ANS-C00 Exam Question 146

Your company maintains an Amazon Route 53 private hosted zone. DNS resolution is restricted to a single, pre-existing VPC. For a new application deployment, you create an additional VPC in the same AWS account.
Both this new VPC and your on-premises DNS infrastructure must resolve records in the existing private hosted zone.
Which two activities are required to enable DNS resolution both within the new VPC and from the on-premises infrastructure? (Select two.)
  • ANS-C00 Exam Question 147

    A network architect is designing an internet website. It has web, application, and database tiers that will run in AWS. The website uses Amazon DynamoDB.
    Which architecture will minimize public exposure of the back-end instances?
  • ANS-C00 Exam Question 148

    A Lambda function needs to access the private address of an Amazon ElastiCache cluster in a VPC. The Lambda function also needs to write messages to Amazon SQS. The Lambda function has been configured to run in a subnet in the VPC.
    Which of the following actions meet the requirements? (Select two.)
  • ANS-C00 Exam Question 149

    A company is about to migrate an application from its on-premises data center to AWS. As part of the planning process, the following requirements involving DNS have been identified.
    The organization's VPC uses the CIDR block 172.16.0.0/16.
    Assuming that there is no DNS namespace overlap, how can these requirements be met?
  • ANS-C00 Exam Question 150

    The Payment Card Industry Data Security Standard (PCI DSS) merchants that handle credit card data must use strong cryptography. These merchants must also use security protocols to protect sensitive data during transmission over public networks.
    You are migrating your PCI DSS application from on-premises SSL appliance and Apache to a VPC behind Amazon CloudFront.
    How should you configure CloudFront to meet this requirement?