Courseiva

SAP-C02 · domain

Continuous Improvement for Existing Solutions

Domain 4 of SAP-C02 covers reviewing deployed workloads and making them better: cost, performance, reliability, and operational excellence. Questions present an existing architecture with a symptom or goal, then ask which AWS service, configuration change, or redesign fixes it. Expect DynamoDB key redesign, Auto Scaling policies, network diagnostics, and DR strategy trade-offs.

228 questions52 easy114 medium62 hard

Focused practice

Practice Continuous Improvement for Existing Solutions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Continuous Improvement for Existing Solutions

Given an existing workload, identify the bottleneck or risk, then pick the AWS service or configuration change that resolves it at acceptable cost. The single most important skill is mapping a stated symptom, such as throttling or slow failover, to the specific AWS feature that addresses it.

Diagnosing EC2 network paths with VPC Flow Logs and AWS Network Manager / Reachability Analyzer

Redesigning DynamoDB partition keys and using adaptive capacity or on-demand to fix hot partitions

Choosing Auto Scaling target tracking, step, or scheduled policies driven by custom CloudWatch metrics

Selecting DR strategies (backup/restore, pilot light, warm standby, multi-site) per RTO and RPO

Watch out for

Common Continuous Improvement for Existing Solutions exam traps

  • ▸Assuming DynamoDB hot partitions are fixed only by adding read/write capacity instead of changing the partition key design.
  • ▸Picking CloudWatch basic monitoring when detailed monitoring or custom metrics are required for fine-grained Auto Scaling.
  • ▸Treating multi-site active-active as always correct for DR, ignoring cost and the stated RTO/RPO requirements.

Question index

All Continuous Improvement for Existing Solutions questions (228)

Click any question to see the full explanation, or start a practice session above.

1

A company uses AWS CodePipeline to deploy a web application to an Elastic Beanstalk environment. The deployment pipeline includes a source stage, a build stage using CodeBuild, and a deploy stage. Recently, deployments have been failing in the deploy stage with the error: 'The environment is in an invalid state for this operation.' The developer confirms the build artifacts are correct. What is the MOST likely cause?

Medium
2

A company is using AWS Lambda functions to process data from an S3 bucket. Recently, the function has been timing out. The function has a 5-minute timeout configured. What is the most likely cause of the timeout?

Medium
3

A DevOps engineer notices that a CloudFormation stack update fails with the error: 'UPDATE_ROLLBACK_FAILED'. The stack is in a state where some resources were updated, but others failed to update. The engineer needs to fix the stack and complete the update. What should the engineer do FIRST?

Easy
4

Refer to the exhibit. A solutions architect runs the AWS CLI command to check the state of an EC2 instance. The output shows the instance is running. However, the application team reports that the instance is unreachable over SSH. What is the MOST likely cause?

Medium
5

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The application experiences periodic spikes in traffic. The operations team wants to ensure that the application can handle the spikes without manual intervention. What is the MOST cost-effective solution?

Easy
6

Drag and drop the steps to deploy a serverless application using AWS SAM in the correct order.

Medium
7

A company is using AWS CodePipeline to automate deployments of a web application. The pipeline includes a build stage using AWS CodeBuild and a deploy stage using AWS CodeDeploy to an Auto Scaling group. Recently, deployments have been failing during the deploy stage with an error indicating that the target instances are not in a healthy state. The CodeDeploy agent logs show that the agent is running but the application validation scripts are failing. Which THREE actions should the solutions architect take to troubleshoot and resolve the issue?

Hard
8

A company runs a critical Java application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in local instance memory, and the Auto Scaling group is configured to terminate instances when CPU utilization drops below 20%. During a recent scaling event, users were unexpectedly logged out and lost shopping cart contents. A solutions architect needs to make the application stateless so that instances can be terminated without impacting users, while minimizing changes to the application code. Which solution meets these requirements?

Medium
9

A company runs a critical web application on EC2 instances behind an Application Load Balancer (ALB). During a recent deployment, users experienced errors. The team wants to automatically roll back the deployment if the error rate exceeds 5% within 10 minutes after deployment. Which solution meets these requirements with minimal operational overhead?

Hard
10

A company has a legacy application that runs on a single EC2 instance. The application writes logs to a local file. The company wants to centralize log management without modifying the application code. Which solution is MOST operationally efficient?

Hard
11

A company runs a batch processing application on a scheduled EC2 instance that starts every night. The instance processes a large number of files from an S3 bucket and writes results to another S3 bucket. The job takes approximately 6 hours to complete. Recently, the job has been failing after 4 hours with an error indicating that the instance's EBS root volume is full. The instance type is t3.medium with a 20 GB gp2 root volume. The application writes temporary files to the root volume. The company wants to fix this with minimal changes to the application and infrastructure. What should a solutions architect recommend?

Medium
12

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores session state in a local file on each instance. Users report that they are randomly logged out when the ALB routes their requests to a different instance. The company wants to improve the user experience and ensure that sessions persist across multiple instances. The company wants a solution that requires minimal changes to the application code. Which solution meets these requirements?

Medium
13

A company's security team wants to ensure that all S3 buckets are encrypted at rest. They have thousands of existing buckets. Which approach should a Solutions Architect use to identify noncompliant buckets?

Easy
14

A company wants to monitor CPU utilization of their EC2 instances and receive an alert when utilization exceeds 80% for 10 minutes. Which AWS service should be used?

Easy
15

A company uses Amazon DynamoDB as its primary database. The operations team is seeing increased read latency during peak hours. The table has a provisioned read capacity of 1000 RCU, but CloudWatch metrics show that consumed read capacity frequently reaches 1000 RCU. The application uses eventually consistent reads. What is the MOST cost-effective way to reduce read latency?

Medium
16

A company is running a production web application on AWS Auto Scaling EC2 instances behind an Application Load Balancer. Recent deployments have caused intermittent errors. The team wants to implement a deployment strategy that minimizes downtime and allows for quick rollback. Which strategy should they use?

Medium
17

A company uses AWS CloudFormation to manage infrastructure. They want to detect drift from the intended template configuration. Which service should they use?

Easy
18

A company runs a batch processing application on AWS. The application reads input files from an S3 bucket, processes them on EC2 instances, and writes results to another S3 bucket. The processing job runs once a day and takes approximately 3 hours. The company wants to reduce costs and operational overhead. The Solutions Architect suggests using AWS Lambda for processing, but the processing time per file can exceed the Lambda maximum execution time of 15 minutes. The architect also considers using AWS Batch. The company wants to minimize the need for infrastructure management. Which solution should the Solutions Architect recommend?

Medium
19

A company uses AWS CodePipeline to deploy a web application. They want to automatically roll back the deployment if the new version fails CloudWatch alarm-based health checks. Which feature should they use?

Easy
20

A company runs a multi-account AWS environment managed with AWS Organizations. Each account sends VPC Flow Logs, AWS CloudTrail logs, and application logs to a central Amazon S3 bucket in the logging account. The security team needs to query up to 5 years of logs with ad-hoc SQL, correlate events across accounts, and minimize ongoing storage cost for logs older than 90 days. The logs must remain immediately queryable without restoration. Which solution meets these requirements MOST cost-effectively?

Hard
21

A company has a serverless application that uses AWS Lambda functions. The functions are invoked by Amazon API Gateway and write to an Amazon DynamoDB table. The company wants to improve the existing solution to reduce latency for read-heavy workloads and reduce DynamoDB costs. The application reads the same items repeatedly. Which solution meets these requirements with the LEAST development effort?

Medium
22

A company has a monolithic application running on a single EC2 instance. The application experiences performance issues during peak hours. The company decides to migrate to a microservices architecture using AWS Lambda and Amazon API Gateway. The migration must be done incrementally without downtime. What strategy should the company use?

Hard
23

A company operates a microservices platform on Amazon EKS. During incidents, engineers manually inspect CloudWatch metrics, logs, and traces to find the root cause, which takes hours. The company wants to reduce mean time to resolution by automating anomaly detection and correlating metrics, logs, and traces across services. Which approach should a solutions architect recommend?

Hard
24

A company is using Amazon DynamoDB as the primary database for a web application. The application experiences occasional throttling on writes. The company wants to implement a solution that automatically increases write capacity during traffic spikes. Which solution should they use?

Easy
25

A company is deploying a new three-tier application on AWS. The application consists of a web tier, an application tier, and a database tier. The company wants to ensure that the application can withstand the failure of a single Availability Zone and that the database tier can fail over automatically. The company also wants to minimize operational overhead. Which two solutions should a solutions architect recommend? (Choose two.)

Medium
26

An e-commerce company runs its application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses an Amazon Aurora MySQL DB cluster with one writer and two reader instances. During a sales event, the database CPU utilization is high, and read replicas show high replica lag. The company needs to improve the read scalability and reduce replica lag. Which THREE actions should the company take? (Choose THREE.)

Medium
27

A solutions architect deployed the above CloudFormation template. However, the Lambda function is not triggered when objects are uploaded to the S3 bucket. What is the most likely cause?

Medium
28

A company uses Amazon S3 to store critical data. They need to ensure that data is automatically replicated to another AWS Region for disaster recovery. Which configuration meets this requirement with minimal operational overhead?

Medium
29

A company has a multi-account AWS organization with hundreds of accounts. The security team wants to ensure that all accounts have AWS Config enabled with a specific set of rules. They also want to automatically remediate non-compliant resources. Which solution is MOST scalable and operationally efficient?

Hard
30

A company runs a stateless web application on EC2 instances in an Auto Scaling group. The application is deployed across multiple Availability Zones. The team notices that during a recent traffic spike, some instances were terminated and replaced, causing a temporary drop in performance. How can the team improve the resilience of the application?

Medium
31

A company runs a critical application on Amazon EC2 instances in an Auto Scaling group. The application writes logs to ephemeral instance storage. The operations team needs to retain these logs for 90 days for compliance and wants to search them using a central service. The logs are currently lost when instances are terminated. Which solution meets these requirements with the LEAST operational overhead?

Medium
32

A company runs a microservices application on Amazon ECS with the Fargate launch type. The services communicate over HTTP and are deployed across multiple Availability Zones. The company wants to improve the application's resilience by implementing automatic retries and circuit breaking for inter-service communication. The services are registered in AWS Cloud Map. Which solution should a solutions architect recommend to meet these requirements with the LEAST operational overhead?

Medium
33

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application stores user-uploaded files in an Amazon S3 bucket. The company wants to improve the security of the application by ensuring that the EC2 instances can access the S3 bucket without embedding long-term AWS credentials in the application code or on the instances. Which solution meets these requirements with the LEAST operational overhead?

Easy
34

A company uses Amazon S3 to store sensitive data. The security team requires that all objects be encrypted at rest. The company currently uses server-side encryption with S3-managed keys (SSE-S3). The security team wants to ensure that only authorized users can access the decryption keys. What should the company do?

Easy
35

A social media startup uses AWS Lambda functions to process user-uploaded images. The Lambda function resizes images and stores them in Amazon S3. The function uses the S3 SDK to put objects. Recently, the team noticed that the function sometimes fails with 'Timeout' errors for large images. The Lambda function has a timeout of 5 seconds and 256 MB of memory. The team wants to improve the solution to handle larger images reliably and cost-effectively. Which solution should the team implement?

Medium
36

A company runs a two-tier web application on Amazon EC2 instances behind an Application Load Balancer. The database tier is Amazon RDS for MySQL with a single Availability Zone deployment. The company requires a recovery point objective (RPO) of 5 minutes and a recovery time objective (RTO) of 2 hours. The database is 500 GB. Which solution should a solutions architect recommend to meet these requirements MOST cost-effectively?

Medium
37

A company is using Amazon S3 to store sensitive data. The security team wants to ensure that all objects uploaded to specific S3 buckets are encrypted at rest. Which TWO actions should they take? (Choose 2)

Medium
38

A company is using Amazon ECS with Fargate launch type for a microservices application. The application experiences intermittent latency spikes. CloudWatch metrics show high CPU utilization but no obvious pattern. What should the company do to identify the cause?

Easy
39

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in a self-managed Redis cluster on a single EC2 instance. During a recent load test, the Redis instance became a bottleneck, causing session timeouts and degraded performance. The company wants to improve the scalability and availability of the session store while minimizing application changes. Which solution meets these requirements?

Medium
40

A company is running a web application on EC2 instances in an Auto Scaling group behind an ALB. The application uses an Amazon RDS for MySQL database. Recently, the application has become slow, and the operations team identifies that the database is the bottleneck due to a high number of read queries. Which TWO actions should a solutions architect take to improve read performance? (Choose two.)

Medium
41

A company runs a static website on Amazon S3 with a custom domain using Amazon Route 53. The website content is updated frequently by multiple developers. The company wants to implement a workflow where updates are automatically tested and deployed. They have existing CI/CD tools that integrate with AWS CodeCommit. The Solutions Architect needs to design a deployment pipeline that rebuilds the website only when changes are pushed to the main branch, and then invalidates the Amazon CloudFront cache if a CloudFront distribution is used. Which solution meets these requirements with the least operational overhead?

Easy
42

A company has an S3 bucket that stores sensitive data. The company wants to ensure that all objects uploaded to the bucket are encrypted at rest. Which solution should the solutions architect recommend?

Easy
43

A company is using AWS CloudFormation to manage infrastructure. They want to ensure that any changes to a production stack are reviewed and approved before being applied. What is the BEST way to achieve this?

Easy
44

A company runs a batch processing workload on Amazon EC2 Spot Instances managed by an Auto Scaling group. The workload checkpoints progress to Amazon S3 every 10 minutes. Spot Instances are frequently interrupted, causing the workload to restart from the last checkpoint. The team wants to reduce the impact of interruptions and improve job completion time. Which solution should a solutions architect recommend?

Medium
45

A company is using AWS CloudFormation to manage infrastructure. The stack creation fails with the error 'Resource handler returned message: 'User: arn:aws:sts::123456789012:assumed-role/Admin/MySession is not authorized to perform: ec2:RunInstances'. What is the MOST likely cause?

Easy
46

A company has a CI/CD pipeline that builds and deploys a containerized application to Amazon ECS Fargate. The pipeline uses AWS CodeBuild to run tests and build Docker images. Recently, the pipeline has been failing intermittently with the error 'CannotPullContainerError: Error response from daemon: manifest for <image> not found'. The image is stored in Amazon ECR. The team suspects the issue is related to image tag inconsistency. The pipeline tags images with the commit hash. Which change will prevent this error?

Medium
47

A company runs a critical application on EC2 instances behind an Application Load Balancer. The security team requires that all traffic to the application be encrypted in transit and that the load balancer use a certificate from AWS Certificate Manager (ACM). The application currently uses HTTP. What should the company do to meet the security requirement?

Medium
48

A company runs a containerized application on Amazon ECS with Fargate launch type. The application is deployed across multiple Availability Zones. Recently, deployments have been failing because new tasks cannot register with the Application Load Balancer (ALB) target group. The health checks are failing. What is the MOST likely cause?

Hard
49

A startup runs its application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer to distribute traffic. During a recent marketing campaign, the application experienced high latency and some requests returned 503 errors. The team suspects that the tasks are hitting resource limits. The team wants to automatically scale the tasks based on CPU utilization. Which solution should the team implement?

Easy
50

A CloudFormation stack is created using the template above. The stack creation fails with the error: 'The following resource(s) failed to create: [EC2Instance]'. Logs show: 'AMI 'ami-0abcdef1234567890' does not exist.' What is the most likely cause?

Medium
51

A company has a data pipeline that uses AWS Glue to process large datasets in Amazon S3. The pipeline runs daily and takes over 12 hours to complete. The company wants to reduce the processing time. Which approach would be MOST effective?

Hard
52

A company uses AWS CloudFormation to manage its infrastructure. The operations team reports that stack updates often fail because of resource conflicts. The team wants to improve the reliability of updates without manual intervention. Which solution provides the MOST automated recovery from update failures?

Easy
53

A solutions architect is optimizing a data processing workload that runs on AWS Lambda. The function processes large JSON files stored in Amazon S3, performs CPU-intensive transformations, and writes results to Amazon DynamoDB. The function currently has 512 MB of memory and takes about 10 minutes to process each file, occasionally timing out. The architect needs to reduce processing time and avoid timeouts. Which action is MOST effective?

Hard
54

A company uses AWS CloudTrail to log all API calls. The security team wants to be alerted when an IAM user creates a new access key. What is the MOST efficient way to achieve this?

Medium
55

A company uses AWS CloudFormation to manage infrastructure. The stack fails to update with the error: 'Resource handler returned message: The subnet 'subnet-xxx' is in use by a network interface.' The subnet is associated with a Lambda function in a VPC. The CloudFormation template is trying to delete the subnet. What should the company do to resolve this?

Hard
56

A company uses AWS CloudFormation to manage infrastructure. The operations team wants to implement a change management process where all stack updates must be reviewed and approved before execution. The team currently uses AWS CodePipeline for CI/CD. Which solution meets these requirements with the LEAST operational overhead?

Medium
57

Refer to the exhibit. $ aws ec2 describe-instances --region us-east-1 --filters Name=tag:Name,Values=WebServer --query 'Reservations[].Instances[].{ID:InstanceId,State:State.Name,Type:InstanceType,LaunchTime:LaunchTime}' --output table A DevOps engineer runs the above command. The Auto Scaling group for WebServer instances has a desired count of 3, but the engineer notices that there are 5 instances with the same tag. What is the MOST likely cause?

Medium
58

A company has a serverless application using AWS Lambda, API Gateway, and DynamoDB. During a traffic spike, some API requests fail with 5xx errors. The CloudWatch logs show 'ProvisionedThroughputExceededException' for DynamoDB. The team wants to handle this gracefully without losing requests. What should they do?

Hard
59

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local instance storage. The operations team wants to centralize log analysis and enable real-time alerting on specific error patterns. The solution must be highly available and require minimal changes to the application. Which approach should a solutions architect recommend?

Medium
60

A company is running a critical microservices application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer (ALB) to distribute traffic. Recently, the team noticed that the ALB's 5xx error rate has increased. The error is HTTP 503. The team suspects the target group is unhealthy. Which THREE steps should the team take to diagnose and resolve the issue?

Hard
61

Refer to the exhibit. A CloudFormation stack was successfully created. The stack's template includes an S3 bucket and a Lambda function. A developer runs the CLI command shown but receives an error that the stack does not exist. What is the MOST likely cause?

Hard
62

A company runs a containerized application on Amazon ECS with Fargate. The application needs to access an Amazon S3 bucket that contains sensitive data. The security team requires that all traffic between the ECS tasks and S3 remain within the AWS network and not traverse the internet. What is the MOST secure way to meet this requirement?

Medium
63

A company runs a critical application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application experiences intermittent high latency due to CPU spikes on some instances. The company wants to automatically replace unhealthy instances and optimize costs. What should a solutions architect do?

Medium
64

A company runs a static website on Amazon S3 behind Amazon CloudFront. The website uses a custom domain and SSL certificate from AWS Certificate Manager (ACM). Users report that they sometimes see an older version of the website after updates. What should the company do to ensure users always see the latest content?

Easy
65

A company uses Amazon RDS for MySQL for its database. The operations team notices that read queries are slow during peak hours. The application is read-heavy and can tolerate eventual consistency. Which solution would improve read performance with minimal application changes?

Easy
66

A company runs a critical application on Amazon EC2 instances in a single AWS Region. The application uses an Amazon RDS for MySQL database with a read replica in another Availability Zone. The company wants to improve the disaster recovery posture to meet an RPO of 5 minutes and an RTO of 15 minutes in case of a regional failure. The application must be able to fail over to a secondary Region with minimal data loss. Which solution meets these requirements?

Hard
67

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application uses a self-signed SSL certificate on the instances, and an Application Load Balancer (ALB) terminates SSL. Users report intermittent SSL certificate errors. The security team requires that the certificate be managed and rotated automatically. Which solution should a solutions architect implement to meet these requirements?

Medium
68

A company uses AWS CloudFormation to manage infrastructure. A recent stack update failed because a resource exceeded a service quota. The team wants to be notified proactively when service limits are approaching. Which solution meets this requirement?

Hard
69

A company runs a microservices application on Amazon EKS. The application consists of multiple services that communicate over HTTP. The operations team wants to implement a service mesh to gain observability, traffic management, and security features without modifying application code. They also want to minimize operational overhead. Which solution should a solutions architect recommend?

Hard
70

A company uses AWS Lambda functions behind an Amazon API Gateway REST API. The Lambda functions query an Amazon RDS for PostgreSQL database. Recently, the company has noticed increased latency and occasional timeouts during peak hours. A solutions architect needs to improve the performance and scalability of the database layer. Which solution will meet these requirements with the LEAST operational overhead?

Medium
71

A company uses Amazon CloudFront to deliver static content from an S3 bucket. They want to restrict access so that only CloudFront can access the S3 bucket. What configuration should they use?

Easy
72

A company runs a web application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer. The operations team notices that the ALB returns 503 errors during peak traffic. Which TWO actions should the solutions architect take to resolve this issue?

Hard
73

A company runs a steady-state HTTP API on a fleet of Amazon EC2 instances behind an Application Load Balancer. The operations team needs to reduce cost without degrading performance or availability. They observe that CPU utilization is consistently 8–12% and memory utilization is around 40%. The workload is stateless and can tolerate a brief instance restart during deployment. Which change should a solutions architect recommend to meet the cost-reduction goal?

Medium
74

A company runs a critical application on EC2 instances in an Auto Scaling group. They want to be notified immediately if any instance fails a status check. What is the simplest solution?

Easy
75

A company runs a production AWS Lambda function that processes orders. Recently, the function has been timing out occasionally. The function uses a VPC with a single private subnet and has a timeout of 30 seconds. What is the MOST likely cause of the timeout?

Medium
76

A company runs a critical web application on a fleet of Amazon EC2 instances behind an Application Load Balancer (ALB). The operations team notices that during peak traffic, the ALB reports a high number of HTTP 5xx errors, and CloudWatch metrics show that the target group's HealthyHostCount drops significantly. The application logs indicate that the instances are running out of memory and becoming unresponsive. The company wants to improve the reliability of the application with minimal operational overhead. Which solution should a solutions architect recommend?

Medium
77

A company runs a critical database on an RDS for MySQL Multi-AZ DB instance. The database is experiencing high read latency. The application is read-heavy and uses many complex joins. The company needs to improve read performance with minimal application changes. Which solution is MOST appropriate?

Hard
78

A company uses AWS CloudFormation to deploy infrastructure. A Solutions Architect needs to update a stack that includes an RDS DB instance. The update requires modifying the DB instance's storage type from gp2 to io1. What change should be made to the CloudFormation template to minimize downtime?

Easy
79

A startup runs a stateless REST API on a fleet of Amazon EC2 instances in an Auto Scaling group. The API stores session tokens in a local in-memory cache on each instance. During a scaling event, users are randomly logged out because their session token is not present on the new instance that serves their request. The team wants sessions to survive instance replacement and scale-out without changing the API code significantly. Which change should the solutions architect recommend?

Easy
80

A company uses AWS CloudTrail to log API activity. The compliance team requires that logs be stored for 7 years and be immediately accessible for the first 90 days, after which access can take up to 12 hours. Which storage solution meets these requirements cost-effectively?

Medium
81

A company uses Amazon CloudFront with an S3 origin to serve static content. They recently updated the content in S3, but users still see the old files. What is the MOST likely reason?

Medium
82

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores user session data in a self-managed Redis cluster on a single EC2 instance. Users report being logged out intermittently, especially during peak traffic. The company wants to improve the reliability and scalability of session management with minimal application changes. Which solution should a solutions architect recommend?

Medium
83

A startup runs a containerized microservices application on Amazon ECS with Fargate. They use an Application Load Balancer to distribute traffic. The application consists of 10 services, each with its own ECS service. Recently, the startup launched a marketing campaign and traffic increased 10x. The application started returning HTTP 503 errors. The ECS service metrics show that the number of running tasks is at the maximum desired count for each service. The ALB target group health checks are failing intermittently. The startup needs to handle the increased traffic and prevent 503 errors. What should they do?

Hard
84

A company wants to reduce costs for a batch processing workload that runs nightly on Amazon EMR. The workload is fault-tolerant and can handle interruptions. Which TWO strategies should they implement? (Choose TWO.)

Medium
85

A company has a multi-tier application running on AWS. The web tier uses an Application Load Balancer (ALB) with an Auto Scaling group of EC2 instances. The application tier runs on a separate Auto Scaling group of EC2 instances. The database tier uses Amazon RDS for MySQL. During a recent load test, the application became unresponsive. Monitoring showed that the database's CPU utilization was at 100% and the number of database connections was at the maximum limit. The application tier instances were healthy, but the web tier instances were returning 503 errors. The Solutions Architect determined that the application tier was making too many database connections because each request opened a new connection and did not close it properly. The team wants to fix the issue with minimal changes to the application code. Which solution should the Solutions Architect recommend?

Medium
86

A company is using AWS CodePipeline to automate deployments. They want to add a manual approval step before deploying to production. How should they configure this?

Medium
87

A company runs a production application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer (ALB) to distribute traffic to tasks. The company has configured an Auto Scaling target tracking policy based on average CPU utilization. During a marketing campaign, traffic spikes cause the ALB to return 503 errors. The ECS service dashboard shows that the number of tasks scaled out to the maximum allowed but the CPU utilization remained high. What is the MOST likely cause of the 503 errors?

Hard
88

A company operates a web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in a self-managed Redis cluster on EC2. During a recent marketing campaign, the Redis cluster became a bottleneck, causing session timeouts and poor user experience. The company wants to improve the solution's scalability and resilience with minimal operational overhead. Which solution should a solutions architect recommend?

Medium
89

A company is deploying a web application that uses an Application Load Balancer and an Auto Scaling group of EC2 instances. The application must be able to handle sudden spikes in traffic. Which TWO actions should the Solutions Architect take to improve scalability and reduce latency? (Choose two.)

Medium
90

A company is using an AWS Lambda function to process records from an Amazon Kinesis stream. The function stores results in an Amazon DynamoDB table. The team notices that the Lambda function sometimes fails due to throttling from DynamoDB. Which TWO actions should the team take to improve the continuous processing of records? (Choose TWO.)

Easy
91

A company runs a critical application on Amazon RDS for PostgreSQL. The database performance has degraded over time. The Solutions Architect notices that read queries are slow and the DB instance's ReadIOPS metric is consistently high. Which action would improve read performance with minimal operational overhead?

Medium
92

A company runs a production AWS environment with Amazon EC2 instances managed by Auto Scaling groups. The operations team notices that after a recent deployment, the application is returning higher error rates. Which TWO steps should the team take to enable a quick rollback and improve future deployments?

Medium
93

Refer to the exhibit. A CloudFormation template is used to create an S3 bucket with versioning enabled and a DeletionPolicy of Retain. The stack is deleted. What happens to the bucket and its objects?

Hard
94

A company is using Amazon CloudFront to deliver static content from an S3 bucket. The company wants to ensure that users can only access content through CloudFront and not directly from the S3 bucket. What should the company do?

Easy
95

A company runs a high-traffic web application on an EC2 Auto Scaling group behind an Application Load Balancer. The operations team notices that during sudden traffic spikes, new instances take several minutes to become healthy and serve traffic, causing elevated latency. The team wants to reduce the time from instance launch to serving traffic. Which change should a solutions architect recommend?

Medium
96

A company has a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application experiences occasional timeouts during peak hours. After reviewing AWS X-Ray traces, the team finds that DynamoDB queries are slow. Which THREE actions should the team take to improve performance and continuously optimize the solution?

Hard
97

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local instance storage. The operations team wants to centralize log analysis and enable near-real-time monitoring for errors. They also want to archive logs for long-term compliance. The logs are generated continuously and can be large in volume. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Medium
98

A company runs a stateful web application on a single Amazon EC2 instance with an attached Amazon EBS volume. The application stores session data locally on the instance's root volume. The company wants to make the application highly available across multiple Availability Zones with minimal application changes. The application must continue to function if an Availability Zone fails. Which solution should a solutions architect recommend?

Hard
99

A company runs a production web application on EC2 instances in an Auto Scaling group behind an ALB. The application logs are stored on an EBS volume attached to each instance. The operations team notices that the logs are not being sent to a central location. What is the MOST efficient way to centralize log collection with minimal code changes?

Medium
100

A company runs a monolithic application on a single EC2 instance. The application is critical and must be highly available. The company wants to migrate to a containerized architecture on Amazon ECS with minimal downtime. Which approach should the company take?

Medium
101

A company uses AWS CloudFormation to deploy infrastructure. The operations team notices that stack updates frequently fail because of updates to resources that are not supported for updates. What is the BEST way to handle this?

Medium
102

A company uses Amazon RDS for MySQL with Multi-AZ deployment. The database experiences occasional read replica lag of up to 5 seconds. The application requires read-after-write consistency. Which action should the company take to improve the solution?

Medium
103

A company has an existing web application that stores user-uploaded images in an Amazon S3 bucket. The bucket has S3 Standard storage and versioning enabled. Over time, storage costs have increased because many old object versions are never accessed after 30 days, but they must be retained for 1 year for compliance. The security team requires that no object version be permanently deleted before 365 days. Which solution is the MOST cost-effective while meeting the compliance requirement?

Medium
104

A company runs a critical workload on a fleet of Amazon EC2 instances behind an Application Load Balancer. The workload is latency-sensitive and the operations team wants to continuously improve performance without changing the application code. They have enabled detailed monitoring and AWS X-Ray tracing. Which solution will provide the MOST actionable, near-real-time insight into which downstream dependencies are causing increased response times?

Hard
105

A company uses AWS CloudFormation to deploy resources. The operations team notices that some stack updates fail due to resource conflicts. What is the BEST practice to minimize such failures?

Easy
106

Which TWO AWS services can be used to monitor and troubleshoot network connectivity issues between EC2 instances? (Choose two.)

Easy
107

A company runs a web application on EC2 instances behind an ALB. They want to improve the security posture by implementing defense in depth. Which TWO measures should they implement? (Choose TWO.)

Easy
108

A company has a microservices application running on Amazon ECS with the EC2 launch type. Each service runs as an ECS service with a desired count of 4 tasks across two Availability Zones. The operations team wants to reduce cost during predictable low-traffic nights while maintaining availability. They also want to ensure that a sudden traffic spike during the day does not cause outages. Which solution should a solutions architect recommend?

Medium
109

A company is using Amazon RDS for MySQL and notices that read replicas are falling behind the primary. The primary instance is experiencing high write traffic. What is the best solution to reduce replica lag?

Medium
110

A company is using Amazon CloudFront with an S3 origin. They notice that users are receiving outdated content. What configuration change should be made to ensure users always get the latest content?

Medium
111

A developer notices that CloudWatch Logs for a Lambda function show no logs after a recent deployment. The function is invoked successfully. What is the most likely cause?

Medium
112

A company runs a nightly batch job on a single Amazon EC2 instance that reads 2 TB of data from Amazon S3, transforms it, and writes results back to S3. The job currently takes 9 hours and must finish within a 4-hour maintenance window. The instance is a compute-optimized type with 10 Gbps network bandwidth, and CloudWatch shows the CPU is never above 35%. Which change should a solutions architect make to shorten the runtime?

Medium
113

A company uses Amazon DynamoDB for a gaming application. The table has a partition key of user_id and a sort key of timestamp. During a new game launch, the table experiences throttling on a few partitions. The company wants to improve the partition distribution. Which action should the company take?

Hard
114

An IAM policy attached to a user allows s3:GetObject and s3:PutObject on my-bucket, but denies all actions on the confidential/ prefix. The user reports that they can still upload objects to the confidential/ folder. Why?

Hard
115

A company uses Amazon S3 to store backups. The backup process uploads objects with a prefix 'backups/' and sets the storage class to STANDARD_IA. The company wants to automatically move objects older than 30 days to GLACIER. What is the most efficient way to achieve this?

Medium
116

A company runs a critical application on an Amazon RDS for PostgreSQL DB instance. The database experiences periodic slowdowns. The team notices that the DB instance has a large number of connections in an idle state. What is the BEST way to address this issue?

Medium
117

A company has an AWS Lambda function that processes messages from an SQS queue. The function is experiencing timeouts. Which TWO changes could help resolve the timeout issue? (Choose 2)

Easy
118

A company has a critical application running on AWS Lambda that processes messages from an Amazon SQS queue. The queue occasionally receives a large backlog of messages, causing Lambda to scale up significantly and incur high costs. The company wants to optimize costs while ensuring that all messages are processed in a timely manner. Which solution should a solutions architect recommend?

Medium
119

A company runs a critical application on a single Amazon EC2 instance in a development environment. The application writes data to an instance store volume. After a planned stop and start of the instance, the data on the instance store is lost. The company wants to prevent data loss in the future for this instance. What should a solutions architect recommend?

Medium
120

A company is running a stateful web application on EC2 instances in an Auto Scaling group. Users report that their sessions are lost when instances are terminated during scale-in. What should a solutions architect do to preserve session state?

Medium
121

A company is using Amazon CloudFront to serve content from an S3 origin. The content is updated infrequently. Users in some regions report seeing stale content. The company wants to ensure that users always see the latest version without waiting for TTL expiration. What is the MOST cost-effective solution?

Medium
122

A company is migrating a legacy application to AWS. The application runs on a single EC2 instance and uses an attached EBS volume for data storage. The company wants to improve high availability. Which THREE actions should the company take? (Choose three.)

Medium
123

A company stores sensitive data in an S3 bucket encrypted with SSE-KMS. They need to audit all access requests to the bucket. Which AWS service should they use?

Easy
124

A company runs a production application on Amazon EC2 instances behind an Application Load Balancer. Recently, error rates increased due to a misconfiguration. The operations team wants to automatically roll back to the previous working configuration if errors exceed a threshold. Which solution provides the fastest rollback?

Medium
125

A developer is deploying a serverless application using AWS SAM. The deployment fails with a 'ResourceNotReady' error. What is the most likely cause?

Easy
126

A company has an AWS Lambda function that processes messages from an Amazon SQS queue. The function is invoked with a batch size of 10. Some messages are failing repeatedly, causing the function to retry them up to the maximum retry count and then they are sent to a dead-letter queue (DLQ). The company wants to improve the resilience of the application by handling partial batch failures more efficiently. What should a solutions architect do?

Medium
127

A company has an application that runs on Amazon EC2 instances in an Auto Scaling group. The application writes logs to local disk. The company wants to centralize log storage and enable near-real-time analysis of the logs. The company also wants to retain the logs for 7 years for compliance. The logs are currently stored in a file on each instance. The company wants a solution that requires minimal changes to the application and is cost-effective. Which solution meets these requirements?

Medium
128

A company is running a stateful web application on a single Amazon EC2 instance. The application stores session data on an instance store volume. The company wants to improve the availability and durability of the application by moving to a multi-AZ architecture. The application must remain accessible if an Availability Zone fails. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Hard
129

A company has a critical application that uses an Amazon Aurora MySQL database cluster. The application experiences occasional slow queries during peak hours, impacting user experience. A solutions architect needs to identify the root cause and improve performance with minimal changes. The architect has enabled Performance Insights and sees high wait times on the database. Which action should the architect take FIRST to resolve the issue?

Hard
130

Which THREE factors should be considered when designing a disaster recovery plan for a multi-tier application using AWS? (Choose three.)

Hard
131

A company runs a web application on EC2 instances in an Auto Scaling group. The application receives a variable workload. The company wants to scale based on a custom metric that tracks the number of active users. What is the MOST efficient way to achieve this?

Medium
132

A company is migrating a monolithic application to a microservices architecture on AWS. They want to improve deployment frequency and reduce risk. Which TWO strategies should they adopt?

Medium
133

A company has a microservices architecture running on Amazon ECS with Fargate. Each service writes logs to CloudWatch Logs. The operations team needs to search across all logs for a specific error pattern. Currently, they manually query each log group, which is time-consuming. What is the MOST efficient way to enable centralized log search?

Hard
134

A company runs a production database on Amazon RDS for PostgreSQL. The database experiences high write latency during peak hours. The company wants to improve write performance with minimal cost. Which action should a solutions architect take?

Hard
135

A company is migrating from a monolithic application to microservices on AWS. They need to reduce the blast radius of failures. Which architecture pattern should they implement?

Hard
136

A company uses Amazon CloudWatch Logs to collect application logs. The operations team wants to be notified when a specific error message appears in the logs. What is the SIMPLEST way to achieve this?

Easy
137

A company runs a serverless application using AWS Lambda functions that process messages from an Amazon SQS queue. The company wants to improve the reliability of message processing by ensuring that failed messages are not lost and can be reprocessed later. Which solution should a solutions architect recommend?

Easy
138

A company has a monolithic application running on a single Amazon EC2 instance. The application consists of a web server and a backend worker process. The company wants to migrate to a microservices architecture using containers on Amazon ECS with Fargate. The solutions architect needs to design a solution that minimizes downtime during the migration. Which approach should the solutions architect recommend?

Hard
139

A company is using AWS CloudTrail to log all API activity. The security team wants to be alerted when an IAM user creates a new access key. What is the simplest way to achieve this?

Easy
140

A company runs a critical web application on EC2 instances behind an ALB. The application stores session data in an ElastiCache Redis cluster. During a recent outage, the Redis cluster failed and all active sessions were lost, causing users to be logged out. Which solution would provide the HIGHEST availability for session data?

Medium
141

A company is migrating a monolithic application to microservices on Amazon ECS. The application uses a legacy database that does not support distributed transactions. The team wants to ensure data consistency across services. Which solution is BEST for achieving eventual consistency with minimal code changes?

Hard
142

A company has a web application that uses an Amazon RDS for PostgreSQL database. The database is experiencing high read traffic, and the application is seeing increased latency. The database is currently a Single-AZ deployment with a db.r5.2xlarge instance. The company wants to improve read performance and also increase availability with minimal application changes. Which solution should a solutions architect recommend?

Medium
143

Refer to the exhibit. A company uses this IAM policy to allow an automation script to manage Amazon EBS snapshots. The script runs on an EC2 instance with this attached IAM role. The script is failing when trying to create a snapshot from a volume and tag it. The error message indicates an authorization failure. What is the root cause?

Hard
144

A company is migrating a legacy application to AWS. The application requires a relational database with high availability and automated backups. Which TWO AWS services should the company consider? (Choose two.)

Easy
145

Refer to the exhibit. An AWS Lambda function logs the error above. The function uses the AWS SDK to call an Amazon DynamoDB table. What is the MOST likely cause?

Easy
146

Which TWO actions would improve the security of an S3 bucket that contains sensitive data? (Choose two.)

Medium
147

A company wants to reduce costs for its Amazon RDS for MySQL database without affecting performance. The database is used by a read-intensive application. Which action should the company take?

Easy
148

A company runs a web application on EC2 instances behind an Application Load Balancer. Users report intermittent 503 errors. CloudWatch logs show the ALB's healthy host count occasionally drops to zero during traffic spikes. Which design change should a solutions architect implement to improve availability?

Medium
149

A company uses AWS Lambda functions to process events from Amazon S3. They notice that some Lambda invocations are failing with 'ResourceNotFoundException' errors when trying to write to an Amazon DynamoDB table. The Lambda execution role has a policy that grants dynamodb:PutItem on the table. What is the most likely cause of these errors?

Easy
150

A company runs a microservices application on Amazon ECS with the Fargate launch type. The application uses an Application Load Balancer (ALB) to distribute traffic. During a recent incident, one service became unresponsive, but the ALB continued to send traffic to it because the health check only verified that the container was running. The company wants to improve the health check to detect application-level failures and automatically replace unhealthy tasks. Which solution should a solutions architect recommend?

Hard
151

A company runs a stateful web application on EC2 instances behind an Application Load Balancer. The application stores session data locally on the instances. The company wants to improve availability and scalability. What should a solutions architect recommend?

Medium
152

A company operates a multi-account AWS Organization with AWS Control Tower. A new compliance rule requires that all Amazon S3 buckets in every account block public access and that any noncompliant bucket be remediated automatically within minutes. The security team wants a central view of compliance and minimal per-account configuration. Which solution BEST meets these requirements?

Hard
153

A company uses AWS CloudFormation to manage infrastructure. The operations team wants to ensure that all future stack updates follow best practices for change management. Which THREE actions should the team implement?

Easy
154

A company is using AWS CloudFormation to manage infrastructure. The operations team wants to be notified when a stack operation fails. Which approach is the MOST efficient?

Easy
155

A development team deploys a web application on Amazon EC2 instances behind an Application Load Balancer. The application experiences intermittent 503 errors. A Solutions Architect notices that the errors coincide with high CPU utilization on the EC2 instances. What is the MOST effective way to improve the application's availability?

Easy
156

A company is using AWS CloudFormation to deploy infrastructure. They want to ensure that updates to a stack do not cause downtime for a critical web application. Which THREE strategies should they consider? (Choose THREE.)

Easy
157

A company uses AWS CloudFormation to deploy infrastructure. A stack update fails with a resource update failure. The team wants to investigate the specific error without rolling back the stack. What is the BEST approach?

Medium
158

A company runs a containerized application on Amazon ECS with the Fargate launch type. The application writes logs to stdout, which are captured by the awslogs driver and sent to Amazon CloudWatch Logs. The operations team notices that during peak hours, log ingestion costs have increased significantly, and they want to reduce costs without losing critical error logs. Which solution should a solutions architect recommend?

Medium
159

A solutions architect deployed an AWS Lambda function using a deployment package. The function logs the error shown in the exhibit. What is the most likely cause?

Medium
160

A company runs a stateless web application on an Auto Scaling group of Amazon EC2 instances behind an Application Load Balancer. The instances use a launch template with a base Amazon Machine Image and run a user data script that installs the application, which takes about 8 minutes. During a scale-out event, new instances fail the load balancer health checks for several minutes, causing 5xx errors. The company wants to reduce the time from instance launch to serving traffic without changing the application. Which solution will meet these requirements MOST cost-effectively?

Hard
161

A company runs a web application on Amazon EC2 instances in an Auto Scaling group. The application stores user session data in a local MySQL database on each instance, which has caused issues when instances are replaced. The company wants to make the application stateless and improve scalability. Which solution should a solutions architect recommend?

Medium
162

A company has a serverless application using AWS Lambda and Amazon API Gateway. The application experiences cold starts that cause latency spikes. Which solution would reduce the impact of cold starts?

Medium
163

A company uses AWS CodePipeline to deploy a serverless application built with AWS SAM. The pipeline has a source stage from CodeCommit, a build stage using CodeBuild, and a deploy stage using CloudFormation. The team wants to ensure that the application is automatically tested in a staging environment before being deployed to production. The testing should include integration tests that simulate user interactions. Which solution should a solutions architect recommend to meet these requirements with minimal changes?

Medium
164

A company runs a critical application on EC2 instances in an Auto Scaling group. They want to ensure that during a patching cycle, the application remains available and no requests are dropped. Which TWO strategies should they implement? (Choose TWO.)

Hard
165

A company is using AWS CloudTrail to log API activity. The security team wants to ensure that log files are tamper-proof and can be used for forensic analysis. Which TWO actions should the company take?

Hard
166

A company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences intermittent latency spikes. The operations team has enabled detailed CloudWatch metrics and logs, but cannot identify the root cause. What is the MOST effective way to troubleshoot the latency issue?

Hard
167

A solutions architect runs the above commands for an EC2 instance. The instance state is 'running' but the system status is 'impaired'. What should the solutions architect do to restore the instance?

Medium
168

A solutions architect is reviewing an application that writes millions of small records per hour to an Amazon DynamoDB table. The table uses a partition key of customer ID, and a few very large customers generate most of the traffic. During peak periods, the application receives ProvisionedThroughputExceededException errors even though total consumed capacity is below the provisioned amount. Which action will resolve the throttling MOST effectively?

Medium
169

Match each AWS database service to its characteristic.

Medium
170

Drag and drop the steps to troubleshoot an EC2 instance that is unreachable via SSH in the correct order.

Medium
171

A Lambda function logs are being retained for 30 days. The company wants to reduce costs by deleting logs older than 7 days. What should they do?

Medium
172

A company runs a microservices application on Amazon ECS with the EC2 launch type. The application consists of multiple services that communicate over HTTP. The operations team wants to improve observability and reduce the time to diagnose performance issues between services. They have already enabled CloudWatch Logs and metrics. They want to trace requests as they flow through the services and identify latency bottlenecks. What should a solutions architect recommend?

Hard
173

A company is migrating an on-premises application to AWS. The application requires persistent shared storage that can be accessed by multiple EC2 instances simultaneously with strong consistency. Which AWS storage solution should the company use?

Medium
174

A company runs a microservices architecture on Amazon ECS with Fargate. The operations team observes that some services are experiencing high latency during peak hours. The team wants to identify the root cause. Which THREE approaches should the team use? (Choose THREE.)

Hard
175

A solutions architect is reviewing an existing three-tier application running on Amazon EC2 instances in an Auto Scaling group. The database tier uses Amazon RDS for MySQL with a single Availability Zone deployment. The business requires improved resilience and wants to minimize changes to the application. The RPO is 5 minutes and the RTO is 2 minutes. Which change should the architect recommend?

Medium
176

A company has a legacy monolithic application running on a single EC2 instance. The application stores customer data in an attached EBS volume. The company wants to modernize the application to improve scalability and availability. Which approach should a solutions architect recommend?

Hard
177

A company is deploying a new application on AWS and wants to implement a least-privilege IAM policy for an EC2 instance that needs to read from an S3 bucket (my-bucket) and write logs to CloudWatch Logs. Which TWO statements should be included in the IAM policy? (Choose two.)

Hard
178

A company is using t3.large instances in an Auto Scaling group. They want to launch instances that support both x86_64 and arm64 architectures. Based on the exhibit, can they meet this requirement with t3.large?

Hard
179

A financial services company runs a critical application on Amazon EC2 instances in an Auto Scaling group across multiple Availability Zones. The application uses an Amazon RDS for MySQL database with Multi-AZ deployment. The company has a recovery time objective (RTO) of 15 minutes and a recovery point objective (RPO) of 1 hour for the database. During a recent disaster recovery drill, the solutions architect simulated an Availability Zone failure by terminating all EC2 instances and the primary RDS instance in one AZ. The Auto Scaling group launched new instances in the other AZ, and the RDS Multi-AZ failover completed in about 2 minutes. However, the application remained unavailable for 30 minutes because the new EC2 instances could not connect to the RDS secondary instance. The security groups are configured correctly. The RDS instance is not publicly accessible. What is the MOST likely cause of the connectivity issue?

Hard
180

A company runs a web application on Amazon EC2 instances in an Auto Scaling group. The application uses an Amazon RDS for MySQL database. The company wants to improve the performance of read-heavy workloads and reduce the load on the primary database instance. The application currently connects to the primary instance for all read and write operations. The solutions architect needs to implement a solution that requires minimal changes to the application code. Which approach should the solutions architect recommend?

Medium
181

A company runs a web application on a single EC2 instance. They want to improve availability and fault tolerance with minimal architectural changes. What should they do?

Medium
182

A company has a monolithic application running on a single Amazon RDS for MySQL DB instance. The application is experiencing performance issues due to heavy read traffic. The company wants to implement a solution that offloads read traffic with minimal application changes. What should a solutions architect do?

Hard
183

A company runs a containerized application on Amazon ECS with Fargate. The application uses an Application Load Balancer (ALB) to distribute traffic. The company has configured a target tracking scaling policy based on average memory utilization. During a traffic spike, the ECS service scales out, but the new tasks are immediately deregistered and replaced. The CloudWatch logs show that the new tasks are failing the ALB health check. The health check is configured to ping the '/health' endpoint on the container. The solutions architect verifies that the application container correctly responds to the '/health' endpoint with a 200 status code. What is the MOST likely cause of the health check failures?

Medium
184

An IAM policy condition allows launching EC2 instances only if the instance type is t2.micro or t2.small. A developer tries to launch a t2.medium instance. What happens?

Medium
185

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores session state locally on each instance. The company wants to improve the availability and scalability of the application by making the session state external and allowing any instance to handle any request. The solution must minimize latency for session access and require minimal changes to the application code. Which approach should a solutions architect recommend?

Medium
186

A company is migrating a monolithic application to microservices on AWS. They want to implement a continuous improvement process for existing services. Which AWS service should they use to collect and analyze operational metrics and logs from all microservices in a centralized location?

Easy
187

Refer to the exhibit. A company has an Amazon ECS task definition with two containers. The 'web' container is essential, and the 'sidecar' container is not. The 'sidecar' container exits unexpectedly. What will happen to the task?

Easy
188

A company has a production Amazon ECS service running on Fargate. The service needs to be updated to use a new task definition with different environment variables. The company wants to perform a rolling update with minimal impact. What is the correct way to update the service?

Medium
189

A company uses AWS CloudFormation to deploy infrastructure. The operations team wants to automatically roll back a stack update if it fails, and receive a notification. What should be configured to meet these requirements?

Easy
190

A company uses AWS CodeBuild to compile and test code. The build process takes a long time because dependencies are downloaded from the internet each time. The company wants to speed up the build process. Which TWO actions should the company take? (Choose TWO.)

Medium
191

A company runs a batch processing job on a schedule using AWS Lambda. The job processes files from an S3 bucket and writes results to another S3 bucket. Recently, the job has been failing with the error 'Access Denied' when trying to write to the destination bucket. The Lambda function's execution role has the following IAM policy attached: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetObject", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::source-bucket/*", "arn:aws:s3:::source-bucket" ] }, { "Effect": "Allow", "Action": [ "s3:PutObject" ], "Resource": "arn:aws:s3:::destination-bucket/*" } ] } The Lambda function also has a VPC configuration to access an RDS instance. The S3 buckets are in the same region. The Solutions Architect verified that the destination bucket policy does not deny access. What is the MOST likely cause of the 'Access Denied' error?

Easy
192

A company runs a serverless image-processing pipeline. When an image is uploaded to an S3 bucket, an AWS Lambda function is invoked to resize it and write the output to another S3 bucket. The company wants to reduce the cost of Lambda invocations and improve performance for a new workload that processes large batches of images at scheduled intervals. The images are already stored in S3 and do not require immediate processing. What is the MOST cost-effective solution?

Medium
193

A company runs a critical application on Amazon RDS for PostgreSQL. The database experiences high read traffic. The application is read-heavy and can tolerate eventual consistency for some queries. What is the MOST effective way to improve read performance without significant architectural changes?

Medium
194

A company runs a three-tier web application on AWS. The database tier uses Amazon RDS for PostgreSQL with a single primary instance and no read replicas. The application experiences heavy read traffic during business hours, causing CPU utilization on the primary to exceed 90%. The team wants to offload read traffic without changing the application's write path. Which solution should a solutions architect recommend?

Medium
195

A company is running a stateful web application on EC2 instances in an Auto Scaling group behind an ALB. The application stores session data locally on the instance. The company notices that users are frequently logged out and lose session data during scaling events. What is the MOST operationally efficient way to preserve session state?

Hard
196

A company is using an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application has a health check endpoint at /health. Recently, the ALB is marking instances as unhealthy even though the application is running. The health check settings are: interval 30 seconds, timeout 5 seconds, unhealthy threshold 2. What is the most likely cause?

Medium
197

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application experiences variable traffic patterns, and the operations team wants to optimize costs by using a mix of On-Demand and Spot Instances. The team also wants to ensure that the application remains available even if some instances are terminated. Which solution should a solutions architect recommend?

Easy
198

A company runs a stateful web application on EC2 instances in an Auto Scaling group. The application uses a shared EFS file system for persistent data. The operations team notices that during scale-in events, some requests fail because the instance is terminated while still processing. What is the BEST way to prevent request failures during scale-in?

Medium
199

A company uses AWS CloudFormation to deploy infrastructure. They have a stack that creates an Amazon RDS for MySQL database. The stack creation fails with the error 'The following resource(s) failed to create: [DBInstance]'. The solutions architect needs to troubleshoot the issue. Which approach should be taken first?

Medium
200

A company is running a web application on AWS using an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application experiences periodic traffic spikes that cause increased latency. The company wants to implement a solution to automatically adjust capacity in anticipation of traffic changes. What should a solutions architect do?

Medium
201

A company is using AWS Config to evaluate resource compliance. They want to receive notifications when a noncompliant resource is detected. Which AWS service should be used to send these notifications to an email endpoint?

Easy
202

A company is deploying a web application on EC2 instances behind an Application Load Balancer. The application experiences high traffic during business hours and low traffic at night. The company wants to automatically scale the instances based on CPU utilization. Which TWO steps are required to achieve this?

Medium
203

A company runs a web application on EC2 instances behind an Application Load Balancer. Users report intermittent slowdowns. CloudWatch metrics show high CPU utilization on the instances. The company wants to improve performance with minimal architectural changes. What should a solutions architect do?

Medium
204

A company's AWS CloudTrail logs are stored in an S3 bucket. A Solutions Architect needs to analyze the logs to identify API calls that created or modified IAM roles in the last 30 days. What is the MOST efficient way to perform this analysis?

Medium
205

A company runs a stateful application on EC2 instances in an Auto Scaling group behind a Network Load Balancer (NLB). The application requires that client sessions are maintained to the same instance. The operations team notices that after scaling events, some clients lose their sessions. Which configuration change should the team implement to ensure session persistence?

Medium
206

A company is migrating a monolithic application to microservices on Amazon ECS. They want to implement a service mesh for observability and traffic management. Which THREE AWS services should they consider?

Hard
207

A company runs a latency-sensitive trading application on Amazon EC2 instances behind a Network Load Balancer. The application must maintain persistent TCP connections and uses a custom health check on port 8080. During a recent incident, the operations team observed that when an instance became unhealthy, existing connections continued to be routed to it for several minutes, causing failed trades. The team needs to ensure that unhealthy targets are removed from the load balancer rotation as quickly as possible while preserving connection draining for graceful shutdown. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

Hard
208

A company runs a web application on EC2 instances in an Auto Scaling group. The application stores session data locally on the EC2 instances. The operations team reports that after scaling events, users lose their sessions. Which TWO actions should the Solutions Architect take to resolve this issue?

Medium
209

A company is migrating a legacy application to AWS. The application requires a fixed IP address for whitelisting by a third-party service. The application will run on EC2 instances behind an Application Load Balancer. The company needs a solution that provides a static IP address for outbound traffic. What should a solutions architect do?

Hard
210

A company runs a microservices application on Amazon ECS with the Fargate launch type. The services communicate over a service mesh. The operations team wants to improve observability and reduce troubleshooting time for inter-service communication issues. They need to capture detailed request traces and metrics without modifying application code. Which solution should a solutions architect recommend?

Hard
211

A company uses AWS CodeBuild to run unit tests. The build process is taking longer than expected. The buildspec.yml file includes a pre-build phase that downloads dependencies from a public repository. What is the most effective way to reduce build time?

Hard
212

A company uses AWS CloudFormation to deploy infrastructure. The team wants to ensure that all resources are tagged with a CostCenter tag. They want to automatically remediate any stack that creates resources without the required tag. Which approach is MOST effective?

Hard
213

A company uses an Amazon RDS for MySQL DB instance. The database is experiencing high read latency. The team wants to improve read performance with minimal application changes. Which TWO actions should the team take? (Choose two.)

Medium
214

A company is using Amazon S3 to store critical data. The security team requires that all data at rest be encrypted using AWS KMS with automatic rotation of the customer master key (CMK) every year. What should a solutions architect do to meet this requirement?

Easy
215

A company uses an AWS CodePipeline to deploy a serverless application. The pipeline includes a build stage that runs on AWS CodeBuild and a deploy stage that updates an AWS Lambda function. The company wants to add a manual approval step before the deploy stage. What is the most efficient way to implement this?

Hard
216

A company runs a containerized application on Amazon ECS with Fargate. The application needs to securely access an Amazon S3 bucket. The company wants to follow the principle of least privilege. What should a solutions architect recommend?

Hard
217

A company is running a stateful web application on Amazon EC2 instances in an Auto Scaling group. The instances store session data in an Amazon ElastiCache for Redis cluster. The company wants to improve the application's fault tolerance and ensure that session data is not lost if an Availability Zone fails. What should the solutions architect do?

Medium
218

A company runs a batch processing job on Amazon EC2 instances that are part of an Auto Scaling group. The job runs every night and takes approximately 2 hours. The instances are launched using a launch template with a Spot Instance request. Recently, the job has been failing because Spot Instances are being reclaimed before the job completes. The company wants a cost-effective solution that ensures the job completes reliably. The job can handle interruptions by checkpointing. Which solution should the company implement?

Easy
219

A company has a production AWS account with multiple VPCs connected via a transit gateway. The security team wants to centrally capture all VPC flow logs for analysis in Amazon Athena. What is the MOST cost-effective way to store the flow logs?

Easy
220

A company has deployed a web application on Amazon ECS with Fargate. The application needs to access an Amazon RDS database. The security team mandates that the database must not be publicly accessible. What is the best way to securely connect the ECS tasks to the RDS database?

Easy
221

A company uses AWS CodePipeline to deploy a web application to Amazon ECS. The deployment often fails because the ECS service's desired count is not met during the update. The company wants to implement a blue/green deployment with automated rollback on failure. What is the MOST effective approach?

Hard
222

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). Users report intermittent 503 errors. The ALB target group health checks are failing. Which step is MOST likely to resolve the issue?

Medium
223

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences performance degradation during peak hours. CloudWatch metrics show that the CPU utilization of the EC2 instances regularly reaches 90-100% during these periods. The company wants to ensure the application remains responsive during peak loads while minimizing costs. Which solution should a solutions architect recommend?

Medium
224

A Solutions Architect runs the above AWS CLI command and gets the output shown. The instance is 'running' but the application is not accessible. What should the Solutions Architect check next?

Medium
225

A company uses AWS CloudFormation to deploy infrastructure. A recent change to a stack failed because an IAM role name already exists. The company wants to avoid this issue in the future. What should a solutions architect do?

Easy
226

A company runs a stateful containerized application on Amazon ECS using the EC2 launch type. The application requires persistent storage that must be accessible from multiple tasks simultaneously and must provide high throughput. The company wants to minimize operational overhead. Which storage solution should a solutions architect recommend?

Hard
227

A company has a multi-region architecture using DynamoDB global tables. They notice that write conflicts are occurring frequently between regions. What is the MOST likely cause and how should they resolve it?

Hard
228

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application stores session state in a self-managed Redis cluster on EC2 instances. During a recent marketing campaign, the Redis cluster became a bottleneck, causing session timeouts and lost carts. The company wants to improve the scalability and availability of the session store with minimal application changes. Which solution should a solutions architect recommend?

Hard

Frequently asked questions

What does the Continuous Improvement for Existing Solutions domain cover on the SAP-C02 exam?
Given an existing workload, identify the bottleneck or risk, then pick the AWS service or configuration change that resolves it at acceptable cost. The single most important skill is mapping a stated symptom, such as throttling or slow failover, to the specific AWS feature that addresses it.
How many questions are in this domain?
This page lists all 228 Continuous Improvement for Existing Solutions questions in the SAP-C02 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Continuous Improvement for Existing Solutions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
aws-sap-c02 AWS-SAP-C02 continuous improvement Practice Questions