SAA-C03 #3 Comprehensive
Questions (Frequently Tested) with
Verified Answers Graded A+
Professional Academic Assistance Services
Services Offered
• Proctored Exam Assistance
• Online Class Management (Full Course Support)
• Exam Preparation & Study Materials
• Assignments and Coursework Support
• Essay and Research Paper Writing
• Discussion Posts & Responses
• Editing and Proofreading
• Confidential Academic Consultation
Helping Students Achieve Academic Excellence
You currently manage a set of web servers hosted on EC2 Servers with
public IP addresses. These IP addresses are mapped to domain names.
There was an urgent maintenance activity that had to be carried out on
the servers and the servers had to be restarted. Now the web
application hosted on these EC2 Instances is not accessible via the
domain names configured earlier.
,Which of the following could be a reason for this?
The Route53 hosted zone needs to be restarted.
The network interfaces need to initialized again.
The public IP addresses need to associated to the ENI again.
The public IP addresses have changed after the instance was stopped
and started - Answer: The public IP addresses have changed after the
instance was stopped and started
You are responsible to deploying a critical application onto AWS. Part of
the requirements for this application is to ensure that the controls set
for this application met PCI compliance. Also there is a need to monitor
web application logs to identify any malicious activity.
Which of the following services can be used to fulfil this requirement?
(Select 2)
Amazon Cloudwatch Logs
Amazon VPC Flow Logs
,Amazon AWS Config
Amazon Cloudtrail - Answer: Amazon Cloudwatch Logs
Amazon Cloudtrail
There is a requirement to host a database server. This server should not
be able to connect to the internet except in the case of downloading
the required database patches. Which of the following solutions would
be the best to satisfy all the above requirements?
Set up the database in a private subnet with a security group which
only
allows outbound traffic.
Set up the database in a public subnet with a security group which only
allows inbound traffic.
Set up the database in a local data center and use a private gateway to
connect the application to the database.
Set up the database in a private subnet which connects to the Internet
via a NAT instance. - Answer: Set up the database in a private subnet
which connects to the Internet via a NAT instance.
, You have instances running on your VPC. You have both production and
development based instances running in the VPC. You want to ensure
that people who are responsible for the development instances don't
have the access to work on the production instances to ensure better
security.
Using policies, which of the following would be the best way to
accomplish this?
Launch the test and production instances in separate VPC's and use VPC
peering
Create an IAM policy with a condition which allows access to only
instances that are used for production or development
Launch the test and production instances in different Availability Zones
and use Multi Factor Authentication
Define the tags on the test and production servers and add a condition
to the IAM policy which allows access to specific tags - Answer: Define
the tags on the test and production servers and add a condition to the
IAM policy which allows access to specific tags
Questions (Frequently Tested) with
Verified Answers Graded A+
Professional Academic Assistance Services
Services Offered
• Proctored Exam Assistance
• Online Class Management (Full Course Support)
• Exam Preparation & Study Materials
• Assignments and Coursework Support
• Essay and Research Paper Writing
• Discussion Posts & Responses
• Editing and Proofreading
• Confidential Academic Consultation
Helping Students Achieve Academic Excellence
You currently manage a set of web servers hosted on EC2 Servers with
public IP addresses. These IP addresses are mapped to domain names.
There was an urgent maintenance activity that had to be carried out on
the servers and the servers had to be restarted. Now the web
application hosted on these EC2 Instances is not accessible via the
domain names configured earlier.
,Which of the following could be a reason for this?
The Route53 hosted zone needs to be restarted.
The network interfaces need to initialized again.
The public IP addresses need to associated to the ENI again.
The public IP addresses have changed after the instance was stopped
and started - Answer: The public IP addresses have changed after the
instance was stopped and started
You are responsible to deploying a critical application onto AWS. Part of
the requirements for this application is to ensure that the controls set
for this application met PCI compliance. Also there is a need to monitor
web application logs to identify any malicious activity.
Which of the following services can be used to fulfil this requirement?
(Select 2)
Amazon Cloudwatch Logs
Amazon VPC Flow Logs
,Amazon AWS Config
Amazon Cloudtrail - Answer: Amazon Cloudwatch Logs
Amazon Cloudtrail
There is a requirement to host a database server. This server should not
be able to connect to the internet except in the case of downloading
the required database patches. Which of the following solutions would
be the best to satisfy all the above requirements?
Set up the database in a private subnet with a security group which
only
allows outbound traffic.
Set up the database in a public subnet with a security group which only
allows inbound traffic.
Set up the database in a local data center and use a private gateway to
connect the application to the database.
Set up the database in a private subnet which connects to the Internet
via a NAT instance. - Answer: Set up the database in a private subnet
which connects to the Internet via a NAT instance.
, You have instances running on your VPC. You have both production and
development based instances running in the VPC. You want to ensure
that people who are responsible for the development instances don't
have the access to work on the production instances to ensure better
security.
Using policies, which of the following would be the best way to
accomplish this?
Launch the test and production instances in separate VPC's and use VPC
peering
Create an IAM policy with a condition which allows access to only
instances that are used for production or development
Launch the test and production instances in different Availability Zones
and use Multi Factor Authentication
Define the tags on the test and production servers and add a condition
to the IAM policy which allows access to specific tags - Answer: Define
the tags on the test and production servers and add a condition to the
IAM policy which allows access to specific tags