AWS Practice Exam 6 (Design Secure
Architectures) Questions And Answers
A silicon valley based healthcare startup uses AWS Cloud for its IT
infrastructure. The startup stores patient health records on Amazon
S3. The engineering team needs to implement an archival solution
based on Amazon S3 Glacier to enforce regulatory and compliance
controls on data access.
As a solutions architect, which of the following solutions would you
recommend? -
correct answer ✅Use S3 Glacier vault to store the sensitive
archived data and then use a vault lock policy to enforce
compliance controls
The infrastructure team at a company maintains 5 different VPCs
(let's call these VPCs A, B, C, D, E) for resource isolation. Due to the
changed organizational structure, the team wants to interconnect
all VPCs together. To facilitate this, the team has set up VPC peering
connections between VPC A and all other VPCs in a hub and spoke
model with VPC A at the center. However, the team has still failed
to establish connectivity between all VPCs.
As a solutions architect, which of the following would you
recommend as the MOST resource-efficient and scalable solution? -
correct answer ✅Use a transit gateway to interconnect the VPCs
, AWS Practice Exam 6 (Design Secure
Architectures) Questions And Answers
A developer in your team has set up a classic 3 tier architecture
composed of an Application Load Balancer, an Auto Scaling group
managing a fleet of EC2 instances, and an Aurora database. As a
Solutions Architect, you would like to adhere to the security pillar
of the well-architected framework.
How do you configure the security group of the Aurora database to
only allow traffic coming from the EC2 instances? -
correct answer ✅Add a rule authorizing the EC2 security group
An online gaming company wants to block access to its application
from specific countries; however, the company wants to allow its
remote development team (from one of the blocked countries) to
have access to the application. The application is deployed on EC2
instances running under an Application Load Balancer (ALB) with
AWS WAF.
As a solutions architect, which of the following solutions can be
combined to address the given use-case? (Select two) -
correct answer ✅Use WAF geo match statement listing the
countries that you want to block
Use WAF IP set statement that specifies the IP addresses that you
want to allow through
Architectures) Questions And Answers
A silicon valley based healthcare startup uses AWS Cloud for its IT
infrastructure. The startup stores patient health records on Amazon
S3. The engineering team needs to implement an archival solution
based on Amazon S3 Glacier to enforce regulatory and compliance
controls on data access.
As a solutions architect, which of the following solutions would you
recommend? -
correct answer ✅Use S3 Glacier vault to store the sensitive
archived data and then use a vault lock policy to enforce
compliance controls
The infrastructure team at a company maintains 5 different VPCs
(let's call these VPCs A, B, C, D, E) for resource isolation. Due to the
changed organizational structure, the team wants to interconnect
all VPCs together. To facilitate this, the team has set up VPC peering
connections between VPC A and all other VPCs in a hub and spoke
model with VPC A at the center. However, the team has still failed
to establish connectivity between all VPCs.
As a solutions architect, which of the following would you
recommend as the MOST resource-efficient and scalable solution? -
correct answer ✅Use a transit gateway to interconnect the VPCs
, AWS Practice Exam 6 (Design Secure
Architectures) Questions And Answers
A developer in your team has set up a classic 3 tier architecture
composed of an Application Load Balancer, an Auto Scaling group
managing a fleet of EC2 instances, and an Aurora database. As a
Solutions Architect, you would like to adhere to the security pillar
of the well-architected framework.
How do you configure the security group of the Aurora database to
only allow traffic coming from the EC2 instances? -
correct answer ✅Add a rule authorizing the EC2 security group
An online gaming company wants to block access to its application
from specific countries; however, the company wants to allow its
remote development team (from one of the blocked countries) to
have access to the application. The application is deployed on EC2
instances running under an Application Load Balancer (ALB) with
AWS WAF.
As a solutions architect, which of the following solutions can be
combined to address the given use-case? (Select two) -
correct answer ✅Use WAF geo match statement listing the
countries that you want to block
Use WAF IP set statement that specifies the IP addresses that you
want to allow through