{"id":67239,"date":"2021-06-18T00:10:08","date_gmt":"2021-06-18T05:40:08","guid":{"rendered":"https:\/\/www.whizlabs.com\/blog\/?p=67239"},"modified":"2025-11-28T14:59:21","modified_gmt":"2025-11-28T09:29:21","slug":"aws-solutions-architect-associate-exam-questions","status":"publish","type":"post","link":"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/","title":{"rendered":"AWS Solutions Architect Certification Exam Questions[2025]"},"content":{"rendered":"<p><i><span style=\"font-weight: 400;\">Preparing for the AWS Certified Solutions Architect Associate Exam? Here we&#8217;ve a list of <strong>\u00a0free <a href=\"http:\/\/whizlabs.com\/aws-solutions-architect-associate\/\" target=\"_blank\" rel=\"noopener\">AWS Solutions Architect Exam Questions and Answers<\/a><\/strong> for you to prepare well for the AWS Solution Architect exam. This practice exam questions are very similar to the practice questions in the real exam format.<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">AWS certification training<\/span><span style=\"font-weight: 400;\"> plays an important role in the journey of <\/span><span style=\"font-weight: 400;\">AWS certification preparation<\/span><span style=\"font-weight: 400;\"> as it validates your skills in depth. Also, the aws practice questions play an important role in getting you ready for the real time examination.<\/span><\/p>\n<p>If you are planning to <a href=\"https:\/\/www.whizlabs.com\/blog\/aws-certified-solutions-architect-associate\/\" target=\"_blank\" rel=\"noopener\">prepare for the AWS architect certification<\/a>, you can start with going through these free sample questions created by Whizlabs team.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_76 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #ea7e02;color:#ea7e02\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #ea7e02;color:#ea7e02\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#AWS_Solutions_Architect_Associate_Exam_Questions\" >AWS Solutions Architect Associate Exam Questions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Free_AWS_Certification_Exam_Questions\" >Free AWS Certification Exam Questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Architectures\" >Domain : Design Secure Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures\" >Domain: Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-2\" >Domain : Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures\" >Domain: Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-2\" >Domain:\u00a0Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Resilient_Architectures\" >Domain: Design Resilient Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-3\" >Domain: Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Applications_and_Architectures\" >Domain: Design Secure Applications and Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Resilient_Architectures-2\" >Domain: Design Resilient Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Applications_and_Architectures-2\" >Domain: Design Secure Applications and Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Applications_and_Architectures-3\" >Domain: Design Secure Applications and Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-4\" >Domain :\u00a0Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-5\" >Domain :\u00a0Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-6\" >Domain : Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-7\" >Domain :\u00a0Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Resilient_Architectures-3\" >Domain :\u00a0Design Resilient Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-8\" >Domain :\u00a0Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Resilient_Architectures-4\" >Domain :\u00a0Design Resilient Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Architectures-2\" >Domain :\u00a0Design Secure Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-9\" >Domain :\u00a0Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Architectures-3\" >Domain :\u00a0Design Secure Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-24\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-3\" >Domain :\u00a0Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-25\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-4\" >Domain :\u00a0Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-26\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-5\" >Domain :\u00a0Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-27\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-6\" >Domain :\u00a0Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-28\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-7\" >Domain :\u00a0Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-29\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Latest_Updated_Questions_2023\" >Latest Updated Questions 2023<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-30\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-10\" >Domain: Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-31\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Resilient_Architectures-5\" >Domain: Design Resilient Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-32\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-8\" >Domain: Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-33\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Resilient_Architectures-6\" >Domain: Design Resilient Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-34\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-9\" >Domain: Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-35\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Resilient_Architectures-7\" >Domain: Design Resilient Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-36\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-10\" >Domain: Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-37\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Resilient_Architectures-8\" >Domain: Design Resilient Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-38\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-11\" >Domain: Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-39\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-11\" >Domain: Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-40\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-12\" >Domain: Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-41\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-13\" >Domain: Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-42\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-14\" >Domain: Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-43\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Cost-Optimized_Architectures-12\" >Domain: Design Cost-Optimized Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-44\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Architectures-4\" >Domain: Design Secure Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-45\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Architectures-5\" >Domain: Design Secure Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-46\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_High-Performing_Architectures-15\" >Domain: Design High-Performing Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-47\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Architectures-6\" >Domain: Design Secure Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-48\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Domain_Design_Secure_Architectures-7\" >Domain: Design Secure Architectures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-49\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Old_Questions\" >Old Questions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-50\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Frequently_Asked_Questions_FAQs\" >Frequently Asked Questions (FAQs)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-51\" href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/#Summary\" >Summary<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2 style=\"text-align: center;\"><span class=\"ez-toc-section\" id=\"AWS_Solutions_Architect_Associate_Exam_Questions\"><\/span><span style=\"color: #000080;\">AWS Solutions Architect Associate Exam Questions<\/span><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><a href=\"http:\/\/whizlabs.com\/aws-solutions-architect-associate\/\" target=\"_blank\" rel=\"noopener\"><strong>AWS Certified Solutions Architect Associate exam <\/strong><\/a><span style=\"font-weight: 400;\">\u00a0is for those who are performing the role of solutions architect with at least one year of experience in designing scalable, available, robust, and cost-effective distributed applications and systems on the AWS platform.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">AWS Solutions Architect Associate (SAA-C03) exam validates your knowledge and skills for<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Architecting and deploying robust and secure applications on the AWS platform using AWS technologies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defining a solution with the use of architectural design principles based on customer requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Providing guidance for the implementation on the basis of best practices to the organization over the project lifecycle.<\/span><\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"Free_AWS_Certification_Exam_Questions\"><\/span>Free AWS Certification Exam Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><span style=\"font-weight: 400;\">While preparing for the<\/span> <a href=\"https:\/\/www.whizlabs.com\/blog\/new-aws-csaa-exam-preparation-released-march-2020\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">AWS certification exam<\/span><\/a><span style=\"font-weight: 400;\">, you may find a number of resources for the preparation such as AWS documentation, AWS whitepapers, AWS books, AWS Videos, and AWS FAQs. But the practice matters a lot if you are determined to clear the exam on your first attempt.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So, <strong><em>our<\/em> <em>expert team<\/em><\/strong> has curated a list of aws solutions architect practice exam questions with correct answers and detailed explanations for the AWS Certification exam. The same pattern we have followed in Whizlabs most popular <a href=\"https:\/\/www.whizlabs.com\/blog\/new-aws-csaa-exam-preparation-released-march-2020\/\" target=\"_blank\" rel=\"noopener\">AWS Certified Solutions Architect Associate Practice Tests<\/a> so that you could identify and understand which option is correct and why.<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p>To pass the exam, you&#8217;ll need to have a good understanding of AWS services and how to use them to solve common customer problems.<\/p>\n<p>The best way to prepare for the exam is to get <a href=\"https:\/\/www.whizlabs.com\/labs\/library\" target=\"_blank\" rel=\"noopener\">AWS Hands on-Labs<\/a> experience with AWS services &amp; also to get real time experience on<a href=\"https:\/\/www.whizlabs.com\/aws-sandbox\/\" target=\"_blank\" rel=\"noopener\"> AWS Sandbox<\/a>. This can be done by using the AWS console, getting hands-on experience with AWS CLI, or using the AWS SDKs. Additionally, there are practice exam and online resources that can help you prepare for the exam.<\/p>\n<p><span style=\"font-weight: 400;\">Try these <a href=\"https:\/\/www.whizlabs.com\/blog\/aws-certified-solutions-architect-associate-released-february-2018\/\" target=\"_blank\" rel=\"noopener\">AWS Solutions Architect Associate exam questions<\/a> SAA-C03 now and check your preparation level. Let&#8217;s see how many of these AWS Solutions Architect questions you can solve at Associate-level! Let\u2019s get started!<\/span><\/p>\n<blockquote><p>You can download the <a href=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/aws-solutions-architect-associate-exam-questions.pdf\" target=\"_blank\" rel=\"noopener\">AWS solutions architect-associate exam questions pdf<\/a> for the easy download and reference.<\/p><\/blockquote>\n<hr \/>\n<p><em><strong>1) You are an AWS Solutions Architect. Your company has a successful web application deployed in an AWS Auto Scaling group. The application attracts more and more global customers. However, the application\u2019s performance is impacted. Your manager asks you how to improve the performance and availability of the application. Which of the following AWS services would you recommend?\u00a0<\/strong><\/em><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. AWS DataSync<\/span><br \/>\nB. Amazon DynamoDB Accelerator<br \/>\n<span style=\"font-weight: 400;\">C. AWS Lake Formation<\/span><br \/>\n<span style=\"font-weight: 400;\">D. AWS Global Accelerator<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\">Answer: D<\/span><\/p>\n<p><b><\/b>AWS Global accelerator provides static IP addresses that are anycast in the AWS edge network. Incoming traffic is distributed across endpoints in AWS regions. The performance and availability of the application are improved.<\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bA \u200bis\u200b \u200bincorrect:\u200b Because DataSync is a tool to automate the data transfer and does not help to improve the performance.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bB \u200bis\u200b \u200bincorrect:\u200b DynamoDB is not mentioned in this question.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bC \u200bis\u200b \u200bincorrect:\u200b Because AWS Lake Formation is used to manage a large amount of data in AWS which would not help in this situation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bD \u200bis\u200b CORRECT:\u200b Check the <a href=\"https:\/\/docs.aws.amazon.com\/global-accelerator\/latest\/dg\/introduction-benefits-of-migrating.html\" target=\"_blank\" rel=\"nofollow noopener\">AWS Global Accelerator use cases<\/a>.\u00a0<\/span><span style=\"font-weight: 400;\">The Global Accelerator service can improve both application performance and availability.<\/span><\/p>\n<hr \/>\n<p><em><b>2) Your team is developing a high-performance computing (HPC) application. The application resolves complex, compute-intensive problems and needs a high-performance and low-latency Lustre file system. You need to configure this file system in AWS at a low cost. Which method is the most suitable?<\/b><\/em><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Create a Lustre file system through Amazon FSx.<br \/>\n<\/span>B. Launch a high-performance Lustre file system in Amazon EBS.<br \/>\nC. Create a high-speed volume cluster in an EC2 placement group.<br \/>\nD. Launch the Lustre file system from AWS Marketplace.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\">Answer: A<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Lustre file system is an open-source, parallel file system that can be used for HPC applications. Refer to<\/span><a href=\"http:\/\/lustre.org\/\" target=\"_blank\" rel=\"nofollow noopener\"> <span style=\"font-weight: 400;\">http:\/\/lustre.org\/<\/span><\/a><span style=\"font-weight: 400;\"> for its introduction. In Amazon FSx, users can quickly launch a Lustre file system at a low cost.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bA \u200bis\u200b CORRECT:\u200b Amazon FSx supports Lustre file systems and users pay for only the resources they use.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bB \u200bis\u200b \u200bincorrect:\u200b Although users may be able to configure a Lustre file system through EBS, it needs lots of extra configurations, Option A is more straightforward.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bC \u200bis\u200b \u200bincorrect:\u200b Because the EC2 placement group does not support a Lustre file system.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bD \u200bis\u200b \u200bincorrect:\u200b Because products in AWS Marketplace are not cost-effective. For Amazon FSx, there are no minimum fees or set-up charges. Check its pricing in\u00a0<\/span><a href=\"https:\/\/aws.amazon.com\/fsx\/lustre\/pricing\/\" target=\"_blank\" rel=\"nofollow noopener\">Amazon FSx for Lustre Pricing<\/a>.<\/p>\n<p><b>Read Now:<\/b> <a href=\"https:\/\/www.whizlabs.com\/blog\/amazon-braket\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\"><strong>Amazon Braket<\/strong><\/span><\/a><\/p>\n<hr \/>\n<p><em><b>3) You host a static website in an S3 bucket and there are global clients from multiple regions. You want to use an AWS service to store cache for frequently accessed content so that the latency is reduced and the data transfer rate is increased. Which of the following options would you choose?\u00a0<\/b><\/em><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Use AWS SDKs to horizontally scale parallel requests to the Amazon S3 service endpoints.<br \/>\n<\/span><span style=\"font-weight: 400;\">B. Create multiple Amazon S3 buckets and put Amazon EC2 and S3 in the same AWS Region.<br \/>\n<\/span><span style=\"font-weight: 400;\">C. Enable Cross-Region Replication to several AWS Regions to serve customers from different locations.<br \/>\n<\/span><span style=\"font-weight: 400;\">D. Configure CloudFront to deliver the content in the S3 bucket.<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>\u200bAnswer\u200b:<\/b><span style=\"font-weight: 400;\">\u200b D<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">CloudFront is able to store the frequently accessed content as a cache and the performance is optimized. Other options may help on the performance however they do not store cache for the S3 objects.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bA \u200bis\u200b \u200bincorrect:\u200b This option may increase the throughput however it does not store cache.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bB \u200bis\u200b \u200bincorrect:\u200b Because this option does not use cache.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bC \u200bis\u200b \u200bincorrect:\u200b This option creates multiple S3 buckets in different regions. It does not improve the performance using cache.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bD \u200bis\u200b CORRECT:\u200b Because CloudFront caches copies of the S3 files in its edge locations and users are routed to the edge location that has the lowest latency.<\/span><\/p>\n<hr \/>\n<p><em><b>4) Your company has an online game application deployed in an Auto Scaling group. The traffic of the application is predictable. Every Friday, the traffic starts to increase, remains high on weekends and then drops on Monday. You need to plan the scaling actions for the Auto Scaling group. Which method is the most suitable for the scaling policy?\u00a0<\/b><\/em><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Configure a scheduled CloudWatch event rule to launch\/terminate instances at the specified time every week.<br \/>\nB. <\/span>Create a predefined target tracking scaling policy based on the average CPU metric and the ASG will scale automatically.<br \/>\nC. Select the ASG and on the Automatic Scaling tab, add a step scaling policy to automatically scale-out\/in at fixed time every week.<br \/>\nD. Configure a scheduled action in the Auto Scaling group by specifying the recurrence, start\/end time, capacities, etc.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer\u200b:\u200b<\/b><span style=\"font-weight: 400;\"> D<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">The correct scaling policy should be scheduled scaling as it defines your own scaling schedule. Refer to<\/span><a href=\"https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/userguide\/schedule_time.html\" target=\"_blank\" rel=\"nofollow noopener\"> <span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/userguide\/schedule_time.html<\/span><\/a><span style=\"font-weight: 400;\"> for details.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bA \u200bis\u200b \u200bincorrect:\u200b This option may work. However, you have to configure a target such as a Lambda function to perform the scaling actions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bB \u200bis\u200b \u200bincorrect:\u200b The target tracking scaling policy defines a target for the ASG. The scaling actions do not happen based on a schedule.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bC \u200bis\u200b \u200bincorrect:\u200b The step scaling policy does not configure the ASG to scale at a specified time.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bD \u200bis\u200b CORRECT:\u200b With scheduled scaling, users define a schedule for the ASG to scale. This option can meet the requirements.<\/span><\/p>\n<hr \/>\n<p><b><em>5) You are creating several EC2 instances for a new application. For better performance of the application, both low network latency and high network throughput are required for the EC2 instances. All instances should be launched in a single availability zone. How would you configure this?<\/em>\u00a0<\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Launch all EC2 instances in a placement group using a Cluster placement strategy.<br \/>\nB. <\/span>Auto-assign a public IP when launching the EC2 instances.<br \/>\nC. Launch EC2 instances in an EC2 placement group and select the Spread placement strategy.<br \/>\nD. When launching the EC2 instances, select an instance type that supports enhanced networking.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><strong>Answer:<\/strong> A<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Cluster placement strategy helps to achieve a low-latency and high throughput network. The reference is in<\/span><a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/placement-groups.html#placement-groups-limitations-partition\" target=\"_blank\" rel=\"nofollow noopener\"> <span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/placement-groups.html#placement-groups-limitations-partition<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bA \u200bis\u200b CORRECT:\u200b The Cluster placement strategy can improve network performance among EC2 instances. The strategy can be selected when creating a placement group:<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-74755 size-full\" title=\"EC2 placement groups\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/EC2-placement-groups.png\" alt=\"EC2 placement groups\" width=\"595\" height=\"300\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/EC2-placement-groups.png 595w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/EC2-placement-groups-300x151.png 300w\" sizes=\"(max-width: 595px) 100vw, 595px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bB \u200bis\u200b \u200bincorrect:\u200b Because the public IP cannot improve network performance.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bC \u200bis\u200b \u200bincorrect:\u200b The Spread placement strategy is recommended when a number of critical instances should be kept separate from each other. This strategy should not be used in this scenario.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bD \u200bis\u200b \u200bincorrect:\u200b The description in the option is inaccurate. The correct method is creating a placement group with a suitable placement strategy.<\/span><\/p>\n<p><b>Also Read:<\/b><a href=\"https:\/\/www.whizlabs.com\/blog\/aws-opsworks\/\" target=\"_blank\" rel=\"noopener\"> <span style=\"font-weight: 400;\">AWS OpsWorks<\/span><\/a><\/p>\n<hr \/>\n<p><em><b>6) You need to deploy a machine learning application in AWS EC2. The performance of inter-instance communication is very critical for the application and you want to attach a network device to the instance so that the performance can be greatly improved. Which option is the most appropriate to improve the performance?\u00a0<\/b><\/em><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Enable enhanced networking features in the EC2 instance.<br \/>\n<\/span>B. Configure Elastic Fabric Adapter (EFA) in the instance.<br \/>\nC. Attach high-speed Elastic Network Interface (ENI) in the instance.<br \/>\nD. Create an Elastic File System (EFS) and mount the file system in the instance.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer\u200b:<\/b><span style=\"font-weight: 400;\"> B<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">With Elastic Fabric Adapter (EFA), users can get better performance if compared with enhanced networking (Elastic Network Adapter) or Elastic Network Interface. Check the differences between EFAs and ENAs in<\/span><a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/efa.html\" target=\"_blank\" rel=\"nofollow noopener\"> <span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/efa.html<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bA \u200bis\u200b \u200bincorrect:\u200b Because with Elastic Fabric Adapter (EFA), users can achieve a better network performance than enhanced networking.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bB \u200bis\u200b CORRECT:\u200b Because EFA is the most suitable method for accelerating High-Performance Computing (HPC) and machine learning application.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bC \u200bis\u200b \u200bincorrect:\u200b Because Elastic Network Interface (ENI) cannot improve the performance as required.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bD \u200bis\u200b \u200bincorrect:\u200b The Elastic File System (EFS) cannot accelerate inter-instance communication.<\/span><\/p>\n<hr \/>\n<p><b><em>7) You have an S3 bucket that receives photos uploaded by customers. When an object is uploaded, an event notification is sent to an SQS queue with the object details. You also have an ECS cluster that gets messages from the queue to do the batch processing. The queue size may change greatly depending on the number of incoming messages and backend processing speed. Which metric would you use to scale up\/down the ECS cluster capacity?<\/em> <\/b><\/p>\n<p style=\"padding-left: 40px;\">A. The number of messages in the SQS queue.<br \/>\nB. Memory usage of the ECS cluster.<br \/>\nC. Number of objects in the S3 bucket.<br \/>\nD. Number of containers in the ECS cluster.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>\u200bAnswer\u200b:\u200b<\/b><span style=\"font-weight: 400;\"> A<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this scenario, the SQS queue is used to store the object details which is a highly scalable and reliable service. ECS is ideal to perform batch processing and it should scale up or down based on the number of messages in the queue. Details please check<\/span><a href=\"https:\/\/github.com\/aws-samples\/ecs-refarch-batch-processing\" target=\"_blank\" rel=\"nofollow noopener\"> <span style=\"font-weight: 400;\">https:\/\/github.com\/aws-samples\/ecs-refarch-batch-processing<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bA \u200bis\u200b CORRECT:\u200b Users can configure a CloudWatch alarm based on the number of messages in the SQS queue and notify the ECS cluster to scale up or down using the alarm.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bB \u200bis\u200b \u200bincorrect:\u200b Because memory usage may not be able to reflect the workload.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bC \u200bis\u200b \u200bincorrect:\u200b Because the number of objects in S3 cannot determine if the ECS cluster should change its capacity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option\u200b \u200bD \u200bis\u200b \u200bincorrect:\u200b Because the number of containers cannot be used as a metric to trigger an auto-scaling event.<\/span><\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p><em><strong>10) When creating an AWS CloudFront distribution, which of the following is not an origin?<\/strong><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. Elastic Load Balancer<br \/>\nB. AWS S3 bucket<br \/>\nC. AWS MediaPackage channel endpoint<br \/>\nD. AWS Lambda<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\">Answer: D<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67240\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-CloudFront-1-.png\" alt=\"\" width=\"1071\" height=\"396\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-CloudFront-1-.png 1071w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-CloudFront-1--300x111.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-CloudFront-1--768x284.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-CloudFront-1--1024x379.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-CloudFront-1--640x237.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-CloudFront-1--681x252.png 681w\" sizes=\"(max-width: 1071px) 100vw, 1071px\" \/><\/p>\n<p>Explanation: AWS Lambda is not supported directly as the CloudFront origin. However, Lambda can be invoked through API Gateway which can be set as the origin for AWS CloudFront. Read more here: <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/Introduction.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/Introduction.html<\/a><\/p>\n<hr \/>\n<p><b><i>14) Your organization is building a collaboration platform for which they chose AWS EC2 for web and application servers and MySQL RDS instance as the database. Due to the nature of the traffic to the application, they would like to increase the number of connections to RDS instances. How can this be achieved?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Login to RDS instance and modify database config file under \/etc\/mysql\/my.cnf<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">B. Create a new parameter group, attach it to the DB instance and change the setting.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">C. Create a new option group, attach it to the DB instance and change the setting.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">D. Modify setting in the default options group attached to the DB instance.<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> B<\/span><\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67250\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-RDS-1.png\" alt=\"\" width=\"624\" height=\"669\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-RDS-1.png 624w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-RDS-1-280x300.png 280w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-RDS-1-392x420.png 392w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/UserGuide\/USER_WorkingWithParamGroups\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/UserGuide\/USER_WorkingWithParamGroups<\/a><\/p>\n<hr \/>\n<p><b><i>15) You will be launching and terminating EC2 instances on a need basis for your workloads. You need to run some shell scripts and perform certain checks connecting to the AWS S3 bucket when the instance is getting launched. Which of the following options will allow performing any tasks during launch? (choose multiple)<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\">A. Use Instance user data for shell scripts.<br \/>\nB. Use Instance metadata for shell scripts.<br \/>\nC. Use AutoScaling Group lifecycle hooks and trigger AWS Lambda function through CloudWatch events.<br \/>\nD. Use Placement Groups and set \u201cInstanceLaunch\u201d state to trigger AWS Lambda functions.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> A, C<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option A is correct.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67246\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-1.png\" alt=\"\" width=\"618\" height=\"368\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-1.png 618w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-1-300x179.png 300w\" sizes=\"(max-width: 618px) 100vw, 618px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Option C is correct.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67247\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-2.png\" alt=\"\" width=\"863\" height=\"350\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-2.png 863w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-2-300x122.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-2-768x311.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-2-640x260.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-Autoscaling-2-681x276.png 681w\" sizes=\"(max-width: 863px) 100vw, 863px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/userguide\/lifecycle-hooks.html#preparing-for-notification\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/userguide\/lifecycle-hooks.html#preparing-for-notification<\/span><\/a><\/p>\n<hr \/>\n<p><b><i>16) Your organization has an AWS setup and planning to build Single Sign-On for users to authenticate with on-premise Microsoft Active Directory Federation Services (ADFS) and let users log in to the AWS console using AWS STS Enterprise Identity Federation. Which of the following services do you need to call from AWS STS service after you authenticate with your on-premise?<\/i><\/b><\/p>\n<p>A. AssumeRoleWithSAML<br \/>\nB. GetFederationToken<br \/>\nC. AssumeRoleWithWebIdentity<br \/>\nD. GetCallerIdentity<\/p>\n<p><b>Answer:<\/b><span style=\"font-weight: 400;\"> A<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67248\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-IAM-CTS-1.png\" alt=\"\" width=\"668\" height=\"149\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-IAM-CTS-1.png 668w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-IAM-CTS-1-300x67.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-IAM-CTS-1-640x143.png 640w\" sizes=\"(max-width: 668px) 100vw, 668px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/STS\/latest\/APIReference\/API_AssumeRoleWithSAML.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/STS\/latest\/APIReference\/API_AssumeRoleWithSAML.html<\/a><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67249\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-IAM-CTS-2.png\" alt=\"\" width=\"631\" height=\"372\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-IAM-CTS-2.png 631w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-IAM-CTS-2-300x177.png 300w\" sizes=\"(max-width: 631px) 100vw, 631px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/id_roles_providers_saml.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/id_roles_providers_saml.html<\/a><\/p>\n<hr \/>\n<p><em><b>18) Your organization was planning to develop a web application on AWS EC2. Application admin was tasked to perform AWS setup required to spin EC2 instance inside an existing private VPC. He\/she has created a subnet and wants to ensure no other subnets in the VPC can communicate with your subnet except for the specific IP address. So he\/she created a new route table and associated with the new subnet. When he\/she was trying to delete the route with the target as local, there is no option to delete the route. What could have caused this behavior?<\/b><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. Policy attached to IAM user does not have access to remove routes.<br \/>\nB. A route with the target as local cannot be deleted.<br \/>\nC. You cannot add\/delete routes when associated with the subnet. Remove associated, add\/delete routes and associate again with the subnet.<br \/>\nD. There must be at least one route on the route table. Add a new route to enable delete option on existing routes.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> B<\/span><\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67265\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-1-1.png\" alt=\"\" width=\"575\" height=\"65\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-1-1.png 575w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-1-1-300x34.png 300w\" sizes=\"(max-width: 575px) 100vw, 575px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/VPC_Route_Tables.html#RouteTa\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/VPC_Route_Tables.html#RouteTa<\/span><\/a><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67266\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-2-1.png\" alt=\"\" width=\"590\" height=\"146\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-2-1.png 590w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-2-1-300x74.png 300w\" sizes=\"(max-width: 590px) 100vw, 590px\" \/><\/p>\n<hr \/>\n<p><em><b>20) Organization ABC has a requirement to send emails to multiple users from their application deployed on EC2 instance in a private VPC. Email receivers will not be IAM users. You have decided to use AWS Simple Email Service and configured from email address. You are using AWS SES API to send emails from your EC2 instance to multiple users. However, email sending getting failed. Which of the following options could be the reason?<\/b><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. You have not created VPC endpoint for SES service and configured in the route table.<br \/>\nB. AWS SES is in sandbox mode by default which can send emails only to verified email addresses.<br \/>\nC. IAM user of configured from email address does not have access AWS SES to send emails.<br \/>\nD. AWS SES cannot send emails to addresses which are not configured as IAM users. You have to use the SMTP service provided by AWS.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><strong>Answer:<\/strong><span style=\"font-weight: 400;\"> B<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Amazon SES is an email platform that provides an easy, cost-effective way for you to send and receive email using your own email addresses and domains.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example, you can send marketing emails such as special offers, transactional emails such as order confirmations, and other types of correspondence such as newsletters. When you use Amazon SES to receive mail, you can develop software solutions such as email autoresponders, email unsubscribe systems and applications that generate customer support tickets from incoming emails.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67271\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Simple-Email-Service-1.png\" alt=\"\" width=\"563\" height=\"304\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Simple-Email-Service-1.png 563w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Simple-Email-Service-1-300x162.png 300w\" sizes=\"(max-width: 563px) 100vw, 563px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/ses\/latest\/DeveloperGuide\/limits.html\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/ses\/latest\/DeveloperGuide\/limits.html<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/ses\/latest\/DeveloperGuide\/request-production-access.html\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/ses\/latest\/DeveloperGuide\/request-production-access.html<\/span><\/a><\/p>\n<hr \/>\n<p><b><i>21) You have configured AWS S3 event notification to send a message to AWS Simple Queue Service whenever an object is deleted. You are performing a ReceiveMessage API operation on the AWS SQS queue to receive the S3 delete object message onto AWS EC2 instance. For any successful message operations, you are deleting them from the queue. For failed operations, you are not deleting the messages. You have developed a retry mechanism which reruns the application every 5 minutes for failed ReceiveMessage operations. However, you are not receiving the messages again during the rerun. What could have caused this?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. AWS SQS deletes the message after it has been read through ReceiveMessage API<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">B. You are using Long Polling which does not guarantee message delivery.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">C. Failed ReceiveMessage queue messages are automatically sent to Dead Letter Queues. You need to ReceiveMessage from Dead Letter Queue for failed retries.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">D. Visibility Timeout on the SQS queue is set to 10 minutes.<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> D<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">When a consumer receives and processes a message from a queue, the message remains in the queue. Amazon SQS doesn&#8217;t automatically delete the message. Because Amazon SQS is a distributed system, there&#8217;s no guarantee that the consumer actually receives the message (for example, due to a connectivity issue, or due to an issue in the consumer application). Thus, the consumer must delete the message from the queue after receiving and processing it.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67272\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-SQS-1.png\" alt=\"\" width=\"599\" height=\"333\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-SQS-1.png 599w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-SQS-1-300x167.png 300w\" sizes=\"(max-width: 599px) 100vw, 599px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AWSSimpleQueueService\/latest\/SQSDeveloperGuide\/sqs-visibility-timeout.html\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AWSSimpleQueueService\/latest\/SQSDeveloperGuide\/sqs-visibility-timeout.html<\/span><\/a><\/p>\n<hr \/>\n<p><b><i>22) You had set up an internal HTTP(S) Elastic Load Balancer to route requests to two EC2 instances inside a private VPC. However, one of the target EC2 instance is showing Unhealthy status. Which of the following options could not be a reason for this?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Port 80\/443 is not allowed on EC2 instance\u2019s Security Group from the load balancer.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">B. An EC2 instance is in different availability zones than load balancer.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">C. The ping path does not exist on the EC2 instance.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">D. The target did not return a successful response code<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> B<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a target is taking longer than expected to enter the InService state, it might be failing health checks. Your target is not in service until it passes one health check.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67273\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-ELB-1.png\" alt=\"\" width=\"602\" height=\"586\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-ELB-1.png 602w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-ELB-1-300x292.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-ELB-1-431x420.png 431w\" sizes=\"(max-width: 602px) 100vw, 602px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/load-balancer-troubleshooting.html#target-not-inservice\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/load-balancer-troubleshooting.html#target-not-inservice<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/target-group-health-checks.html\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/target-group-health-checks.html<\/span><\/a><\/p>\n<hr \/>\n<p><b><i>23) Your organization has an existing VPC setup and has a requirement to route any traffic going from VPC to AWS S3 bucket through AWS internal network. So they have created a VPC endpoint for S3 and configured to allow traffic for S3 buckets. The application you are developing involves sending traffic to AWS S3 bucket from VPC for which you planned to use a similar approach. You have created a new route table, added route to VPC endpoint and associated route table with your new subnet. However, when you are trying to send a request from EC2 to S3 bucket using AWS CLI, the request is getting failed with 403 access denied errors. What could be causing the failure?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. AWS S3 bucket is in a different region than your VPC.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">B. EC2 security group outbound rules not allowing traffic to S3 prefix list.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">C. VPC endpoint might have a restrictive policy and does not contain the new S3 bucket.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">D. S3 bucket CORS configuration does not have EC2 instances as the origin.<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> C<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option A is not correct. The question states \u201c403 access denied\u201d. If the S3 bucket is in a different region than VPC, the request looks for a route with NAT Gateway or Internet Gateway. If it exists, the request goes through the internet to S3. If it does not exist, the request gets failed with connection refused or connection timed out. Not with an error \u201c403 access denied\u201d.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option B is not correct. Same as above, when the security group does not allow traffic, the failure cause will be 403 access denied.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option C is correct.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67274\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-and-VPC-1.png\" alt=\"\" width=\"555\" height=\"322\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-and-VPC-1.png 555w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-and-VPC-1-300x174.png 300w\" sizes=\"(max-width: 555px) 100vw, 555px\" \/><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67275\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-and-VPC-2.png\" alt=\"\" width=\"566\" height=\"391\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-and-VPC-2.png 566w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-and-VPC-2-300x207.png 300w\" sizes=\"(max-width: 566px) 100vw, 566px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Option D is not correct.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cross-origin resource sharing (CORS) defines a way for client web applications that are loaded in one domain to interact with resources in a different domain. With CORS support, you can build rich client-side web applications with Amazon S3 and selectively allow cross-origin access to your Amazon S3 resources.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this case, the request is not coming from a web client.<\/span><\/p>\n<hr \/>\n<p><b><i>24) You have launched an RDS instance with MySQL database with default configuration for your file sharing application to store all the transactional information. Due to security compliance, your organization wants to encrypt all the databases and storage on the cloud. They approached you to perform this activity on your MySQL RDS database. How can you achieve this?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\">A. Copy snapshot from the latest snapshot of your RDS instance, select encryption during copy and restore a new DB instance from the newly encrypted snapshot.<br \/>\nB. Stop the RDS instance, modify and select the encryption option. Start the RDS instance, it may take a while to start an RDS instance as existing data is getting encrypted.<br \/>\nC. Create a case with AWS support to enable encryption for your RDS instance.<br \/>\nD. AWS RDS is a managed service and the data at rest in all RDS instances are encrypted by default.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> A<\/span><\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67276\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-RDS-1-1.png\" alt=\"\" width=\"482\" height=\"581\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-RDS-1-1.png 482w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-RDS-1-1-249x300.png 249w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-RDS-1-1-348x420.png 348w\" sizes=\"(max-width: 482px) 100vw, 482px\" \/><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/blogs\/aws\/amazon-rds-update-share-encrypted-snapshots-encrypt-existing-instances\/\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/blogs\/aws\/amazon-rds-update-share-encrypted-snapshots-encrypt-existing-instances\/<\/span><\/a><\/p>\n<hr \/>\n<p><b><i>26) You have successfully set up a VPC peering connection in your account between two VPCs \u2013 VPC A and VPC B, each in a different region. When you are trying to make a request from VPC A to VPC B, the request fails. Which of the following could be a reason?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Cross-region peering is not supported in AWS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">B. CIDR blocks of both VPCs might be overlapping.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">C. Routes not configured in route tables for peering connections.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">D. VPC A security group default outbound rules not allowing traffic to VPC B IP range.<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> C<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option A is not correct. Cross-region VPC peering is supported in AWS.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option B is not correct.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67280\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-Peering-1.png\" alt=\"\" width=\"596\" height=\"342\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-Peering-1.png 596w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-Peering-1-300x172.png 300w\" sizes=\"(max-width: 596px) 100vw, 596px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">When the VPC IP CIDR blocks are overlapping, you cannot create a peering connection. Question states the peering connection was successful.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option C is correct.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To send private IPv4 traffic from your instance to an instance in a peer VPC, you must add a route to the route table that&#8217;s associated with your subnet in which your instance resides. The route points to the CIDR block (or portion of the CIDR block) of the peer VPC in the VPC peering connection.<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/PeeringGuide\/vpc-peering-routing.html\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/PeeringGuide\/vpc-peering-routing.html<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">Option D is not correct.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A security group\u2019s default outbound rule allows all traffic to go out from the resources attached to the security group.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67281\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-Peering-2.png\" alt=\"\" width=\"599\" height=\"209\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-Peering-2.png 599w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-Peering-2-300x105.png 300w\" sizes=\"(max-width: 599px) 100vw, 599px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/VPC_SecurityGroups.html#Defaul\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/VPC_SecurityGroups.html#Defaul<\/span><\/a><\/p>\n<hr \/>\n<p><b><i>27) Which of the following statements are true in terms of allowing\/denying traffic from\/to VPC assuming the default rules are not in effect? (choose multiple)<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. In a Network ACL, for a successful HTTPS connection, add an inbound rule with HTTPS type, IP range in source and ALLOW traffic.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">B. In a Network ACL, for a successful HTTPS connection, you must add an inbound rule and outbound rule with HTTPS type, IP range in source and destination respectively and ALLOW traffic.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">C. In a Security Group, for a successful HTTPS connection, add an inbound rule with HTTPS type and IP range in the source.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">D. In a Security Group, for a successful HTTPS connection, you must add an inbound rule and outbound rule with HTTPS type, IP range in source and destination respectively.<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> B, C<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Security groups are stateful \u2014 if you send a request from your instance, the response traffic for that request is allowed to flow in regardless of inbound security group rules. Responses to allowed inbound traffic are allowed to flow out, regardless of outbound rules.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Network ACLs are stateless; responses to allowed inbound traffic are subject to the rules for outbound traffic (and vice versa).<\/span><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Option A is not correct. NACL must have an outbound rule defined for a successful connection due to its stateless nature.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Option B is correct.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Option C is correct.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Configuring an inbound rule in a security group is enough for a successful connection due to its stateful nature.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Option D is not correct.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Configuring an outbound rule for incoming connection is not required in security groups.<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/VPC_ACLs.html#ACLs\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/VPC_ACLs.html#ACLs<\/span><\/a><\/li>\n<li><a href=\"https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/VPC_SecurityGroups.html#VPCSe\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/VPC_SecurityGroups.html#VPCSe<\/span><\/a><\/li>\n<\/ul>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Architectures\"><\/span>Domain : Design Secure Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>28) A gaming company stores large size (terabytes to petabytes) of clickstream events data into their central S3 bucket. The company wants to analyze this clickstream data to generate business insight. Amazon Redshift, hosted securely in a private subnet of a VPC, is used for all data warehouse-related and analytical solutions. Using Amazon Redshift, the company wants to explore some solutions to securely run complex analytical queries on the clickstream data stored in S3 without transforming\/copying or loading the data in the Redshift.\u00a0<\/em><\/strong><br \/>\n<em><strong>As a Solutions Architect, which of the following AWS services would you recommend for this requirement, knowing that security and cost are two major priorities for the company?<\/strong><br \/>\n<\/em><\/p>\n<p><strong>A.\u00a0<\/strong>Create a VPC endpoint to establish a secure connection between Amazon Redshift and the S3 central bucket and use Amazon Athena to run the query<br \/>\n<strong>B.\u00a0<\/strong>Use NAT Gateway to connect Amazon Redshift to the internet and access the S3 static website. Use Amazon Redshift Spectrum to run the query<br \/>\n<strong>C.\u00a0<\/strong>Create a VPC endpoint to establish a secure connection between Amazon Redshift and the S3 central bucket and use Amazon Redshift Spectrum to run the query<br \/>\n<strong>D.\u00a0<\/strong>Create Site-to-Site VPN to set up a secure connection between Amazon Redshift and the S3 central bucket and use Amazon Redshift Spectrum to run the query<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> C<\/span><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b>\u00a0because Amazon Athena can directly query data in S3. Hence this will bypass the use of Redshift, which is not the requirement for the customer. They insisted on Amazon Redshift for the query purpose for usage.<br \/>\n<b>Option B is incorrect.\u00a0<\/b>Even though it is possible, NAT Gateway will connect Redshift to the internet and make the solution less secure. Plus, this is also not a cost-effective solution. Remember that security and cost both are important for the company.<br \/>\n<b>Option C is CORRECT<\/b>\u00a0because VPC Endpoint is a secure and cost-effective way to connect a VPC with Amazon S3 privately, and the traffic does not pass through the internet. Using Amazon Redshift Spectrum, one can run queries against the data stored in the S3 bucket without needing the data to be copied to Amazon Redshift. This meets both the requirements of building a secure yet cost-effective solution.<br \/>\n<b>Option D is incorrect<\/b>\u00a0because Site-to-Site VPN is used to connect an on-premises data center to AWS Cloud securely over the internet and is suitable for use cases like Migration, Hybrid Cloud, etc.<\/p>\n<p><b>References:\u00a0<\/b><a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/privatelink\/vpc-endpoints-s3.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/vpc\/latest\/privatelink\/vpc-endpoints-s3.html<\/a>,\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/s2svpn\/VPC_VPN.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/vpn\/latest\/s2svpn\/VPC_VPN.html<\/a>,\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/redshift\/latest\/dg\/c-getting-started-using-spectrum.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/redshift\/latest\/dg\/c-getting-started-using-spectrum.html<\/a><\/p>\n<hr \/>\n<p><strong>29) <\/strong><strong><em>The drug research team in a Pharmaceutical company produces highly sensitive data and stores them in Amazon S3. The team wants to ensure top-notch security for their data while it is stored in Amazon S3. To have better control of the security, the team wants to use their own encryption key but doesn\u2019t want to maintain any code to perform data encryption and decryption. Also, the team wants to be responsible for storing the Secret key.<\/em><\/strong><br \/>\n<strong><em>As a Solutions Architect, which of the following encryption types will suit the above requirement?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Server-side encryption with customer-provided encryption keys (SSE-C).<br \/>\n<strong>B.\u00a0<\/strong>Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)<br \/>\n<strong>C.\u00a0<\/strong>Server-Side Encryption with KMS keys Stored in AWS Key Management Service (SSE-KMS)<br \/>\n<strong>D.\u00a0<\/strong>Protect the data using\u00a0Client-Side Encryption<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> A<\/span><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>Data protection refers to the protection of data while in transit (as it travels to and from Amazon S3) and at rest (while it is stored on disks in Amazon S3 data centers).<\/p>\n<p>While data in transit can be protected using Secure Socket Layer\/Transport Layer Security (SSL\/TLS) or client-side encryption, one has the following options for protecting data at rest in Amazon S3:<\/p>\n<p>Server-Side Encryption \u2013 Request Amazon S3 to encrypt your object before saving it on disks in its data centers and then decrypt it when you download the objects.<\/p>\n<p>There are three types of Server-side encryption:<\/p>\n<p>Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)<\/p>\n<p>Server-Side Encryption with KMS keys Stored in AWS Key Management Service (SSE-KMS)<\/p>\n<p>Server-side encryption with customer-provided encryption keys (SSE-C).<\/p>\n<p>Client-Side Encryption \u2013 Encrypt data client-side and upload the encrypted data to Amazon S3. In this case, you manage the encryption process, the encryption keys, and related tools.<\/p>\n<p>In this scenario, the customer is referring to data at rest.<\/p>\n<p><b>Option A is CORRECT<\/b>\u00a0because data security is the top priority for the team, and they want to use their own encryption key. In this option, the customer provides the encryption key while S3 manages encryption \u2013 decryption. So there won\u2019t be any operational overhead, yet the customer will have better control in managing the key.<br \/>\n<b>Option B is incorrect<\/b>\u00a0because each object is encrypted with a unique key\u00a0when you use Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3). It also encrypts the key itself with a root key that rotates regularly.<\/p>\n<p>This encryption type uses one of the strongest block ciphers available, 256-bit Advanced Encryption Standard (AES-256) GCM, to encrypt your data, but it does not let customers create or manage the key. Hence this is not a choice here.<\/p>\n<p><b>Option C is incorrect<\/b>\u00a0because\u00a0Server-Side Encryption with AWS KMS keys (SSE-KMS) is similar to SSE-S3 but with some additional benefits and charges for using this service.<\/p>\n<p>There are separate permissions for the use of a KMS key that provides protection against unauthorized access to your objects in Amazon S3.<\/p>\n<p>This option is mainly neglected because AWS still manages the storage of the encryption key or master key (in KMS) while encryption-decryption is managed by the customer. The expectation from the team in the above scenario is just the opposite.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-84117 size-large\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa2-1024x393.png\" alt=\"csa2\" width=\"1024\" height=\"393\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa2-1024x393.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa2-300x115.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa2-768x295.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa2-640x245.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa2-681x261.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa2-150x58.png 150w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa2.png 1069w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p><b>Option D is incorrect\u00a0<\/b>because, in this case, one has to manage the encryption process, the encryption keys, and related tools. And it is mentioned clearly above that the team does not want that.<\/p>\n<p><b>Reference:\u00a0\u00a0<\/b><a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/serv-side-encryption.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/serv-side-encryption.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures\"><\/span>Domain: Design Cost-Optimized Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>30) An online retail company stores a large number of customer data (terabytes to petabytes) into Amazon S3.The company wants to drive some business insight out of this data. They plan to securely run SQL-based complex analytical queries on the S3 data directly and process it to generate business insights and build a data visualization dashboard for the business and management review and decision-making.\u00a0<\/em><\/strong><br \/>\n<strong><em>You are hired as a Solutions Architect to provide a cost-effective and quick solution to this. Which of the following AWS services would you recommend?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Use Amazon Redshift Spectrum to run SQL-based queries on the data stored in Amazon S3 and then process it to Amazon Kinesis Data Analytics for creating a dashboard<br \/>\n<strong>B.\u00a0<\/strong>Use Amazon Redshift to run SQL-based queries on the data stored in Amazon S3 and then process it on a custom web-based dashboard for data visualization<br \/>\n<strong>C.\u00a0<\/strong>Use Amazon EMR to run SQL-based queries on the data stored in Amazon S3 and then process it to Amazon Quicksight for data visualization<br \/>\n<strong>D.\u00a0<\/strong>Use Amazon Athena to run SQL-based queries on the data stored in Amazon S3 and then process it to Amazon Quicksight for dashboard view<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> D<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b>\u00a0because Amazon Kinesis Data Analytics cannot be used to generate business insights as mentioned in the requirement. It neither can be used for data visualization.<\/p>\n<p>One must depend on some BI tool after processing data from Amazon Kinesis Data Analytics. It is not a cost-optimized solution.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84118 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1.png\" sizes=\"(max-width: 1224px) 100vw, 1224px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1.png 1224w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1-300x118.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1-1024x402.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1-768x302.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1-1069x420.png 1069w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1-640x252.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1-681x268.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.1-150x59.png 150w\" alt=\"\" width=\"1224\" height=\"481\" \/><\/p>\n<p><b>Option B is incorrect<\/b>\u00a0primarily due to the cost factors. Using Amazon Redshift for querying S3 data requires the transfer and loading of the data to Redshift instances. It also takes time and additional cost to create a custom web-based dashboard or data visualization tool.<br \/>\n<b>Option C is incorrect<\/b>\u00a0because Amazon EMR is a cloud big data platform for running large-scale distributed data processing jobs, interactive SQL queries, and machine learning (ML) applications using open-source analytics frameworks such as Apache Spark, Apache Hive, and Presto. It is mainly used to perform big data analytics, process real-time data streams, accelerate data science and ML adoption. The requirement here is not to build any of such solutions on a Big Data platform. Hence this option is not suitable. It is neither quick nor cost-effective compared to option D.<br \/>\n<b>Option D is CORRECT<\/b>\u00a0because Amazon Athena is the most cost-effective solution to run SQL-based analytical queries on S3 data and then publish it to Amazon QuickSight for dashboard view.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84119 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.2.png\" sizes=\"(max-width: 1013px) 100vw, 1013px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.2.png 1013w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.2-300x63.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.2-768x162.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.2-640x135.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.2-681x144.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.2-150x32.png 150w\" alt=\"\" width=\"1013\" height=\"214\" \/><img decoding=\"async\" class=\"aligncenter size-full wp-image-84120 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.3.png\" sizes=\"(max-width: 1226px) 100vw, 1226px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.3.png 1226w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.3-300x85.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.3-1024x289.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.3-768x217.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.3-640x181.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.3-681x192.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa3.3-150x42.png 150w\" alt=\"\" width=\"1226\" height=\"346\" \/><\/p>\n<p><b>References:\u00a0<\/b><a href=\"https:\/\/aws.amazon.com\/kinesis\/data-analytics\/?nc=sn&amp;loc=1\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/kinesis\/data-analytics\/?nc=sn&amp;loc=1<\/a>,\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/athena\/latest\/ug\/when-should-i-use-ate.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/athena\/latest\/ug\/when-should-i-use-ate.html<\/a>,\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/quicksight\/latest\/user\/welcome.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/quicksight\/latest\/user\/welcome.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-2\"><\/span>Domain : Design Cost-Optimized Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>31)<\/strong><\/em> <strong><em>An organization has archived all their data to Amazon S3 Glacier for a long term. However, the organization needs to retrieve some portion of the archived data regularly. This retrieval\u00a0 process is quite random and incurs a good amount of cost for the organization. As expense is the top priority,\u00a0the organization wants to set a data retrieval policy to avoid any data retrieval charges.<\/em><\/strong><br \/>\n<strong><em>Which one of the following retrieval policies suits this in the best way?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>No Retrieval Limit<br \/>\n<strong>B.\u00a0<\/strong>Free Tier Only<br \/>\n<strong>C.\u00a0<\/strong>Max Retrieval Rate<br \/>\n<strong>D.\u00a0<\/strong>Standard Retrieval<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> B<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b>\u00a0because\u00a0No Retrieval Limit, the default data retrieval policy, is used when you do not want to set any retrieval quota. All valid data retrieval requests are accepted. This retrieval policy incurs a high cost to your AWS account for each region.<br \/>\n<b>Option B is CORRECT<\/b>\u00a0because\u00a0using a Free Tier Only policy, you can keep your retrievals within your daily AWS Free Tier allowance and not incur any data retrieval costs. And in this policy,\u00a0S3 Glacier synchronously rejects retrieval requests that exceed your AWS Free Tier allowance.<br \/>\n<b>Option C is incorrect<\/b>\u00a0because\u00a0you use Max Retrieval Rate policy when you want to retrieve more data than what is in your AWS Free Tier allowance. Max Retrieval Rate policy sets a bytes-per-hour retrieval-rate quota. The Max Retrieval Rate policy ensures that the peak retrieval rate from all retrieval jobs across your account in an AWS Region does not exceed the bytes-per-hour quota that you set. Max Retrieval rate policy is not in the free tier.<br \/>\n<b>Option D is incorrect<\/b>\u00a0because Standard Retrieval is a process of data retrieval from S3 Glacier that takes around 12 hours to retrieve data. This retrieval type is chargeable and incurs costs on the AWS account per region wise.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84121 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa4.png\" sizes=\"(max-width: 1039px) 100vw, 1039px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa4.png 1039w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa4-300x104.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa4-1024x356.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa4-768x267.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa4-640x222.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa4-681x237.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa4-150x52.png 150w\" alt=\"\" width=\"1039\" height=\"361\" \/><\/p>\n<p><b>References:\u00a0<\/b><a href=\"https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/glacier-retrieval-fees\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/glacier-retrieval-fees\/<\/a>,\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/restoring-objects-retrieval-options.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/restoring-objects-retrieval-options.html<\/a>,\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/amazonglacier\/latest\/dev\/data-retrieval-policy.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/amazonglacier\/latest\/dev\/data-retrieval-policy.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures\"><\/span>Domain: Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>32) A gaming company planned to launch their new gaming application that will be in both web and mobile platforms. The company considers using GraphQL API to securely query or update data through a single endpoint from multiple databases, microservices, and several other API endpoints. They also want some portions of the data to be updated and accessed in real-time.<\/em><\/strong><br \/>\n<strong><em>The customer prefers to build this new application mostly on serverless components of AWS.<\/em><\/strong><br \/>\n<strong><em>As a Solutions Architect, which of the following AWS services would you recommend the customer to develop their GraphQL API?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Kinesis Data Firehose<br \/>\n<strong>B.\u00a0<\/strong>Amazon Neptune<br \/>\n<strong>C.\u00a0<\/strong>Amazon API Gateway<br \/>\n<strong>D.\u00a0<\/strong>AWS AppSync<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> D<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b>\u00a0because\u00a0Amazon Kinesis Data Firehose is a fully managed service for delivering real-time streaming data to destinations such as Amazon S3, Amazon Redshift, Amazon OpenSearch, etc. It cannot create GraphQL API.<br \/>\n<b>Option B is incorrect<\/b>. Amazon Neptune is a fast, reliable, fully managed graph\u00a0<b>database<\/b>\u00a0service that makes it easy to build and run applications. It is a database and cannot be used to create GraphQL API.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84122 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa5.png\" sizes=\"(max-width: 894px) 100vw, 894px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa5.png 894w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa5-300x65.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa5-768x167.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa5-640x139.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa5-681x148.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa5-150x33.png 150w\" alt=\"\" width=\"894\" height=\"194\" \/><b>Option C is incorrect<\/b>\u00a0because Amazon API Gateway supports RESTful APIs (HTTP and REST API) and WebSocket APIs. It is not meant for the development of GraphQL API.<br \/>\n<b>Option D is CORRECT<\/b>\u00a0because with AWS AppSync one can create serverless GraphQL APIs that simplify application development by providing a single endpoint to securely query or update data from multiple data sources and leverage GraphQL to implement engaging real-time application experiences.<\/p>\n<p><b>References:\u00a0<\/b><a href=\"https:\/\/aws.amazon.com\/neptune\/features\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/neptune\/features\/<\/a>,\u00a0<a href=\"https:\/\/aws.amazon.com\/api-gateway\/features\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/api-gateway\/features\/<\/a>,\u00a0<a href=\"https:\/\/aws.amazon.com\/appsync\/product-details\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/appsync\/product-details\/<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-2\"><\/span>Domain:\u00a0Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>33) A weather forecasting company comes up with the requirement of building a high-performance, highly parallel POSIX-compliant file system that stores data across multiple network file systems to serve thousands of simultaneous clients, driving millions of IOPS (Input\/Output Operations per Second) with sub-millisecond latency. The company needs a cost-optimized file system storage for short-term, processing-heavy workloads that can provide burst throughput to meet this requirement.<\/strong><\/em><br \/>\n<em><strong>What type of file systems storage will suit the company in the best way?<\/strong><\/em><\/p>\n<p><strong>A.\u00a0<\/strong>FSx for Lustre with Deployment Type as Scratch File System<br \/>\n<strong>B.\u00a0<\/strong>FSx for Lustre with Deployment Type as Persistent file systems<br \/>\n<strong>C.\u00a0<\/strong>Amazon Elastic File System (Amazon EFS)<br \/>\n<strong>D.\u00a0<\/strong>Amazon FSx for Windows File Server<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> A<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>File system deployment options for FSx for Lustre:<\/b><\/p>\n<p>Amazon FSx for Lustre provides two file system deployment options: scratch and persistent.<\/p>\n<p>Both deployment options support solid-state drive (SSD) storage. However, hard disk drive (HDD) storage is supported only in one of the persistent deployment types.<\/p>\n<p>You choose the file system deployment type when you create a new file system using the AWS Management Console, the AWS Command Line Interface (AWS CLI), or the Amazon FSx for Lustre API.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84123 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.1.png\" sizes=\"(max-width: 798px) 100vw, 798px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.1.png 798w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.1-300x169.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.1-768x433.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.1-745x420.png 745w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.1-640x361.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.1-681x384.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.1-150x85.png 150w\" alt=\"\" width=\"798\" height=\"450\" \/><\/p>\n<p><b>Option A is CORRECT<\/b>\u00a0because FSx for Lustre with Deployment Type as Scratch File System is designed for temporary storage and shorter-term data processing. Data isn\u2019t replicated and doesn\u2019t persist if a file server fails. Scratch file systems provide high burst throughput of up to six times the baseline throughput of 200 MBps per TiB storage capacity.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84124 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.2.png\" sizes=\"(max-width: 938px) 100vw, 938px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.2.png 938w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.2-300x217.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.2-768x555.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.2-581x420.png 581w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.2-640x463.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.2-681x492.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.2-150x108.png 150w\" alt=\"\" width=\"938\" height=\"678\" \/><b>Option B is incorrect<\/b>\u00a0because FSx for Lustre with Deployment Type as Persistent file systems are designed for longer-term storage and workloads. The file servers are highly available, and data is automatically replicated within the same Availability Zone in which the file system is located. The data volumes attached to the file servers are replicated independently from the file servers to which they are attached.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84125 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.3.png\" sizes=\"(max-width: 924px) 100vw, 924px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.3.png 924w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.3-300x219.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.3-768x559.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.3-577x420.png 577w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.3-640x466.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.3-681x496.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa6.3-150x109.png 150w\" alt=\"\" width=\"924\" height=\"673\" \/><b>Option C is incorrect<\/b>\u00a0because Amazon EFS is not as effective as Amazon FSx for Luster when it comes to HPC design to deliver millions of IOPS (Input\/Output Operations per Second) with sub-millisecond latency.<br \/>\n<b>Option D is incorrect.\u00a0<\/b>The storage requirement here is for POSIX-compliant file systems to support Linux-based workloads. Hence\u00a0Amazon FSx for Windows File Server is not suitable here.<\/p>\n<p><b>Reference:\u00a0<\/b><a href=\"https:\/\/docs.aws.amazon.com\/fsx\/latest\/LustreGuide\/using-fsx-lustre.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/fsx\/latest\/LustreGuide\/using-fsx-lustre.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Resilient_Architectures\"><\/span>Domain: Design Resilient Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>34) You are a solutions architect working for an online retailer. Your online website uses REST API calls via API Gateway and Lambda from your Angular SPA front-end to interact with your DynamoDB data store. Your DynamoDB tables are used for customer preferences, account, and product information. When your web traffic spikes, some requests return a 429 error response. What might be the reason your requests are returning a 429 response<\/strong><\/em><\/p>\n<p><strong>A.\u00a0<\/strong>Your Lambda function has exceeded the concurrency limit<br \/>\n<strong>B.\u00a0<\/strong>DynamoDB concurrency limit has been exceeded<br \/>\n<strong>C.\u00a0<\/strong>Your Angular service failed to connect to your API Gateway REST endpoint<br \/>\n<strong>D.\u00a0<\/strong>Your Angular service cannot handle the volume spike<br \/>\n<strong>E.\u00a0<\/strong>Your API Gateway has exceeded the steady-state request rate and burst limits<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> A &amp; E<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is correct<\/b><b>.<\/b>\u00a0When your traffic spikes, your Lambda function can exceed the limit set on the number of concurrent instances that can be run (burst concurrency limit in the US: 3,000).<br \/>\n<b>Option B is incorrect<\/b>.\u00a0When your table exceeds its provisioned throughput DynamoDB will return a 400 error to the requesting service, in this case, API Gateway. This will not result in the propagation of a 429 error response (too many requests) back to the Angular SPA service.<br \/>\n<b>Option C is incorrect.<\/b>\u00a0If your Angular service fails to connect to your API Gateway REST endpoint your code will not generate a 429 error response\u00a0(too many requests).<br \/>\n<b>Option D is incorrect.\u00a0<\/b>Since your Angular SPA code runs in the individual user\u2019s web browser, this option makes no sense.<br \/>\n<b>Option E is correct.<\/b>\u00a0When your API Gateway request volume reaches the steady-state request rate and bursting limit, API Gateway throttles your requests to protect your back-end services. When these requests are throttled, API Gateway returns a 429 error response\u00a0(too many requests).<\/p>\n<p><b>Reference:\u00a0<\/b>Please see the Amazon API Gateway developer guide titled\u00a0Throttle API requests for better throughput (<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/api-gateway-request-throttling.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/api-gateway-request-throttling.html<\/a>), the Towards Data Science article titled Full Stack Development Tutorial: Integrate AWS Lambda Serverless Service into Angular SPA\u00a0(<a href=\"https:\/\/towardsdatascience.com\/full-stack-development-tutorial-integrate-aws-lambda-serverless-service-into-angular-spa-abb70bcf417f\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/towardsdatascience.com\/full-stack-development-tutorial-integrate-aws-lambda-serverless-service-into-angular-spa-abb70bcf417f<\/a>), the\u00a0Amazon API Gateway developer guide\u00a0titled Invoking a REST API in Amazon API Gateway (<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/how-to-call-api.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/how-to-call-api.html<\/a>), the AWS Lambda developer guide titled Lambda function scaling (<a href=\"https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/invocation-scaling.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/invocation-scaling.html<\/a>), and the Amazon DynamoDB developer guide titled Error Handling with DynamoDB (<a href=\"https:\/\/docs.aws.amazon.com\/amazondynamodb\/latest\/developerguide\/Programming.Errors.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/amazondynamodb\/latest\/developerguide\/Programming.Errors.html<\/a>)<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-3\"><\/span>Domain: Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>35) <em>You are a solutions architect working for a financial services firm. Your firm requires a very low latency response time for requests via API Gateway and Lambda integration to your securities master database. The securities master database, housed in Aurora, contains data about all of the securities your firm trades. The data consists of the security ticker, the trading exchange, trading partner firm for the security, etc. As this securities data is relatively static, you can improve the performance of your API Gateway REST endpoint by using API Gateway caching. Your REST API calls for equity security request types and fixed income security request types to be cached separately. Which of the following options is the most efficient way to separate your cache responses via request type using API Gateway caching?\u00a0<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Payload compression<br \/>\n<strong>B.\u00a0<\/strong>Custom domain name<br \/>\n<strong>C.\u00a0<\/strong>API Stage<br \/>\n<strong>D.\u00a0<\/strong>Query string<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> D<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b><b>.<\/b>\u00a0Payload compression is used to compress and decompress the payload to and from your API Gateway. It is not used to separate cache responses.<br \/>\n<b>Option B is incorrect.<\/b>\u00a0Custom domain names are used to provide more readable URLs for the users of your AIPs. They are\u00a0not used to separate cache responses.<br \/>\n<b>Option C is incorrect.<\/b>\u00a0An API stage is used to create a name for your API deployments. They are used to deploy your API in an optimal way.<br \/>\n<b>Option D is correct.<\/b>\u00a0You can use your query string parameters as part of your cache key. This allows you to separate cache responses for equity requests from fixed income request responses.<\/p>\n<p><b>References:\u00a0<\/b>Please see the Amazon API Gateway developer guide titled Enabling API caching to enhance responsiveness\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/api-gateway-caching.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/api-gateway-caching.html<\/a>), the\u00a0Amazon API Gateway REST API Reference page titled Making HTTP Requests to Amazon API Gateway\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/api-reference\/making-http-requests\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/api-reference\/making-http-requests\/<\/a>), the Amazon API Gateway developer guide titled Enabling payload compression for an API\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/api-gateway-gzip-compression-decompression.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/api-gateway-gzip-compression-decompression.html<\/a>),\u00a0the Amazon API Gateway developer guide titled Setting up custom domain names for REST APIs\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/how-to-custom-domains.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/how-to-custom-domains.html<\/a>),\u00a0and the Amazon API Gateway developer guide titled Setting up a stage for a REST API\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/set-up-stages.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/set-up-stages.html<\/a>)<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Applications_and_Architectures\"><\/span>Domain: Design Secure Applications and Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>36) <em>You are a solutions architect working for a healthcare provider. Your company uses REST APIs to expose critical patient data to internal front-end systems used by doctors and nurses. The data for your patient information is stored in Aurora.<\/em><\/strong><br \/>\n<strong><em>How can you ensure that your patient data REST endpoint is only accessed by your authorized internal users?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Run your Aurora DB cluster on an EC2 instance in a private subnet<\/p>\n<p><strong>B.\u00a0<\/strong>Use a Gateway VPC Endpoint to make your REST endpoint private and only accessible from within your VPC<br \/>\n<strong>C.\u00a0<\/strong>Use IAM resource policies to restrict access to your REST APIs by adding the aws:SourceVpce condition to the API Gateway resource policy<br \/>\n<strong>D.\u00a0<\/strong>Use an Interface VPC Endpoint to make your REST endpoint private and only accessible from within your VPC and through your VPC endpoint<br \/>\n<strong>E.\u00a0<\/strong>Use IAM resource policies to restrict access to your REST APIs by adding the aws:SourceArn condition to the API Gateway resource policy<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> C &amp; D<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b><b>.\u00a0<\/b>Controlling access to your back-end database running on Aurora will not restrict access to your API Gateway REST endpoint. Access to your API Gateway REST endpoint must be controlled at the API Gateway and VPC level.<br \/>\n<b>Option B is incorrect.<\/b>\u00a0The Gateway VPC Endpoint is only used for the S3 and DynamoDB services.<br \/>\n<b>Option C is correct.<\/b>\u00a0You can make your REST APIs private by using the\u00a0aws:SourceVpce condition in your API Gateway resource policy to restrict access to only your VPC Endpoint.<br \/>\n<b>Option D is correct.<\/b>\u00a0Use a VPC Interface Endpoint to restrict access to your REST APIs to traffic that arrives via the VPC Endpoint.<br \/>\n<b>Option E is incorrect.\u00a0<\/b>The aws:SourceArn condition key is not used to restrict access to traffic that arrives via the VPC Endpoint.<\/p>\n<p><b>References:\u00a0<\/b>Please see the Amazon API Gateway developer guide titled Creating a private API in Amazon API Gateway\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/apigateway-private-apis.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/apigateway-private-apis.html<\/a>),\u00a0the Amazon API Gateway developer guide titled Example: Allow private API traffic based on source VPC or VPC endpoint\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/apigateway-resource-policies-examples.html#apigateway-resource-policies-source-vpc-example\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/apigateway-resource-policies-examples.html#apigateway-resource-policies-source-vpc-example<\/a>),\u00a0the Amazon Aurora user guide titled Amazon Aurora security\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Aurora.Overview.Security.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Aurora.Overview.Security.html<\/a>),\u00a0the Amazon Aurora user guide titled Amazon Aurora DB clusters\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Aurora.Overview.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Aurora.Overview.html<\/a>),\u00a0the Amazon Aurora user guide titled Aurora DB instance classes\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Concepts.DBInstanceClass.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Concepts.DBInstanceClass.html<\/a>),\u00a0the Amazon API Gateway developer guide titled AWS condition keys that can be used in API Gateway resource policies\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/apigateway-resource-policies-aws-condition-keys.html\" rel=\"noopener\" target=\"_blank\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/apigateway-resource-policies-aws-condition-keys.html<\/a>),\u00a0and the Amazon Virtual Private Cloud AWS PrivateLink page titled VPC endpoints\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/privatelink\/vpc-endpoints.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/vpc\/latest\/privatelink\/vpc-endpoints.html<\/a>)<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Resilient_Architectures-2\"><\/span>Domain: Design Resilient Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>37) You are a solutions architect working for a data analytics company that delivers analytics data to politicians that need the data to manage their campaigns. Political campaigns use your company\u2019s analytics data to decide on where to spend their campaign money to get the best results for the efforts. Your political campaign users access your analytics data through an Angular SPA via API Gateway REST endpoints. You need to manage the access and use of your analytics platform to ensure that the individual campaign data is separate. Specifically, you need to produce logs of all user requests and responses to those requests, including request payloads, response payloads, and error traces. Which type of AWS logging service should you use to achieve your goals?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Use CloudWatch access logging<br \/>\n<strong>B.\u00a0<\/strong>Use CloudWatch execution logging<br \/>\n<strong>C.\u00a0<\/strong>Use CloudTrail logging<br \/>\n<strong>D.\u00a0<\/strong>Use CloudTrail execution logging<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> B<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b><b>.\u00a0<\/b>CloudWatch access logging captures which resource accessed an API and the method used to access the API. It is not used for execution traces, such as capturing request and response payloads.<br \/>\n<b>Option B is correct.\u00a0<\/b>CloudWatch execution logging allows you to capture user\u00a0request and response payloads as well as error traces.<br \/>\n<b>Option C is incorrect.<\/b>\u00a0CloudTrail captures actions by users, roles, and AWS services. CloudTrail records all AWS account activity. CloudTrail does not capture error traces.<br \/>\n<b>Option D is incorrect.<\/b>\u00a0CloudTrail does not have a feature called execution logging.<\/p>\n<p><b>References:\u00a0<\/b>Please see the Amazon API Gateway developer guide titled Setting up CloudWatch logging for a REST API in API Gateway\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/set-up-logging.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/set-up-logging.html<\/a>),\u00a0and the AWS CloudTrail user guide titled How CloudTrail works\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/awscloudtrail\/latest\/userguide\/how-cloudtrail-works.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/awscloudtrail\/latest\/userguide\/how-cloudtrail-works.html<\/a>)<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Applications_and_Architectures-2\"><\/span>Domain: Design Secure Applications and Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>38) You are a solutions architect working for a social media company that provides a place for civil discussion of political and news-related events. Due to the ever-changing regulatory requirements and restrictions placed on social media apps that provide these services, you need to build your app in an environment where you can change your implementation instantly without updating code. You have chosen to build the REST API endpoints used by your social media app user interface code using Lambda. How can you securely configure your Lambda functions without updating code?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Pass environment variables to your Lambda function via the request header sent to your API Gateway methods<br \/>\n<strong>B.\u00a0<\/strong>Configure your Lambda functions to use key configuration<br \/>\n<strong>C.\u00a0<\/strong>Use encryption helpers<br \/>\n<strong>D.\u00a0<\/strong>Use Lambda layers<br \/>\n<strong>E.\u00a0<\/strong>Use Lambda aliases<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> B &amp; C<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b><b>.<\/b>\u00a0Sending environment variables to your Lambda function as request parameters would expose the environment variables as plain text. This is not a secure approach.<br \/>\n<b>Option B is correct.\u00a0<\/b>Lambda key configuration allows you to have your Lambda functions use an encryption key. You create the key in AWS KMS. The key is used to encrypt the environment variables that you can use to change your function without deploying any code.<br \/>\n<b>Option C is correct.<\/b>\u00a0Encryption helpers make your lambda function more secure by allowing you to encrypt your environment variables before they are sent to Lambda.<br \/>\n<b>Option D is incorrect.\u00a0<\/b>Lambda layers are used to package common code such as libraries, configuration files, or custom runtime images. Layers will not give you the same flexibility as environment variables for use in managing change without deploying any code.<br \/>\n<b>Option E is incorrect.<\/b>\u00a0Lambda aliases are used to refer to a specific version of your Lambda function. You could switch between many versions of your Lambda function, but you would have to deploy new code to create a different version of your Lambda function.<\/p>\n<p><b>References:\u00a0<\/b>Please see the AWS Lambda developer guide titled Data protection in AWS Lambda\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/security-dataprotection.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/security-dataprotection.html<\/a>),\u00a0the AWS Lambda developer guide titled Lambda concepts\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/gettingstarted-concepts.html#gettingstarted-concepts-layer\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/gettingstarted-concepts.html#gettingstarted-concepts-layer<\/a>),\u00a0the AWS Lambda developer guide titled Lambda function aliases\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/configuration-aliases.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/configuration-aliases.html<\/a>),\u00a0and the AWS Lambda developer guide titled Using AWS Lambda environment variables\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/configuration-envvars.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/configuration-envvars.html<\/a>)<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Applications_and_Architectures-3\"><\/span>Domain: Design Secure Applications and Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>39) You are a solutions architect working for a media company that produces stock images and videos for sale via a mobile app and website. Your app and website allow users to gain access only to stock content they have purchased. Your content is stored in S3 buckets. You need to restrict access to multiple files that your users have purchased. Also, due to the nature of the stock content (purchasable by multiple users), you don\u2019t want to change the URLs of each stock item.<\/em><\/strong><br \/>\n<strong><em>Which access control option best fits your scenario?\u00a0<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Use CloudFront signed URLs<br \/>\n<strong>B.\u00a0<\/strong>Use S3 Presigned URLs<br \/>\n<strong>C.\u00a0<\/strong>Use CloudFront Signed Cookies<br \/>\n<strong>D.\u00a0<\/strong>Use S3 Signed Cookies<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> C<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect<\/b><b>.\u00a0<\/b>CloudFront signed URLs allow you to restrict access to individual files. It\u00a0 requires you to change your content URLs for each customer access.<br \/>\n<b>Option B is incorrect.<\/b>\u00a0S3 Presigned URLs\u00a0require you to change your content URLs. The presigned URL expires after its defined expiration date.<br \/>\n<b>Option C is correct<\/b>.\u00a0CloudFront Signed Cookies allow you to control access to multiple content files and you don\u2019t have to change your URL for each customer access.<br \/>\n<b>Option D is incorrect.<\/b>\u00a0There is no S3 Signed Cookies feature.<\/p>\n<p><b>References:\u00a0<\/b>Please see the Amazon CloudFront developer guide titled Using signed cookies\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/private-content-signed-cookies.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/private-content-signed-cookies.html<\/a>),\u00a0the Amazon Simple Storage Service user guide titled Sharing an object with a presigned URL\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/ShareObjectPreSignedURL.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/ShareObjectPreSignedURL.html<\/a>),\u00a0the Amazon Simple Storage Service user guide titled Using presigned URLs\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/using-presigned-url.html#PresignedUrlUploadObject-LimitCapabilities\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/using-presigned-url.html#PresignedUrlUploadObject-LimitCapabilities<\/a>),\u00a0and the Amazon CloudFront developer guide titled Choosing between signed URLs and signed cookies\u00a0(<a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/private-content-choosing-signed-urls-cookies.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/private-content-choosing-signed-urls-cookies.html<\/a>)<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-4\"><\/span>Domain :\u00a0Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>40) A company is developing a web application to be hosted in AWS. This application needs a data store for session data.\u00a0<\/em><\/strong><br \/>\n<strong><em>As an AWS Solution Architect, what would you recommend as an ideal option to store session data?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>CloudWatch<br \/>\n<strong>B.\u00a0<\/strong>DynamoDB<br \/>\n<strong>C.\u00a0<\/strong>Elastic Load Balancing<br \/>\n<strong>D.\u00a0<\/strong>ElastiCache<br \/>\n<strong>E.\u00a0<\/strong>Storage Gateway<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> B &amp; D<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>DynamoDB and ElastiCache are perfect options for storing session data.<\/p>\n<p>AWS Documentation mentions the following on Amazon DynamoDB:<\/p>\n<p>Amazon DynamoDB is a fast and flexible NoSQL database service for all applications that need consistent, single-digit millisecond latency at any scale. It is a fully managed cloud database and supports both document and key-value store models. Its flexible data model, reliable performance, and automatic scaling of throughput capacity make it a great fit for mobile, web, gaming, ad tech, IoT, and many other applications.<\/p>\n<p>For more information on AWS DynamoDB, please visit the following URL:\u00a0<a href=\"https:\/\/aws.amazon.com\/dynamodb\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/dynamodb\/<\/a><\/p>\n<p>AWS Documentation mentions the following on AWS ElastiCache:<\/p>\n<p>AWS ElastiCache is a web service that makes it easy to set up, manage, and scale a distributed in-memory data store or cache environment in the cloud. It provides a high-performance, scalable, and cost-effective caching solution while removing the complexity associated with the deployment and management of a distributed cache environment.<\/p>\n<p>For more information on AWS Elasticache, please visit the following URL:\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/AmazonElastiCache\/latest\/UserGuide\/WhatIs.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonElastiCache\/latest\/UserGuide\/WhatIs.html<\/a><\/p>\n<p><b>Option A is incorrect.\u00a0<\/b>AWS CloudWatch offers cloud monitoring services for the customers of AWS resources.<br \/>\n<b>Option C is incorrect.\u00a0<\/b>AWS Elastic Load Balancing automatically distributes incoming application traffic across multiple targets.<br \/>\n<b>Option E is incorrect.<\/b>\u00a0AWS Storage Gateway is a hybrid storage service that enables your on-premises applications to use AWS cloud storage seamlessly.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-5\"><\/span>Domain :\u00a0Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>41) You are creating a new architecture for a financial firm. The architecture consists of some EC2 instances with the same type and size (M5.large). In this architecture, all the EC2 mostly communicate with each other. Business people have asked you to create this architecture keeping in mind low latency as a priority. Which placement group option could you suggest for the instances?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Partition Placement Group<br \/>\n<strong>B.\u00a0<\/strong>Clustered Placement Group<br \/>\n<strong>C.\u00a0<\/strong>Spread Placement Group<br \/>\n<strong>D.\u00a0<\/strong>Enhanced Networking Placement Group<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> B<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect.<\/b>\u00a0Partition Placement Groups distribute the instances in different partitions. The partitions are placed in the same AZ, but do not share the same rack. This type of placement group does not provide low latency throughput to the instances.<br \/>\n<b>Option B is CORRECT.\u00a0<\/b>Clustered Placement Group places all the instances on the same rack. This placement group option provides 10 Gbps connectivity between instances ( Internet connectivity in the instances has a maximum of 5 Gbps). This option of placement group is perfect for the workload that needs low latency.<br \/>\n<b>Option C is incorrect.<\/b>\u00a0Placement Groups place all the instances in different racks in the same AZ. These types of placement groups do not provide low latency throughput to the instances.<br \/>\n<b>Option D is incorrect.<\/b>\u00a0Enhanced Networking Placement Group does not exist.<\/p>\n<p><b>Reference:\u00a0<\/b><a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/placement-groups.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/placement-groups.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-6\"><\/span>Domain : Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>42) Your team is developing a high-performance computing (HPC) application. The application resolves complex, compute-intensive problems and needs a high-performance and low-latency Lustre file system. You need to configure this file system in AWS at a low cost. Which method is the most suitable?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Create a Lustre file system through Amazon FSx<br \/>\n<strong>B.\u00a0<\/strong>Launch a high performance Lustre file system in Amazon EBS<br \/>\n<strong>C.\u00a0<\/strong>Create a high-speed volume cluster in EC2 placement group<br \/>\n<strong>D.\u00a0<\/strong>Launch the Lustre file system from AWS Marketplace<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> A<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>The Lustre file system is an open-source, parallel file system that can be used for HPC applications. Refer to<a href=\"http:\/\/lustre.org\/\" target=\"_blank\" rel=\"nofollow noopener\">\u00a0http:\/\/lustre.org\/<\/a>\u00a0for its introduction. In Amazon FSx, users can quickly launch a Lustre file system at a low cost.<\/p>\n<p><b>Option\u200b \u200bA \u200bis\u200b CORRECT<\/b>:\u200b Amazon FSx supports Lustre file systems, and users pay for only the resources they use.<br \/>\n<b>Option\u200b \u200bB \u200bis\u200b \u200bincorrect<\/b>:\u200b Although users may be able to configure a Lustre file system through EBS, it needs lots of extra configurations. Option A is more straightforward.<br \/>\n<b>Option\u200b \u200bC \u200bis\u200b \u200bincorrect<\/b>:\u200b Because the EC2 placement group does not support a Lustre file system.<br \/>\n<b>Option\u200b \u200bD \u200bis\u200b \u200bincorrect<\/b>:\u200b Because products in AWS Marketplace are not cost-effective. For Amazon FSx, there are no minimum fees or set-up charges. Check its pricing in<\/p>\n<p><b>Reference:\u00a0<\/b><a href=\"https:\/\/aws.amazon.com\/fsx\/lustre\/pricing\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/fsx\/lustre\/pricing\/<\/a>.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-7\"><\/span>Domain :\u00a0Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>43) A company has an application hosted in AWS. This application consists of EC2 Instances that sit behind an ELB. The following are the requirements from an administrative perspective:<\/em><\/strong><br \/>\n<strong><em>a) Ensure that notifications are sent when the read requests go beyond 1000 requests per minute.<\/em><\/strong><br \/>\n<strong><em>b) Ensure that notifications are sent when the latency goes beyond 10 seconds.<\/em><\/strong><br \/>\n<strong><em>c)\u00a0 Monitor all AWS API request activities on the AWS resources.<\/em><\/strong><br \/>\n<strong><em>Which of the following can be used to satisfy these requirements?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Use CloudTrail to monitor the API Activity<br \/>\n<strong>B.\u00a0<\/strong>Use CloudWatch Logs to monitor the API Activity<br \/>\n<strong>C.\u00a0<\/strong>Use CloudWatch Metrics for the metrics that need to be monitored as per the requirement and set up an alarm activity to send out notifications when the metric reaches the set threshold limit<br \/>\n<strong>D.\u00a0<\/strong>Use custom log software to monitor the latency and read requests to the ELB<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> A &amp; C<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is correct<\/b>. CloudTrail is a web service that records AWS API calls for all the resources in your AWS account. It also delivers log files to an Amazon S3 bucket. The recorded information includes the identity of the user, the start time of the AWS API call, the source IP address, the request parameters, and the response elements returned by the service.<br \/>\n<b>Option B is incorrect<\/b>\u00a0because CloudWatch Logs can be used to monitor log files from other services. CloudWatch Logs and CloudWatch are different.<\/p>\n<p>Amazon CloudWatch Logs are used to monitor, store, and access your\u00a0<b>log files<\/b>\u00a0from Amazon Elastic Compute Cloud (Amazon EC2) instances, AWS CloudTrail, Route 53, and other sources. CloudWatch Logs reports the data to a CloudWatch metric.<\/p>\n<p>Rather you can monitor\u00a0<b>Amazon EC2 API<\/b>\u00a0requests using Amazon CloudWatch.<\/p>\n<p><b>Option C is correct.<\/b>\u00a0Use Cloudwatch Metrics for the metrics that need to be monitored as per the requirement. Set up an alarm activity to send out notifications when the metric reaches the set threshold limit.<br \/>\n<b>Option D is incorrect<\/b>\u00a0because there is no need to use custom log software as you can set up CloudWatch alarms based on CloudWatch Metrics.<\/p>\n<p><b>References:\u00a0<\/b><a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/logs\/WhatIsCloudWatchLogs.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/logs\/WhatIsCloudWatchLogs.html<\/a>,\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/awscloudtrail\/latest\/APIReference\/Welcome.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/awscloudtrail\/latest\/APIReference\/Welcome.html<\/a>,\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/classic\/elb-cloudwatch-metrics.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/classic\/elb-cloudwatch-metrics.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Resilient_Architectures-3\"><\/span>Domain :\u00a0Design Resilient Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>44) You are creating several EC2 instances for a new application. The instances need to communicate with each other. For a better performance of the application, both low network latency and high network throughput are required for the EC2 instances. All instances should be launched in a single availability zone. How would you configure this?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Launch all EC2 instances in a placement group using a Cluster placement strategy<br \/>\n<strong>B.\u00a0<\/strong>Auto assign a public IP when launching the EC2 instances<br \/>\n<strong>C.\u00a0<\/strong>Launch EC2 instances in an EC2 placement group and select the Spread placement strategy<br \/>\n<strong>D.\u00a0<\/strong>When launching the EC2 instances, select an instance type that supports enhanced networking<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> A<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>The Cluster placement strategy helps to achieve a low-latency and high throughput network.<\/p>\n<p><b>Option\u200b \u200bA \u200bis\u200b CORRECT<\/b>:\u200b The Cluster placement strategy can improve the network performance among EC2 instances. The strategy can be selected when creating a placement group.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84126 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17.png\" sizes=\"(max-width: 1116px) 100vw, 1116px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17.png 1116w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17-300x149.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17-1024x507.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17-768x381.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17-848x420.png 848w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17-640x317.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17-681x337.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa17-150x74.png 150w\" alt=\"\" width=\"1116\" height=\"553\" \/><b>Option\u200b \u200bB \u200bis\u200b \u200bincorrect<\/b>:\u200b Because the public IP cannot improve the network performance.<br \/>\n<b>Option\u200b \u200bC \u200bis\u200b \u200bincorrect<\/b>:\u200b The Spread placement strategy is recommended when several critical instances should be kept separate from each other. This strategy should not be used in this scenario.<br \/>\n<b>Option\u200b \u200bD \u200bis\u200b \u200bincorrect<\/b>:\u200b The description in the option is inaccurate. The correct method is creating a placement group with a suitable placement strategy.<\/p>\n<p><b>Reference:\u00a0<\/b><a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/placement-groups.html#placement-groups-limitations-partition\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/placement-groups.html#placement-groups-limitations-partition<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-8\"><\/span>Domain :\u00a0Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>45) You are a solutions architect working for a regional bank that is moving its data center to the AWS cloud. You need to migrate your data center storage to a new S3 and EFS data store in AWS. Since your data includes Personally Identifiable Information (PII), you have been asked to transfer data from your data center to AWS without traveling over the public internet. Which option gives you the most efficient solution that meets your requirements?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Migrate your on-prem data to AWS using the DataSync agent using NAT Gateway<br \/>\n<strong>B.\u00a0<\/strong>Create a public VPC endpoint, and configure the DataSync agent to communicate to the DataSync public service endpoints via the VPC endpoint using Direct Connect<br \/>\n<strong>C.\u00a0<\/strong>Migrate your on-prem data to AWS using the DataSync agent using Internet Gateway<br \/>\n<strong>D.\u00a0<\/strong>Create a private VPC endpoint, and configure the DataSync agent to communicate to the DataSync private service endpoints via the VPC endpoint using VPN<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> D<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>AWs documentation mentions the following:<\/p>\n<p>While configuring this setup,\u00a0 you\u2019ll place a private VPC endpoint in your VPC that connects to the DataSync service. This endpoint will be used for communication between your agent and the DataSync service.<\/p>\n<p>In addition, for each transfer task, four elastic network interfaces (ENIs) will automatically get placed in your VPC. DataSync agent will send traffic through these ENIs in order to transfer data from your on-premises shares into AWS.<\/p>\n<p><b>\u201c<\/b>When you use DataSync with a private VPC endpoint, the DataSync agent can communicate directly with AWS without the need to cross the public internet.<b>\u201c<\/b><\/p>\n<p><b>Option A is incorrect.<\/b>\u00a0To ensure your data isn\u2019t sent over the public internet, you need to use a VPC endpoint to connect the DataSync agent to the DataSync service endpoints.<br \/>\n<b>Option B is incorrect.\u00a0<\/b>You need to use a private VPC endpoint, not the public VPC endpoint to keep your data away from traveling over the public internet.<br \/>\n<b>Option C is incorrect.<\/b>\u00a0Using the Internet Gateway by definition sends your traffic over the public internet, which is the solution as per the requirement.<br \/>\n<b>Option D is correct.<\/b>\u00a0Using a private VPC endpoint and the DataSync private service endpoints to communicate over your VPN will give you the non-internet transfer you require.<\/p>\n<p><b>References:\u00a0<\/b>Please see the AWS DataSync user guide titled\u00a0Using AWS DataSync in a virtual private cloud (<a href=\"https:\/\/docs.aws.amazon.com\/datasync\/latest\/userguide\/datasync-in-vpc.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/datasync\/latest\/userguide\/datasync-in-vpc.html<\/a>), and the AWS Storage Blog titled Transferring files from on-premises to AWS and back without leaving your VPC using AWS DataSync (<a href=\"https:\/\/aws.amazon.com\/blogs\/storage\/transferring-files-from-on-premises-to-aws-and-back-without-leaving-your-vpc-using-aws-datasync\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/blogs\/storage\/transferring-files-from-on-premises-to-aws-and-back-without-leaving-your-vpc-using-aws-datasync\/<\/a>)<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Resilient_Architectures-4\"><\/span>Domain :\u00a0Design Resilient Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>46) You currently have your EC2 instances running in multiple availability zones in an AWS region. You need to create NAT gateways for your private instances to access internet. How would you set up the NAT gateways so that they are highly available?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Create two NAT Gateways and place them behind an ELB<br \/>\n<strong>B.\u00a0<\/strong>Create a NAT Gateway in each Availability Zone<br \/>\n<strong>C.\u00a0<\/strong>Create a NAT Gateway in another region<br \/>\n<strong>D.\u00a0<\/strong>Use Auto Scaling groups to scale the NAT Gateways<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> B<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option A is incorrect\u00a0<\/b>because you cannot create such configurations.<br \/>\n<b>Option B is CORRECT<\/b>\u00a0because this is recommended by AWS. With this option, if a NAT gateway\u2019s Availability Zone is down, resources in other Availability Zones can still access internet.<br \/>\n<b>Option C is incorrect<\/b>\u00a0because the EC2 instances are in one AWS region so there is no need to create a NAT Gateway in another region.<br \/>\n<b>Option D is incorrect<\/b>\u00a0because you cannot create an Auto Scaling group for NAT Gateways.<\/p>\n<p>For more information on the NAT Gateway, please refer to the below URL:<a href=\"https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/vpc-nat-gateway.html\" target=\"_blank\" rel=\"nofollow noopener\">\u00a0https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/vpc-nat-gateway.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Architectures-2\"><\/span>Domain :\u00a0Design Secure Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>47) Your company has designed an app and requires it to store data in DynamoDB. The company has registered the app with identity providers for users to sign-in using third-parties like Google and Facebook. What must be in place such that the app can obtain temporary credentials to access DynamoDB?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Multi-factor authentication must be used to access DynamoDB<br \/>\n<strong>B.\u00a0<\/strong>AWS CloudTrail needs to be enabled to audit usage<br \/>\n<strong>C.\u00a0<\/strong>An IAM role allowing the app to have access to DynamoDB<br \/>\n<strong>D.\u00a0<\/strong>The user must additionally log into the AWS console to gain database access<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> C<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option C is correct.<\/b>\u00a0The user will have to assume a role that has the permissions to interact with DynamoDB.<br \/>\n<b>Option A is incorrect.<\/b>\u00a0Multi-factor authentication is available but not required.<br \/>\n<b>Option B is incorrect.<\/b>\u00a0CloudTrail is recommended for auditing but is not required.<br \/>\n<b>Option D is incorrect.\u00a0<\/b>A second log-in event to the management console is not required.<\/p>\n<p><b>References<\/b>:\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/cognito\/latest\/developerguide\/cognito-user-pools-identity-federation.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/cognito\/latest\/developerguide\/cognito-user-pools-identity-federation.html<\/a>,\u00a0h<a href=\"https:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/id_roles_providers_oidc.html\" target=\"_blank\" rel=\"nofollow noopener\">ttps:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/id_roles_providers_oidc.html<\/a>,\u00a0<a href=\"https:\/\/aws.amazon.com\/articles\/web-identity-federation-with-mobile-applications\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/articles\/web-identity-federation-with-mobile-applications\/<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-9\"><\/span>Domain :\u00a0Design High-Performing Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>48) A company has a lot of data hosted on their On-premises infrastructure. Running out of storage space, the company wants a quick win solution using AWS. There should be low latency for the frequently accessed data. Which of the following would allow the easy extension of their data infrastructure to AWS?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>The company could start using Gateway Cached Volumes<br \/>\n<strong>B.\u00a0<\/strong>The company could start using Gateway Stored Volumes<br \/>\n<strong>C.\u00a0<\/strong>The company could start using the Amazon S3 Glacier Deep Archive storage class<br \/>\n<strong>D.\u00a0<\/strong>The company could start using Amazon S3 Glacier<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> A<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>Volume Gateways and Cached Volumes can be used to start storing data in S3.<\/p>\n<p>AWS Documentation mentions the following:<\/p>\n<p>You store your data in Amazon Simple Storage Service (Amazon S3) and retain a copy of frequently accessed data subsets locally. Cached volumes offer substantial cost savings on primary storage and minimize the need to scale your storage on-premises. You also retain low-latency access to your frequently accessed data.<\/p>\n<p>This is the difference between Cached and stored volumes:<\/p>\n<ul>\n<li aria-level=\"1\"><b>Cached volumes<\/b>\u00a0\u2013 You store your data in S3 and retain a copy of frequently accessed data subsets locally. Cached volumes offer substantial cost savings on primary storage and \u201cminimize the need to scale your storage on-premises. You also retain low-latency access to your frequently accessed data.\u201d<\/li>\n<li aria-level=\"1\"><b>Stored volumes<\/b>\u00a0\u2013 If you need low-latency access to your entire data set, first configure your on-premises gateway to store all your data locally. Then asynchronously back up point-in-time snapshots of this data to Amazon S3. \u201cThis configuration provides durable and inexpensive off-site backups that you can recover to your local data center or Amazon EC2.\u201d For example, if you need replacement capacity for disaster recovery, you can recover the backups to Amazon EC2.<\/li>\n<\/ul>\n<p>As described in the answer: The company wants a quick win solution to store data with AWS, avoiding scaling the on-premise setup rather than backing up the data.<\/p>\n<p>In the question, they mentioned that\u00a0<b>\u201cA company has a lot of data hosted on their On-premises infrastructure.\u201d\u00a0<\/b>From On-premises to cloud infrastructure, you can use AWS storage gateways.<\/p>\n<p><b>Options C and D are incorrect<\/b>\u00a0as they are talking about the S3 storage classes, but the requirement is (How) to transfer or migrate your data from On-premises to Cloud infrastructure.<\/p>\n<p><b>Reference:\u00a0<\/b><a href=\"https:\/\/docs.aws.amazon.com\/storagegateway\/latest\/userguide\/WhatIsStorageGateway.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/storagegateway\/latest\/userguide\/WhatIsStorageGateway.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Architectures-3\"><\/span>Domain :\u00a0Design Secure Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>49) A start-up firm has a corporate office in New York &amp; a regional office in Washington &amp; Chicago. These offices are interconnected over Internet links. Recently they have migrated a few application servers to EC2 instance launched in the AWS US-east-1 region. The Developer Team located at the corporate office requires secure access to these servers for initial testing &amp; performance checks before go-live of the new application. Since the go-live date is approaching soon, the IT team is looking for quick connectivity to be established. As an AWS consultant, which link option will you suggest as a cost-effective &amp; quick way to establish secure connectivity from on-premise to servers launched in AWS?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Use AWS Direct Connect to establish IPSEC connectivity from On-premise to VGW<br \/>\n<strong>B.\u00a0<\/strong>Install a third party software VPN appliance from AWS Marketplace in the EC2 instance to create a VPN connection to the on-premises network<br \/>\n<strong>C.\u00a0<\/strong>Use Hardware VPN over AWS Direct Connect to establish IPSEC connectivity from On-premise to VGW<br \/>\n<strong>D.\u00a0<\/strong>Use AWS Site-to-Site VPN to establish IPSEC VPN connectivity between VPC and the on-premises network<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> D<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>Using AWS VPN is the fastest &amp; cost-effective way of establishing IPSEC connectivity from on-premise to AWS. IT teams can quickly set up a VPN connection with VGW in the US-east-1 region so that internal users can seamlessly connect to resources hosted on AWS.<\/p>\n<p><b>Option A is incorrect<\/b>\u00a0as AWS Direct Connect does not provide IPSEC connectivity. It is not a quick way to establish connectivity.<br \/>\n<b>Option B is incorrect<\/b>\u00a0as you need to look for a third party solution from AWS Marketplace. And it may not be as cost-efficient as option D.<br \/>\n<b>Option C is incorrect<\/b>\u00a0as although this will provide a high performance secure IPSEC connectivity from On-premise to AWS, it is not a quick way to establish connectivity. It may take weeks or months to configure the AWS Direct Connect connection. AWS Direct Connect is also not cost-effective.<\/p>\n<p>For more information on using AWS Direct Connect &amp; VPN, refer to the following URL:\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-vpc-connectivity-options\/network-to-amazon-vpc-connectivity-options.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-vpc-connectivity-options\/network-to-amazon-vpc-connectivity-options.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-3\"><\/span>Domain :\u00a0Design Cost-Optimized Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>50) A Media firm is saving all its old videos in S3 Glacier Deep Archive. Due to the shortage of new video footage, the channel has decided to reuse all these old videos. Since these are old videos, the channel is not sure of their popularity &amp; response from users. Channel Head wants to make sure that these huge size files do not shoot up their budget. For this, as an AWS consultant, you advise them to use the S3 intelligent storage class. The Operations Team is concerned about moving these files to the S3 Intelligent-Tiering storage class. Which of the following actions can be taken to move objects in Amazon S3 Glacier Deep Archive to the S3 Intelligent-Tiering storage class?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Use Amazon S3 Console to copy these objects from S3 Glacier Deep Archive to the required S3 Intelligent-Tiering storage class<br \/>\n<strong>B.\u00a0<\/strong>Use Amazon S3 Glacier Console to restore objects from S3 Glacier Deep Archive &amp; then copy these objects to the required S3 Intelligent-Tiering storage class<br \/>\n<strong>C.\u00a0<\/strong>Use Amazon S3 console to restore objects from S3 Glacier Deep Archive &amp; then copy these objects to the required S3 Intelligent-Tiering storage class<br \/>\n<strong>D.\u00a0<\/strong>Use the Amazon S3 Glacier console to copy these objects to the required S3 Intelligent-Tiering storage class<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> C<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>To move objects from Glacier Deep Archive to different storage classes, first, need to restore them to original locations using the Amazon S3 console &amp; then use the lifecycle policy to move objects to the required S3 Intelligent-Tiering storage class.<\/p>\n<p><b>Options A &amp; D are incorrect<\/b>\u00a0as Objects in Glacier Deep Archive cannot be directly moved to another storage class. These need to be restored first &amp; then copied to the desired storage class.<br \/>\n<b>Option B is incorrect<\/b>\u00a0as the Amazon S3 Glacier console can be used to access the vaults and objects in them. But it cannot be used to restore the objects.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-84127 td-animation-stack-type0-2\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23.jpg\" sizes=\"(max-width: 856px) 100vw, 856px\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23.jpg 856w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-300x223.jpg 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-768x571.jpg 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-565x420.jpg 565w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-80x60.jpg 80w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-100x75.jpg 100w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-180x135.jpg 180w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-238x178.jpg 238w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-640x476.jpg 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-681x506.jpg 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2022\/08\/csa23-150x111.jpg 150w\" alt=\"\" width=\"856\" height=\"636\" \/><\/p>\n<p>For more information on moving objects between S3 storage classes, refer to the following URL:\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/dev\/lifecycle-transition-general-considerations.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/dev\/lifecycle-transition-general-considerations.html<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-4\"><\/span>Domain :\u00a0Design Cost-Optimized Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>51) You are building an automated transcription service where Amazon EC2 worker instances process an uploaded audio file and generate a text file. You must store both of these files in the same durable storage until the text file is retrieved. Customers fetch the text files frequently. You do not know about the storage capacity requirements. Which storage option would be both cost-efficient and highly available in this situation?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Multiple Amazon EBS Volume with snapshots<br \/>\n<strong>B.\u00a0<\/strong>A single Amazon Glacier Vault<br \/>\n<strong>C.\u00a0<\/strong>A single Amazon S3 bucket<br \/>\n<strong>D.\u00a0<\/strong>Multiple instance stores<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> C<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p>Amazon S3 is the perfect storage solution for audio and text files. It is a highly available and durable storage device.<\/p>\n<p><b>Option A is incorrect\u00a0<\/b>because storing files in EBS is not cost-efficient.<br \/>\n<b>Option B is incorrect<\/b>\u00a0because files need to be retrieved frequently so Glacier is not suitable.<br \/>\n<b>Option D is incorrect\u00a0<\/b>because the instance store is not highly available compared with S3.<\/p>\n<p>For more information on Amazon S3, please visit the following URL:\u00a0<a href=\"https:\/\/aws.amazon.com\/s3\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/s3\/<\/a><\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-5\"><\/span>Domain :\u00a0Design Cost-Optimized Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>52) A large amount of structured data is stored in Amazon S3 using the JSON format. You need to use a service to analyze the S3 data directly with standard SQL. In the meantime, the data should be easily visualized through data dashboards. Which of the following services is the most appropriate?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Amazon Athena and Amazon QuickSight<br \/>\n<strong>B.\u00a0<\/strong>AWS Glue and Amazon Athena<br \/>\n<strong>C.\u00a0<\/strong>AWS Glue and Amazon QuickSight<br \/>\n<strong>D.\u00a0<\/strong>Amazon Kinesis Data Stream and Amazon QuickSight<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> A<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Option\u200b \u200bA \u200bis\u200b CORRECT<\/b>\u00a0because Amazon Athena is the most suitable to run ad-hoc queries to analyze data in S3. Amazon Athena is serverless, and you are charged for the amount of scanned data. Besides, Athena can integrate with Amazon QuickSight that visualizes the data via dashboards.<br \/>\n<b>Option\u200b \u200bB \u200bis\u200b \u200bincorrect<\/b>\u00a0because AWS Glue is an ETL (extract, transform, and load) service that organizes, cleanses, validates, and formats data in a data warehouse. This service is not required in this scenario.<br \/>\n<b>Option\u200b \u200bC \u200bis\u200b \u200bincorrect<\/b>\u00a0because it is the same as Option B. AWS Glue is not required.<br \/>\n<b>Option\u200b \u200bD \u200bis\u200b \u200bincorrect<\/b>\u00a0because, with Amazon Kinesis Data Stream, users cannot perform queries for the S3 data through standard SQL.<\/p>\n<p><b>References:\u00a0<\/b><a href=\"https:\/\/aws.amazon.com\/athena\/pricing\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/athena\/pricing\/<\/a>.\u00a0<a href=\"https:\/\/docs.aws.amazon.com\/quicksight\/latest\/user\/create-a-data-set-athena.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.aws.amazon.com\/quicksight\/latest\/user\/create-a-data-set-athena.html<\/a>.<\/p>\n<hr \/>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-6\"><\/span>Domain :\u00a0Design Cost-Optimized Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>53) To manage a large number of AWS accounts in a better way, you create a new AWS Organization and invite multiple accounts. You only enable the \u201cConsolidated billing\u201d out of the two feature sets (All features and Consolidated billing) available in the AWS Organizations. Which of the following is the primary benefit of using Consolidated billing feature?<\/em><\/strong><\/p>\n<p><strong>A.\u00a0<\/strong>Apply SCPs to restrict the services that IAM users can access<br \/>\n<strong>B.\u00a0<\/strong>Configure tag policies to maintain consistent tags for resources in the organization\u2019s accounts<br \/>\n<strong>C.\u00a0<\/strong>Configure a policy to prevent IAM users in the organization from disabling AWS CloudTrail<br \/>\n<strong>D.\u00a0<\/strong>Combine the usage across all accounts to share the volume pricing discounts<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><strong> D<\/strong><\/span><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><b>Available feature sets in AWS Organizations:<\/b><\/p>\n<ul>\n<li aria-level=\"1\"><b>All features<\/b>\u00a0\u2013 The default feature set that is available to AWS Organizations. It includes all the functionality of consolidated billing, plus advanced features that give you more control over accounts in your organization.<\/li>\n<li aria-level=\"1\"><b>Consolidated billing<\/b>\u00a0\u2013 This feature set provides shared billing functionality but does\u00a0<i>not<\/i>\u00a0include the more advanced features of AWS Organizations.<\/li>\n<\/ul>\n<p><b>Option\u200b \u200bA \u200bis\u200b \u200bincorrect<\/b>:\u200b Because SCP is part of the advanced features which belong to \u201cAll features\u201d.<br \/>\n<b>Option\u200b \u200bB \u200bis\u200b \u200bincorrect<\/b>:\u200b Because tag policies can be applied under the feature set of \u201cAll features\u201d.<br \/>\n<b>Option\u200b \u200bC \u200bis\u200b \u200bincorrect<\/b>:\u200b This is implemented using SCP which is not supported in \u201cConsolidated billing\u201d.<br \/>\n<b>Option\u200b \u200bD \u200bis\u200b CORRECT<\/b>:\u200b \u2018Consolidated billing\u2019 feature set provides shared billing functionality.<\/p>\n<p>For the differences between \u201cConsolidated billing\u201d and \u201cAll features\u201d, refer to the reference below:<a href=\"https:\/\/docs.aws.amazon.com\/organizations\/latest\/userguide\/orgs_getting-started_concepts.html#feature-set-cb-only\" target=\"_blank\" rel=\"nofollow noopener\">\u00a0https:\/\/docs.aws.amazon.com\/organizations\/latest\/userguide\/orgs_getting-started_concepts.html#feature-set-cb-only<\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-7\"><\/span>Domain :\u00a0Design Cost-Optimized Architectures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>54)<\/strong><\/em> <em><strong>A large manufacturing company is looking to track IoT sensor data collected from thousands of equipment across multiple factory units. This is extremely high-volume traffic that needs to be collected in real-time and should be efficiently visualized. The company is looking for a suitable database in the AWS cloud for storing these sensor data.<\/strong><\/em><\/p>\n<p><em><strong>Which of the following cost-effective databases can be selected for this purpose?<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\"><strong>A.<\/strong> Send sensor data to Amazon RDS (Relational Database Service) using Amazon Kinesis and visualized data using Amazon QuickSight.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>B.<\/strong> Send sensor data to Amazon Neptune using Amazon Kinesis and visualized data using Amazon QuickSight.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>C.<\/strong> Send sensor data to Amazon DynamoDB using Amazon Kinesis and visualized data using Amazon QuickSight.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>D.<\/strong> Send sensor data to Amazon Timestream using Amazon Kinesis and visualized data using Amazon QuickSight.<\/span><\/p>\n<p><strong>Answer: D<\/strong><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Explanation<\/strong><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Timestream is the most suitable serverless time series database for IoT and operational services. It can store trillions of events from these sources. Storing this time series data in Amazon Timestream ensures faster processing and is more cost-effective than storing such data in a regular relational database.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Timestream is integrated with data collection services in AWS such as Amazon Kinesis, and Amazon MSK, and open-source tools such as Telegraf. Data stored in Amazon Timestream can be further visualized using Amazon QuickSight. It can also be integrated with Amazon Sagemaker for machine learning.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A<\/strong> is <strong>incorrect<\/strong> as Amazon RDS <\/span><span style=\"font-weight: 400;\">(Relational Database Service) is best suited for traditional applications such as CRM (customer relationship management) and ERP (Enterprise resource planning). Using Amazon RDS for storing IoT sensor data will be costly and slow as compared to the Amazon Timestream.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B<\/strong> is <strong>incorrect<\/strong> as Amazon Neptune is suitable for creating graph databases querying large amounts of data. <\/span><span style=\"font-weight: 400;\">Amazon Neptune is not a suitable option for storing IoT sensor data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C<\/strong> is <strong>incorrect<\/strong> as Amazon DynamoDB is suitable for web applications supporting key-value NoSQL databases.<\/span><span style=\"font-weight: 400;\"> Using Amazon DynamoDB for storing IoT sensor data will be costly.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Amazon Timestream, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/products\/databases\/\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/products\/databases\/<\/span><\/a><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/timestream\/features\/?nc=sn&amp;loc=2\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/timestream\/features\/?nc=sn&amp;loc=2<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Latest_Updated_Questions_2023\"><\/span><span class=\"ui-provider gr b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\"><strong>Latest Updated Questions 2023<\/strong> <\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-10\"><\/span><b>Domain: Design High-Performing Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>55) A start-up firm is using a JSON-based database for content management. They are planning to rehost this database to AWS Cloud from on-premises. For this, they are looking for a suitable option to deploy this database, which can handle millions of requests per second with low latency. Databases should have a flexible schema that can store any type of user data from multiple sources and should effectively process similar data stored in different formats.\u00a0<\/strong><\/em><\/p>\n<p><em><strong>Which of the following databases can be selected to meet the requirements?\u00a0\u00a0<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\"><strong>A.<\/strong> Use Amazon DocumentDB (with MongoDB compatibility) in the AWS cloud to rehost the database from an on-premises location.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>B.<\/strong> Use Amazon Neptune in the AWS cloud to rehost the database from an on-premises location.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>C.<\/strong> Use Amazon Timestream in AWS cloud to rehost database from an on-premises location.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>D.<\/strong> Use Amazon Keyspaces in AWS cloud to rehost database from an on-premises location.<\/span><\/p>\n<p><strong>Answer: A<\/strong><\/p>\n<p><strong>Explanation<\/strong><\/p>\n<p><span style=\"font-weight: 400;\"> Amazon DocumentDB is a fully managed database that supports JSON workloads for content management in the AWS cloud. Amazon DocumentDB supports millions of requests per second with low latency. Amazon DocumentDB has a flexible schema that can store data in different attributes and data values. Due to the flexible schema, it&#8217;s best suited for content management which allows users to store different data types such as images, videos, and comments.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With relational databases, for storing different documents, separate tables are required to store different types of documents or need a single table with unused fields as null values. Amazon DocumentDB is a semi-structured database that supports different formats of the documents in the same document without null values.\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B<\/strong> is <strong>incorrect<\/strong> as Amazon Neptune is suitable for creating graph databases querying large amounts of data. It is not a suitable option for content management with different data formats.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C<\/strong> is <strong>incorrect<\/strong> as Amazon Timestream is suitable for time series databases such as IoT base sensor data, DevOps, or clickstream data. It is not a suitable option for content management with different data formats.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D<\/strong> is <strong>incorrect<\/strong> as Amazon Keyspaces is a highly available and scalable database supporting Apache Cassandra. It is not a suitable option for content management with different data formats.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on the features of Amazon DocumentDB, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/documentdb\/features\/\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/documentdb\/features\/<\/span><\/a><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/products\/databases\/\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/products\/databases\/<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/documentdb\/latest\/developerguide\/document-database-use-cases.html\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/documentdb\/latest\/developerguide\/document-database-use-cases.html<\/span><\/a><\/p>\n<p><b>Domain: Design High-Performing Architectures<\/b><\/p>\n<p><em><strong>56). A start-up firm has created account A using the Amazon RDS DB instance as a database for a web application. The operations team regularly creates manual snapshots for this DB instance in unencrypted format. The Projects Team plans to create a DB instance in other accounts using these snapshots. They are looking for your suggestion for sharing this snapshot and restoring it to DB instances in other accounts. While sharing this snapshot, it must allow only specific accounts specified by the project teams to restore DB instances from the snapshot.<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\">What actions can be initiated for this purpose?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. From Account A, share the manual snapshot by setting the \u2018DB snapshot\u2019 visibility option as private. In other Accounts, directly restore to DB instances from the snapshot.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. From Account A, share the manual snapshot by setting the \u2018DB snapshot\u2019 visibility option as public. In other Accounts, directly restore to DB instances from the snapshot.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. From Account A, share the manual snapshot by setting the \u2018DB snapshot\u2019 visibility option as private. In other Accounts, create a copy from the snapshot and then restore it to the DB instance from that copy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. From Account A, share the manual snapshot by setting the \u2018DB snapshot\u2019 visibility<\/span><span style=\"font-weight: 400;\">option as public. In other Accounts, create a copy from the snapshot and then restore it to the DB instance from that copy.<\/span><\/p>\n<p><strong>Correct Answer : A<\/strong><\/p>\n<p><strong>Explanation<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">DB snapshot can be shared with other authorized AWS accounts which can be up to 20 accounts. These snapshots can be either in encrypted or unencrypted format.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For manual snapshots in an unencrypted format, accounts can directly restore a DB instance from the snapshot.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For manual snapshots in an encrypted format, accounts first need to copy the snapshot and then restore it to a DB instance.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While sharing a manual unencrypted snapshot, all accounts can use this snapshot to restore to the DB instance when DB snapshot visibility is set to public.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While sharing a manual unencrypted snapshot, only specified accounts can restore a DB instance when DB snapshot visibility is set to private.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the case of manual encrypted snapshots, the only available option for DB snapshot visibility is private, as encrypted snapshots cannot be made public.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B<\/strong> is <strong>incorrect<\/strong> as marking DB snapshot visibility as the public is not an ideal option since snapshots need to share only with specific accounts. Marking DB snapshot visibility as public will provide all Amazon accounts access to the manual snapshot and will be able to restore DB instances using this snapshot.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C<\/strong> is <strong>incorrect<\/strong> as DB instances can be directly restored from the snapshot for a manual unencrypted snapshot. There is no need to create a copy of the snapshot to restore a DB instance.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D<\/strong> is <strong>incorrect<\/strong> as already discussed, marking DB snapshot visibility as the public is not an ideal option. For a manual unencrypted snapshot, DB instances can be directly restored from the snapshot.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on sharing Amazon RDS snapshots, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/rds-snapshots-share-account\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/rds-snapshots-share-account\/<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.amazonaws.cn\/en_us\/AmazonRDS\/latest\/UserGuide\/USER_ShareSnapshot.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.amazonaws.cn\/en_us\/AmazonRDS\/latest\/UserGuide\/USER_ShareSnapshot.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Resilient_Architectures-5\"><\/span><b>Domain: Design Resilient Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>57). An electronic manufacturing company plans to deploy a web application using the Amazon Aurora database. The Management is concerned about the disk failures with DB instances and needs your advice for increasing reliability using Amazon Aurora automatic features. In the event of disk failures, data loss should be avoided, reducing additional work to perform from the point-in-time restoration.<\/em><\/strong><\/p>\n<p><span style=\"font-weight: 400;\">What design suggestions can be provided to increase reliability?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Add Aurora Replicas to primary DB instances by placing them in different regions. Aurora&#8217;s crash recovery feature will avoid data loss post disk failure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Add Aurora Replicas to primary DB instances by placing them in different availability zones. Aurora storage auto-repair feature will avoid data loss post disk failure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Add Aurora Replicas to the primary DB instance by placing them in different regions. Aurora Survivable page cache feature will avoid data loss post disk failure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Add Aurora Replicas to the primary DB instance by placing them in different availability zones.\u00a0 Aurora&#8217;s crash recovery feature will avoid data loss post disk failure.<\/span><\/p>\n<p><strong>Correct Answer : B<\/strong><\/p>\n<p><strong>Explanation<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Aurora Database reliability can be increased by adding Aurora Replicas to the primary DB instance and placing them in different Availability zones. Each of the DB clusters can have a primary DB instance and up to 15 Aurora Replicas. In case of primary DB instance failure, Aurora automatically fails over to replicas. Amazon Aurora also uses the following automatic features to enhance reliability,\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>Storage auto-repair:<\/strong> Aurora maintains multiple copies of the data in three different Availability zones. This helps in avoiding data loss post disk failure. If any segment of the disk fails, Aurora automatically recovers data on the segment by using data stored in other cluster volumes. This reduces additional work to perform point-in-time restoration post disk failure.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>Survivable page cache:<\/strong> Manage page cache in a separate process than the database. <\/span><span style=\"font-weight: 400;\">In the event of database failure, the page cache is stored in the memory. Post restarting the database, applications continue to read data from the page cache providing performance gain.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Crash recovery: <\/strong><span style=\"font-weight: 400;\">Crash recovery can be used for faster recovery post any crash in the database. With the crash recovery feature, Amazon Aurora performs recovery asynchronously on parallel threads enabling applications to read data from the database without binary logs.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\"><strong>Option A<\/strong> is <strong>incorrect<\/strong>. Aurora Replicas should be created in different Availability zones and not in different regions for better availability. The crash recovery does not minimize data loss post disk failures.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C<\/strong> is <strong>incorrect<\/strong>. The Survivable page cache feature provides performance gains but does not minimize data loss post disk failures. Aurora Replicas should be created in different Availability zones and not in different regions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D<\/strong> is <strong>incorrect<\/strong> as the crash recovery feature does not minimize data loss post disk failures.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Amazon Aurora reliability features, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Aurora.Overview.StorageReliability.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Aurora.Overview.StorageReliability.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-8\"><\/span><b>Domain: Design Cost-Optimized Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>58). A financial institute has deployed a critical web application in the AWS cloud. The management team is looking for a resilient solution with RTO\/RPO in ten minutes during a disaster. They have budget concerns, and the cost of provisioning the backup infrastructure should not be very high. As a solution architect, you have been assigned to work on setting a resilient solution meeting the RTO\/RPO requirements within the cost constraints.<\/em><\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Which strategy is suited perfectly?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Multi-Site Active\/Active<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Warm Standby<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Backup &amp; Restore<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Pilot Light<\/span><\/p>\n<p><strong>Correct Answer : D<\/strong><\/p>\n<p><strong>Explanation<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">RTO (Recovery Time Objective) is a period for which downtime is observed post-disaster. It\u2019s the time between the disaster and application recovery to serve full workloads. RPO (Recovery Point Objective) defines the amount of data loss during a disaster. It measures the time window when the last backup was performed, and the time when the disaster happened. Various Disaster recovery solutions can be deployed based on RTO\/RPO and budget requirements for critical applications.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The following are options available with Disaster recovery,\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup and Restore: Least expensive among all the options but RTO\/RPO will be very high in hours. All backup resources will be initiated only after a disaster at the primary location.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pilot Light: Less expensive than warm standby and multi-site active\/active. RTO\/RPO happens in tens of minutes.\u00a0<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">In this strategy, a minimum number of active resources are deployed at the backup locations. Resources required for data synchronization between primary and backup locations are only provisioned and are active. Other components such as application servers are switched off and are provisioned post a disaster at the primary location. In the above scenario, Pilot Light is the most suitable option to meet RTO\/RPO requirements on a low budget.\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm Standby: Expensive Than Pilot Light. RPO\/RTO happens in minutes. The application is running at the backup location on scaled-down resource capacity. Once a disaster occurs at the primary location, all the resources are scaled up to meet the desired workload.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multi-site active\/active: Most expensive. No downtime or data loss is incurred as applications are active from multiple regions.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">The following diagram shows the difference between each strategy with respect to\u00a0 \u00a0 RTO\/RPO and cost.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A<\/strong> is <strong>incorrect<\/strong> as with a multi-site active\/active approach, RPO\/RTO will be the least, but it will incur considerable cost.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B<\/strong> is <strong>incorrect<\/strong> as, with a Warm Standby approach, RPO\/RTO will be in minutes, but it will incur additional costs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C<\/strong> is <strong>incorrect<\/strong> as with the Backup &amp; Restore approach, RPO\/RTO will be in hours, <\/span><span style=\"font-weight: 400;\">not in minutes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Disaster Recovery, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/disaster-recovery-workloads-on-aws\/disaster-recovery-options-in-the-cloud.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/disaster-recovery-workloads-on-aws\/disaster-recovery-options-in-the-cloud.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Resilient_Architectures-6\"><\/span><b>Domain: Design Resilient Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>59). A critical application deployed in AWS Cloud requires maximum availability to avoid any outages. The project team has already deployed all resources in multiple regions with redundancy at all levels. They are concerned about the configuration of Amazon Route 53 for this application which should complement higher availability and reliability. Route 53 should be configured to use failover resources during a disaster.<\/em><\/strong><\/p>\n<p><span style=\"font-weight: 400;\">What solution can be implemented with Amazon Route 53 for maximum availability and increased reliability?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Associate multiple IP endpoints in different regions to Route 53 hostname. Use a weighted route policy to change the weights of the primary and failover resources. So, all traffic is diverted to failover resources during a disaster.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Create two sets of public-hosted zones for resources in multiple regions. During a disaster, update Route 53 public-hosted zone records to point to a healthy endpoint.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Create two sets of private hosted zones for resources in multiple regions. During a disaster, update Route 53 private hosted zone records to point to a healthy endpoint.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Associate multiple IP endpoints in different regions to Route 53 hostname. Using health checks, configure Route 53 to automatically failover to healthy endpoints during a disaster.<\/span><\/p>\n<p><strong>\u00a0Correct Answer : D<\/strong><\/p>\n<p><strong>Explanation<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Route 53 uses control planes to perform management-related activities such as creating, updating, and deleting resources.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Data plane is used for performing core services of Amazon Route 53 such as authoritative DNS service, health checks, and responding to DNS queries in an Amazon VPC.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Data plane is globally distributed, offering 100% availability SLA. Control plane traffic is optimized for data consistency and may be impacted during disruptive events in the infrastructure.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While configuring failover between multiple sites, data plane functions such as health checks should be preferred instead of control plane functions. In the above case, multiple endpoints in different regions can be associated with Route 53. Route 53 can be configured to failover to a healthy endpoint based upon the health checks which is a data plane function and always available.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A<\/strong> is <strong>incorrect<\/strong> as updating weights in a weighted routing policy is a control plane function. For additional resiliency during a disaster, use data plane functions instead of control plane functions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Options B and C<\/strong> are <strong>incorrect<\/strong> as creating, updating, and deleting private or public hosted zone records are part of control plane actions. In case of a disaster, control planes might get affected. Data plane functions such as health checks should be used for resources that are always available.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Amazon Route 53 control and data plane, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/route-53-concepts.html#route-53-concepts-control-and-data-plane\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/route-53-concepts.html#route-53-concepts-control-and-data-plane<\/span><\/a><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/creating-disaster-recovery-mechanisms-using-amazon-route-53\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/creating-disaster-recovery-mechanisms-using-amazon-route-53\/<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-9\"><\/span><b>Domain: Design Cost-Optimized Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>60). An IT company is using EBS volumes for storing projects related work. Some of these projects are already closed. The data for these projects should be stored long-term as per regulatory guidelines and will be rarely accessed. The operations team is looking for options to store the snapshots created from EBS volumes. The solution should be cost-effective and incur the least admin work.<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\">What solution can be designed for storing data from EBS volumes?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Create EBS Snapshots from the volumes and store them in the EBS Snapshots Archive.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Use Lambda functions to store incremental EBS snapshots to AWS S3 Glacier.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Create EBS Snapshots from the volumes and store them in a third-party low-cost, long-term storage.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Create EBS Snapshots from the volumes and store them in the EBS standard tier.<\/span><\/p>\n<p><strong>Correct Answer: A<\/strong><\/p>\n<p><strong>Explanation<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EBS has a new storage tier named Amazon EBS Snapshots Archive for storing snapshots that are accessed rarely and stored for long periods.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">By default, snapshots created from Amazon EBS volumes are stored in Amazon EBS Snapshot standard tier. These are incremental snapshots. When EBS snapshots are archived, incremental snapshots are converted to full snapshots.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These snapshots are stored in the EBS Snapshots Archive instead of the standard tier. Storing snapshots in the EBS Snapshots archive costs much less than storing snapshots in the standard tier. EBS snapshot archive helps store snapshots for long durations for governance or compliance requirements, which will be rarely accessed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B<\/strong> is <strong>incorrect<\/strong> as it will require additional work for creating an AWS Lambda function. EBS Snapshots archive is a more efficient way of storing snapshots for the long term.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C<\/strong> is <strong>incorrect<\/strong> as using third-party storage will incur additional costs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D<\/strong> is <strong>incorrect<\/strong> as all EBS snapshots are stored in a standard tier by default. Storing snapshots that will be rarely accessed in the standard tier will be costlier than storing in the EBS snapshots archive.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on the Amazon EBS snapshot archive, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/blogs\/aws\/new-amazon-ebs-snapshots-archive\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/blogs\/aws\/new-amazon-ebs-snapshots-archive<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/snapshot-archive.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/snapshot-archive.html<\/span><\/a><\/p>\n<p><b>Domain: Design High-Performing Architectures<\/b><\/p>\n<p><strong><em>Q61). A start-up firm has created account A using the Amazon RDS DB instance as a database for a web application. The operations team regularly creates manual snapshots for this DB instance in unencrypted format. The Projects Team plans to create a DB instance in other accounts using these snapshots. They are looking for your suggestion for sharing this snapshot and restoring it to DB instances in other accounts. While sharing this snapshot, it must allow only specific accounts specified by the project teams to restore DB instances from the snapshot.<\/em><\/strong><\/p>\n<p><span style=\"font-weight: 400;\">What actions can be initiated for this purpose?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. From Account A, share the manual snapshot by setting the \u2018DB snapshot\u2019 visibility option as private. In other Accounts, directly restore to DB instances from the snapshot.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. From Account A, share the manual snapshot by setting the \u2018DB snapshot\u2019 visibility option as public. In other Accounts, directly restore to DB instances from the snapshot.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. From Account A, share the manual snapshot by setting the \u2018DB snapshot\u2019 visibility option as private. In other Accounts, create a copy from the snapshot and then restore it to the DB instance from that copy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. From Account A, share the manual snapshot by setting the \u2018DB snapshot\u2019 visibility <\/span><span style=\"font-weight: 400;\">option as public. In other Accounts, create a copy from the snapshot and then restore it to the DB instance from that copy.<\/span><\/p>\n<p><strong>Correct Answer \u2013 A<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">DB snapshot can be shared with other authorized AWS accounts which can be up to 20 accounts. These snapshots can be either in encrypted or unencrypted format.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For manual snapshots in an unencrypted format, accounts can directly restore a DB instance from the snapshot.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For manual snapshots in an encrypted format, accounts first need to copy the snapshot and then restore it to a DB instance.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While sharing a manual unencrypted snapshot, all accounts can use this snapshot to restore to the DB instance when DB snapshot visibility is set to public.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While sharing a manual unencrypted snapshot, only specified accounts can restore a DB instance when DB snapshot visibility is set to private.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the case of manual encrypted snapshots, the only available option for DB snapshot visibility is private, as encrypted snapshots cannot be made public.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B<\/strong> is <strong>incorrect<\/strong> as marking DB snapshot visibility as the public is not an ideal option since snapshots need to share only with specific accounts. Marking DB snapshot visibility as public will provide all Amazon accounts access to the manual snapshot and will be able to restore DB instances using this snapshot.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C<\/strong> is <strong>incorrect<\/strong> as DB instances can be directly restored from the snapshot for a manual unencrypted snapshot. There is no need to create a copy of the snapshot to restore a DB instance.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D<\/strong> is <strong>incorrect<\/strong> as already discussed, marking DB snapshot visibility as the public is not an ideal option. For a manual unencrypted snapshot, DB instances can be directly restored from the snapshot.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on sharing Amazon RDS snapshots, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/rds-snapshots-share-account\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/rds-snapshots-share-account\/<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.amazonaws.cn\/en_us\/AmazonRDS\/latest\/UserGuide\/USER_ShareSnapshot.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.amazonaws.cn\/en_us\/AmazonRDS\/latest\/UserGuide\/USER_ShareSnapshot.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Resilient_Architectures-7\"><\/span><b>Domain: Design Resilient Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>62). An electronic manufacturing company plans to deploy a web application using the Amazon Aurora database. The Management is concerned about the disk failures with DB instances and needs your advice for increasing reliability using Amazon Aurora automatic features. In the event of disk failures, data loss should be avoided, reducing additional work to perform from the point-in-time restoration.<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\">What design suggestions can be provided to increase reliability?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Add Aurora Replicas to primary DB instances by placing them in different regions. Aurora&#8217;s crash recovery feature will avoid data loss post disk failure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Add Aurora Replicas to primary DB instances by placing them in different availability zones. Aurora storage auto-repair feature will avoid data loss post disk failure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Add Aurora Replicas to the primary DB instance by placing them in different regions. Aurora Survivable page cache feature will avoid data loss post disk failure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Add Aurora Replicas to the primary DB instance by placing them in different availability zones.\u00a0 Aurora&#8217;s crash recovery feature will avoid data loss post disk failure.<\/span><\/p>\n<p><strong>Correct Answer \u2013 B<\/strong><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Explanation:<\/strong> Amazon Aurora Database reliability can be increased by adding Aurora Replicas to the primary DB instance and placing them in different Availability zones. Each of the DB clusters can have a primary DB instance and up to 15 Aurora Replicas. In case of primary DB instance failure, Aurora automatically fails over to replicas. Amazon Aurora also uses the following automatic features to enhance reliability,\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage auto-repair: Aurora maintains multiple copies of the data in three different Availability zones. This helps in avoiding data loss post disk failure. If any segment of the disk fails, Aurora automatically recovers data on the segment by using data stored in other cluster volumes. This reduces additional work to perform point-in-time restoration post disk failure.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Survivable page cache: Manage page cache in a separate process than the database. <\/span><span style=\"font-weight: 400;\">In the event of database failure, the page cache is stored in the memory. Post restarting the database, applications continue to read data from the page cache providing performance gain.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Crash recovery: <\/span><span style=\"font-weight: 400;\">Crash recovery can be used for faster recovery post any crash in the database. With the crash recovery feature, Amazon Aurora performs recovery asynchronously on parallel threads enabling applications to read data from the database without binary logs.<\/span><\/li>\n<\/ol>\n<p><strong style=\"font-size: 16px;\">Option A is incorrect<\/strong><span style=\"font-size: 16px; font-weight: 400;\">. Aurora Replicas should be created in different Availability zones and not in different regions for better availability. The crash recovery does not minimize data loss post disk failures.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong>. The Survivable page cache feature provides performance gains but does not minimize data loss post disk failures. Aurora Replicas should be created in different Availability zones and not in different regions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as the crash recovery feature does not minimize data loss post disk failures.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Amazon Aurora reliability features, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Aurora.Overview.StorageReliability.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonRDS\/latest\/AuroraUserGuide\/Aurora.Overview.StorageReliability.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-10\"><\/span><b>Domain: Design Cost-Optimized Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>63). A financial institute has deployed a critical web application in the AWS cloud. The management team is looking for a resilient solution with RTO\/RPO in ten minutes during a disaster. They have budget concerns, and the cost of provisioning the backup infrastructure should not be very high. As a solution architect, you have been assigned to work on setting a resilient solution meeting the RTO\/RPO requirements within the cost constraints.<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\">Which strategy is suited perfectly?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Multi-Site Active\/Active<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Warm Standby<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C.Backup &amp; Restore<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Pilot Light<\/span><\/p>\n<p><strong>Correct Answer \u2013 D<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">RTO (Recovery Time Objective) is a period for which downtime is observed post-disaster. It\u2019s the time between the disaster and application recovery to serve full workloads. RPO (Recovery Point Objective) defines the amount of data loss during a disaster. It measures the time window when the last backup was performed, and the time when the disaster happened. Various Disaster recovery solutions can be deployed based on RTO\/RPO and budget requirements for critical applications.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The following are options available with Disaster recovery,\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Backup and Restore: Least expensive among all the options but RTO\/RPO will be very high in hours. All backup resources will be initiated only after a disaster at the primary location.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Pilot Light: Less expensive than warm standby and multi-site active\/active. RTO\/RPO happens in tens of minutes.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this strategy, a minimum number of active resources are deployed at the backup locations. Resources required for data synchronization between primary and backup locations are only provisioned and are active. Other components such as application servers are switched off and are provisioned post a disaster at the primary location. In the above scenario, Pilot Light is the most suitable option to meet RTO\/RPO requirements on a low budget.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Warm Standby: Expensive Than Pilot Light. RPO\/RTO happens in minutes. The application is running at the backup location on scaled-down resource capacity. Once a disaster occurs at the primary location, all the resources are scaled up to meet the desired workload.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Multi-site active\/active: Most expensive. No downtime or data loss is incurred as applications are active from multiple regions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The following diagram shows the difference between each strategy with respect to\u00a0 \u00a0 RTO\/RPO and cost.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> as with a multi-site active\/active approach, RPO\/RTO will be the least, but it will incur considerable cost.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as, with a Warm Standby approach, RPO\/RTO will be in minutes, but it will incur additional costs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as with the Backup &amp; Restore approach, RPO\/RTO will be in hours, <\/span><span style=\"font-weight: 400;\">not in minutes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Disaster Recovery, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/disaster-recovery-workloads-on-aws\/disaster-recovery-options-in-the-cloud.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/disaster-recovery-workloads-on-aws\/disaster-recovery-options-in-the-cloud.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Resilient_Architectures-8\"><\/span><b>Domain: Design Resilient Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>64). A critical application deployed in AWS Cloud requires maximum availability to avoid any outages. The project team has already deployed all resources in multiple regions with redundancy at all levels. They are concerned about the configuration of Amazon Route 53 for this application which should complement higher availability and reliability. Route 53 should be configured to use failover resources during a disaster.<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\">What solution can be implemented with Amazon Route 53 for maximum availability and increased reliability?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Associate multiple IP endpoints in different regions to Route 53 hostname. Use a weighted route policy to change the weights of the primary and failover resources. So, all traffic is diverted to failover resources during a disaster.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Create two sets of public-hosted zones for resources in multiple regions. During a disaster, update Route 53 public-hosted zone records to point to a healthy endpoint.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Create two sets of private hosted zones for resources in multiple regions. During a disaster, update Route 53 private hosted zone records to point to a healthy endpoint.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Associate multiple IP endpoints in different regions to Route 53 hostname. Using health checks, configure Route 53 to automatically failover to healthy endpoints during a disaster.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><strong>Correct Answer \u2013 D<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Route 53 uses control planes to perform management-related activities such as creating, updating, and deleting resources.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Data plane is used for performing core services of Amazon Route 53 such as authoritative DNS service, health checks, and responding to DNS queries in an Amazon VPC.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Data plane is globally distributed, offering 100% availability SLA. Control plane traffic is optimized for data consistency and may be impacted during disruptive events in the infrastructure.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While configuring failover between multiple sites, data plane functions such as health checks should be preferred instead of control plane functions. In the above case, multiple endpoints in different regions can be associated with Route 53. Route 53 can be configured to failover to a healthy endpoint based upon the health checks which is a data plane function and always available.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> as updating weights in a weighted routing policy is a control plane function. For additional resiliency during a disaster, use data plane functions instead of control plane functions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Options B and C are incorrect<\/strong> as creating, updating, and deleting private or public hosted zone records are part of control plane actions. In case of a disaster, control planes might get affected. Data plane functions such as health checks should be used for resources that are always available.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Amazon Route 53 control and data plane, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/route-53-concepts.html#route-53-concepts-control-and-data-plane\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/route-53-concepts.html#route-53-concepts-control-and-data-plane<\/span><\/a><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/creating-disaster-recovery-mechanisms-using-amazon-route-53\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/creating-disaster-recovery-mechanisms-using-amazon-route-53\/<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-11\"><\/span><b>Domain: Design Cost-Optimized Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>65). An IT company is using EBS volumes for storing projects related work. Some of these projects are already closed. The data for these projects should be stored long-term as per regulatory guidelines and will be rarely accessed. The operations team is looking for options to store the snapshots created from EBS volumes. The solution should be cost-effective and incur the least admin work.<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\">What solution can be designed for storing data from EBS volumes?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Create EBS Snapshots from the volumes and store them in the EBS Snapshots Archive.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Use Lambda functions to store incremental EBS snapshots to AWS S3 Glacier.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Create EBS Snapshots from the volumes and store them in a third-party low-cost, long-term storage.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Create EBS Snapshots from the volumes and store them in the EBS standard tier.<\/span><\/p>\n<p><strong>Correct Answer \u2013 A<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EBS has a new storage tier named Amazon EBS Snapshots Archive for storing snapshots that are accessed rarely and stored for long periods.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">By default, snapshots created from Amazon EBS volumes are stored in Amazon EBS Snapshot standard tier. These are incremental snapshots. When EBS snapshots are archived, incremental snapshots are converted to full snapshots.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These snapshots are stored in the EBS Snapshots Archive instead of the standard tier. Storing snapshots in the EBS Snapshots archive costs much less than storing snapshots in the standard tier. EBS snapshot archive helps store snapshots for long durations for governance or compliance requirements, which will be rarely accessed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as it will require additional work for creating an AWS Lambda function. EBS Snapshots archive is a more efficient way of storing snapshots for the long term.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as using third-party storage will incur additional costs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as all EBS snapshots are stored in a standard tier by default. Storing snapshots that will be rarely accessed in the standard tier will be costlier than storing in the EBS snapshots archive.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on the Amazon EBS snapshot archive, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/blogs\/aws\/new-amazon-ebs-snapshots-archive\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/blogs\/aws\/new-amazon-ebs-snapshots-archive<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/snapshot-archive.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/snapshot-archive.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-11\"><\/span><b>Domain: Design High-Performing Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>Q66). A manufacturing firm has a large number of smart devices installed in various locations worldwide. Hourly logs from these devices are stored in an Amazon S3 bucket. Management is looking for comprehensive dashboards which should incorporate usages of these devices and forecast usage trends for these devices.<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\">Which tool is the best suited to get this required dashboard?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Use S3 as a source for Amazon QuickSight and create dashboards for usage and forecast trends.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Use S3 as a source for Amazon Redshift and create dashboards for usage and forecast trends.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Copy data from Amazon S3 to Amazon DynamoDB. Use Amazon DynamoDB as a source for Amazon QuickSight and create dashboards for usage and forecast trends.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Copy data from Amazon S3 to Amazon RDS. Use Amazon RDS as a source for Amazon QuickSight and create dashboards for usage and forecast trends.<\/span><\/p>\n<p><strong>Correct Answer \u2013 A<\/strong><\/p>\n<p><strong>Explanation:<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0 Amazon QuickSight is a business analytical tool that can be used to build visualizations and perform ad-hoc analysis integrating with ML insights. It can connect to various data sources which can either be in the AWS cloud or in the on-premises network or in any third-party applications. <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">For AWS it supports various services such as Amazon RDS, Amazon Aurora, Amazon Redshift, Amazon Athena, and Amazon S3 as sources. Based on this data, Amazon QuickSight creates custom dashboards that include anomaly detections, forecasting, and auto-narratives. <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">In the above case, logs from the devices are stored in Amazon S3. Amazon QuickSight can be used to fetch this data, perform analysis, and generate comprehensive custom dashboards for device usage as well as forecasting device usage.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as Amazon Redshift is a data warehousing service for analyzing structured or semi-structured data. It is not a useful tool for creating dashboards.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect <\/strong>as Amazon S3 can be used directly as a source for Amazon QuickSight. There is no need to copy data from Amazon S3 to Amazon DynamoDB.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as Amazon S3 can be used directly as a source for Amazon QuickSight. There is no need to copy data from Amazon S3 to Amazon RDS.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Amazon QuickSight, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/quicksight\/resources\/faqs\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/quicksight\/resources\/faqs\/<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-12\"><\/span><b>Domain: Design High-Performing Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>Q67). A company has launched Amazon EC2 instances in an Auto Scaling group for deploying a web application. The Operations Team is looking to capture custom metrics for this application from all the instances. These metrics should be viewed as aggregated metrics for all instances in an Auto Scaling group.<\/em><\/strong><\/p>\n<p><span style=\"font-weight: 400;\">What configuration can be implemented to get the metrics as required?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. <\/span><span style=\"font-weight: 400;\">Use Amazon CloudWatch metrics with detail monitoring enabled and send to CloudWatch console where all the metrics for an Auto Scaling group will be aggregated by default.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Install a unified CloudWatch agent on all Amazon EC2 instances in an Auto Scaling group and use &#8220;aggregation_dimensions&#8221; in an agent configuration file to aggregate metrics for all instances.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Install unified CloudWatch agent on all Amazon EC2 instances in an Auto Scaling group and use \u201cappend-config\u201d<\/span> <span style=\"font-weight: 400;\">in an agent configuration file to aggregate metrics for all instances<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Use Amazon CloudWatch metrics with detail monitoring enabled and create a single Dashboard to display metrics from all the instances.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Correct Answer \u2013 B<\/strong><\/span><\/p>\n<p><strong>Explanation:<\/strong><\/p>\n<p><span style=\"font-weight: 400;\"> Unified CloudWatch agent can be installed on Amazon EC2 instance for the following cases,\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Collect Internal System-level metrics from Amazon EC2 installed as well as from on-premises servers.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Collect custom metrics from the applications on the Amazon EC2 instance using StatsD and collectd protocols.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Collect logs from EC2 instances or from on-premises servers for both Windows and Linux OS.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><span style=\"font-weight: 400;\">In the case of the Instances which are part of an Auto Scaling group, metrics from all the instances can be aggregated using &#8220;aggregation_dimensions&#8221; in the agent configuration file.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> as for retrieving custom level metrics for applications on an Amazon EC2 Instance, a unified CloudWatch agent is required. Amazon CloudWatch metrics with detail monitoring will be capturing metrics every 1 minute but it won\u2019t capture custom application metrics.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as the append-config configuration in an agent configuration file can be used to have multiple CloudWatch agent configuration files. This command is not suitable for aggregate metrics from all the instances in an Auto Scaling group.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as for retrieving custom level metrics for applications on an Amazon EC2 Instance, a unified CloudWatch agent is required. Dashboards can be used to create a customized view of the metrics, but they won\u2019t aggregate metrics from the instance in an Auto Scaling Group.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on the CloudWatch agent, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/monitoring\/Install-CloudWatch-Agent.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/monitoring\/Install-CloudWatch-Agent.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-13\"><\/span><b>Domain: Design High-Performing Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>Q68). A critical web application is deployed on multiple Amazon EC2 instances which are part of an Autoscaling group. One of the Amazon EC2 instances in the group needs to have a software upgrade. The Operations Team is looking for your suggestions to advise for this upgrade without impacting another instance in the group. Post upgradation the same instance should be part of the Auto Scaling group.\u00a0\u00a0<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\">What steps can be initiated to complete this upgrade?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A. Hibernate the instance and perform upgradation in offline mode. Post upgrades start the instance which will be part of the same auto-scaling group.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Use cooldown timers to perform upgrades on the instance. Post cooldown timers\u2019 instances would be part of the same auto-scaling group.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Put the instance in Standby mode. Post upgrade, move instance back to InService mode. It will be part of the same auto-scaling group.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Use lifecycle hooks to perform upgrades on the instance. Once these timers expire, the instance would be part of the same auto-scaling group.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Correct Answer \u2013 C<\/strong><\/span><\/p>\n<p><strong>Explanation:<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EC2 instances in an Auto Scaling group can be moved to Standby mode from InService mode. In standby mode, software upgradation or troubleshooting can be performed on the instance. Post upgradation, instances can be again put in InService mode back in the same Auto Scaling group. With instance in a standby mode, Auto Scaling does not terminate this group as a part of health checks or scale-in events.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> as Hibernate is not supported on an Amazon EC2 instance which is part of an Auto Scaling group. When an instance in an Auto Scaling group is hibernated, the Auto-scaling group marks the hibernated instance as unhealthy, terminates it, and launches a new instance. Hibernating an instance will not be useful for upgrading software on an instance.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as cooldown timers are the timers that will prevent launching or terminating instances in an Auto Scaling group till previous activities of launch or termination are completed. This timer provides a time for an instance to be in an active state before the Auto Scaling group adds a new one. This timer would not be useful for troubleshooting an instance.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as a Lifecycle hook can help to perform custom actions such as data backups before an instance is terminated or to perform software instances once an instance is launched. This hook is not useful for upgrading a running instance in an Auto Scaling Group and adding back to the original group.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on upgrading the Amazon EC2 instance in an Auto Scaling group, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/instance-hibernate-limitations.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/instance-hibernate-limitations.html<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/userguide\/as-enter-exit-standby.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/userguide\/as-enter-exit-standby.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-14\"><\/span><b>Domain: Design High-Performing Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>Hybrid connectivity is built between an on-premises network and VPC using a Site-to-Site VPN. At the on-premises network, a legacy firewall is deployed which allows a single \/28 IP prefix from VPC to access the on-premises network. Access to this firewall is blocked and the operations team needs to allow communication from an additional IP pool from VPC. Operations Head is looking for a temporary workaround to enable communication from the new IP pool to the on-premises network.\u00a0<\/em><\/strong><\/p>\n<p><strong><em>What connectivity can be deployed to mitigate this issue?<\/em><\/strong><\/p>\n<p><span style=\"font-weight: 400;\"><strong>A. <\/strong>Deploy public NAT gateway in a private subnet with IP pool allowed in on-premises firewall. Launch the instance which needs to have communication with the on-premises network in a separate private subnet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>B. <\/strong>Deploy public NAT gateway in a public subnet with IP pool allowed in on-premises firewall. Launch the instance which needs to have communication with the on-premises network in a separate public subnet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>C. <\/strong>Deploy private NAT gateway in a public subnet with IP pool allowed in on-premises firewall.Launch the instance which needs to have communication with the on-premises network in a separate private subnet.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>D. <\/strong>Deploy private NAT gateway in a private subnet with IP pool allowed in on-premises firewall. Launch the instance which needs to have communication with the on-premises network in a separate private subnet.<\/span><\/p>\n<p><strong>Correct Answer \u2013 D<\/strong><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Explanation:<\/strong> Private NAT Gateway can be used to establish connectivity from an instance in a private subnet of the VPC to other VPCs or to an on-premises network. With a private NAT gateway, the source IP address of the instance is replaced with the IP address pool of the private NAT Gateway. In the above scenario, legacy firewalls will allow communication from VPC to on-premises networks only from \/28 IP pool. <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">To establish communication from an instance with a new IP pool, NAT Gateway can be deployed in an \/28 IP pool which is allowed in Firewall. The instance will be deployed in a separate private subnet. While communicating with the On-premises network, Instance IP will be replaced with the NAT Gateway IP Pool which is already allowed in a firewall and connectivity will be established without any changes in the firewall.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Diagram showing connectivity from Private subnet to On-premises using a Private NAT gateway,<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> because resources in a VPC require to have communications with an on-premises network and not with the Internet, so a Public NAT gateway is not an ideal option. A Public NAT gateway is placed in a public subnet to provide internet access for resources in private subnets.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as the resources in a VPC require to have communications with an on-premises network and not with the Internet, so a Public NAT gateway is not an ideal option. A Public NAT gateway is used to provide internet access for resources in private subnets.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as to provide communication from a private subnet to an on-premises network, a private NAT gateway should be placed in a private subnet and not in a public subnet.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on NAT Gateways, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-nat-gateway.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-nat-gateway.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Cost-Optimized_Architectures-12\"><\/span><b>Domain: Design Cost-Optimized Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"font-weight: 400;\">A third-party vendor based in an on-premises location needs to have temporary connectivity to database servers launched in a single Amazon VPC. The proposed connectivity for these few users should be secure, and access should be provided only to authenticated users.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Which connectivity option can be deployed for this requirement in the most cost-effective way?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>A. <\/strong>Deploy an AWS Client VPN from third-party vendor&#8217;s client machines to access databases in Amazon VPC.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>B. <\/strong>Deploy AWS Direct Connect connectivity from the on-premises network to AWS.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>C. <\/strong>Deploy an AWS Managed VPN connectivity to a Virtual Private gateway from an on-premises network.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>D. <\/strong>Deploy an AWS Managed VPN connectivity to the AWS Transit gateway from the on-premises network.<\/span><\/p>\n<p><strong>Correct Answer \u2013 A<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">AWS Client VPC is a managed client-based VPN for having secure access to resources in VPC as well as resources in on-premises networks. Clients looking for access to these resources use an OpenVPN-based VPN client. Access to resources in VPC is secure over TLS and clients are authenticated before access is granted.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the above case, since third-party vendors from on-premises need secure temporary connectivity to resources in VPC, AWS Client VPN can be used to provide this connectivity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as since there are only a few users accessing resources from a single VPC for temporary purposes, using AWS Direct Connect will be costly and will require a longer time for deployment.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as using Managed VPN for a few users will be costlier than using AWS Client VPN for those few users accessing databases from VPC.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as Connectivity to AWS Transit gateway will be useful for accessing resources from multiple VPCs. Also, since only a few users access resources from a single VPC for temporary purposes, AWS Client VPN is a cost-effective option.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on the difference between various options for Hybrid connectivity, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/scenario-vpc.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/scenario-vpc.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Architectures-4\"><\/span><b>Domain: Design Secure Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>A company is storing data in an Amazon S3 bucket which is accessed by global users. Amazon S3 bucket is encrypted with AWS KMS. The company is planning to use Amazon CloudFront as a CDN for high performance. The Operations Team is looking for your suggestions to create an S3 bucket policy to restrict access to the S3 bucket only via specific CloudFront distribution.\u00a0<\/em><\/strong><\/p>\n<p><strong><em>How can the S3 bucket policy be implemented to control access to the S3 bucket?<\/em><\/strong><\/p>\n<p><span style=\"font-weight: 400;\"><strong>A.<\/strong> Use a Principal element in the policy to match service as CloudFront distribution that contains the S3 origin.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>B.<\/strong> Use a Condition element in the policy to allow CloudFront to access the bucket only when the request is on behalf of the CloudFront distribution that contains the S3 origin.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>C.<\/strong> Use a Principal element in the policy to allow CloudFront Origin Access Identity (OAI).<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>D.<\/strong> Use a Condition element in the policy to match service as cloudfront.amazonaws.com.<\/span><\/p>\n<p><strong>Correct Answer \u2013 B<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">While using Amazon CloudFront with Amazon S3 as an origin, there are two ways to control access to the S3 bucket via Amazon CloudFront,\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OAI (Origin Access Identity):\u00a0 This is a legacy method that does not support AWS KMS as encryption or dynamic requests to the Amazon S3 and Opt-in regions.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OAC (Origin Access Control): This is a new method and supports the following three points such as AWS KMS for encryption, dynamic requests to the Amazon S3 and Opt-in regions which are not supported by OAI. <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">While creating policy for OAC, the principal element should have service as \u201c<\/span><span style=\"font-weight: 400;\">cloudfront.amazonaws.com\u201d and the condition element should match the CloudFront distribution which contains S3 origin.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> as the Principal element in the policy should match service as CloudFront and not CloudFront distribution.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as using CloudFront Origin Access Identity is a legacy method and does not support the Amazon S3 bucket with AWS KMS server-side encryption.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as a Condition element should match CloudFront distribution that contains S3 origin and not the service name as cloudfront.amazonaws.com.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on creating Origin Access Control with Amazon S3, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/private-content-restricting-access-to-s3.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/private-content-restricting-access-to-s3.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Architectures-5\"><\/span><b>Domain: Design Secure Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>A company is using microservices-based applications using Amazon ECS for an online shopping application. For different services, multiple tasks are created in a container using the EC2 launch type. The security team is looking for some specific security controls for the tasks in the containers along with granular network monitoring using various tools for each task.<\/strong><\/em><\/p>\n<p><em><strong>What networking mode configuration can be considered with Amazon ECS to meet this requirement?<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\"><strong>A.<\/strong> Use host networking mode for Amazon ECS tasks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>B.<\/strong> By default, an elastic network interface (ENI) with a primary private IP address is assigned to each task.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>C.<\/strong> Use awsvpc networking mode for Amazon ECS tasks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>D.<\/strong> Use bridge networking mode for Amazon ECS tasks.<\/span><\/p>\n<p><strong>Correct Answer \u2013 C<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Amazon ECS with EC2 launch type supports the following networking mode,\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Host Mode: This is a basic mode in which the networking of the container is directly tied to the underlying host.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge Mode: In this mode, a network bridge is created between host and container networking. This bridge mode allows the remapping of ports between host and container ports.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">None mode: In this mode, networking is not attached to the container. With this mode, containers do not have external connectivity.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWSVPC Mode: In this mode, each task is allocated a separate ENI (Elastic Network Interface). Each Task will receive a separate IP address and a separate security group can be assigned to each ENI. This helps to have separate security policies for each task and helps to get granular monitoring for traffic flowing via each task.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">In the above scenario, using AWSVPC mode, the security team can assign different security policies for each task as well as monitor traffic from each task distinctly.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> as with host networking mode, networking of containers uses the network interface of the Amazon EC2 instance on which it&#8217;s running. This is a basic network type and each task does not get assigned a different networking mode.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as <\/span><span style=\"font-weight: 400;\">an elastic network interface (ENI) with the primary private IP address is assigned for Fargate task networking, not for ECS task networking.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as Bridge mode uses Docker\u2019s built-in virtual network. Containers connected to the bridge can communicate with others. Containers using different bridges cannot communicate with each other while providing isolation. It does not provide each task with a separate networking mode that can be used for security controls and network monitoring.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Amazon ECS task networking and choosing a network mode, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/developerguide\/task-networking.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/developerguide\/task-networking.html<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/bestpracticesguide\/networking-networkmode.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/bestpracticesguide\/networking-networkmode.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_High-Performing_Architectures-15\"><\/span><b>Domain: Design High-Performing Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>A start-up firm is planning to deploy container-based applications using Amazon ECS. The firm is looking for the least latency from on-premises networks to the workloads in the containers. The proposed solution should be scalable and should support consistent high CPU and memory requirements.<\/strong><\/em><\/p>\n<p><em><strong>What deployment can be implemented for this purpose?\u00a0<\/strong><\/em><\/p>\n<p><span style=\"font-weight: 400;\"><strong>A.<\/strong> Create a Fargate launch type with Amazon ECS and deploy it in the AWS Outpost.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>B.<\/strong> Create a Fargate launch type with Amazon ECS and deploy it in the AWS Local Zone.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>C.<\/strong> Create an EC2 launch type with Amazon ECS and deploy it in the AWS Local Zone.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>D.<\/strong> Create an EC2 launch type with Amazon ECS and deploy it in the AWS Outpost.<\/span><\/p>\n<p><strong>Correct Answer \u2013 D<\/strong><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Explanation:\u00a0<\/strong> Amazon ECS can be deployed in AWS Outposts to provide the least latency from the on-premises location. With AWS Outposts, the EC2 launch type is only supported with Amazon ECS. EC2 launch type is best suited when there is a requirement of consistent high CPU and memory for container-based applications.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> as the AWS Fargate launch type is not supported with Amazon ECS deployed in the AWS Outpost.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as the AWS Fargate launch type is not supported with Amazon ECS deployed in the AWS Local Zone.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as with AWS Local Zones, other services such as Amazon EC2 instances, Amazon FSx file servers, and Application Load Balancers need to be implemented before deploying Amazon ECS in the Local Zones.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With AWS Outposts, native AWS services and infrastructure is enabled which makes it an ideal choice for low latency from on-premises networks.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on the Amazon ECS service on AWS Outposts, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/developerguide\/ecs-on-outposts.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/developerguide\/ecs-on-outposts.html<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/developerguide\/cluster-regions-zones.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/developerguide\/cluster-regions-zones.html<\/span><\/a><b><\/b><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Architectures-6\"><\/span><b>Domain: Design Secure Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong><em>A new application is deployed in an Amazon EC2 instance which is launched in a private subnet of Amazon VPC. This application will be fetching data from Amazon S3 as well as from Amazon DynamoDB. The communication between the Amazon EC2 instance and Amazon S3 as well as with Amazon DynamoDB should be secure and should not transverse over internet links. The connectivity should also support accessing data in Amazon S3 from an on-premises network in the future.<\/em><\/strong><\/p>\n<p><strong><em>What design can be implemented to have secure connectivity?<\/em><\/strong><\/p>\n<p><span style=\"font-weight: 400;\">A. Access Amazon DynamoDB from an instance in a private subnet using a gateway endpoint. Access Amazon S3 from an instance in a private subnet using an interface endpoint.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">B. Access Amazon S3 and Amazon DynamoDB from an instance in a private subnet using a private NAT gateway.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">C. Access Amazon S3 and Amazon DynamoDB from an instance in a private subnet using a public NAT gateway.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">D. Access Amazon S3 and Amazon DynamoDB from an instance in a private subnet using a gateway endpoint.<\/span><\/p>\n<p><strong>Correct Answer \u2013 A<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Using Gateway endpoints, secure and reliable connectivity can be established from a private subnet in a VPC to Amazon S3 or Amazon DynamoDB. This traffic does not transverse over internet links, but it flows over AWS private links.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Amazon S3 supports two types of VPC endpoints: Gateway Endpoint and Interface Endpoint. Both these connectivity options do not transverse over Internet links which makes them secure and reliable connectivity options. With Interface Endpoint, S3 can also be accessed from an on-premises network along with private subnets in a VPC.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the above scenario, to access Amazon DynamoDB, the Gateway endpoint can be used while to access Amazon S3 from a private subnet as well as from an on-premises network in the future, the Interface Endpoint can be used.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Accessing Amazon S3 over Interface Endpoints:\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Accessing Amazon DynamoDB over Gateway Endpoints:<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option B is incorrect<\/strong> as a private NAT gateway can be used to have communication between VPCs or with on-premises networks. It is not an option to have communication from a private subnet in a VPC to an Amazon S3 or Amazon DynamoDB.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as with public NAT Gateway, traffic will transverse over the Internet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as with Gateway endpoint, the on-premises network would not be able to access data in Amazon S3 securely over the private link.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on Gateway Endpoints and Interface Endpoints, refer to the following URL,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/privatelink\/gateway-endpoints.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/vpc\/latest\/privatelink\/gateway-endpoints.html<\/span><\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/privatelink-interface-endpoints.html#types-of-vpc-endpoints-for-s3\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/privatelink-interface-endpoints.html#types-of-vpc-endpoints-for-s3<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Domain_Design_Secure_Architectures-7\"><\/span><b>Domain: Design Secure Architectures<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"font-weight: 400;\">A static website named \u2018<\/span><i><span style=\"font-weight: 400;\">whizexample\u2019<\/span><\/i><span style=\"font-weight: 400;\"> is hosted using the Amazon S3 bucket. JavaScript on the web pages stored in the Amazon S3 bucket needs to make authenticated GET requests to the bucket using the Amazon S3 API endpoint for the bucket, <\/span><i><span style=\"font-weight: 400;\">example.s3.us-west-1.amazonaws.com<\/span><\/i><span style=\"font-weight: 400;\">.\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What additional configuration will be required for allowing this access?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>A.<\/strong> Create CORS configuration with Access-Control-Request-Header as GET using JSON and add CORS configuration to the bucket from the S3 console.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>B.<\/strong> Create CORS configuration with Access-Control-Request-Method as GET using JSON and add CORS configuration to the bucket from the S3 console.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>C.<\/strong> Create CORS configuration with Access-Control-Request-Method as GET using XML and add CORS configuration to the bucket from the S3 console.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>D.<\/strong> Create CORS configuration with Access-Control-Request-Header as GET using XML and add CORS configuration to the bucket from the S3 console.<\/span><\/p>\n<p><strong>Correct Answer \u2013 B<\/strong><\/p>\n<p><strong>Explanation:\u00a0\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">CORS (Cross Origin resource sharing) is a configuration that allows web applications deployed in one domain to interact with applications in different domains. Enabling CORS on an S3 bucket selectively allows content in the S3 bucket to be accessed.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the above scenario, when CORS is not enabled, JavaScript will not be able to access content in the S3 bucket using the S3 API endpoint. To allow this access, CORS configuration using JSON needs to be created and added to the S3 bucket from the S3 console.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">CORS can be enabled with the following settings,\u00a0<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access-Control-Allow-Origin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access-Control-Allow-Methods<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access-Control-Allow-Headers<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">For successful access, Origin, Methods, and Headers from the requestor should match the values defined in the configuration files. In the above scenario, the GET method should be added to the CORS configuration file.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option A is incorrect<\/strong> as for GET requests, Access-Control-Allow-Methods should be defined in the configuration file and not the Access-Control-Allow-Headers.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option C is incorrect<\/strong> as CORS configuration with XML is not supported while configuring CORS using the S3 console.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Option D is incorrect<\/strong> as for GET request, Access-Control-Allow-Methods should be defined in the configuration file and not the Access-Control-Allow-Headers. CORS configuration with XML is not supported while configuring CORS using the S3 console.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For more information on configuring CORS in Amazon S3, refer to the following URLs,<\/span><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/cors.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/cors.html<\/span><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Old_Questions\"><\/span>Old Questions<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><em><strong>8) You are planning to build a fleet of EBS-optimized EC2 instances for your new application. Due to security compliance, your organization wants you to encrypt root volume which is used to boot the instances. How can this be achieved?<\/strong><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. Select the Encryption option for the root EBS volume while launching the EC2 instance.<br \/>\nB. Once the EC2 instances are launched, encrypt the root volume using AWS KMS Master Key.<br \/>\nC. Root volumes cannot be encrypted. Add another EBS volume with an encryption option selected during launch. Once EC2 instances are launched, make encrypted EBS volume as root volume through the console.<br \/>\nD. Launch an unencrypted EC2 instance and create a snapshot of the root volume. Make a copy of the snapshot with the encryption option selected and CreateImage using the encrypted snapshot. Use this image to launch EC2 instances.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><strong>Answer:<\/strong> D<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When launching an EC2 instance, the EBS volume for root cannot be encrypted.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-67243 size-full\" title=\"EBS Storage Addtion Question\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-1.png\" alt=\"EBS Storage Addtion Question\" width=\"1105\" height=\"197\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-1.png 1105w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-1-300x53.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-1-768x137.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-1-1024x183.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-1-640x114.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-1-681x121.png 681w\" sizes=\"(max-width: 1105px) 100vw, 1105px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">You can launch the instance with unencrypted root volume and create a snapshot of the root volume. Once the snapshot is created, you can copy the snapshot where you can make the new snapshot encrypted.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-67244 size-full\" title=\"EBS Add Storage Snapshot\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-2.png\" alt=\"EBS Add Storage Snapshot\" width=\"1067\" height=\"561\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-2.png 1067w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-2-300x158.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-2-768x404.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-2-1024x538.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-2-799x420.png 799w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-2-640x336.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-2-681x358.png 681w\" sizes=\"(max-width: 1067px) 100vw, 1067px\" \/><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67245\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-3.png\" alt=\"\" width=\"1068\" height=\"511\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-3.png 1068w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-3-300x144.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-3-768x367.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-3-1024x490.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-3-878x420.png 878w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-3-640x306.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-EC2-3-681x326.png 681w\" sizes=\"(max-width: 1068px) 100vw, 1068px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/AMIEncryption.html#AMIEncryption_\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/AMIEncryption.html#AMIEncryption<\/span><\/a><\/p>\n<hr \/>\n<p><em><strong>9) Organization XYZ is planning to build an online chat application for their enterprise level collaboration for their employees across the world. They are looking for a single digit latency fully managed database to store and retrieve conversations. What would AWS Database service you recommend?<\/strong><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. AWS DynamoDB<br \/>\nB. AWS RDS<br \/>\nC. AWS Redshift<br \/>\nD. AWS Aurora<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\">Answer: A<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67241\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-1.png\" alt=\"\" width=\"705\" height=\"80\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-1.png 705w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-1-300x34.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-1-640x73.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-1-681x77.png 681w\" sizes=\"(max-width: 705px) 100vw, 705px\" \/><\/p>\n<p>Read more here: <a href=\"https:\/\/aws.amazon.com\/dynamodb\/#whentousedynamodb\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/dynamodb\/#whentousedynamodb<\/a><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67242\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-2.png\" alt=\"\" width=\"714\" height=\"286\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-2.png 714w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-2-300x120.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-2-640x256.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Database-2-681x273.png 681w\" sizes=\"(max-width: 714px) 100vw, 714px\" \/><\/p>\n<p>Read more here: <a href=\"https:\/\/aws.amazon.com\/about-aws\/whats-new\/2015\/07\/amazon-dynamodb-available-now-cross-region-replication-triggers-and-streams\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/about-aws\/whats-new\/2015\/07\/amazon-dynamodb-available-now-cross-region-replication-triggers-and-streams\/<\/a><\/p>\n<p><em><strong>11) Which of the following statements are true with respect to VPC? (choose multiple)<\/strong><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. A subnet can have multiple route tables associated with it.<br \/>\nB. A network ACL can be associated with multiple subnets.<br \/>\nC. A route with target \u201clocal\u201d on the route table can be edited to restrict traffic within VPC.<br \/>\nD. Subnet\u2019s IP CIDR block can be same as the VPC CIDR block.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\">Answer: B, D<\/span><\/p>\n<p>Option A is not correct. A subnet can have only one route table associated with it.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67253\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-1.png\" alt=\"\" width=\"723\" height=\"201\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-1.png 723w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-1-300x83.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-1-640x178.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-1-681x189.png 681w\" sizes=\"(max-width: 723px) 100vw, 723px\" \/><\/p>\n<p>Option B is correct.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67254\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-2.png\" alt=\"\" width=\"659\" height=\"206\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-2.png 659w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-2-300x94.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-2-640x200.png 640w\" sizes=\"(max-width: 659px) 100vw, 659px\" \/><\/p>\n<p>Option C is not correct.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67255\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-3.png\" alt=\"\" width=\"716\" height=\"102\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-3.png 716w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-3-300x43.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-3-640x91.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-3-681x97.png 681w\" sizes=\"(max-width: 716px) 100vw, 716px\" \/><\/p>\n<p>Option D is correct.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67256\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-4.png\" alt=\"\" width=\"745\" height=\"370\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-4.png 745w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-4-300x149.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-4-640x318.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-4-681x338.png 681w\" sizes=\"(max-width: 745px) 100vw, 745px\" \/><\/p>\n<p>Aspired to learn AWS? Here we bring the <a href=\"https:\/\/www.whizlabs.com\/blog\/aws-cheat-sheet\/\" target=\"_blank\" rel=\"noopener\">AWS CHEAT SHEET<\/a> that will take you through cloud Computing and AWS basics along with AWS products and services!<\/p>\n<hr \/>\n<p><em><strong>12) Organization ABC has a customer base in the US and Australia that would be downloading 10s of GBs files from your application. For them to have a better download experience, they decided to use the AWS S3 bucket with cross-region replication with the US as the source and Australia as the destination. They are using existing unused S3 buckets and had set up cross-region replication successfully. However, when files uploaded to the US bucket, they are not being replicated to Australia bucket. What could be the reason?<\/strong><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. Versioning is not enabled on the source and destination buckets.<br \/>\nB. Encryption is not enabled on the source and destination buckets.<br \/>\nC. Source bucket has a policy with DENY and the role used for replication is not excluded from DENY.<br \/>\nD. Destination bucket\u2019s default CORS policy does not have source bucket added as the origin.<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\">Answer: C<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67260\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-1.png\" alt=\"\" width=\"699\" height=\"146\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-1.png 699w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-1-300x63.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-1-640x134.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-1-681x142.png 681w\" sizes=\"(max-width: 699px) 100vw, 699px\" \/><\/p>\n<p>When you have a bucket policy which has explicit DENY, you must exclude all IAM resources which need to access the bucket.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67261\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-2.png\" alt=\"\" width=\"710\" height=\"404\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-2.png 710w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-2-300x171.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-2-640x364.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-2-681x387.png 681w\" sizes=\"(max-width: 710px) 100vw, 710px\" \/><\/p>\n<p>Read more here: <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/how-to-create-a-policy-that-whitelists-access-to-sensitive-amazon-s3-buckets\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/aws.amazon.com\/blogs\/security\/how-to-create-a-policy-that-whitelists-access-to-sensitive-amazon-s3-buckets\/<\/a><\/p>\n<p>For option A, Cross region replication cannot be enabled without enabling versioning. The question states that cross-region replication has been successfully enabled. So this option is not correct.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67251\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-3.png\" alt=\"\" width=\"673\" height=\"378\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-3.png 673w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-3-300x168.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-S3-3-640x359.png 640w\" sizes=\"(max-width: 673px) 100vw, 673px\" \/><\/p>\n<hr \/>\n<p><em><b>13) Which of the following is not a category in AWS Trusted Advisor service checks?<\/b><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. Cost Optimization<br \/>\nB. Fault Tolerance<br \/>\nC. Service Limits<br \/>\nD. Network Optimization<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> D<\/span><\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67252\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Trusted-Advisor-1.png\" alt=\"AWS Trusted Advisor\" width=\"683\" height=\"372\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Trusted-Advisor-1.png 683w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Trusted-Advisor-1-300x163.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Trusted-Advisor-1-640x350.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Trusted-Advisor-1-681x372.png 681w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/premiumsupport\/trustedadvisor\/\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/aws.amazon.com\/premiumsupport\/trustedadvisor\/<\/span><\/a><\/p>\n<p><em><b>17) How many VPCs can an Internet Gateway be attached to at any given time?<\/b><\/em><\/p>\n<p><b>A. 2<br \/>\n<\/b><b>B. 5<br \/>\n<\/b><b>C. 1<br \/>\n<\/b><b>D. By default 1. But it can be attached to any VPC peered with its belonging VPC.<\/b><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> C<\/span><\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67257\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-5.png\" alt=\"\" width=\"666\" height=\"256\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-5.png 666w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-5-300x115.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-5-640x246.png 640w\" sizes=\"(max-width: 666px) 100vw, 666px\" \/><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/amazon-vpc-limits.html#vpc-limits-gateways\" target=\"_blank\" rel=\"nofollow noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/AmazonVPC\/latest\/UserGuide\/amazon-vpc-limits.html#vpc-limits-gateways<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">At any given time, an Internet Gateway can be attached to only one VPC. It can be detached from the VPC and be used for another VPC.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67258\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-6.png\" alt=\"\" width=\"583\" height=\"233\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-6.png 583w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-6-300x120.png 300w\" sizes=\"(max-width: 583px) 100vw, 583px\" \/><\/p>\n<p><em><b>19) Which of the following are not backup and restore solutions provided by AWS? (choose multiple)<\/b><\/em><\/p>\n<p style=\"padding-left: 40px;\">A. AWS Elastic Block Store<br \/>\nB. AWS Storage Gateway<br \/>\nC. AWS Elastic Beanstalk<br \/>\nD. AWS Database Migration Hub<br \/>\nE. AWS CloudFormation<\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> C, E<\/span><\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67267\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-1.png\" alt=\"\" width=\"645\" height=\"535\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-1.png 645w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-1-300x249.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-1-506x420.png 506w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-1-640x531.png 640w\" sizes=\"(max-width: 645px) 100vw, 645px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Option A is snapshot based data backup solution.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67268\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-2.png\" alt=\"\" width=\"625\" height=\"287\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-2.png 625w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-2-300x138.png 300w\" sizes=\"(max-width: 625px) 100vw, 625px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Option B, AWS Storage Gateway provides multiple solutions for backup &amp; recovery.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67269\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-3.png\" alt=\"\" width=\"580\" height=\"584\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-3.png 580w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-3-150x150.png 150w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-3-298x300.png 298w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-3-417x420.png 417w\" sizes=\"(max-width: 580px) 100vw, 580px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Option D can be used as a Database backup solution.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67270\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-4.png\" alt=\"\" width=\"572\" height=\"295\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-4.png 572w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Backup-Recovery-4-300x155.png 300w\" sizes=\"(max-width: 572px) 100vw, 572px\" \/><\/p>\n<p><b><i>25) Which of the following is an AWS component which consumes resources from your VPC?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">A. Internet Gateway<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">B. Gateway VPC Endpoints<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">C. Elastic IP Addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">D. NAT Gateway<\/span><\/p>\n<p><span class=\"td_btn td_btn_sm td_default_btn\"><b>Answer:<\/b><span style=\"font-weight: 400;\"> D<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option A is not correct.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67277\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-6-1.png\" alt=\"\" width=\"474\" height=\"338\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-6-1.png 474w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-6-1-300x214.png 300w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">An internet gateway is an AWS component which sits outside of your VPC does not consume any resources from your VPC.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option B is not correct.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Endpoints are virtual devices. They are horizontally scaled, redundant, and highly available VPC components that allow communication between instances in your VPC and services without imposing availability risks or bandwidth constraints on your network traffic.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67278\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-7.png\" alt=\"\" width=\"495\" height=\"282\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-7.png 495w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-7-300x171.png 300w\" sizes=\"(max-width: 495px) 100vw, 495px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Option C is not correct.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">An Elastic IP address is a static, public IPv4 address designed for dynamic cloud computing. You can associate an Elastic IP address with any instance or network interface for any VPC in your account. With an Elastic IP address, you can mask the failure of an instance by rapidly remapping the address to another instance in your VPC.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">They do not belong to a single VPC.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Option D is correct.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To create a NAT gateway, you must specify the public subnet in which the NAT gateway should reside. For more information about public and private subnets, see Subnet Routing. You must also specify an Elastic IP address to associate with the NAT gateway when you create it. After you&#8217;ve created a NAT gateway, you must update the route table associated with one or more of your private subnets to point Internet-bound traffic to the NAT gateway. This enables instances in your private subnets to communicate with the internet.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-67279\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-8.png\" alt=\"\" width=\"508\" height=\"399\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-8.png 508w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-VPC-8-300x236.png 300w\" sizes=\"(max-width: 508px) 100vw, 508px\" \/><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions_FAQs\"><\/span>Frequently Asked Questions (FAQs)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>How many questions are on AWS\u00a0 Solution Architect Associate exam?<\/strong><\/p>\n<p>The number of questions in the AWS Architect exam is around 60-70. This number could be varry.<\/p>\n<p><strong>What is passing score for AWS?<\/strong><\/p>\n<p>The passing score of the exam is around 70-75%. AWS doesn&#8217;t officially announce the passing score, but these are based on the exam taker&#8217;s experience.<\/p>\n<p><strong>Is AWS Associate Solutions Architect exam hard?<\/strong><\/p>\n<p>Not very tough. When you compare to Cloud Practitioner exam, it&#8217;s harder. However, compare to the SysOps exam, it&#8217;s easier.<\/p>\n<p><strong>How many questions are on the AWS Solutions Architect Associate exam?<\/strong><\/p>\n<p>The number of questions in the AWS Architect exam is around 60-70. This number could be varry.<\/p>\n<div id=\"exacc_VTPyYeenOsLmz7sP4pOIsAE3\" class=\"iDjcJe IX9Lgd wwB5gf\"><strong>Can I pass AWS Solution Architect Associate?<\/strong><\/div>\n<div>Yes. Anyone can pass the AWS Solutions Architect Associate exam with the proper preparation and practice using sample questions from Whizlabs. Whizlabs offering 765 practice questions that are very detailed in the explanations would help you to pass the certification exam in the first attempt. You can also try the free tests.<\/div>\n<div><\/div>\n<div><strong>Which AWS exam is hardest?<\/strong><\/div>\n<div>\n<div aria-hidden=\"true\">\n<div class=\"group w-full text-gray-800 dark:text-gray-100 border-b border-black\/10 dark:border-gray-900\/50 bg-gray-50 dark:bg-[#444654]\">\n<div class=\"text-base gap-4 md:gap-6 md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0 m-auto\">\n<div class=\"relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]\">\n<div class=\"flex flex-grow flex-col gap-3\">\n<div class=\"min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap\">\n<div class=\"markdown prose w-full break-words dark:prose-invert light\">\n<p>AWS Architect Professional certification is considered as hardest and\u00a0 most prestigious cloud certification. Achieving this certification requires a deep understanding and expertise of the AWS cloud platform, making it a highly challenging and sought-after certification.<\/p>\n<div class=\"JlqpRe\"><strong><span class=\"JCzEY ZwRhJd\">How long is AWS Solution Architect Associate certification valid?<\/span><\/strong><\/div>\n<div class=\"aj35ze\">AWS Solution Architect Associate certification valid for three years and it needs to be recertification to continue the expertise level.<\/div>\n<div><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div id=\"exacc_3BzmY8aRJ8y15NoPt4m_iAI_2\" class=\"iDjcJe IX9Lgd wwB5gf\" aria-hidden=\"true\"><strong>Is AWS Solution Architect Associate worth it?<\/strong><\/div>\n<div aria-hidden=\"true\"><span style=\"font-size: 16px;\">Yes, the AWS Certified Solutions Architect &#8211; Associate certification is worth it for several reasons:<\/span><\/div>\n<div aria-hidden=\"true\">\n<ol>\n<li>Recognition: The AWS certification is one of the most recognized and respected certifications in the cloud computing industry.<\/li>\n<li>Career Opportunities: The AWS certification can help individuals demonstrate their knowledge of AWS and increase their chances of landing a job or promotion in the cloud computing field.<\/li>\n<li>Hands-on Experience: Preparing for the AWS certification requires hands-on experience working with AWS services and solutions, which can be valuable in and of itself.<\/li>\n<li>Keeping Up with the Latest Trends: The AWS certification requires individuals to stay up-to-date with the latest trends and best practices in cloud computing, which can be beneficial for their careers and organizations.<\/li>\n<li>Increased Earnings Potential: Individuals with AWS certifications often command higher salaries and have better job prospects compared to those without certifications.<\/li>\n<\/ol>\n<div id=\"exacc_3BzmY8aRJ8y15NoPt4m_iAI_7\" class=\"iDjcJe IX9Lgd wwB5gf\" aria-hidden=\"true\"><strong>Does AWS Solution Architect Associate require coding?<\/strong><\/div>\n<div aria-hidden=\"true\">The AWS Certified Solutions Architect &#8211; Associate certification exam does not require extensive coding skills, but it does test the candidate&#8217;s understanding of AWS services and how they can be used to build secure, scalable, and highly available solutions.<\/div>\n<div aria-hidden=\"true\"><\/div>\n<div aria-hidden=\"true\">It&#8217;s important to note that the exam primarily focuses on the design and implementation of AWS solutions, not on writing code. Candidates should familiarize themselves with AWS services, their use cases, and the best practices for designing, deploying, and operating solutions on AWS.<\/div>\n<\/div>\n<\/div>\n<div class=\"YsGUOb\"><\/div>\n<div>\n<div id=\"exacc_VTPyYeenOsLmz7sP4pOIsAE1\" class=\"iDjcJe IX9Lgd wwB5gf\"><strong>How do I prepare for AWS Solution Architect exam?<\/strong><\/div>\n<div>Here is the very detailed steps on <a href=\"https:\/\/www.whizlabs.com\/blog\/aws-certified-solutions-architect-associate\/\" target=\"_blank\" rel=\"noopener\">how to prepare for the AWS Solutions Architect Certification Exam<\/a>. This would definitely help you.<\/div>\n<div>Below is the snapshot of what&#8217;s covered in the Whizlabs courses. This will definitely help you.<\/div>\n<div><img decoding=\"async\" class=\"size-large wp-image-81120 aligncenter\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training-1024x540.png\" alt=\"Whizlabs Solutions Architect Course Contents\" width=\"640\" height=\"338\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training-1024x540.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training-300x158.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training-768x405.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training-1536x810.png 1536w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training-796x420.png 796w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training-640x338.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training-681x359.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2021\/06\/whizlabs-solutions-architect-exam-training.png 1960w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/div>\n<div><strong>Whether Hands-on Labs in the Solutions Architect certification Exam?<\/strong><\/div>\n<\/div>\n<div>No. As of now, only <a href=\"https:\/\/www.whizlabs.com\/blog\/aws-sysops-certification\/\" target=\"_blank\" rel=\"noopener\">SysOps Certification Exam has the Hands-on Labs<\/a>.<\/div>\n<div><\/div>\n<h3><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"font-weight: 400;\">So, here we&#8217;ve presented 50+ Free AWS Solutions Architect exam questions for the<\/span> <span style=\"font-weight: 400;\">AWS associate certification<\/span><span style=\"font-weight: 400;\"> exam. Definitely, these AWS CSAA practice questions\u00a0 would have helped you to check your preparation level and boost your confidence for the exam. We, at Whizlabs, are aiming to prepare you for the<\/span> <span style=\"font-weight: 400;\">AWS Solution Architect Associate exam<\/span><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-tips\/\" target=\"_blank\" rel=\"noopener\"> (SAA-C03)<\/a>.<\/span><\/p>\n<p>Note that these are not aws certification exam dumps. This AWS Solutions Architect Associate practice questions are real exam simulators that would help you to pass the exam in the first attempt. Buying aws exam dumps or brain dumps are not a good idea to pass the exam.<\/p>\n<p>Here is the list of practice questions offered by Whizlabs. These are created by certified experts.<\/p>\n<p><img decoding=\"async\" class=\"size-large wp-image-80613 aligncenter\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628-1024x612.png\" alt=\"CSAA Exam Practice Questions\" width=\"640\" height=\"383\" srcset=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628-1024x612.png 1024w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628-300x179.png 300w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628-768x459.png 768w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628-1536x918.png 1536w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628-703x420.png 703w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628-640x382.png 640w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628-681x407.png 681w, https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2016\/11\/image_2022-01-01_060628.png 1864w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/p>\n<p><strong>If you have any questions about our aws csaa exam questions, please contact our support at support@whizlabs.com.<\/strong><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Preparing for the AWS Certified Solutions Architect Associate Exam? Here we&#8217;ve a list of \u00a0free AWS Solutions Architect Exam Questions and Answers for you to prepare well for the AWS Solution Architect exam. This practice exam questions are very similar to the practice questions in the real exam format. AWS certification training plays an important role in the journey of AWS certification preparation as it validates your skills in depth. Also, the aws practice questions play an important role in getting you ready for the real time examination. If you are planning to prepare for the AWS architect certification, you [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":79257,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[4932],"class_list":["post-67239","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aws-certifications","tag-saa-c03-exam"],"uagb_featured_image_src":{"full":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",600,315,false],"thumbnail":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers-150x150.png",150,150,true],"medium":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers-300x158.png",300,158,true],"medium_large":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",600,315,false],"large":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",600,315,false],"1536x1536":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",600,315,false],"2048x2048":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",600,315,false],"profile_24":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",24,13,false],"profile_48":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",48,25,false],"profile_96":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",96,50,false],"profile_150":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",150,79,false],"profile_300":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",300,158,false],"tptn_thumbnail":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers-250x250.png",250,250,true],"web-stories-poster-portrait":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",600,315,false],"web-stories-publisher-logo":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",96,50,false],"web-stories-thumbnail":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS-Solutions-Architect-Associate-Exam-Free-Questions-Answers.png",150,79,false]},"uagb_author_info":{"display_name":"Pavan Gumaste","author_link":"https:\/\/www.whizlabs.com\/blog\/author\/pavan\/"},"uagb_comment_info":1643,"uagb_excerpt":"Preparing for the AWS Certified Solutions Architect Associate Exam? Here we&#8217;ve a list of \u00a0free AWS Solutions Architect Exam Questions and Answers for you to prepare well for the AWS Solution Architect exam. This practice exam questions are very similar to the practice questions in the real exam format. AWS certification training plays an important&hellip;","_links":{"self":[{"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/posts\/67239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/comments?post=67239"}],"version-history":[{"count":96,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/posts\/67239\/revisions"}],"predecessor-version":[{"id":100184,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/posts\/67239\/revisions\/100184"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/media\/79257"}],"wp:attachment":[{"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/media?parent=67239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/categories?post=67239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/tags?post=67239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}