Tüm alıştırma soruları
1964 soru
An enterprise is reviewing its existing AWS network setup to optimize performance and latency. The architecture consists of multiple VPCs, including a shared services VPC containing a Route 53 Private Hosted Zone (PHZ) for internal service discovery. The instances in the private subnets of a new application VPC need to download software updates from the internet and resolve DNS names hosted in the shared services VPC. Currently, they experience high inter-zone latency and name resolution failures. Which two actions should the solutions architect take to resolve these issues and optimize performance?
Geçerli olan tümünü seçin
A company is designing a new application environment on AWS. The application consists of workloads running in private subnets across two Availability Zones (us-east-1a and us-east-1b) in VPC-A. The workloads in VPC-A must access external updates from the internet securely and also resolve private domain names hosted in a Route 53 Private Hosted Zone in VPC-B. VPC-A and VPC-B are connected using an AWS Transit Gateway. Which two configuration steps should the solutions architect perform to establish secure, redundant internet egress and private DNS resolution? (Select TWO.)
Geçerli olan tümünü seçin
A company hosts a high-frequency flash sale application on a fleet of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application data is stored in an Amazon RDS for MySQL Multi-AZ DB instance. During scheduled weekly flash sales, traffic surges instantly by within two minutes. During these peaks, users experience HTTP 503 Service Unavailable errors, and database read response times increase significantly. A Solutions Architect needs to optimize both compute and storage performance to handle the next flash sale without service degradation.
Which combination of actions should the Solutions Architect take to address these performance issues? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is designing a high-performance network topology to connect its on-premises corporate offices to three VPCs in the `eu-west-1` Region: a shared services VPC and two application spoke VPCs. The architecture requires resilient, private, bidirectional connectivity between the on-premises networks and all VPCs, as well as private DNS resolution. Specifically, DNS queries for the private on-premises domain `corp.internal` must resolve from the application spoke VPCs, and DNS queries for the AWS private domain `aws.internal` must resolve from the on-premises network. The design must also enforce that outbound internet egress from the spoke VPCs is centralized through a firewall cluster in the shared services VPC.
Which of the following configurations should the solutions architect implement to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A solutions architect is auditing a multi-account AWS environment to strengthen identity and access controls. A new member AWS account is placed under an Organizational Unit (OU) that has a Service Control Policy (SCP) attached. The SCP explicitly allows only read and write actions for Amazon S3. The administrator expects the IAM users in the member account to immediately have access to Amazon S3, but the users receive 'Access Denied' errors when attempting to list S3 buckets. Which of the following explains why the users cannot access Amazon S3?
An enterprise has a web application running in a single AWS Region. The application uses an Amazon RDS for PostgreSQL database and an Auto Scaling group of Amazon EC2 instances behind an Application Load Balancer. The Solutions Architect needs to configure a Pilot Light disaster recovery (DR) strategy in a secondary Region. The company requires a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 4 hours. Which of the following actions should the Solutions Architect take to meet these requirements at the lowest cost? (Select TWO.)
Geçerli olan tümünü seçin
A company runs a high-traffic e-commerce application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application reads and writes data to an Amazon Aurora MySQL DB cluster. During seasonal sales events, the application experiences sudden spikes in traffic, leading to CPU exhaustion on the EC2 instances and increased read replication lag on the Aurora database due to a surge in read queries. Which combination of actions should a solutions architect implement to optimize compute and storage performance? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is designing a new VPC named `Production-VPC` in the `us-east-1` Region to host a web application across two Availability Zones, `us-east-1a` and `us-east-1b`. EC2 instances in the private subnets of both zones require outbound internet access to download software updates, but they must not be directly reachable from the internet. The solution must be highly resilient to Availability Zone outages and minimize operational overhead.
Which of the following configuration steps should the Solutions Architect perform to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A financial services firm hosts a critical transactional application on AWS. The application runs on Amazon ECS tasks on AWS Fargate in the us-east-1 Region, across three Availability Zones. The tasks connect to an Amazon Aurora MySQL database cluster in the same Region. Outbound traffic to external payment processors is routed through a single NAT Gateway located in one of the public subnets.
The firm needs to enhance the reliability of the system and establish a disaster recovery (DR) strategy in the us-west-2 Region. The DR solution must support a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 5 minutes. Additionally, the outbound connectivity in the primary Region must be highly resilient against Availability Zone failures.
Which TWO actions should the Solutions Architect take to meet these requirements?
Geçerli olan tümünü seçin
A media processing company hosts a video rendering application across two VPCs in the us-west-2 Region. The rendering nodes in VPC A need to transfer large, uncompressed media files to a storage caching cluster in VPC B. Both sets of EC2 instances are located within the same Availability Zone (us-west-2a). Currently, the VPCs are connected via an AWS Transit Gateway, but the transfer times are high and network latency is inconsistent. The company needs to optimize the network path to maximize throughput and minimize latency between these systems.
Which two actions should the Solutions Architect take to achieve this?
Geçerli olan tümünü seçin
A company is hosting a hybrid application on a fleet of self-managed Linux EC2 instances. The application writes its runtime logs to `/var/log/app/application.log`. These logs are rotated hourly using a log utility that renames the active file to `application.log.YYYY-MM-DD-HH` and creates a new empty `application.log` file. The solutions architect needs to centralize these application logs into an Amazon CloudWatch Logs group in a central Security account. Additionally, the solutions architect must configure a multi-account AWS CloudTrail trail to deliver management events from all AWS accounts in the AWS Organization to a centralized Amazon S3 bucket in the same Security account. Which combination of actions should the solutions architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is designing a highly secure and regulated payment processing network on AWS. The architecture is deployed across three AWS Regions (us-east-1, eu-west-1, and ap-southeast-1) and utilizes a multi-account structure managed under AWS Organizations. A dedicated Shared Services account hosts core services, including a Route 53 Private Hosted Zone (PHZ) named payment.internal. Multiple application accounts contain spoke VPCs that run transactional workloads across multiple Availability Zones. These workloads require resolution of names within payment.internal, resilient outbound internet access, and low-latency hybrid connectivity to an on-premises partner data center via AWS Direct Connect. Which TWO configurations should a solutions architect implement to meet these requirements while preventing single points of failure and routing limitations?
Geçerli olan tümünü seçin
An enterprise SaaS company has a multi-region application deployed in us-west-2 and ap-northeast-1 behind Application Load Balancers (ALBs). Users in Asia are reporting high latency and connection instability when connecting to the application's public endpoints. Additionally, the company's on-premises data center in Tokyo is connected to the ap-northeast-1 VPC via an AWS Direct Connect (DX) connection with a Private Virtual Interface (VIF) to a Virtual Private Gateway (VGW). The Solutions Architect must optimize global network performance, reduce latency for end-users, and enable transitive routing from the on-premises data center to both the ap-northeast-1 and us-west-2 VPCs. Which two actions should the Solutions Architect take to meet these requirements?
Geçerli olan tümünü seçin
An enterprise manages a multi-account environment using AWS Organizations. The transaction workloads run on Amazon ECS on AWS Fargate across several member accounts, with application containers sending log events to local Amazon CloudWatch log groups. To comply with security audits, the enterprise must aggregate all member account AWS CloudTrail trails into a centralized Amazon S3 bucket in a dedicated security account. Additionally, all application logs must be streamed in real-time to an Amazon OpenSearch Service domain located in the security account. Currently, cross-account CloudTrail logs are failing to deliver to the S3 bucket, and application logs remain isolated within their local member accounts. Which combination of actions will securely centralize both the CloudTrail logs and the application logs with the least operational overhead? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise hosts a critical transaction session synchronization layer across two AWS Regions. The compute layer runs on Amazon Elastic Container Service (Amazon ECS) on AWS Fargate in a Production Account. The caching and session state layer is managed by an Amazon ElastiCache for Redis Global Datastore, with the primary cluster in us-east-1 and a read-only secondary cluster in us-west-2. Internal microservices resolve the Redis cluster endpoint using a Route 53 Private Hosted Zone (PHZ) for cache.internal managed in a separate Shared Services Account. The enterprise wants to optimize their disaster recovery (DR) strategy to achieve a Recovery Time Objective (RTO) of under 10 minutes and a Recovery Point Objective (RPO) of under 1 minute. During a DR simulation where a primary region outage is simulated, the secondary ECS tasks in us-west-2 fail to resolve cache.internal, and write operations to the cache in us-west-2 are blocked because the secondary cluster remains read-only. Which TWO actions should the Solutions Architect take to resolve these issues and establish a reliable multi-region DR failover process?
Geçerli olan tümünü seçin
A financial transaction processor uses AWS Organizations to manage multiple member accounts. Under PCI-DSS compliance requirements, all payment gateway application logs must be secured and centrally archived. The payment gateway runs on Amazon ECS using AWS Fargate within a Production account (). These logs must be written directly to a centralized Amazon S3 bucket located in a Security Auditing account (). The S3 bucket is configured with default encryption using a customer-managed AWS KMS key (KMS CMK) to enforce security team control over key rotation and policies. The architecture must enforce the principle of least privilege, preventing unauthorized internal access from other accounts within the AWS Organization.
Which two configurations are required to establish this secure log transport?
Geçerli olan tümünü seçin
An enterprise financial analytics company runs daily risk simulation models on AWS. The simulation runs on a fleet of Amazon EC2 `c5.4xlarge` instances in an Auto Scaling group. The simulations read a massive set of historical market data (around ) from an Amazon S3 bucket at the start of each run and write massive temporary scratch files (up to per instance) during execution.
Currently, the EC2 instances are configured with a single General Purpose SSD (gp3) EBS volume for both the operating system and scratch space. During the run, the company observes that scratch writes hit I/O limits, causing CPU utilization to drop while waiting for I/O. Additionally, the initial download of the historical market data from S3 takes over , delaying the start of the simulation.
Which two modifications should the Solutions Architect implement to optimize the compute and storage performance for this workload? (Select two.)
Geçerli olan tümünü seçin
A financial services firm runs a real-time risk analysis engine on Amazon EC2 instances in an Auto Scaling group. The instances process large market feeds retrieved from an Amazon S3 bucket, write large temporary datasets to attached EBS `gp3` volumes, and query metadata from an Amazon Aurora PostgreSQL database.
During market open hours, the following performance bottlenecks are observed:
* The EC2 instances experience high I/O wait times; the EBS volumes are operating at the baseline performance of and throughput.
* The application receives HTTP (Slow Down) errors from Amazon S3 due to a high volume of concurrent GET requests directed at a single date-based folder structure (e.g., `s3://bucket/year=2026/month=07/day=16/`).
* Read queries to the Aurora database experience high latency due to transient read spikes, and the application requires read-scaling without impacting write performance.
Which combination of actions will optimize compute and storage performance while resolving these bottlenecks? (Select TWO.)
Geçerli olan tümünü seçin
A financial technology company deploys a multi-tenant payment gateway application across multiple AWS accounts managed under a single organization in AWS Organizations. The application is hosted on Amazon EC2 instances within Auto Scaling groups. The application writes transaction events locally to /var/log/payment-app/transaction.log. A local script rotates these log files hourly by appending the current timestamp to the filename (e.g., transaction.log.2026-07-16-11) and creating a new empty transaction.log file.
To comply with audit regulations, all transaction logs must be aggregated in near real-time into a centralized Amazon S3 bucket located in a dedicated Security account. The logs must be encrypted at rest using a Customer Managed Key (CMK) in AWS KMS, and the architecture must prevent log loss or duplicate log ingestion.
Which combination of actions should a solutions architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A solutions architect is configuring an active-passive multi-region disaster recovery solution using Amazon Route 53 failover routing. The architect creates a primary failover record pointing to the application load balancer in the primary region, and a secondary failover record pointing to the disaster recovery site in the secondary region. During a failure drill, the primary region is simulated to be completely offline, but client traffic continues to be routed to the primary region. What is the most likely cause of this behavior?