New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

SAA-C02 Questions Bank

Page: 18 / 27
Total 1 questions

AWS Certified Solutions Architect - Associate (SAA-C03) Questions and Answers

Question 69

A solutions architect is deploying a distributed database on multiple Amazon EC2 instances. The database stores all data on multiple instances so it can withstand the loss of an instance. The database requires block storage with latency and throughput to support several million transactions per second per server.

Which storage solution should the solutions architect use?

Options:

A.

Amazon EBS

B.

Amazon EC2 instance store

C.

Amazon EFS

D.

Amazon S3

Question 70

A company's website is used to sell products to the public The site runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB) There is also an Amazon CloudFront distribution and AWS WAF Is being used to protect against SQL injection attacks The ALB is the origin for the CloudFront distribution A recent review of security logs revealed an external malicious IP that needs to be blocked from accessing the website

What should a solutions architect do to protect the application?

Options:

A.

Modify the network ACL on the CloudFront distribution to add a deny rule for the malicious IP address

B.

Modify the configuration of AWS WAF to add an IP match condition to block the malicious IP address

C.

Modify the network ACL for the EC2 instances in the target groups behind the ALB to deny the malicious IP address

D.

Modify the security groups for the EC2 instances in the target groups behind the ALB to deny the malicious IP address

Question 71

A developer is creating an AWS Lambda function to perform dynamic updates to a database when an item is added to an Amazon Simple Queue Service (Amazon SOS) queue A solutions architect must recommend a solution that tracks any usage of database credentials in AWS CloudTrail. The solution also must provide auditing capabilities.

Which solution will meet these requirements?

Options:

A.

Store the encrypted credentials in a Lambda environment variable

B.

Create an Amazon DynamoDB table to store the credentials Encrypt the table

C.

Store the credentials as a secure string in AWS Systems Manager Parameter Store

D.

Use an AWS Key Management Service (AWS KMS) key store to store the credentials

Question 72

A company wants to perform an online migration of active datasets from an on-premises NFS server to an Amazon S3 bucket that is named DOC-EXAMPLE-BUCKET Data integrity verification is required during the transfer and at the end of the transfer. The data also must he encrypted

A solutions architect is using an AWS solution to migrate the data.

Which solution meets these requirements?

Options:

A.

AWS Storage Gateway file gateway

B.

S3 Transfer Acceleration

C.

AWS DataSync

D.

AWS Snowhall Edge Storage Optimized

Page: 18 / 27
Total 1 questions