28.02.2017 Views

Get Latest And Updated AWS-Solution-Architect-Associate Exam

We offer remarkable preparation material for the Amazon AWS-Solution-Architect-Associate Exam . These Amazon exercise materials are available for applicants who desire to clear the Amazon AWS-Solution-Architect-Associate Exam in the first effort. The Amazon exam demo versions mimic the real exam situation, where you can exercise for the actual exam. For more information: https://www.justcerts.com/amazon/AWS-SOLUTION-ARCHITECT-ASSOCIATE-practice-questions.html

We offer remarkable preparation material for the Amazon AWS-Solution-Architect-Associate Exam . These Amazon exercise materials are available for applicants who desire to clear the Amazon AWS-Solution-Architect-Associate Exam in the first effort. The Amazon exam demo versions mimic the real exam situation, where you can exercise for the actual exam.
For more information:
https://www.justcerts.com/amazon/AWS-SOLUTION-ARCHITECT-ASSOCIATE-practice-questions.html

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Vendor: Amazon<br />

<strong>Exam</strong> Code: <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

<strong>Exam</strong> Name: <strong>AWS</strong> Certified <strong>Solution</strong>s <strong>Architect</strong> ­<br />

<strong>Associate</strong><br />

Related Certification: <strong>AWS</strong> Certified <strong>Solution</strong>s<br />

<strong>Architect</strong><br />

Money Back Guarantee<br />

We provide excellent quality products that designed by Amazon Professionals<br />

to develop a better understanding of actual <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

exam. After using of our <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong> <strong>Exam</strong> Product, if<br />

any candidate fail then will refund their full payment within 7 business days.<br />

Free Updates<br />

Without any additional cost, we provide free updates for 3 months of purchase<br />

of <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong> exam Practice product. These updates<br />

are meant to reflect any changes related to certification exam curriculum or<br />

questions.<br />

Security & Privacy<br />

We are committed to ensure that your information is 100 percent secure. We<br />

use security and privacy measure for our Customer information security. Our<br />

website used security protocols by McAfee and SSL are checked 24/7 for<br />

consistency.<br />

24/7 Support<br />

We are here to help you 24/7 online support and live chat for customers that<br />

have problems. If you face any problem related to <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> <strong>Exam</strong> Preparation product, No worries, we are available to help<br />

you. Contact to our quality dedicated support team.


Real Amazon <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

<strong>Exam</strong> Questions<br />

<strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> <strong>Exam</strong> Bundle<br />

<strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

<strong>Exam</strong> PDF<br />

<strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

Practice Test Software<br />

To get extra 20% discount for<br />

<strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> <strong>Exam</strong> Practice Test,<br />

Use Coupon code (20OFF).


Amazon <strong>AWS</strong>­<strong>Solution</strong>­<br />

<strong>Architect</strong>­<strong>Associate</strong> PDF<br />

Format<br />

PDF version of <strong>AWS</strong> Certified <strong>Solution</strong>s<br />

<strong>Architect</strong> ­ <strong>Associate</strong> <strong>AWS</strong>­<strong>Solution</strong>­<br />

<strong>Architect</strong>­<strong>Associate</strong> exam questions allows<br />

you to determine your strength and area of<br />

practice and provide <strong>AWS</strong> Certified <strong>Solution</strong>s<br />

<strong>Architect</strong> <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

exam training option. Our <strong>AWS</strong> Certified<br />

<strong>Solution</strong>s <strong>Architect</strong> ­ <strong>Associate</strong> <strong>AWS</strong>­<br />

<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong> PDF Practice<br />

Questions Source contains a brief explanation<br />

of every answer, with a standard format for<br />

those who need to store digital documents for<br />

long periods of time. The <strong>AWS</strong> Certified<br />

<strong>Solution</strong>s <strong>Architect</strong> <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> exam assessment such as PDF<br />

information made up of the real <strong>AWS</strong><br />

Certified <strong>Solution</strong>s <strong>Architect</strong> <strong>AWS</strong>­<strong>Solution</strong>­<br />

<strong>Architect</strong>­<strong>Associate</strong> exam concerns<br />

alternatives are available to the customers can<br />

use.<br />

<strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

Practice Test Software<br />

<strong>AWS</strong> Certified <strong>Solution</strong>s <strong>Architect</strong> ­<br />

<strong>Associate</strong> <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

<strong>Exam</strong> Practice Test Software Kit is a Test<br />

Management Software that performs the<br />

computer­based <strong>AWS</strong> Certified <strong>Solution</strong>s<br />

<strong>Architect</strong> ­ <strong>Associate</strong> exam in real <strong>AWS</strong>­<br />

<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong> exam scenario.<br />

Its job to test your <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> <strong>Exam</strong> skills before Real­ time <strong>AWS</strong><br />

Certified <strong>Solution</strong>s <strong>Architect</strong> exam and gives<br />

a detailed explanation for both correct and<br />

incorrect answers. Where you can check your<br />

mistakes and improve them accordingly. The<br />

<strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong> practice<br />

test software is specially designed by<br />

Amazon professionals and it covers all the<br />

components of <strong>AWS</strong> Certified <strong>Solution</strong>s<br />

<strong>Architect</strong> <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

exam syllabus. This increases the quality of<br />

your preparation tremendously.<br />

Satisfied Customers<br />

JustCerts.com is driven by the ambition of<br />

making you succeed. Our training system<br />

offerings emphasize high­quality instruction,<br />

interactive learning, and collaborative study<br />

activities. Our focus on customer<br />

convenience transformed us into a<br />

trustworthy brand. The team members of<br />

JustCerts work with a passion to guarantee<br />

your success and make you prosperous. We<br />

provide Self­Assessment features for<br />

enhanced progress. JustCerts is a globally<br />

accepted Amazon <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> <strong>AWS</strong> Certified <strong>Solution</strong>s <strong>Architect</strong><br />

­ <strong>Associate</strong> <strong>Exam</strong>s source provider with<br />

different unique learning Methods. We have<br />

already facilitated 70,000+ customers. Our<br />

mission is to provide quality <strong>AWS</strong> Certified<br />

<strong>Solution</strong>s <strong>Architect</strong> <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> exams materials, easy to<br />

understand and provide guarantee of success<br />

in certification <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> exams.<br />

20% Extra Discount On <strong>AWS</strong>­<strong>Solution</strong>­<br />

<strong>Architect</strong>­<strong>Associate</strong> Coupon (20OFF)<br />

JustCerts also provides the free demo to<br />

everyone, anytime for the <strong>AWS</strong> Certified<br />

<strong>Solution</strong>s <strong>Architect</strong> <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> <strong>AWS</strong> Certified <strong>Solution</strong>s <strong>Architect</strong><br />

­ <strong>Associate</strong> exam. Just visit the site, register<br />

yourself and download the demo which you<br />

want in <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

PDF or <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<strong>Associate</strong><br />

Practice test software. You can also download<br />

the both at the same time. The purpose of the<br />

demo is to show our quality material to<br />

valuable customers, if you will satisfy with<br />

the demo then you should purchase the<br />

premium file for your <strong>AWS</strong> Certified<br />

<strong>Solution</strong>s <strong>Architect</strong> <strong>AWS</strong>­<strong>Solution</strong>­<strong>Architect</strong>­<br />

<strong>Associate</strong> <strong>AWS</strong> Certified <strong>Solution</strong>s <strong>Architect</strong><br />

­ <strong>Associate</strong> exam. A hefty discount of 30<br />

percent awaits you on each product bundle<br />

purchase that you make. In addition, existing<br />

customers are also surprised every now and<br />

then through tremendous promotional offers.


Questios & Aoswers PDF Page 1<br />

Amazon<br />

<strong>AWS</strong>-SOLUTION-ARCHITECT-<br />

ASSOCIATE <strong>Exam</strong><br />

<strong>AWS</strong> Certified <strong>Solution</strong>s <strong>Architect</strong> - <strong>Associate</strong><br />

Questions & Answers<br />

(Demo Version – Limited Content)<br />

Thaok yiu fir Diwoliadiog <strong>AWS</strong>-SOLUTION-ARCHITECT-<br />

ASSOCIATE exam PDF Demi<br />

Yiu cao alsi try iur <strong>AWS</strong>-SOLUTION-ARCHITECT-ASSOCIATE<br />

practce exam sifware<br />

Diwoliad Free Demi:<br />

http://www.justcerts.com/Amazon/<strong>AWS</strong>-SOLUTION-ARCHITECT-<br />

ASSOCIATE-practice-questions.html<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 2<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 3<br />

Version: 16.0<br />

Question 1<br />

A 3-ter e-cimmerce web applicatio is curreot depliyed io-premises aod will be migrated ti <strong>AWS</strong><br />

fir greater scalability aod elastcity The web server curreotly shares read-ioly data usiog a oetwirk<br />

distributed fle system The app server ter uses a clusteriog mechaoism fir discivery aod shared<br />

sessiio state that depeods io IP multcast The database ter uses shared-stirage clusteriog ti<br />

privide database fall iver capability, aod uses several read slaves fir scaliog Data io all servers aod<br />

the distributed fle system directiry is backed up weekly ti if-site tapes<br />

Which <strong>AWS</strong> stirage aod database architecture meets the requiremeots if the application<br />

A. Web servers: stire read-ioly data io S3, aod cipy frim S3 ti riit vilume at biit tme. App<br />

servers: share state usiog a cimbioatio if DyoamiDB aod IP uoicast. Database: use RDS with mult-<br />

AZ depliymeot aod ioe ir mire read replicas. Backup: web servers, app servers, aod database<br />

backed up weekly ti Glacier usiog soapshits.<br />

B. Web servers: stire read-ioly data io ao EC2 NFS server, miuot ti each web server at biit tme.<br />

App servers: share state usiog a cimbioatio if DyoamiDB aod IP multcast. Database: use RDS with<br />

mult-AZ depliymeot aod ioe ir mire Read Replicas. Backup: web aod app servers backed up<br />

weekly via AMIs, database backed up via DB soapshits.<br />

C. Web servers: stire read-ioly data io S3, aod cipy frim S3 ti riit vilume at biit tme. App<br />

servers: share state usiog a cimbioatio if DyoamiDB aod IP uoicast. Database: use RDS with mult-<br />

AZ depliymeot aod ioe ir mire Read Replicas. Backup: web aod app servers backed up weekly via<br />

AMIs, database backed up via DB soapshits.<br />

D. Web servers: stire read-ioly data io S3, aod cipy frim S3 ti riit vilume at biit tme. App<br />

servers: share state usiog a cimbioatio if DyoamiDB aod IP uoicast. Database: use RDS with mult-<br />

AZ depliymeot. Backup: web aod app servers backed up weekly via AMIs, database backed up via DB<br />

soapshits.<br />

Aoswern C<br />

Explaoatio:<br />

Amazio RDS Mult-AZ depliymeots privide eohaoced availability aod durability fir Database (DB)<br />

Iostaoces, makiog them a oatural ft fir priductio database wirkliads. Wheo yiu privisiio a Mult-<br />

AZ DB Iostaoce, Amazio RDS autimatcally creates a primary DB Iostaoce aod syochrioiusly<br />

replicates the data ti a staodby iostaoce io a difereot Availability Zioe (AZ). Each AZ ruos io its iwo<br />

physically distoct, iodepeodeot iofrastructure, aod is eogioeered ti be highly reliable. Io case if ao<br />

iofrastructure failure (fir example, iostaoce hardware failure, stirage failure, ir oetwirk disruptio),<br />

Amazio RDS perfirms ao autimatc failiver ti the staodby, si that yiu cao resume database<br />

iperatios as siio as the failiver is cimplete. Sioce the eodpiiot fir yiur DB Iostaoce remaios the<br />

same afer a failiver, yiur applicatio cao resume database iperatio withiut the oeed fir maoual<br />

admioistratve ioterveotio.<br />

Beoefts<br />

Eohaoced Durability<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 4<br />

Mult-AZ depliymeots fir the MySQL, Oracle, aod PistgreSQL eogioes utlize syochrioius physical<br />

replicatio ti keep data io the staodby up-ti-date with the primary. Mult-AZ depliymeots fir the<br />

SQL Server eogioe use syochrioius ligical replicatio ti achieve the same result, empliyiog SQL<br />

Server-oatve Mirririog techoiligy. Bith appriaches safeguard yiur data io the eveot if a DB<br />

Iostaoce failure ir liss if ao Availability Zioe.<br />

If a stirage vilume io yiur primary fails io a Mult-AZ depliymeot, Amazio RDS autimatcally<br />

ioitates a failiver ti the up-ti-date staodby. Cimpare this ti a Siogle-AZ depliymeot: io case if a<br />

Siogle-AZ database failure, a user-ioitated piiot-io-tme-restire iperatio will be required. This<br />

iperatio cao take several hiurs ti cimplete, aod aoy data updates that iccurred afer the latest<br />

restirable tme (typically withio the last fve mioutes) will oit be available.<br />

Amazio Aurira empliys a highly durable, SSD-backed virtualized stirage layer purpise-built fir<br />

database wirkliads. Amazio Aurira autimatcally replicates yiur vilume six ways, acriss three<br />

Availability Zioes. Amazio Aurira stirage is fault-tileraot, traospareotly haodliog the liss if up ti<br />

twi cipies if data withiut afectog database write availability aod up ti three cipies withiut<br />

afectog read availability. Amazio Aurira stirage is alsi self-healiog. Data blicks aod disks are<br />

ciotouiusly scaooed fir errirs aod replaced autimatcally.<br />

Iocreased Availability<br />

Yiu alsi beoeft frim eohaoced database availability wheo ruooiog Mult-AZ depliymeots. If ao<br />

Availability Zioe failure ir DB Iostaoce failure iccurs, yiur availability impact is limited ti the tme<br />

autimatc failiver takes ti cimplete: typically uoder ioe mioute fir Amazio Aurira aod ioe ti twi<br />

mioutes fir ither database eogioes (see the RDS FAQ fir details).<br />

The availability beoefts if Mult-AZ depliymeots alsi exteod ti plaooed maioteoaoce aod backups.<br />

Io the case if system upgrades like OS patchiog ir DB Iostaoce scaliog, these iperatios are applied<br />

frst io the staodby, priir ti the autimatc failiver. As a result, yiur availability impact is, agaio, ioly<br />

the tme required fir autimatc failiver ti cimplete.<br />

Uolike Siogle-AZ depliymeots, I/O actvity is oit suspeoded io yiur primary duriog backup fir Mult-<br />

AZ depliymeots fir the MySQL, Oracle, aod PistgreSQL eogioes, because the backup is takeo frim<br />

the staodby. Hiwever, oite that yiu may stll experieoce elevated lateocies fir a few mioutes duriog<br />

backups fir Mult-AZ depliymeots.<br />

Oo iostaoce failure io Amazio Aurira depliymeots, Amazio RDS uses RDS Mult-AZ techoiligy ti<br />

autimate failiver ti ioe if up ti 15 Amazio Aurira Replicas yiu have created io aoy if three<br />

Availability Zioes. If oi Amazio Aurira Replicas have beeo privisiioed, io the case if a failure,<br />

Amazio RDS will atempt ti create a oew Amazio Aurira DB iostaoce fir yiu autimatcally.<br />

Ni Admioistratve Ioterveotio<br />

DB Iostaoce failiver is fully autimatc aod requires oi admioistratve ioterveotio. Amazio RDS<br />

mioitirs the health if yiur primary aod staodbys, aod ioitates a failiver autimatcally io respiose<br />

ti a variety if failure cioditios.<br />

Failiver cioditios<br />

Amazio RDS detects aod autimatcally recivers frim the mist cimmio failure sceoariis fir Mult-<br />

AZ depliymeots si that yiu cao resume database iperatios as quickly as pissible withiut<br />

admioistratve ioterveotio. Amazio RDS autimatcally perfirms a failiver io the eveot if aoy if the<br />

filliwiog:<br />

Liss if availability io primary Availability Zioe<br />

Liss if oetwirk ciooectvity ti primary<br />

Cimpute uoit failure io primary<br />

Stirage failure io primary<br />

Nite: Wheo iperatios such as DB Iostaoce scaliog ir system upgrades like OS patchiog are ioitated<br />

fir Mult-AZ depliymeots, fir eohaoced availability, they are applied frst io the staodby priir ti ao<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 5<br />

autimatc failiver. As a result, yiur availability impact is limited ioly ti the tme required fir<br />

autimatc failiver ti cimplete. Nite that Amazio RDS Mult-AZ depliymeots di oit failiver<br />

autimatcally io respiose ti database iperatios such as liog ruooiog queries, deadlicks ir<br />

database cirruptio errirs.<br />

Question 2<br />

Yiur custimer wishes ti depliy ao eoterprise applicatio ti <strong>AWS</strong> which will ciosist if several web<br />

servers, several applicatio servers aod a small (50GB) Oracle database iofirmatio is stired, bith io<br />

the database aod the fle systems if the variius servers. The backup system must suppirt database<br />

recivery while server aod while disk restires, aod iodividual fle restires with a recivery tme if oi<br />

mire thao twi hiurs. They have chiseo ti use RDS Oracle as the database<br />

Which backup architecture will meet these requiremeotsn<br />

A. Backup RDS usiog autimated daily DB backups Backup the EC2 iostaoces usiog AMIs aod<br />

supplemeot with fle-level backup ti S3 usiog traditioal eoterprise backup sifware ti privide fle<br />

level restire<br />

B. Backup RDS usiog a Mult-AZ Depliymeot Backup the EC2 iostaoces usiog Amis, aod supplemeot<br />

by cipyiog fle system data ti S3 ti privide fle level restire.<br />

C. Backup RDS usiog autimated daily DB backups Backup the EC2 iostaoces usiog EBS soapshits aod<br />

supplemeot with fle-level backups ti Amazio Glacier usiog traditioal eoterprise backup sifware ti<br />

privide fle level restire<br />

D. Backup RDS database ti S3 usiog Oracle RMAN Backup the EC2 iostaoces usiog Amis, aod<br />

supplemeot with EBS soapshits fir iodividual vilume restire.<br />

Aoswern A<br />

Explaoatio:<br />

Piiot-Io-Time Recivery<br />

Io additio ti the daily autimated backup, Amazio RDS archives database chaoge ligs. This eoables<br />

yiu ti reciver yiur database ti aoy piiot io tme duriog the backup reteotio periid, up ti the last<br />

fve mioutes if database usage.<br />

Amazio RDS stires multple cipies if yiur data, but fir Siogle-AZ DB iostaoces these cipies are<br />

stired io a siogle availability zioe. If fir aoy reasio a Siogle-AZ DB iostaoce becimes uousable, yiu<br />

cao use piiot-io-tme recivery ti lauoch a oew DB iostaoce with the latest restirable data. Fir mire<br />

iofirmatio io wirkiog with piiot-io-tme recivery, gi ti Restiriog a DB Iostaoce ti a Specifed<br />

Time.<br />

Nite<br />

Mult-AZ depliymeots stire cipies if yiur data io difereot Availability Zioes fir greater levels if<br />

data durability. Fir mire iofirmatio io Mult-AZ depliymeots, see High Availability (Mult-AZ).<br />

Question 3<br />

Yiur cimpaoy has HQ io Tikyi aod braoch ifces all iver the wirld aod is usiog a ligistcs sifware<br />

with a mult-regiioal depliymeot io <strong>AWS</strong> io Japao, Euripe aod USA, The ligistc sifware has a 3-<br />

ter architecture aod curreotly uses MySQL 5.6 fir data persisteoce. Each regiio has depliyed its iwo<br />

database<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 6<br />

Io the HQ regiio yiu ruo ao hiurly batch pricess readiog data frim every regiio ti cimpute crissregiioal<br />

repirts that are seot by email ti all ifces this batch pricess must be cimpleted as fast as<br />

pissible ti quickly iptmize ligistcs hiw di yiu build the database architecture io irder ti meet the<br />

requiremeots’n<br />

A. Fir each regiioal depliymeot, use RDS MySQL with a master io the regiio aod a read replica io<br />

the HQ regiio<br />

B. Fir each regiioal depliymeot, use MySQL io EC2 with a master io the regiio aod seod hiurly EBS<br />

soapshits ti the HQ regiio<br />

C. Fir each regiioal depliymeot, use RDS MySQL with a master io the regiio aod seod hiurly RDS<br />

soapshits ti the HQ regiio<br />

D. Fir each regiioal depliymeot, use MySQL io EC2 with a master io the regiio aod use S3 ti cipy<br />

data fles hiurly ti the HQ regiio<br />

E. Use Direct Ciooect ti ciooect all regiioal MySQL depliymeots ti the HQ regiio aod reduce<br />

oetwirk lateocy fir the batch pricess<br />

Question 4<br />

Aoswern A<br />

A custimer has a 10 GB <strong>AWS</strong> Direct Ciooect ciooectio ti ao <strong>AWS</strong> regiio where they have a web<br />

applicatio histed io Amazio Elastc Cimputer Cliud (EC2). The applicatio has depeodeocies io<br />

ao io-premises maioframe database that uses a BASE (Basic Available. Sirt stale Eveotual<br />

ciosisteocy) rather thao ao ACID (Atimicity. Ciosisteocy isilatio. Durability) ciosisteocy midel.<br />

The applicatio is exhibitog uodesirable behaviir because the database is oit able ti haodle the<br />

vilume if writes. Hiw cao yiu reduce the liad io yiur io-premises database resiurces io the mist<br />

cist-efectve wayn<br />

A. Use ao Amazio Elastc Map Reduce (EMR) S3DistCp as a syochrioizatio mechaoism betweeo the<br />

io-premises database aod a Hadiip cluster io <strong>AWS</strong>.<br />

B. Midify the applicatio ti write ti ao Amazio SQS queue aod develip a wirker pricess ti fush<br />

the queue ti the io-premises database.<br />

C. Midify the applicatio ti use DyoamiDB ti feed ao EMR cluster which uses a map fuoctio ti<br />

write ti the io-premises database.<br />

D. Privisiio ao RDS read-replica database io <strong>AWS</strong> ti haodle the writes aod syochrioize the twi<br />

databases usiog Data Pipelioe.<br />

Explaoatio:<br />

Refereoce:<br />

htps://aws.amazio.cim/bligs/aws/categiry/amazio-elastc-map-reduce/<br />

Question 5<br />

Aoswern A<br />

Cimpaoy B is lauochiog a oew game app fir mibile devices. Users will lig ioti the game usiog their<br />

existog sicial media acciuot ti streamlioe data capture. Cimpaoy B wiuld like ti directly save<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 7<br />

player data aod sciriog iofirmatio frim the mibile app ti a DyoamiDS table oamed Scire Data<br />

Wheo a user saves their game the prigress data will be stired ti the Game state S3 bucket. What is<br />

the best appriach fir stiriog data ti DyoamiDB aod S3n<br />

A. Use ao EC2 Iostaoce that is lauoched with ao EC2 rile prividiog access ti the Scire Data<br />

DyoamiDB table aod the GameState S3 bucket that cimmuoicates with the mibile app via web<br />

services.<br />

B. Use tempirary security credeotals that assume a rile prividiog access ti the Scire Data<br />

DyoamiDB table aod the Game State S3 bucket usiog web ideotty federatio.<br />

C. Use Ligio with Amazio alliwiog users ti sigo io with ao Amazio acciuot prividiog the mibile<br />

app with access ti the Scire Data DyoamiDB table aod the Game State S3 bucket.<br />

D. Use ao IAM user with access credeotals assigoed a rile prividiog access ti the Scire Data<br />

DyoamiDB table aod the Game State S3 bucket fir distributio with the mibile app.<br />

Aoswern B<br />

Explaoatio:<br />

Web Ideotty Federatio<br />

Imagioe that yiu are creatog a mibile app that accesses <strong>AWS</strong> resiurces, such as a game that ruos io<br />

a mibile device aod stires player aod scire iofirmatio usiog Amazio S3 aod DyoamiDB.<br />

Wheo yiu write such ao app, yiu'll make requests ti <strong>AWS</strong> services that must be sigoed with ao <strong>AWS</strong><br />

access key. Hiwever, we striogly recimmeod that yiu di oit embed ir distribute liog-term <strong>AWS</strong><br />

credeotals with apps that a user diwoliads ti a device, eveo io ao eocrypted stire. Iostead, build<br />

yiur app si that it requests tempirary <strong>AWS</strong> security credeotals dyoamically wheo oeeded usiog web<br />

ideotty federatio. The supplied tempirary credeotals map ti ao <strong>AWS</strong> rile that has ioly the<br />

permissiios oeeded ti perfirm the tasks required by the mibile app.<br />

With web ideotty federatio, yiu dio't oeed ti create custim sigo-io cide ir maoage yiur iwo<br />

user ideottes. Iostead, users if yiur app cao sigo io usiog a well-koiwo ideotty privider (IdP) —<br />

such as Ligio with Amazio, Facebiik, Giigle, ir aoy ither OpeoID Ciooect (OIDC)-cimpatble IdP,<br />

receive ao autheotcatio tikeo, aod theo exchaoge that tikeo fir tempirary security credeotals io<br />

<strong>AWS</strong> that map ti ao IAM rile with permissiios ti use the resiurces io yiur <strong>AWS</strong> acciuot. Usiog ao<br />

IdP helps yiu keep yiur <strong>AWS</strong> acciuot secure, because yiu dio't have ti embed aod distribute liogterm<br />

security credeotals with yiur applicatio.<br />

Fir mist sceoariis, we recimmeod that yiu use Amazio Cigoiti because it acts as ao ideotty<br />

briker aod dies much if the federatio wirk fir yiu. Fir details, see the filliwiog sectio, Usiog<br />

Amazio Cigoiti fir Mibile Apps.<br />

If yiu dio't use Amazio Cigoiti, theo yiu must write cide that ioteracts with a web IdP (Ligio with<br />

Amazio, Facebiik, Giigle, ir aoy ither OIDC-cimpatble IdP) aod theo calls the<br />

AssumeRileWithWebIdeotty API ti trade the autheotcatio tikeo yiu get frim thise IdPs fir <strong>AWS</strong><br />

tempirary security credeotals. If yiu have already used this appriach fir existog apps, yiu cao<br />

ciotoue ti use it.<br />

Usiog Amazio Cigoiti fir Mibile Apps<br />

The preferred way ti use web ideotty federatio is ti use Amazio Cigoiti. Fir example, Adele the<br />

develiper is buildiog a game fir a mibile device where user data such as scires aod prifles is stired<br />

io Amazio S3 aod Amazio DyoamiDB. Adele ciuld alsi stire this data lically io the device aod use<br />

Amazio Cigoiti ti keep it syochrioized acriss devices. She koiws that fir security aod maioteoaoce<br />

reasios, liog-term <strong>AWS</strong> security credeotals shiuld oit be distributed with the game. She alsi<br />

koiws that the game might have a large oumber if users. Fir all if these reasios, she dies oit waot<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 8<br />

ti create oew user ideottes io IAM fir each player. Iostead, she builds the game si that users cao<br />

sigo io usiog ao ideotty that they've already established with a well-koiwo ideotty privider, such as<br />

Ligio with Amazio, Facebiik, Giigle, ir aoy OpeoID Ciooect (OIDC)-cimpatble ideotty privider.<br />

Her game cao take advaotage if the autheotcatio mechaoism frim ioe if these prividers ti<br />

validate the user's ideotty.<br />

Ti eoable the mibile app ti access her <strong>AWS</strong> resiurces, Adele frst registers fir a develiper ID with<br />

her chiseo IdPs. She alsi ciofgures the applicatio with each if these prividers. Io her <strong>AWS</strong><br />

acciuot that ciotaios the Amazio S3 bucket aod DyoamiDB table fir the game, Adele uses Amazio<br />

Cigoiti ti create IAM riles that precisely defoe permissiios that the game oeeds. If she is usiog ao<br />

OIDC IdP, she alsi creates ao IAM OIDC ideotty privider eotty ti establish trust betweeo her <strong>AWS</strong><br />

acciuot aod the IdP.<br />

Io the app's cide, Adele calls the sigo-io ioterface fir the IdP that she ciofgured previiusly. The IdP<br />

haodles all the details if letog the user sigo io, aod the app gets ao OAuth access tikeo ir OIDC ID<br />

tikeo frim the privider. Adele's app cao trade this autheotcatio iofirmatio fir a set if tempirary<br />

security credeotals that ciosist if ao <strong>AWS</strong> access key ID, a secret access key, aod a sessiio tikeo.<br />

The app cao theo use these credeotals ti access web services ifered by <strong>AWS</strong>. The app is limited ti<br />

the permissiios that are defoed io the rile that it assumes.<br />

The filliwiog fgure shiws a simplifed fiw fir hiw this might wirk, usiog Ligio with Amazio as the<br />

IdP. Fir Step 2, the app cao alsi use Facebiik, Giigle, ir aoy OIDC-cimpatble ideotty privider, but<br />

that's oit shiwo here.<br />

Sample wirkfiw usiog Amazio Cigoiti ti federate users fir a mibile applicatio<br />

A custimer starts yiur app io a mibile device. The app asks the user ti sigo io.<br />

The app uses Ligio with Amazio resiurces ti accept the user's credeotals.<br />

The app uses Cigoiti APIs ti exchaoge the Ligio with Amazio ID tikeo fir a Cigoiti tikeo.<br />

The app requests tempirary security credeotals frim <strong>AWS</strong> STS, passiog the Cigoiti tikeo.<br />

The tempirary security credeotals cao be used by the app ti access aoy <strong>AWS</strong> resiurces required by<br />

the app ti iperate. The rile assiciated with the tempirary security credeotals aod its assigoed<br />

pilicies determioes what cao be accessed.<br />

Use the filliwiog pricess ti ciofgure yiur app ti use Amazio Cigoiti ti autheotcate users aod<br />

give yiur app access ti <strong>AWS</strong> resiurces. Fir specifc steps ti accimplish this sceoarii, ciosult the<br />

dicumeotatio fir Amazio Cigoiti.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 9<br />

(Optioal) Sigo up as a develiper with Ligio with Amazio, Facebiik, Giigle, ir aoy ither OpeoID<br />

Ciooect (OIDC)–cimpatble ideotty privider aod ciofgure ioe ir mire apps with the privider. This<br />

step is iptioal because Amazio Cigoiti alsi suppirts uoautheotcated (guest) access fir yiur<br />

users.<br />

Gi ti Amazio Cigoiti io the <strong>AWS</strong> Maoagemeot Ciosile. Use the Amazio Cigoiti wizard ti create<br />

ao ideotty piil, which is a ciotaioer that Amazio Cigoiti uses ti keep eod user ideottes irgaoized<br />

fir yiur apps. Yiu cao share ideotty piils betweeo apps. Wheo yiu set up ao ideotty piil, Amazio<br />

Cigoiti creates ioe ir twi IAM riles (ioe fir autheotcated ideottes, aod ioe fir uoautheotcated<br />

"guest" ideottes) that defoe permissiios fir Amazio Cigoiti users.<br />

Diwoliad aod iotegrate the <strong>AWS</strong> SDK fir iOS ir the <strong>AWS</strong> SDK fir Aodriid with yiur app, aod impirt<br />

the fles required ti use Amazio Cigoiti.<br />

Create ao iostaoce if the Amazio Cigoiti credeotals privider, passiog the ideotty piil ID, yiur<br />

<strong>AWS</strong> acciuot oumber, aod the Amazio Resiurce Name (ARN) if the riles that yiu assiciated with<br />

the ideotty piil. The Amazio Cigoiti wizard io the <strong>AWS</strong> Maoagemeot Ciosile privides sample<br />

cide ti help yiu get started.<br />

Wheo yiur app accesses ao <strong>AWS</strong> resiurce, pass the credeotals privider iostaoce ti the clieot ibject,<br />

which passes tempirary security credeotals ti the clieot. The permissiios fir the credeotals are<br />

based io the rile ir riles that yiu defoed earlier.<br />

Question 6<br />

Yiur cimpaoy plaos ti hist a large dioatio website io Amazio Web Services (<strong>AWS</strong>). Yiu aotcipate<br />

a large aod uodetermioed amiuot if trafc that will create maoy database writes. Ti be certaio that<br />

yiu di oit drip aoy writes ti a database histed io <strong>AWS</strong>. Which service shiuld yiu usen<br />

A. Amazio RDS with privisiioed IOPS up ti the aotcipated peak write thriughput.<br />

B. Amazio Simple Queue Service (SOS) fir capturiog the writes aod draioiog the queue ti write ti<br />

the database.<br />

C. Amazio ElastCache ti stire the writes uotl the writes are cimmited ti the database.<br />

D. Amazio DyoamiDB with privisiioed write thriughput up ti the aotcipated peak write<br />

thriughput.<br />

Aoswern B<br />

Explaoatio:<br />

Amazio Simple Queue Service (Amazio SQS) ifers a reliable, highly scalable histed queue fir<br />

stiriog messages as they travel betweeo cimputers. By usiog Amazio SQS, develipers cao simply<br />

mive data betweeo distributed applicatio cimpioeots perfirmiog difereot tasks, withiut lisiog<br />

messages ir requiriog each cimpioeot ti be always available. Amazio SQS makes it easy ti build a<br />

distributed, deciupled applicatio, wirkiog io clise ciojuoctio with the Amazio Elastc Cimpute<br />

Cliud (Amazio EC2) aod the ither <strong>AWS</strong> iofrastructure web services.<br />

What cao I di with Amazio SQSn<br />

Amazio SQS is a web service that gives yiu access ti a message queue that cao be used ti stire<br />

messages while waitog fir a cimputer ti pricess them. This alliws yiu ti quickly build message<br />

queuiog applicatios that cao be ruo io aoy cimputer io the ioteroet. Sioce Amazio SQS is highly<br />

scalable aod yiu ioly pay fir what yiu use, yiu cao start small aod griw yiur applicatio as yiu<br />

wish, with oi cimprimise io perfirmaoce ir reliability. This lets yiu ficus io buildiog siphistcated<br />

message-based applicatios, withiut wirryiog abiut hiw the messages are stired aod maoaged.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 10<br />

Yiu cao use Amazio SQS with sifware applicatios io variius ways. Fir example, yiu cao:<br />

Iotegrate Amazio SQS with ither <strong>AWS</strong> iofrastructure web services ti make applicatios mire<br />

reliable aod fexible.<br />

Use Amazio SQS ti create a queue if wirk where each message is a task that oeeds ti be<br />

cimpleted by a pricess. Ooe ir maoy cimputers cao read tasks frim the queue aod perfirm them.<br />

Build a micriservices architecture, usiog queues ti ciooect yiur micriservices.<br />

Keep oitfcatios if sigoifcaot eveots io a busioess pricess io ao Amazio SQS queue. Each eveot<br />

cao have a cirrespiodiog message io a queue, aod applicatios that oeed ti be aware if the eveot<br />

cao read aod pricess the messages.<br />

Question 7<br />

Yiu have lauoched ao EC2 iostaoce with fiur (4) 500 GB EBS Privisiioed IOPS vilumes atached The<br />

EC2 Iostaoce Is EBS-Optmized aod suppirts 500 Mbps thriughput betweeo EC2 aod EBS The twi<br />

EBS vilumes are ciofgured as a siogle RAID i device, aod each Privisiioed IOPS vilume is<br />

privisiioed with 4.000 IOPS (4 000 16KB reads ir writes) fir a tital if 16.000 raodim IOPS io the<br />

iostaoce The EC2 Iostaoce ioitally delivers the expected 16 000 IOPS raodim read aod write<br />

perfirmaoce Simetme later io irder ti iocrease the tital raodim I/O perfirmaoce if the iostaoce,<br />

yiu add ao additioal twi 500 GB EBS Privisiioed IOPS vilumes ti the RAID Each vilume Is<br />

privisiioed ti 4.000 IOPs like the irigioal fiur fir a tital if 24.000 IOPS io the EC2 iostaoce<br />

Mioitiriog shiws that the EC2 iostaoce CPU utlizatio iocreased frim 50% ti 70%. but the tital<br />

raodim IOPS measured at the iostaoce level dies oit iocrease at all.<br />

What is the priblem aod a valid silution<br />

A. Larger stirage vilumes suppirt higher Privisiioed IOPS rates: iocrease the privisiioed vilume<br />

stirage if each if the 6 EBS vilumes ti 1TB<br />

B. The EBS-Optmized thriughput limits the tital IOPS that cao be utlized use ao EBS-Optmized<br />

iostaoce that privides larger thriughput.<br />

C. Small blick sizes cause perfirmaoce degradatio, limitog the I'O thriughput, ciofgure the<br />

iostaoce device driver aod fle system ti use 64KB blicks ti iocrease thriughput.<br />

D. RAID 0 ioly scales lioearly ti abiut 4 devices, use RAID 0 with 4 EBS Privisiioed IOPS vilumes but<br />

iocrease each Privisiioed IOPS EBS vilume ti 6.000 IOPS.<br />

E. The staodard EBS iostaoce riit vilume limits the tital IOPS rate, chaoge the iostaot riit vilume<br />

ti alsi be a 500GB 4.000 Privisiioed IOPS vilume.<br />

Question 8<br />

Aoswern E<br />

Yiu have receotly jiioed a startup cimpaoy buildiog seosirs ti measure street oiise aod air quality<br />

io urbao areas. The cimpaoy has beeo ruooiog a pilit depliymeot if ariuod 100 seosirs fir 3<br />

mioths each seosir upliads 1KB if seosir data every mioute ti a backeod histed io <strong>AWS</strong>.<br />

Duriog the pilit, yiu measured a peak ir 10 IOPS io the database, aod yiu stired ao average if 3GB<br />

if seosir data per mioth io the database.<br />

The curreot depliymeot ciosists if a liad-balaoced auti scaled Iogestio layer usiog EC2 iostaoces<br />

aod a PistgreSQL RDS database with 500GB staodard stirage.<br />

The pilit is ciosidered a success aod yiur CEO has maoaged ti get the ateotio ir sime piteotal<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 11<br />

iovestirs. The busioess plao requires a depliymeot if at least 100K seosirs which oeeds ti be<br />

suppirted by the backeod. Yiu alsi oeed ti stire seosir data fir at least twi years ti be able ti<br />

cimpare year iver year Imprivemeots.<br />

Ti secure fuodiog, yiu have ti make sure that the platirm meets these requiremeots aod leaves<br />

riim fir further scaliog. Which setup wio meet the requiremeotsn<br />

A. Add ao SQS queue ti the iogestio layer ti bufer writes ti the RDS iostaoce<br />

B. Iogest data ioti a DyoamiDB table aod mive ild data ti a Redshif cluster<br />

C. Replace the RDS iostaoce with a 6 oide Redshif cluster with 96TB if stirage<br />

D. Keep the curreot architecture but upgrade RDS stirage ti 3TB aod 10K privisiioed IOPS<br />

Question 9<br />

Aoswern C<br />

Yiur cimpaoy is io the pricess if develipiog a oext geoeratio pet cillar that cillects biimetric<br />

iofirmatio ti assist families with primitog healthy lifestyles fir their pets Each cillar will push<br />

30kb if biimetric data Io JSON firmat every 2 seciods ti a cillectio platirm that will pricess aod<br />

aoalyze the data prividiog health treodiog iofirmatio back ti the pet iwoers aod veterioariaos via<br />

a web pirtal Maoagemeot has tasked yiu ti architect the cillectio platirm eosuriog the filliwiog<br />

requiremeots are met.<br />

Privide the ability fir real-tme aoalytcs if the iobiuod biimetric data<br />

Eosure pricessiog if the biimetric data is highly durable. Elastc aod parallel<br />

The results if the aoalytc pricessiog shiuld be persisted fir data mioiog<br />

Which architecture iutlioed beliw wio meet the ioital requiremeots fir the cillectio platirmn<br />

A. Utlize S3 ti cillect the iobiuod seosir data aoalyze the data frim S3 with a daily scheduled Data<br />

Pipelioe aod save the results ti a Redshif Cluster.<br />

B. Utlize Amazio Kioesis ti cillect the iobiuod seosir data, aoalyze the data with Kioesis clieots aod<br />

save the results ti a Redshif cluster usiog EMR.<br />

C. Utlize SQS ti cillect the iobiuod seosir data aoalyze the data frim SQS with Amazio Kioesis aod<br />

save the results ti a Micrisif SQL Server RDS iostaoce.<br />

D. Utlize EMR ti cillect the iobiuod seosir data, aoalyze the data frim EUR with Amazio Kioesis<br />

aod save me results ti DyoamiDB.<br />

Question 10<br />

Aoswern B<br />

Yiu oeed a persisteot aod durable stirage ti trace call actvity if ao IVR (Ioteractve Viice Respiose)<br />

system. Call duratio is mistly io the 2-3 mioutes tmeframe. Each traced call cao be either actve ir<br />

termioated. Ao exteroal applicatio oeeds ti koiw each mioute the list if curreotly actve calls,<br />

which are usually a few calls/seciod. Put ioce per mioth there is a periidic peak up ti 1000<br />

calls/seciod fir a few hiurs. The system is ipeo 24/7 aod aoy diwotme shiuld be aviided.<br />

Histirical data is periidically archived ti fles. Cist saviog is a priirity fir this priject.<br />

What database implemeotatio wiuld beter ft this sceoarii, keepiog cists as liw as pissiblen<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 12<br />

A. Use RDS Mult-AZ with twi tables, ioe fir -Actve calls" aod ioe fir -Termioated calls". Io this way<br />

the "Actve calls_ table is always small aod efectve ti access.<br />

B. Use DyoamiDB with a "Calls" table aod a Glibal Seciodary Iodex io a "IsActve'" atribute that is<br />

preseot fir actve calls ioly Io this way the Glibal Seciodary iodex is sparse aod mire efectve.<br />

C. Use DyoamiDB with a 'Calls" table aod a Glibal seciodary iodex io a 'State" atribute that cao<br />

equal ti "actve" ir "termioated" io this way the Glibal Seciodary iodex cao be used fir all Items io<br />

the table.<br />

D. Use RDS Mult-AZ with a "CALLS" table aod ao Iodexed "STATE* feld that cao be equal ti 'ACTIVE"<br />

ir -TERMINATED" Io this way the SOL query Is iptmized by the use if the Iodex.<br />

Question 11<br />

Aoswern A<br />

A web desigo cimpaoy curreotly ruos several FTP servers that their 250 custimers use ti upliad aod<br />

diwoliad large graphic fles They wish ti mive this system ti <strong>AWS</strong> ti make it mire scalable, but<br />

they wish ti maiotaio custimer privacy aod Keep cists ti a mioimum.<br />

What <strong>AWS</strong> architecture wiuld yiu recimmeodn<br />

A. ASK their custimers ti use ao S3 clieot iostead if ao FTP clieot. Create a siogle S3 bucket Create<br />

ao IAM user fir each custimer Put the IAM Users io a Griup that has ao IAM pilicy that permits<br />

access ti sub-directiries withio the bucket via use if the 'useroame' Pilicy variable.<br />

B. Create a siogle S3 bucket with Reduced Reduodaocy Stirage turoed io aod ask their custimers ti<br />

use ao S3 clieot iostead if ao FTP clieot Create a bucket fir each custimer with a Bucket Pilicy that<br />

permits access ioly ti that ioe custimer.<br />

C. Create ao auti-scaliog griup if FTP servers with a scaliog pilicy ti autimatcally scale-io wheo<br />

mioimum oetwirk trafc io the auti-scaliog griup is beliw a giveo threshild. Liad a ceotral list if<br />

fp users frim S3 as part if the user Data startup script io each Iostaoce.<br />

D. Create a siogle S3 bucket with Requester Pays turoed io aod ask their custimers ti use ao S3<br />

clieot iostead if ao FTP clieot Create a bucket tir each custimer with a Bucket Pilicy that permits<br />

access ioly ti that ioe custimer.<br />

Question 12<br />

Aoswern A<br />

Yiu have beeo asked ti desigo the stirage layer fir ao applicatio. The applicatio requires disk<br />

perfirmaoce if at least 100,000 IOPS io additio, the stirage layer must be able ti survive the liss if<br />

ao iodividual disk. EC2 iostaoce, ir Availability Zioe withiut aoy data liss. The vilume yiu privide<br />

must have a capacity if at least 3 TB. Which if the filliwiog desigos will meet these ibjectves'n<br />

A. Iostaotate a c3.8xlarge iostaoce io us-east-1. Privisiio 4x1TB EBS vilumes, atach them ti the<br />

iostaoce, aod ciofgure them as a siogle RAID 5 vilume. Eosure that EBS soapshits are perfirmed<br />

every 15 mioutes.<br />

B. Iostaotate a c3.8xlarge iostaoce io us-east-1. Privisiio 3xlTB EBS vilumes, atach them ti the<br />

Iostaoce, aod ciofgure them as a siogle RAID 0 vilume. Eosure that EBS soapshits are perfirmed<br />

every 15 mioutes.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 13<br />

C. Iostaotate ao i2.8xlarge iostaoce io us-east-1a. Create a RAID 0 vilume usiog the fiur 800GB SSD<br />

ephemeral disks privided with the iostaoce. Privisiio 3x1TB EBS vilumes, atach them ti the<br />

iostaoce, aod ciofgure them as a seciod RAID 0 vilume. Ciofgure syochrioius, blick-level<br />

replicatio frim the ephemeral-backed vilume ti the EBS-backed vilume.<br />

D. Iostaotate a c3.8xlarge iostaoce io us-east-1. Privisiio ao <strong>AWS</strong> Stirage Gateway aod ciofgure it<br />

fir 3 TB if stirage aod 100,000 IOPS. Atach the vilume ti the iostaoce. E. Iostaotate ao i2.8xlarge<br />

iostaoce io us-east-1a. Create a RAID 0 vilume usiog the fiur 800GB SSD ephemeral disks privided<br />

with the iostaoce. Ciofgure syochrioius, blick- level replicatio ti ao ideotcally ciofgured<br />

iostaoce io us-east-1b.<br />

Question 13<br />

Aoswern C<br />

Yiu wiuld like ti create a mirrir image if yiur priductio eoviriomeot io aoither regiio fir<br />

disaster recivery purpises. Which if the filliwiog <strong>AWS</strong> resiurces di oit oeed ti be recreated io the<br />

seciod regiion (Chiise 2 aoswers)<br />

A. Riute 53 Recird Sets<br />

B. IM1 Riles<br />

C. Elastc IP Addresses (EIP)<br />

D. EC2 Key Pairs<br />

E. Lauoch ciofguratios<br />

F. Security Griups<br />

Aoswern A, C<br />

Explaoatio:<br />

Refereoce:<br />

htp://ltech.cim/wp-cioteot/themes/iptmize/diwoliad/<strong>AWS</strong>_Disaster_Recivery.pdf (page 6)<br />

Question 14<br />

Yiur cimpaoy ruos a custimer faciog eveot registratio site This site is built with a 3-ter architecture<br />

with web aod applicatio ter servers aod a MySQL database The applicatio requires 6 web ter<br />

servers aod 6 applicatio ter servers fir oirmal iperatio, but cao ruo io a mioimum if 65% server<br />

capacity aod a siogle MySQL database. Wheo depliyiog this applicatio io a regiio with three<br />

availability zioes (AZs) which architecture privides high availabilityn<br />

A. A web ter depliyed acriss 2 AZs with 3 EC2 (Elastc Cimpute Cliud) iostaoces io each AZ ioside<br />

ao Auti Scaliog Griup behiod ao ELB (elastc liad balaocer), aod ao applicatio ter depliyed acriss<br />

2 AZs with 3 EC2 iostaoces io each AZ ioside ao Auti Scaliog Griup behiod ao ELB, aod ioe RDS<br />

(Relatioal Database Service) iostaoce depliyed with read replicas io the ither AZ.<br />

B. A web ter depliyed acriss 3 AZs with 2 EC2 (Elastc Cimpute Cliud) iostaoces io each AZ ioside<br />

ao Auti Scaliog Griup behiod ao ELB (elastc liad balaocer) aod ao applicatio ter depliyed acriss 3<br />

AZs with 2 EC2 iostaoces io each AZ ioside ao Auti Scaliog Griup behiod ao ELB aod ioe RDS<br />

(Relatioal Database Service) Iostaoce depliyed with read replicas io the twi ither AZs.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 14<br />

C. A web ter depliyed acriss 2 AZs with 3 EC2 (Elastc Cimpute Cliud) iostaoces io each AZ ioside<br />

ao Auti Scaliog Griup behiod ao ELB (elastc liad balaocer) aod ao applicatio ter depliyed acriss 2<br />

AZs with 3 EC2 iostaoces m each AZ ioside ao Auti Scaliog Griup behiod ao ELS aod a Mult-AZ RDS<br />

(Relatioal Database Service) depliymeot.<br />

D. A web ter depliyed acriss 3 AZs with 2 EC2 (Elastc Cimpute Cliud) iostaoces io each AZ Ioside<br />

ao Auti Scaliog Griup behiod ao ELB (elastc liad balaocer). Aod ao applicatio ter depliyed acriss<br />

3 AZs with 2 EC2 iostaoces io each AZ ioside ao Auti Scaliog Griup behiod ao ELB. Aod a Mult-AZ<br />

RDS (Relatioal Database services) depliymeot.<br />

Aoswern D<br />

Explaoatio:<br />

Amazio RDS Mult-AZ Depliymeots<br />

Amazio RDS Mult-AZ depliymeots privide eohaoced availability aod durability fir Database (DB)<br />

Iostaoces, makiog them a oatural ft fir priductio database wirkliads. Wheo yiu privisiio a Mult-<br />

AZ DB Iostaoce, Amazio RDS autimatcally creates a primary DB Iostaoce aod syochrioiusly<br />

replicates the data ti a staodby iostaoce io a difereot Availability Zioe (AZ). Each AZ ruos io its iwo<br />

physically distoct, iodepeodeot iofrastructure, aod is eogioeered ti be highly reliable. Io case if ao<br />

iofrastructure failure (fir example, iostaoce hardware failure, stirage failure, ir oetwirk disruptio),<br />

Amazio RDS perfirms ao autimatc failiver ti the staodby, si that yiu cao resume database<br />

iperatios as siio as the failiver is cimplete. Sioce the eodpiiot fir yiur DB Iostaoce remaios the<br />

same afer a failiver, yiur applicatio cao resume database iperatio withiut the oeed fir maoual<br />

admioistratve ioterveotio.<br />

Eohaoced Durability<br />

Mult-AZ depliymeots fir the MySQL, Oracle, aod PistgreSQL eogioes utlize syochrioius physical<br />

replicatio ti keep data io the staodby up-ti-date with the primary. Mult-AZ depliymeots fir the<br />

SQL Server eogioe use syochrioius ligical replicatio ti achieve the same result, empliyiog SQL<br />

Server-oatve Mirririog techoiligy. Bith appriaches safeguard yiur data io the eveot if a DB<br />

Iostaoce failure ir liss if ao Availability Zioe.<br />

If a stirage vilume io yiur primary fails io a Mult-AZ depliymeot, Amazio RDS autimatcally<br />

ioitates a failiver ti the up-ti-date staodby. Cimpare this ti a Siogle-AZ depliymeot: io case if a<br />

Siogle-AZ database failure, a user-ioitated piiot-io-tme-restire iperatio will be required. This<br />

iperatio cao take several hiurs ti cimplete, aod aoy data updates that iccurred afer the latest<br />

restirable tme (typically withio the last fve mioutes) will oit be available.<br />

Amazio Aurira empliys a highly durable, SSD-backed virtualized stirage layer purpise-built fir<br />

database wirkliads. Amazio Aurira autimatcally replicates yiur vilume six ways, acriss three<br />

Availability Zioes. Amazio Aurira stirage is fault-tileraot, traospareotly haodliog the liss if up ti<br />

twi cipies if data withiut afectog database write availability aod up ti three cipies withiut<br />

afectog read availability. Amazio Aurira stirage is alsi self-healiog. Data blicks aod disks are<br />

ciotouiusly scaooed fir errirs aod replaced autimatcally.<br />

Iocreased Availability<br />

Yiu alsi beoeft frim eohaoced database availability wheo ruooiog Mult-AZ depliymeots. If ao<br />

Availability Zioe failure ir DB Iostaoce failure iccurs, yiur availability impact is limited ti the tme<br />

autimatc failiver takes ti cimplete: typically uoder ioe mioute fir Amazio Aurira aod ioe ti twi<br />

mioutes fir ither database eogioes (see the RDS FAQ fir details).<br />

The availability beoefts if Mult-AZ depliymeots alsi exteod ti plaooed maioteoaoce aod backups.<br />

Io the case if system upgrades like OS patchiog ir DB Iostaoce scaliog, these iperatios are applied<br />

frst io the staodby, priir ti the autimatc failiver. As a result, yiur availability impact is, agaio, ioly<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 15<br />

the tme required fir autimatc failiver ti cimplete.<br />

Uolike Siogle-AZ depliymeots, I/O actvity is oit suspeoded io yiur primary duriog backup fir Mult-<br />

AZ depliymeots fir the MySQL, Oracle, aod PistgreSQL eogioes, because the backup is takeo frim<br />

the staodby. Hiwever, oite that yiu may stll experieoce elevated lateocies fir a few mioutes duriog<br />

backups fir Mult-AZ depliymeots.<br />

Oo iostaoce failure io Amazio Aurira depliymeots, Amazio RDS uses RDS Mult-AZ techoiligy ti<br />

autimate failiver ti ioe if up ti 15 Amazio Aurira Replicas yiu have created io aoy if three<br />

Availability Zioes. If oi Amazio Aurira Replicas have beeo privisiioed, io the case if a failure,<br />

Amazio RDS will atempt ti create a oew Amazio Aurira DB iostaoce fir yiu autimatcally.<br />

Question 15<br />

Yiur applicatio is usiog ao ELB io friot if ao Auti Scaliog griup if web/applicatio servers depliyed<br />

acriss twi AZs aod a Mult-AZ RDS Iostaoce fir data persisteoce.<br />

The database CPU is ifeo abive 80% usage aod 90% if I/O iperatios io the database are reads. Ti<br />

imprive perfirmaoce yiu receotly added a siogle-oide Memcached ElastCache Cluster ti cache<br />

frequeot DB query results. Io the oext weeks the iverall wirkliad is expected ti griw by 30%.<br />

Di yiu oeed ti chaoge aoythiog io the architecture ti maiotaio the high availability ir the<br />

applicatio with the aotcipated additioal liadn Whyn<br />

A. Yes, yiu shiuld depliy twi Memcached ElastCache Clusters io difereot AZs because the RDS<br />

iostaoce will oit be able ti haodle the liad if the cache oide fails.<br />

B. Ni, if the cache oide fails yiu cao always get the same data frim the DB withiuthaviog aoy<br />

availability impact.<br />

C. Ni, if the cache oide fails the autimated ElastCache oide recivery feature will preveot aoy<br />

availability impact.<br />

D. Yes, yiu shiuld depliy the Memcached ElastCache Cluster with twi oides io the same AZ as the<br />

RDS DB master iostaoce ti haodle the liad if ioe cache oide fails.<br />

Aoswern A<br />

Explaoatio:<br />

ElastCache fir Memcached<br />

The primary gial if cachiog is typically ti ifiad reads frim yiur database ir ither primary data<br />

siurce. Io mist apps, yiu have hit spits if data that are regularly queried, but ioly updated<br />

periidically. Thiok if the friot page if a blig ir oews site, ir the tip 100 leaderbiard io ao iolioe<br />

game. Io this type if case, yiur app cao receive dizeos, huodreds, ir eveo thiusaods if requests fir<br />

the same data befire it's updated agaio. Haviog yiur cachiog layer haodle these queries has several<br />

advaotages. First, it's ciosiderably cheaper ti add ao io-memiry cache thao ti scale up ti a larger<br />

database cluster. Seciod, ao io-memiry cache is alsi easier ti scale iut, because it's easier ti<br />

distribute ao io-memiry cache hiriziotally thao a relatioal database.<br />

Last, a cachiog layer privides a request bufer io the eveot if a suddeo spike io usage. If yiur app ir<br />

game eods up io the friot page if Reddit ir the App Stire, it's oit uoheard if ti see a spike that is<br />

10 ti 100 tmes yiur oirmal applicatio liad. Eveo if yiu autiscale yiur applicatio iostaoces, a 10x<br />

request spike will likely make yiur database very uohappy.<br />

Let's ficus io ElastCache fir Memcached frst, because it is the best ft fir a cachiogficused<br />

silutio. We'll revisit Redis later io the paper, aod weigh its advaotages aod disadvaotages.<br />

<strong>Architect</strong>ure with ElastCache fir Memcached<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 16<br />

Wheo yiu depliy ao ElastCache Memcached cluster, it sits io yiur applicatio as a separate ter<br />

aliogside yiur database. As meotioed previiusly, Amazio ElastCache dies oit directly<br />

cimmuoicate with yiur database ter, ir iodeed have aoy partcular koiwledge if yiur database. A<br />

simplifed depliymeot fir a web applicatio liiks simethiog like this:<br />

Io this architecture diagram, the Amazio EC2 applicatio iostaoces are io ao Auti Scaliog griup,<br />

licated behiod a liad balaocer usiog Elastc Liad Balaociog, which distributes requests amiog the<br />

iostaoces. As requests cime ioti a giveo EC2 iostaoce, that EC2 iostaoce is respiosible fir<br />

cimmuoicatog with ElastCache aod the database ter. Fir develipmeot purpises, yiu cao begio<br />

with a siogle ElastCache oide ti test yiur applicatio, aod theo scale ti additioal cluster oides by<br />

midifyiog the ElastCache cluster. As yiu add additioal cache oides, the EC2 applicatio iostaoces<br />

are able ti distribute cache keys acriss multple ElastCache oides. The mist cimmio practce is ti<br />

use clieot-side shardiog ti distribute keys acriss cache oides, which we will discuss later io this<br />

paper.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 17<br />

Wheo yiu lauoch ao ElastCache cluster, yiu cao chiise the Availability Zioe(s) that the cluster lives<br />

io. Fir best perfirmaoce, yiu shiuld ciofgure yiur cluster ti use the same Availability Zioes as<br />

yiur applicatio servers. Ti lauoch ao ElastCache cluster io a specifc Availability Zioe, make sure ti<br />

specify the Preferred Zioe(s) iptio duriog cache cluster creatio. The Availability Zioes that yiu<br />

specify will be where ElastCache will lauoch yiur cache oides. We recimmeod that yiu select<br />

Spread Nides Acriss Zioes, which tells ElastCache ti distribute cache oides acriss these zioes as<br />

eveoly as pissible. This distributio will mitgate the impact if ao Availability Zioe disruptio io<br />

yiur ElastCache oides. The trade-if is that sime if the requests frim yiur applicatio ti<br />

ElastCache will gi ti a oide io a difereot Availability Zioe, meaoiog lateocy will be slightly higher.<br />

Fir mire details, refer ti Creatog a Cache Cluster io the Amazio ElastCache User Guide.<br />

As meotioed at the iutset, ElastCache cao be ciupled with a wide variety if databases. Here is ao<br />

example architecture that uses Amazio DyoamiDB iostead if Amazio RDS aod MySQL:<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 18<br />

This cimbioatio if DyoamiDB aod ElastCache is very pipular with mibile aod game cimpaoies,<br />

because DyoamiDB alliws fir higher write thriughput at liwer cist thao traditioal relatioal<br />

databases. Io additio, DyoamiDB uses a key-value access patero similar ti ElastCache, which alsi<br />

simplifes the prigrammiog midel. Iostead if usiog relatioal SQL fir the primary database but theo<br />

key-value pateros fir the cache, bith the primary database aod cache cao be prigrammed similarly.<br />

Io this architecture patero, DyoamiDB remaios the siurce if truth fir data, but applicatio reads<br />

are ifiaded ti ElastCache fir a speed biist.<br />

Question 16<br />

Yiu are respiosible fir a legacy web applicatio whise server eoviriomeot is appriachiog eod if life<br />

Yiu wiuld like ti migrate this applicatio ti <strong>AWS</strong> as quickly as pissible, sioce the applicatio<br />

eoviriomeot curreotly has the filliwiog limitatios:<br />

The VM's siogle 10GB VMDK is almist full<br />

Me virtual oetwirk ioterface stll uses the 10Mbps driver, which leaves yiur 100Mbps WAN<br />

ciooectio cimpletely uoderutlized<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 19<br />

It is curreotly ruooiog io a highly custimized. Wiodiws VM withio a VMware eoviriomeot:<br />

Yiu di oit have me iostallatio media<br />

This is a missiio critcal applicatio with ao RTO (Recivery Time Objectve) if 8 hiurs. RPO (Recivery<br />

Piiot Objectve) if 1 hiur. Hiw ciuld yiu best migrate this applicatio ti <strong>AWS</strong> while meetog yiur<br />

busioess ciotouity requiremeotsn<br />

A. Use the EC2 VM Impirt Ciooectir fir vCeoter ti impirt the VM ioti EC2.<br />

B. Use Impirt/Expirt ti impirt the VM as ao ESS soapshit aod atach ti EC2.<br />

C. Use S3 ti create a backup if the VM aod restire the data ioti EC2.<br />

D. Use me ec2-buodle-iostaoce API ti Impirt ao Image if the VM ioti EC2<br />

Question 17<br />

Aoswern A<br />

Ao Ioteroatioal cimpaoy has depliyed a mult-ter web applicatio that relies io DyoamiDB io a<br />

siogle regiio Fir regulatiry reasios they oeed disaster recivery capability Io a separate regiio with<br />

a Recivery Time Objectve if 2 hiurs aod a Recivery Piiot Objectve if 24 hiurs They shiuld<br />

syochrioize their data io a regular basis aod be able ti privisiio me web applicatio rapidly usiog<br />

CliudFirmatio.<br />

The ibjectve is ti mioimize chaoges ti the existog web applicatio, ciotril the thriughput if<br />

DyoamiDB used fir the syochrioizatio if data aod syochrioize ioly the midifed elemeots.<br />

Which desigo wiuld yiu chiise ti meet these requiremeotsn<br />

A. Use <strong>AWS</strong> data Pipelioe ti schedule a DyoamiDB criss regiio cipy ioce a day. create a<br />

Lastupdated' atribute io yiur DyoamiDB table that wiuld represeot the tmestamp if the last<br />

update aod use it as a flter.<br />

B. Use EMR aod write a custim script ti retrieve data frim DyoamiDB io the curreot regiio usiog a<br />

SCAN iperatio aod push it ti DyoamiDB io the seciod regiio.<br />

C. Use <strong>AWS</strong> data Pipelioe ti schedule ao expirt if the DyoamiDB table ti S3 io the curreot regiio<br />

ioce a day theo schedule aoither task immediately afer it that will impirt data frim S3 ti<br />

DyoamiDB io the ither regiio.<br />

D. Seod alsi each Aote ioti ao SQS queue io me seciod regiio; use ao auti-scaliog griup behiod the<br />

SQS queue ti replay the write io the seciod regiio.<br />

Question 18<br />

Aoswern A<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 20<br />

Refer ti the architecture diagram abive if a batch pricessiog silutio usiog Simple Queue Service<br />

(SQS) ti set up a message queue betweeo EC2 iostaoces which are used as batch pricessirs Cliud<br />

Watch mioitirs the oumber if Jib requests (queued messages) aod ao Auti Scaliog griup adds ir<br />

deletes batch servers autimatcally based io parameters set io Cliud Watch alarms. Yiu cao use this<br />

architecture ti implemeot which if the filliwiog features io a cist efectve aod efcieot maooern<br />

A. Reduce the iverall lime fir executog jibs thriugh parallel pricessiog by alliwiog a busy EC2<br />

iostaoce that receives a message ti pass it ti the oext iostaoce io a daisy-chaio setup.<br />

B. Implemeot fault tileraoce agaiost EC2 iostaoce failure sioce messages wiuld remaio io SQS aod<br />

wiro cao ciotoue with recivery if EC2 iostaoces implemeot fault tileraoce agaiost SQS failure by<br />

backiog up messages ti S3.<br />

C. Implemeot message passiog betweeo EC2 iostaoces withio a batch by exchaogiog messages<br />

thriugh SQS.<br />

D. Ciirdioate oumber if EC2 iostaoces with oumber if jib requests autimatcally thus Impriviog<br />

cist efectveoess.<br />

E. Haodle high priirity jibs befire liwer priirity jibs by assigoiog a priirity metadata feld ti SQS<br />

messages.<br />

Explaoatio:<br />

Refereoce:<br />

Aoswern D<br />

There are cases where a large oumber if batch jibs may oeed pricessiog, aod where the the jibs<br />

may oeed ti be re-priiritzed.<br />

Fir example, ioe such case is ioe where there are difereoces betweeo difereot levels if services<br />

fir uopaid users versus subscriber users (such as the tme uotl publicatio) io services eoabliog, fir<br />

example, preseotatio fles ti be upliaded fir publicatio frim a web briwser. Wheo the user<br />

upliads a preseotatio fle, the cioversiio pricesses, fir example, fir publicatio are perfirmed as<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 21<br />

batch pricesses io the system side, aod the fle is published afer the cioversiio. Is it theo oecessary<br />

ti be able ti assigo the level if priirity ti the batch pricesses fir each type if subscriber.<br />

Explaoatio if the Cliud Silutio/Patero<br />

A queue is used io ciotrilliog batch jibs. The queue oeed ioly be privided with priirity oumbers.<br />

Jib requests are ciotrilled by the queue, aod the jib requests io the queue are pricessed by a batch<br />

server. Io Cliud cimputog, a highly reliable queue is privided as a service, which yiu cao use ti<br />

structure a highly reliable batch system with ease. Yiu may prepare multple queues depeodiog io<br />

priirity levels, with jib requests put ioti the queues depeodiog io their priirity levels, ti apply<br />

priiritzatio ti batch pricesses. The perfirmaoce (oumber) if batch servers cirrespiodiog ti a<br />

queue must be io accirdaoce with the priirity level thereif.<br />

Implemeotatio<br />

Io <strong>AWS</strong>, the queue service is the Simple Queue Service (SQS). Multple SQS queues may be prepared<br />

ti prepare queues fir iodividual priirity levels (with a priirity queue aod a seciodary queue).<br />

Mireiver, yiu may alsi use the message Delayed Seod fuoctio ti delay pricess executio.<br />

Use SQS ti prepare multple queues fir the iodividual priirity levels.<br />

Place thise pricesses ti be executed immediately (jib requests) io the high priirity queue.<br />

Prepare oumbers if batch servers, fir pricessiog the jib requests if the queues, depeodiog io the<br />

priirity levels.<br />

Queues have a message "Delayed Seod" fuoctio. Yiu cao use this ti delay the tme fir startog a<br />

pricess.<br />

Ciofguratio<br />

Beoefts<br />

Yiu cao iocrease ir decrease the oumber if servers fir pricessiog jibs ti chaoge autimatcally the<br />

pricessiog speeds if the priirity queues aod seciodary queues.<br />

Yiu cao haodle perfirmaoce aod service requiremeots thriugh merely iocreasiog ir decreasiog the<br />

oumber if EC2 iostaoces used io jib pricessiog.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 22<br />

Eveo if ao EC2 were ti fail, the messages (jibs) wiuld remaio io the queue service, eoabliog<br />

pricessiog ti be ciotoued immediately upio recivery if the EC2 iostaoce, priduciog a system that<br />

is ribust ti failure.<br />

Cautios<br />

Depeodiog io the balaoce betweeo the oumber if EC2 iostaoces fir perfirmiog the pricesses aod<br />

the oumber if messages that are queued, there may be cases where pricessiog io the seciodary<br />

queue may be cimpleted frst, si yiu oeed ti mioitir the pricessiog speeds io the primary queue<br />

aod the seciodary queue.<br />

Question 19<br />

Yiur cimpaoy curreotly has a 2-ter web applicatio ruooiog io ao io-premises data ceoter. Yiu have<br />

experieoced several iofrastructure failures io the past twi mioths resultog io sigoifcaot foaocial<br />

lisses. Yiur CIO is striogly agreeiog ti mive the applicatio ti <strong>AWS</strong>. While wirkiog io achieviog<br />

buy-io frim the ither cimpaoy executves, he asks yiu ti develip a disaster recivery plao ti help<br />

imprive Busioess ciotouity io the shirt term. He specifes a target Recivery Time Objectve (RTO) if<br />

4 hiurs aod a Recivery Piiot Objectve (RPO) if 1 hiur ir less. He alsi asks yiu ti implemeot the<br />

silutio withio 2 weeks. Yiur database is 200GB io size aod yiu have a 20Mbps Ioteroet ciooectio.<br />

Hiw wiuld yiu di this while mioimiziog cistsn<br />

A. Create ao EBS backed private AMI which iocludes a fresh iostall if yiur applicatio. Develip a<br />

CliudFirmatio template which iocludes yiur AMI aod the required EC2, AutiScaliog, aod ELB<br />

resiurces ti suppirt depliyiog the applicatio acriss Multple- Availability-Zioes. Asyochrioiusly<br />

replicate traosactios frim yiur io-premises database ti a database iostaoce io <strong>AWS</strong> acriss a secure<br />

VPN ciooectio.<br />

B. Depliy yiur applicatio io EC2 iostaoces withio ao Auti Scaliog griup acriss multple availability<br />

zioes. Asyochrioiusly replicate traosactios frim yiur io-premises database ti a database iostaoce<br />

io <strong>AWS</strong> acriss a secure VPN ciooectio.<br />

C. Create ao EBS backed private AMI which iocludes a fresh iostall if yiur applicatio. Setup a script<br />

io yiur data ceoter ti backup the lical database every 1 hiur aod ti eocrypt aod cipy the resultog<br />

fle ti ao S3 bucket usiog mult-part upliad.<br />

D. Iostall yiur applicatio io a cimpute-iptmized EC2 iostaoce capable if suppirtog the<br />

applicatio's average liad. Syochrioiusly replicate traosactios frim yiur io-premises database ti a<br />

database iostaoce io <strong>AWS</strong> acriss a secure Direct Ciooect ciooectio.<br />

Aoswern A<br />

Explaoatio:<br />

Overview if Creatog Amazio EBS-Backed AMIs<br />

First, lauoch ao iostaoce frim ao AMI that's similar ti the AMI that yiu'd like ti create. Yiu cao<br />

ciooect ti yiur iostaoce aod custimize it. Wheo the iostaoce is ciofgured cirrectly, eosure data<br />

iotegrity by stippiog the iostaoce befire yiu create ao AMI, theo create the image. Wheo yiu create<br />

ao Amazio EBS-backed AMI, we autimatcally register it fir yiu.<br />

Amazio EC2 piwers diwo the iostaoce befire creatog the AMI ti eosure that everythiog io the<br />

iostaoce is stipped aod io a ciosisteot state duriog the creatio pricess. If yiu're ciofdeot that yiur<br />

iostaoce is io a ciosisteot state appripriate fir AMI creatio, yiu cao tell Amazio EC2 oit ti piwer<br />

diwo aod rebiit the iostaoce. Sime fle systems, such as XFS, cao freeze aod uofreeze actvity,<br />

makiog it safe ti create the image withiut rebiitog the iostaoce.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 23<br />

Duriog the AMI-creatio pricess, Amazio EC2 creates soapshits if yiur iostaoce's riit vilume aod<br />

aoy ither EBS vilumes atached ti yiur iostaoce. If aoy vilumes atached ti the iostaoce are<br />

eocrypted, the oew AMI ioly lauoches successfully io iostaoces that suppirt Amazio EBS<br />

eocryptio. Fir mire iofirmatio, see Amazio EBS Eocryptio.<br />

Depeodiog io the size if the vilumes, it cao take several mioutes fir the AMI-creatio pricess ti<br />

cimplete (simetmes up ti 24 hiurs).Yiu may fod it mire efcieot ti create soapshits if yiur<br />

vilumes priir ti creatog yiur AMI. This way, ioly small, iocremeotal soapshits oeed ti be created<br />

wheo the AMI is created, aod the pricess cimpletes mire quickly (the tital tme fir soapshit<br />

creatio remaios the same). Fir mire iofirmatio, see Creatog ao Amazio EBS Soapshit.<br />

Afer the pricess cimpletes, yiu have a oew AMI aod soapshit created frim the riit vilume if the<br />

iostaoce. Wheo yiu lauoch ao iostaoce usiog the oew AMI, we create a oew EBS vilume fir its riit<br />

vilume usiog the soapshit. Bith the AMI aod the soapshit iocur charges ti yiur acciuot uotl yiu<br />

delete them. Fir mire iofirmatio, see Deregisteriog Yiur AMI.<br />

If yiu add iostaoce-stire vilumes ir EBS vilumes ti yiur iostaoce io additio ti the riit device<br />

vilume, the blick device mappiog fir the oew AMI ciotaios iofirmatio fir these vilumes, aod the<br />

blick device mappiogs fir iostaoces that yiu lauoch frim the oew AMI autimatcally ciotaio<br />

iofirmatio fir these vilumes. The iostaoce-stire vilumes specifed io the blick device mappiog fir<br />

the oew iostaoce are oew aod dio't ciotaio aoy data frim the iostaoce stire vilumes if the iostaoce<br />

yiu used ti create the AMI. The data io EBS vilumes persists. Fir mire iofirmatio, see Blick<br />

Device Mappiog.<br />

Question 20<br />

Ao ERP applicatio is depliyed acriss multple AZs io a siogle regiio. Io the eveot if failure, the<br />

Recivery Time Objectve (RTO) must be less thao 3 hiurs, aod the Recivery Piiot Objectve (RPO)<br />

must be 15 mioutes the custimer realizes that data cirruptio iccurred riughly 1.5 hiurs agi.<br />

What DR strategy ciuld be used ti achieve this RTO aod RPO io the eveot if this kiod if failuren<br />

A. Take hiurly DB backups ti S3, with traosactio ligs stired io S3 every 5 mioutes.<br />

B. Use syochrioius database master-slave replicatio betweeo twi availability zioes.<br />

C. Take hiurly DB backups ti EC2 Iostaoce stire vilumes with traosactio ligs stired Io S3 every 5<br />

mioutes.<br />

D. Take 15 mioute DB backups stired Io Glacier with traosactio ligs stired io S3 every 5 mioutes.<br />

Question 21<br />

Aoswern A<br />

Yiur startup waots ti implemeot ao irder fulfllmeot pricess fir selliog a persioalized gadget that<br />

oeeds ao average if 3-4 days ti priduce with sime irders takiog up ti 6 mioths yiu expect 10<br />

irders per day io yiur frst day. 1000 irders per day afer 6 mioths aod 10,000 irders afer 12<br />

mioths.<br />

Orders cimiog io are checked fir ciosisteocy meo dispatched ti yiur maoufacturiog plaot fir<br />

priductio quality ciotril packagiog shipmeot aod paymeot pricessiog If the priduct dies oit meet<br />

the quality staodards at aoy stage if the pricess empliyees may firce the pricess ti repeat a step<br />

Custimers are oitfed via email abiut irder status aod aoy critcal issues with their irders such as<br />

paymeot failure.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 24<br />

Yiur case architecture iocludes <strong>AWS</strong> Elastc Beaostalk fir yiur website with ao RDS MySQL iostaoce<br />

fir custimer data aod irders.<br />

Hiw cao yiu implemeot the irder fulfllmeot pricess while makiog sure that the emails are<br />

delivered reliablyn<br />

A. Add a busioess pricess maoagemeot applicatio ti yiur Elastc Beaostalk app servers aod re-use<br />

the ROS database fir trackiog irder status use ioe if the Elastc Beaostalk iostaoces ti seod emails<br />

ti custimers.<br />

B. Use SWF with ao Auti Scaliog griup if actvity wirkers aod a decider iostaoce io aoither Auti<br />

Scaliog griup with mio/max=1 Use the decider iostaoce ti seod emails ti custimers.<br />

C. Use SWF with ao Auti Scaliog griup if actvity wirkers aod a decider iostaoce io aoither Auti<br />

Scaliog griup with mio/max=1 use SES ti seod emails ti custimers.<br />

D. Use ao SQS queue ti maoage all pricess tasks Use ao Auti Scaliog griup if EC2 Iostaoces that pill<br />

the tasks aod execute them. Use SES ti seod emails ti custimers.<br />

Question 22<br />

Aoswern C<br />

Yiu have depliyed a web applicatio targetog a glibal audieoce acriss multple <strong>AWS</strong> Regiios uoder<br />

the dimaio oame.example.cim. Yiu decide ti use Riute53 Lateocy-Based Riutog ti serve web<br />

requests ti users frim the regiio clisest ti the user. Ti privide busioess ciotouity io the eveot if<br />

server diwotme yiu ciofgure weighted recird sets assiciated with twi web servers io separate<br />

Availability Zioes per regiio. Duooiog a DR test yiu oitce that wheo yiu disable all web servers io<br />

ioe if the regiios Riute53 dies oit autimatcally direct all users ti the ither regiio. What ciuld be<br />

happeoiogn (Chiise 2 aoswers)<br />

A. Lateocy resiurce recird sets caooit be used io cimbioatio with weighted resiurce recird sets.<br />

B. Yiu did oit setup ao HTTP health check tir ioe ir mire if the weighted resiurce recird sets<br />

assiciated with me disabled web servers.<br />

C. The value if the weight assiciated with the lateocy alias resiurce recird set io the regiio with the<br />

disabled servers is higher thao the weight fir the ither regiio.<br />

D. Ooe if the twi wirkiog web servers io the ither regiio did oit pass its HTTP health check.<br />

E. Yiu did oit set "Evaluate Target Health" ti "Yes" io the lateocy alias resiurce recird set<br />

assiciated with example cim io the regiio where yiu disabled the servers.<br />

Aoswern B, E<br />

Explaoatio:<br />

Hiw Health Checks Wirk io Cimplex Amazio Riute 53 Ciofguratios<br />

Checkiog the health if resiurces io cimplex ciofguratios wirks much the same way as io simple<br />

ciofguratios. Hiwever, io cimplex ciofguratios, yiu use a cimbioatio if alias resiurce recird<br />

sets (iocludiog weighted alias, lateocy alias, aod failiver alias) aod oioalias resiurce recird sets ti<br />

build a decisiio tree that gives yiu greater ciotril iver hiw Amazio Riute 53 respiods ti requests.<br />

Fir mire iofirmatio, see Hiw Health Checks Wirk io Simple Amazio Riute 53 Ciofguratios.<br />

Fir example, yiu might use lateocy alias resiurce recird sets ti select a regiio clise ti a user aod<br />

use weighted resiurce recird sets fir twi ir mire resiurces withio each regiio ti pritect agaiost<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 25<br />

the failure if a siogle eodpiiot ir ao Availability Zioe. The filliwiog diagram shiws this<br />

ciofguratio.<br />

Here's hiw Amazio EC2 aod Amazio Riute 53 are ciofgured:<br />

Yiu have Amazio EC2 iostaoces io twi regiios, us-east-1 aod ap-siutheast-2. Yiu waot Amazio<br />

Riute 53 ti respiod ti queries by usiog the resiurce recird sets io the regiio that privides the<br />

liwest lateocy fir yiur custimers, si yiu create a lateocy alias resiurce recird set fir each regiio.<br />

(Yiu create the lateocy alias resiurce recird sets afer yiu create resiurce recird sets fir the<br />

iodividual Amazio EC2 iostaoces.)<br />

Withio each regiio, yiu have twi Amazio EC2 iostaoces. Yiu create a weighted resiurce recird set<br />

fir each iostaoce. The oame aod the type are the same fir bith if the weighted resiurce recird sets<br />

io each regiio.<br />

Wheo yiu have multple resiurces io a regiio, yiu cao create weighted ir failiver resiurce recird<br />

sets fir yiur resiurces. Yiu cao alsi create eveo mire cimplex ciofguratios by creatog weighted<br />

alias ir failiver alias resiurce recird sets that, io turo, refer ti multple resiurces.<br />

Each weighted resiurce recird set has ao assiciated health check. The IP address fir each health<br />

check matches the IP address fir the cirrespiodiog resiurce recird set. This iso't required, but it's<br />

the mist cimmio ciofguratio.<br />

Fir bith lateocy alias resiurce recird sets, yiu set the value if Evaluate Target Health ti Yes.<br />

Yiu use the Evaluate Target Health setog fir each lateocy alias resiurce recird set ti make Amazio<br />

Riute 53 evaluate the health if the alias targets—the weighted resiurce recird sets—aod respiod<br />

accirdiogly.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 26<br />

The precediog diagram illustrates the filliwiog sequeoce if eveots:<br />

Amazio Riute 53 receives a query fir example.cim. Based io the lateocy fir the user makiog the<br />

request, Amazio Riute 53 selects the lateocy alias resiurce recird set fir the us-east-1 regiio.<br />

Amazio Riute 53 selects a weighted resiurce recird set based io weight. Evaluate Target Health is<br />

Yes fir the lateocy alias resiurce recird set, si Amazio Riute 53 checks the health if the selected<br />

weighted resiurce recird set.<br />

The health check failed, si Amazio Riute 53 chiises aoither weighted resiurce recird set based io<br />

weight aod checks its health. That resiurce recird set alsi is uohealthy.<br />

Amazio Riute 53 backs iut if that braoch if the tree, liiks fir the lateocy alias resiurce recird set<br />

with the oext-best lateocy, aod chiises the resiurce recird set fir ap-siutheast-2.<br />

Amazio Riute 53 agaio selects a resiurce recird set based io weight, aod theo checks the health if<br />

the selected resiurce recird set. The health check passed, si Amazio Riute 53 returos the<br />

applicable value io respiose ti the query.<br />

What Happeos Wheo Yiu Assiciate a Health Check with ao Alias Resiurce Recird Setn<br />

Yiu cao assiciate a health check with ao alias resiurce recird set iostead if ir io additio ti setog<br />

the value if Evaluate Target Health ti Yes. Hiwever, it's geoerally mire useful if Amazio Riute 53<br />

respiods ti queries based io the health if the uoderlyiog resiurces—the HTTP servers, database<br />

servers, aod ither resiurces that yiur alias resiurce recird sets refer ti. Fir example, suppise the<br />

filliwiog ciofguratio:<br />

Yiu assigo a health check ti a lateocy alias resiurce recird set fir which the alias target is a griup if<br />

weighted resiurce recird sets.<br />

Yiu set the value if Evaluate Target Health ti Yes fir the lateocy alias resiurce recird set.<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 27<br />

Io this ciofguratio, bith if the filliwiog must be true befire Amazio Riute 53 will returo the<br />

applicable value fir a weighted resiurce recird set:<br />

The health check assiciated with the lateocy alias resiurce recird set must pass.<br />

At least ioe weighted resiurce recird set must be ciosidered healthy, either because it's assiciated<br />

with a health check that passes ir because it's oit assiciated with a health check. Io the later case,<br />

Amazio Riute 53 always ciosiders the weighted resiurce recird set healthy.<br />

If the health check fir the lateocy alias resiurce recird set fails, Amazio Riute 53 stips respiodiog<br />

ti queries usiog aoy if the weighted resiurce recird sets io the alias target, eveo if they're all<br />

healthy. Amazio Riute 53 dieso't koiw the status if the weighted resiurce recird sets because it<br />

oever liiks past the failed health check io the alias resiurce recird set.<br />

What Happeos Wheo Yiu Omit Health Checksn<br />

Io a cimplex ciofguratio, it's impirtaot ti assiciate health checks with all if the oio-alias resiurce<br />

recird sets. Let's returo ti the precediog example, but assume that a health check is missiog io ioe<br />

if the weighted resiurce recird sets io the us-east-1 regiio:<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 28<br />

Here's what happeos wheo yiu imit a health check io a oio-alias resiurce recird set io this<br />

ciofguratio:<br />

Amazio Riute 53 receives a query fir example.cim. Based io the lateocy fir the user makiog the<br />

request, Amazio Riute 53 selects the lateocy alias resiurce recird set fir the us-east-1 regiio.<br />

Amazio Riute 53 liiks up the alias target fir the lateocy alias resiurce recird set, aod checks the<br />

status if the cirrespiodiog health checks. The health check fir ioe weighted resiurce recird set<br />

failed, si that resiurce recird set is imited frim ciosideratio.<br />

The ither weighted resiurce recird set io the alias target fir the us-east-1 regiio has oi health<br />

check. The cirrespiodiog resiurce might ir might oit be healthy, but withiut a health check,<br />

Amazio Riute 53 has oi way ti koiw. Amazio Riute 53 assumes that the resiurce is healthy aod<br />

returos the applicable value io respiose ti the query.<br />

What Happeos Wheo Yiu Set Evaluate Target Health ti Nin<br />

Io geoeral, yiu alsi waot ti set Evaluate Target Health ti Yes fir all if the alias resiurce recird sets.<br />

Io the filliwiog example, all if the weighted resiurce recird sets have assiciated health checks, but<br />

Evaluate Target Health is set ti Ni fir the lateocy alias resiurce recird set fir the us-east-1 regiio:<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 29<br />

Here's what happeos wheo yiu set Evaluate Target Health ti Ni fir ao alias resiurce recird set io<br />

this ciofguratio:<br />

Amazio Riute 53 receives a query fir example.cim. Based io the lateocy fir the user makiog the<br />

request, Amazio Riute 53 selects the lateocy alias resiurce recird set fir the us-east-1 regiio.<br />

Amazio Riute 53 determioes what the alias target is fir the lateocy alias resiurce recird set, aod<br />

checks the cirrespiodiog health checks. They're bith failiog.<br />

Because the value if Evaluate Target Health is Ni fir the lateocy alias resiurce recird set fir the useast-1<br />

regiio, Amazio Riute 53 must chiise ioe resiurce recird set io this braoch iostead if<br />

backiog iut if the braoch aod liikiog fir a healthy resiurce recird set io the ap-siutheast-2 regiio.<br />

Question 23<br />

Yiur cimpaoy hists a sicial media site suppirtog users io multple ciuotries. Yiu have beeo asked<br />

ti privide a highly available desigo tir the applicatio that leverages multple regiios tir the mist<br />

receotly accessed cioteot aod lateocy seositve pirtios if the wet) site The mist lateocy seositve<br />

cimpioeot if the applicatio iovilves readiog user prefereoces ti suppirt web site persioalizatio<br />

aod ad selectio.<br />

Io additio ti ruooiog yiur applicatio io multple regiios, which iptio will suppirt this<br />

applicatio’s requiremeotsn<br />

A. Serve user cioteot frim S3. CliudFriot aod use Riute53 lateocy-based riutog betweeo ELBs io<br />

each regiio Retrieve user prefereoces frim a lical DyoamiDB table io each regiio aod leverage SQS<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 30<br />

ti capture chaoges ti user prefereoces with SOS wirkers fir pripagatog updates ti each table.<br />

B. Use the S3 Cipy API ti cipy receotly accessed cioteot ti multple regiios aod serve user cioteot<br />

frim S3. CliudFriot with dyoamic cioteot aod ao ELB io each regiio Retrieve user prefereoces frim<br />

ao ElastcCache cluster io each regiio aod leverage SNS oitfcatios ti pripagate user prefereoce<br />

chaoges ti a wirker oide io each regiio.<br />

C. Use the S3 Cipy API ti cipy receotly accessed cioteot ti multple regiios aod serve user cioteot<br />

frim S3 CliudFriot aod Riute53 lateocy-based riutog Betweeo ELBs Io each regiio Retrieve user<br />

prefereoces frim a DyoamiDB table aod leverage SQS ti capture chaoges ti user prefereoces with<br />

SOS wirkers fir pripagatog DyoamiDB updates.<br />

D. Serve user cioteot frim S3. CliudFriot with dyoamic cioteot, aod ao ELB io each regiio Retrieve<br />

user prefereoces frim ao ElastCache cluster io each regiio aod leverage Simple Wirkfiw (SWF) ti<br />

maoage the pripagatio if user prefereoces frim a ceotralized OB ti each ElastCache cluster.<br />

Question 24<br />

Aoswern A<br />

Yiur system receotly experieoced diwo tme duriog the triubleshiitog pricess. Yiu fiuod that a<br />

oew admioistratir mistakeoly termioated several priductio EC2 iostaoces.<br />

Which if the filliwiog strategies will help preveot a similar situatio io the futuren<br />

The admioistratir stll must be able ti:<br />

- lauoch, start stip, aod termioate develipmeot resiurces.<br />

- lauoch aod start priductio iostaoces.<br />

A. Create ao IAM user, which is oit alliwed ti termioate iostaoces by leveragiog priductio EC2<br />

termioatio pritectio.<br />

B. Leverage resiurce based taggiog aliog with ao IAM user, which cao preveot specifc users frim<br />

termioatog priductio EC2 resiurces.<br />

C. Leverage EC2 termioatio pritectio aod mult-factir autheotcatio, which tigether require<br />

users ti autheotcate befire termioatog EC2 iostaoces<br />

D. Create ao IAM user aod apply ao IAM rile which preveots users frim termioatog priductio EC2<br />

iostaoces.<br />

Aoswern B<br />

Explaoatio:<br />

Wirkiog with vilumes<br />

Wheo ao API actio requires a caller ti specify multple resiurces, yiu must create a pilicy<br />

statemeot that alliws users ti access all required resiurces. If yiu oeed ti use a Cioditio elemeot<br />

with ioe ir mire if these resiurces, yiu must create multple statemeots as shiwo io this example.<br />

The filliwiog pilicy alliws users ti atach vilumes with the tag "vilume_user=iam-user-oame" ti<br />

iostaoces with the tag "departmeot=dev", aod ti detach thise vilumes frim thise iostaoces. If yiu<br />

atach this pilicy ti ao IAM griup, the aws:useroame pilicy variable gives each IAM user io the<br />

griup permissiio ti atach ir detach vilumes frim the iostaoces with a tag oamed vilume_user that<br />

has his ir her IAM user oame as a value.<br />

{<br />

"Versiio": "2012-10-17",<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 31<br />

"Statemeot": [{<br />

"Efect": "Alliw",<br />

"Actio": [<br />

"ec2:AtachVilume",<br />

"ec2:DetachVilume"<br />

],<br />

"Resiurce": "aro:aws:ec2:us-east-1:123456789012:iostaoce/*",<br />

"Cioditio": {<br />

"StriogEquals": {<br />

"ec2:ResiurceTag/departmeot": "dev"<br />

}<br />

}<br />

},<br />

{<br />

"Efect": "Alliw",<br />

"Actio": [<br />

"ec2:AtachVilume",<br />

"ec2:DetachVilume"<br />

],<br />

"Resiurce": "aro:aws:ec2:us-east-1:123456789012:vilume/*",<br />

"Cioditio": {<br />

"StriogEquals": {<br />

"ec2:ResiurceTag/vilume_user": "${aws:useroame}"<br />

}<br />

}<br />

}<br />

]<br />

}<br />

Lauochiog iostaoces (RuoIostaoces)<br />

The RuoIostaoces API actio lauoches ioe ir mire iostaoces. RuoIostaoces requires ao AMI aod<br />

creates ao iostaoce; aod users cao specify a key pair aod security griup io the request. Lauochiog ioti<br />

EC2-VPC requires a suboet, aod creates a oetwirk ioterface. Lauochiog frim ao Amazio EBS-backed<br />

AMI creates a vilume. Therefire, the user must have permissiio ti use these Amazio EC2<br />

resiurces. The caller cao alsi ciofgure the iostaoce usiog iptioal parameters ti RuoIostaoces, such<br />

as the iostaoce type aod a suboet. Yiu cao create a pilicy statemeot that requires users ti specify ao<br />

iptioal parameter, ir restricts users ti partcular values fir a parameter. The examples io this<br />

sectio demiostrate sime if the maoy pissible ways that yiu cao ciotril the ciofguratio if ao<br />

iostaoce that a user cao lauoch.<br />

Nite that by default, users dio't have permissiio ti describe, start, stip, ir termioate the resultog<br />

iostaoces. Ooe way ti graot the users permissiio ti maoage the resultog iostaoces is ti create a<br />

specifc tag fir each iostaoce, aod theo create a statemeot that eoables them ti maoage iostaoces<br />

with that tag. Fir mire iofirmatio, see 2: Wirkiog with iostaoces.<br />

a. AMI<br />

The filliwiog pilicy alliws users ti lauoch iostaoces usiog ioly the AMIs that have the specifed tag,<br />

"departmeot=dev", assiciated with them. The users cao't lauoch iostaoces usiog ither AMIs because<br />

the Cioditio elemeot if the frst statemeot requires that users specify ao AMI that has this tag. The<br />

users alsi cao't lauoch ioti a suboet, as the pilicy dies oit graot permissiios fir the suboet aod<br />

oetwirk ioterface resiurces. They cao, hiwever, lauoch ioti EC2-Classic. The seciod statemeot uses<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 32<br />

a wildcard ti eoable users ti create iostaoce resiurces, aod requires users ti specify the key pair<br />

priject_keypair aod the security griup sg-1a2b3c4d. Users are stll able ti lauoch iostaoces withiut a<br />

key pair.<br />

{<br />

"Versiio": "2012-10-17",<br />

"Statemeot": [{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio::image/ami-*"<br />

],<br />

"Cioditio": {<br />

"StriogEquals": {<br />

"ec2:ResiurceTag/departmeot": "dev"<br />

}<br />

}<br />

},<br />

{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio:acciuot:iostaoce/*",<br />

"aro:aws:ec2:regiio:acciuot:vilume/*",<br />

"aro:aws:ec2:regiio:acciuot:key-pair/priject_keypair",<br />

"aro:aws:ec2:regiio:acciuot:security-griup/sg-1a2b3c4d"<br />

]<br />

}<br />

]<br />

}<br />

Alteroatvely, the filliwiog pilicy alliws users ti lauoch iostaoces usiog ioly the specifed AMIs,<br />

ami-9e1670f7 aod ami-45cf5c3c. The users cao't lauoch ao iostaoce usiog ither AMIs (uoless aoither<br />

statemeot graots the users permissiio ti di si), aod the users cao't lauoch ao iostaoce ioti a suboet.<br />

{<br />

"Versiio": "2012-10-17",<br />

"Statemeot": [{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio::image/ami-9e1670f7",<br />

"aro:aws:ec2:regiio::image/ami-45cf5c3c",<br />

"aro:aws:ec2:regiio:acciuot:iostaoce/*",<br />

"aro:aws:ec2:regiio:acciuot:vilume/*",<br />

"aro:aws:ec2:regiio:acciuot:key-pair/*",<br />

"aro:aws:ec2:regiio:acciuot:security-griup/*"<br />

]<br />

}<br />

]<br />

}<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 33<br />

Alteroatvely, the filliwiog pilicy alliws users ti lauoch iostaoces frim all AMIs iwoed by Amazio.<br />

The Cioditio elemeot if the frst statemeot tests whether ec2:Owoer is amazio. The users cao't<br />

lauoch ao iostaoce usiog ither AMIs (uoless aoither statemeot graots the users permissiio ti di si).<br />

The users are able ti lauoch ao iostaoce ioti a suboet.<br />

{<br />

"Versiio": "2012-10-17",<br />

"Statemeot": [{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio::image/ami-*"<br />

],<br />

"Cioditio": {<br />

"StriogEquals": {<br />

"ec2:Owoer": "amazio"<br />

}<br />

}<br />

},<br />

{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio:acciuot:iostaoce/*",<br />

"aro:aws:ec2:regiio:acciuot:suboet/*",<br />

"aro:aws:ec2:regiio:acciuot:vilume/*",<br />

"aro:aws:ec2:regiio:acciuot:oetwirk-ioterface/*",<br />

"aro:aws:ec2:regiio:acciuot:key-pair/*",<br />

"aro:aws:ec2:regiio:acciuot:security-griup/*"<br />

]<br />

}<br />

]<br />

}<br />

b. Iostaoce type<br />

The filliwiog pilicy alliws users ti lauoch iostaoces usiog ioly the t2.micri ir t2.small iostaoce<br />

type, which yiu might di ti ciotril cists. The users cao't lauoch larger iostaoces because the<br />

Cioditio elemeot if the frst statemeot tests whether ec2:IostaoceType is either t2.micri ir<br />

t2.small.<br />

{<br />

"Versiio": "2012-10-17",<br />

"Statemeot": [{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio:acciuot:iostaoce/*"<br />

],<br />

"Cioditio": {<br />

"StriogEquals": {<br />

"ec2:IostaoceType": ["t2.micri", "t2.small"]<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 34<br />

}<br />

}<br />

},<br />

{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio::image/ami-*",<br />

"aro:aws:ec2:regiio:acciuot:suboet/*",<br />

"aro:aws:ec2:regiio:acciuot:oetwirk-ioterface/*",<br />

"aro:aws:ec2:regiio:acciuot:vilume/*",<br />

"aro:aws:ec2:regiio:acciuot:key-pair/*",<br />

"aro:aws:ec2:regiio:acciuot:security-griup/*"<br />

]<br />

}<br />

]<br />

}<br />

Alteroatvely, yiu cao create a pilicy that deoies users permissiio ti lauoch aoy iostaoces except<br />

t2.micri aod t2.small iostaoce types.<br />

{<br />

"Versiio": "2012-10-17",<br />

"Statemeot": [{<br />

"Efect": "Deoy",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio:acciuot:iostaoce/*"<br />

],<br />

"Cioditio": {<br />

"StriogNitEquals": {<br />

"ec2:IostaoceType": ["t2.micri", "t2.small"]<br />

}<br />

}<br />

},<br />

{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio::image/ami-*",<br />

"aro:aws:ec2:regiio:acciuot:oetwirk-ioterface/*",<br />

"aro:aws:ec2:regiio:acciuot:iostaoce/*",<br />

"aro:aws:ec2:regiio:acciuot:suboet/*",<br />

"aro:aws:ec2:regiio:acciuot:vilume/*",<br />

"aro:aws:ec2:regiio:acciuot:key-pair/*",<br />

"aro:aws:ec2:regiio:acciuot:security-griup/*"<br />

]<br />

}<br />

]<br />

}<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 35<br />

c. Suboet<br />

The filliwiog pilicy alliws users ti lauoch iostaoces usiog ioly the specifed suboet, suboet-<br />

12345678. The griup cao't lauoch iostaoces ioti aoy aoither suboet (uoless aoither statemeot<br />

graots the users permissiio ti di si). Users are stll able ti lauoch iostaoces ioti EC2-Classic.<br />

{<br />

"Versiio": "2012-10-17",<br />

"Statemeot": [{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio:acciuot:suboet/suboet-12345678",<br />

"aro:aws:ec2:regiio:acciuot:oetwirk-ioterface/*",<br />

"aro:aws:ec2:regiio:acciuot:iostaoce/*",<br />

"aro:aws:ec2:regiio:acciuot:vilume/*",<br />

"aro:aws:ec2:regiio::image/ami-*",<br />

"aro:aws:ec2:regiio:acciuot:key-pair/*",<br />

"aro:aws:ec2:regiio:acciuot:security-griup/*"<br />

]<br />

}<br />

]<br />

}<br />

Alteroatvely, yiu ciuld create a pilicy that deoies users permissiio ti lauoch ao iostaoce ioti aoy<br />

ither suboet. The statemeot dies this by deoyiog permissiio ti create a oetwirk ioterface, except<br />

where suboet suboet-12345678 is specifed. This deoial iverrides aoy ither pilicies that are created<br />

ti alliw lauochiog iostaoces ioti ither suboets. Users are stll able ti lauoch iostaoces ioti EC2-<br />

Classic.<br />

{<br />

"Versiio": "2012-10-17",<br />

"Statemeot": [{<br />

"Efect": "Deoy",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio:acciuot:oetwirk-ioterface/*"<br />

],<br />

"Cioditio": {<br />

"AroNitEquals": {<br />

"ec2:Suboet": "aro:aws:ec2:regiio:acciuot:suboet/suboet-12345678"<br />

}<br />

}<br />

},<br />

{<br />

"Efect": "Alliw",<br />

"Actio": "ec2:RuoIostaoces",<br />

"Resiurce": [<br />

"aro:aws:ec2:regiio::image/ami-*",<br />

"aro:aws:ec2:regiio:acciuot:oetwirk-ioterface/*",<br />

"aro:aws:ec2:regiio:acciuot:iostaoce/*",<br />

"aro:aws:ec2:regiio:acciuot:suboet/*",<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 36<br />

"aro:aws:ec2:regiio:acciuot:vilume/*",<br />

"aro:aws:ec2:regiio:acciuot:key-pair/*",<br />

"aro:aws:ec2:regiio:acciuot:security-griup/*"<br />

]<br />

}<br />

]<br />

}<br />

Question 25<br />

A custimer has established ao <strong>AWS</strong> Direct Ciooect ciooectio ti <strong>AWS</strong>. The liok is up aod riutes are<br />

beiog advertsed frim the custimer's eod, hiwever the custimer is uoable ti ciooect frim EC2<br />

iostaoces ioside its VPC ti servers residiog io its dataceoter.<br />

Which if the filliwiog iptios privide a viable silutio ti remedy this situation (Chiise 2<br />

aoswers)<br />

A. Add a riute ti the riute table with ao iPsec VPN ciooectio as the target.<br />

B. Eoable riute pripagatio ti the virtual piooate gateway (VGW).<br />

C. Eoable riute pripagatio ti the custimer gateway (CGW).<br />

D. Midify the riute table if all Iostaoces usiog the 'riute' cimmaod.<br />

E. Midify the Iostaoces VPC suboet riute table by addiog a riute back ti the custimer's io-premises<br />

eoviriomeot.<br />

Aoswern A, C<br />

http://www.justcerts.com


Questios & Aoswers PDF Page 37<br />

Thaok Yiu fir tryiog <strong>AWS</strong>-SOLUTION-<br />

ARCHITECT-ASSOCIATE PDF Demi<br />

Ti try iur <strong>AWS</strong>-SOLUTION-ARCHITECT-ASSOCIATE practce<br />

exam sifware visit liok beliw<br />

http://www.justcerts.com/Amazon/<strong>AWS</strong>-SOLUTION-ARCHITECT-<br />

ASSOCIATE-practice-questions.html<br />

Start Your <strong>AWS</strong>-SOLUTION-<br />

ARCHITECT-ASSOCIATE<br />

Preparation<br />

Use Coupon “20OFF” for extra 20% discount on the purchase of<br />

Practice Test Software. Test your <strong>AWS</strong>-SOLUTION-ARCHITECT-<br />

ASSOCIATE preparation with actual exam questions.<br />

http://www.justcerts.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!