Tüm alıştırma soruları
1964 soru
A financial services company is designing a disaster recovery (DR) solution for a critical transaction processing application. The primary infrastructure is deployed in the `us-east-1` Region, using Amazon EC2 instances in private subnets across three Availability Zones (AZs) and an Amazon Aurora PostgreSQL database. The application must remain highly available within the primary Region and resilient to regional failures. The DR solution in the `us-west-2` Region must achieve a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 1 minute. The company wants to minimize ongoing running costs for the DR environment.
Which of the following architectures meets these requirements?
A software-as-a-service (SaaS) company is designing a highly available, multi-region web application on AWS with a primary deployment in us-east-1 and a disaster recovery (DR) site in us-west-2. The application relies on an Amazon Aurora MySQL database and must communicate with external payment APIs. The business requirements specify a Recovery Time Objective (RTO) of minutes and a Recovery Point Objective (RPO) of minutes. The design must ensure high availability within each Region and minimize single points of failure. Which two actions should a solutions architect take to meet these requirements?
Geçerli olan tümünü seçin
A digital publishing company is designing a disaster recovery (DR) architecture for its high-traffic content management application. The primary database is an Amazon RDS for PostgreSQL instance. The application tier runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The business requirements specify a Recovery Time Objective (RTO) of less than minutes and a Recovery Point Objective (RPO) of less than minutes. Additionally, the secondary database must be capable of serving read-only search queries to local users in the secondary region during normal operations to offload read traffic. The solution must also support internal service discovery using a Route 53 Private Hosted Zone (PHZ). Which two actions should the solutions architect take to meet these requirements?
Geçerli olan tümünü seçin
A global automotive manufacturer is designing a new critical parts tracking system on AWS. The application will be deployed across two AWS Regions: us-east-1 as the primary active region and us-west-2 for disaster recovery. The business requires a Recovery Time Objective (RTO) of 10 minutes and a Recovery Point Objective (RPO) of 5 minutes. The database tier must support cross-region replication, and the network design must ensure outbound internet connectivity remains highly available even if an entire Availability Zone experiences an outage. External client traffic must automatically fail over to the secondary region if the primary region's endpoints become degraded. Which architecture meets these requirements while minimizing cost and operational complexity?
A municipal smart-grid utility provider is launching a new smart-meter data ingestion system on AWS. The system's primary workload runs in the us-east-1 Region, and the company requires a disaster recovery (DR) solution in the us-west-2 Region. The application requires outbound internet access from its private subnets to register meters. The database tier uses Amazon Aurora PostgreSQL. The business requires a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 5 minutes. Which design meets these objectives with the lowest cost and operational complexity while maintaining high availability in the primary region?
A retail company manages a multi-account AWS environment with ten spoke VPCs connected to a central AWS Transit Gateway in the us-east-1 Region. The VPCs are split into six Production spoke VPCs and four Development spoke VPCs. The company's security policy requires that Production VPCs must be able to communicate with each other, and Development VPCs must be able to communicate with each other. However, any traffic between Production and Development VPCs must be completely blocked. Additionally, all ten spoke VPCs must have access to a Shared Services VPC that hosts centralized security monitoring and scanning tools. Which two Transit Gateway routing configurations should the Solutions Architect implement to meet these requirements with the least administrative overhead? (Select TWO.)
Geçerli olan tümünü seçin
A retail company is launching a new serverless microservice using AWS Lambda and Amazon API Gateway. To minimize deployment risk for new updates, a solutions architect must design a deployment strategy that routes of API traffic to the new version of the Lambda function. The strategy must monitor the deployment for a period of minutes using Amazon CloudWatch alarms, and automatically roll back to the previous version within seconds if errors are detected. If no errors are detected, the remaining traffic must be routed to the new version. Which deployment strategy and configuration meets these requirements with the least operational overhead?
A company needs to migrate of historical data from an on-premises NFS file system to Amazon S3. The initial migration must be completed within 30 days. After the initial migration, the company needs to replicate daily incremental updates of approximately from the same NFS file system to Amazon S3. The company has a dedicated internet connection available for this migration. Security policies require that all data at rest in Amazon S3 be encrypted using a Customer Managed Key (CMK) in AWS KMS, and the migration process must minimize administrative overhead. Which two actions should a Solutions Architect recommend to meet these requirements?
Geçerli olan tümünü seçin
A metropolitan transit authority is launching a digital boarding verification system across its entire rail network. The system processes QR code passenger scans from active turnstiles. During morning rush hour, boarding verification requests surge from a baseline of requests per second to a peak of requests per second within . The system must validate passenger ticket balances, update transit logs, and return boarding decisions with sub-millisecond database read response times to prevent passenger queues.
Which architecture scales to meet this sudden workload surge while maintaining performance and operational efficiency?
A global logistics and fleet tracking platform is designing a new multi-region disaster recovery (DR) and high availability architecture for its core routing and dispatch system. The application is deployed across eu-west-1 (Primary) and eu-central-1 (Secondary). The business requires a Recovery Time Objective (RTO) of less than 15 minutes and a Recovery Point Objective (RPO) of less than 1 minute.
The application layer consists of containerized microservices running on Amazon ECS on Fargate in private subnets. These microservices must make outbound API calls to external traffic mapping services, which must remain highly available even if an entire Availability Zone (AZ) in the active region experiences an outage. The database layer uses Amazon Aurora PostgreSQL. For internal service discovery, the microservices use a Route 53 Private Hosted Zone.
Which of the following architectures meets these requirements with the lowest operational complexity?
A company is designing a high-throughput event processing platform to ingest JSON telemetry logs from IoT devices. The platform must support two primary requirements:
1. Low-latency, single-digit millisecond writes to ingest telemetry logs, which must be stored for real-time dashboarding. The telemetry data must automatically expire after days to minimize storage costs.
2. An audit compliance mandate requires raw logs to be archived for years. These archives must be queryable via standard SQL on-demand, without provisioning permanent database compute resources.
Which two database and storage strategies will satisfy these requirements?
Geçerli olan tümünü seçin
A global meteorological agency operates a severe weather monitoring platform that ingests telemetry from active IoT weather sensors. Under normal conditions, each sensor transmits data every . However, during sudden severe weather events, up to sensors in the affected regions immediately transition to high-frequency reporting, transmitting data every . The platform’s ingestion layer uses stateless web servers hosted on Amazon ECS tasks using the AWS Fargate launch type, positioned behind an Application Load Balancer (ALB). The persistence layer is an Amazon Aurora PostgreSQL DB cluster. During simulations of a sudden localized storm, the platform experiences severe request drops at the ingestion layer, and read latency for the real-time public dashboard increases exponentially. Which architectural strategy will optimize performance and ensure scalability during these unpredictable spikes?
A retail enterprise manages member accounts within an organization in AWS Organizations. The security team requires that all VPC Flow Logs from all VPCs in all member accounts be centralized into a single Amazon S3 bucket located in a dedicated Logging account. To comply with security policies, all logs must be encrypted at rest using a customer managed KMS key, and the data transfer must not utilize intermediate CloudWatch log groups in the member accounts. Which configuration should the Solutions Architect implement in the central Logging account to enable successful delivery of the VPC Flow Logs?
A financial services company is designing a hybrid network connectivity architecture to connect its on-premises data center to its AWS environment. The AWS environment consists of a Production VPC in us-east-1 and a Development VPC in us-west-2, both attached to a central AWS Transit Gateway. The primary path must use an AWS Direct Connect connection with bandwidth, and an IPsec VPN over the public internet must serve as a backup path. Both paths connect to the same AWS Transit Gateway. The company wants to ensure that the IPsec VPN is used only if the Direct Connect connection fails, without requiring manual administrative intervention during failover. Which configuration will achieve this routing behavior automatically?
A healthcare provider is designing a new telemedicine consultation platform. The platform runs on Amazon EC2 instances in private subnets across two Availability Zones in the us-east-1 (Primary) Region and needs a disaster recovery (DR) solution in the us-west-2 (Secondary) Region. The backend database is an Amazon RDS for PostgreSQL instance. The platform must meet a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 5 minutes. To control costs, active application servers must not run in the recovery region during normal operations. Additionally, the platform must automatically route user traffic to the secondary region during a disaster, and outbound connectivity from the EC2 instances to external pharmacy APIs must be highly available and redundant within each region. Which architecture should a Solutions Architect design to meet these requirements?
A logistics company is designing a new real-time package delivery tracking system. During peak holiday seasons, query traffic for package status is expected to spike instantly from requests per second to requests per second. The system must also ingest GPS coordinate updates per second from delivery vehicles. The tracking status queries require a latency of less than . Which architecture meets these performance and scalability requirements with the least operational overhead?
A financial services company is designing a hybrid network architecture for its multi-account environment on AWS. The environment contains spoke VPCs in a single AWS Region: Production VPCs and Development VPCs. The company's on-premises infrastructure consists of a corporate headquarters connected via AWS Direct Connect and a backup recovery center connected via an IPsec VPN.
The network design must satisfy the following requirements:
- All spoke VPCs must have bi-directional connectivity with the corporate headquarters and the recovery center.
- Production VPCs must be able to communicate with each other.
- Development VPCs must be completely isolated from each other and from the Production VPCs.
- Administrative overhead for routing configuration must be minimized.
Which network architecture and routing configuration should the solutions architect implement?
A real-estate Multiple Listing Service (MLS) provider is modernizing its legacy property listing management system by migrating to a serverless architecture on AWS. The application uses Amazon API Gateway and AWS Lambda, and must securely access an Amazon RDS PostgreSQL database located in a private subnet. The application experiences highly variable traffic with sudden, massive spikes during peak hours. The solution must ensure high availability, prevent database connection exhaustion, protect other critical functions in the AWS account from throttling, and support secure cross-account credentials access.
Which combination of actions should a solutions architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An energy trading enterprise runs its core transaction processing platform on Amazon ECS tasks within a Production account (Account 111111111111). The enterprise is designing a compliance archiving architecture where transaction logs must be written directly from the ECS tasks to an Amazon S3 bucket located in a dedicated Audit account (Account 222222222222).
The security requirements are as follows:
- Cryptographic control over the logs must remain within the Production account.
- The logs must be encrypted at rest when stored in the S3 bucket.
- The Audit account users must have the ability to read and decrypt these logs.
- The S3 Object Ownership must be configured so that the Audit account automatically owns all uploaded logs, and access control lists (ACLs) are disabled.
- The ECS task roles must be granted only the minimum required permissions.
Which configuration strategy meets these requirements while adhering to the principle of least privilege?
An enterprise is designing a new multi-tenant financial transaction platform (OLTP workload). The platform requires a relational database that handles moderate write volumes and dynamically scales read capacity across AWS Regions to support end-of-month reporting spikes. The solution must achieve a recovery time objective (RTO) of less than hour and a recovery point objective (RPO) of less than minutes. Additionally, compliance regulations require database exports stored in Amazon S3 to be directly decryptable by a central security audit team operating in a separate AWS account. Which database and storage strategy meets these requirements?