Amazon Web Services · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
20% of exam · 6 sample questions below
A company runs a production EC2 instance that experiences intermittent connectivity issues. The instance is part of an Auto Scaling group behind an Application Load Balancer. Which step should be taken FIRST to diagnose the issue?
Modify the security group to allow all traffic temporarily
Review CloudWatch metrics for the instance and the ALB target group
CloudWatch metrics for the instance and ALB target group reveal health-check failures, latency spikes, and connection errors, narrowing whether the fault lies in the instance or load balancer. This satisfies the stem's requirement to diagnose first, before changing configuration or restarting anything.
Terminate the instance and let Auto Scaling launch a new one
Attach an additional Elastic Network Interface (ENI) to the instance
A DevOps engineer needs to automatically restart a specific service on an EC2 instance whenever the service crashes. The instance is running Amazon Linux 2. Which approach is the MOST operationally efficient?
Set up a CloudWatch alarm that triggers an SSM Run Command to restart the service
Write a cron job that checks the service status every minute and restarts it if needed
Configure the service as a systemd unit with Restart=on-failure
A systemd unit with Restart=on-failure makes the init system supervise the process and relaunch it automatically after any non-zero exit, requiring no custom scripting. Cron polling or CloudWatch alarms with Lambda add latency and operational overhead compared with native service supervision.
Use an AWS Lambda function that polls the service status and calls the EC2 reboot API
A company uses AWS Config to record resource changes and evaluate rules. Recently, the compliance status of an S3 bucket rule changed from COMPLIANT to NON_COMPLIANT. The operations team investigates and finds that the bucket policy was modified. What is the MOST efficient way to identify who made the change and the exact time?
Examine the S3 server access logs for the bucket.
Search AWS CloudTrail event history for PutBucketPolicy events for the S3 bucket.
Searching CloudTrail event history for PutBucketPolicy events directly satisfies the requirement to identify the principal and timestamp of the bucket policy modification. CloudTrail records the API caller identity and event time for every management event, whereas AWS Config only reports the resulting compliance state change, not who caused it.
Review the configuration timeline in AWS Config for the S3 bucket.
Use AWS Systems Manager Automation to run a script that checks CloudWatch Logs.
A company wants to centralize monitoring of EC2 instance metrics across multiple AWS accounts. Which solution is MOST scalable and cost-effective?
Log in to each account and view CloudWatch metrics individually.
Use CloudWatch cross-region metrics to aggregate metrics in a single account.
Configure each account to publish metrics to an S3 bucket and use Athena to query.
Set up CloudWatch cross-account observability with a monitoring account.
CloudWatch cross-account observability links source accounts to a single monitoring account, letting one dashboard query metrics across all accounts without duplicating data or per-account tooling. This directly satisfies the centralised, scalable and cost-effective requirement, unlike per-account polling or exported metric streams.
A company uses AWS Lambda functions with reserved concurrency to process messages from an SQS queue. The operations team notices that the Lambda function sometimes throttles, causing messages to remain in the queue. What is the MOST likely cause and solution?
The SQS visibility timeout is too short; increase it.
The Lambda function's dead-letter queue (DLQ) is not configured; set up a DLQ.
The SQS queue's redrive policy is too aggressive; reduce the maxReceiveCount.
The reserved concurrency is set too low; increase the reserved concurrency for the function.
Reserved concurrency caps the function's simultaneous invocations; when set below the queue's arrival rate, Lambda throttles and messages accumulate. Raising the reserved concurrency value allows more parallel executions, draining the SQS queue and eliminating the throttling.
A company is designing a disaster recovery plan for a critical application running on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application uses an RDS Multi-AZ database. Which TWO actions should the operations team take to minimize recovery time and data loss?
Configure automated EBS snapshots for EC2 instances and copy them to a secondary region.
Snapshots can be used to restore volumes in another region.
Enable cross-region read replicas for the RDS database and promote to master if needed.
Cross-region replicas reduce RPO and RTO.
Create an AMI from a running instance and share it with the secondary region.
Use Route53 health checks to automatically failover traffic to a standby environment.
Want more Operations and Maintenance practice?
Practice this domainA company is migrating a legacy .NET application to AWS. The application uses Windows Authentication and relies on Active Directory for user authentication. The company wants to minimize changes to the application code. Which AWS service should be used to integrate Active Directory with the migrated application?
AWS Directory Service for Microsoft Active Directory
Provides full managed AD with native support for Windows Authentication.
Amazon Cognito
AD Connector
Simple AD
A company is migrating a web application from an on-premises data center to AWS. The application uses a MySQL database that is 500 GB in size. The company wants to minimize downtime during the migration. Which approach should the company use?
Use an RDS read replica and promote it
Use AWS Database Migration Service (DMS) with ongoing replication
AWS DMS with ongoing replication performs a full load then continuously applies change data capture from the source MySQL database, keeping the target in sync until cutover. This minimises downtime, satisfying the migration requirement for a 500 GB database.
Stop the database, take a mysqldump, and restore to RDS
Use AWS Schema Conversion Tool (SCT) to migrate the schema and data
A company is migrating a multi-tier application to AWS. The application includes a load balancer, web servers, and an Oracle database. The migration plan includes using AWS DMS for the database. During the initial full load, the DMS task fails with an error indicating insufficient memory. The source database is on an EC2 instance with 4 GB RAM. What should the migration team do to resolve this issue?
Disable LOB support in the DMS task
Split the migration into multiple smaller tasks
Increase the size of the DMS replication instance
AWS DMS performs the full load and transformation work on the replication instance, so insufficient memory there causes the failure. Increasing that instance's size provides the RAM needed, satisfying the stem's constraint without altering the 4 GB source EC2 database.
Increase the memory of the source EC2 instance
A company is migrating a 10 TB SQL Server database to Amazon RDS for SQL Server using AWS DMS. The migration is taking longer than expected. Which TWO actions can improve the migration speed? (Choose two.)
Use a single DMS task with full LOB mode
Enable parallel loading by splitting tables into multiple tasks
Parallel tasks utilize more resources and speed up data transfer.
Use S3 multipart upload for the data
Increase the DMS replication instance size
Larger instance provides more network, CPU, and memory throughput.
Disable transaction logging on the source
A company is migrating a legacy on-premises application to AWS. The application uses a proprietary database that is not supported by AWS Database Migration Service (DMS). The company needs to minimize downtime and automate the migration as much as possible. Which approach should be used?
Use AWS Database Migration Service (DMS) with a custom endpoint.
Use AWS Application Migration Service (MGN) to replicate the entire server, including the database, to AWS.
AWS Application Migration Service replicates servers at the block level, so the proprietary database migrates intact without DMS engine support. This satisfies the unsupported-database constraint while continuous replication keeps cutover downtime minimal, and the automated agent-based process removes manual export and import steps.
Export the database as a flat file, upload to Amazon S3, and import into Amazon RDS.
Use AWS Snowball to transfer database backups, then restore in Amazon RDS.
An organization is migrating a large data lake (500 TB) from on-premises HDFS to Amazon S3. The migration must be completed within 3 weeks. The network bandwidth between on-premises and AWS is 1 Gbps. What is the MOST efficient migration approach?
Use AWS DataSync over the existing internet connection.
Order a dedicated AWS Direct Connect circuit at 10 Gbps and use AWS DataSync.
Use Amazon S3 Transfer Acceleration to speed up the transfer over the internet.
Use multiple AWS Snowball Edge devices to transfer the data in parallel.
Snowball Edge provides high-capacity offline storage and multiple devices can be used concurrently, meeting the deadline.
Want more Migration practice?
Practice this domain30% of exam · 6 sample questions below
A company runs SAP Business Suite on an SAP HANA database on AWS. The database uses EBS gp2 volumes. The operations team notices high latency during peak hours. The metrics show that the volume queue depth is consistently above the recommended threshold. What is the MOST cost-effective change to reduce latency?
Migrate from gp2 to io2 EBS volumes with the same size.
Modify the volume to use Provisioned IOPS (io1) with a higher IOPS value.
Add an additional EBS volume and stripe the volumes using LVM.
Increase the size of the existing EBS gp2 volume to a larger size.
Larger gp2 volumes have higher baseline IOPS, reducing queue depth.
A company is designing a new SAP environment on AWS. The SAP application servers communicate with the database over the network. The architect wants to minimize latency and maximize throughput. Which placement strategy should the architect use?
Place all servers in a single Availability Zone and use a cluster placement group.
A cluster placement group packs instances onto the same underlying hardware within one Availability Zone, giving low-latency, high-throughput network paths between SAP application servers and the database. This directly satisfies the stem's latency and throughput constraints, which a spread placement group or multi-AZ layout would compromise.
Place the application servers in one Availability Zone and the database in a different Availability Zone.
Place the application servers in one VPC and the database in a different VPC connected via VPC peering.
Place the application servers in one AWS Region and the database in another Region.
A company is migrating its SAP NetWeaver system to AWS and wants to implement a high-availability architecture for the SAP Central Services (ASCS) and Enqueue Replication Server (ERS). Which TWO of the following are required components in a recommended AWS HA setup for ASCS and ERS?
A shared file system (e.g., Amazon EFS) to store the SAP transport directory and global profile.
ASCS and ERS require shared storage for transport directory.
An Application Load Balancer to distribute traffic between ASCS and ERS instances.
A floating IP address (using Elastic IP or Route 53 health checks) to manage the ASCS virtual hostname.
A virtual IP is required for ASCS failover.
A read replica of the SAP HANA database to offload application traffic.
A secondary Windows Server Failover Cluster in a different Availability Zone.
A company runs SAP S/4HANA on AWS with a large HANA database (10 TB). The database uses EBS gp3 volumes. The system experiences performance degradation due to high disk I/O. The architect decides to migrate to EBS io2 Block Express volumes. Which THREE factors should the architect consider when planning the migration?
The maximum IOPS per volume supported by io2 Block Express is 256,000.
High IOPS per volume is a key benefit for large HANA systems.
SAP HANA supports RAID 0 across multiple io2 volumes without additional software.
io2 Block Express volumes can be attached to multiple EC2 instances simultaneously using EBS Multi-Attach.
To achieve the required throughput, multiple io2 volumes should be striped using LVM.
Striping multiple volumes increases performance.
The cost of io2 Block Express volumes is higher than gp3 volumes on a per-GB basis.
Cost is a consideration when migrating to higher performance storage.
A company plans to migrate their SAP HANA database to AWS. They require the highest availability with automatic failover in case of an AZ failure. Which architecture should they use?
Multi-AZ with HANA System Replication in sync mode and automatic failover.
HANA System Replication in sync mode replicates every commit to the standby in a second AZ before acknowledgement, giving zero data loss, while automatic failover promotes the standby if the primary AZ fails. This satisfies the stem's demand for highest availability with automatic failover.
Single AZ with HANA System Replication to a standby in the same AZ.
Single AZ with daily backups to Amazon S3.
Multi-AZ with HANA System Replication in async mode and manual failover.
A company runs SAP Business Suite on AWS. They notice that their SAP application servers are not evenly distributing load across multiple instances. They have configured an Application Load Balancer (ALB) in front of the SAP Web Dispatchers. What is the MOST likely cause of uneven load distribution?
Sticky sessions (session stickiness) are enabled on the ALB.
Sticky sessions bind each client to a single target for the session's duration, so subsequent requests bypass load balancing and concentrate on one instance. Disabling stickiness lets the ALB distribute requests across all SAP Web Dispatchers, resolving the uneven distribution.
The ALB health check interval is too short.
Cross-zone load balancing is enabled.
The ALB is using the least outstanding requests routing algorithm.
Want more Design of SAP Workloads on AWS practice?
Practice this domainA solutions architect is designing a disaster recovery plan for a critical application that runs on Amazon RDS for PostgreSQL. The application requires a Recovery Point Objective (RPO) of less than 5 seconds and a Recovery Time Objective (RTO) of less than 1 minute. Which RDS deployment option meets these requirements?
A single-AZ deployment with cross-Region automated backups.
A single-AZ deployment with a standby instance manually promoted.
A Multi-AZ deployment with synchronous replication.
RDS Multi-AZ with synchronous replication commits each write to the standby before acknowledging, giving an RPO near zero, and failover completes automatically in roughly 60-120 seconds. This satisfies the sub-5-second RPO and sub-1-minute RTO constraints.
A Multi-AZ deployment with a Read Replica in a different Region.
Refer to the exhibit. An IAM policy is attached to an IAM role used by an EC2 instance. The EC2 instance has an Elastic IP address of 203.0.113.5 and is running in a VPC with CIDR 10.0.0.0/16. When the application on the instance tries to upload an object to the S3 bucket 'my-bucket', it receives an Access Denied error. What is the MOST likely cause?
The policy does not allow the s3:PutObject action.
The resource ARN is incorrect; it should be arn:aws:s3:::my-bucket without the asterisk.
The policy is missing a Deny statement for other IP addresses.
The condition checks the source IP address, but the EC2 instance uses a private IP address within the VPC when communicating with S3 via a VPC endpoint.
When using a VPC endpoint, the source IP is the private IP of the instance, which is within the allowed range, but the condition is evaluated against the public IP? Actually, the condition is on the source IP, which for traffic through a VPC endpoint is the private IP. The private IP (10.x.x.x) matches the condition. However, if the instance is communicating via the internet, the source IP would be the Elastic IP, which is not in the allowed range. But the error suggests the condition is blocking. The most likely cause is that the condition is checking the public IP, but the instance is using a VPC endpoint? Actually, the correct answer is D: the condition checks the source IP, but if using a VPC endpoint, the source IP is the private IP, which is within range, so it would work. The error occurs if the instance is communicating via the internet and the Elastic IP is not in the allowed range. Since the condition specifies 10.0.0.0/16, which is the VPC CIDR, it expects the private IP. If the instance uses a VPC endpoint, it works. If not, it fails. The exhibit does not specify a VPC endpoint, so likely the instance is using the internet, and the source IP is the Elastic IP, which is not in the allowed range. So answer D is correct because the condition is checking the source IP, but the instance's public IP is not in the allowed range. The explanation in the JSON is slightly off but the key idea is correct.
Refer to the exhibit. An Application Load Balancer is configured to route traffic to an Auto Scaling group of web servers. The health check for the target group is failing. The web servers are healthy and running, but the health check endpoint is returning a 503 status code because the application cannot connect to the database. The database is an Amazon RDS instance in the same VPC. Which action should the solutions architect take to resolve the health check failure?
Restart the web server instances to reset the database connection.
Change the health check endpoint to a static page that does not require database connectivity.
The 503 arises because the health check queries a database-dependent endpoint, so the target is marked unhealthy despite running servers. Pointing the health check at a static page removes that dependency, letting the load balancer verify instance liveness independently of RDS availability.
Modify the application's health check endpoint to return a 200 OK status even when the database is unavailable.
Increase the health check interval to allow more time for the database to respond.
A company is designing a multi-tier web application on AWS. The web tier must scale based on CPU utilization, and the application tier must scale based on request count. Both tiers are deployed in a VPC with public and private subnets. Which combination of AWS services should the company use?
Application Load Balancer for the web tier and Network Load Balancer for the application tier
This is a standard architecture: ALB handles HTTP/HTTPS traffic and can scale based on CPU; NLB handles TCP traffic and can scale based on request count.
Classic Load Balancer for both tiers
Network Load Balancer for the web tier and Application Load Balancer for the application tier
Amazon API Gateway for the web tier and Application Load Balancer for the application tier
A company is migrating a legacy monolithic application to a microservices architecture on AWS. The application currently uses an Oracle database with complex stored procedures. The company wants to minimize changes to the application code during migration. Which database migration strategy should the company use?
Migrate the database to Amazon Aurora with PostgreSQL compatibility using the AWS Database Migration Service (DMS)
Store the data in Amazon S3 and use Athena for querying
Refactor the application to use Amazon DynamoDB as the database
Replatform the application by migrating the Oracle database to Amazon RDS for Oracle
Migrating to Amazon RDS for Oracle preserves PL/SQL stored procedures and Oracle-specific syntax, so the application's database calls remain unchanged. This directly satisfies the stem's constraint of minimising code changes, since replatforming swaps the hosting layer while retaining the same database engine and schema objects.
A company runs a stateful web application on EC2 instances in an Auto Scaling group with a dynamic scaling policy based on CPU utilization. The application maintains session state in memory on each instance. Users report that they are frequently logged out and lose their session data during scaling events. What should the company do to resolve this issue?
Change the scaling policy to a simple scaling policy instead of dynamic scaling
Enable sticky sessions (session affinity) on the Application Load Balancer
Modify the application to store session state in an Amazon ElastiCache cluster
In-memory session state is tied to each EC2 instance, so scaling events and instance replacement discard it. Storing sessions in ElastiCache externalises state to a shared, highly available cluster, so any instance in the Auto Scaling group can serve any user, eliminating forced logouts during scaling.
Increase the cooldown period for the Auto Scaling group
Want more Technology practice?
Practice this domainThe PAS-C01 exam has 65 questions and must be completed in 170 minutes. The passing score is 750/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Operations and Maintenance, Migration, Design of SAP Workloads on AWS, Technology. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Amazon Web Services PAS-C01 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.