Lets you launch AWS resources inside a logically isolated virtual network that you define yourself
Connects an on-premises network to AWS over a dedicated connection, bypassing the ISPs along the route
Lets you use domain registration, DNS routing, and health checks, choosing any combination you need
Delivers web content to users at low latency from a worldwide network of edge locations
AnswerA. Lets you launch AWS resources inside a logically isolated virtual network that you define yourself
VPC is a service that lets you launch AWS resources inside a logically isolated virtual network that you define yourself, letting you build a configuration on AWS that closely resembles a traditional network in your own data center. Delivering content from edge locations is CloudFront's job, providing domain registration, DNS routing, and health checks is Route 53's job, and running a dedicated connection that bypasses ISPs along the route is Direct Connect's job.
Q2 | Subnet
Which correctly describes a VPC subnet?
A table that decides where traffic from a subnet is directed, of which only one can be placed per VPC
An IP address range that spans every Availability Zone within a Region
An IP address range within a VPC that always belongs to a single Availability Zone
The gateway that connects a VPC to the internet, of which only one can be placed per VPC
AnswerC. An IP address range within a VPC that always belongs to a single Availability Zone
A subnet is an IP address range within a VPC that always belongs to a single Availability Zone. So a subnet cannot span AZs, and distributing across multiple AZs means creating one subnet per AZ. Deciding where traffic is directed is the route table's job, and the gateway to the internet is the internet gateway — both are separate components from a subnet.
Q3 | Route table
Which role does a VPC route table fulfill?
Serves as the gateway that itself provides the connection between the VPC and the internet
Decides where traffic from a subnet or gateway is directed
Proxies and relays outbound traffic on behalf of resources that have private IPs
Carves out and defines the actual IP address range usable in a subnet
AnswerB. Decides where traffic from a subnet or gateway is directed
A route table is a table that decides where traffic from a subnet or gateway is directed. Carving out the IP address range is the subnet's job, providing the connection to the internet is the internet gateway's job, and proxying outbound traffic for resources with private IPs is the NAT gateway's job. The four components do not overlap in their roles.
Q4 | Outbound traffic
You want an EC2 instance that has only a private IP address to connect to a repository on the internet. Which configuration is appropriate?
Create a Direct Connect virtual interface and point the default route there
Place a NAT gateway in a public subnet and point the default route there
Create a CloudFront distribution and point the default route there
Connect an internet gateway directly to the private subnet and route through it
AnswerB. Place a NAT gateway in a public subnet and point the default route there
A NAT gateway is a mechanism that lets a resource with a private IP address access the internet while remaining private. Because it only proxies traffic from inside going out, an inbound connection from outside cannot be established through it. An internet gateway connects the VPC itself to the internet and is not a component placed inside a subnet. Direct Connect is a dedicated connection to an on-premises network, and CloudFront is a content delivery service — neither is used for this purpose.
Q5 | Route 53 features
Which is the correct combination of the three functions Amazon Route 53 provides?
Domain registration, content delivery, and load balancing
Domain registration, DNS routing, and health checking
Domain registration, certificate issuance, and content delivery
DNS routing, certificate issuance, and load balancing
AnswerB. Domain registration, DNS routing, and health checking
Route 53 is a highly available, scalable DNS web service with three functions — domain registration, DNS routing, and health checking — which can be combined in any way you need. Content delivery is CloudFront's job, and distributing incoming traffic is Elastic Load Balancing's job; neither is a function of Route 53.
Q6 | What gets delivered
Which content does Amazon CloudFront speed up delivery for?
Only dynamic web content is a target; static files are not
Only static web content is a target; dynamic responses are not
Only traffic passing through a dedicated connection to an on-premises network is a target
Both static and dynamic web content are targets
AnswerD. Both static and dynamic web content are targets
CloudFront is a CDN that speeds up the delivery of both static and dynamic web content. It is often assumed to deliver only static files, but the official description includes dynamic content as well. Delivery happens through a worldwide network of data centers called edge locations, from whichever location has the lowest latency. Handling a dedicated connection to an on-premises network is Direct Connect's job, not CloudFront's.
Q7 | Direct Connect
Which is a characteristic of AWS Direct Connect?
Connects VPCs to each other so they can communicate while keeping private IP addresses
Speeds up responses for traffic from on-premises by routing it through edge locations
Bypasses the ISPs along the route and connects on-premises networks to AWS over a dedicated connection
Builds an encrypted tunnel over an internet connection and connects to a VPC through it
AnswerC. Bypasses the ISPs along the route and connects on-premises networks to AWS over a dedicated connection
Direct Connect is a service that connects an on-premises network to a Direct Connect location using standard Ethernet fiber-optic cable, bypassing the ISPs along the network path, and creates a virtual interface directly to AWS services. The key point is that it is a dedicated connection that does not go over the internet, which is where it differs from an approach that builds an encrypted tunnel over the internet.
Q8 | What distinguishes public
What determines the difference between a public subnet and a private subnet?
Whether the subnet belongs to only a single Availability Zone
Whether an instance within the subnet is equipped with a NAT gateway
Whether the route table points to an internet gateway
Whether the IP address range assigned to the subnet is a public-use range
AnswerC. Whether the route table points to an internet gateway
A route table is a table that decides where traffic from a subnet or gateway is directed. A subnet whose route table has a route to an internet gateway is conventionally called a public subnet, and one without such a route is called a private subnet. A subnet always belongs to a single AZ, so the number of AZs does not distinguish them. When a resource in a private subnet goes outbound, it goes through a NAT gateway.
Q9 | Origin
What does an "origin" refer to in Amazon CloudFront?
The caching location that returns content from the location closest to the user
The DNS mechanism that directs a delivery destination in response to a name lookup
The intermediate caching layer placed between an edge location and the source of the content
An S3 bucket or HTTP server that holds the source of the content being delivered
AnswerD. An S3 bucket or HTTP server that holds the source of the content being delivered
An origin is the location that holds the source of the content CloudFront delivers, such as an S3 bucket or an HTTP server. When the content requested is not at the edge location, CloudFront fetches it from the origin and delivers it. Returning content from the location closest to the user is the edge location's job, the intermediate caching layer between an edge location and the origin is the Regional Edge Cache, and directing a destination in response to a name lookup is Route 53's DNS routing.
Q10 | Choosing functions
Your company's domain name is already registered with a different registrar. What can you still do with Route 53 in this case?
No function can be used unless the domain is transferred to Route 53
Only the domain registration function is usable; DNS routing cannot be used
Only the health-checking function is usable; DNS routing cannot be used
You can choose and use only the functions you need, such as DNS routing or health checking
AnswerD. You can choose and use only the functions you need, such as DNS routing or health checking
Route 53 is a DNS web service whose three functions — domain registration, DNS routing, and health checking — can be combined in any way you need. It is not a system where all three must be present to function, so you can leave the domain registered elsewhere while entrusting only DNS routing to Route 53, or use only health checking. Transferring the domain is not a prerequisite for using it.
Q11 | ALB's layer
At which OSI layer does an Application Load Balancer operate?
Layer 4 (transport layer)
Layer 7 (application layer)
Layer 3 (network layer)
Layer 2 (data link layer)
AnswerB. Layer 7 (application layer)
ALB operates at Layer 7, the application layer, handling HTTP, HTTPS, and gRPC. Because it looks this deep, it can use the contents of HTTP as a basis for decisions, enabling flexible routing such as content-based routing. NLB operates at Layer 4 (TCP, UDP, TLS), and Gateway Load Balancer operates at Layers 3 and 4 (IP).
Q12 | NLB's protocols
Which combination of protocols can a Network Load Balancer handle?
TCP, UDP, and TLS
IP, HTTP, and HTTPS
HTTP, HTTPS, and gRPC
TCP, TLS, and gRPC
AnswerA. TCP, UDP, and TLS
NLB is a Layer 4 load balancer that handles TCP, UDP, and TLS. It is the choice when you need extremely high performance and a static IP address. Handling HTTP, HTTPS, and gRPC is the Layer 7 ALB's job, and passing IP traffic through transparently without terminating flows is Gateway Load Balancer's job. gRPC is not on NLB's list of supported protocols.
Q13 | GWLB's properties
Which is a characteristic of Gateway Load Balancer?
Terminates TLS, centralizing certificate management on the load balancer's side
Operates at Layers 3 and 4, passing flows through transparently to an appliance without terminating them
Routes requests to different targets by looking at the HTTP path or hostname
Has a static IP address and distributes UDP-based traffic to targets with high performance
AnswerB. Operates at Layers 3 and 4, passing flows through transparently to an appliance without terminating them
GWLB operates at Layers 3 and 4, handling the IP protocol. It is a mechanism for placing appliance-based security or network functions in the traffic path, and the decisive difference from the other two is that it passes flows through transparently without terminating them. Routing by looking at HTTP contents is the Layer 7 ALB's forte, and a static IP with UDP is the Layer 4 NLB's forte.
Q14 | Fixed IP
You need a load balancer with an unchanging IP address so a business partner can register it in their firewall. Which is appropriate?
Classic Load Balancer. It supports SSL/TLS termination
Network Load Balancer. It can be given a static IP address
Gateway Load Balancer. It can pass an appliance through transparently
Application Load Balancer. It can route based on content
AnswerB. Network Load Balancer. It can be given a static IP address
When a static IP address is required, choose NLB. NLB operates at Layer 4 and is officially positioned as suited to scenarios requiring extremely high performance and a static IP. ALB operates at Layer 7, handling HTTP, HTTPS, and gRPC, with content-based routing as its forte. GWLB is for inserting an appliance transparently. Classic Load Balancer is an older generation that supports TCP, SSL/TLS, HTTP, and HTTPS.
Q15 | ELB's role
What is the basic role of Elastic Load Balancing?
Distributes traffic across Regions and also handles domain name registration
Automatically distributes traffic to multiple targets across one or more Availability Zones
Distributes traffic only to targets within a single Availability Zone
Replicates content to edge locations and delivers it to users from the nearest one
AnswerB. Automatically distributes traffic to multiple targets across one or more Availability Zones
ELB automatically distributes incoming application traffic across multiple targets in one or more Availability Zones. It is not confined to a single AZ, and being able to distribute across targets split among multiple AZs is the foundation of availability design. Domain name registration is Route 53's job, and delivery from edge locations is CloudFront's job.
Q16 | gRPC
You want a load balancer to receive traffic that uses gRPC. Which is appropriate?
Classic Load Balancer. It supports both Layer 4 and Layer 7
Application Load Balancer. It can handle gRPC at Layer 7
Gateway Load Balancer. It passes traffic through transparently at Layers 3 and 4
Network Load Balancer. It delivers high performance at Layer 4
AnswerB. Application Load Balancer. It can handle gRPC at Layer 7
The protocols ALB handles are HTTP, HTTPS, and gRPC, and it operates at Layer 7. Of these options, ALB is the only one that can directly handle gRPC. NLB is a Layer 4 load balancer handling TCP, UDP, and TLS, and GWLB is a Layer 3/4 load balancer handling IP. Classic Load Balancer supports TCP, SSL/TLS, HTTP, and HTTPS.
Q17 | Distributing UDP
You want to distribute UDP-based traffic across multiple targets. Which is appropriate?
Application Load Balancer. It is stated to support HTTPS
Classic Load Balancer. It is stated to support SSL/TLS
Gateway Load Balancer. It is stated to pass IP through as is
Network Load Balancer. It is stated to support UDP
AnswerD. Network Load Balancer. It is stated to support UDP
NLB is a Layer 4 load balancer that handles TCP, UDP, and TLS, so it can distribute UDP traffic. What ALB handles is HTTP, HTTPS, and gRPC, which does not include UDP. GWLB handles IP, but it is meant for passing traffic transparently to an appliance, not for general-purpose load balancing. Classic Load Balancer supports TCP, SSL/TLS, HTTP, and HTTPS.
Q18 | Layer lineup
Which combination correctly states the OSI layers at which ALB, NLB, and GWLB operate?
ALB at Layer 4, NLB at Layer 7, GWLB at Layers 3 and 4
ALB at Layers 3 and 4, NLB at Layer 7, GWLB at Layer 4
ALB at Layer 7, NLB at Layer 4, GWLB at Layers 3 and 4
ALB at Layer 7, NLB at Layers 3 and 4, GWLB at Layer 4
AnswerC. ALB at Layer 7, NLB at Layer 4, GWLB at Layers 3 and 4
ALB handles HTTP, HTTPS, and gRPC at Layer 7; NLB handles TCP, UDP, and TLS at Layer 4; and GWLB handles IP at Layers 3 and 4. It helps to remember the lineup by thinking that the higher the layer number, the more high-level information is visible for routing decisions. GWLB alone spans two layers because of its nature of passing IP packets through transparently as is.
Q19 | Path-based routing
You want to change where a request is sent based on the URL path. Which load balancer is appropriate, and why?
Classic Load Balancer, because it is built to terminate both TCP and HTTP
Application Load Balancer, because it can see the contents of HTTP at Layer 7
Gateway Load Balancer, because it can pass IP through transparently at Layers 3 and 4
Network Load Balancer, because it can process TCP at Layer 4 with high speed
AnswerB. Application Load Balancer, because it can see the contents of HTTP at Layer 7
Routing based on the contents of HTTP, such as the path or hostname, is called content-based routing and is the forte of ALB, which operates at Layer 7. NLB operates at Layer 4, so it does not see the contents of HTTP. GWLB passes flows through without terminating them, so the only thing available for routing decisions is IP. Classic Load Balancer is also an older-generation design; ALB is the choice for this purpose.
Q20 | Inspection appliance
You want to place a third-party security inspection appliance in the traffic path and pass everything through it. Which is appropriate?
Network Load Balancer. It offers high performance and a static IP at Layer 4
Amazon CloudFront. It checks content at the edge location before delivering it
Gateway Load Balancer. It can pass flows through transparently without terminating them
Application Load Balancer. It can inspect requests at Layer 7
AnswerC. Gateway Load Balancer. It can pass flows through transparently without terminating them
GWLB operates at Layers 3 and 4, handling the IP protocol, and is a load balancer designed for appliance-based security or network functions. Because it passes flows through transparently without terminating them, inserting an inspection appliance in the middle does not change how the traffic looks. ALB and NLB are designed to receive traffic themselves and distribute it, not to pass it through transparently. CloudFront is a content delivery service.
Q21 | What IAM covers
What does AWS Identity and Access Management manage?
Creating keys used for data encryption and signing, and controlling their use
Monitoring HTTP requests arriving at a web application and controlling access
Access control over resources: who is authenticated and who is authorized
Storing database credentials and API keys, and rotating them
AnswerC. Access control over resources: who is authenticated and who is authorized
IAM is a service that securely controls access to AWS resources, managing who is authenticated (signed in) and who is authorized (holds permissions). Creating and controlling keys is KMS's job, monitoring and controlling HTTP requests is WAF's job, and storing and rotating credentials and API keys is Secrets Manager's job. The roles do not overlap.
Q22 | Authentication and authorization
Which correctly describes authentication and authorization as handled by IAM?
Authentication decides whether you can sign in; authorization decides whether you hold permissions
Both authentication and authorization turn permission strength into numbers for comparison
Authentication decides whether you hold permissions; authorization decides whether you can sign in
Both authentication and authorization check, in two steps, whether you can sign in
AnswerA. Authentication decides whether you can sign in; authorization decides whether you hold permissions
IAM is a service that manages "who is authenticated (signed in) and who is authorized (holds permissions)." Authentication is the step of confirming you are who you say you are, and authorization is the subsequent step that decides what you are allowed to do — they differ both in order and in role. Even if you can sign in, you cannot perform an operation not permitted by policy. Swapping the two when memorizing them leads to misreading permission design.
Q23 | KMS keys
Which correctly describes how a KMS key in AWS Key Management Service is handled?
It is protected by a certified HSM and never leaves KMS unencrypted
Each time it is rotated, the new key value is notified to the customer in plaintext
The customer can export it in plaintext to a location of their choosing for storage
It is designed to be embedded in an application's configuration file for distribution
AnswerA. It is protected by a certified HSM and never leaves KMS unencrypted
KMS is a managed service that makes it easy to create and control keys used for encryption and signing, and a KMS key is protected by an HSM certified to FIPS 140-3 Security Level 3. The key never leaves KMS in an unencrypted state. So exporting or distributing it in plaintext is not something that can be done; instead, encryption and decryption operations are requested from KMS.
Q24 | WAF actions
Which combination of actions can AWS WAF take on a request?
Log, notify, aggregate, display on a dashboard
Encrypt, decrypt, sign, rotate keys
Allow, block, count, CAPTCHA
Register domain, resolve name, transfer, monitor
AnswerC. Allow, block, count, CAPTCHA
WAF monitors HTTP and HTTPS requests forwarded to a protected web application resource and controls access using actions such as allow, block, count, and CAPTCHA or challenge. Because there is a count action, you can measure the impact before turning a rule into a full block, rather than blocking immediately. Encryption and signing belong to KMS, logging and visualization to CloudWatch, and domain registration and name resolution to Route 53.
Q25 | Shield tiers
Which correctly describes the difference between AWS Shield Standard and Advanced?
Neither Standard nor Advanced costs extra, differing only in geographic coverage
Standard is automatically included at no extra cost, and Advanced is extended protection for an extra fee
Standard is extended protection for an extra fee, and Advanced is automatically included at no extra cost
Both Standard and Advanced require an extra fee, differing only in contract length
AnswerB. Standard is automatically included at no extra cost, and Advanced is extended protection for an extra fee
Shield provides protection against DDoS attacks. Standard is basic protection automatically included at no extra cost with things like AWS WAF, and Advanced is extended protection available for an additional fee. Advanced provides automatic mitigation of Layer 7 DDoS attacks, detailed visibility, and dedicated support from the Shield Response Team (SRT). Watch out for an answer choice that reverses which one costs extra.
Q26 | SRT
Which is available with AWS Shield Advanced?
A rotation feature that periodically swaps out database credentials
A mechanism for centrally managing protection settings across multiple accounts
Dedicated support and detailed visibility from the Shield Response Team
A user directory responsible for customer sign-in and token issuance
AnswerC. Dedicated support and detailed visibility from the Shield Response Team
Shield Advanced is extended protection for an extra fee, providing automatic mitigation of Layer 7 DDoS attacks, detailed visibility, and dedicated support from the Shield Response Team (SRT). Rotation is Secrets Manager's job, centrally managing protection across multiple accounts is AWS Firewall Manager's job, and a user directory with token issuance is Amazon Cognito's user pools.
Q27 | Managing secrets
Which is the role of AWS Secrets Manager?
Records changes in resource configuration and evaluates compliance against rules
Accepts customer sign-ins and issues tokens for applications
Manages, retrieves, and rotates database credentials and API keys
Creates encryption keys themselves and lets them be used while protected inside an HSM
AnswerC. Manages, retrieves, and rotates database credentials and API keys
Secrets Manager is a service that manages, retrieves, and rotates secrets — such as database credentials, application credentials, OAuth tokens, and API keys — across their entire lifecycle. Sign-in and token issuance is Cognito's job, recording configuration and evaluating compliance is AWS Config's job, and creating and protecting the keys themselves is KMS's job. It helps to remember Secrets Manager as the one that carries values around.
Q28 | Two pools
Which correctly describes Amazon Cognito user pools and identity pools?
User pools issue temporary AWS credentials, and identity pools issue tokens
User pools are a user directory, and identity pools issue AWS credentials
User pools decide permissions on AWS resources, and identity pools decide whether sign-in is allowed
User pools and identity pools must always be used as a pair; neither can be used alone
AnswerB. User pools are a user directory, and identity pools issue AWS credentials
A user pool is a user directory that authenticates and authorizes users for apps and APIs, functioning as an independent OIDC identity provider that issues OAuth 2.0 tokens and JWTs. An identity pool grants authenticated or unauthenticated users access to AWS resources, issuing temporary AWS credentials via AWS STS. Integrating the two is not mandatory for either; each can be used on its own.
Q29 | Temporary keys
You want to give a mobile app's users temporary credentials for accessing AWS resources. Which is appropriate?
Use a Cognito identity pool to issue temporary credentials via AWS STS
Create one IAM user per user and assign a policy to each
Pass the JWT issued by a Cognito user pool directly as the credential
Distribute long-term credentials stored in Secrets Manager to each user
AnswerA. Use a Cognito identity pool to issue temporary credentials via AWS STS
An identity pool is a mechanism that grants authenticated or unauthenticated users access to AWS resources, issuing temporary AWS credentials via AWS STS. What a user pool issues is OAuth 2.0 tokens and JWTs, which are not credentials for calling AWS APIs directly. Distributing long-term credentials, or creating an IAM user per user, is not suited to this purpose.
Q30 | Central management
Which is the role of AWS Firewall Manager?
Individually inspects requests to a web application within a single account
Consolidates customer sign-in information into one place across accounts
Centrally manages protection settings across multiple accounts and resources
Creates an encryption key for each account and keeps a log of its use
AnswerC. Centrally manages protection settings across multiple accounts and resources
Firewall Manager is a service that centrally manages protections — such as AWS WAF, Shield Advanced, VPC security groups and network ACLs, Network Firewall, and Route 53 Resolver DNS Firewall — across multiple accounts and resources. Inspecting individual requests is WAF's own job, creating keys is KMS's job, and handling sign-in information is Cognito's job.
Q31 | What CloudWatch covers
What does Amazon CloudWatch primarily handle?
Real-time monitoring of resource performance and state
Resource configuration and its history of changes
A record of who performed which API operation
Building resources based on templates
AnswerA. Real-time monitoring of resource performance and state
CloudWatch monitors AWS resources and the applications running on them in real time, visualizing performance, operational status, and resource utilization through metrics, logs, alarms, and dashboards. Recording who performed which API operation is CloudTrail's job, recording configuration and its changes is AWS Config's job, and building resources from templates is CloudFormation's job.
Q32 | Who did it
You want to find out who changed a resource's configuration last month. What would you use?
Run Command in AWS Systems Manager
Amazon CloudWatch metrics and alarms
The list of AWS CloudFormation stacks
Events recorded in AWS CloudTrail
AnswerD. Events recorded in AWS CloudTrail
CloudTrail records the actions taken by users, roles, and AWS services as events. It covers operations through the management console, CLI, and SDK or API, letting you trace afterward who performed which API operation. CloudWatch handles performance and status monitoring, CloudFormation handles building from templates, and Systems Manager handles operational tasks on nodes — none of them is aimed at tracing who performed an action.
Q33 | Config
Which correctly describes AWS Config?
Collects resource metrics and issues notifications when a threshold is exceeded
Lets you write resource creation into a template, build it all at once, and delete it too
Records which user operated on a resource and what that operation was
Records resource configuration and relationships and evaluates compliance against rules
AnswerD. Records resource configuration and relationships and evaluates compliance against rules
Config provides a detailed view of resource configuration, recording relationships between resources and how they were configured in the past so configuration changes can be tracked. It also evaluates configuration with Config rules, flagging non-compliant resources that violate them. Monitoring thresholds is CloudWatch's job, building from templates is CloudFormation's job, and recording operations is CloudTrail's job.
Q34 | Three distinctions
Which combination correctly matches the roles of CloudWatch, CloudTrail, and AWS Config?
CloudWatch records operations, CloudTrail records configuration, Config monitors performance
CloudWatch monitors performance, CloudTrail records operations, Config records configuration
CloudWatch monitors performance, CloudTrail records configuration, Config records operations
CloudWatch records configuration, CloudTrail monitors performance, Config records operations
AnswerB. CloudWatch monitors performance, CloudTrail records operations, Config records configuration
It helps to memorize the three together: CloudWatch is real-time monitoring of performance and status, CloudTrail is a record of who performed which API operation, and Config is a record of resource configuration and an evaluation of compliance. They are not competing services — a CloudTrail trail is stored in an S3 bucket and can optionally also be delivered to CloudWatch Logs, making CloudTrail the sender and CloudWatch Logs a possible receiving end.
Q35 | IaC building blocks
Which correctly describes the relationship between an AWS CloudFormation template and a stack?
A template is a group of built resources, and a stack is the design that produced them
A template is a document describing the resources needed, and a stack is the group of resources created
A template is an execution log of a build, and a stack is the procedure for replaying it
Both a template and a stack are monthly reports aggregating resource usage
AnswerB. A template is a document describing the resources needed, and a stack is the group of resources created
In CloudFormation, you create a template, a text file describing the resources you need, and CloudFormation provisions and configures the resources accordingly. The resources created can be managed together as a single unit called a stack, and can also be deleted together. So a template corresponds to a blueprint, and a stack corresponds to the resulting group of resources.
Q36 | Stack
Which correctly describes a CloudFormation stack?
Deleting a stack leaves the resources created from the template still in place
Resources created from a template can only be deleted one at a time individually
It records the content of a template over time as a history of configuration changes
A group of resources created from a template can be handled together as a single unit
AnswerD. A group of resources created from a template can be handled together as a single unit
The group of resources CloudFormation creates can be managed as a single unit called a stack, and it can also be deleted all at once. It is not the case that resources can only be handled individually; deleting the stack deletes the resources it contains together with it. Recording configuration changes over time is AWS Config's role. Being able to build as a group and tear down as a group is a benefit of treating infrastructure as code.
Q37 | Where SSM fits
Where is AWS Systems Manager positioned?
A unified entry point for managing AWS and on-premises nodes centrally at scale
A mechanism that records changes to resource configuration and surfaces non-compliant resources
A mechanism that automatically distributes incoming traffic across multiple targets
A mechanism that reads a template and builds resources all at once
AnswerA. A unified entry point for managing AWS and on-premises nodes centrally at scale
Systems Manager is a unified interface for viewing, managing, and operating nodes across AWS, on-premises, and multi-cloud environments centrally at scale, including capabilities such as Run Command, Session Manager, Automation, Parameter Store, Patch Manager, and Fleet Manager. Recording configuration is Config's job, building from templates is CloudFormation's job, and distributing traffic is ELB's job.
Q38 | Spot
Which is a characteristic of EC2 Spot Instances?
They use unused capacity in the AWS Cloud and can be interrupted
They receive a discount in exchange for a 1-year or 3-year usage commitment
They have no upfront payment or commitment and are billed per hour or per second
They receive a discount in exchange for committing to fixed instance attributes
AnswerA. They use unused capacity in the AWS Cloud and can be interrupted
Spot Instances are a purchasing option that uses unused EC2 capacity in the AWS Cloud, offering a substantial discount but with the possibility of interruption. They suit batch processing or test environments that can tolerate interruption. Committing to usage is Savings Plans, committing to instance attributes is a Reserved Instance, and having no upfront payment or commitment is On-Demand.
Q39 | Savings Plans vs. Reserved Instances
Which correctly describes the difference between Savings Plans and Reserved Instances?
Savings Plans terms are only 1 year, while Reserved Instances are only 3 years
Savings Plans can be interrupted, while Reserved Instances cannot
Savings Plans commit to a usage level, while Reserved Instances commit to instance attributes
Savings Plans require upfront payment, while Reserved Instances cannot be paid upfront
AnswerC. Savings Plans commit to a usage level, while Reserved Instances commit to instance attributes
Savings Plans is a pricing model that gives a discount in exchange for committing to a set usage level, while a Reserved Instance is a pricing model that gives a discount in exchange for committing to attributes such as instance type, platform, and tenancy. Both have terms of 1 year or 3 years, and payment can be chosen as all upfront, partial upfront, or no upfront. It is Spot Instances that can be interrupted.
Q40 | Types of Savings Plans
Which correctly describes the difference between Compute Savings Plans and EC2 Instance Savings Plans?
Compute allows only no-upfront payment, and EC2 Instance allows only all-upfront payment
Compute has only a 1-year term, and EC2 Instance is limited to only 3 years
Compute can span both family and Region, but EC2 Instance cannot
Compute fixes the instance family, and EC2 Instance fixes the Region
AnswerC. Compute can span both family and Region, but EC2 Instance cannot
Compute Savings Plans are the most flexible, supporting changes in instance family, changes in Region, moving between EC2, Fargate, and Lambda, and changes of OS. EC2 Instance Savings Plans commit to a specific instance family in a specific Region, so while size changes within the family and OS changes are possible, changing family or Region is not. The term for both is 1 year or 3 years, and payment can be chosen as all upfront, partial upfront, or no upfront.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original