A CloudOps engineer needs to configure a caching layer for a read-heavy application that uses an Amazon RDS for PostgreSQL database. The application exists across three AWS Regions. Read and write activities occur in the primary Region. In the two secondary Regions, read-only activity occurs on RDS for PostgreSQL cross-Region read replicas.
The cache in each Region must consist of the same data to provide a consistent user experience across Regions.
Which solution for the caching layer will meet these requirements?
A. Set up an Amazon ElastiCache (Redis OSS) global datastore. Include a read and write cluster in the primary Region. Include a read-only cluster in each secondary Region.
B. Set up an Amazon ElastiCache (Memcached) global database. Include a read and write cluster in the primary Region. Include a read-only cluster in each secondary Region.
C. Set up query caching on the RDS for PostgreSQL database in the primary Region. Configure query cache replication to the secondary RDS cross-Region replicas.
D. Set up an Amazon ElastiCache (Memcached) cluster with cluster mode enabled in all three Regions. Set up ElastiCache cross-Region replication from the primary Region to the secondary Regions.
Show Answer
Correct Answer: A
Explanation: Amazon ElastiCache for Redis OSS Global Datastore is designed to replicate cache data across Regions. It supports a single writable primary cluster and read-only secondary clusters in other Regions, providing a consistent cache close to users. Memcached does not support global datastore or cross-Region replication, and PostgreSQL does not provide the described query cache replication feature.
Question 39
A security team requires that all Amazon S3 buckets that contain sensitive data must be tagged as "Confidential" and use a restrictive bucket policy. All other buckets must be tagged as "Nonconfidential".
A CloudOps engineer needs to provide a self-service provisioning mechanism that allows different development teams to create S3 buckets with the appropriate tags and policies applied upon creation.
Which solution will meet these requirements in the MOST reliable way?
A. Create an AWS CloudFormation template to create S3 buckets that include a parameter for the classification tag. Distribute the template to all the development teams to use when creating S3 buckets.
B. Create an AWS Step Functions workflow that is triggered by every newly created S3 bucket. Configure the workflow to assign the correct bucket policy after the buckets are provisioned by the development teams.
C. Create an AWS Config rule to check if newly created S3 buckets are correctly tagged as "Nonconfidential" or "Confidential" after the buckets are provisioned by the development teams. Create an AWS Systems Manager Automation document to be triggered by AWS Config for noncompliant buckets.
D. Create two separate AWS Service Catalog products named "Nonconfidential S3 Bucket" and "Confidential S3 Bucket" for creating the S3 buckets. Preconfigure each product with an S3 bucket and the appropriate bucket policy for its classification tag.
Show Answer
Correct Answer: D
Explanation: AWS Service Catalog provides a controlled self-service provisioning mechanism. Separate preconfigured products can create buckets with the correct classification tag and matching bucket policy at creation time, reducing reliance on teams to apply the controls correctly. A distributed CloudFormation template is less reliable because teams could modify or bypass it; the Config and workflow options act after creation.
Question 40
A CloudOps engineer is unable to launch Amazon EC2 instances into a VPC because there are no available private IPv4 addresses in the VPC.
Which combination of actions must the CloudOps engineer take to launch the instances? (Choose two.)
A. Associate a secondary IPv4 CIDR block with the VPC.
B. Associate a primary IPv6 CIDR block with the VPC.
C. Create a new subnet for the VP
D. Modify the CIDR block of the VPC.
E. Modify the CIDR block of the subnet that is associated with the instances.
Show Answer
Correct Answer: A, C
Explanation: If a VPC has exhausted available private IPv4 addresses, you can expand its address space by associating a secondary IPv4 CIDR block. You cannot modify an existing VPC CIDR block or resize an existing subnet CIDR block. After adding the secondary CIDR, you must create a new subnet from that new address range to launch instances into it. Adding IPv6 does not solve the lack of private IPv4 addresses.
Question 40
Users are reporting consistent forced logouts from a stateful web application. The web application is hosted on Amazon EC2 instances that are in an Auto Scaling group. The instances run behind an Application Load Balancer (ALB) that has multiple target groups with one listener rule. The ALB is configured as the origin in an Amazon CloudFront distribution.
Which combination of actions should a CloudOps engineer take to resolve the logout problem? (Choose two.)
A. Change to the least outstanding requests algorithm on the ALB target group.
B. Configure cookie forwarding in the CloudFront distribution's cache behavior settings.
C. Configure header forwarding in the CloudFront distribution's cache behavior settings.
D. Enable group-level stickiness on the ALB listener rule for the target groups.
E. Configure weighted target groups on the ALB.
Show Answer
Correct Answer: B, D
Explanation: CloudFront must forward the ALB stickiness cookies so the browser’s target-group affinity is preserved on subsequent requests. Because the ALB listener rule forwards to multiple target groups, enable group-level stickiness on that rule to keep a client routed to the same target group. Changing the load-balancing algorithm does not provide session persistence.
Question 41
A company uses default settings to create an AWS Lambda function. The function needs to access an Amazon RDS database that is in a private subnet of a VPC. The function has the correct IAM permissions to access the database. The private subnet has appropriate routing configurations and is accessible from within the VPC. However, the Lambda function is unable to connect to the RDS instance.
What is the likely reason the Lambda function cannot connect to the RDS instance?
A. The company did not set the RDS instance as the destination for the Lambda function in the function configuration.
B. The Lambda function configuration did not deploy the function in the same VPC that contains the RDS instance.
C. The VPC where the Lambda function is deployed is not peered with the VPC where the RDS instance is deployed.
D. The security group for the Lambda function does not allow outbound access to the RDS instance.
Show Answer
Correct Answer: B
Explanation: By default, AWS Lambda functions are not attached to a customer's VPC. An Amazon RDS instance in a private subnet is reachable only through network connectivity within that VPC (or connected networks). IAM permissions alone do not provide network access. The Lambda function must be configured to run in the appropriate VPC and subnets with suitable security groups. Option A is not an AWS configuration concept, C is unnecessary if both resources are intended to be in the same VPC, and D is unlikely with default security groups because outbound is typically allowed by default.
Question 41
A company has created an AWS Site-to-Site VPN connection with logging enabled between the company's VPC and an on-premises data center. The company's finance team has begun to experience intermittent connectivity issues when the team tries to access an application that runs in the VPC from the data center.
The company needs to implement an automated monitoring solution to receive immediate notifications when a VPN tunnel becomes unavailable.
Which combination of steps will meet this requirement? (Choose two.)
A. Use Amazon CloudWatch Logs to collect and store VPN collection logs. Convert the logs into readable metrics. Create a metric filter to filter the logs for VPN tunnel metrics.
B. Use AWS CloudTrail to collect VPN logs. Store the logs in an Amazon S3 bucket. Use Amazon Athena to query the data to find site-to-site VPN tunnel connection errors. Store the error files in a second S3 bucket.
C. Use VPN tunnel metrics to create an Amazon CloudWatch alarm. Use Amazon SNS to send a notification when a VPN tunnel state changes.
D. Use Amazon EventBridge rules to invoke an AWS Lambda function. Configure the Lambda function to use Amazon SNS to send a notification when a VPN tunnel connection error is detected.
E. Use AWS Systems Manager to manage the VPN tunnels and to monitor VPN tunnels for any connection errors.
Show Answer
Correct Answer: A, C
Explanation: VPN connection logs can be sent to CloudWatch Logs, where metric filters can extract relevant tunnel events as metrics. CloudWatch alarms on VPN tunnel metrics—such as TunnelState—can then publish immediate notifications through Amazon SNS when a tunnel becomes unavailable.
Question 42
A company has an Amazon S3 bucket that has server-side encryption with AWS KMS keys (SSE-KMS) enabled. Several applications read from the S3 bucket for daily reporting. The company clears the data in the S3 bucket weekly when the company moves the data into a data warehouse.
As more applications read from the S3 bucket, the cost of KMS-related transactions is increasing. A CloudOps engineer needs to reduce the KMS costs without removing S3 encryption and without losing access to existing objects.
Which solution will meet these requirements with the LEAST operational overhead?
A. Enable S3 Bucket Keys on the S3 bucket. Specify the existing KMS key.
B. Change the encryption type on the S3 bucket to server-side encryption with customer-provided keys (SSE-C).
C. Use Amazon CloudFront to cache the objects in the S3 bucket and to serve the objects to the applications.
D. Configure the applications to connect to the S3 bucket through an S3 access point.
Show Answer
Correct Answer: A
Explanation: Amazon S3 Bucket Keys reduce AWS KMS request traffic for SSE-KMS objects by using a bucket-level key cached by S3, significantly lowering KMS costs while retaining SSE-KMS encryption. Existing objects remain accessible, and enabling Bucket Keys requires minimal operational effort. SSE-C changes the encryption model and key management, CloudFront does not address KMS request costs for S3 encryption in this scenario, and S3 Access Points only simplify access management.
Question 42
A company must receive an email notification immediately when new Amazon EC2 instances launch in the company's main AWS production account.
Which solution will meet this requirement?
A. Create a user data script that sends an email message through an SMTP mail relay. Include the company's email address in the user data script as the recipient. Ensure that all new EC2 instances include the user data script as part of a standardized build process.
B. Create an Amazon SNS topic. Configure AWS Systems Manager to publish EC2 events to the SNS topic. Create an AWS Lambda function to poll the SNS topic. Configure the Lambda function to send messages to the company's email address.
C. Create an Amazon SNS topic and a subscription that uses the email protocol. Enter the company's email address as the subscriber. Create an Amazon EventBridge rule that reacts when EC2 instances launch. Specify the SNS topic as the rule's target.
D. Create an Amazon SNS topic and a subscription that uses the email protocol. Enter the company's email address as the subscriber. Use the EC2 AssociateInstanceEventWindow operation to specify the SNS topic as the event target when EC2 instances launch.
Show Answer
Correct Answer: C
Explanation: Create an EventBridge rule that matches EC2 launch events and sends them to an SNS topic with an email subscription. This directly routes the event to the company’s email address; the recipient must confirm the SNS subscription. The other options either rely on instance-specific setup, add unnecessary polling, or use an operation that is not for configuring launch-event notifications.
Question 43
A company plans to deploy a database on an Amazon Aurora MySQL DB cluster. The database will store data for a demonstration environment. The data must be reset on a daily basis.
What is the MOST operationally efficient solution that meets these requirements?
A. Create a manual snapshot of the DB cluster after the data has been populated. Create an Amazon EventBridge rule to invoke an AWS Lambda function on a daily basis. Configure the function to restore the snapshot and then delete the previous DB cluster.
B. Enable the Backtrack feature during the creation of the DB cluster. Specify a target backtrack window of 48 hours. Create an Amazon EventBridge rule to invoke an AWS Lambda function on a daily basis. Configure the function to perform a backtrack operation.
C. Export a manual snapshot of the DB cluster to an Amazon S3 bucket after the data has been populated. Create an Amazon EventBridge rule to invoke an AWS Lambda function on a daily basis. Configure the function to restore the snapshot from Amazon S3.
D. Set the DB cluster backup retention period to 2 days. Create an Amazon EventBridge rule to invoke an AWS Lambda function on a daily basis. Configure the function to restore the DB cluster to a point in time and then delete the previous DB cluster.
Show Answer
Correct Answer: B
Explanation: Amazon Aurora Backtrack is designed to quickly rewind an Aurora MySQL cluster to an earlier point in time without restoring from snapshots. For a demo environment that must be reset daily, enabling Backtrack and scheduling a daily backtrack operation is the most operationally efficient approach. Restoring snapshots or performing point-in-time restores creates new clusters and requires more operational overhead. Exporting snapshots to S3 cannot be restored directly into Aurora.
Question 43
A CloudOps engineer has an AWS CloudFormation template that deploys an encrypted Amazon Machine Image (AMI). The AMI is encrypted with an AWS KMS asymmetric key.
The CloudFormation template needs to be used in a second account. The CloudOps engineer copies the encrypted AMI to the second account. The new CloudFormation stack in the second account fails to launch.
Which action should the CloudOps engineer take to resolve this issue?
A. Update the CloudFormation template with the ID of the AMI in the second account. In the KMS key policy, allow the second account to access the KMS key.
B. Convert the KMS key to a symmetric key. Copy the AMI to the second account. Deregister the AMI in the initial account. Register the AMI in the second account.
C. Export the KMS key from the initial account. Import the KMS key into the second account. Update the CloudFormation template with the KMS key's new Amazon Resource Name (ARN).
D. Export the KMS key from the initial account. Change the AMI permissions to mark the AMI as public. Import the KMS key into the second account.
Show Answer
Correct Answer: A
Explanation: The copied AMI has a different AMI ID, so the template must reference that ID. Cross-account access to the encryption key must also be allowed in the key policy. Note: literally, EBS-backed AMIs can be encrypted only with symmetric KMS keys—not asymmetric keys—so the question’s premise is technically inconsistent; A is the intended answer if “asymmetric” is a wording error.
$19
Get all 194 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.