[{"data":1,"prerenderedAt":1210},["ShallowReactive",2],{"practiceExams":3,"practice-exam-questions-\u002Fpractice-exams\u002Faws-certified-devops-engineer-professional-dop-c02\u002Fquestions":79},[4,15,23,32,42,51,61,70],{"id":5,"slug":6,"description":7,"questionCount":8,"isActive":9,"datePublicModified":10,"difficulty":11},9,"aws-certified-data-engineer-associate-dea-c01","Prepare for your AWS Certified Data Engineer - Associate exam with our practice exam simulator. Featuring real exam scenarios, detailed explanations, and instant feedback to boost your confidence and success rate.",3312,true,"2024-11-13T00:00:00.000Z",{"title":12,"subtitle":13,"slug":6,"coverImageUrl":14},"AWS Certified Data Engineer - Associate","DEA-C01","",{"id":16,"slug":17,"description":18,"questionCount":19,"isActive":9,"datePublicModified":10,"difficulty":20},10,"aws-certified-advanced-networking-specialty-ans-c01","The AWS Certified Advanced Networking - Specialty practice exam simulates the real test, offering scenario-based questions that assess your ability to design, implement, and troubleshoot complex AWS networking solutions. ",3531,{"title":21,"subtitle":22,"slug":17,"coverImageUrl":14},"AWS Certified Advanced Networking - Specialty","ANS-C01",{"id":24,"slug":25,"description":26,"questionCount":27,"isActive":9,"datePublicModified":28,"difficulty":29},8,"aws-certified-devops-engineer-professional-dop-c02","Boost your readiness for the AWS Certified DevOps Engineer - Professional (DOP-C02) exam with our practice exam simulator. Featuring realistic questions and detailed explanations, it helps you identify knowledge gaps and improve your skills.",2775,"2024-08-08T00:00:00.000Z",{"title":30,"subtitle":31,"slug":25,"coverImageUrl":14},"AWS Certified DevOps Engineer - Professional","DOP-C02",{"id":33,"slug":34,"description":35,"questionCount":36,"isActive":9,"datePublicModified":37,"difficulty":38},1,"aws-certified-solutions-architect-associate-saa-c03","Unlock your potential with the AWS Certified Solutions Architect - Associate Practice Exam Simulator. This comprehensive tool is designed to prepare you thoroughly and assess your readiness for the most sought-after AWS associate certification.",3813,"2024-06-13T00:00:00.000Z",{"title":39,"subtitle":40,"slug":34,"coverImageUrl":41},"AWS Certified Solutions Architect - Associate","SAA-C03","\u002Fimages\u002Fdifficulties\u002Faws-certified-solutions-architect-associatesaa-c03\u002Fcovers\u002Faws-SAA-C03.png",{"id":43,"slug":44,"description":45,"questionCount":46,"isActive":9,"datePublicModified":37,"difficulty":47},5,"aws-certified-cloud-practitioner-clf-c02","Master your AWS Certified Cloud Practitioner exam with our Practice Exam Simulator. Prepare effectively and assess your readiness with realistic practice exams designed to mirror the most popular official AWS exam.",4227,{"title":48,"subtitle":49,"slug":44,"coverImageUrl":50},"AWS Certified Cloud Practitioner","CLF-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-cloud-practitionerclf-c02\u002Fcovers\u002Faws-CLF-C02.png",{"id":52,"slug":53,"description":54,"questionCount":55,"isActive":9,"datePublicModified":56,"difficulty":57},4,"aws-certified-developer-associate-dva-c02","Unlock your potential as a software developer with the AWS Certified Developer - Associate Exam Simulator! Prepare thoroughly with realistic practice exams designed to mirror the official exam.",3787,"2024-06-06T00:00:00.000Z",{"title":58,"subtitle":59,"slug":53,"coverImageUrl":60},"AWS Certified Developer - Associate","DVA-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-developer-associatedva-c02\u002Fcovers\u002Faws-DVA-C02.png",{"id":62,"slug":63,"description":64,"questionCount":65,"isActive":9,"datePublicModified":56,"difficulty":66},6,"aws-certified-solutions-architect-professional-sap-c02","Elevate your career with the AWS Certified Solutions Architect - Professional Exam Simulator. Get ready to ace the most popular Professional AWS exam with our realistic practice exams. Assess your readiness, boost your confidence, and ensure your success.",8203,{"title":67,"subtitle":68,"slug":63,"coverImageUrl":69},"AWS Certified Solutions Architect - Professional","SAP-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-solutions-architect-professionalsap-c02\u002Fcovers\u002Faws-SAP-C02.png",{"id":71,"slug":72,"description":73,"questionCount":74,"isActive":9,"datePublicModified":56,"difficulty":75},7,"aws-certified-security-specialty-scs-c02","Advance your career in cloud cybersecurity with the AWS Certified Security - Specialty Exam Simulator! Tailored for professionals, this tool offers realistic practice exams to mirror the official exam.",5439,{"title":76,"subtitle":77,"slug":72,"coverImageUrl":78},"AWS Certified Security - Specialty","SCS-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-security-specialtyscs-c02\u002Fcovers\u002Faws_SCS_c02.png",{"id":24,"slug":25,"description":26,"content":80,"formalQuestionCount":81,"minQuestionCount":33,"maxQuestionCount":81,"formalTimeLimitCount":82,"minTimeLimitCount":16,"maxTimeLimitCount":83,"passingScore":81,"questionCount":27,"isActive":9,"dateCreated":84,"dateModified":85,"datePublicModified":28,"difficulty":86,"tags":1209},"\u003Cp>The AWS Certified DevOps Engineer - Professional (DOP-C02) certification is designed for individuals with extensive experience in managing AWS environments. It assesses your ability to implement and manage continuous delivery systems and methodologies on AWS. Before attempting this certification, it is recommended to have a solid understanding of modern development and operations processes and methodologies, as well as experience in developing code in at least one high-level programming language and managing automated infrastructures.\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>The exam consists of 75 questions in multiple-choice and multiple-response formats. You have 180 minutes to complete the exam, which can be taken at a Pearson VUE testing center or online with a proctor. The cost of the exam is $300, and it is available in several languages, including English, Japanese, Korean, and Simplified Chinese. To pass, you need a score of 750 out of 1000.\u003C\u002Fp>\u003Cp>This certification focuses on six main areas: automating the software development lifecycle (SDLC), managing infrastructure as code (IaC), creating resilient cloud solutions, monitoring and logging, incident and event response, and ensuring security and compliance. Key AWS services you need to be familiar with include AWS CodeCommit, AWS CodeBuild, AWS CodeDeploy, AWS CloudFormation, Amazon CloudWatch, AWS Lambda, and AWS IAM.\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>Preparing for this certification involves reviewing the official exam guide, which details the domains covered and their respective weightages. Practical experience is crucial, so setting up a lab environment to practice using AWS services is highly recommended. Additionally, enrolling in relevant training courses, such as those offered by experts like Stephane Maarek and Adrian Cantrill, can provide valuable insights and hands-on experience. Practice exams, like those by Jon Bonso, can help you get accustomed to the exam format and identify areas where you need to focus more.\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>Overall, achieving the AWS Certified DevOps Engineer - Professional certification demonstrates your proficiency in managing and automating AWS environments using DevOps principles, making it a valuable credential for advancing your career in cloud computing and DevOps.\u003C\u002Fp>",75,180,200,"2024-08-08T19:15:04.295Z","2024-08-09T09:21:56.000Z",{"id":62,"title":30,"subtitle":31,"rating":87,"slug":25,"guideUrl":88,"categories":89,"services":625},4.5,"https:\u002F\u002Fd1.awsstatic.com\u002Ftraining-and-certification\u002Fdocs-devops-pro\u002FAWS-Certified-DevOps-Engineer-Professional_Exam-Guide.pdf",[90,202,287,372,456,541],{"id":91,"title":92,"subtitle":93,"description":94,"content":94,"coverImageUrl":14,"weight":95,"subcategories":96},23,"SDLC Automation","Domain 1",null,22,[97,124,150,176],{"id":98,"title":99,"subtitle":100,"description":94,"questions":101},98,"Implement CI\u002FCD pipelines","Task 1.1",[102],{"id":103,"subcategoryId":98,"content":104,"hint":105,"isPublic":9,"answers":106},27239,"You are a DevOps Engineer at a company that has a microservices architecture built using AWS Lambda. You have been tasked with setting up a Continuous Integration\u002FContinuous Deployment (CI\u002FCD) pipeline that automates the deployment of these Lambda functions. The deployment must ensure zero downtime and should integrate seamlessly with AWS CodeDeploy. Which deployment strategy should you choose?","Consider deployment strategies in AWS CodeDeploy that ensure minimal disruption and zero downtime.",[107,112,116,120],{"id":108,"questionId":103,"content":109,"hint":110,"isCorrect":111},122754,"All-at-once Deployment","All-at-once Deployment deploys the new version of the application to all instances simultaneously, which can cause downtime if any issues arise during deployment.",false,{"id":113,"questionId":103,"content":114,"hint":115,"isCorrect":111},122755,"Rolling Deployment","Rolling Deployment can make a phased update to instances, but it is more applicable to EC2 or container-based applications rather than strictly serverless architectures like AWS Lambda.",{"id":117,"questionId":103,"content":118,"hint":119,"isCorrect":111},122756,"Blue\u002FGreen Deployment","While Blue\u002FGreen Deployment can ensure zero downtime, it typically involves a more complex setup with two separate environments, which may not integrate as seamlessly with AWS Lambda as a Canary Deployment would.",{"id":121,"questionId":103,"content":122,"hint":123,"isCorrect":9},122757,"Canary Deployment","Canary Deployment gradually shifts traffic to the Lambda function in small increments, ensuring that any issues can be detected and rolled back quickly if needed, thus guaranteeing zero downtime.",{"id":125,"title":126,"subtitle":127,"description":94,"questions":128},99,"Integrate automated testing into CI\u002FCD pipelines","Task 1.2",[129],{"id":130,"subcategoryId":125,"content":131,"hint":132,"isPublic":9,"answers":133},27302,"Your team is responsible for maintaining an application's CI\u002FCD pipeline. Recently, there have been frequent bugs discovered in production. To improve the quality of code being deployed, you decide to integrate automated testing into your CI\u002FCD pipeline. Your pipeline currently uses AWS CodePipeline, and deploys the application using AWS CodeDeploy. Which of the following is the MOST appropriate method to ensure automated testing is performed before the deployment stage with AWS CodeDeploy?","Think about where in the CI\u002FCD pipeline you should place automated testing to ensure the code is thoroughly verified before it reaches the deployment stage.",[134,138,142,146],{"id":135,"questionId":130,"content":136,"hint":137,"isCorrect":111},123006,"Integrate a testing stage in AWS CodePipeline after the deployment stage with AWS CodeDeploy.","Testing after deployment means the code has already been deployed, potentially introducing bugs to the production environment.",{"id":139,"questionId":130,"content":140,"hint":141,"isCorrect":111},123007,"Run automated tests as a post-deployment validation using AWS CodeDeploy hooks.","Running tests after deployment does not prevent faulty code from reaching production, which could lead to discovering issues only after they have potentially affected users.",{"id":143,"questionId":130,"content":144,"hint":145,"isCorrect":111},123008,"Manually test code before triggering the deployment in AWS CodeDeploy.","Manual testing is not in alignment with the goal of CI\u002FCD automation. It leads to slower cycles and increased chances of human error.",{"id":147,"questionId":130,"content":148,"hint":149,"isCorrect":9},123009,"Integrate a testing stage in AWS CodePipeline before the deployment stage that runs automated tests using AWS CodeBuild.","Integrating a testing stage in AWS CodePipeline ensures that all automated tests are executed before the deployment stage, thus ensuring only tested and stable code is deployed using AWS CodeDeploy.",{"id":151,"title":152,"subtitle":153,"description":94,"questions":154},100,"Build and manage artifacts","Task 1.3",[155],{"id":156,"subcategoryId":151,"content":157,"hint":158,"isPublic":9,"answers":159},27365,"As a DevOps engineer at a rapidly growing tech company, you are tasked with automating the build and deployment of EC2 instances and container images. Your company uses AWS CloudFormation to manage its infrastructure as code. Recently, the team decided to utilize EC2 Image Builder to streamline the creation and update of both EC2 and container images. You need to ensure that the image creation process is automated and integrates seamlessly with your existing CloudFormation setup. Which approach would you use to achieve this goal?","Consider how AWS CloudFormation can be used to incorporate other AWS services for automation and what resources or components you may need to define in your template.",[160,164,168,172],{"id":161,"questionId":156,"content":162,"hint":163,"isCorrect":111},123258,"Use EC2 User Data scripts to automate instance and image creation during instance boot time.","While EC2 User Data scripts can automate some tasks during instance boot, they are not suitable for integrating EC2 Image Builder and do not leverage CloudFormation for defining infrastructure.",{"id":165,"questionId":156,"content":166,"hint":167,"isCorrect":111},123259,"Manually trigger EC2 Image Builder pipelines from the AWS Management Console.","Manually triggering EC2 Image Builder pipelines from the AWS Management Console would not be an automated approach and would not integrate with CloudFormation, which contradicts the requirement to automate the process.",{"id":169,"questionId":156,"content":170,"hint":171,"isCorrect":111},123260,"Plan to use AWS Elastic Beanstalk to manage the build and deployment of your instances and containers.","AWS Elastic Beanstalk is used for deploying and managing applications and doesn't provide the necessary integration for automating EC2 Image Builder pipelines through CloudFormation.",{"id":173,"questionId":156,"content":174,"hint":175,"isCorrect":9},123261,"Define EC2 Image Builder components, recipes, and pipelines as CloudFormation resources in your template.","AWS CloudFormation supports the definition of EC2 Image Builder components, recipes, and pipelines. By defining these resources in CloudFormation, you can automate the creation and update of EC2 instances and container images seamlessly within your existing infrastructure as code (IaC) setup.",{"id":177,"title":178,"subtitle":179,"description":94,"questions":180},101,"Implement deployment strategies for instance, container, and serverless environments","Task 1.4",[181],{"id":182,"subcategoryId":177,"content":183,"hint":184,"isPublic":9,"answers":185},27445,"You are a DevOps engineer at a company that is deploying a new microservices architecture on Amazon EKS. The team decided to use a blue\u002Fgreen deployment strategy to release a new version of a critical microservice in order to minimize risks and downtime. Which method should you employ to ensure traffic is gradually shifted from the existing version (blue) to the new version (green) within Amazon EKS?","Consider how traffic routing in Kubernetes is managed and which Kubernetes resources can facilitate gradual traffic switching.",[186,190,194,198],{"id":187,"questionId":182,"content":188,"hint":189,"isCorrect":9},123578,"Use an ingress controller with weighted routing to split traffic between the blue and green versions.","Using an ingress controller with weighted routing, such as an AWS Application Load Balancer (ALB) Ingress Controller, allows you to gradually shift traffic between the existing and new versions of a microservice. This ensures that you can monitor the new version's performance before fully switching over.",{"id":191,"questionId":182,"content":192,"hint":193,"isCorrect":111},123579,"Use a rolling update strategy to replace the blue version with the green version.","A rolling update strategy updates instances of the application one at a time, but it doesn't fit the blue\u002Fgreen deployment paradigm where both versions run in parallel to ensure minimal risk.",{"id":195,"questionId":182,"content":196,"hint":197,"isCorrect":111},123580,"Deploy both versions behind separate Load Balancers and switch DNS records to the new version.","Switching DNS records might lead to DNS propagation delays and could result in some users hitting the old version while others hit the new one. This method doesn't facilitate a gradual traffic shift.",{"id":199,"questionId":182,"content":200,"hint":201,"isCorrect":111},123581,"Manually update the Kubernetes service selector to point to the green version.","Manually updating the Kubernetes service selector doesn't provide a controlled and gradual traffic shift between versions. It swaps traffic instantaneously, which can introduce risks.",{"id":203,"title":204,"subtitle":205,"description":206,"content":94,"coverImageUrl":14,"weight":207,"subcategories":208},24,"Configuration Management and IaC","Domain 2","Focused on defining and deploying infrastructure as code (IaC) templates, this domain also covers managing AWS accounts at scale, automating complex tasks, and ensuring consistent configurations across AWS environments.",17,[209,235,261],{"id":210,"title":211,"subtitle":212,"description":94,"questions":213},102,"Define cloud infrastructure and reusable components to provision and manage systems throughout their lifecycle","Task 2.1",[214],{"id":215,"subcategoryId":210,"content":216,"hint":217,"isPublic":9,"answers":218},27514,"You are a DevOps engineer at a mid-sized tech company. Your team is in the process of implementing a new infrastructure as code (IaC) strategy using AWS CloudFormation to manage your cloud resources. You have created several reusable CloudFormation templates to standardize the deployment of various AWS services, including EC2 instances, RDS databases, and VPC configurations. However, you recently discovered that some of your templates grant overly permissive IAM roles, which has raised security concerns. Now, you need to enforce more stringent IAM policies within your CloudFormation templates and ensure that only needed permissions are granted to various resources. Which solution will help you achieve this objective most effectively?","Consider AWS services and features that help in managing IAM roles and policies in a structured and repeatable way.",[219,223,227,231],{"id":220,"questionId":215,"content":221,"hint":222,"isCorrect":111},123854,"Use AWS Service Catalog to catalog and deploy your CloudFormation templates without additional IAM policy adjustments.","While AWS Service Catalog helps with standardizing and deploying CloudFormation templates, it does not directly address the need for more granular IAM policy conditions within the templates.",{"id":224,"questionId":215,"content":225,"hint":226,"isCorrect":111},123855,"Disable IAM roles in your CloudFormation templates and manage permissions manually using the AWS Management Console.","This approach is not practical for maintaining standardization and could lead to human error. It defeats the purpose of using IaC to automate infrastructure management.",{"id":228,"questionId":215,"content":229,"hint":230,"isCorrect":111},123856,"Create new IAM users with administrator access and embed them in the CloudFormation templates.","This approach is insecure and goes against AWS best practices by providing excessive permissions. The goal should be to implement least privilege access, not to grant administrator access unnecessarily.",{"id":232,"questionId":215,"content":233,"hint":234,"isCorrect":9},123857,"Use IAM policy conditions within your CloudFormation templates to specify more granular access controls tailored to specific resources.","IAM policy conditions allow you to define explicit rules about when a policy effect is allowed or denied. Using conditions makes your IAM policies more secure and customized to specific scenarios.",{"id":236,"title":237,"subtitle":238,"description":94,"questions":239},103,"Deploy automation to create, onboard, and secure AWS accounts in a multi-account or multi-Region environment","Task 2.2",[240],{"id":241,"subcategoryId":236,"content":242,"hint":243,"isPublic":9,"answers":244},27564,"You are a DevOps engineer working for a company that has recently decided to scale its cloud infrastructure using AWS. You have been tasked with setting up a governance framework for multiple AWS accounts across different regions. One of the requirements is to automate the provisioning of AWS resources to ensure they adhere to best practices and security policies. You want to use a service that allows you to easily create and manage catalogs of approved AWS resources that can be deployed across multiple accounts and regions. Which service should you choose to meet these requirements?","Consider a service that offers a way to create and manage catalogs of approved AWS resources and ensures that deployments adhere to best practices and security policies.",[245,249,253,257],{"id":246,"questionId":241,"content":247,"hint":248,"isCorrect":111},124054,"AWS Security Hub","AWS Security Hub provides comprehensive security checks and compliance auditing across AWS accounts but doesn't offer cataloging and provisioning capabilities for AWS resources.",{"id":250,"questionId":241,"content":251,"hint":252,"isCorrect":111},124055,"AWS Control Tower","AWS Control Tower is used for setting up and governing a secure, multi-account AWS environment based on AWS best practices. While it helps with governance, it doesn't specifically create and manage catalogs of approved resources for deployment.",{"id":254,"questionId":241,"content":255,"hint":256,"isCorrect":9},124056,"AWS Service Catalog","AWS Service Catalog allows you to create and manage catalogs of IT services that are approved for use on AWS. It enables you to centrally manage deployed IT services and achieve consistent governance, compliance, and security.",{"id":258,"questionId":241,"content":259,"hint":260,"isCorrect":111},124057,"AWS Config","AWS Config is primarily used for assessing, auditing, and evaluating the configurations of your AWS resources. It does not offer a catalog of approved resources for deployment.",{"id":262,"title":263,"subtitle":264,"description":94,"questions":265},104,"Design and build automated solutions for complex tasks and large-scale environments","Task 2.3",[266],{"id":267,"subcategoryId":262,"content":268,"hint":269,"isPublic":9,"answers":270},27620,"You are working for a large e-commerce company that needs to ensure its software environment is compliant with regulatory standards across multiple AWS accounts. Your team uses AWS Config to maintain this compliance by checking the state of AWS resources against predefined rules. Recently, you have been tasked with designing and building an automated solution to handle this process for hundreds of AWS accounts and thousands of resources. Which approach would best achieve this objective?","Consider how AWS Config's aggregation and multi-account features, along with automation capabilities, can be leveraged to manage a large-scale environment.",[271,275,279,283],{"id":272,"questionId":267,"content":273,"hint":274,"isCorrect":9},124278,"Use AWS Config Aggregator to collect configuration and compliance data from multiple accounts and set up AWS Systems Manager Automation to remediate non-compliant resources.","AWS Config Aggregator allows you to collect and view compliance data across multiple accounts, and AWS Systems Manager Automation can be leveraged to automatically handle remediation actions, thereby achieving large-scale automated compliance management.",{"id":276,"questionId":267,"content":277,"hint":278,"isCorrect":111},124279,"Use AWS Trusted Advisor to monitor compliance and AWS Config to remediate non-compliant resources.","AWS Trusted Advisor is more focused on best practice checks rather than compliance with regulatory standards, and AWS Config is best suited for ongoing configuration monitoring and compliance assessment.",{"id":280,"questionId":267,"content":281,"hint":282,"isCorrect":111},124280,"Set up Amazon CloudWatch Alarms to trigger AWS Lambda functions for remediation of non-compliant resources.","While CloudWatch and Lambda can provide remediation capabilities, this approach lacks the centralized compliance data management and scaling features offered by AWS Config Aggregator for large-scale environments.",{"id":284,"questionId":267,"content":285,"hint":286,"isCorrect":111},124281,"Manually review compliance reports from each AWS account and remediate non-compliant resources as necessary.","This approach is not feasible for large-scale environments with hundreds of AWS accounts and thousands of resources, as it requires too much manual effort and is prone to human error.",{"id":288,"title":289,"subtitle":290,"description":291,"content":94,"coverImageUrl":14,"weight":292,"subcategories":293},25,"Resilient Cloud Solutions","Domain 3","Emphasizes the implementation of highly available and scalable solutions that meet business continuity requirements. It includes designing for resilience, automating recovery processes, and deploying applications across multiple AWS regions.",15,[294,320,346],{"id":295,"title":296,"subtitle":297,"description":94,"questions":298},105,"Implement highly available solutions to meet resilience and business requirements","Task 3.1",[299],{"id":300,"subcategoryId":295,"content":301,"hint":302,"isPublic":9,"answers":303},27715,"Your company runs a fleet of web applications across multiple AWS regions to ensure high availability and low latency for users around the globe. The architecture leverages Amazon EC2 instances running behind Elastic Load Balancers (ELBs) and uses Amazon Route 53 for DNS routing. The business requirements dictate that even in the event of a regional outage, your users should experience minimal downtime and uninterrupted service. How can you meet these requirements with the least amount of manual intervention while also improving the performance of your globally distributed applications?","Consider solutions that not only provide automatic failover for regional availability but also optimize performance based on user proximity.",[304,308,312,316],{"id":305,"questionId":300,"content":306,"hint":307,"isCorrect":111},124658,"Set up EC2 Auto Scaling groups spanning across multiple Availability Zones within a single region.","While EC2 Auto Scaling across multiple AZs increases resilience within a region, it does not provide a solution for cross-region high availability or performance optimization based on global user traffic.",{"id":309,"questionId":300,"content":310,"hint":311,"isCorrect":9},124659,"Use AWS Global Accelerator to route traffic to healthy application endpoints in multiple AWS regions, ensuring automatic failover and optimized performance based on user's location.","AWS Global Accelerator provides a single entry point to your application and automatically routes user traffic to the optimal endpoint based on network latency, ensuring low latency and high availability. In case a region becomes unhealthy, Global Accelerator will route traffic to the next best region.",{"id":313,"questionId":300,"content":314,"hint":315,"isCorrect":111},124660,"Configure Route 53 to use a simple failover routing policy with health checks.","While Route 53 failover routing can manage regional outages, it doesn't provide optimal performance based on user location and can introduce additional latency. It also requires manual configuration and might have a slower failover time compared to Global Accelerator.",{"id":317,"questionId":300,"content":318,"hint":319,"isCorrect":111},124661,"Deploy an Application Load Balancer (ALB) with cross-zone load balancing enabled.","An ALB with cross-zone load balancing ensures availability within a single region but does not address cross-region traffic management or failover. It also does not enhance performance based on user's location.",{"id":321,"title":322,"subtitle":323,"description":94,"questions":324},106,"Implement solutions that are scalable to meet business requirements","Task 3.2",[325],{"id":326,"subcategoryId":321,"content":327,"hint":328,"isPublic":9,"answers":329},27802,"You are a DevOps engineer working for a financial services company that is expanding its services to global markets. The company aims to provide a highly available and scalable architecture to handle a large influx of API requests for processing transactions. You’ve been tasked with designing a serverless architecture that ensures each step in the transaction process, such as validation, authorization, and transaction logging, is carried out reliably and is highly available. Which of the following architectures best meets these requirements using AWS services?","Consider AWS services and features that allow you to manage the sequential steps of a business process while ensuring high availability and scalability.",[330,334,338,342],{"id":331,"questionId":326,"content":332,"hint":333,"isCorrect":9},125006,"Use AWS Step Functions to define the workflow for transaction processing, including Lambda functions for validation, authorization, and logging, fronted by Amazon API Gateway.","AWS Step Functions allow you to orchestrate various AWS services, ensuring that your transaction workflow is reliably executed. Each step can call a Lambda function for specific tasks, and an Amazon API Gateway can manage the API requests efficiently, ensuring high availability and scalability.",{"id":335,"questionId":326,"content":336,"hint":337,"isCorrect":111},125007,"Deploy a monolithic application on an Amazon RDS instance to handle validation, authorization, and logging.","An RDS-based monolithic application would not be scalable nor highly available to the same degree as a serverless architecture using AWS Step Functions and Lambda. RDS does not fit well for orchestrating multiple serverless functions and managing a high volume of API requests efficiently.",{"id":339,"questionId":326,"content":340,"hint":341,"isCorrect":111},125008,"Use Amazon EC2 instances to perform validation, authorization, and logging tasks, managed through Auto Scaling groups.","While EC2 instances can handle the tasks and Auto Scaling can help with scalability, this approach is not inherently serverless and can introduce unnecessary complexities compared to AWS Step Functions and Lambda for orchestrating and scaling the tasks.",{"id":343,"questionId":326,"content":344,"hint":345,"isCorrect":111},125009,"Use AWS Fargate to run containers that perform each step of the transaction workflow, managed by Amazon ECS.","AWS Fargate is a good option for container management and provides some serverless features, but it is not as seamless for orchestrating multi-step workflows as AWS Step Functions. Using Fargate alone would also require additional configurations to handle high availability and reliability at the level AWS Step Functions provides.",{"id":347,"title":348,"subtitle":349,"description":94,"questions":350},107,"Implement automated recovery processes to meet RTO and RPO requirements","Task 3.3",[351],{"id":352,"subcategoryId":347,"content":353,"hint":354,"isPublic":9,"answers":355},27867,"You are working as a DevOps engineer for a company that runs a web application using Amazon RDS with a Multi-AZ deployment for its database backend. The application is distributed across multiple EC2 instances behind an Application Load Balancer (ALB). Recently, you discovered that when a primary instance in your RDS Multi-AZ deployment fails, there is a brief period during which the application experiences downtime until the failover to the standby instance completes. The company's Service Level Agreement (SLA) requires minimal downtime to meet its Recovery Time Objective (RTO) and Recovery Point Objective (RPO) mandates. What steps should you take to configure the load balancer to ensure seamless recovery and maintain high availability in case of a backend failure?","Consider the role of the load balancer and how it handles traffic distribution and failover situations in the context of Amazon RDS Multi-AZ deployments. Think about how automated processes can be leveraged to meet RTO and RPO requirements.",[356,360,364,368],{"id":357,"questionId":352,"content":358,"hint":359,"isCorrect":9},125266,"Configure health checks on the Application Load Balancer to detect failures and reroute traffic accordingly.","By configuring health checks, the ALB can periodically determine the health state of the backend instances, including the RDS instances, and automatically reroute traffic to healthy instances, ensuring minimal disruption and meeting RTO and RPO requirements.",{"id":361,"questionId":352,"content":362,"hint":363,"isCorrect":111},125267,"Deploy the application across multiple regions to handle failover scenarios.","While deploying across multiple regions can enhance availability, it introduces complexity and does not directly address the configuration of the load balancer for automated recovery processes within a region.",{"id":365,"questionId":352,"content":366,"hint":367,"isCorrect":111},125268,"Modify the DNS settings to manually reroute traffic during failover.","This approach involves manual intervention, which can result in longer downtimes, not meeting the SLA requirements for automated recovery processes to achieve the desired RTO and RPO.",{"id":369,"questionId":352,"content":370,"hint":371,"isCorrect":111},125269,"Increase the instance size of the primary RDS database instance to handle failover more efficiently.","Increasing the instance size of the primary RDS instance does not directly address failover handling or optimize the load balancer's ability to reroute traffic seamlessly during backend failures.",{"id":373,"title":374,"subtitle":375,"description":376,"content":94,"coverImageUrl":14,"weight":292,"subcategories":377},26,"Monitoring and Logging","Domain 4","Covers the configuration, aggregation, and storage of logs and metrics. It also involves auditing, monitoring, and analyzing logs to detect issues, as well as automating monitoring and event management in complex environments.",[378,404,430],{"id":379,"title":380,"subtitle":381,"description":94,"questions":382},108,"Configure the collection, aggregation, and storage of logs and metrics","Task 4.1",[383],{"id":384,"subcategoryId":379,"content":385,"hint":386,"isPublic":9,"answers":387},27990,"A healthcare company uses AWS to host its applications, and it is critical to ensure the privacy and security of patient information. The DevOps team has been tasked with configuring Amazon CloudWatch to monitor application logs and store them in an encrypted format to comply with stringent security policies and industry regulations like HIPAA. After setting up CloudWatch, they must ensure that the log data collected is encrypted at rest. Which of the following actions should the DevOps team take to properly configure the encryption of log data using AWS KMS while ensuring the log metrics remain available for alerting and analysis?","Think about where and how CloudWatch Logs stores the log data and the mechanisms AWS provides to encrypt data at rest.",[388,392,396,400],{"id":389,"questionId":384,"content":390,"hint":391,"isCorrect":111},125758,"Manually encrypt the CloudWatch Logs data using an external encryption tool before storing them in S3.","This approach is cumbersome and counterintuitive, as CloudWatch Logs already provides built-in integration with AWS KMS for encryption. Manually handling encryption would add unnecessary complexity and potential for error.",{"id":393,"questionId":384,"content":394,"hint":395,"isCorrect":111},125759,"Set up CloudWatch Agent to encrypt logs using SSL\u002FTLS before transmitting them to CloudWatch Logs.","SSL\u002FTLS encrypts data in transit, but it does not provide encryption at rest. The question focuses on encrypting log data while stored, which SSL\u002FTLS does not address.",{"id":397,"questionId":384,"content":398,"hint":399,"isCorrect":9},125760,"Use AWS KMS to create a Customer Master Key (CMK) and configure CloudWatch Logs to use this CMK for encrypting log data.","CloudWatch Logs natively supports the use of AWS KMS Customer Master Keys (CMKs) for encrypting log data at rest. By creating a CMK and configuring CloudWatch Logs to use it, the logs will be encrypted according to the specified key, ensuring compliance with security policies.",{"id":401,"questionId":384,"content":402,"hint":403,"isCorrect":111},125761,"Enable Amazon S3 server-side encryption (SSE-S3) for the S3 bucket used by CloudWatch Logs.","While S3 server-side encryption is a valid method for encrypting data stored in S3, it does not apply to the native storage of CloudWatch Logs. CloudWatch Logs does not use S3 directly for log storage, and this approach would not address the encryption requirement.",{"id":405,"title":406,"subtitle":407,"description":94,"questions":408},109,"Audit, monitor, and analyze logs and metrics to detect issues","Task 4.2",[409],{"id":410,"subcategoryId":405,"content":411,"hint":412,"isPublic":9,"answers":413},28097,"A mid-sized e-commerce company uses AWS services to handle its backend operations. They store web server access logs in an Amazon S3 bucket and want to analyze these logs to identify potential security issues such as unauthorized access attempts and unusual traffic patterns. The company wants to use AWS services to perform these analyses efficiently. Which combination of AWS services should they use to achieve their goal?","Consider AWS services that can help you query and analyze data stored in S3, while also allowing deep log analysis and visualization.",[414,418,422,426],{"id":415,"questionId":410,"content":416,"hint":417,"isCorrect":9},126186,"Use Amazon Athena to query the logs stored in the S3 bucket and Amazon CloudWatch Logs Insights to further analyze the log data and create visualizations.","Amazon Athena allows querying of data directly in S3 using SQL, making it easy to analyze large sets of log data. Amazon CloudWatch Logs Insights can then be used for in-depth analysis and visualization of the logs, helping to detect and understand security issues.",{"id":419,"questionId":410,"content":420,"hint":421,"isCorrect":111},126187,"Use Amazon Redshift to store the logs and Amazon QuickSight to visualize the log data.","Amazon Redshift is a data warehouse solution and not optimized for log storage or real-time analysis. Amazon QuickSight can visualize data but requires the data to first be in a suitable database like Redshift, making the process more complex compared to using Athena and CloudWatch Logs Insights.",{"id":423,"questionId":410,"content":424,"hint":425,"isCorrect":111},126188,"Use AWS CloudTrail to monitor API calls and AWS Config to track resource changes for log analysis.","AWS CloudTrail tracks API calls, and AWS Config monitors configuration changes, but neither is specifically designed for the purpose of querying and analyzing logs stored in S3. They serve different monitoring and compliance purposes rather than log data analysis.",{"id":427,"questionId":410,"content":428,"hint":429,"isCorrect":111},126189,"Use AWS Glue to transform the logs stored in the S3 bucket and AWS Lambda to process log files for analysis.","While AWS Glue can transform data and AWS Lambda can process log files, this combination is not primarily designed for querying and analyzing logs. It would also require custom scripts and potentially more management overhead.",{"id":431,"title":432,"subtitle":433,"description":94,"questions":434},110,"Automate monitoring and event management of complex environments","Task 4.3",[435],{"id":436,"subcategoryId":431,"content":437,"hint":438,"isPublic":9,"answers":439},28207,"You are managing a large-scale web application deployed on AWS. The application uses an Application Load Balancer (ALB) and Amazon Route 53 to distribute traffic across multiple EC2 instances. To ensure high availability and fault tolerance, you have configured health checks for both the ALB and Route 53. You want to automate monitoring and event management such that if any of the health checks fail, an alert is triggered, and specific remediation steps are automatically initiated. Which of the following solutions best accomplishes this task using AWS Config?","Consider how AWS Config can be used to monitor the configuration of AWS resources and trigger automated actions based on changes or specific conditions.",[440,444,448,452],{"id":441,"questionId":436,"content":442,"hint":443,"isCorrect":111},126626,"Use CloudWatch Alarms to directly monitor the health check statuses and manually initiate remediation steps when an alarm is triggered.","While CloudWatch Alarms can monitor health check statuses, this solution lacks automation for the remediation steps. The goal is to automate both monitoring and event management, which this approach doesn’t fully satisfy.",{"id":445,"questionId":436,"content":446,"hint":447,"isCorrect":111},126627,"Configure AWS Elastic Beanstalk to manage health checks and automatically replace unhealthy instances.","AWS Elastic Beanstalk simplifies application deployment and management but does not provide the specific level of automation and integration that AWS Config offers for monitoring health checks and initiating predefined remediation steps.",{"id":449,"questionId":436,"content":450,"hint":451,"isCorrect":111},126628,"Use AWS Trusted Advisor to monitor health checks and notify the admin team via email for manual intervention.","AWS Trusted Advisor offers insights and recommendations to optimize AWS infrastructure but is not designed for real-time monitoring or automated event management.",{"id":453,"questionId":436,"content":454,"hint":455,"isCorrect":9},126629,"Create an AWS Config rule to monitor the health check status of ALB and Route 53, and set up an Amazon SNS topic to trigger an AWS Lambda function for remediation steps if the rule is violated.","Using AWS Config rules allows you to continually evaluate the configuration settings of your AWS resources. By integrating with Amazon SNS and AWS Lambda, you can automate alerts and remediation steps effectively when specific conditions are met, such as the failure of health checks.",{"id":457,"title":458,"subtitle":459,"description":460,"content":94,"coverImageUrl":14,"weight":461,"subcategories":462},27,"Incident and Event Response","Domain 5","Involves managing event sources, processing events, implementing configuration changes, and troubleshooting system and application failures to ensure timely incident response and system recovery.",14,[463,489,515],{"id":464,"title":465,"subtitle":466,"description":94,"questions":467},111,"Manage event sources to process, notify, and take action in response to events","Task 5.1",[468],{"id":469,"subcategoryId":464,"content":470,"hint":471,"isPublic":9,"answers":472},28236,"Your team has built a financial application that stores transactional data in an Amazon DynamoDB table. To ensure the consistency and reliability of your system, you need to update a secondary system whenever there is an insertion or update in your DynamoDB table. The requirements are to process these changes efficiently, ensure persistence, and allow retry mechanisms in case of failures. What AWS service combination would be the most suitable for this task?","Consider services that are designed to capture changes and can process, notify, and take action in response to events, especially focusing on data consistency and reliability.",[473,477,481,485],{"id":474,"questionId":469,"content":475,"hint":476,"isCorrect":9},126742,"Use DynamoDB Streams to capture changes, send them to an AWS Lambda function to process the data, and then use an Amazon SQS queue to handle any retry logic.","DynamoDB Streams can capture changes to the table. AWS Lambda can process those changes and Amazon SQS can provide the required durability and retry logic for eventual consistency.",{"id":478,"questionId":469,"content":479,"hint":480,"isCorrect":111},126743,"Use Amazon SNS to publish changes directly from DynamoDB and then process them with an AWS Lambda function.","Amazon SNS can send notifications, but it doesn't support retries and persistence in the same way Amazon SQS does.",{"id":482,"questionId":469,"content":483,"hint":484,"isCorrect":111},126744,"Use AWS Step Functions to monitor changes in DynamoDB and coordinate the processing steps.","AWS Step Functions are excellent for orchestrating complex workflows, but they are not designed to natively capture changes in DynamoDB.",{"id":486,"questionId":469,"content":487,"hint":488,"isCorrect":111},126745,"Use Amazon Kinesis Data Streams to capture changes, a Kinesis Data Firehose to transform the data, and Amazon SNS to notify the secondary system.","Amazon Kinesis is highly scalable and can process large streams of data, but it is more complex and may be overkill for simple change processing. Also, Amazon Kinesis Data Firehose and SNS don't provide built-in retries and persistence like SQS.",{"id":490,"title":491,"subtitle":492,"description":94,"questions":493},112,"Implement configuration changes in response to events","Task 5.2",[494],{"id":495,"subcategoryId":490,"content":496,"hint":497,"isPublic":9,"answers":498},28286,"You are working as an AWS DevOps Engineer and you recently implemented an instance monitoring solution using AWS EventBridge. Your EventBridge rule is triggering an AWS Lambda function whenever a specific EC2 instance enters a 'Stopped' state unexpectedly. The Lambda function should automatically remediate this non-desired state by starting the instance again. During a system audit, you noticed the instance remained in a 'Stopped' state and was never started as expected. Which action will most likely resolve this issue?","Consider the key components involved in triggering events and performing actions with AWS EventBridge and Lambda.",[499,503,507,511],{"id":500,"questionId":495,"content":501,"hint":502,"isCorrect":111},126942,"Modify the Lambda function to use AWS Systems Manager Run Command instead of directly calling EC2 API.","While AWS Systems Manager Run Command can be used to manage EC2 instances, the core issue is the permissions for the Lambda function. Changing the method of execution will not resolve the permission issue.",{"id":504,"questionId":495,"content":505,"hint":506,"isCorrect":9},126943,"Check the IAM role permissions for the Lambda function and ensure it has 'ec2:StartInstances' permission.","If the Lambda function does not have the appropriate permissions to start the EC2 instance, it will not be able to execute the necessary API call to change the state from 'Stopped' to 'Running'.",{"id":508,"questionId":495,"content":509,"hint":510,"isCorrect":111},126944,"Update the EventBridge rule to trigger more frequently.","Updating the frequency of the EventBridge rule does not address the issue of Lambda not having the necessary permissions to start the EC2 instance.",{"id":512,"questionId":495,"content":513,"hint":514,"isCorrect":111},126945,"Increase the memory and timeout settings of the Lambda function.","Increased memory and timeout settings can help with performance but will not resolve the core issue of the Lambda function lacking the necessary permissions to execute 'StartInstances' API calls.",{"id":516,"title":517,"subtitle":518,"description":94,"questions":519},113,"Troubleshoot system and application failures","Task 5.3",[520],{"id":521,"subcategoryId":516,"content":522,"hint":523,"isPublic":9,"answers":524},28328,"Your company has deployed a set of microservices on Amazon ECS using the Fargate launch type for a new application. Recently, some of the containers have started failing intermittently. Upon investigation, you’ve noticed that tasks are being killed unexpectedly. To ensure the stability of the application, you need to troubleshoot and resolve this issue promptly. What action should you take to troubleshoot the cause of the failed ECS tasks?","Consider the different aspects of the task lifecycle in ECS, including resource limits, logging, and service events.",[525,529,533,537],{"id":526,"questionId":521,"content":527,"hint":528,"isCorrect":111},127110,"Restart the ECS service to refresh the tasks and resolve the failure issue.","Restarting the ECS service might temporarily resolve the problem, but it does not address the underlying cause of the task failures. Proper troubleshooting using logs and other diagnostic tools is crucial to identify and fix the root cause.",{"id":530,"questionId":521,"content":531,"hint":532,"isCorrect":9},127111,"Check the CloudWatch Logs for the ECS tasks to identify error messages and investigate resource constraints or application-level issues.","CloudWatch Logs provide detailed information about the application running inside the containers. Reviewing this information can help you identify any error messages, resource constraints, or other issues that may be causing the tasks to fail.",{"id":534,"questionId":521,"content":535,"hint":536,"isCorrect":111},127112,"Increase the task memory and CPU settings to maximum values to prevent tasks from being killed.","While resource constraints can cause tasks to fail, simply increasing the CPU and memory values to the maximum without understanding the root cause can lead to resource wastage and potential other issues. The appropriate action is to first diagnose the issue using the logs.",{"id":538,"questionId":521,"content":539,"hint":540,"isCorrect":111},127113,"Disable auto-scaling for the ECS service to stabilize the running tasks.","Disabling auto-scaling does not resolve the issue of tasks being killed. Auto-scaling is designed to manage resource allocation according to demand, and turning it off could lead to under-provisioning or over-provisioning of resources. The focus should be on identifying the root cause of the failures.",{"id":542,"title":543,"subtitle":544,"description":545,"content":94,"coverImageUrl":14,"weight":207,"subcategories":546},28,"Security and Compliance","Domain 6","This domain addresses the implementation of security controls and compliance measures at scale, including identity and access management, data protection, security monitoring, and auditing within AWS environments.",[547,573,599],{"id":548,"title":549,"subtitle":550,"description":94,"questions":551},114,"Implement techniques for identity and access management at scale","Task 6.1",[552],{"id":553,"subcategoryId":548,"content":554,"hint":555,"isPublic":9,"answers":556},28416,"You are designing a new internal application for an enterprise that is rapidly scaling its AWS infrastructure. To ensure secure access management, you need to implement permissions boundaries to restrict the maximum permissions that IAM and machine identities can receive. You also need to ensure that only certain trusted administrators can grant IAM roles with elevated permissions. What combination of approaches should you use to achieve this?\n\nA) Apply permissions boundaries to all IAM roles and users, and grant administrators the necessary IAM permissions to make changes.\n\nB) Use AWS Organizations Service Control Policies (SCPs) to manage permissions across accounts, and use IAM roles with MFA to restrict access further.\n\nC) Apply permissions boundaries to IAM roles and users, use AWS STS for temporary elevated permissions when required, and implement MFA for administrative actions.\n\nD) Use IAM access advisor combined with VPC endpoint policies to restrict permissions and access.","Consider how permissions boundaries limit the permissions of IAM roles and users, and how temporary credentials and MFA enhance security for administrative tasks.",[557,561,565,569],{"id":558,"questionId":553,"content":559,"hint":560,"isCorrect":111},127462,"A) Apply permissions boundaries to all IAM roles and users, and grant administrators the necessary IAM permissions to make changes.","While applying permissions boundaries is correct, simply granting administrators necessary IAM permissions doesn't address temporary elevated permissions for specific tasks or include MFA, reducing overall security.",{"id":562,"questionId":553,"content":563,"hint":564,"isCorrect":111},127463,"D) Use IAM access advisor combined with VPC endpoint policies to restrict permissions and access.","IAM access advisor helps in analyzing and reviewing permissions but does not provide enforcement or define boundaries. VPC endpoint policies manage access to VPC endpoints and do not directly relate to permissions management for roles and users.",{"id":566,"questionId":553,"content":567,"hint":568,"isCorrect":9},127464,"C) Apply permissions boundaries to IAM roles and users, use AWS STS for temporary elevated permissions when required, and implement MFA for administrative actions.","This approach ensures that IAM roles and users have restricted permissions through permissions boundaries. AWS STS can provide temporary credentials for elevated permissions, and MFA adds a layer of security for administrative actions, aligning with best practices for identity and access management at scale.",{"id":570,"questionId":553,"content":571,"hint":572,"isCorrect":111},127465,"B) Use AWS Organizations Service Control Policies (SCPs) to manage permissions across accounts, and use IAM roles with MFA to restrict access further.","SCPs help in managing permissions across accounts but do not restrict permissions at the level of individual roles and users. Although MFA enhances security, SCPs alone are not sufficient for fine-grained control using permissions boundaries.",{"id":574,"title":575,"subtitle":576,"description":94,"questions":577},115,"Apply automation for security controls and data protection","Task 6.2",[578],{"id":579,"subcategoryId":574,"content":580,"hint":581,"isPublic":9,"answers":582},28480,"You are designing a secure application that stores sensitive configuration data, such as database credentials, API keys, and authentication information. Your goal is to ensure that this data is both encrypted at rest and securely accessible by your application during runtime without exposing the secrets in plain text. To achieve this, you decide to use AWS Secrets Manager in conjunction with AWS Key Management Service (KMS). Which of the following approaches will help you automate the security controls and data protection for this application?","Consider how AWS Secrets Manager integrates with other AWS services for encryption and managing access to secrets to protect sensitive data.",[583,587,591,595],{"id":584,"questionId":579,"content":585,"hint":586,"isCorrect":111},127718,"Store sensitive data in Amazon S3 using server-side encryption and manually update the application configuration files whenever changes are needed.","While server-side encryption with Amazon S3 provides data at rest protection, manually updating application configuration files introduces human error and does not fully automate the process, failing to meet the requirement for automated security controls.",{"id":588,"questionId":579,"content":589,"hint":590,"isCorrect":111},127719,"Store the secrets in a DynamoDB table with encryption enabled and restrict access via IAM policies, implementing a script to periodically rotate the secrets.","Storing secrets in DynamoDB and using IAM policies for access control ensures data protection, but manually scripting secret rotation introduces complexity and potential security risks, lacking full automation and robust management features provided by AWS Secrets Manager.",{"id":592,"questionId":579,"content":593,"hint":594,"isCorrect":9},127720,"Use AWS Secrets Manager to store the sensitive data and configure it to use an AWS KMS key for encryption. Implement a Lambda function that automatically rotates the secrets and updates the application configuration accordingly.","Using AWS Secrets Manager with AWS KMS ensures that the sensitive data is encrypted at rest. Automating secret rotation with a Lambda function helps keep the secrets updated and secure without manual intervention, aligning with the task of applying automation for security controls and data protection.",{"id":596,"questionId":579,"content":597,"hint":598,"isCorrect":111},127721,"Use AWS Systems Manager Parameter Store to store sensitive data and configure it with default encryption settings without configuring Lambda for rotation.","AWS Systems Manager Parameter Store can store sensitive data and supports encryption, but it doesn't automatically integrate with IAM policies or provide automated secret rotation without additional configuration. Lack of automation does not align with the requirement for continuous and automated data protection.",{"id":600,"title":601,"subtitle":602,"description":94,"questions":603},116,"Implement security monitoring and auditing solutions","Task 6.3",[604],{"id":605,"subcategoryId":600,"content":606,"hint":607,"isPublic":9,"answers":608},28548,"Your company operates several microservices that are critical to business operations. You've recently noticed some suspicious activity in the logs and need to ensure that your AWS environment remains compliant with security policies. Your team uses AWS Config for this purpose. Which of the following actions would allow you to continuously monitor and analyze the logs, metrics, and security findings to ensure compliance with your security policies?","Consider features of AWS Config that are related to compliance and remediation.",[609,613,617,621],{"id":610,"questionId":605,"content":611,"hint":612,"isCorrect":111},127990,"Use AWS Glue to transform and move data from Amazon S3 to Amazon Redshift for log analysis.","AWS Glue is an ETL (Extract, Transform, Load) service that is not directly related to continuous monitoring and compliance of security policies. It's used for preparing data for analytics, not for real-time security compliance.",{"id":614,"questionId":605,"content":615,"hint":616,"isCorrect":9},127991,"Set up AWS Config rules to continuously evaluate the configuration settings of your AWS resources and integrate it with Amazon CloudWatch to analyze metrics and AWS CloudTrail for security logging.","AWS Config rules can be used to continuously check compliance of AWS resources based on specified rules. Integration with Amazon CloudWatch and AWS CloudTrail helps to monitor and analyze logs and metrics in real-time, ensuring all suspicious activities are detected and proper actions are taken.",{"id":618,"questionId":605,"content":619,"hint":620,"isCorrect":111},127992,"Deploy AWS Elastic Beanstalk to automatically handle compliance settings for applications.","AWS Elastic Beanstalk is a service for deploying and scaling web applications and services; it does not provide tools specifically for monitoring and compliance of security policies.",{"id":622,"questionId":605,"content":623,"hint":624,"isCorrect":111},127993,"Configure Amazon QuickSight to visualize data from AWS Config and CloudTrail.","While Amazon QuickSight can help you visualize data, it does not provide real-time monitoring or compliance checks necessary for security and compliance tasks.",[626,631,636,642,648,654,660,666,671,676,681,687,693,699,705,711,717,723,729,735,741,747,753,759,765,771,777,783,789,795,801,807,813,817,821,826,831,836,841,846,851,855,860,865,871,877,883,889,895,901,907,913,919,925,931,937,943,949,955,961,967,973,979,985,991,997,1003,1008,1014,1020,1026,1032,1038,1044,1050,1056,1062,1068,1074,1080,1086,1092,1098,1104,1110,1116,1122,1128,1134,1140,1145,1151,1157,1163,1169,1175,1181,1187,1192,1197,1203],{"id":33,"title":627,"description":628,"slug":629,"coverImageUrl":630},"Amazon Athena","Amazon Athena is a query service for analyzing data in Amazon S3 using SQL, allowing direct data analysis in S3 without loading it into databases or warehouses.","amazon-athena","\u002Fimages\u002Fprovider-services\u002Famazon-athena\u002Fcovers\u002FArch_Amazon-Athena_64.png",{"id":52,"title":632,"description":633,"slug":634,"coverImageUrl":635},"Amazon EMR","Amazon EMR is a managed AWS service for large-scale data processing with frameworks like Hadoop and Spark, offering petabyte-scale analytics on a scalable infrastructure at a lower cost than owning Hadoop clusters.","amazon-emr","\u002Fimages\u002Fprovider-services\u002Famazon-emr\u002Fcovers\u002FArch_Amazon-EMR_64.png",{"id":637,"title":638,"description":639,"slug":640,"coverImageUrl":641},11,"Amazon OpenSearch Service","Amazon OpenSearch Service is a scalable and fully managed search and analytics service powered by the open source Elasticsearch and OpenSearch engines, designed for real-time application monitoring, log analytics, and search functionality.","amazon-opensearch-service","\u002Fimages\u002Fprovider-services\u002Famazon-opensearch-service\u002Fcovers\u002FArch_Amazon-OpenSearch-Service_64.png",{"id":643,"title":644,"description":645,"slug":646,"coverImageUrl":647},12,"Amazon Redshift","Amazon Redshift is a fully managed, petabyte-scale data warehouse service in the cloud from Amazon Web Services (AWS), designed for large scale data set storage and analysis.","amazon-redshift","\u002Fimages\u002Fprovider-services\u002Famazon-redshift\u002Fcovers\u002FArch_Amazon-Redshift_64.png",{"id":649,"title":650,"description":651,"slug":652,"coverImageUrl":653},13,"Amazon QuickSight","Amazon QuickSight is a fast, cloud-powered business intelligence service that makes it easy to deliver insights to everyone in your organization by providing interactive visualizations, dashboards, and ML-powered insights.","amazon-quicksight","\u002Fimages\u002Fprovider-services\u002Famazon-quicksight\u002Fcovers\u002FArch_Amazon-QuickSight_64.png",{"id":655,"title":656,"description":657,"slug":658,"coverImageUrl":659},18,"Amazon AppFlow","Amazon AppFlow is a fully managed integration service that enables users to securely transfer data between Software as a Service (SaaS) applications like Salesforce, ServiceNow, and AWS services, and Amazon S3, facilitating automated workflows and data synchronization.","amazon-appflow","\u002Fimages\u002Fprovider-services\u002Famazon-appflow\u002Fcovers\u002FArch_Amazon-AppFlow_64.png",{"id":661,"title":662,"description":663,"slug":664,"coverImageUrl":665},21,"Amazon EventBridge","Amazon EventBridge is a serverless event bus service provided by AWS that enables applications to communicate with each other using events, facilitating the building of event-driven architectures.","amazon-eventbridge","\u002Fimages\u002Fprovider-services\u002Famazon-eventbridge\u002Fcovers\u002FArch_Amazon-EventBridge_64.png",{"id":91,"title":667,"description":668,"slug":669,"coverImageUrl":670},"Amazon Simple Notification Service (Amazon SNS)","Amazon Simple Notification Service (Amazon SNS) is a fully managed messaging service for both application-to-application (A2A) and application-to-person (A2P) communication, enabling the delivery of messages or notifications to subscribers or other applications.","amazon-simple-notification-service-(amazon-sns)","\u002Fimages\u002Fprovider-services\u002Famazon-simple-notification-service-(amazon-sns)\u002Fcovers\u002FArch_Amazon-Simple-Notification-Service_64.png",{"id":203,"title":672,"description":673,"slug":674,"coverImageUrl":675},"Amazon Simple Queue Service (Amazon SQS)","Amazon Simple Queue Service (Amazon SQS) is a scalable, fully managed message queuing service that enables the decoupling and scaling of microservices, distributed systems, and serverless applications.","amazon-simple-queue-service-(amazon-sqs)","\u002Fimages\u002Fprovider-services\u002Famazon-simple-queue-service-(amazon-sqs)\u002Fcovers\u002FArch_Amazon-Simple-Queue-Service_64.png",{"id":288,"title":677,"description":678,"slug":679,"coverImageUrl":680},"AWS Step Functions","AWS Step Functions is a cloud service from Amazon Web Services that enables developers to coordinate multiple AWS services into serverless workflows, allowing the creation and execution of complex business processes and applications through visual workflows.","aws-step-functions","\u002Fimages\u002Fprovider-services\u002Faws-step-functions\u002Fcovers\u002FArch_AWS-Step-Functions_64.png",{"id":682,"title":683,"description":684,"slug":685,"coverImageUrl":686},34,"Amazon EC2","Amazon EC2 (Elastic Compute Cloud) is a web service that provides resizable compute capacity in the cloud, allowing users to run and manage virtual servers.","amazon-ec2","\u002Fimages\u002Fprovider-services\u002Famazon-ec2\u002Fcovers\u002FArch_Amazon-EC2_64.png",{"id":688,"title":689,"description":690,"slug":691,"coverImageUrl":692},36,"Amazon EC2 Auto Scaling","Amazon EC2 Auto Scaling is a service that automatically adjusts the number of Amazon EC2 instances in your deployment to maintain performance and minimize costs based on defined conditions such as traffic or resource utilization.","amazon-ec2-auto-scaling","\u002Fimages\u002Fprovider-services\u002Famazon-ec2-auto-scaling\u002Fcovers\u002FArch_Amazon-EC2-Auto-Scaling_64.png",{"id":694,"title":695,"description":696,"slug":697,"coverImageUrl":698},37,"AWS Elastic Beanstalk","AWS Elastic Beanstalk is a cloud deployment service that automates the process of deploying applications in the AWS cloud, allowing developers to upload their code and have the service automatically handle the deployment details such as resource provisioning, load balancing, auto-scaling, and monitoring.","aws-elastic-beanstalk","\u002Fimages\u002Fprovider-services\u002Faws-elastic-beanstalk\u002Fcovers\u002FArch_AWS-Elastic-Beanstalk_64.png",{"id":700,"title":701,"description":702,"slug":703,"coverImageUrl":704},39,"AWS Serverless Application Repository","The AWS Serverless Application Repository is a managed repository for serverless applications and components, allowing developers to discover, deploy, and publish serverless applications and components on AWS.","aws-serverless-application-repository","\u002Fimages\u002Fprovider-services\u002Faws-serverless-application-repository\u002Fcovers\u002FArch_AWS-Serverless-Application-Repository_64.png",{"id":706,"title":707,"description":708,"slug":709,"coverImageUrl":710},47,"Amazon EKS Distro","Amazon EKS Distro is an open-source Kubernetes distribution provided by Amazon Web Services (AWS) that enables users to create reliable and secure Kubernetes clusters on-premises or in the cloud, compatible with Amazon EKS.","amazon-eks-distro","\u002Fimages\u002Fprovider-services\u002Famazon-eks-distro\u002Fcovers\u002FArch_Amazon-EKS-Distro_64.png",{"id":712,"title":713,"description":714,"slug":715,"coverImageUrl":716},48,"Amazon Elastic Container Registry (Amazon ECR)","Amazon Elastic Container Registry (Amazon ECR) is a fully managed Docker container registry that makes it easy for developers to store, manage, and deploy Docker container images.","amazon-elastic-container-registry-(amazon-ecr)","\u002Fimages\u002Fprovider-services\u002Famazon-elastic-container-registry-(amazon-ecr)\u002Fcovers\u002FArch_Amazon-Elastic-Container-Registry_64.png",{"id":718,"title":719,"description":720,"slug":721,"coverImageUrl":722},54,"Amazon Elastic Container Service (Amazon ECS)","Amazon Elastic Container Service (Amazon ECS) is a fully managed container orchestration service that allows you to run and scale containerized applications on AWS.","amazon-elastic-container-service-(amazon-ecs)","\u002Fimages\u002Fprovider-services\u002Famazon-elastic-container-service-(amazon-ecs)\u002Fcovers\u002FArch_Amazon-Elastic-Container-Service_64.png",{"id":724,"title":725,"description":726,"slug":727,"coverImageUrl":728},55,"Amazon Elastic Kubernetes Service (Amazon EKS)","Amazon Elastic Kubernetes Service (Amazon EKS) is a managed service that makes it easy to deploy, manage, and scale containerized applications using Kubernetes on AWS.","amazon-elastic-kubernetes-service-(amazon-eks)","\u002Fimages\u002Fprovider-services\u002Famazon-elastic-kubernetes-service-(amazon-eks)\u002Fcovers\u002FArch_Amazon-Elastic-Kubernetes-Service_64.png",{"id":730,"title":731,"description":732,"slug":733,"coverImageUrl":734},56,"Amazon Aurora","Amazon Aurora is a fully managed relational database service by Amazon Web Services (AWS) that is designed to be compatible with MySQL and PostgreSQL while offering the performance and availability of commercial databases with improved scalability, durability, and security.","amazon-aurora","\u002Fimages\u002Fprovider-services\u002Famazon-aurora\u002Fcovers\u002FArch_Amazon-Aurora_64.png",{"id":736,"title":737,"description":738,"slug":739,"coverImageUrl":740},57,"Amazon Aurora Serverless","Amazon Aurora Serverless is an on-demand, auto-scaling configuration for the Amazon Aurora database that automatically adjusts computing resources based on application demand, optimizing both performance and cost.","amazon-aurora-serverless","\u002Fimages\u002Fprovider-services\u002Famazon-aurora-serverless\u002Fcovers\u002FArch_Amazon-Aurora_64.png",{"id":742,"title":743,"description":744,"slug":745,"coverImageUrl":746},59,"Amazon DocumentDB (with MongoDB compatibility)","Amazon DocumentDB (with MongoDB compatibility) is a fully managed, scalable, and highly available document database service designed to be compatible with MongoDB workloads, allowing you to use MongoDB tools and drivers for managing and querying your data.","amazon-documentdb-(with-mongodb-compatibility)","\u002Fimages\u002Fprovider-services\u002Famazon-documentdb-(with-mongodb-compatibility)\u002Fcovers\u002FArch_Amazon-DocumentDB_64.png",{"id":748,"title":749,"description":750,"slug":751,"coverImageUrl":752},60,"Amazon DynamoDB","Amazon DynamoDB is a fully managed NoSQL database service provided by Amazon Web Services (AWS) that offers fast and predictable performance with seamless scalability for applications that need consistent, single-digit millisecond latency at any scale.","amazon-dynamodb","\u002Fimages\u002Fprovider-services\u002Famazon-dynamodb\u002Fcovers\u002FArch_Amazon-DynamoDB_64.png",{"id":754,"title":755,"description":756,"slug":757,"coverImageUrl":758},61,"Amazon ElastiCache","Amazon ElastiCache is a fully managed in-memory caching service that helps improve the performance of web applications by allowing you to retrieve information from fast, managed, in-memory caches, instead of relying solely on slower disk-based databases.","amazon-elasticache","\u002Fimages\u002Fprovider-services\u002Famazon-elasticache\u002Fcovers\u002FArch_Amazon-ElastiCache_64.png",{"id":760,"title":761,"description":762,"slug":763,"coverImageUrl":764},65,"Amazon RDS","Amazon RDS (Relational Database Service) is a managed service provided by Amazon Web Services (AWS) that makes it easier to set up, operate, and scale a relational database in the cloud by handling routine database tasks such as provisioning, patching, backup, recovery, and scaling.","amazon-rds","\u002Fimages\u002Fprovider-services\u002Famazon-rds\u002Fcovers\u002FArch_Amazon-RDS_64.png",{"id":766,"title":767,"description":768,"slug":769,"coverImageUrl":770},67,"AWS X-Ray","AWS X-Ray is a service provided by Amazon Web Services that allows developers to analyze and debug production, distributed applications, such as those built using a microservices architecture, by providing insights into how applications and their underlying services are performing to identify and troubleshoot the root cause of performance issues and errors.","aws-x-ray","\u002Fimages\u002Fprovider-services\u002Faws-x-ray\u002Fcovers\u002FArch_AWS-X-Ray_64.png",{"id":772,"title":773,"description":774,"slug":775,"coverImageUrl":776},73,"Amazon API Gateway","Amazon API Gateway is a fully managed service that makes it easy for developers to create, publish, maintain, monitor, and secure APIs at any scale, providing a way to facilitate communication between software applications through web services.","amazon-api-gateway","\u002Fimages\u002Fprovider-services\u002Famazon-api-gateway\u002Fcovers\u002FArch_Amazon-API-Gateway_64.png",{"id":778,"title":779,"description":780,"slug":781,"coverImageUrl":782},88,"AWS Auto Scaling","AWS Auto Scaling is a service provided by Amazon Web Services that automatically adjusts the number of computing resources in response to demand, ensuring that your application maintains consistent performance at the lowest possible cost.","aws-auto-scaling","\u002Fimages\u002Fprovider-services\u002Faws-auto-scaling\u002Fcovers\u002FArch_AWS-Auto-Scaling_64.png",{"id":784,"title":785,"description":786,"slug":787,"coverImageUrl":788},92,"AWS CloudFormation","AWS CloudFormation is a service that enables users to model, provision, and manage AWS and third-party application resources in a safe, repeatable, and efficient manner using templates.","aws-cloudformation","\u002Fimages\u002Fprovider-services\u002Faws-cloudformation\u002Fcovers\u002FArch_AWS-CloudFormation_64.png",{"id":790,"title":791,"description":792,"slug":793,"coverImageUrl":794},93,"AWS CloudTrail","AWS CloudTrail is a service that provides a comprehensive log of user activity and API usage across the AWS infrastructure, enabling security monitoring, compliance auditing, and operational troubleshooting.","aws-cloudtrail","\u002Fimages\u002Fprovider-services\u002Faws-cloudtrail\u002Fcovers\u002FArch_AWS-CloudTrail_64.png",{"id":796,"title":797,"description":798,"slug":799,"coverImageUrl":800},95,"Amazon CloudWatch","Amazon CloudWatch is a monitoring and observability service offered by Amazon Web Services (AWS) that provides data and actionable insights to monitor applications, respond to system-wide performance changes, optimize resource utilization, and get a unified view of operational health.","amazon-cloudwatch","\u002Fimages\u002Fprovider-services\u002Famazon-cloudwatch\u002Fcovers\u002FArch_Amazon-CloudWatch_64.png",{"id":802,"title":803,"description":804,"slug":805,"coverImageUrl":806},96,"AWS Command Line Interface (AWS CLI)","The AWS Command Line Interface (AWS CLI) is a unified tool that allows you to manage and automate AWS services directly from the terminal or command prompt.","aws-command-line-interface-(aws-cli)","\u002Fimages\u002Fprovider-services\u002Faws-command-line-interface-(aws-cli)\u002Fcovers\u002FArch_AWS-Command-Line-Interface_64.png",{"id":808,"title":809,"description":810,"slug":811,"coverImageUrl":812},97,"AWS Compute Optimizer","AWS Compute Optimizer is a service that provides recommendations to optimize Amazon Web Services compute resources for performance and cost by analyzing historical utilization metrics.","aws-compute-optimizer","\u002Fimages\u002Fprovider-services\u002Faws-compute-optimizer\u002Fcovers\u002FArch_AWS-Compute-Optimizer_64.png",{"id":98,"title":259,"description":814,"slug":815,"coverImageUrl":816},"AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources, providing a detailed view of their compliance with the configurations specified by your internal guidelines and regulatory standards.","aws-config","\u002Fimages\u002Fprovider-services\u002Faws-config\u002Fcovers\u002FArch_AWS-Config_64.png",{"id":125,"title":251,"description":818,"slug":819,"coverImageUrl":820},"AWS Control Tower is a cloud service that automatically sets up and governs a secure, multi-account AWS environment based on best practices established through AWSâs experience working with thousands of enterprises.","aws-control-tower","\u002Fimages\u002Fprovider-services\u002Faws-control-tower\u002Fcovers\u002FArch_AWS-Control-Tower_64.png",{"id":151,"title":822,"description":823,"slug":824,"coverImageUrl":825},"AWS Health Dashboard","The AWS Health Dashboard is a service provided by Amazon Web Services that shows the current status of AWS services and alerts to any operational issues or scheduled maintenance events affecting the user's resources.","aws-health-dashboard","\u002Fimages\u002Fprovider-services\u002Faws-health-dashboard\u002Fcovers\u002FArch_AWS-Health-Dashboard_64.png",{"id":177,"title":827,"description":828,"slug":829,"coverImageUrl":830},"AWS License Manager","AWS License Manager is a service that helps users manage software licenses from various vendors across AWS and on-premises environments, enabling them to enforce license rules and avoid compliance risks.","aws-license-manager","\u002Fimages\u002Fprovider-services\u002Faws-license-manager\u002Fcovers\u002FArch_AWS-License-Manager_64.png",{"id":210,"title":832,"description":833,"slug":834,"coverImageUrl":835},"Amazon Managed Grafana","Amazon Managed Grafana is a fully managed service by AWS that provides scalable, secure, and easily deployable visualizations for real-time analytics, operational dashboards, and monitoring across various data sources.","amazon-managed-grafana","\u002Fimages\u002Fprovider-services\u002Famazon-managed-grafana\u002Fcovers\u002FArch_Amazon-Managed-Grafana_64.png",{"id":321,"title":837,"description":838,"slug":839,"coverImageUrl":840},"Amazon Managed Service for Prometheus","Amazon Managed Service for Prometheus is a fully managed Prometheus-compatible monitoring service that makes it easy to monitor containerized applications at scale on AWS.","amazon-managed-service-for-prometheus","\u002Fimages\u002Fprovider-services\u002Famazon-managed-service-for-prometheus\u002Fcovers\u002FArch_Amazon-Managed-Service-for-Prometheus_64.png",{"id":379,"title":842,"description":843,"slug":844,"coverImageUrl":845},"AWS Organizations","AWS Organizations is a cloud service from Amazon Web Services that allows you to centrally manage and govern your environment as you scale your AWS resources across multiple accounts.","aws-organizations","\u002Fimages\u002Fprovider-services\u002Faws-organizations\u002Fcovers\u002FArch_AWS-Organizations_64.png",{"id":405,"title":847,"description":848,"slug":849,"coverImageUrl":850},"AWS Proton","AWS Proton is a fully managed application delivery service from Amazon Web Services designed to automate and manage the provisioning, deployment, and monitoring of serverless and container-based applications, facilitating the adoption of microservices architecture with less effort.","aws-proton","\u002Fimages\u002Fprovider-services\u002Faws-proton\u002Fcovers\u002FArch_AWS-Proton_64.png",{"id":431,"title":255,"description":852,"slug":853,"coverImageUrl":854},"AWS Service Catalog allows organizations to create and manage catalogs of IT services that are approved for use on AWS, enabling users to easily find and deploy the cloud resources they need.","aws-service-catalog","\u002Fimages\u002Fprovider-services\u002Faws-service-catalog\u002Fcovers\u002FArch_AWS-Service-Catalog_64.png",{"id":490,"title":856,"description":857,"slug":858,"coverImageUrl":859},"AWS Systems Manager","AWS Systems Manager is a management service that provides visibility and control over your AWS resources, enabling you to automate operational tasks, gather system inventory, apply OS patches, automate the creation of Amazon Machine Images, and configure your operating systems and applications.","aws-systems-manager","\u002Fimages\u002Fprovider-services\u002Faws-systems-manager\u002Fcovers\u002FArch_AWS-Systems-Manager_64.png",{"id":516,"title":861,"description":862,"slug":863,"coverImageUrl":864},"AWS Trusted Advisor","AWS Trusted Advisor is an online tool that provides real-time guidance to help users optimize their Amazon Web Services (AWS) infrastructure for cost, performance, security, and fault tolerance by scanning their environment and offering recommendations based on best practices.","aws-trusted-advisor","\u002Fimages\u002Fprovider-services\u002Faws-trusted-advisor\u002Fcovers\u002FArch_AWS-Trusted-Advisor_64.png",{"id":866,"title":867,"description":868,"slug":869,"coverImageUrl":870},122,"AWS Database Migration Service (AWS DMS)","AWS Database Migration Service (AWS DMS) is a cloud service that simplifies the migration of relational databases, data warehouses, NoSQL databases, and other types of data stores to AWS, between on-premises instances, or between different AWS services, with minimal downtime.","aws-database-migration-service-(aws-dms)","\u002Fimages\u002Fprovider-services\u002Faws-database-migration-service-(aws-dms)\u002Fcovers\u002FArch_AWS-DataSync_64.png",{"id":872,"title":873,"description":874,"slug":875,"coverImageUrl":876},127,"AWS Client VPN","AWS Client VPN is a managed client-based VPN service that enables secure access to AWS resources and on-premises networks from any location.","aws-client-vpn","\u002Fimages\u002Fprovider-services\u002Faws-client-vpn\u002Fcovers\u002FArch_AWS-Client-VPN_64.png",{"id":878,"title":879,"description":880,"slug":881,"coverImageUrl":882},128,"Amazon CloudFront","Amazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency, high transfer speeds, all within a developer-friendly environment.","amazon-cloudfront","\u002Fimages\u002Fprovider-services\u002Famazon-cloudfront\u002Fcovers\u002FArch_Amazon-CloudFront_64.png",{"id":884,"title":885,"description":886,"slug":887,"coverImageUrl":888},130,"Elastic Load Balancing (ELB)","Elastic Load Balancing (ELB) is a service provided by Amazon Web Services (AWS) that automatically distributes incoming application traffic across multiple targets, such as EC2 instances, containers, and IP addresses, to ensure fault tolerance and scalability.","elastic-load-balancing-(elb)","\u002Fimages\u002Fprovider-services\u002Felastic-load-balancing-(elb)\u002Fcovers\u002FArch_Elastic-Load-Balancing_64.png",{"id":890,"title":891,"description":892,"slug":893,"coverImageUrl":894},132,"AWS PrivateLink","AWS PrivateLink is a networking service that allows AWS customers to securely access services across the Amazon Web Services (AWS) network in a private manner, without using public IPs or requiring the traffic to traverse the public internet.","aws-privatelink","\u002Fimages\u002Fprovider-services\u002Faws-privatelink\u002Fcovers\u002FArch_AWS-PrivateLink_64.png",{"id":896,"title":897,"description":898,"slug":899,"coverImageUrl":900},133,"Amazon Route 53","Amazon Route 53 is a scalable cloud Domain Name System (DNS) web service designed to give developers and businesses a reliable way to route end users to Internet applications by translating names like www.example.com into the numeric IP addresses like 192.0.2.1 that computers use to connect to each other.","amazon-route-53","\u002Fimages\u002Fprovider-services\u002Famazon-route-53\u002Fcovers\u002FArch_Amazon-Route-53_64.png",{"id":902,"title":903,"description":904,"slug":905,"coverImageUrl":906},134,"AWS Site-to-Site VPN","AWS Site-to-Site VPN is a service that allows you to establish a secure and private connection between your on-premises network and your Amazon Virtual Private Cloud (VPC), enabling secure data transfer and remote access to your AWS resources.","aws-site-to-site-vpn","\u002Fimages\u002Fprovider-services\u002Faws-site-to-site-vpn\u002Fcovers\u002FArch_AWS-Site-to-Site-VPN_64.png",{"id":908,"title":909,"description":910,"slug":911,"coverImageUrl":912},135,"AWS Transit Gateway","AWS Transit Gateway is a service that enables customers to connect their Amazon Virtual Private Clouds (VPCs) and their on-premises networks to a single gateway, simplifying their network architecture and enabling scalable, efficient routing among thousands of VPCs, AWS accounts, and on-premises environments.","aws-transit-gateway","\u002Fimages\u002Fprovider-services\u002Faws-transit-gateway\u002Fcovers\u002FArch_AWS-Transit-Gateway_64.png",{"id":914,"title":915,"description":916,"slug":917,"coverImageUrl":918},136,"Amazon VPC","Amazon VPC (Virtual Private Cloud) is a service that allows users to launch AWS resources in a logically isolated virtual network that they can define and control, including IP address ranges, subnets, route tables, and gateways.","amazon-vpc","\u002Fimages\u002Fprovider-services\u002Famazon-vpc\u002Fcovers\u002FVirtual-private-cloud-VPC_32.png",{"id":920,"title":921,"description":922,"slug":923,"coverImageUrl":924},141,"AWS Certificate Manager (ACM)","AWS Certificate Manager (ACM) is a service provided by Amazon Web Services that simplifies the creation, management, and deployment of SSL\u002FTLS certificates for use with AWS services and your internal connected resources.","aws-certificate-manager-(acm)","\u002Fimages\u002Fprovider-services\u002Faws-certificate-manager-(acm)\u002Fcovers\u002FArch_AWS-Certificate-Manager_64.png",{"id":926,"title":927,"description":928,"slug":929,"coverImageUrl":930},142,"AWS CloudHSM","AWS CloudHSM is a cloud-based hardware security module service offered by Amazon Web Services that provides key storage and cryptographic operations within a tamper-resistant hardware appliance.","aws-cloudhsm","\u002Fimages\u002Fprovider-services\u002Faws-cloudhsm\u002Fcovers\u002FArch_AWS-CloudHSM_64.png",{"id":932,"title":933,"description":934,"slug":935,"coverImageUrl":936},143,"Amazon Cognito","Amazon Cognito is a cloud service provided by Amazon Web Services (AWS) that provides authentication, authorization, and user management for web and mobile applications.","amazon-cognito","\u002Fimages\u002Fprovider-services\u002Famazon-cognito\u002Fcovers\u002FArch_Amazon-Cognito_64.png",{"id":938,"title":939,"description":940,"slug":941,"coverImageUrl":942},144,"Amazon Detective","Amazon Detective is a security service that automatically collects, organizes, and analyzes data from AWS resources to help users easily investigate and quickly identify the root cause of potential security issues or suspicious activities.","amazon-detective","\u002Fimages\u002Fprovider-services\u002Famazon-detective\u002Fcovers\u002FArch_Amazon-Detective_64.png",{"id":944,"title":945,"description":946,"slug":947,"coverImageUrl":948},145,"AWS Directory Service","AWS Directory Service is a managed service provided by Amazon Web Services that allows users to connect AWS resources with an existing on-premises Microsoft Active Directory or to set up and operate a new, fully managed directory in the AWS Cloud.","aws-directory-service","\u002Fimages\u002Fprovider-services\u002Faws-directory-service\u002Fcovers\u002FArch_AWS-Directory-Service_64.png",{"id":950,"title":951,"description":952,"slug":953,"coverImageUrl":954},147,"Amazon GuardDuty","Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.","amazon-guardduty","\u002Fimages\u002Fprovider-services\u002Famazon-guardduty\u002Fcovers\u002FArch_Amazon-GuardDuty_64.png",{"id":956,"title":957,"description":958,"slug":959,"coverImageUrl":960},148,"AWS IAM Identity Center (AWS Single Sign-On)","AWS IAM Identity Center (formerly AWS Single Sign-On) is a cloud service that enables secure and unified authentication for users to access AWS accounts and business applications with a single set of credentials.","aws-iam-identity-center-(aws-single-sign-on)","\u002Fimages\u002Fprovider-services\u002Faws-iam-identity-center-(aws-single-sign-on)\u002Fcovers\u002FArch_AWS-IAM-Identity-Center_64.png",{"id":962,"title":963,"description":964,"slug":965,"coverImageUrl":966},149,"AWS Identity and Access Management (IAM)","AWS Identity and Access Management (IAM) is a cloud service that helps securely control access to AWS resources by allowing you to create and manage AWS users and groups, and use permissions to allow and deny their access to AWS resources.","aws-identity-and-access-management-(iam)","\u002Fimages\u002Fprovider-services\u002Faws-identity-and-access-management-(iam)\u002Fcovers\u002FArch_AWS-Identity-and-Access-Management_64.png",{"id":968,"title":969,"description":970,"slug":971,"coverImageUrl":972},150,"Amazon Inspector","Amazon Inspector is a security assessment service offered by Amazon Web Services (AWS) that automatically assesses applications for vulnerabilities or deviations from best practices, and produces a detailed list of security findings prioritized by level of severity.","amazon-inspector","\u002Fimages\u002Fprovider-services\u002Famazon-inspector\u002Fcovers\u002FArch_Amazon-Inspector_64.png",{"id":974,"title":975,"description":976,"slug":977,"coverImageUrl":978},151,"AWS Key Management Service (AWS KMS)","AWS Key Management Service (AWS KMS) is a managed service that makes it easy for you to create and control the cryptographic keys used to secure your data across AWS services and in your applications.","aws-key-management-service-(aws-kms)","\u002Fimages\u002Fprovider-services\u002Faws-key-management-service-(aws-kms)\u002Fcovers\u002FArch_AWS-Key-Management-Service_64.png",{"id":980,"title":981,"description":982,"slug":983,"coverImageUrl":984},152,"Amazon Macie","Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in AWS.","amazon-macie","\u002Fimages\u002Fprovider-services\u002Famazon-macie\u002Fcovers\u002FArch_Amazon-Macie_64.png",{"id":986,"title":987,"description":988,"slug":989,"coverImageUrl":990},153,"AWS Network Firewall","AWS Network Firewall is a managed service provided by Amazon Web Services that enables users to deploy essential network protections such as stateful firewall rules, intrusion detection and prevention, and web filtering within their Virtual Private Cloud (VPC) environments.","aws-network-firewall","\u002Fimages\u002Fprovider-services\u002Faws-network-firewall\u002Fcovers\u002FArch_AWS-Firewall-Manager_64.png",{"id":992,"title":993,"description":994,"slug":995,"coverImageUrl":996},154,"AWS Resource Access Manager (AWS RAM)","AWS Resource Access Manager (AWS RAM) is a service that enables you to easily and securely share AWS resources with any AWS account or within your AWS Organization.","aws-resource-access-manager-(aws-ram)","\u002Fimages\u002Fprovider-services\u002Faws-resource-access-manager-(aws-ram)\u002Fcovers\u002FArch_AWS-Resource-Access-Manager_64.png",{"id":998,"title":999,"description":1000,"slug":1001,"coverImageUrl":1002},155,"AWS Secrets Manager","AWS Secrets Manager is a service provided by Amazon Web Services that enables users to securely store, manage, and retrieve sensitive information such as API keys, passwords, and database credentials.","aws-secrets-manager","\u002Fimages\u002Fprovider-services\u002Faws-secrets-manager\u002Fcovers\u002FArch_AWS-Secrets-Manager_64.png",{"id":1004,"title":247,"description":1005,"slug":1006,"coverImageUrl":1007},156,"AWS Security Hub is a cloud security management service that aggregates, organizes, and prioritizes security alerts or findings from multiple AWS services and AWS Partner Network (APN) security solutions, providing a comprehensive view of security and compliance across an AWS environment.","aws-security-hub","\u002Fimages\u002Fprovider-services\u002Faws-security-hub\u002Fcovers\u002FArch_AWS-Security-Hub_64.png",{"id":1009,"title":1010,"description":1011,"slug":1012,"coverImageUrl":1013},157,"AWS Shield","AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS against DDoS attacks.","aws-shield","\u002Fimages\u002Fprovider-services\u002Faws-shield\u002Fcovers\u002FArch_AWS-Shield_64.png",{"id":1015,"title":1016,"description":1017,"slug":1018,"coverImageUrl":1019},158,"AWS WAF","AWS WAF (Web Application Firewall) is a web application firewall service that helps protect web applications and APIs from common web exploits and bots that may affect availability, compromise security, or consume excessive resources.","aws-waf","\u002Fimages\u002Fprovider-services\u002Faws-waf\u002Fcovers\u002FArch_AWS-WAF_64.png",{"id":1021,"title":1022,"description":1023,"slug":1024,"coverImageUrl":1025},166,"AWS Fargate","AWS Fargate is a serverless compute engine for containers that allows you to run containers without having to manage servers or clusters.","aws-fargate","\u002Fimages\u002Fprovider-services\u002Faws-fargate\u002Fcovers\u002FArch_AWS-Fargate_64.png",{"id":1027,"title":1028,"description":1029,"slug":1030,"coverImageUrl":1031},168,"AWS Lambda","AWS Lambda is a serverless computing service provided by Amazon Web Services that allows developers to run code in response to events without provisioning or managing servers.","aws-lambda","\u002Fimages\u002Fprovider-services\u002Faws-lambda\u002Fcovers\u002FArch_AWS-Lambda_64.png",{"id":1033,"title":1034,"description":1035,"slug":1036,"coverImageUrl":1037},169,"AWS Backup","AWS Backup is a fully managed backup service that makes it easy to centralize and automate the backup of data across AWS services in the cloud and on-premises.","aws-backup","\u002Fimages\u002Fprovider-services\u002Faws-backup\u002Fcovers\u002FArch_AWS-Backup_64.png",{"id":1039,"title":1040,"description":1041,"slug":1042,"coverImageUrl":1043},170,"Amazon Elastic Block Store (Amazon EBS)","Amazon Elastic Block Store (Amazon EBS) is a high-performance block storage service designed for use with Amazon Elastic Compute Cloud (EC2) for both throughput and transaction-intensive workloads at any scale.","amazon-elastic-block-store-(amazon-ebs)","\u002Fimages\u002Fprovider-services\u002Famazon-elastic-block-store-(amazon-ebs)\u002Fcovers\u002FArch_Amazon-Elastic-Block-Store_64.png",{"id":1045,"title":1046,"description":1047,"slug":1048,"coverImageUrl":1049},171,"Amazon Elastic File System (Amazon EFS)","Amazon Elastic File System (Amazon EFS) is a cloud-based file storage service offered by Amazon Web Services (AWS) that provides a simple, scalable, elastic file system for use with AWS Cloud services and on-premise resources.","amazon-elastic-file-system-(amazon-efs)","\u002Fimages\u002Fprovider-services\u002Famazon-elastic-file-system-(amazon-efs)\u002Fcovers\u002FArch_Amazon-EFS_64.png",{"id":1051,"title":1052,"description":1053,"slug":1054,"coverImageUrl":1055},172,"Amazon FSx","Amazon FSx provides fully managed file storage solutions, including FSx for Windows File Server for Microsoft Windows-based applications, FSx for Lustre for high-performance computing applications, and FSx for OpenZFS and FSx for NetApp ONTAP for POSIX-compliant file systems, all offering seamless integration, high reliability, and scalability.","amazon-fsx-(for-all-types)","\u002Fimages\u002Fprovider-services\u002Famazon-fsx-(for-all-types)\u002Fcovers\u002FArch_Amazon-FSx_64.png",{"id":1057,"title":1058,"description":1059,"slug":1060,"coverImageUrl":1061},173,"Amazon S3","Amazon S3 (Simple Storage Service) is a scalable cloud storage service offered by Amazon Web Services (AWS) that allows users to store and retrieve any amount of data from anywhere on the web.","amazon-s3","\u002Fimages\u002Fprovider-services\u002Famazon-s3\u002Fcovers\u002FArch_Amazon-Simple-Storage-Service_64.png",{"id":1063,"title":1064,"description":1065,"slug":1066,"coverImageUrl":1067},174,"Amazon S3 Glacier","Amazon S3 Glacier is a secure, low-cost cloud storage service provided by Amazon Web Services (AWS) designed for data archiving and long-term backup, offering highly durable storage with retrieval times ranging from minutes to hours.","amazon-s3-glacier","\u002Fimages\u002Fprovider-services\u002Famazon-s3-glacier\u002Fcovers\u002FArch_Amazon-Simple-Storage-Service-Glacier_64.png",{"id":1069,"title":1070,"description":1071,"slug":1072,"coverImageUrl":1073},175,"AWS Storage Gateway","AWS Storage Gateway is a hybrid cloud storage service that enables on-premises applications to seamlessly use AWS cloud storage for backup, archiving, disaster recovery, and cloud data processing by providing storage interfaces such as file, volume, and tape.","aws-storage-gateway","\u002Fimages\u002Fprovider-services\u002Faws-storage-gateway\u002Fcovers\u002FArch_AWS-Storage-Gateway_64.png",{"id":1075,"title":1076,"description":1077,"slug":1078,"coverImageUrl":1079},185,"AWS Cloud Development Kit (AWS CDK)","The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework designed to model and provision cloud application resources using familiar programming languages.","aws-cloud-development-kit-(aws-cdk)","\u002Fimages\u002Fprovider-services\u002Faws-cloud-development-kit-(aws-cdk)\u002Fcovers\u002FArch_AWS-Cloud-Development-Kit_64.png",{"id":1081,"title":1082,"description":1083,"slug":1084,"coverImageUrl":1085},186,"AWS CloudShell","AWS CloudShell is a browser-based shell that provides command-line access to AWS services, enabling users to manage and interact with AWS resources directly from their web browser without needing to install or configure CLI tools locally.","aws-cloudshell","\u002Fimages\u002Fprovider-services\u002Faws-cloudshell\u002Fcovers\u002FArch_AWS-CloudShell_64.png",{"id":1087,"title":1088,"description":1089,"slug":1090,"coverImageUrl":1091},188,"AWS CodeArtifact","AWS CodeArtifact is a managed artifact repository service that makes it easy for organizations to securely store, publish, and share software packages used in their software development process across their teams.","aws-codeartifact","\u002Fimages\u002Fprovider-services\u002Faws-codeartifact\u002Fcovers\u002FArch_AWS-CodeArtifact_64.png",{"id":1093,"title":1094,"description":1095,"slug":1096,"coverImageUrl":1097},189,"AWS CodeBuild","AWS CodeBuild is a fully managed build service that compiles source code, runs tests, and produces software packages ready to deploy, without the need for provisioning, managing, or scaling your own build servers.","aws-codebuild","\u002Fimages\u002Fprovider-services\u002Faws-codebuild\u002Fcovers\u002FArch_AWS-CodeBuild_64.png",{"id":1099,"title":1100,"description":1101,"slug":1102,"coverImageUrl":1103},190,"AWS CodeCommit","AWS CodeCommit is a secure, highly scalable, managed source control service hosted by Amazon Web Services that makes it easy for teams to collaboratively manage and store their code repositories in the cloud.","aws-codecommit","\u002Fimages\u002Fprovider-services\u002Faws-codecommit\u002Fcovers\u002FArch_AWS-CodeCommit_64.png",{"id":1105,"title":1106,"description":1107,"slug":1108,"coverImageUrl":1109},191,"AWS CodeDeploy","AWS CodeDeploy is a fully managed deployment service that automates software deployments to a variety of compute services such as Amazon EC2, AWS Fargate, AWS Lambda, and your on-premises servers.","aws-codedeploy","\u002Fimages\u002Fprovider-services\u002Faws-codedeploy\u002Fcovers\u002FArch_AWS-CodeDeploy_64.png",{"id":1111,"title":1112,"description":1113,"slug":1114,"coverImageUrl":1115},192,"Amazon CodeGuru","Amazon CodeGuru is a machine learning-powered service offered by Amazon Web Services (AWS) that automatically reviews code for bugs and suggests optimizations to improve performance and reduce costs for developers.","amazon-codeguru","\u002Fimages\u002Fprovider-services\u002Famazon-codeguru\u002Fcovers\u002FArch_Amazon-CodeGuru_64.png",{"id":1117,"title":1118,"description":1119,"slug":1120,"coverImageUrl":1121},193,"AWS CodeStar","AWS CodeStar is a cloud-based service from Amazon Web Services that provides tools to quickly develop, build, and deploy applications on AWS.","aws-codestar","\u002Fimages\u002Fprovider-services\u002Faws-codestar\u002Fcovers\u002FArch_AWS-CodeStar_64.png",{"id":1123,"title":1124,"description":1125,"slug":1126,"coverImageUrl":1127},195,"AWS Fault Injection Simulator (AWS FIS)","AWS Fault Injection Simulator (AWS FIS) is a managed service designed to help developers intentionally introduce faults into their applications on Amazon Web Services to test resilience and fault-tolerance.","aws-fault-injection-simulator-(aws-fis)","\u002Fimages\u002Fprovider-services\u002Faws-fault-injection-simulator-(aws-fis)\u002Fcovers\u002FArch_AWS-Fault-Injection-Simulator_64.png",{"id":1129,"title":1130,"description":1131,"slug":1132,"coverImageUrl":1133},196,"AWS Tools and SDKs","AWS Tools and SDKs are a collection of software and tools provided by Amazon Web Services to facilitate the development, deployment, and management of applications and services on the AWS platform.","aws-tools-and-sdks","\u002Fimages\u002Fprovider-services\u002Faws-tools-and-sdks\u002Fcovers\u002FArch_AWS-Tools-and-SDKs_64.png",{"id":1135,"title":1136,"description":1137,"slug":1138,"coverImageUrl":1139},230,"AWS OpsWorks","AWS OpsWorks is a cloud computing service from Amazon Web Services (AWS) that provides managed instances of Chef and Puppet, two popular automation platforms, to automate how servers are configured, deployed, and managed across a cloud environment or on-premises.","aws-opsworks","\u002Fimages\u002Fprovider-services\u002Faws-opsworks\u002Fcovers\u002FArch_AWS-OpsWorks_64.png",{"id":1141,"title":1142,"description":1143,"slug":1144,"coverImageUrl":14},245,"AWS Copilot","AWS Copilot is a command line interface tool that simplifies deploying and managing containerized applications on AWS, specifically on Amazon ECS and AWS Fargate, by automating the setup and management processes.","aws-copilot",{"id":1146,"title":1147,"description":1148,"slug":1149,"coverImageUrl":1150},246,"Amazon MemoryDB for Redis","Amazon MemoryDB for Redis is a fully managed, in-memory database service that provides a highly available, scalable, and compatible layer for Redis, designed to deliver ultra-fast performance for data-intensive applications.","amazon-memorydb-for-redis","\u002Fimages\u002Fprovider-services\u002Famazon-memorydb-for-redis\u002Fcovers\u002FArch_Amazon-MemoryDB-for-Redis_64.png",{"id":1152,"title":1153,"description":1154,"slug":1155,"coverImageUrl":1156},250,"AWS Security Token Service (AWS STS)","AWS Security Token Service (AWS STS) is a web service that enables you to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that you authenticate (federated users).","aws-security-token-service-(aws-sts)","\u002Fimages\u002Fprovider-services\u002Faws-security-token-service-(aws-sts)\u002Fcovers\u002FRes_AWS-Identity-Access-Management_AWS-STS-Alternate_48.png",{"id":1158,"title":1159,"description":1160,"slug":1161,"coverImageUrl":1162},270,"AWS Elastic Disaster Recovery","AWS Elastic Disaster Recovery is a cloud service by Amazon Web Services designed to help minimize downtime and data loss with fast, reliable recovery of physical, virtual, and cloud-based servers into AWS.","aws-elastic-disaster-recovery","\u002Fimages\u002Fprovider-services\u002Faws-elastic-disaster-recovery\u002Fcovers\u002FArch_AWS-Elastic-Disaster-Recovery_64.png",{"id":1164,"title":1165,"description":1166,"slug":1167,"coverImageUrl":1168},274,"Amazon Kinesis Data Firehose","Amazon Kinesis Data Firehose is a fully managed service designed to load streaming data in real time into data lakes, data stores, and analytics services such as Amazon S3, Amazon Redshift, Amazon Elasticsearch Service, and Splunk.","amazon-kinesis-data-firehose","\u002Fimages\u002Fprovider-services\u002Famazon-kinesis-data-firehose\u002Fcovers\u002FArch_Amazon-Kinesis-Data-Firehose_64.png",{"id":1170,"title":1171,"description":1172,"slug":1173,"coverImageUrl":1174},275,"Amazon Kinesis Data Streams","Amazon Kinesis Data Streams is a scalable and durable real-time data streaming service that enables developers to continuously capture gigabytes of data per second from hundreds of thousands of sources such as website clickstreams, database event streams, financial transactions, social media feeds, IT logs, and location-tracking events.","amazon-kinesis-data-streams","\u002Fimages\u002Fprovider-services\u002Famazon-kinesis-data-streams\u002Fcovers\u002FArch_Amazon-Kinesis-Data-Streams_64.png",{"id":1176,"title":1177,"description":1178,"slug":1179,"coverImageUrl":1180},277,"AWS App Runner","AWS App Runner is a fully managed service provided by Amazon Web Services that makes it easy for developers to quickly deploy containerized web applications and APIs, without worrying about infrastructure management.","aws-app-runner","\u002Fimages\u002Fprovider-services\u002Faws-app-runner\u002Fcovers\u002FArch_AWS-App-Runner_64.png",{"id":1182,"title":1183,"description":1184,"slug":1185,"coverImageUrl":1186},279,"AWS CodePipeline","AWS CodePipeline is a continuous integration and continuous delivery (CI\u002FCD) service for fast and reliable application and infrastructure updates.","aws-codepipeline","\u002Fimages\u002Fprovider-services\u002Faws-codepipeline\u002Fcovers\u002FArch_AWS-CodePipeline_64.png",{"id":1188,"title":1189,"description":1190,"slug":1191,"coverImageUrl":14},289,"AWS Serverless Application Model (AWS SAM)","AWS Serverless Application Model (AWS SAM) is a framework for building serverless applications that simplifies the process of defining, deploying, and managing serverless infrastructure on AWS using familiar infrastructure as code techniques.","aws-serverless-application-model-(aws-sam)",{"id":1193,"title":1194,"description":1195,"slug":1196,"coverImageUrl":14},290,"AWS App2Container","AWS App2Container is a command-line tool from Amazon Web Services that automates the process of containerizing existing applications running on-premises or in virtual machines, making it easier to deploy and manage them on AWS container services.","aws-app2container",{"id":1198,"title":1199,"description":1200,"slug":1201,"coverImageUrl":1202},291,"Red Hat OpenShift Service on AWS (ROSA)","Red Hat OpenShift Service on AWS (ROSA) is a managed service that offers OpenShift's powerful container orchestration and application deployment capabilities on the AWS Cloud, simplifying the deployment, management, and scaling of Kubernetes applications.","red-hat-openshift-service-on-aws-(rosa)","\u002Fimages\u002Fprovider-services\u002Fred-hat-openshift-service-on-aws-(rosa)\u002Fcovers\u002FArch_Red-Hat-OpenShift-Service-on-AWS_64.png",{"id":1204,"title":1205,"description":1206,"slug":1207,"coverImageUrl":1208},292,"AWS Resilience Hub","AWS Resilience Hub is a service designed to help organizations improve the resilience of their applications and workloads running on Amazon Web Services (AWS) by identifying and managing risks, automating recovery processes, and providing guidance and recommendations to meet desired resilience goals.","aws-resilience-hub","\u002Fimages\u002Fprovider-services\u002Faws-resilience-hub\u002Fcovers\u002FArch_AWS-Resilience-Hub_64.png",[],1790430981530]