When working with Amazon RDS, by default AWS is responsible for implementing which two management-related activities? (Pick 2 correct answers)
Importing data and optimizing queries
Installing and periodically patching the database software
Creating and maintaining automated database backups with a point-in-time recovery of up to five minutes
Creating and maintaining automated database backups in compliance with regulatory long-term retention requirements
You maintain an application on AWS to provide development and test platforms for your developers.
Currently both environments consist of an m1.small EC2 instance. Your developers notice performance degradation as they increase network load in the test environment.
How would you mitigate these performance issues in the test environment?
Upgrade the m1.small to a larger instance type
Add an additional ENI to the test instance
Use the EBS optimized option to offload EBS traffic
Configure Amazon Cloudwatch to provision more network bandwidth when network utilization exceeds 80%
解析：添加ENI并不会增加带宽；m1.small机器类型没有EBS optimized option;network utilisation与机器类型相关，无法对m1.small provision更多的带宽
Per the AWS Acceptable Use Policy, penetration testing of EC2 instances:
may be performed by the customer against their own instances, only if performed from EC2 instances.
may be performed by AWS, and is periodically performed by AWS.
may be performed by AWS, and will be performed by AWS upon customer request.
are expressly prohibited under all circumstances.
may be performed by the customer against their own instances with prior authorization from AWS.
You have been tasked with identifying an appropriate storage solution for a NoSQL database that requires random I/O reads of greater than 100,000 4kB IOPS.
Which EC2 option will meet this requirement?
EBS provisioned IOPS
SSD instance store
EBS optimized instances
High Storage instance configured in RAID 10
解析：这道题只有SSD instance store能提供10万的IOPS
Instance A and instance B are running in two different subnets A and B of a VPC. Instance A is not able to ping instance B.
What are two possible reasons for this? (Pick 2 correct answers)
The routing table of subnet A has no target route to subnet B
The security group attached to instance B does not allow inbound ICMP traffic
The policy linked to the IAM role on instance A is not configured correctly
The NACL on subnet B does not allow outbound ICMP traffic
Your web site is hosted on 10 EC2 instances in 5 regions around the globe with 2 instances per region.
How could you configure your site to maintain site availability with minimum downtime if one of the 5 regions was to lose network connectivity for an extended period of time?
Create an Elastic Load Balancer to place in front of the EC2 instances. Set an appropriate health check on each ELB.
Establish VPN Connections between the instances in each region. Rely on BGP to failover in the case of a region wide connectivity outage
Create a Route 53 Latency Based Routing Record Set that resolves to an Elastic Load Balancer in each region. Set an appropriate health check on each ELB.
Create a Route 53 Latency Based Routing Record Set that resolves to Elastic Load Balancers in each region and has the Evaluate Target Health flag set to true.
解析：只有开启了Evaluate Target Health flag，Route53才会根据健康情况进行路由
You run a stateless web application with the following components: Elastic Load Balancer (ELB), 3 Web/Application servers on EC2, and 1 MySQL RDS database with 5000 Provisioned IOPS. Average response time for users is increasing. Looking at CloudWatch, you observe 95% CPU usage on the Web/Application servers and 20% CPU usage on the database. The average number of database disk operations varies between 2000 and 2500.
Which two options could improve response times? (Pick 2 correct answers)
Choose a different EC2 instance type for the Web/Application servers with a more appropriate CPU/memory ratio
Use Auto Scaling to add additional Web/Application servers based on a CPU load threshold
Increase the number of open TCP connections allowed per web/application EC2 instance
Use Auto Scaling to add additional Web/Application servers based on a memory usage threshold
Which features can be used to restrict access to data in S3? (Pick 2 correct answers)
Create a CloudFront distribution for the bucket.
Set an S3 bucket policy.
Use S3 Virtual Hosting.
Set an S3 ACL on the bucket or the object.
Enable IAM Identity Federation.
You need to establish a backup and archiving strategy for your company using AWS. Documents should be immediately accessible for 3 months and available for 5 years for compliance reasons.
Which AWS service fulfills these requirements in the most cost effective way?
Use StorageGateway to store data to S3 and use life-cycle policies to move the data into Redshift for long-time archiving
Use DirectConnect to upload data to S3 and use IAM policies to move the data into Glacier for longtime archiving
Upload the data on EBS, use life-cycle policies to move EBS snapshots into S3 and later into Glacier for long-time archiving
Upload data to S3 and use life-cycle policies to move the data into Glacier for long-time archiving
Given the following IAM policy:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
What does the IAM policy allow? (Pick 3 correct answers)
The user is allowed to read objects from all S3 buckets owned by the account
The user is allowed to write objects into the bucket named ‘corporate_bucket’
The user is allowed to change access rights for the bucket named ‘corporate_bucket’
The user is allowed to read objects in the bucket named ‘corporate_bucket’ but not allowed to list the objects in the bucket
The user is allowed to read objects from the bucket named ‘corporate_bucket’
答案：A B E