Tüm alıştırma soruları
1473 soru
A renewable energy firm is developing a smart grid monitoring application. They want to avoid buying expensive physical servers upfront and want the ability to deploy their application to wind farms located in multiple geographic regions around the world. Which two benefits of the AWS Cloud are they directly utilizing? (Select TWO.)
Geçerli olan tümünü seçin
Altus Manufacturing is planning to migrate its legacy on-premises inventory management application to AWS. To reduce operational overhead, the IT department decides to migrate the self-managed database to Amazon Relational Database Service (Amazon RDS) for PostgreSQL, while keeping the application server's configuration and code unchanged. Which migration strategy is Altus Manufacturing using for this database migration?
A financial services firm runs compliance monitoring agents on Amazon EC2 instances within a dedicated subnet. These agents must establish outbound connections to an external regulatory API on port to upload audit logs. The security team implements a strict Network Access Control List (Network ACL) for the subnet, adding an outbound rule that permits traffic to the API's IP range on TCP port . No inbound rules are added to the Network ACL. The associated Security Groups are left at their default settings (allowing all outbound traffic and no inbound traffic). During testing, the agents fail to establish a connection with the API.
Which modification is required to allow this communication while maintaining the principle of least privilege?
A company is setting up its security guidelines for access management in AWS. The IT manager wants to enforce Multi-Factor Authentication (MFA) to protect the account's resources. According to AWS security best practices, which of the following identities should have MFA enabled? (Select TWO.)
Geçerli olan tümünü seçin
An agricultural technology company runs a crop monitoring system. The system requires massive compute resources for two weeks during the bi-annual harvesting season to process telemetry data. For the remaining 11 months of the year, the compute demand is near zero. The company is evaluating the financial impact of migrating this workload from its on-premises data center to AWS. Which of the following represents the primary economic advantage of this migration?
A security team needs to monitor and audit IP traffic routing through network interfaces in a Virtual Private Cloud (VPC) to investigate network connectivity issues. Which AWS feature should the team enable to collect this network traffic information?
A financial research firm needs to run a complex risk analysis simulation once a week. The simulation requires a large cluster of compute instances for six hours. The firm uses infrastructure as code to automatically provision the instances, run the simulation, and then immediately terminate the entire cluster. Which AWS Cloud design principle is directly demonstrated by this operational workflow?
A retail company is migrating its customer database and product catalogs to Amazon S3. The company's security policy requires that all data stored in the cloud must be encrypted at rest. Under the AWS Shared Responsibility Model, which of the following is a customer responsibility regarding this encryption requirement?
Stellaris Hospitality is preparing to migrate its legacy application portfolio to the AWS Cloud. During the discovery phase, the IT team evaluates two applications:
- A proprietary, custom-built property management system that must be redesigned to leverage serverless databases and auto-scaling.
- An on-premises commercial billing software that will be retired in favor of a web-based Software-as-a-Service (SaaS) solution.
Which of the following migration strategies represent the correct approach for these two systems? (Select TWO.)
Geçerli olan tümünü seçin
An automotive telemetry platform processes vehicle sensor data using a fleet of Amazon EC2 instances. The security team needs to implement a solution to scan these EC2 instances for known software vulnerabilities and continuously monitor the AWS accounts for malicious activity or unauthorized behavior. Which two AWS services should the platform use to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A logistics company uses Amazon Simple Queue Service (SQS) to decouple its order processing systems. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer?
Geçerli olan tümünü seçin
An enterprise client is designing a security monitoring architecture for their AWS environment. The client must satisfy two requirements:
1. Detect and alert in real-time when administrative actions, such as the deletion of an Amazon S3 bucket, are initiated by any user or role.
2. Continuously monitor the network activity of Amazon EC2 instances to identify active threat behaviors, such as outbound port scanning or communication with known malicious command-and-control servers.
Which combination of AWS services should the client implement to meet these requirements?
A company is migrating its database to Amazon RDS. Under the AWS Shared Responsibility Model, which task is the responsibility of the customer?
A company wants to secure its Virtual Private Cloud (VPC) by controlling traffic entering and leaving its subnets. The security team needs a solution that evaluates traffic using stateless rules at the subnet boundary. Which AWS resource or feature should the company configure to achieve this?
A healthcare technology company runs its patient portal on a fleet of Amazon EC2 instances. The security compliance officer needs to ensure that the operating systems of these instances are regularly checked for software vulnerabilities and unintended network exposure. According to the AWS Shared Responsibility Model, which customer-managed action should the company take to meet this requirement?
A pharmaceutical research firm must encrypt clinical trial data stored in Amazon S3. The firm's compliance policy mandates that encryption keys must be generated and stored on dedicated, single-tenant hardware security modules (HSMs) directly controlled by the firm's security team. However, the firm still wants to leverage the automated, seamless server-side encryption features of Amazon S3 without custom application-side coding. Which of the following approaches meets these requirements?
A digital marketing agency runs website analytics reports for its clients. The reports are generated only during the first three days of each month, leaving their on-premises servers underutilized for the rest of the month. The agency is planning to migrate these workloads to AWS.
Which TWO of the following describe the primary cloud economic benefits of this migration? (Select TWO.)
Geçerli olan tümünü seçin
An online retail company is designing a security and operational monitoring strategy. The company needs to audit administrative API activities (such as who created a resource or modified access policies) and track EC2 instance CPU utilization to trigger alerts if performance degrades. Which AWS services should the company use to meet these two requirements?
An enterprise is migrating its legacy web application to AWS and decides to run it inside Docker containers using AWS Fargate. Under the AWS Shared Responsibility Model, which two of the following operational tasks are the responsibility of the customer?
Geçerli olan tümünü seçin
A company needs to grant an external auditor temporary access to view the configuration of their AWS resources. The auditor does not have an AWS account but has a corporate identity provider (IdP). Which of the following is the most secure AWS-recommended method to grant this access?