A company wants DNS-based routing to send users to the closest AWS Region and automatically fail over during regional outages.
Which Route 53 configuration is REQUIRED?
A. Latency-based routing onlyA company's security policy prohibits connecting to Amazon EC2 instances through SSH and RDP. Instead, staff must use AWS Systems Manager Session Manager. Users report they cannot connect to one Ubuntu instance, even though they can connect to others.
What should a CloudOps engineer do to resolve this issue?
A. Add an inbound rule for port 22 in the security group associated with the Ubuntu instance.A CloudOps engineer needs organization-wide visibility into security best-practice violations.
Which service should be used?
A. Amazon GuardDutyA company is storing backups in an Amazon S3 bucket. These backups must not be deleted for at least 3 months after creation.
What should the CloudOps engineer do?
A. Configure an IAM policy that denies the s3:DeleteObject action for all users. Three months after an object is written, remove the policy.A company wants to monitor the p95 latency of an application based on log data.
Which CloudWatch feature should be used?
A. Contributor InsightsA CloudOps engineer needs to trigger automated remediation when an Amazon CloudWatch alarm enters the ALARM state.
Which AWS service should be used to route the alarm event?
A. Amazon SNSA CloudOps engineer uses AWS CloudTrail Lake to investigate an incident involving Amazon S3 data access.
The engineer must identify which IAM role accessed a specific object and retrieve the request parameters used during the access.
Which approach should the engineer use?
A. Query S3 server access logs with Amazon Athena.A company uses AWS Systems Manager to manage a fleet of Amazon EC2 instances across multiple AWS accounts in an organization.
The CloudOps engineer needs to ensure that future EC2 instances are automatically managed by Systems Manager without manual IAM configuration.
Which solution will meet this requirement?
A. Attach the AmazonSSMManagedInstanceCore policy to each EC2 instance role manually.An Amazon EC2 instance is running an application that uses Amazon Simple Queue Service (Amazon SQS) queues. A CloudOps engineer must ensure that the application can read, write, and delete messages from the SQS queues.
Which solution will meet these requirements in the MOST secure manner?
A. Create an IAM user with an IAM policy that allows the sqs:SendMessage permission, the sqs: ReceiveMessage permission, and the sqs:DeleteMessage permission to the appropriate queues. Embed the IAM user's credentials in the application's configuration.A company hosts a critical legacy application on two Amazon EC2 instances that are in one Availability Zone. The instances run behind an Application Load Balancer (ALB).
The company uses Amazon CloudWatch alarms to send Amazon Simple Notification Service (Amazon SNS) notifications when the ALB health checks detect an unhealthy instance. After a notification, the company's engineers manually restart the unhealthy instance. A CloudOps engineer must configure the application to be highly available and more resilient to failures.
Which solution will meet these requirements?
A. Create an Amazon Machine Image (AMI) from a healthy instance. Launch additional instances from the AMI in the same Availability Zone. Add the new instances to the ALB target group.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SOA-C03 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.