backup system. The company wants to investigate cloud-based storage but doesn’t want to lose its software investment either. Which type of storage gateway would you recommend?
File gatewayCached volume gatewayStored volume gatewayTape gatewayYou are helping a medium-sized business migrate its large datasets to the cloud. However, the business has limited resources and has long used a tape backup system. It does not want to lose the investment in the software and systems that already have been configured to use this backup system. Which storage gateway would you recommend?
File gatewayCached volume gatewayStored volume gatewayTape gatewayYou are tasked with prototyping a cloud-based storage solution for a small business. The business’s chief concern is low network latency, as its systems need near-instant access to all of its datasets. Which storage gateway would you recommend?
File gatewayCached volume gatewayStored volume gatewayTape gatewayYou are the solutions architect for a mapping division that has inherited a massive geospatial dataset from a recent acquisition. The data is all on local disk drives, and you want to transition the data to AWS. With datasets of over 10 TB, what is the best approach to getting this data into AWS?
S3 with Transfer AccelerationCached volume gatewaySnowballShipping the drives to AWSWhich of the following are not reasons to use a cached volumes storage gateway? (Choose two.)
You want low-latency access to your entire dataset.You want to reduce the cost of on-site storage.You want to support iSCSI storage volumes.You want low-latency access to your most commonly accessed data.Which of the following storage gateway options is best for traditional backup applications?
File gatewayCached volume gatewayStored volume gatewayTape gatewayWhich of the following storage gateway options is best for applications where latency of specific portions of your entire dataset is the priority?
File gatewayCached volume gatewayStored volume gatewayTape gatewayWhich of the following storage gateway options is best for applications where latency of your entire dataset is the priority?
File gatewayCached volume gatewayStored volume gatewayTape gatewayWhich of the following storage gateway options is best for reducing the costs associated with an off-site disaster recovery solution?
File gatewayCached volume gatewayStored volume gatewayTape gatewayWhich of the following storage classes is optimized for long-term data storage at the expense of retrieval time?
S3S3-IAS3 One Zone-IAGlacierWhich of the following need to be considered across all regions in your account? (Choose two.)
Launch configurationsIAM usersEC2 instancesS3 bucket namesWhat HTTP code would you expect after a successful upload of an object to an S3 bucket?
HTTP 200HTTP 307HTTP 404HTTP 501What is the durability of S3 One Zone-IA?
99.0%99.9%99.99%99.999999999%What is the durability of S3-IA?
99.0%99.9%99.99%99.999999999%What is the durability of S3?
99.0%99.9%99.99%99.999999999%What is the availability of S3 One Zone-IA?
99.5%99.9%99.99%99.999999999%What is the availability of S3-IA?
99.5%99.9%99.99%99.999999999%What is the availability of S3?
99.5%99.9%99.99%99.999999999%Which S3 storage class supports SSL for data in transit?
S3S3-IAS3 One Zone-IAAll of the aboveWhich S3 storage class supports encryption for data at rest?
S3S3-IAS3 One Zone-IAAll of the aboveFor which of the following storage classes do you need to specify a region?
S3S3-IAS3 One Zone-IAAll of the aboveFor which of the following storage classes do you need to specify an availability zone?
S3S3-IAS3 One Zone-IANone of the aboveHow does S3 store your objects?
As key-value pairsAs relational entries.Using a NoSQL interfaceAs blocks in a block storageIn what ways can you access your data stored in S3 buckets? (Choose two.)
Through FTP access to the bucketThrough SFTP access to the bucketThrough a REST-based web service interfaceThrough the AWS consoleWhich of the following are true about S3 data access when traffic spikes (increases)? (Choose two.)
S3 will scale to handle the load if you have Auto Scaling set up.S3 will scale automatically to ensure your service is not interrupted.Scale spreads evenly across AWS network to minimize the effect of a spike.A few instances are scaled up dramatically to minimize the effect of the spike.You have been tasked with helping a company migrate its expensive off-premises storage to AWS. It will still primarily back up files from its on-premises location to a local NAS. These files then need to be stored off-site (in AWS rather than the original off-site location). The company is concerned with durability and cost and wants to retain quick access to its files. What should you recommend?
Copying files from the NAS to an S3 standard class bucketCopying files from the NAS to an S3 One Zone-IA class bucketCopying the files from the NAS to EBS volumes with provisioned IOPSCopying the files from the NAS to Amazon GlacierWhich S3 storage class would you recommend if you were building out storage for an application that you anticipated growing in size exponentially over the next 12 months?
Amazon GlacierS3 standardS3-IAThere is not enough information to make a good decision.How many S3 buckets can you create per AWS account, by default?
2550100There is not a default limit.How are objects uploaded to S3 by default?
In partsIn a single operationYou must configure this option for each S3 bucket explicitly.Via the REST APIWhen does AWS suggest you start uploading objects via the Multipart Upload API?
When you’re uploading a lot of files at onceWhen you’re uploading files of 10 GB or moreWhen you have multiple applications uploading files to the same S3 bucketWhen you need the greatest network throughput for uploadsWhich of the following are the ways you should consider using Multipart Upload?
For uploading large objects over a stable high-bandwidth network to maximize bandwidthFor uploading large objects to reduce the cost of ingress related to those objectsFor uploading any size files over a spotty network to increase resiliencyFor uploading files that must be appended to existing filesHow is a presigned URL different from a normal URL? (Choose two.)
A presigned URL has permissions associated with certain objects provided by the creator of the URL.A presigned URL has permissions associated with certain objects provided by the user of the URL.A presigned URL allows access to private S3 buckets without requiring AWS credentials.A presigned URL includes encrypted credentials as part of the URL.Which of the following can be put behind a presigned URL?
An S3 object storeAn EC2 instance with a web interfaceAn AWS CloudFront distributionAll of the aboveHow long is a presigned URL valid?
60 seconds60 minutes24 hoursAs long as it is configured to lastWhich of the following HTTP methods with regard to S3 have eventual consistency? (Choose two.)
UPDATEsDELETEsPUTs of new objectsOverwrite PUTsWhich of the following behaviors is consistent with how S3 handles object operations on a bucket?
A process writes a new object to Amazon S3 and immediately lists keys within its bucket. The new object does not appear in the list of keys.A process deletes an object, attempts to immediately read the deleted object, and S3 still returns the deleted data.A process deletes an object and immediately lists the keys in the bucket. S3 returns a list with the deleted object in the list.All of the aboveIn which regions does Amazon S3 offer eventual consistency for overwrite PUTs and DELETEs?
All US regionsAll US and EU regionsAll regionsNo regions, eventual consistency is not the model for overwrite PUTs.Which of the following storage media are object based? (Choose two.)
S3-IAEBSEFSS3 standardEBS stands for what?
Elastic Based StorageElastic Block StorageExtra Block StorageEphemeral Block StorageWhat is the consistency model in S3 for PUTs of new objects?
Write after read consistencyRead after write consistencyEventual consistencySynchronous consistencyHow many PUTs per second does S3 support?
100150035005000You have been asked to create a new S3 bucket with the name prototypeBucket32 in the US West region. What would the URL for this bucket be?
https://s3-us-east-1.amazonaws.com/prototypeBucket32https://s3-us-west-1.amazonaws.com/prototypeBucket32https://s3.prototypeBucket32-us-east-1.amazonaws.com/https://s3-prototypeBucket32.us-east-1.amazonaws.com/What unique domain name do S3 buckets created in US East (N. Virginia) have, as compared to other regions?
s3.amazonaws.coms3-us-east-1.amazonaws.coms3-us-east.amazonaws.coms3-amazonaws.comWhich of the following are valid domain names for S3 buckets? (Choose two.)
s3.us-east-1.amazonaws.coms3-us-west-2.amazonaws.coms3.amazonaws.coms3-jp-west-2.amazonaws.comWhat are the two styles of URLs that AWS supports for S3 bucket access? (Choose two.)
Virtual-hosted-style URLsDomain-hosted-style URLsApex zone record URLsPath-style URLsWhich of the following are valid URLs for accessing S3 buckets? (Choose two.)
https://s3-us-west-1-prototypeBucket32.amazonaws.com/https://s3-us-west-1.amazonaws.com/prototypeBucket32https://s3-mx-central-1.amazonaws.com/prototypeBucket32https://prototypeBucket32.s3-us-west-1.amazonaws.comWhat is an AWS storage gateway?
A device to reside at a customer site that is part of a VPN connection between an on-premises site and AWSA device that enables an on-premises site to upload files to S3 faster than over the public InternetA device to facilitate large data migrations into S3A device that can be used to cache S3-stored objects at an on-premises siteWhich of the following statements is not true about an AWS storage gateway?
It is a virtual appliance.It is available as both a physical and virtual appliance.It caches data locally at a customer site.It interacts with S3 buckets.Which of the following are not true about S3? (Choose two.)
Buckets are created in specific regions.Bucket names exist in a per-region namespace.Buckets are object-based.Each S3 bucket stores up to 5 TB of object data.Which of the following consistency models are supported by S3? (Choose two.)
Read after write consistencySynchronous consistencyWrite after read consistencyEventual consistencyEvery object in S3 has a ____________. (Choose two.)
KeyValueBoth A and BVersion IDWhich of the following is the best approach to ensuring that objects in your S3 buckets are not accidentally deleted?
Restrictive bucket permissionsEnabling versioning on bucketsEnabling MFA Delete on bucketsAll of these options are equally useful.What HTTP request header is used by MFA Delete requests?
x-deletex-amz-mfax-aws-mfax-amz-deleteWhich of the following operations will take advantage of MFA Delete, if it is enabled? (Choose two.)
Deleting an S3 bucketChanging the versioning state of a bucketPermanently deleting an object versionDeleting an object’s metadataWhen using an MFA Delete–enabled bucket to delete an object, from where does the authentication code come?
A hardware or virtual MFA deviceThe token section of the AWS consoleThe AWS REST API under delete-codes in a bucket’s metadataNone of theseWho can enable MFA Delete on an S3 bucket?
All authorized IAM users of the bucketAll authorized IAM users that can update the bucketThe bucket ownerThe root account that owns the bucketWho can enable versioning on an S3 bucket?
All authorized IAM users of the bucketA, C, and DThe bucket ownerThe root account that owns the bucketWhich of the following exist and are attached to an object stored in S3? (Choose two.)
MetadataDataAuthentication IDVersion historyWhich of the following is the AWS mechanism for adding object metadata using the AWS console?
LabelsTagsMetadataObject nameWhich of the following is the exception to S3 storing all versions of an object?
When an object is deleted via MFA DeleteWhen all of the versions of an object are deletedWhen an object’s current version is deletedThere are no exceptions.You have an S3 bucket with versioning enabled. How can you turn off versioning?
Update the bucket properties in the AWS console and turn off versioning.Versioning can only be turned off through the AWS CLI or API. Use your application keys to change versioning to “off” on the bucket.Send a message to the S3 bucket using the HTML request header x-amz-versioning and the value of “off.”You can’t turn off versioning once it has been enabled.CloudFront is a web service for distributing what type of content? (Choose two.)
Object-based storageStatic filesScript-generated or programmatically generated dynamic contentAll of the aboveWhat are the sources of information that CloudFront serves data from called?
Service providersSource serversStatic serversOrigin serversWhich of the following are typical origin servers for a CloudFront distribution? (Choose two.)
EC2 instancesAmazon Glacier archivesAPI GatewayS3 bucketsWhich of the following are not origin servers for a CloudFront distribution? (Choose two.)
Docker containers running on ECSMySQL ResultSetS3 bucketsRedshift workloadsWhat is the location where content will be cached in a CloudFront distribution called?
Availability zoneEdge locationRemote locationOrigin edgeWhich of the following are not origin servers for a CloudFront distribution? (Choose two.)
Elastic load balancerRoute 53 recordsetsSQS subscription endpointSNS topic retrieval endpointWhat is a collection of edge locations called?
RegionAvailability zoneCloudFrontDistributionRank the total number of regions, availability zones, and edge locations in order from the least number to the greatest number.
Availability zones < regions < edge locationsRegions < availability zones < edge locationsEdge locations < regions < availability zonesEdge locations < availability zones < regionsWhich of the following statements are true? (Choose two.)
There are more edge locations than availability zones.There are fewer regions than edge locations.There are fewer edge locations than availability zones.Each availability zone has a corresponding edge location.Which of the following store content that is served to users in a CloudFront-enabled web application? (Choose two.)
Availability zonesEdge locationsRoute 53EC2 instancesWhich of the following are true about edge locations? (Choose two.)
Edge locations are readable.Edge locations are read-only.Edge locations are write-only.Edge locations are writable.To which of the following can objects be written? (Choose two.)
Edge locationsEC2 instancesS3 bucketsAvailability zonesWhat does TTL stand for?
Time to LiveTotal Time to LiveTotal traffic lifeTraffic total lifeYou support a web application that uses a CloudFront distribution. A banner ad that was posted the previous night at midnight has an error in it, and you’ve been tasked with removing the ad so that users don’t see the error. What steps should you take? (Choose two.)
Delete the banner image from S3.Remove the ad from the website.Wait for 24 hours and the edge locations will automatically expire the ad from their caches.Clear the cached object manually.By default, how long do edge locations cache objects?
12 hours24 hours48 hours360 minutesWhat is the default visibility of a newly created S3 bucket?
PublicPrivatePublic to registered IAM users of your accountNone of the aboveWhich of the following are valid ways to set up access to your buckets? (Choose two.)
NACLsACLsBucket policiesJSONWhich of the following languages is used for writing bucket policies?
XMLYAMLJSONAMLHow are datasets utilized by stored volumes backed up to S3?
AsynchronouslySynchronouslyThe backup method is specified by the user at configuration time.Synchronously unless the backup takes more than 2 seconds; then the backup switches to asynchronousWhich of the following is equivalent to a tape volume?
VTLVPCNetBackupVPNWhat is Amazon’s petabyte-scale data transport solution?
SnowballGlacierTransfer AccelerationEdge transportWhat language(s) are supported by Snowball?
Perl, PHPJSON, YAMLCloudFormationNone of theseWhen should you use AWS Direct Connect instead of Snowball?
AWS Direct Connect is usually a better option than Snowball.AWS Direct Connect is almost never a better option than Snowball.If you have more than 50 TB of data to transfer, use Snowball.If you have less than 50 TB of data to transfer, use Snowball.What is the difference between Snowball and Snowball Edge?
Snowball is for data transfer; Snowball Edge provides local data processing prior to returning the data to AWS.Snowball Edge is for data transfer; Snowball provides local data processing prior to returning the data to AWS.Snowball and Snowball Edge are both for data transfer, but Snowball Edge offers caching when the data arrives at AWS.Snowball and Snowball Edge are both for data transfer, but Snowball Edge offers additional storage capacity.Which of the following can Snowball do?
Import data into S3 (but not export data)Export data from S3 (but not import data)Import data into S3 and export data from S3Snowball can import data into S3, but only Snowball Edge can export data from S3.What is the main benefit of decoupling an application?
To enforce different security modelsTo enforce different network transport modelsTo reduce interdependencies to isolate failures from an entire applicationTo reduce network connections to improve performanceWhich of the following AWS services provides analytic data warehouse provisioning and tooling?
AuroraElastiCacheDynamoDBRedshiftWhich of the following is a basic principle of fault tolerance in AWS?
Launch instances in separate VPCs.Launch instances in separate regions.Launch instances in separate subnets.Launch instances in edge locations.Which of the following services use AWS edge locations?
CloudFrontCustomer gatewayStorage gatewaySnowballWhich of the following is a benefit of running an application in two availability zones?
It is more secure than running an application in a single availability zone.It is more performant than running an application in a single availability zone.It increases the fault tolerance of running an application in a single availability zone.It decreases the network latency of running an application in a single availability zone.Which of the following AWS services can be used to store files? (Choose two.)
Amazon AthenaS3MySQLEBSWhich of the following AWS services can be used to store large objects? (Choose two.)
RedshiftS3OracleEC2How would you speed up transfers of data to S3?
Use Snowball to transfer large files more quickly.Enable S3 Transfer Acceleration.Configure AWS to use multiple network paths to your S3 bucket.Configure AWS to use an internet gateway for routing traffic to your S3 buckets.What users would benefit most from S3 Transfer Acceleration?
Users geographically closest to your S3 bucketsUsers geographically farthest from your S3 bucketsUsers taking advantage of HTTPS for uploadsAll users equally benefit.Which of the following are good reasons to use S3 Transfer Acceleration? (Choose two.)
You have customers that upload to your buckets from around the world.You have customers complaining about performance of your applications.You transfer gigabytes of data on a regular basis across continents.You are seeing network latency in uploads to your S3 buckets.Which services can you use to host websites? (Choose two.)
EC2Elastic Load BalancingS3GlacierYou have a bucket called newyorkhotdogs in US West 1. You have enabled static website hosting on this bucket and want to provide its URL to beta customers. What URL should you provide?
http://newyorkhotdogs.s3-website.us-west-1.amazonaws.comhttps://s3-us-west-1.amazonaws.com/newyorkhotdogshttp://newyorkhotdogs.s3-website-us-west-1.amazonaws.comhttp://newyorkhotdogs.s3-website.us-east-1.amazonaws.comYou have created a static website and posted an HTML page as home.html in the root level of your S3 bucket. The bucket is named californiaroll and is located in US West 2. At what URL can you access the HTML page?
http://californiaroll.s3-website.us-west-1.amazonaws.com/home.htmlhttp://s3-website-us-west-1.amazonaws.com/californiaroll/home.htmlhttp://californiaroll.s3-website-us-west-2.amazonaws.com/public_html/home.htmlhttp://californiaroll.s3-website-us-west-1.amazonaws.com/home.htmlYou have a variety of images with names like image-001.jpg and image-002.jpg in an S3 bucket named phoneboothPhotos created in the EU West 1 region. You have enabled website hosting on this bucket. Which URL would allow access to the photos?
http://phoneboothPhotos.s3-website-eu-west-1.amazonaws.com/ phoneboothPhotos/image-001.jpghttp://phoneboothPhotos.s3-website-eu-west-1.amazonaws.com/ phoneboothphotos/image-001.jpghttp://phoneboothPhotos.s3-website-eu-west-1.amazonaws.com/ public_html/phoneboothPhotos/image-001.jpghttp://phoneboothPhotos.s3-website.eu-west-1.amazonaws.com/ phoneboothPhotos/image-001.jpgYou have your own custom domain and want to host a static website on that domain. You also want to minimize compute costs. Which of the following AWS services would you use to host your website on your custom domain? (Choose two.)
S3EC2LambdaRoute 53You have your own custom domain and want to host a dynamic website on that domain. You also want to minimize compute costs. Which of the following AWS services would you use to host your website on your custom domain? (Choose two.)
S3EC2LambdaRoute 53Which of the following provide capability for serverless websites? (Choose two.)
S3EC2LambdaRoute 53Which of the following provide capability for dynamic websites? (Choose two.)
S3EC2LambdaRoute 53Which of the following does Elastic Beanstalk provide? (Choose two.)
Deployment of codeSecurityCapacity provisioningCost optimizationWhich of the following does Elastic Beanstalk not provide? (Choose two.)
Deployment of codeSecurity hardeningApplication health monitoringLog inspection and backupWhich of the following does Elastic Beanstalk support? (Choose two.)
DockerC++ScalaNode.jsWhich of the following application types does Elastic Beanstalk support?
Node.jsJavaPythonAll of the aboveWhich of the following database technologies does Elastic Beanstalk support? (Choose two.)
All AWS-supported RDS optionsDynamoDBOracle running on EC2RedshiftHow do you convert application code managed by Elastic Beanstalk from test to production?
Update the codebase to use a production-driven CloudFormation file.Update the database connection string in your application code.Set the Elastic Beanstalk environment to use your production database in that particular environment’s Elastic Beanstalk configuration.You cannot deploy to production using Elastic Beanstalk.Which AWS service allows you to run code without provisioning any of the underlying resources required by that code?
EC2ECSDynamoDBLambdaWhich of the following AWS services allow you to run code without worrying about provisioning specific resources for that code? (Choose two.)
Elastic BeanstalkECSDynamoDBLambdaDo Lambda functions run on servers?
Yes, they automatically spin up an EC2 instance as needed without user intervention.Yes, you must provide an existing EC2 instance to run on.No, Lambda code runs purely in the cloud without a server involved.No, Lambda code runs in a container.Which of the following languages work on Lambda? (Choose two.)
JavaScriptNode.jsScalaC++Which of the following are reasons to use Lambda versus EC2? (Choose two.)
You need to install Oracle and want to avoid compute costs.Your code primarily responds to events from other AWS services.Your primary concern is scaling.You want to deploy your own Docker containers.What AWS service converts media files to formats suitable for different sized devices?
Elastic TranscoderSWFLightsailElastic BeanstalkWhat AWS service is ideal for gathering business intelligence from multiple data sources?
LightsailQuickSightCloudTrailRDSWhat is AWS’s system for sending out alerts and alarms based on specific events in an environment?
SQSSNSSWFCloudTrailWhich service would you use to create a single-sign on system for a user base that already has credentials they want to use outside of AWS?
CognitoKinesisSWFIAMWhat does an AWS region consist of?
A collection of virtual data centers spread across a continentA collection of virtual data centers spread across a specific geographic areaA collection of virtual servers spread across a continentA collection of virtual databases spread across a specific geographic areaWhat type of services are associated with an AWS VPC?
Storage servicesDatabase servicesCompute servicesNetworking servicesWhat type of services are associated with ECS?
Storage servicesDatabase servicesCompute servicesNetworking servicesWhat type of services are associated with RDS?
Storage servicesDatabase servicesCompute servicesNetworking servicesWhat type of services are associated with Route 53?
Storage servicesDatabase servicesCompute servicesNetworking servicesWhat type of services are associated with a customer gateway?
Storage servicesDatabase servicesCompute servicesNetworking servicesWhat type of services are associated with S3 lifecycle management?
Storage servicesDatabase servicesCompute servicesNetworking servicesWhat type of services are associated with Amazon Lightsail?
Storage servicesNetworking servicesCompute servicesAll of the aboveWhat type of services are associated with Elastic Beanstalk?
Storage servicesNetworking servicesCompute servicesAll of the aboveWhat type of services are associated with EFS?
Storage servicesNetworking servicesCompute servicesAll of the aboveWhat type of services are associated with Redshift?
Storage servicesNetworking servicesDatabase servicesAll of the aboveWhat type of services are associated with CloudFront?
Storage servicesNetworking servicesCompute servicesBoth B and CWhat type of services are associated with Amazon Athena?
Storage servicesNetworking servicesCompute servicesAnalytic servicesWhat type of services are associated with EMR?
Storage servicesAnalytic servicesCompute servicesNetworking servicesWhat type of services are associated with Cloud9?
Storage servicesAnalytic servicesDeveloper servicesNetworking servicesWhat type of services are associated with Direct Connect?
Storage servicesAnalytic servicesDeveloper servicesNetworking servicesWhat type of services are associated with Workspaces?
Mobile servicesAnalytic servicesDeveloper servicesDesktop servicesWhat type of services are associated with Kinesis?
Mobile servicesAnalytic servicesDeveloper servicesDesktop servicesWhat type of services are associated with Elastic Transcoder?
Mobile servicesAnalytic servicesMedia servicesDesktop servicesWhat type of services are associated with OpsWorks?
Mobile servicesAnalytic servicesMedia servicesManagement servicesWhat type of services are associated with Lex?
Machine learning servicesAnalytic servicesMedia servicesManagement servicesWhich service is best suited for monitoring the performance of your compute instances?
CloudWatchCloudTrailOpsWorksConfigWhat is an availability zone?
A virtual data centerA geographical area with redundancy within that area for compute, networking, and storage serviceA distinct location within AWS designed to be isolated from failuresBoth A and CWhat is a region?
A virtual data centerA geographical area with redundancy within that area for compute, networking, and storage serviceA distinct location within AWS designed to be isolated from failuresBoth A and CWhich of the following statements do not describe a region? (Choose two.)
A region is an area with specific AWS managed services (compute, networking, storage, etc.).A region is a virtual data center with built-in redundancy.A region is a collection of availability zones for redundancy.A region is a geographic area with at least two virtual data centers.