Free AWS-SysOps Exam Braindumps (page: 16)

Page 15 of 121

A company uses an AWS Service Catalog portfolio to create and manage resources. A SysOps administrator must create a replica of the company's existing AWS infrastructure in a new AWS account.
What is the MOST operationally efficient way to meet this requirement?

  1. Create an AWS CloudFormation template to use the AWS Service Catalog portfolio in the new AWS account.
  2. In the new AWS account, manually create an AWS Service Catalog portfolio that duplicates the original portfolio.
  3. Run an AWS Lambda function to create a new AWS Service Catalog portfolio based on the output of the DescribePortfolio API operation.
  4. Share the AWS Service Catalog portfolio with the new AWS account. Import the portfolio into the new AWS account.

Answer(s): D



A SysOps administrator must manage the security of an AWS account. Recently, an IAM user's access key was mistakenly uploaded to a public code repository.
The SysOps administrator must identify anything that was changed by using this access key.
How should the SysOps administrator meet these requirements?

  1. Create an Amazon EventBridge (Amazon CloudWatch Events) rule to send all IAM events to an AWS Lambda function for analysis.
  2. Query Amazon EC2 logs by using Amazon CloudWatch Logs Insights for all events initiated with the compromised access key within the suspected timeframe.
  3. Search AWS CloudTrail event history for all events initiated with the compromised access key within the suspected timeframe.
  4. Search VPC Flow Logs for all events initiated with the compromised access key within the suspected timeframe.

Answer(s): C



A company runs a retail website on multiple Amazon EC2 instances behind an Application Load Balancer (ALB). The company must secure traffic to the website over an HTTPS connection.
Which combination of actions should a SysOps administrator take to meet these requirements? (Choose two.)

  1. Attach the certificate to each EC2 instance.
  2. Attach the certificate to the AL
  3. Create a private certificate in AWS Certificate Manager (ACM).
  4. Create a public certificate in AWS Certificate Manager (ACM).
  5. Export the certificate, and attach it to the website.

Answer(s): B,D



SIMULATION
Instructions
If the copy-paste functionality is not working in your environment, refer to the instructions file on the VM desktop and use Ctrl+C, Ctrl+V or Command-C,
Command-V.
Configure Amazon EventBridge to meet the following requirements.
1. Use the us-east-2 Region for all resources.
2. Unless specified below, use the default configuration settings.
3. Use your own resource naming unless a resource name is specified below.
4. Ensure all Amazon EC2 events in the default event bus are replayable for the past 45 days.
5. Create a rule named RunFunction to send the exact message {"name":"example") every 15 minutes to an existing AWS Lambda function named LogEventFunction
6. Create a rule named SpotWarning to send a notification to a new standard Amazon SNS topic named TopicEvents whenever an Amazon EC2 Spot Instance is interrupted. Do NOT create any topic subscriptions. The notification must match the following structure:
Input path:
{`instance`:`detail.instance-id}
Input template:
`The EC2 Spot Instance <instance> has been interrupted.`
Important: Click the Next button to complete this lab and continue to the next lab. Once you click the Next button, you will NOT be able to return to this lab.

  1. See Explanation section for answer.

Answer(s): A

Explanation:


































Post your Comments and Discuss Amazon AWS-SysOps exam with other Community members:

AWS-SysOps Discussions & Posts