exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 86 discussion

Your system recently experienced down time during the troubleshooting process. You found that a new administrator mistakenly terminated several production
EC2 instances.
Which of the following strategies will help prevent a similar situation in the future?
The administrator still must be able to:
✑ launch, start stop, and terminate development resources.
✑ launch and start production instances.

  • A. Create an IAM user, which is not allowed to terminate instances by leveraging production EC2 termination protection.
  • B. Leverage resource based tagging, along with an IAM user which can prevent specific users from terminating production, EC2 resources.
  • C. Leverage EC2 termination protection and multi-factor authentication, which together require users to authenticate before terminating EC2 instances
  • D. Create an IAM user and apply an IAM role which prevents users from terminating production EC2 instances.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
amog
Highly Voted 3 years, 6 months ago
Answer is B Keyword is "launch and start production instances" => C does not stop him to do terminate
upvoted 10 times
Ibranthovic
3 years, 6 months ago
" still must be able to: ✑ launch, start stop, and terminate development resources." It is C
upvoted 4 times
kapara
2 years, 7 months ago
Launch, start, stop and terminate **development** resources" - notice this is development environment. The production environment requirement is that they can only "launch and start production instances" - they should not be able to terminate, so B is correct.
upvoted 2 times
madmike123
4 months, 1 week ago
If an administrator is prevented from terminating production instances 100% of the time, the implication is you'd need some shadow admin to perform the task when it's needed. In this case, 'c' makes the most sense as it prevents accidental termination which is the objective.
upvoted 1 times
...
...
...
helpaws
2 years, 8 months ago
it's C. Keyword here actually is "mistake." This will prevent mistake only.
upvoted 3 times
...
...
CloudFloater
Highly Voted 3 years, 6 months ago
B http://jayendrapatil.com/tag/tags/
upvoted 5 times
...
amministrazione
Most Recent 8 months, 1 week ago
B. Leverage resource based tagging, along with an IAM user which can prevent specific users from terminating production, EC2 resources.
upvoted 1 times
...
Jesuisleon
1 year, 11 months ago
B is right and C is wrong. C just complicates the stopping procedure and can NOT prevent admin from stopping them.
upvoted 1 times
...
hollie
2 years, 3 months ago
Selected Answer: B
obviously terminate production instance should be denied.
upvoted 1 times
...
hobokabobo
2 years, 4 months ago
Selected Answer: C
Well this is so poorly worded that one can only guess: A) "not allowed ... by leveraging termination protection". Termination protection is not user specific. B) So you have an IAM user that prevents "specific users": so an I am user is patrolling and as soon as one of the "specific users" tries to terminate an instance this hero steps in preventing the damage ... C) Multifactor requires to authenticate: yes, and with a second device. It does not prevent termination but at least its not completely ridiculous. D) It says apply an role to a user ... nonesense? Yes C its bad as it gets. Who would do it that way? But C is only bad and not complete nonsense .
upvoted 1 times
...
TigerInTheCloud
2 years, 4 months ago
Selected Answer: C
A. Wrong. EC2 termination protection prevents anyone to perform the termination unless the protection is disabled. B. Doable but too much work that C C. This is the answer. Instance termination protection is the easiest and simplest way to go. I use Terraform to bring up and manage AWS resources with the default setting to protect resources, not just EC2, from being terminated by mistake with a default variable file and another specific variable file for unsetting the protection during the development phase or using the command line variables (or even manually) disable the protection before performing any change after the development phase. D. Misunderstand IAM user, role, and policy
upvoted 1 times
...
welcomeYM
2 years, 7 months ago
Selected Answer: C
CCCCCC
upvoted 2 times
...
hilft
2 years, 9 months ago
thought it was D. not B.
upvoted 1 times
...
aandc
2 years, 9 months ago
Selected Answer: B
key word "launch and start production instances." -> terminate production should be prohibited
upvoted 1 times
...
Kb80
2 years, 10 months ago
Selected Answer: C
C. https://aws.amazon.com/premiumsupport/knowledge-center/accidental-termination/
upvoted 2 times
...
tartarus23
2 years, 12 months ago
Selected Answer: B
B. because it allows u separate dev and prod instances and utilize IAM to disable the prod termination access
upvoted 2 times
...
tartarus23
2 years, 12 months ago
Selected Answer: B
b lets you separate dev and prod
upvoted 1 times
...
jyrajan69
3 years, 2 months ago
A B and D assume that you will login as this user that has been created, what if he is not logged in as that user? Therefore only possible answer is C
upvoted 1 times
...
HellGate
3 years, 2 months ago
CCCCCC
upvoted 2 times
HellGate
3 years, 2 months ago
Change to B
upvoted 1 times
...
...
CoryD
3 years, 3 months ago
Correct answer is C. Ignore everyone sayings it's B...IT'S NOT B. The requirement states that he still needs to be able to delete resources after the fix is implemented. This question was made for termination protection and MFA just adds onto it.
upvoted 2 times
lulz111
3 years, 2 months ago
It states that he has to be able to terminate DEVELOPMENT resources after the fix, not all resources. The idea here is to allow them to continue to interact with dev ec2 instances but not kill prod instances.
upvoted 1 times
...
...
bwestpha
3 years, 4 months ago
Pretty sure its C . He still has to be able to terminate them, just not y accident. Yes MFA won't help here, but termination protection does.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago