Exams > Amazon > AWS-SysOps: AWS Certified SysOps Administrator
AWS-SysOps: AWS Certified SysOps Administrator
Page 11 out of 91 pages Questions 101-110 out of 910 questions
Question#101

A user has enabled session stickiness with ELB. The user does not want ELB to manage the cookie; instead he wants the application to manage the cookie. What will happen when the server instance, which is bound to a cookie, crashes?

  • A. The response will have a cookie but stickiness will be deleted
  • B. The session will not be sticky until a new cookie is inserted
  • C. ELB will throw an error due to cookie unavailability
  • D. The session will be sticky and ELB will route requests to another server as ELB keeps replicating the Cookie
Discover Answer Hide Answer

B
With Elastic Load Balancer, if the admin has enabled a sticky session with application controlled stickiness, the load balancer uses a special cookie generated by the application to associate the session with the original server which handles the request. ELB follows the lifetime of the application-generated cookie corresponding to the cookie name specified in the ELB policy configuration. The load balancer only inserts a new stickiness cookie if the application response includes a new application cookie. The load balancer stickiness cookie does not update with each request. If the application cookie is explicitly removed or expires, the session stops being sticky until a new application cookie is issued.

Question#102

A user is observing the EC2 CPU utilization metric on CloudWatch. The user has observed some interesting patterns while filtering over the 1 week period for a particular hour. The user wants to zoom that data point to a more granular period. How can the user do that easily with CloudWatch?

  • A. The user can zoom a particular period by selecting that period with the mouse and then releasing the mouse
  • B. The user can zoom a particular period by double clicking on that period with the mouse
  • C. The user can zoom a particular period by specifying the aggregation data for that period
  • D. The user can zoom a particular period by specifying the period in the Time Range
Discover Answer Hide Answer

A

Question#103

A user has created an Auto Scaling group with default configurations from CLI. The user wants to setup the CloudWatch alarm on the EC2 instances, which are launched by the Auto Scaling group. The user has setup an alarm to monitor the CPU utilization every minute. Which of the below mentioned statements is true?

  • A. It will fetch the data at every minute but the four data points [corresponding to 4 minutes] will not have value since the EC2 basic monitoring metrics are collected every five minutes
  • B. It will fetch the data at every minute as detailed monitoring on EC2 will be enabled by the default launch configuration of Auto Scaling
  • C. The alarm creation will fail since the user has not enabled detailed monitoring on the EC2 instances
  • D. The user has to first enable detailed monitoring on the EC2 instances to support alarm monitoring at every minute
Discover Answer Hide Answer

B
CloudWatch is used to monitor AWS as well as the custom services. To enable detailed instance monitoring for a new Auto Scaling group, the user does not need to take any extra steps. When the user creates an Auto Scaling launch config using CLI, each launch configuration contains a flag named
InstanceMonitoring.Enabled. The default value of this flag is true. Thus, by default detailed monitoring will be enabled for Auto Scaling as well as for all the instances launched by that Auto Scaling group.

Question#104

A user has created a VPC with public and private subnets using the VPC wizard. Which of the below mentioned statements is not true in this scenario?

  • A. The VPC will create a routing instance and attach it with a public subnet
  • B. The VPC will create two subnets
  • C. The VPC will create one internet gateway and attach it to VPC
  • D. The VPC will launch one NAT instance with an elastic IP
Discover Answer Hide Answer

A
A user can create a subnet with VPC and launch instances inside that subnet. If the user has created a public private subnet, the instances in the public subnet can receive inbound traffic directly from the internet, whereas the instances in the private subnet cannot. If these subnets are created with Wizard, AWS will create a NAT instance with an elastic IP. Wizard will also create two subnets with route tables. It will also create an internet gateway and attach it to the VPC.

Question#105

A user has configured ELB with a TCP listener at ELB as well as on the back-end instances. The user wants to enable a proxy protocol to capture the source and destination IP information in the header. Which of the below mentioned statements helps the user understand a proxy protocol with TCP configuration?

  • A. If the end user is requesting behind a proxy server then the user should not enable a proxy protocol on ELB
  • B. ELB does not support a proxy protocol when it is listening on both the load balancer and the back-end instances
  • C. Whether the end user is requesting from a proxy server or directly, it does not make a difference for the proxy protocol
  • D. If the end user is requesting behind the proxy, then the user should add the ג€isproxyג€ flag to the ELB Configuration
Discover Answer Hide Answer

A
When the user has configured Transmission Control Protocol (TCP. or Secure Sockets Layer (SSL) for both front-end and back-end connections of the Elastic
Load Balancer, the load balancer forwards the request to the back-end instances without modifying the request headers unless the proxy header is enabled. If the end user is requesting from a Proxy Protocol enabled proxy server, then the ELB admin should not enable the Proxy Protocol on the load balancer. If the Proxy
Protocol is enabled on both the proxy server and the load balancer, the load balancer will add another header to the request which already has a header from the proxy server. This duplication may result in errors.

Question#106

A user has launched 5 instances in EC2-CLASSIC and attached 5 elastic IPs to the five different instances in the US East region. The user is creating a VPC in the same region. The user wants to assign an elastic IP to the VPC instance. How can the user achieve this?

  • A. The user has to request AWS to increase the number of elastic IPs associated with the account
  • B. AWS allows 10 EC2 Classic IPs per region; so it will allow to allocate new Elastic IPs to the same region
  • C. The AWS will not allow to create a new elastic IP in VPC; it will throw an error
  • D. The user can allocate a new IP address in VPC as it has a different limit than EC2
Discover Answer Hide Answer

D
Section: (none)
A Virtual Private Cloud (VPC) is a virtual network dedicated to the user's AWS account. A user can create a subnet with VPC and launch instances inside that subnet. A user can have 5 IP addresses per region with EC2 Classic. The user can have 5 separate IPs with VPC in the same region as it has a separate limit than EC2 Classic.

Question#107

A user has created a subnet in VPC and launched an EC2 instance within it. The user has not selected the option to assign the IP address while launching the instance. Which of the below mentioned statements is true with respect to this scenario?

  • A. The instance will always have a public DNS attached to the instance by default
  • B. The user can directly attach an elastic IP to the instance
  • C. The instance will never launch if the public IP is not assigned
  • D. The user would need to create an Internet gateway and then attach an elastic IP to the instance to connect from internet
Discover Answer Hide Answer

D
A Virtual Private Cloud (VPC) is a virtual network dedicated to the user's AWS account. A user can create a subnet with VPC and launch instances inside that subnet. When the user is launching an instance he needs to select an option which attaches a public IP to the instance. If the user has not selected the option to attach the public IP, then it will only have a private IP when launched. The user cannot connect to the instance from the internet. If the user wants an elastic IP to connect to the instance from the Internet, he should create an internet gateway and assign an elastic IP to instance.

Question#108

An organization has applied the below mentioned policy on an IAM group which has selected the IAM users. What entitlements do the IAM users avail with this policy?

  • A. The policy is not created correctly. It will throw an error for wrong resource name
  • B. The policy is for the group. Thus, the IAM user cannot have any entitlement to this
  • C. It allows full access to all AWS services for the IAM users who are a part of this group
  • D. If this policy is applied to the EC2 resource, the users of the group will have full access to the EC2 Resources
Discover Answer Hide Answer

C
AWS Identity and Access Management is a web service which allows organizations to manage users and user permissions for various AWS services. The IAM group allows the organization to specify permissions for a collection of users. With the below mentioned policy, it will allow the group full access (Admin to all AWS services).

Question#109

A user is configuring a CloudWatch alarm on RDS to receive a notification when the CPU utilization of RDS is higher than 50%. The user has setup an alarm when there is some inactivity on RDS, such as RDS unavailability. How can the user configure this?

  • A. Setup the notification when the CPU is more than 75% on RDS
  • B. Setup the notification when the state is Insufficient Data
  • C. Setup the notification when the CPU utilization is less than 10%
  • D. It is not possible to setup the alarm on RDS
Discover Answer Hide Answer

B
Amazon CloudWatch alarms watch a single metric over a time period that the user specifies and performs one or more actions based on the value of the metric relative to a given threshold over a number of time periods. The alarm has three states: Alarm, OK and Insufficient data. The Alarm will change to Insufficient Data when any of the three situations arise: when the alarm has just started, when the metric is not available or when enough data is not available for the metric to determine the alarm state. If the user wants to find that RDS is not available, he can setup to receive the notification when the state is in Insufficient data.

Question#110

George has shared an EC2 AMI created in the US East region from his AWS account with Stefano. George copies the same AMI to the US West region. Can
Stefano access the copied AMI of George's account from the US West region?

  • A. No, copy AMI does not copy the permission
  • B. It is not possible to share the AMI with a specific account
  • C. Yes, since copy AMI copies all private account sharing permissions
  • D. Yes, since copy AMI copies all the permissions attached with the AMI
Discover Answer Hide Answer

A
Within EC2, when the user copies an AMI, the new AMI is fully independent of the source AMI; there is no link to the original (source) AMI. AWS does not copy launch the permissions, user-defined tags or the Amazon S3 bucket permissions from the source AMI to the new AMI. Thus, in this case by default Stefano will not have access to the AMI in the US West region.

chevron rightPrevious Nextchevron right