Architecting On AWS Certification Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Architecting On AWS Certification flashcards as text
A company wants to migrate its on-premises data warehouse to AWS with minimal code changes. Which service is the BEST choice?
Answer: Amazon Redshift
Amazon Redshift is a fully managed petabyte-scale data warehouse that supports standard SQL and minimizes code changes from on-premises data warehouses.
Which VPC feature allows instances in a private subnet to initiate outbound internet traffic without exposing them to inbound connections?
Answer: NAT Gateway
A NAT Gateway allows private subnet instances to reach the internet for outbound traffic while blocking unsolicited inbound connections.
An architect is designing a solution where Lambda functions need to access an RDS database securely without hardcoding credentials. Which approach is BEST?
Answer: Use AWS Secrets Manager with automatic rotation
AWS Secrets Manager stores and automatically rotates database credentials, which Lambda retrieves at runtime via API without hardcoding.
A global application requires low-latency content delivery for static and dynamic content. Which architecture BEST achieves this?
Answer: Use Amazon CloudFront with an Application Load Balancer as origin
CloudFront caches static content at edge locations globally and forwards dynamic requests to the ALB origin with low latency.
Which AWS service provides a managed message broker that supports both AMQP and MQTT protocols for existing applications?
Answer: Amazon MQ
Amazon MQ is a managed message broker service for ActiveMQ and RabbitMQ that supports industry-standard protocols like AMQP, MQTT, and STOMP.
A company needs to replicate data between two VPCs in different AWS accounts with high bandwidth and low latency. What is the RECOMMENDED approach?
Answer: VPC Peering
VPC Peering provides private, high-bandwidth, low-latency connectivity between VPCs across accounts without traversing the public internet.
What does the AWS Shared Responsibility Model state is the customer's responsibility when using Amazon RDS?
Answer: Configuring security groups and managing database user access
AWS manages the database engine patching and hardware, while customers are responsible for network access controls and database-level user permissions.