Free SOA-C02 Exam Braindumps (page: 53)

Page 53 of 106

A company needs to deploy a new workload on AWS. The company must encrypt all data at rest and must rotate the encryption keys once each year. The workload uses an Amazon RDS for MySQL Multi-AZ database for data storage.

Which configuration approach will meet these requirements?

  1. Enable Transparent Data Encryption (TDE) in the MySQL configuration file. Manually rotate the key every 12 months.
  2. Enable RDS encryption on the database at creation time by using the AWS managed key for Amazon RDS.
  3. Create a new AWS Key Management Service (AWS KMS) customer managed key. Enable automatic key rotation. Enable RDS encryption on the database at creation time by using the KMS key.
  4. Create a new AWS Key Management Service (AWS KMS) customer managed key. Enable automatic key rotation. Enable encryption on the Amazon Elastic Block Store (Amazon EBS) volumes that are attached to the RDS DB instance.

Answer(s): C



A company has an application that is deployed to two AWS Regions in an active-passive configuration. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB) in each Region. The instances are in an Amazon EC2 Auto Scaling group in each Region. The application uses an Amazon Route 53 hosted zone for DNS. A SysOps administrator needs to configure automatic failover to the secondary Region.

What should the SysOps administrator do to meet these requirements?

  1. Configure Route 53 alias records that point to each ALB. Choose a failover routing policy. Set Evaluate Target Health to Yes.
  2. Configure CNAME records that point to each ALChoose a failover routing policy. Set Evaluate Target Health to Yes.
  3. Configure Elastic Load Balancing (ELB) health checks for the Auto Scaling group. Add a target group to the ALB in the primary Region. Include the EC2 instances in the secondary Region as targets.
  4. Configure EC2 health checks for the Auto Scaling group. Add a target group to the ALB in the primary Region. Include the EC2 instances in the secondary Region as targets.

Answer(s): A



A company is implementing a monitoring solution that is based on machine learning. The monitoring solution consumes Amazon EventBridge (Amazon CloudWatch Events) events that are generated by Amazon EC2 Auto Scaling. The monitoring solution provides detection of anomalous behavior such as unanticipated scaling events and is configured as an EventBridge (CloudWatch Events) API destination.

During initial testing, the company discovers that the monitoring solution is not receiving events. However, Amazon CloudWatch is showing that the EventBridge (CloudWatch Events) rule is being invoked. A SysOps administrator must implement a solution to retrieve client error details to help resolve this issue.

Which solution will meet these requirements with the LEAST operational effort?

  1. Create an EventBridge (CloudWatch Events) archive for the event pattern to replay the events. Increase the logging on the monitoring solution. Use replay to invoke the monitoring solution. Examine the error details.
  2. Add an Amazon Simple Queue Service (Amazon SQS) standard queue as a dead-letter queue for the target. Process the messages in the dead-letter queue to retrieve error details.
  3. Create a second EventBridge (CloudWatch Events) rule for the same event pattern to target an AWS Lambda function. Configure the Lambda function to invoke the monitoring solution and to record the results to Amazon CloudWatch Logs. Examine the errors in the logs.
  4. Configure the EventBridge (CloudWatch Events) rule to send error messages to an Amazon Simple Notification Service (Amazon SNS) topic.

Answer(s): B



A company is storing backups in an Amazon S3 bucket. The backups must not be deleted for at least 3 months after the backups are created.

What should a SysOps administrator do to meet this requirement?

  1. Configure an IAM policy that denies the s3:DeleteObject action for all users. Three months after an object is written, remove the policy.
  2. Enable S3 Object Lock on a new S3 bucket in compliance mode. Place all backups in the new S3 bucket with a retention period of 3 months.
  3. Enable S3 Versioning on the existing S3 bucket. Configure S3 Lifecycle rules to protect the backups.
  4. Enable S3 Object Lock on a new S3 bucket in governance mode. Place all backups in the new S3 bucket with a retention period of 3 months.

Answer(s): B



Page 53 of 106



Post your Comments and Discuss Amazon SOA-C02 exam with other Community members:

FN commented on November 21, 2024
Great work team!
ITALY
upvote

Tech Savvy commented on November 04, 2024
Great work team!, would be good if you list 10 questions at each page,
Anonymous
upvote

DeMalio commented on September 30, 2024
Very helpful and very accurate. Could not have passed this exam without this exam dump. Very grateful.
UNITED STATES
upvote

Omkar commented on June 26, 2024
Useful Dump
Anonymous
upvote

john commented on February 24, 2024
It's my first review so excuse me if I overlooked any etiquettes or etc. I had been studying off and on since Nov. I received a 790 a few hours ago and what I did was the following: Took the practice tests and got a passing score a couple times in a row Overall, I'd say that everything provided for reasonable price by along with the dumps helped me out the most. All of that plus just not psyching yourself out about the difficulty of the exam, picking a date and forcing yourself to be ready by that date should pretty much set you up for success.
UNITED STATES
upvote

tomAws commented on July 18, 2023
nice questions
BRAZIL
upvote

Emma commented on November 27, 2023
Nice questions
VIET NAM
upvote

Freya commented on October 24, 2023
I got my results today and I am delighted by them as I scored 83% on the SOA-C02 exam. I owe it all to this platform, I am I purchased this course as it is worth it.
Anonymous
upvote

tomAws commented on July 18, 2023
Questions so precious, I can already smell the certification :D
BRAZIL
upvote

tomAws commented on July 18, 2023
Nice questions
BRAZIL
upvote

SANDRO commented on March 01, 2023
It has been a wonderful experince dealing with the support team. They helped me update my files. And the new version seems to cover all the new topics. Very greatful.
UNITED STATES
upvote

StuckWithThis commented on June 14, 2022
Passed today. Do not take life serious. :-) Use these cheat sheets and pass.
UNITED STATES
upvote

Zack commented on May 04, 2021
Worth every penny! Just passed my exam. I was very concerned but these practice questions are magic!
UNITED STATES
upvote