passdrill

EC2 & Compute

38 cards · AWS SAA-C03 · answer each one, then read the explanation. Your score tallies below.

0 / 38 answered · 0 correct

AWS SAA-C03 · EC2 & Compute · Card 001/038 easy

A company runs an application on an EC2 instance that uses instance store volumes for scratch data. An engineer stops the instance overnight to save costs. What happens to the data on the instance store volumes?

  1. The data persists and is available when the instance starts again
  2. The data is lost when the instance is stopped
  3. The data is automatically backed up to Amazon S3
  4. The data is migrated to an EBS volume
AWS SAA-C03 · EC2 & Compute · Card 002/038 easy

A media company needs to run a nightly video transcoding job that can tolerate interruptions and restarts. The finance team wants the lowest possible EC2 compute cost. Which purchasing option best fits this workload?

  1. On-Demand Instances
  2. Dedicated Hosts
  3. A zonal Reserved Instance
  4. Spot Instances
AWS SAA-C03 · EC2 & Compute · Card 003/038 easy

A web application runs on a single On-Demand EC2 instance with no load balancer. As part of routine maintenance, an engineer stops the instance and then starts it again (this is not a reboot). No Elastic IP is associated with the instance. What happens to its public IPv4 address?

  1. The public IPv4 address is retained exactly as it was before the stop
  2. The instance permanently loses all public IPv4 connectivity
  3. The instance is assigned a new public IPv4 address
  4. AWS automatically converts the address into a permanent Elastic IP
AWS SAA-C03 · EC2 & Compute · Card 004/038 easy

A team runs a t3.medium EC2 instance for a workload that is mostly idle but occasionally needs to sustain CPU usage above the instance's baseline for extended periods. With the default 'Standard' credit configuration, performance drops sharply once accumulated CPU credits run out. Which change lets the instance sustain high CPU performance during these bursts, while accepting that AWS may charge extra for the additional usage?

  1. Switch the instance's credit specification to Unlimited mode
  2. Move the instance into a Spread placement group
  3. Enable EBS optimization on the instance
  4. Change the Auto Scaling group's health check type to ELB
AWS SAA-C03 · EC2 & Compute · Card 005/038 easy

A security team wants to reduce the risk of an application vulnerability being exploited to steal an EC2 instance's IAM role credentials via the instance metadata service. Which configuration change most directly mitigates this specific risk?

  1. Replace the instance's shared tenancy with a Dedicated Host
  2. Enable detailed CloudWatch monitoring on the instance
  3. Move the instance into a cluster placement group
  4. Require IMDSv2 by setting the instance metadata options' HttpTokens parameter to required
AWS SAA-C03 · EC2 & Compute · Card 006/038 easy

An architect must run 5 critical instances of a distributed application in a single Availability Zone. Each instance must run on genuinely distinct underlying hardware, so that a single hardware failure cannot affect more than one instance. Which EC2 placement group strategy fits this requirement?

  1. Cluster placement group
  2. Spread placement group
  3. Partition placement group
  4. No placement group, relying on AWS's default instance placement
AWS SAA-C03 · EC2 & Compute · Card 007/038 medium

An Auto Scaling group launches instances registered with an Application Load Balancer target group. One instance passes its EC2 status checks (the underlying hardware, network, and OS are healthy), but its application process has crashed and no longer responds to any requests. The Auto Scaling group's health check type is left at its default value. What happens to this instance?

  1. The Auto Scaling group leaves it running, because by default it only evaluates EC2 status checks
  2. The Application Load Balancer automatically restarts the crashed application process on the instance
  3. The Auto Scaling group launches an additional instance instead of taking any action on the unhealthy one
  4. The Auto Scaling group marks it unhealthy and replaces it, because it also evaluates target group health by default
AWS SAA-C03 · EC2 & Compute · Card 008/038 medium

A team currently manages EC2 Auto Scaling using a Launch Configuration created two years ago. They now want to launch a new instance type and combine On-Demand and Spot purchase options across multiple instance types within the same Auto Scaling group. What should they do?

  1. Edit the existing Launch Configuration to add the new instance type and mixed purchase options
  2. Do nothing, because Launch Configurations already support mixed instances policies
  3. Migrate to a Launch Template, which supports versioning and mixed instances policies
  4. Create a second, separate Auto Scaling group that uses only Spot Instances
AWS SAA-C03 · EC2 & Compute · Card 009/038 medium

A company runs a legacy Windows Server workload under an existing license that is bound to specific physical processor sockets and cores, and it must be able to report the exact host ID, socket count, and core count its instances run on for compliance purposes. Which EC2 tenancy option satisfies both requirements?

  1. Default (shared) tenancy
  2. Dedicated Instances
  3. Dedicated Hosts
  4. A cluster placement group
AWS SAA-C03 · EC2 & Compute · Card 010/038 hard

A company purchased a 1-year Standard Reserved Instance covering an m5.large in us-east-1 for a steady workload. Six months into the term, the workload permanently moves to a c6g.large, a different instance family built on a different processor architecture, for the remainder of the term. Which statement is correct?

  1. The Standard RI can simply be exchanged for a c6g.large RI covering the remaining term
  2. Both Standard and Convertible RIs can freely change instance family at any point during their term
  3. No Reserved Instance type ever supports a mid-term change; the company must wait until renewal
  4. The Standard RI cannot change instance family; only a Convertible RI supports exchanging into a different instance family
AWS SAA-C03 · EC2 & Compute · Card 011/038 easy

A company launches an EC2 instance from an instance-store-backed AMI for a workload that needs the full local NVMe scratch capacity. An engineer later tries to reduce cost by stopping the instance overnight, the same way they do for other instances in the fleet. What happens?

  1. The instance stops normally and can be started again later, exactly like an EBS-backed instance
  2. The stop action is not available; the instance can only be rebooted or terminated, never stopped
  3. The instance stops, but AWS automatically converts its root volume to an EBS volume first
  4. The instance hibernates instead of stopping, preserving the instance store contents
AWS SAA-C03 · EC2 & Compute · Card 012/038 medium

An engineer launches an EC2 instance using the AWS CLI's run-instances command, attaching one additional (non-root) EBS data volume in the same launch request, without explicitly setting DeleteOnTermination on that volume. Later, when the instance is terminated, what happens to that additional volume by default?

  1. It is preserved, because non-root volumes are never deleted automatically
  2. Its deletion behavior always matches whatever was chosen for the root volume
  3. It is preserved only if it was created from a snapshot
  4. It is deleted, because the CLI's default DeleteOnTermination behavior for a data volume attached at launch differs from the console's default
AWS SAA-C03 · EC2 & Compute · Card 013/038 easy

An HPC team is building a tightly coupled MPI simulation cluster and wants the lowest possible inter-instance network latency and the highest throughput between nodes, achieved by grouping all nodes together using a placement group. Which statement about a Cluster placement group is correct?

  1. All instances in a Cluster placement group must reside in a single Availability Zone
  2. A Cluster placement group can span multiple Availability Zones to increase resilience
  3. A Cluster placement group guarantees that no single hardware failure can affect more than one instance
  4. A Cluster placement group is required before you can enable enhanced networking on an instance
AWS SAA-C03 · EC2 & Compute · Card 014/038 easy

An engineer hibernates an EC2 instance overnight instead of leaving it running, in order to save cost while preserving its exact in-memory state for the next morning. Which statement about billing during hibernation is correct?

  1. The company is billed the full On-Demand instance rate the entire time it is hibernated
  2. The company is billed nothing at all, including for the storage used by the saved RAM contents
  3. The company is not billed for instance usage while hibernated, but continues to pay for EBS storage, including the space used to store the RAM contents
  4. The company is billed a reduced, discounted instance rate while hibernated, similar to a Spot Instance
AWS SAA-C03 · EC2 & Compute · Card 015/038 medium

A production EC2 instance has termination protection enabled (its DisableApiTermination attribute is set to true) and is a member of an Auto Scaling group. Which of the following can still terminate this instance despite termination protection being enabled?

  1. A user calling the TerminateInstances API directly
  2. The Auto Scaling group replacing the instance during a scale-in event
  3. A user terminating the instance from the AWS Management Console's Instance State menu
  4. Termination protection has no exceptions; nothing can terminate the instance once it is enabled
AWS SAA-C03 · EC2 & Compute · Card 016/038 hard

An Auto Scaling group uses a Pending:Wait lifecycle hook with its default heartbeat timeout to let a configuration management agent finish installing software before a new instance enters service. The install job unpredictably takes anywhere from 10 minutes to just under 4 hours. With no heartbeat calls sent from the instance and everything left at its defaults, what happens for an install that takes 3 hours?

  1. The instance times out of the wait state after the default 1-hour heartbeat timeout, and Auto Scaling proceeds using the hook's configured default result before the 3-hour install finishes
  2. The instance waits the full 3 hours, because the default heartbeat timeout is 4 hours
  3. The instance waits indefinitely, because lifecycle hooks never time out unless a heartbeat explicitly ends them
  4. The instance is terminated immediately once the hook is created, before the install can even start
AWS SAA-C03 · EC2 & Compute · Card 017/038 medium

An Auto Scaling group serves an application with a slow, multi-minute boot process. The team configures a warm pool with instances kept in the Stopped state to cut scale-out latency. Immediately after setup, while instances sit in the warm pool but have not yet been drawn into service, how do they affect the group's reported desired capacity?

  1. Each pooled instance immediately counts toward the group's desired capacity, the same as an InService instance
  2. Pooled instances double-count, appearing in both the warm pool metrics and the desired capacity
  3. The warm pool cannot exist unless desired capacity is first reduced to zero
  4. Pooled instances sit outside the desired capacity and only begin counting toward it once they leave the pool and enter service
AWS SAA-C03 · EC2 & Compute · Card 018/038 medium

An architect wants to launch a single batch of compute capacity that combines multiple instance types, spans several Availability Zones, and mixes On-Demand and Spot purchase options, all from one API request, with automatic replacement of any interrupted Spot capacity. Which EC2 capability is purpose-built for this?

  1. A single Launch Template with one instance type specified
  2. A Standard Reserved Instance covering one instance type in one Availability Zone
  3. EC2 Fleet (or Spot Fleet), which launches a fleet across multiple instance types, Availability Zones, and purchase options in one request
  4. A Dedicated Host allocated for the workload's peak capacity
AWS SAA-C03 · EC2 & Compute · Card 019/038 hard

A team wants guaranteed On-Demand capacity for an m5.large in a specific Availability Zone for an upcoming three-day event, starting immediately, with no long-term commitment, and they also want those instances to run inside a placement group. Which combination is valid?

  1. An On-Demand Capacity Reservation combined with a Spread placement group
  2. An On-Demand Capacity Reservation for immediate use combined with a Cluster placement group
  3. A one-year Standard Reserved Instance combined with a Dedicated Host
  4. An On-Demand Capacity Reservation combined with a Partition placement group
AWS SAA-C03 · EC2 & Compute · Card 020/038 easy

An instance's system status check fails due to a hardware problem on its underlying host, and automatic instance recovery successfully migrates it to a new host. Compared with an engineer manually stopping and starting the same instance, which detail is different about automatic recovery's outcome?

  1. Automatic recovery preserves the instance's existing public IPv4 address, while a manual stop and start assigns a new public IPv4 address unless an Elastic IP is attached
  2. Automatic recovery always loses instance store data, while a manual stop and start always preserves it
  3. Automatic recovery changes the instance's private IP address, while a manual stop and start keeps it the same
  4. Automatic recovery moves the instance to a different Availability Zone, while a manual stop and start keeps it in the same one
AWS SAA-C03 · EC2 & Compute · Card 021/038 easy

An engineer researching why modern Nitro-based EC2 instance types deliver almost all of a host's CPU and memory resources to customer workloads, while still providing high-speed networking and low-latency EBS access, asks what makes this possible. What is the correct explanation?

  1. AWS removed the hypervisor entirely, so instances run directly on bare hardware with no virtualization layer at all
  2. A software-only hypervisor upgrade eliminated the need for any dedicated hardware changes
  3. Every Nitro-based instance type is automatically billed as a Dedicated Host at no extra charge
  4. Dedicated Nitro Cards offload networking, storage, and security functions from the host CPU, while a lightweight Nitro Hypervisor and a Nitro Security Chip handle the rest
AWS SAA-C03 · EC2 & Compute · Card 022/038 easy

A security team wants engineers to connect to private EC2 instances that have no public IP address and no inbound rule for SSH or RDP, without managing SSH key pairs or a bastion host, while keeping a centralized, IAM-controlled, logged record of every session. Which approach satisfies all of these requirements?

  1. EC2 Instance Connect, since it also avoids opening inbound SSH ports
  2. AWS Systems Manager Session Manager, using the SSM Agent and an IAM role attached to the instance
  3. A bastion host in a public subnet with a security group restricted to the engineers' office IP range
  4. Enabling IMDSv2 on each instance to allow authenticated shell access over the metadata endpoint
AWS SAA-C03 · EC2 & Compute · Card 023/038 easy

An engineer adds a shell script as user data to an already-running Linux EC2 instance's configuration, expecting it to reinstall a monitoring agent every time the instance reboots. After the script runs successfully at initial launch, the engineer reboots the instance and finds the script did not run again. Why?

  1. User data scripts can only ever run once per instance for the lifetime of that instance, with no way to change this
  2. The script failed silently the second time, because reboots automatically clear all instance user data
  3. By default, user data scripts and cloud-init directives run only during the first boot cycle at launch, not on subsequent reboots or starts, unless explicitly configured to run every time
  4. Reboots never re-read user data at all; only a full stop and start re-reads it
AWS SAA-C03 · EC2 & Compute · Card 024/038 medium

A company's workloads frequently shift between instance families and AWS Regions as teams experiment with new architectures, but overall hourly compute spend is fairly predictable. They want a 1-year discount commitment that keeps working even as the specific instance types and Regions in use change, without reserving physical capacity in any particular Availability Zone. Which purchase option fits best?

  1. A Compute Savings Plan, which discounts EC2 (and Fargate/Lambda) usage regardless of instance family, size, OS, tenancy, or Region
  2. A zonal Reserved Instance, which reserves capacity in one Availability Zone for one specific instance type
  3. An On-Demand Capacity Reservation, since it can be created for any duration with no commitment
  4. A Dedicated Host reservation, since it guarantees the same discount across every instance family automatically
AWS SAA-C03 · EC2 & Compute · Card 025/038 easy

A team is choosing between gp2 and gp3 General Purpose SSD volumes for a fleet of small (50 GiB) boot volumes and wants to understand how their baseline performance differs. Which statement is correct?

  1. gp2 volumes provide a fixed 3,000 IOPS and 125 MiB/s baseline no matter how large the volume is
  2. gp3 and gp2 both scale baseline IOPS proportionally with volume size, with no fixed floor
  3. gp3 volumes provide a fixed 3,000 IOPS and 125 MiB/s baseline regardless of volume size, while gp2's baseline IOPS scale with volume size (3 IOPS per GiB, subject to a burst ceiling)
  4. gp2 volumes provide a fixed 16,000 IOPS baseline regardless of size, while gp3 does not support a baseline at all
AWS SAA-C03 · EC2 & Compute · Card 026/038 medium

A team runs a mission-critical database and wants to maximize the underlying EBS volume's durability without switching to an entirely different storage architecture. They are choosing between io1 and io2 Provisioned IOPS SSD volumes. Which option is correct?

  1. io2, because it is designed for 99.999% annual durability, versus io1's 99.8%-99.9%, while offering the same Provisioned IOPS SSD architecture
  2. io1, because it supports a higher maximum IOPS ceiling than io2 in every AWS Region
  3. gp3, because General Purpose SSD volumes now match Provisioned IOPS SSD durability at a lower cost
  4. st1, because Throughput Optimized HDD volumes are rated for the same 99.999% durability as io2 at a fraction of the price
AWS SAA-C03 · EC2 & Compute · Card 027/038 easy

An engineer wants the lowest-cost EBS volume for the root/boot volume of a new EC2 instance and is considering Cold HDD (sc1) to save money. What should they know before choosing it?

  1. sc1 is fully supported as a boot volume and is actually the recommended choice for minimizing boot volume cost
  2. sc1 can be used as a boot volume only if the instance is launched from an instance-store-backed AMI
  3. sc1 can be used as a boot volume only after Fast Snapshot Restore is enabled on the underlying snapshot
  4. sc1 (Cold HDD), like st1 (Throughput Optimized HDD), cannot be used as a boot volume at all; only SSD-backed volume types (gp2, gp3, io1, io2) support that role
AWS SAA-C03 · EC2 & Compute · Card 028/038 medium

A team wants to attach a single EBS volume to multiple EC2 instances simultaneously for a clustered application using EBS Multi-Attach. Which statement about Multi-Attach is correct?

  1. Multi-Attach works with any EBS volume type, including gp3, as long as all instances are in the same Availability Zone
  2. Multi-Attach enabled io1/io2 volumes can be attached to up to 16 Nitro-based instances, but only within a single Availability Zone, and Multi-Attach does not by itself coordinate concurrent writes, so a standard file system like XFS or EXT4 still needs a cluster-aware layer on top
  3. Multi-Attach lets instances in different Availability Zones, and even different Regions, share the same volume for cross-Region high availability
  4. Multi-Attach can only be enabled at instance launch time via the RunInstances API, not afterward
AWS SAA-C03 · EC2 & Compute · Card 029/038 easy

A team takes a snapshot of a 500 GiB EBS volume, then a week later takes a second snapshot after only a small fraction of the data has changed. How does the storage behavior of the second snapshot compare to the first?

  1. The second snapshot is incremental, storing only the blocks that changed since the first snapshot, so it typically consumes far less storage than a full copy of the volume
  2. The second snapshot always duplicates the entire 500 GiB again, regardless of how little data changed
  3. The second snapshot only exists as a pointer and consumes no storage at all, since EBS snapshots after the first are always free
  4. The second snapshot's size depends entirely on the volume's provisioned IOPS setting, not on how much data changed
AWS SAA-C03 · EC2 & Compute · Card 030/038 hard

A company wants to share a custom AMI, backed by EBS snapshots encrypted with a customer managed KMS key, with a second AWS account so that account can launch instances from it. What must they do?

  1. Sharing the AMI's launch permissions with the second account is sufficient by itself; encryption keys are automatically made available to any account granted launch permissions
  2. Encrypted AMIs can only ever be shared within the same AWS account; cross-account sharing of an encrypted AMI is not possible under any circumstances
  3. The company must switch the AMI's snapshots to use an AWS managed key before cross-account sharing becomes possible, since AWS managed keys support cross-account grants but customer managed keys do not
  4. The company must grant the second account launch permissions on the AMI AND update the customer managed KMS key's policy to grant that account the permissions needed to use the key (e.g., Decrypt, CreateGrant), since AWS managed keys cannot be shared across accounts at all
AWS SAA-C03 · EC2 & Compute · Card 031/038 medium

An account administrator enables the "Always encrypt new EBS volumes" (EBS encryption by default) setting in a Region, hoping this will secure the account's existing unencrypted volumes and snapshots too. What actually happens?

  1. The setting immediately re-encrypts every existing unencrypted volume and snapshot in that Region in the background
  2. The setting only applies going forward: newly created volumes and snapshots in that Region are encrypted automatically, but volumes and snapshots that already existed before the setting was enabled remain unencrypted unless the administrator explicitly migrates them
  3. The setting applies retroactively to existing volumes but not to existing snapshots
  4. The setting has no effect on snapshots at all in any case, only on volumes
AWS SAA-C03 · EC2 & Compute · Card 032/038 medium

A team frequently launches new volumes from a "golden" snapshot to seed fresh environments, but sees degraded I/O performance on first access to blocks that haven't been touched yet, until the whole volume has been "warmed up". Which feature directly addresses this?

  1. Provisioned IOPS (io1/io2), since only Provisioned IOPS volumes can be created from a snapshot at all
  2. EBS Multi-Attach, since spreading reads across multiple attached instances hides the latency
  3. Fast Snapshot Restore (FSR), enabled per snapshot per Availability Zone, which makes a volume created from that snapshot fully initialized immediately, delivering its full provisioned performance from the first I/O instead of lazily pulling unread blocks from Amazon S3 on first access
  4. EBS encryption by default, since encrypted volumes skip the lazy-loading step entirely
AWS SAA-C03 · EC2 & Compute · Card 033/038 easy

An engineer deregisters an old, unused custom AMI to "clean up" and stop paying for it, but the next month's bill shows storage charges continuing for what turns out to be that AMI's underlying EBS snapshot. What explains this?

  1. This must be a billing error, since deregistering an AMI always deletes its underlying snapshots automatically
  2. Deregistering an AMI only removes the AMI's registration (so it can no longer be used to launch new instances); it does not, by default, delete the EBS snapshots that backed it, so those snapshots keep incurring storage charges until they are deleted separately
  3. The snapshot charges will stop automatically within 30 days as AWS's standard grace period for deregistered AMIs expires
  4. Deregistering an AMI only stops the snapshot charges if the AMI was shared with another account first
AWS SAA-C03 · EC2 & Compute · Card 034/038 easy

A company copies a custom AMI from us-east-1 to eu-west-1 so it can launch instances there. A few weeks later, they deregister the original AMI in us-east-1 because it's no longer needed. What happens to the copy in eu-west-1?

  1. The copied AMI in eu-west-1 is entirely independent, with its own distinct AMI ID; deregistering the original AMI in us-east-1 has no effect on it
  2. Deregistering the source AMI in us-east-1 automatically deregisters the copy in eu-west-1 too, since copies stay linked to their source
  3. The copy in eu-west-1 shares the exact same AMI ID as the original in us-east-1, since AMI IDs are global across Regions
  4. The copy cannot be used to launch instances until the original AMI in us-east-1 is deregistered first
AWS SAA-C03 · EC2 & Compute · Card 035/038 easy

An engineer sees the instance type "m6a.large" in a couple of the fleet's launch templates and wants to decode the name to understand what it commits them to. Which statement correctly decodes it?

  1. "m6a" tells you only the vCPU count; the "large" suffix determines the instance family
  2. The "6" indicates the number of CPU cores, and "a" indicates the AWS Region the instance type is available in
  3. "m6a" specifies the operating system license included with the instance, and "large" specifies the pricing model (On-Demand vs Reserved)
  4. "m" identifies the instance family (general purpose), "6" identifies the generation number within that family, and the additional letter "a" indicates a processor variant (AMD-based, in this case), while "large" is the instance size within that type
AWS SAA-C03 · EC2 & Compute · Card 036/038 easy

A team migrating from very old EC2 instance types to current-generation instance types wonders whether they'll need to pay extra and separately enable "EBS-optimized" to get full EBS performance, the way some very old instance types required. What should they know?

  1. EBS optimization was deprecated and no longer exists as a feature on current-generation instance types
  2. EBS optimization must still be explicitly enabled and paid for separately on every instance type, old and new alike
  3. Nearly all current-generation instance types, including all instance types built on the Nitro System, are EBS-optimized by default at no additional charge, unlike some older-generation instance types that required explicitly enabling it (sometimes for an extra fee)
  4. EBS optimization is now bundled entirely into gp3 pricing, so it depends on volume type rather than instance type
AWS SAA-C03 · EC2 & Compute · Card 037/038 hard

An engineer sets up a CloudWatch alarm to run the built-in "Recover this instance" action on a StatusCheckFailed_System alarm, expecting it to work uniformly across the whole fleet, which includes some instances using local instance store volumes, some using Dedicated Host tenancy, and some bare-metal instance types. What should the engineer expect?

  1. The recover action is guaranteed to work identically across all of these instances, since any instance with an EC2 status check can be recovered
  2. The recover action is unavailable for instances that use instance store volumes, for instances running with Dedicated Host tenancy, and for bare-metal instance types; only a subset of instance types and configurations support it
  3. The recover action only fails for bare-metal instance types; instance store volumes and Dedicated Host tenancy have no effect on eligibility
  4. The recover action is unavailable for every instance except those using Dedicated Host tenancy, since that tenancy model is specifically designed to support automated recovery
AWS SAA-C03 · EC2 & Compute · Card 038/038 medium

A company processes highly sensitive customer data (for example, for tokenization) and wants an isolated compute environment carved out of an existing EC2 instance that has no persistent storage, no external network access, and can cryptographically prove to a service like AWS KMS exactly what code it's running before being granted decryption access. Which approach fits?

  1. A second, network-isolated EC2 instance placed in a private subnet with no internet gateway route
  2. An EC2 instance running inside a Dedicated Host, since dedicated tenancy alone guarantees this level of isolation
  3. An Auto Scaling group configured with a warm pool, since pooled instances have no active network path until put into service
  4. An AWS Nitro Enclave: an isolated virtual machine carved out of CPU and memory from a Nitro-based parent EC2 instance, with no persistent storage and no external network connectivity of its own (communicating with the parent only over a local vsock channel), which can generate a Nitro Hypervisor-signed cryptographic attestation document that AWS KMS can use as a condition for authorizing decryption