Free SOA-C02 Exam Braindumps (page: 14)

Page 14 of 106

A compliance team requires all administrator passwords for Amazon RDS DB instances to be changed at least annually.
Which solution meets this requirement in the MOST operationally efficient manner?

  1. Store the database credentials in AWS Secrets Manager. Configure automatic rotation for the secret every 365 days.
  2. Store the database credentials as a parameter in the RDS parameter group. Create a database trigger to rotate the password every 365 days.
  3. Store the database credentials in a private Amazon S3 bucket. Schedule an AWS Lambda function to generate a new set of credentials every 365 days.
  4. Store the database credentials in AWS Systems Manager Parameter Store as a secure string parameter. Configure automatic rotation for the parameter every 365 days.

Answer(s): A



A SysOps administrator is responsible for managing a fleet of Amazon EC2 instances. These EC2 instances upload build artifacts to a third-party service. The third-party service recently implemented a strict IP allow list that requires all build uploads to come from a single IP address.
What change should the systems administrator make to the existing build fleet to comply with this new requirement?

  1. Move all of the EC2 instances behind a NAT gateway and provide the gateway IP address to the service.
  2. Move all of the EC2 instances behind an internet gateway and provide the gateway IP address to the service.
  3. Move all of the EC2 instances into a single Availability Zone and provide the Availability Zone IP address to the service.
  4. Move all of the EC2 instances to a peered VPC and provide the VPC IP address to the service.

Answer(s): A



A company uses an Amazon CloudFront distribution to deliver its website. Traffic logs for the website must be centrally stored, and all data must be encrypted at rest.
Which solution will meet these requirements?

  1. Create an Amazon OpenSearch Service (Amazon Elasticsearch Service) domain with internet access and server-side encryption that uses the default AWS managed customer master key (CMK). Configure CloudFront to use the Amazon OpenSearch Service (Amazon Elasticsearch Service) domain as a log destination.
  2. Create an Amazon OpenSearch Service (Amazon Elasticsearch Service) domain with VPC access and server-side encryption that uses AES-256. Configure CloudFront to use the Amazon OpenSearch Service (Amazon Elasticsearch Service) domain as a log destination.
  3. Create an Amazon S3 bucket that is configured with default server-side encryption that uses AES-256. Configure CloudFront to use the S3 bucket as a log destination.
  4. Create an Amazon S3 bucket that is configured with no default encryption. Enable encryption in the CloudFront distribution, and use the S3 bucket as a log destination.

Answer(s): C



An organization created an Amazon Elastic File System (Amazon EFS) volume with a file system ID of fs-85ba41fc, and it is actively used by 10 Amazon EC2 hosts. The organization has become concerned that the file system is not encrypted.
How can this be resolved?

  1. Enable encryption on each host's connection to the Amazon EFS volume. Each connection must be recreated for encryption to take effect.
  2. Enable encryption on the existing EFS volume by using the AWS Command Line Interface.
  3. Enable encryption on each host's local drive. Restart each host to encrypt the drive.
  4. Enable encryption on a newly created volume and copy all data from the original volume. Reconnect each host to the new volume.

Answer(s): D



Page 14 of 106



Post your Comments and Discuss Amazon SOA-C02 exam with other Community members:

FN commented on November 21, 2024
Great work team!
ITALY
upvote

Tech Savvy commented on November 04, 2024
Great work team!, would be good if you list 10 questions at each page,
Anonymous
upvote

DeMalio commented on September 30, 2024
Very helpful and very accurate. Could not have passed this exam without this exam dump. Very grateful.
UNITED STATES
upvote

Omkar commented on June 26, 2024
Useful Dump
Anonymous
upvote

john commented on February 24, 2024
It's my first review so excuse me if I overlooked any etiquettes or etc. I had been studying off and on since Nov. I received a 790 a few hours ago and what I did was the following: Took the practice tests and got a passing score a couple times in a row Overall, I'd say that everything provided for reasonable price by along with the dumps helped me out the most. All of that plus just not psyching yourself out about the difficulty of the exam, picking a date and forcing yourself to be ready by that date should pretty much set you up for success.
UNITED STATES
upvote

tomAws commented on July 18, 2023
nice questions
BRAZIL
upvote

Emma commented on November 27, 2023
Nice questions
VIET NAM
upvote

Freya commented on October 24, 2023
I got my results today and I am delighted by them as I scored 83% on the SOA-C02 exam. I owe it all to this platform, I am I purchased this course as it is worth it.
Anonymous
upvote

tomAws commented on July 18, 2023
Questions so precious, I can already smell the certification :D
BRAZIL
upvote

tomAws commented on July 18, 2023
Nice questions
BRAZIL
upvote

SANDRO commented on March 01, 2023
It has been a wonderful experince dealing with the support team. They helped me update my files. And the new version seems to cover all the new topics. Very greatful.
UNITED STATES
upvote

StuckWithThis commented on June 14, 2022
Passed today. Do not take life serious. :-) Use these cheat sheets and pass.
UNITED STATES
upvote

Zack commented on May 04, 2021
Worth every penny! Just passed my exam. I was very concerned but these practice questions are magic!
UNITED STATES
upvote