exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 295 discussion

A company manages its multi-account environment by using AWS Organizations. The company needs to automate the creation of daily incremental backups of any Amazon Elastic Block Store (Amazon EBS) volume that is marked with a Lifecycle: Production tag in one of its primary AWS accounts.

The company wants to prevent users from using Amazon EC2 * permissions to delete any of these production snapshots.

What should a SysOps administrator do to meet these requirements?

  • A. Create a daily snapshot of all EBS volumes by using Amazon Data Lifecycle Manager. Specify Lifecycle as the tag key. Specify Production as the tag value.
  • B. Associate a service control policy (SCP) with the account to deny users the ability to delete EBS snapshots. Create an Amazon EventBridge rule with a 24-hour cron schedule. Configure EBS Create Snapshot as the target. Target all EBS volumes with the specified tags.
  • C. Create a daily snapshot of all EBS volumes by using AWS Backup. Specify Lifecycle as the tag key. Specify Production as the tag value.
  • D. Create a daily Amazon Machine Image (AMI) of every production EC2 instance within the AWS account by using Amazon Data Lifecycle Manager.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DocHolliday
Highly Voted 1 year, 3 months ago
Selected Answer: B
I'm gonna go against the grain here and go with answer B. While initially it looks like an elephant because of its complexity compared to the other options...it does satisfy every requirement and its the ONLY option that satisfies the stipulation that denys the deletion of a resource.
upvoted 15 times
AgboolaKun
8 months ago
It is also the one option that mentions the SCP. Remember that the accounts are in AWS Organizations.
upvoted 1 times
...
Hatem08
1 year ago
Agreed I will go with B. It covers all the requirements needed.
upvoted 2 times
...
joaocarvalhojp
1 year ago
Exactly that, letter A does not resolve the stipulation of denying the deletion of snapshots, just resolve the problem of creating automated daily basis snapshots.
upvoted 3 times
...
...
Gomer
Highly Voted 1 year, 7 months ago
Selected Answer: C
I think answer is "C" because using AWS backup is the established method/tool for this, and EC2 instance role/profile would not be allow to control or delete backups unless explicitly allowed. The word "cron" in en answer "B" is red flag that is is the wrong answer. I know all about cron, and it's invaluable and bullet proof on a system. However, it's anathema to AWS Cloud way of doing things. Wherever you see the word "cron" in AWS response, you know its the wrong answer (IMHO).
upvoted 10 times
confusedyeti69
9 months, 2 weeks ago
Doesn't prevent users from using Amazon EC2 * permissions to delete snapshots still.
upvoted 1 times
...
...
numark
Most Recent 2 days, 6 hours ago
Selected Answer: B
Come on people, B is literally the ONLY answer that addresses a way to prevent deletion. The answer in C does not state a way to prevent deletion, even IF AWS Backbackup can do it, it doesn't say it in that answer.
upvoted 1 times
...
igor12ghsj577
2 weeks, 3 days ago
Selected Answer: C
c is the answer
upvoted 1 times
...
igor12ghsj577
2 weeks, 3 days ago
Selected Answer: C
AWS BACKUP comes with features to manage access to the created AMIs and snapshots, and protect them from deletion with a vault lock.
upvoted 1 times
...
VerRi
4 months, 3 weeks ago
Selected Answer: B
B is the only option for handling the deletion of any of these production snapshots.
upvoted 1 times
...
Ramdi1
4 months, 3 weeks ago
Selected Answer: B
Even though it is a complex solution, the two facts are that accounts are in organizations and the best way to control is using SCP's
upvoted 1 times
...
kaszczur
5 months, 4 weeks ago
Selected Answer: C
Aws backup fulfills all needs. So C
upvoted 2 times
...
Tarsmandaturd
7 months ago
Selected Answer: C
For me the answer has to be C. Cron is usually a red herring that it's the wrong answer. Whilst B makes sense in the fact that it's using SCP controls alongside organizations, Cron just feels like bad practice in the context of AWS exams. Consider in backup controls that you are not able to delete unless specifically allowed and to really prevent deletion at an organizational level you can apply compliance mode which after a cooling off period, will not allow any users to delete the resource: https://docs.aws.amazon.com/aws-backup/latest/devguide/vault-lock.html#:~:text=AWS%20Backup%20ensures%20that%20your%20backups%20are%20available,locked%20vault%2C%20AWS%20Backup%20will%20deny%20the%20operation.
upvoted 2 times
...
Koshi202
8 months ago
Selected Answer: C
Incremental backup, TAG, Manage permissions for the backup. All fit
upvoted 1 times
...
icecool36
10 months, 1 week ago
Selected Answer: C
AWS backup is the only one to fulfil the requirements
upvoted 1 times
...
TareDHakim
11 months, 1 week ago
Selected Answer: C
The question mentioned the solution requirements are: 1. Automated EBS backups 2. Incremental EBS backups 3. Lifecycle policy 4. Prevent deletion by users (with Permission to delete snapshots) AWS Backup is smarter than DLM, they both automatically create AMIs and Incremental Snapshots. However, AWS BACKUP comes with features to manage access to the created AMIs and snapshots, and protect them from deletion with a vault lock. https://repost.aws/questions/QU8o5m88yhQk6UVAgQA3Mnng/aws-backup-vs-aws-data-lifecycle-management.
upvoted 5 times
icecool36
10 months, 1 week ago
incremental was the trick word in this question indeed
upvoted 1 times
...
...
konieczny69
12 months ago
Selected Answer: B
Altough not elegant, its the only option that fulfils `prevent deletion` requirement
upvoted 2 times
...
mattyb123abc
1 year ago
Selected Answer: B
bbbbbbbbb
upvoted 2 times
...
Hatem08
1 year ago
Selected Answer: B
bbbbbbbb
upvoted 2 times
...
Hatem08
1 year ago
Selected Answer: B
B for me as It covers all the requirements needed (the deletion part)
upvoted 4 times
...
xSohox
1 year, 3 months ago
Selected Answer: C
The correct answer is C. Option A is incorrect, because it is clearly said that you need to prevent users from using Amazon EC2 * permissions to delete any of these production snapshots. AWS Backup is another service where users will not be able to use EC2 * permissions.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago