A) Use an AWS Storage Gateway tape gateway to copy the on-premises files into Amazon S3.
B) Use an AWS Storage Gateway volume gateway to copy the on-premises files into Amazon S3.
C) Use an AWS Storage Gateway file gateway to copy the on-premises files to Amazon Elastic Block Store (Amazon EBS) .
D) Attach an Amazon Elastic File System (Amazon EFS) file system to the on-premises servers. Copy the files to Amazon EFS.
Correct Answer
verified
Multiple Choice
A) Migrate the file server to an Amazon EC2 instance in a public subnet. Configure the security group to limit inbound traffic to the employees' IP addresses.
B) Migrate the files to an Amazon FSx for Windows File Server file system. Integrate the Amazon FSx file system with the on-premises Active Directory. Configure AWS Client VPN.
C) Migrate the files to Amazon S3, and create a private VPC endpoint. Create a signed URL to allow download.
D) Migrate the files to Amazon S3, and create a public VPC endpoint. Allow employees to sign on with AWS Single Sign-On.
Correct Answer
verified
Multiple Choice
A) Add a secondary DB instance using Multi-AZ.
B) Set up a road replica and Multi-AZ on Amazon RDS.
C) Set up a standby replica and Multi-AZ on Amazon RDS.
D) Use caching on Amazon RDS to improve the overall performance.
Correct Answer
verified
Multiple Choice
A) AWS CloudHSM with the CloudHSM client
B) AWS Key Management Service (AWS KMS) with AWS CloudHSM
C) AWS Key Management Service (AWS KMS) with an external key material origin
D) AWS Key Management Service (AWS KMS) with AWS managed customer master keys (CMKs)
Correct Answer
verified
Multiple Choice
A) Use AWS Secrets Manager with customer master keys (CMKs) to store master key material and apply a routine to create a new CMK periodically and replace it in AWS Secrets Manager.
B) Use AWS Key Management Service (AWS KMS) with customer master keys (CMKs) to store master key material and apply a routine to re-create a new key periodically and replace it in AWS KMS.
C) Use an AWS CloudHSM cluster with customer master keys (CMKs) to store master key material and apply a routine to re-create a new key periodically and replace it in the CloudHSM cluster nodes.
D) Use AWS Systems Manager Parameter Store with customer master keys (CMKs) to store master key material and apply a routine to re-create a new key periodically and replace it in the Parameter Store.
Correct Answer
verified
Multiple Choice
A) Amazon EBS
B) Amazon EFS
C) Amazon EC2 instance store
D) Amazon S3
Correct Answer
verified
Multiple Choice
A) Set up AWS Global Accelerator and add endpoints.
B) Set up AWS Direct Connect locations in multiple Regions.
C) Set up an Amazon CloudFront distribution to access an application.
D) Set up an Amazon Route 53 geoproximity routing policy to route traffic.
Correct Answer
verified
Multiple Choice
A) Use the CreateQueue API call to create a new queue.
B) Use the AddPermission API call to add appropriate permissions.
C) Use the ReceiveMessage API call to set an appropriate wait time.
D) Use the ChangeMessageVisibility API call to increase the visibility timeout.
Correct Answer
verified
Multiple Choice
A) Create two policy documents using the AWS Management Console in each account. Assign the policy to developers who need access.
B) Create an IAM role in the Development account. Give one IAM role access to the Production account. Allow developers to assume the role.
C) Create an IAM role in the Production account with the trust policy that specifies the Development account. Allow developers to assume the role.
D) Create an IAM group in the Production account and add it as a principal in the trust policy that specifies the Production account. Add developers to the group.
Correct Answer
verified
Multiple Choice
A) Use Amazon FSx for Windows File Server
B) Use Amazon Elastic File System (Amazon EFS)
C) Use AWS Storage Gateway in file gateway mode.
D) Deploy a Windows file server on two On Demand instances across two Availability Zones.
Correct Answer
verified
Multiple Choice
A) A Network Load Balancer with an associated Elastic IP address.
B) An Application Load Balancer with an associated Elastic IP address
C) An A record in an Amazon Route 53 hosted zone pointing to an Elastic IP address
D) An EC2 instance with a public IP address running as a proxy in front of the load balancer
Correct Answer
verified
Multiple Choice
A) Configure an accelerator in AWS Global Accelerator. Add a listener for the port that the application listens on and attach it to a Regional endpoint in each Region. Add the ALB as the endpoint.
B) Create an Amazon CloudFront distribution and specify the ALB as the origin server. Configure the cache behavior to use origin cache headers. Use AWS Lambda functions to optimize the traffic.
C) Create an Amazon CloudFront distribution and specify Amazon S3 as the origin server. Configure the cache behavior to use origin cache headers. Use AWS Lambda functions to optimize the traffic.
D) Configure an Amazon DynamoDB database to serve as the data store for the application. Create a DynamoDB Accelerator (DAX) cluster to act as the in-memory cache for DynamoDB hosting the application data.
Correct Answer
verified
Multiple Choice
A) Create a security group with a rule to allow TCP port 443 from source 0.0.0.0/0.
B) Create a security group with a rule to allow TCP port 443 to destination 0.0.0.0/0.
C) Update the network ACL to allow TCP port 443 from source 0.0.0.0/0.
D) Update the network ACL to allow inbound/outbound TCP port 443 from source 0.0.0.0/0 and to destination 0.0.0.0/0.
E) Update the network ACL to allow inbound TCP port 443 from source 0.0.0.0/0 and outbound TCP port 32768-65535 to destination 0.0.0.0/0.
Correct Answer
verified
Multiple Choice
A) Attach the kms:decrypt permission to the Lambda function's resource policy.
B) Grant the decrypt permission for the Lambda IAM role in the KMS key's policy.
C) Grant the decrypt permission for the Lambda resource policy in the KMS key's policy.
D) Create a new IAM policy with the kms:decrypt permission and attach the policy to the Lambda function.
E) Create a new IAM role with the kms:decrypt permission and attach the execution role to the Lambda function.
Correct Answer
verified
Multiple Choice
A) Create a separate application tier using EC2 instances dedicated to email processing.
B) Configure the web instance to send email through Amazon Simple Email Service (Amazon SES) .
C) Configure the web instance to send email through Amazon Simple Notification Service (Amazon SNS) .
D) Create a separate application tier using EC2 instances dedicated to email processing. Place the instances in an Auto Scaling group.
Correct Answer
verified
Multiple Choice
A) Amazon Elastic Block Store (Amazon EBS)
B) Amazon Elastic File System (Amazon EFS)
C) Amazon FSx for Windows
D) Amazon S3
E) AWS Storage Gateway file gateway
Correct Answer
verified
Multiple Choice
A) Create an ACL to provide access to the services or actions.
B) Create a security group to allow accounts and attach it to user groups.
C) Create cross-account roles in each account to deny access to the services or actions.
D) Create a service control policy in the root organizational unit to deny access to the services or actions.
Correct Answer
verified
Multiple Choice
A) Deploy a NAT gateway to access the S3 buckets.
B) Deploy AWS Storage Gateway to access the S3 buckets.
C) Deploy an S3 gateway endpoint to access the S3 buckets.
D) Deploy an S3 interface endpoint to access the S3 buckets.
Correct Answer
verified
Multiple Choice
A) AWS DataSync with a VPC endpoint
B) AWS Direct Connect
C) AWS Snowball Edge Storage Optimized
D) AWS Storage Gateway
Correct Answer
verified
Multiple Choice
A) Implement EC2 Spot Instances.
B) Purchase EC2 Reserved Instances.
C) Implement EC2 On-Demand Instances.
D) Implement the processing on AWS Lambda.
Correct Answer
verified
Showing 441 - 460 of 596
Related Exams