Which of the following is not a potential cause of latency on an RDS read-only instance?
Correct Answer:B. There exists significant load on the ECS that is connected to this read-only instance.
Explanation:
Latency on an RDS read-only instance can be caused by high loads on the instance itself, inadequate instance specifications, or excessive write operations on the master instance, as these factors directly impact replication delay and resource contention. However, a high load on the ECS instance connected to the RDS read-only instance would not inherently cause latency on the RDS instance, as the ECS and RDS operate independently in terms of processing.
Question 2
Which of the following methods can be used to connect with the database in RDS for MySQL? (Choose three.)
Correct Answer:A. MySQL-Front; B. Navicat MySQL; C. Log on using MySQL commands
Explanation:
RDS for MySQL supports connections through tools that are compatible with MySQL, such as MySQL-Front, Navicat MySQL, and command-line MySQL commands. SQL Server Management Studio (SSMS) is designed for Microsoft SQL Server and is not compatible with MySQL, so option D is incorrect.
Question 3
When using ECS, you don't have to stop the ECS instance before resizing the system disk.
Correct Answer:B. False
Explanation:
In Alibaba Cloud, resizing the system disk of an ECS instance requires stopping the instance temporarily. This ensures data integrity and successful resizing. Once the system disk is resized, the instance can be restarted to reflect the new disk size.
Question 4
Alibaba Cloud VPC utilizes tunneling technology. Each VPC has a unique tunnel ID, and a tunnel ID corresponds to a virtual network. As a result, VPC can achieve a similar isolation effect as that of a traditional VLAN.
Correct Answer:A. TRUE
Explanation:
Alibaba Cloud VPC uses tunneling technology with unique tunnel IDs to create isolated virtual networks that offer similar isolation capabilities as VLANs in traditional networks. This allows each VPC to function as an independent, secure network environment within the cloud, ensuring traffic separation and resource isolation.
Question 5
Elastic Compute Service (ECS) instances you created in different zones within the same region are not interconnected with each other through the Intranet by default.
Correct Answer:A. TRUE
Explanation:
By default, ECS instances in different zones within the same region are not interconnected via the Intranet. To enable communication between instances across zones, you would need to configure a VPC or use other network configurations. This setup provides isolation and flexibility in managing network traffic within different zones.
Question 6
Before data communication is setup, the security groups match the security group rules one by one to query whether to allow access requests Assume that the user has created two security group rules 1 and 2 The protocol type, port range, authorization type, and authorization object of the two security group rules are the same. The difference is that Rule 1 is a denial policy, rule 2 is an allowed policy, so the following statement is correct_______ (Number of correct answers 2)
Correct Answer:A. If rule 1 and rule 2 have the same priority, the rule of the denial policy takes effect first, and the rule of the allowed policy does not take effect; C. If rule 1 and rule 2 have different priorities, the rule with a small priority number takes effect
Explanation:
Before data communication is set up, the security groups match the security group rules one by one to query whether to allow access requests. If the protocol type, port range, authorization type, and authorization object of two security group rules are the same, the following rules apply:
If the two rules have the same priority, the rule of the denial policy takes effect first, and the rule of the allowed policy does not take effect. This is because the security group rules follow the principle of minimum permission, which means that the most restrictive rule is applied when there is a conflict.
If the two rules have different priorities, the rule with a smaller priority number takes effect. This is because the security group rules follow the principle of priority, which means that the rule with a higher priority (lower number) is applied when there is a conflict. Reference: ECS Security Groups - Alibaba Fundamentals - Cloud Academy, Security group rules - Elastic Compute Service - Alibaba Cloud Documentation Center
Question 7
Object Storage Service (OSS) supports sub accounts, and you can allocate access permissions to different buckets for each sub account.
Correct Answer:A. True
Explanation:
Object Storage Service (OSS) supports sub accounts, which are the accounts that belong to a parent account and share the resources of the parent account. You can allocate access permissions to different buckets for each sub account by using bucket policies or RAM policies. Bucket policies are the access control policies that are attached to buckets and specify the permissions that other users have on the resources in the buckets. RAM policies are the access control policies that are attached to RAM users or RAM user groups and specify the permissions that the RAM users or RAM user groups have on the OSS resources. Reference:
Object Storage Service:Overview - Alibaba Cloud
Object Storage Service:FAQ - Alibaba Cloud
Authentication - Object Storage Service - Alibaba Cloud
Question 8
Alibaba Cloud will check source IP addresses that connect to ApsaraDB for RDS through the public internet. When Alibaba Cloud Situation Awareness detects an alert reporting ''a seldom-used IP address connecting to the database,'' which of the following is the safest way to handle this alert?
Correct Answer:B. Log on to Alibaba Cloud console, modify the IP address whitelist for authorized access to RDS, and retain the IP addresses that need to connect to RDS
Explanation:
The safest response to a seldom-used IP alert connecting to ApsaraDB for RDS is to adjust the IP whitelist to allow only trusted IP addresses. By limiting the IP addresses in the whitelist, unauthorized or unfamiliar IP addresses cannot access the database. This approach provides direct control over access to RDS and minimizes potential security risks. Checking SQL audit logs (as suggested in option D) is useful but not sufficient on its own for a comprehensive security response.
Question 9
User A is the system administrator of a company who frequently travels to Shanghai. Each time he remotely logs on to the server in Shanghai, an alert is reported, prompting, ''Someone is remotely logging on to the server. Please pay attention to your server security.'' Which of the following methods can be used to quickly and automatically resolve this problem?
Correct Answer:C. Log on to Alibaba Cloud console, and add a frequent logon location to the Security Center configuration item.
Explanation:
To prevent frequent alerts when User A logs in from Shanghai, the best solution is to configure the Security Center to recognize Shanghai as a frequent login location. This will prevent unnecessary security alerts each time User A accesses the server from this location.
Question 10
When the "'Obtain the Visitor's Real IP Address" function is enabled in Alibaba Cloud SLB For layer 7 services, you can obtain the real IP addresses of visitors through the______________field in HTTP header
Correct Answer:D. X-Forwarded-For
Explanation:
The X-Forwarded-For field in HTTP header is used to identify the originating IP address of a client connecting to a web server through an HTTP proxy or a load balancer. When the ''Obtain the Visitor's Real IP Address'' function is enabled in Alibaba Cloud SLB, the SLB instance adds the X-Forwarded-For field to the HTTP header of each request and forwards the request to the backend server. The backend server can then obtain the real IP address of the visitor from the X-Forwarded-For field1. The format of the X-Forwarded-For field is as follows:
X-Forwarded-For: client, proxy1, proxy2
where the value is a comma+space separated list of IP addresses, the left-most being the original client, and each successive proxy that passed the request adding the IP address where it received the request from. In this example, the request passed through proxy1, proxy2, and then the SLB instance (proxy3).2
Question 11
For ECS and RDS instances under different Alibaba Cloud accounts but in the same region, which of the following statements is NOT correct for migrating self-built MySQL databases (running on ECS) to RDS?
Correct Answer:A. The data can be imported via the Intranet
Explanation:
Data Transmission Service (DTS) is a real-time data streaming service that supports data transmission between data sources such as relational databases, NoSQL, and Big Data (OLAP). DTS supports data migration, data synchronization, and change data subscription scenarios. DTS can migrate your data to and from most of the widely used commercial and open source databases. It supports homogeneous migrations such as MySQL to MySQL, as well as heterogeneous migrations between different database platforms, such as Oracle to MySQL. Migrations can be from on-premises databases to RDS or ECS, databases running on ECS to RDS, or vice versa, as well as from one RDS database to another RDS database. DTS also supports migrating data between RDS instances of different Alibaba Cloud accounts, as long as they are in the same region1. Therefore, the statement B. The data cannot be migrated is NOT correct for migrating self-built MySQL databases (running on ECS) to RDS. The other statements are correct, as the data can be imported via the Intranet, the public network, or by running mysqldump234. Reference:
1: Migrate Self-built Database to RDS - Alibaba Cloud
2: Migrating a Self-built MySQL Database to Alibaba Cloud RDS for MySQL with Minimal Downtime - Alibaba Cloud Community
3: Migrating Data from a Self-Managed SQL Server Database on an ECS to an ApsaraDB RDS for SQL Server Database
4: Migrate data between RDS instances of different Alibaba Cloud accounts,Data Transmission Service
Question 12
Which of the following statements about file uploading to OSS is NOT correct?
Correct Answer:A. All file uploading methods provided by Alibaba Cloud OSS service will support resuming from break point.
Explanation:
Not all upload methods in Alibaba Cloud OSS support resuming from a breakpoint. Only specific methods, such as multipart upload, support this feature. Small files can be uploaded using a single PUT request, while APPEND is useful for continuously updated log files. For large files, multipart uploading is recommended to handle potential interruptions.
Question 13
The backend server pool of an Alibaba Cloud SLB contains multiple ECS instances, which may have different service capacities. To exploit the different service capacities of backend ECS instances, which of the following statements is correct?
Correct Answer:A. Choose Weighted Round Robin mode to set higher weights to ECS instances with higher capacities The higher the weight of the backend ECS instance the higher chance that the instance will receive requests.
Explanation:
Weighted Round Robin (WRR) is a load balancing mode that assigns requests to backend ECS instances based on their weights. The higher the weight of the backend ECS instance, the higher the chance that the instance will receive requests. This mode can exploit the different service capacities of backend ECS instances by setting higher weights to ECS instances with higher capacities. For example, if there are two ECS instances in the backend server pool, one with a weight of 10 and the other with a weight of 20, the ECS instance with a weight of 20 will receive twice as many requests as the ECS instance with a weight of 10.
1: SLB overview - Server Load Balancer - Alibaba Cloud Documentation Center
4: Server Load Balancer - Alibaba Cloud
5: Alibaba Server Load Balancer (SLB) Course - Cloud Academy
Question 14
Alibaba Cloud CloudMonitor allows you to customize monitoring metrics and alert policies. Which of the following statements about customized monitoring are correct? (Choose two.)
Correct Answer:A. Users can monitor concerned services and report collected monitoring data to CloudMonitor so that CloudMonitor processes the data and generates alerts according to the result.; D. The number of customized monitoring metrics is not limited, and programs used to report metric data may be deployed on devices other than the Alibaba Cloud server.
Explanation:
CloudMonitor allows users to create custom monitoring metrics and report data, which can then be analyzed and used for alerts. Customized monitoring is flexible, with no set limits on the number of metrics, and users can report data from Alibaba Cloud servers or other devices.
Question 15
When creating cloud product instances in Alibaba Cloud, you can choose the default VPC and VSwitch. The difference between non-default VPC/VSwitch and default VPC/VSwitch is that default VPC and VSwitch can only be created by Alibaba Cloud. Which of the following statements is incorrect about default VSwitch?
Correct Answer:C. Default and non-default VSwitches have the same constraints and operations
Explanation:
Default and non-default VSwitches do not have the same constraints and operations. Default VSwitches have specific configurations and limitations set by Alibaba Cloud, designed to simplify initial setups. In contrast, non-default VSwitches, created by users, allow for more customized configurations and are typically used in more complex or specialized networking environments. Thus, option C is incorrect as the constraints and operations differ between default and non-default VSwitches.