Cloud Infrastructure Flashcards
7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cloud Infrastructure flashcards as text
When a cloud VM instance is terminated, which storage type loses its data by default?
Answer: Instance store (ephemeral storage)
Instance store volumes are physically attached to the host and are ephemeral — their data is lost when the instance stops or terminates.
What does RPO (Recovery Point Objective) measure in a cloud disaster recovery plan?
Answer: The maximum tolerable data loss measured in time
RPO defines how much data loss (measured as time) is acceptable; a 1-hour RPO means up to 1 hour of data may be lost in a disaster.
Which cloud security service continuously monitors AWS accounts and workloads for malicious activity and unauthorized behavior?
Answer: AWS GuardDuty
AWS GuardDuty is a threat detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs to identify threats.
A serverless function (e.g., AWS Lambda) has a maximum execution timeout. What happens when the function exceeds this limit?
Answer: The function is forcibly terminated and an error is returned
Serverless platforms enforce a hard execution timeout; once exceeded, the function invocation is killed and a timeout error is returned to the caller.
Which DNS record type maps a domain name to an IPv4 address?
Answer: A
An 'A' record (Address record) maps a hostname directly to a 32-bit IPv4 address.
In cloud cost optimization, what is the trade-off when using Spot/Preemptible instances instead of On-Demand instances?
Answer: Significant cost savings but instances can be reclaimed by the provider with short notice
Spot/Preemptible instances offer up to 90% cost savings over on-demand pricing but can be interrupted by the cloud provider when capacity is needed.
What is the function of a security group in AWS cloud networking?
Answer: Acts as a stateful virtual firewall controlling inbound and outbound traffic at the instance level
Security groups are stateful firewalls that control traffic to and from EC2 instances based on rules for ports, protocols, and IP ranges.