Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SOA-C02 Topic 2 Question 95 Discussion

Actual exam question for Amazon's SOA-C02 exam
Question #: 95
Topic #: 2
[All SOA-C02 Questions]

A SysOps administrator needs to control access to groups of Amazon EC2 instances using AWS Systems Manager Session Manager. Specific tags on the EC2 instances have already been added.

Which additional actions should the administrator take to control access? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: D

AWS Global Accelerator and Amazon CloudFront are separate services that use the AWS global network and its edge locations around the world. CloudFront improves performance for both cacheable content (such as images and videos) and dynamic content (such as API acceleration and dynamic site delivery). Global Accelerator improves performance for a wide range of applications over TCP or UDP by proxying packets at the edge to applications running in one or more AWS Regions. Global Accelerator is a good fit for non-HTTP use cases, such as gaming (UDP), IoT (MQTT), or Voice over IP, as well as for HTTP use cases that specifically require static IP addresses or deterministic, fast regional failover. Both services integrate with AWS Shield for DDoS protection.

https://medium.com/awesome-cloud/aws-difference-between-application-load-balancer-and-network-load-balancer-cb8b6cd296a4 https://aws.amazon.com/global-accelerator/faqs/?nc1=h_ls


Contribute your Thoughts:

Hyun
7 days ago
I'm not sure about option B - attaching an IAM role to the instances themselves seems like overkill for this use case. Let's go with A and E.
upvoted 0 times
...
Walker
9 days ago
I also think creating an IAM policy that grants access based on specific tags is important.
upvoted 0 times
...
Bernadine
10 days ago
I agree with Ty. It's a good way to control access to the EC2 instances.
upvoted 0 times
...
Ty
15 days ago
I think we should attach an IAM policy to the users or groups.
upvoted 0 times
...
Deangelo
18 days ago
I believe we should also create an IAM policy that grants access to EC2 instances with a specific tag.
upvoted 0 times
...
James
18 days ago
Options A and E look like the right choices here. Attaching an IAM policy to users/groups and using a tag-based condition in the policy should give us the access control we need.
upvoted 0 times
...
Daniela
19 days ago
I agree with Deangelo. That's one of the actions we should take. What's the other one?
upvoted 0 times
...
Deangelo
21 days ago
I think we should attach an IAM policy to the users or groups that need access.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77