Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

AWS Certified Specialty ANS-C00 Amazon Web Services Study Notes

Page: 6 / 6
Total 154 questions

AWS Certified Advanced Networking-Specialty Questions and Answers

Question 21

Your company needs to leverage Amazon Simple Storage Solution (S3) for backup and archiving. According to company policy, data should not flow on the public Internet even if data is encrypted. You have set up two S3 buckets in us-east-1 and us-west-2. Your company data center is located on the West Coast of the United States. The design must be cost-effective and enable minimal latency.

Which design should you set up?

Options:

A.

An AWS Direct Connect connection to us-east-1 and a Direct Connect connection to us-west-2.

B.

An AWS Direct Connect connection to us-east-1.

C.

An AWS Direct Connect connection to us-west-2.

D.

An AWS Direct Connect connection to us-west-2 and a VPN connection to us-east-1.

Question 22

Your company runs an HTTPS application using an Elastic Load Balancing (ELB) load balancer/PHP on nginx server/RDS in multiple Availability Zones. You need to apply Geographic Restriction and identify the client’s IP address in your application to generate dynamic content.

How should you utilize AWS services in a scalable fashion to perform this task?

Options:

A.

Modify the nginx log configuration to record value in X-Forwarded-For and use CloudFront to apply the Geographic Restriction.

B.

Enable ELB access logs to store the client IP address and parse these to dynamically modify a blacklist.

C.

Use X-Forwarded-For with security groups to apply the Geographic Restriction.

D.

Modify the application code to use value of X-Forwarded-For and CloudFront to apply the Geographic Restriction.

Question 23

The Web Application Development team is worried about malicious activity from 200 random IP addresses. Which action will ensure security and scalability from this type of threat?

Options:

A.

Use inbound security group rules to block the IP addresses.

B.

Use inbound network ACL rules to block the IP addresses.

C.

Use AWS WAF to block the IP addresses.

D.

Write iptables rules on the instance to block the IP addresses.

Page: 6 / 6
Total 154 questions