CLF-C02 (Ref EXM 1) Flashcards

1
Q

What are the three fundamental drivers of cost with AWS?

A

compute, storage, and outbound data transfer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Amazon DynamoDB?

A

A fully managed, serverless, key-value NoSQL database designed to run high-performance applications at any scale

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some things DynamoDB offers?

A

DynamoDB offers built-in security, continuous backups, automated multi-region replication, in-memory caching, and data export tools.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Amazon Macie?

A

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect your sensitive data in AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is AWS EC2 Instance Store?

A

An instance store provides temporary block-level storage for your instance. (Low latency storage, data does not persist when the instance is terminated).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a EC2 Dedicated Host ?

A

An Amazon EC2 Dedicated Host allows you to use your eligible software licenses from vendors such as Microsoft and Oracle on Amazon EC2 so that you get the flexibility and cost-effectiveness of using your licenses, but with the resiliency, simplicity, and elasticity of AWS. (It is a physical server).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the pretenses for removing an AWS account?

A

The AWS account must be able to operate as a standalone account. Only then it can be removed from AWS organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Amazon Transcribe?

A

It is a way to add speech-to-text capability to your applications. (Uses deep learning process ASR to convert speech to text quickly and accurately).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are three best practice areas for Reliability in the cloud?

A

Foundations, Change Management, and Failure Management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is AWS X-Ray used for?

A

You can use AWS X-Ray to analyze and debug serverless and distributed applications such as those built using a microservices architecture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which security service of AWS is enabled for all AWS customers, by default, at no additional cost?

A

AWS Shield Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How is AWS Web Application Firewall (AWS WAF) charged?

A

AWS WAF charges based on the number of web access control lists (web ACLs) that you create, the number of rules that you add per web ACL, and the number of web requests that you receive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is AWS Secrets Manager?

A

The service enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is AWS Shield?

A

AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Amazon CloudWatch?

A

It is a service that monitors applications, responds to performance changes, optimizes resource use, and provides insights into operational health

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What can CloudWatch be used for?

A

CloudWatch provides data and actionable insights to monitor applications, respond to system-wide performance changes, optimize resource utilization, and get a unified view of operational health.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is AWS Key Management Service (AWS KMS) ?

A

AWS Key Management Service (KMS) makes it easy for you to create and manage cryptographic keys and control their use across a wide range of AWS services and in your applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the differences between Dedicated Hosts and Dedicated Instances?

A

https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-overview.html

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which 2 AWS services support VPC Endpoint Gateway?

A

Only Amazon S3 and Amazon DynamoDB support VPC gateway endpoint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the minimum time charge for Linux EC2 instances?

A

One-minute minimum charge for Linux based EC2 instances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which of the following AWS Support plans provide access to guidance, configuration, and troubleshooting of AWS interoperability with third-party software?

A

AWS Business Support and AWS Enterprise Support

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What services do you get for AWS Enterprise Support?

A

You get 24x7 technical support from high-quality engineers, tools and technology to automatically manage the health of your environment, consultative architectural guidance delivered in the context of your applications and use-cases, and a designated Technical Account Manager (TAM) to coordinate access to proactive/preventative programs and AWS subject matter experts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What services do you get for AWS Business Support?

A

You get 24x7 phone, email and chat access to technical support and architectural guidance in the context of your specific use-cases. You get full access to AWS Trusted Advisor Best Practice Checks. You get access to guidance, configuration, and troubleshooting of AWS interoperability with many common operating systems, platforms, and application stack

24
Q

What services do you get for AWS Developer Support?

A

This plan also supports general guidance on how services can be used for various use cases, workloads, or applications. You do not get access to Infrastructure Event Management with this plan.

25
Q

What services do you get for AWS Basic Support?

A

You get 24x7 access to customer service, documentation, whitepapers, and support forums. AWS Trusted Advisor - Access to the core Trusted Advisor checks and guidance to provision your resources following best practices to increase performance and improve security?

26
Q

What is AWS Compute Optimizer?

A

AWS Compute Optimizer recommends optimal AWS resources for your workloads to reduce costs and improve performance by using machine learning to analyze historical utilization metrics?

27
Q

What are AWS Budgets ?

A

AWS Budgets allows you to set custom budgets to track your cost and usage from the simplest to the most complex use cases.

28
Q

What is AWS Cost Explorer?

A

AWS Cost Explorer has an easy-to-use interface that lets you visualize, understand, and manage your AWS costs and usage over time.

29
Q

What is Amazon Inspector?

A

Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on your Amazon EC2 instances.

30
Q

What is customer managed key (CMK)?

A

Customer managed keys are KMS keys in your AWS account that you create, own, and manage.

31
Q

What is AWS Software Developer Kit (SDK)?

A

SDKs take the complexity out of coding by providing language-specific APIs for AWS services.

32
Q

Shared Responsibility Model Overview:

A

https://aws.amazon.com/compliance/shared-responsibility-model/

33
Q

What is AWS Deep Glacier Archive?

A

Amazon S3 Glacier Deep Archive is Amazon S3’s lowest-cost storage class and supports long-term retention and digital preservation for data that may be accessed once or twice in a year. (Reference to storage classes https://aws.amazon.com/s3/storage-classes/ )

34
Q

What is AWS Professional services?

A

The AWS Professional Services organization is a global team of experts that can help you realize your desired business outcomes when using the AWS Cloud?

35
Q

What is AWS Partner Network?

A

The AWS Partner Network (APN) is the global partner program for technology and consulting businesses that leverage Amazon Web Services to build solutions and services for customers.

36
Q

What are the 7 AWS Route 53 routing policies?

A

Simple routing
Failover routing
Geolocation routing
Geoproximity routing (traffic flow only)
Latency-based routing
IP-based routing
Multivalue answer routing
Weighted routing.(link https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-policy.html)

37
Q

What is AWS CloudTrail Logs?

A

AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. (Has encryption enabled by default)

38
Q

What is Amazon Redshift?

A

Amazon Redshift is a fully-managed petabyte-scale cloud-based data warehouse product designed for large scale data set storage and analysis.

39
Q

What are AWS security groups?

A

A security group acts as a virtual firewall for your instance to control inbound and outbound traffic. Security groups act at the instance level, not at the subnet level. You can specify allow rules, but not deny rules. https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html

40
Q

What is a network ACL?

A

A network access control list (network ACL) is an optional layer of security for your VPC that acts as a firewall for controlling traffic in and out of one or more subnets (i.e. it works at subnet level).
https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html

41
Q

What is Amazon Elastic Block Store (EBS) ?

A

is an easy to use, high-performance block storage service designed for use with Amazon Elastic Compute Cloud (EC2) for both throughput and transaction-intensive workloads at any scale.

42
Q

What is Amazon Elastic File System (Amazon EFS)?

A

EFS provides a simple, scalable, fully managed elastic NFS file system for use with AWS Cloud services and on-premises resources.

43
Q

What is Access Key ID and Secret Access Key?

A

Access keys are long-term credentials for an IAM user or the AWS account root user. You can use access keys to sign programmatic requests to the AWS CLI or AWS API (directly or using the AWS SDK). Access keys consist of two parts: an access key ID and a secret access key. As a user name and password, you must use both the access key ID and secret access key together to authenticate your requests.

44
Q

What AWS services support reservation of instances to reduce costs?

A

Amazon Elastic Compute Cloud (Amazon EC2)
Amazon DynamoDB
Amazon Relational Database Service (Amazon RDS)

45
Q

What is APN Consulting Partner?

A

The AWS Partner Network (APN) is the global partner program for technology and consulting businesses that leverage Amazon Web Services to build solutions and services for customers.

46
Q

What is AWS Artifact?

A

AWS Artifact is your go-to, central resource for compliance-related information that matters to your organization. It provides on-demand access to AWS security and compliance reports and select online agreements.

47
Q

What is AWS Elastic Load Balancing (ELB)

A

Elastic Load Balancing (ELB) is used to automatically distribute your incoming application traffic across all the EC2 instances that you are running.

48
Q

What is AWS Abuse team?

A

The AWS Abuse team can assist you when AWS resources are used to engage in abusive behavior.

49
Q

What is AWS Direct Connect?

A

AWS Direct Connect is a cloud service solution that makes it easy to establish a dedicated network connection from your premises to AWS

50
Q

What is VPC Endpoint?

A

A VPC endpoint enables you to privately connect your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.

51
Q

What is AWS Global Accelerator (AMS SSPS)?

A

Global Accelerator is a network layer service in which you create accelerators to improve availability and performance for internet applications used by a global audience

52
Q

What is AWS Site-to-Site VPN ?

A

AWS Site-to-Site VPN creates a secure connection between your data center or branch office and your AWS cloud resources

53
Q

What is AWS Elastic Beanstalk?

A

AWS Elastic Beanstalk is an easy-to-use service for deploying and scaling web applications and services developed with various programming languages

54
Q

What should you think with CloudTrail?

A

account-specific activity and audit

55
Q

What should you think with CloudWatch?

A

resource performance monitoring, events, and alerts

56
Q

What should you think with Config?

A

resource-specific change history, audit, and compliance