Tüm alıştırma soruları
1964 soru
An enterprise manages a multi-account AWS environment using AWS Organizations. The security team has established a centralized identity account containing a SAML 2.0 Identity Provider (IdP) integration. Users first authenticate via the IdP to assume a central broker role (`arn:aws:iam::111111111111:role/FederatedHubRole`) in the identity account. From this central hub, users must transition to target execution roles (e.g., `arn:aws:iam::222222222222:role/TargetExecutionRole`) in various member accounts to perform administrative tasks. During deployment, federated users receive an access denied error when attempting to assume the target execution roles in the member accounts. Which configuration of the target execution role's trust policy will resolve the access issues and permit users to access resources in the member accounts?
A global logistics company is migrating its supply chain management systems to AWS. The company is using AWS Organizations to manage a multi-account environment. A central Shared Services account contains a VPC connected to the on-premises corporate network via AWS Transit Gateway and AWS Direct Connect. The Shared Services account hosts a Route 53 Private Hosted Zone (PHZ) for corp.internal containing service endpoints. A Production account and a Development account each have a VPC connected to the Transit Gateway. The on-premises network uses the domain onprem.internal for its internal DNS. The solutions architect must design a hybrid DNS solution that allows EC2 instances in the Production and Development VPCs to resolve hosts in both corp.internal and onprem.internal, and on-premises client machines to resolve hosts in corp.internal. The architecture must minimize cost by avoiding redundant endpoints, and must scale as new VPCs are added to the organization. Which of the following strategies should the solutions architect implement to achieve these requirements?
A company is setting up a multi-account environment using AWS Organizations. The cloud engineering team wants to allow developers in various member accounts to launch Amazon EC2 instances into a set of pre-defined private subnets located in a central VPC. To simplify administration and maintain control over IP address allocation, the team wants to share these subnets directly without creating separate VPCs or peering connections. Which approach should the solutions architect recommend to share these subnets with the member accounts?
A financial services organization is consolidating its infrastructure under AWS Organizations with consolidated billing enabled. To streamline operations and minimize costs, the infrastructure team wants to implement a shared VPC model where a centralized network account hosts and shares subnets with individual application accounts. The application accounts run various containerized and serverless workloads on Amazon EC2, AWS Fargate, and AWS Lambda. Additionally, the compliance team requires that AWS CloudTrail logs from all member accounts be written to a single Amazon S3 bucket in a dedicated security audit account, encrypted using keys that support cross-account sharing and customized key rotation schedules.
Which TWO actions should the Solutions Architect take to meet these requirements?
Geçerli olan tümünü seçin
A multinational enterprise manages a multi-account environment under AWS Organizations with all features enabled. The architecture includes a management account, a centralized shared services account, and multiple member accounts allocated to external clients. The enterprise wants to implement the following requirements:
* Provide a customized chargeback billing view to specific client accounts. The clients must see a consolidated invoice showing a flat markup on all Amazon EC2 and Amazon RDS resources, while ensuring that enterprise-level Savings Plans and Reserved Instance (RI) discounts applied at the management account are not visible or shared with these client accounts.
* Share a centralized AWS Glue Data Catalog located in the shared services account with the client accounts so they can perform cross-account Amazon Athena queries without duplicating catalog metadata. This resource sharing must be restricted strictly to the enterprise's AWS Organization.
* Purchase a Savings Plan that provides the maximum discount coverage for client workloads running on a mix of Amazon EC2 instances, AWS Lambda, and AWS Fargate on Amazon EKS.
Which combination of actions will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A retail company is migrating its regional store inventory management system to AWS. The architecture requires connecting spoke VPCs, each owned by a different AWS account within the same AWS Organization, to a shared on-premises system. A Solutions Architect plans to deploy AWS Transit Gateway in a dedicated network hub account.
Which TWO configurations must the architect perform to establish basic multi-account network connectivity between the spoke VPCs and the shared Transit Gateway? (Select TWO.)
Geçerli olan tümünü seçin
A company has four VPCs across multiple AWS accounts in the same AWS Region. They need to design a network architecture that allows all VPCs to communicate with each other and also connect to their on-premises data center using a single existing AWS Direct Connect connection. Which of the following architectures meets these requirements with the least operational complexity?
An enterprise is implementing a federated identity solution using an external SAML 2.0 compliant identity provider (IdP) to grant database administrators single sign-on access to Amazon RDS databases across multiple member accounts in AWS Organizations. The solutions architect has configured the SAML identity provider entity in each AWS account. However, during initial testing, users attempting to federate from the IdP dashboard receive an access denied error before they can choose a role. Which configuration step must the solutions architect perform to resolve this authentication error?
An enterprise manages its multi-account environment using AWS Organizations. The structure consists of a Management account, a Security organizational unit (OU) containing a Security Audit account, and several workload OUs containing production and development accounts. The security team designates the Security Audit account as the delegated administrator for Amazon GuardDuty and AWS Security Hub. The team requires that member accounts in the workload OUs must be prevented from disabling GuardDuty or Security Hub, and any new accounts created in or moved to these OUs must have these services enabled automatically. However, the Security Audit account must maintain the ability to configure, update, and disable these services across all member accounts for troubleshooting purposes. Which strategy meets these requirements with the least operational overhead?
A global logistics provider is establishing a hybrid DNS architecture. On-premises servers must resolve DNS names in an AWS Private Hosted Zone (PHZ) named corp.logistics.aws associated with AWS VPCs. Conversely, EC2 instances inside AWS VPCs must resolve DNS names for on-premises servers under the domain onprem.logistics.local. A centralized network VPC contains the hybrid connectivity interfaces. Which configuration steps must the solutions architect perform to establish two-way DNS resolution? (Select TWO.)
Geçerli olan tümünü seçin
A logistics company is designing a multi-account AWS environment in the `us-east-1` Region. The architecture consists of spoke VPCs for different business units, a central inspection VPC for outbound internet traffic, and a shared services VPC that hosts common tools and a Route 53 Private Hosted Zone (PHZ) named `logistics.local`.
The company's network requirements are:
1. All spoke VPCs must route outbound internet traffic through the central inspection VPC.
2. The egress architecture must be highly available and resilient to Availability Zone (AZ) failures.
3. Resources in all spoke VPCs must resolve DNS queries for `logistics.local`.
4. Operational complexity and cost must be minimized.
Which architecture meets these requirements?
A financial services firm is designing a hybrid network architecture to connect spoke VPCs in the `eu-west-1` Region to its on-premises data centers in London () and Dublin (). Each spoke VPC is attached to a centralized AWS Transit Gateway (TGW) in the `eu-west-1` Region.
The architecture must meet the following requirements:
- The London data center must connect to AWS using a AWS Direct Connect (DX) connection as the primary path, and a redundant IPsec VPN connection over the internet as a backup.
- The Dublin data center must connect to AWS using a separate DX connection as the primary path, and a redundant IPsec VPN connection over the internet as a backup.
- If the local DX connection fails, traffic to and from that data center must fail over to its local VPN connection.
- A data center must only route traffic through the other data center's connections if both its local DX and VPN connections are unavailable.
- Asymmetric routing must be avoided, and BGP routing must be configured dynamically.
Which two configuration options should the solutions architect implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A global financial enterprise is migrating its workload to a multi-account, multi-region AWS environment. They have spoke VPCs distributed across the `us-east-1` and `eu-west-1` Regions. The enterprise must establish a hybrid network architecture connecting these VPCs to their on-premises data centers in New York and London. The design must meet the following requirements:
- Primary high-bandwidth connectivity must use AWS Direct Connect.
- Private IP communication is required between all spoke VPCs across both Regions and the on-premises data centers.
- An IPsec VPN over the public internet must serve as an active-passive backup to the Direct Connect connections.
- The design must minimize administrative overhead and avoid manual routing table updates when VPCs are added or removed.
Which TWO actions should the solutions architect take to meet these connectivity requirements?
Geçerli olan tümünü seçin
A company is deploying a new version of a microservice hosted on AWS Lambda. The deployment process must ensure zero downtime. The system must route of the incoming traffic to the new version of the function for a duration of minutes. If there are no errors, all remaining traffic must be routed to the new version immediately. If errors are detected, the deployment must automatically roll back.
Which two options should the solutions architect combine to achieve this deployment strategy? (Select two.)
Geçerli olan tümünü seçin
A solutions architect is designing a centralized logging solution for an AWS Organization with multiple member accounts. The security team requires all AWS CloudTrail logs to be consolidated into a single Amazon S3 bucket located in a dedicated Security account. The architecture must support encryption at rest for the log files. Which configuration meets these requirements?
A company manages a multi-account AWS environment under AWS Organizations. The network engineering team has created a central VPC in a Shared Services account and wants to share specific subnets with development accounts in the Organization to streamline IP address management. Additionally, the finance team has purchased a Compute Savings Plan in the management account to cover compute usage across the Organization, but wants to exclude a subset of testing accounts from benefiting from these discounts to accurately track their un-discounted research and development (R&D) costs.
Which of the following actions should the Solutions Architect recommend to achieve these goals? (Select TWO.)
Geçerli olan tümünü seçin
An organization wants to configure federated single sign-on (SSO) to allow corporate users to access the AWS Management Console using their existing on-premises SAML 2.0 compliant Identity Provider (IdP). To establish this trust relationship, which of the following configuration steps must be performed within AWS Identity and Access Management (IAM)? (Select TWO.)
Geçerli olan tümünü seçin
An organization needs to implement basic governance controls across its multi-account environment using AWS Organizations. The administrator wants to ensure that member accounts cannot disable AWS CloudTrail and cannot delete a centralized IAM role used for security auditing.
Which of the following actions should the administrator take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is designing a multi-account strategy using AWS Organizations. The architecture consists of a management account, a shared network account, a centralized security logging account, and multiple application accounts organized into a Developer Organizational Unit (OU). The Solutions Architect must implement the following requirements:
1. Share VPC subnets created in the shared network account with the Developer OU to enable application deployment.
2. Capture VPC Flow Logs from the shared subnets and centralize them into an Amazon S3 bucket in the security logging account. The log files must be encrypted at rest using an AWS KMS key.
3. Maximize cost savings across the organization's compute portfolio, which includes Amazon EC2 instances, AWS Fargate tasks, and AWS Lambda functions.
Which combination of actions should the Solutions Architect take to meet these requirements securely and efficiently? (Select TWO.)
Geçerli olan tümünü seçin
A company's security team is setting up identity federation to allow corporate users to access the AWS Management Console of a member account. The users will authenticate using an external SAML 2.0 Identity Provider (IdP). An IAM SAML identity provider entity has been created in the target AWS account. The solutions architect now needs to configure the trust policy of the IAM role that the federated users will assume. Which configuration must be specified in the trust policy to allow users authenticated by the SAML IdP to assume this role?