Courseiva

SAA-C03 (SAA-C03) — Questions 76–150

935 questions total · 13pages · All types, answers revealed

Page 1

Page 2 of 13

Page 3
76
MCQmedium

A company stores sensitive customer data in an Amazon S3 bucket. The security team wants to ensure that all data is encrypted at rest using keys that the company controls, including the ability to rotate keys and audit key usage. They also want to minimize operational overhead for key management. Which solution meets these requirements?

A.Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).
B.Use S3 server-side encryption with customer-provided keys (SSE-C).
C.Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3).
D.Encrypt the data client-side before uploading to S3 using an open-source library, and store the keys in AWS Secrets Manager.
AnswerA

SSE-KMS with customer managed keys gives the company control over the KMS key, including key policies, rotation, and auditing via AWS CloudTrail. It integrates natively with S3, so no application changes are needed, minimizing operational overhead. This meets the requirements for customer-controlled keys, rotation, and auditability while leveraging AWS-managed infrastructure.

Why this answer

SSE-KMS with customer managed keys allows the company to control the KMS keys, configure automatic rotation, and audit key usage through CloudTrail. It is a native S3 feature, so no application changes are needed. SSE-S3 does not give key control, SSE-C requires the customer to manage keys per request, and client-side encryption adds significant operational burden.

Exam trap

The trap here is assuming that any server-side encryption provides customer-controlled keys and auditability.

77
MCQmedium

A public API for a customer analytics portal is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used? The design must avoid adding custom operational scripts.

A.API keys only
B.JWT authorizer configured for the OpenID Connect issuer
C.IAM authorization for all internet users
D.A VPC endpoint policy
AnswerB

This is correct because API Gateway's JWT authorizer validates the RS256 signature, issuer, audience, and expiry of a JWT issued by your customer's OpenID Connect (OIDC) provider. It automatically discovers the provider's JWKS keys through the OIDC discovery endpoint, so no custom Lambda code is required. The verified token claims are then passed to the integration via context, enabling clean, low-operational-overhead authentication for public API users. This directly matches the need to confirm the identity of each caller.

Why this answer

A JWT authorizer in API Gateway can validate tokens issued by an external OpenID Connect (OIDC) provider without requiring custom code. The JWT authorizer automatically verifies the token's signature, expiry, and issuer against the OIDC provider's JWKS endpoint, meeting the requirement for standards-based authentication and avoiding custom operational scripts.

Exam trap

The trap here is that candidates often confuse API keys (which are for rate limiting and usage plans, not authentication) with token-based authorization, or mistakenly think IAM authorization can be used for external users without AWS credentials.

How to eliminate wrong answers

Option A is wrong because API keys only provide simple identification, not authentication or authorization; they do not validate token claims or integrate with an OpenID Connect provider. Option C is wrong because IAM authorization is designed for AWS principals (e.g., IAM users/roles) and requires AWS credentials, not standards-based tokens from an external OIDC provider; it also cannot be used for all internet users without custom signing logic. Option D is wrong because a VPC endpoint policy controls access to API Gateway via VPC endpoints, not authentication or token validation; it does not address client authentication with OIDC tokens.

78
Multi-Selecthard

A financial services firm runs a batch settlement job on a fleet of Amazon EC2 instances that pull work from an Amazon SQS queue. The job must not lose messages if an instance is terminated mid-processing, and duplicate processing must be minimized because each settlement charge is expensive. The team also wants to avoid indefinite reprocessing of a message that repeatedly fails. Which two changes should the solutions architect make to meet these requirements? (Choose two.)

Select 2 answers
A.Switch the queue to an Amazon SQS FIFO queue with content-based deduplication.
B.Increase the queue's visibility timeout so it exceeds the maximum expected processing time.
C.Store a processing flag in an Amazon ElastiCache for Redis cluster and check it before charging.
D.Enable long polling on the queue by setting ReceiveMessageWaitTimeSeconds to 20.
E.Configure a dead-letter queue on the source queue with a maximumReceiveCount.
AnswersB, E

If the visibility timeout is shorter than the processing time, the message becomes visible again and a second consumer can pick it up, causing duplicate settlement charges. Setting the timeout above the worst-case processing duration prevents this overlap and is essential for minimizing duplicates in a pull-based worker fleet.

Why this answer

Raising the visibility timeout above the maximum processing time prevents a still-running message from being redelivered to another consumer, which directly reduces duplicate settlement charges. Attaching a dead-letter queue with a maximumReceiveCount moves repeatedly failing messages aside after a set number of receives, so they are not reprocessed indefinitely while healthy traffic continues.

Exam trap

The trap here is assuming that switching to a FIFO queue alone guarantees no duplicates, when the visibility timeout and a dead-letter queue are what actually control redelivery and poison messages.

79
MCQhard

Based on the exhibit, a workload in Account B must assume a role in Account A. Security requires that only the specific role arn:aws:iam::444455556666:role/PipelineExecRole can assume it, and only when the caller supplies the external ID acct-b-prod-7788. Which change best satisfies the requirement with the least privilege?

A.Keep the root principal and add an aws:PrincipalTag condition in the trust policy to require the tag acct-b-prod-7788.
B.Replace the principal with arn:aws:iam::444455556666:role/PipelineExecRole and add a StringEquals condition on sts:ExternalId = acct-b-prod-7788.
C.Attach a permission boundary to the role in Account A so that only PipelineExecRole can use it.
D.Add an SCP in Account B that allows sts:AssumeRole only for PipelineExecRole.
AnswerB

This change directly restricts trust to one named role in Account B and adds a confused-deputy defense with the external ID. The role trust policy is the correct place to control who can assume the role, and the external ID ensures only the expected caller can complete the STS request.

Why this answer

It explicitly restricts the trust policy principal to the specific IAM role ARN `arn:aws:iam::444455556666:role/PipelineExecRole` and adds a `StringEquals` condition on `sts:ExternalId` set to `acct-b-prod-7788`. This satisfies the security requirement by ensuring only that exact role can assume the role in Account A, and only when the correct external ID is provided, following the principle of least privilege.

Exam trap

The trap here is that candidates often confuse the trust policy's `Principal` element with permission boundaries or SCPs, mistakenly thinking those can restrict who can assume a role, when in fact only the trust policy controls the assumption, and the external ID condition is required to prevent confused deputy attacks.

How to eliminate wrong answers

Option A is wrong because using a root principal (which allows any IAM entity in Account B) combined with an `aws:PrincipalTag` condition does not restrict the caller to the specific role `PipelineExecRole`; tags can be modified or absent, and the root principal is overly permissive. Option C is wrong because a permission boundary attached to the role in Account A limits the permissions of that role but does not control which external principal can assume it; the trust policy alone governs who can assume the role. Option D is wrong because an SCP in Account B can deny or allow `sts:AssumeRole` actions for principals in Account B, but it cannot enforce the external ID requirement or restrict which role in Account A is assumed; the trust policy in Account A is the authoritative mechanism.

80
MCQhard

A company runs a stateful workload on Amazon EC2 instances in an Auto Scaling group. The workload writes session data to the instance store and to an Amazon EBS volume attached at launch. The company wants the workload to survive an Availability Zone failure without losing session data. What should the solutions architect do?

A.Create an Amazon EBS snapshot schedule for the attached volumes and restore the snapshots in another Availability Zone after a failure.
B.Move session data to Amazon ElastiCache for Redis with Multi-AZ enabled, and configure the Auto Scaling group to span multiple Availability Zones.
C.Attach an additional EBS volume to each instance and configure RAID 0 across the two volumes for higher durability.
D.Enable termination protection on the instances and configure the Auto Scaling group to use a single Availability Zone.
AnswerB

Storing session data in ElastiCache for Redis with Multi-AZ provides automatic failover to a replica in another Availability Zone. Spreading the Auto Scaling group across zones lets replacement instances launch in a healthy zone and reconnect to the session store, preserving sessions through a zone failure.

Why this answer

Session data must be moved off instance-bound storage to a multi-AZ data store. ElastiCache for Redis with Multi-AZ automatically fails over to a replica in another zone, and an Auto Scaling group spanning multiple zones can launch replacement instances that reconnect to the session store.

Exam trap

The trap here is assuming that EBS snapshots, RAID, or termination protection can preserve live session data when an entire Availability Zone fails.

81
MCQmedium

A fintech company has a two-Region DR requirement: RPO must be within 15 minutes and RTO must be under 2 hours. To control cost, they do not want to run full production infrastructure in the secondary Region continuously. They plan to continuously replicate the database and keep the application infrastructure in the secondary Region prepared, but at reduced capacity. Which DR strategy best matches this requirement and accurately describes their plan?

A.Pilot light: keep only minimal components (for example, replicated storage and a small amount of core services), so the app scales up during a disaster.
B.Warm standby: keep the essential parts of the application running in the secondary Region at reduced capacity, while using database replication to meet the RPO.
C.Active-active: run the application fully in both Regions with synchronized writes and share traffic continuously.
D.Cold standby: store backups in the secondary Region and provision all infrastructure only during a disaster.
AnswerB

Warm standby runs a fully functional but reduced-capacity version of the application stack in the secondary Region, including application servers and a database that is continuously replicated from the primary Region (for example, via Amazon RDS cross-Region read replicas or Aurora Global Database). Because the environment is already running, failover only requires scaling up the existing infrastructure and promoting the replica, which keeps RTO well under 2 hours. Continuous replication also keeps data lag within the 15-minute RPO, making this the correct choice for the given constraints.

Why this answer

Warm standby is the correct strategy because it runs a scaled-down version of the production application in the secondary Region continuously, with database replication (e.g., Amazon RDS Multi-Region or Aurora Global Database) meeting the 15-minute RPO. The reduced-capacity infrastructure can be scaled up within the 2-hour RTO during a disaster, balancing cost and recovery requirements.

Exam trap

The trap here is confusing pilot light with warm standby: candidates often think any pre-provisioned infrastructure qualifies as pilot light, but warm standby explicitly runs the application at reduced capacity, whereas pilot light keeps only core services and storage without running the application stack.

How to eliminate wrong answers

Option A is wrong because pilot light keeps only minimal core services and storage, not a running application at reduced capacity, and requires provisioning and scaling up compute resources during a disaster, which may not meet the 2-hour RTO if scaling takes significant time. Option C is wrong because active-active runs the application fully in both Regions with synchronized writes and continuous traffic sharing, which violates the cost control requirement of not running full production infrastructure continuously. Option D is wrong because cold standby stores only backups and provisions all infrastructure during a disaster, leading to RTOs that typically exceed 2 hours due to provisioning and data restoration delays.

82
MCQeasy

A media company stores generated video thumbnails in an Amazon S3 bucket. The bucket currently uses the S3 Standard storage class, and the objects are accessed frequently for the first 30 days and then almost never. The company wants to reduce storage costs automatically without changing the application and must retain the objects for at least one year. Which action should a solutions architect take?

A.Enable S3 Intelligent-Tiering on the bucket and let AWS move the objects between access tiers automatically.
B.Configure an S3 Lifecycle rule to transition objects to S3 One Zone-IA after 30 days and expire them after 365 days.
C.Configure an S3 Lifecycle rule to transition objects to S3 Standard-IA after 30 days and to S3 Glacier Instant Retrieval after 90 days.
D.Configure an S3 Lifecycle rule to transition objects to S3 Standard-IA after 30 days and retain them for the required period.
AnswerD

S3 Standard-IA is designed for data accessed infrequently but requiring rapid access when needed, and its lower storage price with a 30-day minimum duration matches the access pattern described. A lifecycle transition applies automatically without application changes and preserves the objects for the required retention period.

Why this answer

The access pattern is known and stable: frequent for about 30 days, then rarely. A lifecycle rule that transitions objects to S3 Standard-IA after 30 days lowers storage cost automatically, requires no application change, and keeps the objects available for the required retention period.

Exam trap

The trap here is reaching for S3 Intelligent-Tiering when the access pattern is already known and predictable rather than unknown.

83
MCQmedium

A company hosts a customer analytics portal on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

A.An internet gateway attached to the private subnet
B.A public Elastic IP address on each instance
C.AWS Systems Manager Session Manager with the required instance role
D.A bastion host with SSH open to 0.0.0.0/0
AnswerC

AWS Systems Manager Session Manager establishes an interactive shell connection through the SSM Agent using a bidirectional channel over the AWS API, controlled by the instance's IAM role. Because no security group ingress rule is needed, there is no inbound SSH/RDP exposure, and each session is automatically audited through AWS CloudTrail with optional session logs to S3/CloudWatch Logs. The required IAM role grants least-privilege permissions (e.g., AmazonSSMManagedInstanceCore) and lets administrators restrict actions centrally via IAM policies, providing secure, audited administrative access.

Why this answer

AWS Systems Manager Session Manager allows secure, auditable shell access to EC2 instances without opening inbound SSH (port 22) or RDP (port 3389) ports to the internet. It uses the AWS Systems Manager agent on the instance, which initiates an outbound connection to the AWS Systems Manager service over HTTPS (port 443), and the required IAM instance role grants permissions for this communication. This eliminates the need for a bastion host or public IP addresses, meeting the security requirement of no open inbound ports.

Exam trap

The trap here is that candidates often default to a bastion host (Option D) as the traditional solution for secure administrative access, but fail to recognize that Session Manager provides the same functionality without any inbound ports, which is the exact requirement stated in the question.

How to eliminate wrong answers

Option A is wrong because an internet gateway attached to a private subnet does not provide direct connectivity to the internet; it is used for public subnets and would require a route table entry to a NAT device for outbound-only access, not for administrative connections without open ports. Option B is wrong because assigning a public Elastic IP address to each instance exposes them directly to the internet, requiring open SSH or RDP ports to connect, which violates the requirement. Option D is wrong because a bastion host with SSH open to 0.0.0.0/0 exposes the bastion to the entire internet, creating a security risk and still requires opening SSH (port 22) or RDP (port 3389) on the bastion, contradicting the 'without opening SSH or RDP ports to the internet' constraint.

84
MCQmedium

Your security team needs to detect and alert on any attempt to change sensitive policies, specifically S3 bucket policy changes and KMS key policy changes. The team wants alerts within minutes, and logs must be centrally retained for forensics. Which design best meets these detective control requirements using AWS-native services?

A.Enable CloudTrail management events and configure an EventBridge rule to send notifications for PutBucketPolicy and PutKeyPolicy API calls, while also delivering CloudTrail logs to a dedicated S3 bucket for retention.
B.Rely on AWS Config resource snapshots only; use the snapshots to infer policy changes and generate alerts from the daily compliance summary reports.
C.Enable S3 access logging on the affected buckets only; treat these logs as sufficient evidence for KMS key policy modifications.
D.Turn on CloudWatch Logs for the S3 bucket and KMS key; alert on any log line containing the word 'policy' to detect changes.
AnswerA

CloudTrail management events capture control-plane API calls, including PutBucketPolicy and PutKeyPolicy, recording the request parameters, principal, source IP, and timestamp. An EventBridge rule can match these event names and invoke an SNS topic or Lambda function to notify the security team within seconds of the call. Delivering the raw CloudTrail logs to a dedicated S3 bucket creates a tamper-evident, centrally retained audit trail for post-incident analysis and compliance reporting, whereas simply watching resource state via Config would not provide the same event-level specificity.

Why this answer

CloudTrail management events capture all API calls for S3 bucket policies (PutBucketPolicy) and KMS key policies (PutKeyPolicy) by default, and EventBridge rules can trigger near-real-time alerts (within minutes) for these specific API calls. Additionally, delivering CloudTrail logs to a dedicated S3 bucket provides centralized, immutable retention for forensic analysis, meeting both the alerting and retention requirements.

Exam trap

The trap here is that candidates often confuse S3 access logs (which record data-plane operations) with CloudTrail management events (which record control-plane operations), leading them to choose Option C, or they mistakenly think AWS Config snapshots provide real-time alerts, when in fact they are periodic and lack API-level detail.

How to eliminate wrong answers

Option B is wrong because AWS Config resource snapshots are taken periodically (e.g., every 1 hour or 6 hours), not within minutes, and they only show the state of resources at a point in time, not the specific API call that made the change, making them unsuitable for near-real-time alerting and forensic detail. Option C is wrong because S3 access logs record object-level access requests (e.g., GET, PUT, DELETE) on S3 buckets, not management events like bucket policy changes or KMS key policy modifications, and they cannot capture KMS key policy changes at all. Option D is wrong because CloudWatch Logs for S3 buckets and KMS keys do not exist as native log sources; CloudWatch Logs can ingest CloudTrail logs, but simply alerting on any log line containing the word 'policy' would generate excessive false positives (e.g., from normal operations like listing policies) and lacks the precision to detect only policy modification API calls.

85
MCQmedium

In an AWS Organizations environment, developers create IAM roles using an automation tool. The security team wants to guarantee that even if a developer attaches an overly permissive inline policy, the role cannot exceed a fixed set of allowed actions. The team already uses permission boundaries on each role. The tool’s role-creation API call succeeds, but one developer’s new role can still delete production S3 buckets. What is the most likely reason, and what should be corrected?

A.Permission boundaries do not affect permissions for resources created with role chaining; enable role chaining instead to apply the boundary.
B.The boundary policy was not actually attached during role creation, or the automation tool attached the wrong boundary ARN; correct the role-creation request to set the intended PermissionBoundary.
C.KMS key policies override permission boundaries for S3, so deletion permission comes from the KMS policy; restrict the KMS key policy instead.
D.Permission boundaries apply only to managed policies, not to inline policies; move the overly permissive permissions to a managed policy type to keep it bounded.
AnswerB

Permission boundaries work by intersecting allowed actions from the role’s attached policies with the actions permitted by the boundary policy. If the automation tool fails to set the PermissionBoundary ARN (or sets an incorrect one), then the role can use the developer’s attached policies without the intended restriction. Fixing the PermissionBoundary parameter in the role creation call is the direct remedy.

Why this answer

Permission boundaries must be explicitly attached to an IAM role during creation via the `PermissionBoundary` parameter. If the automation tool fails to attach the intended boundary policy or attaches the wrong ARN, the role will have no effective boundary, allowing any inline policy to grant full access. The developer's role could then delete production S3 buckets because the boundary was not enforced.

Exam trap

The trap here is that candidates may assume permission boundaries are automatically inherited from the AWS Organizations policy or that they only affect managed policies, when in fact they must be explicitly attached and apply to all policy types.

How to eliminate wrong answers

Option A is wrong because permission boundaries do apply to roles used in role chaining; role chaining does not bypass boundaries, and enabling it would not fix the issue. Option C is wrong because KMS key policies control encryption operations, not S3 bucket deletion permissions; S3 delete actions are governed by S3 resource-based policies and IAM policies, not KMS policies. Option D is wrong because permission boundaries apply to both managed and inline policies equally; they limit the maximum permissions a role can have regardless of policy type.

86
MCQmedium

A batch analytics job has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity?

A.DynamoDB on-demand capacity mode
B.Reserved capacity for maximum daily traffic
C.Provisioned capacity set for peak traffic
D.Global tables in every Region
AnswerA

On-demand capacity is suitable for unpredictable workloads and charges per request without capacity planning.

Why this answer

DynamoDB on-demand capacity mode automatically scales to handle unpredictable traffic spikes and idle periods, charging only for the reads and writes you perform. This eliminates the need to provision capacity for peak traffic, avoiding costs during long idle periods and reducing operational overhead from capacity management.

Exam trap

The trap here is that candidates may confuse 'Reserved capacity' with DynamoDB's reserved capacity option (which does not exist) or think provisioned capacity is always cheaper, ignoring the cost of idle provisioned throughput during unpredictable workloads.

How to eliminate wrong answers

Option B is wrong because Reserved capacity is not a DynamoDB pricing model; it applies to Amazon EC2 and RDS, not DynamoDB, and would still require provisioning for peak traffic. Option C is wrong because Provisioned capacity set for peak traffic would incur costs for idle periods when traffic is low, as you pay for the provisioned capacity regardless of actual usage. Option D is wrong because Global tables are a replication feature for multi-Region active-active setups, not a capacity mode; they do not address cost optimization for unpredictable traffic and add complexity and cost.

87
Multi-Selectmedium

A logistics company runs an order-processing workflow using AWS Step Functions. A task state invokes a Lambda function that charges customer credit cards through a third-party gateway. Occasionally the gateway times out, and the workflow fails even though the charge may have succeeded. The architect must make the workflow resilient to these transient failures and avoid duplicate charges. (Choose two.)

Select 2 answers
A.Increase the Lambda function's reserved concurrency to the account limit so more charge requests can run in parallel.
B.Configure a Retry policy on the task state with an exponential backoff and a bounded MaxAttempts value for the relevant error names.
C.Add a Catch field to the task state that transitions to a Fail state so the workflow stops cleanly on any error.
D.Generate an idempotency key for each charge and pass it to the payment gateway so repeated invocations are deduplicated.
E.Enable AWS X-Ray tracing on the state machine and Lambda function to record where the timeouts occur.
AnswersB, D

A Retry policy with exponential backoff lets Step Functions re-invoke the task when the gateway times out, absorbing transient failures without abandoning the workflow. Bounding MaxAttempts prevents infinite retries that could amplify load on a struggling gateway. Because retries happen within the state machine, the workflow resumes automatically once the gateway responds, satisfying the resilience requirement.

Why this answer

Resilience to transient gateway timeouts requires the workflow to retry the task, and safety requires that retries not charge the customer twice. A bounded Retry policy with exponential backoff handles the transient failure, while an idempotency key carried into each attempt lets the payment gateway recognize and deduplicate repeated requests. Together they deliver both reliability and correctness.

Exam trap

The trap here is assuming that adding retries alone is safe, when retrying a non-idempotent charge without a deduplication key can create duplicate payments.

88
MCQmedium

A healthcare company runs a stateless patient-intake API on a fleet of Amazon EC2 instances in a single VPC. The compliance team requires the workload to survive the complete loss of one Availability Zone with no manual intervention, and the instances must be replaced automatically if they fail health checks. The application stores no local state and writes all data to Amazon RDS. Which approach meets these requirements with the LEAST operational effort?

A.Launch the instances directly with a launch template into two subnets in different Availability Zones, and attach each instance to a Network Load Balancer with cross-zone load balancing enabled.
B.Place the instances behind an Application Load Balancer in one Availability Zone and configure an Amazon Route 53 health check with a failover record pointing to a static Elastic IP address.
C.Deploy the instances as an Auto Scaling group in a single Availability Zone and enable detailed CloudWatch monitoring with a scaling policy based on CPU utilization.
D.Create an Auto Scaling group spanning two Availability Zones with a launch template, and attach it to an Application Load Balancer target group with health checks enabled.
AnswerD

An Auto Scaling group across multiple Availability Zones redistributes capacity when a zone is lost, and its health checks replace instances that fail. Attaching the group to an Application Load Balancer target group means ELB health checks drive replacement of unhealthy instances. This satisfies both zone-failure survival and automatic instance replacement with minimal operational overhead.

Why this answer

Resilience to a full Availability Zone loss requires capacity spread across at least two zones, and automatic instance replacement requires an Auto Scaling group whose health checks are tied to the load balancer. Combining a multi-AZ Auto Scaling group with an Application Load Balancer target group delivers both properties without manual intervention, which is exactly what the compliance requirement demands.

Exam trap

The trap here is assuming that a load balancer alone provides high availability, when it only distributes traffic and does not replace failed compute capacity.

89
MCQhard

A payments API uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure?

A.A FIFO queue without a redrive policy
B.A dead-letter queue with an appropriate maxReceiveCount
C.A larger message retention period only
D.Short polling instead of long polling
AnswerB

A dead-letter queue combined with a redrive policy's maxReceiveCount is the correct solution. Each time a message is received, SQS increments its receive count; when the count exceeds maxReceiveCount, SQS moves the message from the source queue into the configured DLQ, isolating it from normal traffic. This lets the payments consumer continue processing healthy messages while the poison message is held for investigation. An appropriate threshold (for example, 3 to 5) balances retrying transient errors against letting a permanently bad message consume all subsequent visibility timeouts and retries.

Why this answer

B is correct because a dead-letter queue (DLQ) with an appropriate maxReceiveCount allows the payments API to isolate poison messages after a specified number of failed processing attempts. This prevents repeated failures from blocking useful retries, as the problematic messages are moved to the DLQ for manual inspection or separate handling, while the main queue continues processing valid messages.

Exam trap

The trap here is that candidates often confuse increasing the retention period or switching polling methods as solutions for poison messages, when the correct mechanism is a dead-letter queue with a maxReceiveCount to limit retries.

How to eliminate wrong answers

Option A is wrong because a FIFO queue without a redrive policy does not automatically handle poison messages; without a DLQ, failed messages will continue to be retried indefinitely, blocking the queue. Option C is wrong because increasing the message retention period only extends how long messages stay in the queue, but does not address the repeated failure and blocking caused by poison messages. Option D is wrong because short polling (vs. long polling) affects how often the queue is polled for messages, not the handling of poison messages or retry behavior.

90
MCQeasy

A content publishing system exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most?

A.IAM Access Analyzer
B.AWS Backup Vault Lock
C.CloudFront caching with appropriate TTLs
D.S3 Select
AnswerC

CloudFront caching with appropriate TTLs is correct because CloudFront edge locations store copies of S3 objects and serve them directly to viewers based on the configured cache TTL. If the S3 origin becomes temporarily unavailable, requests can still be fulfilled from cached content at the edge as long as the object is still in the cache and its TTL has not expired—this effectively masks origin downtime. Choosing appropriate TTLs (e.g., long TTL for immutable static assets) maximizes the chance that cached copies remain available during an outage while balancing freshness, and CloudFront can even serve stale content when it fails to reach the origin.

Why this answer

CloudFront caches responses from the S3 origin based on configured TTLs (Cache-Control or Expires headers). If the S3 origin experiences a short outage, CloudFront can still serve cached content to users until the TTL expires, maintaining availability. This is the most direct way to ensure users receive pages during transient origin failures.

Exam trap

The trap here is confusing data protection features (like Backup Vault Lock) or data retrieval features (like S3 Select) with caching mechanisms that directly improve availability during origin outages.

How to eliminate wrong answers

Option A is wrong because IAM Access Analyzer helps identify unintended access to resources but does not provide caching or origin failover capabilities. Option B is wrong because AWS Backup Vault Lock prevents deletion of backups but does not affect content delivery or caching behavior. Option D is wrong because S3 Select is a feature to retrieve subsets of object data using SQL queries, not a mechanism for caching or serving static content during outages.

91
MCQhard

Based on the exhibit, the team serves versioned JavaScript and CSS files from an S3 origin through CloudFront. After a release, the cache hit ratio dropped and origin fetches increased sharply. What change best reduces both CloudFront and S3 costs without changing the application’s public behavior?

A.Increase the CloudFront price class to include more edge locations.
B.Create a cache policy that excludes Authorization, cookies, and unnecessary query strings, and narrow the origin request policy to forward only the headers the S3 origin actually needs.
C.Disable CloudFront and serve the files directly from S3 to avoid cache invalidation overhead.
D.Use Lambda@Edge to rewrite every request into a unique path so that clients never receive stale files.
AnswerB

The hit ratio is low because CloudFront is varying the cache on request attributes that do not change versioned static files. Removing Authorization, cookies, and irrelevant query strings from the cache key allows CloudFront to reuse cached objects across users and sessions. Reducing the origin request policy avoids sending unnecessary viewer context to the origin. Because the filenames are already versioned, long TTLs can be used safely and will lower origin requests and S3 request costs.

Why this answer

B is correct because versioned JavaScript and CSS files are immutable, so CloudFront should cache them aggressively. By creating a cache policy that excludes unnecessary headers (like Authorization and cookies) and query strings, and narrowing the origin request policy to forward only required headers, you maximize cache hits and reduce origin fetches. This directly lowers both CloudFront data transfer costs (fewer origin requests) and S3 request costs (fewer GET requests), without altering the application's public behavior.

Exam trap

The trap here is that candidates often think increasing edge locations (Option A) or using Lambda@Edge (Option D) will improve performance, but for versioned static files, the real cost optimization comes from maximizing cache hits by properly configuring cache and origin request policies, not from adding more infrastructure or rewriting requests.

How to eliminate wrong answers

Option A is wrong because increasing the CloudFront price class to include more edge locations increases costs (more regional data transfer) and does not improve cache hit ratio for versioned static files—it may even reduce it by spreading requests across more locations. Option C is wrong because disabling CloudFront and serving files directly from S3 eliminates caching entirely, drastically increasing S3 request costs (GET, data transfer) and latency, while also losing CloudFront's edge caching benefits. Option D is wrong because using Lambda@Edge to rewrite every request into a unique path would bypass caching entirely (each unique path is a cache miss), increasing origin fetches and costs, and it does not solve the stale-file problem because versioned files are already immutable.

92
MCQmedium

A digital agency runs a web application on a fleet of Amazon EC2 instances behind an Application Load Balancer. Traffic is steady and predictable during business hours but drops to near zero overnight and on weekends. The operations team wants to reduce compute costs without impacting availability during peak periods. They cannot modify the application code and must keep the same instance types. What should a solutions architect recommend?

A.Enable burstable T3 instances and rely on CPU credits to absorb the peak traffic periods.
B.Switch the fleet to Spot Instances and configure the Auto Scaling group to maintain the same desired capacity at all times.
C.Purchase a 1-year Standard Reserved Instance for each instance and leave the fleet running 24/7.
D.Create an Auto Scaling group with a scheduled scaling policy that scales the desired capacity up before business hours and down after hours.
AnswerD

Scheduled scaling lets you increase or decrease the desired capacity of an Auto Scaling group based on a date and time, which matches a workload with a known, repeating peak pattern. Scaling in overnight and on weekends terminates unneeded instances, so you pay only for the capacity actually required, while scaling out before business hours preserves availability during peak traffic.

Why this answer

The workload has a predictable daily and weekly pattern, so the most direct cost control is to align capacity with demand. A scheduled scaling policy changes desired capacity at known times, terminating instances when traffic is near zero and adding them back before the peak. This avoids paying for idle capacity while keeping the application available when users need it, and it requires no application changes.

Exam trap

The trap here is assuming that a Reserved Instance or Savings Plan reduces cost for a workload that is idle half the time, when in fact commitments bill for the full term regardless of utilization.

93
MCQmedium

An application runs on EC2 in us-east-1 and frequently reads objects from an S3 bucket that is physically located in us-west-2. The finance team reports unexpectedly high inter-Region data transfer charges because the application retrieves objects for many user requests. A constraint: the bucket in us-west-2 must remain the system of record for compliance, but the application can read from a replica in us-east-1. What should the solutions architect do to minimize network spend while meeting the compliance constraint?

A.Enable S3 Cross-Region Replication from the us-west-2 source bucket to a destination bucket in us-east-1, and update the app to read from the us-east-1 bucket.
B.Create an interface VPC endpoint for S3 in us-east-1 and keep all object reads pointing to the us-west-2 bucket.
C.Use VPC peering between two regions and route all requests to the us-west-2 bucket over the peering link.
D.Use Route 53 latency-based routing to send users to a us-west-2 web endpoint and keep the S3 bucket unchanged.
AnswerA

S3 Cross-Region Replication (CRR) creates an asynchronous, automatic copy of every object in the us-west-2 source bucket to a destination bucket in us-east-1. By updating the application to read from the us-east-1 bucket, all GET requests stay within the same Region, eliminating inter-Region data transfer charges that currently accrue for each cross-Region read. Since CRR transfers each object once during replication (rather than on every read), this pattern becomes cost-effective when the application frequently reads the same large objects. You must still account for a short replication lag, so the app should tolerate eventual consistency for newly written objects.

Why this answer

S3 Cross-Region Replication (CRR) automatically replicates objects from the source bucket in us-west-2 to a destination bucket in us-east-1, satisfying the compliance requirement that the us-west-2 bucket remains the system of record. By updating the application to read from the us-east-1 bucket, all read traffic stays within the same region, eliminating inter-region data transfer charges for object retrievals. This approach directly addresses the cost issue while preserving the original bucket as the authoritative source.

Exam trap

The trap here is that candidates may assume VPC endpoints or peering can eliminate inter-region costs, but S3 data transfer charges are based on the bucket's physical region, not the network path, so only replicating the data locally avoids the charges.

Why the other options are wrong

B

An interface VPC endpoint does not eliminate inter-region data transfer charges; traffic from the endpoint in us-east-1 to the bucket in us-west-2 still traverses the public internet or AWS backbone across regions, incurring costs.

C

VPC peering does not reduce inter-region data transfer charges because traffic between peered VPCs in different regions still incurs standard inter-region data transfer costs. Additionally, the application would still read from the us-west-2 bucket, not reducing costs.

D

Route 53 latency-based routing directs user traffic to a web endpoint in us-west-2, but the application still reads from the S3 bucket in us-west-2, incurring inter-Region data transfer charges. It does not create a replica in us-east-1, so the compliance constraint of reading from a replica is not met.

When would these options actually be correct?

B

If the S3 bucket were in the same region as the VPC endpoint (e.g., both in us-east-1) and the goal were to avoid public internet exposure or reduce data transfer costs within a region, an interface VPC endpoint would be correct.

C

If the application needs to access an S3 bucket in another region with lower latency and the data transfer costs are not a concern, or if the bucket is in the same region as the VPC (e.g., both in us-east-1), VPC peering could provide private connectivity without traversing the public internet.

D

This option would be correct if the application needed to minimize latency for global users accessing a web application hosted in multiple regions, and the S3 bucket was in the same region as the web endpoint, with no requirement to replicate data or reduce inter-Region transfer costs.

Why candidates pick the wrong answer

B

Candidates may think that using a VPC endpoint privatizes all traffic and eliminates all data transfer costs, not realizing that inter-region traffic still incurs charges regardless of endpoint type.

C

Candidates may think VPC peering provides free or cheaper inter-region data transfer, but AWS charges for inter-region traffic even over peering. They might also confuse VPC peering with other connectivity options like Direct Connect or VPN.

D

Candidates may think latency-based routing optimizes performance and reduces costs by directing users to the nearest endpoint, but they overlook that the S3 bucket remains in us-west-2, causing inter-Region charges when the application reads from it.

94
MCQeasy

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences variable traffic patterns, with sudden spikes during marketing campaigns. The operations team wants to ensure that the application can scale out quickly to handle the spikes and scale in when traffic decreases, while minimizing costs. Which solution should a solutions architect recommend?

A.Configure an Auto Scaling group with a target tracking scaling policy based on average CPU utilization.
B.Deploy the application on AWS Lambda behind an API Gateway and remove the EC2 instances.
C.Use a scheduled scaling policy that adds instances at the start of each marketing campaign.
D.Enable sticky sessions on the ALB and increase the instance size.
AnswerA

A target tracking scaling policy automatically adjusts the number of instances to maintain a specified metric, such as average CPU utilization, at a target value. This is ideal for variable traffic because it scales out when CPU rises and scales in when it falls. It helps handle sudden spikes and reduces costs during low traffic by terminating unnecessary instances.

Why this answer

A target tracking scaling policy with an Auto Scaling group is the most effective way to handle variable traffic. It automatically adjusts capacity based on CPU utilization, scaling out during spikes and scaling in during low traffic, which optimizes both performance and cost. Other options are either static, do not address scaling, or require major architectural changes.

Exam trap

The trap here is assuming that scheduled scaling is always sufficient for variable traffic, when in fact unpredictable spikes require dynamic scaling policies.

95
Multi-Selecthard

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The implementation must work across routine deployments without manual intervention.

Select 2 answers
A.Interface VPC endpoint for Systems Manager
B.Internet gateway attached to the VPC
C.NAT gateway in each Availability Zone
D.Gateway VPC endpoint for Amazon S3
AnswersA, D

An interface VPC endpoint, powered by AWS PrivateLink, creates an elastic network interface with a private IP address directly in the subnets of your VPC. This allows instances in the private subnets to reach Systems Manager and Parameter Store using private DNS, with no internet gateway, NAT gateway, or public IP required. The traffic stays entirely within the AWS network, satisfying the requirement for fully private connectivity. This endpoint also supports security group attachment for granular traffic control.

Why this answer

Interface VPC endpoints (AWS PrivateLink) for Systems Manager allow private subnets to access Systems Manager Parameter Store without traversing the internet, using private IP addresses within the VPC. Gateway VPC endpoints for S3 provide a highly available, redundant path to S3 via route table entries, ensuring traffic stays within the AWS network. Together, they eliminate the need for internet gateways or NAT gateways, meeting the requirement for no public internet routing.

Exam trap

The trap here is that candidates often confuse gateway VPC endpoints (used for S3 and DynamoDB) with interface VPC endpoints (used for most other AWS services), leading them to incorrectly select NAT gateways or internet gateways for private subnet access.

96
MCQmedium

A healthcare company is designing a new application on AWS. The application will store protected health information (PHI) in an Amazon S3 bucket. The security team requires that all data be encrypted at rest using a customer managed AWS KMS key so that they can control key rotation and audit key usage. They also need to ensure that only the application's IAM role can decrypt the data. Which solution meets these requirements?

A.Use SSE-KMS with a customer managed KMS key and update the key policy to allow only the application's IAM role to decrypt.
B.Use SSE-C with a customer-provided key stored in AWS Secrets Manager and grant the application's IAM role access to the secret.
C.Use client-side encryption with an AWS KMS customer managed key before uploading to S3, and store the encrypted data in the bucket.
D.Use SSE-S3 with an S3 Bucket Key and restrict access with a bucket policy that allows only the application's IAM role.
AnswerA

SSE-KMS with a customer managed key allows the company to control key rotation and audit usage via AWS CloudTrail. The key policy can be scoped to allow only the application's IAM role to perform the Decrypt operation, ensuring that no other principals can access the data. This meets all stated requirements.

Why this answer

The requirement is for server-side encryption with a customer managed KMS key, enabling control over rotation and auditing. SSE-KMS with a customer managed key provides this, and the key policy can restrict decryption to the application's IAM role. Other options either use AWS-managed keys, require custom key management, or shift encryption to the client side, none of which fully satisfy the stated needs.

Exam trap

The trap here is assuming that SSE-S3 with a bucket policy provides the same key control as a customer managed KMS key.

97
Multi-Selecthard

A solutions architect is reviewing an Amazon S3 bucket that stores application assets. The bucket has S3 Versioning enabled and accumulates many noncurrent object versions that are no longer needed. The team wants to reduce storage cost while preserving the ability to recover from accidental deletions of current objects. Which two actions should the architect take? (Choose two.)

Select 2 answers
A.Enable S3 Transfer Acceleration on the bucket to reduce storage charges.
B.Configure a lifecycle rule to expire noncurrent versions after a defined number of days.
C.Add a lifecycle rule to abort incomplete multipart uploads after a set number of days.
D.Transition current object versions to S3 Glacier Deep Archive immediately upon creation.
E.Disable S3 Versioning on the bucket to stop new versions from being created.
AnswersB, C

Expiring noncurrent versions after a retention period removes old versions that are no longer needed, directly reducing storage charges while keeping current objects and recent versions protected. This is the standard S3 lifecycle action for controlling version accumulation cost.

Why this answer

The two cost drivers are accumulated noncurrent versions and lingering incomplete multipart uploads. A lifecycle rule expiring noncurrent versions removes unneeded old copies while preserving current-object recovery, and a rule aborting incomplete multipart uploads eliminates billable orphaned parts. Together they reduce storage cost without disabling versioning or harming retrieval of active assets.

Exam trap

The trap here is thinking that disabling versioning is the way to cut version-related storage cost, when it neither deletes existing noncurrent versions nor preserves the accidental-deletion recovery the team requires.

98
MCQmedium

A partner company needs read-only access to reports in an S3 bucket for a B2B file exchange site. The partner has its own AWS account. What is the most secure scalable access pattern?

A.Make the objects public and rely on difficult-to-guess object names
B.Create an IAM user in the company account and share the access keys
C.Create a bucket policy that grants the partner role least-privilege access to the required prefix
D.Copy the objects to a public website bucket
AnswerC

A bucket policy is a resource-based policy that can explicitly grant the partner's IAM role principal (e.g., 'arn:aws:iam::partner-account-id:role/PartnerReadOnlyRole') permission to call 's3:GetObject' on the 'reports/' prefix. By scoping the 'Resource' to 'arn:aws:s3:::your-bucket/reports/*' and optionally adding a condition such as 'aws:SourceArn' or 'ExternalId', you enforce least privilege without creating or distributing long-lived keys. This is the standard AWS pattern for granting cross-account read-only access to a limited S3 prefix.

Why this answer

It uses a resource-based bucket policy that grants the partner's IAM role (from their own AWS account) least-privilege read-only access to a specific prefix. This avoids sharing long-term credentials, follows the principle of cross-account access using IAM roles and bucket policies, and is fully scalable without managing external users.

Exam trap

The trap here is that candidates often choose Option B (sharing IAM user keys) because it seems simpler, but AWS recommends cross-account IAM roles for secure, temporary, and auditable access between accounts.

How to eliminate wrong answers

Option A is wrong because making objects public bypasses all access control and relies on security through obscurity (guessable object names), which is not secure or auditable. Option B is wrong because creating an IAM user in the company account and sharing access keys introduces long-term static credentials that must be rotated, shared securely, and managed, violating the principle of least privilege and creating a security risk. Option D is wrong because copying objects to a public website bucket exposes them to the internet without any access control, and it adds unnecessary data duplication and cost.

99
MCQeasy

Based on the exhibit, which EBS volume type should the team use to meet the performance need at lower cost than overprovisioning capacity?

A.Use gp3 and provision the needed IOPS independently of volume size.
B.Use sc1 because it is optimized for infrequent access and large objects.
C.Use st1 because it provides high throughput for streaming data.
D.Use standard magnetic storage because it is compatible with all EC2 instances.
AnswerA

gp3 is the best fit because it lets you provision IOPS and throughput separately from volume size. The exhibit shows the workload needs around 10,000 IOPS and experiences queue buildup on gp2. With gp3, the team can raise performance without unnecessarily increasing storage capacity, which is usually more cost-effective for this kind of database workload.

Why this answer

The team needs to meet performance requirements at lower cost than overprovisioning capacity. gp3 allows you to provision baseline performance of 3,000 IOPS and 125 MiB/s throughput for any volume size, and you can independently increase IOPS up to 16,000 and throughput up to 1,000 MiB/s without needing to increase volume size. This avoids the cost of overprovisioning large gp2 volumes to achieve higher IOPS, which are tied to volume size (3 IOPS per GiB).

Exam trap

The trap here is that candidates assume all EBS volume types require overprovisioning capacity to achieve higher IOPS, forgetting that gp3 decouples performance from size, making it the most cost-effective choice for workloads needing specific IOPS without large storage.

Why the other options are wrong

B

The question asks for lower cost than overprovisioning capacity, but sc1 is a cold HDD volume that cannot meet performance needs requiring IOPS independent of volume size; it has low IOPS and throughput limits unsuitable for consistent performance.

C

The question asks for a lower-cost solution than overprovisioning capacity, but st1 is a throughput-optimized HDD volume that requires provisioning storage to achieve baseline throughput, which can lead to overprovisioning. Additionally, the performance need likely involves IOPS, not just throughput, and st1 has low IOPS.

D

Standard magnetic storage (previous generation) does not offer the ability to provision IOPS independently of volume size, so it cannot meet the performance need at lower cost than overprovisioning capacity. It also lacks the performance and cost efficiency of gp3 for this use case.

When would these options actually be correct?

B

sc1 would be correct if the question described a workload with infrequent access, large sequential reads/writes, and cost minimization as the primary goal, such as a data warehouse for rarely accessed logs or backup storage where performance is not critical.

C

This option would be correct if the workload requires high sequential throughput (e.g., streaming data, big data, or log processing) and cost is a priority over IOPS. For example, a question asking for a cost-effective EBS volume for a data warehouse with large sequential reads.

D

Standard magnetic storage would be correct if the question specified a legacy application that requires compatibility with all EC2 instance types and has very low I/O performance requirements, where cost is the absolute priority and gp3/sc1/st1 are not options.

Why candidates pick the wrong answer

B

Candidates may see 'lower cost' and 'infrequent access' and assume sc1 is a cheap option, overlooking that the question's performance need requires provisioned IOPS, which sc1 cannot provide independently of volume size.

C

Candidates may confuse throughput with IOPS or assume that st1's high throughput is suitable for any performance need, overlooking the specific requirement to avoid overprovisioning capacity.

D

Candidates may think standard magnetic is universally compatible and cheap, overlooking that gp3 provides better performance at lower cost for most workloads, and that 'compatible with all EC2 instances' is not a performance or cost optimization criterion.

100
MCQmedium

Your company needs a high-throughput, low-latency TCP service using a custom binary protocol. Requirements: preserve the original client source IP for rate limiting, keep latency minimal, and use TCP health checks. The current setup uses an Application Load Balancer and performance is inconsistent. Which load balancer choice best meets these requirements?

A.Keep the Application Load Balancer (ALB), because ALBs also preserve client source IP for TCP protocols.
B.Use a Network Load Balancer (NLB) with TCP listeners so traffic stays at Layer 4 and the original source IP is preserved.
C.Use Amazon API Gateway because it preserves client source IP and provides TCP health checks for all protocols.
D.Use Amazon CloudFront with an S3 origin, because CloudFront reduces latency for TCP-based protocols.
AnswerB

NLB is designed for Layer 4 TCP/UDP traffic with very low latency and high throughput. It supports TCP health checks and preserves the original client source IP by default, which enables accurate client-IP-based rate limiting for a custom TCP protocol.

Why this answer

A Network Load Balancer (NLB) operates at Layer 4 and preserves the original client source IP by default, which is essential for accurate rate limiting. Its TCP listeners provide low-latency, high-throughput handling of custom binary protocols, and it supports TCP health checks natively. This directly addresses the performance inconsistency seen with the Application Load Balancer, which operates at Layer 7 and introduces additional processing overhead.

Exam trap

The trap here is that candidates often assume Application Load Balancers preserve client source IP for all protocols, but they only do so for HTTP/HTTPS traffic via the X-Forwarded-For header, not for raw TCP traffic, and they introduce higher latency due to Layer 7 processing.

How to eliminate wrong answers

Option A is wrong because an Application Load Balancer operates at Layer 7 (HTTP/HTTPS) and does not preserve the original client source IP for TCP traffic; it terminates the client connection and re-establishes a new one, so the source IP seen by the backend is the ALB's private IP. Option C is wrong because Amazon API Gateway is a fully managed service for creating RESTful and WebSocket APIs, not a load balancer; it does not support TCP listeners or TCP health checks, and it operates at Layer 7. Option D is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations, but it does not support TCP-based custom binary protocols (it works with HTTP/HTTPS and WebSocket) and cannot use an S3 origin for a TCP service; it also does not preserve the original client source IP for TCP traffic.

101
MCQmedium

A company runs an application behind an Application Load Balancer (ALB). An Auto Scaling group (ASG) is configured with desired capacity 2, but it is attached only to subnets in a single Availability Zone. The ALB is healthy because it is configured across multiple Availability Zones. When the Availability Zone that contains the ASG subnets experiences an outage, what change most directly improves resilience and allows capacity to be restored automatically?

A.Update the ASG to use subnet IDs that span at least two Availability Zones so it can launch replacement instances after an AZ outage.
B.Reduce the ALB health check interval to speed up detection of unhealthy targets.
C.Enable connection draining on the ALB so existing requests complete before targets are terminated.
D.Increase the ASG desired capacity from 2 to 6 to compensate for the missing subnets.
AnswerA

If the ASG is attached to subnets in multiple Availability Zones, when instances in the failed AZ become unhealthy/terminate, Auto Scaling can launch new instances in the remaining AZs to restore the desired capacity. This directly addresses the root cause: the ASG cannot create capacity outside the AZs it is configured for.

Why this answer

An Auto Scaling group (ASG) can only launch instances into the subnets explicitly assigned to it. If those subnets reside in a single Availability Zone (AZ) and that AZ fails, the ASG has no capacity to launch replacement instances, even though the ALB is multi-AZ. By configuring the ASG with subnet IDs spanning at least two AZs, the ASG can automatically launch instances in a healthy AZ, restoring capacity and resilience.

Exam trap

The trap here is that candidates assume a multi-AZ ALB automatically makes the entire architecture resilient, overlooking that the ASG must also be configured with subnets in multiple AZs to launch replacement instances after an AZ failure.

Why the other options are wrong

B

Reducing the ALB health check interval speeds up detection of unhealthy targets but does not address the root cause: the ASG is confined to a single AZ. Without instances in other AZs, the ASG cannot launch replacements during an AZ outage.

C

Connection draining helps complete in-flight requests before terminating instances, but it does not improve resilience or automatically restore capacity after an AZ outage. The issue is the ASG's lack of multi-AZ subnets, not request handling during termination.

D

Increasing desired capacity does not address the root cause: the ASG is confined to a single AZ. During an AZ outage, all instances in that AZ become unavailable, and the ASG cannot launch replacements because no subnets exist in other AZs. Higher desired capacity does not help if there are no subnets to launch into.

When would these options actually be correct?

B

This option would be correct in a scenario where the ASG already spans multiple AZs and the goal is to reduce recovery time after a failure. For example, an application requires faster failover to healthy instances, and the question asks how to minimize the time to mark instances as unhealthy.

C

In a scenario where an ALB is deregistering unhealthy targets and you need to ensure existing user sessions finish without interruption before the targets are terminated, enabling connection draining would be the correct answer.

D

In a scenario where the ASG already spans multiple AZs but experiences increased load, increasing desired capacity (e.g., from 2 to 6) would help handle the traffic and maintain performance. This would be correct if the question focused on scaling to meet demand rather than AZ failure recovery.

Why candidates pick the wrong answer

B

Candidates may think that faster health checks will automatically restore capacity by quickly detecting unhealthy instances, but they overlook that the ASG must have subnets in other AZs to launch replacements.

C

Candidates may confuse connection draining with a resilience feature, thinking it helps maintain availability during failures, when it actually only manages graceful termination of existing connections.

D

Candidates may think that adding more instances (higher desired capacity) provides a buffer against failures, but they overlook the fact that the ASG cannot launch instances in other AZs if it is only configured with subnets in one AZ. The temptation is to solve capacity issues with numbers rather than architectural redundancy.

102
Matchinghard

A company runs a stateless application tier behind an Application Load Balancer. Match each observed scaling pattern on the left to the best Auto Scaling strategy or metric on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Scale the Auto Scaling group on ALB RequestCountPerTarget.

Scale on SQS queue depth using a custom CloudWatch metric.

Use scheduled scaling to add capacity before the recurring surge.

Use target tracking on EC2 CPUUtilization.

Why these pairings

Steady increase is best handled by step scaling for gradual adjustments; sudden spikes use simple scaling for immediate action; cyclical patterns benefit from scheduled scaling; consistent low traffic may not need scaling; unpredictable bursts are managed by target tracking to maintain a metric; gradual decrease uses simple scaling to reduce capacity.

103
MCQmedium

An administrator needs the ability to read and update infrastructure for a specific AWS account, but only when using MFA. The security team wants to eliminate long-lived administrator access keys and ensure that even if someone obtains temporary session credentials, actions are only allowed with MFA present. Which IAM design best meets these requirements?

A.Create an IAM user for administrators with AdministratorAccess and require MFA only at the IAM user login.
B.Create an IAM role for administration and use a permissions policy that allows only the required read/write actions. Add a condition to deny all allowed actions unless aws:MultiFactorAuthPresent is true.
C.Attach policies to an IAM user that allow read/write actions and enable MFA in the account, but do not use condition keys in IAM policies.
D.Use a role with the correct actions but enforce MFA only in the application by prompting users for an OTP before every API call.
AnswerB

A role-based approach removes long-lived keys and supports temporary credentials. Using a permissions-policy condition to require MFA presence enforces that the session must have MFA to perform actions, aligning with the “actions only allowed with MFA present” requirement.

Why this answer

It uses an IAM role with a condition key `aws:MultiFactorAuthPresent` set to `true` to enforce MFA for all API calls made with temporary credentials. This eliminates long-lived access keys and ensures that even if temporary session credentials are compromised, actions are denied unless MFA was used during the session. The policy explicitly denies all allowed actions when MFA is not present, meeting the security team's requirement for MFA on every administrative action.

Exam trap

The trap here is that candidates often confuse requiring MFA at login (console) with enforcing MFA for all API calls, failing to realize that without a condition key in the IAM policy, access keys or temporary credentials can be used without MFA after the initial login.

Why the other options are wrong

A

Option A only requires MFA at login, but does not enforce MFA for API calls made with temporary credentials, allowing actions without MFA if session credentials are obtained.

C

This option does not use a condition key in IAM policies to require MFA for API calls, so temporary session credentials obtained without MFA could still perform actions. It only enforces MFA at login, not for subsequent API operations.

D

Enforcing MFA only at the application level (via OTP prompt) does not prevent actions taken through other means like AWS CLI or SDK, and does not use IAM condition keys to enforce MFA for all API calls, leaving a security gap.

When would these options actually be correct?

A

This option would be correct if the requirement was simply to require MFA for console access and the administrator uses long-lived access keys for programmatic access without needing MFA enforcement for API calls.

C

If the requirement were only to enforce MFA for console login (not for programmatic access or API calls), and long-lived access keys were acceptable, then attaching policies to an IAM user with MFA enabled at the account level would suffice.

D

If the requirement was to enforce MFA only for application-level API calls (e.g., a custom web app) and not for other AWS access methods, and the application already handles MFA separately, then this design could be acceptable.

Why candidates pick the wrong answer

A

Candidates may think that enabling MFA on the IAM user account globally protects all actions, not realizing that MFA at login does not extend to API calls made with access keys or temporary credentials.

C

Candidates may think that enabling MFA on the account or user automatically protects all actions, not realizing that IAM condition keys are needed to enforce MFA for API calls made with temporary credentials.

D

Candidates may think that application-level MFA enforcement is sufficient and simpler to implement, overlooking that IAM policies must enforce MFA at the API level to cover all access methods.

104
MCQhard

A logistics company runs an order-processing workload that reads messages from an Amazon SQS queue and writes results to an Amazon DynamoDB table. Occasionally the same order is processed twice and produces duplicate shipments. The architects must ensure each order is processed exactly once end to end, while keeping throughput as high as possible. What should they do?

A.Keep the SQS Standard queue and increase the visibility timeout to several hours.
B.Use an SQS FIFO queue with a message group ID per order and a DynamoDB conditional write on the order ID.
C.Enable DynamoDB Streams on the table and process changes with a second Lambda function.
D.Move the queue to Amazon SNS and subscribe a Lambda function to fan out the orders.
AnswerB

A FIFO queue with content-based deduplication and per-order message group IDs delivers each message once and preserves order within a group, while a DynamoDB conditional write using an order ID attribute rejects a second attempt even if a retry slips through. Together they provide exactly-once processing with high parallelism across order groups.

Why this answer

Exactly-once processing requires both a transport that deduplicates and orders messages per key, and an idempotent write at the destination. An SQS FIFO queue with per-order message group IDs provides the first, and a DynamoDB conditional write on the order ID provides the second, so retries cannot create duplicate shipments.

Exam trap

The trap here is assuming that a longer visibility timeout on a Standard queue eliminates duplicates, when Standard queues only guarantee at-least-once delivery.

105
MCQeasy

A company is deploying a new web application on AWS. The application will serve static content (HTML, CSS, JavaScript, images) and dynamic API requests. The company expects a global user base and wants to minimize latency for all users. The static content is stored in an Amazon S3 bucket, and the dynamic APIs are hosted on Amazon EC2 instances behind an Application Load Balancer. Which service should the company use to accelerate both static and dynamic content delivery?

A.Amazon Route 53 with latency-based routing to multiple Regions
B.Amazon CloudFront with the S3 bucket and ALB as origins
C.AWS Global Accelerator
D.AWS Direct Connect with a public virtual interface
AnswerB

Amazon CloudFront is a content delivery network that caches static content at edge locations and can also forward dynamic requests to the ALB origin. By configuring both the S3 bucket and the ALB as origins, CloudFront can serve static content from cache and dynamically route API calls, reducing latency for global users. This is the most effective solution for mixed content.

Why this answer

Amazon CloudFront is a global content delivery network that caches static content at edge locations and can also forward dynamic requests to an Application Load Balancer origin. By using CloudFront with both the S3 bucket and the ALB as origins, the company can accelerate delivery of static and dynamic content for a global user base, reducing latency and improving performance.

Exam trap

The trap here is confusing AWS Global Accelerator with a CDN; Global Accelerator does not cache content at the edge, so it is not the best choice for accelerating static content delivery.

106
MCQmedium

A SaaS vendor needs temporary access to an S3 bucket in your AWS account to read customer exports. The vendor will assume an IAM role you created. During integration testing, the vendor reports that their AssumeRole requests succeed, but your security team is concerned about the possibility of confused-deputy attacks. Which trust policy approach most directly mitigates this risk?

A.Add an sts:ExternalId condition to the role trust policy that must match the unique external ID you provide to the vendor.
B.Require the vendor to use the same MFA device serial number as your internal administrators in the trust policy.
C.Remove the role’s permissions policy and rely only on the S3 bucket policy to validate the caller.
D.Allow sts:AssumeRole from the vendor account root principal without restricting to the vendor’s specific IAM role.
AnswerA

The sts:ExternalId condition is a common protection against confused-deputy scenarios in cross-account role assumption. It ensures that only principals who know the unique external ID can successfully assume the role. This mitigates a third party tricking the vendor’s identity into assuming your role, even if they can call AssumeRole.

Why this answer

The `sts:ExternalId` condition in the trust policy forces the vendor to include a unique external ID in their `AssumeRole` API call. This prevents a confused-deputy attack by ensuring that the role can only be assumed when the caller provides the exact external ID you have pre-shared, thereby verifying the intended purpose of the cross-account access.

Exam trap

The trap here is that candidates may think MFA or bucket policies are sufficient for cross-account security, but the confused-deputy attack is specifically mitigated by the `sts:ExternalId` condition, not by authentication factors or resource-based policies alone.

Why the other options are wrong

B

Requiring the vendor to use the same MFA device serial number as your internal administrators is impractical and does not prevent confused-deputy attacks; the vendor cannot use your administrators' MFA device, and this condition does not tie the request to a specific external entity.

D

Allowing sts:AssumeRole from the vendor account root principal without restricting to the vendor’s specific IAM role does not mitigate confused-deputy attacks because any role or user in the vendor account can assume the role, increasing the risk of misuse.

When would these options actually be correct?

B

If the question were about ensuring that only authenticated users with a specific MFA device (e.g., a hardware token assigned to a known partner) can assume a role, and the vendor is able to use that device, then requiring the same MFA serial number in the trust policy would be correct.

D

In a scenario where the vendor account is fully trusted and the goal is to simplify access without needing to specify a particular role, allowing the root principal might be acceptable if the vendor account is controlled by the same organization or has strict internal controls.

Why candidates pick the wrong answer

B

Candidates may think that MFA adds a strong layer of authentication and assume it can prevent confused-deputy attacks, but they overlook that MFA does not provide a unique identifier for the external party's intent.

D

Candidates may think that allowing the root principal is simpler and still secure because the vendor account is trusted, overlooking the need for granularity to prevent confused-deputy attacks.

107
Multi-Selectmedium

A team runs a containerized API on Amazon ECS on Fargate in a single Region. Traffic is steady during business hours but drops to near zero overnight, and the team wants to reduce cost without rewriting the application. The team already uses Application Load Balancer and CloudWatch. Which two actions will reduce cost while keeping the API available? (Choose two.)

Select 2 answers
A.Reduce the Fargate task CPU and memory to the minimum supported values for all tasks regardless of load.
B.Use Fargate Spot capacity for a portion of the ECS tasks and keep a baseline of on-demand Fargate tasks behind the load balancer.
C.Switch the ECS service launch type to EC2 and purchase 3-year All Upfront Reserved Instances for the cluster.
D.Configure ECS Service Auto Scaling with a target tracking policy on ALB request count per target to scale tasks down overnight.
E.Enable ECS Exec on all tasks and remove the Application Load Balancer to save on ALB hourly charges.
AnswersB, D

Fargate Spot offers up to 70% lower cost for interruptible tasks, and mixing it with a small on-demand baseline preserves availability when Spot capacity is reclaimed. Because the API runs behind an ALB with multiple tasks, a reclaimed Spot task is replaced and traffic continues, making this a valid cost reduction.

Why this answer

Combining Fargate Spot for part of the fleet with a small on-demand baseline lowers the hourly compute rate while preserving availability, and target tracking on ALB request count per target shrinks the task count overnight so the service pays only for needed capacity. Together they reduce cost without rewriting the application and keep the API reachable through the load balancer.

Exam trap

The trap here is assuming Fargate has no Spot option or that scaling only adjusts tasks, when in fact Fargate Spot and Application Auto Scaling target tracking both reduce cost while keeping the service available.

108
MCQmedium

An engineering team runs application servers in private subnets. The instances must download patches and software packages from Amazon S3, but the company does not want the traffic to traverse the internet or a NAT gateway. Which design should they use?

A.Add an internet gateway to the VPC and route private subnet traffic through it.
B.Use an Amazon S3 gateway VPC endpoint in the route tables for the private subnets.
C.Use a security group rule that allows outbound traffic to the S3 public IP range.
D.Create a VPC peering connection to the S3 service VPC.
AnswerB

A gateway VPC endpoint for S3 keeps traffic between the VPC and S3 on the AWS network without using the public internet or a NAT gateway. This is the standard private-connectivity pattern for S3 access from private subnets. It also simplifies the architecture and reduces NAT-related cost while preserving access to the bucket from workloads that must remain nonpublic.

Why this answer

An S3 Gateway VPC endpoint allows instances in private subnets to access Amazon S3 without traversing the internet or a NAT gateway. The endpoint uses AWS’s internal network and is added to the route table of the private subnets, directing S3 traffic through the endpoint prefix list. This design meets the requirement of keeping traffic off the internet while providing secure, low-latency access to S3.

Exam trap

The trap here is that candidates often confuse Gateway VPC endpoints with Interface VPC endpoints, or mistakenly think that a security group rule alone can bypass the need for a routing path to the internet, when in fact routing decisions are made at the subnet route table level, not by security groups.

Why the other options are wrong

A

An internet gateway allows traffic to the internet, but the company explicitly does not want traffic to traverse the internet or a NAT gateway. Using an internet gateway would route traffic over the internet, violating the requirement.

D

VPC peering does not support transitive routing to AWS services like S3; S3 is not a VPC that can be peered with. Traffic would still need internet access or a gateway endpoint.

When would these options actually be correct?

A

If the requirement were to provide internet access to instances in private subnets (e.g., for general web downloads) and a NAT gateway was not allowed due to cost, but internet traffic was acceptable, then adding an internet gateway and routing private subnet traffic through it (with appropriate NAT) would be correct.

D

When connecting two separate VPCs (e.g., in different accounts or regions) to allow private IP communication between instances, such as for database replication or shared services, without using the internet or a VPN.

Why candidates pick the wrong answer

A

Candidates may think an internet gateway is the standard way to provide outbound internet access, overlooking the specific constraint that traffic must not traverse the internet.

D

Candidates may think VPC peering provides direct private connectivity to any AWS service, misunderstanding that peering only connects VPCs, not service endpoints.

109
MCQmedium

A financial analytics team stores sensitive customer data in an Amazon S3 bucket. The bucket uses SSE-KMS with a customer-managed key. Analysts access objects using an IAM role attached to an EC2 instance in a private subnet. The role has s3:GetObject permission on the bucket. However, analysts report AccessDenied errors when downloading objects. The KMS key policy currently grants full access to the account root user only. What is the most likely cause of the AccessDenied errors?

A.The IAM role lacks the kms:Decrypt permission on the customer-managed KMS key used for SSE-KMS.
B.The S3 bucket is configured with default encryption using SSE-S3, which conflicts with SSE-KMS and causes decryption failures.
C.The S3 bucket policy does not explicitly allow the IAM role to perform s3:GetObject.
D.The EC2 instance's security group does not allow outbound HTTPS traffic to the AWS KMS endpoint.
AnswerA

With SSE-KMS using a customer-managed key, the caller must have both s3:GetObject and kms:Decrypt on the key. The KMS key policy grants only the account root, so the EC2 role has no kms:Decrypt permission. Without it, S3 cannot decrypt the object for the caller, resulting in AccessDenied. Adding kms:Decrypt to the role or key policy resolves the issue.

Why this answer

Objects encrypted with SSE-KMS using a customer-managed key require the caller to have kms:Decrypt permission on that key. The EC2 role has s3:GetObject but no KMS permissions, and the key policy grants access only to the account root. S3 evaluates both the S3 and KMS permissions when serving the object.

Without kms:Decrypt, S3 returns AccessDenied even though the S3 permission is present.

Exam trap

The trap here is assuming that s3:GetObject alone is sufficient for reading SSE-KMS encrypted objects, overlooking the separate kms:Decrypt requirement.

110
MCQmedium

A global application experiences frequent writes and must survive a full Regional outage with near-zero data loss. The product team also requires that users can continue to write during the incident using the closest Region. Which approach is most aligned with these requirements?

A.Use an active/active design with multi-Region data replication (for example, global tables for the write-heavy datastore) and route traffic to multiple Regions based on health and latency.
B.Use warm standby with periodic backups of the primary write datastore every 24 hours.
C.Use pilot light where the secondary Region runs only infrastructure templates and starts data replication only after detecting failure.
D.Use a single-writer model in one Region and deploy read-only replicas in the other Region for continuity.
AnswerA

Active/active with multi-Region replication (such as DynamoDB global tables) allows writes to succeed in multiple AWS Regions simultaneously, ensuring near-zero RPO and immediate write availability during a Regional failure. Routing traffic by health and latency distributes load intelligently and automatically shifts users to the nearest healthy Region, which directly satisfies the global, write-heavy workload's requirement for continuous writes with minimal data loss.

Why this answer

An active/active design with multi-Region data replication, such as Amazon DynamoDB global tables, allows writes to occur in any Region and replicates them to all other Regions with near-real-time latency (typically sub-second). This meets the requirement for near-zero data loss during a full Regional outage, as data is asynchronously replicated to multiple Regions, and users can continue writing to the closest healthy Region via Route 53 latency-based or geolocation routing.

Exam trap

The trap here is that candidates often confuse 'multi-Region replication' with 'read replicas only' (Option D) or assume that periodic backups (Option B) provide sufficient durability, failing to recognize that near-zero data loss requires continuous asynchronous replication, not batch-based or on-demand replication.

Why the other options are wrong

B

This option does not meet the requirement for near-zero data loss during a full Regional outage, as backups every 24 hours could lose up to a day's worth of writes. It also fails to allow users to continue writing during the incident.

C

Pilot light does not support near-zero data loss because data replication starts only after failure detection, leading to potential data loss during the gap. It also does not allow writes during the incident as the secondary region is not active.

D

A single-writer model cannot survive a full Regional outage with near-zero data loss because writes are only accepted in the primary Region; if that Region fails, writes must stop until failover occurs, violating the requirement for continuous writes during the incident.

When would these options actually be correct?

B

This option would be correct for a non-critical application that can tolerate up to 24 hours of data loss and does not require write availability during a disaster. For example, a batch processing system where data is not time-sensitive and recovery time objective (RTO) is measured in hours.

C

A question requiring cost-effective disaster recovery with RPO of hours and RTO of minutes, where the primary region is expected to recover quickly and data loss of a few minutes is acceptable. For example: 'An application needs to recover from a regional failure within 30 minutes and can tolerate up to 1 hour of data loss.'

D

This option would be correct for a read-heavy application that requires strong consistency and can tolerate brief write interruptions during failover, with the primary goal of minimizing read latency in secondary Regions via read replicas.

Why candidates pick the wrong answer

B

Candidates may think periodic backups are sufficient for disaster recovery, underestimating the requirement for near-zero data loss and continuous write availability. They might also confuse backup frequency with replication.

C

Candidates may confuse pilot light with active/active designs, thinking that infrastructure templates imply rapid failover, but they overlook the replication delay and lack of write capability during the incident.

D

Candidates may think read replicas provide write continuity, but they are read-only; the single-writer model seems simpler and familiar from traditional database setups, overlooking the need for multi-Region write capability.

111
MCQmedium

A server assumes an IAM role and must read export objects only from this prefix in an S3 bucket: s3://customer-data/exports/acme/ . The application also needs to list the objects under that exact prefix so it can discover which export folders exist. The application performs ListBucket requests with Prefix set to exactly "exports/acme/". The current role policy allows s3:ListBucket on the bucket ARN without a prefix condition, and security reports the role can list other tenants’ export object keys. Which IAM policy change best enforces least privilege for both ListBucket and GetObject?

A.Keep s3:ListBucket allowed on arn:aws:s3:::customer-data, but restrict s3:GetObject to arn:aws:s3:::customer-data/exports/acme/*.
B.Allow s3:ListBucket on arn:aws:s3:::customer-data only when s3:prefix equals "exports/acme/" (for example, using a StringEquals condition on s3:prefix). Also allow s3:GetObject only on arn:aws:s3:::customer-data/exports/acme/*.
C.Allow s3:ListBucket only on arn:aws:s3:::customer-data/exports/acme/* and allow s3:GetObject on arn:aws:s3:::customer-data/*.
D.Add a Deny statement for s3:GetObject outside arn:aws:s3:::customer-data/exports/acme/*, but keep s3:ListBucket unrestricted on arn:aws:s3:::customer-data.
AnswerB

ListBucket must be authorized at the bucket ARN level, then scoped using a Condition on the request prefix (so only the approved listing prefix is allowed). GetObject is authorized at the object ARN level and is restricted to exports/acme/*, preventing reads outside the prefix.

Why this answer

It uses an s3:prefix condition with StringEquals on the ListBucket action to restrict listing to exactly 'exports/acme/', preventing the role from enumerating other tenants' objects. It also restricts GetObject to the same prefix using a resource ARN of arn:aws:s3:::customer-data/exports/acme/*, ensuring least privilege for both read operations. This combination enforces the principle of least privilege by scoping both actions to the specific tenant prefix.

Exam trap

The trap here is that candidates often confuse bucket-level actions (like s3:ListBucket) with object-level actions (like s3:GetObject), incorrectly applying resource ARNs with key prefixes to ListBucket, or forgetting that a condition on s3:prefix is required to scope listing to a specific prefix.

Why the other options are wrong

A

This option does not restrict s3:ListBucket to the specific prefix, so the role can still list objects under other prefixes (e.g., other tenants' exports), violating least privilege.

C

Option C incorrectly applies s3:ListBucket to an object ARN (arn:aws:s3:::customer-data/exports/acme/*), but ListBucket operates on bucket ARNs, not object ARNs. The condition on prefix must be specified via a condition key, not the resource ARN.

D

Option D does not restrict s3:ListBucket, so the role can still list objects under other prefixes (e.g., other tenants' exports), violating least privilege.

When would these options actually be correct?

A

If the application only needed to read objects under the prefix and did not require ListBucket at all, or if the ListBucket permission was granted via a separate policy that already enforced the prefix condition, then restricting only GetObject would be sufficient.

C

If the question required restricting both ListBucket and GetObject to a specific prefix using resource-based policies (e.g., bucket policy) where ListBucket can be scoped to a prefix via the resource element in some services, but in IAM policies for S3, ListBucket must target the bucket ARN and use condition keys.

D

If the requirement was to allow listing all objects in the bucket (e.g., for administrative purposes) but restrict GetObject to a specific prefix, then a Deny for GetObject outside that prefix combined with unrestricted ListBucket would be appropriate.

Why candidates pick the wrong answer

A

Candidates may focus on the GetObject restriction and overlook that ListBucket without a prefix condition still exposes object keys under other prefixes, assuming that restricting GetObject alone is enough to enforce least privilege.

C

Candidates mistakenly think that ListBucket can be scoped to a subdirectory by using an object ARN, similar to GetObject, not realizing that ListBucket always applies to the entire bucket and must use condition keys for prefix restriction.

D

Candidates may think that a Deny statement for GetObject is sufficient to prevent unauthorized reads, overlooking that ListBucket also exposes object keys, which is a security concern.

112
Multi-Selecthard

A genomics research team stores about 400 TB of compressed sequence files in Amazon S3 and runs a distributed analysis on Amazon EC2 instances in the same Region. The analysis reads each file sequentially and writes intermediate results to local instance storage. The team reports that the S3 GET requests are a bottleneck and wants to improve read throughput while keeping data durable. (Choose two.)

Select 2 answers
A.Prefix the object keys with a hash or random value to spread requests across multiple S3 partitions.
B.Use S3 byte-range fetches to retrieve each object in parallel parts across multiple threads or instances.
C.Mount the bucket with an S3 File Gateway and read the files over NFS from the EC2 fleet.
D.Enable S3 Versioning on the bucket so concurrent readers can access older object versions.
E.Configure the bucket for S3 Standard-Infrequent Access to lower the cost of frequent GET requests.
AnswersA, B

S3 scales request rates by partitioning an index by key prefix, and a hot prefix can throttle GET throughput. Distributing keys with a high-cardinality prefix spreads the load across many partitions, raising the request rate the bucket can sustain. This complements byte-range fetches and keeps objects durable in S3, directly improving the reported GET bottleneck.

Why this answer

S3 request performance is bounded by how well requests spread across the index partitions and by per-object concurrency. Randomizing key prefixes distributes GETs across many partitions so no single prefix throttles, and byte-range fetches let many threads or instances read one large object in parallel. Together they raise aggregate read throughput for the 400 TB analysis while the objects stay durable in S3.

Exam trap

The trap here is reaching for storage-class changes or gateway products to fix throughput, when the real levers are request distribution across partitions and parallel byte-range reads.

113
MCQeasy

An internal web application is exposed through an Application Load Balancer (ALB). The ALB currently has only an HTTP listener on port 80. Security requires that all client traffic be encrypted in transit. What is the best next step?

A.Enable S3 bucket encryption for application files, since it ensures encryption in transit.
B.Configure an ALB HTTPS listener on port 443 using an ACM certificate, and redirect HTTP (80) to HTTPS (443).
C.Turn on default encryption for CloudFront origin access, which automatically encrypts all ALB traffic.
D.Add KMS permissions to the ALB role so TLS is enabled automatically.
AnswerB

Configuring an HTTPS listener on the ALB with an ACM certificate terminates TLS at the load balancer, encrypting all traffic between clients and the ALB. The ACM certificate is validated and managed by AWS, and the listener negotiates a TLS connection using an appropriate security policy. Adding an HTTP-to-HTTPS redirect rule ensures that any request sent to port 80 is automatically sent over port 443, so every client is forced to use an encrypted connection. This directly meets the requirement for encrypting traffic in transit for the internal web application.

Why this answer

The requirement to encrypt all client traffic in transit is met by adding an HTTPS listener on port 443 using an ACM certificate, which enables TLS encryption. Additionally, configuring a redirect from HTTP (port 80) to HTTPS (port 443) ensures that any client attempting to connect over unencrypted HTTP is automatically upgraded to HTTPS, enforcing encryption for all traffic.

Exam trap

The trap here is that candidates often confuse encryption at rest (e.g., S3 bucket encryption) with encryption in transit, or assume that enabling KMS or CloudFront settings automatically secures ALB traffic without explicit listener configuration.

How to eliminate wrong answers

Option A is wrong because S3 bucket encryption (e.g., SSE-S3 or SSE-KMS) protects data at rest, not data in transit, and does not affect ALB traffic encryption. Option C is wrong because CloudFront default encryption refers to encrypting traffic between CloudFront and the origin (ALB), but it does not automatically encrypt client-to-ALB traffic; also, the question does not mention CloudFront being in use. Option D is wrong because KMS permissions on the ALB role are used for decrypting TLS private keys or for KMS-based certificate management, but they do not automatically enable TLS; the ALB must be explicitly configured with an HTTPS listener and a certificate.

114
MCQmedium

A company runs a batch processing job on Amazon EC2 instances that takes approximately 4 hours to complete. The job can be interrupted and resumed from a checkpoint. The company wants to minimize the cost of running this job. Which pricing model should they use?

A.Dedicated Hosts
B.Spot Instances
C.Reserved Instances
D.On-Demand Instances
AnswerB

Spot Instances offer the largest discounts (up to 90% off On-Demand) and are ideal for fault-tolerant, flexible workloads like batch processing that can be interrupted and resumed. Since the job checkpoints its progress, it can handle interruptions gracefully. Using Spot Instances directly addresses the cost minimization goal while accommodating the job's interruptible nature.

Why this answer

Spot Instances are the most cost-effective choice for interruptible batch jobs that can checkpoint and resume. They leverage spare EC2 capacity at steep discounts, and the job's design tolerates interruptions. Reserved and On-Demand pricing do not offer the same savings for this use case, and Dedicated Hosts are overkill.

Thus, Spot Instances align with both the workload characteristics and the cost objective.

Exam trap

The trap here is assuming that any batch job should use Reserved Instances for savings, overlooking that the job is interruptible and short-term, making Spot Instances the better fit.

115
MCQmedium

A high-volume telemetry pipeline writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate?

A.Amazon Kinesis Data Streams
B.AWS DataSync
C.Amazon EBS
D.Amazon Route 53
AnswerA

Kinesis Data Streams retains ordered records for a configurable period, letting multiple independent consumers read the same stream at their own pace via separate iterators. This satisfies the stem's requirement for parallel, independent processing of high-volume click events.

Why this answer

Amazon Kinesis Data Streams is the most appropriate service because it is designed for real-time streaming data ingestion and processing. It can capture and store terabytes of data per hour from hundreds of thousands of sources, such as click events, and allows multiple independent consumers to read and process the same stream concurrently using the Kinesis Client Library (KCL) or enhanced fan-out with dedicated throughput.

Exam trap

The trap here is that candidates may confuse Kinesis Data Streams with simpler messaging services like SQS or SNS, but the key differentiator is that Kinesis supports multiple independent consumers processing the same stream in real-time with replay capability, whereas SQS is designed for point-to-point message delivery and SNS for pub/sub with push-based fan-out.

How to eliminate wrong answers

Option B (AWS DataSync) is wrong because it is a data transfer service for moving large datasets between on-premises storage and AWS services, not for real-time streaming or multiple consumer processing. Option C (Amazon EBS) is wrong because it provides block-level storage volumes for EC2 instances, not a streaming data ingestion or processing capability. Option D (Amazon Route 53) is wrong because it is a DNS web service for domain name resolution and routing, not for handling streaming telemetry data.

116
MCQmedium

A data analytics team runs an Amazon EMR cluster for 2 hours every weekday morning to process a daily batch. The cluster must be fully available during that window, and the team wants the lowest possible compute cost. The jobs are stateless and can be re-run if a node fails. Which configuration should a solutions architect recommend?

A.Provision the EMR cluster entirely with Dedicated Hosts to guarantee physical isolation and predictable pricing.
B.Provision the EMR cluster with On-Demand Instances for the master node and Spot Instances for task nodes.
C.Provision the EMR cluster with On-Demand Instances for all node types and enable automatic scaling.
D.Provision the EMR cluster with Reserved Instances for a 3-year term to lock in the lowest hourly rate.
AnswerB

Using On-Demand for the master node keeps the cluster's control plane stable, while Spot Instances on task nodes can reduce compute cost because the stateless batch jobs can be re-run if a Spot node is reclaimed. This matches the SAA-C03 cost-optimization goal for transient, fault-tolerant analytics workloads.

Why this answer

The workload is a short, recurring, fault-tolerant batch job, so the best cost strategy is to combine a stable On-Demand master with Spot task nodes that can be reclaimed and restarted. This preserves cluster availability while taking advantage of Spot's lower pricing. Long-term commitments and Dedicated Hosts are poor fits because the compute is neither continuous nor compliance-driven.

Exam trap

The trap here is assuming any long-running or recurring workload automatically benefits from Reserved Instances, when short daily batch jobs are better served by Spot for fault-tolerant task nodes.

117
MCQmedium

A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers?

A.AWS WAF
B.Amazon CloudFront
C.Amazon SQS queue
D.Amazon Route 53 weighted routing
AnswerC

Amazon SQS is a distributed message queue that decouples the patient portal from the order-processing backend: the portal sends each order as a message, and SQS durably stores it across multiple Availability Zones until a consumer polls and processes it. During a burst, SQS absorbs the unprocessed messages, allowing the backend to scale out or catch up at its own pace rather than being overwhelmed. The visibility timeout prevents the same message from being processed by multiple workers, while a dead-letter queue captures any messages that fail repeatedly after a configured number of attempts. This buffering plus retry capability directly addresses the bursting workload described in the scenario.

Why this answer

Amazon SQS is the correct choice because it acts as a durable, highly available message buffer between the web tier and the fulfilment workers. It decouples the components, allowing the web tier to enqueue requests immediately without waiting for the downstream service, and the workers can poll and process messages at their own pace. SQS automatically retains messages for up to 14 days and supports retries via a dead-letter queue, ensuring no requests are lost even during spikes.

Exam trap

The trap here is that candidates may confuse a load-balancing or caching service (like CloudFront or Route 53) with a message queue, failing to recognize that only a queue provides durable, asynchronous decoupling and retry capability for request processing.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that filters HTTP/S traffic based on rules (e.g., SQL injection, XSS) and does not provide message buffering, retry logic, or decoupling for asynchronous processing. Option B is wrong because Amazon CloudFront is a content delivery network (CDN) that caches and accelerates static and dynamic content at edge locations; it cannot buffer or persist requests for downstream workers to process asynchronously. Option D is wrong because Route 53 weighted routing distributes DNS traffic across multiple endpoints based on weights, but it operates at the DNS level and cannot absorb spikes or retry failed requests; it provides no queueing or persistence.

118
MCQeasy

An engineering team deploys a stateless web API on EC2 using an Auto Scaling group and an Application Load Balancer (ALB). During a recent test, they noticed that when one Availability Zone was unavailable, traffic failed until new instances were manually launched. Which change most directly improves automatic failover for the compute layer within a single Region?

A.Place the Auto Scaling group in only one subnet so instance launches are simpler.
B.Ensure the ALB and Auto Scaling group span multiple subnets in at least two Availability Zones.
C.Increase the target group deregistration delay to allow old instances to stay longer.
D.Use a Network Load Balancer, but keep all subnets in a single Availability Zone.
AnswerB

An Application Load Balancer is a regional service that routes traffic to healthy targets across the Availability Zones it is enabled in. By spanning the ALB and Auto Scaling group across at least two AZs, an AZ failure leaves the remaining instances serving traffic while health checks automatically redirect requests away from the failed zone, preserving availability for the stateless web API. This aligns with AWS best practices for fault-tolerant multi-AZ architectures.

Why this answer

An Application Load Balancer (ALB) and Auto Scaling group must span multiple subnets in at least two Availability Zones (AZs) to provide automatic failover. When one AZ becomes unavailable, the ALB automatically reroutes traffic to healthy targets in the remaining AZs, and the Auto Scaling group can launch replacement instances in the surviving AZs. This architecture ensures that the compute layer remains available without manual intervention.

Exam trap

The trap here is that candidates often think a single-AZ deployment with a load balancer provides failover, but without multiple AZs, the load balancer itself becomes a single point of failure and cannot reroute traffic when the AZ goes down.

Why the other options are wrong

A

Placing the Auto Scaling group in only one subnet (single AZ) defeats the purpose of high availability; if that AZ fails, all instances are lost, and the ALB has no healthy targets in other AZs to route traffic to, causing complete failure.

C

Increasing the deregistration delay keeps old instances longer, but does not help automatically launch new instances in a healthy AZ when one AZ fails. It only delays connection draining, not failover.

D

Using a single Availability Zone for all subnets does not provide automatic failover; if that zone fails, the NLB and instances become unavailable, which does not solve the problem described.

When would these options actually be correct?

A

If the question asked for a cost-optimized design for a non-critical application where high availability is not required, and the goal is to simplify management and reduce cross-AZ data transfer costs, then using a single subnet would be appropriate.

C

This option would be correct in a scenario where the question asks how to ensure in-flight requests complete gracefully during a deployment or scaling event, without dropping connections. For example: 'An application requires that all active requests finish before instances are terminated during a rolling update. Which setting should be adjusted?'

D

When the requirement is to handle extremely high throughput and low latency for a TCP/UDP workload, and the application is designed to run in a single Availability Zone (e.g., due to data locality constraints), a Network Load Balancer in that zone would be the correct choice.

Why candidates pick the wrong answer

A

Candidates may think that simplifying subnet configuration reduces complexity and potential misconfigurations, overlooking that this eliminates fault tolerance and the ability to survive an AZ outage.

C

Candidates may think that keeping instances longer provides more time for failover, confusing connection draining with automatic recovery. They overlook that the core issue is lack of multi-AZ redundancy, not connection timeout.

D

Candidates may think that a Network Load Balancer inherently provides better failover than an ALB, but failover depends on multi-AZ architecture, not the load balancer type.

119
Multi-Selecthard

A payments API requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The team wants the control to be enforceable during normal operations.

Select 2 answers
A.Deletion protection or tightly controlled delete permissions
B.Point-in-time recovery
C.Global secondary indexes
D.DAX
AnswersA, B

Deletion protection on DynamoDB tables is a table-level setting that blocks delete table operations via the API, console, or SDK, while tightly controlled IAM permissions ensure only authorized principals can execute destructive actions. Together they create a robust defense-in-depth mechanism that directly mitigates the risk of accidental table removal. This is a required control for a payments API because losing the entire table would be catastrophic, even if backups exist.

Why this answer

Deletion protection (Option A) prevents accidental table deletion by blocking drop-table operations, which is enforceable during normal operations. Point-in-time recovery (Option B) enables continuous backups with 35-day granularity, allowing restoration to any second within that window. Together, they satisfy the requirements for accidental-delete protection and point-in-time recovery.

Exam trap

The trap here is that candidates often confuse point-in-time recovery with backup solutions like AWS Backup or assume that GSIs or DAX provide data protection, when in fact they serve entirely different purposes (performance optimization and caching).

120
MCQmedium

A CI/CD system creates an IAM role (CICDRole) used for deployments. Your organization uses IAM permission boundaries to prevent developers from granting themselves higher privileges. After an incident, you discover that CICDRole can perform unintended IAM actions because the role’s identity policy includes broad permissions. Which change most directly ensures permission boundaries continue to restrict CICDRole regardless of what is later added to the role’s identity policies?

A.Remove the permission boundary from CICDRole so that only the identity policy controls access.
B.Ensure CICDRole is created with the required permissions boundary ARN, and verify that the boundary policy does not allow the unintended IAM actions.
C.Add an identity-policy deny for iam:CreatePolicy and iam:UpdateRole on all resources.
D.Rely on CloudTrail alerts to stop deployments from performing IAM changes after the fact.
AnswerB

Permission boundaries cap the maximum effective permissions for the role by intersecting the identity policy and the permissions boundary at authorization time. Even if the identity policy later expands, the boundary still prevents actions not allowed by the boundary policy, providing deterministic enforcement against privilege escalation.

Why this answer

IAM permission boundaries define the maximum permissions that an IAM role can have, regardless of what is later added to its identity-based policies. By ensuring CICDRole is created with a permission boundary that explicitly denies the unintended IAM actions, even if broad permissions are added to the role's identity policy, the boundary will override and restrict those actions. This directly addresses the requirement to prevent privilege escalation through policy modifications.

Exam trap

The trap here is that candidates often think adding deny statements to the identity policy is sufficient, but they overlook that permission boundaries are the only mechanism that can restrict permissions added later, and that deny statements in the identity policy can be overridden by a broader allow if not carefully scoped.

How to eliminate wrong answers

Option A is wrong because removing the permission boundary eliminates the only mechanism that caps the role's maximum permissions, allowing any broad identity policy to grant unintended IAM actions without restriction. Option C is wrong because adding a deny for iam:CreatePolicy and iam:UpdateRole does not prevent the role from using other IAM actions like iam:PassRole or iam:AttachRolePolicy that could still lead to privilege escalation; it is an incomplete fix that does not address the root cause of broad permissions. Option D is wrong because relying on CloudTrail alerts is a detective control, not a preventive one; it only notifies after the fact, allowing unauthorized IAM actions to occur before any response can be taken.

121
MCQmedium

A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load?

A.Amazon Kinesis Data Firehose
B.S3 Transfer Acceleration
C.DynamoDB Accelerator (DAX)
D.AWS Glue Data Catalog
AnswerC

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache designed specifically for Amazon DynamoDB, delivering microsecond response times for repeated reads. When the document portal queries the same product key frequently, DAX serves subsequent identical queries from memory, drastically reducing read latency and offloading read capacity units from the table. It integrates seamlessly with the DynamoDB API, requiring only an endpoint change, and is the correct solution for this read-heavy, hot-key access pattern.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache for Amazon DynamoDB that delivers up to 10x read performance improvement by caching frequently accessed data. For a read-heavy workload querying the same product catalogue data, DAX reduces read latency to microseconds and offloads read requests from the DynamoDB table, lowering consumed read capacity units and table load.

Exam trap

The trap here is that candidates often confuse caching services (DAX) with data transfer acceleration (S3 Transfer Acceleration) or data ingestion (Kinesis Data Firehose), failing to recognize that the core requirement is to reduce DynamoDB read latency and table load, which only a dedicated in-memory cache like DAX can achieve.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis Data Firehose is a streaming data ingestion service for loading data into data stores or analytics tools, not a caching layer for DynamoDB read operations. Option B is wrong because S3 Transfer Acceleration speeds up uploads and downloads to Amazon S3 over long distances using AWS edge locations, but it does not cache DynamoDB data or reduce read latency for DynamoDB queries. Option D is wrong because AWS Glue Data Catalog is a metadata repository for data assets used in ETL and analytics, not a cache for DynamoDB read requests.

122
MCQmedium

A healthcare company runs a containerized claims-processing service on Amazon ECS with the Fargate launch type in a single AWS Region. The service must survive the loss of an entire Availability Zone with no manual intervention, and the architecture must keep the same service endpoint for callers. The service is fronted by an Application Load Balancer. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

A.Deploy the ECS tasks on Amazon EC2 launch type instances in an Auto Scaling group that spans one Availability Zone, and attach an Elastic Load Balancer health check to the group.
B.Create a second ECS service in a different AWS Region and use an Amazon Route 53 latency-based routing policy with health checks to send traffic to the Regional Application Load Balancers.
C.Increase the ECS task CPU and memory reservation so each task can absorb the load of a failed Availability Zone, and enable container health checks in the task definition.
D.Configure the ECS service with a desired count of at least two tasks and use the spread placement strategy across the subnets of multiple Availability Zones, then register those subnets with the Application Load Balancer.
AnswerD

Spreading ECS tasks across subnets in multiple Availability Zones with a desired count of two or more means the loss of one Availability Zone leaves running tasks in the remaining zones, and the Application Load Balancer health checks route traffic only to healthy targets. The ALB DNS name stays constant, so callers need no changes and no manual failover step is required.

Why this answer

Resilience to an Availability Zone failure requires capacity to exist in more than one zone simultaneously. An ECS service with a desired count of two or more and the spread placement strategy across multiple Availability Zone subnets keeps tasks running elsewhere when one zone fails, and the Application Load Balancer automatically stops routing to unhealthy targets while preserving a stable DNS endpoint.

Exam trap

The trap here is assuming that scaling up a single task's CPU and memory provides high availability, when resilience against an Availability Zone failure requires additional task replicas placed in separate zones.

123
MCQhard

A claims workflow uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure?

A.A FIFO queue without a redrive policy
B.Short polling instead of long polling
C.A dead-letter queue with an appropriate maxReceiveCount
D.A larger message retention period only
AnswerC

A dead-letter queue (DLQ) paired with a redrive policy that sets a specific maxReceiveCount (for example, 5) is the correct solution. When a message is received from the source queue more times than the configured limit without being deleted, SQS automatically moves the message to the DLQ. This quarantines unfixable messages so they can be analyzed or replayed later, preventing them from consuming worker instances and blocking normal workflow processing.

Why this answer

A dead-letter queue (DLQ) with an appropriate maxReceiveCount allows messages that repeatedly fail processing to be moved out of the source queue after a specified number of receive attempts. This prevents poison messages from blocking the queue and consuming retry capacity, enabling the workflow to continue processing valid messages without interruption.

Exam trap

The trap here is that candidates often confuse increasing the retention period or changing polling behavior with solving poison message issues, when the correct solution is to use a dead-letter queue with a maxReceiveCount to isolate failing messages.

How to eliminate wrong answers

Option A is wrong because a FIFO queue without a redrive policy does not automatically handle poison messages; without a DLQ, failed messages remain in the queue and continue to block retries. Option B is wrong because short polling reduces latency but does not address the issue of poison messages; it returns fewer messages per request and can increase costs, but it does not prevent repeated failures. Option D is wrong because increasing the message retention period only keeps messages in the queue longer; it does not remove or isolate poison messages, so they will continue to fail and block useful retries.

124
MCQmedium

A company has a steady-state workload on Amazon EC2 that runs 24/7 for the next 3 years. They want to achieve the maximum possible discount and are willing to make a upfront payment. Which purchasing option should they choose?

A.Reserved Instances with All Upfront payment
B.On-Demand Instances
C.Spot Instances
D.Dedicated Hosts with All Upfront payment
AnswerA

Reserved Instances with All Upfront payment provide the highest discount (up to 72% off On-Demand) for a 1- or 3-year commitment. By paying the entire amount upfront, the company maximizes savings. This option is ideal for steady-state workloads where the instance type and region are known, and the company is willing to commit for 3 years.

Why this answer

Reserved Instances with All Upfront payment offer the maximum discount for a 3-year commitment on a steady-state workload. This option provides significant savings over On-Demand and is more reliable than Spot. Dedicated Hosts are not cost-optimized for general workloads.

Therefore, All Upfront Reserved Instances are the best choice for maximum discount.

Exam trap

The trap here is assuming that Spot Instances always provide the greatest discount, but they are unsuitable for workloads that cannot tolerate interruptions, such as a 24/7 steady-state service.

125
MCQmedium

An orders service publishes payment instructions to an Amazon SQS queue. After occasional processing timeouts, the downstream consumer sometimes processes the same instruction twice, resulting in duplicate payment attempts. The team currently uses an SQS Standard queue with a visibility timeout of 2 minutes and relies on the consumer to finish before the timeout expires. What approach best improves resilience against duplicate processing?

A.Decrease visibility timeout to 10 seconds so duplicates are less likely to occur.
B.Make the consumer idempotent using the order ID as a deduplication key, and set the visibility timeout longer than the worst-case processing time.
C.Use an EventBridge rule with a fixed retry policy that only retries when the payload matches exactly.
D.Enable a dead-letter queue (DLQ) only, without changing the queue type or consumer logic.
AnswerB

SQS Standard provides at-least-once delivery, so duplicates can still occur. The most resilient design is to make the payment handler idempotent so repeated deliveries do not create duplicate side effects, and to set the visibility timeout long enough to cover the worst-case processing time to reduce unnecessary re-delivery.

Why this answer

Making the consumer idempotent using the order ID as a deduplication key ensures that even if the same message is processed multiple times, the downstream system will only apply the payment once. Setting the visibility timeout longer than the worst-case processing time prevents the message from becoming visible again before the consumer finishes, eliminating the root cause of duplicate processing in a Standard queue.

Exam trap

The trap here is that candidates often think reducing the visibility timeout or adding a DLQ alone solves duplicates, but they overlook that Standard queues inherently allow at-least-once delivery, so idempotency is the only reliable solution.

How to eliminate wrong answers

Option A is wrong because decreasing the visibility timeout to 10 seconds would increase the likelihood of duplicates by making the message reappear sooner if the consumer takes longer than 10 seconds, exacerbating the timeout issue. Option C is wrong because an EventBridge rule with a fixed retry policy does not address duplicate processing; EventBridge is a event bus service, not a queue, and its retry policy cannot prevent duplicate delivery from SQS. Option D is wrong because enabling only a DLQ without changing the queue type or consumer logic does not prevent duplicates; a DLQ captures failed messages but does not make the consumer idempotent or adjust visibility timeout to avoid reprocessing.

126
MCQmedium

Based on the exhibit, why is the IAM role still receiving AccessDenied even though it has AdministratorAccess attached?

A.AdministratorAccess is always evaluated before SCPs, so the SCP is ignored in production accounts.
B.The SCP is acting as a maximum permission guardrail, so its explicit deny overrides the IAM allow.
C.The role needs a session duration of at least 12 hours before SCPs stop applying.
D.The account needs an AWS Config rule to approve the snapshot action before IAM can work.
AnswerB

SCPs set the outer boundary for permissions in an account or OU. They do not grant access, but they can block actions even when the IAM role has AdministratorAccess. The explicit deny in the SCP is therefore the reason CreateSnapshot fails. To allow the operation, the organization must change the SCP or move the account out of the restrictive scope.

Why this answer

B is correct because Service Control Policies (SCPs) act as a maximum permission guardrail in AWS Organizations. Even if an IAM role has the AdministratorAccess policy attached, an SCP with an explicit deny on the ec2:CreateSnapshot action will override that allow, resulting in an AccessDenied error. SCPs are evaluated after IAM policies, and an explicit deny in an SCP cannot be overridden by any IAM allow.

Exam trap

The trap here is that candidates often assume AdministratorAccess grants full permissions unconditionally, forgetting that SCPs can impose a higher-level deny that overrides any IAM allow, especially in AWS Organizations.

Why the other options are wrong

A

SCPs are evaluated before IAM policies and can explicitly deny actions, overriding any IAM allow, including AdministratorAccess. The statement that AdministratorAccess is always evaluated before SCPs is incorrect.

C

Session duration does not affect SCP evaluation; SCPs apply to all principals regardless of session length. The AccessDenied is due to an SCP explicitly denying the action, not a session duration issue.

D

AWS Config rules can trigger remediation actions or evaluate compliance, but they do not grant or deny IAM permissions. The AccessDenied error is caused by an SCP explicit deny, not by the absence of a Config rule.

When would these options actually be correct?

A

This option would be correct if the question described a scenario where an SCP allows an action but an IAM policy denies it, and the question asks about evaluation order. In that case, IAM deny overrides SCP allow, so AdministratorAccess (IAM allow) would not be evaluated before the SCP deny.

C

If a question described a role that assumes a long-running session and the error is 'Session token expired' or 'AccessDenied' due to temporary credentials timing out, then increasing session duration (e.g., to 12 hours) would resolve it.

D

In a scenario where an IAM role is allowed by an SCP but still denied access to a specific resource, and the question states that AWS Config rules are used to enforce compliance by automatically revoking permissions via a custom Lambda function, then D could be correct if the Config rule is misconfigured or not triggering the remediation.

Why candidates pick the wrong answer

A

Candidates may confuse the evaluation order of IAM policies and SCPs, mistakenly thinking that IAM policies are always evaluated first or that AdministratorAccess is an exception to SCPs.

C

Candidates may confuse session duration limits with SCP evaluation, thinking that longer sessions bypass SCPs, or they may misremember that SCPs only apply to short-lived sessions.

D

Candidates may confuse AWS Config's compliance evaluation with IAM authorization, thinking that Config rules act as a gatekeeper for API actions, similar to how SCPs or resource-based policies work.

127
MCQhard

Based on the exhibit, which change best reduces latency during peak traffic without overprovisioning the fleet?

A.Replace the instances with a larger instance family so each server has more headroom.
B.Change the Auto Scaling policy to target tracking on ALB RequestCountPerTarget.
C.Use scheduled scaling to add instances only during the business hours peak window.
D.Replace the ALB with a Network Load Balancer to reduce request latency.
AnswerB

RequestCountPerTarget matches the actual demand reaching each instance and scales capacity before the thread pool saturates. Because CPU is still low, CPU-based scaling would react too late or not at all. Target tracking on request count helps keep queue depth and latency down while avoiding unnecessary overprovisioning during quieter periods.

Why this answer

Using a target tracking scaling policy on ALB RequestCountPerTarget dynamically adjusts the fleet size based on the actual load per instance, ensuring that capacity scales with demand during peak traffic without manual intervention or overprovisioning. This approach directly addresses latency caused by high request rates per instance by maintaining a target request count, which reduces response time without adding unnecessary instances during off-peak periods.

Exam trap

The trap here is that candidates confuse 'reducing latency' with 'improving network throughput' (Option D) or 'static capacity increases' (Option A), missing that dynamic scaling based on per-target request count directly addresses the latency caused by overloaded instances during peak traffic.

How to eliminate wrong answers

Option A is wrong because simply replacing instances with a larger family increases per-instance capacity but does not automatically scale the fleet; it leads to overprovisioning during low traffic and fails to adapt to variable peak loads, wasting cost and not reducing latency efficiently. Option C is wrong because scheduled scaling adds instances only during a fixed business hours window, which cannot handle unpredictable peak traffic spikes outside that window, leaving the fleet either under-provisioned or over-provisioned. Option D is wrong because replacing the ALB with a Network Load Balancer (NLB) reduces transport-layer latency but does not address the root cause of latency—high request load per target—and NLB lacks the application-layer metrics (like RequestCountPerTarget) needed for intelligent Auto Scaling based on request volume.

128
MCQhard

A healthcare company stores protected health information in an Amazon S3 bucket. Auditors require that every object be encrypted with a customer managed AWS KMS key, that key rotation be controlled by the company, and that the company be able to revoke access to the data immediately by disabling the key. Which encryption configuration meets these requirements?

A.Client-side encryption with a data key stored in the application configuration file.
B.SSE-S3 with bucket versioning enabled and S3 Object Lock in compliance mode.
C.SSE-KMS with a customer managed key in AWS KMS, with automatic key rotation enabled.
D.SSE-KMS with an AWS managed key (aws/s3) and automatic annual rotation enabled.
AnswerC

A customer managed key in AWS KMS gives the company control over the key policy, rotation settings, and key state. Enabling automatic rotation rotates the backing key material annually while retaining the same key ID, and disabling the key immediately prevents new decrypt operations, satisfying both the rotation and revocation requirements.

Why this answer

Using SSE-KMS with a customer managed key lets the company define the key policy, enable automatic rotation, and disable the key to immediately block decryption. AWS managed keys cannot be disabled or rotated on a company-defined schedule, and SSE-S3 keys are fully managed by AWS, so neither provides the required control or revocation capability.

Exam trap

The trap here is treating automatic rotation of an AWS managed key as equivalent to customer-controlled rotation and revocation.

129
MCQmedium

A backend service in AWS uses an IAM role to upload large files to an S3 bucket using multipart upload. The upload typically succeeds, but it intermittently fails during cleanup with this error: "AccessDenied: User is not authorized to perform: s3:AbortMultipartUpload" The role identity policy currently allows only: - s3:PutObject on arn:aws:s3:::my-bucket/uploads/* - s3:ListBucket on arn:aws:s3:::my-bucket with a prefix condition What is the best least-privilege change to fix the cleanup failure?

A.Add s3:AbortMultipartUpload for arn:aws:s3:::my-bucket/uploads/*.
B.Add s3:AbortMultipartUpload for arn:aws:s3:::my-bucket/*.
C.Add s3:ListBucket for arn:aws:s3:::my-bucket/uploads/* so the service can find parts to abort.
D.Add kms:Decrypt permissions for the KMS key used to encrypt objects in the bucket.
AnswerA

For multipart uploads, S3 clients use s3:AbortMultipartUpload to stop/cleanup an in-progress multipart upload (for example, when an upload fails or the client cancels). Granting s3:AbortMultipartUpload only on the uploads prefix matches the denied API in the symptom and keeps the permission scoped to the exact objects the service uploads.

Why this answer

The error occurs because the IAM role lacks permission to abort multipart uploads. Multipart uploads in S3 require s3:AbortMultipartUpload to clean up incomplete upload parts after a failure or interruption. Option A grants this permission on the specific uploads/* prefix, which is the least-privilege fix because it scopes the action to the exact path where the service uploads files.

Exam trap

The trap here is that candidates may confuse the need for s3:AbortMultipartUpload with other permissions like s3:ListBucket or KMS actions, or they may over-scope the permission to the entire bucket instead of the specific prefix.

How to eliminate wrong answers

Option B is wrong because it grants s3:AbortMultipartUpload on the entire bucket (/*), which is broader than necessary and violates least-privilege principles. Option C is wrong because s3:ListBucket is already allowed with a prefix condition; adding it again does not grant the missing abort permission, and listing parts requires s3:ListMultipartUploadParts, not s3:ListBucket. Option D is wrong because the error is an S3 access denied, not a KMS permission issue; KMS permissions are needed for encrypting/decrypting objects, not for aborting multipart uploads.

130
Multi-Selecthard

A healthcare company stores 80 TB of medical imaging data in Amazon S3. The data is written once and must be retained for seven years for compliance. New images are accessed frequently for the first 30 days, then almost never after that, but auditors occasionally request a specific image with no advance notice and expect it within minutes. The company wants to minimize storage cost while meeting the retrieval requirement. Which two actions should a solutions architect recommend? (Choose two.)

Select 2 answers
A.Configure an S3 Lifecycle policy to transition objects to S3 Glacier Instant Retrieval after 30 days.
B.Enable S3 Versioning on the bucket to protect the imaging data from accidental deletion.
C.Add an S3 Object Lock retention policy in compliance mode for seven years.
D.Configure an S3 Lifecycle policy to transition objects to S3 Glacier Deep Archive after 30 days.
E.Configure an S3 Lifecycle policy to transition objects to S3 Standard-IA after 30 days.
AnswersA, C

S3 Glacier Instant Retrieval is designed for long-lived, rarely accessed data that still needs millisecond retrieval. It costs significantly less than S3 Standard-IA for storage while meeting the auditors' requirement to fetch any image within minutes. This aligns storage cost with the access pattern over the seven-year retention period.

Why this answer

Transitioning to S3 Glacier Instant Retrieval after 30 days matches the long-term, rarely accessed pattern while preserving millisecond retrieval for auditor requests, which keeps storage cost low. Adding a seven-year compliance-mode Object Lock enforces the regulatory retention mandate. Together these actions satisfy both the cost and compliance requirements without compromising retrieval speed.

Exam trap

The trap here is choosing the cheapest archive tier or a versioning control, when the retrieval-time requirement eliminates Deep Archive and the retention mandate calls for Object Lock.

131
MCQmedium

A production internal reporting portal runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy?

A.Spot Instances only
B.Dedicated Instances
C.Compute Savings Plan
D.S3 Intelligent-Tiering
AnswerC

A Compute Savings Plan is the most cost-effective option because it provides a significant discount (up to 66% versus On-Demand) in exchange for a one- or three-year hourly spend commitment, while allowing flexibility across instance families, sizes, availability zones, regions, and even compute services like Lambda and Fargate. For a production portal that runs continuously, the predictable, always-on usage justifies the commitment, and the plan automatically applies to any EC2 instance usage without needing specific instance configurations.

Why this answer

A Compute Savings Plan offers the lowest prices on EC2 usage (up to 66% off On-Demand) in exchange for a 1- or 3-year commitment, and it automatically applies to any EC2 instance family in any region, giving the flexibility the team needs. Since the workload runs continuously with predictable usage for three years, this plan is ideal for reducing costs while retaining the ability to change instance families if needed.

Exam trap

The trap here is that candidates often confuse Compute Savings Plans with EC2 Instance Savings Plans, assuming any Savings Plan locks you to a specific instance family, but Compute Savings Plans provide broader flexibility across families and services.

How to eliminate wrong answers

Option A is wrong because Spot Instances are designed for fault-tolerant, interruptible workloads and can be terminated with a 2-minute notice, making them unsuitable for a continuously running production reporting portal. Option B is wrong because Dedicated Instances are physically isolated at the host hardware level and billed per instance, which does not inherently provide a discount and lacks the instance-family flexibility of a Savings Plan. Option D is wrong because S3 Intelligent-Tiering is a storage class for objects with changing access patterns, not a compute pricing model, and cannot be applied to EC2 instances.

132
MCQmedium

An orders system sends payment instructions to an Amazon SQS queue. The consumer sometimes times out after it has already created the payment record but before it deletes the SQS message. As a result, the same instruction can be processed more than once. Which design best ensures the consumer remains resilient and does not create duplicate payments when the same instruction is delivered multiple times?

A.Assume the consumer will always delete the SQS message in the same execution path, and ignore the timeout case.
B.Use idempotency: store a deterministic payment request identifier in a DynamoDB table and only create a payment when a conditional write indicates it was not processed before.
C.Switch to SQS Standard because it provides exactly-once delivery, so duplicates cannot happen.
D.Increase the consumer timeout and reduce the number of retries so that duplicates rarely occur.
AnswerB

Implementing idempotency with a DynamoDB table keyed by a deterministic payment request ID (for example, an MD5/SHA-256 hash of the order ID, amount, and currency) lets a consumer use a conditional PutItem with ConditionExpression 'attribute_not_exists(id)'. A successful conditional write claims the ID for the first request; a failed write on retry tells the consumer the payment was already handled, so no charge is created again. This turns at-least-once SQS delivery into effectively exactly-once processing because duplicate messages either see the existing record or lose the race to create it, and the payment action is triggered only on the first successful claim.

Why this answer

It implements idempotency using a DynamoDB table with a conditional write. By storing a deterministic payment request identifier (e.g., a hash of the message body) and only creating the payment if the conditional write succeeds (i.e., the identifier does not already exist), the consumer can safely process the same SQS message multiple times without creating duplicate payments. This pattern ensures resilience against the at-least-once delivery semantics of SQS and consumer timeouts that prevent message deletion.

Exam trap

The trap here is that candidates assume SQS FIFO queues provide exactly-once delivery, but the question specifies an SQS queue (likely Standard), and even FIFO queues only guarantee exactly-once processing within a limited deduplication window, not absolute idempotency; the correct solution is to make the consumer itself idempotent.

How to eliminate wrong answers

Option A is wrong because ignoring the timeout case violates the principle of designing for failure; SQS guarantees at-least-once delivery, and timeouts are a real-world occurrence that must be handled explicitly. Option C is wrong because SQS Standard does not provide exactly-once delivery; it offers at-least-once delivery, and duplicates can still occur due to network retries or consumer failures. Option D is wrong because increasing the consumer timeout and reducing retries only reduces the probability of duplicates but does not eliminate them, and it does not address the fundamental issue of at-least-once delivery semantics.

133
MCQmedium

A company runs an application in private subnets (no inbound internet). The application must access Amazon S3 and AWS Secrets Manager endpoints without routing through the public internet and without exposing the instances to NAT gateways due to cost. Security requirements also state that only the required VPC traffic should be allowed to reach AWS services. Which architecture best satisfies these requirements?

A.Place instances in private subnets but use NAT gateways so traffic to S3 and Secrets Manager goes through the internet; restrict security groups to instance-to-instance only.
B.Add a VPC gateway endpoint for S3 and an interface VPC endpoint for Secrets Manager; keep instances in private subnets and configure security group rules attached to the endpoints to allow inbound traffic only from the application subnets.
C.Use public subnets with instances that have no security group rules; rely on AWS services to reject unauthorized traffic.
D.Create an S3 bucket policy that allows requests from the application instances’ private IP addresses and enable public access to Secrets Manager via the default service endpoint.
AnswerB

Gateway endpoints provide private routing to S3, and interface endpoints provide private access to Secrets Manager without internet traversal. Security group controls on interface endpoints restrict traffic to only the application subnets, meeting segmentation and cost constraints.

Why this answer

It uses a VPC gateway endpoint for S3 and an interface VPC endpoint for Secrets Manager, both of which allow private subnet instances to access these AWS services without traversing the public internet or requiring a NAT gateway. The security group rules attached to the interface endpoint restrict inbound traffic to only the application subnets, satisfying the security requirement of allowing only required VPC traffic. This architecture avoids NAT gateway costs and keeps instances isolated from inbound internet traffic.

Exam trap

The trap here is that candidates may assume all AWS service endpoints require a NAT gateway or internet gateway for private subnet access, overlooking the cost-effective and secure alternative of VPC endpoints (gateway and interface) that keep traffic within the AWS network.

Why the other options are wrong

A

NAT gateways route traffic through the public internet, violating the requirement to avoid public internet and incurring additional cost, which the question explicitly wants to avoid.

C

Using public subnets without security groups exposes instances to inbound internet traffic, violating the requirement to avoid public internet and the security rule that only required VPC traffic should be allowed to reach AWS services.

D

Option D is wrong because enabling public access to Secrets Manager via the default service endpoint would expose the service to the internet, violating the requirement to avoid routing through the public internet and the security requirement to allow only required VPC traffic.

When would these options actually be correct?

A

If the question required internet access for other purposes (e.g., software updates) and cost was not a constraint, using NAT gateways in private subnets would be appropriate for outbound traffic to AWS services.

C

If the question required a simple, low-security setup for a non-production environment where instances need unrestricted outbound internet access and cost is the only concern, public subnets with no security groups might be acceptable.

D

This option would be correct in a scenario where the application instances have public IPs and the requirement is to restrict access to S3 and Secrets Manager based on source IP addresses, while allowing internet access for other purposes. For example, a company using public subnets with security groups that restrict inbound traffic and needing to allow access to S3 and Secrets Manager from specific private IPs via bucket policies and resource-based policies.

Why candidates pick the wrong answer

A

Candidates may default to using NAT gateways for private subnet outbound traffic without considering VPC endpoints, or overlook the cost and internet routing constraints.

C

Candidates may think public subnets are simpler and cheaper, and mistakenly believe that AWS services inherently reject unauthorized traffic, ignoring the need for security groups and the requirement to avoid public internet.

D

Candidates may think that using S3 bucket policies with IP restrictions and enabling public access to Secrets Manager is a simple way to allow access without additional VPC endpoints, overlooking the security and routing requirements that mandate private connectivity.

134
MCQhard

A logistics company runs an order processing system on Amazon EC2 instances that read and write to an Amazon RDS for MySQL database. The database is currently a Single-AZ deployment. The company needs the database to survive an Availability Zone failure with automatic failover and minimal downtime. The application connects using a hardcoded DNS name. Which change should a solutions architect make?

A.Convert the RDS for MySQL database to a Multi-AZ DB instance deployment and continue using the existing endpoint.
B.Enable automated backups with a longer retention period and restore the database to a new instance during a failure.
C.Create a read replica in another Availability Zone and update the application to use the read replica endpoint for writes.
D.Migrate the database to Amazon DynamoDB with global tables enabled.
AnswerA

Converting to a Multi-AZ DB instance deployment creates a synchronous standby in a different Availability Zone and provides automatic failover. The DNS endpoint remains the same, so the hardcoded connection string continues to work after failover. This meets the requirements for zone resilience and minimal downtime with the least application change.

Why this answer

Converting the RDS for MySQL database to a Multi-AZ DB instance deployment creates a synchronous standby in a second Availability Zone and enables automatic failover. The database endpoint remains unchanged, so the application's hardcoded DNS name continues to work, satisfying the requirements for zone resilience and minimal downtime.

Exam trap

The trap here is confusing a read replica with a Multi-AZ standby; a read replica is asynchronous and does not provide automatic failover for writes.

135
MCQeasy

CloudWatch metrics show your EC2 instances have average CPU utilization around 10% with stable performance over several weeks. The application does not require additional headroom right now. What is the most effective cost-optimization action?

A.Right-size the instances to a smaller size that matches the observed utilization
B.Increase the Auto Scaling desired capacity to add more instances
C.Switch to Spot Instances immediately even though interruptions would impact users
D.Disable detailed monitoring to reduce CPU usage from the monitoring agent
AnswerA

Right sizing reduces cost by matching instance capacity to actual demand. If average CPU is consistently low (around 10%) and performance is stable, it strongly indicates overprovisioning. Moving to a smaller instance (or a smaller capability within the same family) typically lowers hourly cost while maintaining sufficient capacity for the workload.

Why this answer

Right-sizing EC2 instances to match observed utilization is the most effective cost-optimization action because the current instances are over-provisioned (average CPU at 10%). By selecting a smaller instance type that aligns with the actual workload, you reduce hourly costs without impacting performance, as the application has stable behavior and no need for headroom.

Exam trap

The trap here is that candidates may think increasing capacity (Option B) or switching to Spot Instances (Option C) is always cost-effective, but they fail to recognize that right-sizing is the foundational first step before scaling or using Spot, especially when current utilization is low and stable.

Why the other options are wrong

B

Increasing Auto Scaling desired capacity adds more instances, which increases cost without addressing the existing over-provisioning. The question states CPU utilization is low and stable, so adding instances would waste resources.

C

Switching to Spot Instances immediately would risk interruptions that impact users, which is unacceptable for a production application requiring stable performance. The question states the application does not require additional headroom, but it does not indicate tolerance for interruptions.

D

Disabling detailed monitoring does not reduce CPU usage from the monitoring agent; it only reduces the frequency of metric data sent to CloudWatch, which has negligible impact on CPU. The question focuses on cost optimization, and detailed monitoring costs extra, but the primary issue is that the instances are over-provisioned, not that monitoring costs are significant.

When would these options actually be correct?

B

This option would be correct if the application is experiencing high CPU utilization and performance degradation, and the goal is to improve performance or ensure high availability by distributing load across more instances.

C

A question where the application is fault-tolerant, can handle interruptions gracefully (e.g., using Spot Instance best practices like checkpointing), and cost reduction is the primary goal, with no requirement for stable performance or minimal user impact.

D

A scenario where the question asks: 'Your EC2 instances are running a batch job that is not performance-sensitive, and you want to reduce CloudWatch costs without affecting application performance. What should you do?' In that case, disabling detailed monitoring (switching to basic monitoring) would be correct to save on monitoring fees.

Why candidates pick the wrong answer

B

Candidates may think adding instances is always good for performance or cost optimization, or they confuse Auto Scaling with right-sizing, not realizing that adding instances increases cost when existing instances are underutilized.

C

Candidates know Spot Instances are cheaper and may assume any cost-saving measure is good, overlooking the critical requirement of stable performance and user impact from interruptions.

D

Candidates may think that disabling detailed monitoring reduces CPU overhead from the CloudWatch agent, thereby lowering utilization and costs. They might also confuse the cost of monitoring with compute costs, or believe that any reduction in monitoring activity directly saves significant money.

136
Multi-Selectmedium

A customer portal must recover from a regional outage within a few hours. The business wants lower ongoing cost than a fully active second Region and does not want to rebuild everything from scratch during the outage. Which two DR patterns best fit that goal? Select two.

Select 2 answers
A.Backup and restore
B.Pilot light
C.Warm standby
D.Multi-site active-active
E.Single-AZ deployment
AnswersB, C

Pilot light keeps only core components such as the database replication running in the second Region, so recovery within hours is achievable without rebuilding everything, while ongoing cost stays well below an active-active deployment. It matches the lower-cost, few-hours RTO constraint.

Why this answer

Pilot light (B) is correct because it keeps a minimal, always-on core (for example replicated data and pre-provisioned but scaled-down compute) in the DR Region, so recovery only requires scaling up and starting the remaining resources rather than rebuilding everything from scratch, and its low baseline footprint keeps ongoing cost well below a fully active second Region. Warm standby (C) is correct because it runs a scaled-down but fully functional copy of the workload in the second Region, allowing it to be scaled up to production capacity within hours while still costing less than a fully active second Region. Backup and restore (A) is not the best fit because recovery means redeploying and rebuilding the entire environment from backups, which typically exceeds a few hours and requires substantial manual effort.

Multi-site active-active (D) is excluded because running full production capacity in two Regions simultaneously is the most expensive option and contradicts the goal of lower ongoing cost. Single-AZ deployment (E) is not a cross-Region DR pattern at all and provides no protection against a regional outage.

Exam trap

AWS often tests the distinction between pilot light and warm standby—the trap here is that candidates may confuse pilot light with backup and restore, not realizing that pilot light maintains a live, minimal environment (e.g., database replicas) rather than just backup files, enabling faster recovery without full rebuild.

Why the other options are wrong

A

Backup and restore typically has a Recovery Time Objective (RTO) of hours to days, which may not meet the 'within a few hours' requirement, and it often involves rebuilding infrastructure from backups, which the question explicitly wants to avoid.

D

Multi-site active-active requires fully active resources in two regions simultaneously, which incurs higher ongoing costs than a fully active second Region, contradicting the requirement for lower cost.

E

Single-AZ deployment does not provide any cross-region recovery capability; a regional outage would cause complete downtime, contradicting the requirement to recover within hours.

When would these options actually be correct?

A

A question where the RTO is measured in days (e.g., 24-48 hours) and the business can tolerate rebuilding the entire environment from scratch using backups, with minimal ongoing cost as the primary driver.

D

An application requires near-zero RTO and RPO with automatic failover, and the business has budget for continuous dual-region operation, such as a global e-commerce platform that cannot tolerate any downtime.

E

For a non-critical application with low cost priority and tolerance for downtime during an AZ failure, where the question specifies 'single Availability Zone' and does not mention regional outage recovery.

Why candidates pick the wrong answer

A

Candidates may think backup and restore is the cheapest DR option and assume it can meet a 'few hours' RTO if backups are restored quickly, underestimating the time needed to provision infrastructure and validate the environment.

D

Candidates may assume that active-active provides the best recovery time and mistakenly think it can be cost-effective if traffic is balanced, overlooking the higher infrastructure and data replication costs.

E

Candidates may confuse high availability within a single region with disaster recovery across regions, or think that a single AZ is sufficient for 'low cost' without considering regional failure.

137
MCQmedium

A financial services company runs a three-tier web application on AWS. The application tier consists of EC2 instances in an Auto Scaling group behind an Application Load Balancer. Security policy requires that the EC2 instances never receive public IP addresses and that all outbound internet traffic from the application tier be routed through a NAT gateway. The company also wants to ensure that only the load balancer can initiate connections to the application instances on port 443. Which combination of VPC configuration and security group rules should a solutions architect implement to meet these requirements?

A.Place the EC2 instances in private subnets. Configure the instances' security group to allow inbound TCP 443 from 0.0.0.0/0, and route 0.0.0.0/0 through a NAT gateway in a public subnet.
B.Place the EC2 instances in private subnets. Configure the instances' security group to allow inbound TCP 443 from the load balancer's security group, and attach an internet gateway directly to the private subnets to provide outbound access.
C.Place the EC2 instances in private subnets. Configure the instances' security group to allow inbound TCP 443 from the load balancer's security group, and configure the load balancer's security group to allow inbound TCP 443 from 0.0.0.0/0. Route 0.0.0.0/0 through a NAT gateway in a public subnet.
D.Place the EC2 instances in public subnets with an internet gateway. Configure the instances' security group to allow inbound TCP 443 from the load balancer's IP addresses, and route 0.0.0.0/0 through the internet gateway.
AnswerC

This design places instances in private subnets so they have no public IPs or direct internet route, while the NAT gateway in a public subnet provides outbound internet access. Referencing the load balancer's security group as the source of the inbound rule on the instances' security group ensures that only the ALB can open connections to port 443, which is exactly the required restriction and avoids hardcoding CIDR ranges.

Why this answer

The requirement to keep instances off the public internet while allowing outbound access is met by private subnets plus a NAT gateway in a public subnet. Restricting inbound port 443 to the load balancer's security group as the source enforces that only the ALB can initiate connections to the application tier, which is the tightest and most maintainable control for this scenario.

Exam trap

The trap here is assuming that referencing the load balancer's security group only works for the load balancer's own outbound rules, when security groups can in fact reference peer security groups as inbound sources.

138
MCQmedium

A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The architecture review board prefers a managed AWS-native control.

A.A larger S3 bucket
B.Amazon CloudFront distribution with the S3 bucket as origin
C.RDS read replicas
D.An EC2 Auto Scaling group in one Region
AnswerB

CloudFront caches the static images and JavaScript at edge locations worldwide, so distant users retrieve objects from nearby points of presence instead of the S3 origin region. This directly cuts latency, and it is a managed AWS-native service, satisfying the architecture review board's stated preference.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches static content (images, JavaScript) at edge locations closer to users, drastically reducing latency for distant countries. By using the S3 bucket as the origin, CloudFront offloads requests from S3 and accelerates delivery via HTTP/2, TCP optimizations, and persistent connections. This is the most effective managed AWS-native solution for improving global load times for static assets.

Exam trap

The trap here is that candidates may confuse scaling storage (larger bucket) or compute (Auto Scaling) with performance improvement, overlooking that latency for static content is primarily a network distance problem solved by a CDN like CloudFront.

How to eliminate wrong answers

Option A is wrong because increasing the S3 bucket size does not improve data transfer speed or reduce latency; S3 performance is independent of bucket size and is limited by the bucket's regional location. Option C is wrong because RDS read replicas are designed for scaling database read traffic, not for serving static files or accelerating HTTP content delivery. Option D is wrong because an EC2 Auto Scaling group in a single Region does not reduce latency for users in distant countries; it only provides regional scalability and fault tolerance, not global edge caching.

139
MCQmedium

A company runs a microservices application on Amazon ECS with AWS Fargate. The tasks run continuously, and the company has committed to a 3-year term. The team wants to reduce Fargate compute cost while keeping the same task definitions and architecture. Which action should a solutions architect take?

A.Reduce the task CPU and memory values in the task definition to lower the Fargate rate.
B.Convert the Fargate tasks to EC2 launch type with Spot Instances.
C.Enable Fargate Spot for all tasks to obtain the lowest possible compute rate.
D.Purchase a Compute Savings Plan to cover the Fargate vCPU and memory usage.
AnswerD

Compute Savings Plans apply to AWS Fargate usage as well as EC2 and Lambda, so they reduce the effective rate for Fargate vCPU and memory while preserving the existing task definitions. For a continuous 3-year commitment, this is the direct way to lower Fargate compute cost without changing the architecture.

Why this answer

Compute Savings Plans cover Fargate usage and provide a discount in exchange for a term commitment, so they lower the vCPU and memory rate without changing task definitions or the ECS architecture. Fargate Spot and EC2 Spot introduce interruption risk unsuitable for continuously running services, and resizing task resources changes the workload rather than the pricing model.

Exam trap

The trap here is reaching for Fargate Spot because it advertises the lowest rate, while overlooking that continuously running microservices cannot accept Spot interruptions and that Compute Savings Plans already discount Fargate.

140
MCQmedium

A healthcare analytics company runs an Amazon RDS for MySQL database in a private subnet. A compliance requirement mandates that all data at rest be encrypted with a key that the company can rotate, audit, and immediately revoke. The database is currently unencrypted. What is the MOST operationally efficient way to meet this requirement?

A.Enable encryption on the existing DB instance by modifying it and specifying a customer managed AWS KMS key.
B.Take a snapshot of the DB instance, restore it with encryption enabled using a customer managed KMS key, and repoint the application to the new instance.
C.Create an encrypted read replica from the unencrypted instance, promote it, and update the application endpoint.
D.Enable encryption by restoring the automated backup to a new instance with the default AWS managed key aws/rds.
AnswerB

This is the standard supported method to encrypt an existing unencrypted RDS instance. You snapshot the instance, restore the snapshot with encryption enabled and a customer managed KMS key, then update the application connection string. It satisfies the requirement for customer-controlled key rotation, auditing, and revocation via KMS.

Why this answer

Encryption at rest for RDS must be enabled at creation. For an existing unencrypted instance, the supported path is to snapshot, restore with encryption using a customer managed KMS key, and repoint the application. This meets the need for customer-controlled rotation, audit trails, and revocability.

Exam trap

The trap here is assuming you can simply modify an existing unencrypted RDS instance to turn on encryption, when RDS only allows changing the key of an already-encrypted instance.

141
MCQhard

A media company stores master video files in an Amazon S3 bucket in the us-east-1 Region. A compliance policy requires that the data remain readable even if the entire us-east-1 Region becomes unavailable, and the recovery point objective is 15 minutes. The team wants the lowest operational overhead and does not want to modify application code. Which solution should the architect implement?

A.Use AWS DataSync to copy the bucket to a second Region every hour and store the copy in an S3 bucket with versioning enabled.
B.Configure an S3 Lifecycle policy to transition objects to S3 Glacier Deep Archive in a second Region and restore them during a disaster.
C.Enable S3 Cross-Region Replication to a bucket in us-west-2 with S3 Replication Time Control set to 15 minutes and enable versioning on both buckets.
D.Enable S3 Transfer Acceleration on the bucket and use an Amazon CloudFront distribution with origin failover to serve the video files.
AnswerC

S3 Cross-Region Replication with Replication Time Control provides a predictable 15-minute replication SLA and replicates objects, versions, and metadata to the destination bucket. The application can be pointed to the destination bucket during a Regional outage, and no code changes are needed because S3 APIs remain the same, meeting both RPO and low-overhead requirements.

Why this answer

Cross-Region Replication with S3 Replication Time Control replicates new and updated objects to a second Region within a defined 15-minute window and supports versioning and metadata. The destination bucket can serve reads during a Regional outage without application changes, giving the required RPO with minimal operational effort.

Exam trap

The trap here is confusing S3 Lifecycle storage-class transitions with cross-Region replication, when lifecycle actions keep data in the same Region and archival restores are far too slow for a 15-minute RPO.

142
MCQhard

A financial analytics platform runs an Amazon Aurora MySQL cluster with one writer and two readers. During month-end reporting, read traffic spikes and the application sometimes receives TooManyConnections errors on the reader endpoint. The architect wants to absorb bursts without changing application code and must keep failover behaviour intact. Which change meets these requirements?

A.Increase the aurora_max_connections parameter on the cluster parameter group and reboot the readers
B.Replace the reader endpoint with a Network Load Balancer that distributes TCP connections across the Aurora readers
C.Add an Amazon RDS Proxy in front of the Aurora cluster and point the application at the proxy endpoint
D.Convert the readers to Aurora Replicas in a second Region and use a global database secondary cluster
AnswerC

RDS Proxy pools and shares database connections, so bursts of application connections are multiplexed onto a smaller set of database connections, eliminating TooManyConnections errors without code changes beyond the endpoint. It preserves Aurora failover by automatically redirecting to the new writer, and it can be associated with read-only endpoints for reader traffic. This directly addresses connection exhaustion while keeping resilience.

Why this answer

Amazon RDS Proxy sits between the application and Aurora, maintaining a warm pool of database connections that are shared across many client connections. This absorbs connection bursts and prevents TooManyConnections errors without application changes beyond updating the endpoint. Because RDS Proxy is failover-aware, it automatically routes to the new writer during a failover, preserving the resilience behaviour the architect requires.

Exam trap

The trap here is treating a load balancer as a connection pooler, when only RDS Proxy multiplexes client connections onto a smaller backend set.

143
MCQhard

A claims portal uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

A.Store the database password in user data
B.Embed the database password in the AMI
C.IAM database authentication for RDS with an EC2 instance role
D.Use a security group rule that allows only application instances
AnswerC

IAM database authentication generates short-lived tokens from the EC2 instance role, so no database password is stored on the instance. This directly satisfies the requirement that credentials never reside on EC2 and that authentication uses temporary tokens.

Why this answer

IAM database authentication for RDS with an EC2 instance role allows the application to obtain a short-lived authentication token (valid for 15 minutes) using the AWS CLI or SDK, without storing any credentials on the instance. The EC2 instance role provides the necessary permissions to generate the token, which is then used instead of a static password, meeting both security requirements.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups) with authentication mechanisms, or assume that storing credentials in user data or AMIs is acceptable because they are 'hidden' from the application code, but AWS explicitly considers these insecure practices for production workloads.

How to eliminate wrong answers

Option A is wrong because storing the database password in user data persists the credential in plaintext on the instance metadata and can be exposed via the console or API, violating the requirement to not store credentials on EC2. Option B is wrong because embedding the database password in the AMI hard-codes the credential into the image, making it static and long-lived, and any instance launched from that AMI inherits the password, which cannot be rotated without rebuilding the AMI. Option D is wrong because a security group rule controls network access at the transport layer but does not address credential storage or authentication; it only restricts which IPs or instances can connect, not how the application authenticates.

144
MCQhard

A risk simulation workload in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost?

A.A larger NAT gateway
B.Gateway VPC endpoint for Amazon S3
C.S3 Object Lambda
D.AWS Shield Advanced
AnswerB

A gateway VPC endpoint for Amazon S3 inserts a prefix-list route into the VPC route table, directing traffic destined for S3 to the AWS network without leaving through a NAT gateway or internet gateway. Gateway endpoints are free—there is no hourly fee and no per-GB data processing charge—so the NAT gateway's per-GB processing fee on these downloads is completely eliminated. This is the only option that directly removes the data processing cost while preserving private connectivity.

Why this answer

A Gateway VPC endpoint for Amazon S3 allows instances in private subnets to access S3 directly via the AWS network, bypassing the NAT gateway entirely. This eliminates NAT data processing charges (per GB) for S3 traffic, which can be significant for large data downloads. The endpoint is free to use and routes traffic through AWS's private backbone, not the internet.

Exam trap

The trap here is that candidates often assume all VPC endpoints incur costs or require NAT gateways, but Gateway endpoints for S3 and DynamoDB are free and specifically designed to eliminate NAT data processing charges for those services.

How to eliminate wrong answers

Option A is wrong because a larger NAT gateway would increase, not reduce, costs due to higher hourly charges and data processing fees per GB. Option C is wrong because S3 Object Lambda is a feature for transforming data on the fly during retrieval, not for reducing network costs or bypassing a NAT gateway. Option D is wrong because AWS Shield Advanced is a DDoS protection service that adds cost and does not address NAT gateway data processing charges.

145
MCQmedium

A DynamoDB table stores device status items. The partition key is deviceId, and the partition distribution is healthy (no single partition dominates). However, during peak periods the application experiences high read latency because many clients repeatedly request the latest status for the same devices. Which action best improves read latency without changing the DynamoDB partitioning model?

A.Add Amazon DAX as a caching layer in front of DynamoDB and route repeated read operations through DAX.
B.Change the partition key to a random value for each request to eliminate hot partitions.
C.Increase write capacity only, because writes generally determine read latency in DynamoDB.
D.Create an additional Global Secondary Index (GSI) and read exclusively from the index to accelerate reads.
AnswerA

Amazon DAX is an in-memory caching layer for DynamoDB that accelerates repeated reads. When many clients request the same items (for example, “latest status” point reads by deviceId), DAX can serve cached responses directly, reducing round trips to DynamoDB and lowering read latency during peak periods.

Why this answer

Amazon DAX is a fully managed, in-memory cache for DynamoDB that provides microsecond read latency. By caching the results of repeated GetItem and Query requests for the same device status items, DAX offloads read traffic from the underlying DynamoDB table, reducing the number of read capacity units consumed and eliminating the latency caused by repeated fetches from disk. This directly addresses the high read latency during peak periods without altering the existing partition key or partitioning model.

Exam trap

The trap here is that candidates may think a GSI can magically speed up reads, but GSIs do not provide caching and still read from the same storage layer, so they do not reduce latency for repeated identical queries.

Why the other options are wrong

C

Increasing write capacity does not reduce read latency; read latency is affected by read capacity and throttling, not write capacity. The problem is high read demand on the same items, which write capacity cannot address.

D

Creating a GSI does not reduce read latency for repeated requests to the same items; it only provides an alternate query pattern. The hot partition issue is caused by high read frequency on specific items, which a GSI does not alleviate.

When would these options actually be correct?

C

This option would be correct if the question described high write latency or write throttling during peak periods, and the solution required increasing write capacity to handle the write load without changing the partitioning model.

D

A DynamoDB table has a suboptimal partition key leading to hot partitions, and you need to improve read performance by distributing reads across partitions. Creating a GSI with a different partition key can spread the read load and reduce latency.

Why candidates pick the wrong answer

C

Candidates may mistakenly think that writes and reads are coupled in DynamoDB, or that increasing any capacity will improve overall performance, not realizing that read and write capacities are independent.

D

Candidates may think that indexes always speed up reads, not realizing that GSIs don't cache data or reduce the load on the base table's partitions for repeated identical queries.

146
MCQhard

Based on the exhibit, the company runs a self-managed RabbitMQ cluster on EC2 for asynchronous work. The queue only needs durable at-least-once delivery, and the application does not require AMQP-specific features such as exchanges, routing keys, or broker plugins. Which change is the best cost-optimization move?

A.Replace RabbitMQ with Amazon SQS Standard and keep the workers unchanged except for the queue client library.
B.Replace RabbitMQ with Amazon MQ for RabbitMQ to keep the same protocol and reduce costs.
C.Increase the RabbitMQ instance size and add a fourth node for higher availability.
D.Move the queue to Amazon DynamoDB and use scans for consumers to detect new messages.
AnswerA

Amazon SQS is a fully managed queue that satisfies durable, at-least-once messaging without requiring broker administration. It removes the EC2 broker fleet, patching, backups, and failover testing, and it reduces outage risk from broker maintenance. Because the workload does not need AMQP-specific features such as exchanges or routing keys, SQS is the most cost-effective and operationally simple replacement.

Why this answer

Amazon SQS Standard provides at-least-once delivery and durable message storage without requiring AMQP-specific features like exchanges or routing keys. Replacing RabbitMQ with SQS eliminates the operational overhead of managing EC2 instances and RabbitMQ clusters, while SQS's pay-per-request pricing is more cost-effective than running EC2 instances 24/7 for a self-managed queue.

Exam trap

The trap here is that candidates assume Amazon MQ for RabbitMQ is always the cheapest managed option, but SQS is more cost-effective when AMQP-specific features are not required, as it eliminates per-instance costs and leverages a serverless pricing model.

How to eliminate wrong answers

Option B is wrong because Amazon MQ for RabbitMQ is a managed broker service that still incurs hourly instance costs, which is typically more expensive than SQS's serverless, pay-per-request model for workloads that don't need AMQP features. Option C is wrong because increasing instance size and adding nodes increases costs without addressing the core cost-optimization goal, and the current setup already meets the requirements. Option D is wrong because DynamoDB is not a queue service; using scans to detect new messages is inefficient, costly (consumes read capacity units), and does not provide at-least-once delivery semantics or message visibility timeouts, leading to potential duplicate processing and higher latency.

147
Multi-Selectmedium

A company is designing a secure architecture for a three-tier web application on AWS. The web tier runs on Amazon EC2 instances in public subnets, the application tier runs on EC2 instances in private subnets, and the database tier runs on Amazon RDS in private subnets. The security team requires that the application tier instances can access the internet for software updates without being directly reachable from the internet, and that the database tier is not accessible from the internet. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Place the RDS database in a public subnet and rely on a security group that allows only the application tier's IP range.
B.Configure the RDS database security group to allow inbound traffic only from the application tier security group.
C.Create a VPC peering connection between the application tier VPC and the database tier VPC, and route all database traffic over the peering connection.
D.Attach an Elastic IP address to each application tier instance and configure security groups to allow only outbound traffic.
E.Place the application tier instances in private subnets and configure a NAT gateway in a public subnet to allow outbound internet access.
AnswersB, E

Referencing the application tier security group as the source in the RDS security group rules ensures that only application instances can connect to the database. This enforces least privilege and prevents internet access. It also simplifies management because instances added to the application security group automatically gain access.

Why this answer

A NAT gateway in a public subnet allows private application instances to initiate outbound internet traffic for updates without being reachable inbound. Referencing the application security group in the RDS security group restricts database access to only those instances. Together, these actions provide secure outbound access and database isolation.

Exam trap

The trap here is using Elastic IPs or public subnets to enable outbound access, which exposes instances to inbound internet traffic.

148
MCQmedium

A containerized service fleet running on EC2 instances needs to share user-uploaded files and access them with low latency. The workload is bursty: sometimes dozens of instances concurrently read the same directory for short periods, and then traffic drops. Which Amazon EFS configuration best matches these performance needs?

A.Use Amazon EFS General Purpose performance mode and Throughput mode set to Bursting.
B.Use Amazon EFS Max I/O performance mode with Throughput mode set to Provisioned.
C.Use Amazon EFS General Purpose performance mode with Throughput mode set to Provisioned.
D.Use Amazon EFS Max I/O performance mode with Throughput mode set to Bursting.
AnswerA

EFS General Purpose performance mode is designed for latency-sensitive use cases with a broad range of I/O sizes, including typical file-sharing and web-content workloads. Throughput mode Bursting provides baseline throughput and allows throughput to scale up during demand spikes, which matches the pattern of short read bursts from many instances. When traffic drops, the system returns to baseline without requiring you to provision peak throughput for all time.

Why this answer

The workload is bursty with concurrent reads of the same directory, which favors the General Purpose performance mode for its strong consistency and lower latency per operation. The Bursting Throughput mode is ideal for bursty traffic as it allows the file system to accumulate burst credits during idle periods and consume them during high-demand spikes, matching the described pattern without incurring additional costs.

Exam trap

The trap here is that candidates often assume Max I/O is always better for high concurrency, but they overlook that General Purpose mode provides lower latency and stronger consistency for directory-heavy bursty reads, which is the actual requirement.

How to eliminate wrong answers

Option B is wrong because Max I/O performance mode is designed for highly parallelized workloads (e.g., thousands of instances) but sacrifices consistency and can introduce higher per-operation latency, which is not suitable for low-latency access to the same directory. Option C is wrong because Provisioned Throughput mode is intended for steady-state throughput requirements and would waste cost on a bursty workload that could use Bursting mode's credit-based model. Option D is wrong because Max I/O performance mode is not optimal for low-latency, directory-heavy access patterns, and while Bursting mode fits the bursty nature, the combination with Max I/O undermines the low-latency requirement.

149
MCQmedium

A batch process uploads artifacts to an Amazon S3 bucket using multipart uploads. The bucket policy contains a statement that explicitly denies PutObject and CreateMultipartUpload unless the request uses server-side encryption with AWS KMS (SSE-KMS) and includes these request headers/parameters: x-amz-server-side-encryption=aws:kms and x-amz-server-side-encryption-aws-kms-key-id set to a specific CMK. After the process was updated, uploads intermittently fail with AccessDenied errors. Which change is the best way to make uploads succeed while still meeting the bucket policy's encryption requirement?

A.Update the IAM role policy to add s3:PutObject permissions for the bucket prefix.
B.Update the uploader so the CreateMultipartUpload request includes SSE-KMS with the required CMK key ID; any separate PutObject uploads should include the same headers.
C.Remove the bucket policy's explicit Deny statement so the IAM permissions control access.
D.Switch to client-side encryption (SSE-C) because it also encrypts data at rest in S3.
AnswerB

For multipart uploads, SSE-KMS is specified on CreateMultipartUpload rather than on individual UploadPart calls. Supplying the required SSE-KMS settings and CMK key ID on the upload initiation request satisfies the bucket policy's condition without weakening the encryption requirement.

Why this answer

The bucket policy explicitly denies `PutObject` and `CreateMultipartUpload` unless the request includes both `x-amz-server-side-encryption=aws:kms` and the specific `x-amz-server-side-encryption-aws-kms-key-id` header. The intermittent failures occur because the batch process's `CreateMultipartUpload` request (which initiates the multipart upload) is missing these required headers, causing the explicit Deny to trigger. By ensuring that the `CreateMultipartUpload` request includes SSE-KMS with the correct CMK key ID, and that any subsequent `PutObject` parts also include the same headers, the uploads will satisfy the bucket policy and succeed.

Exam trap

The trap here is that candidates assume the encryption requirement only applies to the final object or to `PutObject` calls, but the explicit Deny in the bucket policy applies to the `CreateMultipartUpload` API call itself, which must also include the required headers to avoid AccessDenied errors.

How to eliminate wrong answers

Option A is wrong because adding `s3:PutObject` permissions to the IAM role does not override the bucket policy's explicit Deny statement; an explicit Deny in a bucket policy always takes precedence over any Allow, regardless of IAM permissions. Option C is wrong because removing the Deny statement would violate the encryption requirement the policy is designed to enforce, leaving the bucket unencrypted for those operations and failing the security objective. Option D is wrong because SSE-C (client-side encryption) does not use the `x-amz-server-side-encryption` or `x-amz-server-side-encryption-aws-kms-key-id` headers required by the policy; SSE-C uses a different header (`x-amz-server-side-encryption-customer-algorithm`) and a customer-provided key, so it would still be denied by the explicit Deny.

150
MCQmedium

A media company stores video masters in an Amazon S3 bucket encrypted with a customer managed AWS KMS key. Editors sign in through a corporate identity provider that is federated to AWS IAM Identity Center, and they must be able to download and re-upload objects. The security team wants every editor's read of the key material recorded in CloudTrail with the editor's own identity, and wants to be able to revoke one editor's access without affecting the others. Which configuration meets these requirements?

A.Generate a data key with kms:GenerateDataKeyWithoutPlaintext once, store it in AWS Secrets Manager, and have each editor retrieve it to encrypt and decrypt objects locally before uploading.
B.Enable S3 server access logging on the bucket and create a separate IAM user for each editor with an inline policy allowing kms:Decrypt on the key.
C.Create a KMS key policy statement that allows kms:Decrypt and kms:GenerateDataKey to the IAM Identity Center permission set role, and let each editor assume that role with their federated identity.
D.Attach a bucket policy to the S3 bucket that grants s3:GetObject to the federated principal, and rely on the default aws/s3 AWS managed key for encryption so no KMS permissions are needed.
AnswerC

Because editors assume a permission set role through IAM Identity Center, CloudTrail records each kms:Decrypt and kms:GenerateDataKey call with the role session and the federated user identity, satisfying the audit requirement. Removing a single editor from the permission set assignment in IAM Identity Center removes their ability to assume the role, revoking only that person's access without touching the shared key policy.

Why this answer

When objects use SSE-KMS, every download requires kms:Decrypt and every upload requires kms:GenerateDataKey, and those calls appear in CloudTrail tied to the calling principal. Federating editors into a permission set role means the role session carries their identity, giving per-person audit records and per-person revocation by removing the assignment, while the key policy authorizes the shared role.

Exam trap

The trap here is assuming that S3 bucket permissions alone control access to SSE-KMS objects, when the KMS key policy must also grant the caller Decrypt and GenerateDataKey or the request fails.

Page 1

Page 2 of 13

Page 3