Summary Flashcards

1
Q

Receive alerts when the reservation utilization falls

A

AWS Budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Amazon S3 vs EFS

A

S3 does not support file append like EFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AWS Neptune

A

Build and run graph applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Support Plans

A

Developer Business Enterprise-on-ramp Enterprise
<12 hrs < 1hr <30 mins <15 mins

    • TAMs 1 TAM

Business 24/7 24/7 24/7
hours email
access
- AWS Sup API AWS Sup API AWS Sup API
Incident detection for
additional fee

	                                   AWS Managed Srvs   AWS Managed Srvs 
                                               for additional fee	for additional fee

	                                   re:Post:Private            re:Post:Private 
                                               for additional fee        for additional fee
                                               
                                              Access to                       Access to architectural
                                              architectural                  reviews
                                               reviews
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

MFA devices

A
  1. U2F security key - Plug into a USB port on your computer. Authenticated by tapping the device instead of manually entering a code
  2. Virtual Multi-Factor Authentication (AWS MFA) device - Software app that runs on a phone or other device and emulates a physical device. Authenticated by typing a valid code from the device
  3. Hardware Multi-Factor Authentication (AWS MFA) device - Hardware device that generates a six-digit numeric code. Authenticated by typing a valid code from the device
  4. SMS text message-based Multi-Factor Authentication (AWS MFA) - IAM user settings include the phone number of the user’s SMS-compatible mobile device. Authenticated by OTP
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Disaster Recovery Plans

A

Automated backups - Same region (Recovery Time Objective is lowest)
Manual snapshots - Cross region (Recovery Point Objective is lowest)
Read replicas - Cross region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Amazon EC2 instance user data and metadata

A

Bootstrap script or configuration parameters while launching your instance
Metadata is data about your instance that you can use to manage the instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

S3 pricing

A

There are four cost components to consider for S3 pricing –
storage pricing;
request and data retrieval pricing;
data transfer and transfer acceleration pricing;
and data management features pricing.

Under “Data Transfer”, You pay for all bandwidth into and out of Amazon S3, except for the following:
(1) Data transferred in from the internet,
(2) Data transferred out to an Amazon Elastic Compute Cloud (Amazon EC2) instance, when the instance is in the same AWS Region as the S3 bucket,
(3) Data transferred out to Amazon CloudFront (CloudFront).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AWS Web Application Firewall (AWS WAF) lets you monitor the HTTP and HTTPS requests that are forwarded to….

A
  1. Application Load Balancer
  2. Amazon CloudFront
  3. Amazon API Gateway
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Billing alarms

A

CloudWatch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AWS Shield Advanced provides protection for the following AWS Services

A
  1. EC2,
  2. Elastic Load Balances,
  3. Amazon CloudFront,
  4. Amazon Route 53,
  5. AWS Global Accelerator
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which of the following is available across all AWS Support plans

A

AWS Health Dashboard – Your account health

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Key components of S3 Glacier

A
  1. Access Policy
  2. Archive
  3. Vault
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Routing algorithm for ALB

A

ALB selects target based on the routing rule then selects node using round robin strategy
The classic ALB using round robin for TCP listners only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Bucket Policies and ACLs wrt to S3

A

Bucket Policies control access to entire bucket and ACLs to individual object within the bucket

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

URL structure of S3

A

https.<bucket>.<S3>/<object></object></S3></bucket>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Amazon Glacier components

A

Archive, Vault(Groups of archives) and Access Policies(to control access to objects within archive and vaults)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Database migration services

A

Can migrate to and from AWS and on-premise
Can migrate from EC2 to RDS
Can migrate to Redshift and DynamoDB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

VPC Peering some facts

A

It can happen across regions and between different AWS accounts
It also used to store data for fault tolerance, DR and redundnacy
Traffic between different regions is encrypted by default but not encrypted by defualt within same region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

TCO

A

Recommendations on resource types based on operational best practices and user inputs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

DataSync

A

Transfer from on-premise to AWS storage services
Between AWS storage services
Between public clouds to AWS storage services
Its for continuous synching vs DMS which is for Database migration only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Athena some facts

A

Serverless query service

Interactive query service that makes it easy to analyze unstructured, semi-structured, and structured data stored in Amazon S3 directly in Amazon Simple Storage Service (Amazon S3) using standard SQL

Compatible with CSV, JSON, AVRO or columnar data formats such as Apache Parquet and Apache ORC,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

DynamoDB Backups, who configures and who takes backup?

A

Customer configures and AWS takes backups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

AppSync

A

Simplify application development with GraphQL APIs by providing a single endpoint to securely query or update data from multiple databases, microservices, and APIs

Consolidate data from multiple databases, APIs, and microservices in a single network call, from a single endpoint, abstracting backend complexity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Amplify

A

Facilitate the development and deployment of web and mobile applications. Quickly build full-stack applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

AWS Firewall Manager

A

Simplifies your administration and maintenance tasks across multiple accounts and resources for a variety of protections, including AWS WAF, AWS Shield Advanced, Amazon VPC security groups, AWS Network Firewall, and Amazon Route 53 Resolver DNS Firewall. It does not work with Network ACLs

Security Hub collects security data across AWS accounts, AWS services, and supported third-party products and helps you analyze your security trends and identify the highest priority security issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

SCPs

A

Service control policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization.

Not enabled by default

SCPs offer central control over the maximum available permissions for all accounts in your organization. SCPs help you to ensure your accounts stay within your organization’s access control guidelines

SCPs alone are not sufficient in granting permissions to the accounts in your organization. No permissions are granted by an SCP. An SCP defines a guardrail, or sets limits, on the actions that the account’s administrator can delegate to the IAM users and roles in the affected accounts.
The administrator must still attach identity-based or resource-based policies to IAM users or roles, or to the resources in your accounts to actually grant permissions.
The effective permissions are the logical intersection between what is allowed by the SCP and what is allowed by the IAM and resource-based policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

If an instance store reboots, does the data in the instance persist?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which tool lets you visualise and manage your AWS costs?

A

AWS Cost Explorer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Which AWS service reduces network latency?

A

CloudFront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Which Amazon S3 storage class has the lowest cost?

A

S3 Glacier Deep Archive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Which perspective of the AWS Cloud Adoption Framework focuses on minimizing the business risks?

A

Governance Perspective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Which AWS service helps you build text chatbots?

A

Amazon Lex

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

What is Service Quotas in AWS?

A

Quotas, also referred to as limits in AWS services, are the maximum values for the resources, actions, and items in your AWS account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Scope of VPC

A

A VPC can span all Availability Zones within an AWS Region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

AWS Resource Explorer

A

Facilitates resource search and discovery within AWS accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

AWS Knowledge Center

A

Available through AWS re:Post, offers official articles and videos addressing common questions and requests from AWS customers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Individual Amazon S3 objects range?

A

0 to 5TB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

AWS Tape Gateway

A

You can use it to directly connect to your tape drive on premise and using AWS Storage Gateway backup the data on Amazon S3 Tape Library w/o any code changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Securing EC2

A
  1. SSH (IP is public and key stored on accessing machine)
  2. EC2 in private subnet, which talks to bastion host on public subnet which inturn talks to user over internet (key stored on accessing machine)
  3. Add MFA on access
  4. SSM (No need of bastion host. EC2 in private subnet with access to internet using NAT or VPC endpoint)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Migration strategies

A

Rehosting — Otherwise known as “lift-and-shift”
Replatforming — I sometimes call this “lift-tinker-and-shift”
Repurchasing — Moving to a different product
Refactoring / Re-architecting 
Retire — Get rid of
Retain — Usually this means “revisit” or do nothing (for now)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Amazon WorkLink

A

Fully managed service introduced by AWS that facilitates secure, one-click access to internal corporate websites for employees

Secure access from iOS and Android phones to internal websites and web apps, simplifying the user experience with a single-step process

Generates webpage content in the AWS cloud and transfers it to the user’s phone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

AWS CloudShell

A

AWS CloudShell is a browser-based shell that allows users to run scripts with the AWS Command Line Interface (CLI) and experiment with service APIs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

AWS Application Composer

A

Visual designer that you can use to build your serverless applications from multiple AWS services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Amazon Timestream

A

Time Stream DB for IoT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Amazon S3 Object Lock

A

Prevent the deletion or overwriting of objects in Amazon S3 for a specified duration or indefinitely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

DynamoDB vs DocumentDB

A

Fully managed Vs gives admin access to users
Less costly Vs More Costly
Does not support MongoDB Vs SupportsMongoDB
NoSQL Vs NoSQL
Key-Value Vs JSON

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

AWS Compute Optimzer Vs Cost Explorer

A

Compute Optimizer delivers all recommendations regardless of the cost implications wheres Cost Explorer recommends pertaining to cost only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

AWS OpsWork Vs AWS OpsHub Vs AWS Opscenter Vs AWS Workspace

A

Configuration management service for cloud enterprises, utilizing Puppet or Chef for application configuration and operation
Vs
Unified view and automates operational tasks on AWS Snow Family devices
Vs
Capability of AWS systems manager for configuration management of aws resources like firewall settings, anti virus settings, patch update, etc
Vs
Virtual desktop service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

AWS Glue Vs AWS Macie Vs AWS Neptune

A

ETL
Vs
PII
Vs
Database service powering graph

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

AWS Service Catalog Vs AWS Config

A

Create and manage catalogs of IT services that are approved for AWS
Vs
Assessing, auditing, and evaluating the configurations and relationships of resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

Amazon MQ Vs AWS SQS

A

Set up and operate message brokers on AWS Vs message queue(Storing messages as they travel between computers)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

Network ACL Vs Security Group

A

Stateless(Separate rules for inbound and outbound Traffic) Vs Statefull(If allowed inbound, outbound is automatically allowed)
Allow/Deny Vs Allow
Subnet Vs EC2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

Which CAF perspective covers Benefit Management?

A

Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

Which CAF perspective covers Risk Management?

A

Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

Which CAF perspective covers data curation?

A

Governance

57
Q

Which CAF perspective covers portfolio managment?

A

Business

58
Q

Which CAF perspective covers product managment?

A

Business

59
Q

Which CAF perspective covers data science?

A

Business

60
Q

Which CAF perspective covers change acceleration?

A

People

61
Q

Which CAF perspective covers organization design?

A

People

62
Q

Which CAF perspective covers provisioning and orchestration?

A

Platform

63
Q

Which CAF perspective covers CI/CD?

A

Platform

64
Q

Which CAF perspective covers incident and problem mgmt?

A

Operations

65
Q

Which CAF perspective covers Configuration mgmt?

A

Operations

66
Q

Which CAF perspective covers change and release mgmt?

A

Operations

67
Q

Which CAF perspective covers performance and capacity?

A

Operations

68
Q

Which CAF perspective covers event management?

A

Operations

69
Q

Which CAF perspective covers Incident Response?

A

Security

70
Q

Which CAF perspective covers Incident and Problem management?

A

Operations

71
Q

Make frequent, small, reversible changes, which WAF pillar?

A

Operational Excellence

72
Q

Anticipate failure, which WAF pillar?

A

Operational Excellence

73
Q

Go global in minutes, which WAF pillar?

A

Performance Efficiency

74
Q

Experiment more often, which WAF pillar?

A

Performance Efficiency

75
Q

Democratize advanced technologies, which WAF pillar?

A

Performance Efficiency

76
Q

Automatically recover from failure, which WAF pillar?

A

Reliability

77
Q

Test recovery procedures, which WAF pillar?

A

Reliability

78
Q

Stop guessing capacity, which WAF pillar?

A

Reliability

79
Q

Manage change through automation, which WAF pillar?

A

Reliability

80
Q

Implement cloud financial management, which WAF pillar?

A

Cost optimization

81
Q

Which CAF perspective covers Cloud Financial mgmt?

A

Governance

82
Q

OLTP Vs OLAP which service?

A

OLTP->Amazon RDS,Amazon DynamoDB
OLAP->Amazon Redshift(DW)

83
Q

What is EFS scope

A

EFS can be accessed within the same region across all AZs

84
Q

Kinesis data stream
vs
data analytics
vs
client library
vs
data firehose

A

Capture, process and store(Ingestion service) data for consumers
vs
Analytical service using SQL service
vs
Analytical service using SQL KCL (more complex than Anlytical service)
vs
ETL service to load data in data lakes, data stores, and analytics services

85
Q

AWS Billing Conductor
Vs
AWS Cost Explorer
Vs
AWS Cost and Usage Report
Vs
AWS Organization

A

Grouping of accounts for billing and apply custom pricing plans
Vs
Visualize, understand, forcast and manage your AWS costs and usage over time
Vs
Publish your AWS billing reports to an Amazon Simple Storage Service (Amazon S3) bucket that you own. Reports that break down your costs by the hour or day, by product or product resource, or by tags that you define yourself
Vs
If you create multiple accounts, you can use the consolidated billing feature of AWS Organizations to combine all your member accounts under one management account and receive a single bill

86
Q

FSx vs EFS

A

FSx is designed for Windows workloads, offering fully managed Windows file systems, including Windows-native features like Active Directory integration and Windows ACLs (Access Control Lists).
Vs
EFS is a managed Network File System (NFS) for Linux-based workloads

87
Q

IoT Greengrass vs IoT Core

A

IoT Core operates in the cloud, while Greengrass is designed for edge computing, allowing devices to perform computations locally

88
Q

AWS Data Pipeline vs AWS SQS

A

Automates the movement and transformation of data, allowing users to define data-driven workflows
Vs
scalable and fully managed message queuing service for decoupling components of a cloud application, ensuring reliable and asynchronous communication

89
Q

AWS Managed services vs professional services

A

Managed services are ongoing and typically contracted, addressing daily IT needs comprehensively
Vs
Professional services offer expertise for specific projects, ensuring optimal implementation and functionality

90
Q

AWS Audit Manager Vs Security Hub

A

Security Hub conducts automated security checks aligned to different industry and regulatory frameworks. Audit Manager automatically collects the findings generated by these Security Hub checks as a form of evidence and combines them with other evidence, such as AWS CloudTrail logs, to help customers generate assessment reports
It is cloud security posture management (CSPM) service

Audit Manager helps you manage stakeholder reviews of your controls and enables you to build audit-ready reports with much less manual effort

91
Q

AWS workspaces vs appstream

A

AWS WorkSpaces is a fully managed desktop-as-a-service (DaaS) solution that lets you provide virtual desktops to your users
Vs
AWS AppStream is a fully managed application streaming service that lets you stream desktop applications to any computer running a web browser

92
Q

Stateless Vs Stateful

A

Configure and more control
Vs
Ready configured and less control

93
Q

EC2 Image Builder Vs AMI

A

Service facilitating automated creation, management, and deployment ofmachine and container images. It simplifies the creation of virtual machines
Vs
Snapshot of an EC2 instance that includes the operating system and application software

EC2 Image Builder can distribute AMIs or container images to any AWS Region

94
Q

AWS Manage Parameter Store Vs Secrets Manager

A

Designed for centralizing configuration data with only one version and with or without encryption using KMS (Mostly non secret data and no additional charge)
Vs
Securely storing and managing sensitive information, such as API keys and database credentials which always encrypted with multiple versions(additional charge)

95
Q

CSSPF ( Trusted Advisor)

EALS (CAF Life Cycle)

BGPPOS (CAF)

TPOP (CAF Domains)

CORPSS (Well Architected Framework)

A

Cost, Security, Service Limits, Performance, Fault Tolerance

Envision, Align, Launch, Scale

Business, Governance, People, Platform, Operations, Security

Technology, Process, Organization, Product

Cost Optimization, Operational Excellence, Reliability, Performance Efficiency, Security and Sustainability

96
Q

AWS Owned
Vs
AWS Managed
Vs
Customer Managed keys

A

Encryption keys owned by AWS and NOT stored in customer account and used across multiple customer accounts and stored under default key store. Customer cannot access it
Vs
Encryption keys created, managed, and used on your behalf by an AWS service that is integrated with AWS KMS and stored in customer account under default key store. Customer can access it.
Vs
Encryption keys you create, own, and manage and stored in customer account under custom key store. Customer can access it.

97
Q

Conceirge
Vs
TAM
Vs
Partner Network (APN Partner)
Vs
Managed Service Provider(MSP)
Vs
Professional Services

A

Billing and Accounts support
Vs
TAM provide architectural and operational guidance under enterprise support plans
Vs
Consists of MSP(Overall), Competency Partners(Technical) , Service Partners(s/w products) and consulting partners (advisory)
They are enagaged with customer during the migration into dev/test. For migration to production they involve professional services that work with customer management. After production for continued support they enagage MSP
Vs
MSP provide end-to-end AWS solutions and services after the migration is completed
Vs
During cloud Adoption stage provide professional service through APN partner

98
Q

AWS Backup
Vs
Data Sync
Vs
Storage Gateway

A

Automated backup service within AWS
Vs
Onpremise to AWS sending of data over internet
Vs
Accessing AWS storage services on premise + data back capabilities

99
Q

AWS GuardDuty Vs AWS Detective

A

RealTime Threat Detection Vs Post Incident Analysis

100
Q

AWS Systems Manger Insights

A

AWS Systems Manager’s built-in insights are dashboards that include recent API calls through AWS CloudTrail,
recent configuration changes through AWS Config,
instance software inventory listings,
instance patch compliance views,
and instance configuration compliance views

101
Q

Object Vs File Vs Block

A

Cannot modify object only recreate
Cannot lock object
Suitable for huge volume of unstructured data
Fast searcheable
IoT, Video Surveliance, Emails
Vs
Can modify file
Can lock file
Suitable for less volume of structured data
Easy access
Documents, Archiving
Vs
Can modify block
Cannot lock block
Suitable for huge volume
Cannor search
Databases, Emails, Virtual Machine file system

102
Q

Billing Alarms Vs Budget Alerts

A

The billing alarm represents only the amount you have been already charged. In contrast, a budget can alarm you based on forecasted charges, which can give you a bit of head up to figure out what’s happening before you get hit with excess bill usage.

The other key difference is that Budgets allow you to create filtered alarms, only for some regions and services of interest. Filtering by region is not possible with billing alerts. Another thing is that budget support linked accounts, which again is not possible with the billing alerts.

103
Q

Pricing Options for AWS storage services

A

EBS - GB you provision per month + Additional input/output operations per second (IOPS) + Throughput beyond baseline performance

EBS Snapshot - Storage Pricing + Restore Pricing

EFS - Storage + Throughput

S3 - Storage + Throughput

104
Q

Common Features among Developer, Business and Enterprise

A

General guidance: < 24 hours**
System impaired: < 12 hours**

Support Automation Workflows

Prioritized responses on AWS re:Post

105
Q

Common Features Business and Enterprise

A

General guidance: < 24 hours
System impaired: < 12 hours
Production system impaired: < 4 hours
Production system down: < 1 hour

Architectural Guidance

Support Automation Workflows
AWS Countdown Premium (paid in business)

Full set of Trusted Advisor checks

Prioritized responses on AWS re:Post
24/7 phone, web, and chat access to Cloud Support Engineers
Access to AWS Support App in Slack

AWS Support API

Third Party Software Support : Interoperability and configuration guidance and troubleshooting

106
Q

Underutilized resources can be identified by?

A

Cost Explorer - rightsizing recommendation
Trusted Advisor -

107
Q

For Startup what is the sequence:

LightSail
Cloud Foundation
Quick Starts (AWS Partner Solutions)

A

Cloud Foundation -> LightSail -> Quick Starts

108
Q

After disaster event happens and recovery time?

Backup and Restore
Vs
Pilot Light
Vs
Warm Standby
Vs
Multi-site active-active

A

Provision all AWS resources after event and restore backup (hours)
Vs
Provision some AWS resourses and scale after event (10s of minutes)
Vs
Scale after event (minutes)
Vs
No need to provision and scale after event (real time)

109
Q

Dedicated Host Vs Dedicated Instance

A

Hardware doesn’t change after stop/start of the instance
Vs
Hardware may change after stop/start of the instance

In both hardware is not shared with any other aws accounts

110
Q

Storage class Availability Sequence

A

99.99(Std) —> 99.9(IT) —> 99.9(IA) —> 99.5(IA-1 Zone) —> 99.9(IR)—> 99.99(F)—>99.99(Deep)

111
Q

Storage class minimum storage duration

A

NA(Std)—>NA(IT)—>30 days(IA)—>30 Days(IA-1 Zone)—>90 days(IR)—>90 days(F)—>180 days(Deep)

112
Q

Storage class minimum capacity charge

A

NA(Std)—>NA(IT)—>128 KB(IA)—>128 KB(IA-1 Zone)—>128 KB(IR)—>40 KB(F)—>40 KB(Deep)

113
Q

To extract event logs for analysis what is the most cost effective way?

A
  1. Extract logs in S3 and use Athena

Others are

  1. ETL into
114
Q

How to do automated backup of all EBS Volumes?

A

Amazon Data Lifescycle Manager

115
Q

Enables a single Aurora database to extend across multiple AWS regions, facilitating high-performance for globally distributed applications

A

Amazon Global Database

116
Q

S3 Glacier

A

Host Infrequently Accessed Data

117
Q

How to monitor the swap spaces in EC2 instances

A

CloudWatch with SwapUtilization on

118
Q

Implement FanOut Messaging

A

SNS Topic with multiple SQS

119
Q

Implement Read Replication < 1 sec

A

Aurora with CRR

120
Q

Load balancer to use for UDP communication with many game servers

A

Network Load Balancer

121
Q

Retrieve a subset of data from large CSV file stored in S3

A

Perform S3 select operation using bucket name and object’s key

122
Q

To upload 1 TB file on S3

A

Use S3 multipart upload API. Uploads large objects in part using parallel upload resumable transfer

123
Q

Retrieve instance ID, Public keys and Public IP of EC2 instance

A

Use the magic URL after logging into the EC2 instance

124
Q

Cost effective solution to manage over provisioning of resources

A

Use target tracking scaling in ASG solution

125
Q

Accelerate the transfer of historical records on premise to AWS using most cost effective solution

A

DataSync on Amazon Glacier Deep Archive

126
Q

Globally deliver static content with low latency

A

Use S3 bucket with cloudfront distribution

127
Q

Minimize data transfer cost between 2 EC2 instances

A

Deploy EC2 instances in the same region. Data transfer is not charged at all if they are in the same region

128
Q

Import the SSL/TLS certification in AWS

A

Use AWS Certification Manager or upload it into AWS IAM

129
Q

Encrypt EBS Volumes from uncrypted EBS snapshots

A

Copy snapshots using symmetric customer master key

130
Q

Limit the maximum number of requests from single IP

A

Create a rate based rule in WAF

131
Q

How to restrict accidental deletion/overwriting of objects in S3 bucket

A

Enable versioning and MFA delete

132
Q

How to keep data transfer cost low

A

Limit Unnecessary Outbound Data Transfers
Cache content in Amazon CloudFront
Keep Data Transfer within a Single Region
Keep EC2 Data Transfers within a Single Availability Zone

133
Q

How to give on premise AD credential access to AWS services

A

Use AWS Managed Microsoft AD and configure AD connector

134
Q

To secure the sensitive data stored in EBS volumes

A

Enable EBS encryption to encrypt data at rest

135
Q

How to ensure data in transit and data at rest in S3 is always encrypted

A

Enable S3 server side or client side encryption

136
Q

EC2 instance types

A

TM=General Purpose
RXZ=Memory
PGFV=Accelerated Computing
IDH=Storage
HPC=High Performance Computing

137
Q

Operation Excellence
Performance Efficiency
Reliability

A

Operation Excellence - IaC, Managed Service, Observability
Performance Efficiency - Serverless, Go global in minutes, RightSizing
Reliability - DR, Availability, Test Recovery, Stop guessing capacity

138
Q

Serverless AWS services

A

AWS Lambda
AWS Fargate
Amazon DynamoDB
Amazon CloudWatch
Amazon S3
Amazon API Gateway
Amazon Aurora
Amazon SNS
Amazon SQS
Amazon QuickSight