An organization needs a data store to handle the following data types and access patterns
• Faceting
• Search
• Flexible schema (JSON) and fixed schema
• Noise word elimination
Which data store should the organization choose?

  • A. Amazon Relational Database Service (RDS)
  • B. Amazon Redshift
  • C. Amazon DynamoDB
  • D. Amazon Elasticsearch Service

Answer: C

When will you incur costs with an Elastic IP address (EIP)?

  • A. When an EIP is allocated.
  • B. When it is allocated and associated with a running instance.
  • C. When it is allocated and associated with a stopped instance.
  • D. Costs are incurred regardless of whether the EIP is associated with a running instance.

Answer: C

A company is building a new application is AWS. The architect needs to design a system to collect application log events. The design should be a repeatable pattern that minimizes data loss if an application instance fails, and keeps a durable copy of all log data for at least 30 days.
What is the simplest architecture that will allow the architect to analyze the logs?

  • A. Write them directly to a Kinesis Firehos
  • B. Configure Kinesis Firehose to load the events into an Amazon Redshift cluster for analysis.
  • C. Write them to a file on Amazon Simple Storage Service (S3). Write an AWS lambda function that runs in response to the S3 events to load the events into Amazon Elasticsearch service for analysis.
  • D. Write them to the local disk and configure the Amazon cloud watch Logs agent to lead the data into CloudWatch Logs and subsequently into Amazon Elasticsearch Service.
  • E. Write them to CloudWatch Logs and use an AWS Lambda function to load them into HDFS on an Amazon Elastic MapReduce (EMR) cluster for analysis.

Answer: A

A user has launched an EC2 instance and deployed a production application in it. The user wants to prohibit any mistakes from the production team to avoid accidental termination. How can the user achieve this?

  • A. The user can the set DisableApiTermination attribute to avoid accidental termination
  • B. It is not possible to avoid accidental termination
  • C. The user can set the Deletion termination flag to avoid accidental termination
  • D. The user can set the InstanceInitiatedShutdownBehavior flag to avoid accidental termination

Answer: A

Customers have recently been complaining that your web application has randomly stopped responding. During a deep dive of your logs, the team has discovered a major bug in your Java web application. This bug is causing a memory leak that eventually causes the application to crash.
Your web application runs on Amazon EC2 and was built with AWS CloudFormation.
Which techniques should you see to help detect theses problems faster, as well as help eliminate the server’s unresponsiveness? Choose 2 answers

  • A. Update your AWS CloudFormation configuration and enable a CustomResource that uses cfn- signal to detect memory leaks
  • B. Update your CloudWatch metric granularity config for all Amazon EC2 memory metrics to support five-second granularit
  • C. Create a CloudWatch alarm that triggers an Amazon SNS notification to page your team when the application memory becomes too large
  • D. Update your AWS CloudFormation configuration to take advantage of Auto Scaling group
  • E. Configure an Auto Scaling group policy to trigger off your custom CloudWatch metrics
  • F. Create a custom CloudWatch metric that you push your JVM memory usage to create a CloudWatch alarm that triggers an Amazon SNS notification to page your team when the application memory usage becomes too large
  • G. Update your AWS CloudFormation configuration to take advantage of CloudWatch metrics Agen
  • H. Configure the CloudWatch Metrics Agent to monitor memory usage and trigger an Amazon SNS alarm

Answer: CD

You are currently hosting multiple applications in a VPC and have logged numerous port scans coming in from a specific IP address block. Your security team has requested that all access from the offending IP address block be denied for the next 24 hours.
Which of the following is the best method to quickly and temporarily deny access from the specified IP address block?

  • A. Create an AD policy to modify Windows Firewall settings on all hosts in the VPC to deny access from the IP address block
  • B. Modify the Network ACLs associated with all public subnets in the VPC to deny access from the IP address block
  • C. Add a rule to all of the VPC 5 Security Groups to deny access from the IP address block
  • D. Modify the Windows Firewall settings on all Amazon Machine Images (AMIs) that your organization uses in that VPC to deny access from the IP address block

Answer: B

A data engineer is about to perform a major upgrade to the DDL contained within an Amazon Redshift cluster to support a new data warehouse application. The upgrade scripts will include user permission updates, view and table structure changes as well as additional loading and data manipulation tasks. The data engineer must be able to restore the database to its existing state in the event of issues.
Which action should be taken prior to performing this upgrade task?

  • A. Run an UNLOAD command for all data in the warehouse and save it to S3
  • B. Create a manual snapshot of the Amazon Redshift cluster
  • C. Make a copy of the automated snapshot on the Amazon Redshift cluster
  • D. Call the wait For Snap Shot Available command from either the AWS CLI or an AWS SDK

Answer: B

You have identified network throughput as a bottleneck on your m1.small EC2 instance when uploading data Into Amazon S3 In the same region. How do you remedy this situation?

  • A. Add an additional ENI
  • B. Change to a larger Instance
  • C. Use DirectConnect between EC2 and S3
  • D. Use EBS PIOPS on the local volume

Answer: B

The department of transportation for a major metropolitan area has placed sensors on roads at key locations around the city. The goal is to analyze the flow of traffic and notifications from emergency services to identity potential issues and to help planners correct trouble spots.
A data engineer needs a scalable and fault-tolerant solution that allows planners to respond to issues within 30 seconds of their occurrence.
Which solution should the data engineer choose?

  • A. Collect the sensor data with Amazon Kinesis Firehose and store it in Amazon Redshift for analysi
  • B. Collect emergency services events with Amazon SQS and store in Amazon DynamoDB for analysis
  • C. Collect the sensor data with Amazon SQS and store in Amazon DynamoDB for analysis.Collect emergency services events with Amazon Kinesis Firehouse and store in Amazon Redshift for analysis
  • D. Collect both sensor data and emergency services events with Amazon Kinesis Streams and use Amazon DynamoDB for analysis
  • E. Collect both sensor data and emergency services events with Amazon Kinesis Firehouse and use Amazon Redshift for Analysis

Answer: A

You have a video Trans coding application running on Amazon EC2. Each instance pools a queue to find out which video should be Trans coded, and then runs a Trans coding process.
If this process is interrupted, the video will be Trans coded by another instance based on the queuing system. You have a large backlog of videos which need to be Trans coded and would like to reduce this backlog by adding more instances. You will need these instances only until the backlog is reduced. Which type of Amazon EC2 instance should you use to reduce the backlog in the most cost- effective way?

  • A. Dedicated instances
  • B. Spot instances
  • C. On-demand instances
  • D. Reserved instances

Answer: B

There are thousands of text files on Amazon S3. The total size of the files is 1 PB. The files contain
retail order information for the past 2 years. A data engineer needs to run multiple interactive queries to manipulate the data. The data Engineer has AWS access to spin up an Amazon EMR cluster. The data Engineer needs to use an application on the cluster to process this data and return the results in interactive time frame. Which application on the cluster should be the data engineer use?

  • A. Oozie
  • B. Apache Pig with Tachyon
  • C. Apache Hive
  • D. Presto

Answer: D

A photo sharing service stores pictures in Amazon Simple Storage Service (S3) and allows application
signin using an Open ID Connect compatible identity provider. Which AWS Security Token approach to temporary access should you use for the Amazon S3 operations?

  • A. SAML-based identity Federation
  • B. Cross-Account Access
  • C. AWS identity and Access Management roles
  • D. Web identity Federation

Answer: A

An enterprise customer is migrating to Redshift and is considering using dense storage nodes in its
Redshift cluster. The customer wants to migrate 50 TB of data. The customer’s query patterns involve performing many joins with thousands of rows. The customer needs to know how many nodes are needed in its target Redshift cluster. The customer has a limited budget and needs to avoid performing tests unless absolutely needed. Which approach should this customer use?

  • A. Start with many small nodes
  • B. Start with fewer large nodes
  • C. Have two separate clusters with a mix of small and large nodes
  • D. Insist on performing multiple tests to determine the optimal configuration

Answer: D

An administrator needs to manage a large catalog of items from various external sellers. The administration needs to determine if the items should be identified as minimally dangerous, dangerous or highly dangerous based on their textual description. The administrator already has some items with the danger attribute, but receives hundreds of new item descriptions every day without such classification.
The administrator has a system that captures dangerous goods reports from customer support team or from user feedback. What is a cost –effective architecture to solve this issue?

  • A. Build a set of regular expression rules that are based on the existing example
  • B. And run them on the DynamoDB streams as every new item description is added to the system.
  • C. Build a kinesis Streams process that captures and marks the relevant items in the dangerous goods reports using a Lambda function once more than two reports have been filed.
  • D. Build a machine learning model to properly classify dangerous goods and run it on the DynamoDB streams as every new item description is added to the system.
  • E. Build a machine learning model with binary classification for dangerous goods and run it on the DynamoDB streams as every new item description is added to the system.

Answer: C

Which of the following are characteristics of Amazon VPC subnets? Choose 2 answers

  • A. Each subnet maps to a single Availability Zone
  • B. A CIDR block mask of /25 is the smallest range supported
  • C. Instances in a private subnet can communicate with the internet only if they have an Elastic IP.
  • D. By default, all subnets can route between each other, whether they are private or public
  • E. Each subnet spans at least 2 Availability zones to provide a high-availability environment

Answer: AD

You are deploying an application to track GPS coordinates of delivery in the United States.
Coordinates are transmitted from each delivery truck once every three seconds. You need to design an architecture that will enable realtime processing of these coordinates from multiple consumers. Which service should you use to implement data ingestion?

  • A. Amazon Kinesis
  • B. AWS Data Pipeline
  • C. Amazon AppStream
  • D. Amazon Simple Queue Service

Answer: A

A user has setup an RDS DB with Oracle. The user wants to get notifications when someone modifies
the security group of that DB. How can the user configure that?

  • A. It is not possible to get the notifications on a change in the security group
  • B. Configure SNS to monitor security group changes
  • C. Configure event notification on the DB security group
  • D. Configure the CloudWatch alarm on the DB for a change in the security group

Answer: C

You have a load balancer configured for VPC, and all backend Amazon EC2 instances are in service. However, your web browser times out when connecting to the load balancer’s DNS name. Which options are probable causes of this behavior?

  • A. The load balancer was not configured to use a public subnet with an Internet gateway configured
  • B. The Amazon EC2 instances do not have a dynamically allocated private IP address
  • C. The security groups or network ACLs are not properly configured for web traffic
  • D. The load balancer is not configured in a private subnet with a NAT instance
  • E. The VPC does not have a VGW configured

Answer: AC

A customer is collecting clickstream data using Amazon kinesis and is grouping the events by IP address into 5-minute chunks stored in Amazon S3.
Many analysts in the company use Hive on Amazon EMR to analyze this data. Their queries always reference a single IP address. Data must be optimized for querying based on UP address using Hive running on Amazon EMR. What is the most efficient method to query the data with Hive?

  • A. Store an index of the files by IP address in the Amazon DynamoDB metadata store for EMRFS
  • B. Store the Amazon S3 objects with the following naming scheme: bucketname/source=ip_address/year=yy/month=mm/day=dd/hour=hh/filename
  • C. Store the data in an HBase table with the IP address as the row key
  • D. Store the events for an IP address as a single file in Amazon S3 and add metadata with key:Hive_Partitioned_IPAddress

Answer: B

A user has launched an EC2 instance from an instance store backed AMI. The user has attached an
additional instance store volume to the instance. The user wants to create an AMI from the running instance. Will the AMI have the additional instance store volume data?

  • A. Yes, the block device mapping will have information about the additional instance store volume
  • B. No, since the instance store backed AMI can have only the root volume bundled
  • C. It is not possible to attach an additional instance store volume to the existing instance store backed AMI instance
  • D. No, since this is ephermal storage it will not be a part of the AMI

Answer: A

Your customers located around the globe require low-latency access to private video files. Which
configuration meets these requirements?

  • A. Use Amazon CloudFront with signed URLs
  • B. Use Amazon EC2 with provisioned IOPS Amazon EBS volumes
  • C. Use Amazon S3 with signed URLs
  • D. Use Amazon S3 with access control lists

Answer: A

A user is running one instance for only 3 hours every day. The user wants to save some cost with the
instance. Which of the below mentioned Reserved Instance categories is advised in this case?

  • A. The user should not use RI; instead only go with the on-demand pricing
  • B. The user should use the AWS high utilized RI
  • C. The user should use the AWS medium utilized RI
  • D. The user should use the AWS low utilized RI

Answer: A

You need to design a VPC for a web-application consisting of an Elastic Load Balancer (ELB). A fleet of web/application servers, and an RDS database The Entire Infrastructure must be distributed over 2 availability zones.
Which VPC configuration works while assuring the database is not available from the Internet?

  • A. One public subnet for ELB one public subnet for the web-servers, and one private subnet for the database
  • B. One public subnet for ELB two private subnets for the web-servers, two private subnets for RDS
  • C. Two public subnets for ELB two private subnets for the web-servers and two private subnets for RDS
  • D. Two public subnets for ELB two public subnets for the web-servers, and two public subnets for RDS

Answer: C


