Global Content Delivery Flashcards

1
Q

Regional service handles the complexity of creating, storing, and renewing public and private SSL/TLS X.509 certificates and keys that protect your AWS websites and applications

A

AWS Certficate manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Applications need to trust

A

Private Certificate Authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Browers trust a list of providers which can trust other providers

A

Public Certificate Authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CloudFront and Load Balancers are the only supported services for ACM

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can EC2 be used with ACM?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can you use Certifications from one region in another region?

A

No, certifications cannot leave the region they are generated/imported from

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In CloudFront if you want to add certificates the always need to be in US East 1

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Do self signed certificates work in CloudFront?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The two SSL connections in CloudFront (viewer -> CF, CF -> origin) both need to have public certificates

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

TLS extension which tells the server which domain name it is trying to access

A

SNI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Restrict s3 access so that it is only accessible via CloudFront distribution

A

S3 origin with legacy access identites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

if using an S3 origin are the viewer and origin protocols the same?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Used to secure custom Origins

A

Custom headers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Provide Access to one object

A

SignedURLS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

If client doesnt support cookies which should you use

A

SignedURLS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Provides access to groups of objects which are all the same type

A

SignedCookies

17
Q

allow lightweight lambda functions at edge locations

A

Lambda@Edge

18
Q

Lambda@Edge only supports Node.js and Python

A

True

19
Q

Allows single IP to be in multiple locations

A

Anycast IP

20
Q

Data transits globally across the AWS global backbone network directly under AWS control and with fewer hops

A

Global accelerator