Courseiva

SAA-C03 (SAA-C03) — Questions 676–750

935 questions total · 13pages · All types, answers revealed

Page 9

Page 10 of 13

Page 11
676
MCQmedium

A company stores private customer documents in an S3 bucket. They want only CloudFront to be able to read objects from the bucket (no direct S3 URL access), even if the bucket name and object key are known. Which configuration best meets this requirement?

A.Attach an AWS WAF Web ACL to CloudFront and allow public reads on the S3 bucket so WAF can block direct object access.
B.Use CloudFront Origin Access Control (OAC) and update the bucket policy to allow s3:GetObject only when the principal is cloudfront.amazonaws.com and aws:SourceArn equals the CloudFront distribution ARN.
C.Create IAM users with s3:GetObject permissions and share the IAM credentials with customers so they can fetch objects directly from S3.
D.Enable S3 static website hosting on the bucket and use the S3 website endpoint as the CloudFront origin so access controls can be enforced at CloudFront.
AnswerB

With OAC, CloudFront signs requests to S3 using an AWS-managed identity (the cloudfront.amazonaws.com service principal). A bucket policy that allows s3:GetObject only when AWS:SourceArn matches your specific CloudFront distribution ARN ensures the bucket is not readable from S3 by other principals. Direct S3 requests from users do not present the required CloudFront context, so they are denied at S3 authorization time.

Why this answer

CloudFront Origin Access Control (OAC) allows you to restrict S3 bucket access exclusively to CloudFront. By configuring the bucket policy to allow s3:GetObject only when the principal is cloudfront.amazonaws.com and the aws:SourceArn matches the CloudFront distribution ARN, you ensure that direct S3 URL requests are denied, even if the bucket name and object key are known. This prevents any unauthorized direct access to the S3 bucket.

Exam trap

The trap here is that candidates often confuse CloudFront's ability to cache content with its ability to enforce access control, mistakenly thinking that enabling static website hosting or using WAF alone can prevent direct S3 access, when in fact only Origin Access Control (or OAI) with a properly scoped bucket policy can achieve this.

How to eliminate wrong answers

Option A is wrong because AWS WAF operates at the application layer (Layer 7) and cannot block direct S3 URL access; it only filters HTTP/HTTPS requests to CloudFront, and allowing public reads on the S3 bucket would still permit direct S3 access. Option C is wrong because sharing IAM credentials with customers violates security best practices, and it does not prevent direct S3 URL access if the credentials are used outside CloudFront. Option D is wrong because enabling S3 static website hosting does not restrict access to CloudFront; the S3 website endpoint is publicly accessible and does not enforce CloudFront-only access controls.

677
MCQhard

An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a financial reporting platform. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy?

A.A security group rule that allows HTTPS to S3
B.A condition that matches aws:RequestedRegion to the bucket Region
C.A deny statement for all IAM users except the EC2 role
D.A condition that matches aws:sourceVpce to the endpoint ID
AnswerD

The aws:sourceVpce condition restricts S3 access to requests that arrive through the specified VPC endpoint.

Why this answer

The bucket policy can use the `aws:sourceVpce` condition key to restrict access to requests that originate from a specific VPC endpoint (a Gateway VPC Endpoint for S3). This ensures that only traffic flowing through that endpoint can access the bucket, meeting the security team's requirement. The EC2 instance in the private subnet routes S3 traffic through the endpoint via the subnet's route table, and the bucket policy enforces the restriction at the resource level.

Exam trap

The trap here is that candidates often confuse `aws:sourceVpce` with `aws:SourceVpc` or think that a security group rule (Option A) can enforce endpoint-based access, but only the bucket policy condition key can restrict based on the specific VPC endpoint ID.

How to eliminate wrong answers

Option A is wrong because security group rules control network traffic at the instance level, not at the S3 bucket policy level, and they cannot enforce that traffic must come through a specific VPC endpoint. Option B is wrong because `aws:RequestedRegion` checks the AWS Region in the request, not the VPC endpoint used; it does not restrict traffic to a specific endpoint. Option C is wrong because denying all IAM users except the EC2 role would block legitimate access from other authorized principals (e.g., cross-account roles or services) and does not enforce the endpoint requirement.

678
MCQhard

Based on the exhibit, a media rendering job runs on a single EC2 instance and writes a large working set of metadata to block storage. The workload performs sustained random reads and writes and must keep latency consistently low for the entire run. The instance may be stopped and started between jobs, and the data must persist. Which storage choice best meets the requirements?

A.Amazon S3 with multipart uploads because it provides durable object storage and high throughput.
B.Amazon EFS because it can be mounted by EC2 and supports persistent file access.
C.Provisioned IOPS SSD EBS volume (io2).
D.Amazon FSx for Windows File Server because it offers durable storage and low latency.
AnswerC

io2 is designed for sustained high IOPS with low and consistent latency on EC2 block storage. The workload is single-instance, random I/O intensive, and needs persistence across stop/start, which matches EBS block storage behavior well.

Why this answer

The workload requires sustained low-latency random reads and writes to block storage, and the data must persist across instance stop/start cycles. Provisioned IOPS SSD EBS volumes (io2) are block-level storage designed for high-performance, low-latency workloads with consistent IOPS, and they persist independently of the EC2 instance lifecycle.

Exam trap

The trap here is that candidates confuse file storage (EFS, FSx) or object storage (S3) with block storage, failing to recognize that sustained low-latency random reads and writes require a block-level device like EBS, not a network-mounted file system.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is object storage, not block storage, and does not support low-latency random read/write access required for a working set of metadata; multipart uploads are for throughput, not latency-sensitive random I/O. Option B is wrong because Amazon EFS is a file-level NFS service that introduces network latency and does not provide the consistent sub-millisecond latency of local block storage for sustained random I/O. Option D is wrong because Amazon FSx for Windows File Server is file-level storage with higher latency than direct-attached block storage and is optimized for Windows workloads, not for the low-latency random block I/O pattern described.

679
MCQmedium

A media company stores original uploads in an S3 bucket. They must recover from accidental overwrites/deletes and also recover quickly from a full Region outage. The required RPO is about 1 hour. Which configuration best meets these requirements?

A.Enable an S3 lifecycle policy to transition objects to Glacier after 7 days without enabling versioning.
B.Enable S3 cross-Region replication (CRR) but leave the bucket without versioning enabled.
C.Enable S3 versioning and configure cross-Region replication to a bucket in another Region.
D.Rely on frequent EBS snapshots of a temporary cache used during uploads.
AnswerC

Enabling S3 versioning preserves every version of an object, allowing retrieval of prior versions if an object is accidentally overwritten or deleted. Cross-Region Replication (CRR) asynchronously copies objects to a bucket in another Region, protecting against a Regional disaster. Because CRR requires versioning on both source and destination buckets, this combination satisfies both logical protection and geographic redundancy.

Why this answer

Enabling S3 versioning protects against accidental overwrites and deletes by preserving all object versions, while cross-Region replication (CRR) asynchronously replicates objects to a bucket in another Region, providing recovery from a full Region outage. With versioning enabled, CRR replicates both current and previous object versions, meeting the ~1-hour RPO (typically within minutes for new objects) and ensuring data durability across Regions.

Exam trap

AWS often tests the misconception that CRR can work without versioning, but the S3 API explicitly requires versioning on the source bucket for replication to function, and candidates may overlook that versioning is also the mechanism that protects against accidental overwrites and deletes.

Why the other options are wrong

A

Without versioning, the lifecycle policy cannot protect against accidental overwrites or deletes, and Glacier transition does not provide quick recovery from a full Region outage (RPO ~1 hour).

B

Without versioning, S3 cross-Region replication cannot protect against accidental overwrites or deletes because replication only copies the current version; deleted or overwritten objects are not recoverable.

D

EBS snapshots are for EC2 instance volumes, not for S3 data. They cannot protect against accidental overwrites/deletes in S3, nor do they provide cross-Region recovery for S3 objects.

When would these options actually be correct?

A

A company needs to archive old data to reduce costs, has a separate backup strategy for disaster recovery, and can tolerate retrieval times of hours for data older than 7 days.

B

A company needs to replicate objects to another Region for low-latency access or compliance, but does not require protection against accidental deletion or overwrite. Versioning is not needed because the source bucket is append-only or objects are immutable.

D

This would be correct if the question asked about recovering an EC2 instance's root volume or data volume after a failure, with RPO of 1 hour, and the uploads were temporarily cached on an EBS volume before being moved to S3.

Why candidates pick the wrong answer

A

Candidates may think that transitioning to Glacier provides a low-cost backup, but they overlook that versioning is required for recovery from accidental changes and that Glacier retrieval is too slow for a 1-hour RPO.

B

Candidates may think CRR alone provides disaster recovery, overlooking that versioning is essential for recovering from user errors like overwrites and deletes.

D

Candidates may confuse EBS snapshots as a general backup mechanism for any data, or think that since uploads pass through a cache, snapshots of that cache can protect the data.

680
MCQmedium

A media platform runs a CPU-heavy thumbnail generation workload on an EC2 Auto Scaling group using t3.large instances. During peak traffic, p95 processing time increases significantly even though average CPU remains around 40–50%. CloudWatch also shows CPU credit depletion behavior. Which change will most directly improve performance predictability for this workload?

A.Increase the t3.large maximum CPU credits and keep the Auto Scaling group using the same burstable instance type.
B.Change the Auto Scaling group instance type to a compute-optimized family (for example, c7i) to provide steady CPU performance.
C.Add a placement group to the existing t3.large instances so they are packed close together for lower latency between nodes.
D.Switch the workload to run on Lambda with the same logic so invocations automatically scale without instance selection changes.
AnswerB

Compute-optimized instances are designed for consistently high CPU performance and do not rely on a burst-credit model. Switching to a steady-performance family removes the credit-depletion/throttling pattern that is driving the p95 latency spikes under sustained load.

Why this answer

The t3.large instances rely on CPU credits for burst performance, and when credits are exhausted, CPU performance is throttled to the baseline (e.g., 30% for t3.large). This causes unpredictable processing times during peak traffic, even if average CPU is moderate. Switching to a compute-optimized family like c7i provides dedicated, consistent CPU performance without credit-based throttling, directly improving predictability for CPU-heavy thumbnail generation.

Exam trap

The trap here is that candidates assume 'CPU credit depletion' can be fixed by increasing credits or scaling out, but the real issue is that burstable instances are fundamentally unsuitable for sustained CPU-heavy workloads, and only switching to a non-burstable instance type (e.g., compute-optimized) guarantees predictable performance.

How to eliminate wrong answers

Option A is wrong because increasing maximum CPU credits (which is not a configurable parameter; t3 instances have a fixed credit earning/balance limit) would only delay throttling, not eliminate it, and the workload would still face unpredictable performance once credits are depleted. Option C is wrong because placement groups optimize network latency between instances (e.g., for tightly coupled workloads like HPC), but the issue here is CPU credit exhaustion, not network latency. Option D is wrong because Lambda has a 15-minute execution timeout and limited CPU allocation per invocation (proportional to memory), making it unsuitable for long-running, CPU-heavy thumbnail generation; it also introduces cold start latency and does not inherently solve the CPU credit problem.

681
Multi-Selectmedium

A DevOps team is designing a high-performance CI/CD pipeline to build and test code changes. The pipeline needs to scale to handle hundreds of concurrent builds, with fast build times and minimal idle compute cost. The builds are containerized and require consistent, reproducible environments. Which three options should be used to meet these requirements? (Choose three.)

Select 3 answers
.Use AWS CodeBuild with a large number of concurrent build projects.
.Use self-managed Jenkins on EC2 Spot Instances to reduce costs.
.Use AWS CodePipeline to orchestrate the build, test, and deploy stages.
.Use AWS CodeBuild with pre-built Docker images cached in Amazon ECR.
.Use Amazon EC2 Auto Scaling with a custom AMI for build agents.
.Use Amazon S3 as a cache store for CodeBuild to speed up dependency download.

Why this answer

AWS CodePipeline is the correct orchestration service to define and manage the CI/CD pipeline stages (build, test, deploy) in a serverless, highly available manner. Pre-built Docker images cached in Amazon ECR ensure consistent, reproducible environments and drastically reduce build times by avoiding image rebuilds. Using Amazon S3 as a cache store for CodeBuild allows storing and retrieving dependency caches (e.g., Maven .m2, npm node_modules) across builds, minimizing download times and speeding up the pipeline.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing self-managed or auto-scaling options (like Jenkins or EC2 Auto Scaling) instead of recognizing that AWS managed services (CodePipeline, CodeBuild, ECR, S3) provide the required scalability, speed, and cost efficiency with far less operational overhead.

682
MCQhard

A company runs EC2 workloads including web servers (m5.large), batch jobs (c5.xlarge), and a data processing service that will migrate from r5 to r6i instances within 6 months. The company wants to commit to 1 year to reduce costs but needs flexibility for the planned instance family migration. Which purchasing option provides the GREATEST savings while accommodating the change?

A.Standard Reserved Instances for each instance type with a 1-year term
B.Compute Savings Plans with a 1-year term commitment
C.EC2 Instance Savings Plans for the r5 instance family with a 1-year term
D.Convertible Reserved Instances for all instance types with a 1-year term
AnswerB

Compute Savings Plans offer up to 66% savings compared to On-Demand and apply automatically to any EC2 instance family, including the transition from r5 to r6i, with no reconfiguration or exchange needed. The hourly commitment is flexible across instance sizes and operating systems, so the migration does not disrupt your discount. This makes it the only option that fully supports an instance family migration without manual intervention or wasted commitments.

Why this answer

Compute Savings Plans automatically apply to any EC2 instance regardless of family, size, region, OS, or tenancy — including both r5 and r6i. When the data processing service migrates from r5 to r6i, the Compute Savings Plan continues to apply without any action required.

EC2 Instance Savings Plans lock to a specific instance family in a specific region. When the workload migrates from r5 to r6i, the EC2 Instance Savings Plan for r5 no longer applies — leaving the r6i workload billed at On-Demand rates.

Exam trap

EC2 Instance Savings Plans offer a deeper discount (up to 72%) but are locked to a specific instance family and region. Compute Savings Plans sacrifice ~2-5% discount compared to EC2 Instance Savings Plans but cover all families, sizes, regions, and Lambda/Fargate. When a family migration is planned, Compute Savings Plans are the correct choice — EC2 Instance Savings Plans would not cover the new r6i family.

Why the other options are wrong

A

Standard RIs are locked to a specific instance type, size, and region. When the r5 workload migrates to r6i, the r5 RI continues billing but no longer matches the running instances — creating waste and uncovered On-Demand charges.

C

EC2 Instance Savings Plans lock to a specific instance family (e.g., r5) in a specific region. When the workload migrates to r6i, the Savings Plan no longer covers the new instances — they are charged at On-Demand rates.

D

Convertible RIs allow exchanging for different families, which could handle the r5→r6i migration. However, the exchange process is manual, requires purchasing new RIs of equal or greater value, and Compute Savings Plans provide the same flexibility automatically.

683
Multi-Selectmedium

An application in Account B reads objects from an Amazon S3 bucket in Account A. The bucket uses SSE-KMS with a customer managed key in Account A. The role in Account B already has s3:GetObject, but downloads fail with AccessDenied on decrypt. Which two changes are required for the role to read the object successfully? Select two.

Select 2 answers
A.Add an SCP that grants the role additional permissions for KMS usage.
B.Add kms:Decrypt permission in the role's IAM policy for the KMS key.
C.Update the KMS key policy in Account A to allow the role from Account B to use Decrypt.
D.Grant the role read access with an S3 bucket ACL.
E.Enable S3 Transfer Acceleration on the bucket.
AnswersB, C

To successfully read an SSE-KMS-encrypted S3 object from another account, the IAM role must have an explicit kms:Decrypt permission on the customer master key (CMK) that encrypted the object. Without this identity-based allow, KMS returns an AccessDenied error even if S3 GetObject is permitted by bucket policy or ACL. The KMS key policy in Account A must also explicitly allow the role (or Account B) to call kms:Decrypt; both the key policy and the identity policy must be satisfied for KMS to authorize the decryption.

Why this answer

The role in Account B needs explicit kms:Decrypt permission in its IAM policy to use the KMS key for decrypting the S3 objects. Option C is correct because the KMS key policy in Account A must grant the role from Account B permission to call kms:Decrypt, as the key is customer managed and cross-account access requires both the key policy and the IAM policy to allow the action.

Exam trap

The trap here is that candidates often think only the IAM policy (Option B) is needed, forgetting that cross-account KMS access requires the key policy (Option C) to explicitly grant the external role decrypt permission, as IAM policies alone are insufficient for resource-based policies like KMS key policies.

684
MCQmedium

Your company has an internal service hosted behind a Network Load Balancer (NLB) in VPC 10.0.0.0/16. A consumer team in a different VPC (10.1.0.0/16) must call the service without using the public internet. You want private connectivity using AWS PrivateLink. Which configuration best enables least-privilege access while keeping the traffic private?

A.Expose the NLB with an Internet Gateway route and restrict access using a security group attached to the NLB.
B.Create a VPC endpoint (interface endpoint) in the consumer VPC that points to the service name published by the provider account, and limit allowed clients using the endpoint’s security group rules.
C.Create an S3 Gateway endpoint in the consumer VPC and store the service hostname in SSM Parameter Store so clients can resolve privately.
D.Use a bastion host in the provider VPC and allow the consumer VPC to SSH to it; from there, the consumer makes HTTP calls to the NLB.
AnswerB

PrivateLink uses an interface VPC endpoint in the consumer VPC (using the provider’s published service name). Traffic stays on the AWS network, not the public internet. Security groups on the interface endpoint provide least-privilege control over which client resources can reach the endpoint, and the provider side can also restrict who can connect.

Why this answer

AWS PrivateLink uses an interface VPC endpoint in the consumer VPC to connect privately to a Network Load Balancer (NLB) in the provider VPC, without traversing the public internet. The endpoint’s security group acts as a least-privilege firewall, allowing only specific clients (by source IP or security group) to access the service. This keeps traffic within the AWS network and avoids exposing the NLB to the internet.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints (which only work for S3 and DynamoDB) with Interface Endpoints (which support PrivateLink for services behind an NLB), leading them to pick Option C incorrectly.

Why the other options are wrong

A

NLBs do not support security groups; they rely on target group health checks and network ACLs. Additionally, routing through an Internet Gateway would expose the NLB to the public internet, violating the requirement for private connectivity.

C

S3 Gateway endpoints only provide private access to S3 services, not to NLB-hosted services. They cannot route traffic to a Network Load Balancer or any non-S3 endpoint.

D

Using a bastion host requires SSH access and does not provide private connectivity via AWS PrivateLink; it introduces a single point of failure, management overhead, and violates the least-privilege principle by granting broad network access.

When would these options actually be correct?

A

If the question required public internet access to an Application Load Balancer (ALB) and asked for access restriction, an Internet Gateway with a security group attached to the ALB would be appropriate. For example: 'Allow external clients to access an ALB over the internet, but restrict access to a specific IP range.'

C

This option would be correct if the question asked for private access to an S3 bucket from a consumer VPC, and the service hostname was stored in SSM Parameter Store for client configuration. For example: 'Your company needs to allow a consumer VPC to access an S3 bucket privately without using the internet.'

D

A scenario where a consumer needs occasional, interactive access to a provider's internal resources (e.g., database administration) and the provider cannot expose a service via PrivateLink; a bastion host with strict security group rules and SSH key management would be appropriate.

Why candidates pick the wrong answer

A

Candidates may mistakenly think security groups can be attached to any load balancer, and that an Internet Gateway is necessary for any cross-VPC communication, overlooking AWS PrivateLink as a private solution.

C

Candidates may confuse 'Gateway Endpoint' with 'Interface Endpoint' or think that any VPC endpoint can provide private connectivity to any service, not realizing S3 Gateway endpoints are service-specific.

D

Candidates may think a bastion host is a standard pattern for cross-VPC access and overlook that PrivateLink offers a more secure, managed, and scalable solution without requiring SSH or a jump box.

685
MCQhard

A warehouse integration service must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The design must avoid adding custom operational scripts.

A.Use CloudFront signed URLs
B.Use Amazon SQS standard queue and design consumers to be idempotent
C.Use UDP messages sent directly to workers
D.Use an in-memory queue on one EC2 instance
AnswerB

An Amazon SQS standard queue provides high-throughput, distributed, and durable messaging with at-least-once delivery semantics. Because duplicates can occur due to the distributed architecture, consumers must be idempotent to correctly handle repeated messages without side effects. The queue also decouples event producers from workers, automatically buffering events and allowing independent scaling of processing capacity, which satisfies the requirement to process every event reliably.

Why this answer

Amazon SQS standard queues provide at-least-once delivery, ensuring every event is processed at least once, with the possibility of duplicates. Designing consumers to be idempotent handles duplicates without requiring custom scripts, aligning with the requirement to avoid operational overhead. This approach is serverless, scalable, and fits the warehouse integration use case.

Exam trap

The trap here is that candidates may choose UDP (Option C) thinking it is lightweight and fast, but they overlook its lack of delivery guarantees, which fails the 'process every event at least once' requirement.

How to eliminate wrong answers

Option A is wrong because CloudFront signed URLs are for controlling access to content, not for event processing or messaging; they do not provide at-least-once delivery guarantees. Option C is wrong because UDP is a connectionless, unreliable protocol that does not guarantee message delivery, making it unsuitable for processing every event at least once. Option D is wrong because an in-memory queue on a single EC2 instance introduces a single point of failure and requires custom scripts for management, violating the 'avoid adding custom operational scripts' constraint.

686
MCQmedium

A content publishing system uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The team wants the control to be enforceable during normal operations.

A.Lambda reserved concurrency set to zero
B.A larger deployment package
C.CloudFront error pages
D.A Lambda dead-letter queue or failure destination
AnswerD

A Lambda dead-letter queue (an SQS queue or SNS topic) or an asynchronous failure destination is the AWS-recommended way to retain events that exhaust Lambda's two built-in retries. After the retry attempts fail, Lambda writes the event payload to the configured SQS/SNS or invokes a destination like another Lambda, EventBridge, or SNS, enabling a separate process to analyze or replay the failed event. To use it, the function must have a resource-based policy granting Lambda permissions to send to the DLQ/destination, and the configuration must be set on the function's event-invoke settings.

Why this answer

A Lambda dead-letter queue (DLQ) or failure destination allows you to capture events that have exhausted all retry attempts from an asynchronous invocation. This ensures failed events are retained in Amazon SQS or SNS for later investigation, providing enforceable control during normal operations without impacting the function's ability to process successful events.

Exam trap

The trap here is that candidates may confuse Lambda's synchronous invocation error handling (where DLQs are not supported) with asynchronous invocation, or mistakenly think that increasing function resources (like deployment package size) can improve reliability against external API failures.

How to eliminate wrong answers

Option A is wrong because setting Lambda reserved concurrency to zero would completely disable the function, preventing any invocations and thus failing to process events at all, which does not address the need to retain failed events after retries. Option B is wrong because a larger deployment package does not affect error handling or retention of failed events; it only increases the function's size, potentially impacting cold start times and deployment limits. Option C is wrong because CloudFront error pages are used for customizing HTTP error responses for web distributions, not for capturing or retaining Lambda invocation failures from asynchronous API calls.

687
Multi-Selectmedium

A SaaS application is deployed in us-east-1 and us-west-2 behind separate ALBs. The business wants DNS to send new clients to the primary Region when it is healthy and automatically fail over to the secondary Region when the primary endpoint is unhealthy. Which two Route 53 settings are required? Select two.

Select 2 answers
A.Use a failover routing policy with a primary and secondary record.
B.Create a health check and associate it with the primary endpoint.
C.Use weighted routing with a 50/50 traffic split between both Regions.
D.Use latency-based routing so clients always choose the fastest Region.
E.Use a geolocation policy without health checks.
AnswersA, B

Failover routing is Route 53's active-passive policy: you create a primary record pointing to the us-east-1 endpoint and a secondary record pointing to us-west-2. When a health check attached to the primary fails, Route 53 automatically returns the secondary record in DNS responses. This is the exact mechanism that provides automatic region-level failover for your SaaS application, and it also lets you designate a definitive secondary failover target.

Why this answer

A failover routing policy is correct because it allows you to designate one record as primary and another as secondary. Route 53 will route traffic to the primary record as long as it is healthy, and automatically fail over to the secondary record when the primary is unhealthy. This directly meets the requirement to send new clients to the primary region when healthy and fail over to the secondary region.

Exam trap

The trap here is that candidates often confuse failover routing with weighted or latency-based routing, thinking any multi-region setup with health checks will automatically fail over, but only failover routing policy provides the explicit primary/secondary failover behavior required.

Why the other options are wrong

C

Weighted routing with a 50/50 split distributes traffic evenly regardless of health, failing to automatically fail over to the secondary region when the primary endpoint is unhealthy.

D

Latency-based routing directs traffic to the region with the lowest latency for each user, not to a primary region with failover to a secondary region when the primary is unhealthy.

E

Geolocation routing directs traffic based on client location, not health. Without health checks, it cannot automatically fail over when the primary endpoint is unhealthy, which is the core requirement.

When would these options actually be correct?

C

When the requirement is to distribute traffic evenly across two healthy endpoints for load balancing, without automatic failover, such as for A/B testing or gradual rollout.

D

A global application wants to minimize latency for users worldwide and does not require active failover; each user should be routed to the region that provides the fastest response time, with health checks optionally used to exclude unhealthy endpoints.

E

A question requiring traffic to be routed to specific endpoints based on client geographic origin (e.g., 'Route users from Europe to eu-west-1, and users from North America to us-east-1') without needing automatic failover would make geolocation policy correct.

Why candidates pick the wrong answer

C

Candidates may think a 50/50 split provides redundancy, but it lacks health-based failover and does not meet the requirement for automatic failover to a secondary region.

D

Candidates may confuse latency-based routing with failover because both involve multiple regions, but latency routing optimizes for speed, not for a primary-secondary failover pattern.

E

Candidates may confuse geolocation with failover, thinking that routing by location inherently provides redundancy, or they overlook the explicit need for health checks to trigger failover.

688
MCQmedium

A logistics company runs an order-tracking API on a fleet of EC2 instances in a single Availability Zone behind a Network Load Balancer. The architecture team must make the API resilient to the loss of that Availability Zone without changing the API endpoint that clients already use. The instances are stateless and store session data in a shared Amazon ElastiCache cluster. Which change should the solutions architect make to meet these requirements?

A.Enable termination protection on the EC2 instances and configure an Elastic IP address per instance so that clients can reconnect to the same address after a zone failure.
B.Replace the Network Load Balancer with an Application Load Balancer deployed in one Availability Zone and attach an Auto Scaling group with a desired capacity of two instances.
C.Create a second Network Load Balancer in a different Availability Zone and use Amazon Route 53 weighted routing to send half the client traffic to each load balancer.
D.Create an Auto Scaling group that spans at least two Availability Zones, register the instances with a target group attached to the existing Network Load Balancer, and enable cross-zone load balancing.
AnswerD

A Network Load Balancer is a Regional resource with nodes in each enabled Availability Zone, so extending the Auto Scaling group across multiple Availability Zones lets healthy instances in a surviving zone serve traffic without any DNS or endpoint change. Cross-zone load balancing distributes traffic evenly so the remaining zone absorbs the full load, and because sessions live in ElastiCache, no instance holds state that would be lost.

Why this answer

The resilient pattern is to spread stateless compute across multiple Availability Zones and let the existing Regional Network Load Balancer route to whichever targets are healthy. Because the load balancer already has nodes in every enabled zone, adding an Auto Scaling group that spans zones gives the surviving zone capacity to absorb traffic, and cross-zone load balancing keeps distribution even. Session state already lives in ElastiCache, so no failover logic is needed in the application.

Exam trap

The trap here is assuming the load balancer itself needs replacing or duplicating, when the real single point of failure is the compute capacity confined to one Availability Zone.

689
MCQmedium

A public web application is fronted by Amazon CloudFront and an ALB. The team is seeing SQL injection attempts and bursts of malicious HTTP requests that increase origin load. They want to block common web attacks before they reach the ALB. What should they do?

A.Associate an AWS WAF web ACL with the CloudFront distribution.
B.Add an inbound security group rule to the ALB for the attacker IP ranges.
C.Use a network ACL to inspect and block SQL statements in the request body.
D.Enable Amazon KMS encryption on the ALB listener certificates.
AnswerA

AWS WAF is the correct service for filtering HTTP(S) requests based on patterns such as SQL injection, bad bots, and rate-based abuse. When associated with CloudFront, the filtering happens at the edge before traffic reaches the ALB and origin, reducing load and blocking malicious requests earlier in the path. Shield Standard is already included for basic DDoS protection, but WAF is the component that provides the application-layer controls needed here.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting. By associating an AWS WAF web ACL with the CloudFront distribution, you can inspect and filter HTTP(S) requests at the edge before they reach the ALB, reducing origin load and blocking malicious traffic early. This is the recommended approach for defending against layer 7 attacks at the CDN level.

Exam trap

The trap here is that candidates often confuse network-layer controls (security groups, NACLs) with application-layer protection, mistakenly thinking they can block SQL injection at the network level, when only a WAF can inspect HTTP request bodies for such attacks.

Why the other options are wrong

B

Security group rules operate at the network/transport layer and cannot inspect application-layer content like SQL injection payloads. They only filter based on IP, port, and protocol, not HTTP request bodies.

C

Network ACLs operate at the subnet level and cannot inspect application-layer content like SQL statements in request bodies; they only filter based on IP, port, and protocol.

D

KMS encryption on ALB listener certificates secures data in transit but does not inspect or block SQL injection or malicious HTTP requests; it provides no web attack protection.

When would these options actually be correct?

B

If the question asked to block all traffic from a specific IP range at the network level before it reaches the ALB, adding an inbound security group rule denying that IP range would be correct. For example: 'Block all requests from a known malicious IP range at the ALB.'

C

A question asks to block traffic from a specific IP range at the subnet boundary for a VPC, where application-layer inspection is not required.

D

A question asks how to enforce encryption for data in transit between the ALB and clients, or to meet compliance requirements for TLS termination using customer-managed keys, where the ALB must use certificates encrypted with KMS.

Why candidates pick the wrong answer

B

Candidates may think security groups can block attacks because they are a common security control, but they confuse network-layer filtering with application-layer inspection that WAF provides.

C

Candidates may confuse network ACLs with WAF, thinking ACLs can perform deep packet inspection, or they overestimate the capabilities of network-layer filtering.

D

Candidates may confuse encryption with security controls, thinking that encrypting traffic somehow prevents attacks, or they may overestimate the scope of KMS capabilities.

690
MCQhard

A dev sandbox currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first?

A.Disabling route tables
B.Replacing every NAT gateway with an internet gateway attached to private subnets
C.Moving all workloads to public subnets
D.Whether one NAT gateway per AZ is sufficient for the required private subnets
AnswerD

The correct cost-first question is whether one NAT gateway per AZ is sufficient for the required private subnets. Each NAT gateway incurs an hourly charge, so having two NAT gateways in the same AZ is redundant because they provide no additional resilience—AWS already makes a single NAT gateway highly available within its AZ. For a dev sandbox that may only use a single AZ or does not demand multi-AZ high availability, one NAT gateway is enough to serve all private subnets in that AZ. This optimization directly reduces the number of NAT gateways billed, while still meeting the actual connectivity and resilience needs if positioned correctly per AZ.

Why this answer

The question states that only one private subnet per AZ needs outbound internet access, so using two NAT gateways per AZ is likely over-provisioned and costly. The architect should first review whether one NAT gateway per AZ is sufficient, as NAT gateways are billed per hour and per gigabyte of data processed, and reducing from two to one per AZ can cut costs without sacrificing availability. This aligns with the cost-optimized design principle of right-sizing resources to actual demand.

Exam trap

The trap here is that candidates may assume more NAT gateways always improve availability or performance, but the question tests cost optimization by recognizing that one per AZ is often enough for low-traffic private subnets, and the first step is to verify sufficiency before making changes.

How to eliminate wrong answers

Option A is wrong because disabling route tables would break all routing for the subnets, not just optimize costs, and is not a valid review step for reducing NAT gateway count. Option B is wrong because internet gateways cannot be attached to private subnets; they are used for public subnets and do not provide outbound-only internet access for private resources. Option C is wrong because moving workloads to public subnets would expose them directly to the internet, violating security best practices and the sandbox's likely need for private, isolated environments.

691
MCQmedium

A CI pipeline in account A uploads build artifacts to an S3 bucket (arn:aws:s3:::build-artifacts-prod) under the prefix teamA/. The pipeline must not be able to list other prefixes, and it must only upload objects under teamA/. Which IAM policy design best enforces least privilege for this requirement?

A.Allow s3:PutObject on arn:aws:s3:::build-artifacts-prod/* and allow s3:ListBucket on arn:aws:s3:::build-artifacts-prod with no condition.
B.Allow s3:PutObject on arn:aws:s3:::build-artifacts-prod/teamA/* and allow s3:ListBucket on arn:aws:s3:::build-artifacts-prod with a condition that requires s3:prefix equals 'teamA/'.
C.Allow s3:PutObject on arn:aws:s3:::build-artifacts-prod/teamA/* and allow s3:GetBucketLocation on arn:aws:s3:::build-artifacts-prod/teamA/.
D.Allow s3:* on arn:aws:s3:::build-artifacts-prod/teamA/* and allow s3:ListAllMyBuckets for easier auditing.
AnswerB

This scopes uploads to exactly the teamA/ object path by using the object ARN arn:aws:s3:::build-artifacts-prod/teamA/*. For listing, it targets the bucket ARN (arn:aws:s3:::build-artifacts-prod) and restricts listing results to only the requested prefix using the s3:prefix condition key.

Why this answer

It grants the minimal permissions required: s3:PutObject is scoped to the specific prefix teamA/*, preventing uploads to other prefixes, and s3:ListBucket is allowed only with a condition that restricts the s3:prefix to 'teamA/', ensuring the pipeline cannot list objects under other prefixes. This enforces least privilege by combining resource-level and condition-based access control.

Exam trap

The trap here is that candidates often assume that scoping the resource ARN to a prefix (e.g., arn:aws:s3:::bucket/prefix/*) alone is sufficient to restrict listing, but without a condition on s3:ListBucket, the ListBucket action still returns all objects in the bucket, bypassing the intended restriction.

How to eliminate wrong answers

Option A is wrong because it allows s3:PutObject on the entire bucket (arn:aws:s3:::build-artifacts-prod/*) without restricting the prefix, so the pipeline could upload to any prefix, violating the requirement to only upload under teamA/. Option C is wrong because it allows s3:GetBucketLocation on the prefix path, which is not a valid ARN for that action (GetBucketLocation operates on the bucket, not a prefix) and does not grant the necessary s3:ListBucket permission to list objects, so the pipeline cannot verify uploads or list objects under teamA/. Option D is wrong because it allows s3:* on the prefix, granting excessive permissions like s3:DeleteObject or s3:GetObject, and s3:ListAllMyBuckets is irrelevant for restricting access to a specific bucket and prefix, violating least privilege.

692
MCQeasy

An application uses an Amazon Aurora cluster. The workload becomes read-heavy, but the team cannot change the database schema. They need higher read throughput while keeping writes on the primary. What should they do?

A.Create Aurora read replicas and use the reader endpoint for read traffic
B.Switch the cluster to a single-AZ Aurora configuration to reduce coordination overhead
C.Increase DynamoDB capacity units instead of modifying the database layer
D.Enable CloudFront caching for database queries to serve results from edge locations
AnswerA

Aurora read replicas are purpose-built to offload read traffic by creating up to 15 additional compute instances that share the same underlying storage volume. The cluster's reader endpoint automatically load-balances connections across these replicas, so read queries do not compete with the writer instance for CPU, memory, or I/O capacity. Because this is a native Aurora feature, it requires no schema changes or application rewrites, and it preserves the durability and replication benefits of the multi-AZ cluster architecture.

Why this answer

Aurora read replicas are designed to offload read traffic from the primary instance, and the reader endpoint automatically load-balances connections across all replicas. Since the workload is read-heavy and the schema cannot change, adding read replicas directly increases read throughput without modifying the application's database schema. The reader endpoint ensures that read queries are directed to the replicas while writes continue to hit the primary instance.

Exam trap

The trap here is that candidates may confuse Aurora read replicas with RDS read replicas, which have different replication mechanics and lag characteristics, or they may think that switching to a single-AZ configuration improves performance by reducing overhead, when in fact it only reduces availability.

How to eliminate wrong answers

Option B is wrong because switching to a single-AZ configuration reduces availability and does not increase read throughput; it only eliminates the standby replica, which does not serve read traffic. Option C is wrong because DynamoDB is a different database service with a different API and data model; the question explicitly states the application uses an Aurora cluster, and migrating to DynamoDB would require schema changes, which are not allowed. Option D is wrong because CloudFront caches static content at edge locations, not dynamic database query results; database queries are typically dynamic and cannot be cached effectively at edge locations without complex application-level caching logic.

693
MCQmedium

A containerized web service on Amazon ECS reads a database password at startup. Today, the password is stored in a plain environment variable and updated manually. Auditors require that credentials: (1) are encrypted at rest using AWS-managed controls, (2) can be rotated without redeploying the task definition, and (3) are accessible only to the running task via least-privilege permissions. Which solution best meets these requirements?

A.Store the password in Systems Manager Parameter Store as a SecureString and grant the ECS task role GetParameter only for that parameter ARN. Have the application call GetParameter on each request or on a short refresh interval.
B.Store the password in AWS Secrets Manager. Configure rotation for the secret. Grant the ECS task role secretsmanager:GetSecretValue for only that secret ARN. Update the application to fetch the secret at runtime and cache it briefly.
C.Store the password in a local file within the container image and mount it as a Docker secret at build time to avoid environment variables.
D.Store the password in an S3 bucket with server-side encryption and allow all ECS tasks to read it using a broad IAM policy on the bucket prefix.
AnswerB

Secrets Manager is the purpose-built service for credentials: it encrypts secret values at rest with KMS, supports scheduled rotation, and integrates with ECS task roles via resource-level IAM, so the task can call secretsmanager:GetSecretValue for only this secret ARN. Fetching the password at runtime and caching it briefly lets the application pick up rotated values without a task definition redeploy while avoiding the overhead of retrieving the secret on every request.

Why this answer

AWS Secrets Manager encrypts secrets at rest using AWS KMS (AWS-managed key by default), supports automatic rotation without requiring a task definition redeploy, and allows least-privilege access by granting the ECS task role only secretsmanager:GetSecretValue for the specific secret ARN. The application fetches the secret at runtime and caches it briefly, satisfying all three auditor requirements.

Exam trap

The trap here is that candidates may choose Option A (Parameter Store) because it also supports SecureString and IAM policies, but they overlook that Secrets Manager is the only service that natively provides automatic rotation without additional custom infrastructure, which is explicitly required by the auditors.

Why the other options are wrong

A

Option A requires the application to call GetParameter on each request or a short refresh interval, which does not meet the requirement for credentials to be rotated without redeploying the task definition. Additionally, Parameter Store SecureString does not support automatic rotation, failing the rotation requirement.

C

Storing the password in a local file within the container image at build time prevents rotation without redeploying the task definition, violating requirement (2). It also does not use AWS-managed encryption controls for the password at rest, as the image may be stored in Amazon ECR without encryption.

D

Option D fails because it does not support credential rotation without redeploying the task definition, and the broad IAM policy on the bucket prefix violates least-privilege permissions by allowing all ECS tasks to read the password.

When would these options actually be correct?

A

If the requirements did not include automatic rotation and allowed the application to fetch the secret on each request (e.g., for a non-critical config value that changes infrequently), Parameter Store SecureString with IAM least-privilege would be a valid, cost-effective solution.

C

This option would be correct if the requirement was to avoid any runtime dependency on AWS services for secret retrieval (e.g., offline or air-gapped environment) and rotation was not required, with the password being static and updated only via image rebuild.

D

This option would be correct if the requirement was to store a large, static configuration file (e.g., a machine learning model) that is encrypted at rest, accessed by multiple tasks, and does not require rotation or strict least-privilege per task.

Why candidates pick the wrong answer

A

Candidates may confuse Parameter Store SecureString with Secrets Manager, thinking both support encryption and IAM policies, and overlook the specific rotation requirement. They might also assume that caching the secret is unnecessary or that Parameter Store is sufficient for secrets management.

C

Candidates may think that embedding secrets in the image as a file is more secure than environment variables and avoids network calls, but they overlook the rotation and redeployment constraints.

D

Candidates may think S3 with SSE provides encryption at rest and is easy to set up, overlooking the lack of rotation support and the overly permissive access policy that violates least-privilege.

694
MCQmedium

A service runs in private subnets. It must call AWS APIs (for example, S3 and Secrets Manager). The team currently sends all outbound traffic through a NAT Gateway, and NAT charges have become a major cost driver. The workload must not traverse the public internet. What change most directly reduces NAT Gateway cost while maintaining private connectivity to those AWS services?

A.Continue using the NAT Gateway but reduce CloudWatch log retention to 1 day.
B.Replace the NAT Gateway route with VPC endpoints: use a Gateway VPC endpoint for S3 and an Interface VPC endpoint for Secrets Manager.
C.Launch a bastion host in a public subnet and force private instances to use SSH tunneling for API calls.
D.Switch to public subnets and attach security groups with the same rules to limit inbound access.
AnswerB

VPC endpoints provide private connectivity to AWS services without sending traffic through the internet or through NAT. A Gateway endpoint is used for S3, and an Interface endpoint is used for services like Secrets Manager. Traffic to those services stays within the AWS network, reducing or eliminating NAT charges for those API calls.

Why this answer

VPC endpoints allow private connectivity to AWS services without traversing the internet or a NAT Gateway. A Gateway VPC endpoint for S3 uses route table entries to reach S3 privately, and an Interface VPC endpoint for Secrets Manager uses an elastic network interface with a private IP. This eliminates NAT Gateway data processing charges entirely while keeping traffic within the AWS network.

Exam trap

The trap here is that candidates may think NAT Gateway is the only way to provide outbound connectivity, overlooking that VPC endpoints can provide private, cost-effective access to AWS services without internet routing.

How to eliminate wrong answers

Option A is wrong because reducing CloudWatch log retention does not affect NAT Gateway data processing costs, which are based on volume of traffic passing through the gateway, not log storage. Option C is wrong because forcing private instances to use SSH tunneling through a bastion host would still require outbound internet access for API calls, and SSH tunneling adds complexity, latency, and security risks without eliminating NAT costs. Option D is wrong because switching to public subnets would expose instances to the internet, violating the requirement that the workload must not traverse the public internet, and it would not reduce costs related to NAT Gateway.

695
MCQhard

A payments API uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The architecture review board prefers a managed AWS-native control.

A.A FIFO queue without a redrive policy
B.A dead-letter queue with an appropriate maxReceiveCount
C.A larger message retention period only
D.Short polling instead of long polling
AnswerB

A dead-letter queue with maxReceiveCount moves messages aside after a set number of failed receives, so poison messages stop blocking the main queue and useful retries continue. This is the managed, AWS-native control the review board requires, needing no custom code.

Why this answer

A dead-letter queue (DLQ) with an appropriate maxReceiveCount is the correct AWS-native solution for handling poison messages. When a message is repeatedly received from an SQS queue but fails processing, it is considered a poison message. By configuring a DLQ and setting a maxReceiveCount (e.g., 3 or 5), the message is automatically moved to the DLQ after exceeding that threshold, preventing it from blocking further retries and allowing the main queue to process valid messages.

Exam trap

The trap here is that candidates may confuse poison message handling with ordering or polling optimizations, and incorrectly choose FIFO queues or short polling, not realizing that only a DLQ with a redrive policy isolates repeatedly failing messages.

How to eliminate wrong answers

Option A is wrong because a FIFO queue without a redrive policy does not automatically handle poison messages; it only ensures strict ordering and exactly-once processing, but failed messages remain in the queue and continue to block retries. Option C is wrong because increasing the message retention period only keeps messages longer in the queue, but does nothing to isolate or remove poison messages that are repeatedly failing. Option D is wrong because short polling (returning immediately even if no messages are available) versus long polling (waiting for messages) affects latency and cost, but does not address the poison message problem; poison messages are a content/processing issue, not a polling mechanism issue.

696
MCQeasy

Your organization hosts an internet-facing application behind an Amazon CloudFront distribution. You want to mitigate common web exploits (for example, SQL injection and XSS) at the edge. Which action is the most appropriate way to do this using AWS services?

A.Create an AWS WAF web ACL using managed rule sets and associate it with the CloudFront distribution.
B.Add inbound rules to the security group so that only port 443 is open from the internet.
C.Enable AWS Shield Advanced to block SQL injection and XSS.
D.Restrict IAM permissions for the application’s EC2 instances so that SQL injection payloads cannot be executed.
AnswerA

AWS WAF examines incoming HTTP/HTTPS requests at the edge (when associated to CloudFront) and applies rule logic to detect common exploit patterns. Managed rule sets provide pre-built protections for threats like SQL injection and XSS before requests reach your origin.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). By creating a web ACL with managed rule sets (e.g., the AWS Managed Rules for SQL injection and XSS) and associating it with your CloudFront distribution, you can inspect incoming HTTP/HTTPS requests at the edge and block malicious payloads before they reach your origin. This is the most appropriate and scalable way to mitigate these threats at the edge.

Exam trap

The trap here is that candidates often confuse network-layer controls (security groups) or DDoS-specific services (Shield Advanced) with application-layer filtering, or mistakenly think IAM permissions can block malicious request payloads, when only a WAF can inspect and filter HTTP/HTTPS content at the edge.

Why the other options are wrong

B

Security groups operate at the instance level, not at the edge, and cannot inspect application-layer payloads like SQL injection or XSS. They only filter traffic based on IP addresses, protocols, and ports.

C

AWS Shield Advanced provides DDoS protection, not application-layer filtering for SQL injection or XSS. It does not inspect HTTP request payloads for these exploits.

D

Restricting IAM permissions for EC2 instances does not prevent SQL injection or XSS attacks at the edge; it only limits what the application can do after an attack payload reaches the instance. The question specifically asks for mitigation at the edge, which is before traffic reaches the application.

When would these options actually be correct?

B

If the question asked for 'restricting inbound traffic to only HTTPS from the internet to an EC2 instance' without mentioning web exploits, then adding inbound rules to the security group for port 443 would be appropriate.

C

When the question asks for the best service to protect against large-scale DDoS attacks (e.g., volumetric or state-exhaustion attacks) targeting an application behind CloudFront, and the requirement is for enhanced DDoS mitigation with 24/7 support and cost protection.

D

This option would be correct in a question about limiting the blast radius of a compromised application, such as: 'How can you ensure that an EC2 instance running a web application cannot delete S3 buckets if it is compromised via SQL injection?'

Why candidates pick the wrong answer

B

Candidates may confuse network-layer security (security groups) with application-layer protection (WAF), assuming that restricting ports is sufficient to block web exploits.

C

Candidates may confuse AWS Shield Advanced with AWS WAF, assuming it includes web application firewall capabilities, or overestimate its scope of protection.

D

Candidates may think that restricting IAM permissions can block the execution of malicious payloads, but IAM controls API actions, not application-level input validation or attack patterns like SQL injection.

697
MCQmedium

A log archive serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The design must avoid adding custom operational scripts.

A.Instance store volumes
B.S3 Standard-IA or S3 One Zone-IA depending on resilience requirements
C.S3 Standard for all objects
D.S3 Glacier Deep Archive
AnswerB

S3 Standard-IA and One Zone-IA both provide immediate millisecond retrieval with lower storage pricing than S3 Standard, matching infrequently accessed documents needing instant availability. Choosing between them depends on resilience: One Zone-IA sacrifices multi-AZ durability, and neither requires custom operational scripts.

Why this answer

S3 Standard-IA or S3 One Zone-IA is the best cost fit because the workload involves infrequently accessed documents that require immediate retrieval. These storage classes offer lower storage costs than S3 Standard while maintaining low-latency access (milliseconds), and they avoid custom operational scripts since retrieval is automatic via standard S3 GET requests. The choice between Standard-IA and One Zone-IA depends on whether the data requires multi-AZ resilience or can tolerate a single-AZ failure.

Exam trap

AWS often tests the misconception that 'infrequently accessed' automatically means Glacier or Deep Archive, but the key differentiator is the 'immediate availability' requirement, which eliminates any cold storage class with retrieval delays.

How to eliminate wrong answers

Option A is wrong because instance store volumes are ephemeral block storage attached to EC2 instances, not a durable S3 storage class, and they lose data on instance stop/termination, making them unsuitable for long-term log archives. Option C is wrong because S3 Standard is designed for frequently accessed data with higher storage costs, making it cost-inefficient for infrequently accessed documents, even though it provides immediate availability. Option D is wrong because S3 Glacier Deep Archive has retrieval times of 12-48 hours (not immediate), which violates the requirement for documents to be available immediately when requested.

698
Multi-Selecthard

A startup has three sandbox accounts and one production account. The CTO wants lower cost and operational overhead while keeping central purchasing and spend visibility. Which two actions are best? Select two.

Select 2 answers
A.Enable consolidated billing under AWS Organizations so discounts and shared purchasing apply across accounts.
B.Move each sandbox to its own payer account to isolate spend from the rest.
C.Use managed services such as Amazon RDS or Amazon S3 instead of self-managed EC2-based databases and file servers where practical.
D.Buy Dedicated Hosts for sandbox workloads to get a lower blended rate.
E.Disable AWS Budgets because consolidated billing already solves visibility.
AnswersA, C

Consolidated billing under AWS Organizations pools usage across all four accounts, so volume discounts and Savings Plans apply to aggregate spend rather than per-account totals. This directly satisfies the CTO's lower-cost and central-purchasing requirements, while the management account retains unified spend visibility without extra tooling.

Why this answer

Option A is correct because AWS Organizations consolidated billing places all four accounts under a single payer account, which aggregates usage for volume discounts (such as S3 tiered pricing and Reserved Instance/Savings Plans sharing), centralizes purchasing, and provides a single bill for spend visibility — exactly matching the CTO's goals of lower cost, less overhead, and central purchasing. Option C is correct because replacing self-managed EC2-based databases and file servers with managed services like Amazon RDS and Amazon S3 reduces operational overhead (patching, backups, scaling handled by AWS) and typically lowers total cost, aligning with the startup's desire to minimize operational burden. Option B is wrong because separate payer accounts fragment billing, forfeit volume discounts and RI/SP sharing, and increase overhead rather than reduce it.

Option D is wrong because Dedicated Hosts are a premium-priced option intended for licensing/compliance needs, not a cost-saving measure for sandbox workloads. Option E is wrong because AWS Budgets is a free cost-visibility and alerting tool; disabling it removes the very spend visibility the CTO wants, and consolidated billing alone does not provide budget alerts or thresholds.

Exam trap

The trap here is that candidates might think Dedicated Hosts (Option D) reduce costs for sandbox workloads, but they actually increase costs due to per-host billing and are intended for specific licensing scenarios, not general cost optimization.

Why the other options are wrong

B

Moving each sandbox to its own payer account increases operational overhead and reduces cost visibility, contradicting the goal of lowering cost and overhead while maintaining central purchasing and spend visibility.

D

Dedicated Hosts increase cost and operational overhead, contradicting the goal of lowering cost and overhead. They are not needed for sandbox workloads and do not provide a lower blended rate compared to Reserved Instances or Savings Plans under consolidated billing.

E

Disabling AWS Budgets removes spend visibility, which the CTO explicitly wants to maintain. Consolidated billing does not automatically provide visibility; budgets and alerts are still needed.

When would these options actually be correct?

B

If the CTO required strict cost isolation between accounts (e.g., for regulatory compliance or chargeback to different departments) and did not need central purchasing or consolidated discounts, then separate payer accounts would be appropriate.

D

A question requiring dedicated tenancy for licensing or compliance reasons (e.g., Microsoft SQL Server with per-core licensing) where Dedicated Hosts are necessary to meet license terms, and cost is less of a concern.

E

If the question stated that the CTO wants to reduce operational overhead and budgets are causing excessive alert noise with no value, and the company already has a separate cost monitoring tool that provides visibility, then disabling AWS Budgets could be correct.

Why candidates pick the wrong answer

B

Candidates may think separate payer accounts provide clearer cost isolation, but they overlook the increased management overhead and loss of volume discounts from consolidated billing.

D

Candidates may think Dedicated Hosts offer cost savings through licensing benefits or assume 'dedicated' implies better pricing, not realizing they are more expensive and only beneficial for specific licensing scenarios.

E

Candidates may incorrectly assume consolidated billing alone provides full visibility and that budgets are redundant, overlooking that budgets are a separate tool for proactive cost monitoring and alerts.

699
MCQmedium

A internal reporting portal serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The architecture review board prefers a managed AWS-native control.

A.Instance store volumes
B.S3 Glacier Deep Archive
C.S3 Standard for all objects
D.S3 Standard-IA or S3 One Zone-IA depending on resilience requirements
AnswerD

S3 Standard-IA and S3 One Zone-IA both deliver the same millisecond data access as S3 Standard while charging lower storage fees for data that is infrequently retrieved. Standard-IA stores data redundantly across multiple Availability Zones, providing high resilience, whereas One Zone-IA stores data only within a single AZ, reducing cost further but risking loss if that AZ fails. For an internal reporting portal with sparse usage, choose Standard-IA when durability and availability are critical, or One Zone-IA if the data can be regenerated and lower cost is prioritized.

Why this answer

S3 Standard-IA or S3 One Zone-IA is the best cost fit because the data is infrequently accessed but requires immediate availability when requested. These storage classes offer lower storage costs than S3 Standard while providing millisecond first-byte latency, meeting the 'immediately available' requirement. The choice between Standard-IA and One Zone-IA depends on the resilience needs (e.g., multi-AZ vs. single-AZ durability).

Exam trap

The trap here is that candidates often confuse 'infrequently accessed' with 'archival' and incorrectly choose S3 Glacier Deep Archive, overlooking the critical requirement for immediate availability on request.

How to eliminate wrong answers

Option A is wrong because instance store volumes are ephemeral, tied to a specific EC2 instance, and not a managed AWS-native control for object storage; they lose data on instance stop/termination and are not suitable for durable document storage. Option B is wrong because S3 Glacier Deep Archive has retrieval times of 12 hours or more (expedited retrieval is not available), which violates the 'immediately available when requested' requirement. Option C is wrong because S3 Standard is designed for frequently accessed data and would incur higher storage costs than necessary for infrequently accessed documents, making it not cost-optimal.

700
MCQhard

Based on the exhibit, a distributed analytics workload runs on 12 EC2 instances in one Availability Zone. The nodes exchange thousands of small messages per second and require the lowest possible intra-cluster latency and jitter. Which EC2 placement strategy is the best fit?

A.Spread placement group, because it places each instance on distinct underlying hardware.
B.Partition placement group, because it isolates nodes across rack partitions.
C.Cluster placement group, because it places instances physically close together in one Availability Zone.
D.Move the workload behind an Application Load Balancer so node-to-node traffic is balanced more efficiently.
AnswerC

Cluster placement groups are designed for workloads that need very low network latency, low jitter, and high packet-per-second performance. Placing the instances physically close together within the same Availability Zone reduces network hop distance and is the best match for a message-heavy distributed analytics cluster.

Why this answer

A cluster placement group is the best choice because it places all 12 EC2 instances in a single Availability Zone within the same high-bandwidth, low-latency logical segment of the network. This minimizes the physical distance and network hops between nodes, achieving the lowest possible intra-cluster latency and jitter required for the thousands of small messages exchanged per second.

Exam trap

The trap here is that candidates confuse 'spread' or 'partition' placement groups as providing better performance due to isolation, but they fail to recognize that cluster placement groups are the only strategy designed specifically for the lowest latency and jitter within a single AZ.

How to eliminate wrong answers

Option A is wrong because a spread placement group places each instance on distinct underlying hardware (different racks and often different AZs), which increases network distance and latency, making it unsuitable for high-frequency, low-latency messaging. Option B is wrong because a partition placement group isolates nodes across rack partitions to reduce correlated failures, but it does not guarantee the tight physical proximity needed for the lowest latency and jitter; it is designed for large distributed systems like HDFS or Cassandra, not for latency-sensitive micro-batch workloads. Option D is wrong because moving the workload behind an Application Load Balancer (ALB) would introduce an intermediary that adds significant latency and jitter for node-to-node traffic, and ALBs are designed for client-to-server load balancing, not for optimizing internal cluster communication.

701
MCQhard

A document portal needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable? The design must avoid adding custom operational scripts.

A.Amazon OpenSearch Service
B.AWS Config
C.Amazon EFS
D.Amazon SQS
AnswerA

Amazon OpenSearch Service (successor to Amazon Elasticsearch Service) is a distributed search and analytics engine built on Apache Lucene. It indexes documents into an inverted index, enabling near-real-time full-text search with tokenization, stemming, and relevance scoring, making it the purpose-built service for low-latency text queries across a document portal.

Why this answer

Amazon OpenSearch Service is the correct choice because it is a fully managed service that provides low-latency full-text search and filtering capabilities, ideal for indexing and searching product descriptions and attributes. It eliminates the need for custom operational scripts by handling cluster management, scaling, and backups automatically, aligning with the requirement to avoid custom operational overhead.

Exam trap

The trap here is that candidates may confuse AWS Config (a compliance tool) with a search service due to its name, or mistakenly think Amazon EFS or SQS can be adapted for search with custom scripts, ignoring the requirement to avoid custom operational scripts.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it is a service for auditing and evaluating resource configurations against compliance rules, not for full-text search or indexing. Option C (Amazon EFS) is wrong because it is a scalable file storage service for shared access to files, not a search engine or indexing solution. Option D (Amazon SQS) is wrong because it is a message queuing service for decoupling application components, not designed for search or querying of product data.

702
MCQmedium

A startup runs an HTTP/2 API that also supports WebSocket connections. They need path-based routing to separate microservices (for example, /api/* to Service A and /metrics/* to Service B) and want TLS terminated at the load balancer. Which AWS option best meets these requirements while maintaining high request performance?

A.Use an Amazon NLB and configure target groups with HTTP health checks and listener rules for path-based routing.
B.Use an Amazon ALB with HTTP/2 support, WebSocket upgrades enabled, and listener rules for host/path-based routing.
C.Use Amazon API Gateway with a single backend integration and rely on the client to route requests to different microservices.
D.Use Amazon CloudFront without an ALB, and route requests to microservices using only custom origin headers.
AnswerB

An ALB supports Layer 7 features needed here: it can terminate TLS on an HTTPS listener, evaluate HTTP host/path routing rules, and it supports WebSocket by allowing HTTP Upgrade behavior through the ALB to the targets. ALBs also support HTTP/2 on HTTPS listeners, which helps maintain high request performance.

Why this answer

An Application Load Balancer (ALB) natively supports HTTP/2, WebSocket upgrades, and path-based routing via listener rules. It terminates TLS at the load balancer, offloading encryption from backend services, and maintains high performance for both HTTP/2 and WebSocket traffic. This makes ALB the correct choice for the startup's requirements.

Exam trap

The trap here is that candidates may confuse NLB's Layer 4 capabilities with ALB's Layer 7 features, incorrectly assuming NLB can handle path-based routing or WebSocket upgrades, when in fact it cannot inspect application-layer data.

Why the other options are wrong

A

NLB does not support path-based routing or HTTP/2; it operates at Layer 4 and cannot inspect HTTP paths or handle WebSocket upgrades natively.

C

API Gateway does not natively support WebSocket connections with path-based routing to separate microservices; it would require custom integration logic and cannot directly route to different services based on path patterns like /api/* and /metrics/*.

D

CloudFront does not natively support WebSocket connections or path-based routing to separate microservices based on URL paths like /api/* and /metrics/*; it is a CDN, not a load balancer with those routing capabilities.

When would these options actually be correct?

A

When the requirement is for ultra-high performance with static IP addresses, and routing is based on TCP/UDP traffic (e.g., port-based) without need for HTTP features like path-based routing or WebSocket support.

C

When the requirement is to expose a RESTful API with features like throttling, caching, and authentication, and the backend is a single service or can be handled via a single integration, with no need for WebSocket support or path-based routing to multiple microservices.

D

A question requiring global content delivery with low latency, DDoS protection, and caching for static or dynamic content, where the backend is a single origin (e.g., an ALB or S3) and WebSocket support is not needed.

Why candidates pick the wrong answer

A

Candidates may think NLB can handle HTTP/2 and path routing because it supports HTTP health checks, but NLB lacks Layer 7 capabilities needed for path-based routing and WebSocket upgrades.

C

Candidates may think API Gateway is a natural choice for API management and assume it can handle WebSocket and path-based routing, but they overlook its limitations with WebSocket and direct microservice routing without custom workarounds.

D

Candidates may think CloudFront can handle path-based routing via behaviors and assume it supports WebSocket, but WebSocket support in CloudFront is limited and not designed for microservice path-based routing with TLS termination at the edge.

703
MCQeasy

A company wants to give a third-party auditor read-only access to a specific Amazon S3 bucket for a limited period. The auditor has an AWS account and will use their own IAM credentials. The company must not share long-term credentials and wants to revoke access automatically when the audit ends. What is the most secure way to grant this access?

A.Create an IAM role in the company account with a trust policy that allows the auditor's AWS account to assume it, and attach a read-only S3 policy with a condition limiting access to the audit period.
B.Enable S3 Block Public Access and provide the auditor with the bucket's ARN so they can configure their own access.
C.Create an IAM user in the company account with read-only S3 permissions and share the access keys with the auditor.
D.Generate a presigned URL for each object in the bucket and send the URLs to the auditor.
AnswerA

Cross-account IAM role assumption lets the auditor use their own credentials to obtain temporary session tokens, so no long-term secrets are shared. The trust policy and permissions can include time-based conditions, and removing the trust or the role revokes access immediately when the audit ends.

Why this answer

Cross-account IAM role assumption is the standard secure pattern for granting temporary access to external parties. The auditor assumes a role using their own identity, receives temporary credentials, and the company retains full control over permissions and revocation. This avoids sharing long-term credentials and supports time-bound access conditions.

Exam trap

The trap here is thinking that presigned URLs provide the same level of controlled, revocable, bucket-wide access as a cross-account IAM role, when they are object-specific and harder to revoke centrally.

704
MCQeasy

Your AWS Organizations environment has an SCP that explicitly denies kms:Decrypt for principals in the Production OU. A member account IAM policy for a user grants kms:Decrypt on the required KMS key. If that user attempts kms:Decrypt, what happens?

A.The request succeeds because the IAM policy explicitly allows kms:Decrypt
B.The request is denied because the SCP explicit deny overrides IAM allows
C.The request succeeds, but only when using the KMS key policy to allow the user
D.The request succeeds for read-only actions and fails only for writes
AnswerB

SCPs are evaluated as a permissions filter for the member account. When an SCP contains an explicit Deny matching kms:Decrypt, that Deny takes precedence over any IAM Allow decisions in the account, and the action is blocked.

Why this answer

In AWS Organizations, Service Control Policies (SCPs) act as a guardrail that sets the maximum available permissions for all accounts in an OU. An explicit deny in an SCP overrides any allow in an IAM policy, even if the IAM policy explicitly grants the action. Therefore, the user's kms:Decrypt request is denied because the SCP's explicit deny takes precedence over the IAM allow.

Exam trap

The trap here is that candidates often assume IAM policy allows are sufficient, forgetting that SCPs act as a higher-level permission boundary that can override those allows with an explicit deny.

How to eliminate wrong answers

Option A is wrong because it ignores the hierarchical nature of AWS authorization: an explicit deny in an SCP at the OU level overrides any allow in an IAM policy, so the request cannot succeed. Option C is wrong because even if the KMS key policy grants kms:Decrypt to the user, the SCP explicit deny still applies and blocks the action; SCPs are evaluated before resource-based policies. Option D is wrong because kms:Decrypt is a single action, not a read or write category, and SCPs apply uniformly to all actions they specify; there is no distinction between read-only and write actions in this context.

705
Multi-Selectmedium

A company runs a stateless web application on a fleet of six On-Demand EC2 instances behind an Application Load Balancer. The instances are spread across three Availability Zones in a single AWS Region and run 24/7. The workload is steady and predictable, and the company wants to reduce compute costs without changing the application architecture or reducing availability. The company is willing to commit to a one-year term. Which two actions will reduce the EC2 compute cost for this workload? (Choose two.)

Select 2 answers
A.Purchase a one-year Standard Reserved Instance for each of the six running instances in the same instance family and Region.
B.Enable detailed monitoring on all instances and configure an Auto Scaling target tracking policy at 40% CPU.
C.Replace the On-Demand instances with Spot Instances and let the Auto Scaling group replace any interrupted capacity.
D.Purchase a one-year Compute Savings Plan covering the expected steady-state compute usage.
E.Move the instances into a placement group and enable cluster networking between them.
AnswersA, D

Standard Reserved Instances for a specific instance family and Region provide a significant discount compared to On-Demand for steady-state usage and are a valid way to reduce cost when the instance family is stable. Because the fleet is constant and the term matches the company's one-year willingness to commit, this achieves the cost reduction without altering the architecture or availability.

Why this answer

For steady, predictable, always-on compute, commitment-based discounts are the correct lever. Compute Savings Plans and Standard Reserved Instances both convert On-Demand hourly pricing into a lower committed rate for a one-year term, satisfying the cost goal while preserving the multi-AZ, always-available design. Spot capacity and monitoring changes do not meet the availability requirement or do not change the compute rate.

Exam trap

The trap here is assuming that any discount mechanism is interchangeable, when the requirement to keep availability high across three Availability Zones rules out interruption-prone capacity even though it is cheaper.

706
MCQmedium

A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The design must avoid adding custom operational scripts.

A.AWS WAF
B.Amazon CloudFront
C.Amazon SQS queue
D.Amazon Route 53 weighted routing
AnswerC

Amazon SQS decouples the web tier from fulfilment workers, buffering burst order volumes so spikes are absorbed rather than dropped. Its native at-least-once delivery and visibility-timeout retry mechanism reprocess failed messages without custom operational scripts, satisfying the no-scripts constraint.

Why this answer

Amazon SQS is the correct choice because it acts as a durable, fully managed message buffer that decouples the web tier from the fulfilment workers. When bursts of orders arrive, SQS queues the messages and allows workers to poll at their own pace, absorbing spikes without data loss. The built-in retry logic (visibility timeout and dead-letter queue) ensures failed processing attempts are automatically retried, and no custom operational scripts are needed.

Exam trap

The trap here is that candidates often confuse decoupling with caching or DNS-level distribution, picking CloudFront or Route 53 because they think 'absorbing spikes' means scaling web servers, but the question specifically requires buffering and retry without custom scripts, which only a queue service like SQS provides.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that filters HTTP/S traffic based on rules (e.g., SQL injection, XSS); it does not buffer or retry messages between tiers. Option B is wrong because Amazon CloudFront is a content delivery network (CDN) that caches and accelerates static/dynamic content at edge locations; it cannot queue or retry asynchronous order processing. Option D is wrong because Amazon Route 53 weighted routing distributes DNS traffic across multiple endpoints based on weights; it provides load balancing at the DNS level but does not absorb spikes or provide retry mechanisms for message processing.

707
MCQmedium

An Auto Scaling group for a background worker runs EC2 instances continuously. Over the last 30 days, CloudWatch shows sustained CPU utilization around 6% with no memory pressure, and queue processing latency meets all SLAs. The team wants to lower monthly cost with minimal risk. What is the best next action?

A.Increase the instance size to reduce CPU throttling risk
B.Perform right sizing by downsizing to a smaller instance family/size and validate SLAs
C.Switch the group to Spot Instances to reduce cost without changing instance sizing
D.Buy Reserved Instances with a long term commitment before making any sizing changes
AnswerB

Right sizing uses actual utilization to remove overprovisioning. With low CPU and no memory pressure and SLAs already met, downsizing (while validating under load and during a controlled rollout) is the safest way to reduce waste.

Why this answer

The current instance type is over-provisioned, as sustained CPU utilization is only 6% with no memory pressure and all SLAs are met. Right-sizing to a smaller instance family or size directly reduces compute cost while maintaining performance, making it the lowest-risk, cost-optimization action. This aligns with the AWS Well-Architected Framework's cost optimization pillar, which recommends matching instance capacity to actual workload requirements.

Exam trap

The trap here is that candidates may assume Spot Instances are always the cheapest option, but they ignore the risk of interruption for a continuously running workload where SLAs must be met, making right-sizing the safer and more appropriate first step.

How to eliminate wrong answers

Option A is wrong because increasing instance size would raise costs and is unnecessary given the low CPU utilization and no performance issues. Option C is wrong because switching to Spot Instances introduces the risk of interruption, which is not minimal risk for a continuously running background worker that must meet SLAs. Option D is wrong because buying Reserved Instances before right-sizing locks in a commitment for an over-provisioned instance type, increasing cost without addressing the root cause of waste.

708
MCQmedium

A media company stores original video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that a readable copy of every object exist in the eu-west-1 Region within 15 minutes of upload, and that the objects in eu-west-1 be usable directly by an application there. No transformations are required. Which S3 feature should the solutions architect enable?

A.S3 Multi-Region Access Points with an active-passive routing configuration
B.S3 Same-Region Replication (SRR) between the us-east-1 bucket and a second bucket in us-east-1
C.S3 Lifecycle policies that transition objects to S3 Glacier Instant Retrieval in eu-west-1 after 15 minutes
D.S3 Cross-Region Replication (CRR) with S3 Versioning enabled on both the source and destination buckets
AnswerD

CRR asynchronously replicates new and updated objects to a destination bucket in another Region, and most objects replicate within minutes, satisfying the 15-minute requirement. Versioning is mandatory on both source and destination buckets for replication rules to work. Because the replicated objects are full readable copies, the application in eu-west-1 can read them directly without any restore step.

Why this answer

Cross-Region Replication is the purpose-built S3 capability for maintaining an automatically updated, readable object copy in a different Region, and its asynchronous replication latency generally falls well inside a 15-minute window. Versioning on both buckets is a prerequisite, so the architect must enable it as part of the design. The other choices either keep data in one Region, move data only between storage classes, or route requests without creating a second copy.

Exam trap

The trap here is confusing request-routing features such as Multi-Region Access Points with data-replication features, and forgetting that S3 Versioning must be enabled on both buckets before a replication rule can be created.

709
MCQeasy

A company stores private report PDFs in an S3 bucket. They want users to access PDFs only through CloudFront. Even if someone knows the S3 object URL, direct S3 access must fail. What is the best S3 bucket policy approach?

A.Keep the bucket private and allow s3:GetObject only to the CloudFront origin access identity (OAI) or origin access control (OAC) principal (optionally restricting with aws:SourceArn for the specific distribution).
B.Allow s3:GetObject to "Principal": "*" but rely on CloudFront signed URLs to prevent access.
C.Allow s3:GetObject to the CloudFront distribution using a Condition on aws:SourceIp without restricting the Principal.
D.Only enable default encryption (SSE-KMS) and leave bucket permissions unchanged.
AnswerA

CloudFront is granted permission to read the objects from S3 using its OAI/OAC principal. Because no other principals are allowed s3:GetObject, direct requests to the S3 object URL are denied even if the URL is known.

Why this answer

It uses an Origin Access Identity (OAI) or Origin Access Control (OAC) to grant CloudFront exclusive read access to the S3 bucket. By setting a bucket policy that allows s3:GetObject only to the CloudFront OAI/OAC principal (and optionally restricting with aws:SourceArn for the specific distribution), direct S3 object URL requests are denied, ensuring users can only access PDFs through CloudFront.

Exam trap

The trap here is that candidates often think encryption (SSE-KMS) or IP-based restrictions are sufficient to block direct S3 access, but they fail to understand that only a bucket policy explicitly denying access to all principals except CloudFront's OAI/OAC can enforce the requirement.

How to eliminate wrong answers

Option B is wrong because allowing s3:GetObject to 'Principal': '*' makes the bucket publicly readable, bypassing CloudFront entirely; anyone with the S3 URL can access the PDFs directly, violating the requirement. Option C is wrong because restricting by aws:SourceIp without specifying a Principal still leaves the bucket open to any principal, and CloudFront's IP addresses are not a reliable way to enforce exclusive access (they can change and be spoofed). Option D is wrong because enabling SSE-KMS encryption does not restrict access; it only encrypts data at rest, leaving the bucket policy unchanged and allowing direct S3 access if the URL is known.

710
Multi-Selecthard

A regional web application for a content publishing system must fail over automatically to a secondary Region if the primary endpoint becomes unhealthy. Which two services or features are required? The design must avoid adding custom operational scripts.

Select 2 answers
A.AWS Organizations service control policies
B.Route 53 failover routing with health checks
C.S3 Transfer Acceleration
D.A deployed standby application stack in the secondary Region
AnswersB, D

Route 53 failover routing with health checks monitors the primary endpoint and automatically redirects DNS to the secondary when it turns unhealthy. This satisfies the automatic failover constraint without custom operational scripts, since health evaluation and DNS switching are managed by Route 53 itself.

Why this answer

Option B is correct because Route 53 failover routing with health checks automatically redirects DNS queries to the secondary endpoint when the primary health check is deemed unhealthy, providing the required automatic failover without custom scripts. Option D is correct because a deployed standby application stack in the secondary Region is necessary to actually serve traffic after failover; DNS redirection alone cannot run the application. Option A is incorrect because AWS Organizations service control policies govern permissions and guardrails, not traffic failover or health-based routing.

Option C is incorrect because S3 Transfer Acceleration only speeds up uploads to S3 buckets and does not provide regional failover or health checking.

Exam trap

The trap here is that candidates often assume Route 53 alone is sufficient, forgetting that the secondary Region must have a fully deployed and running application stack to receive traffic after failover.

711
MCQmedium

A logistics company runs an order-tracking service that exposes a REST API. The service must remain available during a single Availability Zone failure and must keep read latency low for a globally distributed user base. The data store must support automatic multi-AZ replication without the team managing database servers. Which solution meets these requirements?

A.Amazon DynamoDB with global tables and on-demand capacity mode.
B.Amazon RDS for MySQL with a read replica in a second Availability Zone.
C.Amazon ElastiCache for Redis with a cluster mode disabled replication group in one Availability Zone.
D.Amazon RDS for PostgreSQL with Multi-AZ DB instance deployment and a cross-Region read replica.
AnswerA

DynamoDB is a fully managed, multi-AZ service by default, and global tables replicate data across Regions for low-latency reads near users. On-demand capacity removes provisioning concerns. The team does not manage servers, and the design remains available during a single Availability Zone failure without manual failover steps.

Why this answer

DynamoDB is a fully managed, multi-AZ key-value store, so a single Availability Zone failure does not interrupt service and no database servers are managed. Global tables replicate data across Regions so users read from a nearby replica with low latency, and on-demand capacity removes the need to provision throughput, meeting both resilience and performance goals.

Exam trap

The trap here is choosing an RDS read replica for failover, when read replicas are not automatic failover targets and require manual promotion.

712
MCQmedium

A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The design must avoid adding custom operational scripts.

A.Provisioned IOPS SSD such as io2
B.st1 Throughput Optimized HDD
C.Instance store only
D.sc1 Cold HDD
AnswerA

Provisioned IOPS SSD (io2) is the correct choice because it delivers consistent, high IOPS with single-digit millisecond latency and 99.999% durability, making it ideal for business-critical transactional workloads like a media archive's metadata database. Unlike throughput-oriented HDD types, io2 lets you specify a guaranteed IOPS level, up to 64,000 IOPS per volume on standard io2 (or 256,000 with Block Express), so the storage performance remains stable even under sustained load.

Why this answer

A Provisioned IOPS SSD (io2) volume is the correct choice because it delivers consistent, high IOPS required for transactional databases, with a 99.999% durability guarantee and the ability to provision IOPS independently of storage capacity. This avoids custom operational scripts by providing predictable performance natively through the EBS volume type.

Exam trap

The trap here is that candidates may choose instance store (Option C) thinking it provides the highest performance, but they overlook its lack of persistence and the requirement for custom scripts to manage data durability, which violates the 'no custom operational scripts' constraint.

How to eliminate wrong answers

Option B (st1 Throughput Optimized HDD) is wrong because it is designed for throughput-intensive workloads like big data and log processing, not for consistent high IOPS; its performance is burst-based and degrades under sustained small random I/O. Option C (Instance store only) is wrong because instance store volumes are ephemeral and data is lost on instance stop or termination, making them unsuitable for a persistent transactional database without custom backup scripts. Option D (sc1 Cold HDD) is wrong because it is optimized for infrequently accessed data with the lowest cost per GB, offering very low IOPS that cannot meet the demands of a transactional database.

713
MCQmedium

A team serves image files from S3 through CloudFront. During a performance review, they notice that CloudFront cache hit ratio is low and the S3 origin receives many repeated requests for the same images. Request URLs include a volatile query parameter called 'sessionId' that changes for each user, but the image content is identical regardless of 'sessionId'. What configuration change will most effectively increase cache hit ratio?

A.Update the CloudFront cache policy so that 'sessionId' is not included in the cache key (and only stable query parameters are used).
B.Enable origin request policy to forward all query strings to S3 so responses are always correct for every sessionId.
C.Set the CloudFront minimum TTL to 0 seconds so cached objects expire quickly and fetch fresh content more often.
D.Disable caching by using CloudFront managed caching disabled so that every request validates with the origin.
AnswerA

Including sessionId in the cache key means CloudFront treats each session's request as a distinct object, so identical images requested with different sessionId values create separate cache entries and miss the cache. A cache policy that excludes volatile parameters like sessionId (while still allowing stable ones that affect the image) collapses those requests to a single cache key, letting edge locations serve the same object to many sessions. This directly increases the cache hit ratio without requiring any change to origin behavior, because the underlying image content has not actually changed.

Why this answer

The low cache hit ratio is caused by the volatile 'sessionId' query parameter being included in the CloudFront cache key, which creates a unique cache entry for every user request even though the image content is identical. By updating the cache policy to exclude 'sessionId' from the cache key, CloudFront will treat all requests for the same image as the same cached object, dramatically increasing the cache hit ratio and reducing load on the S3 origin.

Exam trap

The trap here is that candidates may confuse the purpose of cache policies (which control the cache key) with origin request policies (which control what is forwarded to the origin), leading them to incorrectly choose Option B thinking that forwarding query strings will fix the issue, when in fact it does not affect the cache key.

How to eliminate wrong answers

Option B is wrong because forwarding all query strings to S3 via an origin request policy would still include the volatile 'sessionId' in the request to the origin, but it does not change the cache key — the cache key is controlled by the cache policy, not the origin request policy, so the cache hit ratio would remain low. Option C is wrong because setting the minimum TTL to 0 seconds would cause CloudFront to treat every object as immediately expired, forcing frequent revalidation with the origin and actually decreasing the cache hit ratio further. Option D is wrong because disabling caching entirely would eliminate any cache hits, making every request go to the S3 origin, which is the opposite of increasing the cache hit ratio.

714
MCQhard

A financial analytics team runs a batch job every night that scans a 4 TB Amazon Redshift provisioned cluster table to compute aggregates for a reporting dashboard. The dashboard queries are read-only, run for several hours each morning, and compete with ETL writes on the same cluster, causing slow dashboard response times. The team wants to isolate the dashboard workload and improve query performance without changing the ETL job. Which solution meets these requirements with the LEAST operational effort?

A.Enable concurrency scaling on the provisioned cluster and configure a workload management (WLM) queue for the dashboard queries.
B.Take a nightly snapshot of the cluster and restore it into a second provisioned cluster that serves only the dashboard queries.
C.Move the table to Amazon S3 and query it with Amazon Athena, pointing the dashboard at the Athena results.
D.Create a Redshift Serverless workgroup and use Redshift data sharing to expose the provisioned cluster's data to the serverless workgroup for the dashboard queries.
AnswerD

Redshift data sharing lets a Redshift Serverless workgroup read live data from a provisioned cluster without copying it, isolating the dashboard's compute from the ETL writes. The dashboard gets its own automatically scaled compute, so morning queries no longer contend with the batch job, and no data movement or application rewrite is required. This is the lowest-effort way to separate read and write workloads.

Why this answer

Redshift data sharing separates compute so the dashboard reads live producer data through a serverless consumer without copying or snapshotting. That removes contention with the ETL writes and lets the dashboard scale independently, all with minimal setup. Concurrency scaling still shares the cluster, snapshot restores give stale data, and moving to Athena requires a costly migration and SQL rewrite.

Exam trap

The trap here is reaching for concurrency scaling as the isolation mechanism, when it only adds burst capacity to the same cluster and does not separate the dashboard from the ETL workload's data and leader-node resources.

715
MCQmedium

Your web application is deployed in two AWS Regions (Region A and Region B). You want Route 53 to automatically fail over DNS traffic from Region A to Region B when Region A is unhealthy. The failover decision must be based on health checks that verify whether the application in Region A is reachable. Which Route 53 routing configuration best meets these requirements?

A.Latency-based routing with regional aliases to split traffic based on measured latency.
B.Geolocation routing using country-based routing policies.
C.Failover routing using a primary record with an associated health check for Region A and a secondary record for Region B.
D.Weighted routing with weights set to 100 for Region A and 0 for Region B.
AnswerC

Route 53 failover routing is designed for active/standby patterns. You configure the Region A record as primary with a health check. When that health check fails, Route 53 automatically returns the Region B (secondary) record, enabling health-check-driven regional failover.

Why this answer

Route 53 failover routing allows you to create a primary record with an associated health check for Region A and a secondary record for Region B. When the health check for Region A fails, Route 53 automatically returns the secondary record's IP address, directing traffic to Region B. This directly meets the requirement for automatic failover based on application reachability.

Exam trap

The trap here is that candidates often confuse failover routing with weighted routing, mistakenly thinking that setting weights to 100/0 will achieve failover, but weighted routing does not automatically adjust weights based on health checks.

Why the other options are wrong

A

Latency-based routing directs traffic based on lowest latency, not health status. It cannot automatically fail over to Region B when Region A is unhealthy because it lacks health check integration.

B

Geolocation routing directs traffic based on the geographic location of the user, not on the health of the endpoint. It cannot automatically failover from Region A to Region B when Region A becomes unhealthy.

D

Weighted routing with 100/0 weights does not provide automatic failover; it simply sends all traffic to Region A until you manually change weights. It lacks health checks to trigger failover when Region A becomes unhealthy.

When would these options actually be correct?

A

You need to route users to the region with the lowest latency for better performance, and you have health checks to exclude unhealthy endpoints. Latency-based routing with health checks would be correct.

B

A company needs to route users to the nearest regional endpoint based on their country for compliance or content localization, and failover is not required. Geolocation routing would be correct if the requirement is to direct traffic from specific countries to specific regions.

D

A scenario where you want to gradually shift traffic from one region to another (e.g., for blue/green deployment or load balancing) without automatic failover. For example, you want to send 10% of traffic to a new region and 90% to the old region, adjusting weights manually over time.

Why candidates pick the wrong answer

A

Candidates may confuse latency-based routing with failover, thinking that routing to the lowest latency region inherently provides failover, but it does not consider health unless health checks are explicitly used.

B

Candidates may confuse geolocation routing with failover routing because both involve multiple regions, but geolocation focuses on user location rather than endpoint health.

D

Candidates may think setting weights to 100/0 is a simple way to direct all traffic to Region A, and assume failover can be achieved by manually changing weights to 0/100 when Region A fails, overlooking the requirement for automatic failover based on health checks.

716
MCQmedium

A test environment has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations? The architecture review board prefers a managed AWS-native control.

A.AWS DataSync
B.AWS Shield
C.AWS Artifact
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer uses machine learning to analyze historical utilization metrics from CloudWatch, including CPU, memory, network, and storage, to identify whether EC2 instances are oversized, undersized, or optimally sized. It then produces instance type recommendations with a performance risk score, directly answering the question of whether the test environment's instances are oversized. Its findings are actionable, enabling cost savings without sacrificing workload performance.

Why this answer

AWS Compute Optimizer is a managed service that uses machine learning to analyze historical utilization metrics (CPU, memory, network, and storage) and provides rightsizing recommendations for EC2 instances. It identifies over-provisioned resources and suggests instance types that better match workload requirements, directly addressing the oversized EC2 instances in the test environment.

Exam trap

The trap here is that candidates may confuse AWS Compute Optimizer with other monitoring or cost tools (like AWS Trusted Advisor or Cost Explorer), but the question specifically asks for a managed AWS-native service that identifies rightsizing recommendations, which is Compute Optimizer's primary function.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is a data transfer service for moving large datasets between on-premises storage and AWS services (e.g., S3, EFS), not a tool for analyzing EC2 utilization or providing rightsizing recommendations. Option B is wrong because AWS Shield is a managed DDoS protection service that safeguards applications against distributed denial-of-service attacks, unrelated to cost optimization or instance sizing. Option C is wrong because AWS Artifact is a self-service portal for downloading AWS compliance reports and agreements (e.g., SOC, PCI), not a service for monitoring or recommending EC2 instance changes.

717
MCQmedium

An application in account A needs to use an encrypted EBS volume whose snapshots were copied from account B. The EBS volume is encrypted with a customer-managed KMS key in account B. After attaching the volume, the instance fails to mount it and logs show KMS access errors (kms:Decrypt) for the instance role. The instance role in account A already has an IAM policy allowing kms:Decrypt on that key ARN, but the mount still fails. What must be updated in account B to allow the mount to succeed?

A.Enable KMS automatic key rotation for the customer-managed key in account B.
B.Update the KMS key policy in account B to allow the instance role’s principal from account A to call kms:Decrypt and kms:CreateGrant.
C.Attach the key policy as an IAM permissions policy to the instance role in account A only; key policies are not evaluated cross-account.
D.Disable encryption on the EBS volume until authorization is fixed, then re-enable encryption after mount.
AnswerB

Customer-managed KMS keys use resource-based key policies to control cross-account usage. Even if the IAM role in account A has kms:Decrypt permissions, the account B key policy must also allow that principal to use the key. Including kms:Decrypt (and often kms:CreateGrant) resolves cross-account mount authorization.

Why this answer

The instance role in account A has an IAM policy allowing kms:Decrypt on the key ARN, but cross-account KMS access requires the key policy in account B to explicitly grant the external principal (the instance role's ARN) the necessary permissions. Without a key policy statement in account B that allows kms:Decrypt and kms:CreateGrant for the instance role, the KMS service will deny the decryption request, even if the IAM policy in account A permits it. The kms:CreateGrant permission is required because attaching an encrypted EBS volume internally creates a grant to allow the EC2 service to use the key on behalf of the instance.

Exam trap

The trap here is that candidates assume an IAM policy in the consuming account is sufficient for cross-account KMS operations, but AWS requires the key policy in the key-owning account to explicitly grant access to the external principal, and kms:CreateGrant is a commonly overlooked required permission for EBS volume attachments.

Why the other options are wrong

A

Enabling automatic key rotation does not grant cross-account permissions; it only rotates the key material periodically. The mount fails due to missing cross-account access in the key policy, not due to key rotation.

C

In cross-account KMS access, the key policy in account B must explicitly grant permissions to the IAM role in account A; IAM policies in account A alone are insufficient because the key policy is the primary authorization mechanism for the KMS key in account B.

D

Disabling and re-enabling encryption on an EBS volume is not possible without recreating the volume, and it does not resolve cross-account KMS authorization issues. The root cause is missing key policy permissions in account B.

When would these options actually be correct?

A

In a scenario where a customer-managed KMS key is used within the same account and the question asks for a best practice to improve security without changing permissions, enabling automatic key rotation would be correct to meet compliance requirements.

C

This option would be correct if the KMS key and the EBS volume were in the same account (account A). In that case, the key policy can be attached as an IAM permissions policy to the instance role, and the key policy itself is not evaluated separately for the same account.

D

In a scenario where an EBS volume is encrypted with a customer-managed KMS key and the instance role lacks kms:Decrypt permissions due to a misconfigured IAM policy, temporarily disabling encryption is not an option. This option would never be correct because EBS encryption cannot be toggled on an existing volume; it must be set at creation.

Why candidates pick the wrong answer

A

Candidates may think that key rotation resolves access issues because they confuse key management with access control, or they believe that rotation refreshes permissions.

C

Candidates may think that IAM policies in the requesting account are sufficient for cross-account access, overlooking that KMS key policies must explicitly allow principals from other accounts.

D

Candidates may think that disabling encryption bypasses the KMS error temporarily, or they misunderstand that EBS encryption can be changed after volume creation. They might also confuse this with the ability to modify other volume attributes.

718
MCQeasy

An internal team runs a report-generation job once per day. It typically finishes in a few minutes, and even on its slowest days it still completes in under 15 minutes. The team wants to reduce operational overhead and pay primarily for actual runtime instead of keeping servers running 24/7. Which AWS approach best matches these goals?

A.Deploy the job on EC2 instances and keep them running continuously for the daily schedule.
B.Use AWS Lambda triggered by a schedule (for example, EventBridge) to run the report at the required time.
C.Run the job in an RDS database using stored procedures scheduled by the database engine.
D.Use an Auto Scaling group with a fixed minimum size of one instance and disable scaling.
AnswerB

Lambda runs only when EventBridge invokes it on schedule, so billing reflects invocation duration rather than idle server hours. The job finishes well within Lambda's 15-minute limit, so the runtime ceiling is not exceeded and operational overhead drops.

Why this answer

AWS Lambda, triggered by Amazon EventBridge (CloudWatch Events), is ideal for short-lived, infrequent jobs like this daily report. It eliminates idle server costs by running only when invoked, and the 15-minute execution timeout comfortably covers the job's maximum runtime. This serverless approach directly reduces operational overhead and aligns with a pay-per-use cost model.

Exam trap

The trap here is that candidates may assume EC2 or Auto Scaling is needed for any scheduled job, overlooking that Lambda's 15-minute timeout and serverless pricing perfectly suit short, infrequent tasks, while the 'pay primarily for actual runtime' requirement explicitly points away from always-on compute.

Why the other options are wrong

A

Keeping EC2 instances running 24/7 incurs costs for idle time, contradicting the goal of paying primarily for actual runtime when the job completes in under 15 minutes daily.

C

Running the job as stored procedures in RDS would still require a running database instance 24/7, incurring costs for idle time, and does not align with the goal of paying primarily for actual runtime.

D

An Auto Scaling group with a fixed minimum size of one instance keeps an EC2 instance running 24/7, which incurs costs for idle time and does not reduce operational overhead or pay-per-use runtime.

When would these options actually be correct?

A

If the job required a persistent, stateful environment (e.g., large local storage, specific OS configurations) or needed to run multiple times per day with unpredictable latency demands, EC2 instances running continuously would be appropriate.

C

If the question required processing large datasets directly within a database (e.g., complex aggregations on terabytes of data) and the team already had a running RDS instance for other purposes, using stored procedures could be efficient without additional compute overhead.

D

A question where a workload requires a single EC2 instance to always be available (e.g., a legacy application that cannot be containerized or serverless) and must automatically recover from failure, with the goal of high availability rather than cost optimization.

Why candidates pick the wrong answer

A

Candidates may default to EC2 for any compute workload without considering serverless alternatives, overlooking the cost and operational overhead of idle instances.

C

Candidates might think that using RDS stored procedures eliminates the need for separate compute resources, overlooking that the database instance itself must remain running continuously, incurring costs regardless of job execution.

D

Candidates may think Auto Scaling automatically reduces costs, but a fixed minimum of one instance means the instance never scales in, so it runs continuously, failing to meet the 'pay primarily for actual runtime' requirement.

719
MCQhard

A claims portal must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

A.Tag encrypted volumes after creation
B.Enable VPC Flow Logs
C.Use an SCP that denies ec2:CreateVolume when the encrypted condition is false
D.Run a daily Lambda function to encrypt unencrypted volumes
AnswerC

An SCP attached to an organizational unit or account can deny ec2:CreateVolume whenever the ec2:Encrypted request condition is false, preventing the API call from succeeding across all affected accounts. This works at the IAM/Organizations evaluation layer, so the request is rejected before a single unencrypted volume is provisioned. For robust enforcement, the SCP condition should use the Bool operator with ec2:Encrypted set to 'false' to explicitly block noncompliant volume creation. This is a preventive control rather than a detective or corrective one, which is why it is the correct answer.

Why this answer

Service Control Policies (SCPs) are a preventive control that can deny the ec2:CreateVolume action when the encryption condition is false. This ensures that unencrypted EBS volumes cannot be created at all, enforcing encryption at the point of creation across the entire AWS account or organizational unit.

Exam trap

The trap here is that candidates often confuse detective or corrective controls (like tagging or Lambda remediation) with preventive controls, failing to recognize that only an SCP or IAM policy with a deny effect on the CreateVolume action can proactively block the creation of unencrypted volumes.

How to eliminate wrong answers

Option A is wrong because tagging encrypted volumes after creation is a detective or corrective control, not preventive; it does not block the creation of unencrypted volumes. Option B is wrong because VPC Flow Logs capture network traffic metadata and have no effect on EBS volume creation or encryption enforcement. Option D is wrong because running a daily Lambda function to encrypt unencrypted volumes is a reactive/corrective control; it does not prevent the initial creation of unencrypted volumes, leaving a window of exposure.

720
MCQmedium

A media company stores original video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that a readable copy of every object exists in eu-west-1 within 15 minutes of upload, and that objects deleted in the source bucket do not automatically disappear from the destination. Which S3 feature should the solutions architect enable?

A.S3 Same-Region Replication into a bucket in us-east-1 with S3 Object Lock in compliance mode
B.AWS Backup with a cross-Region backup vault and a daily scheduled backup plan for the bucket
C.S3 Cross-Region Replication with S3 Replication Time Control and DeleteMarkerReplication disabled
D.S3 Transfer Acceleration on the source bucket with a lifecycle rule transitioning objects to S3 Glacier Deep Archive
AnswerC

S3 Cross-Region Replication copies objects to a bucket in another Region, and S3 Replication Time Control provides an SLA that 99.99% of objects replicate within 15 minutes. Disabling DeleteMarkerReplication prevents delete markers created in the source bucket from being replicated, so deletions in us-east-1 will not remove the copy in eu-west-1. This satisfies both the timing and the retention requirements.

Why this answer

S3 Cross-Region Replication is the AWS feature that asynchronously copies new and updated objects to a bucket in another Region. S3 Replication Time Control adds an SLA that 99.99% of objects replicate within 15 minutes, matching the compliance window. Disabling DeleteMarkerReplication keeps the destination copy intact when the source object is deleted, which is exactly the retention behaviour the compliance team requires.

Exam trap

The trap here is assuming that any replication option guarantees a 15-minute window, when only S3 Replication Time Control provides that SLA.

721
MCQmedium

A media processing company runs a stateless thumbnail-generation fleet on Amazon EC2 instances behind an Application Load Balancer. The instances store no local state, and the team wants the fleet to survive the loss of an entire Availability Zone without manual intervention. The fleet must also scale out automatically based on CPU. Which combination of AWS services should the solutions architect use to meet these requirements with the LEAST operational overhead?

A.Two independent Auto Scaling groups in separate Availability Zones, each attached to its own Application Load Balancer, with Route 53 failover routing between them.
B.A single Auto Scaling group pinned to one Availability Zone, with a Network Load Balancer in front and an Amazon Route 53 latency record.
C.An Amazon ECS cluster on AWS Fargate with tasks placed in one Availability Zone and an Application Load Balancer using sticky sessions.
D.An Auto Scaling group configured across multiple Availability Zones with a health check against the load balancer, plus an Application Load Balancer with cross-zone load balancing enabled.
AnswerD

Spreading the Auto Scaling group across multiple Availability Zones means capacity remains if one AZ fails, and the ELB health check replaces unhealthy instances automatically. Cross-zone load balancing distributes requests evenly to remaining healthy targets, so the stateless fleet keeps serving traffic without manual action and still scales on CPU.

Why this answer

Resilience against an Availability Zone failure for a stateless fleet is achieved by distributing capacity across multiple Availability Zones and letting the Auto Scaling group replace unhealthy instances using load balancer health checks. A single multi-AZ Auto Scaling group behind one Application Load Balancer with cross-zone load balancing delivers this with minimal operational effort, while still supporting CPU-based scaling.

Exam trap

The trap here is assuming a load balancer alone provides Availability Zone resilience, when the compute capacity must also be spread across multiple zones by the Auto Scaling group.

722
MCQhard

Based on the exhibit, the company has one shared S3 bucket for many internal teams. Security wants each team to access only its own prefix, ACLs must remain disabled, and the current bucket policy has become too large and error-prone. What is the best redesign?

A.Re-enable object ACLs and manage access by setting object-level ACLs for each team's prefix.
B.Split the bucket into one bucket per team and keep using a single shared bucket policy for all of them.
C.Create one S3 access point per team and attach an access point policy that limits that team to its own prefix.
D.Make the bucket public and issue presigned URLs for team access so IAM policies are no longer needed.
AnswerC

S3 access points are designed for simplifying access management to shared buckets. A separate access point per team keeps the bucket private, avoids ACLs, and lets each team have a smaller, easier-to-review policy boundary. This reduces the blast radius of a policy mistake and scales far better than a single giant bucket policy with many prefix rules.

Why this answer

S3 Access Points allow you to create separate access points for each team, each with its own policy that restricts access to a specific prefix (e.g., s3://shared-bucket/team-a/). This eliminates the need for a large, error-prone bucket policy while keeping ACLs disabled, as access is managed through IAM policies and access point policies. It also maintains a single shared bucket, simplifying management and cost allocation.

Exam trap

The trap here is that candidates may think splitting the bucket per team (Option B) is simpler, but they overlook that a single shared bucket with access points is more cost-effective and manageable, and that ACLs (Option A) are explicitly disallowed by the requirement.

How to eliminate wrong answers

Option A is wrong because re-enabling object ACLs violates the requirement that ACLs must remain disabled, and managing access at the object level is not scalable for many teams. Option B is wrong because splitting into one bucket per team increases management overhead and does not solve the bucket policy size issue; a single shared bucket policy for all buckets would still be complex and error-prone. Option D is wrong because making the bucket public exposes data to the internet, violating security best practices, and presigned URLs are temporary and not suitable for ongoing team access management.

723
MCQmedium

A trading dashboard uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The design must avoid adding custom operational scripts.

A.A single-AZ Aurora cluster
B.Aurora Global Database
C.Manual snapshots copied monthly
D.An ElastiCache Redis replica
AnswerB

Aurora Global Database is a feature specifically designed for cross-region disaster recovery and low-latency global reads. It replicates data from a primary Region to up to five secondary Regions with typical latency of under a second, using dedicated storage-based replication rather than binlog-based replication. In a regional failure, you can promote one of the secondary regions to become the new primary in as little as one minute, which gives a low RTO, while snapshot-based approaches would take much longer.

Why this answer

Aurora Global Database is the correct choice because it provides a fully managed cross-Region disaster recovery solution with a typical RPO of 1 second or less, using storage-based replication that does not require custom scripts. This meets the low RPO requirement while avoiding operational overhead, as replication is handled automatically by the Aurora storage layer.

Exam trap

The trap here is that candidates may confuse cross-Region read replicas (which require manual promotion and scripting) with Aurora Global Database, which provides automated, low-latency replication without custom operational scripts.

How to eliminate wrong answers

Option A is wrong because a single-AZ Aurora cluster lacks any cross-Region replication or failover capability, offering no disaster recovery across Regions. Option C is wrong because manual snapshots copied monthly result in an RPO of up to one month, which is far too high for a trading dashboard requiring low RPO. Option D is wrong because an ElastiCache Redis replica is an in-memory cache, not a database with persistent cross-Region replication, and it does not provide the required disaster recovery for Aurora MySQL data.

724
MCQmedium

A internal reporting portal serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The design must avoid adding custom operational scripts.

A.Instance store volumes
B.S3 Glacier Deep Archive
C.S3 Standard for all objects
D.S3 Standard-IA or S3 One Zone-IA depending on resilience requirements
AnswerD

S3 Standard-IA is the correct default because it retains S3's 11 nines of durability and millisecond retrieval while reducing storage cost for infrequently accessed data. S3 One Zone-IA lowers the cost further by storing the data in a single Availability Zone, which trades away resilience against an AZ failure; this is acceptable if the documents are easily reproducible or stored elsewhere. The choice between them depends on resilience requirements: choose Standard-IA if the documents must survive a data center loss, or One Zone-IA if cost reduction is more important than that resilience, making this combined answer technically precise.

Why this answer

S3 Standard-IA or S3 One Zone-IA is the best cost fit because the data is infrequently accessed but requires immediate availability when requested. These storage classes offer lower storage costs than S3 Standard while providing low-latency retrieval (milliseconds), avoiding the retrieval delays or operational overhead of archival tiers. The choice between Standard-IA and One Zone-IA depends on resilience needs: Standard-IA stores data across multiple AZs, while One Zone-IA stores data in a single AZ at a lower cost.

Exam trap

The trap here is that candidates often choose S3 Glacier Deep Archive for infrequently accessed data without considering the immediate availability requirement, or they default to S3 Standard assuming all infrequent access needs archival storage, missing the cost-optimized middle ground of Standard-IA or One Zone-IA.

How to eliminate wrong answers

Option A is wrong because instance store volumes are ephemeral block storage attached to EC2 instances, not a durable S3 storage class, and they lose data when the instance stops or terminates, making them unsuitable for long-term document storage. Option B is wrong because S3 Glacier Deep Archive has retrieval times of 12-48 hours, which violates the requirement that documents must be available immediately when requested. Option C is wrong because S3 Standard is designed for frequently accessed data and would incur higher storage costs than necessary for infrequently accessed documents, making it not the best cost fit.

725
MCQmedium

An e-commerce application uses Aurora MySQL. Writes are modest, but the product-detail page generates many read-only queries and the writer instance CPU is high. The application can tolerate a small amount of replication lag on those reads. What should the team do?

A.Add Aurora read replicas and send read-only traffic to the reader endpoint.
B.Increase the writer instance size and keep all traffic on the primary.
C.Replace Aurora with DynamoDB to eliminate replication lag.
D.Enable Multi-AZ failover only, because it increases read throughput automatically.
AnswerA

Aurora read replicas are the right way to scale read-heavy workloads and reduce pressure on the writer instance. By directing read-only traffic to the reader endpoint, the application can offload product-page queries while keeping writes on the primary instance. Because a small amount of replication lag is acceptable, this approach aligns well with the workload's consistency and performance needs.

Why this answer

Adding Aurora read replicas and directing read-only traffic to the reader endpoint offloads SELECT queries from the writer instance, reducing its CPU load. Aurora replicas share the same underlying storage volume, so replication lag is minimal (typically <100ms) and acceptable for the product-detail page. This scales read throughput without increasing writer instance size or cost.

Exam trap

The trap here is confusing Multi-AZ (which only provides failover) with read replicas (which offload reads), leading candidates to pick Option D thinking it improves read performance.

Why the other options are wrong

B

Increasing the writer instance size does not offload read traffic from the primary node, so CPU remains high from read queries. The question explicitly allows replication lag, making read replicas a more cost-effective and scalable solution.

C

DynamoDB is a NoSQL database that does not support the same relational query patterns as Aurora MySQL, and the application would require significant refactoring. Additionally, DynamoDB does not inherently eliminate replication lag; it uses eventually consistent reads by default, which can have lag.

D

Multi-AZ failover provides high availability but does not increase read throughput; the standby replica cannot serve reads, so it does not offload the writer instance's CPU.

When would these options actually be correct?

B

If the application cannot tolerate any replication lag and all queries must be strongly consistent, or if the read workload is already low and the bottleneck is write performance, then increasing the writer instance size would be correct.

C

A question where the application requires a fully managed NoSQL database with single-digit millisecond latency at any scale, and the data model is key-value or document-based, with no need for complex joins or transactions. For example: 'A gaming leaderboard needs to store player scores and retrieve top players with low latency; the data is simple and does not require relational queries.'

D

A question where the primary concern is database availability during an AZ outage, and read scaling is not required. For example: 'An application needs automatic failover to a standby instance in another AZ with zero data loss. What should be enabled?'

Why candidates pick the wrong answer

B

Candidates may think that a larger instance handles more throughput overall, overlooking that read replicas can distribute read load without scaling the writer.

C

Candidates may think DynamoDB is always faster and has no replication lag, overlooking the fact that it uses eventually consistent reads and requires application changes to adapt to a different data model.

D

Candidates may confuse Multi-AZ with read replicas, thinking the standby can handle read traffic, or assume that failover automatically improves performance.

726
MCQmedium

A company hosts a B2B file exchange site on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use? The design must avoid adding custom operational scripts.

A.A bastion host with SSH open to 0.0.0.0/0
B.AWS Systems Manager Session Manager with the required instance role
C.A public Elastic IP address on each instance
D.An internet gateway attached to the private subnet
AnswerB

Session Manager brokers shell access through the Systems Manager agent and instance role, so no inbound SSH or RDP ports are exposed to the internet. It provides audited sessions without custom operational scripts, satisfying both the security and no-scripting constraints.

Why this answer

AWS Systems Manager Session Manager allows administrators to establish secure shell access to EC2 instances without opening inbound SSH or RDP ports, using the Systems Manager agent and an IAM instance role. This meets the requirement for no internet-exposed ports and avoids custom operational scripts because Session Manager is a fully managed AWS service.

Exam trap

The trap here is that candidates often assume a bastion host is the only secure way to access private instances, but AWS Systems Manager Session Manager provides a fully managed, agent-based alternative that avoids opening any inbound ports and requires no custom scripts.

How to eliminate wrong answers

Option A is wrong because a bastion host with SSH open to 0.0.0.0/0 exposes a management port to the entire internet, violating the requirement to avoid opening SSH or RDP ports to the internet. Option C is wrong because assigning a public Elastic IP address to each instance directly exposes them to the internet, requiring open SSH or RDP ports for administrative access. Option D is wrong because an internet gateway attached to a private subnet does not provide administrative access; it only enables outbound internet connectivity for instances in that subnet, and administrators still need a way to connect without open ports.

727
MCQmedium

A company hosts a B2B file exchange site on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

A.A bastion host with SSH open to 0.0.0.0/0
B.AWS Systems Manager Session Manager with the required instance role
C.A public Elastic IP address on each instance
D.An internet gateway attached to the private subnet
AnswerB

AWS Systems Manager Session Manager is correct because it provides secure, audited shell access to the instances without requiring any inbound SSH/RDP ports or an internet-facing management interface. The EC2 instance must have the SSM Agent installed and an IAM instance role with AmazonSSMManagedInstanceCore, and a VPC endpoint or standard internet route for the agent to communicate with the AWS control plane. Each session is logged to AWS CloudTrail and can be streamed to S3 or CloudWatch, giving administrators full auditability.

Why this answer

AWS Systems Manager Session Manager allows secure shell access to EC2 instances without opening inbound ports (SSH 22 or RDP 3389) to the internet. It uses the AWS Systems Manager agent and an IAM instance role to establish a bidirectional connection via the AWS cloud, eliminating the need for a bastion host or public IP. This meets the requirement for administrators to connect without exposing any network ports.

Exam trap

The trap here is that candidates often default to a bastion host (Option A) as the traditional solution, overlooking that AWS Systems Manager Session Manager provides a more secure, port-free alternative that fully meets the 'no open ports' requirement.

How to eliminate wrong answers

Option A is wrong because a bastion host with SSH open to 0.0.0.0/0 exposes the instance to the entire internet, violating the requirement to avoid opening SSH or RDP ports. Option C is wrong because assigning a public Elastic IP address to each instance would require opening SSH or RDP ports to the internet for direct access, which is explicitly prohibited. Option D is wrong because an internet gateway attached to a private subnet does not provide administrative connectivity; it only enables outbound internet access for instances, and inbound administrative access would still require open ports or a bastion host.

728
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be highly available and able to withstand the failure of an entire AWS Region. The company wants to minimize operational overhead and ensure that failover is automatic. Which solution should a solutions architect recommend?

A.Deploy the application in two AWS Regions. Use Amazon Route 53 with a weighted routing policy and equal weights for both Regions.
B.Deploy the application in two Availability Zones within a single Region. Use an Application Load Balancer to distribute traffic across both AZs.
C.Deploy the application in two AWS Regions. Use Amazon Route 53 with a failover routing policy and health checks to route traffic to the secondary Region if the primary becomes unhealthy.
D.Deploy the application in a single Region using AWS Global Accelerator to route traffic to the nearest edge location.
AnswerC

A multi-Region active-passive setup with Route 53 failover routing and health checks provides automatic failover at the DNS level. The secondary Region must have the same application stack and data replication. This meets the requirements for Region-level resilience and minimal operational overhead because failover is automatic.

Why this answer

To withstand a Region failure with automatic failover, the application must be deployed in at least two Regions. Route 53 failover routing with health checks automatically redirects traffic to the secondary Region when the primary is unhealthy. This minimizes operational overhead because the failover is managed by Route 53 and does not require manual intervention.

Exam trap

The trap here is confusing weighted routing with failover routing. Weighted routing distributes traffic based on weights but does not automatically remove an unhealthy Region unless health checks are explicitly configured to do so, and even then, it may not fully redirect all traffic.

729
MCQmedium

A order processing API stores audit logs in S3. The compliance team requires that logs cannot be overwritten or deleted for seven years. What should be configured? The design must avoid adding custom operational scripts.

A.S3 server access logging
B.S3 lifecycle expiration after seven years
C.S3 versioning only
D.S3 Object Lock in compliance mode with an appropriate retention period
AnswerD

S3 Object Lock in compliance mode provides robust Write Once, Read Many (WORM) protection, making objects immutable for a specified retention period. Once an object is locked in compliance mode, it cannot be overwritten or deleted by any user, including the root account, until the retention period expires. This ensures the highest level of data integrity and immutability, which is essential for audit logs subject to stringent regulatory compliance requirements.

Why this answer

S3 Object Lock in compliance mode prevents any user, including the root user, from overwriting or deleting objects for the specified retention period. This meets the compliance requirement of a seven-year immutable audit log without custom scripts. Compliance mode enforces a legal hold that cannot be removed by any user, ensuring logs remain intact.

Exam trap

The trap here is that candidates often confuse versioning with immutability, thinking versioning alone prevents deletion, but it only preserves overwritten versions while still allowing the current version to be deleted unless combined with Object Lock or MFA Delete.

How to eliminate wrong answers

Option A is wrong because S3 server access logging only records requests made to the bucket, it does not prevent deletion or overwriting of existing logs. Option B is wrong because S3 lifecycle expiration automatically deletes objects after a period, which directly violates the requirement that logs cannot be deleted for seven years. Option C is wrong because S3 versioning alone preserves previous versions of objects but does not prevent deletion of the current version or overwriting; it requires additional controls like MFA Delete or Object Lock to enforce immutability.

730
MCQhard

A dev sandbox currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first? The design must avoid adding custom operational scripts.

A.Disabling route tables
B.Replacing every NAT gateway with an internet gateway attached to private subnets
C.Moving all workloads to public subnets
D.Whether one NAT gateway per AZ is sufficient for the required private subnets
AnswerD

Consolidating to one NAT gateway per AZ still provides outbound access for each AZ's private subnet while removing three redundant gateways. This satisfies the stem's constraint of avoiding custom operational scripts, since NAT gateway placement is a native configuration change rather than scripted failover logic.

Why this answer

The question asks what the architect should review first to optimize costs while maintaining functionality. Using two NAT gateways per AZ when only one private subnet per AZ needs outbound internet access is redundant; a single NAT gateway per AZ can handle the traffic for all private subnets in that AZ. The design must avoid custom operational scripts, so the simplest review is to check if one NAT gateway per AZ is sufficient, which would reduce costs without breaking connectivity.

Exam trap

The trap here is that candidates may assume more NAT gateways are always better for high availability, but the question asks for a cost-optimization review first, and the current setup is over-provisioned for the stated requirement.

How to eliminate wrong answers

Option A is wrong because disabling route tables would break all routing, not just optimize NAT gateway usage, and it would require custom scripts to restore functionality, violating the design constraint. Option B is wrong because internet gateways cannot be attached to private subnets; they are used for public subnets and would expose instances directly to the internet, breaking the private subnet isolation requirement. Option C is wrong because moving all workloads to public subnets would expose them to the internet, which is not suitable for a dev sandbox that likely requires private subnets for security, and it does not address the NAT gateway cost issue.

731
Multi-Selectmedium

A startup runs two EC2-based workloads in the same AWS Region. Its customer-facing API is always on, and its nightly video transcoding fleet can restart jobs from checkpoints if an instance is interrupted. The finance team wants the lowest monthly compute cost without changing the application design. Which two actions should the team take? Select two.

Select 2 answers
A.Purchase an All Upfront Reserved Instance for the transcoding fleet only.
B.Buy a Compute Savings Plan to cover the always-on API baseline usage.
C.Run the transcoding fleet on Spot Instances because interrupted jobs can resume from checkpoints.
D.Increase the API instance size so CPU utilization stays below 30 percent.
E.Move the API tier to Dedicated Hosts to improve isolation and lower spend.
AnswersB, C

A Compute Savings Plan applies discounted rates to eligible EC2 usage across instance families, sizes, tenancy and Regions, so it covers the API's steady always-on baseline without locking the fleet to a specific instance type. That satisfies the finance team's lowest-cost requirement while preserving the existing application design.

Why this answer

A Compute Savings Plan offers the lowest cost for steady-state workloads like the always-on API, providing up to 66% savings over On-Demand in exchange for a 1- or 3-year commitment. It applies to any EC2 instance family within a Region, making it flexible and cost-effective for the baseline usage. Option C is correct because Spot Instances can be up to 90% cheaper than On-Demand and are ideal for fault-tolerant workloads like the transcoding fleet, which can resume from checkpoints if interrupted.

Exam trap

The trap here is that candidates often assume Reserved Instances are always the cheapest option, but for interruptible workloads like transcoding, Spot Instances provide far greater savings, and a Savings Plan better covers the steady-state API usage without locking into a specific instance family.

Why the other options are wrong

A

The transcoding fleet can handle interruptions, so Spot Instances are cheaper than Reserved Instances. Purchasing All Upfront Reserved Instances for the transcoding fleet would lock in higher costs unnecessarily.

D

Increasing instance size to keep CPU below 30% wastes compute capacity and increases cost, contradicting the goal of lowest monthly compute cost. The question explicitly states not to change application design, and this action changes the instance type.

E

Dedicated Hosts increase cost due to per-host billing and do not lower spend; they are used for licensing or compliance, not cost savings. The question asks for lowest compute cost, so this option is counterproductive.

When would these options actually be correct?

A

If the question specified that both workloads must run continuously without interruption and the transcoding fleet cannot tolerate any interruptions, then purchasing All Upfront Reserved Instances for the transcoding fleet would provide the lowest cost for steady-state usage.

D

In a scenario where the application is latency-sensitive and requires consistent low CPU utilization to handle sudden spikes, and cost is not the primary concern, increasing instance size could be correct to ensure performance.

E

A question where the company has a per-socket or per-core software license (e.g., Windows Server, SQL Server) that requires dedicated physical servers to remain compliant. In that case, Dedicated Hosts can reduce licensing costs despite higher infrastructure spend.

Why candidates pick the wrong answer

A

Candidates may think Reserved Instances always provide the lowest cost, overlooking that Spot Instances are even cheaper for fault-tolerant workloads.

D

Candidates may think that larger instances are more cost-effective per unit of compute, or that keeping CPU low improves reliability, but this overlooks that the startup's goal is to minimize total cost, not optimize utilization.

E

Candidates may think 'dedicated' implies better performance or security at lower cost, but Dedicated Hosts are actually more expensive and are chosen for licensing or regulatory reasons, not cost optimization.

732
MCQmedium

A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The team wants the control to be enforceable during normal operations.

A.Amazon Kinesis Data Firehose
B.S3 Transfer Acceleration
C.DynamoDB Accelerator (DAX)
D.AWS Glue Data Catalog
AnswerC

DAX provides an in-memory write-through cache in front of DynamoDB, serving repeated catalogue reads in microseconds and cutting table load. It is natively enforceable during normal operations, satisfying the stem's requirement without custom caching code or application changes.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache specifically designed for DynamoDB that can reduce read latency from single-digit milliseconds to microseconds, while offloading read traffic from the underlying table. This directly addresses the read-heavy workload and millisecond latency requirements, and the team can enforce its use during normal operations by configuring the application to route reads through the DAX cluster endpoint.

Exam trap

The trap here is that candidates may confuse DAX with ElastiCache (which is a general-purpose cache but not DynamoDB-native) or assume that S3 Transfer Acceleration can improve DynamoDB read performance, when in fact DAX is the only AWS service purpose-built to cache DynamoDB reads with sub-millisecond latency.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis Data Firehose is a streaming data ingestion service for loading data into data lakes and analytics tools, not a caching layer for DynamoDB reads. Option B is wrong because S3 Transfer Acceleration speeds up uploads to S3 over long distances using AWS edge locations, but it does not cache DynamoDB query results or reduce table load. Option D is wrong because AWS Glue Data Catalog is a metadata repository for ETL jobs and data lake schemas, not a read cache for DynamoDB.

733
MCQmedium

A marketing site runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost? The architecture review board prefers a managed AWS-native control.

A.Cross-Region data replication for all data
B.io2 Block Express volumes for all instances
C.AWS Graviton-based instances after performance testing
D.Dedicated Hosts by default
AnswerC

AWS Graviton instances run on custom Arm-based processors and, for many workloads, deliver up to 40% better price performance than comparable x86 instances, especially for web servers running open-source software that is already compiled for ARM. The recommended approach is to performance-test the application on Graviton first—because it's a different architecture and some native libraries must be recompiled—then use instance types like m7g or t4g for production, which can cut compute cost without sacrificing throughput.

Why this answer

AWS Graviton-based instances use ARM-based custom processors that offer up to 40% better price-performance compared to comparable x86 instances for many workloads. Since the marketing site runs open-source software with no architecture-specific licensing restrictions, migrating to Graviton after performance testing can significantly reduce compute costs while leveraging a managed AWS-native control (e.g., EC2 Auto Scaling groups with Graviton instance types).

Exam trap

The trap here is that candidates may assume Dedicated Hosts (Option D) are cost-effective for all workloads, but they actually increase costs due to per-host billing and are only justified for specific licensing or compliance needs, not general compute cost reduction.

How to eliminate wrong answers

Option A is wrong because cross-Region data replication increases data transfer and storage costs, and it does not directly reduce compute costs; it is a data durability and disaster recovery feature, not a compute optimization. Option B is wrong because io2 Block Express volumes are high-performance EBS volumes designed for latency-sensitive workloads, not for reducing compute costs; they increase storage costs and do not address compute instance pricing. Option D is wrong because Dedicated Hosts incur additional hourly charges for physical server isolation and are typically used for licensing or compliance requirements, not for cost reduction; they increase costs compared to shared tenancy instances.

734
MCQhard

A financial services firm runs a stateful trading application on EC2 instances in an Auto Scaling group. Each instance maintains an in-memory cache that takes several minutes to rebuild after a restart, and the team wants the application to survive the loss of an Availability Zone with minimal disruption. The application cannot be made stateless in the near term. Which approach should a solutions architect recommend?

A.Move the in-memory cache to an Amazon ElastiCache for Redis cluster with Multi-AZ enabled and keep the Auto Scaling group in one Availability Zone.
B.Create a second Auto Scaling group in another Availability Zone and use Amazon Route 53 failover routing with health checks to switch traffic when the primary zone fails.
C.Enable EC2 Auto Recovery on all instances and configure the Auto Scaling group to use a single Availability Zone with a larger instance type.
D.Configure the Auto Scaling group to span three Availability Zones with a capacity that leaves headroom in each zone, and enable instance warm-up and health check grace periods so that replacement instances are fully initialized before receiving traffic.
AnswerD

Spreading capacity across three zones means the loss of one zone leaves two zones with running, already-warmed instances that can absorb the load immediately. Instance warm-up and health check grace periods prevent the Auto Scaling group from treating a still-initializing instance as unhealthy, which matters because the in-memory cache takes several minutes to rebuild and premature termination would cause a restart loop.

Why this answer

For a stateful application that cannot be re-architected immediately, the practical resilience pattern is to run warmed instances in more than two Availability Zones so that a single zone loss leaves sufficient capacity already serving traffic. Warm-up and grace period settings are essential because they stop the Auto Scaling group from killing instances that are still rebuilding their in-memory caches, which would otherwise produce repeated restarts and prolonged unavailability.

Exam trap

The trap here is assuming that Auto Recovery or DNS failover replaces the need for live, warmed capacity in multiple Availability Zones for a stateful workload.

735
MCQmedium

A finance application stores invoices in Amazon S3. Security requires that the data be encrypted with a key they control, and they want the ability to disable access quickly if the application is suspected of compromise. Developers do not want to manage encryption in application code. Which solution best meets these requirements?

A.Use SSE-S3 with the default Amazon-managed key for all uploads.
B.Use SSE-KMS with a customer-managed AWS KMS key.
C.Encrypt objects on the client side and store the encryption key in the same S3 bucket.
D.Use Amazon S3 replication to a second bucket in another region.
AnswerB

SSE-KMS with a customer-managed KMS key gives the security team explicit control over key policy, grants, auditing, and revocation. The application can upload objects normally while S3 handles encryption and decryption on the service side, so developers do not need custom cryptography code. If compromise is suspected, the key or grants can be disabled to block future access, which is exactly why a customer-managed key is preferable here.

Why this answer

SSE-KMS with a customer-managed AWS KMS key meets the requirements because it allows the finance application to encrypt data at rest using a key that the customer controls, and it provides the ability to quickly disable access by revoking or disabling the KMS key, which immediately blocks any decryption attempts. The developers do not need to manage encryption in application code because encryption is handled server-side by S3 using the KMS key.

Exam trap

The trap here is that candidates often confuse SSE-S3 with customer-managed keys or think S3 replication provides security controls, but the key distinction is that only SSE-KMS with a customer-managed key gives you both customer-controlled keys and the ability to quickly revoke access without changing application code.

Why the other options are wrong

A

SSE-S3 uses an AWS-managed key, not a customer-controlled key, so it fails the requirement that the customer controls the encryption key.

C

Client-side encryption requires managing encryption in application code, which contradicts the requirement that developers do not want to manage encryption in the application. Additionally, storing the encryption key in the same S3 bucket is insecure and violates the principle of separating keys from data.

D

S3 replication does not provide encryption with a customer-controlled key or the ability to quickly disable access; it only copies objects to another bucket, which may still use the same encryption settings.

When would these options actually be correct?

A

A question that requires server-side encryption with minimal management overhead and no need for customer key control or quick key disabling, e.g., 'A company wants to encrypt all S3 objects by default with no additional cost or key management burden.'

C

This option would be correct if the requirement was that data must be encrypted before it reaches AWS (e.g., for compliance with data sovereignty laws) and the application team is willing to manage encryption logic, but they want to store the key separately (e.g., in AWS Secrets Manager or a different bucket with strict access controls).

D

A question requiring cross-region disaster recovery or compliance with data residency requirements, where the goal is to automatically replicate objects to a bucket in another region for redundancy, without specific encryption control or access revocation needs.

Why candidates pick the wrong answer

A

Candidates may think SSE-S3 provides encryption and is simple to implement, overlooking the specific requirement for customer-controlled keys and the ability to quickly disable access.

C

Candidates may think client-side encryption gives them full control over the key and avoids AWS-managed services, but they overlook the explicit requirement to avoid managing encryption in application code and the security risk of storing keys with data.

D

Candidates may think replication adds a layer of security or control, but it does not address encryption key management or rapid access revocation as required.

736
MCQeasy

An EC2 workload runs in one region on a single instance type. For the last month, CloudWatch metrics show average CPU utilization of 12% and no sustained memory pressure. The team wants to reduce cost while maintaining the current performance level. What is the best first step?

A.Use AWS Compute Optimizer to get recommendations for instance type and size changes.
B.Increase the instance size to reduce the risk of performance regression.
C.Switch to Spot Instances immediately to reduce cost regardless of utilization.
D.Disable detailed monitoring to lower CloudWatch charges.
AnswerA

AWS Compute Optimizer analyzes historical metrics (such as CPU and memory utilization) and recommends instance type and size changes to improve cost-effectiveness while targeting performance. Given sustained low CPU and no sustained memory pressure, this is the most direct first step to identify a smaller/fewer-overprovisioned instance configuration that can maintain performance.

Why this answer

AWS Compute Optimizer analyzes historical utilization metrics (CPU, memory, I/O) and provides actionable recommendations for right-sizing instances. Given the average CPU utilization of only 12% and no memory pressure, Compute Optimizer will likely recommend a smaller instance type or family that matches the workload's actual resource needs, reducing cost without affecting performance.

Exam trap

The trap here is that candidates may think increasing instance size (Option B) is a safe 'performance buffer' move, but the question explicitly asks to reduce cost while maintaining current performance, making right-sizing via Compute Optimizer the logical first step.

How to eliminate wrong answers

Option B is wrong because increasing instance size would raise costs unnecessarily when utilization is already low, and it does not address the goal of cost reduction. Option C is wrong because switching to Spot Instances without first analyzing workload suitability risks interruption and potential performance degradation; Spot Instances are not a guaranteed cost-reduction strategy for all workloads. Option D is wrong because disabling detailed monitoring (1-minute metrics) saves only a trivial amount and does not address the primary cost driver—compute instance charges—while losing granular visibility needed for right-sizing decisions.

737
MCQmedium

A security operations team wants continuous compliance checks for AWS resources. They need to know when an EBS volume becomes unencrypted or when a security group starts allowing SSH from 0.0.0.0/0. Which AWS service should they use?

A.AWS CloudTrail, because it records every API call made in the account.
B.AWS Config, because it evaluates resource configuration against compliance rules.
C.Amazon GuardDuty, because it automatically encrypts noncompliant resources.
D.Amazon Macie, because it manages encryption settings for all AWS resources.
AnswerB

AWS Config is the right service for continuous resource compliance monitoring. It tracks configuration changes over time and can evaluate rules that check for conditions such as encrypted EBS volumes or overly permissive security groups. This makes it ideal for governance and drift detection, especially when the team needs to know the current state of resources rather than only the history of API calls.

Why this answer

AWS Config is the correct service because it continuously monitors and evaluates the configuration of AWS resources against desired compliance rules. It can detect when an EBS volume is unencrypted or when a security group rule allows SSH (port 22) from 0.0.0.0/0, and trigger notifications or remediation actions via AWS Config rules.

Exam trap

The trap here is that candidates confuse AWS CloudTrail's API logging with AWS Config's configuration evaluation, assuming that recording API calls is sufficient for compliance checks, but CloudTrail does not assess the current state of resources against rules.

Why the other options are wrong

A

CloudTrail records API calls but does not perform continuous compliance checks or evaluate resource configurations against rules; it lacks the ability to detect unencrypted EBS volumes or security group misconfigurations in real time.

C

Amazon GuardDuty is a threat detection service that monitors for malicious activity, not a compliance service that checks resource configurations like EBS encryption or security group rules.

D

Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data, not to manage encryption settings or perform compliance checks on resource configurations like EBS encryption or security group rules.

When would these options actually be correct?

A

CloudTrail would be correct if the question asked for auditing all API calls made in the account, such as tracking who created or modified resources, or for detecting unauthorized API activity.

C

If the question asked for a service that automatically detects and alerts on suspicious API calls or network traffic patterns (e.g., compromised EC2 instances or unusual data exfiltration), GuardDuty would be the correct answer.

D

A scenario where Macie would be correct: 'A company needs to automatically discover and protect sensitive data such as PII or financial records stored in S3 buckets, and receive alerts when such data is exposed.'

Why candidates pick the wrong answer

A

Candidates may confuse logging API calls with monitoring resource configurations, assuming that recording changes is sufficient for compliance checks.

C

Candidates may confuse GuardDuty's security monitoring with compliance checking, or mistakenly think it can enforce encryption policies because of its 'security' label.

D

Candidates may confuse Macie's focus on data protection with compliance monitoring, or mistakenly think it handles encryption settings due to its 'security' branding.

738
MCQeasy

A startup runs a static website hosted on Amazon S3. The website is accessed globally, and users in Europe report slow load times. The company wants to improve performance for these users without changing the website's code. Which AWS service should the company use?

A.Amazon CloudFront with an S3 origin.
B.AWS Global Accelerator with an S3 endpoint.
C.AWS Direct Connect.
D.Amazon S3 Transfer Acceleration.
AnswerA

CloudFront is a content delivery network that caches content at edge locations worldwide. By distributing the S3-hosted static website through CloudFront, users in Europe are served from nearby edge locations, reducing latency and improving load times. This requires no code changes, only a CloudFront distribution pointing to the S3 bucket.

Why this answer

CloudFront caches static content at edge locations worldwide, bringing it closer to users. For a static website on S3, creating a CloudFront distribution with the S3 bucket as the origin is the standard solution to reduce latency for global users. It requires no changes to the website code, only configuration of the distribution and updating DNS to point to CloudFront.

Exam trap

The trap here is confusing S3 Transfer Acceleration with CloudFront; Transfer Acceleration speeds up uploads to S3, not downloads for website users.

739
MCQhard

A healthcare company runs a patient portal on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in memory on each instance, and users are being logged out when the load balancer routes them to a different instance. The company wants to keep the application stateless and avoid modifying application code. Which solution best meets these requirements?

A.Configure the Auto Scaling group to use a warm pool so that new instances inherit the session state from existing instances.
B.Store session data in an Amazon ElastiCache for Redis cluster and have the instances read and write sessions there.
C.Enable sticky sessions on the Application Load Balancer using duration-based cookie stickiness.
D.Enable cross-zone load balancing on the Application Load Balancer to ensure sessions are distributed evenly.
AnswerB

Externalizing session state to ElastiCache for Redis removes session data from individual instances, making the application stateless. Any instance can serve any user because session data is shared and highly available. This meets the requirement without modifying application logic beyond the session store configuration, and it scales with the fleet.

Why this answer

To keep an application stateless, session data must live outside the compute instances. ElastiCache for Redis provides a shared, low-latency session store that any instance can access, so users remain logged in regardless of which instance handles the request. Sticky sessions, warm pools, and cross-zone load balancing either mask the problem or address unrelated concerns without removing instance-local state.

Exam trap

The trap here is treating sticky sessions as a way to make an application stateless, when stickiness actually preserves state on a specific instance.

740
Multi-Selectmedium

A workload runs in private subnets and must reach Amazon S3 and AWS Secrets Manager without using the internet or a NAT gateway. The team wants to keep the traffic on AWS private networking and avoid public IPs. Which two changes should the architect make? Select two.

Select 2 answers
A.Create an S3 gateway VPC endpoint and update the route tables for the private subnets.
B.Place a NAT gateway in the public subnet so the private instances can reach AWS services.
C.Create an interface VPC endpoint for AWS Secrets Manager and allow the workload security group to reach it.
D.Assign public IPv4 addresses to the instances and restrict them with security groups.
E.Use VPC peering to the AWS service endpoints instead of VPC endpoints.
AnswersA, C

An S3 gateway endpoint attaches to the private subnet route tables, directing S3 traffic through AWS's private network instead of the internet or NAT gateway. This satisfies the constraint of reaching S3 without public IPs, and gateway endpoints cost nothing per hour.

Why this answer

Option A is correct because an S3 gateway VPC endpoint provides private access to Amazon S3 by adding a prefix-list route to the private subnet route tables, so traffic to S3 stays on the AWS network without internet or NAT. Option C is correct because AWS Secrets Manager is accessed through an interface VPC endpoint (AWS PrivateLink), which creates an elastic network interface in the subnet and requires the workload's security group to allow outbound/inbound access to that endpoint on port 443. Option B is wrong because a NAT gateway still routes traffic through the internet and requires a public subnet, which the scenario explicitly excludes.

Option D is wrong because assigning public IPv4 addresses exposes the instances to the internet and does not provide private AWS service access. Option E is wrong because VPC peering connects VPCs, not AWS service endpoints, and cannot be used to reach S3 or Secrets Manager privately.

Exam trap

The trap here is that candidates often confuse gateway endpoints (for S3 and DynamoDB) with interface endpoints (for most other services) and may incorrectly assume a NAT gateway is needed for all AWS service access, ignoring that gateway endpoints provide a free, internet-free alternative for S3.

741
MCQhard

A company runs an Amazon DynamoDB table that stores session data for a consumer application. The table is 800 GB and receives highly variable read and write traffic with sharp, unpredictable peaks during marketing campaigns. The team currently provisions 20,000 read capacity units and 10,000 write capacity units and frequently sees throttling during peaks and wasted capacity between them. A solutions architect must reduce cost and eliminate throttling with the least operational effort. Which solution meets these requirements?

A.Increase provisioned capacity to 60,000 read capacity units and 30,000 write capacity units and enable auto scaling.
B.Add a DynamoDB Accelerator (DAX) cluster in front of the table and keep the current provisioned capacity.
C.Enable DynamoDB auto scaling with a target utilization of 70% for both read and write capacity.
D.Switch the table to on-demand capacity mode.
AnswerD

On-demand mode instantly accommodates whatever traffic arrives, so unpredictable campaign peaks no longer cause throttling, and you pay only for the read and write request units actually consumed. There is no capacity planning or scaling configuration to manage, which satisfies the least-operational-effort requirement while removing charges for idle provisioned capacity between peaks.

Why this answer

The traffic pattern is spiky and unpredictable, which is exactly where provisioned capacity with reactive auto scaling falls short and where on-demand mode excels. On-demand billing charges per request unit consumed, scales instantly to any traffic level, and removes the need to tune capacity, so it both eliminates throttling and avoids paying for idle provisioned throughput between campaigns.

Exam trap

The trap here is treating auto scaling as equivalent to on-demand capacity; auto scaling is reactive and metric-driven, so it can lag behind sudden spikes and still leave a provisioned baseline that is billed around the clock.

742
MCQmedium

An application uses an Amazon Aurora DB cluster. The cluster performs an automatic failover from the writer instance to a standby instance. After failover completes, reads succeed, but all new writes fail with errors indicating the application is connecting to the old writer endpoint. Which change best fixes the resiliency issue after failover?

A.Update the application to use the Aurora cluster writer endpoint (or the cluster endpoint intended for writes) rather than an instance-specific endpoint.
B.Enable Multi-AZ on the individual writer instance settings so it can automatically create a new instance during failover.
C.Increase the failover timeout for Aurora to 60 minutes to ensure the app finishes reconnecting.
D.Switch the cluster to a single-AZ configuration to reduce connection retries after failover.
AnswerA

During Aurora failover, the writer role moves to a different underlying DB instance. The cluster writer endpoint is stable and always resolves to the current writer, even after failover. An instance-specific endpoint continues to point to the original (now non-writer) instance, so write operations fail if the application keeps using that stale endpoint.

Why this answer

The application is failing writes because it is connecting to the old writer instance's endpoint, which is no longer the writer after failover. The Aurora cluster writer endpoint is a DNS name that always points to the current primary (writer) instance, regardless of failovers. By using the cluster writer endpoint, the application automatically connects to the new writer after failover, eliminating the need to manually update connection strings.

Exam trap

The trap here is that candidates often confuse instance-specific endpoints with cluster endpoints, assuming that failover automatically updates all DNS records, but only the cluster endpoint is dynamically updated to reflect the new writer.

How to eliminate wrong answers

Option B is wrong because Multi-AZ is already inherent in Aurora clusters (by default, Aurora stores data across three Availability Zones) and enabling it on an individual instance does not change the failover behavior or fix the endpoint issue. Option C is wrong because increasing the failover timeout to 60 minutes does not address the root cause; the application will still connect to the old writer endpoint and fail writes indefinitely. Option D is wrong because switching to a single-AZ configuration would actually reduce resiliency and increase the risk of data loss, and it does not solve the problem of the application using the wrong endpoint.

743
MCQmedium

A media platform stores originals in an S3 bucket. The application must: (1) prevent any public access to the bucket, (2) allow authenticated users to upload and download objects using presigned URLs, and (3) enforce that all requests use HTTPS and only touch objects under the user-specific prefix (for example, s3://media-originals/user-123/*). The bucket currently allows uploads but sometimes returns 403 AccessDenied for presigned URLs. Which change is the best fix while meeting the security requirements?

A.Disable S3 Block Public Access and add an ACL that grants READ and WRITE to the bucket owner only.
B.Keep Block Public Access enabled, remove any Allow statement to Principal="*", and use a bucket policy or access point policy that denies non-HTTPS requests and allows PutObject/GetObject only when the object key matches the authenticated user's session tag, such as arn:aws:s3:::media-originals/${aws:PrincipalTag/userId}/*.
C.Use bucket website hosting and allow public GET requests so presigned URLs are not needed for downloads.
D.Use ACLs to grant ObjectOwner full control and rely on the application to generate presigned URLs with longer expirations to avoid 403 errors.
AnswerB

Block Public Access ensures the bucket cannot become public. A policy that denies non-HTTPS traffic and scopes object ARNs to a session tag or equivalent identity attribute enforces user-specific access without relying on public principals.

Why this answer

It keeps S3 Block Public Access enabled (preventing any public access), uses a bucket policy or access point policy with a condition key like `aws:PrincipalTag` to restrict `PutObject`/`GetObject` to the user-specific prefix (e.g., `arn:aws:s3:::media-originals/${aws:PrincipalTag/userId}/*`), and denies non-HTTPS requests via a `aws:SecureTransport` condition. This ensures presigned URLs work only for authenticated users with the correct session tag, while enforcing HTTPS and preventing public access.

Exam trap

The trap here is that candidates mistakenly think presigned URLs bypass bucket policies, but in reality, presigned URLs are still subject to the bucket policy—so a policy that denies access to anonymous principals or lacks conditions for user-specific prefixes will cause 403 errors even with valid presigned URLs.

Why the other options are wrong

C

Option C suggests using bucket website hosting and allowing public GET requests, which violates the requirement to prevent any public access to the bucket. Presigned URLs are needed for authenticated access, not public access.

D

ACLs cannot enforce HTTPS or restrict access to user-specific prefixes; they only grant coarse permissions. Presigned URLs already provide time-limited access, so extending expiration does not fix the 403 error caused by missing policy conditions.

When would these options actually be correct?

C

A question where the requirement is to serve static website content publicly (e.g., a public-facing blog or documentation site) and the bucket policy allows public read access, with no need for presigned URLs or user-specific prefixes.

D

A question where the requirement is simply to allow bucket owner full control over objects while using presigned URLs for temporary access, with no need for prefix restrictions or HTTPS enforcement. For example: 'An app uses presigned URLs to share files; the bucket must prevent public access but allow the owner to manage all objects.'

Why candidates pick the wrong answer

C

Candidates may think website hosting simplifies access and eliminates the need for presigned URLs, but they overlook the strict security requirement of no public access.

D

Candidates may think ACLs are sufficient for access control and that longer presigned URL expirations solve 403 errors, overlooking that the real issue is a missing policy condition (like aws:PrincipalTag) to restrict access to user-specific prefixes.

744
MCQmedium

A media company has an Amazon RDS for MySQL database in a private subnet. A web application on Amazon EC2 instances must connect to the database, and the security team requires that the database credentials be rotated every 30 days without application downtime. Which solution should a solutions architect recommend?

A.Store the credentials in an encrypted Amazon S3 object and have the application download the object on each connection.
B.Store the credentials in AWS Secrets Manager, enable automatic rotation with a Lambda rotation function, and have the application retrieve the secret at runtime.
C.Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter and rotate them with a scheduled Lambda function.
D.Use IAM database authentication for Amazon RDS and have the application generate an authentication token with its IAM role.
AnswerB

Secrets Manager natively supports automatic rotation of RDS credentials using a Lambda rotation function, and it updates both the secret and the database user password. Retrieving the secret at runtime lets the application pick up new credentials without a redeploy, meeting the 30-day rotation and zero-downtime requirements.

Why this answer

Secrets Manager is designed for this use case: it stores the RDS credentials, uses a Lambda rotation function to change the password on a schedule, and updates the secret value atomically. Applications that fetch the secret at runtime receive the current credentials, so rotation happens without downtime or application redeployment.

Exam trap

The trap here is assuming Parameter Store provides the same native RDS rotation as Secrets Manager, when it requires custom rotation logic.

745
MCQeasy

A company needs to store application logs in a durable and highly available manner. The logs are written continuously by multiple EC2 instances and are accessed infrequently for compliance audits. The company wants a solution that provides 99.999999999% (11 9's) durability and automatically replicates data across multiple Availability Zones. Which AWS service should the company use?

A.Amazon EC2 instance store volumes.
B.Amazon Elastic Block Store (Amazon EBS) volumes attached to each EC2 instance.
C.Amazon RDS for MySQL with a Multi-AZ deployment.
D.Amazon S3 with the STANDARD storage class.
AnswerD

Amazon S3 Standard provides 99.999999999% durability and automatically replicates data across multiple Availability Zones within a Region. It is highly available and suitable for infrequently accessed compliance logs. Multiple EC2 instances can write to the same bucket concurrently.

Why this answer

Amazon S3 Standard is designed for 99.999999999% durability and automatically replicates data across multiple Availability Zones within a Region. It supports concurrent writes from multiple EC2 instances and is a cost-effective solution for storing and retrieving logs. This meets the durability and availability requirements.

Exam trap

The trap here is assuming that EBS volumes or instance store provide similar durability to S3. EBS volumes are replicated within a single AZ, and instance store is ephemeral, so neither meets the cross-AZ durability requirement.

746
MCQhard

A healthcare document service uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

A.Embed the database password in the AMI
B.Store the database password in user data
C.Use a security group rule that allows only application instances
D.IAM database authentication for RDS with an EC2 instance role
AnswerD

IAM database authentication lets the EC2 instance assume a role with an rds-db:connect permission; the application then generates a temporary authentication token with aws rds generate-db-auth-token and supplies it as the PostgreSQL password. This token, signed with SigV4, expires in 15 minutes, so no long-lived password is stored in code, configuration, or the AMI. The instance role also gives you a clean, auditable identity that can be scoped precisely to that DB user. Note that the database user must still be created (with the name matching the IAM principal) for the role to work.

Why this answer

IAM database authentication for RDS with an EC2 instance role is correct because it allows the EC2 instance to assume an IAM role and obtain a short-lived authentication token (valid for 15 minutes) to connect to the PostgreSQL database, eliminating the need to store any credentials on the instance. This approach meets both requirements: no credentials stored on EC2 and the use of short-lived credentials. The token is generated using the AWS CLI or SDK with the IAM role's temporary security credentials, and the RDS instance must be configured to accept IAM authentication.

Exam trap

The trap here is that candidates may think security groups alone solve credential management, but they only control network access, not authentication or credential lifecycle, so they fail to address the short-lived credential requirement.

How to eliminate wrong answers

Option A is wrong because embedding the database password in the AMI stores credentials persistently on the EC2 instance, violating the requirement that credentials must not be stored on the instance, and the password is long-lived, not short-lived. Option B is wrong because storing the database password in user data also places credentials on the EC2 instance (accessible via the instance metadata), again violating the no-storage requirement and providing a long-lived credential. Option C is wrong because a security group rule only controls network access at the transport layer; it does not address authentication or credential management, and it does not provide short-lived credentials.

747
MCQmedium

Based on the exhibit, which AWS service should the security team enable to continuously discover sensitive data stored inside Amazon S3 objects?

A.AWS CloudTrail
B.Amazon Macie
C.AWS Config
D.Amazon GuardDuty
AnswerB

Macie is the AWS service designed to discover and classify sensitive data in S3. It can continuously analyze buckets for personal data patterns and produce findings when sensitive information is detected. That matches the requirement for ongoing classification of object contents rather than audit logs or configuration checks.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as personally identifiable information (PII) or financial data stored in Amazon S3. It provides continuous visibility into data security risks by generating findings when sensitive data is detected, making it the correct choice for this use case.

Exam trap

The trap here is that candidates often confuse Amazon Macie with Amazon GuardDuty, mistakenly thinking GuardDuty's threat detection includes scanning for sensitive data, when in fact GuardDuty focuses on security threats and anomalies, not data classification or content inspection.

Why the other options are wrong

A

AWS CloudTrail records API activity for auditing, not for discovering sensitive data within S3 objects. It cannot inspect object contents for sensitive information like PII or financial data.

C

AWS Config is designed to evaluate and monitor resource configurations and compliance, not to discover or classify sensitive data within S3 objects. It cannot inspect the content of objects for sensitive information like PII or financial data.

D

Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for discovering sensitive data within S3 objects. It does not perform content inspection or classification of data stored in S3.

When would these options actually be correct?

A

A security team needs to audit all API calls made to S3 buckets, including who accessed objects and when, to meet compliance requirements. CloudTrail would be the correct service to enable for tracking S3 API activity.

C

A security team needs to continuously monitor and record changes to S3 bucket policies, ACLs, and other resource configurations to ensure compliance with internal security standards. AWS Config would be the correct service to track configuration changes and evaluate rules against desired configurations.

D

GuardDuty would be correct if the question asked for a service that continuously monitors for suspicious API calls or potential security threats (e.g., compromised credentials, unusual data access patterns) across AWS accounts and workloads, including S3 access patterns.

Why candidates pick the wrong answer

A

Candidates may confuse CloudTrail's logging of S3 operations with data discovery, assuming that logging all actions includes scanning object contents, which it does not.

C

Candidates may confuse AWS Config's ability to monitor S3 bucket configurations with the capability to inspect object content, assuming that 'monitoring' includes data discovery, or they may think Config can scan objects for compliance rules.

D

Candidates may confuse GuardDuty's threat detection capabilities with data discovery, assuming it can identify sensitive data as part of its monitoring, or they may think it scans S3 objects for anomalies that could indicate sensitive data exposure.

748
MCQeasy

A startup expects steady compute usage around the clock for the next year. They want to reduce costs compared to On-Demand pricing, without tightly planning specific instance types. Which option best matches their goal?

A.Purchase a Compute Savings Plan to receive discounted rates for a usage amount over a 1-year term.
B.Purchase a Reserved Instance that must be tied to exactly one specific instance size (no flexibility to switch instance families).
C.Only use Spot Instances and set the workload to stop immediately if capacity is interrupted.
D.Rely on On-Demand pricing and add more alarms to detect when costs spike.
AnswerA

Compute Savings Plans provide discounted EC2 usage (and related compute usage) versus On-Demand for a committed amount per hour. They are not limited to a single instance type, so the team can change instance families while staying within the committed usage.

Why this answer

A Compute Savings Plan offers the lowest prices on EC2 compute usage (including Fargate and Lambda) in exchange for a commitment to a consistent amount of compute (measured in $/hour) over a 1-year or 3-year term. This matches the startup's steady, predictable usage and provides up to 66% savings over On-Demand, while allowing flexibility to change instance families, sizes, regions, or even switch to containers without renegotiating the plan.

Exam trap

The trap here is that candidates often confuse Compute Savings Plans with Reserved Instances, assuming both lock you to a specific instance type, but Compute Savings Plans provide full flexibility across instance families, sizes, and even compute services.

How to eliminate wrong answers

Option B is wrong because a Reserved Instance (Standard or Convertible) is tied to a specific instance family and often a specific size within that family, which contradicts the requirement for flexibility across instance types. Option C is wrong because Spot Instances can be interrupted with only a 2-minute warning, making them unsuitable for steady, around-the-clock compute workloads that cannot tolerate interruptions. Option D is wrong because relying solely on On-Demand pricing with alarms does not reduce costs; alarms only notify of cost spikes but do not provide any discount mechanism.

749
MCQmedium

Based on the exhibit, the application should continue serving requests if one Availability Zone fails. Which change best improves resilience with the least operational complexity?

A.Increase the desired capacity in AZ-a so more instances can absorb the failure of that same Availability Zone.
B.Add at least one subnet from a second Availability Zone to both the ALB and the Auto Scaling group.
C.Disable health checks so the ALB stops removing targets during brief infrastructure issues.
D.Move the application to a single larger instance type so the fleet has fewer moving parts.
AnswerB

A resilient design needs the load balancer and the Auto Scaling group to span multiple Availability Zones. If one AZ fails, the ALB can still route to healthy targets in the remaining AZs and the Auto Scaling group can replenish capacity there. This is the simplest and most common way to achieve AZ-level fault tolerance.

Why this answer

Adding subnets from a second Availability Zone to both the ALB and the Auto Scaling group distributes the application across multiple AZs. This ensures that if one AZ fails, the ALB can route traffic to healthy targets in the remaining AZ, and the Auto Scaling group can maintain capacity by launching instances in the surviving AZ. This approach directly addresses the requirement to continue serving requests during an AZ failure with minimal operational complexity.

Exam trap

The trap here is that candidates often think increasing capacity in a single AZ (Option A) provides resilience, but it actually concentrates risk in that AZ, while the correct answer requires distributing resources across multiple AZs to achieve true fault tolerance.

How to eliminate wrong answers

Option A is wrong because increasing the desired capacity in a single AZ does not provide resilience against the failure of that same AZ; all instances would be lost if the AZ fails. Option C is wrong because disabling health checks would prevent the ALB from detecting and removing unhealthy targets, causing traffic to be routed to failed instances and degrading application availability. Option D is wrong because moving to a single larger instance type creates a single point of failure; if that instance fails, the entire application becomes unavailable, and it does not address AZ-level failures.

750
MCQeasy

A company hosts static images, CSS, and JavaScript files in an Amazon S3 bucket. Users around the world report slow page loads, and the origin receives many repeated requests for the same files. What should the team use to improve performance?

A.Amazon CloudFront
B.AWS Direct Connect
C.Amazon Route 53 health checks
D.Amazon EFS
AnswerA

Amazon CloudFront is a global content delivery network (CDN) that caches static assets—such as images, CSS, and JavaScript—at edge locations geographically closer to end users. This reduces latency, offloads requests from the origin server, and improves the overall user experience for global audiences. CloudFront also integrates natively with S3, supports custom domains, SSL/TLS encryption, and allows you to set cache TTLs to control freshness, making it the definitive AWS service for efficient static content distribution.

Why this answer

Amazon CloudFront is a content delivery network (CDN) that caches static content (images, CSS, JavaScript) at edge locations worldwide. By serving cached copies from the edge closest to each user, CloudFront reduces latency, offloads repeated requests from the origin S3 bucket, and improves page load times for a global audience.

Exam trap

The trap here is that candidates may confuse a CDN (CloudFront) with a private network connection (Direct Connect) or a DNS routing service (Route 53), failing to recognize that caching at edge locations is the key to reducing latency and origin load for static content served globally.

Why the other options are wrong

B

AWS Direct Connect establishes a dedicated network connection from on-premises to AWS, which does not address global latency or repeated requests for static content served from S3.

C

Amazon Route 53 health checks are used to monitor the health of resources and route traffic away from unhealthy endpoints; they do not cache content or reduce repeated requests to the origin, so they cannot improve page load performance for static assets.

D

Amazon EFS is a file storage service for EC2 instances, not designed for serving static web content globally or reducing repeated requests. It does not provide edge caching or content delivery acceleration.

When would these options actually be correct?

B

A company needs a consistent, low-latency connection between its on-premises data center and AWS for large data transfers or real-time applications, and the question specifies hybrid cloud connectivity requirements.

C

A company has a multi-region application deployment and wants to automatically route users to healthy endpoints, failing over if an endpoint becomes unhealthy. In that scenario, Route 53 health checks combined with DNS failover would be the correct answer.

D

A question where a company needs a shared file system accessible by multiple EC2 instances for concurrent read/write operations, such as a web application's shared content or a data processing pipeline, with low-latency access within a region.

Why candidates pick the wrong answer

B

Candidates may think a dedicated connection improves speed for all traffic, but Direct Connect does not provide global edge caching or reduce repeated requests to the origin.

C

Candidates may think that health checks can somehow optimize performance by directing users to faster endpoints, but health checks only verify availability, not speed, and do not address caching or repeated requests.

D

Candidates may confuse EFS with S3 for static content storage, or think a shared file system can improve performance by centralizing files, but overlook that EFS lacks global caching and edge delivery capabilities.

Page 9

Page 10 of 13

Page 11