{"id":15548,"date":"2026-09-18T05:50:46","date_gmt":"2026-09-18T05:50:46","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15548"},"modified":"2026-09-18T05:50:46","modified_gmt":"2026-09-18T05:50:46","slug":"amazon-aws-certified-cloudops-engineer-associate-soa-c03-practice-test-questions-and-exam-dumps-part-20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-cloudops-engineer-associate-soa-c03-practice-test-questions-and-exam-dumps-part-20-q381-400\/","title":{"rendered":"Amazon AWS Certified CloudOps Engineer &#8211; Associate SOA-C03 Practice Test Questions and Exam Dumps Part 20 Q381-400"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-cloudops-engineer-associate-soa-c03-exam-dumps\"><b>Amazon AWS Certified CloudOps Engineer &#8211; Associate SOA-C03 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 381. Which CloudWatch feature allows an administrator to calculate a new metric by performing mathematical operations on existing metrics?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch metric math<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch Logs Insights<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch Contributor Insights<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch Synthetics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. CloudWatch metric math<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudWatch metric math allows administrators to create calculations using one or more existing CloudWatch metrics. This capability is useful when a single raw metric does not provide enough information for operational monitoring. For example, administrators can calculate error percentages, utilization ratios, rates, or other derived values by combining metrics with mathematical expressions. The resulting expression can be visualized on dashboards or used with alarms. Logs Insights is designed for querying logs, Contributor Insights analyzes patterns in log and metric data, and Synthetics runs automated tests. Therefore, CloudWatch metric math is the appropriate feature for creating derived metrics from existing CloudWatch measurements.<\/span><\/p>\n<h3><b>Question 382. A company wants to identify the most frequently occurring contributors to a specific operational pattern in CloudWatch logs. Which feature can provide real-time analysis of top contributors?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch Dashboard<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch Contributor Insights<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch Agent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch Alarm<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. CloudWatch Contributor Insights<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudWatch Contributor Insights is designed to analyze time-series data and identify the top contributors to operational patterns. It can help administrators understand which resources, IP addresses, API operations, or other dimensions are contributing most significantly to a particular behavior. This can be useful during troubleshooting when an operations team needs to identify the primary sources of traffic, errors, or other events without manually processing large amounts of data. A dashboard mainly visualizes metrics, the CloudWatch agent collects telemetry, and alarms evaluate thresholds. Contributor Insights is therefore the appropriate choice for identifying and analyzing top contributors.<\/span><\/p>\n<h3><b>Question 383. An organization stores application logs in CloudWatch Logs and wants to reduce storage costs by automatically deleting logs after a specified period. Which configuration should the administrator use?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch Logs retention policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch anomaly detection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch metric math<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudWatch dashboard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. CloudWatch Logs retention policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudWatch Logs retention settings allow administrators to define how long log events should remain in a log group. Once the configured retention period is reached, CloudWatch Logs automatically removes older log events. This is useful for controlling storage costs while still retaining logs for the period required by operational, security, or compliance requirements. Metric math creates derived metric calculations, anomaly detection identifies unusual metric behavior, and dashboards provide visualization. None of those features controls the lifetime of stored log events. Therefore, configuring a CloudWatch Logs retention policy is the appropriate operational solution for automatically removing older logs.<\/span><\/p>\n<h3><b>Question 384. A company needs to send CloudTrail management events from multiple AWS accounts into a centralized S3 bucket for security analysis. Which configuration is most appropriate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Separate local CloudTrail event histories only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An organization trail<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A CloudWatch dashboard<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An AWS Config rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. An organization trail<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CloudTrail organization trail allows an organization to create a centralized trail that records activity across accounts within AWS Organizations. Events can be delivered to a centralized S3 bucket, providing security and operations teams with a consistent location for audit data. This simplifies centralized monitoring and helps establish organization-wide logging standards. Individual event history views are useful for account-level investigation but do not provide the same centralized long-term collection model. CloudWatch dashboards visualize monitoring data, while AWS Config evaluates resource configuration. Therefore, an organization trail is the appropriate CloudTrail configuration for centralized multi-account audit logging.<\/span><\/p>\n<h3><b>Question 385. An administrator needs to investigate which S3 API calls were made against objects in a bucket, rather than only tracking management operations. Which CloudTrail capability should be enabled?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudTrail Insights<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudTrail data events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudTrail organization trail only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Config recording<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. CloudTrail data events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudTrail data events provide visibility into resource-level API activity such as Amazon S3 object operations. This is different from management events, which generally capture control-plane actions such as creating or modifying AWS resources. If an administrator needs to investigate actions such as object access or object-level API calls, data events are the relevant CloudTrail capability. CloudTrail Insights is intended to identify unusual API activity patterns, while AWS Config focuses on resource configuration state. An organization trail can centrally collect events but does not by itself replace the need to configure the appropriate event type. Therefore, S3 data events should be enabled for object-level API visibility.<\/span><\/p>\n<h3><b>Question 386. A company wants to replay previously captured Amazon EventBridge events after correcting an application issue. Which EventBridge capability supports this operational requirement?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EventBridge archive and replay<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EventBridge Scheduler only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EventBridge rule target filtering only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EventBridge partner event source<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. EventBridge archive and replay<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EventBridge archive and replay allows organizations to retain selected events in an archive and later replay those events to event-processing workflows. This can be useful when an application has experienced an outage or processing error and the team needs to reprocess events after correcting the underlying issue. Replaying events can reduce the need for applications to recreate historical event data manually. EventBridge Scheduler is designed primarily for scheduled invocation, while event filtering determines which events match rules. Partner event sources are used to receive events from supported external applications. Therefore, archive and replay is the appropriate operational capability.<\/span><\/p>\n<h3><b>Question 387. A company uses an Amazon S3 bucket and wants objects to automatically move to a lower-cost storage class after they become infrequently accessed. Which S3 capability should be configured?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> S3 Event Notifications<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> S3 Lifecycle rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> S3 Object Lock<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> S3 Access Points<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. S3 Lifecycle rules<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon S3 Lifecycle rules can automatically transition objects between storage classes based on conditions such as object age. This allows organizations to optimize storage costs without requiring administrators or applications to manually move objects. A lifecycle configuration can also define expiration or deletion behavior when appropriate. S3 Event Notifications are used to send notifications about object events, Object Lock provides retention and deletion protection, and Access Points simplify controlled access to shared data. Therefore, when the operational requirement is to automatically transition infrequently accessed objects to a different storage class, S3 Lifecycle rules are the appropriate solution.<\/span><\/p>\n<h3><b>Question 388. An organization stores versioned objects in Amazon S3 and wants older object versions to automatically transition to a lower-cost storage class. Which lifecycle capability should be configured?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Current-version expiration only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Noncurrent version transition<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bucket ACLs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> S3 Transfer Acceleration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Noncurrent version transition<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When S3 Versioning is enabled, multiple versions of an object can remain in the bucket even after a newer version becomes current. These noncurrent versions can consume significant storage if they are retained indefinitely. S3 Lifecycle rules provide specific actions for noncurrent versions, including transitions to other storage classes and eventual expiration when appropriate. Current-version expiration does not address the lifecycle of older versions, while ACLs control access and Transfer Acceleration improves data transfer performance. Therefore, a noncurrent version transition is the appropriate lifecycle action when older versions need to move to a lower-cost storage class.<\/span><\/p>\n<h3><b>Question 389. A security team wants to ensure that newly created Amazon EBS volumes are encrypted by default within an AWS Region. Which configuration should be enabled?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS encryption by default<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS Fast Snapshot Restore<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS Elastic Volumes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS snapshot archive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. EBS encryption by default<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EBS encryption by default allows an AWS account to automatically encrypt newly created EBS volumes and supported snapshot copies in a Region. Enabling this setting helps establish a consistent encryption baseline without requiring administrators or applications to remember to specify encryption for every new volume. EBS Fast Snapshot Restore is intended to improve snapshot restoration performance, Elastic Volumes allows certain volume attributes to be modified without detaching the volume, and snapshot archive reduces storage costs for long-term snapshot retention. Therefore, EBS encryption by default directly addresses the requirement to make newly created EBS storage encrypted automatically.<\/span><\/p>\n<h3><b>Question 390. An operations team needs to reduce the storage cost of EBS snapshots that are rarely accessed but must be retained for long-term recovery. Which feature is appropriate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS Multi-Attach<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS snapshot archive<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS Elastic Volumes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS Auto Scaling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. EBS snapshot archive<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EBS Snapshots Archive provides a lower-cost storage tier for snapshots that do not need to be accessed frequently but must be retained for long-term purposes. This can help organizations reduce the ongoing cost associated with maintaining older recovery data while preserving the ability to restore it when needed. The archived tier is intended for snapshots with long-term retention requirements rather than frequently accessed operational recovery points. Multi-Attach allows supported EBS volumes to be attached to multiple instances, Elastic Volumes supports volume modification, and EBS Auto Scaling is not an EBS snapshot storage feature. Therefore, Snapshot Archive is the suitable option.<\/span><\/p>\n<h3><b>Question 391. An EC2 instance is configured with hibernation support. What happens when the instance is hibernated?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The instance is permanently terminated<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The root volume is deleted immediately<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The contents of RAM are preserved on the root EBS volume<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The instance is converted into an AMI<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The contents of RAM are preserved on the root EBS volume<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EC2 hibernation allows a supported instance to preserve the contents of system memory when it is stopped. The RAM contents are written to the root EBS volume, allowing the instance to resume later with applications and processes restored to their previous state rather than performing a completely fresh operating-system boot. Hibernation is useful for workloads where preserving in-memory application state can reduce startup time. It does not convert an instance into an AMI, permanently terminate it, or automatically delete its root volume. Therefore, preservation of RAM contents on the root EBS volume is the defining behavior of EC2 hibernation.<\/span><\/p>\n<h3><b>Question 392. A company wants to control how long stopped EC2 instances retain their associated EBS volumes. Which EC2 behavior should the administrator understand?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS volumes are always deleted when an instance stops<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EBS volumes are generally retained when an instance is stopped<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All EBS volumes are automatically converted to snapshots<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stopping an instance always deletes its IAM role<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. EBS volumes are generally retained when an instance is stopped<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Stopping an EC2 instance is different from terminating it. When an instance is stopped, its EBS-backed volumes are generally preserved so that the instance can be started again with its stored data intact. Whether a particular volume is deleted depends on the volume&#8217;s DeleteOnTermination attribute, which primarily becomes relevant when the instance is terminated rather than simply stopped. Understanding this distinction is important for operations teams because stopping an instance can continue to incur EBS storage charges even though compute charges are no longer being incurred. Therefore, administrators should verify volume retention and deletion settings when managing instance lifecycle.<\/span><\/p>\n<h3><b>Question 393. A company needs an EC2 capacity reservation in a specific Availability Zone so that capacity is available when instances need to be launched. Which feature is designed for this purpose?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Capacity Reservation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Auto Scaling target tracking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Spot Fleet only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> S3 Lifecycle<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Capacity Reservation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EC2 Capacity Reservations allow an organization to reserve compute capacity for a specified instance configuration in a particular Availability Zone. This can help ensure that the required EC2 capacity is available when workloads need to launch, which is especially important for predictable capacity requirements or critical applications. Capacity Reservations are different from cost optimization mechanisms such as Savings Plans because their primary purpose is capacity assurance rather than simply reducing pricing. Auto Scaling adjusts the number of instances based on demand, while S3 Lifecycle manages object storage. Therefore, Capacity Reservation is the appropriate EC2 feature when guaranteed capacity in a specific Availability Zone is required.<\/span><\/p>\n<h3><b>Question 394. An organization wants to use a DNS routing policy that distributes traffic across multiple resources according to assigned relative weights. Which Route 53 routing policy should be configured?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failover routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Latency-based routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geolocation routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Weighted routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Route 53 weighted routing allows DNS responses to be distributed among multiple resources according to configured weights. A higher weight generally causes a resource to receive a larger proportion of DNS queries relative to resources with lower weights. This can be useful for controlled traffic distribution, gradual application deployments, testing, or directing different percentages of traffic to separate environments. Failover routing focuses on primary and secondary resources, latency-based routing selects resources based on network latency, and geolocation routing uses the location of DNS users. Therefore, weighted routing is the correct choice when traffic distribution is based on assigned relative percentages.<\/span><\/p>\n<h3><b>Question 395. A company wants Route 53 to route users to resources based on the geographic location of the users making DNS requests. Which routing policy should be used?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Simple routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geolocation routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Multivalue answer routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Geolocation routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 geolocation routing allows DNS responses to be selected based on the geographic location associated with the DNS query. Organizations can use this policy when they need to direct users in different geographic areas to different endpoints, applications, or content. This can support regional application designs, location-specific content, or regulatory requirements where traffic needs to be handled differently depending on user location. Weighted routing distributes traffic according to configured weights, while multivalue answer routing returns multiple healthy values. Simple routing does not make location-based decisions. Therefore, geolocation routing is the appropriate policy for geographic traffic steering.<\/span><\/p>\n<h3><b>Question 396. An organization wants applications in a VPC to resolve DNS names for resources in another connected VPC through Route 53 Resolver. Which component should be configured to receive DNS queries from the other network?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolver inbound endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolver outbound endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Resolver inbound endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Route 53 Resolver inbound endpoint allows DNS queries from networks outside a VPC to be sent into the VPC for resolution by Route 53 Resolver. This is useful in hybrid and multi-VPC environments where DNS resolution needs to cross network boundaries. An outbound endpoint serves the opposite direction by allowing DNS queries originating within a VPC to be forwarded to DNS resolvers outside the VPC. NAT Gateways provide network address translation for outbound internet access, while Internet Gateways provide connectivity between a VPC and the internet. Therefore, an inbound Resolver endpoint is appropriate when external networks need to send DNS queries into a VPC.<\/span><\/p>\n<h3><b>Question 397. A Network Load Balancer must accept encrypted client connections and terminate TLS before forwarding traffic to targets. Which listener type should be configured?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> UDP listener<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP listener without TLS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TLS listener<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP listener<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. TLS listener<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Network Load Balancer TLS listener allows the load balancer to accept encrypted TLS connections from clients and terminate TLS at the load balancer. This can offload certificate management and cryptographic processing from backend targets while allowing the NLB to forward traffic according to the configured target group settings. A plain TCP listener does not terminate TLS because it treats the traffic as TCP data, while UDP is intended for datagram-based traffic. HTTP listeners are associated with Application Load Balancers rather than NLB TLS termination. Therefore, a TLS listener is the appropriate configuration for terminating encrypted client connections at an NLB.<\/span><\/p>\n<h3><b>Question 398. A company wants to preserve the original client IP address when traffic reaches targets behind a Network Load Balancer. Which NLB capability should the administrator consider?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Source IP preservation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront compression<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway port mapping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Source IP preservation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Load Balancers can preserve the source IP address of clients for supported traffic configurations, allowing backend applications to see the original client address rather than only seeing the load balancer&#8217;s address. This can be important for application logging, access control, auditing, and client-aware processing. The exact behavior depends on the listener, target type, and network configuration, so administrators should verify the supported configuration for the workload. CloudFront compression optimizes content delivery, Route 53 weighted routing controls DNS distribution, and NAT Gateway performs address translation. Therefore, source IP preservation is the relevant NLB capability for retaining client address information.<\/span><\/p>\n<h3><b>Question 399. A company wants CloudFront to deliver private content only to clients that have been granted access through signed requests. Which CloudFront capability should be used?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront signed URLs or signed cookies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront invalidation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront origin failover<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. CloudFront signed URLs or signed cookies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFront signed URLs and signed cookies allow an application to control access to private content by issuing time-limited, cryptographically signed requests to authorized users. Signed URLs are commonly useful for individual files or specific resources, while signed cookies can support access to multiple restricted files without requiring a separate signed URL for every object. This provides application-controlled access to content delivered through CloudFront. Invalidation removes cached objects, origin failover provides resilience between origins, and compression improves transfer efficiency. Therefore, signed URLs or signed cookies are the appropriate CloudFront mechanisms for restricting access to private content.<\/span><\/p>\n<h3><b>Question 400. An ECS service needs to distribute tasks across different infrastructure capacity options, such as On-Demand and Spot capacity, while allowing ECS to select appropriate capacity according to configured strategy. Which feature should be used?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECS task execution role<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECS capacity providers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECS deployment circuit breaker<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ECS task definition logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. ECS capacity providers<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon ECS capacity providers allow services and tasks to use different underlying compute capacity options according to a configured capacity provider strategy. They can be used with environments such as ECS on EC2 and, where supported, Fargate capacity options, enabling organizations to control how tasks are placed across available capacity. Capacity provider strategies can help balance workload placement and support operational objectives such as using a mixture of capacity types. The task execution role provides permissions for ECS task startup operations, deployment circuit breakers help respond to failed deployments, and task definition logging controls container log configuration. Therefore, ECS capacity providers are appropriate for managing task placement across capacity options.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified CloudOps Engineer &#8211; Associate SOA-C03 Exam Dumps and Practice Test Dumps &nbsp; Question 381. Which CloudWatch feature allows an administrator to calculate a new metric by performing mathematical operations on existing metrics? CloudWatch metric math CloudWatch Logs Insights CloudWatch Contributor Insights CloudWatch Synthetics Correct Answer: 1. CloudWatch metric math Explanation: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15548"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15548"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15548\/revisions"}],"predecessor-version":[{"id":15591,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15548\/revisions\/15591"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}