Amazon

SOA-C03 Free Practice Questions — Page 10

Question 44

A CloudOps engineer must troubleshoot performance issues for a web application that is delivered through Amazon CloudFront. The metrics show a consistently low cache hit ratio that leads to many requests being forwarded to the origin. Which configuration will increase the cache hit ratio?

A. Modify the origin's Cache-Control header to max-age=0.
B. Reduce the TTL for cached objects.
C. Reduce the number of request headers, query strings, and cookies included in the cache key.
D. Configure signed URLs or signed cookies to restrict access to content.
Show Answer
Correct Answer: C
Explanation:
A low CloudFront cache hit ratio is commonly caused by an overly specific cache key. Including unnecessary request headers, query strings, or cookies creates many unique cache entries and reduces cache reuse. Reducing these cache key components increases the likelihood that requests match cached objects. Option A (max-age=0) effectively disables caching, B reduces cache lifetime and generally lowers hit ratio, and D controls access rather than improving cache efficiency.

Question 44

A development team is building an application that will use an Amazon API Gateway REST API and AWS Lambda functions to receive and process requests. The Lambda functions will deliver messages to an Amazon SNS topic. External stakeholders subscribe to the SNS topic. The company wants to prevent sensitive data from being published to the SNS topic. Which solution will meet these requirements?

A. Associate a data protection policy with the SNS topic. Define policy statements that identify and protect the sensitive data.
B. Run a sensitive data discovery job in Amazon Macie. Define the scope to identify and redact sensitive information within the workflow before publishing messages to the SNS topic.
C. Deploy Amazon GuardDuty Lambda Protection. Define sensitive data patterns that generate specific finding types when the patterns are matched. Send notifications to the development team.
D. Use Amazon Inspector to scan the Lambda function code for sensitive information. Activate an alert when Amazon Inspector finds sensitive information.
Show Answer
Correct Answer: A
Explanation:
Amazon SNS data protection policies can inspect messages for specified sensitive data and audit, mask, or block publishing based on policy statements. This helps prevent sensitive information from reaching the topic and its external subscribers. Macie, GuardDuty, and Inspector do not provide this message-level protection for SNS publishing.

Question 45

A company uses an organization in AWS Organizations to manage a multi-account AWS environment. The company creates a new Amazon EBS backed Amazon Machine Image (AMI). The company shares the AMI across the organization. Employees must use the AMI to launch all new Linux-based Amazon EC2 instances across the entire organization. In one of the company's application accounts, an employee uses the new AMI to launch a new workload. The EC2 instance launches, but it is terminated immediately. What the MOST likely reason that the instance did not fully boot?

A. The user who launched the instance does not have ec2:RunInstances permissions within the application account.
B. The company encrypted the AMI by using an AWS KMS key that the user who launched the EC2 instance does not have access to.
C. There is a service control policy (SCP) that denies the user who launched the EC2 instance access to launch instances in the application account.
D. The user launched the EC2 instance into a subnet that does not have access to the internet.
Show Answer
Correct Answer: B
Explanation:
An EC2 instance that launches and then immediately transitions to the terminated state commonly indicates a launch-time failure rather than a networking issue. If the AMI is EBS-backed and encrypted with a customer-managed AWS KMS key, the launching principal and EC2 service must be able to use that KMS key to create and decrypt the EBS volumes. Without the necessary KMS permissions, the root volume cannot be created/decrypted, so the instance cannot boot and is terminated. The other options would typically prevent the launch request entirely (missing RunInstances permission or an SCP deny) or would not cause immediate termination (no internet access).

Question 45

A company needs to view a list of security groups that are open to the internet on port 3389. What should a CloudOps engineer do to meet this requirement?

A. Configure Amazon GuardDuty to scan security groups and report unrestricted access on port 3389.
B. Configure a service control policy (SCP) to identify security groups that allow unrestricted access on port 3389.
C. Use AWS Identity and Access Management Access Analyzer to find any instances that have unrestricted access on port 3389.
D. Use AWS Trusted Advisor to find security groups that allow unrestricted access on port 3389.
Show Answer
Correct Answer: D
Explanation:
AWS Trusted Advisor checks security groups for unrestricted access to commonly used ports, including RDP on port 3389, and can report the groups that are exposed to the internet.

Question 46

A company has scientists who upload large data objects to an Amazon S3 bucket. The scientists upload the objects as multipart uploads. The multipart uploads often fail because of poor end-client connectivity. The company wants to optimize storage costs that are associated with the data. A CloudOps engineer must implement a solution that presents metrics for incomplete uploads. The solution also must automatically delete any incomplete uploads after 7 days. Which solution will meet these requirements?

A. Review the Incomplete Multipart Upload Bytes metric in the S3 Storage Lens dashboard. Create an S3 Lifecycle policy to automatically delete any incomplete multipart uploads after 7 days.
B. Implement S3 Intelligent-Tiering to move data into lower-cost storage classes after 7 days. Create an S3 Storage Lens policy to automatically delete any incomplete multipart uploads after 7 days.
C. Access the S3 console. Review the Metrics tab to check the storage that incomplete multipart uploads are consuming. Create an AWS Lambda function to delete any incomplete multipart uploads after 7 days.
D. Use the S3 analytics storage class analysis tool to identify and measure incomplete multipart uploads. Configure an S3 bucket policy to enforce restrictions on multipart uploads to delete incomplete multipart uploads after 7 days.
Show Answer
Correct Answer: A
Explanation:
Amazon S3 Storage Lens provides the 'Incomplete Multipart Upload Bytes' metric to identify storage consumed by incomplete multipart uploads. An S3 Lifecycle rule with the AbortIncompleteMultipartUpload action can automatically abort and remove incomplete multipart uploads after a specified number of days, such as 7. The other options reference features that do not provide this capability or incorrectly attribute lifecycle behavior to other services.

Question 46

A company has multiple AWS accounts that run applications in different AWS Regions. The company has configured Amazon CloudWatch alarms in each account to monitor CPU utilization and request latency metrics. An operations team must create a centralized dashboard in a single Region within the operations team's AWS account. The dashboard needs to be able to display metrics and alarm states from all applications. Which solution will meet these requirements?

A. Enable the CloudWatch cross-account cross-Region console in each application account. Configure the sharing of metrics and alarms with the operations team's AWS account. In the operations team's AWS account, create a CloudWatch dashboard with the metrics and alarms from the application account.
B. Create an Amazon EventBridge rule in each application account to forward CloudWatch alarm state changes to an Amazon SNS topic in the operations team's AWS account. In the operations team's AWS account, create a CloudWatch dashboard with the metrics and alarms from the application accounts.
C. Deploy AWS Lambda functions in each application account. Configure the functions to periodically extract CloudWatch metrics and alarm states and copy the values to CloudWatch in the operations team's AWS account. In the operations team's AWS account, create a CloudWatch dashboard with the metrics and alarms from the application accounts.
D. Set up CloudWatch cross-account observability. Designate the operations team's AWS account as the monitoring account. Configure the application accounts as source accounts. In the operations team's AWS account, create a CloudWatch dashboard with the metrics and alarms from the application accounts.
Show Answer
Correct Answer: D
Explanation:
CloudWatch cross-account observability uses source accounts linked to a monitoring account, allowing the operations team to view metrics and alarm information centrally and build dashboards from application accounts. Configure the links in the relevant Regions, then create the dashboard in the operations account.

Question 47

A CloudOps engineer needs to ensure that AWS resources across multiple AWS accounts are tagged consistently. The company uses an organization in AWS Organizations to centrally manage the accounts. The company wants to implement cost allocation tags to accurately track the costs that are allocated to each business unit. Which solution will meet these requirements with the LEAST operational overhead?

A. Use Organizations tag policies to enforce mandatory tagging on all resources. Enable cost allocation tags in the AWS Billing and Cost Management console.
B. Configure AWS CloudTrail events to invoke an AWS Lambda function to detect untagged resources and to automatically assign tags based on predefined rules.
C. Use AWS Config to evaluate tagging compliance. Use AWS Budgets to apply tags for cost allocation.
D. Use AWS Service Catalog to provision only pre-tagged resources. Use AWS Trusted Advisor to enforce tagging across the organization.
Show Answer
Correct Answer: A
Explanation:
AWS Organizations tag policies provide centralized governance for tagging across multiple AWS accounts with minimal operational overhead by standardizing and enforcing tag keys and values. To use tags for cost reporting, the relevant cost allocation tags must also be activated in AWS Billing and Cost Management. The other options require custom automation or misuse services that do not enforce or apply cost allocation tags.

Question 47

A gaming company uses Amazon EC2 Spot Instances to run game servers. Currently, the company uses small instance types. However, the company occasionally experiences spot unavailability. The company needs a solution that can automatically modify a spot request and add a new instance family when current instance types are unavailable. Which solution will meet this requirement?

A. Use Amazon CloudWatch to log the event instance-stopped-no-capacity. Invoke an AWS Lambda function to modify the spot request.
B. Use AWS CloudTrail to log EC2 spot request state changes. Configure an Amazon EventBridge rule on the CloudTrail log to invoke an AWS Lambda function to modify the spot request.
C. Use Amazon CloudWatch logs and metrics to invoke an AWS Lambda function to modify the spot request.
D. Configure AWS Systems Manager Automation to detect spot request failures and run a runbook to implement the spot request.
Show Answer
Correct Answer: B
Explanation:
Use CloudTrail to capture EC2 Spot request state changes, then create an EventBridge rule that invokes a Lambda function when a request becomes unavailable. The function can update the request to include another instance family, allowing the company to respond automatically.

Question 48

A company runs a web-based application on Amazon EC2 instances behind an Application Load Balancer (ALB) in the us-east-1 Region. Users from around the world access the application. Users from outside North America report high latency and inconsistent application performance. The company must improve latency and application performance for all global users. Which solution will meet this requirement?

A. Use AWS Global Accelerator in front of the ALB.
B. Deploy a Network Load Balancer (NLB) in front of the AL
C. Replace the ALB with a Network Load Balancer (NLB).
D. Configure Amazon Route 53 health checks to failover between AWS Regions based on latency thresholds.
Show Answer
Correct Answer: A
Explanation:
AWS Global Accelerator improves performance for global users by routing traffic onto the AWS global network to the optimal regional endpoint (the ALB), reducing latency and improving consistency without requiring a multi-Region deployment. Replacing or adding an NLB does not address global internet path latency, and Route 53 failover is for availability rather than performance.

Question 48

A company runs a website from Sydney, Australia. Users in the United States (US) and Europe are reporting that images and videos are taking a long time to load. However, local testing in Australia indicates no performance issues. The website has a large amount of static content in the form of images and videos that are stored in Amazon S3. Which solution will result in the MOST improvement in the user experience for users in the US and Europe?

A. Configure AWS PrivateLink for Amazon S3.
B. Configure S3 Transfer Acceleration.
C. Create an Amazon CloudFront distribution. Distribute the static content to the CloudFront edge locations.
D. Create an Amazon API Gateway API in each AWS Region. Cache the content locally.
Show Answer
Correct Answer: C
Explanation:
Amazon CloudFront caches static images and videos at edge locations near users in the US and Europe, reducing latency and improving load times. S3 Transfer Acceleration is primarily for faster transfers to and from S3, while PrivateLink and API Gateway do not provide the same global content-delivery benefit.

$19

Get all 194 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.