Q: 1
A company's network engineer must implement a cloud-based networking environment for a
network operations team to centrally manage. Other teams will use the environment. Each team
must be able to deploy infrastructure to the environment and must be able to manage its own
resources. The environment must feature IPv4 and IPv6 support and must provide internet
connectivity in a dual-stack configuration.
The company has an organization in AWS Organizations that contains a workload account for the
teams. The network engineer creates a new networking account in the organization.
Which combination of steps should the network engineer take next to meet the requirements?
(Select THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
A company is migrating an existing application to a new AWS account. The company will deploy the
application in a single AWS Region by using one VPC and multiple Availability Zones. The application
will run on Amazon EC2 instances. Each Availability Zone will have several EC2 instances. The EC2
instances will be deployed in private subnets.
The company's clients will connect to the application by using a web browser with the HTTPS
protocol. Inbound connections must be distributed across the Availability Zones and EC2 instances.
All connections from the same client session must be connected to the same EC2 instance. The
company must provide end-to-end encryption for all connections between the clients and the
application by using the application SSL certificate.
Which solution will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
A company wants to improve visibility into its AWS environment. The AWS environment consists of
multiple VPCs that are connected to a transit gateway. The transit gateway connects to an on-
premises data center through an AWS Direct Connect gateway and a pair of redundant Direct
Connect connections that use transit VIFs. The company must receive notification each time a new
route is advertised to AWS from on premises over Direct Connect.
What should a network engineer do to meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
A company has several AWS Site-to-Site VPN connections between an on-premises customer
gateway and a transit gateway. The company's application uses IPv4 to communicate through the
VPN connections.
The company has updated the VPC to be dual stack and wants to transition to using IPv6-only for new
workloads. When the company tries to communicate through the existing VPN connections, IPv6
traffic fails.
Which solution will provide IPv6 support with the LEAST operational overhead?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
A company is moving its record-keeping application to the AWS Cloud. All traffic between the
company's on-premises data center and AWS must be encrypted at all times and at every transit
device during the migration.
The application will reside across multiple Availability Zones in a single AWS Region. The application
will use existing 10 Gbps AWS Direct Connect dedicated connections with a MACsec capable port. A
network engineer must ensure that the Direct Connect connection is secured accordingly at every
transit device.
The network engineer creates a Connection Key Name and Connectivity Association Key (CKN/CAK)
pair for the MACsec secret key.
Which combination of additional steps should the network engineer take to meet the requirements?
(Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A company has an application that runs on a fleet of Amazon EC2 instances. A new company
regulation mandates that all network traffic to and from the EC2 instances must be sent to a
centralized third-party EC2 appliance for content inspection.
Which solution will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
A company has critical VPC workloads that connect to an on-premises data center through two
redundant active-passive AWS Direct Connect connections. However, a recent outage on one Direct
Connect connection revealed that it takes more than a minute for traffic to fail over to the secondary
Direct Connect connection. The company wants to reduce the failover time from minutes to seconds.
Which solution will provide the LARGEST reduction in the BGP failover time?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
A company is migrating its containerized application to AWS. For the architecture the company will
have an ingress VPC with a Network Load Balancer (NLB) to distribute the traffic to front-end pods in
an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. The front end of the application will
determine which user is requesting access and will send traffic to 1 of 10 services VPCs. Each services
VPC will include an NLB that distributes traffic to the services pods in an EKS cluster.
The company is concerned about overall cost. User traffic will be responsible for more than 10 TB of
data transfer from the ingress VPC to services VPCs every month. A network engineer needs to
recommend how to design the communication between the VPCs.
Which solution will meet these requirements at the LOWEST cost?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
A team of infrastructure engineers wants to automate the deployment of Application Load Balancer
(ALB) components by using the AWS Cloud Development Kit (AWS CDK). The CDK application must
deploy an infrastructure stack that is reusable and consistent across multiple environments, AWS
Regions, and AWS accounts.
The lead network architect on the project has already bootstrapped the target accounts. The lead
network architect also has deployed core network components such as VPCs and Amazon Route 53
private hosted zones across the multiple environments and Regions. The infrastructure engineers
must design the ALB components in the CDK application to use the existing core network
components.
Which combination of steps will meet this requirement with the LEAST manual effort between
environment deployments? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
A company hosts a web application that runs on a fleet of Amazon EC2 instances behind an
Application Load Balancer (ALB). The instances are in an Auto Scaling group. The company uses an
Amazon CloudFront distribution with the ALB as an origin.
The application recently experienced an attack. In response, the company associated an AWS WAF
web ACL with the CloudFront distribution. The company needs to use Amazon Athena to analyze
application attacks that AWS WAF detects.
Which solution will meet this requirement?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2