Free AWS-SysOps Exam Braindumps (page: 18)

Page 17 of 121

The security team is concerned because the number of AWS Identity and Access Management (IAM) policies being used in the environment is increasing. The team tasked a SysOps administrator to report on the current number of IAM policies in use and the total available IAM policies.
Which AWS service should the administrator use to check how current IAM policy usage compares to current service limits?

  1. AWS Trusted Advisor
  2. Amazon Inspector
  3. AWS Config
  4. AWS Organizations

Answer(s): A

Explanation:


Reference:

https://docs.aws.amazon.com/awssupport/latest/user/trusted-advisor-check-reference.html#iam-policies



A SysOps administrator is trying to set up an Amazon Route 53 domain name to route traffic to a website hosted on Amazon S3. The domain name of the website is www.example.com and the S3 bucket name DOC-EXAMPLE-BUCKET. After the record set is set up in Route 53, the domain name www.anycompany.com does not seem to work, and the static website is not displayed in the browser.
Which of the following is a cause of this?

  1. The S3 bucket must be configured with Amazon CloudFront first.
  2. The Route 53 record set must have an IAM role that allows access to the S3 bucket.
  3. The Route 53 record set must be in the same region as the S3 bucket.
  4. The S3 bucket name must match the record set name in Route 53.

Answer(s): D

Explanation:


Reference:

https://aws.amazon.com/premiumsupport/knowledge-center/route-53-no-targets/



A SysOps administrator has used AWS CloudFormation to deploy a serverless application into a production VPC. The application consists of an AWS Lambda function, an Amazon DynamoDB table, and an Amazon API Gateway API. The SysOps administrator must delete the AWS CloudFormation stack without deleting the DynamoDB table.
Which action should the SysOps administrator take before deleting the AWS CloudFormation stack?

  1. Add a Retain deletion policy to the DynamoDB resource in the AWS CloudFormation stack.
  2. Add a Snapshot deletion policy to the DynamoDB resource in the AWS CloudFormation stack.
  3. Enable termination protection on the AWS CloudFormation stack.
  4. Update the application's IAM policy with a Deny statement for the dynamodb:DeleteTable action.

Answer(s): A



A SysOps administrator is notified that an Amazon EC2 instance has stopped responding. The AWS Management Console indicates that the system checks are failing.
What should the administrator do first to resolve this issue?

  1. Reboot the EC2 instance so it can be launched on a new host.
  2. Stop and then start the EC2 instance so that it can be launched on a new host.
  3. Terminate the EC2 instance and relaunch it.
  4. View the AWS CloudTrail log to investigate what changed on the EC2 instance.

Answer(s): B






Post your Comments and Discuss Amazon AWS-SysOps exam with other Community members:

AWS-SysOps Discussions & Posts