Tüm alıştırma soruları
1462 soru
A financial services company is setting up a development AWS account. The company wants to allow the development team leads to create and manage IAM roles for their applications' Amazon EC2 instances. However, the security team must ensure that the team leads cannot create roles that grant access to sensitive S3 buckets, even though the team leads themselves have administrative permissions in the account. Which solution meets these security requirements with the least administrative overhead?
An enterprise has a legacy payroll application running on physical servers in an on-premises data center. The application must securely upload daily transaction logs to an Amazon S3 bucket. The company's security policy strictly prohibits the storage of long-term AWS credentials on physical on-premises servers. The company already maintains an internal Public Key Infrastructure (PKI) and a private Certificate Authority (CA). Which solution meets these security requirements with the least administrative overhead?
An airline is designing an application to process loyalty rewards points accrual events. For each passenger, events must be processed in the exact chronological sequence they are generated to ensure loyalty tiers are calculated accurately. If an event fails to process after five attempts, it must be isolated for investigation without blocking the processing of events for other passengers.
Which solution meets these requirements with the least operational overhead?
A financial services firm is deploying a containerized risk analysis platform on Amazon Elastic Kubernetes Service (Amazon EKS) across two Availability Zones. The platform's pods require concurrent, shared read and write access to a persistent storage volume that supports standard POSIX file systems, permissions, and locking. The storage must handle up to during peak processing times, and must scale throughput and capacity automatically without manual provisioning or downtime.
Which of the following configurations should a solutions architect recommend? (Select TWO.)
Geçerli olan tümünü seçin
A solutions architect is designing the network security for a two-tier application in a VPC. The database tier runs on Amazon EC2 instances in a private subnet, and the web tier runs in a public subnet. The database instances must accept incoming database connections on TCP port 3306 from the web tier. Additionally, the database instances must be able to download software updates from the internet over HTTPS (TCP port 443) via a NAT Gateway. No other outbound connections from the database instances should be allowed. The architect wants to implement these controls using both Security Groups and Network Access Control Lists (Network ACLs) under the principle of least privilege. Which combination of configurations will satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise architecture team is reviewing the security posture of an analytics application that processes sensitive financial data. The application requires access to a database password, and all associated Amazon EBS volumes must be encrypted. To comply with internal security policies, the database password must be rotated every 30 days without manual intervention, and the KMS keys used for EBS volume encryption must be automatically rotated annually. Which strategy should a solutions architect implement to meet these requirements with the least operational effort?
A company hosts its static website assets in an Amazon S3 bucket located in the us-east-1 Region. To ensure high availability and resiliency, the company replicates these assets to a secondary S3 bucket in the us-west-2 Region. A solutions architect needs to configure Amazon CloudFront to deliver these assets with low latency and automatically serve files from the backup S3 bucket if the primary S3 bucket returns an HTTP 503 Service Unavailable error. Which configuration should the solutions architect use to meet these requirements?
An international logistics provider runs a critical tracking application using Amazon RDS for PostgreSQL in the us-east-1 Region. The company requires a disaster recovery (DR) solution in the us-west-2 Region with a Recovery Point Objective (RPO) of less than 5 minutes and a Recovery Time Objective (RTO) of less than 15 minutes. Additionally, the secondary region must serve read-only reporting workloads during normal operations to offload the primary database. Which combination of actions will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A global agricultural logistics company is migrating its telemetry archiving system to AWS. The system must store critical supply chain data with an RPO of minutes and an RTO of minutes. The architecture must ensure the data is resilient to regional disasters and remains immediately readable from a secondary destination region for localized reporting. Which two configurations should the solutions architect combine to meet these resilience and recovery requirements?
Geçerli olan tümünü seçin
An insurance company manages a multi-account environment on AWS using AWS Organizations. The company wants to allow its on-premises Active Directory users to access resources across these accounts using their existing corporate credentials. The solution must minimize operational overhead, avoid user data replication, and allow central management of permissions. Which of the following actions should the solutions architect take to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A software development company runs nightly build integration tests. The build artifacts, which average each, are uploaded to an Amazon S3 Standard bucket. The developers access these build artifacts frequently for the first days to debug any integration issues. After days, the artifacts are rarely accessed, but the company's compliance policy requires that they be retained for a total of days before being permanently deleted. Millisecond retrieval times are required if an older artifact needs to be inspected. Which of the following lifecycle configurations is the most cost-effective?
A smart grid utility company collects electricity consumption readings from smart meters every . The total data volume during peak hours reaches of XML data. The company needs to ingest this data, convert the format from XML to JSON in near-real-time, and store the output in Amazon S3 for downstream analytics. The ingestion pipeline must scale automatically to handle load fluctuations and require minimal operational overhead. Which combination of actions should the solutions architect recommend to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A company is deploying a high-performance clustered database application on Amazon EC2 instances located in a single Availability Zone. The application requires shared block-level access to a single storage volume that will be formatted with a cluster-aware file system. The storage volume must deliver a consistent performance of with sub-millisecond latencies.
Which storage configuration will meet these requirements?
A digital ticketing platform plans to migrate its database to Amazon Aurora MySQL. The database must sustain high availability during an Availability Zone outage with a recovery time objective (RTO) of less than 60 seconds and zero data loss (recovery point objective or RPO of 0). In addition, the database must dynamically scale to support a large, unpredictable volume of read queries. Which two configurations should a solutions architect implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A startup runs a public web application on Amazon EC2 instances that requires a baseline capacity of four instances running 24/7 to handle steady-state traffic. The application writes to an Amazon DynamoDB table that experiences sudden, highly unpredictable spikes in database traffic. In addition, the startup runs daily batch processing jobs on AWS Fargate that are fault-tolerant and can be interrupted at any time.
Which combination of purchasing strategies should a solutions architect recommend to minimize compute costs for these workloads? (Select TWO.)
Geçerli olan tümünü seçin
A manufacturing company is migrating its workloads to a multi-account environment on AWS managed by AWS Organizations. The company maintains an on-premises Microsoft Active Directory containing all employee accounts. The company wants to allow its security administrators to log in to the AWS Management Console and access the AWS CLI using their existing corporate credentials. The solution must minimize operational overhead, avoid replicating Active Directory passwords to the cloud, and support centralized permission management. Which combination of actions should the solutions architect recommend to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A healthcare software provider is deploying a critical patient portal application on AWS. The application database tier requires high availability within the primary Region (us-east-1) to survive the loss of an Availability Zone with a Recovery Time Objective (RTO) of under 60 seconds. Additionally, the provider requires a cross-region disaster recovery (DR) solution in the us-west-2 Region with a Recovery Point Objective (RPO) of under 1 minute and a Recovery Time Objective (RTO) of under 15 minutes. Which combination of database configurations will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company runs a high-performance web application on a fleet of Amazon EC2 instances distributed across two Availability Zones. The instances require concurrent read/write access to a shared, POSIX-compliant file system to store and retrieve media assets. The storage must scale throughput automatically to handle unpredictable traffic spikes while maintaining low latency.
Which storage solution should a solutions architect recommend to meet these requirements with the least operational overhead?
A maritime fleet management company is designing a high-availability telemetry processing system on AWS. The application runs on Amazon ECS containers across multiple Availability Zones in the primary region (`eu-west-1`). The containers require concurrent read/write access to a shared POSIX-compliant file system. The architecture must support a multi-region disaster recovery (DR) plan in `eu-central-1` with a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 10 minutes. During failover, the file system in the recovery region must be immediately writable without latency or performance degradation. Which combination of configurations will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company hosts a latency-sensitive application across two AWS Regions: us-east-1 and us-west-2. The company needs to route global user traffic to the Region that offers the lowest latency, with automatic failover if a Region becomes unhealthy. Additionally, the company must establish a secure hybrid network connection to replicate database backups from their on-premises data center to both AWS Regions. The replication traffic requires a consistent bandwidth of Gbps. Which architecture should a solutions architect recommend to meet these requirements?