A) Create an AMI from the volume and share the AMI
B) Copy the data to an unencrypted volume and then share
C) Take a snapshot and share the snapshot with a friend
D) If both the accounts are using the same encryption key then the user can share the volume directly
Correct Answer
verified
Multiple Choice
A) SendMessageBatch
B) DeleteMessageBatch
C) CreateQueue
D) DeleteMessageQueue
Correct Answer
verified
Multiple Choice
A) The policy allows the IAM user to modify all IAM user's credentials using the console, SDK, CLI or APIs
B) The policy will give an invalid resource error
C) The policy allows the IAM user to modify all credentials using only the console
D) The policy allows the user to modify all IAM user's password, sign in certificates and access keys using only CLI, SDK or APIs
Correct Answer
verified
Multiple Choice
A) Implement AWS KMS and integrate with the existing on-premises asymmetrical key management system
B) Implement AWS CloudHSM and integrate it with the existing key management infrastructure
C) Deploy an Amazon EC2 instance and choose an AMI from an AWS partner in the AWS Marketplace
D) Create a master key in AWS KMS, and export that key to the existing on-premises asymmetrical key management system
Correct Answer
verified
Multiple Choice
A) The instances will not be registered with ELB and the user has to manually register when the process is resumed
B) The instances will be registered with ELB only once the process has resumed
C) Auto Scaling will not launch the instance during this period due to process suspension
D) It is not possible to suspend only the AddToLoadBalancer process
Correct Answer
verified
Multiple Choice
A) The IP address may be attached to one of the instances
B) The IP address belongs to a different zone than the subnet zone
C) The user has not created an internet gateway
D) The IP addresses belong to EC2 Classic; so they cannot be assigned to VPC
Correct Answer
verified
Multiple Choice
A) The policy allows the IAM user to modify all IAM users' access keys using the console, SDK, CLI or APIs
B) The policy allows the IAM user to modify all IAM users' credentials using the console, SDK, CLI or APIs
C) The policy allows the IAM user to modify all credentials using only the console
D) The policy allows the IAM user to modify the IAM user's own credentials using the console, SDK, CLI or APIs
Correct Answer
verified
Multiple Choice
A) Auto Scaling will not launch or terminate any instances
B) Auto Scaling will allow the instances to grow more than the maximum size
C) Auto Scaling will keep launching instances till the maximum instance size
D) It is not possible to suspend the terminate process while keeping the launch active
Correct Answer
verified
Multiple Choice
A) Work with AWS support to schedule a tour for the auditors.
B) Send a copy of the AWS Security whitepaper to the auditors.
C) Obtain a relevant report from AWS Artifact and share it with the auditors.
D) Find the address for the AWS Direct Connect facility on the AWS Website.
Correct Answer
verified
Multiple Choice
A) Use Dedicated Hosts for the control nodes.
B) Use Reserved Instances for the control nodes.
C) Use Reserved Instances for the worker nodes.
D) Use Spot Instances for the control nodes and On-Demand Instances if there is no Spot availability.
E) Use Spot Instances for the worker nodes and On-Demand Instances if there is no Spot availability.
Correct Answer
verified
Multiple Choice
A) Set up MFA Delete on all the S3 buckets to prevent the buckets from being ddeleted.
B) Use service control policies to deny the s3:DeleteBucket action on all buckets in production accounts. Use service control policies to deny the s3:DeleteBucket action on all buckets in production accounts.
C) Create an IAM group that has an IAM policy to deny the s3:DeleteBucket action on all buckets in production accounts. Create an IAM group that has an IAM policy to deny the
D) Use AWS Shield to deny the s3:DeleteBucket action on the AWS account instead of all S3 buckets. Use AWS Shield to deny the action on the AWS account instead of all S3 buckets.
Correct Answer
verified
Multiple Choice
A) The server side encryption with the user supplied key works when versioning is enabled
B) The user can use the AWS console, SDK and APIs to encrypt or decrypt the content for server side encryption with the user supplied key
C) The user must send an AES-128 encrypted key
D) The user can upload his own encryption key to the S3 console
Correct Answer
verified
Multiple Choice
A) Configure AWS Database Migration Service (AWS DMS) to allow Amazon RDS for MySQL to scale and accept more requests.
B) Configure RDS for MySQL to scale horizontally by adding additional nodes to offload write requests.
C) Enable the Multi-AZ feature for the RDS instance.
D) Modify the RDS MySQL instance so it is a larger instance type.
Correct Answer
verified
Multiple Choice
A) The private and public address remains the same
B) The Elastic IP remains associated with the instance
C) The volume is preserved
D) The instance runs on a new host computer
Correct Answer
verified
Multiple Choice
A) Resources tags defined in the CloudFormation template are specific to the us-east-1 Region.
B) The Amazon Machine Image (AMI) ID referenced in the CloudFormation template could not be found in the us-west-2 Region.
C) The cfn-init script did not execute during resource provisioning in the us-west-2 Region.
D) The IAM user was not created in the specified Region.
Correct Answer
verified
Multiple Choice
A) Shut down the EC2 instance. Enable multi-AZ replication within the EC2 instance, then restart the instance.
B) Launch a secondary EC2 instance running MySQL. Configure a cron job that backs up the database on the primary EC2 instance and copies it to the secondary instance every 30 minutes.
C) Migrate the database to an Amazon RDS Aurora DB instance and create a Read Replica in another Availability Zone.
D) Create an Amazon RDS Microsoft SQL DB instance and enable multi-AZ replication. Back up the existing data and import it into the new database.
Correct Answer
verified
Multiple Choice
A) AWS Simple Notification Service
B) AWS Simple Workflow
C) AWS Simple Queue Service
D) AWS Simple Query Service
Correct Answer
verified
Multiple Choice
A) Yes, the AWS Application Clusters.
B) No, you can only use the available software development kits.
C) Yes, the AWS Management Console.
D) No, you can only use the command line interface.
Correct Answer
verified
Multiple Choice
A) Confirm from the cfn logs that the cfn-signal command was successfully run on the instance.
B) Try to re-create the stack with a different IAM user.
C) Check that the instance has a route to the Internet through a NAT device.
D) Update the AWS CloudFormation stack service role to have iam:PassRole permission.
E) Delete the existing stack and attempt to create a new once.
Correct Answer
verified
Multiple Choice
A) Amazon S3 bucket.
B) Amazon EBS.
C) Amazon Edge locations.
D) Amazon EC2 instance.
Correct Answer
verified
Showing 341 - 360 of 976
Related Exams