Courseiva

AWS Certified Solutions Architect - Associate (SAA-C03) — Questions 1–75

149 questions total · 2pages · All types, answers revealed

Page 1 of 2

Page 2
1
Multi-Selectmedium

An application requires extremely high I/O performance for temporary data processing that can be lost if the instance fails. The architect is considering using EC2 Instance Store. Which TWO statements correctly describe the performance and characteristics of Instance Store volumes?

Select 2 answers
A.Data is preserved when the instance is stopped and started.
B.Instance store provides higher I/O performance compared to EBS.
C.Volumes can be detached and reattached to different instances.
D.Instance store is ideal for swap space and temp databases.
E.Storage capacity can be increased without stopping the instance.
AnswersB, D

Because instance store volumes are physically attached to the host hardware, they avoid the network latency associated with EBS. This results in very high IOPS and low latency, making them perfect for high-performance computing tasks that require rapid access to temporary datasets.

Why this answer

EC2 Instance Store provides high-performance, local block-level storage that is physically attached to the host computer. This makes it ideal for temporary storage of information that changes frequently, such as buffers, caches, and scratch space. Architects must account for its ephemeral nature while leveraging its superior I/O capabilities for high-performance workloads.

Exam trap

Candidates mistakenly believe Instance Store is persistent. Because it is ephemeral, any data stored there is lost if the instance is stopped or terminated, which is a critical design risk.

2
MCQmedium

A developer needs to access an Amazon RDS database from an EC2 instance within a private subnet. The database must only accept traffic from the instance. Which security configuration is most appropriate?

A.Configure the RDS security group to allow inbound traffic from 0.0.0.0/0 on the database port.
B.Configure the RDS security group to allow inbound traffic from the EC2 instance security group ID.
C.Configure the RDS security group to allow inbound traffic from the database's own IP address.
D.Configure the RDS security group to allow inbound traffic from the private IP of the EC2 instance.
AnswerB

Referencing the EC2 security group ID is a best practice for internal VPC communication. It ensures that any instance associated with that security group can connect to the database. This approach is highly dynamic, as it automatically handles instance IP changes and maintains a secure, restricted network path.

Why this answer

Configuring the RDS Security Group to allow inbound traffic on the database port exclusively from the security group ID associated with the EC2 instance follows the principle of least privilege. This stateful configuration ensures that only authorized resources can communicate with the database, significantly reducing the attack surface. By referencing the security group ID instead of an IP address, the architecture remains resilient to dynamic IP changes.

Exam trap

Candidates often suggest using the EC2 instance's private IP address in the RDS security group. This is brittle because IP addresses change when instances are stopped or terminated.

3
Multi-Selecthard

A company is designing a high-throughput, fault-tolerant payment processing system running on Amazon EC2 instances across multiple Availability Zones. The architecture must withstand the sudden failure of any single AZ without dropping active database transactions or corrupting state. Which TWO design practices should the solutions architect implement?

Select 2 answers
A.Deploy an Amazon Aurora database cluster configured across multiple Availability Zones with an automatic failover replica.
B.Store application state files on a single Amazon EBS General Purpose SSD attached to the primary EC2 instance.
C.Configure an Amazon Route 53 latency-based routing policy to direct user traffic directly to EC2 instances in each zone.
D.Distribute Amazon EC2 instances across an Auto Scaling group configured with subnets spanning at least three Availability Zones.
E.Pin all payment processing worker threads to a single static EC2 instance to simplify debugging and transaction logging.
AnswersA, D

Amazon Aurora automatically replicates storage across three Availability Zones and promotes a read replica to primary within seconds if the primary instance fails. This prevents database downtime and protects against data corruption during infrastructure failures.

Why this answer

Deploying the EC2 instances across an Auto Scaling group spanning multiple Availability Zones ensures compute capacity automatically rebalances during failures. Utilizing Amazon Aurora Multi-AZ deployments provides high availability and automatic failover for relational databases. Together, these practices protect both the compute and data tiers from localized outages.

Exam trap

Candidates select Multi-AZ RDS instances instead of Aurora clusters, missing the specific requirement for high-throughput payment processing systems running across multiple Availability Zones with automatic failover.

4
MCQhard

Refer to the exhibit. An S3 bucket contains millions of small log files. The requirements state that data must be moved to a cheaper storage class after 30 days. The exhibit shows a lifecycle policy. Why might this configuration be sub-optimal for cost?

A.Intelligent-Tiering is only supported for objects larger than 128 KB.
B.The lifecycle rule should use S3 Glacier Deep Archive instead of Intelligent-Tiering.
C.Monitoring fees for Intelligent-Tiering may outweigh savings for millions of small files.
D.The prefix filter is too broad and will include active logs.
AnswerC

S3 Intelligent-Tiering charges a small monthly monitoring and automation fee per object. When applied to millions of tiny log files, these fees aggregate significantly. If the access patterns are predictable, using a different storage class like S3 Standard-IA avoids these per-object monitoring costs, resulting in lower total expenditure.

Why this answer

S3 Intelligent-Tiering charges a per-object monitoring and automation fee (currently $0.0025 per 1,000 objects per month) on top of storage costs. With millions of small log files, this monitoring overhead can easily exceed the storage savings from automatic tier transitions, making it economically sub-optimal compared to a simple lifecycle transition rule to Standard-IA or Glacier.

Exam trap

SAA-C03 often tests the misconception that Intelligent-Tiering is a universal cost-saver, when in fact its per-object monitoring fee makes it uneconomical for large volumes of small objects.

How to eliminate wrong answers

Option A is wrong because Intelligent-Tiering has no 128 KB minimum object size — objects under 128 KB are simply not auto-tiered and remain in the Frequent Access tier, but they are still monitored and billed. Option B is wrong because Glacier Deep Archive has a 180-day minimum storage duration and 12-hour retrieval, which is inappropriate for logs needing access after only 30 days, and it does not address the monitoring-fee issue. Option D is wrong because the prefix filter scope is unrelated to the cost problem described; the question is about per-object monitoring fees, not which objects are included.

5
MCQmedium

An application requires a high-throughput, low-latency shared file system for a Linux-based HPC cluster. Which AWS service should be used?

A.Amazon EFS.
B.Amazon EBS Provisioned IOPS.
C.Amazon FSx for Lustre.
D.Amazon S3 with S3 Select.
AnswerC

FSx for Lustre is built for high-performance computing and provides the sub-millisecond latencies and high throughput needed by HPC clusters. Its parallel file system architecture allows multiple compute nodes to read and write large datasets concurrently, making it the industry standard for HPC workloads running on AWS cloud infrastructure.

Why this answer

Amazon FSx for Lustre is a fully managed, high-performance file system optimized for compute-intensive workloads like HPC, machine learning, and media processing. It provides sub-millisecond latencies, millions of IOPS, and hundreds of gigabytes per second of throughput, making it ideal for Linux-based HPC clusters that require a shared, POSIX-compliant file system. Unlike general-purpose file systems, Lustre is designed for parallel access from many compute nodes simultaneously, which is essential for HPC applications.

Exam trap

SAA-C03 often tests the misconception that Amazon EFS is suitable for all shared file system needs, but candidates must recognize that HPC workloads requiring extreme throughput and low latency specifically demand FSx for Lustre.

How to eliminate wrong answers

Option A is wrong because Amazon EFS is a general-purpose, elastic file system that provides high availability and durability but is not optimized for the extreme throughput and low-latency requirements of HPC; its performance is limited compared to Lustre. Option B is wrong because Amazon EBS Provisioned IOPS is a block storage service for single EC2 instances, not a shared file system, and cannot be concurrently attached to multiple Linux nodes in a cluster (except with Multi-Attach on io1/io2, but that's limited to a single AZ and not designed for HPC-scale sharing). Option D is wrong because Amazon S3 with S3 Select is an object storage service with query capabilities, not a POSIX-compliant file system; it introduces higher latency and is not suitable for low-latency, high-throughput shared file system needs of HPC.

6
MCQmedium

A high-traffic application uses an Application Load Balancer (ALB) and an Auto Scaling group (ASG). During peak hours, some EC2 instances fail, but the ASG does not replace them immediately because the instances are still in a 'running' state despite the application being unresponsive. How should the architect fix this?

A.Change the ASG health check type from EC2 to ELB.
B.Increase the ASG health check grace period to 600 seconds.
C.Create a CloudWatch alarm for high CPU usage to trigger replacement.
D.Configure a Lambda function to manually terminate unresponsive instances.
AnswerA

The ELB health check type ensures that the Auto Scaling group considers an instance unhealthy if the Application Load Balancer determines the application is not responding correctly. This provides a more accurate view of application health than basic EC2 status checks, which only monitor the underlying hardware and network connectivity of the virtual machine.

Why this answer

By default, an Auto Scaling group uses EC2 health checks, which only detect instance-level failures (e.g., stopped or terminated instances) and not application-level unresponsiveness. Changing the health check type to ELB makes the ASG rely on the load balancer's health checks, which actively probe the application on each instance; if an instance fails the ELB health check, the ASG marks it unhealthy and replaces it. This directly resolves the issue of running-but-unresponsive instances.

Exam trap

SAA-C03 often tests the difference between EC2 and ELB health check types, and candidates mistakenly believe that increasing the grace period or adding CloudWatch alarms will make the ASG replace unresponsive instances.

How to eliminate wrong answers

Option B is wrong because increasing the health check grace period only delays when health checks begin after launch; it does not change the health check type, so unresponsive instances would still be considered healthy by EC2 checks. Option C is wrong because a CloudWatch alarm on CPU usage does not automatically trigger instance replacement unless paired with a scaling policy, and high CPU may not correlate with unresponsiveness; it is an indirect and unreliable fix. Option D is wrong because a Lambda function manually terminating instances is an operational workaround, not a native ASG health management solution, and it adds unnecessary complexity and latency.

7
MCQmedium

Refer to the exhibit. A security administrator is reviewing a CloudTrail log entry for an 'Access Denied' error. The user 'Alice' is trying to upload a file to an S3 bucket. Alice has an IAM policy that allows 's3:PutObject' on all resources. What is the most likely cause of this error?

A.The S3 bucket has a bucket policy with an explicit Deny for Alice or the action.
B.Alice is not using an encrypted connection (HTTPS) to upload the file.
C.The S3 bucket is located in a different region than the IAM user.
D.Alice's IAM user is missing the 's3:ListBucket' permission.
AnswerA

Even though Alice has an identity-based policy allowing 's3:PutObject', an explicit 'Deny' in a resource-based policy (like a bucket policy) always overrides any 'Allow'. This is a common cause of Access Denied errors when multiple layers of security policies are applied to a resource.

Why this answer

In AWS, access is determined by the intersection of all applicable policies. Even if Alice has an IAM policy allowing the action, an 'Access Denied' error can occur if there is an explicit 'Deny' in a Service Control Policy (SCP), a bucket policy, or if there is a Permissions Boundary restricting her actions.

Exam trap

Candidates often assume that an IAM policy allowing an action is sufficient. They forget that the final authorization decision is the intersection of IAM, SCPs, and resource-based policies like bucket policies.

8
MCQhard

A company has several AWS accounts and wants to take advantage of Savings Plans to reduce their overall compute spend. They have a mix of EC2 instances, AWS Lambda, and AWS Fargate across multiple regions. Which Savings Plan type will provide the most flexibility and cover all these services?

A.EC2 Instance Savings Plans
B.Compute Savings Plans
C.SageMaker Savings Plans
D.Regional Reserved Instances
AnswerB

Compute Savings Plans are the most flexible option. They apply to usage across EC2 (any family, any region), Fargate, and Lambda. This flexibility allows the company to change their compute technology or move workloads between regions while still benefiting from the discounted rates, ensuring long-term cost optimization.

Why this answer

Compute Savings Plans offer the greatest flexibility, providing up to 66% savings compared to On-Demand prices. They apply automatically to EC2 instance usage regardless of instance family, size, AZ, region, OS, or tenancy, and uniquely, they also cover AWS Fargate and AWS Lambda, making them ideal for modern, heterogeneous architectures.

Exam trap

Candidates often select EC2 Instance Savings Plans. These only cover EC2 usage and will fail to provide the required coverage for Lambda and Fargate, leading to incomplete cost optimization.

9
MCQmedium

Refer to the exhibit. An administrator runs a script to identify underutilized EC2 instances. The output shows a production instance that has been running for 30 days. Which action would most effectively reduce costs while maintaining application stability?

A.Change the instance type to a smaller size in the same family, such as m5.large.
B.Convert the instance to a Spot Instance to save up to 90%.
C.Switch the instance to a T3 instance type with Unlimited mode enabled.
D.Purchase a Compute Savings Plan for the current m5.4xlarge instance.
AnswerA

The instance is significantly over-provisioned, as shown by the low peak CPU and memory metrics. Scaling down to a smaller instance type within the same family reduces the hourly cost linearly. This right-sizing approach ensures that the company is not paying for unused compute capacity while still meeting performance needs.

Why this answer

The instance is described as underutilized, meaning its CPU and memory usage are low. Changing the instance type to a smaller size in the same family (e.g., from m5.4xlarge to m5.large) reduces cost while maintaining the same architecture and compatibility, and the application should still perform adequately if it was underutilized. This is the most effective cost reduction without compromising stability.

Exam trap

SAA-C03 often tests the temptation to use Spot Instances for cost savings without considering their unsuitability for production workloads that require stability, or to purchase Savings Plans without first rightsizing.

How to eliminate wrong answers

Option B is wrong because converting a production instance to a Spot Instance can save up to 90% but Spot Instances can be interrupted with a two-minute warning, which is not suitable for a production instance that must maintain stability. Option C is wrong because switching to a T3 instance with Unlimited mode may reduce baseline cost but Unlimited mode charges extra for CPU credits beyond the baseline, and T3 instances are burstable, which may not be appropriate for a production workload with steady or unpredictable demand; it also doesn't directly address underutilization as cleanly as downsizing within the same family. Option D is wrong because purchasing a Compute Savings Plan for the current m5.4xlarge instance locks in a commitment for a larger instance than needed, so it does not reduce cost as effectively as downsizing first; Savings Plans are a pricing model, not a rightsizing action.

10
MCQhard

Refer to the exhibit. A company wants to optimize the performance and security of data transfers between their EC2 instances and an S3 bucket named 'my-app-data'. Which architectural benefit is primarily achieved by implementing the policy shown in the exhibit?

A.It enables S3 Transfer Acceleration for faster global uploads.
B.It ensures traffic remains on the private AWS network, reducing latency.
C.It provides cross-region replication for high availability of data.
D.It allows public access to the bucket for faster content delivery.
AnswerB

By specifying a SourceVpce condition, the policy ensures that only requests coming through the designated VPC Gateway Endpoint are allowed. This configuration routes S3 traffic over the AWS private network backbone rather than the public internet. This results in more consistent performance, lower latency, and reduced data transfer costs for internal AWS traffic.

Why this answer

The policy shown is a VPC endpoint policy (or an S3 bucket policy restricting access to a VPC endpoint), which forces traffic between EC2 and S3 to traverse the AWS private backbone via a Gateway or Interface VPC Endpoint instead of the public internet. This keeps traffic on the private AWS network, reducing latency, avoiding NAT gateway data-processing charges, and improving security posture.

Exam trap

The trap is confusing VPC endpoint policies with S3 Transfer Acceleration or replication — all three mention S3 and performance, but only the endpoint keeps traffic on the private AWS network.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration uses CloudFront edge locations and is enabled via bucket-level configuration (or the accelerate endpoint), not via a VPC endpoint policy. Option C is wrong because cross-region replication is configured with S3 Replication rules (CRR/SRR) and has nothing to do with endpoint policies. Option D is wrong because the policy restricts access to the private endpoint — it does the opposite of enabling public access, and public access would increase, not reduce, latency and risk.

11
MCQmedium

A company is experiencing unauthorized network traffic in their VPC. They need to inspect traffic patterns between subnets to identify the source of the traffic. Which tool should they use?

A.AWS CloudTrail.
B.AWS Config.
C.VPC Flow Logs.
D.AWS Trusted Advisor.
AnswerC

VPC Flow Logs provide a detailed view of all network traffic flowing through the VPC's network interfaces. This allows security teams to monitor for anomalous patterns, identify unauthorized traffic, and verify that security groups and NACLs are behaving as expected, making it the correct tool for this specific scenario.

Why this answer

VPC Flow Logs capture information about the IP traffic going to and from network interfaces in the VPC. By analyzing these logs, administrators can identify blocked connections, traffic spikes, or unusual destination patterns. This data is essential for security auditing, troubleshooting connectivity issues, and detecting potential malicious activity within the network perimeter, providing the visibility needed to strengthen security policies and Network ACLs.

Exam trap

Candidates often confuse VPC Flow Logs with AWS CloudTrail. CloudTrail logs API calls (management plane), whereas VPC Flow Logs capture network traffic metadata (data plane).

12
MCQmedium

A web application runs on Amazon EC2 instances managed by an Auto Scaling group across three Availability Zones behind an Application Load Balancer. The application performs heavy computations that consume high CPU resources. Users report intermittent 504 Gateway Timeouts during peak hours. The solutions architect notices that newly launched instances take several minutes to bootstrap before they can serve traffic. How should the architect resolve this issue?

A.Configure an Amazon SQS queue in front of the EC2 instances to offload computational tasks asynchronously.
B.Implement pre-baked Amazon Machine Images (AMIs) with application code pre-installed and configure an Auto Scaling health check grace period.
C.Switch the load balancer from an Application Load Balancer to a Network Load Balancer for faster TCP packet routing.
D.Decrease the Auto Scaling group health check grace period to zero so failing instances are replaced immediately.
AnswerB

Pre-baked AMIs remove the multi-minute bootstrap, so new instances serve traffic almost immediately and scale out before peak load causes 504s. The health check grace period prevents the Auto Scaling group terminating instances that are still initialising, avoiding premature replacement.

Why this answer

Pre-baked AMIs eliminate the lengthy bootstrap process by having the application code and dependencies already installed, so new instances can serve traffic almost immediately. Configuring an appropriate health check grace period ensures the ASG does not terminate instances prematurely during any remaining startup time, while allowing ELB health checks to replace truly unhealthy instances. This combination reduces the window where the ASG is scaling out but new instances are not yet ready, mitigating 504 errors.

Exam trap

SAA-C03 often tests whether candidates understand that 504 errors during scaling are caused by slow instance readiness, and candidates incorrectly choose load balancer changes or SQS decoupling instead of reducing bootstrap time.

How to eliminate wrong answers

Option A is wrong because adding an SQS queue decouples and offloads tasks but does not address the root cause of slow instance bootstrapping or the 504 timeouts caused by insufficient capacity during peak; it changes the architecture rather than fixing the scaling latency. Option C is wrong because switching to a Network Load Balancer (NLB) improves TCP performance but does not reduce instance bootstrap time; 504 errors are HTTP-level timeouts from the ALB, and NLB operates at layer 4 without HTTP awareness, so it would not resolve application-level timeouts. Option D is wrong because decreasing the health check grace period to zero would cause the ASG to terminate instances before they finish bootstrapping, leading to a continuous cycle of instance replacement and worsening the issue.

13
MCQmedium

A security team needs to identify and protect sensitive data, such as credit card numbers and passport IDs, that may be stored across hundreds of S3 buckets in multiple AWS accounts. Which service should they use to automate this discovery process?

A.Amazon GuardDuty to monitor S3 data plane events for suspicious activity.
B.Amazon Macie to scan S3 buckets for personally identifiable information (PII).
C.AWS Glue to crawl S3 buckets and catalog the data types found in the files.
D.Amazon Inspector to perform deep packet inspection on data uploaded to S3.
AnswerB

Amazon Macie automatically discovers, classifies, and protects sensitive data at scale. It uses built-in sensitive data identifiers for common PII types and allows for custom identifiers. This makes it the ideal tool for organizations needing to audit their S3 storage for regulatory compliance and data privacy.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in S3. It provides a centralized view of where sensitive data resides and how it is being accessed or moved, which is critical for compliance.

Exam trap

Candidates often select AWS Config or CloudTrail. While these audit configurations and API calls, they do not inspect the actual content of S3 objects for sensitive PII like Macie does.

14
Multi-Selecthard

A solutions architect is reviewing the architecture of a large VPC. Currently, thousands of EC2 instances in private subnets transfer several terabytes of data daily to Amazon S3 through a NAT Gateway. The NAT Gateway costs have become prohibitively high. Which TWO changes will reduce these costs?

Select 2 answers
A.Create a Gateway VPC Endpoint for Amazon S3.
B.Replace the NAT Gateway with a NAT Instance.
C.Update the route table to direct S3 traffic through the Gateway Endpoint.
D.Move the EC2 instances to public subnets.
E.Increase the number of NAT Gateways across all Availability Zones.
AnswersA, C

Gateway Endpoints for S3 are provided at no additional cost and do not incur data processing charges. By routing S3 traffic through the endpoint instead of the NAT Gateway, the company eliminates the per-GB processing fee for all data transfers to and from S3, leading to massive cost savings.

Why this answer

NAT Gateways charge both an hourly rate and a per-GB data processing fee, which can become expensive for high-volume data transfers. S3 Gateway Endpoints are free and allow traffic to stay within the AWS network, bypassing the NAT Gateway entirely. This significantly reduces data processing costs for S3-bound traffic from private subnets.

Exam trap

Candidates often choose Interface Endpoints (PrivateLink) instead of Gateway Endpoints. While both connect to S3, Interface Endpoints incur hourly and per-GB data processing fees, failing to solve the cost-prohibitive NAT Gateway issue.

15
MCQmedium

A video transcoding application runs on EC2 instances. The processing is highly CPU-intensive and can be interrupted if the job is resumed later. Which compute strategy offers the best cost-performance balance?

A.Use Reserved Instances for the entire workload.
B.Use On-Demand instances for all processing tasks.
C.Use Spot Instances for the transcoding tasks.
D.Use Dedicated Hosts for the transcoding tasks.
AnswerC

Spot Instances are ideal for fault-tolerant, batch-oriented workloads like video transcoding. They offer significant cost savings, and since the application can handle interruptions by resuming jobs, the risk associated with Spot capacity reclamation is mitigated, resulting in an optimal high-performance and low-cost architectural design for this specific use case.

Why this answer

Spot Instances provide up to a 90% discount over On-Demand pricing. Since the transcoding workload is fault-tolerant and capable of resuming work, it is a perfect candidate for Spot Instances. By using an Auto Scaling group with a mix of Spot and On-Demand instances, the application can achieve high performance at a fraction of the cost, utilizing cheaper capacity while maintaining a safety net of On-Demand instances.

Exam trap

Candidates might choose On-Demand instances out of concern for interruption, missing the specific clue that the transcoding workload is fault-tolerant and capable of resuming, making it ideal for cheap Spot Instances.

16
Multi-Selecthard

A company is building a zero-trust architecture for its internal microservices running on Amazon EKS. Which THREE steps should the solutions architect take to ensure secure, least-privilege communication between services? (Select THREE)

Select 3 answers
A.Assign IAM Roles to individual Kubernetes Service Accounts (IRSA).
B.Use AWS App Mesh to enforce Mutual TLS (mTLS) between microservices.
C.Configure Security Groups for Pods to restrict network traffic between services.
D.Place all microservices in a single public subnet to simplify routing.
E.Disable VPC Flow Logs to reduce latency between microservices.
AnswersA, B, C

IRSA allows you to associate an IAM role with a Kubernetes service account. This provides each pod with the minimum necessary AWS permissions to access services like S3 or DynamoDB, rather than giving permissions to the entire worker node, adhering to the principle of least privilege.

Why this answer

Option A is correct because IAM Roles for Service Accounts (IRSA) lets each Kubernetes Service Account assume a distinct IAM role via the EKS OIDC provider, so individual microservices receive only the AWS permissions they need, which is a core least-privilege control in a zero-trust model. Option B is correct because AWS App Mesh enforces mutual TLS (mTLS) between microservices, providing cryptographic identity verification and encrypted service-to-service traffic so that no service is trusted merely by network location. Option C is correct because Security Groups for Pods (using the VPC CNI and ENI trunking) applies EC2 security group rules directly to pod ENIs, enabling fine-grained, least-privilege network segmentation between specific services.

Option D is not appropriate because placing all microservices in a single public subnet exposes them to the internet and removes the network segmentation that zero-trust requires. Option E is not appropriate because disabling VPC Flow Logs reduces visibility and auditability of traffic, which is essential for detecting and investigating lateral movement in a zero-trust architecture.

Exam trap

SAA-C03 often tests the misconception that a single public subnet or disabling logging improves security or performance, when in fact zero-trust requires segmentation, encryption, and monitoring.

17
Multi-Selecthard

An organization wants to identify and eliminate waste in their AWS account. They are specifically looking for idle resources that are still incurring charges. Which THREE AWS tools or features can help identify these cost-optimization opportunities?

Select 3 answers
A.AWS Trusted Advisor.
B.AWS Compute Optimizer.
C.AWS Cost Explorer Rightsizing Recommendations.
D.AWS CloudTrail.
E.Amazon Inspector.
AnswersA, B, C

Trusted Advisor includes a 'Cost Optimization' pillar that specifically flags idle resources, such as unassociated Elastic IP addresses, underutilized Amazon EBS volumes, and idle Amazon RDS instances. It provides a quick dashboard view of immediate savings that can be achieved by terminating or resizing these resources.

Why this answer

AWS Trusted Advisor (A) is correct because its Cost Optimization checks specifically flag idle or underutilized resources that still incur charges, such as unassociated Elastic IP addresses, idle load balancers, and underutilized Amazon EC2 instances. AWS Compute Optimizer (B) is correct because it analyzes CloudWatch metrics to generate recommendations for over-provisioned resources, including idle or underutilized EC2 instances, Auto Scaling groups, EBS volumes, and Lambda functions, directly surfacing cost-optimization opportunities. AWS Cost Explorer Rightsizing Recommendations (C) is correct because it uses historical utilization data to recommend resizing or terminating idle/underutilized EC2 instances, helping eliminate waste from over-provisioned compute.

AWS CloudTrail (D) is not correct because it records API activity for auditing, security, and compliance, not for identifying idle resources or cost waste. Amazon Inspector (E) is not correct because it is a vulnerability management service that scans workloads for security exposures, not a cost-optimization or idle-resource detection tool.

Exam trap

SAA-C03 often tests the distinction between cost-optimization tools and security/audit tools — candidates must recognize that CloudTrail (audit) and Inspector (vulnerability scanning) are security services that do not identify idle or over-provisioned resources.

18
MCQmedium

A company is migrating a web application to AWS. The application relies on session state. Which approach is the most scalable and performant for managing sessions?

A.Store sessions in a local file on the web server.
B.Use Amazon ElastiCache (Redis) to store session data.
C.Store sessions in a relational database like RDS.
D.Use sticky sessions on the Application Load Balancer.
AnswerB

ElastiCache provides sub-millisecond latency for session data access. By offloading session state to an external cache, the application servers become stateless, which allows for seamless horizontal scaling. This architecture is both highly performant and the industry-standard approach for managing sessions in distributed, high-scale applications.

Why this answer

Amazon ElastiCache for Redis is purpose-built for sub-millisecond, in-memory session storage, so any EC2 instance behind an Auto Scaling group or load balancer can read/write the same session state without shared-disk contention. This decouples session state from individual compute nodes, allowing horizontal scaling and eliminating the need for sticky routing. Redis also supports TTL-based expiration and optional replication/Multi-AZ for durability.

Exam trap

SAA-C03 often tests the misconception that sticky sessions or a shared RDS table are sufficient for scalable session management, when the exam is really looking for an in-memory, decoupled session store like ElastiCache.

How to eliminate wrong answers

Option A is wrong because local file sessions bind the user to a single web server, so any instance replacement or scale-out event loses the session and breaks horizontal scalability. Option C is wrong because RDS-backed sessions add disk I/O latency and connection-pool pressure, making it far slower and less scalable than an in-memory store for high-throughput session reads. Option D is wrong because sticky sessions only pin a client to one target; they do not share state, so an instance failure still drops the session and load distribution becomes uneven.

19
MCQmedium

A company is migrating a legacy application to AWS. The application requires a relational database with very infrequent and unpredictable usage—sometimes it is not used for days, and then it sees a burst of activity for an hour. Which database configuration is most cost-effective?

A.Amazon RDS for MySQL on a T3-medium instance.
B.Amazon Aurora Serverless.
C.Amazon Aurora with a Reserved Instance.
D.Amazon RDS with Multi-AZ enabled.
AnswerB

Aurora Serverless is the most cost-effective choice because it scales to zero capacity (in v1) or a very low baseline (in v2) when there is no traffic. You are only billed for Aurora Capacity Units (ACUs) when the database is actually processing requests, perfectly aligning costs with the 'unpredictable' usage pattern.

Why this answer

Amazon Aurora Serverless is designed for workloads with intermittent, unpredictable, or infrequent usage. It automatically starts up, shuts down, and scales capacity based on application demand, so you only pay for the database capacity consumed during active periods. For an application that is idle for days and then bursts for an hour, this eliminates the cost of provisioning a always-on instance, making it the most cost-effective relational database configuration.

Exam trap

SAA-C03 often tests the misconception that any RDS or Aurora option is equally cost-effective for intermittent workloads, when in fact only Aurora Serverless automatically scales down or pauses to avoid charges during idle periods.

How to eliminate wrong answers

Option A is wrong because an Amazon RDS for MySQL T3-medium instance runs continuously and bills per hour regardless of whether the application is using it, so idle days still incur full instance and storage costs. Option C is wrong because a Reserved Instance requires a one- or three-year commitment and is cost-effective only for steady-state, predictable workloads; it would charge for reserved capacity even during long idle periods. Option D is wrong because Multi-AZ is a high-availability feature that duplicates the database in a standby Availability Zone, roughly doubling the cost, and it does nothing to address infrequent or unpredictable usage patterns.

20
MCQeasy

An application running on an Amazon EC2 instance needs to securely access data in an Amazon DynamoDB table. What is the most secure way to provide the application with the necessary permissions?

A.Store IAM user credentials in a configuration file on the EC2 instance.
B.Create an IAM role with the required permissions and attach it to the EC2 instance profile.
C.Pass the Access Key and Secret Key as environment variables when starting the application.
D.Embed the credentials directly into the application source code.
AnswerB

Attaching an IAM role to an EC2 instance allows the application to use temporary security credentials provided by the Instance Metadata Service. This eliminates the need to hardcode or store long-term keys, adhering to the principle of least privilege and significantly improving the overall security posture.

Why this answer

Option B is correct because IAM roles attached to an EC2 instance profile provide temporary, automatically rotated credentials to the instance via the Instance Metadata Service (IMDS). The application (or AWS SDK) retrieves these credentials without any hardcoded secrets, and permissions are managed centrally through IAM policies. This eliminates the risk of long-term credential leakage and follows AWS best practices for least privilege.

Exam trap

SAA-C03 often tests the misconception that storing credentials in environment variables or configuration files is acceptable for security, when in fact IAM roles are the only secure, AWS-recommended method for EC2-to-AWS-service authentication.

How to eliminate wrong answers

Option A is wrong because storing IAM user credentials in a configuration file creates long-lived secrets that can be accidentally committed to version control, copied, or stolen, and they require manual rotation. Option C is wrong because environment variables are visible in process listings, crash dumps, and logs, and they still use long-term credentials that must be rotated manually. Option D is wrong because embedding credentials in source code is the least secure method—secrets become part of the codebase, are hard to rotate, and are easily exposed through repositories or build artifacts.

21
MCQmedium

A financial services firm must store transaction logs in Amazon S3 for seven years to meet regulatory requirements. The logs must be protected against any modification or deletion by any user, including the root user, during this period. Which S3 feature should be implemented?

A.Enable S3 Versioning on the bucket to keep a history of all changes made to the logs.
B.Use S3 Glacier Deep Archive as the storage class for the logs with a vault lock policy.
C.Enable S3 Object Lock in compliance mode with a retention period of seven years.
D.Configure AWS Backup to take daily snapshots of the S3 bucket and store them in a secure vault.
AnswerC

S3 Object Lock in compliance mode ensures that an object version cannot be overwritten or deleted by any user, including the root user in the AWS account. This mode is essential for meeting regulatory requirements where data must be preserved and remain unalterable for a specified duration without any exceptions.

Why this answer

S3 Object Lock in compliance mode prevents any user, including the root user, from overwriting or deleting an object version for a specified retention period. This meets the requirement of protecting logs from modification or deletion for seven years. Compliance mode is the strictest mode and cannot be overridden, ensuring regulatory compliance.

Exam trap

SAA-C03 often tests the misconception that versioning or backups provide immutability, but only Object Lock in compliance mode guarantees protection against root user deletion.

How to eliminate wrong answers

Option A is wrong because S3 Versioning alone does not prevent deletion; users can still delete object versions or the bucket, and versioning only keeps a history. Option B is wrong because S3 Glacier Deep Archive with a vault lock policy is for Glacier vaults, not S3 buckets; S3 Glacier Vault Lock is a separate feature for Glacier vaults, not S3 objects. Option D is wrong because AWS Backup snapshots do not prevent deletion of the original S3 objects; they provide a backup copy but do not enforce immutability on the source bucket.

22
Multi-Selecthard

A financial application stores data in Amazon Aurora. The architecture must survive a regional outage. Which TWO steps should the architect take to meet this requirement?

Select 2 answers
A.Enable Aurora Multi-AZ deployment in the primary region.
B.Create an Aurora Global Database with a secondary region.
C.Schedule daily Amazon RDS snapshots and copy them to an S3 bucket in the same region.
D.Promote the secondary region to primary if the primary region becomes unavailable.
E.Enable Performance Insights on all Aurora instances.
AnswersB, D

Aurora Global Database is specifically designed for regional disaster recovery. It uses dedicated infrastructure to replicate data to secondary regions with minimal latency, typically under one second. This configuration allows for rapid promotion of a secondary region to read-write status in the event of a primary regional failure.

Why this answer

Option B is correct because an Aurora Global Database replicates data to a secondary region with typical cross-region replication latency under one second, which is the AWS-recommended design for surviving a full regional outage. Option D is correct because, during a regional failure, the secondary region's Aurora cluster must be promoted (via the managed planned or unplanned failover) to become a standalone read/write primary, restoring write capability in the surviving region. Option A is not sufficient because Aurora Multi-AZ (Aurora Replicas across AZs) only protects against an Availability Zone failure within a single region, not a regional outage.

Option C is wrong because RDS snapshots copied to an S3 bucket in the same region are also lost if that region fails, and daily snapshots give a poor RPO. Option E is irrelevant because Performance Insights is a monitoring/performance-tuning feature and provides no disaster-recovery capability.

Exam trap

The trap is confusing Aurora Multi-AZ (intra-region HA) with Aurora Global Database (cross-region DR); candidates often pick Multi-AZ thinking it covers regional outages, but it only protects against AZ failures.

23
Multi-Selectmedium

A company is using Amazon EBS volumes for their EC2 instances. The current volumes are General Purpose SSD (gp2). The company wants to reduce costs without losing performance, and in some cases, they need more control over IOPS without increasing storage size. Which TWO steps should they take?

Select 2 answers
A.Migrate from gp2 volumes to gp3 volumes.
B.Use Provisioned IOPS SSD (io2) for all volumes.
C.Independently provision IOPS and throughput using gp3.
D.Convert the EBS volumes to Cold HDD (sc1).
E.Take frequent snapshots of gp2 volumes and delete the originals.
AnswersA, C

Moving from gp2 to gp3 is a direct cost-saving measure as gp3 is priced 20% lower per GB. It provides a baseline performance of 3,000 IOPS and 125 MB/s for free, regardless of volume size, which often meets or exceeds the performance of small gp2 volumes at a lower price.

Why this answer

Amazon EBS gp3 volumes offer a 20% lower price per GB than gp2 volumes. Additionally, gp3 allows you to provision IOPS and throughput independently of storage capacity. This means you no longer have to 'over-provision' disk space just to get higher performance, leading to significant cost savings for IO-intensive workloads.

Exam trap

Candidates might mistakenly choose io2 (Option B) because it offers high performance, but it is significantly more expensive than gp3 and does not meet the requirement to reduce costs.

24
MCQmedium

Refer to the exhibit. A junior cloud financial analyst needs to monitor and optimize costs across the organization's AWS account. The analyst requires the ability to view historical cost data and check how effectively Reserved Instances and Savings Plans are being used. Which AWS service is the analyst most likely using with this IAM policy?

A.AWS Budgets
B.AWS Trusted Advisor
C.AWS Cost Explorer
D.AWS Compute Optimizer
AnswerC

AWS Cost Explorer is the service that enables users to query cost and usage data programmatically or via the console. The permissions listed in the exhibit allow the analyst to retrieve granular data about spending and the efficiency of their commitment-based pricing models, which is the core functionality of Cost Explorer.

Why this answer

AWS Cost Explorer provides historical cost and usage data, forecasting, and — critically — Reserved Instance (RI) and Savings Plans utilization and coverage reports. The IAM policy granting access to Cost Explorer APIs (ce:GetCostAndUsage, ce:GetReservationUtilization, ce:GetSavingsPlansUtilization) confirms this is the service in use.

Exam trap

The trap is that AWS Budgets and Trusted Advisor both touch on cost, so candidates pick them — but only Cost Explorer provides historical cost data plus RI/Savings Plans utilization and coverage reports, which the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because AWS Budgets is for setting spending thresholds and alerts, not for analyzing historical cost trends or RI/Savings Plans utilization. Option B is wrong because Trusted Advisor provides best-practice checks (including cost optimization recommendations) but does not offer detailed historical cost analysis or RI/SP utilization reporting. Option D is wrong because AWS Compute Optimizer recommends right-sizing for compute resources based on utilization metrics, but it does not provide historical cost data or RI/Savings Plans coverage analysis.

25
MCQhard

A company hosts a monolithic application on EC2. They want to move to a microservices architecture to improve fault isolation. Which approach is best?

A.Increase the size of the existing EC2 instances.
B.Use a load balancer to split traffic between two monolithic instances.
C.Decompose the monolith into independent services using containers.
D.Move the entire application code to a single Lambda function.
AnswerC

Decomposing the monolith into independent services using containers provides the best fault isolation. If one service fails, the other services can continue to operate, limiting the impact of the failure. Using containers also allows for faster deployment, better resource utilization, and easier management, all of which contribute to a more resilient overall architecture.

Why this answer

Decomposing the monolith into independent services running in containers gives each service its own lifecycle, scaling, and failure domain, which is exactly what improves fault isolation. Containers package each service with its dependencies and can be orchestrated by ECS or EKS for resilience.

Exam trap

SAA-C03 often tests the confusion between high availability (multiple copies of the same monolith) and fault isolation (independent services), tempting candidates to pick load balancing or vertical scaling.

How to eliminate wrong answers

Option A is wrong because vertically scaling EC2 instances keeps the monolith intact and does nothing for fault isolation — a failure in one component still takes down the whole application. Option B is wrong because running two copies of the same monolith behind a load balancer improves availability but not fault isolation, since both instances share the same monolithic failure modes. Option D is wrong because moving the entire application into a single Lambda function preserves the monolith and adds Lambda limits (15-minute timeout, memory caps) without any service decomposition.

26
MCQmedium

A company is designing a global application. They need to replicate 1 TB of data monthly between two AWS Regions. What is the most cost-effective way to minimize data transfer costs?

A.Use AWS Direct Connect to link the two regions together.
B.Compress the data before transferring it between regions.
C.Use an Amazon CloudFront distribution to cache data between regions.
D.Deploy a VPC Peering connection between the two regions.
AnswerB

Since inter-region data transfer is billed based on the amount of data (GB) moved across the network, reducing the size of the payload through compression directly reduces the cost. This is a simple, software-based optimization that requires no additional AWS infrastructure and scales effectively with the volume of data.

Why this answer

Compressing data before transferring it between regions reduces the volume of data transferred, thereby lowering data transfer costs. AWS charges for data transfer out from a region, so reducing the number of bytes transferred directly reduces costs. Compression is a simple and effective method to minimize data transfer costs for large datasets.

Exam trap

SAA-C03 often tests the misconception that VPC Peering or Direct Connect reduce inter-region data transfer costs, but they do not; only reducing the data volume (e.g., via compression) directly lowers costs.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not between regions; it does not reduce inter-region data transfer costs and is more expensive. Option C is wrong because CloudFront is a content delivery network that caches data at edge locations; it does not reduce the cost of transferring data between regions, and may even increase costs if used for inter-region transfer. Option D is wrong because VPC Peering between regions still incurs standard inter-region data transfer charges; it does not reduce costs.

27
Multi-Selecthard

A company is running an Amazon RDS for MySQL database that experiences predictable, steady traffic during business hours and very low traffic at night. They want to reduce costs without compromising performance. Which TWO steps should the architect take? (Select TWO.)

Select 2 answers
A.Purchase Reserved Instances for the RDS DB instances.
B.Use Multi-AZ deployments for all read-only workloads.
C.Switch to an Amazon RDS Custom for MySQL instance.
D.Migrate the database to Amazon Aurora Serverless v2.
E.Enable Provisioned IOPS (PIOPS) for all storage volumes.
AnswersA, D

Reserved Instances are ideal for predictable, steady-state workloads because they offer up to 72% discount compared to On-Demand pricing. Since the company knows the database will be running during business hours for the foreseeable future, committing to a one-year or three-year term provides the most substantial baseline cost reduction.

Why this answer

Reserved Instances provide significant discounts for steady-state workloads with a long-term commitment. For the variable nature of the workload, migrating to Aurora Serverless v2 allows the database to scale capacity up and down automatically based on demand, ensuring they only pay for the resources consumed during high and low traffic periods.

Exam trap

Candidates tend to pick only one optimization strategy or select standard scaling policies, missing the dual requirement to cover both steady-state predictable costs and unpredictable variable night traffic.

28
MCQmedium

Refer to the exhibit. A security audit identifies that data is being transmitted to an S3 bucket named 'corporate-data' without encryption in transit. Which behavior does this bucket policy enforce to address this concern?

A.It denies any S3 action if the request does not use an encrypted connection (HTTPS).
B.It ensures that all objects stored in the bucket are encrypted using AES-256 server-side encryption.
C.It logs all access attempts to the bucket to identify users who are not using SSL.
D.It automatically redirects all HTTP requests to HTTPS for the specified S3 bucket.
AnswerA

The policy uses a Deny effect combined with a false condition for secure transport, which means any request not using HTTPS is blocked. This is a preventative control that ensures data is encrypted while moving between the client and S3, protecting it from interception by unauthorized parties.

Why this answer

The bucket policy denies any S3 action if the request does not use an encrypted connection (HTTPS). This is enforced by a condition like aws:SecureTransport: false, which blocks HTTP requests. This directly addresses the concern of data in transit being unencrypted.

Exam trap

SAA-C03 often tests the confusion between encryption in transit (HTTPS) and encryption at rest (SSE), tempting candidates to pick an option about server-side encryption when the question specifies 'in transit'.

How to eliminate wrong answers

Option B is wrong because the policy addresses encryption in transit, not server-side encryption at rest (AES-256). Option C is wrong because the policy denies access, not logs it; logging would require a separate logging configuration. Option D is wrong because S3 does not automatically redirect HTTP to HTTPS; the policy simply denies non-HTTPS requests.

29
MCQmedium

An architect is designing a system that must be resilient against AWS regional failure. Which AWS service is best suited to manage global DNS traffic and provide health-based routing?

A.Elastic Load Balancing (ELB).
B.Amazon Route 53.
C.AWS Direct Connect.
D.Amazon CloudFront.
AnswerB

Route 53 is the primary tool for global traffic management. Its health checks continuously monitor the status of regional endpoints. If an endpoint fails, Route 53 can update DNS records to route traffic to healthy infrastructure in other regions, providing the necessary resilience against regional-wide service interruptions.

Why this answer

Route 53 is a highly available and scalable cloud Domain Name System (DNS) web service. It provides health checks and routing policies, such as failover, latency-based, and geolocation routing. By using health checks, Route 53 can detect the failure of an endpoint in one region and automatically route traffic to a healthy endpoint in another, fulfilling the requirement for regional resilience.

Exam trap

Candidates sometimes choose Global Accelerator or CloudFront. While these provide global traffic management, Route 53 is the primary DNS-based service specifically designed for health-based routing and regional failover.

30
MCQhard

A company needs a Disaster Recovery (DR) strategy with an RTO of 30 minutes and an RPO of 15 minutes. They want to minimize costs while having a scaled-down version of their core environment always running in a second region. Which DR strategy should they use?

A.Backup and Restore.
B.Pilot Light.
C.Warm Standby.
D.Multi-site Active-Active.
AnswerC

Warm Standby keeps a minimized version of the full environment running in the second region. This ensures that the application is always ready to handle traffic, and only needs to be scaled up to meet production loads during a failover. This strategy easily fits the 30-minute RTO and 15-minute RPO requirements while remaining cost-conscious.

Why this answer

A Warm Standby DR strategy involves running a functional but scaled-down version of the application in a separate region. This allows for a very low Recovery Time Objective (RTO) because the core infrastructure is already live. Data is replicated frequently to meet the Recovery Point Objective (RPO) of 15 minutes, providing a balance between cost and speed.

Exam trap

Candidates often confuse Warm Standby with Pilot Light; they choose Pilot Light because it sounds cheaper, missing that Pilot Light's RTO is too high for a 30-minute requirement.

31
MCQmedium

An application uses Amazon DynamoDB. To ensure the application remains resilient to regional outages, what is the best approach?

A.Enable DynamoDB backups in the same region.
B.Use DynamoDB Global Tables.
C.Use AWS Database Migration Service to sync data.
D.Manually replicate data to another region every hour.
AnswerB

DynamoDB Global Tables enable multi-region, multi-active replication, allowing the database to survive a full regional failure. It provides automatic synchronization of data across multiple regions, enabling low-latency access for globally distributed users and ensuring that the application can remain operational even if one of the AWS regions experiences a complete outage.

Why this answer

DynamoDB Global Tables provide multi-region, active-active replication with automatic conflict resolution, ensuring the application can read and write to the table in any region and remain resilient to regional outages. This is the only option that offers automatic, low-latency replication across regions without manual intervention.

Exam trap

The trap is assuming that backups or manual replication provide regional resilience. Candidates often overlook that backups are region-scoped and manual replication lacks automatic failover and conflict resolution.

How to eliminate wrong answers

Option A is wrong because backups in the same region do not protect against regional outages; they are stored redundantly within the region but are unavailable if the region fails. Option C is wrong because AWS DMS is designed for database migration, not for continuous bidirectional synchronization with conflict resolution. Option D is wrong because manual hourly replication is not automatic, has high RPO, and does not provide a seamless failover mechanism.

32
MCQmedium

Refer to the exhibit. An application needs to store highly durable data in S3. The architect wants to ensure data is protected against accidental deletion while maintaining cost-effective storage. What should be done?

A.Enable S3 Versioning on the bucket and use Lifecycle policies to manage older versions.
B.Enable S3 Cross-Region Replication for all objects.
C.Modify the IAM policy to include s3:DeleteObject in the Deny statement.
D.Use S3 Intelligent-Tiering for all objects to reduce storage costs.
AnswerA

S3 Versioning keeps multiple variants of an object in the same bucket, providing protection against accidental deletion. Lifecycle policies automatically handle the transition of older versions to S3 Glacier or perform expirations, ensuring that storage costs remain optimized while maintaining high data durability and recovery capabilities for the bucket.

Why this answer

S3 Versioning preserves every prior version of an object, so an accidental overwrite or delete does not destroy the underlying data — the previous version remains retrievable. Pairing Versioning with Lifecycle policies lets you transition or expire noncurrent versions after a set number of days, which controls the cost of retaining all those versions. Together they deliver durability against accidental deletion while keeping storage spend predictable.

Exam trap

SAA-C03 often tests the misconception that Cross-Region Replication protects against accidental deletion, when in fact replication propagates deletions — Versioning is the correct control for recoverability.

How to eliminate wrong answers

Option B is wrong because Cross-Region Replication copies objects to another region for disaster recovery and latency, but it does not protect against accidental deletion — a delete marker or overwrite propagates to the replica. Option C is wrong because denying s3:DeleteObject via IAM blocks legitimate deletion operations too, which is a blunt control that does not preserve already-deleted data and can break application workflows. Option D is wrong because S3 Intelligent-Tiering only optimizes storage class costs based on access patterns; it provides no versioning or deletion protection whatsoever.

33
MCQmedium

A solutions architect is designing an application that stores user-uploaded images in Amazon S3. The images are accessed frequently for the first 30 days, then rarely accessed thereafter. Which storage class transition strategy is the most cost-effective?

A.Store all images in S3 Intelligent-Tiering from the start.
B.Transition objects to S3 Glacier Deep Archive after 30 days.
C.Transition objects to S3 Standard-IA after 30 days.
D.Manually move images to S3 One Zone-IA after 30 days.
AnswerC

S3 Standard-IA provides a lower storage cost for data that is infrequently accessed. Since the objects are accessed rarely after 30 days, this tier is perfectly suited for the workload. Transitioning via lifecycle policies ensures that storage costs are minimized automatically as the data ages past the frequent-access window.

Why this answer

S3 Standard-IA is the correct choice because the access pattern is well understood: objects are accessed frequently for exactly 30 days, then rarely. Standard-IA costs roughly 40% less than S3 Standard for storage while still providing millisecond retrieval, so a lifecycle rule transitioning objects at day 30 minimizes cost without sacrificing availability. Because the pattern is predictable, Intelligent-Tiering's per-object monitoring fee is unnecessary overhead.

Exam trap

SAA-C03 often tests the misconception that Intelligent-Tiering is always the cheapest option — candidates pick it reflexively, but it carries a per-object monitoring fee that makes it more expensive than a deterministic lifecycle transition when the access pattern is already known.

How to eliminate wrong answers

Option A is wrong because Intelligent-Tiering charges a monthly monitoring and automation fee per object and is designed for unpredictable access patterns — with a known 30-day hot phase, a simple lifecycle transition is cheaper. Option B is wrong because Glacier Deep Archive has a 180-day minimum storage duration and retrieval takes up to 12 hours, making it unsuitable for data that is only 'rarely' accessed and may still need occasional retrieval. Option D is wrong because One Zone-IA stores data in a single Availability Zone (99.5% durability SLA vs 99.9%), and 'manually move' is not a lifecycle strategy — it defeats automation and adds operational risk.

34
MCQmedium

An organization needs to issue and manage SSL/TLS certificates for its internal microservices, which are not accessible from the public internet. They want to avoid the overhead of managing their own PKI infrastructure. Which service should they use?

A.AWS Certificate Manager (ACM) to request public certificates for the services.
B.AWS Certificate Manager (ACM) Private Certificate Authority (PCA).
C.AWS CloudHSM to store and manage the private keys for the certificates.
D.Amazon Inspector to audit the certificates used by the microservices.
AnswerB

ACM Private CA allows you to create a private CA hierarchy and issue certificates that are trusted within your organization. It integrates with ACM to automate certificate renewal and management, providing a highly available and secure way to implement TLS for internal applications without the manual effort of managing PKI.

Why this answer

AWS Certificate Manager (ACM) Private Certificate Authority (PCA) is a managed private CA service that helps you easily and securely manage the lifecycle of your private certificates. It eliminates the need for organizations to maintain their own complex and costly internal PKI while still providing the security of private certificates.

Exam trap

Candidates often suggest AWS Certificate Manager (ACM) public certificates. ACM public certificates are for internet-facing resources and cannot be used for internal-only, private microservices.

35
Multi-Selectmedium

A company needs to store database credentials for an application running on Amazon ECS. The credentials must be encrypted and automatically rotated every 30 days without requiring an application restart. Which TWO AWS services should be used together to achieve this? (Select TWO)

Select 2 answers
A.AWS Secrets Manager
B.AWS Lambda
C.AWS Systems Manager Parameter Store
D.AWS Key Management Service (KMS)
E.Amazon DynamoDB
AnswersA, B

AWS Secrets Manager provides built-in support for rotating credentials for Amazon RDS and other databases. It manages the lifecycle of the secret and can trigger a Lambda function to update the database password, making it the primary service for this requirement of automated rotation.

Why this answer

AWS Secrets Manager (A) is correct because it is purpose-built to store and encrypt database credentials and natively supports automatic rotation on a schedule such as every 30 days, so the ECS application can retrieve the latest secret without a restart. AWS Lambda (B) is correct because Secrets Manager rotation is implemented by a Lambda rotation function that performs the four-step rotation (createSecret, setSecret, testSecret, finishSecret) against the database. AWS Systems Manager Parameter Store (C) can hold encrypted parameters but does not provide built-in automatic rotation, so it does not meet the 30-day rotation requirement.

AWS Key Management Service (D) provides the encryption keys used by Secrets Manager but is not itself a secret store or rotation scheduler, so it is not one of the two services to use together. Amazon DynamoDB (E) is a NoSQL database service and has no role in storing or rotating application credentials.

Exam trap

SAA-C03 often tests the confusion between Secrets Manager and Parameter Store; candidates may choose Parameter Store for rotation, but only Secrets Manager has built-in rotation with Lambda.

36
MCQmedium

A global e-commerce enterprise runs its checkout workflow using AWS Lambda functions integrated with Amazon API Gateway. During flash sales, traffic spikes cause downstream payment APIs to timeout, leading to lost transactions and frustrated customers. The solutions architect needs to redesign the architecture to decouple the frontend from the payment processor and ensure no transaction requests are lost. What should the architect do?

A.Configure API Gateway to cache responses using an Amazon ElastiCache Redis cluster deployed in multi-AZ mode.
B.Integrate an Amazon SQS FIFO queue between API Gateway and the downstream payment processing Lambda functions.
C.Increase the timeout and memory allocation of the API Gateway integration and the AWS Lambda functions.
D.Use AWS Step Functions with standard workflows to execute the payment processing steps sequentially.
AnswerB

An SQS FIFO queue buffers checkout requests when payment Lambdas are throttled, decoupling API Gateway from the processor so requests persist rather than being lost to timeouts. FIFO ordering and exactly-once processing preserve transaction sequence, directly meeting the no-lost-transactions requirement during flash-sale spikes.

Why this answer

Integrating an Amazon SQS FIFO queue between API Gateway and the payment Lambda decouples the frontend from the downstream payment processor, buffering requests during traffic spikes so no transaction is lost. FIFO queues preserve order and provide exactly-once processing, which is critical for payment transactions. The Lambda functions can then poll the queue at a controlled rate, preventing downstream timeouts.

Exam trap

SAA-C03 often tests the misconception that increasing Lambda timeout/memory or adding caching solves decoupling problems, when the real requirement is durable buffering with SQS.

How to eliminate wrong answers

Option A is wrong because ElastiCache caching only stores responses and does not decouple or buffer write transactions — it cannot prevent lost payment requests. Option C is wrong because increasing timeouts and memory does not solve the fundamental problem of downstream overload; it merely delays failures and can worsen throttling. Option D is wrong because Step Functions Standard workflows orchestrate steps but do not provide durable buffering or decoupling from the payment processor under burst load.

37
MCQmedium

A web application hosted on EC2 instances needs to access a DynamoDB table. What is the most secure way to provide the application with the necessary permissions?

A.Store IAM access keys in a configuration file on the EC2 instance.
B.Attach an IAM role to the EC2 instance profile.
C.Assign the EC2 instance a public IP address.
D.Use the root user credentials for the application.
AnswerB

IAM roles provide temporary security credentials that are automatically rotated by AWS. By attaching a role to the EC2 instance, the application gains the necessary permissions without the need for static credentials, which is the industry standard for secure service-to-service authentication and authorization within the AWS ecosystem.

Why this answer

Attaching an IAM role to the EC2 instance profile provides temporary, automatically rotated credentials to the application via the instance metadata service, eliminating the need to store long-term keys. This is the AWS-recommended, most secure way to grant EC2-hosted applications access to DynamoDB.

Exam trap

SAA-C03 often tests whether candidates default to IAM roles for AWS service access; the trap is choosing stored access keys or root credentials, which are insecure and operationally burdensome compared to instance profiles.

How to eliminate wrong answers

Option A is wrong because storing IAM access keys in a configuration file creates long-lived credentials that can be leaked, are hard to rotate, and violate least-privilege and credential-hygiene best practices. Option C is wrong because assigning a public IP address has no bearing on IAM permissions and increases the attack surface; it does not grant DynamoDB access. Option D is wrong because using root user credentials is a severe security anti-pattern — root has unrestricted access, cannot be scoped by IAM policies, and should never be used by applications.

38
MCQmedium

A financial services company needs to store millions of small records for 7 years to meet regulatory requirements. The records are rarely accessed after the first 30 days. The company wants to minimize storage costs while maintaining the ability to retrieve any record within a few minutes if an audit occurs. Which solution is best?

A.Amazon S3 Standard-IA.
B.Amazon S3 Glacier Flexible Retrieval.
C.Amazon S3 Glacier Instant Retrieval.
D.Amazon S3 Glacier Deep Archive.
AnswerC

This storage class provides the low cost of Glacier storage with the same latency and throughput as S3 Standard. It is perfect for regulatory data that must be kept for years but needs to be available immediately for an auditor, offering the best balance of cost and access speed.

Why this answer

S3 Glacier Instant Retrieval is designed for long-lived, rarely accessed data that still requires millisecond retrieval, making it ideal for regulatory archives where audits need quick access. It offers lower storage costs than S3 Standard-IA while maintaining instant retrieval, and it supports lifecycle transitions after 30 days. This matches the requirement to retrieve any record within a few minutes (instant retrieval is far faster) at minimal cost.

Exam trap

SAA-C03 often tests retrieval time distinctions between Glacier tiers, and candidates incorrectly assume Glacier Flexible Retrieval's Expedited tier always meets 'instant' requirements or confuse Deep Archive's retrieval time.

How to eliminate wrong answers

Option A is wrong because S3 Standard-IA is more expensive than Glacier Instant Retrieval for long-term storage and is intended for data accessed monthly, not rarely after 30 days; it does not minimize cost for a 7-year retention. Option B is wrong because Glacier Flexible Retrieval has retrieval times ranging from 1–5 minutes (Expedited) to 3–5 hours (Standard) and 5–12 hours (Bulk); while Expedited can meet 'a few minutes,' it costs extra and is not guaranteed, and the storage cost is higher than Glacier Instant Retrieval for data needing immediate access. Option D is wrong because Glacier Deep Archive has retrieval times of 12–48 hours, which fails the 'within a few minutes' requirement.

39
Multi-Selectmedium

A company is building a mobile application that needs to authenticate users and allow them to upload photos directly to an Amazon S3 bucket. Which TWO Amazon Cognito components should be used to provide a secure and scalable solution?

Select 2 answers
A.Amazon Cognito User Pools to manage user registration and sign-in.
B.Amazon Cognito Identity Pools to provide temporary AWS credentials to users.
C.Amazon Cognito Sync to synchronize user data across multiple devices.
D.IAM Users for each mobile application user to control S3 access.
E.AWS Directory Service to integrate with an on-premises Active Directory.
AnswersA, B

User Pools act as a managed user directory that provides sign-up and sign-in options for app users. They support standard identity providers like Google and Facebook, as well as custom attributes, making them the ideal choice for managing the authentication layer of a modern mobile or web application.

Why this answer

Option A is correct because Amazon Cognito User Pools provide a scalable, managed user directory that handles registration, sign-in, and token issuance (ID, access, and refresh tokens) for the mobile app's authentication layer. Option B is correct because Cognito Identity Pools exchange the User Pool token for temporary, scoped AWS credentials via AWS STS, allowing the app to upload photos directly to S3 without embedding long-term keys. Together they implement the standard authentication-plus-authorization pattern for mobile apps accessing AWS services.

Option C (Cognito Sync) is a legacy data-synchronization service, not an authentication or credential-vending mechanism, and is not needed here. Option D (IAM Users per app user) is an anti-pattern for mobile apps because it requires distributing long-term credentials and does not scale. Option E (AWS Directory Service) is for integrating existing AD/ LDAP directories and does not provide the mobile-native sign-up/sign-in or temporary credential flow required.

Exam trap

The trap is confusing User Pools (authentication) with Identity Pools (authorization/credential vending) — many candidates pick only one, but the question requires both because authentication alone doesn't grant S3 access.

40
Multi-Selectmedium

A company is designing a mission-critical database architecture using Amazon RDS. Which TWO steps should the architect take to ensure high availability and data durability? (Select TWO.)

Select 2 answers
A.Enable Multi-AZ deployment for the RDS instance.
B.Configure a Read Replica in the same Availability Zone.
C.Enable automated backups with a defined retention period.
D.Set the storage type to General Purpose SSD (gp2) only.
E.Disable the deletion protection feature for all instances.
AnswersA, C

Multi-AZ deployment ensures that a synchronous standby instance is maintained in a separate Availability Zone. In the event of a primary instance failure, RDS automatically promotes the standby to primary, significantly reducing downtime and ensuring the database remains available for critical application traffic without manual intervention or data loss.

Why this answer

Option A is correct because an RDS Multi-AZ deployment maintains a synchronous standby replica in a different Availability Zone, and RDS automatically fails over to that standby if the primary instance or its AZ fails, which directly provides high availability for a mission-critical database. Option C is correct because enabling automated backups with a defined retention period gives point-in-time recovery (PITR) to any second within the retention window (up to 35 days), which ensures data durability and recoverability from corruption or accidental deletion. Option B is not appropriate because a Read Replica in the same AZ is asynchronous, does not provide automatic failover, and would not survive an AZ-level outage.

Option D is incorrect because gp2 is just one storage option and choosing it does not by itself deliver high availability or durability. Option E is incorrect because disabling deletion protection increases the risk of accidental data loss rather than protecting the database.

Exam trap

SAA-C03 often tests the confusion between Read Replicas (read scaling, asynchronous) and Multi-AZ (high availability, synchronous failover), causing candidates to select a Read Replica when HA is required.

41
MCQmedium

An enterprise requires all data stored in Amazon S3 to be encrypted at rest. The security team must maintain full control over the encryption keys, including the ability to rotate them annually and define access policies for the keys themselves. Which encryption method meets these requirements with the least operational overhead?

A.Use Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3) for all buckets.
B.Implement client-side encryption using a third-party library before uploading objects.
C.Use Server-Side Encryption with AWS KMS Customer Managed Keys (SSE-KMS).
D.Enable Server-Side Encryption with Customer-Provided Keys (SSE-C) for all uploads.
AnswerC

Using SSE-KMS with a Customer Managed Key (CMK) allows the security team to define specific key policies and manage rotation schedules independently. This solution ensures that the security team retains ownership of the cryptographic material while providing the necessary encryption for objects stored within the S3 bucket.

Why this answer

SSE-KMS with Customer Managed Keys (CMKs) allows the security team to create and manage their own KMS keys, including setting key policies, rotating keys annually, and auditing key usage via CloudTrail. It provides full control over the encryption keys while offloading the encryption/decryption process to S3, minimizing operational overhead.

Exam trap

SAA-C03 often tests the confusion between SSE-S3, SSE-KMS, and SSE-C, particularly regarding who manages the keys and the level of control provided.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses S3-managed keys, giving the customer no control over key rotation or access policies. Option B is wrong because client-side encryption requires the team to manage the encryption process, key storage, and rotation, increasing operational overhead. Option D is wrong because SSE-C requires the customer to provide the encryption key with every request, and they are responsible for key management, which is operationally heavy and does not provide the ability to define key access policies within AWS.

42
Multi-Selectmedium

A company is running a development environment on Amazon RDS for MySQL. The environment is only used by developers during business hours (09:00 to 17:00, Monday through Friday). The company wants to minimize costs for these database instances. Which TWO actions should the company take?

Select 2 answers
A.Stop the RDS instances when they are not in use.
B.Convert the RDS instances to Multi-AZ deployments.
C.Use AWS Instance Scheduler to automate the start and stop times.
D.Purchase All Upfront Reserved Instances for the development environment.
E.Move the databases to Amazon DynamoDB to utilize on-demand scaling.
AnswersA, C

Stopping an RDS instance is highly effective for cost reduction in development environments. While the instance is stopped, you are not charged for compute hours or licensed software. You only pay for the provisioned storage and any manual snapshots, making it ideal for workloads that are strictly limited to business hours.

Why this answer

Option A is correct because stopping an RDS for MySQL instance when it is not in use eliminates instance-hour charges for the DB instance (you still pay for allocated storage and backups), which directly reduces cost for a dev environment idle outside 09:00–17:00 Monday–Friday. Option C is correct because AWS Instance Scheduler lets you define start/stop schedules (e.g., via CloudFormation-deployed Lambda and DynamoDB) so the instances automatically stop at 17:00 and start at 09:00 on business days, avoiding manual intervention and ensuring the savings from Option A are realized consistently. Option B is not appropriate because Multi-AZ deployments run a synchronous standby replica, roughly doubling cost and adding no benefit for a non-production dev environment.

Option D is not appropriate because All Upfront Reserved Instances commit to 24/7 usage for a 1- or 3-year term, which is wasteful for instances used only ~40 hours per week. Option E is not appropriate because migrating to DynamoDB is a major re-architecture away from MySQL and does not address the goal of minimizing cost for the existing RDS instances.

Exam trap

SAA-C03 often tests the misconception that Reserved Instances are always cost-effective, but they are not suitable for instances that are frequently stopped; also, stopping RDS instances does not eliminate storage charges.

43
MCQmedium

Refer to the exhibit. The current IAM policy allows an EC2 instance to read backups. The architect wants to ensure the data is recoverable if the source bucket is compromised by an external actor with write access. What should be done?

A.Enable S3 Object Lock on the bucket.
B.Apply a Bucket Policy to deny s3:PutObject for all users.
C.Create a read-only IAM user for the EC2 instance.
D.Enable S3 Server-Side Encryption (SSE-S3).
AnswerA

Object Lock provides WORM (Write Once, Read Many) protection. By preventing objects from being overwritten or deleted for a set period, it ensures that even an account compromise cannot destroy the backup data. This is the most effective way to secure backups against malicious actors and accidental data loss.

Why this answer

S3 Object Lock enforces a Write Once Read Many (WORM) model, preventing objects from being deleted or overwritten for a specified retention period — even by users with full administrative permissions. This directly addresses the scenario where an external actor with write access could otherwise overwrite or delete backups, ensuring the data remains recoverable. Object Lock requires versioning to be enabled on the bucket.

Exam trap

SAA-C03 often tests whether candidates know that Object Lock provides WORM immutability even against administrators, and candidates mistakenly pick encryption or IAM policies as deletion protection.

How to eliminate wrong answers

Option B is wrong because a bucket policy denying s3:PutObject for all users would also block legitimate backup writes and does not protect existing objects from deletion; it is a blunt instrument that breaks the backup process. Option C is wrong because creating a read-only IAM user for the EC2 instance only restricts that instance's permissions; it does not prevent a compromised external actor with separate write credentials from deleting or overwriting objects. Option D is wrong because SSE-S3 provides encryption at rest but does not prevent deletion or modification of objects — encryption and immutability are orthogonal controls.

44
MCQhard

A legacy application uses a monolithic architecture with a high-performance compute requirement. The application is CPU-bound and requires consistent sub-millisecond latency between compute nodes. Which EC2 feature should the architect use?

A.Spread Placement Groups.
B.Cluster Placement Groups.
C.Auto Scaling groups across multiple Availability Zones.
D.Dedicated Hosts with physical CPU pinning.
AnswerB

Cluster Placement Groups are purpose-built for low-latency and high-throughput network performance. By packing instances into the same physical rack or cluster, they enable the high-speed interconnect required for CPU-bound, latency-sensitive applications. This is the optimal configuration for HPC workloads demanding consistent, ultra-fast inter-instance communication within a single AZ.

Why this answer

Cluster Placement Groups provide high-density, low-latency, and high-throughput networking for compute-intensive applications. By placing instances in a single Availability Zone and a low-latency network cluster, the architect ensures that inter-node communication is as fast as possible. This is essential for HPC (High-Performance Computing) workloads where network jitter and latency can significantly degrade application performance.

It allows the instances to participate in a low-latency, high-bandwidth network fabric within the AWS data center.

45
MCQmedium

A company is hosting a sensitive web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The compliance team requires that all data at rest must be encrypted using keys that are rotated annually, and all access to these keys must be logged for auditing purposes. Which solution meets these requirements with the least administrative effort?

A.Use AWS CloudHSM to manage encryption keys and manually rotate them every year.
B.Encrypt the EC2 EBS volumes using AWS KMS with automatic key rotation enabled.
C.Implement a third-party encryption tool on the EC2 instances and store keys in an S3 bucket.
D.Use Amazon S3 SSE-S3 to encrypt the EBS volumes and monitor access via VPC Flow Logs.
AnswerB

AWS KMS allows for the creation of customer managed keys that support automatic annual rotation. Once enabled, AWS handles the rotation of the backing key material without requiring changes to the application or EBS configuration. This integrates natively with CloudTrail for auditing, making it the most efficient solution available.

Why this answer

AWS KMS with automatic key rotation enabled on the EBS encryption key satisfies annual rotation, and KMS logs every key operation to CloudTrail for auditing. EBS encryption at rest is configured at the volume level using a KMS CMK, and enabling rotation is a single checkbox or API call — the least administrative effort. CloudHSM and third-party tools require manual rotation and more operational overhead.

Exam trap

SAA-C03 often tests the confusion between S3 encryption (SSE-S3, SSE-KMS) and EBS encryption — candidates who pick SSE-S3 for EBS volumes miss that SSE-S3 is an S3-only feature and EBS uses KMS directly.

How to eliminate wrong answers

Option A is wrong because CloudHSM requires the customer to manage the HSM cluster, key lifecycle, and manual annual rotation, which is significantly more administrative effort than KMS automatic rotation. Option C is wrong because a third-party encryption tool on EC2 instances plus keys stored in S3 is an unmanaged, error-prone design that does not integrate with CloudTrail for key access auditing and requires manual rotation. Option D is wrong because SSE-S3 encrypts S3 objects, not EBS volumes, and VPC Flow Logs capture network metadata, not key access events — the option conflates storage and network services.

46
Multi-Selecthard

A solutions architect is tasked with reducing the cost of Amazon EBS volumes across a large AWS environment. Which THREE strategies will lead to lower EBS costs? (Select THREE.)

Select 3 answers
A.Convert all gp2 volumes to io2 Block Express.
B.Migrate gp2 volumes to gp3 volumes.
C.Identify and delete unattached EBS volumes.
D.Increase the size of all volumes to take advantage of bulk pricing.
E.Delete EBS snapshots that are no longer needed for recovery.
AnswersB, C, E

gp3 volumes are the latest generation of general-purpose SSDs and are priced up to 20% lower per GB than gp2. Additionally, gp3 allows you to provision IOPS and throughput independently of storage capacity, which prevents the need to over-provision storage just to get higher performance, leading to further savings.

Why this answer

Option B is correct because gp3 volumes decouple storage capacity from provisioned IOPS and throughput, and gp3 is priced lower per GB than gp2 (about $0.08/GB-month vs $0.10/GB-month in us-east-1), so migrating gp2 to gp3 reduces cost while often improving baseline performance. Option C is correct because unattached (available) EBS volumes still incur full storage charges, so identifying and deleting them with tools like the EBS console, DescribeVolumes, or Trusted Advisor eliminates that waste. Option E is correct because EBS snapshots are billed at $0.05/GB-month for standard snapshot storage, so deleting snapshots no longer needed for recovery directly removes ongoing charges.

Option A is not correct because io2 Block Express is a high-performance, higher-priced volume type, so converting gp2 to it would increase cost, not lower it. Option D is not correct because EBS has no bulk-pricing tier; increasing volume size increases the per-GB charge proportionally and raises cost.

Exam trap

SAA-C03 often tests the misconception that larger volumes or higher-performance types reduce cost, or that snapshots are free; candidates may also overlook that gp2 to gp3 migration is a cost-saving measure.

47
Multi-Selecthard

An application uses a monolithic architecture on EC2 instances. The company wants to improve resilience against regional failures. Which TWO actions should the architect take to achieve this? (Select TWO.)

Select 2 answers
A.Deploy the application to multiple Availability Zones within a single region.
B.Configure Amazon Route 53 with failover routing policies to a secondary region.
C.Implement Amazon Aurora Global Database for cross-region data replication.
D.Use an AWS Direct Connect connection to link the two regions.
E.Increase the minimum number of EC2 instances in the Auto Scaling group.
AnswersB, C

Route 53 failover routing policies monitor the health of primary region endpoints. If health checks fail, traffic is automatically routed to the secondary region. This is a foundational step in building a resilient multi-region architecture that provides automated business continuity during a regional disaster.

Why this answer

Option B is correct because Route 53 failover routing policies with health checks automatically redirect traffic to a secondary region when the primary region becomes unhealthy, directly providing regional failover capability. Option C is correct because Aurora Global Database replicates data across regions with typical latency under one second, enabling a secondary region to serve reads and support fast promotion during a regional failure, which is essential for cross-region resilience of a stateful monolith. Option A is not correct because deploying across multiple Availability Zones within a single region only protects against AZ-level failures, not regional failures.

Option D is not correct because Direct Connect is a dedicated network link between on-premises and AWS (or between regions via Direct Connect Gateway) and does not by itself provide application failover or resilience. Option E is not correct because increasing the minimum EC2 instance count in an Auto Scaling group only adds capacity within a single region and does nothing for regional failure resilience.

Exam trap

SAA-C03 often tests the misconception that multi-AZ deployment equals regional resilience, when true regional failover requires cross-region replication and DNS failover.

48
MCQmedium

A company is using Amazon DynamoDB to store real-time session data. The application requires response times in the sub-millisecond range for frequently accessed keys. The current DynamoDB latency is around 10-15 milliseconds. What should the architect implement to meet the performance goal?

A.Enable DynamoDB Streams and use Lambda to update ElastiCache.
B.Increase the Provisioned Read Capacity Units (RCUs) for the table.
C.Implement Amazon DynamoDB Accelerator (DAX).
D.Use Global Tables to replicate data closer to the application nodes.
AnswerC

DAX is specifically designed to provide microsecond response times for DynamoDB reads. It handles the cache management and is API-compatible, meaning the application can use existing DynamoDB SDKs to access the cache, making it the most efficient way to achieve sub-millisecond latency.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache purpose-built for DynamoDB that delivers microsecond response times for eventually consistent reads — well within the sub-millisecond requirement. DAX sits in front of the table as a write-through cache, so frequently accessed keys are served from RAM rather than from DynamoDB's SSD-backed storage, eliminating the 10-15 ms round trip. It requires only a minor application change (swap the DynamoDB client for the DAX client) and is the standard AWS answer for 'sub-millisecond DynamoDB reads.'

Exam trap

SAA-C03 often tests the misconception that adding read capacity (RCUs) or replicating data geographically reduces latency — both address throughput or availability, not the sub-millisecond read latency that only an in-memory cache like DAX can deliver.

How to eliminate wrong answers

Option A is wrong because DynamoDB Streams plus Lambda is an asynchronous change-data-capture pipeline — it cannot serve reads to the application and adds Lambda cold-start and invocation latency, not sub-millisecond responses. Option B is wrong because increasing RCUs only raises throughput capacity; it does not reduce per-request latency, which is bounded by DynamoDB's single-digit-millisecond service-side response time. Option D is wrong because Global Tables replicate data across Regions for disaster recovery and locality, but each read still hits DynamoDB storage at ~10 ms — geographic proximity does not get you to sub-millisecond.

49
Multi-Selecthard

A security auditor requires that all EC2 instances must be running with specific software versions and that any instance not compliant with these versions must be automatically terminated. Which THREE services should be used to achieve this? (Select THREE.)

Select 3 answers
A.AWS Systems Manager Inventory.
B.AWS Config.
C.AWS Lambda.
D.AWS Trusted Advisor.
E.AWS CloudFront.
AnswersA, B, C

Systems Manager Inventory collects metadata about software, applications, and configurations installed on EC2 instances. This provides the visibility needed to identify which instances are running the non-compliant software versions, which is the foundational step for both reporting and triggering the remediation actions required by the security audit.

Why this answer

Combining AWS Systems Manager for inventory and automation, AWS Config for continuous compliance monitoring, and Lambda for remediation provides a fully automated governance framework. This approach ensures that the environment is continuously scanned for drift, and non-compliant resources are immediately addressed without human intervention. This setup is crucial for meeting strict regulatory requirements where automated enforcement of security and operational standards is mandatory across a large-scale AWS environment.

Exam trap

Candidates often overlook AWS Config for compliance monitoring. They may select only Systems Manager, but Systems Manager detects the state, while Config is required to trigger the remediation workflow.

50
MCQmedium

An application is deployed across two AWS Regions to ensure resilience. The architect needs to direct users to the healthy region with the lowest latency. If the primary region fails, traffic should fail over automatically. Which Route 53 routing policy should be implemented?

A.Simple routing policy.
B.Latency routing policy with health checks.
C.Failover routing policy.
D.Weighted routing policy.
AnswerB

Latency routing optimizes the user experience by serving requests from the AWS Region that provides the lowest network latency. When combined with health checks, it provides both performance optimization and high availability. Route 53 monitors the health of the endpoints and automatically skips any region that fails health checks during the routing decision.

Why this answer

Latency-based routing with health checks directs each user to the AWS Region that provides the lowest latency while the health check removes an unhealthy region's records from DNS responses, achieving automatic failover. This satisfies both requirements: lowest-latency selection under normal conditions and automatic redirection when the primary region fails.

Exam trap

SAA-C03 often tests the misconception that Failover routing automatically picks the lowest-latency region — it does not; it is strictly active-passive, so candidates who overlook the 'lowest latency' requirement choose C incorrectly.

How to eliminate wrong answers

Option A is wrong because Simple routing returns a single static record with no health checking or latency awareness, so it cannot fail over or optimize latency. Option C is wrong because Failover routing is active-passive and always sends traffic to the primary unless it is unhealthy; it does not select the lowest-latency region for each user. Option D is wrong because Weighted routing distributes traffic by fixed proportions (e.g., 70/30) and does not consider latency or provide automatic health-based failover by itself.

51
MCQmedium

A company's web application requires a highly available database layer to survive an Availability Zone failure without manual intervention. The database must remain accessible during maintenance windows and ensure zero data loss. Which solution meets these requirements with the least operational overhead?

A.Configure RDS Read Replicas and manually promote them during an outage.
B.Deploy a Single-AZ RDS instance and use AWS Backup for hourly snapshots.
C.Implement an Amazon RDS Multi-AZ deployment.
D.Host a MySQL database on an Amazon EC2 instance with an EBS volume.
AnswerC

Amazon RDS Multi-AZ uses synchronous replication to a standby instance in a different AZ, providing automatic failover and data redundancy. If the primary instance fails, AWS automatically updates the DNS record to point to the standby. This meets the high availability and zero-intervention requirements while handling maintenance windows with minimal impact on application uptime.

Why this answer

Amazon RDS Multi-AZ maintains a synchronous standby replica in a different Availability Zone and automatically fails over during an AZ failure or maintenance event, with zero data loss (RPO=0) and no manual intervention. It meets high availability, maintenance resilience, and zero data loss with minimal operational overhead.

Exam trap

SAA-C03 often tests the distinction between Multi-AZ (synchronous, automatic failover, HA) and Read Replicas (asynchronous, manual promotion, read scaling); the trap is choosing Read Replicas for a zero-data-loss HA requirement.

How to eliminate wrong answers

Option A is wrong because Read Replicas use asynchronous replication and require manual promotion, so they can lose recent transactions and do not provide automatic failover. Option B is wrong because a Single-AZ instance with hourly snapshots has no automatic failover and can lose up to an hour of data, violating zero data loss. Option D is wrong because self-managed MySQL on EC2 requires the customer to architect, patch, and manage replication and failover, adding significant operational overhead and not guaranteeing zero data loss without careful synchronous setup.

52
MCQhard

A large enterprise uses AWS Organizations to manage multiple accounts. The Chief Information Security Officer (CISO) wants to ensure that no account within the organization can create any resources in regions other than 'us-east-1' and 'us-west-2'. What is the most efficient way to enforce this across the entire organization?

A.Create an IAM Group in the management account with a region-restrictive policy and add all users to it.
B.Apply a Service Control Policy (SCP) to the organization root that denies all actions if the region is not 'us-east-1' or 'us-west-2'.
C.Use AWS Config rules in each account to monitor resource creation and delete any resource found in unauthorized regions.
D.Configure a VPC Endpoint for all services and restrict access to specific regions using VPC Endpoint policies.
AnswerB

SCPs provide central control over the maximum permissions available for all accounts in your organization. By applying the policy at the root, the restriction is inherited by all member accounts, including the root user of those accounts, ensuring consistent compliance with the CISO's regional requirements.

Why this answer

SCPs are the only AWS Organizations mechanism that centrally enforce permission guardrails across every account in the OU/root, and they apply to all principals including the root user. A deny statement conditioned on aws:RequestedRegion outside us-east-1/us-west-2 blocks resource creation in unauthorized regions before the API call succeeds. Attaching it at the organization root propagates the restriction to every member account with a single policy, which is the most efficient approach.

Exam trap

SAA-C03 often tests the misconception that IAM policies or Config rules can enforce organization-wide region restrictions, when only SCPs provide preventive, cross-account guardrails.

How to eliminate wrong answers

Option A is wrong because an IAM Group in the management account only affects IAM users in that one account — it has no effect on member accounts, federated identities, or root users, and IAM policies cannot restrict service-level region usage across an organization. Option C is wrong because AWS Config rules are detective, not preventive — they evaluate after the fact and remediation (deleting resources) is reactive, slow, and leaves a window where unauthorized resources exist. Option D is wrong because VPC endpoints only govern traffic to AWS services over private connectivity; they do not prevent resource creation in other regions and cannot be used as a global region guardrail.

53
Multi-Selectmedium

A media company experiences unpredictable traffic spikes on its web application. The architect needs to ensure the application remains responsive while optimizing for performance. Which TWO strategies should be implemented? (Select TWO.)

Select 2 answers
A.Configure a Target Tracking Scaling Policy for the Auto Scaling group.
B.Use a Simple Scaling Policy with a large cooldown period.
C.Deploy Amazon CloudFront in front of the Application Load Balancer.
D.Provision IOPS (io2) for all EC2 root volumes.
E.Implement vertical scaling by increasing instance sizes manually.
AnswersA, C

Target tracking scaling policies allow the Auto Scaling group to maintain a specific metric value, such as average CPU utilization. This approach ensures the application scales out proactively to handle incoming traffic spikes while scaling in during low activity to maintain optimal performance and cost-efficiency.

Why this answer

Option A is correct because a Target Tracking Scaling Policy for the Auto Scaling group automatically adjusts capacity to maintain a specified metric (such as average CPU utilization or ALB request count per target) at a target value, which directly handles unpredictable traffic spikes while keeping the application responsive. Option C is correct because deploying Amazon CloudFront in front of the Application Load Balancer caches static and cacheable content at edge locations, reduces latency for global users, and offloads traffic from the origin, improving performance during spikes. Option B is not appropriate because a Simple Scaling Policy with a large cooldown period reacts slowly and can leave the application under-provisioned during sudden spikes.

Option D is irrelevant because provisioning io2 IOPS on EC2 root volumes addresses storage throughput, not web traffic responsiveness. Option E is not suitable because manual vertical scaling is slow, requires downtime or restarts, and cannot respond to unpredictable spikes in real time.

Exam trap

SAA-C03 often tests the misconception that vertical scaling or simple scaling with long cooldowns can handle unpredictable spikes effectively, when in fact automatic, responsive scaling is needed.

54
MCQmedium

Refer to the exhibit. This bucket policy grants access to a specific account. A user in that account still cannot access the object. What is the most likely reason?

A.The bucket policy needs to use 'Effect': 'Deny'.
B.The user in the target account lacks IAM permissions.
C.The bucket policy must include 'Principal': '*'.
D.The resource ARN is incorrectly formatted.
AnswerB

In cross-account access, both the bucket policy and the user's local IAM policy must explicitly permit the action. The bucket policy allows access from the account, but the individual user identity still requires an IAM policy that authorizes the s3:GetObject action to complete the authorization request successfully.

Why this answer

The bucket policy grants cross-account access to the account, but for a user in that account to actually access the S3 object, the user must also have IAM permissions that allow the action (e.g., s3:GetObject). AWS evaluates both the bucket policy and the user's IAM policy; access is granted only if both allow it (unless an explicit deny exists). Since the bucket policy is correct, the missing piece is the user's IAM policy.

Exam trap

SAA-C03 often tests the misconception that a bucket policy alone is sufficient for cross-account access, ignoring the need for IAM permissions in the user's account.

How to eliminate wrong answers

Option A is wrong because using 'Effect': 'Deny' would explicitly deny access, which is the opposite of what is needed; the policy already grants access. Option C is wrong because 'Principal': '*' would grant access to everyone, which is broader than intended and not required for cross-account access; the policy already specifies the correct account principal. Option D is wrong because if the resource ARN were incorrectly formatted, the policy would likely be invalid or not apply, but the scenario states the policy grants access to the account, implying the ARN is correct.

55
MCQhard

A company runs a mission-critical web application on EC2. The database is on RDS. How should the architect ensure the fastest possible recovery time objective (RTO) if the primary database instance fails?

A.Configure an RDS Read Replica in a different region and promote it if the primary fails.
B.Enable RDS Multi-AZ deployment.
C.Take hourly automated snapshots and restore from the latest snapshot upon failure.
D.Back up the database to S3 and use a standby EC2 instance to run a database engine.
AnswerB

RDS Multi-AZ is specifically designed for high availability. It maintains a synchronous secondary standby in another AZ. Upon detecting a failure, RDS automatically initiates a failover process. This is the fastest, most reliable way to maintain database availability and minimize downtime for mission-critical applications without manual intervention.

Why this answer

RDS Multi-AZ deployment provides synchronous replication to a standby instance in a different Availability Zone (AZ) within the same region. If the primary instance fails, RDS automatically performs a failover to the standby, updating the DNS record to point to the new primary. This process typically happens in under 60 seconds, which is the most effective native way to achieve a low RTO for RDS.

Exam trap

Candidates often confuse Multi-AZ (high availability within a region) with Cross-Region Read Replicas (disaster recovery across regions).

56
MCQmedium

A globally distributed application needs to provide low-latency access to static content for users around the world. Which AWS service is best suited for this requirement?

A.Amazon S3 Cross-Region Replication.
B.Amazon CloudFront.
C.AWS Global Accelerator.
D.Amazon Route 53 Geolocation Routing.
AnswerB

CloudFront is specifically engineered to deliver content globally with low latency. By distributing content to hundreds of edge locations, it ensures that users receive data from the geographically closest server, significantly reducing round-trip times and providing a high-performance experience that simple regional storage cannot match for global users.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches static content at edge locations worldwide, dramatically reducing latency for geographically distributed users. It integrates natively with S3 origins and supports cache behaviors, signed URLs, and Lambda@Edge for dynamic customization. This makes it the purpose-built service for low-latency global static content delivery.

Exam trap

SAA-C03 often tests the distinction between CloudFront (caching/CDN for HTTP content) and Global Accelerator (network-layer acceleration for TCP/UDP) — candidates pick Global Accelerator thinking 'global' means 'best for global static content'.

How to eliminate wrong answers

Option A is wrong because S3 Cross-Region Replication only copies objects to buckets in other Regions — it does not cache content at edge locations or reduce latency for end users; users still fetch from a single regional endpoint. Option C is wrong because AWS Global Accelerator optimizes routing for TCP/UDP traffic (e.g., gaming, VoIP, IoT) using Anycast IPs and the AWS backbone, but it does not cache static content, so it doesn't deliver the CDN-style latency reduction for HTTP static assets. Option D is wrong because Route 53 Geolocation Routing only directs DNS queries to region-specific endpoints; it provides no caching and does not reduce per-request latency for static files.

57
MCQmedium

An application consists of a web tier and an application tier. The web tier must be accessible from the internet, but the application tier must remain private. How should the architect configure the network for maximum resilience?

A.Deploy all tiers in a single public subnet in one AZ.
B.Deploy web and app tiers across multiple subnets in multiple AZs, with app tiers in private subnets.
C.Put everything in a public subnet and use Security Groups for isolation.
D.Use a single private subnet for both tiers and a NAT Gateway in the same subnet.
AnswerB

This architecture provides both high availability and security. By spreading instances across multiple AZs, the application can survive a data center failure. Placing the application tier in private subnets ensures that sensitive back-end components are not directly reachable from the internet, significantly hardening the application against external attacks.

Why this answer

For maximum resilience, the web and application tiers should be deployed across multiple subnets in multiple Availability Zones, with the web tier in public subnets (accessible from the internet) and the application tier in private subnets (not directly accessible). This design ensures high availability and fault tolerance, and follows the principle of least privilege by isolating the private tier.

Exam trap

SAA-C03 often tests the misconception that Security Groups alone can provide sufficient isolation for a private tier in a public subnet, but network placement (private subnets) is required for true isolation.

How to eliminate wrong answers

Option A is wrong because deploying all tiers in a single public subnet in one AZ creates a single point of failure and exposes the application tier to the internet, violating security best practices. Option C is wrong because placing everything in a public subnet, even with Security Groups, still exposes the application tier to potential inbound traffic if Security Groups are misconfigured, and it does not provide network-level isolation. Option D is wrong because using a single private subnet for both tiers and a NAT Gateway in the same subnet is not possible; NAT Gateways must be in a public subnet, and a single private subnet lacks multi-AZ resilience.

58
MCQmedium

A company is using AWS Direct Connect to connect their on-premises data center to AWS. What is the most resilient way to connect?

A.Use a single 10 Gbps Direct Connect connection.
B.Use two Direct Connect connections in different locations.
C.Use a single VPN connection over the internet.
D.Configure the connection to use only the AWS public IP space.
AnswerB

Redundant Direct Connect connections in different locations provide protection against local failures, such as fiber cuts or data center outages. This ensures that even if one physical path is entirely compromised, connectivity can be maintained through the alternate path, meeting the requirements for a highly available and resilient hybrid cloud network infrastructure.

Why this answer

To achieve high resiliency and maximum redundancy with AWS Direct Connect, a company should establish at least two Direct Connect connections in different AWS locations (or use AWS Direct Connect resiliency recommendations which include multiple connections across multiple locations). Option B provides geographical redundancy, eliminating single points of failure.

Exam trap

Candidates often assume a single high-bandwidth connection (like 10 Gbps) is sufficient for resiliency, but bandwidth does not equal redundancy.

59
MCQmedium

Refer to the exhibit. An administrator has applied the provided bucket policy to 'my-secure-bucket'. What is the effect of this policy on access to the bucket?

A.It allows all users to retrieve objects from the bucket if they are using any IP address.
B.It denies access to anyone from the 192.0.2.0/24 range and allows everyone else.
C.It restricts GetObject access to only those requests originating from the 192.0.2.0/24 CIDR block.
D.It grants full administrative access to the bucket for the 192.0.2.0/24 IP range.
AnswerC

The 'Condition' block acts as a filter on the 'Allow' statement. By using the 'aws:SourceIp' key, the policy ensures that the 's3:GetObject' action is granted only when the request comes from the specified network, effectively implementing a security perimeter around the S3 bucket's data.

Why this answer

The bucket policy uses a Condition with an IpAddress condition key restricting access to the 192.0.2.0/24 CIDR block, and the Action is s3:GetObject. Therefore only requests originating from that IP range are allowed to retrieve objects; all other requests are denied by default because S3 policies are deny-by-default.

Exam trap

SAA-C03 often tests the misconception that an Allow statement with an IP condition denies that IP range, when in fact it permits only that range and implicitly denies everything else.

How to eliminate wrong answers

Option A is wrong because the policy explicitly conditions on the source IP, so not all IP addresses are allowed. Option B is wrong because the policy is an Allow with an IP condition, not a Deny for that range — the range is the only one permitted, not the one blocked. Option D is wrong because the policy only grants s3:GetObject, not full administrative access; administrative actions like s3:PutBucketPolicy or s3:DeleteObject are not included.

60
MCQmedium

A company is migrating a web application to AWS and needs to ensure that all data stored in Amazon S3 is encrypted at rest using keys managed by the company. The company must be able to rotate these keys annually and maintain full control over key access policies. Which solution meets these requirements?

A.Enable S3 Managed Keys (SSE-S3) for all buckets.
B.Use AWS KMS with AWS Managed Keys.
C.Use AWS KMS with Customer Managed Keys.
D.Upload a master key to AWS via the S3 console.
AnswerC

Customer Managed Keys allow the user to define granular key policies and enforce rotation schedules. This provides the level of control required for compliance and security auditing. By managing the key lifecycle, the company fulfills the requirement for ownership and authority over the encryption process for their S3 stored data.

Why this answer

AWS KMS Customer Managed Keys (CMKs) give the company full control over the key policy, allow annual rotation to be enabled, and support auditing via CloudTrail. SSE-S3 uses AWS-owned keys the customer cannot manage or rotate, and AWS Managed Keys have rotation controlled by AWS (every three years) with policies the customer cannot edit. Uploading a raw master key to S3 is not a supported KMS pattern.

Exam trap

SAA-C03 often tests the distinction between SSE-S3, SSE-KMS with AWS Managed Keys, and SSE-KMS with Customer Managed Keys — candidates who pick AWS Managed Keys miss that only CMKs allow customer-controlled rotation and key policies.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses AES-256 keys fully managed by AWS — the customer has no visibility, no rotation control, and no key policy to manage. Option B is wrong because AWS Managed Keys (aws/s3) rotate automatically every three years and their key policies cannot be customized by the customer, so annual rotation and full access control are not achievable. Option D is wrong because AWS KMS does not accept imported master keys via the S3 console; while KMS does support BYOK via import, that is a KMS API operation, not an S3 console upload, and it still requires a KMS key object.

61
Multi-Selecthard

An enterprise organization is planning a centralized logging architecture across hundreds of AWS accounts using AWS CloudTrail and Amazon S3. Security mandates state that all log files delivered to the centralized S3 bucket must be cryptographically verified to ensure they have not been modified or tampered with after delivery. Which TWO actions must a Solutions Architect implement to achieve this mandate? (Choose two.)

Select 2 answers
A.Enable CloudTrail log file integrity validation on each trail.
B.Configure S3 Object Lock in compliance mode on the centralized logging bucket.
C.Use AWS KMS customer managed keys with automatic key rotation enabled for S3 bucket encryption.
D.Enable Amazon S3 Versioning on the centralized logging bucket to preserve previous object iterations.
E.Verify the digital digests generated by CloudTrail using the AWS CLI or SDK commands.
AnswersA, E

CloudTrail log file integrity validation creates digital signatures of log files using SHA-256 for hashing and SHA-256 with RSA for digital signing. This allows you to verify that log files were not modified, deleted, or forged after delivery.

Why this answer

Option A is correct because CloudTrail log file integrity validation is the feature that produces a digest file for each delivered log file, containing a digital signature (SHA-256 hash signed with a private key) that allows detection of any modification, deletion, or tampering after delivery. Option E is correct because enabling validation alone only generates the digests; the architect must actually validate them by running AWS CLI commands such as 'aws cloudtrail validate-logs' (or SDK equivalents) against the S3 bucket to cryptographically confirm the log files match their digests. Option B is not correct because S3 Object Lock prevents deletion or overwrite of objects going forward but does not cryptographically prove that a delivered log file's contents are unmodified.

Option C is not correct because KMS encryption with key rotation protects data confidentiality and key hygiene, not post-delivery tamper detection. Option D is not correct because S3 Versioning preserves prior object versions but does not itself verify the integrity or authenticity of log file contents.

Exam trap

SAA-C03 often tests the confusion between immutability features (S3 Object Lock, Versioning) and cryptographic integrity verification, causing candidates to select options that prevent tampering but do not verify it.

62
MCQeasy

A company is running a large-scale batch processing job that can be interrupted and resumed without loss of data. The job runs for several hours every weekend. Which instance purchasing option will provide the highest cost savings?

A.On-Demand Instances
B.Spot Instances
C.Reserved Instances
D.Dedicated Hosts
AnswerB

Spot Instances offer the deepest discounts in exchange for the possibility that AWS may reclaim the capacity with a two-minute notice. Since the application can resume progress after being stopped, the company can maximize savings by utilizing these instances during the weekend when spare capacity is often high.

Why this answer

Spot Instances offer up to 90% discounts compared to On-Demand pricing by using AWS's spare EC2 capacity. Because the batch job is interruptible and can resume without data loss, it perfectly matches the Spot use case — workloads that tolerate the two-minute interruption notice when AWS reclaims capacity. This makes Spot the most cost-effective choice for fault-tolerant, flexible workloads.

Exam trap

SAA-C03 often tests the misconception that Reserved Instances are always cheapest — candidates must recognize that for interruptible, fault-tolerant workloads, Spot Instances deliver far greater savings than any commitment-based option.

How to eliminate wrong answers

Option A is wrong because On-Demand Instances provide no discount and are the most expensive option for long-running workloads, appropriate only when you cannot tolerate interruption or commitment. Option C is wrong because Reserved Instances require a 1- or 3-year commitment and provide only up to ~72% savings, and they are best for steady-state, predictable workloads — not weekend-only batch jobs. Option D is wrong because Dedicated Hosts are the most expensive option, used for licensing compliance or regulatory requirements, and offer no cost advantage for interruptible batch processing.

63
Multi-Selecthard

A company is migrating a high-traffic web application to AWS. The application uses an Amazon RDS for MySQL database. The database experience high read pressure during business hours, but write activity remains consistent and low. Which TWO architectural changes will reduce costs while maintaining performance? (Select TWO.)

Select 2 answers
A.Create RDS Read Replicas and update the application to split read and write traffic.
B.Scale up the primary RDS instance to a larger instance class with more RAM.
C.Use Amazon ElastiCache in front of the RDS database to cache frequent read queries.
D.Switch the database to Amazon RDS for SQL Server to take advantage of License Inclusion.
E.Enable Multi-AZ for all Read Replicas to ensure high availability.
AnswersA, C

Read Replicas allow the application to scale read capacity independently of the primary instance. By directing read queries to replicas, the primary instance can be smaller and less expensive, while the replicas handle the high read pressure during business hours at a lower cost than a single massive instance.

Why this answer

Offloading read traffic to Read Replicas is more cost-effective than scaling up the primary instance size, as it allows for horizontal scaling of reads. Additionally, using Multi-AZ deployments for the primary instance ensures high availability, while Read Replicas can be placed in different regions or zones to distribute the load without over-provisioning the main database.

Exam trap

Candidates often suggest Multi-AZ for read scaling. Multi-AZ is for high availability and failover, not for scaling read performance; it actually increases costs rather than reducing them.

64
MCQhard

A mission-critical application requires a recovery time objective (RTO) of near-zero. Which disaster recovery strategy should the architect implement?

A.Backup and Restore.
B.Pilot Light.
C.Warm Standby.
D.Multi-Site Active-Active.
AnswerD

The Multi-Site Active-Active approach runs the application in multiple regions simultaneously. Because both regions are already handling production traffic, a failure in one region does not require scaling or recovery time; traffic is simply routed to the remaining active region, resulting in the lowest possible RTO for the application.

Why this answer

The explanation is accurate, but the question requires a defined exam trap and common trap note to help students avoid pitfalls.

Exam trap

Candidates often confuse Warm Standby with Multi-Site Active-Active. While Warm Standby allows for fast recovery, it is not 'near-zero' because it requires scaling up resources or promoting a database, whereas Active-Active is already running at full capacity.

65
MCQeasy

A company has a stable, predictable workload consisting of several Amazon EC2 instances, AWS Lambda functions, and AWS Fargate containers that run 24/7. The company wants to minimize compute costs over a three-year period with minimal administrative effort. Which AWS pricing model should the company choose?

A.EC2 Instance Savings Plans
B.Compute Savings Plans
C.Standard Reserved Instances
D.Spot Instances
AnswerB

Compute Savings Plans are the most versatile option as they apply regardless of instance family, size, AZ, region, OS, or even the compute service. This plan covers EC2, Lambda, and Fargate usage, making it the ideal choice for a multi-service environment where maximizing savings across all platforms is necessary.

Why this answer

Compute Savings Plans offer the largest discount flexibility — they apply automatically to EC2 instances, Lambda functions, and Fargate containers regardless of instance family, Region, tenancy, or OS, in exchange for a one- or three-year hourly spend commitment. Because the workload spans EC2, Lambda, and Fargate and runs 24/7 for three years, Compute Savings Plans cover all three compute types with a single commitment and minimal administrative effort, maximizing savings across the mixed estate.

Exam trap

SAA-C03 often tests the difference between Compute Savings Plans (flexible across EC2, Lambda, Fargate, any Region) and EC2 Instance Savings Plans (locked to a family/Region, deeper discount) — candidates must match the plan to the workload's diversity and the 'minimal administrative effort' requirement.

How to eliminate wrong answers

Option A is wrong because EC2 Instance Savings Plans only apply to EC2 usage within a specific instance family in a specific Region — they do not cover Lambda or Fargate, leaving those workloads at on-demand rates. Option C is wrong because Standard Reserved Instances are tied to a specific instance family, size, OS, and tenancy in a single Region, and they do not cover Lambda or Fargate at all. Option D is wrong because Spot Instances are interruptible (2-minute termination notice) and unsuitable for a stable 24/7 workload — they can be reclaimed by AWS at any time, causing outages.

66
MCQeasy

A solutions architect is designing a system for batch processing of large image files. The process can be interrupted and resumed later without loss of data. The workload is expected to run for several hours each night. Which EC2 instance purchasing option will provide the lowest cost?

A.On-Demand Instances
B.Dedicated Hosts
C.Spot Instances
D.Reserved Instances
AnswerC

Spot Instances allow you to bid on spare AWS capacity at a fraction of the On-Demand price. Because the batch processing job is interruptible and can resume, it is the perfect use case for Spot. If AWS needs the capacity back, the instance is terminated, but the cost savings remain substantial.

Why this answer

Spot Instances offer the deepest discounts (up to 90%) on EC2 capacity. They are ideal for fault-tolerant, flexible, and interruptible workloads like batch processing. Since the application can handle interruptions and resume progress, the risk of AWS reclaiming the capacity is offset by the massive cost savings compared to On-Demand or Reserved Instances.

Exam trap

Candidates frequently choose Reserved Instances. While they provide savings, they are for steady-state workloads, not interruptible batch processing, and do not offer the deepest discounts possible compared to Spot.

67
MCQeasy

A company wants to implement a service that continuously monitors for malicious activity and unauthorized behavior across its AWS accounts, such as cryptocurrency mining or unusual API calls. Which AWS service should they use?

A.Amazon Macie
B.AWS Config
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerC

Amazon GuardDuty provides intelligent threat detection by analyzing various data sources including AWS CloudTrail event logs and VPC Flow Logs. It can identify specific threats like EC2 instances communicating with known malicious IP addresses or performing cryptocurrency mining, making it the correct choice for this scenario.

Why this answer

Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts for malicious activity and unauthorized behavior using machine learning, anomaly detection, and integrated threat intelligence. It specifically detects findings like cryptocurrency mining, unusual API calls, and compromised instances, which matches the requirement exactly.

Exam trap

The trap is confusing logging and compliance services (CloudTrail, Config) with threat detection — candidates pick CloudTrail because it 'monitors API calls,' but it only records them; GuardDuty is what analyzes them for malicious behavior.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data (PII) in S3 — it does not monitor for malicious activity or unauthorized API behavior. Option B is wrong because AWS Config records and evaluates resource configuration changes for compliance, not for threat detection or malicious behavior monitoring. Option D is wrong because AWS CloudTrail logs API activity for auditing and governance, but it does not analyze that activity for threats — it provides the raw data that GuardDuty consumes.

68
MCQhard

A data analytics company uses Amazon Redshift for complex queries. The workload is mostly consistent but experiences heavy spikes during the last three days of every month. What is the most cost-effective way to handle these spikes?

A.Manually resize the Redshift cluster to a larger size during the last three days.
B.Enable Redshift Concurrency Scaling for the cluster.
C.Use a Redshift Serverless workgroup for the monthly reporting tasks.
D.Move the data to Amazon S3 and use Amazon Athena for the monthly spikes.
AnswerB

Concurrency Scaling is designed for exactly this scenario. It provides extra compute power when needed and scales back down when the spike is over. Since Redshift offers free Concurrency Scaling credits for every 24 hours the main cluster is running, the company may even handle these spikes at no additional cost.

Why this answer

Amazon Redshift Concurrency Scaling automatically adds transient cluster capacity to handle increases in concurrent queries. You are only charged for the time the scaling clusters are actually in use, and most clusters earn enough free credits to cover typical monthly spikes, making it more cost-effective than over-provisioning the main cluster.

Exam trap

Candidates often think they need to resize the Redshift cluster or purchase reserved instances for monthly spikes, forgetting that Concurrency Scaling handles temporary high concurrency automatically.

69
Multi-Selectmedium

A research institution is running a High Performance Computing (HPC) workload on AWS that requires a POSIX-compliant file system capable of millions of IOPS and sub-millisecond latencies. Which TWO storage options are most appropriate for this use case?

Select 2 answers
A.Amazon FSx for Lustre.
B.Amazon S3 with S3 Select.
C.Amazon FSx for Windows File Server.
D.EC2 Instance Store with a clustered file system.
E.Amazon EFS in General Purpose mode.
AnswersA, D

FSx for Lustre is a high-performance file system optimized for workloads like HPC, machine learning, and video processing. It can provide hundreds of gigabytes per second of throughput and millions of IOPS, while also integrating seamlessly with S3 for long-term data storage.

Why this answer

Amazon FSx for Lustre (A) is correct because it is a POSIX-compliant, high-performance file system purpose-built for HPC, delivering millions of IOPS and sub-millisecond latencies, and it integrates with S3 for data staging. EC2 Instance Store with a clustered file system (D) is correct because instance store volumes are physically attached NVMe SSDs offering the lowest latency and highest IOPS, and a clustered file system (e.g., Lustre, GPFS) can aggregate them across nodes for shared POSIX access. Amazon S3 with S3 Select (B) is object storage, not POSIX-compliant, and cannot meet sub-millisecond latency requirements.

Amazon FSx for Windows File Server (C) uses SMB and is designed for Windows workloads, not high-IOPS POSIX HPC. Amazon EFS General Purpose mode (E) is POSIX-compliant but its latency and throughput are far below the millions of IOPS and sub-millisecond requirements of this workload.

Exam trap

SAA-C03 often tests the difference between POSIX-compliant file systems and object storage, and candidates mistakenly select EFS or S3 for HPC workloads requiring millions of IOPS and sub-millisecond latency.

70
MCQhard

Refer to the exhibit. An application running on an EC2 instance requires access to S3 objects but is encountering slow performance when fetching large files. An architect observes high network latency between the instance and S3. Which strategy will improve retrieval performance?

A.Update the IAM policy to include s3:ListBucket.
B.Create an S3 VPC Endpoint.
C.Deploy an Amazon CloudFront distribution in front of the S3 bucket.
D.Change the S3 bucket storage class to S3 Intelligent-Tiering.
AnswerB

While VPC endpoints keep traffic within the AWS network, they are primarily for security and private connectivity. CloudFront provides edge caching, which offers superior performance for large file retrieval by serving objects from closer geographical locations, whereas a VPC endpoint only optimizes the path to the S3 region.

Why this answer

Creating an Amazon S3 VPC Endpoint (Gateway Endpoint) allows resources within an Amazon VPC (such as an EC2 instance) to communicate with Amazon S3 without requiring an internet gateway, NAT device, or VPN connection. Traffic between the VPC and S3 leaves the instances and goes directly to S3 via the AWS network backbone, significantly improving retrieval performance, reducing latency, and avoiding public internet bottlenecks. CloudFront is intended for global end-user content delivery rather than optimizing backend EC2-to-S3 communication.

Exam trap

Candidates often assume that CloudFront is always the answer for performance optimization or caching, ignoring that it is meant for edge-to-user delivery, whereas VPC endpoints are designed for secure and optimized internal AWS resource-to-resource traffic.

71
MCQmedium

An application has an unpredictable workload where it receives bursts of traffic for 5 minutes every few hours, followed by periods of complete inactivity. The application is currently running on a small EC2 instance. Which migration strategy would minimize costs for this specific workload?

A.Migrate the application to an AWS Fargate service with an Auto Scaling policy.
B.Refactor the application to run on AWS Lambda.
C.Move the application to an Amazon EC2 T3 instance with Unlimited Credits enabled.
D.Convert the EC2 instance to a Spot Instance to reduce hourly rates.
AnswerB

Lambda functions are only billed during the time they are executing. For a workload that only runs for a total of 60 minutes a day (5 minutes every few hours), the company would only pay for those 60 minutes of compute, resulting in massive savings over a running EC2 instance.

Why this answer

AWS Lambda is a serverless compute service that charges only for the compute time consumed, measured in milliseconds, and does not charge when the code is not running. For a workload with bursts of traffic for 5 minutes every few hours followed by complete inactivity, Lambda's pay-per-invocation model eliminates costs during idle periods. This makes it the most cost-effective option compared to continuously running or auto-scaled services.

Exam trap

SAA-C03 often tests the misconception that auto scaling or spot instances can achieve the same cost savings as serverless for intermittent workloads, but they still incur costs during idle periods or are not suitable for unpredictable bursts.

How to eliminate wrong answers

Option A is wrong because AWS Fargate charges for the vCPU and memory resources allocated to the task for the entire time the task is running, and even with auto scaling, there is a minimum task count and cold start delays, leading to higher costs for sporadic bursts. Option C is wrong because EC2 T3 instances with Unlimited Credits still incur hourly instance charges even when idle, and Unlimited Credits can lead to additional vCPU credit charges, not cost savings. Option D is wrong because Spot Instances reduce hourly rates but do not eliminate charges during inactivity; they are also not suitable for unpredictable workloads that may be interrupted.

72
Multi-Selectmedium

A solutions architect is designing a storage solution for a financial firm. The firm requires that data stored in Amazon S3 must be protected against accidental deletion and all changes to the data must be versioned. Which TWO features should the architect implement to meet these requirements? (Select TWO)

Select 2 answers
A.Enable S3 Versioning on the bucket.
B.Enable MFA Delete on the bucket.
C.Implement S3 Lifecycle policies to move data to Glacier.
D.Configure a Default Retention Period using S3 Object Lock in Governance mode.
E.Use S3 Block Public Access at the account level.
AnswersA, B

S3 Versioning allows multiple variants of an object to be kept in the same bucket. When an object is deleted, S3 inserts a delete marker instead of permanently removing the data, which allows for easy recovery of the original file and maintains a full history of all changes.

Why this answer

Option A is correct because enabling S3 Versioning on the bucket preserves every prior version of an object, so overwrites and deletes create new versions rather than destroying data, directly satisfying the requirement that all changes to the data be versioned. Option B is correct because MFA Delete adds a second authentication factor requiring the bucket owner's MFA token plus a valid request to permanently delete an object version or to suspend versioning, which protects the versioned data against accidental or malicious deletion. Together, Versioning provides the version history and MFA Delete guards the deletion of those versions, which is exactly the combination the financial firm needs.

Option C is not appropriate because Lifecycle policies only transition or expire objects and do not provide versioning or deletion protection. Option D is not appropriate because S3 Object Lock in Governance mode enforces a retention period (WORM) rather than versioning all changes, and Governance mode can be bypassed by users with special permissions. Option E is not appropriate because Block Public Access only restricts public exposure of the bucket and has nothing to do with versioning or protecting against deletion.

Exam trap

SAA-C03 often tests the distinction between versioning (preserves history) and MFA Delete (requires MFA to permanently delete versions), and candidates frequently confuse Object Lock Governance mode with MFA Delete as deletion protection.

73
Multi-Selecthard

A company is designing a multi-tier application. The web tier is public, and the database tier is private. Which TWO actions should the architect take to ensure the database tier is secure? (Select TWO.)

Select 2 answers
A.Place the database instances in a public subnet with a restrictive Network ACL.
B.Place the database instances in a private subnet.
C.Allow the database security group to receive traffic from the web tier security group.
D.Attach an Internet Gateway to the private subnet route table.
E.Use a Network ACL to allow all traffic from the internet to the database.
AnswersB, C

Private subnets are designed for backend resources that do not require direct internet access. By placing the database here, the architect ensures that the database is not exposed to the public internet, satisfying the fundamental security requirement for protecting backend data tiers from external unauthorized access attempts.

Why this answer

Option B is correct because placing the database instances in a private subnet removes them from direct internet reachability, since private subnets have no route to an Internet Gateway, which is the foundational control for protecting a database tier. Option C is correct because referencing the web tier's security group as the source in the database security group's inbound rule enforces least-privilege, instance-level access so only the web tier can reach the database on the required port (for example, 3306 for MySQL or 5432 for PostgreSQL). Option A is wrong because a public subnet is routable to the internet, so even with a restrictive Network ACL the database would still be exposed at the subnet level.

Option D is wrong because attaching an Internet Gateway to the private subnet's route table would make that subnet public and expose the database to inbound internet traffic. Option E is wrong because allowing all internet traffic to the database via a Network ACL directly violates the requirement to keep the database tier private and secure.

Exam trap

SAA-C03 often tests the misconception that a Network ACL alone can secure a database in a public subnet, but private subnet placement and security group references are essential.

74
Multi-Selecthard

A media streaming company stores high-value video assets in an Amazon S3 bucket. The company requires a resilient storage architecture that protects against accidental deletion, malicious overwrites, and zonal or regional outages. Which combinations of features should a Solutions Architect implement to achieve these requirements? (Choose TWO.)

Select 2 answers
A.Enable S3 Versioning on the bucket and configure MFA Delete to prevent accidental or malicious deletion of object versions.
B.Configure Amazon S3 Intelligent-Tiering to automatically move infrequently accessed video assets to lower-cost storage tiers.
C.Implement S3 Cross-Region Replication to asynchronously copy all video assets to an S3 bucket in a different AWS Region.
D.Attach a resource-based bucket policy that explicitly denies all delete object requests from any IAM user except the root account.
E.Enable S3 Object Lock in governance mode with a fixed retention period of 30 days for all uploaded video files.
AnswersA, C

S3 Versioning preserves every version of every object, ensuring deleted or overwritten files can be easily restored. Multi-Factor Authentication Delete adds an extra layer of authorization security, requiring physical or virtual MFA tokens for permanent deletion operations.

Why this answer

Enabling S3 Versioning ensures that previous versions are retained when objects are deleted or overwritten, protecting against accidental data loss. Furthermore, replicating objects to another AWS Region using S3 Cross-Region Replication guarantees durability and availability against catastrophic regional disruptions, satisfying robust disaster recovery best practices for critical media assets.

Exam trap

Candidates often confuse S3 versioning with replication, or pick features like cross-origin resource sharing (CORS) which are unrelated to regional disaster recovery and data protection.

75
Multi-Selectmedium

An architect is designing a secure storage solution for highly sensitive financial data in S3. Which THREE security controls should be implemented? (Select THREE.)

Select 3 answers
A.Enable S3 Block Public Access at the account level.
B.Use AWS KMS with Customer Managed Keys for encryption at rest.
C.Use Bucket Policies to enforce HTTPS/TLS access.
D.Allow all users in the organization to have full access.
E.Store data in a public bucket for easier access.
AnswersA, B, C

Blocking public access acts as a centralized safeguard to prevent accidental exposure of S3 buckets to the public internet. This is a crucial first line of defense, ensuring that no bucket within the account can be made public, regardless of individual bucket policy or IAM configuration errors.

Why this answer

Option A is correct because enabling S3 Block Public Access at the account level applies account-wide guardrails that override bucket policies and ACLs, preventing any bucket or object from being made public—an essential baseline for highly sensitive financial data. Option B is correct because AWS KMS with Customer Managed Keys (CMKs) gives the organization control over the key policy, rotation, and grants, providing encryption at rest with auditable key usage via CloudTrail, which is required for regulated financial data. Option C is correct because bucket policies using the aws:SecureTransport condition (e.g., "aws:SecureTransport": "false" with Deny) enforce HTTPS/TLS for all requests, preventing data in transit from being exposed over plain HTTP.

Option D is incorrect because granting all users in the organization full access violates least privilege and would allow unauthorized or accidental modification or exfiltration of sensitive data. Option E is incorrect because storing data in a public bucket exposes it to the internet and directly contradicts the requirement for a secure storage solution.

Exam trap

SAA-C03 often tests the shared responsibility model and S3 security best practices, and candidates may incorrectly believe that making a bucket public with IP restrictions is secure, or that broad organizational access is acceptable for sensitive data.

Page 1 of 2

Page 2

All pages