Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Amazon Web Services AWS Certified Associate SOA-C03 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

A CloudOps engineer is preparing to deploy an application to Amazon EC2 instances that are in an Auto Scaling group. The application requires dependencies to be installed. Application updates are issued weekly.

The CloudOps engineer needs to implement a solution to incorporate the application updates on a regular basis. The solution also must conduct a vulnerability scan during Amazon Machine Image (AMI) creation.

What is the MOST operationally efficient solution that meets these requirements?

Options:

A.

Create a script that uses Packer and schedule a cron job.


B.

Install the application and dependencies on an EC2 instance and create an AMI.


C.

Use EC2 Image Builder with a custom recipe to install the application and dependencies.


D.

Invoke the EC2 CreateImage API operation by using an EventBridge scheduled rule.


Expert Solution
Questions # 12:

A CloudOps engineer has successfully deployed a VPC with an AWS CloudFormation template. The CloudOps engineer wants to deploy the same template across multiple accounts that are managed through AWS Organizations.

Which solution will meet this requirement with the LEAST operational overhead?

Options:

A.

Assume the OrganizationAccountAccessRole IAM role from the management account. Deploy the template in each of the accounts.


B.

Create an AWS Lambda function to assume a role in each account. Deploy the template by using the AWS CloudFormation CreateStack API call.


C.

Create an AWS Lambda function to query for a list of accounts. Deploy the template by using the AWS CloudFormation CreateStack API call.


D.

Use AWS CloudFormation StackSets from the management account to deploy the template in each of the accounts.


Expert Solution
Questions # 13:

A company’s ecommerce application is running on Amazon EC2 instances that are behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group. Customers report that the website is occasionally down. When the website is down, it returns an HTTP 500 (server error) status code to customer browsers.

The Auto Scaling group’s health check is configured for EC2 status checks, and the instances appear healthy.

Which solution will resolve the problem?

Options:

A.

Replace the ALB with a Network Load Balancer.


B.

Add Elastic Load Balancing (ELB) health checks to the Auto Scaling group.


C.

Update the target group configuration on the ALB. Enable session affinity (sticky sessions).


D.

Install the Amazon CloudWatch agent on all instances. Configure the agent to reboot the instances.


Expert Solution
Questions # 14:

A SysOps administrator needs to give an existing AWS Lambda function access to an existing Amazon S3 bucket. Traffic between the Lambda function and the S3 bucket must not use public IP addresses. The Lambda function has been configured to run in a VPC.

Which solution will meet these requirements?

Options:

A.

Configure VPC sharing between the Lambda VPC and the S3 bucket.


B.

Attach a transit gateway to the Lambda VPC to allow the Lambda function to connect to the S3 bucket.


C.

Create a NAT gateway. Associate the NAT gateway with the subnet where the Lambda function is configured to run.


D.

Create an S3 interface endpoint. Change the Lambda function to use the new S3 DNS name.


Expert Solution
Questions # 15:

A company has a workload that is sending log data to Amazon CloudWatch Logs. One of the fields includes a measure of application latency. A CloudOps engineer needs to monitor the p90 statistic of this field over time.

What should the CloudOps engineer do to meet this requirement?

Options:

A.

Create an Amazon CloudWatch Contributor Insights rule on the log data.


B.

Create a metric filter on the log data.


C.

Create a subscription filter on the log data.


D.

Create an Amazon CloudWatch Application Insights rule for the workload.


Expert Solution
Questions # 16:

A company has two AWS accounts connected by a transit gateway. Each account has one VPC in the same AWS Region. The company wants to simplify inbound and outbound rules in security groups by referencing security group IDs instead of IP CIDR blocks.

Which solution will meet this requirement?

Options:

A.

Create VPC peering connections and remove the transit gateway.


B.

Enable security group referencing support on the transit gateway.


C.

Enable security group referencing support on each transit gateway attachment.


D.

Deploy private NAT gateways in each VPC.


Expert Solution
Questions # 17:

A CloudOps engineer wants to provide access to AWS services by attaching an IAM policy to multiple IAM users. The CloudOps engineer also wants to be able to change the policy and create new versions.

Which combination of actions will meet these requirements? (Select TWO.)

Options:

A.

Add the users to an IAM service-linked role. Attach the policy to the role.


B.

Add the users to an IAM user group. Attach the policy to the group.


C.

Create an AWS managed policy.


D.

Create a customer managed policy.


E.

Create an inline policy.


Expert Solution
Questions # 18:

A company is storing backups in an Amazon S3 bucket. The backups must not be deleted for at least 3 months after the backups are created.

What should a CloudOps engineer do to meet this requirement?

Options:

A.

Configure an IAM policy that denies the s3:DeleteObject action for all users. Remove the policy after three months.


B.

Enable S3 Object Lock on a new S3 bucket in compliance mode. Place all backups in the new S3 bucket with a retention period of 3 months.


C.

Enable S3 Versioning on the existing S3 bucket. Configure S3 Lifecycle rules to protect the backups.


D.

Enable S3 Object Lock on a new S3 bucket in governance mode. Place all backups in the new S3 bucket with a retention period of 3 months.


Expert Solution
Questions # 19:

A company needs to upload gigabytes of files daily to Amazon S3 and requires higher throughput and faster upload speeds.

Which action should a CloudOps engineer take?

Options:

A.

Create an Amazon CloudFront distribution with the GET HTTP method allowed and the S3 bucket as an origin.


B.

Create an Amazon ElastiCache cluster and enable caching for the S3 bucket.


C.

Set up AWS Global Accelerator and configure it with the S3 bucket.


D.

Enable S3 Transfer Acceleration and use the acceleration endpoint when uploading files.


Expert Solution
Questions # 20:

A company has a multi-account AWS environment that includes the following:

• A central identity account that contains all IAM users and groups

• Several member accounts that contain IAM roles

A SysOps administrator must grant permissions for a particular IAM group to assume a role in one of the member accounts. How should the SysOps administrator accomplish this task?

Options:

A.

In the member account, add sts:AssumeRole permissions to the role's policy. In the identity account, add a trust policy to the group that specifies the account number of the member account.


B.

In the member account, add the group Amazon Resource Name (ARN) to the role's trust policy. In the identity account, add an inline policy to the group with sts:AssumeRole permissions.


C.

In the member account, add the group Amazon Resource Name (ARN) to the role's trust policy. In the identity account, add an inline policy to the group with sts:PassRole permissions.


D.

In the member account, add the group Amazon Resource Name (ARN) to the role's inline policy. In the identity account, add a trust policy to the group with sts:AssumeRole permissions.


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions