All practice questions
1473 questions
A healthcare startup stores encrypted patient records in a private Amazon S3 bucket in its production AWS account. An internal compliance officer (an IAM user in the same account) requires read-only access to these records for auditing. Simultaneously, an automated diagnostic application running in an external partner's AWS account must upload new patient reports directly to the same bucket. The startup's security policy prohibits sharing credentials or setting up cross-account identity federation. Which of the following configurations represents the most secure, AWS-recommended approach to grant the required access?
A company is designing an online retail platform on AWS and wants to ensure that a failure in the payment processing component does not disrupt the product browsing or shopping cart services. Which of the following design choices follow AWS Cloud design principles to achieve this requirement? (Select TWO.)
Select all that apply
A global logistics company needs to evaluate its cloud environment against the Federal Risk and Authorization Management Program (FedRAMP) requirements. The company must obtain official AWS compliance documents and verify which AWS services are compliant under the FedRAMP authorization boundary. Which of the following two actions should the company take to meet these requirements? (Select TWO.)
Select all that apply
A real estate agency, ApexHomes, is migrating its legacy on-premises customer relationship management (CRM) system to the AWS Cloud. The agency decides to decommission the custom legacy software and transition to a commercially available Software-as-a-Service (SaaS) CRM platform obtained through the AWS Marketplace. Which cloud migration strategy is ApexHomes using?
A company uses Amazon Route 53 to host and manage its domain name system (DNS) records. Under the AWS Shared Responsibility Model, which of the following tasks is the customer's responsibility?
A municipal agency is planning to host citizen records on AWS. The agency's compliance team needs to obtain AWS SOC 3 reports and sign a Business Associate Addendum (BAA) with AWS. Which of the following options represent the correct service and action to meet these requirements? (Select TWO.)
Select all that apply
A logistics provider, GlobalCargo Logistics, is evaluating its application portfolio to migrate to the AWS Cloud. The migration team has identified two specific workloads:
1. A legacy shipping optimization application running on-premises. The company wants to migrate this application to AWS with minimal modifications, but intends to move the self-managed database to Amazon RDS for Oracle to reduce administrative overhead.
2. A proprietary, monolithic billing application. The company wants to decompose this monolith into a serverless, microservices-based architecture using AWS Lambda and Amazon DynamoDB to maximize scalability and reduce operational costs.
Which migration strategies should GlobalCargo Logistics use for these workloads? (Select TWO.)
Select all that apply
An agricultural technology firm, GreenGrow Solutions, is migrating its legacy inventory tracking system to the AWS Cloud. The system consists of a web server and a self-managed PostgreSQL database currently running on-premises. To minimize application code modifications, the team decides to migrate the web server to Amazon EC2 without changes. However, they decide to move the database to Amazon Relational Database Service (Amazon RDS) for PostgreSQL to eliminate database administration tasks like patching and backups. Which migration strategy is GreenGrow Solutions applying to the database tier?
An online education platform hosts its virtual classroom application on Amazon EC2 instances. To ensure that the platform remains highly available even if an entire data center experiences a power outage, the platform's architecture deploys EC2 instances across multiple Availability Zones behind an Application Load Balancer. Which AWS Cloud design principle is directly represented by this setup?
A company is conducting a security audit of its AWS infrastructure. The audit reveals that the IT team uses the AWS account root user for daily configuration tasks, and several application servers use embedded long-term AWS access keys to write data to Amazon S3. Which of the following actions should the company take to align with AWS Identity and Access Management (IAM) security best practices? (Select TWO.)
Select all that apply
StayBooker, a hotel reservation platform, is planning to migrate its applications to the AWS Cloud. The migration team has identified two specific workloads:
1. An on-premises employee payroll processing application that they want to completely replace with a commercial cloud-hosted software-as-a-service (SaaS) subscription.
2. A legacy mainframe application that cannot be migrated to the cloud at this time due to complex hardware dependencies, which they must keep running in their on-premises environment.
Which two of the following migration strategies represent the correct approach for these workloads?
Select all that apply
A startup is preparing for a security audit and needs to download official AWS compliance documentation. Which AWS service provides on-demand access to AWS security and compliance reports, such as Service Organization Control (SOC) reports and ISO certifications?
An energy technology provider is migrating its financial billing system to AWS. The company's compliance department needs to obtain a confidential AWS System and Organization Controls (SOC) 1 Type II report to prove to their external auditors that the AWS infrastructure controls are operating effectively. Which AWS resource should the company use to locate, accept the terms of, and download this report?
A mobile gaming startup is deploying a high-throughput, low-latency leaderboard and player session store using Amazon ElastiCache for Redis. The startup needs to secure this environment to protect user session tokens from unauthorized external access while maintaining compliance with regional data privacy standards. Under the AWS Shared Responsibility Model, which of the following tasks is the sole responsibility of the customer?
An online media streaming company is undergoing a security audit. The compliance team needs to access AWS security documents and accept standard agreements regarding content protection. Which TWO of the following tasks can the team perform using AWS Artifact to meet these requirements?
Select all that apply
A consulting firm is storing client project documents in an Amazon Simple Storage Service (Amazon S3) bucket. Under the AWS Shared Responsibility Model, which operational task is the sole responsibility of the customer?
A company is using Amazon DynamoDB to store user profile data for a mobile application. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer? (Select TWO.)
Select all that apply
A startup needs to grant a new database administrator access to manage Amazon RDS databases. Which of the following actions aligns with AWS security best practices for identity management?
A public sector organization is migrating a legacy database to AWS and must ensure the architecture meets strict government compliance guidelines. The organization needs to retrieve AWS's third-party compliance reports and must understand the compliance boundaries under the AWS Shared Responsibility Model. Which of the following describes the correct service for retrieving these reports and the compliance responsibility division if they deploy the database on Amazon EC2?
An agricultural analytics firm, AgroOptima, is planning to migrate its application portfolio to the AWS Cloud. The migration team is evaluating the strategies for two specific workloads:
1. A predictive crop-yield analytics application that runs on on-premises virtual machines. To reduce database administration tasks, the team plans to move the application's database to Amazon RDS for PostgreSQL, while hosting the application itself on Amazon EC2 without modifying its core code.
2. A legacy invoicing system with high license maintenance costs. The company plans to decommission this system entirely and transition to a third-party Software-as-a-Service (SaaS) billing solution purchased through AWS Marketplace.
Which combination of migration strategies is AgroOptima using for these two workloads?