Amazon Web Services · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
18% of exam · 6 sample questions below
A database administrator is troubleshooting an Amazon RDS for PostgreSQL DB instance that is experiencing high CPU utilization. The administrator runs the following query to find the current running queries:
SELECT pid, now() - pg_stat_activity.query_start AS duration, query, state FROM pg_stat_activity WHERE state = 'active';
The output shows a high number of queries with a state of 'active' and durations exceeding several minutes. What should the administrator do FIRST to reduce CPU utilization?
Modify the max_connections parameter to limit concurrent sessions.
Scale up the DB instance to a larger instance class.
Use pg_terminate_backend to terminate the long-running queries.
Terminating the long-running active queries with pg_terminate_backend immediately frees CPU consumed by those sessions, providing the fastest relief. This is the first remedial action before investigating root causes such as missing indexes or inefficient query plans.
Enable pg_stat_statements to collect query performance data.
A company is using Amazon RDS for MySQL with a cross-Region read replica to support disaster recovery. The primary DB instance is in us-west-2, and the read replica is in us-east-1. The read replica is used for reporting and also serves as a failover target. The operations team notices that the read replica lag is consistently above 10 seconds during peak hours. What should the team do to reduce replica lag?
Increase the DB instance class of the read replica.
A larger instance class can process replication events faster.
Enable Multi-AZ on the primary DB instance.
Increase the backup retention period for the primary DB instance.
Disable binary logging (binlog) on the primary DB instance.
An IAM policy is attached to a user who needs to restore an Amazon RDS DB instance from a DB snapshot. The user attempts to restore and receives an 'Access Denied' error. Which missing permission is MOST likely causing the failure?
rds:DescribeDBSnapshots
rds:DescribeDBInstances
rds:CreateDBInstance
Restoring from snapshot creates a new DB instance, requiring CreateDBInstance.
rds:CreateDBSubnetGroup
A developer accidentally deleted a critical table from an Amazon RDS for MySQL DB instance. Automated backups are enabled with a retention period of 7 days. The deletion occurred 3 hours ago. What is the fastest way to restore the deleted table without affecting other tables?
Use the RDS Query Editor to run a flashback query that retrieves the deleted data.
Restore the DB instance from the latest manual snapshot and extract the table.
Restore the table from the automated backup using the AWS Management Console table-level restore feature.
Perform a point-in-time restore of the DB instance to a time just before the deletion, then export the table.
Point-in-time restore creates a new DB instance as it was at the specified time, allowing table extraction without affecting the original instance.
A company is migrating an on-premises Oracle database to Amazon RDS for Oracle. The database is 2 TB and has a high number of small transactions. The company needs to minimize downtime during the migration. Which TWO strategies should be used together? (Choose two.)
Use Oracle Data Pump to export the database and import into RDS.
Set up a VPN connection between on-premises and AWS for direct database link.
Create a manual snapshot of the RDS instance during the migration.
Use AWS Database Migration Service (DMS) to perform a full load and ongoing replication.
DMS can migrate data with minimal downtime by using continuous replication after the full load.
Configure change data capture (CDC) on the source database and apply to RDS.
DMS supports CDC to capture ongoing changes and apply them to the target, minimizing downtime.
A company is using Amazon ElastiCache for Redis to cache frequently accessed data from an RDS MySQL database. The cache hit ratio is currently 85%. The operations team notices that during traffic spikes, the cache eviction rate increases significantly, and the database CPU utilization spikes. The cache cluster uses a single r6g.large node. Which THREE actions should the team take to improve performance? (Choose three.)
Add more shards to the cluster to increase total memory.
More shards increase aggregate memory and distribute load.
Reduce the time-to-live (TTL) for cached items to free up memory faster.
Enable cluster mode to distribute data across multiple shards.
Cluster mode allows horizontal scaling, increasing total memory and reducing eviction pressure.
Increase the node type to a larger instance class, such as r6g.2xlarge.
A larger node provides more memory, reducing evictions.
Configure the cache to use lazy loading only for write-through operations.
Want more Management and Operations practice?
Practice this domain20% of exam · 6 sample questions below
A company is migrating an on-premises PostgreSQL database to Amazon RDS for PostgreSQL. The database is 2 TB in size and has a high write workload. The company needs to minimize downtime during the migration. Which AWS service or feature should the company use to achieve this?
Use pg_dump and pg_restore to export and import the database.
Use AWS Database Migration Service (AWS DMS) with ongoing replication.
AWS DMS with ongoing replication performs a full load then continuously applies change data capture from the source, keeping the target synchronised so the cutover window stays minimal despite the 2 TB size and high write workload.
Use the AWS Schema Conversion Tool (AWS SCT) to convert the schema and migrate data.
Use AWS DataSync to replicate the database files.
A company wants to migrate its on-premises Oracle database to Amazon Aurora PostgreSQL. The company needs to automatically convert the Oracle schema to PostgreSQL-compatible format. Which AWS service should the company use?
AWS Database Migration Service (AWS DMS) with the Oracle native dump and load option
AWS Server Migration Service (AWS SMS)
AWS Database Migration Service (AWS DMS)
AWS Schema Conversion Tool (AWS SCT)
AWS SCT performs automated schema conversion between heterogeneous engines, translating Oracle PL/SQL, data types and objects into Aurora PostgreSQL-compatible DDL. This directly satisfies the requirement to convert the Oracle schema automatically, rather than merely replicating data as DMS would.
A company is using AWS Database Migration Service (AWS DMS) to migrate a 5 TB MySQL database to Amazon RDS for MySQL. The migration is taking longer than expected. The company notices that the source database has a high volume of write operations. Which configuration change would MOST likely improve the migration performance?
Increase the number of parallel threads in the DMS task settings.
Parallel threads allow concurrent loading of data, improving throughput for high-write workloads.
Enable Multi-AZ on the target RDS instance.
Use a smaller instance class for the replication instance to reduce cost.
Set the LOB mode to 'Full LOB mode'.
A company needs to migrate a 100 GB MongoDB database to Amazon DocumentDB (with MongoDB compatibility). The migration must have minimal impact on the source database performance. Which approach should the company take?
Use AWS Database Migration Service (AWS DMS) with ongoing replication from the MongoDB source.
AWS DMS supports ongoing change data capture (CDC) from MongoDB oplog, enabling continuous replication with minimal read overhead on the source. This satisfies the stem’s constraint of minimal performance impact, as CDC reads only the oplog rather than scanning the entire 100 GB collection, avoiding sustained load on the production database.
Use AWS DataSync to transfer the MongoDB data files.
Set up a MongoDB replica set on Amazon EC2 and promote it to primary, then migrate to DocumentDB.
Use mongodump to export the data and mongorestore to import into DocumentDB.
A company is planning to migrate a 1 TB MySQL database from on-premises to Amazon RDS for MySQL. The migration must have minimal downtime and support ongoing replication. Which THREE steps should the company include in the migration plan? (Choose THREE.)
Set up an AWS Direct Connect or VPN connection between on-premises and AWS.
Network connectivity is required for DMS to access the source.
Deploy an Amazon EC2 instance to act as a proxy for the DMS replication.
Create the target Amazon RDS for MySQL instance.
The target database must be provisioned before migration.
Use AWS DMS with ongoing replication from the on-premises MySQL database.
Ongoing replication minimizes downtime by capturing changes.
Install the AWS Schema Conversion Tool on the source server to convert the schema.
A company is migrating a 500 GB on-premises PostgreSQL database to Amazon RDS for PostgreSQL. The migration must have minimal downtime and support ongoing replication after the initial load. Which AWS service should be used?
AWS Schema Conversion Tool (SCT)
AWS Database Migration Service (DMS) with full load only
AWS Database Migration Service (DMS) with ongoing replication
AWS DMS performs a full load then continuous change data capture from the PostgreSQL source's logical replication slots, keeping the target RDS instance synchronised until cutover. This satisfies the stem's minimal-downtime and ongoing-replication constraints, which a one-off snapshot restore or native pg_dump/pg_restore cannot provide.
AWS Glue
Want more Deployment and Migration practice?
Practice this domain26% of exam · 6 sample questions below
A company is designing a new e-commerce platform using Amazon DynamoDB. The workload requires single-digit millisecond latency for user session data, which is accessed by session token. The session data is temporary and should be automatically deleted after 24 hours. Which DynamoDB design should the database specialist recommend?
Create an AWS Lambda function that runs every hour and deletes expired session data
Store session data in Amazon S3 with a lifecycle policy to delete objects after 24 hours
Use DynamoDB Accelerator (DAX) to cache session data and set a 24-hour TTL on the cache
Enable DynamoDB Time to Live (TTL) on the session token attribute
DynamoDB TTL automatically deletes expired items at no write cost, satisfying the 24-hour automatic expiry constraint. Session lookups by token use the partition key for single-digit millisecond reads. TTL deletion is eventual, typically within 48 hours, but suits temporary session data.
A financial services company is migrating its Oracle database to Amazon Aurora PostgreSQL. The database runs a critical batch processing job every night that updates millions of rows. The company needs the migration to minimize downtime and ensure data integrity. Which AWS service should the database specialist use to perform the migration?
AWS Database Migration Service (AWS DMS) with ongoing replication from Oracle to Aurora PostgreSQL
AWS DMS performs full load plus change data capture, applying Oracle redo to Aurora PostgreSQL continuously. This satisfies the minimal-downtime constraint: the batch job keeps running on Oracle while replication catches up, then you cut over during a brief window, with transactional consistency preserved.
AWS Data Pipeline to export data from Oracle and import into Aurora PostgreSQL
AWS Schema Conversion Tool (AWS SCT) to convert the schema and then use native PostgreSQL tools to migrate data
AWS Glue to extract data from Oracle and load into Aurora PostgreSQL
A company is running a MySQL database on Amazon RDS and needs to store JSON documents that are frequently queried by fields within the JSON. The company wants to reduce development complexity and improve query performance. Which RDS MySQL feature should the database specialist recommend?
Migrate the JSON data to Amazon DynamoDB and use DynamoDB's document model
Use the JSON data type in MySQL 8.0 and utilize JSON path expressions in queries
MySQL 8.0's native JSON data type stores documents in an optimised binary format and supports JSON path expressions, enabling server-side filtering of nested fields without application parsing. This directly reduces development complexity and improves query performance versus storing JSON as plain text.
Store JSON documents in a VARCHAR(MAX) column and use LIKE operations for queries
Store JSON documents as BLOBs and parse them in application code
A company is designing a multi-tenant SaaS application on Amazon Aurora MySQL. Each tenant has its own database, but some tenants are very large and generate high write traffic. The company wants to isolate tenant workloads to prevent a noisy neighbor from affecting other tenants. Which TWO design strategies should the database specialist recommend?
Use Aurora Serverless for tenants with variable workloads
Aurora Serverless automatically scales compute capacity based on workload, minimizing impact on other tenants.
Use a single Aurora cluster with read replicas for each tenant
Migrate all tenants to Amazon DynamoDB and use DynamoDB Accelerator (DAX) for caching
Use Amazon RDS Proxy to pool connections and limit throughput per tenant
Use separate Aurora clusters for high-traffic tenants
Separate clusters provide complete resource isolation, preventing noisy neighbor issues.
A gaming company uses Amazon DynamoDB for player session data. Each session has a partition key of `game_id` and a sort key of `session_id`. The table has a global secondary index (GSI) on `player_id` for leaderboard queries. Recently, the company noticed that write traffic to the GSI is causing throttling on the base table, even though the base table's write capacity is not fully utilized. What is the MOST likely cause?
The application is using strongly consistent reads on the GSI, which consumes double the read capacity.
The GSI is not designed with a high-cardinality partition key, causing write hot spots on the GSI.
A hot GSI partition can throttle writes, affecting the base table writes.
Point-in-time recovery (PITR) is enabled, consuming extra write capacity.
The table's auto-scaling settings are not configured correctly for the GSI.
A company is migrating a MySQL database to Amazon Aurora MySQL. The current database uses multi-statement transactions with read committed isolation level. The application frequently encounters deadlocks on the source database. Which Aurora MySQL feature can help reduce deadlocks without application changes?
Use Amazon Aurora Auto Scaling to automatically adjust the number of replicas.
Use Amazon Aurora Global Database to replicate data to multiple regions.
Use Amazon RDS Proxy to pool and share database connections.
RDS Proxy reduces connection contention and can help reduce deadlocks.
Use Amazon Aurora Backtrack to quickly revert transactions.
Want more Workload-Specific Database Design practice?
Practice this domain18% of exam · 6 sample questions below
A company is using Amazon RDS for MySQL and notices that the Read IOPS metric is consistently high during business hours. The application is read-heavy. Which configuration change would most likely reduce Read IOPS?
Add a Multi-AZ standby instance.
Create one or more read replicas and redirect read traffic to them.
Read replicas offload read queries from the primary instance, so redirecting read-heavy traffic to them lowers Read IOPS on the primary. This directly addresses the consistently high Read IOPS metric during business hours without changing the application's write path.
Increase the DB instance size to a larger instance type.
Enable storage Auto Scaling on the RDS instance.
A developer reports that an application using Amazon DynamoDB is experiencing high latency during peak hours. The table has a provisioned capacity of 500 read capacity units (RCUs) and 500 write capacity units (WCUs). The application uses eventually consistent reads and the table is about 50 GB. The developer notices throttled write requests in CloudWatch. Which action would most effectively reduce write throttling?
Enable DynamoDB Accelerator (DAX) for the table.
Create a global secondary index on the table.
Increase the provisioned write capacity for the table.
Raising provisioned write capacity directly removes the throttling, since CloudWatch shows write requests exceeding the 500 WCUs ceiling during peaks. Provisioned mode caps throughput at the configured WCUs, so writes are rejected once consumed capacity saturates; adding WCUs lifts that ceiling. Partition count from the 50 GB table already supports higher throughput.
Switch from eventually consistent reads to strongly consistent reads.
A company is migrating an on-premises Oracle database to Amazon RDS for Oracle. During the migration, the database administrator notices that the CPU utilization on the RDS instance is consistently above 90% during peak hours, even though the on-premises server had similar specifications. The application queries are mostly SELECT statements with occasional DML. The RDS instance is db.r5.large with 500 GB of General Purpose SSD (gp2) storage. Which change would most likely reduce CPU utilization?
Create a read replica and redirect all SELECT queries to the replica.
Enable Multi-AZ to offload CPU to the standby instance.
Increase the allocated storage to 1 TB to improve I/O performance.
Upgrade to a larger instance type, such as db.r5.xlarge.
CPU saturation at peak with mostly SELECTs points to compute-bound query processing, not storage. Moving from db.r5.large to db.r5.xlarge doubles vCPUs and memory within the same burstable-free R5 family, directly relieving the processor bottleneck while preserving engine compatibility.
A team manages an Amazon Aurora MySQL database. They observe that the 'Deadlocks' metric in CloudWatch is spiking. The application uses a single writer instance and multiple read replicas. Which action is most effective at reducing deadlocks?
Increase the instance size to handle more concurrent connections.
Redirect read traffic to read replicas to reduce load on the writer.
Enable Multi-AZ to distribute the load.
Review application code to ensure transactions are as short as possible and access tables in a consistent order.
Deadlocks arise from conflicting lock acquisition orders and long-held locks, so shortening transactions and accessing tables consistently removes the circular-wait condition. This satisfies the stem's constraint by addressing the application-level cause rather than read replicas, which do not resolve writer deadlocks.
A database engineer is troubleshooting slow query performance on an Amazon RDS for PostgreSQL instance. The instance is db.r5.large with 500 GB of General Purpose SSD (gp2) storage. CloudWatch metrics show high Read Latency and high Read IOPS, but low CPU utilization. Which TWO actions should the engineer take to improve performance?
Create a read replica and offload read queries to it.
Read replicas reduce the read IOPS on the primary, which can lower latency on the primary.
Increase the DB instance class to a larger size, such as db.r5.2xlarge.
Enable Multi-AZ to use the standby for read traffic.
Optimize queries by adding appropriate indexes.
Switch from General Purpose SSD (gp2) to Provisioned IOPS SSD (io1) with a higher IOPS rate.
Provisioned IOPS provides consistent low latency for I/O-intensive workloads.
A company is using Amazon DynamoDB with autoscaling enabled. The table has a partition key of 'order_id' and a sort key of 'order_date'. The application performs both point queries and range queries. Recently, the 'ConsumedReadCapacityUnits' metric shows that the table is consistently using 100% of the provisioned capacity. Which THREE factors should the database engineer investigate to determine the cause?
Whether autoscaling is configured correctly to add capacity.
Whether the application is using Scan operations instead of Query operations.
Scans consume more read capacity than queries.
Whether the partition key is evenly distributed across partitions.
Uneven distribution leads to hot partitions and throttling.
Whether a specific 'order_id' is being accessed frequently, creating a hot key.
Hot keys can cause high consumption on a single partition.
Whether a global secondary index is being used for queries.
Want more Monitoring and Troubleshooting practice?
Practice this domainA company runs an Amazon RDS for MySQL DB instance in a VPC. Security requirements mandate that only specific EC2 instances in the same VPC can connect to the database. The security group attached to the RDS instance currently allows inbound traffic on port 3306 from 0.0.0.0/0. Which combination of steps should a database specialist take to meet the security requirement without impacting existing application connectivity? (Choose two.)
Modify the network ACL for the DB subnet to allow inbound port 3306 from the EC2 instance's private IP.
Remove the inbound rule for 0.0.0.0/0 on the RDS security group.
Removing the 0.0.0.0/0 rule eliminates the world-open ingress on port 3306, which the security requirement forbids. Because the security group reference rule already permits the specific EC2 instances, existing application connectivity continues unaffected once the overly permissive CIDR rule is deleted.
Add an inbound rule to the RDS security group referencing the security group ID of the EC2 instances.
Referencing the EC2 instances' security group ID as the source lets RDS accept traffic only from those instances, satisfying the mandate that only specific EC2 instances connect. It preserves existing connectivity because those instances already reach port 3306, and security group referencing avoids hard-coded private IP addresses.
Modify the DB subnet group to place the RDS instance in a public subnet with a route to the EC2 instance.
Add an inbound rule to the RDS security group allowing traffic from the VPC CIDR on port 3306.
A company uses Amazon ElastiCache for Redis to cache session data. The security team requires that all data in transit be encrypted. The Redis cluster currently does not have encryption in transit enabled. The database specialist needs to enable encryption in transit with minimal downtime. Which action should the specialist take?
Create a new Redis cluster with encryption in transit enabled, and migrate the data from the existing cluster.
Encryption in transit cannot be enabled on an existing ElastiCache for Redis cluster; it is set only at creation. Building a new cluster with encryption in transit enabled and migrating data is therefore the only viable path, meeting the minimal-downtime constraint.
Update the Redis parameter group to enable the 'encryption-in-transit' parameter and reboot the cluster.
Use a security group to enforce encrypted connections by allowing only TLS traffic.
Modify the existing Redis cluster to enable encryption in transit using the AWS CLI.
Enable encryption in transit on the existing cluster by using the AWS Management Console.
A company is designing a multi-tier application that uses Amazon RDS for PostgreSQL. The application must encrypt data at rest and in transit. Which combination of steps should be taken to meet these requirements? (Choose the single best answer.)
Use client-side encryption for data before sending to RDS, and enable encryption at rest after the instance is created.
Enable encryption at rest when launching the RDS instance, and configure the DB parameter group to require SSL connections.
Enabling encryption at launch encrypts the underlying storage, satisfying encryption at rest, since RDS cannot encrypt an existing unencrypted instance. Setting the parameter group to require SSL forces all client connections to use TLS, covering data in transit. Together these meet both stated requirements.
Launch the RDS instance without encryption, then enable encryption at rest using the AWS Console.
Use AWS KMS to encrypt the connection between the application and RDS.
A company is using Amazon RDS for MySQL with Multi-AZ deployment. The security team wants to ensure that database administrators cannot view sensitive data. Which TWO actions should be taken to achieve this goal?
Use IAM database authentication for application access.
IAM database authentication allows applications to connect without passwords, reducing the need for DBAs to handle credentials.
Enable audit logging to capture all data access.
Store database credentials in AWS Secrets Manager and enforce automatic rotation.
This prevents DBAs from knowing the credentials used by applications.
Enable encryption at rest using a customer-managed KMS key.
Disable query logging to prevent sensitive data from being written to logs.
Arrange the steps to restore an Amazon RDS for MySQL DB instance to a new instance from a manual snapshot in the correct order.
Select the manual snapshot from the list, then configure the new DB instance details, then initiate the restore, then wait for the restore to complete.
This ordering follows the required workflow: you must first select the snapshot, then specify the new instance settings, launch the restore, and finally wait for completion.
Configure the new DB instance details, then select the manual snapshot from the list, then initiate the restore, then wait for the restore to complete.
Select the manual snapshot from the list, then initiate the restore, then configure the new DB instance details, then wait for the restore to complete.
Wait for the restore to complete, then select the manual snapshot from the list, then configure the new DB instance details, then initiate the restore.
Match each AWS database migration tool/service to its function.
AWS DMS: Migrates databases to AWS with minimal downtime
AWS Database Migration Service (DMS) supports continuous replication and migration of databases to AWS with minimal downtime.
AWS SCT: Converts database schema to target engine
AWS Schema Conversion Tool (SCT) helps assess and convert database schema from one engine to another (e.g., Oracle to Aurora).
AWS Snowball: Physically transfers large data volumes to AWS
AWS Snowball is a physical device used to transfer large amounts of data to AWS when network transfer is impractical.
AWS DMS: Converts database schema to target engine
AWS Snowball: Migrates databases to AWS with minimal downtime
Want more Database Security practice?
Practice this domainThe DBS-C01 exam has 65 questions and must be completed in 180 minutes. The passing score is 750/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 5 domains: Management and Operations, Deployment and Migration, Workload-Specific Database Design, Monitoring and Troubleshooting, Database Security. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Amazon Web Services DBS-C01 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.