Pass the Amazon Web Services AWS Certified Associate SOA-C01 Questions and answers with CertsForce

Viewing page 3 out of 8 pages
Viewing questions 21-30 out of questions
Questions # 21:

A company is expanding its use of AWS services across its portfolios. The company wants to provision AWS accounts for each team to ensure a separation of business processes for security, compliance, and billing account creation and bootstrapping should be completed in a scalable and efficient way so new accounts are created with a defined baseline and governance guardrails in place. A sysops administrator needs to design a provisioning process that save time and resources.

Which action should be taken to meet these requirements?

Options:

A.

Automate using AWS Elastic Beanstalk to provision the AWS Accounts, set up infrastructure, and integrate with AWS Organizations.


B.

Create bootstrapping scripts in AWS OpsWorks and combine them with AWS CloudFormation templates to provision accounts and infrastructure.


C.

Use AWS config to provision accounts and deploy instances using AWS service catalog.


D.

Use AWS Control Tower to create a template in account factory and use the template to provision new accounts.


Expert Solution
Questions # 22:

An HTTP web application is launched on Amazon EC2 instances behind an ELB Application Load Balancer. The EC2 instances run across multiple Availability Zones. A network ACL and a security group for the load balancer and EC2 instances allow inbound traffic on port 80. After launch, the website cannot be reached over the internet.

What additional step should be taken?

Options:

A.

Add a rule to the security group allowing outbound traffic on port 80.


B.

Add a rule to the network ACL allowing outbound traffic on port 80.


C.

Add a rule to the security group allowing outbound traffic on ports 1024 through 65535.


D.

Add a rule to the network ACL allowing outbound traffic on ports 1024 through 65535.


Expert Solution
Questions # 23:

A company's Marketing department generates gigabytes of assets each day and stores them locally. They would like to protect the files by backing them up to AWS All the assets should be stored on the cloud but the most recent assets should be available locally for tow latency access

Which AWS service meets the requirements?

Options:

A.

Amazon EBS


B.

Amazon EFS


C.

Amazon S3


D.

AWS Storage Gateway


Expert Solution
Questions # 24:

A company has a business application hosted on Amazon EC2 instances behind an Application Load

Balancer. Amazon CloudWatch metrics show that the CPU utilization on the EC2 instances is very high. There are also reports from users that receive HTTP 503 and 504 errors when they try to connect to the application.

Which action will resolve these issues?

Options:

A.

Place the EC2 instances into an AWS Auto Scaling group.


B.

Configure the ALB's Target Group to use more frequent health checks.


C.

Enable sticky sessions on the Application Load Balancer.


D.

Increase the idle timeout setting of the Application Load Balancer.


Expert Solution
Questions # 25:

A web application accepts orders from online users and places the orders into an Amazon SQS queue. Amazon EC2 instances in an EC2 Auto Scaling group read the messages from the queue, process the orders, and email order confirmations to the users. The Auto Scaling group scales up and down based on the queue depth. At the beginning of each business day, users report confirmation emails are delayed.

What action will address this issue?

Options:

A.

Create a scheduled scaling action to scale up in anticipation of the traffic.


B.

Change the Auto Scaling group to scale up and down based on CPU utilization.


C.

Change the launch configuration to launch larger EC2 instance types.


D.

Modify the scaling policy to deploy more EC2 instances when scaling up.


Expert Solution
Questions # 26:

A company has a web application that is experiencing performance problems many times each night. A root cause analysis reveals spikes in CPU utilization that last 5 minutes on an Amazon EC2 Linux instance. A SysOps administrator is tasked with finding the process ID (PID) of the service or process that is consuming more CPU.

How can the administrator accomplish this with the LEAST amount of effort?

Options:

A.

Configure an AWS Lambda function in Python 3.7 to run every minute to capture the PID and send a notification.


B.

Configure the procstat plugin to collect and send CPU metrics for the running processes.


C.

Log in to the EC2 Linux instance using a .pern key each night and then run the top command


D.

Use the default Amazon CloudWatch CPU utilization metric to capture the PID in the CloudWatch dashboard.


Expert Solution
Questions # 27:

Developers are using 1AM access keys to manage AWS resources using AWS CL1 Company policy requires that access keys are automatically disabled when the access key age is greater than 90 days

Which solution will accomplish this?

Options:

A.

Configure an Amazon CloudWatch alarm to trigger an AWS Lambda function that disables keys older than 90 days


B.

Configure AWS Trusted Advisor to identify and disable keys older than 90 days.


C.

Set a password policy on the account with a 90-day expiration


D.

Use an AWS Config rule to identify noncompliant keys Create a custom AWS Systems Manager Automation document for remediation.


Expert Solution
Questions # 28:

A development team recently deployed new version of a web application to production. After the release, penetration testing revealed a cross-site scripting vulnerability that could expose user data.

Which AWS service will mitigate this issue?

Options:

A.

AWS Shield Standard


B.

AWS WAF


C.

Elastic Load balancing


D.

Amazon Cognito


Expert Solution
Questions # 29:

A security audit revealed that the security groups in a VPC have ports 22 and 3389 open to all. introducing a possible threat that instances can be stopped or configurations can be modified. A SysOps administrator needs to automate remediation.

What should the administrator do to meet these requirements?

Options:

A.

Create an 1AM managed policy lo deny access to ports 22 and 3389 on any security groups in a VPC.


B.

Define an AWS Config rule and remediation action with AWS Systems Manager automation documents.


C.

Enable AWS Trusted Advisor to remediate public port access.


D.

Use AWS Systems Manager configuration compliance to remediate public port access.


Expert Solution
Questions # 30:

An organization has developed a new memory-intensive application that is deployed to a large Amazon EC2 Linux fleet. There is concern about potential memory exhaustion, so the Development team wants to monitor memory usage by using Amazon CloudWatch.

What is the MOST efficient way to accomplish this goal?

Options:

A.

Deploy the solution to memory-optimized EC2 instances, and use the CloudWatch MemoryUtilization metric


B.

Enable the Memory Monitoring option by using AWS Config


C.

Install the AWS Systems Manager agent on the applicable EC2 instances to monitor memory


D.

Monitor memory by using a script within the instance, and send it to CloudWatch as a custom metric


Expert Solution
Viewing page 3 out of 8 pages
Viewing questions 21-30 out of questions