Which components are required to build a successful site-to-site vpn connection on aws?

Video:

1. Which service provides a user the ability to warehouse data in the AWS Cloud?

A. Amazon EFS
B. Amazon Redshift
C. Amazon RDS
D. Amazon VPC

2. A user is planning to migrate an application workload to the AWS Cloud. Which control becomes the responsibility of AWS once the migration is complete?

A. Patching the guest operating system
B. Maintaining physical and environmental controls
C. Protecting communications and maintaining zone security
D. Patching specific applications

3. Which AWS service can be used to provide an on-demand, cloud-based contact center?

A. AWS Direct Connect
B. Amazon Connect
C. AWS Support Center
D. AWS Managed Services

4. What tool enables customers without an AWS account to estimate costs for almost all AWS services?

A. Cost Explorer
B. TCO Calculator
C. AWS Budgets
D. Simple Monthly Calculator

5. Which component must be attached to a VPC to enable inbound Internet access?

A. NAT gateway
B. VPC endpoint
C. VPN connection
D. Internet gateway

6. Which pricing model would result in maximum Amazon Elastic Compute Cloud (Amazon EC2) savings for a database server that must be online for one year?

A. Spot Instance
B. On-Demand Instance
C. Partial Upfront Reserved Instance
D. No Upfront Reserved Instance

7. A company has a MySQL database running on a single Amazon EC2 instance. The company now requires higher availability in the event of an outage. Which set of tasks would meet this requirement?

A. Add an Application Load Balancer in front of the EC2 instance
B. Configure EC2 Auto Recovery to move the instance to another Availability Zone
C. Migrate to Amazon RDS and enable Multi-AZ
D. Enable termination protection for the EC2 instance to avoid outages

8. A company wants to ensure that AWS Management Console users are meeting password complexity requirements. How can the company configure password complexity?

A. Using an AWS IAM user policy
B. Using an AWS Organizations service control policy (SCP)
C. Using an AWS IAM account password policy
D. Using an AWS Security Hub managed insight

9. Under the AWS shared responsibility model, which of the following is the customer’s responsibility?

A. Patching guest OS and applications
B. Patching and fixing flaws in the infrastructure
C. Physical and environmental controls
D. Configuration of AWS infrastructure devices

10. Which of the following tasks is required to deploy a PCI-compliant workload on AWS?

A. Use any AWS service and implement PCI controls at the application layer
B. Use an AWS service that is in-scope for PCI compliance and raise an AWS support ticket to enable PCI compliance at the application layer
C. Use any AWS service and raise an AWS support ticket to enable PCI compliance on that service
D. Use an AWS service that is in scope for PCI compliance and apply PCI controls at the application layer

11. Which are benefits of using Amazon RDS over Amazon EC2 when running relational databases on AWS? (Choose two.)

A. Automated backups
B. Schema management
C. Indexing of tables
D. Software patching
E. Extract, transform, and load (ETL) management

12. What does the Amazon S3 Intelligent-Tiering storage class offer?

A. Payment flexibility by reserving storage capacity
B. Long-term retention of data by copying the data to an encrypted Amazon Elastic Block Store (Amazon EBS) volume
C. Automatic cost savings by moving objects between tiers based on access pattern changes
D. Secure, durable, and lowest cost storage for data archival

13. A company has multiple data sources across the organization and wants to consolidate data into one data warehouse. Which AWS service can be used to meet this requirement?

A. Amazon DynamoDB
B. Amazon Redshift
C. Amazon Athena
D. Amazon QuickSight

14. Which AWS service can be used to track resource changes and establish compliance?

A. Amazon CloudWatch
B. AWS Config
C. AWS CloudTrail
D. AWS Trusted Advisor

15. A user has underutilized on-premises resources. Which AWS Cloud concept can BEST address this issue?

A. High availability
B. Elasticity
C. Security
D. Loose coupling

16. A user has a stateful workload that will run on Amazon EC2 for the next 3 years. What is the MOST cost-effective pricing model for this workload?

A. On-Demand Instances
B. Reserved Instances
C. Dedicated Instances
D. Spot Instances

17. A cloud practitioner needs an Amazon EC2 instance to launch and run for 7 hours without interruptions. What is the most suitable and cost-effective option for this task?

A. On-Demand Instance
B. Reserved Instance
C. Dedicated Host
D. Spot Instance

18. Which of the following are benefits of using AWS Trusted Advisor? (Choose two.)

A. Providing high-performance container orchestration
B. Creating and rotating encryption keys
C. Detecting underutilized resources to save costs
D. Improving security by proactively monitoring the AWS environment
E. Implementing enforced tagging across AWS resources

19. A developer has been hired by a large company and needs AWS credentials. Which are security best practices that should be followed? (Choose two.)

A. Grant the developer access to only the AWS resources needed to perform the job.
B. Share the AWS account root user credentials with the developer.
C. Add the developer to the administrator’s group in AWS IAM.
D. Configure a password policy that ensures the developer’s password cannot be changed.
E. Ensure the account password policy requires a minimum length.

20. Which AWS storage service is designed to transfer petabytes of data in and out of the cloud?

A. AWS Storage Gateway
B. Amazon S3 Glacier Deep Archive
C. Amazon Lightsail
D. AWS Snowball

21. Which AWS service allows for effective cost management of multiple AWS accounts?

A. AWS Organizations
B. AWS Trusted Advisor
C. AWS Direct Connect
D. Amazon Connect

22. A company is piloting a new customer-facing application on Amazon Elastic Compute Cloud (Amazon EC2) for one month. What pricing model is appropriate?

A. Reserved Instances
B. Spot Instances
C. On-Demand Instances
D. Dedicated Hosts

23. Which AWS tools automatically forecast future AWS costs?

A. AWS Support Center
B. AWS Total Cost of Ownership (TCO) Calculator
C. AWS Simple Monthly Calculator
D. Cost Explorer

24. Under the AWS shared responsibility model, which of the following is a responsibility of AWS?

A. Enabling server-side encryption for objects stored in S3
B. Applying AWS IAM security policies
C. Patching the operating system on an Amazon EC2 instance
D. Applying updates to the hypervisor

25. A user is able to set up a master payer account to view consolidated billing reports through:

A. AWS Budgets.
B. Amazon Macie.
C. Amazon QuickSight.
D. AWS Organizations.

26. Performing operations as code is a design principle that supports which pillar of the AWS Well-Architected Framework?

A. Performance efficiency
B. Operational excellence
C. Reliability
D. Security

27. Which design principle is achieved by following the reliability pillar of the AWS Well-Architected Framework?

A. Vertical scaling
B. Manual failure recovery
C. Testing recovery procedures
D. Changing infrastructure manually

28. What is a characteristic of Convertible Reserved Instances (RIs)?

A. Users can exchange Convertible RIs for other Convertible RIs from a different instance family.
B. Users can exchange Convertible RIs for other Convertible RIs in different AWS Regions.
C. Users can sell and buy Convertible RIs on the AWS Marketplace.
D. Users can shorten the term of their Convertible RIs by merging them with other Convertible RIs.

29. The user is fully responsible for which action when running workloads on AWS?

A. Patching the infrastructure components
B. Implementing controls to route application traffic
C. Maintaining physical and environmental controls
D. Maintaining the underlying infrastructure components

30. An architecture design includes Amazon EC2, an Elastic Load Balancer, and Amazon RDS. What is the BEST way to get a monthly cost estimation for this architecture?

A. Open an AWS Support case, provide the architecture proposal, and ask for a monthly cost estimation.
B. Collect the published prices of the AWS services and calculate the monthly estimate.
C. Use the AWS Simple Monthly Calculator to estimate the monthly cost.
D. Use the AWS Total Cost of Ownership (TCO) Calculator to estimate the monthly cost.

31. Which AWS service allows users to download security and compliance reports about the AWS infrastructure on demand?

A. Amazon GuardDuty
B. AWS Security Hub
C. AWS Artifact
D. AWS Shield

32. Which AWS managed services can be used to extend an on-premises data center to the AWS network? (Choose two.)

A. AWS VPN
B. NAT gateway
C. AWS Direct Connect
D. Amazon Connect
E. Amazon Route 53

33. Which requirement must be met for a member account to be unlinked from an AWS Organizations account?

A. The linked account must be actively compliant with AWS System and Organization Controls (SOC).
B. The payer and the linked account must both create AWS Support cases to request that the member account be unlinked from the organization.
C. The member account must meet the requirements of a standalone account.
D. The payer account must be used to remove the linked account from the organization.

34. What AWS benefit refers to a customer’s ability to deploy applications that scale up and down the meet variable demand?

A. Elasticity
B. Agility
C. Security
D. Scalability

35. During a compliance review, one of the auditors requires a copy of the AWS SOC 2 report. Which service should be used to submit this request?

A. AWS Personal Health Dashboard
B. AWS Trusted Advisor
C. AWS Artifact
D. Amazon S3

36. A company wants to set up a highly available workload in AWS with a disaster recovery plan that will allow the company to recover in case of a regional service interruption. Which configuration will meet these requirements?

A. Run on two Availability Zones in one AWS Region, using the additional Availability Zones in the AWS Region for the disaster recovery site.
B. Run on two Availability Zones in one AWS Region, using another AWS Region for the disaster recovery site.
C. Run on two Availability Zones in one AWS Region, using a local AWS Region for the disaster recovery site.
D. Run across two AWS Regions, using a third AWS Region for the disaster recovery site.

37. A company has a 500 TB image repository that needs to be transported to AWS for processing. Which AWS service can import this data MOST cost-effectively?

A. AWS Snowball
B. AWS Direct Connect
C. AWS VPN
D. Amazon S3

38. Which AWS service can run a managed PostgreSQL database that provides online transaction processing (OLTP)?

A. Amazon DynamoDB
B. Amazon Athena
C. Amazon RDS
D. Amazon EMR

39. Which of the following assist in identifying costs by department? (Choose two.)

A. Using tags on resources
B. Using multiple AWS accounts
C. Using an account manager
D. Using AWS Trusted Advisor
E. Using Consolidated Billing

40. A company must store critical business data in Amazon S3 with a backup to another AWS Region. How can this be achieved?

A. Use an Amazon CloudFront Content Delivery Network (CDN) to cache data globally
B. Set up Amazon S3 cross-region replication to another AWS Region
C. Configure the AWS Backup service to back up to the data to another AWS Region
D. Take Amazon S3 bucket snapshots and copy that data to another AWS Region

41. Which AWS Cloud service can send alerts to customers if custom spending thresholds are exceeded?

A. AWS Budgets
B. AWS Cost Explorer
C. AWS Cost Allocation Tags
D. AWS Organizations

42. What is the recommended method to request penetration testing on AWS resources?

A. Open a support case
B. Fill out the Penetration Testing Request Form
C. Request a penetration test from your technical account manager
D. Contact your AWS sales representative

43. A user needs to automatically discover, classify, and protect sensitive data stored in Amazon S3. Which AWS service can meet these requirements?

A. Amazon Inspector
B. Amazon Macie
C. Amazon GuardDuty
D. AWS Secrets Manager

44. Which components are required to build a successful site-to-site VPN connection on AWS? (Choose two.)

A. Internet gateway
B. NAT gateway
C. Customer gateway
D. Transit gateway
E. Virtual private gateway

45. Which Amazon EC2 pricing option is best suited for applications with short-term, spiky, or unpredictable workloads that cannot be interrupted?

A. Spot Instances
B. Dedicated Hosts
C. On-Demand Instances
D. Reserved Instances

46. Which AWS cloud architecture principle states that systems should reduce interdependencies?

A. Scalability
B. Services, not servers
C. Removing single points of failure
D. Loose coupling

47. What is the MOST effective resource for staying up to date on AWS security announcements?

A. AWS Personal Health Dashboard
B. AWS Secrets Manager
C. AWS Security Bulletins
D. Amazon Inspector

48. Which AWS service offers persistent storage for a file system?

A. Amazon S3
B. Amazon EC2 instance store
C. Amazon Elastic Block Store (Amazon EBS)
D. Amazon ElastiCache

49. Which of the following allows AWS users to manage cost allocations for billing?

A. Tagging resources
B. Limiting who can create resources
C. Adding a secondary payment method
D. Running all operations on a single AWS account

50. Which of the following tasks can only be performed after signing in with AWS account root user credentials? (Choose two.)

A. Closing an AWS account
B. Creating a new IAM policy
C. Changing AWS Support plans
D. Attaching a role to an Amazon EC2 instance
E. Generating access keys for IAM users

51. Fault tolerance refers to:

A. the ability of an application to accommodate growth without changing design
B. how well and how quickly an application’s environment can have lost data restored
C. how secure your application is
D. the built-in redundancy of an application’s components

52. A company operating in the AWS Cloud requires separate invoices for specific environments, such as development, testing, and production. How can this be achieved?

A. Use multiple AWS accounts
B. Use resource tagging
C. Use multiple VPCs
D. Use Cost Explorer

53. Which AWS service can be used in the application deployment process?

A. AWS AppSync
B. AWS Batch
C. AWS CodePipeline
D. AWS DataSync

54. What can be used to reduce the cost of running Amazon EC2 instances? (Choose two.)

A. Spot Instances for stateless and flexible workloads
B. Memory optimized instances for high-compute workloads
C. On-Demand Instances for high-cost and sustained workloads
D. Reserved Instances for sustained workloads
E. Spend limits set using AWS Budgets

55. A company is launching an e-commerce site that will store and process credit card data. The company requires information about AWS compliance reports and
AWS agreements. Which AWS service provides on-demand access to these items?

A. AWS Certificate Manager
B. AWS Config
C. AWS Artifact
D. AWS CloudTrail

56. Which AWS service can be used to track unauthorized API calls?

A. AWS Config
B. AWS CloudTrail
C. AWS Trusted Advisor
D. Amazon Inspector

57. A user needs to regularly audit and evaluate the setup of all AWS resources, identify non-compliant accounts, and be notified when a resource changes. Which AWS service can be used to meet these requirements?

A. AWS Trusted Advisor
B. AWS Config
C. AWS Resource Access Manager
D. AWS Systems Manager

58. A user is planning to launch two additional Amazon EC2 instances to increase availability. Which action should the user take?

A. Launch the instances across multiple Availability Zones in a single AWS Region.
B. Launch the instances as EC2 Reserved Instances in the same AWS Region and the same Availability Zone.
C. Launch the instances in multiple AWS Regions, but in the same Availability Zone.
D. Launch the instances as EC2 Spot Instances in the same AWS Region, but in different Availability Zones.

59. A company’s application has flexible start and end times. Which Amazon EC2 pricing model will be the MOST cost-effective?

A. On-Demand Instances
B. Spot Instances
C. Reserved Instances
D. Dedicated Hosts

60. Under the AWS shared responsibility model, what are the customer’s responsibilities? (Choose two.)

A. Physical and environmental security
B. Physical network devices including firewalls
C. Storage device decommissioning
D. Security of data in transit
E. Data integrity authentication

61. A cloud practitioner has a data analysis workload that is infrequently executed and can be interrupted without harm. To optimize for cost, which Amazon EC2 purchasing option should be used?

A. On-Demand Instances
B. Reserved Instances
C. Spot Instances
D. Dedicated Hosts

62. Which AWS container service will help a user install, operate, and scale the cluster management infrastructure?

A. Amazon Elastic Container Registry (Amazon ECR)
B. AWS Elastic Beanstalk
C. Amazon Elastic Container Service (Amazon ECS)
D. Amazon Elastic Block Store (Amazon EBS)

63. Which of the following allows an application running on an Amazon EC2 instance to securely write data to an Amazon S3 bucket without using long term credentials?

A. Amazon Cognito
B. AWS Shield
C. AWS IAM role
D. AWS IAM user access key

64. A company with a Developer-level AWS Support plan provisioned an Amazon RDS database and cannot connect to it. Who should the developer contact for this level of support?

A. AWS Support using a support case
B. AWS Professional Services
C. AWS technical account manager
D. AWS consulting partners

65. What is the purpose of having an internet gateway within a VPC?

A. To create a VPN connection to the VPC
B. To allow communication between the VPC and the Internet
C. To impose bandwidth constraints on internet traffic
D. To load balance traffic from the Internet across Amazon EC2 instances

66. A company must ensure that its endpoint for a database instance remains the same after a single Availability Zone service interruption. The application needs to resume database operations without the need for manual administrative intervention. How can these requirements be met?

A. Use multiple Amazon Route 53 routes to the standby database instance endpoint hosted on AWS Storage Gateway.
B. Configure Amazon RDS Multi-Availability Zone deployments with automatic failover to the standby.
C. Add multiple Application Load Balancers and deploy the database instance with AWS Elastic Beanstalk.
D. Deploy a single Network Load Balancer to distribute incoming traffic across multiple Amazon CloudFront origins.

67. Which AWS managed service can be used to distribute traffic between one or more Amazon EC2 instances?

A. NAT gateway
B. Elastic Load Balancing
C. Amazon Athena
D. AWS PrivateLink

68. AWS Trusted Advisor provides recommendations on which of the following? (Choose two.)

A. Cost optimization
B. Auditing
C. Serverless architecture
D. Performance
E. Scalability

Part 1: https://www.awslagi.com/aws-certified-cloud-practitioner
Part 2: https://www.awslagi.com/aws-certified-cloud-practitioner-p2
Part 3: https://www.awslagi.com/aws-certified-cloud-practitioner-p3
Part 4: https://www.awslagi.com/aws-certified-cloud-practitioner-p4
Part 5: https://www.awslagi.com/aws-certified-cloud-practitioner-p5
Part 6: https://www.awslagi.com/aws-certified-cloud-practitioner-p6
Part 7: https://www.awslagi.com/aws-certified-cloud-practitioner-p7
Part 8: https://www.awslagi.com/aws-certified-cloud-practitioner-p8
Part 9: https://www.awslagi.com/aws-certified-cloud-practitioner-p9
Part 10: https://www.awslagi.com/aws-certified-cloud-practitioner-p10
Part 11: https://www.awslagi.com/aws-certified-cloud-practitioner-p11
Part 12: https://www.awslagi.com/aws-certified-cloud-practitioner-part-12
Part 13: https://www.awslagi.com/aws-certified-cloud-practitioner-part-13

Which components are required to build a successful site

The components involved in a Site-to-Site VPN connection to an AWS VPC are: A Customer Gateway (CGW) on the local network. A Virtual Private Gateway (VGW) on the AWS network. A VPN tunnel to connect CGW and VGW.

What is needed for site

In order to set up an internet-based site-to-site VPN between two sites, a VPN gateway (router, firewall, VPN concentrator, or security appliance) such as the Cisco Adaptive Security Appliance (ASA) is required at both sites.

Which items must be created before configuring a site

To establish a VPN connection between your VPC and your on-premises network, you must create a target gateway on the AWS side of the connection. The target gateway can be a virtual private gateway or a transit gateway.

How does site

Private IP Site-to-Site VPN feature allows you to deploy VPN connections to an AWS Transit Gateway using private IP addresses. Private IP VPN works over an AWS Direct Connect transit virtual interface (VIF). You can select private IP addresses as your outside tunnel IP addresses while creating a new VPN connection.