Tüm alıştırma soruları
1964 soru
A company is planning to migrate a highly transactional Microsoft SQL Server database located on-premises to an Amazon Aurora PostgreSQL-Compatible Edition DB cluster. The migration must be completed with minimal downtime. The source database includes several tables that do not have primary keys, as well as multiple tables containing PDF documents stored in `VARBINARY(MAX)` columns. The solutions architect is designing the replication strategy using AWS Database Migration Service (DMS) and schema conversion using the AWS Schema Conversion Tool (SCT). Which combination of actions should the solutions architect take to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A financial services company is migrating its core ledger application servers from an on-premises data center to AWS using AWS Application Migration Service (MGN). The replication traffic must be routed over a dedicated AWS Direct Connect connection and must not traverse the public internet. The staging area is configured within a dedicated VPC. Which of the following configuration steps must be performed to establish secure, private data replication from the on-premises servers to the staging area? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is planning to migrate its legacy on-premises Oracle database to an Amazon Aurora PostgreSQL-Compatible DB cluster. The database contains complex PL/SQL packages with custom functions that do not have direct equivalents in PostgreSQL. The migration must minimize downtime for the dependent applications. Which of the following represents the correct sequence of steps to successfully perform this migration while ensuring application compatibility and data consistency?
A financial technology company operates a stock portfolio analysis platform. The platform uses a single-node Amazon RDS for PostgreSQL DB instance to store user portfolio holdings and real-time stock price cache data. During periods of high market volatility, user dashboard page load times degrade significantly. Database metrics show CPU utilization at and write IOPS hitting disk limits due to the constant updates of stock prices. The stock price cache data requires replication across multiple Availability Zones to ensure high availability and sub-millisecond read latency, but does not need complex relational queries. The database must also scale to handle peak read queries for portfolio holdings without impacting write operations.
Which combination of actions should the Solutions Architect recommend to improve database and caching efficiency? (Select TWO.)
Geçerli olan tümünü seçin
A maritime shipping company is migrating its legacy Terminal Operating System (TOS) consisting of physical telemetry servers to AWS using AWS Application Migration Service (MGN). The on-premises data center connects to AWS via an AWS Direct Connect connection terminated on an AWS Transit Gateway in a hub VPC. Due to strict security compliance, all replication traffic must be kept entirely private and cannot traverse the public internet. The staging area VPC has no Internet Gateway or NAT Gateway configured. Which TWO configurations are required to ensure the replication agent can communicate with the AWS MGN control plane and successfully replicate block-level data? (Select TWO.)
Geçerli olan tümünü seçin
A financial enterprise is migrating an on-premises Oracle database to an Amazon Aurora PostgreSQL-Compatible Edition DB cluster. The migration must achieve the lowest possible downtime and ensure that schema customizations, secondary indexes, and referential integrity constraints are preserved. The database size is 8 TB, and the application generates a high volume of daily transactions. The Solutions Architect has already run the AWS Schema Conversion Tool (SCT) to generate the target PostgreSQL DDL. Which migration strategy will meet these requirements with the shortest replication cutover window and the highest performance during the initial load?
An enterprise has an existing solution where an application running on Amazon EC2 instances in Account A writes log files to an Amazon S3 bucket in Account B. The S3 bucket is configured with default encryption using the AWS-managed KMS key (aws/s3). The IAM role attached to the EC2 instances has the necessary permissions to write to the S3 bucket, and the bucket policy in Account B allows write access from the IAM role. However, the application's write requests are failing with an Access Denied error. Which solution should the Solutions Architect implement to resolve the write failures and strengthen the security of the cross-account data transfer?
A bioinformatics research institute is migrating 24 local physical servers running genomic analysis pipelines to AWS using AWS Application Migration Service (MGN). The on-premises network is connected to AWS via a 2 Gbps AWS Direct Connect connection using a Transit Virtual Interface (Transit VIF) terminating at a Direct Connect Gateway, which is associated with an AWS Transit Gateway. The Transit Gateway connects a Shared Services VPC and a dedicated Migration Staging VPC. In compliance with strict genomic data privacy regulations, all migration and replication traffic must traverse the private Direct Connect path and cannot route over the public internet. No internet gateway or NAT gateway is permitted in the Migration Staging VPC. Which configuration strategy should the Solutions Architect implement to establish secure, private replication while minimizing operational overhead?
A healthcare diagnostics company is planning to migrate its hybrid application portfolio to AWS. The on-premises environment consists of 100 VMware vSphere VMs running supported Linux and Windows operating systems, and 15 legacy physical bare-metal servers running IBM AIX that host core databases. A strict corporate compliance policy prohibits installing any third-party agent software on the bare-metal database servers. The migration team needs to map network dependencies (such as active TCP connections and process-level interactions) for the entire application portfolio and track the migration progress in a centralized dashboard. Which strategy should the solutions architect recommend to collect the necessary discovery data while complying with all constraints?
A media production company is building a document collaboration platform that manages transactional metadata (OLTP workload) and shared creative files (File storage workload). The file system must scale to handle millions of small, frequently accessed media assets while maintaining POSIX compliance, and must be replicated to a secondary AWS region with a Recovery Point Objective (RPO) of less than 15 minutes. Additionally, the metadata database must support high-performance transactional updates in the primary region, while providing read capabilities in the secondary region for reporting queries with replication latency under 1 second. Which two strategies should the solutions architect select to meet these requirements?
Geçerli olan tümünü seçin
An organization is establishing a secure deployment pipeline from an external OIDC-compliant CI/CD platform to multiple target AWS member accounts within their AWS Organization. A solutions architect must design a federation trust model that allows runners to assume a deployment role (DeployRole) only when executing workflows from a specific repository (org/repo-a) and branch (main), without relying on long-lived credentials. Which of the following configuration steps must the solutions architect perform to establish this federation model? (Choose TWO.)
Geçerli olan tümünü seçin
An enterprise is planning to migrate a unstructured dataset from an on-premises high-performance NFS file system to Amazon S3. The migration must be completed within a strict timeline of during an upcoming datacenter decommissioning event. The company has a dedicated AWS Direct Connect connection, but only of this connection can be allocated for migration traffic due to concurrent production workloads. Post-migration, the data must be encrypted at rest using a Key Management Service (KMS) key that is shared across multiple AWS accounts to support cross-account collaborative analytics. Furthermore, on-premises applications will continue reading and writing to the NFS share until the final cutover, meaning that any changes written during the bulk data transfer phase must be synchronized to AWS. Which of the following migration strategies is the most efficient and compliant?
A logistics company is preparing to migrate its hybrid workload portfolio to AWS. The on-premises infrastructure consists of 250 VMware vSphere VMs, 40 physical Linux servers, and 10 legacy physical servers running IBM AIX. Outbound internet access from the application subnets is blocked, but an outbound proxy server is available in a management subnet. The company must discover server system configurations, network dependencies, and performance characteristics for migration planning. They also want to track the overall migration progress using AWS Migration Hub.
Which combination of actions will meet these requirements while minimizing administrative overhead? (Select TWO.)
Geçerli olan tümünü seçin
A retail enterprise is migrating its legacy inventory management systems, which include on-premises application servers, to AWS using AWS Application Migration Service (MGN). The enterprise connects its on-premises network to AWS via an AWS Direct Connect connection terminated at an AWS Transit Gateway in a central Transit VPC. The Transit VPC connects to the target Migration VPC. Due to strict corporate security compliance, no internet access is permitted from either the on-premises network or the target Migration VPC. The Solutions Architect has installed the AWS Replication Agent on the on-premises servers, but the replication status shows that the agents are unable to communicate with the AWS MGN replication servers and are failing to register with the service. Which of the following configuration steps must the Solutions Architect take to establish connectivity and ensure successful data replication? (Select TWO.)
Geçerli olan tümünü seçin
A company has two core applications deployed in separate VPCs (`VPC-A` and `VPC-B`) within the `us-east-1` Region. The application in `VPC-A` processes telemetry data and replicates approximately of data monthly to a database cluster in `VPC-B`. Both VPCs are connected via an existing AWS Transit Gateway, which also provides hybrid connectivity to the company's on-premises data center. The finance department has flagged high Transit Gateway data processing charges associated with this inter-VPC replication traffic. Which of the following is the most cost-effective routing architecture to reduce data transfer costs while maintaining the existing hybrid connectivity?
An enterprise manages its multi-account environment using AWS Organizations. The environment is structured with a Root OU, a Security OU containing a dedicated security auditing account, and a Workloads OU containing production application accounts. The enterprise's security posture mandates that:
- Development teams must be blocked from modifying, disabling, or deleting security services (Amazon GuardDuty, AWS CloudTrail, and AWS Config) within their workload accounts.
- The central security team must be able to perform emergency maintenance and updates on these configurations within the workload accounts using a pre-deployed IAM role named SecurityAdmin.
- Operational operations must be delegated away from the management account to maintain isolation.
Which solution meets these requirements with the least operational overhead?
A company is planning to migrate its on-premises Microsoft SQL Server database to an Amazon Aurora MySQL-Compatible Edition DB cluster. The migration must occur with minimal downtime, requiring continuous data replication via Change Data Capture (CDC). The source database contains tables with complex foreign key constraints, and several columns contain VARCHAR(MAX) data with sizes up to 128 KB. A Solutions Architect will use the AWS Schema Conversion Tool (SCT) to convert the schema and AWS Database Migration Service (DMS) for the data migration.
Which of the following actions should the Solutions Architect take to ensure a successful and optimized migration? (Select two.)
Geçerli olan tümünü seçin
A financial institution is migrating a core banking application consisting of physical servers from an on-premises data center to AWS. The replication traffic must flow privately over an existing AWS Direct Connect connection to a staging area VPC, which is connected to a shared services VPC via an AWS Transit Gateway. The Solutions Architect has installed the AWS Replication Agent on the source servers, but the replication status shows that the agents are unable to communicate with the replication servers in the staging area VPC, preventing the initialization of the data replication process.
Which action should the Solutions Architect take to resolve this connectivity issue and allow data replication to begin?
A multinational retail e-commerce company is planning to migrate its core inventory management system and order processing services to AWS. The on-premises infrastructure consists of 350 VMware vSphere virtual machines (VMs) running supported versions of Red Hat Enterprise Linux (RHEL) and Windows Server, and 20 bare-metal physical servers running IBM AIX for legacy transaction ledger processing. Security compliance policies strictly prohibit direct outbound internet access from database and application subnets, requiring all outbound traffic to traverse a centralized forward proxy. The migration team needs to gather detailed configuration, performance metrics (CPU, RAM, disk I/O), network connection dependencies, and process-level information for planning. Additionally, they must track the migration status dynamically in AWS Migration Hub using both AWS and partner migration tools. Which two actions should a solutions architect recommend to collect the discovery data and configure tracking?
Geçerli olan tümünü seçin
A company uses a centralized tooling account to host AWS CodePipeline, which automates application infrastructure deployments across multiple target AWS accounts in an AWS Organization. The pipeline uses AWS CloudFormation to deploy resources, using templates stored in an Amazon S3 bucket in the tooling account. To secure database credentials, the CloudFormation template references secret values stored in AWS Secrets Manager in the tooling account.
During a deployment run, the pipeline fails. The pipeline execution logs indicate that the CloudFormation deployment role in the target accounts cannot retrieve the template artifacts from the S3 bucket, and cannot decrypt the database credentials stored in Secrets Manager.
Which two actions should the Solutions Architect take to resolve these deployment failures? (Select two.)
Geçerli olan tümünü seçin