Tüm alıştırma soruları
1964 soru
A company is designing a new portal that will experience highly variable read traffic to its relational database. The database tier must scale horizontally and automatically to handle peak read loads while maintaining high availability. Which configuration should a solutions architect recommend to scale the database's read capacity?
A multinational retail company is designing a federated authentication solution for its multi-account AWS environment managed via AWS Organizations. The company utilizes an external SAML 2.0 compliant Identity Provider (IdP) for identity management. The solutions architect needs to establish federated single sign-on (SSO) so that corporate employees can access resources in various AWS member accounts according to their corporate group memberships. The security team mandates that identity federation must be established directly using IAM SAML identity providers in the member accounts, without deploying AWS IAM Identity Center. Which of the following configuration steps must the solutions architect perform to successfully set up this federation? (Select TWO.)
Geçerli olan tümünü seçin
An organization has configured a multi-account AWS environment using AWS Organizations. They federate their corporate active directory identity provider (IdP) with AWS accounts using SAML 2.0. Users authenticate through the corporate portal and are redirected to the AWS Console, but they receive an error stating that they are not authorized to perform the sts:AssumeRoleWithSAML action. A solutions architect examines the target IAM role in the member account. Which configuration in the IAM role's trust policy is required to resolve this issue?
A Solutions Architect wants to grant a development team in a member account the ability to manage Amazon S3 buckets. The architect attaches a Service Control Policy (SCP) to the Organizational Unit (OU) containing the member account, which explicitly allows all S3 actions. However, the developers in the member account still receive access denied errors when attempting to create a bucket. Which of the following explains this behavior?
A digital media corporation is using AWS Organizations to manage multiple member accounts grouped under separate Organizational Units (OUs) for Development, Testing, and Production. The security team has deployed a centralized auditing tool that relies on an IAM role named 'AuditCollectorRole' present in all member accounts. The Solutions Architect must implement a governance strategy to prevent local administrators in member accounts from deleting or modifying this specific IAM role, without restricting their ability to manage other IAM resources. Which of the following governance strategies should the solutions architect implement to meet these requirements with the least administrative overhead?
An enterprise is designing a multi-account architecture on AWS using AWS Organizations with all features enabled. The networking team has created a centralized VPC in a dedicated Network account and wants to share specific subnets with application development teams operating in separate accounts under an Application Organizational Unit (OU). The application workloads run on a combination of Amazon EC2 instances and AWS Fargate tasks. All EBS volumes and S3 buckets must be encrypted at rest using keys managed in a centralized Security account. The finance team requires that cost optimization benefits are maximized across all compute workloads, and billing is consolidated. Which TWO strategies should the solutions architect implement to meet these requirements securely and cost-effectively?
Geçerli olan tümünü seçin
A financial services company is designing a multi-account architecture using AWS Organizations with 50 member accounts. Security policies require that administrators authenticate using the company's on-premises SAML 2.0 compliant Identity Provider (IdP) to access a highly privileged role named AdminAccessRole in each member account. The security requirements are as follows:
- Federated administrative sessions must support a duration of up to 4 hours.
- Administrators must be blocked from assuming the AdminAccessRole if they did not perform Multi-Factor Authentication (MFA) at the corporate IdP.
Which combination of actions must a solutions architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A retail company manages its multi-account AWS environment. The core infrastructure team maintains a Route 53 Private Hosted Zone (PHZ) named service.internal in Account 111111111111. A development team in Account 222222222222 has deployed a microservice inside a new VPC and needs resources within this VPC to resolve domain names in service.internal. The VPCs in both accounts are connected via an AWS Transit Gateway. Which process should the Solutions Architect implement to enable name resolution for the microservice VPC in Account 222222222222?
An enterprise manages a multi-account environment using AWS Organizations with consolidated billing. The architecture includes a management account, a shared networking account, and multiple member accounts for application teams.
The solutions architect must design a resource sharing and cost management strategy with the following requirements:
- Share VPC subnets from the networking account to application member accounts to allow application deployments.
- Ensure EBS volumes created by application teams in their respective accounts are encrypted using a centralized KMS key managed by the Security team in a dedicated Security account.
- Maximize cost savings across the organization, which runs a combination of Amazon EC2 instances, AWS Fargate tasks, and AWS Lambda functions across all application accounts.
- Ensure the sharing of VPC subnets is restricted strictly to accounts within the AWS Organization.
Which of the following strategies represents the most secure, operationally efficient, and cost-effective solution to meet these requirements?
A shipping logistics enterprise is setting up centralized logging for all member accounts within its AWS Organizations structure. The security team requires that AWS CloudTrail logs from all accounts be delivered to a single Amazon S3 bucket in a dedicated Logging account. The logs must be encrypted using AWS KMS. The architecture must ensure that member accounts cannot modify CloudTrail settings or access the centralized S3 bucket directly. Which configuration meets these requirements?
A retail corporation has configured a multi-account AWS environment using AWS Organizations. The security team is setting up federated single sign-on (SSO) using an on-premises SAML 2.0-compliant Identity Provider (IdP). The solutions architect needs to configure the IAM roles in the member accounts to trust the SAML IdP. When external users attempt to log in through the IdP portal, they receive access denied errors before they can select a role. Which of the following configurations must the solutions architect apply to the IAM roles in the target member accounts to successfully establish the trust relationship?
An enterprise is designing a centralized egress inspection architecture using AWS Transit Gateway (TGW) to connect 50 spoke VPCs (CIDR range ) to a central Inspection VPC (CIDR range ). The Inspection VPC contains a Gateway Load Balancer (GWLB) backed by stateful firewalls to inspect all outbound traffic before it goes to the internet through NAT Gateways. The Inspection VPC is deployed across multiple Availability Zones, with each zone containing a TGW subnet, a GWLB endpoint (GWLBe) subnet, and a NAT Gateway subnet. Which configuration of Transit Gateway (TGW) route tables and Inspection VPC route tables must the solutions architect implement to ensure that all egress traffic is inspected and returned symmetrically without routing loops or dropping packets?
An organization wants to ensure that its developers can create resources in a sandbox Organizational Unit (OU) but are strictly prevented from using any AWS services outside the us-east-1 and us-west-2 Regions. The solutions architect wants to apply this guardrail centrally across all accounts in the sandbox OU without modifying individual IAM roles or users. Which approach should the solutions architect use to meet these requirements?
A health-tech company is migrating its electronic health record (EHR) platform to AWS. The target topology consists of a central Network account containing a hub VPC, and multiple application accounts containing spoke VPCs, all interconnected via AWS Transit Gateway. The on-premises data center is connected to the hub VPC via an AWS Direct Connect connection. A Private Hosted Zone (PHZ) for the domain aws.healthtech.internal is created in a central Shared Services account. AWS resources in the spoke VPCs and servers on-premises must be able to resolve records in aws.healthtech.internal. Which of the following actions should the Solutions Architect take to establish this hybrid DNS resolution? (Select TWO.)
Geçerli olan tümünü seçin
A multinational enterprise is designing a centralized logging architecture across its AWS Organizations structure, which consists of over 200 member accounts. A solutions architect is setting up an organization-wide AWS CloudTrail trail that delivers log files to a single Amazon S3 bucket located in a dedicated Security account. The log files must be encrypted using AWS Key Management Service (AWS KMS).
The solutions architect needs to configure the S3 bucket policy and the KMS key policy in the Security account to allow CloudTrail to write logs and encrypt them, ensuring that the configurations scale dynamically as new accounts are added or removed from the organization.
Which combination of configurations will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is expanding its AWS environment by migrating several regional e-commerce workloads into separate AWS accounts under a single organization in AWS Organizations. The security team has defined the following requirements:
1. Workloads must only be deployed within a set of approved AWS Regions.
2. Member accounts must not be able to disable or modify the compliance monitoring rules established by the security team.
3. Developers must maintain administrative privileges within their dedicated development accounts.
Which two actions should a Solutions Architect take to implement these controls? (Select TWO.)
Geçerli olan tümünü seçin
An automotive manufacturer is establishing a multi-account AWS landing zone. A central Shared Services account hosts a Route 53 Private Hosted Zone (PHZ) for `factory.internal` associated with the Shared Services VPC. Workloads in a Production VPC in a separate Production account need to resolve domains in `factory.internal`. Additionally, on-premises assembly line systems, connected via AWS Direct Connect and AWS Transit Gateway, must resolve domains in `factory.internal`. Which combination of actions will allow both the Production VPC workloads and the on-premises systems to resolve domains in `factory.internal`?
A software company manages its multi-account environment using AWS Organizations. The security team wants to permit developers in the Development Organizational Unit (OU) to use Amazon DynamoDB, while blocking access to all other AWS services. A solutions architect creates a Service Control Policy (SCP) that allows all DynamoDB actions and denies all other service actions, then attaches this SCP to the Development OU. After the policy is applied, developers in the Development OU report that they cannot access DynamoDB tables. Which of the following explains the cause of this issue?
A digital media startup is setting up its AWS multi-account environment using AWS Organizations. The environment consists of a management account, a core networking account, a production workload account, and a development account. The startup has the following requirements:
1. Private subnets created in the core networking account must be shared with the production and development accounts to deploy application resources.
2. Database instances in the production account must be encrypted using an AWS KMS key that can be centrally managed and audited by the security team in the core account.
3. Compute Savings Plans discounts must be applied exclusively to the production account's workloads (which consist of a mix of Amazon EC2 and AWS Fargate) without being consumed by the development account's resources.
Which strategy should a solutions architect recommend to satisfy these requirements?
An enterprise is designing a secure governance framework for its AWS Organizations structure, which consists of multiple organizational units (OUs) and a dedicated centralized Logging account. To comply with regulatory standards, a solutions architect must establish an organizational CloudTrail that logs all API activity across all member accounts. The architecture must adhere to the principle of least privilege by avoiding the use of the Management account for daily auditing tasks, and it must prevent any modifications or deletions of logging resources by member accounts.
What is the correct sequence of steps to configure this centralized, secure auditing solution?
Öğeleri doğru sıraya koymak için sürükleyin