20+ practice questions focused on Continuous Improvement for Existing Solutions — one of the most tested topics on the AWS Certified Solutions Architect Professional SAP-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Continuous Improvement for Existing Solutions PracticeA company is using AWS CloudFormation to deploy infrastructure. The security team requires that all Amazon S3 buckets created by CloudFormation must be encrypted at rest. What should a solutions architect do to enforce this requirement?
Explanation: An S3 bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header enforces encryption at rest for all objects uploaded to the bucket. This policy condition works regardless of how the bucket is created, including via CloudFormation, and ensures that any PutObject operation without the required encryption header is rejected, meeting the security team's requirement.
A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all Amazon S3 buckets across the organization are encrypted at rest. Which TWO steps should the security team take to enforce this requirement?
Explanation: Option A is correct because an AWS Config rule (e.g., the managed rule s3-bucket-server-side-encryption-enabled) continuously evaluates S3 buckets across all accounts in the organization for default encryption and can trigger automatic remediation via SSM Automation documents, providing detective and corrective enforcement. Option B is correct because an SCP applied at the organization or OU level sets the maximum permissions for member accounts, and denying s3:PutObject unless the x-amz-server-side-encryption header is present forces every upload to be encrypted in transit to S3, giving preventive enforcement across the organization. Option C is not correct because GuardDuty is a threat-detection service that identifies suspicious activity and anomalous S3 access patterns, but it cannot enforce encryption at rest. Option D is not correct because an IAM role merely grants permissions; it does not require or enforce that buckets be encrypted, and assigning it to all users does not guarantee encryption. Option E is not correct because CloudTrail only records S3 API activity for auditing, not enforcement of encryption settings.
A company is running a critical application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application needs to process a large batch job that runs once per month and takes 2 hours. The company wants to optimize costs while ensuring the batch job has sufficient capacity. Which THREE steps should a solutions architect recommend?
Explanation: A scheduled scaling policy allows you to increase the desired capacity of the Auto Scaling group before the batch job starts, ensuring sufficient resources are available exactly when needed. This proactive approach avoids the latency of dynamic scaling and optimizes cost by not maintaining extra capacity outside the batch window.
A company runs a critical application on EC2 instances behind an Application Load Balancer (ALB) in a production AWS account. Recently, the application has experienced intermittent timeouts. The operations team notices that the CPU utilization of the instances spikes to 100% for a few minutes during the timeouts. The Auto Scaling group is configured with a target tracking scaling policy based on average CPU utilization at 70%. What should a solutions architect do to improve the application's availability and reduce timeouts?
Explanation: Adding a step scaling policy that triggers at 80% CPU for 1 minute provides a faster, more aggressive scale-out response than the existing target tracking policy alone. This helps preempt the CPU spikes that reach 100% and cause timeouts, improving application availability by adding capacity before performance degrades.
A company is running a containerized microservices application on Amazon ECS with Fargate launch type. The application experiences increased latency during peak hours. Upon investigation, the CPU utilization of the tasks reaches 90%. The ECS service is configured with a target tracking scaling policy based on average CPU at 70%. However, scaling is not keeping up with demand. What should a solutions architect do to improve the responsiveness of the scaling?
Explanation: Adding a step scaling policy provides a more aggressive and immediate scaling response when CPU exceeds 80% for 1 minute, which complements the existing target tracking policy. Target tracking scaling policies are reactive and may not scale quickly enough during rapid demand spikes, whereas step scaling can add a fixed number of tasks instantly when a breach occurs, reducing latency during peak hours.
+15 more Continuous Improvement for Existing Solutions questions available
Practice all Continuous Improvement for Existing Solutions questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Continuous Improvement for Existing Solutions. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Continuous Improvement for Existing Solutions questions on the SAP-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Continuous Improvement for Existing Solutions is tested as part of the AWS Certified Solutions Architect Professional SAP-C02 blueprint. Practicing with targeted Continuous Improvement for Existing Solutions questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SAP-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Continuous Improvement for Existing Solutions is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Continuous Improvement for Existing Solutions practice session with instant scoring and detailed explanations.
Start Continuous Improvement for Existing Solutions Practice →