Free AWS-SysOps Exam Braindumps (page: 14)

Page 14 of 106

A compliance team requires all administrator passwords for Amazon RDS DB instances to be changed at least annually.
Which solution meets this requirement in the MOST operationally efficient manner?

  1. Store the database credentials in AWS Secrets Manager. Configure automatic rotation for the secret every 365 days.
  2. Store the database credentials as a parameter in the RDS parameter group. Create a database trigger to rotate the password every 365 days.
  3. Store the database credentials in a private Amazon S3 bucket. Schedule an AWS Lambda function to generate a new set of credentials every 365 days.
  4. Store the database credentials in AWS Systems Manager Parameter Store as a secure string parameter. Configure automatic rotation for the parameter every 365 days.

Answer(s): A



A SysOps administrator is responsible for managing a fleet of Amazon EC2 instances. These EC2 instances upload build artifacts to a third-party service. The third-party service recently implemented a strict IP allow list that requires all build uploads to come from a single IP address.
What change should the systems administrator make to the existing build fleet to comply with this new requirement?

  1. Move all of the EC2 instances behind a NAT gateway and provide the gateway IP address to the service.
  2. Move all of the EC2 instances behind an internet gateway and provide the gateway IP address to the service.
  3. Move all of the EC2 instances into a single Availability Zone and provide the Availability Zone IP address to the service.
  4. Move all of the EC2 instances to a peered VPC and provide the VPC IP address to the service.

Answer(s): A



A company uses an Amazon CloudFront distribution to deliver its website. Traffic logs for the website must be centrally stored, and all data must be encrypted at rest.
Which solution will meet these requirements?

  1. Create an Amazon OpenSearch Service (Amazon Elasticsearch Service) domain with internet access and server-side encryption that uses the default AWS managed customer master key (CMK). Configure CloudFront to use the Amazon OpenSearch Service (Amazon Elasticsearch Service) domain as a log destination.
  2. Create an Amazon OpenSearch Service (Amazon Elasticsearch Service) domain with VPC access and server-side encryption that uses AES-256. Configure CloudFront to use the Amazon OpenSearch Service (Amazon Elasticsearch Service) domain as a log destination.
  3. Create an Amazon S3 bucket that is configured with default server-side encryption that uses AES-256. Configure CloudFront to use the S3 bucket as a log destination.
  4. Create an Amazon S3 bucket that is configured with no default encryption. Enable encryption in the CloudFront distribution, and use the S3 bucket as a log destination.

Answer(s): C



An organization created an Amazon Elastic File System (Amazon EFS) volume with a file system ID of fs-85ba41fc, and it is actively used by 10 Amazon EC2 hosts. The organization has become concerned that the file system is not encrypted.
How can this be resolved?

  1. Enable encryption on each host's connection to the Amazon EFS volume. Each connection must be recreated for encryption to take effect.
  2. Enable encryption on the existing EFS volume by using the AWS Command Line Interface.
  3. Enable encryption on each host's local drive. Restart each host to encrypt the drive.
  4. Enable encryption on a newly created volume and copy all data from the original volume. Reconnect each host to the new volume.

Answer(s): D



Page 14 of 106



Post your Comments and Discuss Amazon AWS-SysOps exam with other Community members:

Lori commented on August 03, 2019
I managed to pass the exam with good score sing this dump. I failed this exam before. It is too hard to know all the topics. This braindump questions and answers is a life-saver!
UNITED STATES
upvote

Norman commented on May 21, 2019
I love this site and their braindumps material. They have helped me pass 3 of my exams so far. This is the 4th one I am going for. Wish me luck. I hope I can clear it as easy as I did the other 3.
UNITED STATES
upvote

Arian commented on May 17, 2019
I normally don't go for braindumps and cheat sheets but for this exam I had to since I did not have time and there was a deadline set by company. So I used these dumps and it worked. I passed in first try.
UNITED STATES
upvote

streetbites commented on April 26, 2019
Great price will study and post results...
UNITED STATES
upvote

zxczx commented on September 10, 2018
where are my downloads?
UNITED STATES
upvote

db commented on September 10, 2018
website had to navigate and download exams.
UNITED STATES
upvote

sam commented on July 19, 2018
later
INDIA
upvote

Karthik commented on March 20, 2018
Hi Team, Shared dumps answers are wrong, I have cross check most of the answer are wrong. Please refund / share the valid one?. Regards, Karthik M
GERMANY
upvote

Yogi commented on January 23, 2018
Excellant product. Cleared exam with 95%.
UNITED STATES
upvote

Ronnie commented on September 05, 2017
I have heard great things from a colleague ! He has passed every exam by 80+% Thanks to BrainDumps... I'll let you know in 2 weeks how i go!
UNITED STATES
upvote

Rai commented on June 09, 2017
Very helpful content, definitely will help me to pass the certification
UNITED STATES
upvote

musma21 commented on March 05, 2017
I've been using AWS and Azure for a time however I've never tried to take this exam. I'm really thrilled to get the AWS cert with help of this dump!
UNITED STATES
upvote