Tüm alıştırma soruları
1964 soru
A retail company is designing a new global e-commerce order processing platform. The database must support an OLTP workload with strong transactional consistency, scale read operations automatically during flash sales, and support a disaster recovery strategy with a recovery point objective (RPO) of less than 1 minute and a recovery time objective (RTO) of less than 15 minutes. Additionally, corporate security policy mandates that all data be encrypted at rest using a Customer Managed Key (CMK) owned by a centralized security AWS account. Which database and storage strategy meets these requirements with the lowest operational overhead?
A solutions architect is migrating an on-premises Oracle database to an Amazon Aurora PostgreSQL-Compatible Edition DB cluster using AWS Database Migration Service (AWS DMS) and the AWS Schema Conversion Tool (AWS SCT). The solutions architect successfully converts the schema, creates the target tables, and configures an AWS DMS task with full load and Change Data Capture (CDC) enabled. The full load phase completes successfully, but the replication task immediately fails and stalls upon transitioning to the CDC phase. Which two actions should the solutions architect take to resolve this issue and resume replication? (Select two.)
Geçerli olan tümünü seçin
An enterprise has a multi-account AWS environment with VPCs in the us-east-1 and us-west-2 regions. Each region contains an AWS Transit Gateway (TGW-East and TGW-West), and the two Transit Gateways are peered. The on-premises datacenter uses the IP address range .
The datacenter connects to AWS using a Direct Connect Gateway (DXGW) associated with both Transit Gateways via Transit Virtual Interfaces (VIFs). As a backup, AWS Site-to-Site VPN connections are established from the datacenter directly to both TGW-East and TGW-West.
The Solutions Architect must design a routing policy for us-east-1 spoke VPCs to access the network. The policy must prioritize the paths in the following order:
1. Primary: The local Direct Connect link via TGW-East.
2. Secondary: The local backup Site-to-Site VPN via TGW-East.
3. Tertiary: The peered TGW link to TGW-West, then via the us-west-2 Direct Connect link.
Additionally, traffic from the datacenter to the us-east-1 VPCs must prefer the Direct Connect link over the VPN link.
Which TWO configurations should the Solutions Architect implement to meet these requirements?
Geçerli olan tümünü seçin
A media streaming company is setting up centralized logging for its multi-account AWS environment consisting of member accounts managed by AWS Organizations. The security team wants to store all AWS CloudTrail logs in a single Amazon S3 bucket located within a dedicated Security account. The security team also requires that the logs be encrypted at rest using an AWS KMS key that they manage. Which combination of configuration steps will allow AWS CloudTrail to successfully deliver the encrypted logs to the centralized S3 bucket?
An enterprise is configuring federated single sign-on (SSO) for its systems administrators using PingFederate as an external SAML 2.0 Identity Provider (IdP). The administrators must be able to authenticate and access a shared development account in their AWS Organizations. You need to configure the trust relationship in AWS so that the PingFederate IdP can exchange SAML assertions for temporary AWS credentials.
Which of the following configuration steps must be performed in the target AWS account to successfully establish this federation? (Select TWO.)
Geçerli olan tümünü seçin
A pharmaceutical company is migrating its core inventory management system, consisting of 10 on-premises virtual machines, to AWS using AWS Application Migration Service (MGN). The migration network path utilizes a secure IPSec VPN connection terminating on an AWS Transit Gateway, which is associated with a staging VPC. After installing the AWS Replication Agent on the source servers, the replication status displays as stalled. The on-premises network monitoring tools show that the replication agents are failing to communicate with the replication servers in the staging VPC subnet. Which of the following is the most direct and necessary configuration change to resolve this replication issue?
An online education platform leverages AWS Organizations to manage member accounts. To meet strict regulatory standards, the platform's security team needs to implement centralized auditing by consolidating AWS CloudTrail logs from all member accounts into a secure, dedicated Amazon S3 bucket within a centralized Security account. The logs must be encrypted at rest using a key managed by the platform's security team. The setup must ensure that individual member accounts can deliver logs to the central bucket but cannot access or decrypt logs from other accounts. Which configuration strategy should the solutions architect recommend to satisfy these requirements?
An organization needs to migrate of unstructured media files from an on-premises SFTP server to an Amazon S3 bucket located in a separate, newly created AWS account. The organization has a dedicated internet connection available for this migration, and the entire transfer must be completed within days. Active clients must continue to upload new files to the SFTP service during the migration, and the migration must not require client-side configuration or hostname changes. All migrated data must be encrypted at rest in the target S3 bucket using AWS Key Management Service (AWS KMS). Which strategy should a solutions architect recommend to meet these requirements?
A multinational enterprise is migrating its vSphere-based workloads to a VMware Cloud on AWS Software-Defined Data Center (SDDC) linked to a multi-account AWS environment. The workloads to migrate consist of:
1. A production cluster of critical database virtual machines (VMs) that must remain online during the initial data synchronization phase and experience near-zero downtime during the final switchover.
2. A development and testing environment consisting of VMs that can tolerate up to hours of downtime during a scheduled cutover window.
The enterprise has configured a AWS Direct Connect connection to the on-premises data center.
Additionally, the migrated VMs in the SDDC must resolve internal service endpoints in a Private Hosted Zone (PHZ) for `corp.local` hosted in a Shared Services VPC in a separate AWS account. The SDDC is connected to this Shared Services VPC using VMware Cloud on AWS Transit Connect.
Which two actions should the solutions architect take to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A company is planning to migrate its on-premises VMware vSphere virtual machines (VMs) to native Amazon EC2 instances using AWS Application Migration Service (MGN). The migration network path must utilize an existing AWS Direct Connect connection with a backup Site-to-Site VPN. The company's compliance policy mandates that replication traffic must be encrypted and remain entirely within a private network path without traversing the public internet. The migration requires a Recovery Point Objective (RPO) of less than minutes and a replication cutover window with less than minutes of downtime. During the initial agent deployment, the replication status remains in the 'Establishing connection' state, and data replication cannot start. Security groups and network ACLs are configured to allow HTTPS traffic (TCP port 443) to AWS endpoints. Which network configuration modification will resolve the replication connection issue while adhering to all compliance constraints?
An enterprise with member accounts managed under a single organization in AWS Organizations is setting up a centralized logging architecture. The solutions architect is configuring an organization-wide AWS CloudTrail trail to deliver log files to a single Amazon S3 bucket located in a dedicated Log Archive account. To satisfy security policies, all logs must be encrypted at rest using an AWS KMS Customer Managed Key (CMK) managed by the security team, and member account administrators must not be able to disable the trail or modify the logging configurations. Which TWO configurations are required to establish this architecture? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is migrating its legacy database and application servers from an on-premises data center to AWS using AWS Application Migration Service (MGN). The on-premises network is connected to a staging VPC in AWS via an AWS Direct Connect connection attached to an AWS Transit Gateway. Immediately after installing the AWS Replication Agent on the on-premises servers, the migration console shows the replication status as stalled. The on-premises servers cannot establish communication with the replication servers in the staging VPC or the MGN control plane. Which TWO of the following actions must the solutions architect take to resolve this issue and start replication? (Select TWO)
Geçerli olan tümünü seçin
An enterprise needs to migrate of medical imaging data from an on-premises NFSv3 storage system to an Amazon EFS file system. The migration must be completed within a strict window. The enterprise has a dedicated internet connection available for this migration. All data must be encrypted at rest throughout the migration process. Which strategy should a solutions architect recommend to meet these requirements?
An enterprise manages an AWS Organization with fifteen VPCs in a single AWS Region: five Production VPCs, five Development VPCs, and five Shared Services VPCs. The enterprise has established an AWS Direct Connect connection to its on-premises data center. The network design must satisfy the following requirements:
* Production and Development VPCs must be completely isolated from each other.
* Both Production and Development VPCs must be able to communicate with the Shared Services VPCs.
* Only Production VPCs and Shared Services VPCs are permitted to communicate with the on-premises data center.
* Administrative overhead and routing table complexity must be minimized.
The enterprise deploys an AWS Transit Gateway and connects it to a Direct Connect Gateway using a transit virtual interface (Transit VIF).
Which TWO actions should the Solutions Architect take to configure the Transit Gateway routing to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A global retail group manages AWS accounts within an AWS Organization. To comply with strict regulatory audit requirements, a solutions architect must establish an organization-wide AWS CloudTrail trail that delivers log files from all AWS Regions to a centralized Amazon S3 bucket located in a dedicated Auditing account. The organization requires that the logs be encrypted at rest using an AWS Key Management Service (AWS KMS) key. The security team dictates that member accounts must not have permissions to decrypt the CloudTrail logs once written, nor should they be able to disable the logging configuration. Which combination of configuration steps will satisfy these requirements?
An enterprise is configuring federated access to their multi-account AWS environment using an external SAML 2.0 Identity Provider (IdP). The identity team wants to allow users to authenticate through the IdP and assume specific IAM roles in multiple target AWS accounts managed under AWS Organizations. The solutions architect needs to configure the trust relationships and identity provider configurations.
Which TWO configurations must the solutions architect implement to establish this trust and allow users to federate directly into the target accounts? (Select TWO.)
Geçerli olan tümünü seçin
An online travel agency is migrating its legacy customer loyalty application, which runs on 8 on-premises virtual machines, to AWS using AWS Application Migration Service (MGN). The network architecture connects the on-premises data center to a staging VPC in AWS via a 1 Gbps AWS Direct Connect connection terminated at an AWS Transit Gateway. During the migration setup, the MGN agents are successfully installed on the source servers, but the replication status on the MGN console remains stuck in the 'Initiating data replication' state with 0% progress. The network routing and security configurations must maintain a private traffic path. Which of the following actions should the Solutions Architect take to resolve this replication issue?
A company's production application runs on Amazon EC2 instances managed by an Auto Scaling group behind an Application Load Balancer (ALB). A solutions architect is designing a deployment pipeline using AWS CodeDeploy to update the application with zero downtime.
The deployment strategy must meet the following requirements:
1. The new version must be deployed to a completely separate set of EC2 instances for validation.
2. Production traffic must not be routed to the new instances until the development team manually verifies the deployment.
3. Once verified, production traffic must be switched to the new instances.
4. The original EC2 instances must be kept running for 2 hours after traffic is redirected to allow for a quick manual rollback if issues arise, after which they must be terminated.
Which TWO configurations should the solutions architect specify in the AWS CodeDeploy deployment group to meet these requirements? (Select two.)
Geçerli olan tümünü seçin
A medical records company is launching a new patient portal that requires a highly available relational database for a read-heavy OLTP workload. During morning hours, read traffic increases tenfold, while write volume remains low and stable. The database must be encrypted at rest. In the event of an Availability Zone failure, the database must fail over automatically with zero data loss (RPO = 0) and a recovery time of less than 2 minutes (RTO < 2 minutes). Additionally, the database security audit logs must be securely shared with a centralized compliance account in the organization. Which database and storage strategy meets these requirements?
An enterprise is migrating its on-premises VMware vSphere workloads to VMware Cloud on AWS. The virtual machines (VMs) are being migrated to a VMware Cloud on AWS Software-Defined Data Center (SDDC). In the AWS cloud environment, a Route Private Hosted Zone (PHZ) named `corp.internal` is associated with a shared services VPC. The migrated VMs in the SDDC must resolve resources in the `corp.internal` domain. The VMware Cloud on AWS SDDC is connected to the AWS environment using a Transit Gateway via VMware Transit Connect. Which configuration should the solutions architect implement to enable DNS resolution for the migrated VMs?