IMPORT FlashCards

AWS SA FLASHCARDS

1
Q

AUDIT AWS RESOURCES

A

AWS CONFIG

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

API MONITORING SERVICES

A

AWS CLOUD TRAIL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

EVERY TIME A RESOURCE A CHANGED, WHERE DOES CONFIG RECORD THE CHANGE?

A

S3 BUCKET

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

LOGGING SERVICE THAT RECORDS ALL API CALLS TO ANY AWS SERVICE

A

AWS CLOUD TRAIL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

RECORDS DETAILS OF A CALL, LIKE WHICH USER OR APPLICATION MADE THE CALL, WHEN IT WAS MADE AND WHAT IP ADDRESS IT WAS MADE FROM

A

AWS CLOUD TRAIL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

REPORTS ON WHAT HAS CHANGED

A

AWS CONFIG

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

REPORTS ON WHO MADE THE CHANGE, WHEN AND FROM WHICH LOCATION

A

AWS CLOUD TRAIL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

[TERM LINK] RESOURCE AUDIT

A

CLOUDTRAIL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

[TERM LINK] API CALL AUDIT

A

CLOUDWATCH

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

TYPICALLY USED FOR AUDITING AND COMPLIANCE PURPOSES ACROSS ORGANIZATIONS

A

AWS CONFIG

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

WHAT ARE THE TWO DELETEONTERMINATION VALUES?

A

TRUE/FALSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

IF A DELETEONTERMINATION IS SET TO FALSE, WHAT HAPPENS WHEN AN INSTANCE IS TERMINATED?

A

IT PRESERVES THE ROOT VOLUME AND ENSURES IT REMAINS INTACT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

YOUR DB INSTANCE MUST BE IN THE ______ STATE FOR AUTOMATED BACKUPS TO OCCUR

A

ACTIVE STATE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

YOU CREATE A SNAPSHOT AND THEN YOU HAVE TO

A

COPY IT TO ANOTHER REGION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SNS TOPICS ARE USED FOR

A

NOTIFICATION PURPOSES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

UNDERLYING STORAGE FOR A DB INSTANCE, AUTOMATED BACKUPS, READ REPLICAS, AND SNAPSHOTS ARE ALL ….

A

DATA THAT IS ENCRYPTED AT REST

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

_____ CAN BE CONFIGURED TO USE SERVICE AUTO SCALING TO ADJUST ITS DESIRED COUNT UP OR DOWN IN RESPONSE TO CLOUDWATCH ALARMS

A

AMAZON ECS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

_______ FOR LAMBDA FUNCTIONS ENABLE YOU TO DYNAMICALLY PASS SETTINGS TO YOUR FUNCTION CODE AND LIBRARIES, WITHOUT MAKING CHANGES TO YOUR CODE

A

ENVIRONMENT VARIABLES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

YOU CAN USE _____ TO HELP LIBRARIES KNOW WHAT DIRECTORY TO INSTALL FILES IN, WHERE TO STORE OUTPUTS, STORE CONNECTION AND LOGGING SETTINGS, AND MORE

A

ENVIRONMENT VARIABLES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

______POWERED BY AWS PRIVATELINK, AN AWS TECHNOLOGY THAT ENABLES PRIVATE COMMUNICATION BETWEEN AWS SERVICES USING AN ELASTIC NETWORK

A

VPC ENDPOINTS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

WHEN YOU CREATE A TRAIL THAT APPLIES TO ____ _____ CLOUDTRAIL RECORDS EVENTS IN EACH REGIION AND DELIVERS THE CLOUDTRAIL EVENT LOG FILES TO AN S3 BUCKET THAT YOU SPECIFY

A

ALL REGIONS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

IF A REGION IS ADDED AFTER YOU CREATE A TRAIL THAT APPLIES TO ALL REGIONS, THAT NEW REGION IS _____

A

AUTOMATICALLY INCLUDED AND EVENTS IN THAT REGION IS LOGGED

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

YOU CAN CONFIGURE AMAZON REDSHIFT TO AUTOMATICALLY _____

A

COPY SNAPSHOTS TO ANOTHER REGION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

BASTION HOSTS NEED TO BE IN A _____ SUBNET

A

PUBLIC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
BASTION HOST PURPOSE IS TO
PROVIDE ACCESS TO A PRIVATE NETWORK FROM AN EXTERNAL NETWORK
26
VPC ENDPOINT INTERFACES HAVE TO BE
IN THE SAME REGION
27
______ IS A CLOUD SERVICE SOLUTION THAT MAKES IT EASY TO ESTABLISH A DEDICATED NETWORK CONNECTION FROM YOUR PREMISES TO AWS
AWS DIRECT CONNECT
28
____ IS A WEB SERVICE THAT YOU CAN USE TO AUTOMATE THE MOVEMENT AND TRANSFORMATION OF DATA
AWS DATA PIPELINE
29
COMMONLY USED TO TAKE METADATA AND STORE THE METADATA IN DYNAMODB
AWS LAMBDA
30
YOU CAN USE _____ TO DELEGATE ACCESS TO USERS, APPLICATIONS, OR SERVICES THAT DON'T NORMALLY HAVE ACCESS TO YOUR AWS RESOURCES
IAM ROLES
31
DATA IN DYNAMODB IS STORED IN _____ FORMAT
JSON
32
WHEN AN EC2-CLASSIC INSTANCE IS STOPPED, AWS ______ ANY ELASTIC IP ADDRESS THATS ASSOCIATED WITH INSTANCE
DISASSOCIATES
33
WHEN AN EC2-CLASSIC INSTANCE IS STOPPED, AWS RELEASES THE
PUBLIC AND PRIVATE IPV4 ADDRESSES
34
IF YOU USE PuTTY TO CONNECT TO YOUR INSTANCE VIA SSH YOU NEED TO VERIFY THAT YOUR PRIVATE KEY (.pem) HAS BEEN CORRECTLY CONVERTED TO
.ppk (PuTTY FORMAT)
35
EC2 BASIC DATA AVAILABLE AFTER
5 MINS
36
EC2 DETAILED MONITORING DATA AVAILABLE AFTER
1 MIN
37
_____ LAUNCHES A NUMBER OF EC2 INSTANCES FOR ITS HADOOP DATA PROCESSING ENGINE, IS MANAGED BY THE CUSTOMER AND IS USED TO PROCESS VAST AMOUNTS OF DATA
EMR
38
AVAILABLE AMAZON EC2 METRICS
CPU UTILIZATION, NETWORK UTILIZATION, DISK PERFORMANCE AND DISK READ/WRITES
39
[TERM LINK] OBJECT BASED
S3
40
S3 FILE SIZE
0 BT - 5 TB
41
minimal replical lag, usually less than 100 millisecods
AWS AURORA
42
___ ____ component can be used to create web server environments and work environments
ELASTIC BEANSTALK
43
_____ provides scalable file storage
EFS
44
[TERM LINK] | EPHEMERAL
INSTANCE STORES
45
_______ HELPS TO ENSURE THAT YOUR AUTO SCALING GROUP DOESN'T LAUNCH OR TERMINATE ADDITIONAL INSTANCES BEFORE THE PREVIOUS SCALING ACTIVITY TAKES EFFECT
AWS SCALING COOLING PERIOD
46
IAM ROLES IS USED TO DELEGATE ACCESS TO..
USERS, APPLICATIONS OR SERVICES
47
USED FOR ISSUING TOKENS WHILE USING THE API GATEWAY FOR TRAFFIC IN TRANSIT
API GATEWAY WITH STS
48
REDSHIFT WILL NOT BE ABLE TO ACCESS THE S3 VPC ENDPOINTS WITHOUT
ENHANCED VPC ROUTING
49
IF LANGUAGE IS SPECIFIED IN THE QUERY STRING PARAMETERS THEN
CLOUDFRONT SHOULD BE CONFIGURED
50
AWS KINESES DATA FIREHOSE CAN CAPTURE, TRANSFORM AND LOAD STREAMING DATA INTO
* AMAZON REDSHIFT (NOT REDSHIFT SPECTRUM) * AMAZON ELASTICSEARCH SERVICE * SPLUNK
51
AN INSTANCE STORE-BACKED INSTANCE IS EITHER
RUNNING OR TERMINATED , CAN NOT BE STOPPED !
52
AWS REDSHIFT USES TWO FORMS OF ENCRYPTION
AWS KMS OR AWS HSM
53
ON PREMISE ----> AWS RESOURCES
VPN CONNECTION
54
PRIVATE RESOURCES REQUIRED TO ACCESS THE INTERNET?
UTILIZE NAT INSTANCE OR NAT GATEWAY
55
BOTTLENECK
NAT INSTANCE
56
ONCE YOU CONVERT FROM NAT INSTANCE TO NAT GATEWAY YOUR NEXT STEP IS TO
MOVE NAT GATEWAY TO PUBLIC SUBNET
57
SERVICE WHERE YOU ONLY PAY FOR THE TIME THE FUNCTION RUNS AND NOT THE INFRASTRUCTURE, ALSO SAME SERVICE WHEN THE CUSTOMER HAS OWNERSHIP OF THE API
AWS LAMBDA
58
MONITOR API ACTIVITY
CLOUD TRAIL
59
CLOUD TRAIL MONITORS _____ ACTIVITY
API
60
[TERM LINK] API ACTIVITY
CLOUD TRAIL
61
[TERM LINK] CLOUD TRAIL
MONITOR API ACTIVITY
62
YOU CAN TURN ON A _____ACROSS ALL REGIONS
CLOUD TRAIL
63
CLOUDTRAIL DELIVERS LOG FILES TO
S3 BUCKET AND OPTIONAL CLOUDWATCH LOG FILES
64
OFFLOAD DATABASE READS
READ REPLICAS
65
READ REPLICAS
OFFLOAD DB READS
66
HIGH AVAILABILITY
MULTI AZ
67
MULTI AZ MEANS
HIGH AVAILABILITY
68
RDS HIGH AVAILABILITY
MULTI AZ
69
RDS READ REPLICAS
OFFLOAD DB READS
70
BATCH PROCESSING
SPOT INSTANCES
71
SPOT INSTANCES
BATCH PROCESSING
72
AMIS ARE NOT ______ AT REST
ENCRYPTED AT REST
73
ROUTE 53 ROUTES USER TRAFFIC TO RANDOM WEB SERVERS
MULTIVALUE ANSWER
74
MULTIVALUE ANSWER
ROUTE 53 ROUTES USER TRAFFIC TO RANDOM WEB SERVERS
75
RANDOM WEB SERVERS
MULTIVALUE ANSWER
76
INCREASE WRITE PERFORMANCE OF DB HOSTED ON EC2
INCREASE EC2 INSTANCE AND OR USE STANDARD RAID CONFIGURATION
77
NO COST FOR TRANSFERRING DATA FROM
EC2 INSTANCE TO AN S3 BUCKET
78
____ PROVIDES MULTIPLE WAYS TO USE AMAZON CLOUD DIRECTORY AND MICROSOFT ACTIVE DIRECTORY
AWS DIRECTORY SERVICE
79
AWS DIRECTORY SERVICE
LINK BETWEEN CLOUD DIRECTORY AND MICROSOFT AD
80
SNS SENDS NOTIFICATIONS OVER
HTTP, HTTPS, EMAIL, EMAIL-JSON, SQS AND SMS
81
HTTP, HTTPS, EMAIL, EMAIL-JSON, SQS AND SMS
WHAT IS SENT OVER FROM SNS
82
STORE SESSION DATA ON BOTH
DYNAMO DB AND ELASTICACHE
83
IF AN INSTANCE IS STOPPED
DATA IS DELETED
84
DATA IS DELETED WHEN
AN INSTANCE IS STOPPED
85
TO IMPLEMENT STICKY SESSION YOU NEED TWO THINGS
* HTTP/HTTPS LOAD BALANCER | * AT LEAST ONE HEALTHY INSTANCE
86
instance metadata provides
instance ID, public keys, public IP address
87
how to you find instance meta data
fire a URL command
88
S3 Standard IA storage class is designed for
data that is accessed less frequently, but requires rapid access when needed
89
managed cloud service that lets devices (IoT) easily and securely interact with cloud applications and other devices
AWS IoT Core
90
perfect forward secrecy is provided to two aws services
CLOUDFRONT AND ELB
91
AWS MANAGES SECURITY OF:
* FACILITIES * PHYSICAL SECURITY OF HARDWARE * NETWORK INFRASTRUCTURE * VIRTUALIZATION INFRASTRUCTURE
92
THE DATA IN_____ IS STORED IN JSON FORMAT FOR
DYNAMODB
93
DYNAMODB STORES DATA IN _____ FORMAT
JSON
94
SINCE DYNAMODB WORKS WITH IoTs, gaming, ad tech and mobile applications IT IS USED TO STORE
SESSION DATA
95
THIS AWS FEATURE IS REALLY GOOD BECAUSE IT IS DURABLE, ACID COMPLIANT AND ALLOWS SCHEMA CHANGES
AURORA
96
REDSHIFT CLUSTER DISASTER RECOVERY ???
CROSS-REGION SNAPSHOT
97
REDSHIFT HAS TWO FORMS OF ENCRYPTION
AWS KMS AND HSM
98
IN ORDER TO HOST A STATIC WEBSITE IN S3 YOU NEED TO NEED TO ____________ IN THE DOMAIN REGRISTAR
ENTER THE NS RECORDS
99
CLOUD TRAIL MONITORS
API ACTIVITY