Amazon Web Services · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
29% of exam · 6 sample questions below
A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). They want to implement a blue/green deployment strategy with minimal impact on users. Which approach should they use?
Create a new target group with the green instances. Modify the ALB listener rule to forward traffic to the new target group.
Registering green instances in a new target group and repointing the ALB listener rule shifts traffic at the load balancer, giving instant cutover and rollback to blue. This achieves blue/green with minimal user impact, unlike DNS-based approaches with caching delays.
Stop all instances, launch new instances with the new version, and update the target group.
Update the existing target group's instances to the new version, one at a time.
Create a new ALB and update DNS to point to the new ALB.
A company is migrating a monolithic application to microservices on Amazon ECS with Fargate. The application has variable traffic patterns, with high traffic during business hours and low traffic at night. They want to optimize costs while maintaining performance. Which scaling strategy should they implement?
Use target tracking scaling with a schedule to increase minimum capacity during business hours.
Target tracking alone scales on demand but cannot anticipate the predictable daytime peak. Adding a schedule that raises minimum capacity during business hours pre-warms tasks, maintaining performance while target tracking scales down at night to optimise cost.
Use step scaling policies based on memory utilization.
Use scheduled scaling to increase capacity during business hours.
Use simple scaling policies based on CPU utilization.
A company is designing a new application that will process sensitive financial data. They need to ensure encryption at rest and in transit. Which of the following should they use? (Select TWO.)
TLS for all data in transit
TLS encrypts data in transit between clients and services, directly satisfying the in-transit encryption requirement for sensitive financial data. It protects against interception on the network, complementing at-rest encryption. Selecting TLS alongside a KMS-based at-rest control fulfils both stated constraints.
AWS Certificate Manager (ACM) for all encryption
SSL certificates for all connections
AWS Key Management Service (KMS) for encryption at rest
AWS KMS provides managed encryption keys for data at rest across AWS services, satisfying the at-rest encryption requirement for sensitive financial data. It integrates with services such as S3, EBS and DynamoDB, enabling envelope encryption and centralised key control. Paired with TLS, it covers both mandated encryption states.
AWS Identity and Access Management (IAM) for data encryption
A company is designing a new application on AWS that requires a relational database with read replicas across multiple AWS Regions. The database must have automated failover and a recovery point objective (RPO) of less than 5 seconds. Which database solution should the company choose?
Amazon Aurora Global Database
Aurora Global Database replicates at the storage layer with a typical cross-Region lag under one second, comfortably meeting the sub-5-second RPO. It also provides managed failover, promoting a secondary Region to primary in under a minute, satisfying the automated failover and multi-Region read replica requirements.
Amazon RDS for MySQL with Multi-AZ and cross-Region read replicas
Amazon RDS for PostgreSQL with cross-Region read replicas and Multi-AZ
Amazon DynamoDB Global Tables
A company is designing a new containerized application on Amazon EKS. The application must be able to access secrets (e.g., database credentials) securely. The company requires that secrets be automatically rotated and audited. Which THREE actions should the company take to meet these requirements?
Mount the Secrets Store CSI Driver volume directly to the pod without using ASCP
Use IAM roles for service accounts (IRSA) to grant pods access to Secrets Manager
IRSA maps a Kubernetes service account to an IAM role via the EKS OIDC provider, letting pods retrieve Secrets Manager values without long-lived credentials. This enables fine-grained IAM policies and CloudTrail auditing of each secret access.
Store secrets in AWS Secrets Manager and enable automatic rotation
Secrets Manager provides native automatic rotation via Lambda functions and CloudTrail auditing of secret access, directly satisfying the rotation and audit requirements. Storing credentials here rather than in Kubernetes Secrets or environment variables keeps them centralised and versioned.
Use the AWS Secrets and Configuration Provider (ASCP) for the Secrets Store CSI Driver to inject secrets into pods
ASCP mounts Secrets Manager secrets as files inside pods via the Secrets Store CSI Driver, so containers read credentials without hardcoding them. This satisfies secure access on EKS while preserving rotation, since the mounted values refresh from Secrets Manager.
Store secrets in Kubernetes Secrets and use a ConfigMap to reference them
A company is designing a new microservices architecture on AWS. Each microservice must be independently deployable and scalable. The company expects unpredictable traffic patterns with sudden spikes. Which combination of AWS services should be used to build a decoupled, resilient system?
Use Amazon API Gateway, AWS Lambda, Amazon SQS, Amazon DynamoDB, and Amazon CloudWatch.
API Gateway fronts requests, Lambda scales per-invocation for sudden spikes, SQS decouples producers from consumers, DynamoDB provides scalable persistence, and CloudWatch supplies observability. This combination delivers independent deployability and resilience, satisfying the decoupled architecture and unpredictable-traffic constraints.
Use Application Load Balancer, Amazon EC2 Auto Scaling, Amazon SQS, and Amazon RDS.
Use Amazon API Gateway, AWS Lambda, Amazon Kinesis Data Streams, and Amazon DynamoDB.
Use Application Load Balancer, Amazon ECS with Fargate, Amazon SQS, and Amazon RDS with read replicas.
Want more Design for New Solutions practice?
Practice this domain26% of exam · 6 sample questions below
A company has a centralized networking team that manages a shared VPC with multiple AWS Transit Gateway attachments. Application teams create VPCs in separate AWS accounts and want to connect to the shared VPC. The networking team needs to ensure that only authorized VPCs can connect to the shared VPC. What is the MOST secure and scalable way to manage this?
Use a VPN connection from each application VPC to the shared VPC.
Use AWS Resource Access Manager to share the Transit Gateway with the application accounts.
AWS Resource Access Manager shares the Transit Gateway with specific application accounts, so only those accounts can create attachments. This satisfies the requirement that only authorised VPCs connect, and scales without manual peering or per-VPC approval workflows.
Use VPC peering between the shared VPC and each application VPC.
Create IAM roles in each application account that allow the networking team to create VPC attachments.
A company uses AWS Control Tower to manage a multi-account environment. The security team needs to ensure that all accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket. What is the BEST way to achieve this?
Use an AWS Lambda function that runs periodically to enable CloudTrail in accounts where it is disabled.
Create an AWS Config rule in each account to enable CloudTrail if it is disabled.
Use an SCP to require CloudTrail to be enabled in each account.
Use the AWS CloudTrail setup provided by Control Tower, which automatically enables a trail for all accounts in the organization.
Control Tower's built-in CloudTrail configuration creates an organisation-wide trail delivering logs to the central S3 bucket it provisions, covering every account including future ones. This satisfies the requirement for CloudTrail across all accounts with centralised log delivery without custom automation.
Refer to the exhibit. A company runs the AWS CLI command to list accounts in AWS Organizations. The company wants to remove the account '444444444444' from the organization. What must the company do first before it can remove this account?
Close the AWS account from the management account.
Correct. Closing the AWS account from the management account is the prerequisite for removing a member account that was created within the organization.
Create a support ticket to AWS to remove the account.
Remove the account's payment method.
The management account can directly remove the account without any prerequisites.
A multinational corporation is migrating its on-premises Active Directory (AD) to AWS Managed Microsoft AD. The company has a hub-and-spoke VPC topology with a central transit gateway. The AD domain controllers must be deployed in two different AWS Regions for disaster recovery. The corporate security policy requires that all AD traffic between Regions must traverse the transit gateway and be inspected by a third-party firewall appliance deployed in the inspection VPC. Which architecture meets these requirements?
Deploy AD in two Regions and use a VPN connection between the VPCs to replicate data.
Deploy a single AD domain in one Region and use AD replication over a VPC peering connection to a second Region.
Deploy AD in two Regions, attach both VPCs to the transit gateway, and enable cross-Region transit gateway peering. Use route tables to direct AD traffic through the inspection VPC.
Cross-Region transit gateway peering carries AD replication traffic between the two Regional directories, while transit gateway route tables in each Region force that traffic through the inspection VPC attachment, satisfying the security policy's inspection mandate. AWS Managed Microsoft AD domain controllers stay Regional, so DR is met without exposing replication to the public internet.
Deploy AD in two Regions, attach both VPCs to a transit gateway in the primary Region, and use a transit gateway inter-Region peering attachment. Configure route tables to force traffic through the inspection VPC in the primary Region.
A company is using AWS Organizations with multiple organizational units (OUs). The security team needs to enforce that all newly created S3 buckets in the production OU have versioning enabled and are encrypted with AWS KMS. Which solution meets these requirements with minimal operational overhead?
Apply a service control policy (SCP) at the production OU level that denies s3:CreateBucket unless versioning and KMS encryption are specified in the request.
Use AWS CloudTrail to monitor bucket creation and send alerts to the security team.
Create an IAM policy that requires versioning and KMS encryption when creating buckets, and attach it to all users.
Use AWS Config rules to detect noncompliant buckets and auto-remediate with Lambda.
Correct. AWS Config evaluates bucket configurations and uses custom Lambda functions to auto-remediate, enabling versioning and KMS encryption for any noncompliant bucket. This provides automated enforcement with acceptable operational overhead.
A company uses AWS Organizations and has a requirement that all root user activities in member accounts must be immediately reported to the security team. Which combination of actions should be taken to meet this requirement? (Choose the best answer.)
Enable AWS CloudTrail and use Amazon Athena to query logs periodically and send a report.
Enable AWS CloudTrail in all accounts with a trail that logs management events and delivers to a centralized S3 bucket. Use Amazon CloudWatch Events to create a rule that matches root user API calls and sends notifications via Amazon SNS.
CloudTrail with management events captures root user API activity across all member accounts, satisfying the immediate reporting requirement. A CloudWatch Events rule matching those root calls then triggers Amazon SNS notifications, delivering real-time alerts to the security team without polling or delay.
Use AWS Config rules to detect root user activities and trigger an AWS Lambda function to send an email.
Use AWS Trusted Advisor to check for root user usage and generate a weekly report.
Want more Design Solutions for Organizational Complexity practice?
Practice this domain20% of exam · 6 sample questions below
A company wants to migrate a legacy monolithic application to AWS with minimal changes. The application currently runs on a single on-premises server with a Microsoft SQL Server database. The company wants to use AWS managed services to reduce operational overhead. Which combination of services should the company use to meet these requirements?
AWS Application Migration Service (MGN) to Amazon EC2, and AWS DMS to Amazon DynamoDB
AWS Application Migration Service (MGN) to Amazon EC2, and AWS DMS to Amazon RDS for SQL Server
MGN replicates the legacy server to Amazon EC2 with minimal application change, while AWS DMS migrates the SQL Server database to Amazon RDS for SQL Server, a managed service that reduces operational overhead and preserves engine compatibility.
AWS Server Migration Service (SMS) to Amazon EC2, and AWS DMS to Amazon RDS for SQL Server
AWS CloudFormation to provision EC2 instances, and AWS DMS to Amazon RDS for SQL Server
A company plans to modernize an existing .NET Framework 4.7 application running on Windows Server 2012 R2. The company wants to move to a containerized architecture on AWS with minimal code changes. Which service should the company use to meet these requirements?
AWS App2Container (A2C)
App2Container analyses running .NET Framework applications, containerises them and generates ECS or EKS deployment artefacts with minimal code changes. This directly satisfies the containerised AWS requirement while avoiding the re-architecture that replatforming tools or manual containerisation would demand.
AWS Serverless Application Model (SAM)
AWS Copilot
AWS Migration Hub
A company is migrating a 10 TB Oracle database to Amazon Aurora PostgreSQL. The database is business-critical and must have minimal downtime. The company has set up AWS DMS with ongoing replication from the source. During the migration, the company notices that DMS is failing with an error indicating insufficient memory. What should the company do to resolve this issue and complete the migration?
Increase the memory on the source Oracle database
Increase the instance class of the DMS replication instance
DMS memory exhaustion during ongoing replication is resolved by scaling the replication instance to a larger class, providing more RAM for change-data-capture buffers. This addresses the insufficient-memory error without restarting the migration or altering source data.
Change the DMS task to use change data capture (CDC) only and skip the full load
Split the migration into multiple smaller tasks
A company is migrating a multi-tier application to AWS and wants to modernize by using containers and serverless technologies. The application consists of a Node.js frontend, a Java backend, and a PostgreSQL database. The company wants to reduce operational overhead and improve scalability. Which TWO strategies should the company use? (Choose two.)
Refactor the Node.js frontend to run on AWS Lambda with Amazon API Gateway
Migrate the database to Amazon RDS for PostgreSQL
RDS reduces operational overhead compared to managing PostgreSQL on EC2.
Migrate the database to Amazon DynamoDB
Deploy the Java backend on Amazon ECS with AWS Fargate
Fargate eliminates server management for containers.
Deploy the Java backend on Amazon EC2 with Auto Scaling
A company is planning to modernize a legacy Java application that runs on a single on-premises server. The application uses a proprietary file-based storage system. The company wants to migrate to AWS with the following goals: reduce operational overhead, improve availability, and minimize code changes. Which TWO strategies should the company use? (Choose two.)
Use AWS Application Migration Service (MGN) to migrate the application server to Amazon EC2
AWS Application Migration Service replicates the on-premises server block-level and launches it on Amazon EC2, so the Java application runs without modification. This lifts operational overhead to AWS and enables multi-AZ resilience while minimising code changes.
Use Amazon EFS to replace the proprietary file-based storage
Amazon EFS provides a managed, multi-AZ NFS file system that the Java application can mount unchanged, replacing the proprietary file store. This removes server and storage operations overhead and improves availability while requiring no code changes.
Migrate the proprietary storage to Amazon S3
Migrate the proprietary storage to Amazon RDS for PostgreSQL
Refactor the application into microservices and deploy on Amazon EKS
A company is migrating a critical application to AWS and wants to ensure business continuity during the cutover. The migration plan includes a pilot light strategy. Which of the following BEST describes the pilot light pattern?
Take regular backups and restore them in AWS during cutover.
Run a scaled-down but fully functional version of the environment in AWS at all times.
Replicate data to AWS and run a minimal version of the application that can be scaled up during cutover.
Replicating data continuously and running only a minimal core of the application satisfies the pilot light requirement: a small always-on footprint that can be scaled up rapidly during cutover. This differs from warm standby, which runs a fully functional but scaled-down copy, and from backup-and-restore, which provisions nothing until disaster.
Run the application simultaneously in both environments and route traffic to both.
Want more Accelerate Workload Migration and Modernization practice?
Practice this domain25% of exam · 6 sample questions below
A company is running a web application on AWS using an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application experiences periodic traffic spikes that cause increased latency. The company wants to implement a solution to automatically adjust capacity in anticipation of traffic changes. What should a solutions architect do?
Configure a simple scaling policy based on CPU utilization.
Configure a scheduled scaling policy to add instances during known peak hours.
Configure a target tracking scaling policy based on average CPU utilization.
Configure a predictive scaling policy using historical traffic patterns.
Predictive scaling analyses historical CloudWatch traffic patterns and provisions capacity ahead of forecast demand, satisfying the anticipation requirement that reactive target tracking cannot meet. It scales out before the spike arrives, preventing the latency increase.
A company has a monolithic application running on a single Amazon RDS for MySQL DB instance. The application is experiencing performance issues due to heavy read traffic. The company wants to implement a solution that offloads read traffic with minimal application changes. What should a solutions architect do?
Create a read replica of the RDS instance and modify the application connection string to use the reader endpoint.
RDS read replicas replicate asynchronously from the primary, and the reader endpoint load-balances connections across all replicas. Pointing the connection string at this endpoint diverts SELECT queries without schema or code rewrites, satisfying the minimal-change constraint while relieving the primary's read pressure.
Migrate the application to use Amazon DynamoDB with global tables.
Use Amazon RDS Multi-AZ with a standby instance for read traffic.
Implement Amazon ElastiCache in front of the database to cache read queries.
A company runs a containerized application on Amazon ECS with Fargate. The application needs to securely access an Amazon S3 bucket. The company wants to follow the principle of least privilege. What should a solutions architect recommend?
Define an IAM task role with S3 access policies and reference it in the ECS task definition.
An IAM task role is assumed by the Fargate task itself, so containers receive temporary credentials scoped to the attached S3 policy. This avoids embedding long-lived keys and satisfies least privilege, since permissions are limited to the specific task rather than the host.
Attach an IAM role to the underlying EC2 instance.
Assign an IAM role to the ECS service using the ECS service-linked role.
Store AWS credentials in the container environment variables.
A company has an AWS Lambda function that processes messages from an Amazon SQS queue. The function is invoked with a batch size of 10. Some messages are failing repeatedly, causing the function to retry them up to the maximum retry count and then they are sent to a dead-letter queue (DLQ). The company wants to improve the resilience of the application by handling partial batch failures more efficiently. What should a solutions architect do?
Move the messages to a DLQ immediately after the first failure.
Implement reportBatchItemFailures in the Lambda function and enable partial batch response for the SQS event source mapping.
ReportBatchItemFailures lets the function return only the identifiers of failed messages, so Lambda deletes successful ones and retries just the failures. This avoids reprocessing the entire batch of ten, directly satisfying the requirement to handle partial batch failures efficiently and reduce duplicate DLQ entries.
Decrease the batch size to 1 so that each invocation processes a single message.
Increase the batch size to 100 to process more messages per invocation.
A company is running a stateful web application on EC2 instances in an Auto Scaling group behind an ALB. The application stores session data locally on the instance. The company notices that users are frequently logged out and lose session data during scaling events. What is the MOST operationally efficient way to preserve session state?
Migrate session data to ElastiCache for Redis and modify the application to use it.
ElastiCache for Redis externalises session state into a shared, highly available store, so any instance in the Auto Scaling group can serve any user after scaling events. This removes instance-local dependency without custom replication logic, making it the most operationally efficient fix.
Create a custom AMI that pre-populates session data from Amazon S3.
Increase the Auto Scaling group's cooldown period to 600 seconds.
Enable sticky sessions (session affinity) on the ALB.
A company uses AWS CloudFormation to deploy infrastructure. The operations team wants to automatically roll back a stack update if it fails, and receive a notification. What should be configured to meet these requirements?
Use AWS CloudTrail to monitor the UpdateStack API call and trigger a rollback via a Lambda function.
Use AWS Config rules to detect stack failure and revert changes.
Enable rollback on failure in the CloudFormation stack and configure an SNS notification topic.
CloudFormation's rollback-on-failure setting automatically reverts the stack to its last known stable state when an update fails, satisfying the automatic rollback requirement. Pairing it with an Amazon SNS topic delivers the failure notification. Both constraints in the stem are met natively, without custom scripting or external orchestration.
Create a custom resource in the CloudFormation template that performs rollback.
Want more Continuous Improvement for Existing Solutions practice?
Practice this domainThe SAP-C02 exam has 75 questions and must be completed in 170 minutes. The passing score is 750/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Design for New Solutions, Design Solutions for Organizational Complexity, Accelerate Workload Migration and Modernization, Continuous Improvement for Existing Solutions. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Amazon Web Services SAP-C02 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.