AWS的SysOps认证考试样题解析
刚考过了AWS的developer认证,顺手做了一下SysOps的样题。以下是题目和答案。
When working with Amazon RDS, by default AWS is responsible for implementing which two
management-related activities? (Pick 2 correct answers)
A. Importing data and optimizing queries
B. Installing and periodically patching the database software
C. Creating and maintaining automated database backups with a point-in-time recovery of up to five minutes
D. Creating and maintaining automated database backups in compliance with regulatory long-term retention
requirements
答案:B C
参考文档:http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_UpgradeDBInstance.html
You maintain an application on AWS to provide development and test platforms for your developers.
Currently both environments consist of an m1.small EC2 instance. Your developers notice performance
degradation as they increase network load in the test environment.
How would you mitigate these performance issues in the test environment?
A. Upgrade the m1.small to a larger instance type
B. Add an additional ENI to the test instance
C. Use the EBS optimized option to offload EBS traffic
D. Configure Amazon Cloudwatch to provision more network bandwidth when network utilization
exceeds 80%
答案:A
解析:添加ENI并不会增加带宽;m1.small机器类型没有EBS optimized option;network utilisation与机器类型相关,无法对m1.small provision更多的带宽
Per the AWS Acceptable Use Policy, penetration testing of EC2 instances:
A. may be performed by the customer against their own instances, only if performed from EC2
instances.
B. may be performed by AWS, and is periodically performed by AWS.
C. may be performed by AWS, and will be performed by AWS upon customer request.
D. are expressly prohibited under all circumstances.
E. may be performed by the customer against their own instances with prior authorization from AWS.
答案:E
参考文档:https://aws.amazon.com/security/penetration-testing/
You have been tasked with identifying an appropriate storage solution for a NoSQL database that
requires random I/O reads of greater than 100,000 4kB IOPS.
Which EC2 option will meet this requirement?
A. EBS provisioned IOPS
B. SSD instance store
C. EBS optimized instances
D. High Storage instance configured in RAID 10
答案:B
解析:这道题只有SSD instance store能提供10万的IOPS
Instance A and instance B are running in two different subnets A and B of a VPC. Instance A is not able to
ping instance B.
What are two possible reasons for this? (Pick 2 correct answers)
A. The routing table of subnet A has no target route to subnet B
B. The security group attached to instance B does not allow inbound ICMP traffic
C. The policy linked to the IAM role on instance A is not configured correctly
D. The NACL on subnet B does not allow outbound ICMP traffic
答案:B D
解析:同一个VPC下的所有subnet默认可以相互连接,所以A不对;ping连接不需要什么AWS权限,所以C也不对。而控制机器访问有两层,一层是给subnet指定的ACL,另一层是给机器指定的SG。
Your web site is hosted on 10 EC2 instances in 5 regions around the globe with 2 instances per region.
How could you configure your site to maintain site availability with minimum downtime if one of the 5
regions was to lose network connectivity for an extended period of time?
A. Create an Elastic Load Balancer to place in front of the EC2 instances. Set an appropriate health
check on each ELB.
B. Establish VPN Connections between the instances in each region. Rely on BGP to failover in the
case of a region wide connectivity outage
C. Create a Route 53 Latency Based Routing Record Set that resolves to an Elastic Load Balancer in
each region. Set an appropriate health check on each ELB.
D. Create a Route 53 Latency Based Routing Record Set that resolves to Elastic Load Balancers in
each region and has the Evaluate Target Health flag set to true.
答案:D
参考文档:http://docs.aws.amazon.com/Route53/latest/DeveloperGuide/dns-failover-complex-configs.html
解析:只有开启了Evaluate Target Health flag,Route53才会根据健康情况进行路由
You run a stateless web application with the following components: Elastic Load Balancer (ELB), 3
Web/Application servers on EC2, and 1 MySQL RDS database with 5000 Provisioned IOPS. Average
response time for users is increasing. Looking at CloudWatch, you observe 95% CPU usage on the
Web/Application servers and 20% CPU usage on the database. The average number of database disk
operations varies between 2000 and 2500.
Which two options could improve response times? (Pick 2 correct answers)
A. Choose a different EC2 instance type for the Web/Application servers with a more appropriate
CPU/memory ratio
B. Use Auto Scaling to add additional Web/Application servers based on a CPU load threshold
C. Increase the number of open TCP connections allowed per web/application EC2 instance
D. Use Auto Scaling to add additional Web/Application servers based on a memory usage threshold
答案:A B
解析:这里是application机器CPU过载,解决方式是要不加强application机器性能,要不增加更多的application机器,C没有用,D是基于内存门槛,所以都不对
Which features can be used to restrict access to data in S3? (Pick 2 correct answers)
A. Create a CloudFront distribution for the bucket.
B. Set an S3 bucket policy.
C. Use S3 Virtual Hosting.
D. Set an S3 ACL on the bucket or the object.
E. Enable IAM Identity Federation.
答案:B D
参考文档:http://docs.aws.amazon.com/AmazonS3/latest/dev/using-iam-policies.html
http://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html
You need to establish a backup and archiving strategy for your company using AWS. Documents should
be immediately accessible for 3 months and available for 5 years for compliance reasons.
Which AWS service fulfills these requirements in the most cost effective way?
A. Use StorageGateway to store data to S3 and use life-cycle policies to move the data into Redshift for
long-time archiving
B. Use DirectConnect to upload data to S3 and use IAM policies to move the data into Glacier for longtime
archiving
C. Upload the data on EBS, use life-cycle policies to move EBS snapshots into S3 and later into Glacier
for long-time archiving
D. Upload data to S3 and use life-cycle policies to move the data into Glacier for long-time archiving
答案:D
参考文档:http://docs.aws.amazon.com/AmazonS3/latest/dev/object-lifecycle-mgmt.html
解析:S3可以存放经常使用的文档,然后存档文件可以使用life-cycle policies放置到Glacier上
Given the following IAM policy:
1 |
|
What does the IAM policy allow? (Pick 3 correct answers)
A. The user is allowed to read objects from all S3 buckets owned by the account
B. The user is allowed to write objects into the bucket named ‘corporate_bucket’
C. The user is allowed to change access rights for the bucket named ‘corporate_bucket’
D. The user is allowed to read objects in the bucket named ‘corporate_bucket’ but not allowed to list the objects
in the bucket
E. The user is allowed to read objects from the bucket named ‘corporate_bucket’
答案:A B E
解析:AWS的权限认证遵循最小化原则。即:默认情况都是deny的;显式allow会覆盖默认deny;显式deny会覆盖显式allow。
AWS的SysOps认证考试样题解析的更多相关文章
- AWS开发人员认证考试样题解析
最近在准备AWS的开发人员考试认证.所以特意做了一下考试样题.每道题尽量给出了文档出处以及解析. Which of the following statements about SQS is true ...
- 1+X Web前端开发(中级)理论考试样题(附答案)
传送门 教育部:职业教育将启动"1+X"证书制度改革 职业教育改革1+X证书制度试点启动 1+X成绩/证书查询入口 一.单选题(每小题2分,共30小题,共 60 分) 1.在Boo ...
- JS-常考算法题解析
常考算法题解析 这一章节依托于上一章节的内容,毕竟了解了数据结构我们才能写出更好的算法. 对于大部分公司的面试来说,排序的内容已经足以应付了,由此为了更好的符合大众需求,排序的内容是最多的.当然如果你 ...
- 《Web前端开发》等级考试样题~以国家“1+X”职业技能证书为标准,厚溥推出Web前端开发人才培养方案
1+x证书Web前端开发初级理论考试样题2019 http://blog.zh66.club/index.php/archives/149/ 1+x证书Web前端开发初级实操考试样题2019 http ...
- 1+x证书《Web前端开发》等级考试样题
Web前端开发初级理论考试样题2019 http://blog.zh66.club/index.php/archives/149/ Web前端开发初级实操考试样题2019 http://blog.zh ...
- 1+X Web前端开发(初级)理论考试样题(附答案)
传送门 教育部:职业教育将启动"1+X"证书制度改革 职业教育改革1+X证书制度试点启动 1+X成绩/证书查询入口 一.单选题(每题 2 分,共 60 分) 1.在 HTML 中, ...
- AWS助理架构师样题解析
AWS 认证是对其在 AWS 平台上设计.部署和管理应用程序所需的技能和技术知识的一种认可.获得证书有助于证明您使用 AWS 的丰富经验和可信度,同时还能提升您所在的组织熟练使用基于 AWS 云服务应 ...
- AWS助理架构师认证考经
上周考了亚马逊的解决方案架构师-助理级别的认证考试并顺利通过.这也算是对自己AWS服务熟悉程度的一种检验.在准备考试的过程中,把自己学习到的AWS知识都梳理了一遍,也算是收获颇丰.这次特意分享了该认证 ...
- 《PHP程序员面试笔试真题解析》——新书上线
你好,是我--琉忆.很高兴可以跟你分享我的新书. 很高兴,在出版了PHP程序员面试笔试宝典后迎来了我的第二本书出版--<PHP程序员面试笔试真题解析>. 如果你是一个热爱PHP的程序员,刚 ...
随机推荐
- javascript动画系列第三篇——碰撞检测
前面的话 前面分别介绍了拖拽模拟和磁性吸附,当可视区域内存在多个可拖拽元素,就出现碰撞检测的问题,这也是javascript动画的一个经典问题.本篇将详细介绍碰撞检测 原理介绍 碰撞检测的方法有很多, ...
- RPC 使用中的一些注意点
最近线上碰到一点小问题,分析其原因发现是出在对 RPC 使用上的一些细节掌握不够清晰导致.很多时候我们做业务开发会把 RPC 当作黑盒机制来使用,但若不对黑盒的工作原理有个基本掌握,也容易犯一些误用的 ...
- Python高手之路【五】python基础之正则表达式
下图列出了Python支持的正则表达式元字符和语法: 字符点:匹配任意一个字符 import re st = 'python' result = re.findall('p.t',st) print( ...
- PhotoView实现图片随手势的放大缩小的效果
项目需求:在listView的条目中如果有图片,点击条目,实现图片的放大,并且图片可以根据手势来控制图片放大缩小的比例.类似于微信朋友圈中查看好友发布的照片所实现的效果. 思路是这样的:当点击条目的时 ...
- vmware上网的方式
vmware上网设置 vmware虚拟机上网设置 我的一些心得,如下: 如何使vmware虚拟机中的操作系统能够上网? 第一种情况: 主机使用PPPOE拨号上网 方法一:NAT方式 1.先关闭虚拟机中 ...
- Python 正则表达式入门(中级篇)
Python 正则表达式入门(中级篇) 初级篇链接:http://www.cnblogs.com/chuxiuhong/p/5885073.html 上一篇我们说在这一篇里,我们会介绍子表达式,向前向 ...
- 如何使用swing创建一个BeatBox
首先,我们需要回顾一些内容(2017-01-04 14:32:14): 1.Swing组件 Swing的组件(component,或者称之为元件),是较widget更为正确的术语,它们就是会放在GUI ...
- 【算法】(查找你附近的人) GeoHash核心原理解析及代码实现
本文地址 原文地址 分享提纲: 0. 引子 1. 感性认识GeoHash 2. GeoHash算法的步骤 3. GeoHash Base32编码长度与精度 4. GeoHash算法 5. 使用注意点( ...
- nginx启动报错:/usr/local/nginx/sbin/nginx: error while loading shared libraries: libcrypto.so.1.1: cannot open shared object file: No such file or directory
查看依赖库:
- Fedora 22中的Locale and Keyboard Configuration
Introduction The system locale specifies the language settings of system services and user interface ...