Tüm alıştırma soruları
1462 soru
A pharmaceutical company hosts a clinical trial monitoring application on AWS in the `us-east-1` Region. The application's database tier is running on an Amazon RDS for PostgreSQL Multi-AZ DB instance. The application tier runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The company needs to design a disaster recovery (DR) plan in the `us-west-2` Region. The DR plan must meet a Recovery Time Objective (RTO) of hours and a Recovery Point Objective (RPO) of minutes. The company wants to minimize ongoing costs during normal operations. Which of the following database and application tier strategies should a solutions architect recommend to meet these requirements?
An online auction platform allows users to submit bids on items. The platform must process these bids in the exact chronological sequence in which they are received to ensure that the correct winning bid is determined. Bidding activity is highly variable, with sudden spikes in traffic during the final minutes of popular auctions. The architecture must decouple the bid submission layer from the backend processing system to handle these traffic spikes without losing any bids. Which solution meets these requirements with the least operational overhead?
A company needs to grant a third-party audit team temporary access to run query analysis on Amazon Athena using data stored in an Amazon S3 bucket. The audit team manages their users through their own external identity provider (IdP). Which of the following is the most secure method to grant the audit team access according to AWS security best practices?
A logistics company is designing an application to process real-time status updates for package deliveries. The updates must be processed in the exact order they are generated for each package to ensure accurate tracking. If a status update fails to process, it must be isolated for analysis without interrupting the processing of subsequent updates for other packages. Which combination of steps will meet these requirements with the least operational overhead? (Select TWO.)
Geçerli olan tümünü seçin
A company has a development workload running in AWS Account A. Developers assume an IAM role named `DeveloperRole` in Account A to perform their tasks. The solutions architect needs to grant these developers access to an Amazon S3 bucket named `prod-data-archive` located in AWS Account B. The access must be restricted to requests originating from the corporate office IP range (). Which combination of actions should the solutions architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company is migrating its deployment pipeline from a self-hosted server to GitHub Actions. The pipeline workflows must deploy serverless applications in a production AWS account and retrieve sensitive database credentials. The company's security policy requires that all database credentials be rotated automatically every 30 days and strictly prohibits storing long-term AWS credentials or plaintext secrets in external repositories.
Which combination of actions should a solutions architect recommend to meet these security requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is migrating its legacy inventory system to a multi-account AWS environment. A legacy application running on-premises must write daily inventory reports directly to an Amazon S3 bucket located in a centralized AWS account. The company's security policy strictly prohibits the storage of long-term AWS security credentials on-premises. Which solution meets these requirements with the least operational overhead?
An enterprise company wants to grant its employees access to multiple AWS accounts within AWS Organizations. The company uses an external identity provider (IdP) that supports SAML 2.0 to manage its workforce. The company wants to minimize administrative overhead and avoid creating duplicate credentials.
Which solution meets these requirements with the least operational complexity?
A software-as-a-service (SaaS) company hosts a global hotel booking platform in the eu-west-1 Region. The application tier runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The database tier uses an Amazon RDS for PostgreSQL DB instance. The company wants to implement a disaster recovery (DR) strategy in the us-east-1 Region that achieves a recovery point objective (RPO) of 5 minutes and a recovery time objective (RTO) of 30 minutes. Which combination of actions should the solutions architect recommend to meet these requirements at the lowest cost? (Select TWO.)
Geçerli olan tümünü seçin
A company is designing a security baseline for its new multi-account AWS environment. The solution must address two requirements:
First, corporate identity directory users need single sign-on access to the AWS Management Console and CLI.
Second, a containerized application running on Amazon ECS needs to securely retrieve database credentials that must be rotated every days.
Which combination of actions should the solutions architect recommend to meet these requirements securely? (Select TWO.)
Geçerli olan tümünü seçin
A company wants to grant a third-party security audit application access to read log files in an Amazon S3 bucket within the company's AWS account. The third-party application runs in the auditor's AWS account. The company's security policy dictates that no long-term credentials can be shared, and the design must prevent the 'confused deputy' problem. Which configuration should a solutions architect implement to meet these security requirements?
A university needs to provide its staff members with access to the AWS Management Console. The staff identities are stored in an external SAML 2.0-compliant identity provider. The security team wants to ensure that no long-term AWS credentials are created for these users, and access is managed centrally. Which AWS service is the recommended solution to meet this requirement?
A company wants to grant its on-premises Active Directory users access to the AWS Management Console. The solutions architect needs to configure identity federation using AWS IAM Identity Center to allow users to sign in with their existing corporate credentials.
Which two actions must the solutions architect perform to establish this integration? (Select TWO.)
Geçerli olan tümünü seçin
A retail enterprise has recently adopted a multi-account AWS environment using AWS Organizations. The IT security team must enable corporate employees to log in to the AWS Management Console across multiple accounts using their existing Microsoft Active Directory credentials, without creating permanent IAM credentials for each user. Which AWS service should the solutions architect recommend to meet these requirements with the least operational overhead?
A company is designing a new security strategy to grant its development team access to AWS resources. The developers are currently authenticated via an on-premises Active Directory. The solutions architect must implement a solution that allows developers to access the AWS Management Console and AWS CLI without introducing the administrative overhead of managing individual long-term credentials in AWS. Which solution should the solutions architect recommend to meet these requirements?
An e-commerce company is designing an order processing application on AWS. When a customer places an order, the application must publish order events to multiple downstream services. The transaction service must process payments in the exact order they are received to ensure ledger accuracy. However, the shipping notification service and the analytics service can process events asynchronously without strict ordering requirements. If a service fails to process an order event after multiple retries, the event must be isolated for troubleshooting without blocking other orders.
Which TWO configurations should a solutions architect recommend to meet these requirements with the least operational overhead?
Geçerli olan tümünü seçin
A financial services company is setting up a hybrid cloud environment. The company needs to allow its on-premises Active Directory users to log in to the AWS Management Console to manage Amazon EC2 instances. The security policy states that user credentials must not be stored or replicated in the AWS Cloud, and administrative effort must be minimized. Which two actions should a solutions architect take to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
An enterprise is migrating its applications to a multi-account environment managed by AWS Organizations. The company's security policy requires corporate users to authenticate using their existing on-premises Active Directory credentials to access the AWS Management Console of various AWS accounts. The solution must enforce multi-factor authentication (MFA), minimize operational overhead, and avoid synchronizing passwords or user directory data to the cloud. Which two actions should a solutions architect take to implement this architecture? (Select two.)
Geçerli olan tümünü seçin
A solutions architect is configuring the network security settings for resources within an Amazon VPC. The architect needs to establish controls using both security groups and network access control lists (network ACLs). Which TWO of the following statements correctly describe the characteristics of security groups and network ACLs?
Geçerli olan tümünü seçin
A company is establishing a multi-account environment using AWS Organizations. The security team wants to delegate the ability to create IAM roles to the development team lead in a member account. However, the security team must ensure that the team lead cannot create roles that grant permissions exceeding a defined threshold. Furthermore, compliance rules dictate that no entity within the member account—including the AWS account root user—should be able to stop or delete AWS CloudTrail logging. Which TWO options should the solutions architect choose to meet these requirements?
Geçerli olan tümünü seçin