Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Alibaba Cloud CAP-C01 - Alibaba Cloud Certified Professional: Cloud Architect

Page: 1 / 2
Total 50 questions

An application runs on an ECS instance in a VPC. The application reads and processes logs that are stored in an OSS bucket in the SAME region. For security reasons, the ECS instance needs to access the OSS bucket without connectivity to the Internet.

Which of the following solutions can BEST provide private network connectivity to OSS?

A.

Use PrivateLink to create a connection between the VPC and OSS.

B.

Create a gateway endpoint in VPC and use that endpoint to access OSS.

C.

Use VPN Gateway to establish an IPsec-VPN connection between the VPC and OSS.

D.

Directly access the OSS bucket from ECS via OSS ' s internal endpoint.

Belinda is designing an API-driven cloud communications platform. The application is hosted on Elastic Compute Service (ECS) instances behind a Network Load Balancer (NLB). It leverages API Gateway to serve public-facing APIs to customers. For security reasons, Belinda wants to protect the platform against web exploits like SQL injection and large, sophisticated DDoS attacks.

Which combination of solutions provides the MOST protection? (Correct answers: 2)

A.

Use Alibaba Cloud Web Application Firewall (WAF) to protect API Gateway.

B.

Use Alibaba Cloud Web Application Firewall (WAF) to protect the NLB.

C.

Use Alibaba Cloud Anti-DDoS Proxy to protect the NLB.

D.

Use Alibaba Cloud Security Center with Anti-DDoS Basic.

Sam runs a gaming startup, and is launching a real-time, massively multiplayer game on Alibaba Cloud. Based on presales numbers, the startup predicts that there will be millions of concurrent users at launch. To ensure the experience of the gamers, their architecture must be able to deliver sub-50ms latency, scale automatically in response to sudden player surges, and provide efficient session management for millions of concurrent users.

What Alibaba Cloud services can Sam leverage to meet the requirements for the playerbase? (Correct answers: 3)

A.

Deploy Tair (Redis® OSS-Compatible) for low-latency session caching.

B.

Store player data in ApsaraDB for MongoDB to handle unstructured data.

C.

Use Alibaba Cloud CDN for static assets like game textures.

D.

Enable Auto Scaling groups for ECS instances based on CPU utilization.

E.

Use Application Load Balancer (ALB) to distribute traffic to game servers.

Jason ' s company is running a traditional web application on Alibaba Cloud ECS instances. The company wants to improve efficiency by refactoring the application as microservices that run on containers. The application must be deployed across multiple environments: production and testing. Load for the application is variable, but the minimum load and maximum load are known. As a Cloud Architect, you have been assigned the job of designing the updated application with a serverless architecture that minimizes operational complexity.

Which solution will meet these requirements MOST cost-effectively?

A.

Upload the container images to Alibaba Cloud Container Registry (ACR) and configure two Alibaba Cloud Container Service for Kubernetes (ACK) Serverless clusters to manage the expected load. Deploy services from the ACR images, and configure an ALB for each of the ACK Serverless clusters.

B.

Upload the container images to Alibaba Cloud Container Registry (ACR) and configure two Alibaba Cloud Container Service for Kubernetes (ACK) Managed clusters to manage the expected load. Deploy services from the ACR images, and configure an ALB for each of the ACK Managed clusters.

C.

Upload the container images to Serverless App Engine (SAE) and create separate environments and deployments for production and testing. Configure an ALB for each of the SAE deployments.

D.

Upload the container images to Function Compute as functions, and configure a concurrency limit to handle the peak load. Serve the functions over API Gateway.

You ' ve been hired to design a highly available application consisting of web, application, and database tiers. HTTPS content delivery should be as close to the edge as possible, with the least delivery time.

Which of the following solutions meets these requirements and is MOST secure?

A.

Configure a public-facing Application Load Balancer (ALB) with multiple redundant Elastic Compute Service (ECS) instances in private vSwitches. Configure Alibaba Cloud CDN to deliver HTTPS content using the ECS instances as the origin.

B.

Configure a public-facing Application Load Balancer (ALB) with multiple redundant Elastic Compute Service (ECS) instances in private vSwitches. Configure Alibaba Cloud CDN to deliver HTTPS content using the ALB as the origin.

C.

Configure a public-facing Application Load Balancer (ALB) with multiple redundant Elastic Compute Service (ECS) instances in public vSwitches. Configure Alibaba Cloud CDN to deliver HTTPS content using the ECS instances as the origin.

D.

Configure a public-facing Application Load Balancer (ALB) with multiple redundant Elastic Compute Service (ECS) instances in public vSwitches. Configure Alibaba Cloud CDN to deliver HTTPS content using the ALB as the origin.

An e-commerce company needs to execute a daily scheduled job to aggregate and filter sales records stored in an Alibaba Cloud OSS bucket. Each object can be up to 10 GB in size. The task may take up to an hour to run with pre-determined CPU and memory requirements. The goal is to reduce operational management efforts.

Identify an appropriate architecture using Alibaba Cloud services to perform the scheduled job efficiently.

A.

Set up an ACK cluster with ECS (Elastic Compute Service) instances, managed through Auto Scaling and scheduled tasks using Serverless Workflow.

B.

Configure Serverless Workflow to execute server-side processing directly on OSS data with Function Compute.

C.

Deploy a Container Service for Kubernetes (ACK) cluster with Elastic Container Instance (ECI) as the launch type. Use EventBridge to schedule the job.

D.

Use Function Compute with EventBridge to run a scheduled trigger daily.

Clarence runs a technology services company that uses ApsaraDB RDS. The company wants to streamline their database management and set up a robust access control structure.

Which of the following solutions provides the required functionality with the LEAST operational overhead?

A.

Use RAM policies to restrict access to databases and implement ActionTrail to audit actions performed on the database.

B.

Implement access control via IP whitelist to control who has access to the database.

C.

Use the permission management feature of Data Management Service (DMS) to control and audit user access to databases.

D.

Set up a WAF instance in front of the database to block SQL injection attempts and ensure the security of the data.

Clarence runs a retail company that hosts an e-commerce website on Alibaba Cloud across multiple Alibaba Cloud regions. Clarence wants the website to be operational at all times to ensure customers can make purchases around the clock. The website stores data in a PolarDB for MySQL instance.

Which of the following solutions will provide the HIGHEST availability for the database?

A.

Utilize the Global Database Network (GDN) to establish cross-region clusters for PolarDB, enabling both read and write operations across multiple regions. In case of a failure, seamlessly direct traffic to a secondary region that can serve as the primary node, maintaining high availability and minimal downtime.

B.

Create two PolarDB for MySQL clusters configured with read/write splitting in two different regions. When a region fails, use Function Compute to replicate the data in the read-only nodes to the healthy region. Then, configure the website to fail over to the healthy region.

C.

Deploy the Cluster Edition of PolarDB for MySQL to ensure that the system can elect a new primary node from read-only nodes when the primary node fails. Ensure that the website is configured to reconnect to the cluster after the failover.

D.

Configure cross-region backup and restoration in PolarDB. During disruptions, restore the latest backup set to a new PolarDB cluster in another region. Redirect application traffic to this restored cluster and configure read/write splitting for this cluster.

Camila has set up a simple blog hosted on a single Elastic Compute Service (ECS) instance, storing images and files on an Elastic Block Storage (EBS) disk within the ECS instance, and relying on an ApsaraDB RDS for MySQL instance for its data tier. Camila wants to scale up her blog and enhance both resilience and performance with minimal changes to the application.

As a Cloud Architect, which combination of actions can you take to improve both resilience and performance of the website? (Correct answers: 3)

A.

Configure an Alibaba Cloud CDN distribution for the website.

B.

Configure an accelerated IP address in Global Accelerator for the access endpoint.

C.

Migrate the images and files to an Object Storage Service (OSS) bucket that is mounted via ossfs to every ECS instance.

D.

Migrate the images and files to a File Storage NAS instance that is mounted on every ECS instance.

E.

Take a snapshot of the current ECS instance and create a custom image. Use the image to provision a new ECS instance, and add both the original and new instances to a scaling group. Set up an Application Load Balancer (ALB) in front of the scaling group, and configure the scaling group to maintain a minimum of two ECS instances.

Muthu is a Cloud Architect who is designing the architecture of a new application being deployed to Alibaba Cloud. The application will run on Elastic Compute Service (ECS) pay-as-you-go instances and will automatically scale across multiple zones based on load. The ECS cluster will scale in and out frequently throughout the day. An Application Load Balancer (ALB) will handle the load distribution. The architecture needs to support distributed session data management.

What should Muthu do to ensure that the architecture supports distributed session data management?

A.

Use session stickiness of the SLB to manage session data.

B.

Use Tair (Redis® OSS-Compatible) to manage and store session data.

C.

Use CloudMonitor to manage sessions.

D.

Use STS (Security Token Service) for managing sessions.