exam questions

Exam AWS Certified SAP on AWS - Specialty PAS-C01 All Questions

View all questions & answers for the AWS Certified SAP on AWS - Specialty PAS-C01 exam

Exam AWS Certified SAP on AWS - Specialty PAS-C01 topic 1 question 40 discussion

A company has an SAP environment that runs on AWS. The company wants to enhance security by restricting Amazon EC2 Instance Metadata Service (IMDS) to IMDSv2 only. The company’s current configuration option supports both IMDSv1 and IMDSv2. The security enhancement must not create an SAP outage.
What should the company do before it applies the security enhancement on EC2 instances that are running the SAP environment?

  • A. Ensure that the SAP kernel versions are 7.45 or later.
  • B. Ensure that the EC2 instances are Nitro based.
  • C. Ensure that the AWS Data Provider for SAP is installed on each EC2 instance.
  • D. Stop the EC2 instances.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
anttan
Highly Voted 2 years, 3 months ago
Answer is A. Before applying the security enhancement on EC2 instances running the SAP environment to restrict IMDS to IMDSv2 only, the company should ensure that the SAP kernel versions are 7.45 or later. This is because kernel version 7.45 and later supports the IMDSv2 protocol, while earlier versions only support IMDSv1. If the company applies the security enhancement before upgrading to kernel version 7.45 or later, it could result in an SAP outage or other issues.
upvoted 6 times
...
awsmonster
Most Recent 1 year, 4 months ago
Selected Answer: C
Agreed with geoakes !
upvoted 1 times
...
geoakes
1 year, 4 months ago
Selected Answer: C
Why C: https://aws.amazon.com/about-aws/whats-new/2021/05/aws-data-provider-sap-version-4-0-now-available/ Not A or B, since this is a 'SAP environment that runs on AWS' already Not D as that is downtime
upvoted 2 times
...
kaishin0527
1 year, 10 months ago
Selected Answer: B
B: IMDSv2 is only fully supported on Nitro-based instances. If you need to enforce IMDSv2 on an instance, you must ensure that the instance is Nitro-based. These instances are designed to provide enhanced security, networking, and performance.
upvoted 3 times
...
[Removed]
1 year, 10 months ago
Selected Answer: C
Voting C
upvoted 2 times
...
easytoo
1 year, 11 months ago
b-b-b-b-b-b
upvoted 1 times
...
mawsman
2 years ago
Selected Answer: A
The company's current infrastructure already supports both v1 and v2 - meaning instances are already nitro - as per anttan's comments the kernel needs to be 7.45 to update without outages
upvoted 1 times
SONALID
1 year, 7 months ago
nitro only supports kernel higher than 745. So it is not possible to have existing infrastructure in nitro without having kernel higher than 745
upvoted 1 times
...
...
schalke04
2 years, 3 months ago
Selected Answer: B
https://me.sap.com/notes/1656250
upvoted 3 times
...
Kiran1982
2 years, 3 months ago
Selected Answer: B
As described in note 1656250, IMDS version 2 is not supported with SAP in Xen based instances.
upvoted 4 times
...
kk8s
2 years, 4 months ago
C maybe
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...