May 19, 2017

Q31. A user has created a new EBS volume from an existing snapshot. The user mounts the volume on the instance to which it is attached. Which of the below mentioned options is a required step before the user can mount the volume?

A. Run a cyclic check on the device for data consistency

B. Create the file system of the volume

C. Resize the volume as per the original snapshot size

D. No step is required. The user can directly mount the device

Answer: D


When a user is trying to mount a blank EBS volume, it is required that the user first creates a file system within the volume. If the volume is created from an existing snapshot then the user needs not to create a file system on the volume as it will wipe out the existing data.

Reference:       http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-using-volumes.htmI

Q32. Doug has created a VPC with CIDR in his AWS account. In this VPC he has created a public subnet with CIDR block While launching a new EC2 from the console, he is not able to assign the private IP address to this instance. Which is the most likely reason for this issue?

A. Private IP address is not part of the associated subnet's IP address range.

B. Private IP address is blocked via ACLs in Amazon infrastructure as a part of platform security.

C. Private address IP is currently assigned to another interface.

D. Private IP address is reserved by Amazon for IP networking purposes. 

Answer: C


In Amazon VPC, you can assign any Private IP address to your instance as long as it is: Part of the associated subnet's IP address range

Not reserved by Amazon for IP networking purposes Not currently assigned to another interface Reference: http://aws.amazon.com/vpc/faqs/

Q33. When you register an actMty in Amazon SWF, you provide the following information, except:

A. a name

B. timeout values

C. a domain

D. version 

Answer: C


When designing an Amazon SWF workflow, you precisely define each of the required actMties. You then register each actMty with Amazon SWF as an actMty type. When you register the actMty, you provide information such as a name and version, and some timeout values based on how long you expect the actMty to take.

Reference:        http://docs.aws.amazon.com/amazonswf/latest/developerguide/swf-dg-intro-to-swf.html

Q34. A user is trying to share a video file with all his friends. Which of the below mentioned AWS services will be cheapest and easy to use?




D. AWS Glacier 

Answer: C


AWS RRS provides the same functionality as AWS S3, but at a cheaper rate. It is ideally suited for non mission critical applications. It provides less durability than S3, but is a cheaper option.

Reference:      http://docs.aws.amazon.com/AmazonS3/Iatest/dev/UsingRRS.htmI

Q35. When using Amazon SQS how much data can you store in a message?

A. 8 KB

B. 2 KB

C. 16 KB

D. 4 KB



With Amazon SQS version 2008-01-01, the maximum message size for both SOAP and Query requests is 8KB.

If you need to send messages to the queue that are larger than 8 KB, AWS recommends that you split the information into separate messages. Alternatively, you could use Amazon S3 or Amazon Simp|eDB to hold the information and include the pointer to that information in the Amazon SQS message.

If you send a message that is larger than 8KB to the queue, you will receive a MessageTooLong error with HTTP code 400.

Reference: https://aws.amazon.com/items/1343?externaI|D=1343

Q36. A user has created an EBS instance in the US-East-1a AZ. The user has a volume of 30 GB in the US-East-1 b zone. How can the user attach the volume to an instance?

A. Since both the volume and the instance are in the same region, the user can attach the volume

B. Use the volume migrate function to move the volume from one AZ to another and attach to the instance

C. Take a snapshot of the volume. Create a new volume in the USEast-1a and attach that to the instance

D. Use the volume replicate function to create a new volume in the US-East-1a and attach that to the volume



If an EBS volume is not in the same AZ of an EC2 instance, it cannot be attached to the instance. The only option is to take a snapshot of the volume and create a new volume in the instance’s AZ. Reference:       http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSSnapshots.htmI

Q37. When you use the AWS Elastic Beanstalk console to deploy a new application you’II need to upload a source bundle and it should .

A. Consist of a single .zip file

B. Consist of a single .war file

C. Consist of a single .zip file or .war file

D. Consist of a folder with all files 

Answer: C


When you use the AWS Elastic Beanstalk console to deploy a new application or an application version, you’II need to upload a source bundle. Your source bundle must meet the following requirements: Consist of a single .zip file or .war file

Not exceed 512 MB

Not include a parent folder or top-level directory (subdirectories are fine) Reference:


Q38. Which of the below mentioned options is not a best practice to securely manage the AWS access credentials?

A. Enable MFA for prMleged users

B. Create indMdual IAM users

C. Keep rotating your secure access credentials at regular intervals

D. Create strong access key and secret access key and attach to the root account 

Answer: D


It is a recommended approach to avoid using the access and secret access keys of the root account.

Thus, do not download or delete it. Instead make the IAM user as powerful as the root account and use its credentials. The user cannot generate their own access and secret access keys as they are always  generated by AWS.

Reference:       http://docs.aws.amazon.com/IAM/latest/UserGuide/IAMBestPractices.html

Q39. Can one instance be registered with two ELBs in the same region?

A. No

B. Yes, provided both ELBs have the same health check configuration

C. Yes, always

D. Yes, provided both ELBs are in the same AZ 

Answer: C


Yes, it is possible to have one instance part of two separate ELBs, though both ELBs have different configurations. ELBs are never launched in specific zones.



Q40. An orgAMzation has launched two applications: one for blogging and one for ECM on the same AWS Linux EC2 instance running in the AWS VPC. The orgAMzation has attached two private IPs (primary and secondary) to the above mentioned instance. The orgAMzation wants the instance OS to recognize the secondary IP address. How can the orgAMzation configure this?

A. Use the ec2-net-utility package which updates routing tables, uses DHCP to refresh the secondary IP and adds the network interface.

B. Use the ec2-net-utils package which will configure an additional network interface and update the routing table

C. Use the ec2-ip-update package which can configure the network interface as well as update the secondary IP with DHCP.

D. Use the ec2-ip-utility package which can update the routing tables as well as refresh the secondary IP using DHCP.



A Virtual Private Cloud (VPC) is a virtual network dedicated to the user’s AWS account. It enables the

user to launch AWS resources into a virtual network that the user has defined. With VPC the user can specify multiple private IP addresses for his instances.

The number of network interfaces and private IP addresses that a user can specify for an instance depends on the instance type. This scenario helps when the user wants to host multiple websites on a single EC2 instance. After the user has assigned a secondary private IP address to his instance, he   needs to configure the operating system on that instance to recognize the secondary private IP address. For AWS Linux, the ec2-net-utils package can take care of this step. It configures additional network interfaces that the user can attach while the instance is running, refreshes secondary IP addresses during DHCP lease renewal, and updates the related routing rules.

Reference:       http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/MuItipIeIP.html

