NO.1 An organization has setup multiple IAM users. The organization wants that each IAM user
accesses the IAM console only within the organization and not from outside. How can it achieve this?
A. Create an IAM policy with the security group and use that security group for AWS console login
B. Create an IAM policy with a condition which denies access when the IP address range is not from
the organization
C. Create an IAM policy with VPC and allow a secure gateway between the organization and AWS
D. Configure the EC2 instance security group which allows traffic only from the organization's IP range
Answer: B

AWS Identity and Access Management is a web service which allows organizations tomanage users
and user permissions for various AWS services. The user can add conditions as a part of the IAM
policies. Thecondition can be set on AWS Tags, Time, and Client IP as well as on many other
parameters. If the organization wants the user to access only from a specific IP range, they should set
an IAM policy condition which denies access when the IP is not in a certain range. E.g. The sample
policy given below denies all traffic when the IP is not in a certain range.

NO.2 A user has configured ELB with Auto Scaling. The user suspended the Auto Scaling
AlarmNotification which notifies Auto Scaling for CloudWatch alarms. process for a while. What will
Auto Scaling do during this period?
A. Auto Scaling will execute the policy but it will not launch the instances until the process is resumed
B. AWS will receive the alarms but will not execute the Auto Scaling policy
C. AWS will not receive the alarms from CloudWatch
D. It is not possible to suspend the AlarmNotification process
Answer: B

Auto Scaling performs various processes, such as Launch, Terminate AlarmNotification etc. The user
can also suspend individual process. The AlarmNotification process type accepts notifications from
the Amazon CloudWatch alarms that are associated with the Auto Scaling group. If the user suspends
this process type, Auto Scaling will not automatically execute the scaling policies that would be
triggered by the alarms.

NO.3 A user has created a subnet in VPC and launched an EC2 instance within it. The user has not
selected the option to assign the IP address while launching the instance. Which of the below
mentioned statements is true with respect to this scenario?
A. The instance will never launchif the public IP is not assigned
B. The user would need to create an internet gateway and then attach an elastic IP to the instance to
connect from internet
C. The instance will always have a public DNS attached to the instance by default
D. The user can directly attach an elastic IP to the instance
Answer: B

A Virtual Private Cloud (VPC. is a virtual network dedicated to the user's AWS account. A user can
create a subnet with VPC and launch instances inside that subnet. When the user is launching an
instance he needs to select an option which attaches a public IP to the instance. If the user has not
selected the option to attachthe public IP then it will only have a private IP when launched. The user
cannot connectto the instance from the internet. If the user wants an elastic IP to connect to the
instance from the internet he should create an internet gateway and assign an elastic IP to instance.

NO.4 A user has launched an EC2 instance and deployed a production application in it. The user
wants to prohibit any mistakes from the production team to avoid accidental termination. How can
the user achieve this?
A. It is not possible to avoid accidental termination
B. The user can set the InstanceInitiatedShutdownBehavior flag to avoid accidental termination
C. The usercan the set DisableApiTermination attribute to avoid accidental termination
D. The user can set the Deletion termination flag to avoid accidental termination
Answer: C

It is always possible that someone can terminate an EC2 instance using the Amazon EC2 console,
command line interface or API by mistake. If the admin wants to prevent the instancefrom being
accidentally terminated, he can enable termination protection for that instance. The
DisableApiTermination attribute controls whether the instance can be terminated using the console,
CLI or API. By default, termination protection is disabled for an EC2 instance. When it is set it will not
allow the user to terminate the instance from CLI, API or the console.

