Pass the Amazon Web Services AWS Certified Associate SOA-C01 Questions and answers with CertsForce

Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions
Questions # 41:

A sysops administrator is trying to identify why putObject calls are not being made from an Amazon EC2 instance to an Amazon S3 bucket in the same region. The instance is launched in a subnet with CIDR range 10.0.1.0/24 and Auto-assign Public IP’ set to “yes”. The instance profile tied to this instance has ‘AmazonS3FullAccess” Policy.

Security group rules for the instance:

Question # 41

Based on the information provided, what is causing the lack of access to S3 from the instance?

Options:

A.

The instances profile does not have explicit permissions to write objects to the S3 bucket.


B.

The route table does not have a rule for all traffic to pass through a NAT gateway.


C.

The route table does not have a rule for all traffic to pass through an internet gateway.


D.

The security group does not allow all TCP and all UDP traffic.


Expert Solution
Questions # 42:

A company stores thousands of non-critical log files in an Amazon S3 bucket A set of reporting scripts retrieve these log files daily. Which of the following storage options will be the MOST cost efficient for the company's use case?

Options:

A.

Amazon Glacier


B.

Amazon S3 Standard IA (infrequent access) storage


C.

Amazon S3 Standard Storage


D.

AWS Snowball


Expert Solution
Questions # 43:

A SysOps administrator notices a scale-out event for an Amazon EC2 Auto Scaling group Amazon CloudWatch shows a spike in the RequestCount metric tor the associated Application Load Balancer The administrator would like to know the IP addresses for the source of the requests

Where can the administrator find this information?

Options:

A.

Auto Scaling logs


B.

AWS CloudTrail logs


C.

EC2 instance logs


D.

Elastic Load Balancer access logs


Expert Solution
Questions # 44:

A SysOps Administrator created an Amazon VPC with an IPv6 CIDR block, which requires access to the internet. However, access from the internet towards the VPC is prohibited. After adding and configuring the required components to the VPC, the Administrator is unable to connect to any of the domains that reside on the internet.

What additional route destination rule should the Administrator add to the route tables?

Options:

A.

Route ::/0 traffic to a NAT gateway


B.

Route ::/0 traffic to an internet gateway


C.

Route 0.0.0.0/0 traffic to an egress-only internet gateway


D.

Route ::/0 traffic to an egress-only internet gateway


Expert Solution
Questions # 45:

A SysOps Administrator must find a way to set up alerts when Amazon EC2 service limits are close to being reached.

How can the Administrator achieve this requirement?

Options:

A.

Use Amazon Inspector and Amazon CloudWatch Events.


B.

Use AWS Trusted Advisor and Amazon CloudWatch Events.


C.

Use the Personal Health Dashboard and CloudWatch Events.


D.

Use AWS CloudTrail and CloudWatch Events.


Expert Solution
Questions # 46:

Development teams are maintaining several workloads on AWS. Company management is concerned about rising costs and wants the SysOps Administrator to configure alerts so teams are notified when spending approaches preset limits.

Which AWS service will satisfy these requirements?

Options:

A.

AWS Budgets


B.

AWS Cost Explorer


C.

AWS Trusted Advisor


D.

AWS Cost and Usage report


Expert Solution
Questions # 47:

A company is deploying a web service to Amazon EC2 instances behind an Elastic Load Balancer. All resources will be defined and created in a single AWS CloudFormation stack using a template. The creation of each EC2 instance will not be considered complete until an initialization script has been run successfully on the EC2 instance. The Elastic Load Balancer cannot be created until all EC2 instances have been created.

Which CloudFormation resource will coordinate the Elastic Load Balancer creation in the CloudFormation stack template?

Options:

A.

CustomResource


B.

DependsOn


C.

Init


D.

WaitCondition


Expert Solution
Questions # 48:

A SysOps Administrator has an AWS CloudFormation template of the company’s existing infrastructure in us-west-2. The Administrator attempts to use the template to launch a new stack in eu-west-1, but the stack only partially deploys, receives an error message, and then rolls back.

Why would this template fail to deploy? (Choose two.)

Options:

A.

The template referenced an IAM user that is not available in eu-west-1


B.

The template referenced an Amazon Machine Image (AMI) that is not available in eu-west-1


C.

The template did not have the proper level of permissions to deploy the resources


D.

The template requested services that do not exist in eu-west-1


E.

CloudFormation templates can be used only to update existing services


Expert Solution
Questions # 49:

A SysOps Administrator is tasked with deploying and managing a single CloudFormation templates across multiple AWS Accounts.

accomplish this?

Options:

A.

change sets What features of AWS CloudFormation will


B.

Nested stacks


C.

Stack policies


D.

StacksSets


Expert Solution
Questions # 50:

An environment company has discovered that a number of Amazon EC2 instances in a VPC are marked as high risk according to a Common Vulnerabilities and Expressures (CVE) report. The Security tea, requests that all these instances be upgraded.

Who is responsible for upgrading the EC2 instances?

Options:

A.

The AWS Security team


B.

The Amazon EC2 team


C.

The AWS Premium Support team


D.

The company’s System Administrator


Expert Solution
Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions