Karinoya Learning Room

Qualifications · Cloud / AI / Python Success Lab

Networking, Operations, and Pricing

Read the questions and explanations in English. The lectures (explanatory articles) are available in Japanese only.

View the Japanese version (with lectures) →

Q1 | Role of a VPC

Which correctly describes Amazon VPC?

  1. Lets you launch AWS resources inside a logically isolated virtual network that you define yourself
  2. Connects an on-premises network to AWS over a dedicated connection, bypassing the ISPs along the route
  3. Lets you use domain registration, DNS routing, and health checks, choosing any combination you need
  4. Delivers web content to users at low latency from a worldwide network of edge locations
AnswerA. Lets you launch AWS resources inside a logically isolated virtual network that you define yourself

VPC is a service that lets you launch AWS resources inside a logically isolated virtual network that you define yourself, letting you build a configuration on AWS that closely resembles a traditional network in your own data center. Delivering content from edge locations is CloudFront's job, providing domain registration, DNS routing, and health checks is Route 53's job, and running a dedicated connection that bypasses ISPs along the route is Direct Connect's job.

Q2 | Subnet

Which correctly describes a VPC subnet?

  1. A table that decides where traffic from a subnet is directed, of which only one can be placed per VPC
  2. An IP address range that spans every Availability Zone within a Region
  3. An IP address range within a VPC that always belongs to a single Availability Zone
  4. The gateway that connects a VPC to the internet, of which only one can be placed per VPC
AnswerC. An IP address range within a VPC that always belongs to a single Availability Zone

A subnet is an IP address range within a VPC that always belongs to a single Availability Zone. So a subnet cannot span AZs, and distributing across multiple AZs means creating one subnet per AZ. Deciding where traffic is directed is the route table's job, and the gateway to the internet is the internet gateway — both are separate components from a subnet.

Q3 | Route table

Which role does a VPC route table fulfill?

  1. Serves as the gateway that itself provides the connection between the VPC and the internet
  2. Decides where traffic from a subnet or gateway is directed
  3. Proxies and relays outbound traffic on behalf of resources that have private IPs
  4. Carves out and defines the actual IP address range usable in a subnet
AnswerB. Decides where traffic from a subnet or gateway is directed

A route table is a table that decides where traffic from a subnet or gateway is directed. Carving out the IP address range is the subnet's job, providing the connection to the internet is the internet gateway's job, and proxying outbound traffic for resources with private IPs is the NAT gateway's job. The four components do not overlap in their roles.

Q4 | Outbound traffic

You want an EC2 instance that has only a private IP address to connect to a repository on the internet. Which configuration is appropriate?

  1. Create a Direct Connect virtual interface and point the default route there
  2. Place a NAT gateway in a public subnet and point the default route there
  3. Create a CloudFront distribution and point the default route there
  4. Connect an internet gateway directly to the private subnet and route through it
AnswerB. Place a NAT gateway in a public subnet and point the default route there

A NAT gateway is a mechanism that lets a resource with a private IP address access the internet while remaining private. Because it only proxies traffic from inside going out, an inbound connection from outside cannot be established through it. An internet gateway connects the VPC itself to the internet and is not a component placed inside a subnet. Direct Connect is a dedicated connection to an on-premises network, and CloudFront is a content delivery service — neither is used for this purpose.

Q5 | Route 53 features

Which is the correct combination of the three functions Amazon Route 53 provides?

  1. Domain registration, content delivery, and load balancing
  2. Domain registration, DNS routing, and health checking
  3. Domain registration, certificate issuance, and content delivery
  4. DNS routing, certificate issuance, and load balancing
AnswerB. Domain registration, DNS routing, and health checking

Route 53 is a highly available, scalable DNS web service with three functions — domain registration, DNS routing, and health checking — which can be combined in any way you need. Content delivery is CloudFront's job, and distributing incoming traffic is Elastic Load Balancing's job; neither is a function of Route 53.

Q6 | What gets delivered

Which content does Amazon CloudFront speed up delivery for?

  1. Only dynamic web content is a target; static files are not
  2. Only static web content is a target; dynamic responses are not
  3. Only traffic passing through a dedicated connection to an on-premises network is a target
  4. Both static and dynamic web content are targets
AnswerD. Both static and dynamic web content are targets

CloudFront is a CDN that speeds up the delivery of both static and dynamic web content. It is often assumed to deliver only static files, but the official description includes dynamic content as well. Delivery happens through a worldwide network of data centers called edge locations, from whichever location has the lowest latency. Handling a dedicated connection to an on-premises network is Direct Connect's job, not CloudFront's.

Q7 | Direct Connect

Which is a characteristic of AWS Direct Connect?

  1. Connects VPCs to each other so they can communicate while keeping private IP addresses
  2. Speeds up responses for traffic from on-premises by routing it through edge locations
  3. Bypasses the ISPs along the route and connects on-premises networks to AWS over a dedicated connection
  4. Builds an encrypted tunnel over an internet connection and connects to a VPC through it
AnswerC. Bypasses the ISPs along the route and connects on-premises networks to AWS over a dedicated connection

Direct Connect is a service that connects an on-premises network to a Direct Connect location using standard Ethernet fiber-optic cable, bypassing the ISPs along the network path, and creates a virtual interface directly to AWS services. The key point is that it is a dedicated connection that does not go over the internet, which is where it differs from an approach that builds an encrypted tunnel over the internet.

Q8 | What distinguishes public

What determines the difference between a public subnet and a private subnet?

  1. Whether the subnet belongs to only a single Availability Zone
  2. Whether an instance within the subnet is equipped with a NAT gateway
  3. Whether the route table points to an internet gateway
  4. Whether the IP address range assigned to the subnet is a public-use range
AnswerC. Whether the route table points to an internet gateway

A route table is a table that decides where traffic from a subnet or gateway is directed. A subnet whose route table has a route to an internet gateway is conventionally called a public subnet, and one without such a route is called a private subnet. A subnet always belongs to a single AZ, so the number of AZs does not distinguish them. When a resource in a private subnet goes outbound, it goes through a NAT gateway.

Q9 | Origin

What does an "origin" refer to in Amazon CloudFront?

  1. The caching location that returns content from the location closest to the user
  2. The DNS mechanism that directs a delivery destination in response to a name lookup
  3. The intermediate caching layer placed between an edge location and the source of the content
  4. An S3 bucket or HTTP server that holds the source of the content being delivered
AnswerD. An S3 bucket or HTTP server that holds the source of the content being delivered

An origin is the location that holds the source of the content CloudFront delivers, such as an S3 bucket or an HTTP server. When the content requested is not at the edge location, CloudFront fetches it from the origin and delivers it. Returning content from the location closest to the user is the edge location's job, the intermediate caching layer between an edge location and the origin is the Regional Edge Cache, and directing a destination in response to a name lookup is Route 53's DNS routing.

Q10 | Choosing functions

Your company's domain name is already registered with a different registrar. What can you still do with Route 53 in this case?

  1. No function can be used unless the domain is transferred to Route 53
  2. Only the domain registration function is usable; DNS routing cannot be used
  3. Only the health-checking function is usable; DNS routing cannot be used
  4. You can choose and use only the functions you need, such as DNS routing or health checking
AnswerD. You can choose and use only the functions you need, such as DNS routing or health checking

Route 53 is a DNS web service whose three functions — domain registration, DNS routing, and health checking — can be combined in any way you need. It is not a system where all three must be present to function, so you can leave the domain registered elsewhere while entrusting only DNS routing to Route 53, or use only health checking. Transferring the domain is not a prerequisite for using it.

Q11 | ALB's layer

At which OSI layer does an Application Load Balancer operate?

  1. Layer 4 (transport layer)
  2. Layer 7 (application layer)
  3. Layer 3 (network layer)
  4. Layer 2 (data link layer)
AnswerB. Layer 7 (application layer)

ALB operates at Layer 7, the application layer, handling HTTP, HTTPS, and gRPC. Because it looks this deep, it can use the contents of HTTP as a basis for decisions, enabling flexible routing such as content-based routing. NLB operates at Layer 4 (TCP, UDP, TLS), and Gateway Load Balancer operates at Layers 3 and 4 (IP).

Q12 | NLB's protocols

Which combination of protocols can a Network Load Balancer handle?

  1. TCP, UDP, and TLS
  2. IP, HTTP, and HTTPS
  3. HTTP, HTTPS, and gRPC
  4. TCP, TLS, and gRPC
AnswerA. TCP, UDP, and TLS

NLB is a Layer 4 load balancer that handles TCP, UDP, and TLS. It is the choice when you need extremely high performance and a static IP address. Handling HTTP, HTTPS, and gRPC is the Layer 7 ALB's job, and passing IP traffic through transparently without terminating flows is Gateway Load Balancer's job. gRPC is not on NLB's list of supported protocols.

Q13 | GWLB's properties

Which is a characteristic of Gateway Load Balancer?

  1. Terminates TLS, centralizing certificate management on the load balancer's side
  2. Operates at Layers 3 and 4, passing flows through transparently to an appliance without terminating them
  3. Routes requests to different targets by looking at the HTTP path or hostname
  4. Has a static IP address and distributes UDP-based traffic to targets with high performance
AnswerB. Operates at Layers 3 and 4, passing flows through transparently to an appliance without terminating them

GWLB operates at Layers 3 and 4, handling the IP protocol. It is a mechanism for placing appliance-based security or network functions in the traffic path, and the decisive difference from the other two is that it passes flows through transparently without terminating them. Routing by looking at HTTP contents is the Layer 7 ALB's forte, and a static IP with UDP is the Layer 4 NLB's forte.

Q14 | Fixed IP

You need a load balancer with an unchanging IP address so a business partner can register it in their firewall. Which is appropriate?

  1. Classic Load Balancer. It supports SSL/TLS termination
  2. Network Load Balancer. It can be given a static IP address
  3. Gateway Load Balancer. It can pass an appliance through transparently
  4. Application Load Balancer. It can route based on content
AnswerB. Network Load Balancer. It can be given a static IP address

When a static IP address is required, choose NLB. NLB operates at Layer 4 and is officially positioned as suited to scenarios requiring extremely high performance and a static IP. ALB operates at Layer 7, handling HTTP, HTTPS, and gRPC, with content-based routing as its forte. GWLB is for inserting an appliance transparently. Classic Load Balancer is an older generation that supports TCP, SSL/TLS, HTTP, and HTTPS.

Q15 | ELB's role

What is the basic role of Elastic Load Balancing?

  1. Distributes traffic across Regions and also handles domain name registration
  2. Automatically distributes traffic to multiple targets across one or more Availability Zones
  3. Distributes traffic only to targets within a single Availability Zone
  4. Replicates content to edge locations and delivers it to users from the nearest one
AnswerB. Automatically distributes traffic to multiple targets across one or more Availability Zones

ELB automatically distributes incoming application traffic across multiple targets in one or more Availability Zones. It is not confined to a single AZ, and being able to distribute across targets split among multiple AZs is the foundation of availability design. Domain name registration is Route 53's job, and delivery from edge locations is CloudFront's job.

Q16 | gRPC

You want a load balancer to receive traffic that uses gRPC. Which is appropriate?

  1. Classic Load Balancer. It supports both Layer 4 and Layer 7
  2. Application Load Balancer. It can handle gRPC at Layer 7
  3. Gateway Load Balancer. It passes traffic through transparently at Layers 3 and 4
  4. Network Load Balancer. It delivers high performance at Layer 4
AnswerB. Application Load Balancer. It can handle gRPC at Layer 7

The protocols ALB handles are HTTP, HTTPS, and gRPC, and it operates at Layer 7. Of these options, ALB is the only one that can directly handle gRPC. NLB is a Layer 4 load balancer handling TCP, UDP, and TLS, and GWLB is a Layer 3/4 load balancer handling IP. Classic Load Balancer supports TCP, SSL/TLS, HTTP, and HTTPS.

Q17 | Distributing UDP

You want to distribute UDP-based traffic across multiple targets. Which is appropriate?

  1. Application Load Balancer. It is stated to support HTTPS
  2. Classic Load Balancer. It is stated to support SSL/TLS
  3. Gateway Load Balancer. It is stated to pass IP through as is
  4. Network Load Balancer. It is stated to support UDP
AnswerD. Network Load Balancer. It is stated to support UDP

NLB is a Layer 4 load balancer that handles TCP, UDP, and TLS, so it can distribute UDP traffic. What ALB handles is HTTP, HTTPS, and gRPC, which does not include UDP. GWLB handles IP, but it is meant for passing traffic transparently to an appliance, not for general-purpose load balancing. Classic Load Balancer supports TCP, SSL/TLS, HTTP, and HTTPS.

Q18 | Layer lineup

Which combination correctly states the OSI layers at which ALB, NLB, and GWLB operate?

  1. ALB at Layer 4, NLB at Layer 7, GWLB at Layers 3 and 4
  2. ALB at Layers 3 and 4, NLB at Layer 7, GWLB at Layer 4
  3. ALB at Layer 7, NLB at Layer 4, GWLB at Layers 3 and 4
  4. ALB at Layer 7, NLB at Layers 3 and 4, GWLB at Layer 4
AnswerC. ALB at Layer 7, NLB at Layer 4, GWLB at Layers 3 and 4

ALB handles HTTP, HTTPS, and gRPC at Layer 7; NLB handles TCP, UDP, and TLS at Layer 4; and GWLB handles IP at Layers 3 and 4. It helps to remember the lineup by thinking that the higher the layer number, the more high-level information is visible for routing decisions. GWLB alone spans two layers because of its nature of passing IP packets through transparently as is.

Q19 | Path-based routing

You want to change where a request is sent based on the URL path. Which load balancer is appropriate, and why?

  1. Classic Load Balancer, because it is built to terminate both TCP and HTTP
  2. Application Load Balancer, because it can see the contents of HTTP at Layer 7
  3. Gateway Load Balancer, because it can pass IP through transparently at Layers 3 and 4
  4. Network Load Balancer, because it can process TCP at Layer 4 with high speed
AnswerB. Application Load Balancer, because it can see the contents of HTTP at Layer 7

Routing based on the contents of HTTP, such as the path or hostname, is called content-based routing and is the forte of ALB, which operates at Layer 7. NLB operates at Layer 4, so it does not see the contents of HTTP. GWLB passes flows through without terminating them, so the only thing available for routing decisions is IP. Classic Load Balancer is also an older-generation design; ALB is the choice for this purpose.

Q20 | Inspection appliance

You want to place a third-party security inspection appliance in the traffic path and pass everything through it. Which is appropriate?

  1. Network Load Balancer. It offers high performance and a static IP at Layer 4
  2. Amazon CloudFront. It checks content at the edge location before delivering it
  3. Gateway Load Balancer. It can pass flows through transparently without terminating them
  4. Application Load Balancer. It can inspect requests at Layer 7
AnswerC. Gateway Load Balancer. It can pass flows through transparently without terminating them

GWLB operates at Layers 3 and 4, handling the IP protocol, and is a load balancer designed for appliance-based security or network functions. Because it passes flows through transparently without terminating them, inserting an inspection appliance in the middle does not change how the traffic looks. ALB and NLB are designed to receive traffic themselves and distribute it, not to pass it through transparently. CloudFront is a content delivery service.

Q21 | What IAM covers

What does AWS Identity and Access Management manage?

  1. Creating keys used for data encryption and signing, and controlling their use
  2. Monitoring HTTP requests arriving at a web application and controlling access
  3. Access control over resources: who is authenticated and who is authorized
  4. Storing database credentials and API keys, and rotating them
AnswerC. Access control over resources: who is authenticated and who is authorized

IAM is a service that securely controls access to AWS resources, managing who is authenticated (signed in) and who is authorized (holds permissions). Creating and controlling keys is KMS's job, monitoring and controlling HTTP requests is WAF's job, and storing and rotating credentials and API keys is Secrets Manager's job. The roles do not overlap.

Q22 | Authentication and authorization

Which correctly describes authentication and authorization as handled by IAM?

  1. Authentication decides whether you can sign in; authorization decides whether you hold permissions
  2. Both authentication and authorization turn permission strength into numbers for comparison
  3. Authentication decides whether you hold permissions; authorization decides whether you can sign in
  4. Both authentication and authorization check, in two steps, whether you can sign in
AnswerA. Authentication decides whether you can sign in; authorization decides whether you hold permissions

IAM is a service that manages "who is authenticated (signed in) and who is authorized (holds permissions)." Authentication is the step of confirming you are who you say you are, and authorization is the subsequent step that decides what you are allowed to do — they differ both in order and in role. Even if you can sign in, you cannot perform an operation not permitted by policy. Swapping the two when memorizing them leads to misreading permission design.

Q23 | KMS keys

Which correctly describes how a KMS key in AWS Key Management Service is handled?

  1. It is protected by a certified HSM and never leaves KMS unencrypted
  2. Each time it is rotated, the new key value is notified to the customer in plaintext
  3. The customer can export it in plaintext to a location of their choosing for storage
  4. It is designed to be embedded in an application's configuration file for distribution
AnswerA. It is protected by a certified HSM and never leaves KMS unencrypted

KMS is a managed service that makes it easy to create and control keys used for encryption and signing, and a KMS key is protected by an HSM certified to FIPS 140-3 Security Level 3. The key never leaves KMS in an unencrypted state. So exporting or distributing it in plaintext is not something that can be done; instead, encryption and decryption operations are requested from KMS.

Q24 | WAF actions

Which combination of actions can AWS WAF take on a request?

  1. Log, notify, aggregate, display on a dashboard
  2. Encrypt, decrypt, sign, rotate keys
  3. Allow, block, count, CAPTCHA
  4. Register domain, resolve name, transfer, monitor
AnswerC. Allow, block, count, CAPTCHA

WAF monitors HTTP and HTTPS requests forwarded to a protected web application resource and controls access using actions such as allow, block, count, and CAPTCHA or challenge. Because there is a count action, you can measure the impact before turning a rule into a full block, rather than blocking immediately. Encryption and signing belong to KMS, logging and visualization to CloudWatch, and domain registration and name resolution to Route 53.

Q25 | Shield tiers

Which correctly describes the difference between AWS Shield Standard and Advanced?

  1. Neither Standard nor Advanced costs extra, differing only in geographic coverage
  2. Standard is automatically included at no extra cost, and Advanced is extended protection for an extra fee
  3. Standard is extended protection for an extra fee, and Advanced is automatically included at no extra cost
  4. Both Standard and Advanced require an extra fee, differing only in contract length
AnswerB. Standard is automatically included at no extra cost, and Advanced is extended protection for an extra fee

Shield provides protection against DDoS attacks. Standard is basic protection automatically included at no extra cost with things like AWS WAF, and Advanced is extended protection available for an additional fee. Advanced provides automatic mitigation of Layer 7 DDoS attacks, detailed visibility, and dedicated support from the Shield Response Team (SRT). Watch out for an answer choice that reverses which one costs extra.

Q26 | SRT

Which is available with AWS Shield Advanced?

  1. A rotation feature that periodically swaps out database credentials
  2. A mechanism for centrally managing protection settings across multiple accounts
  3. Dedicated support and detailed visibility from the Shield Response Team
  4. A user directory responsible for customer sign-in and token issuance
AnswerC. Dedicated support and detailed visibility from the Shield Response Team

Shield Advanced is extended protection for an extra fee, providing automatic mitigation of Layer 7 DDoS attacks, detailed visibility, and dedicated support from the Shield Response Team (SRT). Rotation is Secrets Manager's job, centrally managing protection across multiple accounts is AWS Firewall Manager's job, and a user directory with token issuance is Amazon Cognito's user pools.

Q27 | Managing secrets

Which is the role of AWS Secrets Manager?

  1. Records changes in resource configuration and evaluates compliance against rules
  2. Accepts customer sign-ins and issues tokens for applications
  3. Manages, retrieves, and rotates database credentials and API keys
  4. Creates encryption keys themselves and lets them be used while protected inside an HSM
AnswerC. Manages, retrieves, and rotates database credentials and API keys

Secrets Manager is a service that manages, retrieves, and rotates secrets — such as database credentials, application credentials, OAuth tokens, and API keys — across their entire lifecycle. Sign-in and token issuance is Cognito's job, recording configuration and evaluating compliance is AWS Config's job, and creating and protecting the keys themselves is KMS's job. It helps to remember Secrets Manager as the one that carries values around.

Q28 | Two pools

Which correctly describes Amazon Cognito user pools and identity pools?

  1. User pools issue temporary AWS credentials, and identity pools issue tokens
  2. User pools are a user directory, and identity pools issue AWS credentials
  3. User pools decide permissions on AWS resources, and identity pools decide whether sign-in is allowed
  4. User pools and identity pools must always be used as a pair; neither can be used alone
AnswerB. User pools are a user directory, and identity pools issue AWS credentials

A user pool is a user directory that authenticates and authorizes users for apps and APIs, functioning as an independent OIDC identity provider that issues OAuth 2.0 tokens and JWTs. An identity pool grants authenticated or unauthenticated users access to AWS resources, issuing temporary AWS credentials via AWS STS. Integrating the two is not mandatory for either; each can be used on its own.

Q29 | Temporary keys

You want to give a mobile app's users temporary credentials for accessing AWS resources. Which is appropriate?

  1. Use a Cognito identity pool to issue temporary credentials via AWS STS
  2. Create one IAM user per user and assign a policy to each
  3. Pass the JWT issued by a Cognito user pool directly as the credential
  4. Distribute long-term credentials stored in Secrets Manager to each user
AnswerA. Use a Cognito identity pool to issue temporary credentials via AWS STS

An identity pool is a mechanism that grants authenticated or unauthenticated users access to AWS resources, issuing temporary AWS credentials via AWS STS. What a user pool issues is OAuth 2.0 tokens and JWTs, which are not credentials for calling AWS APIs directly. Distributing long-term credentials, or creating an IAM user per user, is not suited to this purpose.

Q30 | Central management

Which is the role of AWS Firewall Manager?

  1. Individually inspects requests to a web application within a single account
  2. Consolidates customer sign-in information into one place across accounts
  3. Centrally manages protection settings across multiple accounts and resources
  4. Creates an encryption key for each account and keeps a log of its use
AnswerC. Centrally manages protection settings across multiple accounts and resources

Firewall Manager is a service that centrally manages protections — such as AWS WAF, Shield Advanced, VPC security groups and network ACLs, Network Firewall, and Route 53 Resolver DNS Firewall — across multiple accounts and resources. Inspecting individual requests is WAF's own job, creating keys is KMS's job, and handling sign-in information is Cognito's job.

Q31 | What CloudWatch covers

What does Amazon CloudWatch primarily handle?

  1. Real-time monitoring of resource performance and state
  2. Resource configuration and its history of changes
  3. A record of who performed which API operation
  4. Building resources based on templates
AnswerA. Real-time monitoring of resource performance and state

CloudWatch monitors AWS resources and the applications running on them in real time, visualizing performance, operational status, and resource utilization through metrics, logs, alarms, and dashboards. Recording who performed which API operation is CloudTrail's job, recording configuration and its changes is AWS Config's job, and building resources from templates is CloudFormation's job.

Q32 | Who did it

You want to find out who changed a resource's configuration last month. What would you use?

  1. Run Command in AWS Systems Manager
  2. Amazon CloudWatch metrics and alarms
  3. The list of AWS CloudFormation stacks
  4. Events recorded in AWS CloudTrail
AnswerD. Events recorded in AWS CloudTrail

CloudTrail records the actions taken by users, roles, and AWS services as events. It covers operations through the management console, CLI, and SDK or API, letting you trace afterward who performed which API operation. CloudWatch handles performance and status monitoring, CloudFormation handles building from templates, and Systems Manager handles operational tasks on nodes — none of them is aimed at tracing who performed an action.

Q33 | Config

Which correctly describes AWS Config?

  1. Collects resource metrics and issues notifications when a threshold is exceeded
  2. Lets you write resource creation into a template, build it all at once, and delete it too
  3. Records which user operated on a resource and what that operation was
  4. Records resource configuration and relationships and evaluates compliance against rules
AnswerD. Records resource configuration and relationships and evaluates compliance against rules

Config provides a detailed view of resource configuration, recording relationships between resources and how they were configured in the past so configuration changes can be tracked. It also evaluates configuration with Config rules, flagging non-compliant resources that violate them. Monitoring thresholds is CloudWatch's job, building from templates is CloudFormation's job, and recording operations is CloudTrail's job.

Q34 | Three distinctions

Which combination correctly matches the roles of CloudWatch, CloudTrail, and AWS Config?

  1. CloudWatch records operations, CloudTrail records configuration, Config monitors performance
  2. CloudWatch monitors performance, CloudTrail records operations, Config records configuration
  3. CloudWatch monitors performance, CloudTrail records configuration, Config records operations
  4. CloudWatch records configuration, CloudTrail monitors performance, Config records operations
AnswerB. CloudWatch monitors performance, CloudTrail records operations, Config records configuration

It helps to memorize the three together: CloudWatch is real-time monitoring of performance and status, CloudTrail is a record of who performed which API operation, and Config is a record of resource configuration and an evaluation of compliance. They are not competing services — a CloudTrail trail is stored in an S3 bucket and can optionally also be delivered to CloudWatch Logs, making CloudTrail the sender and CloudWatch Logs a possible receiving end.

Q35 | IaC building blocks

Which correctly describes the relationship between an AWS CloudFormation template and a stack?

  1. A template is a group of built resources, and a stack is the design that produced them
  2. A template is a document describing the resources needed, and a stack is the group of resources created
  3. A template is an execution log of a build, and a stack is the procedure for replaying it
  4. Both a template and a stack are monthly reports aggregating resource usage
AnswerB. A template is a document describing the resources needed, and a stack is the group of resources created

In CloudFormation, you create a template, a text file describing the resources you need, and CloudFormation provisions and configures the resources accordingly. The resources created can be managed together as a single unit called a stack, and can also be deleted together. So a template corresponds to a blueprint, and a stack corresponds to the resulting group of resources.

Q36 | Stack

Which correctly describes a CloudFormation stack?

  1. Deleting a stack leaves the resources created from the template still in place
  2. Resources created from a template can only be deleted one at a time individually
  3. It records the content of a template over time as a history of configuration changes
  4. A group of resources created from a template can be handled together as a single unit
AnswerD. A group of resources created from a template can be handled together as a single unit

The group of resources CloudFormation creates can be managed as a single unit called a stack, and it can also be deleted all at once. It is not the case that resources can only be handled individually; deleting the stack deletes the resources it contains together with it. Recording configuration changes over time is AWS Config's role. Being able to build as a group and tear down as a group is a benefit of treating infrastructure as code.

Q37 | Where SSM fits

Where is AWS Systems Manager positioned?

  1. A unified entry point for managing AWS and on-premises nodes centrally at scale
  2. A mechanism that records changes to resource configuration and surfaces non-compliant resources
  3. A mechanism that automatically distributes incoming traffic across multiple targets
  4. A mechanism that reads a template and builds resources all at once
AnswerA. A unified entry point for managing AWS and on-premises nodes centrally at scale

Systems Manager is a unified interface for viewing, managing, and operating nodes across AWS, on-premises, and multi-cloud environments centrally at scale, including capabilities such as Run Command, Session Manager, Automation, Parameter Store, Patch Manager, and Fleet Manager. Recording configuration is Config's job, building from templates is CloudFormation's job, and distributing traffic is ELB's job.

Q38 | Spot

Which is a characteristic of EC2 Spot Instances?

  1. They use unused capacity in the AWS Cloud and can be interrupted
  2. They receive a discount in exchange for a 1-year or 3-year usage commitment
  3. They have no upfront payment or commitment and are billed per hour or per second
  4. They receive a discount in exchange for committing to fixed instance attributes
AnswerA. They use unused capacity in the AWS Cloud and can be interrupted

Spot Instances are a purchasing option that uses unused EC2 capacity in the AWS Cloud, offering a substantial discount but with the possibility of interruption. They suit batch processing or test environments that can tolerate interruption. Committing to usage is Savings Plans, committing to instance attributes is a Reserved Instance, and having no upfront payment or commitment is On-Demand.

Q39 | Savings Plans vs. Reserved Instances

Which correctly describes the difference between Savings Plans and Reserved Instances?

  1. Savings Plans terms are only 1 year, while Reserved Instances are only 3 years
  2. Savings Plans can be interrupted, while Reserved Instances cannot
  3. Savings Plans commit to a usage level, while Reserved Instances commit to instance attributes
  4. Savings Plans require upfront payment, while Reserved Instances cannot be paid upfront
AnswerC. Savings Plans commit to a usage level, while Reserved Instances commit to instance attributes

Savings Plans is a pricing model that gives a discount in exchange for committing to a set usage level, while a Reserved Instance is a pricing model that gives a discount in exchange for committing to attributes such as instance type, platform, and tenancy. Both have terms of 1 year or 3 years, and payment can be chosen as all upfront, partial upfront, or no upfront. It is Spot Instances that can be interrupted.

Q40 | Types of Savings Plans

Which correctly describes the difference between Compute Savings Plans and EC2 Instance Savings Plans?

  1. Compute allows only no-upfront payment, and EC2 Instance allows only all-upfront payment
  2. Compute has only a 1-year term, and EC2 Instance is limited to only 3 years
  3. Compute can span both family and Region, but EC2 Instance cannot
  4. Compute fixes the instance family, and EC2 Instance fixes the Region
AnswerC. Compute can span both family and Region, but EC2 Instance cannot

Compute Savings Plans are the most flexible, supporting changes in instance family, changes in Region, moving between EC2, Fargate, and Lambda, and changes of OS. EC2 Instance Savings Plans commit to a specific instance family in a specific Region, so while size changes within the family and OS changes are possible, changing family or Region is not. The term for both is 1 year or 3 years, and payment can be chosen as all upfront, partial upfront, or no upfront.

Practice: answer the questions on this page

This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.

* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.

This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original