An insurance company plans to migrate workloads from its on-premises data center to the AWS Cloud. The company needs end-to-end domain name resolution, including bi-directional DNS resolution between AWS and the existing on-premises environments. The workloads will be migrated into multiple VPCs, have dependencies on one another, and will not all migrate at the same time.
Which solution fulfills these requirements?
AConfigure a private hosted zone for each application VPC, and create the requisite records. Create a set of Amazon Route 53 Resolver inbound and outbound endpoints in an egress VPC. Define Route 53 Resolver rules to forward requests for the on-premises domains to the on-premises DNS resolver. Associate the application VPC private hosted zones with the egress VPC, and share the Route 53 Resolver rules with the application accounts by using AWS Resource Access Manager. Configure the on-premises DNS servers to forward the cloud domains to the Route 53 inbound endpoints.
BConfigure a public hosted zone for each application VPC, and create the requisite records. Create a set of Amazon Route 53 Resolver inbound and outbound endpoints in an egress VPC. Define Route 53 Resolver rules to forward requests for the on-premises domains to the on-premises DNS resolver. Associate the application VPC private hosted zones with the egress VPC. and share the Route 53 Resolver rules with the application accounts by using AWS Resource Access Manager. Configure the on-premises DNS servers to forward the cloud domains to the Route 53 inbound endpoints.
CConfigure a private hosted zone for each application VPC, and create the requisite records. Create a set of Amazon Route 53 Resolver inbound and outbound endpoints in an egress VPDefine Route 53 Resolver rules to forward requests for the on-premises domains to the on-premises DNS resolver. Associate the application VPC private hosted zones with the egress VPand share the Route 53 Resolver rules with the application accounts by using AWS Resource Access Manager. Configure the on-premises DNS servers to forward the cloud domains to the Route 53 outbound endpoints.
DConfigure a private hosted zone for each application VPC, and create the requisite records. Create a set of Amazon Route 53 Resolver inbound and outbound endpoints in an egress VPC. Define Route 53 Resolver rules to forward requests for the on-premises domains to the on-premises DNS resolver. Associate the Route 53 outbound rules with the application VPCs, and share the private hosted zones with the application accounts by using AWS Resource Access Manager. Configure the on-premises DNS servers to forward the cloud domains to the Route 53 inbound endpoints.
0
Community Discussion
No comments yet. Be the first to start the discussion!
A company runs an application on Amazon EC2 instances behind an Application Load Balancer (ALB). The company recently had a network security breach. A network engineer needs to collect and analyze logs containing the client IP address, target IP address, target port, and user agent for every user who accesses the application.
What is the MOST operationally efficient solution that fulfills these requirements?
AConfigure the ALB to store logs in an Amazon S3 bucket. Download the files from Amazon S3, and use a spreadsheet application to analyze the logs.
BConfigure the ALB to push logs to Amazon Kinesis Data Streams. Use Amazon Kinesis Data Analytics to analyze the logs.
CConfigure Amazon Kinesis Data Streams to stream data from the ALB to Amazon OpenSearch Service (Amazon Elasticsearch Service). Use search operations in Amazon OpenSearch Service (Amazon Elasticsearch Service) to analyze the data.
DConfigure the ALB to store logs in an Amazon S3 bucket. Use Amazon Athena to analyze the logs in Amazon S3.
0
Community Discussion
No comments yet. Be the first to start the discussion!
A company uses AWS Network Firewall to protect outbound traffic for multiple VPCs in the same AWS account. Each VPC contains Amazon EC2 instances that host the company’s applications. Every EC2 instance is tagged with the name of the application that it hosts. The EC2 instances are in Auto Scaling groups.
A Network Firewall stateful rule group must stay current even when an Auto Scaling group launches or terminates EC2 instances.
Which solution meets this requirement with the LEAST implementation and administrative effort?
ACreate a network ACL for each application. Reference the network ACL in the stateful rule group.
BCreate a prefix list for each application. Reference the prefix list in the stateful rule group.
CCreate an AWS Lambda function that queries the EC2 instance tags for each application name and then updates the stateful rule group with the IP address of each instance.
DCreate a resource group for each application name. Reference the Amazon Resource Name (ARN) for the resource groups in the stateful rule group.
0
Community Discussion
No comments yet. Be the first to start the discussion!
A company is migrating applications from a data center to AWS. Many applications will need to exchange data with the company’s on-premises mainframe.
The company must achieve transfer speeds of 4 Gbps to satisfy peak traffic demands. A network engineer must design a highly available solution that maximizes resiliency. The solution must withstand the loss of circuits or routers.
Which solution satisfies these requirements?
AOrder four 10 Gbps AWS Direct Connect connections that are evenly spread over two locations. Terminate one connection from each Direct Connect location to a router at the company location. Terminate the other connection from each Direct Connect location to a different router at the company location.
BOrder two 10 Gbps AWS Direct Connect connections that are evenly spread over two locations. Terminate the connection from each Direct Connect location to a different router at the company location.
COrder four 1 Gbps AWS Direct Connect connections that are evenly spread over two locations. Terminate one connection from each Direct Connect location to a router at the company location. Terminate the other connection from each Direct Connect location to a different router at the company location.
DOrder two 1 Gbps AWS Direct Connect connections that are evenly spread over two locations. Terminate the connection from each Direct Connect location to a different router at the company location.
0
Community Discussion
No comments yet. Be the first to start the discussion!
A company has an AWS environment containing multiple VPCs connected through a transit gateway. The company has chosen AWS Site-to-Site VPN to establish connectivity between its on-premises network and its AWS environment.
The company does not have a static public IP address for its on-premises network. A network engineer must implement a solution that initiates the VPN connection from the AWS side for traffic from the AWS environment to the on-premises network.
Which combination of steps should the network engineer take to establish VPN connectivity between the transit gateway and the on-premises network?
Choose three
AConfigure the Site-to-Site VPN tunnel options to use Internet Key Exchange version 1 (IKEv1).
BConfigure the Site-to-Site VPN tunnel options to use Internet Key Exchange version 2 (IKEv2).
CUse a private certificate authority (CA) from AWS Private Certificate Authority to create a certificate.
DUse a public certificate authority (CA) from AWS Private Certificate Authority to create a certificate.
ECreate a customer gateway. Specify the current dynamic IP address of the customer gateway device’s external interface.
FCreate a customer gateway without specifying the IP address of the customer gateway device.
0
Community Discussion
No comments yet. Be the first to start the discussion!
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
0
Community Discussion
No comments yet. Be the first to start the discussion!
A company operates workloads across multiple VPCs. The company must securely access a workload in one of the VPCs, called VPC-A, from an on-premises data center. A network engineer establishes an AWS Site-to-Site VPN connection to a transit gateway. The network engineer configures dynamic routing for the connection, and communication functions correctly.
Recently, the owner of VPC-A added an additional CIDR range to the VPC. The VPC-A owner created workloads that use the added CIDR range.
The company's on-premises network cannot reach the new workloads. The network engineer must resolve the network connectivity issue and ensure that connectivity is not affected if more VPC CIDR ranges are added to the VPC in the future.
Which solution meets these requirements with the MOST operational efficiency?
AConfigure route propagation for VPC-A to the VPN attachment route table.
BManually update the VPN attachment route table to include the new CIDR range.
CConfigure an Amazon EventBridge rule to invoke an AWS Lambda function when the rule to matches an update to the VPC-A CIDR range. Configure the Lambda function to update the VPN attachment route table.
DConfigure an Amazon CloudWatch alarm to invoke an AWS Lambda function when there is an update to the VPC-A CIDR range. Configure the Lambda function to update the VPN attachment route table. Restart the VPN tunnels.
A company hosts an application on Amazon EC2 instances behind a Network Load Balancer (NLB). To increase application availability, a solutions architect added EC2 instances in a second Availability Zone and added those instances to the NLB target group.
The company’s operations team observes that traffic is routed only to the instances in the first Availability Zone.
What is the MOST operationally efficient solution to resolve this problem?
AEnable the new Availability Zone on the NLB
BCreate a new NLB for the instances in the second Availability Zone
CEnable proxy protocol on the NLB
DCreate a new target group with the instances in both Availability Zones
A company has AWS accounts within an AWS Organizations organization. It has implemented Amazon VPC IP Address Manager (IPAM) in its networking AWS account and uses AWS Resource Access Manager (AWS RAM) to share IPAM pools with the other AWS accounts. The company created a top-level pool with the CIDR block 10.0.0.0/8. Within that top-level pool, it created an IPAM pool for each AWS account.
A network engineer must implement a solution that ensures users in each AWS account cannot create new VPCs. The solution must also stop users from associating a CIDR block with an existing VPC unless that CIDR block comes from the IPAM pool for that account.
Which solution meets these requirements?
ACreate a new AWS Config rule to find all VPCs that are not configured to allocate their CIDR block from an IPAM pool. Invoke an AWS Lambda function to delete these VPCs.
BCreate a new SCP in Organizations. Add a condition that denies the CreateVpc and AssociateVpcCidrBlock Amazon EC2 actions if the Ipv4IpamPoolId context key value is not the ID of an IPAM pool.
CCreate an AWS Lambda function to check for and delete all VPCs that are not configured to allocate their CIDR block from an IPAM pool. Invoke the Lambda function at regular intervals.
DCreate an Amazon EventBridge rule to check for AWS CloudTrail events for the CreateVpc and AssociateVpcCidrBlock Amazon EC2 actions. Use the rule to invoke an AWS Lambda function to delete all VPCs that are not configured to allocate their CIDR block from an IPAM pool.
A company’s AWS infrastructure spans more than 50 accounts and five AWS Regions. The company needs to manage its security posture with simplified administration and maintenance across all AWS accounts. The company wants to use AWS Firewall Manager to manage firewall rules and requirements.
The company creates an organization with all features enabled in AWS Organizations.
Which combination of steps should the company take next to meet these requirements?
Choose three
AConfigure only the Firewall Manager administrator account to join the organization.
BConfigure all the accounts to join the organization.
CSet an account as the Firewall Manager administrator account.
DSet an account as the Firewall Manager child account.
ESet up AWS Config for all the accounts and all the Regions where the company has resources.
FSet up AWS Config for only the organization's management account.
A company operates hundreds of VPCs on AWS. Every VPC reaches the public endpoints of Amazon S3 and AWS Systems Manager through NAT gateways, and all VPC traffic to Amazon S3 and Systems Manager passes through those NAT gateways. The company's network engineer needs to centralize access to these services and eliminate the use of public endpoints.
Which solution satisfies these requirements with the LEAST operational overhead?
ACreate a central egress VPC that has private NAT gateways. Connect all the VPCs to the central egress VPC by using AWS Transit Gateway. Use the private NAT gateways to connect to Amazon S3 and Systems Manager by using private IP addresses.
BCreate a central shared services VPC. In the central shared services VPC, create interface VPC endpoints for Amazon S3 and Systems Manager to access. Ensure that private DNS is turned off. Connect all the VPCs to the central shared services VPC by using AWS Transit Gateway. Create an Amazon Route 53 forwarding rule for each interface VPC endpoint. Associate the forwarding rules with all the VPCs. Forward DNS queries to the interface VPC endpoints in the shared services VPC.
CCreate a central shared services VPIn the central shared services VPC, create interface VPC endpoints for Amazon S3 and Systems Manager to access. Ensure that private DNS is turned off. Connect all the VPCs to the central shared services VPC by using AWS Transit Gateway. Create an Amazon Route 53 private hosted zone with a full service endpoint name for Amazon S3 and Systems Manager. Associate the private hosted zones with all the VPCs. Create an alias record in each private hosted zone with the full AWS service endpoint pointing to the interface VPC endpoint in the shared services VPC.
DCreate a central shared services VPC. In the central shared services VPC, create interface VPC endpoints for Amazon S3 and Systems Manager to access. Connect all the VPCs to the central shared services VPC by using AWS Transit Gateway. Ensure that private DNS is turned on for the interface VPC endpoints and that the transit gateway is created with DNS support turned on.
A company has one VPC in the us-east-1 Region and plans to create a new VPC in the us-east-2 Region. The existing VPC has an AWS Site-to-Site VPN connection to the company’s on-premises environment that uses a virtual private gateway.
A network engineer must implement a solution that establishes connectivity between the existing VPC and the new VPC. The solution must also provide IPv6 support for the new VPC. New on-premises resources must connect to VPC resources by using IPv6 addresses.
Which solution meets these requirements?
ACreate a new virtual private gateway in us-east-1. Attach the new virtual private gateway to the new VPC. Create two new Site-to-Site VPN connections to the new virtual private gateway with IPv4 and IPv6 support. Configure routing between the VPCs by using VPC peering.
BCreate a transit gateway in us-east-1 and in us-east-2. Attach the existing VPC and the new VPC to each transit gateway. Create a new Site-to-Site VPN connection to each transit gateway with IPv4 and IPv6 support. Configure transit gateway peering. Configure routing between the VPCs and the on-premises environment.
CCreate a new virtual private gateway in us-east-2. Attach the new virtual private gateway to the new VPCreate two new Site-to-Site VPN connections to the new virtual private gateway with IPv4 and IPv6 support. Configure routing between the VPCs by using VPC peering.
DCreate a transit gateway in us-east-1. Attach the existing VPC and the new VPC to the transit gateway. Create two new Site-to-Site VPN connections to the transit gateway with IPv4 and IPv6 support. Configure transit gateway peering. Configure routing between the VPCs and the on-premises environment.
A company is rolling out AWS Cloud WAN with edge locations in the us-east-1 Region and the ap-southeast-2 Region. Separate AWS Cloud WAN segments are configured for the development environment, production environment, and shared services environment at each edge location. Many new VPCs will be deployed for these environments and configured as attachments to the AWS Cloud WAN core network.
The company’s network team needs to ensure that VPC attachments are configured for the appropriate segment. The team will tag VPC attachments with the Environment key and a value that matches the applicable environment segment name. The production environment segment in us-east-1 must require acceptance for attachment requests. All other attachment requests must not require acceptance.
Which solution meets these requirements?
ACreate a rule with a number of 100 that requires acceptance for attachments to the production segment. In the rule, set the condition logic to the "or" value. Include conditions that require a tag:Environment value of Production or a Region value of us-east-1. Create a rule with a number of 200 that does not require acceptance to map any tag:Environment values to their respective segments.
BCreate a rule with a number of 100 that requires acceptance for attachments to the production segment. In the rule, set the condition logic to the "and" value. Include conditions that require a tag:Environment value of Production and a Region value of us-east-1. Create a rule with a number of 200 that does not require acceptance to map any tag.Environment values to their respective segments.
CCreate a rule with a number of 100 that does not require acceptance to map any tag:Environment values to their respective segments. Create a rule with a number of 200 that requires acceptance for attachments to the production segment. In the rule, set the condition logic to the "and" value. Include conditions that require a tag:Environment value of Production and a Region value of us-east-1.
DCreate a rule with a number of 100 that does not require acceptance to map any tag:Environment values to their respective segments. Create a rule with a number of 200 that requires acceptance for attachments to the production segment. In the rule, set the condition logic to the "or" value. Include conditions that require a tag:Environment value of Production or a Region value of us-east-1.
An international company provides early warnings about tsunamis. The company plans to use IoT devices to monitor sea waves worldwide. Data collected by the IoT devices must reach the company’s infrastructure on AWS as quickly as possible. The company uses three operations centers around the world. Each operations center connects to AWS through its own AWS Direct Connect connection. Each operations center connects to the internet through at least two upstream internet service providers.
The company owns provider-independent (PI) address space. The IoT devices use TCP protocols to reliably transmit the data that they collect. The IoT devices have both landline and mobile internet connectivity. The infrastructure and solution will be deployed in multiple AWS Regions. The company will use Amazon Route 53 for DNS services.
A network engineer must design connectivity between the IoT devices and the services running in the AWS Cloud.
Which solution will meet these requirements with the HIGHEST availability?
ASet up an Amazon CloudFront distribution with origin failover. Create an origin group for each Region where the solution is deployed.
BSet up Route 53 latency-based routing. Add latency alias records. For the latency alias records, set the value of Evaluate Target Health to Yes.
CSet up an accelerator in AWS Global Accelerator. Configure Regional endpoint groups and health checks.
DSet up Bring Your Own IP (BYOIP) addresses. Use the same PI addresses for each Region where the solution is deployed.
A company maintains an AWS Site-to-Site VPN connection between AWS and its branch office. A network engineer is investigating connectivity problems affecting the connection. The VPN connection terminates on a transit gateway and uses static routing. The transit gateway route table contains several static routes that target particular subnets in the branch office.
The network engineer identifies the root cause as expansion of the underlying subnet ranges at the branch office during routine maintenance.
Which solution will resolve this issue with the LEAST administrative overhead for future expansion efforts?
ADetermine a supernet for the branch office. In the transit gateway route table, add an aggregate route that targets the VPN attachment. Replace the specific subnet routes in the transit gateway route table with the new supernet route.
BCreate an AWS Direct Connect gateway and a transit VIF. Associate the Direct Connect gateway with the transit gateway. Create a propagation for the Direct Connect attachment to the transit gateway route table.
CCreate a dynamically routed VPN connection on the transit gateway. Connect the dynamically routed VPN connection to the branch office. Create a propagation for the VPN attachment to the transit gateway route table. Remove the existing static VPN connection.
DCreate a prefix list that contains the new subnets and the old subnets for the branch office. Remove the specific subnet routes in the transit gateway route table. Create a prefix list reference in the transit gateway route table.
A gaming company runs in a single AWS Region. Its architecture includes an Application Load Balancer (ALB) and Amazon EC2 instances in an Auto Scaling group that host a frontend application. The company uses AWS WAF integrated with the ALB. The ALB has one security group associated with it. The company uses AWS Network Firewall with stateful rules. The company has configured Network ACLs.
The company needs to automatically block access for game users who violate particular rules. Problematic users must be blocked temporarily for 1 to 2 hours. The company’s software can identify the source IP addresses of problematic users. The company has built a serverless solution to store those IP addresses in Amazon DynamoDB.
The company wants to use its existing serverless architecture to automatically block the problematic users.
Which solution meets these requirements in the MOST scalable way?
Choose two
ACreate a new AWS WAF IP set that the serverless solution updates. Introduce an AWS WAF deny rule to block traffic from any address in the IP set.
BConfigure the serverless solution to modify the network ACLs to block traffic from the IP addresses of the problematic users.
CConfigure the serverless solution to modify the ALB security group to block traffic from the IP addresses of the problematic users.
DCreate a new AWS WAF IP set that is updated by the serverless solution. Create an AWS WAF rule to redirect traffic from sources that match the IP set to a new API for the serverless solution.
ECreate an AWS Network Firewall stateless rule to drop traffic from the IP addresses of the problematic users. Configure the serverless solution to update the new rule with the IP addresses of the problematic users.
A company’s data center connects to a single AWS Region through an AWS Direct Connect dedicated connection. The company has one VPC in that Region and stores logs for all its applications locally in the data center.
The company must retain all application logs for 7 years. It decides to copy all application logs to an Amazon S3 bucket.
Which solution meets these requirements?
ACreate a public VIF on the Direct Connect connection. Create an Amazon S3 gateway endpoint in the VPC.
BCreate a private VIF on the Direct Connect connection. Create an Amazon S3 gateway endpoint in the VPC.
CCreate a private VIF on the Direct Connect connection. Create an Amazon S3 interface endpoint in the VPC.
DCreate a public VIF on the Direct Connect connection. Create an Amazon S3 interface endpoint in the VPC.
A company operates a hybrid cloud environment. Its data center connects to the AWS Cloud through an AWS Direct Connect connection. The AWS environment includes VPCs connected in a hub-and-spoke model by a transit gateway. The AWS environment uses a transit VIF with a Direct Connect gateway for on-premises connectivity.
The company uses a hybrid DNS model. It has configured Amazon Route 53 Resolver endpoints in the hub VPC to permit bidirectional DNS traffic flow. The company runs a backend application in one of the VPCs.
The company uses a message-oriented architecture and uses Amazon Simple Queue Service (Amazon SQS) to receive messages from other applications over a private network. A network engineer wants to use an interface VPC endpoint for Amazon SQS for this architecture. Client services must be able to access the endpoint service from on premises and from multiple VPCs in the company's AWS infrastructure.
Which combination of actions should the network engineer take to ensure that the client applications can resolve DNS for the interface endpoint?
Choose three
ACreate the interface endpoint for Amazon SQS with the option for private DNS names turned on.
BCreate the interface endpoint for Amazon SQS with the option for private DNS names turned off.
CManually create a private hosted zone for sqs.us-east-1.amazonaws.com. Add necessary records that point to the interface endpoint. Associate the private hosted zones with other VPCs.
DUse the automatically created private hosted zone for sqs.us-east-1.amazonaws.com with previously created necessary records that point to the interface endpoint. Associate the private hosted zones with other VPCs.
EAccess the SQS endpoint by using the public DNS name sqs.us-east-1 amazonaws.com in VPCs and on premises.
FAccess the SQS endpoint by using the private DNS name of the interface endpoint .sqs.us-east-1.vpce.amazonaws.com in VPCs and on premises.
A company runs its IT services in a multi-site hybrid infrastructure. The company deploys resources on AWS in the us-east-1 Region and the eu-west-2 Region. It also deploys resources in its own data centers in the United States (US) and the United Kingdom (UK). In both AWS Regions, the company uses a transit gateway to interconnect 15 VPCs. The company has established a transit gateway peering connection between the two transit gateways. The VPC CIDR blocks do not overlap with one another or with IP addresses used in the data centers. The VPC CIDR prefixes can be aggregated either at a Regional level or across the company's entire AWS environment.
The data centers connect to each other through a private WAN connection. IP routing information is dynamically exchanged through Interior BGP (iBGP) sessions. The data centers retain connectivity to AWS by using one AWS Direct Connect connection in the US and one Direct Connect connection in the UK. Each Direct Connect connection terminates on a Direct Connect gateway and is associated with its local transit gateway through a transit VIF.
Traffic takes the shortest geographic path from source to destination. For example, packets from the UK data center that target resources in eu-west-2 traverse the local Direct Connect connection. For cross-Region data transfers, such as from the UK data center to VPCs in us-east-1, the private WAN connection must be used to minimize AWS costs. A network engineer has configured each transit gateway association on the Direct Connect gateway to advertise VPC-specific CIDR IP prefixes only for the local Region. Routes to the other Region must be learned through BGP from routers in the other data center in their original, non-aggregated form.
The company recently had a cross-Region data-transfer issue because of problems with its private WAN connection. The network engineer must modify the routing configuration to avoid similar disruptions in the future. The solution must not change the original traffic-routing goal during normal operation.
Which modifications meet these requirements?
Choose two
ARemove all the VPC CIDR prefixes from the list of subnets advertised through the local Direct Connect connection. Add the company's entire AWS environment aggregate route to the list of subnets advertised through the local Direct Connect connection.
BAdd the CIDR prefixes from the other Region VPCs and the local VPC CIDR blocks to the list of subnets advertised through the local Direct Connect connection. Configure data center routers to make routing decisions based on the BGP communities received.
CAdd the aggregate IP prefix for the other Region and the local VPC CIDR blocks to the list of subnets advertised through the local Direct Connect connection.
DAdd the aggregate IP prefix for the company's entire AWS environment and the local VPC CIDR blocks to the list of subnets advertised through the local Direct Connect connection.
ERemove all the VPC CIDR prefixes from the list of subnets advertised through the local Direct Connect connection. Add both Regional aggregate IP prefixes to the list of subnets advertised through the Direct Connect connection on both sides of the network. Configure data center routers to make routing decisions based on the BGP communities received.
A company runs a corporate website on Amazon EC2 instances behind a Network Load Balancer (NLB). The NLB has a single TLS listener.
The company wants to improve website security by using AWS WAF.
Which solution satisfies this requirement?
AAttach an Elastic IP address to the NLB. Associate an AWS WAF web ACL with the Elastic IP address.
BReplace the NLB with an Application Load Balancer (ALB). Associate an AWS WAF web ACL with the ALB.
CAssociate an AWS WAF web ACL with the NLB.
DAssociate an AWS WAF web ACL with the EC2 instances that are behind the NLB.
A company deployed an application in a VPC that uses a NAT gateway for outbound internet traffic. A network engineer observes a large volume of suspicious network traffic leaving the VPC over the internet for IP addresses on a deny list. The engineer must implement a solution to identify which AWS resources are producing the suspicious traffic. The solution must minimize cost and administrative overhead.
Which solution meets these requirements?
ALaunch an Amazon EC2 instance in the VPC. Use Traffic Mirroring by specifying the NAT gateway as the source and the EC2 instance as the destination. Analyze the captured traffic by using open-source tools to identify the AWS resources that are generating the suspicious traffic.
BUse VPC flow logs. Launch a security information and event management (SIEM) solution in the VPC. Configure the SIEM solution to ingest the VPC flow logs. Run queries on the SIEM solution to identify the AWS resources that are generating the suspicious traffic.
CUse VPC flow logs. Publish the flow logs to a log group in Amazon CloudWatch Logs. Use CloudWatch Logs Insights to query the flow logs to identify the AWS resources that are generating the suspicious traffic.
DConfigure the VPC to stream the network traffic directly to an Amazon Kinesis data stream. Send the data from the Kinesis data stream to an Amazon Kinesis Data Firehose delivery stream to store the data in Amazon S3. Use Amazon Athena to query the data to identify the AWS resources that are generating the suspicious traffic.
A company is relocating its on-premises network from its Virginia data center to its New York data center. The AWS Direct Connect connections for both the Virginia and New York data-center locations are associated with the us-east-1 Region. The company must move a private VIF on an existing Direct Connect hosted connection from Virginia to New York. The company's on-premises network uses this connection to access VPCs through a Direct Connect gateway in us-east-1.
The company has already requested a new Direct Connect hosted connection from the new data center to the New York Direct Connect location.
Which solution satisfies these requirements with the LEAST downtime?
ACreate a new private VIF on the new Direct Connect hosted connection. Create a new Direct Connect gateway and attach the gateway to the new private VIF. Configure BGP routing on the new private VIF as a backup route. Perform the switchover during a maintenance window by shutting down BGP on the existing private VIF. Decommission the existing Direct Connect connection.
BCreate a new private VIF on the new Direct Connect hosted connection. Attach the new private VIF to the existing Direct Connect gateway. Configure BGP routing on the new private VIF as a backup route. Perform the switchover during a maintenance window by shutting down BGP on the existing private VIF. Decommission the existing Direct Connect connection.
CDuring a maintenance window, migrate the existing private VIF to the new Direct Connect hosted connection. Attach the existing private VIF to the existing Direct Connect gateway. Decommission the existing Direct Connect connection.
DDuring a maintenance window, delete the existing private VIF and create a new private VIF to the new Direct Connect hosted connection. Attach the new private VIF to the existing Direct Connect gateway. Decommission the existing Direct Connect hosted connection.
A network engineer must update a company’s hybrid network to support IPv6 for an upcoming release of a new application. The application is hosted in a VPC in the AWS Cloud. The company’s existing AWS infrastructure includes VPCs connected through a transit gateway. The transit gateway connects to the on-premises network through AWS Direct Connect and AWS Site-to-Site VPN. The company’s on-premises devices have been updated to meet the new IPv6 requirements.
The company has enabled IPv6 for the existing VPC by assigning a new IPv6 CIDR block to the VPC and assigning IPv6 addresses to the subnets for dual-stack support. The company has launched new Amazon EC2 instances for the new application in the updated subnets.
When updating the hybrid network for IPv6, the network engineer must avoid changes to the current infrastructure. The network engineer must also prevent direct internet access to the instances’ new IPv6 addresses while allowing the instances outbound internet access.
What is the MOST operationally efficient solution that meets these requirements?
AUpdate the Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6 peering address. Create a new VPN connection that supports IPv6 connectivity. Add an egress-only internet gateway. Update any affected VPC security groups and route tables to provide connectivity within the VPC and between the VPC and the on-premises devices
BUpdate the Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6 peering address. Update the existing VPN connection to support IPv6 connectivity. Add an egress-only internet gateway. Update any affected VPC security groups and route tables to provide connectivity within the VPC and between the VPC and the on-premises devices.
CCreate a Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6 peering address. Create a new VPN connection that supports IPv6 connectivity. Add an egress-only internet gateway. Update any affected VPC security groups and route tables to provide connectivity within the VPC and between the VPC and the on-premises devices.
DCreate a Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6 peering address. Create a new VPN connection that supports IPv6 connectivity. Add a NAT gateway. Update any affected VPC security groups and route tables to provide connectivity within the VPC and between the VPC and the on-premises devices.
A network engineer must design an architecture for a high-performance computing (HPC) workload. Amazon EC2 instances will need 10 Gbps flows and aggregate throughput of up to 100 Gbps across numerous instances, with low-latency communication.
Which architecture solution will optimize this workload?
APlace nodes in a single subnet of a VPC. Configure a cluster placement group. Ensure that the latest Elastic Fabric Adapter (EFA) drivers are installed on the EC2 instances with a supported operating system.
BPlace nodes in multiple subnets in a single VPC. Configure a spread placement group. Ensure that the EC2 instances support Elastic Network Adapters (ENAs) and that the drivers are updated on each instance operating system.
CPlace nodes in multiple VPCs Use AWS Transit Gateway to route traffic between the VPCs. Ensure that the latest Elastic Fabric Adapter (EFA) drivers are installed on the EC2 instances with a supported operating system.
DPlace nodes in multiple subnets in multiple Availability Zones. Configure a cluster placement group. Ensure that the EC2 instances support Elastic Network Adapters (ENAs) and that the drivers are updated on each instance operating system.
A company provides applications over the internet. An Amazon Route 53 public hosted zone serves as the authoritative DNS service for the company and its internet applications, which are all offered under the same domain name.
A network engineer is developing a new version of one application. Every application component is hosted in the AWS Cloud. The application uses a three-tier architecture. Its front end is served by Amazon EC2 instances deployed in public subnets and assigned Elastic IP addresses. Its backend components are deployed in private subnets using RFC1918 addresses.
Application components must be able to access other components within the application's VPC by using the same host names that are used on the public internet. The network engineer must also support future DNS changes, including adding new host names or retiring DNS entries.
Which combination of steps will satisfy these requirements?
Choose three
AAdd a geoproximity routing policy in Route 53.
BCreate a Route 53 private hosted zone for the same domain name Associate the application’s VPC with the new private hosted zone.
CEnable DNS hostnames for the application's VPC.
DCreate entries in the private hosted zone for each name in the public hosted zone by using the corresponding private IP addresses.
ECreate an Amazon EventBridge (Amazon CloudWatch Events) rule that runs when AWS CloudTrail logs a Route 53 API call to the public hosted zone. Create an AWS Lambda function as the target of the rule. Configure the function to use the event information to update the private hosted zone.
FAdd the private IP addresses in the existing Route 53 public hosted zone.
A company operates a hybrid cloud environment and has multiple AWS accounts within an AWS Organizations organization. The company requires a solution to manage a list of on-premises IPv4 hosts that are permitted to access AWS resources. The solution must provide version control for the IPv4 address list and make the list available to the AWS accounts in the organization.
Which solution meets these requirements?
ACreate a customer-managed prefix list. Add entries for the initial list of on-premises IPv4 hosts. Create a resource share in AWS Resource Access Manager. Add the managed prefix list to the resource share. Share the resource with the organization.
BCreate a customer-managed prefix list. Add entries for the initial list of on-premises IPv4 hosts. Use AWS Firewall Manager to share the managed prefix list with the organization.
CCreate a security group. Add inbound rule entries for the initial list of on-premises IPv4 hosts. Create a resource share in AWS Resource Access Manager. Add the security group to the resource share. Share the resource with the organization.
DCreate an Amazon DynamoDB table. Add entries for the initial list of on-premises IPv4 hosts. Create an AWS Lambda function that assumes a role in each AWS account in the organization to authorize inbound rules on security groups based on entries from the DynamoDB table.
Community Discussion