Table of Contents:

Latest AWS Certified Advanced Networking – Specialty (ANS-C00) exam List

AWS Certified Advanced Networking – Specialty: https://aws.amazon.com/certification/certified-advanced-networking-specialty/

[2020.6] AWS Certified Advanced Networking – Specialty (ANS-C00) exam practice questions(1-5)

You are preparing to launch Amazon WorkSpaces and need to configure the appropriate networking resources. What
must be configured to meet this requirement?
A. At least two subnets in different Availability Zones.
B. A dedicated VPC with Active Directory Services.
C. An IPsec VPN to on-premises Active Directory
D. Network address translation for outbound traffic.
Correct Answer: AD
References: https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-vpc.html


An AWS CloudFormation template is being used to create a VPC peering connection between two existing operational
VPCs, each belonging to a different AWS account. All necessary components in the `Remote\\’ (receiving) account are
already in place.
The template below creates the VPC peering connection in the Originating account. It contains these components:examthings ANS-C00 q2

Which additional AWS CloudFormation components are necessary in the Originating account to create an operational
cross-account VPC peering connection with AWS CloudFormation? (Choose two.)

examthings ANS-C00 q2-1

A. Option A
B. Option B
C. Option C
D. Option D
E. Option E
Correct Answer: DE


You have been asked to monitor traffic flows on your Amazon EC2 instance. You will be performing deep packet
inspection, looking for atypical patterns. Which tool will enable you to look at this data?
A. Wireshark
B. VPC Flow Logs
D. CloudWatch Logs
Correct Answer: A
References: https://www.slideshare.net/TeriRadichel/packet-capture-on-aws

You have a three-tier web application with separate subnets for Web, Applications, and Database tiers. Your CISO
suspects your application will be the target of malicious activity. You are tasked with notifying the security team in the
event your application is port scanned by external systems.
Which two AWS Services cloud you leverage to build an automated notification system? (Choose two.)
A. Internet gateway
B. VPC Flow Logs
C. AWS CloudTrail
D. Lambda
E. AWS Inspector
Correct Answer: CD
References: https://aws.amazon.com/blogs/security/how-to-receive-alerts-when-specific-apis-are-called-by-using-awscloudtrail-amazon-sns-and-aws-lambda/


A Network Engineer is provisioning a subnet for a load balancer that will sit in front of a fleet of application servers in a
private subnet. There is limited IP space left in the VPC CIDR. The application has few users now but is expected to
grow quickly to millions of users.
What design will use the LEAST amount of IP space, while allowing for this growth?
A. Use two /29 subnets for an Application Load Balancer in different Availability Zones.
B. Use one /29 subnet for the Network Load Balancer. Add another VPC CIDR to the VPC to allow for future growth.
C. Use two /28 subnets for a Network Load Balancer in different Availability Zones.
D. Use a one /28 subnet for an Application Load Balancer. Add another VPC CIDR to the VPC to allow for future growth.
Correct Answer: D

Latest AWS Certified Database – Specialty (DBS-C01) exam List

AWS Certified Database – Specialty Certification:https://aws.amazon.com/certification/certified-database-specialty/

[2020.6] AWS Certified Database – Specialty (DBS-C01) exam practice questions (1-5)

An IT consulting company wants to reduce costs when operating its development environment databases. The
company\\’s workflow creates multiple Amazon Aurora MySQL DB clusters for each development group. The Aurora DB
are only used for 8 hours a day. The DB clusters can then be deleted at the end of the development cycle, which lasts 2
Which of the following provides the MOST cost-effective solution?
A. Use AWS CloudFormation templates. Deploy a stack with the DB cluster for each development group. Delete the
stack at the end of the development cycle.
B. Use the Aurora DB cloning feature. Deploy a single development and test Aurora DB instance, and create clone
instances for the development groups. Delete the clones at the end of the development cycle.
C. Use Aurora Replicas. From the master, automatic pause computes capacity option, create replicas for each
development group, and promote each replica to master. Delete the replicas at the end of the development cycle.
D. Use Aurora Serverless. Restore the current Aurora snapshot and deploy to a serverless cluster for each development
group. Enable the option to pause the compute capacity on the cluster and set an appropriate timeout.
Correct Answer: D


A Database Specialist is working with a company to launch a new website built on Amazon Aurora with several Aurora
Replicas. This new website will replace an on-premises website connected to a legacy relational database. Due to
issues in the legacy database, the company would like to test the resiliency of Aurora.
Which action can the Database Specialist take to test the resiliency of the Aurora DB cluster?
A. Stop the DB cluster and analyze how the website responds
B. Use Aurora fault injection to crash the master DB instance
C. Remove the DB cluster endpoint to simulate a master DB instance failure
D. Use Aurora Backtrack to crash the DB cluster
Correct Answer: B
Reference: https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/AuroraMySQL.Managing.FaultInjectionQueries.html


A global digital advertising company captures browsing metadata to contextually display relevant images, pages, and
links to targeted users. A single page load can generate multiple events that need to be stored individually. The
maximum size of an event is 200 KB and the average size is 10 KB. Each page load must query the user\\’s browsing
history to provide targeting recommendations. The advertising company expects over 1 billion page visits per day from
users in the United States, Europe, Hong Kong, and India. The structure of the metadata varies depending on the event.
Additionally, the browsing metadata must be written and read with very low latency to ensure a good viewing experience
for the users.
Which database solution meets these requirements?
A. Amazon DocumentDB
B. Amazon RDS Multi-AZ deployment
C. Amazon DynamoDB global table
D. Amazon Aurora Global Database
Correct Answer: C
Reference: https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/GlobalTables.html


A company is looking to move an on-premises IBM Db2 database running AIX on an IBM POWER7 server. Due to
escalating support and maintenance costs, the company is exploring the option of moving the workload to an Amazon
PostgreSQL DB cluster.
What is the quickest way for the company to gather data on the migration compatibility?
A. Perform a logical dump from the Db2 database and restore it to an Aurora DB cluster. Identify the gaps and
compatibility of the objects migrated by comparing row counts from source and target tables.
B. Run AWS DMS from the Db2 database to an Aurora DB cluster. Identify the gaps and compatibility of the objects
migrated by comparing the row counts from source and target tables.
C. Run native PostgreSQL logical replication from the Db2 database to an Aurora DB cluster to evaluate the migration
D. Run the AWS Schema Conversion Tool (AWS SCT) from the Db2 database to an Aurora DB cluster. Create a
migration assessment report to evaluate the migration compatibility.
Correct Answer: D
Reference: https://docs.aws.amazon.com/SchemaConversionTool/latest/userguide/Schema-Conversion-Tool.pdf


A Database Specialist needs to speed up any failover that might occur on an Amazon Aurora PostgreSQL DB cluster.
The Aurora DB cluster currently includes the primary instance and three Aurora Replicas. How can the Database
The specialist ensures that failovers occur with the least amount of downtime for the application?
A. Set the TCP keepalive parameters low
B. Call the AWS CLI failover-dB-cluster command
C. Enable Enhanced Monitoring on the DB cluster
D. Start a database activity stream on the DB cluster
Correct Answer: B

Latest AWS Certified Developer – Associate (DVA-C01) exam List

AWS Certified Developer – Associate Certification:https://aws.amazon.com/certification/certified-developer-associate/

[2020.6] AWS Certified Developer – Associate (DVA-C01) exam practice questions (1-5)

A Developer has written a serverless application using multiple AWS services. The business logic is written as a
Lambda function which has dependencies on third-party libraries. The Lambda function endpoints will be exposed using
Amazon API Gateway. The Lambda function will write the information to Amazon DynamoDB. The Developer is ready to
deploy the application but must have the ability to rollback. How can this deployment be automated, based on these
A. Deploy using Amazon Lambda API operations to create the Lambda function by providing a deployment package.
B. Use an AWS CloudFormation template and use CloudFormation syntax to define the Lambda function resource in
the template.
C. Use syntax conforming to the Serverless Application Model in the AWS CloudFormation template to define the
Lambda function resource.
D. Create a bash script that uses AWS CLI to package and deploy the application.
Correct Answer: A
Reference: https://docs.aws.amazon.com/lambda/latest/dg/automating-deployment.html


A company is running an application built on AWS Lambda functions. One Lambda function has performance issues
when it has to download a 50MB file from the Internet in every execution. This function is called multiple times a second.
What solution would give the BEST performance increase?
A. Cache the file in the /temp directory
B. Increase the Lambda maximum execution time
C. Put an Elastic Load Balancer in front of the Lambda function
D. Cache the file in Amazon S3
Correct Answer: D


A company runs an e-commerce website that uses Amazon DynamoDB where pricing for items is dynamically updated
in real-time. At any given time, multiple updates may occur simultaneously for pricing information on a particular product.
This is causing the original editor\\’s changes to be overwritten without a proper review process.
Which DynamoDB write option should be selected to prevent this overwriting?
A. Concurrent writes
B. Conditional writes
C. Atomic writes
D. Batch writes
Correct Answer: B


A Software Engineer developed an AWS Lambda function in Node.js to do some CPU-intensive data processing. With
the default settings, the Lambda function takes about 5 minutes to complete. Which approach should a Developer take
to increase the speed of completion?
A. Instead of using Node.js, rewrite the Lambda function using Python.
B. Instead of packaging the libraries in the ZIP file with the function, move them to a Lambda layer and use the layer
with the function.
C. Allocate the maximum available CPU units to the function.
D. Increase the available memory to the function.
Correct Answer: D
Reference: https://serverless.zone/my-accidental-3-5x-speed-increase-of-aws-lambda-functions-6d95351197f3


An application under development is required to store hundreds of video files. The data must be encrypted within the
application prior to storage, with a unique key for each video file. How should the Developer code the application?
A. Use the KMS Encrypt API to encrypt the data. Store the encrypted data key and data.
B. Use a cryptography library to generate an encryption key for the application. Use the encryption key to encrypt the
data. Store the encrypted data.
C. Use the KMS GenerateDataKey API to get a data key. Encrypt the data with the data key. Store the encrypted data
key and data.
D. Upload the data to an S3 bucket using server side-encryption with an AWS KMS key.
Correct Answer: B

Latest AWS Certified Cloud Practitioner (CLF-C01) exam List

AWS Certified Cloud Practitioner:https://aws.amazon.com/certification/certified-cloud-practitioner/

[2020.6] AWS Certified Cloud Practitioner (CLF-C01) exam practice questions (1-5)

Which of the following is an AWS Cloud architecture design principle?
A. Implement single points of failure.
B. Implement loose coupling.
C. Implement a monolithic design.
D. Implement vertical scaling.
Correct Answer: B
Loose coupling between services can also be done through asynchronous integration. It involves one component that
generates events and another that consumes them. The two components do not integrate through direct point-to-point
interaction, but usually through an intermediate durable storage layer. This approach decouples the two components
and introduces additional resiliency. So, for example, if a process that is reading messages from the queue fails,
messages can still be added to the queue to be processed when the system recovers.
Reference: https://www.botmetric.com/blog/aws-cloud-architecture-design-principles/


Under the AWS shared responsibility model, AWS is responsible for which security-related task?
A. Lifecycle management of IAM credentials
B. Physical security of the global infrastructure
C. Encryption of Amazon EBS volumes
D. Firewall configuration
Correct Answer: B
Reference: https://cloudacademy.com/blog/aws-shared-responsibility-model-security/


A user needs an automated security assessment report that will identify unintended network access to Amazon EC2
instances and vulnerabilities in those instances. Which AWS service will provide this assessment report?
A. EC2 security groups
B. AWS Config
C. Amazon Macie
D. Amazon Inspector
Correct Answer: D
Amazon Inspector is an automated security assessment service that helps improve the security and compliance of
applications deployed on AWS. Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and
deviations from best practices. After performing an assessment, Amazon Inspector produces a detailed list of security
findings prioritized by level of severity. These findings can be reviewed directly or as part of detailed assessment reports
which are available via the Amazon Inspector console or API.
Reference: https://aws.amazon.com/inspector/


How do customers benefit from Amazon\\’s massive economies of scale?
A. Periodic price reductions as the result of Amazon\\’s operational efficiencies
B. New Amazon EC2 instance types providing the latest hardware
C. The ability to scale up and down when needed
D. Increased reliability in the underlying hardware of Amazon EC2 instances
Correct Answer: A


A company is migrating from on-premises data centers to the AWS Cloud and is looking for hands-on help with the
project. How can the company get this support? (Choose two.)
A. Ask for a quote from the AWS Marketplace team to perform a migration into the company\\’s AWS account.
B. Contact AWS Support and open a case for assistance
C. Use AWS Professional Services to provide guidance and to set up an AWS Landing Zone in the company\\’s AWS
D. Select a partner from the AWS Partner Network (APN) to assist with the migration
E. Use Amazon Connect to create a new request for proposal (RFP) for expert assistance in migrating to the AWS
Correct Answer: BC
Reference: https://aws.amazon.com/solutions/aws-landing-zone/

