A company has migrated a two-tier application from its on-premises data center to the AWS Cloud. The data tier is a Multi-AZ deployment of Amazon RDS for Oracle with 12 TB of General Purpose SSD Amazon Elastic Block Store (Amazon EBS) storage. The application is designed to process and store documents in the database as binary large objects (blobs) with an average document size of 6 MB.
The database size has grown over time, reducing the performance and increasing the cost of storage. The company must improve the database performance and needs a solution that is highly available and resilient.
Which solution will meet these requirements MOST cost-effectively?
A. Reduce the RDS DB instance size. Increase the storage capacity to 24 TiB. Change the storage type to Magnetic.
B. Increase the RDS DB instance size. Increase the storage capacity to 24 TiChange the storage type to Provisioned IOPS.
C. Create an Amazon S3 bucket. Update the application to store documents in the S3 bucket. Store the object metadata in the existing database.
D. Create an Amazon DynamoDB table. Update the application to use DynamoDB. Use AWS Database Migration Service (AWS DMS) to migrate data from the Oracle database to DynamoDB.
Show Answer
Correct Answer: C
Explanation: Storing large binary objects (BLOBs) inside an RDS Oracle database increases database size, storage cost, backup size, and can degrade performance. Moving the documents to Amazon S3 and keeping only object metadata and references in the database is a common AWS architecture that improves database performance while reducing storage costs. Amazon S3 is highly available and durable, satisfying the availability and resilience requirements. Option B only scales expensive database storage without addressing the root cause. Option A reduces performance by using Magnetic storage. Option D is not appropriate because DynamoDB has a 400 KB item size limit, far smaller than the 6 MB average document size.
Question 406
A solutions architect is designing an application that will allow business users to upload objects to Amazon S3. The solution needs to maximize object durability. Objects also must be readily available at any time and for any length of time. Users will access objects frequently within the first 30 days after the objects are uploaded, but users are much less likely to access objects that are older than 30 days.
Which solution meets these requirements MOST cost-effectively?
A. Store all the objects in S3 Standard with an S3 Lifecycle rule to transition the objects to S3 Glacier after 30 days.
B. Store all the objects in S3 Standard with an S3 Lifecycle rule to transition the objects to S3 Standard-Infrequent Access (S3 Standard-IA) after 30 days.
C. Store all the objects in S3 Standard with an S3 Lifecycle rule to transition the objects to S3 One Zone-Infrequent Access (S3 One Zone-IA) after 30 days.
D. Store all the objects in S3 Intelligent-Tiering with an S3 Lifecycle rule to transition the objects to S3 Standard-Infrequent Access (S3 Standard-IA) after 30 days.
Show Answer
Correct Answer: B
Explanation: S3 Standard is appropriate for the first 30 days because objects are accessed frequently. After 30 days, S3 Standard-IA is the most cost-effective option that still provides millisecond retrieval and high availability for data that must remain readily accessible at any time. Glacier does not provide immediate access due to retrieval delays. One Zone-IA stores data in a single AZ, reducing resilience compared with Standard-IA, making it a poorer fit when maximizing durability/resilience and continuous availability is a stated goal. Intelligent-Tiering adds unnecessary monitoring costs because the access pattern is already known.
Question 407
A company's infrastructure consists of hundreds of Amazon EC2 instances that use Amazon Elastic Block Store (Amazon EBS) storage. A solutions architect must ensure that every EC2 instance can be recovered after a disaster.
What should the solutions architect do to meet this requirement with the LEAST amount of effort?
A. Take a snapshot of the EBS storage that is attached to each EC2 instance. Create an AWS CloudFormation template to launch new EC2 instances from the EBS storage.
B. Take a snapshot of the EBS storage that is attached to each EC2 instance. Use AWS Elastic Beanstalk to set the environment based on the EC2 template and attach the EBS storage.
C. Use AWS Backup to set up a backup plan for the entire group of EC2 instances. Use the AWS Backup API or the AWS CLI to speed up the restore process for multiple EC2 instances.
D. Create an AWS Lambda function to take a snapshot of the EBS storage that is attached to each EC2 instance and copy the Amazon Machine Images (AMIs). Create another Lambda function to perform the restores with the copied AMIs and attach the EBS storage.
Show Answer
Correct Answer: C
Explanation: AWS Backup is the managed service designed to centrally automate backups and restores for supported AWS resources, including Amazon EBS and EC2. A backup plan can protect large fleets of instances with minimal operational effort, and the AWS Backup API/CLI can automate bulk restores after a disaster. The other options require custom orchestration or misuse services (Elastic Beanstalk is not a backup solution).
Question 408
A company recently migrated to the AWS Cloud. The company wants a serverless solution for large-scale parallel on-demand processing of a semistructured dataset. The data consists of logs, media files, sales transactions, and IoT sensor data that is stored in Amazon S3. The company wants the solution to process thousands of items in the dataset in parallel.
Which solution will meet these requirements with the MOST operational efficiency?
A. Use the AWS Step Functions Map state in Inline mode to process the data in parallel.
B. Use the AWS Step Functions Map state in Distributed mode to process the data in parallel.
C. Use AWS Glue to process the data in parallel.
D. Use several AWS Lambda functions to process the data in parallel.
Show Answer
Correct Answer: B
Explanation: AWS Step Functions Distributed Map is purpose-built for large-scale, serverless parallel processing of datasets stored in Amazon S3. It supports up to 10,000 parallel child workflow executions and is optimized for processing large collections of S3 objects or records. Inline Map is limited in concurrency, Glue is primarily an ETL service rather than the best fit for orchestrated on-demand parallel item processing, and coordinating many Lambda functions directly is less operationally efficient than using Distributed Map.
Question 409
A company runs its critical database on an Amazon RDS for PostgreSQL DB instance. The company wants to migrate to Amazon Aurora PostgreSQL with minimal downtime and data loss.
Which solution will meet these requirements with the LEAST operational overhead?
A. Create a DB snapshot of the RDS for PostgreSQL DB instance to populate a new Aurora PostgreSQL DB cluster.
B. Create an Aurora read replica of the RDS for PostgreSQL DB instance. Promote the Aurora read replicate to a new Aurora PostgreSQL DB cluster.
C. Use data import from Amazon S3 to migrate the database to an Aurora PostgreSQL DB cluster.
D. Use the pg_dump utility to back up the RDS for PostgreSQL database. Restore the backup to a new Aurora PostgreSQL DB cluster.
Show Answer
Correct Answer: B
Explanation: Creating an Aurora read replica from the existing RDS for PostgreSQL instance enables continuous replication to Aurora, minimizing downtime and data loss. Once replication lag reaches zero, promote the Aurora read replica to a standalone Aurora PostgreSQL cluster. This is the managed migration approach with the least operational overhead compared to snapshots, pg_dump, or S3 import.
Question 410
A company is planning to migrate a TCP-based application into the company's VPC. The application is publicly accessible on a nonstandard TCP port through a hardware appliance in the company's data center. This public endpoint can process up to 3 million requests per second with low latency. The company requires the same level of performance for the new public endpoint in AWS.
What should a solutions architect recommend to meet this requirement?
A. Deploy a Network Load Balancer (NLB). Configure the NLB to be publicly accessible over the TCP port that the application requires.
B. Deploy an Application Load Balancer (ALB). Configure the ALB to be publicly accessible over the TCP port that the application requires.
C. Deploy an Amazon CloudFront distribution that listens on the TCP port that the application requires. Use an Application Load Balancer as the origin.
D. Deploy an Amazon API Gateway API that is configured with the TCP port that the application requires. Configure AWS Lambda functions with provisioned concurrency to process the requests.
Show Answer
Correct Answer: A
Explanation: A Network Load Balancer (NLB) operates at Layer 4, supports TCP traffic on custom ports, is designed for ultra-high performance with very low latency, and can scale to handle millions of requests per second. An ALB is for Layer 7 HTTP/HTTPS traffic, CloudFront does not provide a generic TCP listener, and API Gateway/Lambda do not support arbitrary TCP applications.
Question 411
A company will migrate 10 PB of data to Amazon S3 in 6 weeks. The current data center has a 500 Mbps uplink to the internet. Other on-premises applications share the uplink. The company can use 80% of the internet bandwidth for this one-time migration task.
Which solution will meet these requirements?
A. Configure AWS DataSync to migrate the data to Amazon S3 and to automatically verify the data.
B. Use rsync to transfer the data directly to Amazon S3.
C. Use the AWS CLI and multiple copy processes to send the data directly to Amazon S3.
D. Order multiple AWS Snowball devices. Copy the data to the devices. Send the devices to AWS to copy the data to Amazon S3.
Show Answer
Correct Answer: D
Explanation: The available bandwidth for migration is 80% of 500 Mbps, or 400 Mbps. Transferring 10 PB over a 400 Mbps internet connection would take years, far exceeding the 6-week deadline. AWS Snowball is designed for large-scale offline data transfers, and ordering multiple Snowball devices enables the required data volume to be migrated to Amazon S3 within the timeframe.
Question 412
A company has deployed its newest product on AWS. The product runs in an Auto Scaling group behind a Network Load Balancer. The company stores the product’s objects in an Amazon S3 bucket.
The company recently experienced malicious attacks against its systems. The company needs a solution that continuously monitors for malicious activity in the AWS account, workloads, and access patterns to the S3 bucket. The solution must also report suspicious activity and display the information on a dashboard.
Which solution will meet these requirements?
A. Configure Amazon Macie to monitor and report findings to AWS Config.
B. Configure Amazon Inspector to monitor and report findings to AWS CloudTrail.
C. Configure Amazon GuardDuty to monitor and report findings to AWS Security Hub.
D. Configure AWS Config to monitor and report findings to Amazon EventBridge.
Show Answer
Correct Answer: C
Explanation: Amazon GuardDuty continuously monitors AWS accounts, workloads, and S3 data access for malicious activity by analyzing telemetry such as CloudTrail events, VPC Flow Logs, DNS logs, and S3 protection signals. GuardDuty findings integrate with AWS Security Hub, which provides a centralized dashboard for security findings and alerts. Amazon Macie focuses on sensitive data discovery, Amazon Inspector on vulnerability management, and AWS Config on configuration compliance rather than threat detection.
Question 413
A company wants to migrate an on-premises data center to AWS. The data center hosts a storage server that stores data in an NFS-based file system. The storage server holds 200 GB of data. The company needs to migrate the data without interruption to existing services. Multiple resources in AWS must be able to access the data by using the NFS protocol.
Which combination of steps will meet these requirements MOST cost-effectively? (Choose two.)
A. Create an Amazon FSx for Lustre file system.
B. Create an Amazon Elastic File System (Amazon EFS) file system.
C. Create an Amazon S3 bucket to receive the data.
D. Manually use an operating system copy command to push the data into the AWS destination.
E. Install an AWS DataSync agent in the on-premises data center. Use a DataSync task between the on-premises location and AWS.
Show Answer
Correct Answer: B, E
Explanation: Amazon EFS provides a managed NFS file system that can be mounted by multiple AWS resources, matching the requirement for shared NFS access. AWS DataSync supports migrating data from an on-premises NFS server to Amazon EFS with incremental synchronization, minimizing disruption to existing services. FSx for Lustre is intended for high-performance workloads rather than general NFS sharing, S3 is object storage rather than NFS, and manual copy does not provide efficient, low-disruption migration.
Question 414
A company uses Amazon API Gateway to manage its REST APIs that third-party service providers access. The company must protect the REST APIs from SQL injection and cross-site scripting attacks.
What is the MOST operationally efficient solution that meets these requirements?
A. Configure AWS Shield.
B. Configure AWS WAF.
C. Set up API Gateway with an Amazon CloudFront distribution. Configure AWS Shield in CloudFront.
D. Set up API Gateway with an Amazon CloudFront distribution. Configure AWS WAF in CloudFront.
Show Answer
Correct Answer: B
Explanation: AWS WAF is designed to protect web applications and Amazon API Gateway REST APIs from common web exploits, including SQL injection and cross-site scripting (XSS). AWS Shield is for DDoS protection, not SQLi/XSS. Adding CloudFront is unnecessary because AWS WAF can be associated directly with API Gateway REST APIs, making it the most operationally efficient solution.
$19
Get all 1004 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.