QuestionQ1
Security and ComplianceA company intends to host a public web application on Amazon EC2 instances behind an Elastic Load Balancing (ELB) load balancer. The company’s security team wants to secure the website with AWS Certificate Manager (ACM) certificates. The load balancer must automatically redirect all HTTP requests to HTTPS.
Which solution meets these requirements?
QuestionQ2
Deployment, Provisioning, and AutomationA CloudOps engineer is reviewing the following AWS CloudFormation template:

Why does creation of the stack fail?
Community Discussion
QuestionQ3
Reliability and Business ContinuityA company is implementing Cross-Region Replication (CRR) for its Amazon S3 buckets. The S3 buckets are in the us-east-1 Region. The company uses server-side encryption with Amazon S3 managed keys (SSE-S3) to protect the data in the buckets.
A CloudOps engineer creates a new AWS account to store backups in S3 buckets. All backup buckets are in the us-west-2 Region. The CloudOps engineer enables versioning on both the source buckets and destination buckets. The CloudOps engineer creates an IAM role in the source account for s3.amazonaws.com. The CloudOps engineer grants the IAM role permissions to perform read actions in the source buckets, replicate actions in the destination buckets, and encrypt actions using the destination bucket's key. The destination bucket policy allows the IAM role to perform replicate and read actions.
After completing the replication configuration, the CloudOps engineer notices that objects are not replicating.
What is the likely reason that the objects are not replicating?
Community Discussion
QuestionQ4
Security and ComplianceA CloudOps engineer needs to create an IAM policy for a developer who requires access to particular AWS services. Based on these requirements, the CloudOps engineer creates the following policy:

Which actions are allowed by this policy?
Community Discussion
QuestionQ5
Networking and Content DeliveryA CloudOps engineer created a VPC containing a public subnet and a private subnet. Amazon EC2 instances launched in the private subnet cannot reach the internet. The default network ACL is active for every subnet in the VPC, and every security group permits all outbound traffic.
Which solution will give the EC2 instances in the private subnet internet access?
Community Discussion