
Updated Free Alibaba Cloud ACP-Cloud1 Test Engine Questions with 72 Q&As
The Best Alibaba Cloud Computing ACP-Cloud1 Professional Exam Questions
Alibaba Cloud ACP-Cloud1: ACP Cloud Computing Professional exam is a valuable certification that validates an individual's knowledge and skills in cloud computing. ACP Cloud Computing Professional certification is designed for professionals who want to demonstrate their expertise in cloud computing and gain a competitive edge in the job market. ACP-Cloud1 exam covers essential topics such as cloud computing architecture, security, management, and operations and is available in multiple languages.
NEW QUESTION # 12
Alibaba Cloud Content Delivery Network (CDN) is a distributed network that is built and overlaid on the bearer network Moreover it is composed of edge node server clusters distributed across different regions. It replaces the traditional data transmission mode, which is centered on Web servers. When using Alibaba Cloud CDN, a user's request wilt first reach the edge node, and then receive data from the origin site by means of back-to-source Moreover, the admin can obtain visitor's real IP on the origin site. Which of the following descriptions relate to "obtaining visitors real IP" are correct? (Number of correct answers: 2)
- A. "Visitor's real IP" can only be obtained by modifying the application
- B. In Windows, if IIS is used: after installing "F5XForwardedFor" extension module. 'Visitor's real IP" can then be seen in the log.
- C. You can one-step activate the "recording visitor's real IP" function in Alibaba Cloud CDN console to directly view the visitor's real IP in the access log.
- D. "Visitor's real IP" is saved in "X-Forwarded-For" header in HTTP protocol. It can be directly obtained in the user-defined LOG of Apache and Nginx.
Answer: B,D
NEW QUESTION # 13
Alibaba Cloud Object Storage Service (OSS) is a cloud storage service that features massive capacity, outstanding security, low costs, and high reliability. In an OSS bucket, all elements are stored as________.
- A. Objects
- B. Hashes
- C. Stubs
- D. Keys
Answer: A
Explanation:
Explanation
OSS does not use a hierarchical structure for objects, but instead uses a flat structure. All elements are stored as objects in buckets. To use OSS in the same manner in which local file systems are used, you can configure Cloud Storage Gateway (CSG).
https://www.alibabacloud.com/help/doc-detail/31817.htm
The statement C is correct, because in an OSS bucket, all elements are stored as objects. An object is the basic unit of OSS storage. Each object consists of a unique key, data, and metadata. The key is the name of the object, which is used to identify the object in a bucket. The data is the content of the object, which can be any type of file, such as text, image, video, or audio. The metadata is the information about the object, such as its size, type, creation time, and custom attributes. References: = Object Storage Service:Overview - Alibaba Cloud
NEW QUESTION # 14
Which of the following scenarios can be done using Alibaba Cloud Express Connection? (Number of correct answers: 2)
- A. Intranet communication between VPCs and Smart Access Gateway in customers different branch offices
- B. Intranet communication between two VPCs under the same account in the same region
- C. Intranet communication between two VPCs in different accounts and different CIDR Blocks
- D. Intranet communication between a VPC and servers in an external IDC
Answer: A,D
Explanation:
Explanation
Alibaba Cloud Express Connect is a service that enables high-bandwidth, reliable, secure, and private connections between different networks, such as VPC networks across regions, Alibaba Cloud accounts, and on-premise data centers1. It supports different connection methods, such as physical connections, virtual border routers, and Express Cloud Connect1.
Scenario A: Intranet communication between VPCs and Smart Access Gateway in customers different branch offices. This scenario can be achieved by using Express Cloud Connect, which is based on the hardware capacities of Smart Access Gateway and provides SD-WAN capabilities1. Express Cloud Connect allows you to connect your branch offices to Alibaba Cloud through a dedicated partner backbone network, and access VPC networks in all regions1.
Scenario B: Intranet communication between a VPC and servers in an external IDC. This scenario can be achieved by using physical connections, which are dedicated network connections between on-premise data centers and VPC networks1. You can lease a line from your ISP or work with an Alibaba Cloud partner to establish a physical connection to Alibaba Cloud1. This way, you can access VPC networks in all regions with high bandwidth and low latency1.
Scenario C: Intranet communication between two VPCs in different accounts and different CIDR Blocks. This scenario can be achieved by using peering connections, which are logical connections that enable communication between VPC networks2. Peering connections support cross-region and cross-account scenarios, and allow you to connect VPC networks with different CIDR blocks2. However, peering connections are not part of Alibaba Cloud Express Connect, but a separate service called Cloud Enterprise Network2.
Scenario D: Intranet communication between two VPCs under the same account in the same region. This scenario can also be achieved by using peering connections, which are logical connections that enable communication between VPC networks2. Peering connections support intra-region and same-account scenarios, and allow you to connect VPC networks with different CIDR blocks2. However, peering connections are not part of Alibaba Cloud Express Connect, but a separate service called Cloud Enterprise Network2. References: 1: Express Connect - Alibaba Cloud 2: Introduction to Cloud Enterprise Network - Alibaba Cloud Document Center
NEW QUESTION # 15
Company A constructed a sales management platform using three Elastic Compute Service (ECS) instances.
One of the instances runs MySQL, and is used as the database server. The other two instances are used as Web servers After some time, the number of employees in Company A dramatically increases, leading to higher sales volumes At the same time, the platform response speed is gradually decreasing too.
According to the report from CloudMonitor, the average CPU utilization rate of the two Web servers exceeds
70%, and database load
reaches 75% Company A can select Alibaba Cloud_________ services.to cope with the issue and optimize the performance. (Number of correct answers: 2)
- A. Incorporate Server Load Balancer (SLB) and add additional ECS instances to relieve the load on existing ECS instances
- B. Replace the self-built MySQL database with ApsaraDB for RDS to obtain better database performance, and utilize RDS read-only instances to handle read-only requests
- C. Use Content Delivery Network (CDN) to enhance content loading speed
- D. Import database data into Object Storage Service (OSS) to share the storage pressure on the platform
Answer: A,B
Explanation:
Explanation
Option B is correct because using Server Load Balancer (SLB) and adding additional ECS instances can help to distribute the traffic among multiple servers and improve the availability and scalability of the platform. SLB can also provide health checks and fault tolerance for the ECS instances1 Option D is correct because replacing the self-built MySQL database with ApsaraDB for RDS can provide better database performance, security, and reliability. ApsaraDB for RDS is a fully managed cloud database service that supports MySQL, SQL Server, PostgreSQL, and other engines. It can automatically handle tasks such as backup, recovery, monitoring, and patching. Using RDS read-only instances can also handle read-only requests and reduce the load on the primary database2 Option A is incorrect because importing database data into Object Storage Service (OSS) will not share the storage pressure on the platform. OSS is a cloud storage service that provides high durability, availability, and scalability for storing unstructured data such as images, videos, and documents. It is not suitable for storing structured data such as database tables. Moreover, importing data into OSS will incur additional costs and latency3 Option C is incorrect because using Content Delivery Network (CDN) will not enhance the content loading speed of the platform. CDN is a distributed network that delivers content to users based on their geographic locations, the origin of the content, and the content delivery server. It is mainly used to accelerate the delivery of static content such as images, videos, and scripts. It is not effective for dynamic content such as database queries and transactions4 References:
1: Server Load Balancer - Alibaba Cloud
2: ApsaraDB for RDS - Alibaba Cloud
3: Object Storage Service - Alibaba Cloud
4: Content Delivery Network - Alibaba Cloud
NEW QUESTION # 16
A large enterprise wants to migrate the entire business system to Alibaba Cloud to save the overall IT procurement and O&M costs From the security aspect, the company requires that
1. Must support secured remote O&M because the administrator often takes business trips.
2. Networks between subsystems should be isolated because subsystems are independently used by different departments Which of the followings should be used together to meet the company's requirements? (Number of correct answers: 3)
- A. Build an independent ECS instance as the bastion host or remote logon and O&M, and authorize the bastion host to access ECS instances running other subsystems.
- B. Use the security group function of the ECS instance, and respectively deploy ECS instances running different subsystems to independent security groups.
- C. Enable the VPN on the bastion host (or directly use the VPN image on Alibaba Cloud Marketplace).
The administrator uses VPN encrypted communication during O&M. - D. Create multiple ECS instances in the VPC to install subsystems of different departments- Allocate only Intranet IP addresses to all ECS instances, and deploy them in the same security groups.
Answer: A,B,C
Explanation:
Explanation
To meet the company's security requirements, the following solutions should be used together:
A: Enable the VPN on the bastion host (or directly use the VPN image on Alibaba Cloud Marketplace).
The administrator uses VPN encrypted communication during O&M. This solution can support secure remote O&M, because VPN (Virtual Private Network) is a technology that creates a secure and encrypted connection over the Internet between the bastion host and the administrator's device. VPN can protect the data transmitted between the bastion host and the administrator from being intercepted or tampered by malicious third parties1. Alibaba Cloud provides VPN Gateway service that allows users to create VPN connections between VPCs and on-premises data centers, or between VPCs in different regions2. Users can also use VPN images from Alibaba Cloud Marketplace, such as OpenVPN, to create VPN servers on ECS instances3.
B: Build an independent ECS instance as the bastion host or remote logon and O&M, and authorize the bastion host to access ECS instances running other subsystems. This solution can also support secure remote O&M, because a bastion host is a special-purpose ECS instance that acts as a proxy or a gateway for accessing other ECS instances in the VPC. A bastion host can enhance the security of the ECS instances by limiting the exposure of the ECS instances to the public network, and by implementing security policies and monitoring tools on the bastion host4. Alibaba Cloud provides Bastionhost service that allows users to centrally manage the access to cloud servers from external networks and provide secure connections to VPC resources5.
C: Use the security group function of the ECS instance, and respectively deploy ECS instances running different subsystems to independent security groups. This solution can isolate the networks between subsystems, because a security group is a virtual firewall that controls the inbound and outbound traffic of the ECS instances in the group. Users can configure security group rules to allow or deny access based on the network protocol, port, and source IP address. By deploying ECS instances running different subsystems to independent security groups, users can prevent unauthorized access or communication between the subsystems6.
The other solution is not suitable for the company's scenario, for the following reason:
D: Create multiple ECS instances in the VPC to install subsystems of different departments- Allocate only Intranet IP addresses to all ECS instances, and deploy them in the same security groups. This solution cannot isolate the networks between subsystems, because ECS instances in the same security group can communicate with each other by default, regardless of whether they have intranet or internet IP addresses. Moreover, this solution may also prevent the ECS instances from accessing the internet or providing external services, which may affect the business operation of the company6.
References: What is a VPN? - Virtual Private Network - Cisco, VPN Gateway - Alibaba Cloud, OpenVPN - Alibaba Cloud Marketplace, Bastion Host - Alibaba Cloud Document Center, Bastionhost - Alibaba Cloud, Security groups - Elastic Compute Service - Alibaba Cloud
NEW QUESTION # 17
When using Alibaba Cloud SLB to forward layer 7 (HTTP) service requests. SLB will replace the IP address in the HTTP header file to forward requests.
Therefore the source IP address that can be seen on the backend ECS instance is the IP address of SLB instead of the clients real IP address.
- A. True
- B. False
Answer: A
Explanation:
Explanation
When using Alibaba Cloud SLB to forward layer 7 (HTTP) service requests, SLB will replace the IP address in the HTTP header file to forward requests. Therefore, the source IP address that can be seen on the backend ECS instance is the IP address of SLB instead of the client's real IP address. However, SLB also provides a feature called X-Forwarded-For (XFF) that can help you obtain the real IP address of the client. XFF is a standard HTTP header field that records the original IP address of the client and the proxy servers that the request passes through. You can enable XFF on the SLB console or by using the API, and then configure your backend ECS instance to parse the XFF header field and get the real IP address of the client. References: 1 - SLB overview - Alibaba Cloud Document Center - Layer 7 listeners - X-Forwarded-For
NEW QUESTION # 18
SLB is a load balancing service that distributes traffic to multiple cloud servers It provides a wide range of functions to meet the needs of various business scenarios If a user wants to use SLB and ECS instances to deploy two-way authenticated HTTPS websites, the following statement is correct_______.
- A. SLB can only host SSL certificates, not CA certificates.
- B. You need to host server SSL certificates and client CA certificates on SLB
- C. SLB can only support HTTPS one-way authentication
- D. SLB can only host CA certificates, not SSL certificate
Answer: C
NEW QUESTION # 19
After stopping an Alibaba Cloud Elastic Compute Service (ECS) instance, since the ECS instance is stopped, you will not be charged for anything related to that ECS instance until you start the instance again regardless of which region the instance is located in.
- A. True
- B. False
Answer: A
NEW QUESTION # 20
A Virtual Private Cloud (VPC) is an isolated network environment that is completely isolated from each other The following statements about VPC are correct_________. (Number of correct answers: 2)
- A. Each VPC has an independent tunnel ID, and a tunnel ID corresponds to a virtualized network.
- B. ECS instances in a VPC use security group firewalls for Layer 2 network access control.
- C. The internal networks of different VPCs are completely isolated and can be interconnected through IP addresses mapped to the outside.
- D. Subnets can be divided like the traditional network environment. Different cloud servers within each subnet are connected by the same router and different subnets are interconnected by switches.
Answer: A,C
Explanation:
Explanation
According to the Alibaba Cloud Academy, a VPC is an isolated network environment that is completely isolated from each other. Each VPC has an independent tunnel ID, and a tunnel ID corresponds to a virtualized network. This means that different VPCs cannot communicate with each other through the tunnel ID. Subnets are not divided like the traditional network environment, but rather are logical divisions of the VPC. Different cloud servers within each subnet are connected by the same router, but different subnets are interconnected by route tables, not switches. ECS instances in a VPC use security group firewalls for Layer 4 network access control, not Layer 2. The internal networks of different VPCs are completely isolated and can be interconnected through IP addresses mapped to the outside, such as NAT Gateway or EIP. References: ACP Cloud Computing Certification Preparation Course - Internetworking with VPC, Alibaba Cloud VPC User Guide
NEW QUESTION # 21
All RDS for MySQL backups are full backups.
- A. True
- B. False
Answer: B
Explanation:
Explanation
RDS for MySQL supports both full backups and incremental backups. A full backup is a complete backup of all data in a database. An incremental backup is a backup of only the data that has changed since the last backup. Incremental backups can reduce the backup time and storage space. You can configure the backup cycle and retention period for both types of backups in the RDS console or by using the API.
NEW QUESTION # 22
Alibaba Cloud CloudMonitor is a service that monitors Alibaba Cloud resources and Internet functions currently provided by CloudMonitor? (Number of correct answers: 3)
- A. Cloud service monitoring
- B. Customized monitoring
- C. Custom firewall
- D. Site monitoring
- E. Operation auditing
Answer: A,B,D
Explanation:
Explanation
https://cloudacademy.com/course/alibaba-security-monitoring-1275/introduction-to-cloud-monitor/#:~:text=Clou Option A is correct because site monitoring is one of the functions provided by CloudMonitor. Site monitoring monitors the availability, connectivity, and domain name resolution of sites. It monitors the connectivity and response time of domain names, IP addresses, and ports, and sends alert notifications based on monitoring results1 Option B is correct because customized monitoring is one of the functions provided by CloudMonitor.
Customized monitoring allows you to monitor the metrics of your own applications or services. You can use the CloudMonitor API or SDK to report custom metrics to CloudMonitor and view them on the CloudMonitor console. You can also configure alert rules for your custom metrics2 Option E is correct because cloud service monitoring is one of the functions provided by CloudMonitor.
Cloud service monitoring monitors the metrics of Alibaba Cloud services, such as Elastic Compute Service (ECS), Object Storage Service (OSS), ApsaraDB for RDS, and Server Load Balancer (SLB).
CloudMonitor collects the metrics of these services and displays them on the CloudMonitor console. You can also configure alert rules for these metrics2 Option C is incorrect because custom firewall is not a function provided by CloudMonitor. Custom firewall is a feature of Alibaba Cloud Security Center, which is a different service from CloudMonitor.
Security Center provides security protection for your cloud resources and applications. Custom firewall allows you to customize firewall rules for your ECS instances and control the inbound and outbound traffic3 Option D is incorrect because operation auditing is not a function provided by CloudMonitor. Operation auditing is a feature of Alibaba Cloud ActionTrail, which is a different service from CloudMonitor.
ActionTrail records the operations performed on your Alibaba Cloud resources and delivers the audit logs to OSS or Log Service for storage and analysis. Operation auditing helps you track the changes of your resources and comply with security standards4 References:
2: What is CloudMonitor? - CloudMonitor - Alibaba Cloud Documentation Center
1: Introduction to Cloud Monitor - Alibaba Security & Monitoring Course
3: [Security Center - Alibaba Cloud]
4: [ActionTrail - Alibaba Cloud]
NEW QUESTION # 23
For ECS and RDS instances under different Alibaba Cloud accounts but in the same region, which of the following statements is NOT correct for migrating self-built MySQL databases (running on ECS) to RDS?
- A. The data can be imported via the public network.
- B. The data can be imported via the Intranet
- C. The data can be imported by running mysqldump.
- D. The data cannot be migrated.
Answer: C
NEW QUESTION # 24
Different Alibaba Cloud VPCs are completely isolated from each other.
By default, the VPCs cannot communicate with each other over Intranet, but you can establish VPN connections via the Internet to achieve interconnection between VPCs.
- A. True
- B. False
Answer: B
Explanation:
Explanation
Different Alibaba Cloud VPCs are completely isolated from each other by default, but they can communicate with each other over the intranet by using different methods, such as Cloud Enterprise Network (CEN), VPN gateways, VPC peering connections, and PrivateLink. These methods allow you to establish secure and reliable connections between VPCs without exposing your network traffic to the internet. References:
Overview of VPC connections - Alibaba Cloud
Cross-VPC peering - Alibaba Cloud
ALIYUN::VPC::VpcPeerConnection - Alibaba Cloud
NEW QUESTION # 25
A Virtual Private Cloud (VPC) is an isolated network environment that is completely isolated from each other The following statements about VPC are correct_________. (Number of correct answers: 2)
- A. Subnets can be divided like the traditional network environment. Different cloud servers within each subnet are connected by the same router and different subnets are interconnected by switches.
- B. Each VPC has an independent tunnel ID, and a tunnel ID corresponds to a virtualized network.
- C. ECS instances in a VPC use security group firewalls for Layer 2 network access control.
- D. The internal networks of different VPCs are completely isolated and can be interconnected through IP addresses mapped to the outside.
Answer: A,D
NEW QUESTION # 26
You are using Auto Scaling with one scaling group already created, then you want to execute a task at a specific time such as removing 1 ECS instance every night at 00:00. To achieve this, which of the following operations should be performed'? (Number of correct answers; 2)
- A. Create an event-triggered task.
- B. Create a scaling rule
- C. Create a new scaling group.
- D. Create a scheduled task.
Answer: B,D
Explanation:
Explanation
To execute a task at a specific time such as removing 1 ECS instance every night at 00:00, you need to perform two operations: create a scaling rule and create a scheduled task. A scaling rule is a set of instructions that defines how Auto Scaling scales computing resources in response to changes in business load. A scheduled task is a type of scaling task that can execute a specified scaling rule at a specified time. By creating a scaling rule that removes 1 ECS instance from the scaling group, and creating a scheduled task that executes this scaling rule every night at 00:00, you can achieve the desired result. You do not need to create a new scaling group, because you already have one scaling group created. You also do not need to create an event-triggered task, because this type of scaling task is triggered by events such as Cloud Monitor alarms or API calls, not by a specific time. References: 1, 2, and 3.
NEW QUESTION # 27
When a customer uses Alibaba Cloud Object Storage Service (OSS) service and finds there exist an amount of Internet downstream traffic, he/she can use Alibaba Cloud Content Delivery Network (CDN) service to reduce the traffic cost.
Because the Internet traffic cost of CDN is lower than that of OSS, moreover, the back-to-source traffic cost from CDN to OSS is also lower than a user access to OSS directly.
- A. True
- B. False
Answer: A
NEW QUESTION # 28
After stopping an Alibaba Cloud Elastic Compute Service (ECS) instance, since the ECS instance is stopped, you will not be charged for anything related to that ECS instance until you start the instance again regardless of which region the instance is located in.
- A. True
- B. False
Answer: B
Explanation:
Explanation
After stopping an Alibaba Cloud Elastic Compute Service (ECS) instance, you will not be charged for the instance usage fee or the public bandwidth fee (if applicable) until you start the instance again. However, you will still be charged for the disk usage fee and the snapshot usage fee (if applicable) regardless of which region the instance is located in. This is because the disks and snapshots are still occupying the storage space and need to be billed accordingly. Therefore, the statement is false. References: 1 - Billing FAQ - Alibaba Cloud Document Center - What fees do I need to pay after I stop a Pay-As-You-Go instance?
NEW QUESTION # 29
......
Alibaba Cloud ACP-Cloud1 Exam is an excellent opportunity for individuals to demonstrate their expertise in cloud computing, particularly in Alibaba Cloud services. It is a comprehensive certification program, covering a wide range of topics related to cloud computing. ACP Cloud Computing Professional certification is highly respected in the industry and provides professionals with a competitive edge in the job market. With the right preparation and training, candidates can earn the ACP-Cloud1 certification and take their career to the next level.
Try 100% Updated ACP-Cloud1 Exam Questions [2024]: https://www.actual4dumps.com/ACP-Cloud1-study-material.html
Pass ACP-Cloud1 Exam - Real Questions and Answers: https://drive.google.com/open?id=1ROwT9KB5rR3gsZsHrD-3XuKK-6nkChZ1