Tüm alıştırma soruları
1473 soru
A startup company with limited cloud expertise wants to deploy a simple WordPress website. They need a cost-effective, easy-to-use virtual private server (VPS) solution that bundles compute, storage, databases, and networking into a single monthly plan. Which AWS compute service is best suited for this requirement?
An administrator needs to assign similar security permissions to ten new developers in an organization. Which of the following are AWS-recommended practices for managing these permissions? (Select TWO.)
Geçerli olan tümünü seçin
A smart agriculture startup is launching a new IoT crop-monitoring application. The startup wants to avoid spending its limited capital on purchasing physical servers and building an on-premises data center. Instead, they want to pay for IT resources only as they are consumed.
Which benefit of the AWS Cloud is this startup leveraging?
A logistics company is migrating its supply chain database to AWS. The compliance team requires that all data stored at rest in Amazon S3 be encrypted. The compliance policy specifically mandates that the encryption keys must be generated and stored in a dedicated, single-tenant cryptographic hardware appliance that the company fully controls, while AWS remains responsible for the physical security and maintenance of the appliance hardware. Which service and management model should the company implement?
A company's security team is designing a multi-layered auditing and threat detection strategy for their application servers running on Amazon EC2. The team must satisfy three distinct operational security requirements:
1. Audit and record a history of all API calls, including the specific IAM identities, source IP addresses, and timestamps, to determine who modified resources.
2. Monitor active network traffic patterns to detect potential security threats, such as instances communicating with known command-and-control servers.
3. Track performance metrics of the EC2 instances, such as CPU utilization, and trigger automated alerts if resource usage exceeds defined limits.
Which combination of AWS services will successfully address these three requirements?
A biotechnology company runs high-throughput genomic sequencing pipelines that require massive computational power for a few weeks every quarter. During the off-peak months, their compute usage is negligible. Furthermore, they need to deploy their data-analysis portal across multiple geographic regions to ensure low-latency access for global research collaborators.
Which of the following AWS Cloud benefits directly address these operational requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company is configuring a database for their web application on AWS. To prevent downtime in the event of a hardware failure, they set up a secondary database instance in a different Availability Zone that automatically takes over if the primary database fails. Which AWS Cloud design principle is directly demonstrated by this setup?
Zenith Commerce is planning to migrate its on-premises application portfolio to the AWS Cloud. The IT team has defined two specific goals for this migration phase:
1. Migrate their self-managed relational database to Amazon RDS for PostgreSQL to minimize database administration overhead, without changing the application's core logic.
2. Replace their legacy, self-managed customer relationship management (CRM) software with a cloud-native Software-as-a-Service (SaaS) solution.
Which of the following migration strategies should the company use to achieve these goals? (Select TWO.)
Geçerli olan tümünü seçin
A university is hosting its student registration portal on AWS. The university's compliance department requires a complete history of all API calls and administrative actions taken within the AWS account to audit user activity. Which AWS service should the university use to meet this audit requirement?
A digital marketing agency needs to retrieve the AWS Service Organization Control (SOC) reports to satisfy a client's security questionnaire about the underlying cloud infrastructure. Which AWS tool or service should the agency use to obtain these official documents?
A global organization wants to implement a robust security logging and auditing architecture. They need to meet three distinct security and operational monitoring objectives:
1. They must track and log all management events and API calls across their entire AWS Organization for compliance auditing.
2. They need to monitor CPU utilization and disk read/write metrics of their Amazon EC2 instances to dynamically scale resources and trigger operational alerts.
3. They require intelligent threat detection that uses machine learning to continuously analyze metadata logs (such as VPC Flow Logs and DNS logs) to identify potential malicious activity.
Which combination of AWS services should the organization implement to satisfy these requirements?
A media streaming platform is implementing a security policy to protect user payment information and video assets on AWS. The security team needs to configure encryption for data at rest in Amazon S3 and data in transit between users and the streaming application. Which of the following statements represent the customer's responsibility under the AWS Shared Responsibility Model for this data protection scenario? (Select TWO.)
Geçerli olan tümünü seçin
A cloud administrator is configuring security settings for an Amazon S3 bucket that will store proprietary company documents. To protect data at rest, which security action is the cloud administrator responsible for executing?
A gaming company is migrating its leaderboard database to AWS. The company needs to encrypt the database backups stored in Amazon S3 at rest and ensure that all data sent to the database is encrypted in transit. Under the AWS Shared Responsibility Model, which two of the following tasks are the responsibility of the customer?
Geçerli olan tümünü seçin
A tourism agency is deploying a customer-facing mobile booking application and decides to use Amazon Cognito for user authentication and directory management. Under the AWS Shared Responsibility Model, which of the following is a responsibility of the customer?
A developer needs to run a short Python script for 10 seconds every night to clean up temporary database records. The developer does not want to provision or manage any virtual servers. Which AWS compute service should be used to run this script?
An application developer is configuring security rules for an Amazon EC2 instance. They notice that when they allow inbound traffic on a specific port, the return outbound traffic is automatically allowed without requiring an explicit outbound rule. Which AWS network security component exhibits this stateful behavior?
A newly formed cloud engineering team needs to perform daily administrative duties, such as configuring network settings and launching Amazon EC2 instances. Which approach represents the AWS-recommended best practice for securing the AWS account root user while enabling these tasks?
A cloud engineer has successfully created a new AWS account for a startup. To secure the account immediately, what is the AWS-recommended best practice for performing daily administrative operations?
A financial technology firm wants to enhance its security posture on AWS. The firm needs to meet two specific requirements: first, they want to continuously monitor their AWS accounts, workloads, and data for malicious activity, such as unauthorized API calls or potential data exfiltration. Second, they need an automated way to scan container images stored in Amazon Elastic Container Registry (Amazon ECR) for software vulnerabilities before they are deployed to production.
Which two AWS services should the firm use to satisfy these security requirements? (Select two.)
Geçerli olan tümünü seçin