Exam Details

  • Exam Code
    :SAP-C01
  • Exam Name
    :AWS Certified Solutions Architect - Professional (SAP-C01)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :973 Q&As
  • Last Updated
    :Jul 09, 2023

Amazon Amazon Certifications SAP-C01 Questions & Answers

  • Question 591:

    To ensure failover capabilities on an elastic network interface (ENI), what should you use for incoming traffic?

    A. A Route53 A record

    B. A secondary private IP

    C. A secondary public IP

    D. A secondary ENI

  • Question 592:

    Someone is creating a VPC for their application hosting. He has created two private subnets in the same availability zone and created one subnet in a separate availability zone. He wants to make a High Availability system with an internal Elastic Load Balancer.

    Which choice is true regarding internal ELBs in this scenario? (Choose two.)

    A. Internal ELBs should only be launched within private subnets.

    B. Amazon ELB service does not allow subnet selection; instead it will automatically select all the available subnets of the VPC.

    C. Internal ELBs can support only one subnet in each availability zone.

    D. An internal ELB can support all the subnets irrespective of their zones.

  • Question 593:

    You want to establish redundant VPN connections and customer gateways on your network by setting up a second VPN connection.

    Which of the following will ensure that this functions correctly?

    A. The customer gateway IP address for the second VPN connection must be publicly accessible.

    B. The virtual gateway IP address for the second VPN connection must be publicly accessible.

    C. The customer gateway IP address for the second VPN connection must use dynamic routes.

    D. The customer gateway IP address for the second VPN connection must be privately accessible and be the same public IP address that you are using for the first VPN connection.

  • Question 594:

    A user has created a VPC with public and private subnets using the VPC Wizard. The VPC has CIDR 20.0.0.0/16. The private subnet uses CIDR 20.0.0.0/24.

    Which of the below mentioned entries are required in the main route table to allow the instances in VPC to communicate with each other?

    A. Destination : 20.0.0.0/0 and Target : ALL

    B. Destination : 20.0.0.0/16 and Target : Local

    C. Destination : 20.0.0.0/24 and Target : Local

    D. Destination : 20.0.0.0/16 and Target : ALL

  • Question 595:

    A user has created a VPC with two subnets: one public and one private. The user is planning to run the patch update for the instances in the private subnet.

    How can the instances in the private subnet connect to the internet?

    A. The private subnet can never connect to the internet

    B. Use NAT with an elastic IP

    C. Use the internet gateway with a private IP

    D. Allow outbound traffic in the security group for port 80 to allow internet updates

  • Question 596:

    A user has created a VPC with public and private subnets using the VPC wizard. Which of the below mentioned statements is true in this scenario?

    A. The user has to manually create a NAT instance

    B. The Amazon VPC will automatically create a NAT instance with the micro size only

    C. VPC updates the main route table used with the private subnet, and creates a custom route table with a public subnet

    D. VPC updates the main route table used with a public subnet, and creates a custom route table with a private subnet

  • Question 597:

    A user has created a VPC with public and private subnets. The VPC has CIDR 20.0.0.0/16. The private subnet uses CIDR 20.0.1.0/24 and the public subnet uses CIDR 20.0.0.0/24. The user is planning to host a web server in the public subnet (port 80) and a DB server in the private subnet (port 3306). The user is configuring a security group of the NAT instance.

    Which of the below mentioned entries is not required in NAT's security group for the database servers to connect to the Internet for software updates?

    A. For Outbound allow Destination: 0.0.0.0/0 on port 443

    B. For Inbound allow Source: 20.0.1.0/24 on port 80

    C. For Inbound allow Source: 20.0.0.0/24 on port 80

    D. For Outbound allow Destination: 0.0.0.0/0 on port 80

  • Question 598:

    An organization is planning to host a Wordpress blog as well as joomla CMS on a single instance launched with VPC. The organization wants to create separate domains for each application using Route 53. The organization may have about ten instances each with these two applications. While launching each instance, the organization configured two separate network interfaces (primary + secondary ENI) with their own Elastic IPs to the instance. The suggestion was to use a public IP from AWS instead of an Elastic IP as the number of elastic IPs allocation per region is restricted in the account.

    What action will you recommend to the organization?

    A. Only Elastic IP can be used by requesting limit increase, since AWS does not assign a public IP to an instance with multiple ENIs.

    B. AWS VPC does not attach a public IP to an ENI; so the only way is to use an Elastic IP.

    C. I agree with the suggestion but will prefer that the organization should use separate subnets with each ENI for different public IPs.

    D. I agree with the suggestion and it is recommended to use a public IP from AWS since the organization is going to use DNS with Route 53.

  • Question 599:

    An organization is trying to setup a VPC with Auto Scaling. Which configuration steps below is not required to setup AWS VPC with Auto Scaling?

    A. Configure the Auto Scaling group with the VPC ID in which instances will be launched.

    B. Configure the Auto Scaling Launch configuration with multiple subnets of the VPC to enable the Multi AZ feature.

    C. Configure the Auto Scaling Launch configuration which does not allow assigning a public IP to instances.

    D. Configure the Auto Scaling Launch configuration with the VPC security group.

  • Question 600:

    When configuring your customer gateway to connect to your VPC, the________Association is established first between the virtual private gateway and customer gateway using the Pre-Shared Key as the authenticator.

    A. IPsec

    B. BGP

    C. IKE Security

    D. Tunnel

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SAP-C01 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.