AWS · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A company is concerned about unauthorized access and potential data exfiltration within their AWS environment. They need a service that can continuously monitor VPC Flow Logs, AWS CloudTrail management events, and DNS logs to identify suspicious activities using machine learning. Which solution should the architect recommend for centralized threat detection?
Enable Amazon GuardDuty and integrate it with AWS Organizations for cross-account visibility.
Amazon GuardDuty continuously monitors for malicious activity and unauthorized behavior using machine learning and threat intelligence. It analyzes data sources like VPC Flow Logs and CloudTrail to identify anomalies. This managed service provides a comprehensive view of the security posture across multiple AWS accounts through integration with AWS Organizations.
Configure AWS Inspector to perform network reachability assessments on all EC2 instances.
Deploy AWS Shield Advanced to protect all public-facing endpoints from DDoS attacks.
Use AWS Config to monitor changes in security group rules and VPC configurations.
An enterprise requires all data stored in Amazon S3 to be encrypted at rest. The security team must maintain full control over the encryption keys, including the ability to rotate them annually and define access policies for the keys themselves. Which encryption method meets these requirements with the least operational overhead?
Use Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3) for all buckets.
Implement client-side encryption using a third-party library before uploading objects.
Use Server-Side Encryption with AWS KMS Customer Managed Keys (SSE-KMS).
Using SSE-KMS with a Customer Managed Key (CMK) allows the security team to define specific key policies and manage rotation schedules independently. This solution ensures that the security team retains ownership of the cryptographic material while providing the necessary encryption for objects stored within the S3 bucket.
Enable Server-Side Encryption with Customer-Provided Keys (SSE-C) for all uploads.
A security architect is designing a multi-tier application in a VPC. The requirement is to block all traffic from a specific range of malicious IP addresses (CIDR 192.0.2.0/24) while allowing standard web traffic (HTTPS) from all other sources to the web tier. Which TWO actions should the architect take to implement this? (Select TWO.)
Create an inbound rule in the Network ACL to deny traffic from 192.0.2.0/24.
Network ACLs act as a firewall for associated subnets and are stateless, meaning they require rules for both inbound and outbound traffic. They support explicit deny rules, which allow administrators to block specific malicious CIDR blocks from entering the network at the earliest possible entry point.
Add a deny rule to the web tier Security Group for CIDR 192.0.2.0/24.
Configure AWS Shield Standard to automatically block the 192.0.2.0/24 subnet.
Configure the web tier Security Group to allow inbound traffic on port 443 from 0.0.0.0/0.
Security Groups are used to define the permitted traffic for the application instances. By only allowing traffic from known legitimate sources or common web ports, they complement the Network ACL's ability to block malicious actors, providing a layered defense-in-depth approach to securing the VPC environment.
Update the VPC Route Table to blackhole all traffic destined for 192.0.2.0/24.
An application running on an Amazon EC2 instance needs to securely access data in an Amazon DynamoDB table. What is the most secure way to provide the application with the necessary permissions?
Store IAM user credentials in a configuration file on the EC2 instance.
Create an IAM role with the required permissions and attach it to the EC2 instance profile.
Attaching an IAM role to an EC2 instance allows the application to use temporary security credentials provided by the Instance Metadata Service. This eliminates the need to hardcode or store long-term keys, adhering to the principle of least privilege and significantly improving the overall security posture.
Pass the Access Key and Secret Key as environment variables when starting the application.
Embed the credentials directly into the application source code.
A large corporation uses AWS Organizations to manage hundreds of accounts. The security team wants to ensure that no account can provision resources in unauthorized regions and that only approved AWS services can be used. Which TWO features should be used to enforce these constraints across the entire organization? (Select TWO.)
IAM Policies attached to each administrative user in every member account.
Service Control Policies (SCPs) applied to the root of the Organization.
Service Control Policies (SCPs) can be applied at the organizational unit or account level to restrict the services and actions available to users. By using a Deny statement with a condition for specific regions, administrators can ensure that no resources are provisioned outside of authorized geographic areas.
AWS Resource Access Manager (RAM) to share authorized services across accounts.
AWS Config rules to automatically terminate resources in unauthorized regions.
SCPs with a Condition element to restrict the 'aws:RequestedRegion' key.
Using a Deny statement in an SCP combined with the 'aws:RequestedRegion' condition key effectively locks down accounts to approved locations. This ensures that even if a user has full administrative rights within their account, they are physically unable to launch resources in regions that are not explicitly permitted.
An enterprise organization is planning a centralized logging architecture across hundreds of AWS accounts using AWS CloudTrail and Amazon S3. Security mandates state that all log files delivered to the centralized S3 bucket must be cryptographically verified to ensure they have not been modified or tampered with after delivery. Which TWO actions must a Solutions Architect implement to achieve this mandate? (Choose two.)
Enable CloudTrail log file integrity validation on each trail.
CloudTrail log file integrity validation creates digital signatures of log files using SHA-256 for hashing and SHA-256 with RSA for digital signing. This allows you to verify that log files were not modified, deleted, or forged after delivery.
Configure S3 Object Lock in compliance mode on the centralized logging bucket.
Use AWS KMS customer managed keys with automatic key rotation enabled for S3 bucket encryption.
Enable Amazon S3 Versioning on the centralized logging bucket to preserve previous object iterations.
Verify the digital digests generated by CloudTrail using the AWS CLI or SDK commands.
Once log file integrity validation is enabled, CloudTrail delivers digest files containing hashes of the log files along with digital signatures. Security teams can use the AWS CLI to validate these digests against the delivered logs to prove integrity.
Want more Design Secure Architectures practice?
Practice this domainA solutions architect is designing a batch processing workload that runs for 4 hours every night. The workload can be interrupted and resumed without data loss. Cost optimization is a primary requirement for this deployment.
Use Amazon EC2 Reserved Instances to cover the nightly batch processing requirements over a one-year term.
Provision Amazon EC2 On-Demand Instances and terminate them manually through an AWS Lambda script after completion.
Configure an Auto Scaling group using Amazon EC2 Spot Instances with an appropriate instance diversification strategy.
Spot Instances bill at up to 90% below On-Demand rates and suit interruptible, resumable workloads. Diversifying across instance types and Availability Zones reduces the chance of simultaneous two-minute interruption notices, satisfying the cost-optimisation requirement while tolerating the nightly four-hour job being reclaimed.
Purchase Amazon EC2 Dedicated Hosts to run the nightly batch processing instances securely and predictably.
Refer to the exhibit. An S3 bucket contains millions of small log files. The requirements state that data must be moved to a cheaper storage class after 30 days. The exhibit shows a lifecycle policy. Why might this configuration be sub-optimal for cost?
Intelligent-Tiering is only supported for objects larger than 128 KB.
The lifecycle rule should use S3 Glacier Deep Archive instead of Intelligent-Tiering.
Monitoring fees for Intelligent-Tiering may outweigh savings for millions of small files.
S3 Intelligent-Tiering charges a small monthly monitoring and automation fee per object. When applied to millions of tiny log files, these fees aggregate significantly. If the access patterns are predictable, using a different storage class like S3 Standard-IA avoids these per-object monitoring costs, resulting in lower total expenditure.
The prefix filter is too broad and will include active logs.
A company is running a large-scale batch processing job that can be interrupted and resumed without loss of data. The job runs for several hours every weekend. Which instance purchasing option will provide the highest cost savings?
On-Demand Instances
Spot Instances
Spot Instances offer the deepest discounts in exchange for the possibility that AWS may reclaim the capacity with a two-minute notice. Since the application can resume progress after being stopped, the company can maximize savings by utilizing these instances during the weekend when spare capacity is often high.
Reserved Instances
Dedicated Hosts
A company is running an Amazon RDS for MySQL database that experiences predictable, steady traffic during business hours and very low traffic at night. They want to reduce costs without compromising performance. Which TWO steps should the architect take? (Select TWO.)
Purchase Reserved Instances for the RDS DB instances.
Reserved Instances are ideal for predictable, steady-state workloads because they offer up to 72% discount compared to On-Demand pricing. Since the company knows the database will be running during business hours for the foreseeable future, committing to a one-year or three-year term provides the most substantial baseline cost reduction.
Use Multi-AZ deployments for all read-only workloads.
Switch to an Amazon RDS Custom for MySQL instance.
Migrate the database to Amazon Aurora Serverless v2.
Aurora Serverless v2 scales database capacity in fine-grained increments to match application demand. This is highly cost-effective for workloads with variable traffic, such as the company's low nighttime usage, because it prevents over-provisioning during peak hours and reduces costs to a minimum when the database is mostly idle.
Enable Provisioned IOPS (PIOPS) for all storage volumes.
A company has several VPCs in a single region that need to access an S3 bucket for data processing. Currently, traffic goes through a NAT Gateway in each VPC. What is the most cost-effective way to provide access to S3?
Create an Interface VPC Endpoint for S3 in each VPC.
Set up a Gateway VPC Endpoint for S3 in each VPC.
Gateway Endpoints are a cost-free feature of VPCs that route traffic to S3 through the AWS private network. They do not incur hourly charges or data processing fees, unlike NAT Gateways. This makes them the most economical solution for any VPC-based workload that needs to communicate heavily with S3.
Deploy a single NAT Instance in a shared services VPC.
Use a Transit Gateway to route all S3 traffic through a central VPC.
Refer to the exhibit. An administrator runs a script to identify underutilized EC2 instances. The output shows a production instance that has been running for 30 days. Which action would most effectively reduce costs while maintaining application stability?
Change the instance type to a smaller size in the same family, such as m5.large.
The instance is significantly over-provisioned, as shown by the low peak CPU and memory metrics. Scaling down to a smaller instance type within the same family reduces the hourly cost linearly. This right-sizing approach ensures that the company is not paying for unused compute capacity while still meeting performance needs.
Convert the instance to a Spot Instance to save up to 90%.
Switch the instance to a T3 instance type with Unlimited mode enabled.
Purchase a Compute Savings Plan for the current m5.4xlarge instance.
Want more Design Cost-Optimized Architectures practice?
Practice this domainA financial services company is hosting a critical web application on Amazon EC2 instances behind an Application Load Balancer. The application must remain available even if an entire AWS Region experiences a major outage. The database tier uses Amazon Aurora Global Databases. Which solution provides the most resilient multi-Region architecture with automated failover?
Configure an Application Load Balancer in a single Region with EC2 instances distributed across multiple Availability Zones, and back the application with a standard Aurora MySQL database instance.
Use Amazon Route 53 with weighted routing policies to distribute traffic between two AWS Regions, and configure standard cross-region database replication using Amazon RDS snapshots taken every hour.
Deploy the application stack across two AWS Regions, use Amazon Route 53 with active-passive failover and automated health checks, and configure Amazon Aurora Global Databases with cross-region replication.
Route 53 active-passive routing with health checks automatically detects regional failures and redirects user traffic to the secondary Region. Aurora Global Databases provide low-latency cross-region replication and fast failover capabilities to ensure uninterrupted application availability.
Set up an AWS Global Accelerator standard accelerator with endpoint groups in two AWS Regions, and use Amazon DynamoDB global tables with local secondary indexes for data storage.
A media streaming company stores high-value video assets in an Amazon S3 bucket. The company requires a resilient storage architecture that protects against accidental deletion, malicious overwrites, and zonal or regional outages. Which combinations of features should a Solutions Architect implement to achieve these requirements? (Choose TWO.)
Enable S3 Versioning on the bucket and configure MFA Delete to prevent accidental or malicious deletion of object versions.
S3 Versioning preserves every version of every object, ensuring deleted or overwritten files can be easily restored. Multi-Factor Authentication Delete adds an extra layer of authorization security, requiring physical or virtual MFA tokens for permanent deletion operations.
Configure Amazon S3 Intelligent-Tiering to automatically move infrequently accessed video assets to lower-cost storage tiers.
Implement S3 Cross-Region Replication to asynchronously copy all video assets to an S3 bucket in a different AWS Region.
S3 Cross-Region Replication creates automated, low-latency asynchronous copies of data across geographically separated AWS Regions, ensuring high availability and business continuity in the event of a localized or widespread regional disaster affecting the primary bucket.
Attach a resource-based bucket policy that explicitly denies all delete object requests from any IAM user except the root account.
Enable S3 Object Lock in governance mode with a fixed retention period of 30 days for all uploaded video files.
A company hosts a web application on EC2 instances behind an Application Load Balancer. The application stores session state in local memory, causing users to be logged out whenever the load balancer routes requests to different instances. Which solution provides the most resilient, scalable architecture to resolve this?
Configure the Application Load Balancer to use source IP stickiness.
Use Amazon EBS multi-attach to share session files across instances.
Store session state in Amazon ElastiCache for Redis.
ElastiCache for Redis provides a high-performance, distributed, and managed key-value store that persists session data outside the web server memory. This ensures that session state remains available even when instances are replaced, enabling seamless horizontal scaling and maintaining high availability across multiple Availability Zones.
Replicate session files using a cron job across all web instances.
A company's web application requires a highly available database layer to survive an Availability Zone failure without manual intervention. The database must remain accessible during maintenance windows and ensure zero data loss. Which solution meets these requirements with the least operational overhead?
Configure RDS Read Replicas and manually promote them during an outage.
Deploy a Single-AZ RDS instance and use AWS Backup for hourly snapshots.
Implement an Amazon RDS Multi-AZ deployment.
Amazon RDS Multi-AZ uses synchronous replication to a standby instance in a different AZ, providing automatic failover and data redundancy. If the primary instance fails, AWS automatically updates the DNS record to point to the standby. This meets the high availability and zero-intervention requirements while handling maintenance windows with minimal impact on application uptime.
Host a MySQL database on an Amazon EC2 instance with an EBS volume.
An application is deployed across two AWS Regions to ensure resilience. The architect needs to direct users to the healthy region with the lowest latency. If the primary region fails, traffic should fail over automatically. Which Route 53 routing policy should be implemented?
Simple routing policy.
Latency routing policy with health checks.
Latency routing optimizes the user experience by serving requests from the AWS Region that provides the lowest network latency. When combined with health checks, it provides both performance optimization and high availability. Route 53 monitors the health of the endpoints and automatically skips any region that fails health checks during the routing decision.
Failover routing policy.
Weighted routing policy.
A high-traffic application uses an Application Load Balancer (ALB) and an Auto Scaling group (ASG). During peak hours, some EC2 instances fail, but the ASG does not replace them immediately because the instances are still in a 'running' state despite the application being unresponsive. How should the architect fix this?
Change the ASG health check type from EC2 to ELB.
The ELB health check type ensures that the Auto Scaling group considers an instance unhealthy if the Application Load Balancer determines the application is not responding correctly. This provides a more accurate view of application health than basic EC2 status checks, which only monitor the underlying hardware and network connectivity of the virtual machine.
Increase the ASG health check grace period to 600 seconds.
Create a CloudWatch alarm for high CPU usage to trigger replacement.
Configure a Lambda function to manually terminate unresponsive instances.
Want more Design Resilient Architectures practice?
Practice this domainA research firm is running a tightly coupled High Performance Computing (HPC) workload on AWS using EC2 instances. The firm needs to minimize network latency and maximize inter-node communication speed. Which network enhancement should the architect recommend?
Enable Enhanced Networking with the Elastic Network Adapter (ENA).
Deploy the instances using an Elastic Fabric Adapter (EFA).
Elastic Fabric Adapter provides OS-bypass capabilities, allowing HPC applications to communicate directly with the network interface hardware. This significantly reduces latency and jitter for Message Passing Interface (MPI) workloads, which is essential for tightly coupled clusters that need to share data rapidly between compute nodes.
Use a Spread Placement Group for the EC2 instances.
Implement AWS Global Accelerator for the cluster.
A media company experiences unpredictable traffic spikes on its web application. The architect needs to ensure the application remains responsive while optimizing for performance. Which TWO strategies should be implemented? (Select TWO.)
Configure a Target Tracking Scaling Policy for the Auto Scaling group.
Target tracking scaling policies allow the Auto Scaling group to maintain a specific metric value, such as average CPU utilization. This approach ensures the application scales out proactively to handle incoming traffic spikes while scaling in during low activity to maintain optimal performance and cost-efficiency.
Use a Simple Scaling Policy with a large cooldown period.
Deploy Amazon CloudFront in front of the Application Load Balancer.
Amazon CloudFront caches content at edge locations, which significantly reduces the latency for end-users and decreases the request load on the backend web servers. This allows the application to handle much higher traffic volumes without requiring a proportional increase in expensive EC2 compute resources.
Provision IOPS (io2) for all EC2 root volumes.
Implement vertical scaling by increasing instance sizes manually.
A global e-commerce site uses an Amazon RDS for MySQL database. Users in different regions are complaining about slow page load times when browsing product catalogs. How can the architect improve read performance for global users with minimal changes to the application?
Enable Multi-AZ deployment for the RDS instance.
Create Read Replicas in different AWS Regions.
Creating Read Replicas in regions geographically closer to the users allows the application to redirect read-heavy traffic, such as product catalog browsing, to local replicas. This reduces the round-trip time for database queries, significantly improving the overall responsiveness and performance of the e-commerce application.
Upgrade the RDS instance to a larger instance class.
Enable Enhanced Monitoring with a 1-second granularity.
Refer to the exhibit. An architect is reviewing a CloudFront Cache Policy for a dynamic site. The application is experiencing a low cache hit ratio, leading to high load on the origin servers. Based on the configuration, which change would most likely improve the cache hit ratio?
Change QueryStringBehavior to 'whitelist' or 'none'.
By changing the behavior to 'none' or 'whitelist' only specific parameters, CloudFront can ignore non-essential or unique query strings when generating cache keys. This allows multiple requests with different unimportant parameters to be served from the same cache entry, significantly increasing the cache hit ratio.
Increase the DefaultTTL and MinTTL values.
Set CookieBehavior to 'all' to include session data.
Enable HeaderBehavior for the 'Host' header.
A company has a high-performance database running on Amazon RDS for MySQL. The workload is read-heavy and experiences latency during peak hours. Which solution will improve read performance with minimal architectural changes?
Enable Multi-AZ deployment for the existing RDS instance.
Increase the instance size to a larger DB instance class.
Create one or more RDS Read Replicas and update the application connection string.
Read replicas enable asynchronous replication from the primary database, effectively offloading read traffic. By updating the application to direct read queries to these endpoints, you maximize database throughput. This approach is the most efficient way to scale read performance in RDS environments without complex refactoring.
Migrate the database to Amazon DynamoDB.
Refer to the exhibit. An application running on EC2 instances needs to pull large binary files from an S3 bucket with maximum throughput. Which configuration should the architect implement to ensure the highest network performance?
Attach an Internet Gateway to the VPC.
Configure an S3 Gateway VPC Endpoint in the VPC.
A Gateway VPC Endpoint allows private access to S3 without leaving the AWS network. This provides the highest possible throughput by routing traffic over the internal AWS backbone, minimizing latency and avoiding the limitations associated with NAT gateways or public internet routes, thus optimizing performance for data-intensive tasks.
Use a NAT Gateway for all outbound traffic.
Install an AWS Direct Connect connection.
Want more Design High-Performing Architectures practice?
Practice this domainThe SAA-C03 exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Architecture scenario questions on AWS service selection, resilience, cost optimisation, security, and networking trade-offs.
The exam covers 4 domains: Design Secure Architectures, Design Cost-Optimized Architectures, Design Resilient Architectures, Design High-Performing Architectures. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official AWS SAA-C03 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.