Courseiva

AWS Certified Solutions Architect - Associate (SAA-C03) — Questions 76–149

149 questions total · 2pages · All types, answers revealed

Page 1

Page 2 of 2

76
MCQmedium

A web application stores static files in Amazon S3. Due to regulatory requirements, the company must ensure that the files are replicated to a secondary region. What is the most efficient way to achieve this?

A.Use AWS DataSync to copy files periodically.
B.Enable S3 Cross-Region Replication on the source bucket.
C.Create an EventBridge rule to trigger a Lambda function for every upload.
D.Use AWS Storage Gateway to replicate local data to S3.
AnswerB

S3 Cross-Region Replication is the native, AWS-recommended way to handle automated, asynchronous replication of objects between buckets in different regions. It ensures data durability and compliance with disaster recovery policies by keeping a secondary copy of the data in a separate geographic region with minimal latency and no manual intervention.

Why this answer

S3 Cross-Region Replication (CRR) is the most efficient and native way to automatically replicate objects from a source bucket to a destination bucket in a different region. It replicates new objects as they are uploaded and can also replicate existing objects if configured, providing a managed, low-latency replication solution that meets regulatory requirements.

Exam trap

The trap is selecting custom or hybrid solutions like Lambda triggers or DataSync when a native, automated S3 feature (CRR) directly addresses the requirement with less operational overhead.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is designed for migrating or copying data between on-premises storage and AWS, or between AWS storage services, but it is not a continuous replication mechanism for S3-to-S3 and requires scheduling and management overhead. Option C is wrong because triggering a Lambda function on every upload to copy objects is a custom, serverless approach that adds complexity, potential failures, and does not handle large objects or metadata as efficiently as native CRR. Option D is wrong because AWS Storage Gateway is for hybrid cloud storage integration, not for replicating S3 data between regions.

77
MCQmedium

An application is experiencing intermittent performance issues due to high IOPS demand. The application currently uses a standard General Purpose SSD (gp2) volume. Which action will provide the best performance improvement?

A.Change the volume type to gp3.
B.Change the volume type to Provisioned IOPS SSD (io1/io2).
C.Increase the size of the gp2 volume.
D.Switch to Cold HDD (sc1) storage.
AnswerB

Provisioned IOPS SSD volumes are designed for mission-critical, throughput-intensive, and latency-sensitive workloads. They allow you to provision a specific number of IOPS that the volume will consistently maintain, effectively eliminating the throttling issues associated with general-purpose storage when the workload exceeds the burst capacity of gp2/gp3 volumes.

Why this answer

Provisioned IOPS SSD (io1/io2) volumes are designed for I/O-intensive workloads and allow you to specify a consistent IOPS rate. They provide significantly higher IOPS than gp2 volumes and are the best choice for applications with high IOPS demand. This directly addresses the performance issue.

Exam trap

SAA-C03 often tests the misconception that increasing gp2 volume size is the best way to increase IOPS, but it is inefficient; provisioned IOPS volumes are specifically designed for high IOPS workloads.

How to eliminate wrong answers

Option A is wrong because gp3 volumes, while offering better price-performance than gp2, have a baseline of 3,000 IOPS and can scale up to 16,000 IOPS, but for very high IOPS demands, io1/io2 can deliver up to 64,000 IOPS per volume, making them superior for high IOPS. Option C is wrong because increasing the size of a gp2 volume increases IOPS linearly (3 IOPS per GB), but this is inefficient and may not provide the required IOPS without excessive storage. Option D is wrong because Cold HDD (sc1) is designed for infrequent access and has lower IOPS, so it would worsen performance.

78
MCQhard

Refer to the exhibit. An application running on EC2 is receiving signature errors when accessing S3. The application uses an IAM role. What should the architect investigate first?

A.The IAM role permissions attached to the EC2 instance.
B.The local time on the EC2 instance.
C.The S3 bucket policy for explicit Deny statements.
D.The VPC endpoint for S3 for correct routing.
AnswerB

AWS authentication requires that the timestamp included in a request matches the current time within a small margin of error (usually five minutes). If the EC2 instance's clock is drifting or significantly offset, the signature will be rejected. Synchronizing the clock using NTP is the standard fix for signature mismatch issues.

Why this answer

AWS Signature Version 4, used for authenticating requests to S3, includes a timestamp and requires the client's clock to be within 15 minutes of AWS's time. If the EC2 instance's local time is skewed, the signature will be considered expired, resulting in SignatureDoesNotMatch errors. Since the application uses an IAM role, the credentials are automatically rotated and valid, so the most likely cause is time drift on the instance.

Exam trap

SAA-C03 often tests the misconception that signature errors are always due to permission issues, when in fact time skew is a frequent cause.

How to eliminate wrong answers

Option A is wrong because if the IAM role permissions were insufficient, the error would be AccessDenied, not a signature error. Option C is wrong because an explicit Deny in the bucket policy would also produce an AccessDenied error, not a signature mismatch. Option D is wrong because a misconfigured VPC endpoint would typically cause connectivity issues or timeouts, not signature errors.

79
MCQhard

Refer to the exhibit. An architect is reviewing a CloudFront Cache Policy for a dynamic site. The application is experiencing a low cache hit ratio, leading to high load on the origin servers. Based on the configuration, which change would most likely improve the cache hit ratio?

A.Change QueryStringBehavior to 'whitelist' or 'none'.
B.Increase the DefaultTTL and MinTTL values.
C.Set CookieBehavior to 'all' to include session data.
D.Enable HeaderBehavior for the 'Host' header.
AnswerA

By changing the behavior to 'none' or 'whitelist' only specific parameters, CloudFront can ignore non-essential or unique query strings when generating cache keys. This allows multiple requests with different unimportant parameters to be served from the same cache entry, significantly increasing the cache hit ratio.

Why this answer

In a CloudFront cache policy, QueryStringBehavior set to 'all' (or forwarding all query strings) causes CloudFront to treat every unique query string combination as a separate cache object, drastically reducing the cache hit ratio. Changing it to 'whitelist' (forwarding only the query strings the origin actually needs) or 'none' (ignoring query strings entirely) collapses many variants into a single cached object, which increases the cache hit ratio and reduces origin load. This is the most direct fix for the described symptom.

Exam trap

The trap is assuming that TTL settings or cookie/header forwarding improve cache hit ratio, when in fact forwarding more dimensions (cookies, headers, all query strings) fragments the cache and lowers the hit ratio; candidates must recognize that reducing the cache key dimensions is what improves hit ratio.

How to eliminate wrong answers

Option B is wrong because increasing DefaultTTL and MinTTL only extends how long objects stay in cache; it does not address the root cause of cache fragmentation caused by forwarding all query strings, so the hit ratio may improve marginally but not substantially. Option C is wrong because setting CookieBehavior to 'all' forwards all cookies, which further fragments the cache (each unique cookie combination becomes a separate object) and would likely worsen the hit ratio. Option D is wrong because enabling HeaderBehavior for the 'Host' header adds another cache key dimension, increasing fragmentation rather than reducing it, and the Host header is typically not needed for caching decisions in a standard CloudFront distribution.

80
MCQmedium

An AWS Lambda function processing data from an S3 bucket is experiencing performance issues due to 'cold starts' during sudden bursts of traffic. The company needs to ensure that the function responds with consistent low latency at all times. Which feature should be configured?

A.Increase the Lambda function's memory allocation.
B.Enable Provisioned Concurrency for the function.
C.Use an Amazon SQS queue to buffer requests to Lambda.
D.Deploy the Lambda function in multiple Availability Zones.
AnswerB

Provisioned Concurrency ensures that the function is initialized and ready to execute in double-digit milliseconds. By pre-allocating execution environments, the function avoids the latency penalty of loading the runtime and code, which is essential for maintaining performance during traffic spikes.

Why this answer

Provisioned Concurrency is the recommended solution for reducing cold start latency in AWS Lambda. It keeps a specified number of execution environments initialized and ready to respond immediately to incoming requests. This is critical for high-performance applications where unpredictable spikes in traffic could otherwise lead to unacceptable delays.

Exam trap

Candidates frequently select Amazon ElastiCache or API Gateway caching, assuming they solve Lambda cold starts, whereas only Provisioned Concurrency keeps execution environments initialized for instant response.

81
Multi-Selecteasy

A security team is concerned about accidental or malicious deletion of critical objects in an Amazon S3 bucket. Which TWO features should be enabled to prevent permanent data loss and require additional authentication for deletions?

Select 2 answers
A.S3 Versioning.
B.MFA Delete.
C.S3 Object Lock in compliance mode.
D.S3 Inventory.
E.S3 Transfer Acceleration.
AnswersA, B

Enabling S3 Versioning ensures that whenever an object is deleted, S3 inserts a delete marker instead of permanently removing the data. This allows administrators to easily restore previous versions of the object. It protects against accidental overwrites and provides a history of changes, which is essential for data durability and recovery.

Why this answer

S3 Versioning (A) is correct because it keeps multiple variants of an object in the same bucket, so when an object is overwritten or deleted, a delete marker is placed and the prior version remains recoverable, preventing permanent data loss from accidental or malicious deletion. MFA Delete (B) is correct because it adds an additional authentication factor requirement for permanently deleting object versions or changing the versioning state of the bucket, directly satisfying the requirement for extra authentication on deletions. Together, versioning preserves the data and MFA Delete protects the destructive operations.

S3 Object Lock in compliance mode (C) is not among the marked answers and, while it prevents deletion for a retention period, it does not itself require additional authentication for deletions. S3 Inventory (D) only provides scheduled reports of objects and metadata, and S3 Transfer Acceleration (E) only speeds up uploads/downloads via edge locations; neither prevents permanent deletion or adds authentication.

Exam trap

SAA-C03 often tests the confusion between Object Lock (immutability/retention) and MFA Delete (authentication for deletion) — candidates who pick Object Lock miss that the question explicitly asks for additional authentication.

82
MCQmedium

A company is using AWS Secrets Manager to manage database credentials. The company needs to automatically rotate these credentials every 30 days. How can this be accomplished?

A.Manually update the secret every 30 days.
B.Use a Lambda function integrated with Secrets Manager.
C.Use AWS Config to trigger a password reset.
D.Use Amazon SNS to send an alert for manual rotation.
AnswerB

Secrets Manager uses a Lambda function to perform the actual credential update on the database. This allows for customized rotation logic, such as updating the password in the database engine and then updating the entry in Secrets Manager, ensuring a seamless and fully automated end-to-end rotation lifecycle.

Why this answer

AWS Secrets Manager supports automatic rotation by invoking a Lambda function that implements the rotation logic (create new secret, update the database, test, and finalize). Configuring the rotation schedule (e.g., every 30 days) on the secret triggers this Lambda automatically, eliminating manual intervention.

Exam trap

The trap is selecting AWS Config or SNS because they sound like automation/management services, but only Secrets Manager's native Lambda integration performs actual credential rotation.

How to eliminate wrong answers

Option A is wrong because manual updates do not provide automatic rotation and are error-prone, violating the requirement for automatic 30-day rotation. Option C is wrong because AWS Config is a configuration compliance service, not a credential rotation mechanism, and cannot reset database passwords. Option D is wrong because SNS only sends notifications; it does not perform rotation, so the credentials would still require manual updates.

83
MCQmedium

A company hosts a batch processing application on Amazon EC2 instances that process large datasets during business hours. The jobs are interruptible and can resume from the last checkpoint if terminated. Which strategy provides the most cost-effective solution?

A.Purchase Reserved Instances for the maximum expected load.
B.Use On-Demand instances with Auto Scaling groups.
C.Use Spot Instances for the batch processing jobs.
D.Use Dedicated Hosts to ensure maximum hardware utilization.
AnswerC

Spot Instances provide substantial cost savings for workloads that are fault-tolerant and interruptible. Because the application uses checkpoints to resume processing after a termination, the inherent risk of Spot interruption does not jeopardize data integrity, making this the most cost-optimized choice for non-critical, batch-oriented data processing tasks.

Why this answer

Spot Instances are the most cost-effective choice because the batch jobs are interruptible and can resume from checkpoints, making them tolerant of the sudden termination that Spot Instances can experience. Spot Instances offer up to 90% discounts compared to On-Demand, and since the workload can handle interruptions, the cost savings are maximized without impacting overall job completion. This aligns perfectly with the fault-tolerant nature of the application.

Exam trap

SAA-C03 often tests the trade-off between cost and reliability, and candidates may incorrectly choose Reserved Instances for long-term savings without considering that the workload is interruptible and thus a perfect fit for Spot Instances.

How to eliminate wrong answers

Option A is wrong because Reserved Instances require a long-term commitment and are best for steady-state, non-interruptible workloads, not for interruptible batch jobs where capacity needs may fluctuate. Option B is wrong because On-Demand instances with Auto Scaling provide elasticity but are significantly more expensive than Spot Instances for interruptible workloads. Option D is wrong because Dedicated Hosts are for compliance or licensing requirements and are the most expensive option, offering no cost benefit for interruptible batch processing.

84
MCQmedium

An organization wants to protect their web application from common web exploits like SQL injection and cross-site scripting (XSS). Which AWS service should they use?

A.AWS Shield Standard.
B.AWS WAF.
C.Amazon GuardDuty.
D.Network ACLs.
AnswerB

AWS WAF provides the ability to define rules that block specific application-layer exploits. By applying these rules to an ALB or CloudFront distribution, the organization can actively prevent SQL injection and XSS attacks, directly addressing the requirement to protect the application from these common web-based vulnerabilities.

Why this answer

AWS WAF is the managed web application firewall that inspects HTTP/HTTPS requests at Layer 7 and applies rules to block SQL injection, cross-site scripting, and other OWASP Top 10 exploits. It integrates with CloudFront, ALB, API Gateway, and AppSync, and supports managed rule groups plus custom rules. AWS Shield Standard only defends against Layer 3/4 DDoS, not application-layer exploits.

Exam trap

SAA-C03 often tests the confusion between Shield (DDoS, Layers 3/4) and WAF (application-layer exploits, Layer 7) — candidates who see 'protect from attacks' and pick Shield miss that SQLi/XSS are explicitly Layer 7 concerns.

How to eliminate wrong answers

Option A is wrong because AWS Shield Standard provides automatic DDoS protection at Layers 3 and 4 and does not inspect HTTP payloads for SQLi or XSS. Option C is wrong because Amazon GuardDuty is a threat-detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail to surface suspicious activity — it detects but does not block web exploits. Option D is wrong because Network ACLs are stateless Layer 3/4 subnet-level filters that operate on IP/port/protocol and cannot parse HTTP request bodies or query strings.

85
MCQmedium

A data analysis team needs to perform complex SQL queries on petabytes of data stored in S3. Which service provides the best performance for this analytical workload?

A.Amazon RDS.
B.Amazon Redshift Spectrum.
C.Amazon DynamoDB.
D.AWS Glue.
AnswerB

Redshift Spectrum enables high-performance querying of petabytes of data directly in S3. It uses the same massively parallel processing engine as Amazon Redshift, allowing for efficient, high-speed execution of complex analytical queries across massive datasets, making it the superior choice for large-scale data analysis tasks on cloud storage.

Why this answer

Amazon Athena is a serverless, interactive query service that makes it easy to analyze data in S3 using standard SQL. For large analytical workloads, Amazon Redshift Spectrum allows you to query data directly from S3, providing even higher performance for petabyte-scale data by leveraging the Redshift massively parallel processing engine, which is optimized for complex join and aggregation operations across massive datasets.

Exam trap

Candidates frequently choose Athena for petabyte-scale data analytics, overlooking that Redshift Spectrum leverages a massively parallel processing engine optimized for heavy, complex joins on massive datasets.

86
MCQmedium

A company is launching a new application with a DynamoDB backend. They expect the traffic to be highly unpredictable, with sudden spikes and long periods of inactivity. Which capacity mode is the most cost-effective?

A.Provisioned capacity with Auto Scaling.
B.On-demand capacity.
C.Provisioned capacity with a high baseline and no scaling.
D.Global Tables with Provisioned capacity.
AnswerB

On-demand mode is the most cost-effective for this specific profile because it charges per request. There is no baseline hourly cost for throughput, meaning that during long periods of inactivity, the cost drops to near zero. It also handles sudden, massive spikes instantly without any manual management or scaling lag.

Why this answer

DynamoDB On-Demand capacity mode automatically scales to handle unpredictable traffic without requiring capacity planning, and you pay only for the read/write requests you consume. For workloads with sudden spikes and long idle periods, this eliminates the cost of over-provisioned capacity during inactivity and the risk of throttling during spikes.

Exam trap

SAA-C03 often tests the trade-off between On-Demand (unpredictable/spiky, pay-per-request) and Provisioned with Auto Scaling (predictable, cost-optimized) — candidates pick Provisioned with Auto Scaling thinking it handles spikes, ignoring its reaction delay and idle cost.

How to eliminate wrong answers

Option A is wrong because Provisioned capacity with Auto Scaling still requires setting minimum and maximum capacity bounds and reacts to utilization metrics with some delay — during sudden spikes, scaling may lag and cause throttling, and during idle periods you still pay for the minimum provisioned capacity. Option C is wrong because a high baseline with no scaling wastes money during idle periods and cannot handle spikes beyond the baseline, leading to throttling. Option D is wrong because Global Tables is a multi-Region replication feature, not a capacity mode — it adds cost and complexity without addressing the unpredictable traffic pattern.

87
MCQmedium

A company has a legacy application that requires a persistent file system shared across multiple EC2 instances. The file system must be highly available and support standard file system protocols. Which solution is most appropriate?

A.Mount an Amazon EBS volume to multiple EC2 instances simultaneously.
B.Use Amazon EFS with mount targets in multiple Availability Zones.
C.Create an S3 bucket and use it as a mounted file system via S3FS.
D.Set up a self-managed NFS server on an EC2 instance.
AnswerB

EFS provides a managed, scalable NFS file system that supports simultaneous access from multiple instances. By configuring mount targets in multiple AZs, the solution ensures high availability, as EFS handles data replication across those zones, making it resilient to single AZ failure while meeting shared file system application requirements.

Why this answer

Amazon EFS provides a fully managed, scalable, and highly available NFS file system that can be mounted simultaneously by multiple EC2 instances across multiple AZs. It is designed to be resilient, automatically replicating data across AZs within a region. This makes it the ideal choice for legacy applications that require shared storage without the management overhead of self-managed storage servers or distributed file systems.

Exam trap

Candidates mistakenly select Amazon EBS because it is the default block storage, ignoring that EBS cannot be shared simultaneously across multiple instances in different Availability Zones.

88
MCQhard

Refer to the exhibit. An application running on EC2 instances needs to pull large binary files from an S3 bucket with maximum throughput. Which configuration should the architect implement to ensure the highest network performance?

A.Attach an Internet Gateway to the VPC.
B.Configure an S3 Gateway VPC Endpoint in the VPC.
C.Use a NAT Gateway for all outbound traffic.
D.Install an AWS Direct Connect connection.
AnswerB

A Gateway VPC Endpoint allows private access to S3 without leaving the AWS network. This provides the highest possible throughput by routing traffic over the internal AWS backbone, minimizing latency and avoiding the limitations associated with NAT gateways or public internet routes, thus optimizing performance for data-intensive tasks.

Why this answer

To achieve maximum throughput, the application should use an S3 VPC Endpoint. This ensures that traffic between the EC2 instance and S3 stays within the AWS network, bypassing the public internet and avoiding potential bandwidth bottlenecks. Using VPC Endpoints also provides secure connectivity, which is critical for high-performance data transfers, as it prevents the exposure of traffic to external network risks while maintaining consistent latency and high speed.

Exam trap

Candidates select NAT Gateways or Internet Gateways, assuming any internet route works, missing that VPC Endpoints keep traffic on the private AWS network for maximum throughput.

89
MCQmedium

A company hosts a web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in the local memory of the EC2 instances. Users report losing their sessions when the Auto Scaling group scales in or replaces unhealthy instances. Which solution ensures session persistence while maintaining high availability?

A.Configure the Application Load Balancer to use stickiness with a duration-based cookie.
B.Store the session state in an Amazon S3 bucket with versioning enabled.
C.Move the session state to an Amazon ElastiCache for Redis cluster.
D.Replicate the session data across all EC2 instances using a broadcast script.
AnswerC

ElastiCache for Redis offers low-latency, in-memory performance ideal for session management. By centralizing the session data, the application becomes stateless, allowing the Auto Scaling group to terminate or replace instances without impacting the user experience, as the state is preserved independently of the compute resources.

Why this answer

Storing session state in ElastiCache for Redis externalizes it from the EC2 instances, so any instance in the Auto Scaling group can serve any user's request regardless of scale-in or instance replacement. Redis provides low-latency, highly available shared state with replication and Multi-AZ failover, ensuring session persistence and high availability simultaneously.

Exam trap

SAA-C03 often tests the misconception that ALB stickiness solves session loss — stickiness only helps while the instance lives, so it fails during scale-in or instance replacement, which is exactly the scenario described.

How to eliminate wrong answers

Option A is wrong because ALB stickiness only pins a user to one instance; when that instance is terminated during scale-in or fails, the session is still lost, so it does not solve the underlying problem. Option B is wrong because S3 is object storage with high latency and eventual consistency characteristics for overwrites; it is not designed for high-frequency session reads/writes and would degrade application performance. Option D is wrong because broadcasting session data across instances is fragile, does not scale, and creates race conditions and consistency issues as the group changes size.

90
MCQhard

An enterprise financial application stores critical transaction records in Amazon Aurora MySQL. The company requires a cross-Region disaster recovery strategy with a Recovery Point Objective of less than 1 minute and a Recovery Time Objective of less than 5 minutes. Which architecture achieves this?

A.Take daily automated snapshots of the primary Aurora database and copy the snapshot to a secondary AWS Region.
B.Implement Amazon Aurora Global Databases with a primary writer Region and a cross-Region reader Region.
C.Configure standard MySQL asynchronous replication from an Amazon EC2 instance running MySQL in one Region to another.
D.Deploy a multi-AZ Aurora cluster and use AWS Database Migration Service for continuous replication to another Region.
AnswerB

Aurora Global Database replicates committed writes to a secondary Region with typical latency under one second, meeting the sub-one-minute RPO. Promoting the secondary reader to writer completes in under a minute, satisfying the five-minute RTO for cross-Region disaster recovery.

Why this answer

Amazon Aurora Global Database is designed for cross-Region disaster recovery with typical replication latency under 1 second, easily meeting the RPO of less than 1 minute. It supports fast failover to a secondary Region, typically completing in under 1 minute, which satisfies the RTO of less than 5 minutes. This is the purpose-built solution for low-RPO, low-RTO cross-Region DR on Aurora.

Exam trap

SAA-C03 often tests RPO/RTO numbers — candidates pick Multi-AZ or DMS thinking they provide cross-Region DR, but only Aurora Global Database delivers sub-second RPO and sub-minute RTO across Regions.

How to eliminate wrong answers

Option A is wrong because daily snapshots yield an RPO of up to 24 hours and an RTO measured in hours (snapshot restore time), far exceeding the <1 minute RPO and <5 minute RTO requirements. Option C is wrong because self-managed MySQL on EC2 with asynchronous replication lacks Aurora's managed failover, has higher operational overhead, and cannot guarantee sub-minute RPO/RTO reliably. Option D is wrong because Multi-AZ Aurora only provides HA within a single Region — it does not provide cross-Region DR, and DMS is not designed for sub-minute RPO continuous replication of an Aurora cluster.

91
MCQmedium

A company wants to improve the performance of its static website hosted on S3. Which strategy provides the most significant performance gain for global users?

A.Enable S3 Transfer Acceleration on the bucket.
B.Configure the S3 bucket to use Multi-Region replication.
C.Use Amazon CloudFront with the S3 bucket as the origin.
D.Upgrade the S3 storage class to S3 Intelligent-Tiering.
AnswerC

CloudFront caches static files at hundreds of edge locations worldwide. This drastically reduces latency for global users by serving content from the nearest edge location rather than the origin S3 bucket. This is the industry-standard architecture for high-performance delivery of static web content.

Why this answer

Static websites hosted on S3 are limited by the speed of the browser-to-bucket connection. By placing an Amazon CloudFront distribution in front of the S3 bucket, content is cached at edge locations globally. This brings the content closer to the users, reducing the distance data travels and minimizing latency, which results in faster page load times regardless of where the user is located geographically.

Exam trap

Candidates often select S3 Cross-Region Replication, thinking it optimizes performance, when it is actually a disaster recovery feature. CloudFront is needed for global caching and performance.

92
MCQhard

An application processes large batches of data from an S3 bucket. The process can take hours. If an instance fails, the batch is lost. Which design pattern ensures the most resilient batch processing?

A.Use an Auto Scaling group with a single instance to process the S3 files sequentially.
B.Use an SQS queue to store tasks and an Auto Scaling group to process them.
C.Directly trigger Lambda functions from S3 and increase the timeout.
D.Use a single large EC2 instance to process the data in memory.
AnswerB

This architecture decouples the workload from the compute. If an instance fails, the message remains in the queue to be retried. The Auto Scaling group ensures that sufficient compute power is always available to clear the queue, providing a highly resilient and scalable solution for long-running batch processing.

Why this answer

Using an SQS queue to decouple the producer and consumer is the ideal pattern. The S3 event notification sends a message to the queue, and instances poll the queue for tasks. If an instance fails, the message becomes visible again in the queue after the visibility timeout, allowing another instance to pick up the task and resume processing.

Exam trap

Candidates mistakenly choose SNS or direct S3 notifications to EC2, missing that without SQS decoupling, failed instances will permanently lose the batch processing tasks.

93
MCQhard

Refer to the exhibit. A solutions architect reviewed an AWS CloudFormation template used to deploy an Auto Scaling group for a production web application. During an AWS Availability Zone outage in us-east-1, users experienced partial application downtime even though the Auto Scaling group reported instances running. Why is this architecture failing resiliency best practices?

A.The Launch Template version is hardcoded to version 1 instead of using $Latest or $Default.
B.The Auto Scaling group defines Availability Zones directly instead of referencing subnets across multiple zones.
C.The MinSize and DesiredCapacity are set too low to handle sudden spikes in traffic during an outage.
D.The Auto Scaling group is missing a health check type configuration set to ELB instead of EC2.
AnswerB

Hardcoding Availability Zones rather than referencing subnets across multiple zones prevents the Auto Scaling group from launching replacement instances elsewhere during a zone outage. Referencing multi-AZ subnets satisfies the resiliency constraint, maintaining capacity when one zone fails.

Why this answer

For an Auto Scaling group to survive an Availability Zone outage, it must launch instances across multiple subnets in different AZs. When the ASG specifies Availability Zones directly (or uses a single subnet), all instances land in one AZ, so an AZ failure takes down the entire fleet even though the ASG still reports 'running' instances in the failed zone. Referencing subnets across multiple AZs lets the ASG rebalance and launch replacements in healthy zones.

Exam trap

SAA-C03 often tests the misconception that 'instances running' means the architecture is resilient — candidates overlook that all instances may be in one AZ, so an AZ outage causes downtime despite the ASG reporting healthy.

How to eliminate wrong answers

Option A is wrong because a hardcoded Launch Template version affects configuration drift and update rollout, not AZ resiliency — the instances would still be distributed across AZs if subnets are correct. Option C is wrong because MinSize/DesiredCapacity affect capacity and scaling headroom, not whether instances are spread across AZs; low capacity alone does not cause an AZ outage to take down the app. Option D is wrong because health check type (EC2 vs ELB) affects instance replacement when health checks fail, but it does not control AZ distribution — even with ELB health checks, a single-AZ ASG fails during an AZ outage.

94
MCQmedium

A company has a data lake on Amazon S3 where files are uploaded frequently. The access patterns for these files are unpredictable; some are accessed multiple times a day for a week, while others are never accessed again. The company needs to reduce storage costs without manual intervention or performance impact. Which storage strategy is most cost-effective?

A.Store all data in S3 Standard-Infrequent Access (S3 Standard-IA).
B.Implement S3 Intelligent-Tiering for the data lake.
C.Configure an S3 Lifecycle policy to move objects to S3 Glacier Deep Archive after 30 days.
D.Use S3 One Zone-Infrequent Access (S3 One Zone-IA) for all objects.
AnswerB

Intelligent-Tiering automatically moves objects between frequent, infrequent, and archive instant access tiers as usage changes. There are no retrieval fees, making it the most cost-optimized choice for unpredictable workloads where some data remains hot for a week while other data cools down immediately without a predictable schedule.

Why this answer

S3 Intelligent-Tiering automatically moves objects between access tiers (Frequent, Infrequent, Archive Instant, and optional Archive/Deep Archive) based on changing access patterns, with no retrieval fees and no manual lifecycle rules. This matches the unpredictable access described while reducing storage costs without performance impact.

Exam trap

SAA-C03 often tests the misconception that Standard-IA or lifecycle-to-Glacier is always cheapest, when unpredictable access patterns actually make Intelligent-Tiering the cost-effective, no-management answer.

How to eliminate wrong answers

Option A is wrong because S3 Standard-IA charges a per-GB retrieval fee and has a 30-day minimum storage duration, so frequently accessed files would incur unexpected costs and it doesn't adapt to changing patterns. Option C is wrong because moving objects to Glacier Deep Archive after 30 days would make frequently accessed files unavailable for hours and incur retrieval costs, harming performance. Option D is wrong because S3 One Zone-IA stores data in a single AZ (lower durability) and still charges retrieval fees, and it doesn't adapt to unpredictable access.

95
MCQmedium

A company must share an S3 bucket with a third-party vendor. The vendor has their own AWS account. What is the most secure method to grant the vendor access to the S3 bucket?

A.Share the company's IAM user credentials with the vendor.
B.Create an IAM user for the vendor and share the access keys.
C.Create a cross-account IAM role for the vendor to assume.
D.Make the S3 bucket public and restrict by IP address.
AnswerC

A cross-account role provides a secure, temporary, and audited method for external access. The vendor assumes the role using their own credentials, which AWS then swaps for temporary security tokens. This provides the company with full control over the permissions assigned to the role and the duration of access.

Why this answer

Creating a cross-account IAM role allows the vendor to assume a role in the company's account using their own credentials, granting temporary, scoped access to the S3 bucket without sharing long-term credentials. This follows AWS security best practices for least privilege and credential management. It is the most secure method because no permanent secrets are exchanged.

Exam trap

SAA-C03 often tests the difference between long-term IAM user credentials and temporary role-based access, and candidates may incorrectly choose sharing access keys as a simpler solution without recognizing the security risks.

How to eliminate wrong answers

Option A is wrong because sharing IAM user credentials violates AWS security best practices and gives the vendor full access to that user's permissions, with no auditability or revocation ease. Option B is wrong because creating an IAM user for the vendor and sharing access keys still involves long-term credentials that can be leaked or misused, and it does not follow the principle of least privilege. Option D is wrong because making the bucket public, even with IP restrictions, exposes data to potential unauthorized access and is not considered secure for sensitive data.

96
MCQmedium

Refer to the exhibit. An IAM policy is applied to an IAM user to grant access to an S3 bucket. However, the user is still receiving an 'Access Denied' error when attempting to list the objects in the bucket. What is the cause of this error?

A.The policy is missing the s3:ListBucket permission.
B.The user does not have an IAM role attached.
C.The bucket policy is explicitly denying access.
D.The S3 bucket is encrypted with a KMS key.
AnswerA

The s3:ListBucket action is required to list the contents of an S3 bucket. The current policy only provides read access to the objects themselves, not the bucket's file listing. Adding this action to the policy will resolve the Access Denied error when performing the list command.

Why this answer

The provided policy grants the 's3:GetObject' permission, which allows the user to read specific objects within the bucket, but it does not grant 's3:ListBucket'. The ListBucket permission is required to view the contents of the bucket. Since the user lacks this permission, the operation fails with an Access Denied error despite having access to individual objects.

This is a common permissions oversight in IAM policy management.

Exam trap

Candidates assume that 'GetObject' permission implicitly grants the ability to see the bucket contents. In reality, listing the bucket and accessing an object are two distinct, granular S3 API permissions.

97
Multi-Selecthard

A company is planning to connect its on-premises data center to AWS to support a high-performance hybrid cloud architecture. The connection must support a consistent 10 Gbps bandwidth and provide a private, dedicated network path to reduce jitter and latency. Which TWO steps should the architect take?

Select 2 answers
A.Provision an AWS Direct Connect dedicated connection.
B.Configure a Site-to-Site VPN as the primary connection.
C.Set up a Virtual Private Gateway (VGW) or Direct Connect Gateway.
D.Enable Accelerated Site-to-Site VPN.
E.Use Amazon Route 53 Resolver for all DNS queries.
AnswersA, C

A dedicated connection provides a physical Ethernet port (1 Gbps, 10 Gbps, or 100 Gbps) dedicated to a single customer. This ensures that the bandwidth is not shared and provides the most consistent performance for high-throughput applications compared to hosted connections or VPNs.

Why this answer

Option A is correct because an AWS Direct Connect dedicated connection provides a private, dedicated network path from the on-premises data center to AWS and supports consistent 10 Gbps bandwidth, which directly addresses the requirements for reduced jitter and latency. Option C is correct because the Direct Connect connection must terminate on the AWS side at a Virtual Private Gateway (for a single VPC) or a Direct Connect Gateway (to reach multiple VPCs across Regions), making this a required configuration step for the hybrid architecture. Option B is incorrect because a Site-to-Site VPN runs over the public internet, so it cannot guarantee a consistent 10 Gbps or a dedicated private path.

Option D is incorrect because Accelerated Site-to-Site VPN uses AWS Global Accelerator to improve public-internet VPN performance but still does not provide a dedicated private connection or guaranteed 10 Gbps. Option E is incorrect because Route 53 Resolver handles DNS resolution between on-premises and AWS and is unrelated to establishing the dedicated high-bandwidth network path.

Exam trap

SAA-C03 often tests the misconception that a Site-to-Site VPN can deliver dedicated 10 Gbps consistent bandwidth — candidates who pick VPN or Accelerated VPN miss that only Direct Connect provides a private, dedicated circuit.

98
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer (ALB). The application requires high availability across two Availability Zones (AZs). Which architectural design ensures the most resilient traffic distribution?

A.Deploy all instances in one AZ and use a Route 53 failover policy to a secondary region.
B.Use an Auto Scaling group with a single AZ and enable Cross-Zone Load Balancing on the ALB.
C.Place EC2 instances in an Auto Scaling group distributed across two AZs behind the ALB.
D.Use a Network Load Balancer (NLB) with static IP addresses for each instance in one AZ.
AnswerC

Distributing Auto Scaling groups across multiple AZs ensures that if one AZ experiences an outage, instances in the other AZ continue serving traffic. The ALB automatically routes requests to healthy targets across the available zones, maintaining service continuity and ensuring the application remains resilient against localized hardware or power failures.

Why this answer

High availability across two AZs requires resources to be distributed across both AZs so that the failure of one AZ does not take down the application. An Auto Scaling group spanning two AZs behind an ALB ensures that healthy targets exist in both AZs, and the ALB automatically routes traffic only to healthy targets in each enabled AZ.

Exam trap

SAA-C03 often tests the misconception that enabling Cross-Zone Load Balancing alone provides high availability, when in fact the underlying compute resources must be distributed across multiple AZs.

How to eliminate wrong answers

Option A is wrong because deploying all instances in one AZ creates a single point of failure; a Route 53 failover to a secondary region is a disaster recovery strategy, not high availability within a region, and it introduces significant RTO/RPO. Option B is wrong because a single-AZ Auto Scaling group still concentrates all instances in one AZ; Cross-Zone Load Balancing only distributes traffic evenly across healthy targets in enabled AZs and cannot compensate for the loss of the entire AZ. Option D is wrong because an NLB with static IPs in one AZ does not provide multi-AZ resilience, and static IPs per instance are not how NLB targets are addressed.

99
MCQeasy

A company is launching a high-profile marketing campaign and expects a significant increase in traffic. They are concerned about potential Distributed Denial of Service (DDoS) attacks targeting their Application Load Balancer. Which AWS service provides advanced protection and includes 24/7 access to the AWS Shield Response Team (SRT)?

A.AWS Shield Standard
B.AWS Shield Advanced
C.AWS WAF
D.AWS Global Accelerator
AnswerB

AWS Shield Advanced offers tailored protection for applications running on EC2, ELB, CloudFront, and Route 53. It provides sophisticated detection, real-time visibility into attacks, and direct access to the AWS Shield Response Team for manual intervention during complex attacks, ensuring maximum availability for critical campaigns.

Why this answer

AWS Shield Advanced provides expanded DDoS protection for web applications. Unlike the free Standard tier, it includes additional mitigation capabilities, 24/7 access to the Shield Response Team, and financial protection against bill spikes caused by DDoS attacks, making it ideal for high-profile applications.

Exam trap

Candidates often assume standard AWS Shield provides 24/7 support. Standard is included for free but lacks the dedicated response team and advanced mitigation features found in the paid Advanced tier.

100
MCQmedium

A developer is using an EC2 instance to process images. The images are stored in an S3 bucket. The developer notices that the network transfer between S3 and the EC2 instance is the bottleneck. How can the developer resolve this?

A.Use an Amazon S3 Gateway Endpoint.
B.Increase the EC2 instance size.
C.Enable S3 Transfer Acceleration.
D.Use CloudFront to cache the images.
AnswerA

A Gateway Endpoint allows traffic to route privately and directly from a VPC to S3 within the same region. By keeping traffic within the AWS network, it avoids public internet congestion, leading to improved throughput and lower latency for data-intensive operations like image processing, directly addressing the identified bottleneck.

Why this answer

An Amazon S3 Gateway Endpoint allows EC2 instances in a VPC to access S3 without traversing the public internet or a NAT gateway. Traffic stays within the AWS network, which can reduce latency and improve throughput, resolving the network bottleneck. It also eliminates data transfer costs associated with NAT gateways.

Exam trap

SAA-C03 often tests the misconception that S3 Transfer Acceleration or CloudFront can improve performance for EC2-to-S3 transfers within the same region, when in fact a VPC endpoint is the correct solution.

How to eliminate wrong answers

Option B is wrong because increasing the EC2 instance size may improve compute capacity but does not address network transfer bottlenecks between the instance and S3. Option C is wrong because S3 Transfer Acceleration is designed to speed up uploads to S3 from geographically distant clients by using AWS edge locations; it does not improve performance for EC2 instances in the same region. Option D is wrong because CloudFront caches content at edge locations for external users; it does not accelerate the backend transfer between EC2 and S3.

101
MCQhard

Refer to the exhibit. The web application is showing high latency and 503 errors. The database CPU usage is low. What is the most likely cause and solution?

A.Increase the RDS instance size to handle more connections.
B.Implement Amazon RDS Proxy for connection pooling.
C.Enable Multi-AZ failover to distribute the load.
D.Add more read replicas to the RDS cluster.
AnswerB

RDS Proxy sits between the application and the database, managing a pool of connections and reusing them. This prevents connection exhaustion at the database level and ensures that the application doesn't experience wait times for new connections. It is the ideal solution for high-concurrency, connection-intensive database workloads.

Why this answer

The symptoms — high latency, 503 errors, low database CPU — point to connection exhaustion rather than compute saturation. Each application instance opening its own database connections can exhaust the RDS max_connections limit, causing new connections to be refused and 503s to surface at the web tier. Amazon RDS Proxy pools and multiplexes connections, allowing many application connections to share a smaller set of database connections, which resolves the bottleneck without scaling the database.

Exam trap

SAA-C03 often tests the assumption that 'high latency = need bigger instance' — candidates pick vertical scaling, but the low CPU metric is the tell that the bottleneck is connections, not compute, and the answer is RDS Proxy.

How to eliminate wrong answers

Option A is wrong because the database CPU is low — increasing instance size adds compute that is not the bottleneck and does not address connection limits (though larger instances do raise max_connections, the symptom profile points to pooling, not raw capacity). Option C is wrong because Multi-AZ failover is a high-availability mechanism, not a load-distribution mechanism; the standby does not serve read traffic, so enabling it does nothing for latency or 503s. Option D is wrong because read replicas offload read traffic, but the question does not indicate a read-heavy workload, and adding replicas does not solve connection exhaustion on the primary.

102
MCQmedium

A company wants to ensure that no developer can create an Amazon S3 bucket in any AWS region except for us-east-1 and us-west-2 across their entire AWS Organization. Which solution provides the most efficient and centralized way to enforce this across all member accounts?

A.Apply an IAM policy to every developer user in each account that denies s3:CreateBucket in restricted regions.
B.Configure an S3 bucket policy on all existing buckets to prevent the creation of new buckets in other regions.
C.Attach a Service Control Policy (SCP) to the organization root that denies s3:CreateBucket if the region is not us-east-1 or us-west-2.
D.Enable AWS Config in all accounts and create a custom rule to delete any bucket created in a restricted region.
AnswerC

Service Control Policies allow the organization's management account to set the maximum available permissions for member accounts. A Deny rule in an SCP acts as a guardrail that overrides any local IAM permissions, ensuring that restricted services or regions remain inaccessible regardless of local configurations within the accounts.

Why this answer

A Service Control Policy (SCP) attached to the organization root applies to all member accounts and can deny s3:CreateBucket when the requested region is not us-east-1 or us-west-2. SCPs are the centralized, efficient way to enforce guardrails across an AWS Organization, affecting all principals without per-account changes.

Exam trap

SAA-C03 often tests the misconception that IAM policies or bucket policies can enforce organization-wide region restrictions, when only SCPs provide centralized preventive control.

How to eliminate wrong answers

Option A is wrong because applying IAM policies to every developer in each account is not centralized, is error-prone, and new accounts or users would not be covered. Option B is wrong because S3 bucket policies apply to existing buckets and cannot prevent the creation of new buckets in other regions. Option D is wrong because AWS Config rules are reactive and only delete non-compliant buckets after creation, not prevent them; it also requires per-account setup.

103
MCQmedium

A company is concerned about unauthorized access and potential data exfiltration within their AWS environment. They need a service that can continuously monitor VPC Flow Logs, AWS CloudTrail management events, and DNS logs to identify suspicious activities using machine learning. Which solution should the architect recommend for centralized threat detection?

A.Enable Amazon GuardDuty and integrate it with AWS Organizations for cross-account visibility.
B.Configure AWS Inspector to perform network reachability assessments on all EC2 instances.
C.Deploy AWS Shield Advanced to protect all public-facing endpoints from DDoS attacks.
D.Use AWS Config to monitor changes in security group rules and VPC configurations.
AnswerA

Amazon GuardDuty continuously monitors for malicious activity and unauthorized behavior using machine learning and threat intelligence. It analyzes data sources like VPC Flow Logs and CloudTrail to identify anomalies. This managed service provides a comprehensive view of the security posture across multiple AWS accounts through integration with AWS Organizations.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors VPC Flow Logs, AWS CloudTrail management events, and DNS logs using machine learning and threat intelligence to identify suspicious activities. Integrating it with AWS Organizations enables centralized threat detection across all accounts, matching the requirement for cross-account visibility.

Exam trap

SAA-C03 often tests the confusion between GuardDuty (threat detection) and Inspector (vulnerability assessment) or Config (configuration compliance), causing candidates to select a service that doesn't analyze logs for threats.

How to eliminate wrong answers

Option B is wrong because AWS Inspector performs vulnerability assessments on EC2 instances and container images, not continuous threat detection from logs. Option C is wrong because AWS Shield Advanced provides DDoS protection, not threat detection from VPC Flow Logs, CloudTrail, or DNS logs. Option D is wrong because AWS Config monitors resource configuration changes and compliance, but does not analyze logs with machine learning for threat detection.

104
Multi-Selecthard

An organization is using AWS Control Tower to manage multiple AWS accounts. They need to implement a set of guardrails to ensure that all accounts remain compliant with security best practices. Which THREE components or features are part of a standard AWS Control Tower landing zone implementation?

Select 3 answers
A.Preventive guardrails implemented using Service Control Policies (SCPs).
B.Detective guardrails implemented using AWS Config rules.
C.A centralized logging account and a security tooling account.
D.Amazon Macie enabled by default on all S3 buckets in member accounts.
E.Amazon GuardDuty for automated threat detection across all accounts.
AnswersA, B, C

Control Tower uses preventive guardrails to stop actions that would lead to non-compliance. These are implemented as SCPs that are applied to Organizational Units (OUs). For example, a preventive guardrail might block the ability to disable CloudTrail or change critical security settings across all member accounts.

Why this answer

Option A is correct because AWS Control Tower preventive guardrails are enforced through Service Control Policies (SCPs) attached to OUs, which restrict what actions member accounts can perform. Option B is correct because detective guardrails in Control Tower are implemented as AWS Config rules (often deployed via conformance packs) that detect and flag noncompliant resources. Option C is correct because a standard Control Tower landing zone provisions a dedicated log archive account for centralized logging and an audit (security tooling) account for security and compliance tooling.

Option D is incorrect because Amazon Macie is not enabled by default on all S3 buckets as part of the landing zone; it is an optional data-security service. Option E is incorrect because GuardDuty is not automatically enabled across all accounts by Control Tower itself; it can be integrated via services like AWS Security Hub or delegated administration, but it is not a built-in landing zone component.

Exam trap

SAA-C03 often tests which services are mandatory landing zone components vs optional add-ons, baiting candidates who assume popular services like GuardDuty or Macie are enabled by default.

105
MCQhard

An application has been migrated to AWS, but the performance is inconsistent. The architect finds that the application uses a legacy database driver that requires persistent connections, which is exhausting database connections. What is the best way to handle this?

A.Increase the max_connections parameter.
B.Use Amazon RDS Proxy.
C.Implement a local database connection pooler.
D.Migrate to Amazon Aurora Serverless.
AnswerB

RDS Proxy sits between the application and the database to pool and reuse connections. This effectively reduces the load on the database engine, as it no longer needs to manage thousands of individual client connections. This is the optimal solution for applications that cannot be modified to use modern, efficient connection pooling.

Why this answer

Amazon RDS Proxy sits between the application and the database, pooling and reusing persistent connections so that many application connections map to a small number of database connections. This directly addresses the legacy driver's persistent-connection behavior that is exhausting the database's connection limit, without requiring application changes.

Exam trap

SAA-C03 often tests the misconception that raising max_connections or adding a local pooler solves connection exhaustion, when the real fix is a managed proxy that multiplexes connections at the database endpoint.

How to eliminate wrong answers

Option A is wrong because increasing max_connections only raises the ceiling temporarily and does not solve the underlying connection-exhaustion pattern; it can also degrade performance by overloading the database with too many concurrent sessions. Option C is wrong because a local connection pooler still requires each application instance to maintain its own pool and does not centralize or multiplex connections across the fleet, so it does not fully solve the problem at scale. Option D is wrong because Aurora Serverless scales compute capacity but does not inherently pool or multiplex client connections, so persistent connections can still exhaust the endpoint.

106
Multi-Selectmedium

A security architect is designing a multi-tier application in a VPC. The requirement is to block all traffic from a specific range of malicious IP addresses (CIDR 192.0.2.0/24) while allowing standard web traffic (HTTPS) from all other sources to the web tier. Which TWO actions should the architect take to implement this? (Select TWO.)

Select 2 answers
A.Create an inbound rule in the Network ACL to deny traffic from 192.0.2.0/24.
B.Add a deny rule to the web tier Security Group for CIDR 192.0.2.0/24.
C.Configure AWS Shield Standard to automatically block the 192.0.2.0/24 subnet.
D.Configure the web tier Security Group to allow inbound traffic on port 443 from 0.0.0.0/0.
E.Update the VPC Route Table to blackhole all traffic destined for 192.0.2.0/24.
AnswersA, D

Network ACLs act as a firewall for associated subnets and are stateless, meaning they require rules for both inbound and outbound traffic. They support explicit deny rules, which allow administrators to block specific malicious CIDR blocks from entering the network at the earliest possible entry point.

Why this answer

Option A is correct because Network ACLs are stateless, subnet-level firewalls that support explicit deny rules, so an inbound deny rule for 192.0.2.0/24 blocks that malicious CIDR before it can reach any resource in the subnet. Option D is correct because Security Groups are stateful, instance-level firewalls that only support allow rules, so permitting inbound TCP port 443 from 0.0.0.0/0 allows standard HTTPS web traffic from all other sources to the web tier. Together these satisfy both requirements: the NACL denies the malicious range while the Security Group allows HTTPS from everywhere else.

Option B is wrong because Security Groups cannot contain deny rules; they are allow-only. Option C is wrong because AWS Shield Standard provides automatic protection against common DDoS attacks and does not let you block a specific CIDR like 192.0.2.0/24. Option E is wrong because route tables control routing, not inbound filtering, and blackholing a destination CIDR would not block inbound traffic from that source to the web tier.

Exam trap

SAA-C03 often tests the difference between Security Groups (allow-only) and NACLs (allow/deny), and candidates may incorrectly try to add a deny rule to a Security Group.

107
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer (ALB). The application has spikes in traffic. What should be configured to ensure performance and cost efficiency?

A.Use a fixed size Auto Scaling group at maximum capacity.
B.Implement Auto Scaling with target tracking policies.
C.Configure the ALB to handle all scaling automatically.
D.Use reserved instances to handle all peak traffic.
AnswerB

Target tracking scaling policies allow the architecture to maintain a specific metric, such as average CPU utilization, across a fleet. This ensures that the application always has enough compute power to handle load spikes while reducing the instance count when demand drops, achieving both performance and cost-efficiency.

Why this answer

Target tracking scaling policies automatically adjust the number of EC2 instances based on a specified metric (e.g., average CPU utilization or request count per target), maintaining performance during spikes while scaling in during low demand to optimize cost. This is the most efficient and responsive approach for variable workloads behind an ALB.

Exam trap

SAA-C03 often tests the misconception that the load balancer itself can scale compute capacity, or that reserved instances are suitable for handling traffic spikes, when in fact Auto Scaling with dynamic policies is required.

How to eliminate wrong answers

Option A is wrong because a fixed-size Auto Scaling group at maximum capacity wastes cost during low-traffic periods and does not scale dynamically. Option C is wrong because an ALB does not scale EC2 instances; it only distributes incoming traffic to registered targets, and while ALB itself scales automatically, it cannot manage compute capacity. Option D is wrong because reserved instances provide billing discounts for steady-state usage, not dynamic scaling; they do not handle spikes and can lead to over-provisioning or under-provisioning.

108
MCQmedium

A company wants to improve the security of its Amazon RDS for PostgreSQL database. They want to eliminate the need for storing database passwords in application code and simplify the management of database access for their EC2-based applications. Which solution should they implement?

A.Configure the RDS instance to use IAM Database Authentication and assign a role to the EC2 instances.
B.Use AWS Secrets Manager to store the RDS credentials and retrieve them at runtime.
C.Enable SSL/TLS encryption for all database connections to protect the password in transit.
D.Store the database password in a private S3 bucket and allow the EC2 instances to read the file.
AnswerA

IAM Database Authentication allows applications to connect to RDS using an authentication token generated by IAM. This method leverages the EC2 instance profile to provide the necessary permissions, ensuring that credentials are never stored in the code and are automatically managed and rotated by AWS.

Why this answer

IAM Database Authentication for RDS for PostgreSQL lets EC2 instances (or other AWS principals) authenticate to the database using short-lived authentication tokens generated from their IAM role credentials, so no static database password is ever stored in application code. The EC2 instance assumes an IAM role, and the RDS instance is configured to allow IAM authentication; the application then calls generate-db-auth-token (or the SDK equivalent) to obtain a 15-minute token used as the password. This eliminates password storage and centralizes access management through IAM policies, satisfying both the security and simplification goals.

Exam trap

SAA-C03 often tests the distinction between eliminating static credentials entirely (IAM database authentication) and merely managing them more securely (Secrets Manager); candidates frequently pick Secrets Manager because it sounds like a best practice, but the question specifically asks to eliminate the need for storing passwords in application code, which IAM authentication does more directly.

How to eliminate wrong answers

Option B is wrong because AWS Secrets Manager still requires the application to retrieve and use a stored password, so a secret (albeit managed) is still involved and the application must handle it at runtime; it does not eliminate password storage in the sense of removing static credentials from the authentication flow, and it adds rotation complexity. Option C is wrong because SSL/TLS only encrypts data in transit; it does not remove the need to store a database password in application code or simplify access management. Option D is wrong because storing a password in an S3 bucket is an insecure anti-pattern that still requires the application to fetch and use a static password, and it does not provide IAM-integrated database authentication.

109
MCQmedium

A company's security team identifies that its public-facing web application is being targeted by SQL injection and cross-site scripting (XSS) attacks. The application is running on EC2 instances behind an Application Load Balancer (ALB). Which service should the solutions architect implement to protect the application from these specific web-based attacks?

A.AWS Shield Advanced
B.Amazon GuardDuty
C.AWS WAF
D.Amazon Inspector
AnswerC

AWS WAF allows users to create web ACLs that contain rules to inspect HTTP/HTTPS requests. It includes pre-configured managed rule groups that specifically target SQL injection and XSS patterns, providing a robust defense layer at the application level to mitigate these common security threats effectively.

Why this answer

AWS WAF is purpose-built to inspect HTTP/HTTPS requests at Layer 7 and block application-layer exploits such as SQL injection and cross-site scripting. It integrates natively with ALB, CloudFront, and API Gateway, and provides managed rule groups (e.g., AWSManagedRulesSQLiRuleSet, AWSManagedRulesCommonRuleSet) that detect these exact attack patterns. Because the workload sits behind an ALB, WAF can be attached directly to the load balancer to filter malicious requests before they reach the EC2 instances.

Exam trap

SAA-C03 often tests the confusion between AWS WAF (Layer 7 application attacks like SQLi/XSS) and AWS Shield (Layer 3/4 DDoS), causing candidates to pick Shield Advanced when the question explicitly names web exploits.

How to eliminate wrong answers

Option A is wrong because AWS Shield Advanced only mitigates volumetric DDoS attacks at Layers 3/4 (and some Layer 7 DDoS via automatic WAF rule creation), but it does not natively detect SQL injection or XSS payloads. Option B is wrong because Amazon GuardDuty is a threat-detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events to surface findings — it does not block or filter HTTP requests. Option D is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container images for software CVEs and network exposure; it does not inspect live HTTP traffic for injection attacks.

110
MCQeasy

A company wants to ensure that its internal applications can access Amazon S3 without the traffic ever leaving the AWS network or passing through the public internet. What should they implement to achieve this securely?

A.Configure a NAT Gateway in a public subnet to route S3 traffic.
B.Use an AWS Direct Connect connection between the VPC and S3.
C.Create a VPC Gateway Endpoint for Amazon S3 and update the route tables.
D.Set up a VPN connection between the private subnet and the S3 service.
AnswerC

A Gateway Endpoint for S3 is a cost-effective and highly available way to provide private access to S3. It does not require a NAT gateway or public IP addresses. By adding a route to the VPC route table, all traffic to S3 is automatically routed through the private endpoint.

Why this answer

A VPC Gateway Endpoint for Amazon S3 provides a private, logical connection between a VPC and S3 that keeps traffic on the AWS backbone and never traverses the public internet. Updating route tables to direct S3-bound traffic to the gateway endpoint ensures instances in private subnets reach S3 privately.

Exam trap

The trap is choosing NAT Gateway or VPN because they provide connectivity, but the question's key constraint — traffic never leaving the AWS network — rules them out; only a VPC Gateway Endpoint satisfies that requirement for S3.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway routes traffic through the public internet (via an internet gateway), which violates the requirement that traffic never leave the AWS network. Option B is wrong because AWS Direct Connect is a dedicated physical connection from on-premises to AWS, not a mechanism for VPC-to-S3 private access within AWS. Option D is wrong because a VPN connection encrypts traffic but still routes it over the public internet, and it is designed for on-premises-to-VPC connectivity, not VPC-to-S3.

111
MCQmedium

A company is migrating a high-performance database to Amazon RDS for MySQL. The workload involves intensive read operations, causing significant latency during peak traffic. Which solution provides the most effective performance improvement with minimal architectural changes?

A.Enable Multi-AZ deployment for the RDS instance.
B.Upgrade the RDS instance to a larger instance class.
C.Create one or more RDS Read Replicas.
D.Move the database to Amazon DynamoDB.
AnswerC

Read replicas allow you to distribute read traffic across multiple instances. By offloading read operations from the primary database, you significantly improve performance and application responsiveness. This is the recommended AWS best practice for scaling read-heavy RDS workloads while maintaining the primary instance for critical write operations.

Why this answer

Amazon RDS Read Replicas are designed specifically for read-heavy workloads. By offloading SELECT queries to one or more replicas, the primary instance can focus solely on write operations. This architecture improves throughput and reduces latency without requiring application-level logic changes beyond updating the database connection string.

This approach is standard for scaling RDS instances horizontally to meet fluctuating demand while maintaining data consistency.

Exam trap

Candidates frequently select Multi-AZ deployments for read-heavy workloads, confusing high availability with horizontal read scaling. Multi-AZ is for failover, whereas Read Replicas are for offloading read traffic.

112
MCQmedium

A company has a high-performance database running on Amazon RDS for MySQL. The workload is read-heavy and experiences latency during peak hours. Which solution will improve read performance with minimal architectural changes?

A.Enable Multi-AZ deployment for the existing RDS instance.
B.Increase the instance size to a larger DB instance class.
C.Create one or more RDS Read Replicas and update the application connection string.
D.Migrate the database to Amazon DynamoDB.
AnswerC

Read replicas enable asynchronous replication from the primary database, effectively offloading read traffic. By updating the application to direct read queries to these endpoints, you maximize database throughput. This approach is the most efficient way to scale read performance in RDS environments without complex refactoring.

Why this answer

Creating an RDS Read Replica allows the application to offload read-only traffic from the primary database instance. By routing read queries to the replica, the primary instance can focus solely on write operations. This architecture is a standard practice for scaling read-heavy workloads in relational databases, ensuring lower latency and better resource utilization without requiring significant code modifications or complex database sharding.

Exam trap

Candidates sometimes suggest Multi-AZ to improve read performance. Multi-AZ is for high availability and failover, whereas Read Replicas are specifically designed to offload read traffic and scale performance.

113
MCQmedium

An organization needs to perform continuous security assessments of its Amazon EC2 instances to identify software vulnerabilities and unintended network exposure. Which service should they use to automate these assessments and provide a centralized view of the findings?

A.AWS Trusted Advisor to check for security groups that allow unrestricted access.
B.Amazon Inspector to automatically discover and scan EC2 instances for vulnerabilities.
C.AWS CloudTrail to monitor and log all API calls made to the EC2 instances.
D.VPC Flow Logs to analyze traffic patterns and identify potential security threats.
AnswerB

Amazon Inspector provides automated, continuous vulnerability scanning for EC2 instances and container images. It uses a unified findings format and integrates with AWS Security Hub, making it the standard choice for organizations looking to automate their vulnerability management and maintain a high level of security compliance.

Why this answer

Amazon Inspector is an automated vulnerability management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure. It is particularly effective for EC2 instances as it can scan both the operating system and the installed applications, providing detailed findings and remediation advice to improve the security posture.

Exam trap

Candidates often choose AWS Config or Trusted Advisor. While helpful, these do not perform deep vulnerability scanning of the operating system and installed software packages like Inspector does.

114
MCQmedium

A global e-commerce site uses an Amazon RDS for MySQL database. Users in different regions are complaining about slow page load times when browsing product catalogs. How can the architect improve read performance for global users with minimal changes to the application?

A.Enable Multi-AZ deployment for the RDS instance.
B.Create Read Replicas in different AWS Regions.
C.Upgrade the RDS instance to a larger instance class.
D.Enable Enhanced Monitoring with a 1-second granularity.
AnswerB

Creating Read Replicas in regions geographically closer to the users allows the application to redirect read-heavy traffic, such as product catalog browsing, to local replicas. This reduces the round-trip time for database queries, significantly improving the overall responsiveness and performance of the e-commerce application.

Why this answer

Cross-region read replicas allow you to serve read traffic from a location physically closer to your users, reducing latency. This architectural pattern is essential for high-performing global applications where the primary database is located in a single region but the user base is distributed worldwide.

Exam trap

Candidates often choose database migration tools or global tables for MySQL, overlooking that RDS MySQL supports simple cross-region read replicas.

115
MCQmedium

A company is developing a mobile application that allows users to sign in using their social media accounts (e.g., Google or Facebook). After signing in, the application needs to obtain temporary AWS credentials to upload photos directly to an Amazon S3 bucket. Which service should the architect use?

A.AWS IAM User with static access keys
B.Amazon Cognito
C.AWS Directory Service
D.AWS Security Token Service (STS) with a manual web identity federation implementation
AnswerB

Amazon Cognito Identity Pools enable you to grant your users temporary, limited-privilege access to AWS resources. By federating with social providers, Cognito manages the exchange of identity tokens for AWS STS credentials, providing a secure and scalable way for mobile users to interact with AWS services directly.

Why this answer

Amazon Cognito provides identity pools that directly support social identity providers (Google, Facebook, Amazon, Apple) and exchange the resulting tokens for temporary, scoped AWS credentials via STS. This is the managed, recommended way to implement web identity federation for mobile apps without building the token-exchange flow yourself. Cognito user pools handle authentication, and identity pools handle AWS credential vending.

Exam trap

SAA-C03 often tests Cognito vs manual STS web identity federation, baiting candidates who know STS is the underlying mechanism but miss that Cognito is the managed, recommended service for social login.

How to eliminate wrong answers

Option A is wrong because embedding static IAM user access keys in a mobile app is a severe security anti-pattern — keys can be extracted from the app binary and cannot be safely rotated per user. Option C is wrong because AWS Directory Service is for managed Microsoft AD or Simple AD integration with enterprise directories, not social media login federation. Option D is wrong because while STS AssumeRoleWithWebIdentity is the underlying mechanism, implementing web identity federation manually means building and maintaining the token validation, provider trust, and credential refresh logic that Cognito already provides — it is not the recommended service-level answer.

116
MCQmedium

An application processes data in bursts, running for 30 seconds every few minutes. The workload is unpredictable. Which compute service offers the most cost-effective solution?

A.Amazon EC2 with Auto Scaling
B.AWS Lambda
C.AWS Fargate
D.Amazon EC2 Spot Instances
AnswerB

Lambda is perfectly suited for this pattern because you are only charged when the code is actually running. Since the task only takes 30 seconds and occurs sporadically, Lambda eliminates the cost of idle infrastructure, providing significant savings over any solution that requires maintaining running servers or containers 24/7.

Why this answer

AWS Lambda is a serverless compute service that bills based on the number of requests and the duration of execution in milliseconds. For short-lived, bursty, and unpredictable workloads, Lambda is more cost-effective than provisioning servers that would sit idle for the majority of the time between processing events.

Exam trap

Candidates might choose ECS or EC2 with auto scaling, ignoring that very short, bursty execution times make a fully serverless function approach significantly more cost-effective.

117
MCQhard

A media streaming company stores millions of video assets in an Amazon S3 bucket. Compliance regulations mandate that objects must be protected against accidental deletion, malicious tampering, and region-wide disasters. The solution must prevent permanent deletion even by users with root credentials during a retention period. Which combination of features meets these requirements?

A.Enable S3 Versioning, apply an S3 Lifecycle rule to transition objects to S3 Glacier, and configure AWS Backup vaults.
B.Enable S3 Versioning, configure S3 Object Lock in compliance mode, and set up S3 Cross-Region Replication to another AWS Region.
C.Apply strict AWS Identity and Access Management (IAM) bucket policies denying s3:DeleteObject, and enable server-side encryption.
D.Configure Amazon S3 Intelligent-Tiering, enable Multi-Factor Authentication (MFA) Delete, and attach bucket policies.
AnswerB

S3 Object Lock in compliance mode enforces a WORM retention period that no user, including the root account, can shorten or bypass, directly satisfying the mandate against permanent deletion. Versioning preserves prior object versions against tampering, while Cross-Region Replication provides the required resilience against region-wide disasters.

Why this answer

Enabling S3 Versioning preserves every version of every object, protecting against accidental overwrites and deletions. Configuring S3 Object Lock in compliance mode ensures that objects cannot be deleted or modified by any user, including the root account, until the retention period expires. Finally, S3 Cross-Region Replication protects against catastrophic regional disasters by maintaining synchronized copies.

Exam trap

Candidates forget to include S3 Object Lock in compliance mode, mistakenly believing that standard versioning or bucket policies alone can protect data from being deleted by root users.

118
Multi-Selecthard

An organization needs to improve the resilience of its EC2-based application. Which THREE actions should the architect perform? (Select THREE.)

Select 3 answers
A.Distribute EC2 instances across multiple Availability Zones.
B.Configure an Auto Scaling group to replace unhealthy instances.
C.Use a single large EC2 instance instead of multiple smaller ones.
D.Implement health checks for the load balancer to monitor instances.
E.Place all instances in a single Auto Scaling group with a fixed capacity.
AnswersA, B, D

Spreading instances across multiple Availability Zones ensures that the application remains operational even if an entire data center experiences an outage. This is a primary requirement for high availability, as it mitigates the risk of localized infrastructure failures affecting the entire application availability and preventing end-user service disruption during regional events.

Why this answer

Option A is correct because distributing EC2 instances across multiple Availability Zones ensures the application survives the failure of an entire AZ, since each AZ has independent power, cooling, and networking. Option B is correct because an Auto Scaling group continuously performs health checks and automatically replaces unhealthy instances, restoring capacity without manual intervention. Option D is correct because load balancer health checks detect unhealthy targets and stop routing traffic to them, so users are only sent to functioning instances.

Option C is wrong because a single large instance is a single point of failure and does not improve resilience. Option E is wrong because a fixed-capacity Auto Scaling group cannot scale out to absorb load or compensate for lost capacity, so it does not meaningfully improve resilience.

Exam trap

SAA-C03 often tests the misconception that simply increasing instance size or count in one AZ provides high availability, when true resilience requires distribution across multiple AZs plus automated health checks and replacement.

119
MCQmedium

A company has several VPCs in a single region that need to access an S3 bucket for data processing. Currently, traffic goes through a NAT Gateway in each VPC. What is the most cost-effective way to provide access to S3?

A.Create an Interface VPC Endpoint for S3 in each VPC.
B.Set up a Gateway VPC Endpoint for S3 in each VPC.
C.Deploy a single NAT Instance in a shared services VPC.
D.Use a Transit Gateway to route all S3 traffic through a central VPC.
AnswerB

Gateway Endpoints are a cost-free feature of VPCs that route traffic to S3 through the AWS private network. They do not incur hourly charges or data processing fees, unlike NAT Gateways. This makes them the most economical solution for any VPC-based workload that needs to communicate heavily with S3.

Why this answer

Gateway VPC Endpoints for S3 are free of charge and provide a direct, private connection to S3 within the AWS network. By replacing NAT Gateways—which charge per-hour and per-GB of data processed—with Gateway Endpoints, the company eliminates data transfer costs and the hourly gateway fee for S3-bound traffic.

Exam trap

Candidates often suggest Interface VPC Endpoints or keep NAT Gateways, forgetting that Gateway VPC Endpoints for S3 are completely free and avoid hourly charges and data processing fees.

120
MCQhard

A research firm is running a tightly coupled High Performance Computing (HPC) workload on AWS using EC2 instances. The firm needs to minimize network latency and maximize inter-node communication speed. Which network enhancement should the architect recommend?

A.Enable Enhanced Networking with the Elastic Network Adapter (ENA).
B.Deploy the instances using an Elastic Fabric Adapter (EFA).
C.Use a Spread Placement Group for the EC2 instances.
D.Implement AWS Global Accelerator for the cluster.
AnswerB

Elastic Fabric Adapter provides OS-bypass capabilities, allowing HPC applications to communicate directly with the network interface hardware. This significantly reduces latency and jitter for Message Passing Interface (MPI) workloads, which is essential for tightly coupled clusters that need to share data rapidly between compute nodes.

Why this answer

Elastic Fabric Adapter (EFA) is a network interface for Amazon EC2 instances that enables customers to run applications requiring high levels of inter-node communications at scale. It uses a custom protocol to provide lower and more consistent latency than traditional TCP/IP stacks used in standard networking.

Exam trap

Candidates often choose standard Elastic Network Interfaces (ENIs) or standard placement groups, overlooking the specialized ultra-low latency requirements of HPC workloads.

121
MCQmedium

A company is hosting a web application on EC2 instances behind an Application Load Balancer. The security team requires that all data in transit between the client and the ALB be encrypted using TLS. Which service should the architect use to manage the SSL/TLS certificates for the ALB?

A.AWS Secrets Manager
B.AWS Certificate Manager (ACM)
C.AWS Key Management Service (KMS)
D.IAM Server Certificate Upload
AnswerB

ACM provides a managed service to generate or import SSL/TLS certificates and associate them directly with an ALB. It handles the complexities of certificate lifecycle management, including automated renewals, ensuring that the web application maintains continuous, encrypted communication with clients without manual intervention or certificate expiration risks.

Why this answer

AWS Certificate Manager (ACM) is the managed service designed to provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services like Application Load Balancers, CloudFront, and API Gateway. ACM handles certificate renewal automatically and integrates natively with ALB listeners, making it the correct choice for managing TLS certificates for the ALB.

Exam trap

The trap is confusing certificate management (ACM) with key management (KMS) or secret storage (Secrets Manager), or falling back to the legacy IAM certificate upload method that lacks automatic renewal.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is for storing and rotating secrets such as database credentials and API keys, not for issuing or managing TLS certificates that integrate with ALB listeners. Option C is wrong because AWS KMS is a key management service for encryption keys used to encrypt data at rest, not for provisioning or deploying SSL/TLS certificates to load balancers. Option D is wrong because IAM Server Certificate Upload is a legacy method for uploading third-party certificates to IAM for use with ELB Classic and CloudFront; it does not provide managed renewal and is not the recommended approach for ALB, which uses ACM.

122
MCQhard

Refer to the exhibit. A company has applied the following bucket policy to an S3 bucket named 'finance-reports'. A user is attempting to download a file from this bucket from the IP address 203.0.113.15 using an authenticated session without MFA. What will be the result of this request?

A.The request will be allowed because the IP address is within the allowed range.
B.The request will be denied because both conditions must be true for the policy to grant access.
C.The request will be allowed because the 'Bool' condition is only evaluated if MFA is configured.
D.The request will be denied because S3 bucket policies require an explicit 'Deny' statement to block traffic.
AnswerB

In AWS policy evaluation, multiple conditions within a single statement are evaluated using a logical AND. The user has the correct source IP, but because they did not authenticate with Multi-Factor Authentication, the second condition fails, and the permission is not granted to the user.

Why this answer

S3 bucket policy conditions are evaluated with AND logic by default — all conditions in a single Condition block must be true for the statement to apply. Since the request comes from an allowed IP but lacks MFA authentication, the Bool condition (aws:MultiFactorAuthPresent = true) fails, so the policy does not grant access and the request is denied.

Exam trap

SAA-C03 often tests whether candidates understand that multiple conditions in a single S3 policy statement are ANDed, not ORed — candidates incorrectly assume satisfying one condition is enough.

How to eliminate wrong answers

Option A is wrong because satisfying only the IP condition is insufficient — the MFA Bool condition must also be true, and AND logic applies across all conditions in the statement. Option C is wrong because the 'aws:MultiFactorAuthPresent' condition key is evaluated regardless of whether MFA is configured; if the key is absent or false, the condition evaluates to false and access is denied. Option D is wrong because S3 bucket policies use implicit deny — if no statement explicitly allows the action, access is denied; an explicit Deny is not required to block the request.

123
MCQmedium

A company is hosting a multi-tier web application on AWS using Amazon EC2 instances in a private subnet behind an Application Load Balancer (ALB). The security team requires that all incoming web traffic is encrypted in transit from the client to the ALB and from the ALB to the backend EC2 instances. Which combination of configurations meets these requirements?

A.Configure an HTTP listener on the ALB and configure the backend instances to accept HTTP traffic on port 80.
B.Configure an HTTPS listener on the ALB and route traffic to the backend instances using HTTP on port 80.
C.Configure an HTTPS listener on the ALB using an ACM certificate and configure the backend instances to accept HTTPS traffic.
D.Configure a TCP listener on the ALB and install self-signed certificates directly on the target EC2 instances.
AnswerC

Deploying an HTTPS listener on the ALB terminates client TLS securely using certificates managed by AWS Certificate Manager, while forwarding traffic over HTTPS to backend instances satisfies the explicit requirement for comprehensive end-to-end encryption across all application tiers.

Why this answer

To encrypt traffic from client to ALB, an HTTPS listener with an ACM certificate is required. To encrypt traffic from ALB to backend EC2 instances, the backend must accept HTTPS (TLS) traffic, which means the ALB target group protocol must be HTTPS and the instances must have certificates installed and be listening on the HTTPS port. Option C is the only one that satisfies both requirements.

Exam trap

SAA-C03 often tests the misconception that an HTTPS listener alone encrypts the entire path; candidates forget that the ALB-to-backend connection is separate and must also be configured for HTTPS.

How to eliminate wrong answers

Option A is wrong because an HTTP listener does not encrypt client-to-ALB traffic, and HTTP on port 80 to backends does not encrypt ALB-to-instance traffic. Option B is wrong because while the HTTPS listener encrypts client-to-ALB traffic, routing to backends over HTTP on port 80 leaves the ALB-to-instance leg unencrypted. Option D is wrong because ALB does not support TCP listeners (that is NLB), and even if it did, terminating TLS on the instances without an HTTPS listener on the ALB would not encrypt client-to-ALB traffic.

124
MCQeasy

A company has several VPCs in the same region that need to access an Amazon S3 bucket for data logging. Currently, data is transferred over the public internet, incurring data transfer charges. What is the most cost-effective way to allow the VPCs to access S3?

A.Deploy a NAT Gateway in each VPC.
B.Create an S3 Interface Endpoint (PrivateLink) in each VPC.
C.Establish a AWS Direct Connect connection to S3.
D.Create an S3 Gateway Endpoint in each VPC.
AnswerD

S3 Gateway Endpoints are a free feature of VPCs. They require no management of hardware or software and do not charge for the amount of data processed. By updating the route table to point S3 traffic to the endpoint, the company eliminates data transfer costs to the internet.

Why this answer

S3 Gateway Endpoints are the most cost-effective solution because they are provided at no additional cost and do not incur hourly charges or data processing fees. They allow traffic to stay within the AWS network, eliminating data transfer out charges to the public internet while maintaining high security and performance.

Exam trap

Candidates often suggest a NAT Gateway. While this allows private subnet access, it is expensive due to data processing fees and is not the most cost-effective solution for S3 access.

125
MCQmedium

An application running on Amazon Aurora MySQL experiences significant performance degradation during peak hours due to a surge in read-only traffic. The database currently uses a single primary instance and one replica. What is the most effective way to scale the database for these spikes while maintaining high performance?

A.Manually add more Aurora Replicas during peak hours.
B.Configure Aurora Auto Scaling for the Aurora Replicas.
C.Increase the instance size of the primary Aurora instance.
D.Use Amazon SQS to buffer incoming read requests.
AnswerB

Aurora Auto Scaling automatically manages the number of read replicas based on a specified target metric like CPU utilization. This ensures that the read capacity scales out instantly during traffic peaks and scales in when the demand decreases. It provides a highly performant and cost-optimized solution for managing fluctuating read-heavy workloads on Aurora.

Why this answer

Aurora Auto Scaling automatically adds and removes Aurora Replicas based on metrics like CPU utilization or the number of connections, scaling read capacity in response to demand spikes without manual intervention. This is the most effective solution because it handles peak-hour surges dynamically while maintaining high availability across Availability Zones. Manual scaling (Option A) is reactive and slow, and vertical scaling of the primary (Option C) does not address read traffic distribution.

Exam trap

SAA-C03 often tests the difference between horizontal read scaling (add replicas, use Auto Scaling) and vertical scaling (bigger instance) — candidates pick 'increase instance size' because it sounds like a quick fix, but it does not address read distribution across replicas.

How to eliminate wrong answers

Option A is wrong because manually adding replicas during peak hours requires human intervention, is reactive rather than proactive, and cannot respond quickly enough to sudden traffic surges — it also risks over- or under-provisioning. Option C is wrong because increasing the primary instance size scales write capacity and overall compute, but read-only traffic is served by replicas, so a bigger primary does not distribute read load. Option D is wrong because SQS is a message queue for asynchronous decoupling, not a mechanism for serving synchronous read queries — buffering read requests would add latency and does not scale the database tier.

126
MCQhard

A global gaming company wants to reduce latency for its players who are distributed worldwide. The application uses UDP-based traffic and requires a static entry point to simplify firewall management. Which service should the architect recommend to optimize the network path?

A.Amazon CloudFront.
B.AWS Global Accelerator.
C.Amazon Route 53 with Geolocation routing.
D.AWS Direct Connect.
AnswerB

AWS Global Accelerator is the best choice for this scenario as it provides two static Anycast IP addresses and supports UDP traffic. It routes player traffic over the high-speed AWS global private network instead of the public internet, which reduces jitter and latency, providing a more consistent and resilient gaming experience for global users.

Why this answer

AWS Global Accelerator uses the AWS global network to route traffic to the optimal regional endpoint based on health and proximity. Unlike CloudFront, which is primarily for HTTP/S content, Global Accelerator supports non-HTTP protocols like UDP. It provides static IP addresses that act as a fixed entry point, improving performance by keeping traffic on the AWS backbone.

Exam trap

Candidates often choose Amazon CloudFront because it is the most well-known global routing service, ignoring that CloudFront primarily handles HTTP/S traffic whereas Global Accelerator natively supports UDP-based protocols.

127
MCQeasy

A security engineer needs to block a specific range of malicious IP addresses from accessing an entire subnet within a VPC. The solution must ensure that the traffic is rejected before it reaches any EC2 instances. Which AWS feature should be used to implement this restriction?

A.Security Groups
B.Network Access Control Lists (NACLs)
C.AWS WAF
D.AWS Shield Standard
AnswerB

NACLs provide a layer of security at the subnet level and support both allow and deny rules. By placing a deny rule with a lower rule number than the default allow rule, the security engineer can effectively block the malicious IP range for all resources within that subnet.

Why this answer

Network ACLs are stateless, subnet-level firewalls that evaluate traffic before it reaches any EC2 instance, making them the correct tool to block a malicious IP range at the subnet boundary. Because NACLs support explicit deny rules with CIDR ranges, they can reject the traffic before it hits the instances.

Exam trap

SAA-C03 often tests the misconception that Security Groups can block specific IPs — they cannot, because they only support allow rules; candidates who forget this choose A instead of NACLs.

How to eliminate wrong answers

Option A is wrong because Security Groups are stateful, instance-level firewalls that only support allow rules — they cannot explicitly deny a specific IP range. Option C is wrong because AWS WAF operates at Layer 7 on CloudFront, ALB, or API Gateway and filters HTTP requests, not raw IP traffic at the subnet level. Option D is wrong because AWS Shield Standard only protects against DDoS attacks and does not allow custom IP blocking rules.

128
Multi-Selectmedium

A database administrator needs to ensure that an Amazon RDS for MySQL instance can withstand an Availability Zone failure and provide low-latency reads for a reporting application. Which TWO steps should be taken?

Select 2 answers
A.Enable Multi-AZ deployment for the RDS instance.
B.Create a Read Replica in a different Availability Zone.
C.Use EBS Snapshots to back up the database every 5 minutes.
D.Enable Enhanced Monitoring with a 1-second granularity.
E.Implement a Network Load Balancer in front of the RDS instance.
AnswersA, B

Multi-AZ deployment is the standard feature for high availability in Amazon RDS. It creates a standby instance in a different Availability Zone and uses synchronous replication. In the event of a failure, RDS automatically fails over to the standby, ensuring the database remains available without manual intervention or data loss during the transition.

Why this answer

Enabling Multi-AZ provides the high availability needed to survive an AZ failure by maintaining a synchronous standby. Creating a Read Replica in a different AZ offloads read traffic from the primary instance, improving performance for the reporting application while also providing an additional layer of data redundancy across the region.

Exam trap

Candidates often forget that a Multi-AZ standby is not accessible for reads. To offload read traffic, a separate Read Replica is mandatory, as the standby instance is strictly for failover.

129
MCQeasy

A company is concerned that its database credentials, currently stored as environment variables in AWS Lambda, are not being rotated regularly. Which AWS service should the company use to securely store and automatically rotate these credentials?

A.AWS Systems Manager Parameter Store with SecureString parameters.
B.AWS Key Management Service (KMS) to encrypt the environment variables.
C.AWS Secrets Manager with its built-in rotation feature for Amazon RDS.
D.AWS Identity and Access Management (IAM) roles for the Lambda function.
AnswerC

AWS Secrets Manager provides native support for rotating credentials for RDS, Redshift, and DocumentDB. It can automatically update the password in the database and the secret value simultaneously, ensuring that the application always has access to current credentials without storing them in insecure environment variables.

Why this answer

AWS Secrets Manager is purpose-built for storing secrets and provides native, automatic rotation using Lambda rotation functions, including built-in templates for Amazon RDS, Aurora, Redshift, and DocumentDB credentials. It integrates with RDS so the database password and the secret are rotated together without application downtime. This directly satisfies the requirement to store credentials securely and rotate them automatically.

Exam trap

SAA-C03 often tests the Parameter Store vs Secrets Manager distinction, baiting candidates with SecureString encryption while ignoring that only Secrets Manager provides native automatic rotation.

How to eliminate wrong answers

Option A is wrong because Systems Manager Parameter Store SecureString encrypts values with KMS but has no native automatic rotation — you would have to build and schedule your own rotation Lambda, which does not meet the 'automatically rotate' requirement out of the box. Option B is wrong because KMS encrypts data but does not store or rotate application/database credentials; it is a key management service, not a secrets store. Option D is wrong because IAM roles grant temporary AWS API credentials to the Lambda function but do not manage or rotate the database username/password the application uses to connect to RDS.

130
Multi-Selecthard

A large corporation uses AWS Organizations to manage hundreds of accounts. The security team wants to ensure that no account can provision resources in unauthorized regions and that only approved AWS services can be used. Which TWO features should be used to enforce these constraints across the entire organization? (Select TWO.)

Select 2 answers
A.IAM Policies attached to each administrative user in every member account.
B.Service Control Policies (SCPs) applied to the root of the Organization.
C.AWS Resource Access Manager (RAM) to share authorized services across accounts.
D.AWS Config rules to automatically terminate resources in unauthorized regions.
E.SCPs with a Condition element to restrict the 'aws:RequestedRegion' key.
AnswersB, E

Service Control Policies (SCPs) can be applied at the organizational unit or account level to restrict the services and actions available to users. By using a Deny statement with a condition for specific regions, administrators can ensure that no resources are provisioned outside of authorized geographic areas.

Why this answer

Option B is correct because Service Control Policies (SCPs) applied at the organization root set the maximum available permissions for all accounts in the organization, so they can centrally deny access to unapproved AWS services across every member account. Option E is correct because an SCP with a Condition element using the aws:RequestedRegion global condition key can explicitly deny API calls made to regions outside the approved list, enforcing the region restriction organization-wide. Together, SCPs at the root and region-based conditions satisfy both requirements: restricting services and restricting regions for all accounts.

Option A is not appropriate because IAM policies in each member account are decentralized, must be maintained per account, and do not act as a guardrail against account administrators granting themselves broader permissions. Option C is incorrect because AWS Resource Access Manager (RAM) shares resources such as subnets or Transit Gateways between accounts; it does not restrict which services or regions can be used. Option D is incorrect because AWS Config rules detect and can remediate noncompliant resources after creation, but they do not prevent provisioning in unauthorized regions the way an SCP deny does.

Exam trap

SAA-C03 often tests the misconception that IAM policies or AWS Config can enforce organization-wide preventive controls, when only SCPs provide centralized, preventive permission boundaries.

131
MCQmedium

A solutions architect is designing a mission-critical web application running on Amazon EC2 instances behind an Application Load Balancer. The application must remain highly available even during an Availability Zone outage. Which deployment strategy meets this requirement with optimal resilience?

A.Deploy all EC2 instances in a single Availability Zone and configure an AWS Auto Scaling group with a maximum capacity of one.
B.Distribute EC2 instances across multiple Availability Zones within a single AWS Region using an Auto Scaling group.
C.Provision EC2 instances in multiple AWS Regions and use Route 53 with a latency routing policy.
D.Use a single EC2 instance of a larger size to handle peak traffic loads without scaling.
AnswerB

Spreading instances across multiple Availability Zones guarantees high availability by ensuring that an outage in one zone does not disrupt the entire application workload. The Auto Scaling group automatically maintains the desired capacity across remaining zones.

Why this answer

Distributing EC2 instances across multiple Availability Zones within a single Region using an Auto Scaling group provides high availability against an AZ outage while maintaining low-latency intra-Region communication. If one AZ fails, the ASG can launch replacement instances in surviving AZs, and the ALB routes traffic only to healthy targets. This is the standard AWS-recommended HA pattern.

Exam trap

SAA-C03 often tests the difference between Multi-AZ (HA within a Region) and Multi-Region (DR/global latency) — candidates over-select multi-Region solutions when the requirement only mentions an Availability Zone outage.

How to eliminate wrong answers

Option A is wrong because deploying all instances in a single AZ creates a single point of failure — an AZ outage takes down the entire application, and a max capacity of one prevents any scaling or redundancy. Option C is wrong because multi-Region deployment with Route 53 latency routing addresses geographic latency and Region-level disasters, but it is over-engineered and more expensive for an AZ-outage requirement; it also introduces cross-Region data consistency challenges. Option D is wrong because a single large EC2 instance has no redundancy at all — if the instance or its AZ fails, the application is completely unavailable, and vertical scaling does not provide high availability.

132
MCQmedium

A financial services company is hosting a critical web application on Amazon EC2 instances behind an Application Load Balancer. The application must remain available even if an entire AWS Region experiences a major outage. The database tier uses Amazon Aurora Global Databases. Which solution provides the most resilient multi-Region architecture with automated failover?

A.Configure an Application Load Balancer in a single Region with EC2 instances distributed across multiple Availability Zones, and back the application with a standard Aurora MySQL database instance.
B.Use Amazon Route 53 with weighted routing policies to distribute traffic between two AWS Regions, and configure standard cross-region database replication using Amazon RDS snapshots taken every hour.
C.Deploy the application stack across two AWS Regions, use Amazon Route 53 with active-passive failover and automated health checks, and configure Amazon Aurora Global Databases with cross-region replication.
D.Set up an AWS Global Accelerator standard accelerator with endpoint groups in two AWS Regions, and use Amazon DynamoDB global tables with local secondary indexes for data storage.
AnswerC

Route 53 active-passive routing with health checks automatically detects regional failures and redirects user traffic to the secondary Region. Aurora Global Databases provide low-latency cross-region replication and fast failover capabilities to ensure uninterrupted application availability.

Why this answer

Deploying Route 53 with active-passive failover and automated health checks combined with a secondary Region ensures automatic traffic rerouting during a regional disaster. Aurora Global Databases minimize replication lag and permit fast promotion of the secondary region database, maintaining data consistency and business continuity for critical financial applications requiring minimal recovery time objectives.

Exam trap

Candidates often choose solutions that provide multi-region high availability without considering automated cross-region database failover or active-passive failover mechanisms necessary for disaster recovery in financial applications.

133
Multi-Selectmedium

A web application is deployed on Amazon EC2 instances within a private subnet. The application must receive traffic from an Application Load Balancer (ALB) in a public subnet and connect to an Amazon RDS MySQL database in a different private subnet. Which TWO steps are required to secure this architecture using security groups?

Select 2 answers
A.Configure the EC2 security group to allow inbound traffic on port 80/443 from the ALB security group.
B.Configure the RDS security group to allow inbound traffic on port 3306 from the EC2 security group.
C.Configure the EC2 security group to allow inbound traffic from 0.0.0.0/0 on port 80 to handle web traffic.
D.Configure the RDS security group to allow outbound traffic to the EC2 instances on all ports.
E.Configure the ALB security group to allow inbound traffic from the EC2 security group on port 80.
AnswersA, B

Security groups should be configured to allow traffic only from specific sources using security group referencing. By allowing inbound traffic to the EC2 instances only from the ALB's security group, you ensure that the application cannot be accessed directly from other sources, even within the same VPC.

Why this answer

Option A is correct because the EC2 instances must accept HTTP/HTTPS traffic from the ALB, and referencing the ALB's security group as the source on ports 80/443 restricts inbound access to only that load balancer rather than the whole internet. Option B is correct because the application tier must reach the RDS MySQL database on its listener port 3306, and using the EC2 security group as the source in the RDS security group's inbound rule limits database access to only those application instances. Option C is wrong because allowing 0.0.0.0/0 on port 80 would expose the instances directly to the internet, defeating the purpose of placing them in a private subnet behind an ALB.

Option D is wrong because security groups are stateful, so return traffic for allowed inbound connections is automatically permitted and no outbound rule to the EC2 instances is needed; moreover, RDS does not initiate connections to the instances. Option E is wrong because it reverses the traffic direction: the ALB receives client traffic from the internet, not from the EC2 instances, so the ALB security group should allow inbound 80/443 from the internet (or appropriate clients), not from the EC2 security group.

Exam trap

SAA-C03 often tests whether candidates understand that security groups are stateful and can reference other security groups, luring them into picking CIDR-based rules (0.0.0.0/0) or unnecessary outbound rules.

134
MCQmedium

A developer needs to access an S3 bucket from an EC2 instance. For security best practices, the developer must avoid hardcoding long-term credentials on the instance. What is the most secure method to provide the necessary permissions?

A.Create an IAM user with S3 access and store the access key and secret key in a local configuration file.
B.Attach an IAM role to the EC2 instance with an S3 access policy.
C.Configure the S3 bucket policy to allow public read access to the specific EC2 instance's public IP address.
D.Modify the instance security group to allow all traffic to and from the S3 endpoint.
AnswerB

IAM roles provide temporary credentials via the AWS metadata service, which the SDK uses automatically. This method avoids hardcoding credentials on the disk, follows the principle of least privilege, and ensures that permissions are tied to the compute resource rather than a long-lived user identity.

Why this answer

Attaching an IAM role to the EC2 instance lets the instance obtain temporary, automatically rotated credentials via the Instance Metadata Service (IMDS), eliminating hardcoded long-term keys. The role's policy grants least-privilege S3 access, which is the AWS-recommended best practice for instance-to-service authentication.

Exam trap

SAA-C03 often tests the misconception that security groups or bucket policies tied to IPs can authorize EC2-to-S3 access, when the correct answer is always instance roles for credential-free, least-privilege access.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys in a local config file hardcodes long-term credentials, which can be leaked and must be manually rotated — exactly what the question says to avoid. Option C is wrong because allowing public read access based on an EC2 public IP is insecure, brittle (IPs change), and exposes the bucket to the internet. Option D is wrong because security groups control network traffic, not S3 API authorization; S3 access is governed by IAM policies, not security group rules.

135
Multi-Selectmedium

A solutions architect is designing a caching layer for a high-traffic web application that uses a multi-node cluster. The architect needs to ensure high availability and the ability to scale horizontally while supporting complex data types such as sorted sets and lists. Which TWO features of Amazon ElastiCache for Redis support these requirements?

Select 2 answers
A.Multi-AZ with automatic failover.
B.Support for multi-threaded execution.
C.Redis Cluster mode for horizontal scaling.
D.Automatic data compression at the cache level.
E.Use of UDP protocol for low-latency writes.
AnswersA, C

This feature provides high availability by automatically detecting a primary node failure and promoting a replica to primary in a different Availability Zone. This minimizes downtime and ensures that the caching layer remains performant and available even during infrastructure failures in a single zone.

Why this answer

Option A (Multi-AZ with automatic failover) is correct because ElastiCache for Redis supports replication groups with a primary node and one or more read replicas across Availability Zones; if the primary fails, ElastiCache automatically promotes a replica, providing the high availability the multi-node cluster requires. Option C (Redis Cluster mode for horizontal scaling) is correct because cluster mode shards data across up to 500 shards (nodes), enabling horizontal scaling of both storage and throughput while still supporting complex Redis data structures such as sorted sets and lists. Option B is not correct because ElastiCache for Redis is fundamentally single-threaded for command execution (multi-threaded I/O exists in some versions, but it is not the feature that delivers HA or horizontal scaling here).

Option D is not correct because ElastiCache does not provide automatic data compression at the cache level as a feature for this scenario. Option E is not correct because Redis communicates over TCP, not UDP, and UDP would not provide reliable low-latency writes.

Exam trap

SAA-C03 often tests the distinction between Redis and Memcached features, and candidates incorrectly select multi-threaded execution (a Memcached trait) or UDP as a Redis capability.

136
MCQeasy

A company is migrating a compute-intensive web application to AWS. The application requires high CPU performance and needs to scale automatically based on demand. Which EC2 instance family and scaling feature should the architect choose to ensure optimal performance?

A.T-family instances with a standard Auto Scaling group.
B.R-family instances with a scheduled scaling policy.
C.C-family instances with a dynamic scaling policy.
D.M-family instances with manual scaling adjustments.
AnswerC

C-family instances are compute-optimized and provide the highest ratio of CPU to memory, making them perfect for compute-intensive web applications. Combining these instances with a dynamic scaling policy allows the fleet to expand or contract based on actual CPU utilization. This ensures high performance during peak traffic while maintaining cost-efficiency during periods of low demand.

Why this answer

C-family instances are compute-optimized, delivering the highest CPU performance per dollar for compute-intensive workloads, which matches the application's requirement. Pairing them with a dynamic scaling policy (target tracking or step scaling) lets the Auto Scaling group respond automatically to real-time demand changes. Together they satisfy both the performance and elasticity requirements.

Exam trap

SAA-C03 often tests the confusion between instance families — candidates may pick T-family for 'cost savings' or R-family for 'performance' without recognizing that compute-intensive means CPU-optimized C-family.

How to eliminate wrong answers

Option A is wrong because T-family instances are burstable and rely on CPU credits; sustained compute-intensive workloads exhaust credits and throttle performance, making them unsuitable. Option B is wrong because R-family is memory-optimized, not compute-optimized, and scheduled scaling cannot react to unpredictable demand spikes. Option D is wrong because M-family is general-purpose (not CPU-optimized) and manual scaling defeats the automatic scaling requirement.

137
MCQmedium

Refer to the exhibit. A solutions architect reviews the following IAM policy applied to a user. What is the effect of this policy when the user attempts to access an object in the bucket from an IP address of 198.51.100.5?

A.Access is allowed because the policy grants s3:GetObject permissions to the bucket.
B.Access is denied because the source IP address is not within the 203.0.113.0/24 range.
C.Access is allowed because there is no explicit Deny statement in the policy.
D.Access is denied because the policy does not include permissions for the s3:ListBucket action.
AnswerB

The policy includes an IpAddress condition that limits the Allow effect to the 203.0.113.0/24 subnet. Because the user's IP address (198.51.100.5) does not match this range, the policy does not provide the necessary permission to access the S3 object, resulting in an implicit deny.

Why this answer

The policy includes a condition that restricts access to the IP range 203.0.113.0/24. Since the user's IP address (198.51.100.5) is outside this range, the condition evaluates to false, and the Allow statement does not apply. Therefore, the request is implicitly denied because there is no other Allow statement that grants access.

Exam trap

SAA-C03 often tests the misconception that an Allow statement without an explicit Deny always grants access, ignoring the effect of condition keys like aws:SourceIp that can make the Allow ineffective.

How to eliminate wrong answers

Option A is wrong because the policy's Allow statement is conditional on the source IP being within 203.0.113.0/24; the condition fails for 198.51.100.5, so the grant does not apply. Option C is wrong because AWS IAM uses an implicit deny by default; even without an explicit Deny, the absence of a matching Allow results in denial. Option D is wrong because s3:ListBucket is not required to access an object; the s3:GetObject permission alone would suffice if the IP condition were met, but the failure is due to the IP restriction, not the missing ListBucket permission.

138
Multi-Selecthard

A company's public-facing application is experiencing a Distributed Denial of Service (DDoS) attack. The application is hosted on EC2 instances behind an Application Load Balancer (ALB). Which TWO AWS services or features can be used to mitigate this attack and protect the application?

Select 2 answers
A.AWS Shield Advanced for enhanced DDoS detection and mitigation.
B.AWS WAF with rate-based rules to block IP addresses with high request volumes.
C.Amazon GuardDuty to identify and block malicious traffic at the VPC level.
D.Amazon Inspector to scan EC2 instances for vulnerabilities during the attack.
E.AWS PrivateLink to hide the application from the public internet.
AnswersA, B

AWS Shield Advanced provides additional protections for resources like ALBs and CloudFront distributions. It offers 24/7 access to the AWS Shield Response Team (SRT) and provides more sophisticated detection mechanisms to identify and mitigate large-scale or complex DDoS attacks that target the application layer.

Why this answer

Protecting against DDoS attacks requires a multi-layered approach. AWS Shield provides automatic protection for all AWS customers, while Shield Advanced offers enhanced detection and mitigation for sophisticated attacks. AWS WAF complements this by allowing administrators to create rules that block malicious traffic patterns, such as SQL injection or high-volume IP addresses.

Exam trap

Candidates often confuse AWS Shield Standard with Advanced, or assume Security Groups can block DDoS attacks. Security Groups are stateful firewalls for instance-level traffic, not a solution for large-scale distributed volumetric DDoS mitigation.

139
MCQhard

Refer to the exhibit. A company is using this S3 bucket policy to secure high-performance data accessed by an analytics fleet on EC2. Users report that despite having the correct IAM permissions, they are receiving 403 Forbidden errors when trying to download data. What is the most likely cause of this performance and access issue?

A.The S3 bucket is in a different region than the EC2 instances.
B.The EC2 instances are not using the specified VPC Endpoint to access S3.
C.The IAM role assigned to the EC2 instances lacks S3:GetObject permissions.
D.The S3 bucket has Object Lock enabled, preventing data retrieval.
AnswerB

The policy explicitly denies all S3 actions unless the 'aws:sourceVpce' matches 'vpce-1a2b3c4d'. If the EC2 instances are accessing S3 via a NAT Gateway or public internet rather than the specified VPC Endpoint, the condition will trigger a Deny, resulting in the 403 error reported.

Why this answer

The bucket policy shown in the exhibit restricts access to requests originating from a specific VPC Endpoint (aws:sourceVpce condition). If the EC2 instances are not routing S3 traffic through that endpoint — for example, they are using the public S3 endpoint or a different endpoint — the policy denies the request and S3 returns 403 Forbidden even though the IAM role has s3:GetObject. The fix is to ensure the instances use the specified VPC Endpoint (via route table entries or endpoint policies).

Exam trap

SAA-C03 often tests the misconception that 403 Forbidden always means an IAM permission problem, when in fact a bucket policy condition on aws:sourceVpce can deny access even when IAM allows it.

How to eliminate wrong answers

Option A is wrong because S3 is a global service accessed via regional endpoints; cross-region access does not cause 403 Forbidden — it may add latency but the request still succeeds if authorized. Option C is wrong because the question explicitly states the IAM role has the correct permissions, so lack of s3:GetObject is not the cause. Option D is wrong because S3 Object Lock prevents deletion or overwrite (WORM), not retrieval — GetObject operations are unaffected by Object Lock.

140
Multi-Selectmedium

An architect is designing a secure VPC architecture. Which TWO actions should be taken to ensure the infrastructure is compliant with security best practices regarding network isolation?

Select 2 answers
A.Place all EC2 instances in the public subnet to maximize accessibility.
B.Use Network ACLs as a stateless firewall for subnet-level traffic control.
C.Configure Security Groups to allow all traffic (0.0.0.0/0) on all ports.
D.Implement Security Groups as stateful firewalls for instance-level traffic control.
E.Disable VPC Flow Logs to reduce the storage costs in S3.
AnswersB, D

Network ACLs act as a first line of defense at the subnet level. Because they are stateless, they require explicit rules for both inbound and outbound traffic, providing a robust way to block or allow traffic ranges before it ever reaches the individual EC2 instances residing within the subnet.

Why this answer

Option B is correct because Network ACLs are stateless, subnet-level firewalls that evaluate inbound and outbound rules independently, providing an additional layer of traffic control for network isolation in a VPC. Option D is correct because Security Groups are stateful, instance-level firewalls that automatically allow return traffic for permitted connections, which is a fundamental AWS best practice for controlling access to EC2 instances. Option A is incorrect because placing all EC2 instances in a public subnet exposes them directly to the internet and violates network isolation best practices; instances that don't need public access should reside in private subnets.

Option C is incorrect because allowing all traffic from 0.0.0.0/0 on all ports effectively disables firewall protection and is a severe security misconfiguration. Option E is incorrect because disabling VPC Flow Logs removes valuable network traffic visibility needed for monitoring, auditing, and incident response, and cost reduction should not come at the expense of security observability.

Exam trap

SAA-C03 often tests the confusion between stateful and stateless firewalls, and the misconception that Security Groups can deny traffic (they cannot).

141
MCQmedium

A healthcare company must store patient records in Amazon S3 for a minimum of 7 years to meet regulatory requirements. During this period, the records must not be deleted or modified by any user, including the root user. Which S3 feature should be used to enforce this?

A.S3 Versioning with MFA Delete
B.S3 Object Lock in Governance mode
C.S3 Object Lock in Compliance mode
D.S3 Lifecycle policy with an expiration of 7 years
AnswerC

Compliance mode ensures that an object version cannot be overwritten or deleted by any user, including the AWS account root user. The retention period is strictly enforced, and the mode cannot be changed or shortened, making it the correct choice for meeting high-bar regulatory standards.

Why this answer

S3 Object Lock provides Write-Once-Read-Many (WORM) protection. When configured in Compliance mode, an object version cannot be deleted or overwritten by any user, including the root user, for the duration of the retention period. This is the only way to satisfy strict regulatory requirements for data immutability.

Exam trap

Candidates often suggest S3 Lifecycle Policies. Lifecycle policies move or delete data based on age, but they do not prevent an administrator from manually deleting data before the time expires.

142
MCQmedium

A data analytics company stores massive amounts of data in Amazon S3. They need a way to automatically identify and flag sensitive data, such as Personally Identifiable Information (PII) or financial records, to ensure it is not being mishandled. Which AWS service is designed for this task?

A.Amazon GuardDuty
B.Amazon Macie
C.AWS Glue
D.Amazon Inspector
AnswerB

Amazon Macie is specifically built to discover and protect sensitive data at scale. It scans S3 buckets and identifies data types like credit card numbers, social security numbers, and API keys. This automation helps organizations understand their data exposure and implement appropriate security controls efficiently.

Why this answer

Amazon Macie is a fully managed data security and data privacy service. It uses machine learning and pattern matching to automatically discover and protect sensitive data in Amazon S3. Macie provides a dashboard and findings that alert the security team to PII, helping them maintain data privacy compliance.

Exam trap

Candidates often confuse Amazon Macie with AWS GuardDuty or IAM Access Analyzer, losing track of Macie's specific focus on S3 data discovery.

143
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer. The application stores session state in local memory, causing users to be logged out whenever the load balancer routes requests to different instances. Which solution provides the most resilient, scalable architecture to resolve this?

A.Configure the Application Load Balancer to use source IP stickiness.
B.Use Amazon EBS multi-attach to share session files across instances.
C.Store session state in Amazon ElastiCache for Redis.
D.Replicate session files using a cron job across all web instances.
AnswerC

ElastiCache for Redis provides a high-performance, distributed, and managed key-value store that persists session data outside the web server memory. This ensures that session state remains available even when instances are replaced, enabling seamless horizontal scaling and maintaining high availability across multiple Availability Zones.

Why this answer

Storing session state in Amazon ElastiCache for Redis externalizes session data so any EC2 instance behind the ALB can serve any request, eliminating the logout problem while providing high availability and scalability. Redis is purpose-built for low-latency session stores and supports replication and failover. This is the AWS-recommended pattern for stateless web tiers.

Exam trap

SAA-C03 often tests whether candidates recognize that stickiness and file replication are anti-patterns for scalable session management; the trap is choosing ALB stickiness as a quick fix instead of externalizing state to a managed in-memory store.

How to eliminate wrong answers

Option A is wrong because source IP stickiness ties a user to one instance based on IP, which breaks for users behind NAT/proxies and does not survive instance failure — it is a workaround, not a resilient architecture. Option B is wrong because EBS Multi-Attach is limited to specific instance types in the same AZ and is not designed for shared session files across a scalable, multi-AZ web tier; it also introduces filesystem consistency challenges. Option D is wrong because replicating session files via cron is brittle, non-real-time, and operationally heavy; it does not provide the low-latency, consistent session store needed and fails during instance failures.

144
MCQmedium

A solutions architect is designing a batch processing workload that runs for 4 hours every night. The workload can be interrupted and resumed without data loss. Cost optimization is a primary requirement for this deployment.

A.Use Amazon EC2 Reserved Instances to cover the nightly batch processing requirements over a one-year term.
B.Provision Amazon EC2 On-Demand Instances and terminate them manually through an AWS Lambda script after completion.
C.Configure an Auto Scaling group using Amazon EC2 Spot Instances with an appropriate instance diversification strategy.
D.Purchase Amazon EC2 Dedicated Hosts to run the nightly batch processing instances securely and predictably.
AnswerC

Spot Instances bill at up to 90% below On-Demand rates and suit interruptible, resumable workloads. Diversifying across instance types and Availability Zones reduces the chance of simultaneous two-minute interruption notices, satisfying the cost-optimisation requirement while tolerating the nightly four-hour job being reclaimed.

Why this answer

Spot Instances offer up to 90% discount compared to On-Demand and are ideal for interruptible, resumable batch workloads. Using an Auto Scaling group with instance diversification across multiple instance types and Availability Zones increases the chance of acquiring and retaining Spot capacity, and the workload can tolerate interruptions without data loss. This directly satisfies the cost optimization requirement while maintaining availability.

Exam trap

SAA-C03 often tests the misconception that Reserved Instances are always the cheapest option, when in fact Spot Instances are far cheaper for interruptible workloads.

How to eliminate wrong answers

Option A is wrong because Reserved Instances require a one-year or three-year commitment and are best for steady-state, predictable workloads — not a 4-hour nightly batch that could benefit from steeper Spot discounts. Option B is wrong because On-Demand Instances are the most expensive option and manual termination via Lambda adds operational overhead without cost savings. Option D is wrong because Dedicated Hosts are the most expensive option and are used for licensing or compliance requirements, not cost optimization.

145
MCQmedium

A startup is launching a new application with a microservices architecture. One specific service is an API that is only called a few dozen times per day. The execution time is always under 10 seconds. Which compute service would be the most cost-effective for this microservice?

A.Amazon EC2 T3-micro instances.
B.AWS Lambda.
C.Amazon ECS on AWS Fargate.
D.Amazon Lightsail.
AnswerB

Lambda is perfect for low-frequency, short-duration workloads. Since you only pay for the exact milliseconds the code runs, and the first 1 million requests per month are often free under the AWS Free Tier, the cost for this service would be near zero, providing maximum cost optimization.

Why this answer

AWS Lambda is the most cost-effective choice because it charges only for the compute time consumed per invocation, with no charge when the function is idle. An API called a few dozen times per day with sub-10-second execution fits well within Lambda's 15-minute limit and free tier. There is no need to pay for a continuously running instance or container, making Lambda far cheaper than EC2, Fargate, or Lightsail for this sporadic workload.

Exam trap

SAA-C03 often tests the misconception that a small EC2 instance is always cheapest, when in fact serverless Lambda is more cost-effective for intermittent, low-volume workloads because you pay only for actual execution time.

How to eliminate wrong answers

Option A is wrong because an EC2 T3-micro instance runs 24/7 and incurs hourly charges even when the API is not called, which is wasteful for a few dozen daily invocations. Option C is wrong because Amazon ECS on Fargate bills for the vCPU and memory allocated to running tasks; keeping a task running continuously for sporadic calls is more expensive than Lambda's per-invocation model. Option D is wrong because Amazon Lightsail provides a fixed-price virtual private server that also runs continuously, so it is not cost-optimal for infrequent, bursty API calls.

146
MCQhard

A global gaming company needs to provide low-latency access to user profile data for players in North America, Europe, and Asia. The data is stored in an Amazon Aurora MySQL database. The application requires that reads be as local as possible, while writes are infrequent and can tolerate some propagation delay. Which solution offers the best performance?

A.Deploy a single Aurora cluster and use CloudFront to cache database queries.
B.Set up Aurora Global Database with secondary clusters in each required region.
C.Use Cross-Region Read Replicas for standard RDS MySQL instances.
D.Implement a DynamoDB Global Table with DAX in every region.
AnswerB

Aurora Global Database replicates data to secondary regions with very low latency. Applications in those regions can perform reads locally from the secondary clusters, significantly reducing latency compared to cross-region database calls. This is the most performant and scalable architecture for global database access.

Why this answer

Aurora Global Database is purpose-built for this exact scenario: it replicates data from a primary Aurora cluster to secondary clusters in other regions with typical latency under one second, and the secondary clusters serve low-latency local reads. Because writes are infrequent and can tolerate propagation delay, the asynchronous replication model is acceptable, and each region's application can read from its local secondary cluster endpoint. This delivers the lowest read latency across North America, Europe, and Asia while keeping the source of truth in a single primary region.

Exam trap

SAA-C03 often tests whether candidates confuse CDN caching (CloudFront) with database read scaling, or mistakenly apply RDS Cross-Region Read Replicas to Aurora — the trap is picking a familiar-sounding but architecturally wrong service instead of the Aurora-native global replication feature.

How to eliminate wrong answers

Option A is wrong because CloudFront caches HTTP responses at edge locations, not SQL query results — it cannot sit in front of an Aurora MySQL endpoint and cache arbitrary database queries, and it does nothing for write propagation or query freshness. Option C is wrong because Cross-Region Read Replicas are a feature of standard RDS MySQL, not Aurora; the question specifies Aurora MySQL, and even for RDS the replication lag and operational model are inferior to Aurora Global Database for multi-region read locality. Option D is wrong because it changes the database engine entirely — DynamoDB Global Tables with DAX are a NoSQL solution, and the workload is already on Aurora MySQL, so migrating engines is unnecessary and disruptive when Aurora Global Database solves the requirement natively.

147
MCQmedium

A media company stores millions of small image files in an Amazon S3 bucket. The application frequently requests these images, and the company is experiencing high latency during peak hours. The current architecture uses a single prefix for all objects. How should the architect modify the S3 structure to improve performance?

A.Enable S3 Transfer Acceleration on the bucket.
B.Implement a random or hashed prefix naming convention.
C.Use S3 Intelligent-Tiering to move files to higher performance tiers.
D.Increase the size of the EC2 instances accessing the S3 bucket.
AnswerB

Using a hashed or randomized prefix structure distributes requests across multiple S3 partitions. Since S3 supports 3,500 PUT/POST/DELETE and 5,500 GET requests per second per prefix, creating more prefixes allows the system to scale horizontally to handle millions of requests without hitting performance bottlenecks.

Why this answer

S3 automatically partitions request load by prefix, and a single prefix concentrates all GET requests on one partition, creating a hotspot. Introducing random or hashed prefixes (e.g., a hash of the object key as the first characters) spreads requests across many partitions, allowing S3 to scale request throughput and reduce latency during peak hours. This is the standard fix for high-request-rate workloads on small objects.

Exam trap

SAA-C03 often tests the outdated-but-still-tested prefix hotspot concept — candidates pick Transfer Acceleration or Intelligent-Tiering because they sound performance-related, missing that the issue is request partitioning, not transfer speed or storage tier.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration speeds up uploads/downloads over long geographic distances using edge locations — it does not address request-rate hotspots from a single prefix. Option C is wrong because S3 Intelligent-Tiering optimizes storage cost by moving objects between access tiers; it has no effect on request throughput or latency for frequently accessed small files. Option D is wrong because the bottleneck is S3 request partitioning, not EC2 compute — larger instances will not improve S3 GET latency caused by prefix hotspots.

148
MCQmedium

A solutions architect is designing a mission-critical web application that runs on Amazon EC2 instances behind an Application Load Balancer. The application must remain available even if an entire AWS Region experiences a catastrophic failure. The RPO must be near zero, and the RTO must be less than 15 minutes. Which disaster recovery strategy should the architect implement?

A.Implement a backup and restore strategy using automated daily Amazon EBS snapshots copied to a secondary AWS Region.
B.Deploy a pilot light strategy by maintaining a minimal footprint of core database and configuration services in a secondary Region.
C.Configure a multi-site active-active deployment spanning two AWS Regions with continuous data replication and Route 53 health checks.
D.Set up a warm standby architecture running a scaled-down version of the entire application stack in a secondary Region.
AnswerC

Running active workloads across two regions with continuous data replication ensures that traffic can be rerouted instantly upon failure. Route 53 health checks monitor endpoint availability, delivering an RTO of under 15 minutes and minimal RPO.

Why this answer

A multi-site active-active deployment spanning two AWS Regions with continuous data replication and Route 53 health checks provides near-zero RPO and sub-15-minute RTO by allowing both regions to serve traffic simultaneously. If one region fails, Route 53 automatically redirects traffic to the healthy region, ensuring continuous availability.

Exam trap

SAA-C03 often tests the trade-offs between DR strategies, and candidates may confuse warm standby or pilot light with active-active, not realizing that only active-active can meet near-zero RPO and <15 min RTO.

How to eliminate wrong answers

Option A is wrong because backup and restore typically has an RTO of hours and RPO of hours, not near-zero. Option B is wrong because pilot light maintains only core services and requires significant time to scale up, often exceeding 15 minutes RTO. Option D is wrong because warm standby runs a scaled-down stack that must be scaled up, which can take longer than 15 minutes and may not achieve near-zero RPO without continuous replication.

149
MCQeasy

A company has a multi-region application and wants to provide users with a single entry point that automatically routes traffic to the closest healthy endpoint. The solution must support non-HTTP protocols and provide static IP addresses. Which service should be used?

A.Amazon CloudFront
B.AWS Global Accelerator
C.Application Load Balancer (ALB)
D.Amazon Route 53 with Multivalue Answer routing.
AnswerB

Global Accelerator is the ideal choice as it provides two static Anycast IP addresses and uses the AWS private network to route traffic to the nearest regional endpoint. It supports both TCP and UDP, making it suitable for a wide range of non-HTTP applications.

Why this answer

AWS Global Accelerator uses the AWS global network to improve the availability and performance of applications. It provides static IP addresses that act as a fixed entry point and can route traffic to endpoints in multiple regions using any TCP or UDP protocol, ensuring optimal performance.

Exam trap

Candidates frequently choose Route 53 Latency Routing. While it routes to the closest region, it does not provide the static IP addresses or the AWS private network path that Global Accelerator offers.

Page 1

Page 2 of 2

All pages