Tüm alıştırma soruları
1964 soru
A healthcare enterprise is designing a new cloud-native patient monitoring platform. The architecture comprises a high-throughput telemetry service (NoSQL database workload) and a medical imaging archiving service (Object storage workload). The solution must span two AWS accounts: a Production account (where applications run in the us-east-1 primary region and us-west-2 secondary region) and a centralized Security account.
The system must satisfy the following design constraints:
- Telemetry database writes must support low-latency ingest, and read availability must be maintained in both regions. The disaster recovery requirements dictate a Recovery Time Objective (RTO) of less than 10 minutes and a Recovery Point Objective (RPO) of less than 1 minute.
- Imaging reports must be written directly from application servers in the Production account to an Amazon S3 bucket in the Security account.
- The S3 bucket data must be encrypted at rest. To comply with corporate audits, the encryption keys must support custom rotation schedules and policy-based delegation. The application servers in the Production account must have permission to upload objects and read them back.
Which database and storage strategy meets these requirements?
A digital media platform is planning a large-scale migration of its application portfolio to AWS. The current on-premises infrastructure consists of 150 VMware vSphere virtual machines (VMs) and 25 physical bare-metal servers running CentOS. Due to strict corporate security and compliance policies, installing any software agents on the VMware VMs is strictly prohibited. However, agents are permitted on the physical bare-metal servers. The Solutions Architect must collect CPU and memory utilization history for right-sizing calculations across all servers, determine network dependencies for the physical servers to plan migration groups, and consolidate all tracking data in AWS Migration Hub. Which TWO actions should the Solutions Architect take to perform this discovery and tracking? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise is migrating its legacy document management system to AWS. The system contains of unstructured data stored on on-premises Network File System (NFS) and Server Message Block (SMB) file shares. The company has a AWS Direct Connect connection, but only of this bandwidth can be dedicated to the migration due to ongoing production traffic. The migration must be completed, validated, and fully cut over within a strict window. In addition, external partners must continue to upload daily delta feeds (approximately per day) using the SFTP protocol. The files must be stored in the destination Amazon S3 bucket and encrypted at rest using an AWS Key Management Service (AWS KMS) Customer Managed Key (CMK). Which combination of actions will meet these requirements in the most operationally efficient manner? (Select TWO.)
Geçerli olan tümünü seçin
An aerospace defense company is migrating its multi-tier application portfolio to AWS and must centralize tracking in AWS Migration Hub. The current on-premises environment consists of:
* 200 standard VMware vSphere virtual machines (VMs) running supported Windows and Linux distributions where network dependency mapping is required to group servers into applications.
* 50 highly secured VMware vSphere VMs containing export-controlled data. Regulatory compliance strictly forbids installing third-party agent software or modifying guest configurations, though hypervisor-level monitoring is permitted.
* 50 legacy physical servers running custom Linux distributions with kernels older than version 2.6.18, which cannot be virtualized or upgraded prior to migration.
The migration will be executed using a combination of AWS Application Migration Service (MGN) and a supported partner-developed migration tool.
Which of the following actions must the Solutions Architect take to perform discovery and track migration progress? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise runs an application on Amazon EC2 instances inside a private subnet in VPC A under AWS Account A. The application must retrieve sensitive database credentials stored in AWS Secrets Manager inside a central security account (Account B). Currently, the EC2 instances access Secrets Manager via an Interface VPC Endpoint (AWS PrivateLink) created in VPC A. To strengthen network and identity security, the solutions architect must ensure that only these specific application EC2 instances can retrieve this particular secret, and that no other resources in VPC A can use the Interface VPC Endpoint to access Secrets Manager. Which combination of actions will meet these requirements?
A digital ticketing platform hosts high-profile concert ticket releases on AWS. During these releases, traffic surges from requests per second to over requests per second within a -minute window. The current architecture uses an Application Load Balancer (ALB) to distribute traffic to an Auto Scaling group (ASG) of Amazon EC2 instances in private subnets. The instances use a custom AMI with an application that takes minutes to bootstrap and pass health checks. Outbound licensing checks are routed through a single NAT Gateway in a single Availability Zone.
During recent releases, users experienced HTTP Service Unavailable errors during the first few minutes of the surge. Additionally, the ASG over-provisioned instances, launching far more than needed before the initial scale-out instances could finish bootstrapping. Finally, a brief outage in the Availability Zone containing the NAT Gateway prevented licensing checks for all instances.
Which combination of actions should a solutions architect take to resolve these issues? (Select TWO.)
Geçerli olan tümünü seçin
A company needs to migrate of unstructured data from an on-premises SMB file share to an Amazon S3 bucket within a strict window. The company has a internet connection, but only can be allocated for the migration to avoid impacting production operations. During the migration, the on-premises data will continue to be modified, producing approximately of new or changed files weekly. All migrated data must be encrypted at rest in Amazon S3 using a Customer Managed Key (CMK) in AWS KMS to comply with strict security auditing policies. After the migration, external business partners must be able to securely access specific subsets of the data using the SFTP protocol, authenticating against the company's existing on-premises Active Directory. Which migration and access strategy meets these requirements with the least administrative effort and lowest risk of exceeding the timeline?
A medical diagnostics company is designing a multi-account architecture using AWS Organizations. The organization consists of a Management account, a Security Operations account, and a Production organizational unit (OU) containing multiple application member accounts.
The solutions architect must design a governance strategy to meet the following requirements:
1. Enable centralized management of AWS Security Hub and AWS Backup from the Security Operations account, ensuring that administrative operations can be performed without logging into the Management account.
2. Enforce that all Amazon EC2 instances and Amazon RDS DB instances launched within the Production OU are tagged with a valid 'CostCenter' key and value. Non-compliant resource creation must be blocked at API call time.
3. Ensure that an automated disaster recovery (DR) service, which runs under a cross-account IAM role named 'DR-Automation-Role' from a dedicated DR account, can still launch EC2 instances in the Production OU without being blocked by the tag enforcement.
Which combination of actions should the solutions architect take to meet these requirements with the least administrative overhead?
An e-commerce enterprise is migrating its legacy inventory management servers from an on-premises data center to AWS using AWS Application Migration Service (MGN). The replication path must use a private network link via an existing AWS Direct Connect connection, avoiding the public internet. The staging area VPC in AWS has no route to the internet. During initial setup, the MGN agents installed on the on-premises servers fail to communicate with the staging area in AWS, and replication status remains in the initiating phase. Which of the following actions should the solutions architect take to resolve this connectivity issue and enable private replication? (Select TWO.)
Geçerli olan tümünü seçin
A multinational retail corporation is planning to migrate its hybrid e-commerce and inventory management platform to AWS. The on-premises infrastructure is distributed as follows:
* virtual machines (VMs) hosted on a VMware vSphere cluster. The Solutions Architect must perform detailed network dependency mapping (including active inbound and outbound TCP connections and process-level details) to design AWS Security Groups and identify migration waves.
* bare-metal physical servers running Red Hat Enterprise Linux (RHEL) that host the core database tier. The corporate security and compliance policy strictly prohibits the installation of any third-party software agents on these database systems.
* legacy bare-metal physical servers running IBM AIX that run proprietary inventory lookup services.
The migration must be tracked centrally in AWS Migration Hub. The business requires the integration of both AWS migration tools and custom third-party migration tracking systems to monitor the migration status of all servers.
Which of the following actions should the Solutions Architect take to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
Solas Energy is modernizing its on-premises grid monitoring application by migrating it to AWS. The application consists of a Java-based API and a worker service that processes telemetry data. The target state requires hosting the containers on Amazon ECS with AWS Fargate for serverless operations. The API must be accessible only from a consumer VPC in a separate AWS account via a private connection. The worker service requires access to an Amazon DynamoDB table in the same account and must pull container images from a centralized Amazon ECR repository in a shared services account. The migration design must ensure high availability, use private endpoints, and avoid traversing the public internet.
Which combination of actions should the Solutions Architect implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A company is planning to migrate a legacy on-premises IBM Db2 LUW database to an Amazon Aurora PostgreSQL-Compatible Edition DB cluster. The database contains complex SQL PL stored procedures and triggers. The migration must minimize downtime and allow the database to remain online during the migration process. Which two actions should the Solutions Architect perform to convert the schema and configure the database replication?
Geçerli olan tümünü seçin
A company is designing an automated pipeline to deploy and update application configuration parameters on Amazon EC2 instances across multiple AWS accounts within an AWS Organization. The solution must support dynamic configuration updates without requiring instance recreation, enable automatic rollbacks if Amazon CloudWatch alarms detect application errors during the rollout, and use a centralized encryption key to secure the configurations at rest. Which of the following solutions meets these requirements?
A financial technology company is designing a new high-throughput transaction processing application. The solutions architect must design the database and storage tier to meet the following requirements:
* A relational database to store account balances. The database must automatically scale read capacity during high-traffic events, support automatic failover across multiple Availability Zones, and meet a near-zero RTO and RPO for regional disaster recovery.
* A shared file system to store application configuration files. The file system must be concurrently accessible by multiple Amazon EC2 instances across multiple Availability Zones.
* All data at rest must be encrypted, and the encryption keys must be managed in a way that allows cross-account access for the security auditing team.
Which two configurations should the solutions architect select to meet these requirements?
Geçerli olan tümünü seçin
A solutions architect is planning the heterogeneous migration of a 5 TB on-premises Microsoft SQL Server database to an Amazon Aurora PostgreSQL-Compatible Edition DB cluster. The migration must minimize application downtime. The solutions architect has already used the AWS Schema Conversion Tool (AWS SCT) to convert the schema and apply it to the target Aurora DB cluster. An AWS Database Migration Service (AWS DMS) replication task with 'Full load and ongoing replication' is configured. During testing, the replication task successfully completes the full load phase, but changes made on the source database after the full load started are not being replicated to the target database. Which of the following is the required configuration change to enable ongoing replication?
A multinational retail corporation is migrating its supply chain management platform to AWS. The current on-premises environment consists of 300 VMware vSphere virtual machines (VMs) running Windows Server 2022 and Red Hat Enterprise Linux 8, and 50 bare-metal legacy servers running IBM AIX on POWER processors. Corporate compliance mandates that no software agents may be installed on any production server operating systems. The on-premises network has no direct internet connectivity, but an HTTP proxy is available for outbound HTTPS traffic (port 443) to AWS endpoints without SSL decryption. The company wants to use AWS Migration Hub to track the migration, utilizing both partner-integrated third-party tools and AWS migration tools. Which strategy should a solutions architect recommend to perform the discovery and track the migration progress?
A company is implementing a multi-account federation solution using an external SAML 2.0 Identity Provider (IdP). The solutions architect configures a SAML provider in the primary AWS account and wants to allow federated users to assume a specific IAM role across multiple target member accounts in the AWS Organization. During testing, users receive an access denied error when attempting to authenticate and assume the role in the member accounts. Which of the following configurations is required to successfully establish this federated access to the target member accounts?
A company runs a high-performance compute (HPC) cluster on Amazon EC2 instances in private subnets across two Availability Zones (`us-west-2a` and `us-west-2b`). The instances continuously read and write shared datasets on an Amazon EFS file system in the same Region, processing approximately of data per month. A review of the monthly AWS bill reveals high Inter-AZ Data Transfer charges for EFS access, despite the EFS file system having mount targets in both Availability Zones. Investigation reveals that the EC2 instances are mounted to the EFS file system using the static IP address of the mount target in `us-west-2a` to simplify configuration management. Which of the following changes will minimize the data transfer costs while maintaining the required file sharing capability?
VeloDynamics Manufacturing is modernizing its transaction-clearing microservices by migrating them from on-premises virtual machines to Amazon EKS in a multi-account AWS environment. The EKS worker nodes must be deployed in a highly constrained VPC where the primary subnet allocated for nodes is a single block (), which cannot be expanded due to tight integration with the corporate Transit Gateway mesh. The microservices must scale up to concurrent pods during peak clearing cycles. The pods must communicate with on-premises mainframe databases over AWS Direct Connect via an AWS Transit Gateway. The on-premises firewalls and routing tables are strictly managed and will only route traffic originating from the node primary subnet (); adding routes for new CIDR blocks to the on-premises network is prohibited. Additionally, client applications in other VPCs must connect to the services via an Application Load Balancer (ALB) with direct routing to pods (minimal network hops) to meet latency SLAs. Which of the following architectures meets these requirements with the least operational overhead?
A Solutions Architect is designing the migration of an on-premises Microsoft SQL Server database to an Amazon Aurora PostgreSQL-Compatible Edition DB cluster. The migration must be completed with minimal downtime, and the application must continue writing to the source database during the replication process. Which two actions must the Solutions Architect take to support the schema conversion and data replication phases? (Select two.)
Geçerli olan tümünü seçin