Oct 16, 2023

Skill Assessment - AWS Q30

Q30. When launching an EC2 instance with an instance type that supports instance storage, what use case is best for instance storage?

  • Use the instance storage to serve temporary files that require low I/O latency.
  • Use the instance storage to handle files uploaded by your users. Since it is more secure than an EBS volume, you can isolate any malicious files from infecting your server.
  • Instance storage is faster than EBS volumes, so install the root of the operating system on this volume to speed up server performance.
  • Instance storage is a deprecated option for storage and should not be used.

 

ChatGPT

The best use case for instance storage when launching an EC2 instance is:

 

Use the instance storage to serve temporary files that require low I/O latency.

 

Instance storage, also known as ephemeral storage, is a type of local storage that is physically attached to the host on which your EC2 instance runs. It is ideal for temporary storage of data that doesn't need to be retained long-term, and it's well-suited for use cases where low I/O latency and high performance are critical. However, it's important to note that data stored on instance storage is not persistent, meaning it will be lost if the instance is stopped, terminated, or experiences a hardware failure. It's essential to back up any critical data elsewhere if you choose to use instance storage for temporary files.

 


Q31. What’s the best practice for horizontally scaling a legacy ASP.NET web application that relies on Active Directory and is currently deployed to a single Windows EC2 instance?

  • Use Sysprep to shut down the instance during a maintenance window. Create an AMI image and place both servers behind Application Load Balancer with sticky sessions.
  • Launch a new EC2 with the latest version of Windows Server and install the application again. Use Application Load Balancer and sticky sessions to balance between both servers.
  • Create a clone of the server using an AMI image and user Application Load Balancer to balance the traffic between both instances using sticky sessions.
  • Horizontal scaling is not the best practice in this situation. Increase the size of the existing EC2 instance and vertically scale the application.

ChatGPT answered:

The best practice for horizontally scaling a legacy ASP.NET web application that relies on Active Directory and is currently deployed to a single Windows EC2 instance is:

 

Create a clone of the server using an AMI image and use an Application Load Balancer to balance the traffic between both instances using sticky sessions.

 

This approach involves creating a new EC2 instance based on an AMI (Amazon Machine Image) of the existing server. By using an Application Load Balancer (ALB) with sticky sessions, you can distribute incoming traffic across both instances, ensuring that users' sessions are maintained consistently.

 

Vertical scaling (increasing the size of the existing EC2 instance) is a valid approach, but it has limitations in terms of how much you can scale and may not provide the same level of fault tolerance and availability as horizontal scaling with multiple instances behind a load balancer.

 

Option 1, using Sysprep and placing both servers behind an ALB, would require downtime during maintenance and is more complex than simply creating a clone from an AMI.

 

Option 2, launching a new EC2 instance with the latest version of Windows Server and installing the application, is a valid approach but doesn't address the need for horizontal scaling and high availability.

 

注、ここでも過去問解答とChatGPT解答が異なっており、ChatGPTの説明に説得力がある。

 

Q32. What does this small section of a CloudFormation template do?

FlowLog:

  Type: AWS::EC2::FlowLog

  Properties:

    DeliverLogsPermissionArn: !GetAtt IamRole.Arn

    LogGroupName: FlowLogsGroup

    ResourceId: !Ref LogVpcId

    ResourceType: VPC

    TrafficType: ALL

  • It writes the VPC network flow logs to the CloudWatch FlowLogsGroup log group. You could use this to inspect the network connections of your VPC.
  • It logs all of the network traffic within a VPC except Instance IDs defined by LogVpcID and logs it to the CloudWatch FlowLogsGroup log group.
  • It logs all the network traffic going to and from a single EC2 instance into the CloudWatch FlowLogsGroup log group. You could use this to inspect suspicious network traffic coming into an EC2 instance.
  • It logs all of the DNS requests made by resources within a VPC and logs them to the CloudWatch FlowLogsGroup. Use this to diagnose DNS lookup errors within your environment.

ChatGPT answered:

The purpose of this configuration is:

 

It writes the VPC network flow logs to the CloudWatch FlowLogsGroup log group. You could use this to inspect the network connections of your VPC.

 

This configuration sets up flow logs for the specified VPC, capturing network flow information and sending it to the CloudWatch Logs log group named "FlowLogsGroup." This is a common practice for monitoring and diagnosing network traffic within a VPC, which can be useful for troubleshooting, security analysis, and performance monitoring.

 


Q33. You are running Docker containers on ECS. What is the most important metric to monitor?

  • The running container count for each service from within CloudWatch.
  • The instance health of each EC2 instance in your cluster from within CloudWatch.
  • Monitor the EC2 service dashboard. Watch for posted outages to the ECS service.
  • The memory consumption of each EC2 instance in your cluster from within CloudWatch.

 

ChatGPT:

The most important metric to monitor when running Docker containers on Amazon Elastic Container Service (ECS) is:

 

The memory consumption of each EC2 instance in your cluster from within CloudWatch.

 

Monitoring memory consumption is crucial because it helps ensure that your EC2 instances have enough resources to run the Docker containers effectively. If an instance's memory usage is consistently high or reaches critical levels, it can lead to performance issues, service interruptions, or even container failures.

 

Monitoring the running container count and instance health are also important, but memory consumption is often a critical factor in ensuring the overall health and performance of your Dockerized applications. It helps you proactively address resource constraints before they impact your containers' performance.

 

Google:

AWS Health Checkとは何ですか?

ヘルスチェックは、特定のサーバー上のサービスに、作業を正常に実行できるかどうかを確認する方法です。

EC2のヘルスチェックとは?

EC2 AutoScalingAutoScalingグループ内のEC2が全て正常な状態で起動されるように、インスタンスが正常か異常かを判断しています。 この判断をヘルスチェックと呼びます。2022/09/14

 

※メモリー使用量確認はヘルスチェックには含まれない。クラウドベンダーのヘルスチェック定義に要注意。

 

 

Q34. Application Load Balancer can route traffic to several different target groups based upon several conditions. Which of these use cases is not supported by Application Load Balancer?

 

  • A request with a HTTP header of X-Requested-With: staging can be routed to a target group for an ECS service in your staging environment.
  • Source IPs matching 192.0.2.0/24 on a listener port of 1433 can be routed to a target group for an RDS for SQL Server cluster.
  • A path of /signup* can be routed to a target group for a Lambda function that processes new user registrations.
  • An Http POST query string of ? action=createuser can be routed to a target group for an ECS service.

 

ChatGPT:

The use case that is not supported by an Application Load Balancer (ALB) is:

 

An Http POST query string of ?action=createuser can be routed to a target group for an ECS service.

 

ALB supports routing based on various conditions, including HTTP headers, source IP addresses, paths, and other factors. However, routing based on an HTTP POST query string is not a natively supported condition for ALB. ALB primarily routes traffic based on information in the HTTP request, but it's more focused on headers, paths, and host names rather than the specific details of the query string.

 

The other use cases mentioned can be supported by ALB's routing capabilities. For example, routing based on HTTP headers, source IP addresses, or paths is well-supported, and you can route traffic to different target groups based on these conditions.

 

 

Q36. Can you lose the public IP address associated with your EC2 instance?

 

  • Yes, you can lose it if you reboot the instance.
  • Yes, you can lose it if you stop and start the instance.
  • No, you will never lose the public IP address for your instance.
  • Yes, you can lose it when you edit the instance properties and release the IP address.

 

ChatGPT:

Yes, you can lose the public IP address associated with your EC2 instance in some situations. Specifically:

 

Yes, you can lose it if you stop and start the instance.

 

When you stop and start an EC2 instance, it typically gets a new public IP address. This is because the public IP address is associated with the instance's network interface, and stopping the instance often results in a new network interface being created when the instance is started again.

 

If you want to keep the same public IP address, you can use Elastic IP addresses, which allow you to associate a static public IP with your instance that you can retain even if you stop and start the instance.

 

Elastic IP アドレスは、動的なクラウドコンピューティングのために設計された静的 IPv4 アドレスです。

Elastic IP アドレスはユーザーの AWS アカウントに割り当てられ、リリースするまでユーザーのアドレスになります .. Elastic IP アドレスは、インターネットからアクセス可能なパブリック IPv4 アドレスです。

 https://docs.aws.amazon.com/ja_jp/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html

 

 

Q37. Where is the best place to store database backups on an EC2 instance that is configured as a database server?

 

  • an S3 bucket, synced with the database backups via a script that calls the AWS CLI
  • EBS volume attached to the instance
  • instance attached to the instance
  • instance storage, with a script that replicates the database backups to another instance in a different availability zone.

 

ChatGPT:

The best place to store database backups on an EC2 instance that is configured as a database server is typically on an EBS volume attached to the instance. Here's why:

 

  1. Durability: EBS volumes are highly durable and provide redundancy, reducing the risk of data loss.

 

  1. Persistence: Data stored on EBS volumes persists even if the instance is stopped or terminated, making it a reliable choice for backups.

 

  1. Snapshotting: EBS volumes can be easily snapshot, providing a point-in-time backup of the data.

 

Using an S3 bucket with the AWS CLI is a good practice for backing up data, but it's generally more suitable for long-term backups, off-site storage, or archiving. It's recommended to store the primary database backups on EBS volumes for quick access and recovery.

 

Storing backups on the instance itself or on instance storage is not a recommended practice for durability and recovery, as data on instance storage can be lost if the instance is stopped or terminated. Replicating backups to another instance is complex and requires manual management, making it less suitable for a reliable backup solution.

 

※ここでもChatGPTの説明が分かり易く、解答として説得力があると思う。

過去問解答と異なる場合、設問に曖昧さ(今回は保管期間や保守アクセス頻度等が不明確である)が残る場合が多いように感じる。

 

 

Q38. Which of these is a valid restriction on the properties of a VPC?

 

l  You can have only 10 internet gateways per region on a new AWS account.

l  You can have only 10 VPCs per region on a new AWS account

l  You cannot create a CIDR block with a netmask larger than /16

l  You can have only 10 subnets within a VPC

 

ChatGPT:

Among the options you provided, the valid restriction on the properties of a VPC is:

 

You can have only 10 VPCs per region on a new AWS account.

 

In AWS, the limit for the number of VPCs per region is initially set to 5 by default, but it can be increased to a maximum of 10 VPCs per region for a new AWS account.

 

The other statements are not accurate:

 

There is no specific limit on the number of internet gateways per region; you can attach an internet gateway to a VPC as needed.

You can create a VPC with a CIDR block of any valid size, not limited to /16.

There is no specific limit on the number of subnets within a VPC; you can create as many subnets as needed within the IP address range of the VPC's CIDR block.

 

※アマゾンの案内は下記の通り

l  リージョンあたりの VPC の数 5 調整可(この制限を引き上げて、リージョンあたり何百個もの VPC を使用できるようにします。)

l  VPC 当たりのサブネットの数    200  

l  VPC 当たりの IPv4 CIDR ブロック 5 調整可(最大 50)

l  VPC 当たりの IPv6 CIDR ブロック 5 調整可(最大 50)

Ref. https://docs.aws.amazon.com/ja_jp/vpc/latest/userguide/amazon-vpc-limits.html


※アマゾンの言う”CIDRブロック最大50”は /n で表記できない。

あるいは/16はネットワーク数は65536個で、過去問とアマゾン説明が整合しない。

設問が拙いのでは?

 

Q39. You have a Linux EC2 instance that is not responding to requests and you can not connect to it via SSH. Using the EC2 console, you issued a command to stop the instance, but for the past 10 minutes the instance has been in the “stopping” state. What is the next step you should take?

 

l  Issue another stop action via the EC2 console, and choose the option to forcefully stop the instance.

l  Create an AMI image of the instance, and choose the option to take the image without restarting the instance.

l  Edit the instance properties and increase the instance size.

l  Contact AWS support. Any further actions could corrupt the file system.

 

ChatGPT:

When you have an EC2 instance that is unresponsive and has been stuck in the "stopping" state for an extended period, it's generally best to try a more forceful stop action. However, you should avoid taking actions that could potentially corrupt the file system.

 

The appropriate next step in this situation is:

 

Issue another stop action via the EC2 console, and choose the option to forcefully stop the instance.

 

This allows AWS to forcibly terminate the underlying hardware and should bring the instance to a stopped state. Once the instance is in a stopped state, you can then attempt to start it again.

 

Creating an AMI without restarting the instance may not be necessary at this stage, and it's safer to try a forceful stop first. Increasing the instance size is unlikely to resolve the stopping issue, and contacting AWS support is a viable option but may take some time, so a forceful stop is generally the first step in resolving the issue.

 

過去問ソース

https://www.chase2learn.com/amazon-web-services-linkedin-assessment/

 

関連スキルテスト AWS Q20

 https://akasaka-taro.blogspot.com/2023/10/skill-assessment-aws-q20.html





Oct 11, 2023

Skill Assessment - AWS Q20

Q20. A principle of DevOps is to view infrastructure as code. 

Which AWS service allows you to script your AWS infrastructure?

  •  CloudTrail
  •  CloudFormation
  •  AWS Config
  •  AWS Service Catalog

ChatGPT

The AWS service that allows you to script your AWS infrastructure is "CloudFormation." So, the correct answer is:

·       CloudFormation

 

Please show me the simplest sample of CloudFormation.

 

ChatGPT

Certainly! Here's a very simple example of an AWS CloudFormation template in YAML format. This template creates an Amazon S3 bucket:

yamlCopy code

Resources: MyS3Bucket: Type: AWS::S3::Bucket

In this example:

·       Resources is the section where you define the AWS resources you want to create.

·       MyS3Bucket is a logical name for the S3 bucket resource.

·       Type: AWS::S3::Bucket specifies the AWS resource type, which is an S3 bucket in this case.

You can create more complex templates that include parameters, conditions, and other resources as needed for your infrastructure. CloudFormation allows you to declare your infrastructure as code, making it easier to manage and provision AWS resources consistently.

 

Q21. You created a Windows EC2 instance with a public IP address and installed SQL Server.

When attempting to connect to SQL Server from SQL Server Enterprise Manager on your local computer, the Windows EC2 instance is unable to establish a connection to the server. What is the first thing you should check?

  •  Check the routing tables for the VPC.
  •  Verify that the assigned security groups allow TCP port 1433 traffic from your current IP address.
  •  Check the policies within Windows Firewall.
  •  Verify that you are connecting to the instance using a user that is not sa.

 

Q22. You are hosting an application configured to stream media to its clients on TCP ports 3380-3384, 3386-3388, and 3390.

The Inbound tab below shows three incoming security group policies attached to this instance. Which policy should you use?

  • The rule that exposes TCP ports 3380-3390 would also publicly expose port 3389 (RDP) to the entire internet. Write separate rules to only expose the needed ports.
  • The first security group rule allows all traffic into this instance. Exposing your entire instance to the whole internet leaves the server open to various attacks of the other services running on different port numbers.
  • Verify that the AWS account owners actually control the entire CIDR C block for 12.228.11.0-255 and these are secured IPs for RDP access into this instance.
  • There are no recommendations to make.

 

Q23. You have four front-end web servers behind a load balancer,

which use NFS to access another EC2 instance that resizes and stores images for the front-end application. What security group policies should be assigned to these servers?

  •  Assign Elastic IPs to all of the instances and create a group that allows all traffic to pass between each of the five Elastic IP addresses and allow all inbound HTTPS traffic.
  •  Front-end web servers should allow HTTPS. Assign another group to all of the instances that allows all traffic to pass between instances using that group.
  •  Create a security group that allows inbound NFS, HTTP, and HTTPS traffic from all IP addresses. Apply this group to all of the servers.
  •  Create a security group that allows inbound HTTP and HTTPS traffic from all IP addresses and apply this to the web servers. Create a second security group for the NFS filestore that allows outbound NFS traffic to the private IP range of the front-end web servers.


ChatGPT


The correct approach for securing the described infrastructure is:

Create a security group that allows inbound HTTP and HTTPS traffic from all IP addresses and apply this to the web servers. Create a second security group for the NFS filestore that allows outbound NFS traffic to the private IP range of the front-end web servers.

Here's why:

1.     Front-end web servers: These servers should allow inbound HTTP and HTTPS traffic from clients. Therefore, you need to create a security group for them that allows inbound HTTP and HTTPS traffic.

2.     NFS filestore: The EC2 instance responsible for NFS should have a security group that allows outbound NFS traffic to the private IP range of the front-end web servers. This allows the NFS server to communicate with the front-end servers securely.

This configuration ensures that the web servers are accessible over HTTP and HTTPS while the NFS server can communicate with the web servers via NFS. It follows the principle of least privilege, only allowing the necessary traffic and connections for the specific services.

 

ChatGPTの説明が説得力があると考える。

 


Q24. You have a Linux EC2 web server that suddenly is timing out 

on all HTTP requests and your SSH connection attempts are timing out. You notice that it is failing the system status check in the EC2 console. What action should you take?

  •  Restore the instance from the last AMI image. System status checks indicate that the filesystem on the instance is corrupted.
  •  Stop and start the instance. This will move the instance to another host.
  •  Contact AWS support. Failing a system status check indicates a failure in the underlying hardware and must be addressed by an AWS representative.
  •  Reboot the instance. This will stop and start the instance and move it to another host.

 

ChatGPT

In this situation, the most appropriate action to take is:

Stop and start the instance. This will move the instance to another host.

Stopping and starting the instance can often resolve issues related to the underlying hardware or the instance's networking. When you stop and start an instance, it's moved to a different host, and this can help address issues related to the current host's hardware or network problems. It's a common troubleshooting step for resolving connectivity issues or system status check failures.

Restoring from an AMI would not necessarily address the underlying issue related to the system status check failure.
Contacting AWS support should be considered if the issue persists after stopping and starting the instance.
Rebooting the instance is a less drastic step than stopping and starting, and it may not necessarily move the instance to another host, so it may not be as effective in resolving underlying hardware or networking issues.

 

※ここでもChatGPTの説明に説得力があると感じる。

 

Q25. You have several on-premise servers 

and would like to store your offsite backups on AWS. What fully managed backup service can you use to ship your backups to AWS?

  •  Windows Server 2016 supports S3 as a target when using storage replicas.
  •  Use Storage Gateway.
  •  Sync files directly to S3 with the AWS CLI.
  •  Use the RDS console to force a reboot of the database instance so that the primary server becomes the master server again.

 

ChatGPT

The fully managed service you can use to ship your backups to AWS is AWS Storage Gateway.

AWS Storage Gateway is a hybrid cloud storage service that enables on-premises applications to seamlessly use AWS cloud storage. It allows you to store backups, archives, and other data in AWS cloud storage services like Amazon S3 (Simple Storage Service). You can configure it to act as a backup target for your on-premises servers, and it provides various storage interfaces, including file, volume, and tape, making it a flexible and versatile option for backing up on-premises data to AWS.

 

Q26. What is the best practice for creating a highly available PostgreSQL database 

in RDS that can sustain the loss of a single AWS region?

  •  PostgreSQL cannot be replicated across regions. Restore the database backups from an S3 bucket and repoint your database connections to the new instance.
  •  Create Read Replicas in other AWS regions. You can designate a new master database from any of the read replicas until the regional failure is resolved.
  •  Verify that your instance is configured for Multi-AZ support. Database changes will be automatically synced to another region in the event of a failure and RDS will automatically select a new master until the regional failure is resolved.
  •  Create Read Replicas in other AWS regions. Ensure read operations against the database occur on an available Read Replica, and send write operations to another region if you need to promote a Read Replica to a standalone database if the master is down.

 

ChatGPT

The best practice for creating a highly available PostgreSQL database in Amazon RDS (Relational Database Service) that can sustain the loss of a single AWS region is:

 

Create Read Replicas in other AWS regions. Ensure read operations against the database occur on an available Read Replica, and send write operations to another region if you need to promote a Read Replica to a standalone database if the master is down.

 

This strategy involves setting up Read Replicas in multiple AWS regions for failover and high availability. It allows you to have read-only access to the data in the standby region and promotes a Read Replica to become the new master database if the primary region experiences a failure. This approach helps to minimize downtime and data loss in the event of a regional failure.

Multi-AZ (Availability Zone) support doesn't inherently replicate data across regions, and it only provides high availability within the same region.

 

Q27. You created a new Linux EC2 instance and installed PostgreSQL 

but you are not able to establish a connection to the server from your local computer. What steps do you take to resolve this issue?

  •  Create a security group rule that allows all traffic from 0.0.0.0/0. This will verify whether or not another rule is denying the traffic.
  •  Verify that the assigned security groups allow traffic from your IP address to port 5432. Verify that PostgreSQL is configured to listen to external traffic and is bound to the public interface.
  •  Make sure that you are using an Elastic IP and that it is included within the postgresql.conf configuration file.
  •  Stop and start the instance. New security group rules will only take effect after a restart

 

Q28. What does the statement body of this S3 bucket policy do?

{

  "Sid": "bucketpolicy1",

  "Effect": "Allow",

  "Principal": "*",

  "Action": "s3:GetObject",

  "Resource": "arn:aws:s3:::userreports/*",

  "Condition": {

    "IpAddress": { "aws:SourceIp": "68.249.108.0/24" },

    "NotIpAddress": { "aws:SourceIp": "68.249.108.128/32" }

  }

}

  •  bucketpolicy1 allows any user to perform any action on the objects in the userreports bucket, but limits the objects to read-only permissions for anyone coming from 68.249.108.0 to 68.249.108.255 – except 68.249.108.128.
  •  bucketpolicy1 allows any user coming from the IP range of 68.249.108.0 to access objects in the userreports bucket and denies access to 68.249.108.128.
  •  bucketpolicy1 allows any user to perform any action on the objects in the userreports bucket – except anyone coming from the IP of 68.249.108.128.
  •  bucketpolicy1 allows any user coming from the IP range of 68.249.108.0 to 68.249.108.255 to access objects in the userreports bucket-except anyone coming from the IP of 68.249.108.128.

 

ChatGPT

The statement body of this S3 bucket policy does the following:

 

bucketpolicy1 allows any user to perform any action on the objects in the userreports bucket – except anyone coming from the IP of 68.249.108.128.

 

The "Effect" is set to "Allow," so it allows actions, but the "Condition" specifies that it allows any user from the IP range 68.249.108.0 to 68.249.108.255 to access objects in the "userreports" bucket while denying access to anyone with the specific IP address 68.249.108.128.

 

ChatGPTの解答間違い。解答最終コメントが正しいのだが、問題文選択肢の文脈を取り違えたのか。

 

Q29. A new developer has been added to the team 

and you have been asked to provide access to the organization’s AWS account. What is the best practice for granting access?

  •  Give the new developer the IAM login that is assigned to the development team. This IAM user should already include all of the policies that a developer would need.
  •  Create a IAM user for the new developer. Manually assign policies to the new IAM user account.
  •  Do not give the new developer access to the AWS console. Using the IAM user that is assigned to the development group, generate a new set of access keys and label these with the name of the developer.
  •  Create a IAM user for the new developer. Assign the new developer the a developer group you already created for the other developers.

 

関連スキルテスト編

https://akasaka-taro.blogspot.com/2023/10/skill-assessment-aws-q3.html