AWS CERTIFIED SOLUTIONS ARCHITECT
ASSOCIATE EXAMS SET VERIFIED
QUESTIONS AND ACCURATE ANSWERS
COMPLETE PREPARATION FILE
●● A retail company has its flagship application running on a fleet of
Amazon EC2 instances behind Elastic Load Balancing (ELB). The
engineering team has been seeing recurrent issues wherein the in-flight
requests from the ELB to the Amazon EC2 instances are getting dropped
when an instance becomes unhealthy.
Which of the following features can be used to address this issue?
Answer: A: Connection Draining
Explanation: To ensure that Elastic Load Balancing stops sending
requests to instances that are de-registering or unhealthy while keeping
the existing connections open, use connection draining. This enables the
load balancer to complete in-flight requests made to instances that are
de-registering or unhealthy. The maximum timeout value can be set
between 1 and 3,600 seconds (the default is 300 seconds). When the
maximum time limit is reached, the load balancer forcibly closes
connections to the de-registering instance.
●● A retail organization is moving some of its on-premises data to AWS
Cloud. The DevOps team at the organization has set up an AWS
Managed IPSec VPN Connection between their remote on-premises
network and their Amazon VPC over the internet.
,Which of the following represents the correct configuration for the
IPSec VPN Connection?
Answer: Create a virtual private gateway (VGW) on the AWS side of the
VPN and a Customer Gateway on the on-premises side of the VPN
Amazon VPC provides the facility to create an IPsec VPN connection
(also known as AWS site-to-site VPN) between remote customer
networks and their Amazon VPC over the internet
●● The DevOps team at a multi-national company is helping its
subsidiaries standardize Amazon EC2 instances by using the same
Amazon Machine Image (AMI). Some of these subsidiaries are in the
same AWS region but use different AWS accounts whereas others are in
different AWS regions but use the same AWS account as the parent
company. The DevOps team has hired you as a solutions architect for
this project.
Which of the following would you identify as CORRECT regarding the
capabilities of an Amazon Machine Image (AMI)? (Select three)
Answer: You can copy an Amazon Machine Image (AMI) across AWS
Regions
You can share an Amazon Machine Image (AMI) with another AWS
account
Copying an Amazon Machine Image (AMI) backed by an encrypted
snapshot cannot result in an unencrypted target snapshot
●● An online gaming application has a large chunk of its traffic coming
from users who download static assets such as historic leaderboard
, reports and the game tactics for various games. The current
infrastructure and design are unable to cope up with the traffic and
application freezes on most of the pages.
Which of the following is a cost-optimal solution that does not need
provisioning of infrastructure?
Answer: Use Amazon Cloud Front with Amazon S3 as the storage
solution for the static assets.
●● A retail company has connected its on-premises data center to the
AWS Cloud via AWS Direct Connect. The company wants to be able to
resolve Domain Name System (DNS) queries for any resources in the
on-premises network from the AWS VPC and also resolve any DNS
queries for resources in the AWS VPC from the on-premises network.
As a solutions architect, which of the following solutions can be
combined to address the given use case? (Select two)
Answer: AN: -Create an inbound endpoint on Amazon Route 53
Resolver and then DNS resolvers on the on-premises network can
forward DNS queries to Amazon Route 53 Resolver via this endpoint
-Create an outbound endpoint on Amazon Route 53 Resolver and then
Amazon Route 53 Resolver can conditionally forward queries to
resolvers on the on-premises network via this endpoint
Explanation: Amazon Route 53 is a highly available and scalable cloud
Domain Name System (DNS) web service. Amazon Route 53 effectively
connects user requests to infrastructure running in AWS - such as
Amazon EC2 instances - and can also be used to route users to
infrastructure outside of AWS. By default, Amazon Route 53 Resolver
automatically answers DNS queries for local VPC domain names for
ASSOCIATE EXAMS SET VERIFIED
QUESTIONS AND ACCURATE ANSWERS
COMPLETE PREPARATION FILE
●● A retail company has its flagship application running on a fleet of
Amazon EC2 instances behind Elastic Load Balancing (ELB). The
engineering team has been seeing recurrent issues wherein the in-flight
requests from the ELB to the Amazon EC2 instances are getting dropped
when an instance becomes unhealthy.
Which of the following features can be used to address this issue?
Answer: A: Connection Draining
Explanation: To ensure that Elastic Load Balancing stops sending
requests to instances that are de-registering or unhealthy while keeping
the existing connections open, use connection draining. This enables the
load balancer to complete in-flight requests made to instances that are
de-registering or unhealthy. The maximum timeout value can be set
between 1 and 3,600 seconds (the default is 300 seconds). When the
maximum time limit is reached, the load balancer forcibly closes
connections to the de-registering instance.
●● A retail organization is moving some of its on-premises data to AWS
Cloud. The DevOps team at the organization has set up an AWS
Managed IPSec VPN Connection between their remote on-premises
network and their Amazon VPC over the internet.
,Which of the following represents the correct configuration for the
IPSec VPN Connection?
Answer: Create a virtual private gateway (VGW) on the AWS side of the
VPN and a Customer Gateway on the on-premises side of the VPN
Amazon VPC provides the facility to create an IPsec VPN connection
(also known as AWS site-to-site VPN) between remote customer
networks and their Amazon VPC over the internet
●● The DevOps team at a multi-national company is helping its
subsidiaries standardize Amazon EC2 instances by using the same
Amazon Machine Image (AMI). Some of these subsidiaries are in the
same AWS region but use different AWS accounts whereas others are in
different AWS regions but use the same AWS account as the parent
company. The DevOps team has hired you as a solutions architect for
this project.
Which of the following would you identify as CORRECT regarding the
capabilities of an Amazon Machine Image (AMI)? (Select three)
Answer: You can copy an Amazon Machine Image (AMI) across AWS
Regions
You can share an Amazon Machine Image (AMI) with another AWS
account
Copying an Amazon Machine Image (AMI) backed by an encrypted
snapshot cannot result in an unencrypted target snapshot
●● An online gaming application has a large chunk of its traffic coming
from users who download static assets such as historic leaderboard
, reports and the game tactics for various games. The current
infrastructure and design are unable to cope up with the traffic and
application freezes on most of the pages.
Which of the following is a cost-optimal solution that does not need
provisioning of infrastructure?
Answer: Use Amazon Cloud Front with Amazon S3 as the storage
solution for the static assets.
●● A retail company has connected its on-premises data center to the
AWS Cloud via AWS Direct Connect. The company wants to be able to
resolve Domain Name System (DNS) queries for any resources in the
on-premises network from the AWS VPC and also resolve any DNS
queries for resources in the AWS VPC from the on-premises network.
As a solutions architect, which of the following solutions can be
combined to address the given use case? (Select two)
Answer: AN: -Create an inbound endpoint on Amazon Route 53
Resolver and then DNS resolvers on the on-premises network can
forward DNS queries to Amazon Route 53 Resolver via this endpoint
-Create an outbound endpoint on Amazon Route 53 Resolver and then
Amazon Route 53 Resolver can conditionally forward queries to
resolvers on the on-premises network via this endpoint
Explanation: Amazon Route 53 is a highly available and scalable cloud
Domain Name System (DNS) web service. Amazon Route 53 effectively
connects user requests to infrastructure running in AWS - such as
Amazon EC2 instances - and can also be used to route users to
infrastructure outside of AWS. By default, Amazon Route 53 Resolver
automatically answers DNS queries for local VPC domain names for