Courseiva

SAA-C03 (SAA-C03) — Questions 301–375

935 questions total · 13pages · All types, answers revealed

Page 4

Page 5 of 13

Page 6
301
MCQmedium

A company runs a stateless web application on a fleet of EC2 instances behind an Application Load Balancer. The instances are in an Auto Scaling group that scales between 4 and 40 instances, and utilization is highly variable. The company wants to reduce compute cost while keeping the ability to change instance families and Regions over the next three years. Which purchasing strategy should the company use?

A.Purchase a 3-year Standard Reserved Instance for each of the 40 instances.
B.Use Spot Instances for the entire Auto Scaling group and remove the On-Demand capacity.
C.Purchase a Compute Savings Plan with a commitment equal to the steady-state baseline usage.
D.Purchase a 1-year EC2 Instance Savings Plan scoped to the current instance family and Region.
AnswerC

A Compute Savings Plan applies to EC2, Fargate, and Lambda across families, sizes, tenancies, and Regions, so the company can change instance families or Regions without losing the discount. Committing only to the steady-state baseline covers the always-on capacity and leaves burst capacity billed at On-Demand rates.

Why this answer

A Compute Savings Plan discounts eligible compute regardless of family, size, tenancy, or Region, which matches the requirement to change instance families and Regions over three years. Committing only to the steady-state baseline keeps the discount on always-on capacity while variable burst capacity is billed at On-Demand rates, so the company controls cost without sacrificing flexibility.

Exam trap

The trap here is choosing a larger discount from an EC2 Instance Savings Plan, when its family and Region lock would break the requirement to change instance families and Regions.

302
MCQhard

A company uses AWS Organizations to manage multiple AWS accounts. A security engineer needs to prevent any IAM user in the organization from disabling AWS CloudTrail logging in any account. The solution must apply automatically to all existing and future accounts. What should the security engineer do?

A.Enable AWS CloudTrail organization trail and configure an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail.
B.Create an IAM policy that denies the cloudtrail:StopLogging action and attach it to all IAM users in each account.
C.Use AWS Config to monitor CloudTrail configuration changes and trigger an AWS Lambda function to re-enable logging if it is stopped.
D.Create an IAM role in each account with a permissions boundary that denies cloudtrail:StopLogging and assign it to all users.
AnswerA

An organization trail applies to all accounts in the organization, and an SCP can deny the specific actions that would disable logging. SCPs are inherited by all accounts, including future ones, and affect all principals, including root users. This combination ensures CloudTrail cannot be disabled, meeting the requirement with minimal ongoing effort.

Why this answer

Service control policies (SCPs) in AWS Organizations provide centralized control over the maximum available permissions for all accounts. By denying cloudtrail:StopLogging and cloudtrail:DeleteTrail, the SCP ensures that no principal, including root, can disable the organization trail. This solution automatically applies to all current and future accounts, satisfying the requirement.

Exam trap

The trap here is thinking that IAM policies or permissions boundaries applied per-account can enforce organization-wide restrictions, when only SCPs can centrally deny actions across all accounts and principals, including root users.

303
MCQeasy

Based on the exhibit, the database must fail over automatically if the primary Availability Zone goes down. Which solution should the architect choose?

A.Create a read replica in the same Availability Zone as the primary database.
B.Convert the database to a Multi-AZ RDS deployment.
C.Increase the backup retention period to 35 days.
D.Move the database to an EC2 instance with an attached EBS volume.
AnswerB

A Multi-AZ RDS deployment keeps a synchronous standby in another Availability Zone and automatically fails over when the primary fails. This matches the requirement for minimal manual intervention and preserves the same database endpoint, so the application does not need connection string changes. It is the standard AWS choice for resilient relational databases.

Why this answer

A Multi-AZ RDS deployment automatically provisions and maintains a synchronous standby replica in a different Availability Zone. If the primary AZ fails, Amazon RDS automatically fails over to the standby, typically within 60–120 seconds, without requiring manual intervention or changes to the application connection string.

Exam trap

The trap here is that candidates confuse read replicas (which are asynchronous and require manual promotion) with Multi-AZ deployments (which provide automatic synchronous failover), often selecting a read replica in the same AZ because they think it offers high availability without understanding the fundamental replication mode difference.

How to eliminate wrong answers

Option A is wrong because a read replica in the same AZ does not provide automatic failover; it is designed for read scaling, not high availability, and requires manual promotion. Option C is wrong because increasing the backup retention period to 35 days only affects point-in-time recovery and automated backups, not failover capability. Option D is wrong because moving the database to an EC2 instance with an attached EBS volume requires custom scripting or third-party tools to implement automatic failover, and EBS volumes are AZ-specific, so they cannot survive an AZ outage without manual intervention.

304
MCQmedium

A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered?

A.Aurora Global Database
B.A single-AZ Aurora cluster
C.An ElastiCache Redis replica
D.Manual snapshots copied monthly
AnswerA

Aurora Global Database is the correct choice because it uses storage-based replication to synchronize data across multiple AWS Regions with a typical latency of under one second. It supports up to five secondary Regions, and when a regional failure occurs, you can promote a secondary Region to primary in about a minute, giving you a very low RPO and RTO for fast disaster recovery. This managed feature also enables low-latency global reads and automatic failover, making it vastly superior to any snapshot-based approach.

Why this answer

Aurora Global Database is designed for cross-Region disaster recovery with a typical RPO of 1 second or less, using storage-based replication that does not impact database performance. This meets the requirement for fast failover and low data loss, unlike manual snapshot-based approaches which have higher RPO and slower recovery.

Exam trap

The trap here is that candidates may confuse cross-Region read replicas (which have higher lag and manual promotion) with Aurora Global Database, or assume that ElastiCache or single-AZ deployments can provide adequate DR, when only Aurora Global Database meets the low RPO and fast cross-Region recovery requirements.

How to eliminate wrong answers

Option B is wrong because a single-AZ Aurora cluster lacks any cross-Region replication or failover capability, providing no disaster recovery across Regions. Option C is wrong because ElastiCache Redis is an in-memory cache, not a persistent database, and cannot serve as the primary data store for ticket booking transactions or provide cross-Region DR for the Aurora MySQL data. Option D is wrong because manual snapshots copied monthly result in an RPO of up to one month, which is far too high for the low RPO requirement, and recovery would require provisioning a new cluster from the snapshot, leading to significant downtime.

305
MCQhard

A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The architecture review board prefers a managed AWS-native control.

A.Amazon EFS with mount targets in multiple Availability Zones
B.S3 mounted as a POSIX file system without a file gateway
C.Instance store volumes
D.An EBS volume attached to all instances
AnswerA

Amazon EFS is a regional, managed NFS file system that provides standard POSIX file semantics, including file locking and consistent reads/writes, making it ideal for concurrent access from many EC2 instances. By configuring mount targets in multiple Availability Zones, the service achieves high availability and fault tolerance while instances in any AZ can access the same shared file data.

Why this answer

Amazon EFS provides a fully managed, NFS-based shared file system that can be mounted concurrently by multiple Linux EC2 instances across different Availability Zones. By creating mount targets in each AZ, the file system remains accessible even if one AZ fails, as traffic is automatically routed to the surviving mount targets. This meets the requirement for shared, resilient storage with a managed AWS-native control plane.

Exam trap

The trap here is that candidates often confuse EBS Multi-Attach (which is limited to a single AZ and specific instance types) with the cross-AZ shared file system capability of EFS, or incorrectly assume S3 with a FUSE mount can replace a POSIX-compliant file system.

How to eliminate wrong answers

Option B is wrong because mounting S3 as a POSIX file system (e.g., using s3fs-fuse) does not provide true POSIX compliance, lacks strong consistency guarantees, and introduces performance and locking issues unsuitable for shared file workloads; it also requires a third-party tool, not a fully managed AWS-native service. Option C is wrong because instance store volumes are ephemeral, tied to the lifecycle of a single EC2 instance, and cannot be shared across instances or survive an AZ failure. Option D is wrong because an EBS volume can only be attached to a single EC2 instance at a time (unless using multi-attach, which is limited to specific EBS types and still not designed for cross-AZ shared file systems), and it cannot be simultaneously mounted by instances in multiple Availability Zones.

306
MCQeasy

A worker service consumes messages from an Amazon SQS queue. Some messages are malformed and always fail validation. The worker retries, but it keeps reprocessing the same bad messages and consumes processing capacity that should be used for valid work. What is the best solution to prevent “poison messages” from blocking progress?

A.Configure a Dead-Letter Queue (DLQ) and set a redrive policy so messages move to the DLQ after a maximum number of receives.
B.Increase the visibility timeout so the worker gets fewer retries per hour.
C.Disable SQS retries by deleting messages immediately on any processing error.
D.Create a second worker that polls the queue less frequently until the malformed message is processed successfully.
AnswerA

Configuring a Dead-Letter Queue (DLQ) with a redrive policy is the most effective solution. This mechanism automatically moves messages that fail processing a specified number of times (maxReceiveCount) from the source queue to the DLQ. This prevents 'poison pill' messages from continuously consuming worker resources and allows for their isolation, analysis, and eventual reprocessing or discarding without impacting the main message flow.

Why this answer

A Dead-Letter Queue (DLQ) with a redrive policy is the standard AWS mechanism for handling poison messages. By setting a maximum receive count (e.g., 5), the SQS queue automatically moves messages that fail processing repeatedly to the DLQ, isolating them from the main queue. This prevents the worker from wasting capacity on invalid messages and allows the main queue to continue processing valid work without interruption.

Exam trap

The trap here is that candidates may think increasing the visibility timeout or deleting messages on error is a valid solution, but AWS specifically designed the DLQ pattern to isolate poison messages without losing data or impacting throughput.

How to eliminate wrong answers

Option B is wrong because increasing the visibility timeout only delays the retry, it does not prevent the worker from eventually reprocessing the same bad message, so the poison message still consumes processing capacity. Option C is wrong because SQS does not support disabling retries; deleting messages immediately on error would lose the message entirely without any chance for recovery or analysis, which is not a best practice. Option D is wrong because creating a second worker that polls less frequently does not solve the problem—the malformed message will still be retried and block progress, and a slower poll rate only reduces throughput without addressing the root cause.

307
MCQeasy

A team runs a CPU-intensive image processing service on Amazon EC2. The service spends most of its time resizing and compressing images, and the team wants the best price-performance starting point for compute-heavy work. Which EC2 instance family should they choose?

A.Memory optimized instances
B.Compute optimized instances
C.Storage optimized instances
D.General purpose instances
AnswerB

Compute optimized instances, such as the C5 or C6g families, provide the highest vCPU-to-memory ratio and are purpose-built for CPU-intensive workloads like image processing, scientific modeling, and video encoding. Their enhanced clock speeds and sustained compute performance directly target the processing bottleneck, making them the most efficient and cost-effective choice for this workload.

Why this answer

Compute optimized instances (C family) are designed for workloads that benefit from high-performance processors, such as batch processing, media transcoding, and image processing. Since the team's service is CPU-intensive (resizing and compressing images), the C family provides the best price-performance starting point for compute-heavy work.

Exam trap

The trap here is that candidates may confuse 'CPU-intensive' with 'memory-intensive' or 'storage-intensive' and choose a general purpose instance (D) thinking it is a safe default, but the question specifically asks for the best price-performance starting point for compute-heavy work, which is the compute optimized family.

Why the other options are wrong

A

Memory optimized instances are designed for workloads that process large datasets in memory, not for CPU-intensive tasks like image resizing and compression, which primarily require high compute power.

C

Storage optimized instances are designed for workloads with high sequential I/O access to large datasets on local storage, not for CPU-intensive image processing tasks like resizing and compressing images.

D

General purpose instances balance compute, memory, and networking, but for CPU-intensive image processing, compute optimized instances offer better price-performance due to higher vCPU count and faster clock speeds.

When would these options actually be correct?

A

A question describing a service that processes large in-memory databases or real-time big data analytics, where the primary bottleneck is memory capacity and throughput, would make memory optimized instances the correct choice.

C

A question asking for an EC2 instance family optimized for workloads that require high, sequential read/write access to very large datasets stored locally on the instance, such as distributed file systems, data warehousing, or log processing.

D

A question asks for a balanced instance family for a web application with moderate CPU and memory usage, where cost and flexibility are priorities, and no specific resource is a bottleneck.

Why candidates pick the wrong answer

A

Candidates may mistakenly think that image processing requires large amounts of memory, or they may confuse memory-intensive workloads with compute-intensive ones.

C

Candidates may mistakenly think image processing involves heavy disk I/O due to reading/writing many image files, leading them to choose storage optimized instances instead of focusing on the CPU-bound nature of the task.

D

Candidates may assume 'general purpose' is always a safe starting point, overlooking that CPU-intensive workloads benefit from specialized compute optimized instances for better performance per cost.

308
MCQmedium

A Lambda function behind an API needs consistent low latency. Traffic normally drops to near zero, then spikes several times per hour. During spikes, the p95 latency often spikes above 800 ms due to cold starts. The team wants to keep using Lambda (no containers) but minimize cold start impact during predictable spikes. What is the best AWS configuration to meet this goal?

A.Enable Lambda provisioned concurrency on a published function alias and set the minimum provisioned instances to the baseline expected during spikes.
B.Increase the function memory size to the maximum and rely on the larger memory to eliminate cold starts.
C.Configure an ALB with target group health checks to keep Lambda warm by sending periodic requests.
D.Turn on AWS CloudTrail data events to monitor cold start frequency and tune the runtime accordingly.
AnswerA

Provisioned concurrency pre-creates and initializes Lambda execution environments for a specific published alias or version, so requests are served immediately without a cold start. Setting the provisioned minimum to your baseline expected during spikes ensures that the required capacity is already warm and ready, maintaining consistent low latency under load. This is the correct, managed mechanism designed by AWS for this exact problem.

Why this answer

Provisioned concurrency initializes a specified number of execution environments in advance, keeping them warm and ready to handle requests instantly. By setting the minimum provisioned instances to the baseline expected during spikes, the function avoids cold starts for those requests, ensuring p95 latency stays low even when traffic surges from near zero.

Exam trap

The trap here is that candidates may confuse provisioned concurrency with reserved concurrency, or assume that increasing memory or using health checks can eliminate cold starts, when only provisioned concurrency guarantees pre-warmed environments for predictable spikes.

Why the other options are wrong

B

Increasing memory size can reduce cold start duration but does not eliminate cold starts entirely; it only shortens the initialization time. The question requires minimizing cold start impact during predictable spikes, which provisioned concurrency achieves by keeping instances pre-warmed.

C

ALB health checks send requests to a target, but Lambda functions behind an ALB are invoked only when health checks are configured to hit a specific endpoint. However, health checks are typically sent at intervals (e.g., every 30 seconds), which may not keep the function warm during the unpredictable spikes described. Additionally, health checks can cause unnecessary invocations and costs without guaranteeing that all needed concurrent executions are warm.

When would these options actually be correct?

B

In a scenario where the goal is to reduce Lambda execution duration for CPU-bound tasks without changing concurrency, and the question asks for a simple configuration change that improves performance without addressing cold starts specifically.

C

A question where the goal is to ensure a Lambda function remains warm for periodic requests from an ALB, and the traffic pattern is consistent (e.g., steady low traffic with occasional small spikes). In that case, ALB health checks can keep a single instance warm, reducing cold starts for the first request after idle periods.

Why candidates pick the wrong answer

B

Candidates often believe that more memory (and thus more CPU) can eliminate cold starts, confusing performance improvement with initialization elimination. They may also think that Lambda's scaling behavior is solely dependent on memory allocation.

C

Candidates may think that periodic requests (health checks) will keep the Lambda function warm, similar to using a CloudWatch Events rule to ping the function. They overlook that health checks are not designed to handle concurrency spikes and may not prevent cold starts for all concurrent invocations during a spike.

309
MCQmedium

A warehouse integration service receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The design must avoid adding custom operational scripts.

A.AWS WAF
B.Amazon Route 53 weighted routing
C.Amazon SQS queue
D.Amazon CloudFront
AnswerC

Amazon SQS is a fully managed message queue that decouples order-producing services from warehouse processing consumers. It durably stores messages, allowing bursts of orders to be buffered while consumers poll and process at a controlled rate, and it supports retries via visibility timeout and dead-letter queues for failed processing. This makes SQS the correct choice for absorbing spikes and ensuring no order is lost during high demand.

Why this answer

Amazon SQS is the correct choice because it acts as a durable, scalable message buffer that decouples the web tier from the fulfilment workers. When order bursts arrive, messages are stored reliably in the queue, and workers can poll at their own pace, retrying failed messages automatically without any custom scripts. This pattern absorbs spikes and ensures no requests are lost, meeting the requirement for a fully managed, serverless integration.

Exam trap

The trap here is that candidates often confuse load-balancing or traffic-routing services (like Route 53 or CloudFront) with message queuing, mistakenly thinking they can absorb processing spikes, whereas only a queue like SQS provides durable storage and asynchronous decoupling for request bursts.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that filters HTTP/S traffic based on rules (e.g., SQL injection, XSS) and does not provide message buffering, decoupling, or retry capabilities for downstream services. Option B is wrong because Amazon Route 53 weighted routing distributes DNS traffic across multiple endpoints based on weights, but it operates at the DNS level and cannot absorb processing spikes or retry failed requests; it simply routes new connections. Option D is wrong because Amazon CloudFront is a content delivery network (CDN) that caches static and dynamic content at edge locations to reduce latency, but it does not offer message queuing, buffering, or retry logic for backend processing workloads.

310
MCQeasy

You use a customer managed AWS KMS key (CMK) to encrypt objects in an S3 bucket using SSE-KMS. A specific IAM role must be able to decrypt objects. Where should you grant kms:Decrypt permissions so that the role can decrypt data encrypted with that CMK?

A.In the KMS key policy, allowing kms:Decrypt (and any other required KMS permissions) for the role’s principal ARN.
B.Only in the S3 bucket policy by granting s3:GetObject, because S3 bucket policy controls decryption.
C.Only in the IAM role identity policy; the KMS key policy does not need changes for SSE-KMS.
D.By enabling S3 default encryption; KMS permissions are automatically granted to all IAM roles in the account.
AnswerA

With SSE-KMS, KMS decryption is authorized by KMS for the specific CMK. The CMK key policy is a primary authorization layer; if the key policy does not allow kms:Decrypt for the role (or a matching principal), S3 requests that require KMS decryption will fail even if the S3 or IAM identity policies allow s3:GetObject.

Why this answer

When using a customer managed KMS key (CMK) with SSE-KMS, the KMS key policy is the primary access control mechanism. To allow a specific IAM role to decrypt objects, you must grant kms:Decrypt (and typically kms:DescribeKey) in the key policy for that role's principal ARN. Without this explicit permission in the key policy, the role will be denied decryption even if it has s3:GetObject permissions, because KMS enforces its own authorization.

Exam trap

The trap here is that candidates assume S3 bucket policies or IAM identity policies alone are sufficient for decryption, forgetting that KMS enforces its own authorization layer and the key policy is the gatekeeper for all KMS operations.

Why the other options are wrong

B

S3 bucket policies control S3 actions like s3:GetObject, but they cannot grant KMS permissions. Decrypting SSE-KMS objects requires explicit kms:Decrypt permission on the CMK, which must be granted via the KMS key policy or an IAM policy that the key policy allows.

C

The KMS key policy must explicitly grant kms:Decrypt to the IAM role; without it, the role cannot decrypt objects even if it has an IAM policy allowing kms:Decrypt, because KMS key policies control access to the CMK and can override IAM policies.

D

Enabling S3 default encryption does not automatically grant KMS permissions to IAM roles; you must explicitly grant kms:Decrypt in the key policy or IAM policy for the role to decrypt objects encrypted with a customer managed CMK.

When would these options actually be correct?

B

In a scenario where the question asks how to grant access to decrypt objects encrypted with SSE-S3 (not SSE-KMS) or when the question specifies that the CMK's key policy already allows the account root and the role has an IAM policy granting kms:Decrypt, then the answer would focus on S3 bucket policy for s3:GetObject.

C

This would be correct if the question asked about granting permissions to decrypt objects encrypted with SSE-S3 (not SSE-KMS), where S3 manages the encryption keys and no KMS permissions are needed. In that case, only S3 bucket policy or IAM policy granting s3:GetObject is required.

D

If the question asked about using SSE-S3 (AES-256) with S3 default encryption, then no KMS permissions are needed, and the bucket policy or IAM policy would control access to the objects.

Why candidates pick the wrong answer

B

Candidates may mistakenly think that S3 bucket policies are sufficient for all aspects of S3 access, including decryption, and overlook that SSE-KMS requires separate KMS permissions.

C

Candidates may think that IAM policies alone are sufficient for all AWS services, forgetting that KMS uses a resource-based policy (key policy) that must explicitly allow access, especially when the key is in a different account or when the key policy denies default IAM access.

D

Candidates may mistakenly think that S3 default encryption automatically handles all permissions for decryption, overlooking that SSE-KMS requires explicit KMS key permissions separate from S3 actions.

311
MCQmedium

A test environment stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost?

A.Keep all logs in S3 Standard indefinitely
B.Move all logs immediately to S3 Glacier Deep Archive
C.S3 lifecycle policy that transitions objects to lower-cost storage classes over time
D.Use EBS snapshots for the logs
AnswerC

An S3 lifecycle policy is the correct solution because it lets you automate storage class transitions based on object age: for example, keep logs in S3 Standard for the first 30 days for active queries, then transition them to S3 Standard-IA or S3 Glacier Instant Retrieval for cheaper long-term storage. Lifecycle rules can chain multiple transitions, so you can progressively move objects to even colder classes (e.g., Glacier Flexible Retrieval) after 90 or 180 days. This matches storage cost to actual access patterns while maintaining the ability to retrieve logs when needed, without manual operations or expensive ingestion-time decisions.

Why this answer

An S3 Lifecycle policy automates the transition of objects from S3 Standard (for frequent access) to S3 Standard-IA (infrequent access) after 30 days, then to S3 Glacier Deep Archive (for long-term retention) after one year, minimizing storage costs while maintaining data accessibility as needed.

Exam trap

The trap here is that candidates may choose immediate transition to Glacier Deep Archive (Option B) without considering the 30-day query period, failing to match the lifecycle to the access pattern described in the question.

How to eliminate wrong answers

Option A is wrong because keeping all logs in S3 Standard indefinitely incurs the highest storage cost, ignoring the cost savings from transitioning to lower-cost storage classes for data that is rarely accessed or retained for compliance. Option B is wrong because moving all logs immediately to S3 Glacier Deep Archive is impractical for logs queried frequently in the first 30 days, as retrieval times (hours) and costs would be excessive, and it violates the access pattern described. Option D is wrong because EBS snapshots are designed for block-level backups of EC2 instances, not for storing log files; they are more expensive and less suitable for object-based log storage in S3.

312
Multi-Selecthard

A company is designing a secure architecture for an internal microservices application running on Amazon ECS with the Fargate launch type. The security team wants each microservice to have its own fine-grained permissions to access specific AWS resources, and wants to avoid storing long-term AWS credentials in the container images or task definitions. The company also wants to encrypt data in transit between services. (Choose two.)

Select 2 answers
A.Enable AWS PrivateLink for communication between microservices and use TLS termination at the Network Load Balancer.
B.Attach an IAM user access key to each container through a mounted Amazon EFS volume.
C.Store AWS credentials in AWS Secrets Manager and inject them as environment variables in the task definition.
D.Implement mutual TLS between microservices using AWS App Mesh with certificate management through AWS Certificate Manager Private CA.
E.Use an ECS task IAM role for each microservice with a least-privilege policy attached.
AnswersD, E

AWS App Mesh provides service-to-service communication control and supports mutual TLS, where both sides present certificates to authenticate and encrypt traffic. Integrating with ACM Private CA allows the mesh to issue and rotate certificates automatically. This satisfies the requirement to encrypt data in transit between microservices and adds identity verification, which is a strong security control for internal microservices.

Why this answer

ECS task IAM roles provide each microservice with temporary, scoped credentials without storing secrets in images or task definitions, meeting the fine-grained permission and credential-hygiene requirements. AWS App Mesh with mutual TLS encrypts and authenticates service-to-service traffic using certificates from ACM Private CA, satisfying the in-transit encryption requirement. Together they form a least-privilege, encrypted microservices architecture.

Exam trap

The trap here is assuming that injecting secrets as environment variables or using PrivateLink alone provides the same security as task roles and mutual TLS.

313
MCQmedium

A media company stores video files in an Amazon S3 bucket in the us-east-1 Region. The company wants to ensure that the files are automatically replicated to us-west-2 for disaster recovery, and that replication occurs within 15 minutes of upload. Which solution meets these requirements with the LEAST operational overhead?

A.Configure an AWS Lambda function triggered by S3 event notifications to copy each object to the destination bucket.
B.Use AWS DataSync to schedule a recurring task that synchronizes the source bucket to the destination bucket every 15 minutes.
C.Enable S3 Cross-Region Replication (CRR) on the bucket with a replication rule that applies to all objects.
D.Enable S3 Same-Region Replication (SRR) to a bucket in us-east-1, then use S3 Batch Operations to copy objects to us-west-2 nightly.
AnswerC

S3 Cross-Region Replication automatically replicates objects to a bucket in another Region asynchronously, typically within minutes. It requires versioning on both buckets and an IAM role. Once configured, it operates with no additional infrastructure, providing low operational overhead and meeting the 15-minute replication goal for most objects.

Why this answer

S3 Cross-Region Replication is the managed solution for automatically replicating objects to a bucket in another Region. It is asynchronous but typically completes within minutes, satisfying the 15-minute requirement. It requires versioning and an IAM role, but after setup it runs without ongoing intervention.

This provides the lowest operational overhead compared to custom code or scheduled data transfer tasks.

Exam trap

The trap here is confusing S3 Same-Region Replication with Cross-Region Replication, or assuming that a scheduled copy job can meet a near-real-time replication objective.

314
MCQmedium

Your AWS Organization uses a Service Control Policy (SCP) that includes a Deny statement for secretsmanager:GetSecretValue for all member accounts in the "Finance" OU when requests are made outside us-east-1. An application role has an IAM policy that allows secretsmanager:GetSecretValue for the required secret in us-west-2. In us-west-2, requests fail with AccessDenied. What is the most appropriate action?

A.Update the application role IAM policy to include us-west-2 in the resource ARN.
B.Create a permission boundary that removes the deny behavior for the member account.
C.Modify the SCP to allow secretsmanager:GetSecretValue in us-west-2 for the Finance OU (if that aligns with policy intent), or move the workload to us-east-1.
D.Use sts:AssumeRole into another account that is not in the Finance OU to bypass the SCP.
AnswerC

Because the SCP contains an explicit Deny based on region and OU, the correct remedy is to change the SCP conditions (or operate within allowed regions). SCP evaluation is performed before/independent of IAM identity policies for the permission decision.

Why this answer

SCPs are deny-by-default and act as an outer boundary on all IAM policies in member accounts. Even if the application role's IAM policy allows secretsmanager:GetSecretValue in us-west-2, the SCP's explicit Deny for requests outside us-east-1 overrides that allow. The correct fix is either to modify the SCP to permit the action in us-west-2 (if that aligns with organizational intent) or to relocate the workload to us-east-1, because SCPs cannot be overridden by any IAM policy within the account.

Exam trap

The trap here is that candidates assume IAM policies alone control access and forget that SCPs act as a global deny filter that cannot be bypassed by any IAM-level configuration, leading them to incorrectly choose options that modify IAM policies or use cross-account roles.

How to eliminate wrong answers

Option A is wrong because the IAM policy already allows the action for the secret in us-west-2 (the resource ARN is not the issue); the failure is caused by the SCP's Deny, not a missing resource ARN. Option B is wrong because permission boundaries restrict the maximum permissions an IAM role can have, but they cannot override an SCP Deny; SCPs are evaluated before permission boundaries and a Deny in an SCP always takes precedence. Option D is wrong because assuming a role in another account does not bypass SCPs; the SCP applies to all principals in the member account, and the assumed role would still be subject to the SCP of the target account if it is also in the Finance OU, or the SCP of the source account if the trust policy is evaluated.

315
MCQeasy

A company runs its customer-facing web app on EC2 behind an Application Load Balancer. The database is Amazon RDS for PostgreSQL. The requirement is that if a single Availability Zone fails, the database must automatically fail over within the same AWS Region with minimal application changes. Which database setup best meets this requirement?

A.Use an RDS single-AZ instance and periodically restore from automated backups if needed.
B.Deploy the RDS PostgreSQL instance as Multi-AZ with automatic failover enabled.
C.Create a read replica in a different AZ and use it only when the primary fails.
D.Use RDS with Multi-AZ disabled, but increase storage IOPS to prevent failover.
AnswerB

Multi-AZ maintains a synchronous standby replica in a second Availability Zone; on AZ failure, RDS automatically promotes it and repoints the DNS endpoint, typically within 60–120 seconds. Because the application reconnects via the same endpoint, no code changes are needed, satisfying the in-Region automatic failover and minimal-change constraints.

Why this answer

RDS Multi-AZ for PostgreSQL automatically provisions and maintains a synchronous standby replica in a different Availability Zone. If the primary AZ fails, Amazon RDS automatically fails over to the standby, typically within 60–120 seconds, with no changes required to the application's connection string (the DNS name remains the same). This meets the requirement for minimal application changes and automatic failover within the same Region.

Exam trap

The trap here is that candidates often confuse a read replica (which requires manual promotion and DNS changes) with a Multi-AZ standby (which provides automatic, transparent failover), leading them to incorrectly select Option C.

Why the other options are wrong

A

Single-AZ RDS with manual backup restoration does not provide automatic failover; it requires manual intervention and incurs significant downtime, failing the requirement for automatic failover within the same Region.

C

A read replica is not designed for automatic failover; promoting it requires manual intervention or additional scripting, which does not meet the 'automatically fail over' requirement with minimal application changes.

D

Multi-AZ disabled means no automatic failover; increasing IOPS improves performance but does not provide high availability across AZs, so it fails the requirement of automatic failover during an AZ failure.

When would these options actually be correct?

A

If the requirement were to minimize costs and allow for some data loss (RPO of hours) and downtime (RTO of hours), with no need for automatic failover, then a single-AZ instance with periodic backups would be acceptable.

C

This option would be correct if the requirement was to offload read traffic from the primary database and have a standby for manual failover in a disaster recovery scenario, where some downtime is acceptable and application changes are allowed.

D

If the requirement were to improve database performance for a read-heavy workload without needing automatic failover, increasing IOPS on a single-AZ instance would be correct.

Why candidates pick the wrong answer

A

Candidates may think that restoring from backups is a valid disaster recovery method, but they overlook the requirement for automatic failover with minimal application changes.

C

Candidates may think a read replica in a different AZ provides automatic failover similar to Multi-AZ, but they overlook that read replicas require manual promotion and do not provide automatic, seamless failover.

D

Candidates may confuse performance improvements (IOPS) with availability features, thinking that faster storage can compensate for lack of redundancy.

316
MCQmedium

A web application for a order processing API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

A.Security groups on the application instances
B.Network ACLs on the public subnets
C.AWS WAF associated with the Application Load Balancer
D.AWS Shield Advanced only
AnswerC

AWS WAF is a managed web application firewall that inspects HTTP and HTTPS requests at layer 7 and can be associated with an Application Load Balancer to filter traffic before it reaches backend instances. It supports AWS-managed rule groups, including the SQL database and cross-site scripting rule sets, that examine request components such as headers, query strings, and body payloads. When deployed on an ALB, WAF can block or allow requests in real time based on those rules, directly mitigating the specific attacks described.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS) attacks. By associating an AWS WAF web ACL with the Application Load Balancer, you can filter and monitor HTTP/HTTPS requests based on customizable rules, providing application-layer protection with minimal operational overhead since AWS manages the underlying infrastructure and rule updates.

Exam trap

The trap here is that candidates often confuse network-layer controls (security groups and network ACLs) with application-layer protection, assuming they can filter HTTP-level attacks, when in fact only AWS WAF can inspect and block SQL injection and XSS at the application layer.

How to eliminate wrong answers

Option A is wrong because security groups act as a virtual firewall at the instance level, controlling inbound and outbound traffic based on IP addresses and ports; they do not inspect application-layer payloads and cannot detect or block SQL injection or XSS attacks. Option B is wrong because network ACLs are stateless, subnet-level filters that evaluate traffic based on IP addresses, ports, and protocols; they lack the ability to parse HTTP request bodies or headers for malicious patterns. Option D is wrong because AWS Shield Advanced provides DDoS protection against volumetric attacks but does not include application-layer filtering for SQL injection or XSS; it must be combined with AWS WAF for such threats.

317
MCQmedium

A solutions architect is designing an S3 bucket for a healthcare document service. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?

A.Enable server access logging on the bucket
B.Enable S3 Transfer Acceleration
C.Create an IAM policy that denies s3:GetObject to anonymous users
D.Enable S3 Block Public Access at the account or bucket level
AnswerD

S3 Block Public Access at the account or bucket level provides four protective settings that prohibit public ACLs, ignore existing public ACLs, block public bucket policies, and restrict any bucket policy that would grant public access. For a healthcare document service, this acts as a strict guardrail that nullifies any accidental public exposure, regardless of how a bucket policy or ACL is configured. Since the settings are enforced centrally, they provide comprehensive coverage against bucket misconfiguration.

Why this answer

S3 Block Public Access provides a definitive override that prevents any public access to objects, regardless of bucket policies or object ACLs. When enabled at the account or bucket level, it blocks all public access settings, ensuring that even if a developer later adds an overly broad bucket policy, the objects remain inaccessible to anonymous users. This is essential for compliance with healthcare regulations like HIPAA, where data must never be publicly exposed.

Exam trap

The trap here is that candidates often think an IAM policy can block anonymous users, but IAM policies never apply to unauthenticated requests—only bucket policies and S3 Block Public Access can control anonymous access.

How to eliminate wrong answers

Option A is wrong because enabling server access logging only records requests made to the bucket; it does not prevent public access or enforce any security controls. Option B is wrong because S3 Transfer Acceleration is a performance feature that speeds up uploads over long distances using AWS edge locations; it has no impact on access permissions or public accessibility. Option C is wrong because an IAM policy that denies s3:GetObject to anonymous users is not effective—IAM policies apply only to authenticated IAM principals, not to anonymous (unauthenticated) users; anonymous access is controlled by bucket policies and ACLs, not IAM.

318
Multi-Selectmedium

A company is deploying a stateless web application on Amazon ECS with Fargate. The application must be resilient to individual task failures and Availability Zone failures. Which three steps should the company take to achieve this resilience? (Choose three.)

Select 3 answers
.Configure the ECS service to use a spread placement strategy across Availability Zones.
.Set a minimum healthy percent of 50 and a maximum percent of 200 in the ECS service deployment configuration.
.Place all ECS tasks in a single subnet to minimize network latency.
.Use an Application Load Balancer (ALB) in front of the ECS service to distribute traffic across tasks.
.Store application session data in an attached EFS file system shared across all tasks.
.Disable automatic task replacement to avoid unnecessary task churn during failures.

Why this answer

Configuring the ECS service with a spread placement strategy across Availability Zones ensures tasks are distributed across multiple AZs, providing resilience against AZ failures. Setting a minimum healthy percent of 50 and a maximum percent of 200 allows the service to maintain at least half of the desired tasks during deployments or failures while scaling up to replace failed tasks without downtime. Using an Application Load Balancer (ALB) in front of the ECS service distributes incoming traffic across healthy tasks in different AZs, automatically rerouting traffic if a task or AZ fails.

Exam trap

The trap here is that candidates may confuse stateless applications with stateful ones and incorrectly choose to store session data in EFS, or they may think placing tasks in a single subnet improves performance without considering the single point of failure risk.

319
MCQeasy

Your company hosts an internal API in two AWS Regions. You want Amazon Route 53 to automatically send traffic to the secondary Region if the primary Region’s endpoint becomes unhealthy. Which Route 53 configuration best meets this requirement?

A.Latency-based routing with health checks for both Regions.
B.Failover routing with a primary record associated with a health check, and a secondary (failover) record associated with its own health check settings.
C.Weighted routing to distribute traffic evenly across both Regions.
D.Geolocation routing based on the client’s country to choose a Region.
AnswerB

Route 53 failover routing implements an active-passive pattern by defining a primary record (the desired region) paired with a health check that continuously verifies endpoint availability. When that health check returns an unhealthy status, Route 53 automatically removes the primary record from the response and answers DNS queries with the secondary (failover) record, which also has its own health check settings to ensure the backup is truly reachable. This gives you deterministic, health-driven failover where all traffic shifts to the secondary region after the primary's health check fails, exactly matching the requirement.

Why this answer

Failover routing in Route 53 is specifically designed for active-passive configurations where traffic is directed to a primary resource unless a health check indicates it is unhealthy, at which point traffic is automatically routed to the secondary (failover) record. By associating a health check with the primary record, Route 53 can monitor the endpoint's health and perform the failover seamlessly. This directly meets the requirement to send traffic to the secondary Region when the primary endpoint becomes unhealthy.

Exam trap

The trap here is that candidates often confuse failover routing with latency-based routing, assuming that latency-based routing with health checks will automatically redirect traffic to the next best Region when one is unhealthy, but in reality, latency-based routing only selects the lowest-latency healthy endpoint and does not enforce a strict primary-secondary failover order.

How to eliminate wrong answers

Option A is wrong because latency-based routing directs traffic to the Region with the lowest latency for the client, not based on health status; while health checks can be associated, they only mark records as unhealthy without automatically failing over to a specific secondary Region. Option C is wrong because weighted routing distributes traffic based on assigned weights, not health; if the primary endpoint is unhealthy, traffic would still be sent to it according to the weight, unless the record is marked unhealthy, but there is no automatic failover to a designated secondary. Option D is wrong because geolocation routing directs traffic based on the client's geographic location, not on endpoint health; it does not provide automatic failover to a secondary Region when the primary is unhealthy.

320
MCQmedium

A partner company needs read-only access to reports in an S3 bucket for a e-learning platform. The partner has its own AWS account. What is the most secure scalable access pattern?

A.Copy the objects to a public website bucket
B.Create an IAM user in the company account and share the access keys
C.Create a bucket policy that grants the partner role least-privilege access to the required prefix
D.Make the objects public and rely on difficult-to-guess object names
AnswerC

A bucket policy is a resource-based policy that can explicitly grant the partner's IAM role cross-account access to a specific prefix, such as s3:GetObject on arn:aws:s3:::reports/partner/*. This approach adheres to least privilege by restricting actions to only what is required (e.g., GetObject, ListBucket on that prefix) and by naming a specific external principal. It also avoids sharing long-term keys because the partner role will assume the role using its own credentials, and the policy can be updated or removed centrally by the bucket owner.

Why this answer

It uses a resource-based bucket policy that grants the partner's AWS account (via its root user or an IAM role) least-privilege read-only access to a specific prefix. This approach avoids sharing long-term credentials, leverages AWS's cross-account trust mechanism, and scales securely without managing additional IAM users.

Exam trap

The trap here is that candidates often choose Option B (sharing IAM user credentials) because it seems straightforward, but AWS recommends cross-account roles with bucket policies for secure, auditable, and scalable access without managing external users.

How to eliminate wrong answers

Option A is wrong because copying objects to a public website bucket removes all access control, exposing data to the internet and violating the principle of least privilege. Option B is wrong because creating an IAM user in the company account and sharing access keys introduces long-term static credentials that must be rotated, can be leaked, and do not scale across multiple partner accounts. Option D is wrong because making objects public with difficult-to-guess names relies on security through obscurity, which is not a secure pattern—objects can be discovered via enumeration or leaks, and S3 does not enforce access control based on name complexity.

321
Multi-Selecthard

A media company runs a 24/7 ingestion API on EC2 behind an Application Load Balancer and a nightly transcoding job that can resume from checkpoints. The API fleet runs at roughly 65 percent CPU all day, while the batch workers sit idle most of the time. The company wants to cut compute cost without risking the API. Which two changes should they make? Select two.

Select 2 answers
A.Purchase a Compute Savings Plan for the always-on API fleet.
B.Move the transcoding workers to EC2 Spot Instances and checkpoint progress.
C.Replace the API fleet with Dedicated Hosts to lock in lower rates.
D.Buy Standard Reserved Instances for the batch workers and keep them running 24/7.
E.Increase the worker Auto Scaling minimum to prevent Spot interruptions.
AnswersA, B

Correct. Compute Savings Plans discount steady usage across EC2 and other compute services without forcing a specific instance family. The API has predictable 24/7 demand, so a commitment fits the usage pattern and lowers cost safely.

Why this answer

Option A is correct because the API fleet is an always-on, steady-state workload running 24/7 at ~65% CPU, which is exactly the profile a Compute Savings Plan discounts (up to 66% off On-Demand) while remaining flexible across instance families, sizes, Regions, and even Fargate/Lambda, so it lowers cost without changing capacity or risking the API. Option B is correct because the transcoding job is fault-tolerant and can resume from checkpoints, making it ideal for EC2 Spot Instances, which offer up to 90% off On-Demand; a Spot interruption only triggers a two-minute warning and the job simply resumes from its last checkpoint. Option C is wrong because Dedicated Hosts are for licensing/compliance or BYOL requirements and are typically more expensive, not a cost-optimization lever for a standard ALB-fronted API.

Option D is wrong because buying Standard RIs and keeping batch workers running 24/7 pays for idle capacity the workload does not need, defeating the cost goal. Option E is wrong because raising the Auto Scaling minimum does not prevent Spot interruptions and would increase cost by keeping more idle workers running.

Exam trap

The trap here is that candidates often confuse Savings Plans with Reserved Instances, or assume Dedicated Hosts are a cost-saving measure, when in fact they are a premium isolation feature; the key is recognizing that Spot Instances are ideal for fault-tolerant, checkpointable batch workloads, while a Compute Savings Plan covers the predictable baseline without locking into a specific instance type.

322
MCQmedium

A partner company needs read-only access to reports in an S3 bucket for a customer analytics portal. The partner has its own AWS account. What is the most secure scalable access pattern?

A.Make the objects public and rely on difficult-to-guess object names
B.Create a bucket policy that grants the partner role least-privilege access to the required prefix
C.Copy the objects to a public website bucket
D.Create an IAM user in the company account and share the access keys
AnswerB

A resource policy can grant cross-account access to a specific external role and prefix.

Why this answer

A bucket policy that grants the partner's IAM role (from the partner's AWS account) least-privilege access to a specific prefix is the most secure and scalable pattern. This uses cross-account IAM roles, avoiding long-term credentials and allowing the partner to manage their own users and permissions. The bucket policy explicitly trusts the partner's AWS account, and the partner assumes the role to access only the required objects, following the principle of least privilege.

Exam trap

The trap here is that candidates often choose Option D (sharing IAM user access keys) because it seems straightforward, but the exam tests the understanding that cross-account IAM roles are more secure and scalable than sharing static credentials.

How to eliminate wrong answers

Option A is wrong because making objects public with difficult-to-guess names relies on security through obscurity, which is not a secure pattern; objects can be discovered via enumeration or accidental exposure, and it violates AWS's shared responsibility model. Option C is wrong because copying objects to a public website bucket exposes the data to the internet without any access control, which is insecure and does not scale for read-only access by a specific partner. Option D is wrong because creating an IAM user in the company account and sharing access keys introduces long-term static credentials that must be rotated and managed, increasing the risk of leakage; it also does not scale across multiple partners and violates the principle of using IAM roles for cross-account access.

323
MCQmedium

A company runs a containerized order-processing service on Amazon ECS with the Fargate launch type. The service scales out during business hours and scales down to a small baseline overnight. Usage is expected to remain stable for the next two years, and the team wants to reduce Fargate cost without managing any servers. Which action should the solutions architect take?

A.Enable Fargate Spot for the entire service and remove the On-Demand baseline
B.Purchase a Compute Savings Plan that covers the steady Fargate baseline usage
C.Purchase a 1-year EC2 Instance Savings Plan sized to the nightly baseline
D.Migrate the service to the EC2 launch type and purchase Reserved Instances for the baseline
AnswerB

Compute Savings Plans apply to Fargate vCPU and memory usage as well as to Lambda and EC2, so they discount the steady portion of this service without requiring any server management. Committing to the overnight baseline captures the discount on usage that is certain to occur, while the variable daytime scale-out remains on On-Demand rates.

Why this answer

Compute Savings Plans explicitly cover Fargate vCPU and memory usage, so they reduce cost for a serverless container workload without requiring any infrastructure management. Sizing the commitment to the guaranteed overnight baseline discounts the portion of usage that will certainly occur, while the elastic daytime capacity continues to bill at On-Demand rates without over-committing the company.

Exam trap

The trap here is assuming that a Fargate workload cannot benefit from any savings plan, when Compute Savings Plans cover Fargate as well as Lambda and EC2.

324
MCQmedium

Company A runs an internal app in account A. The app needs to upload objects to an S3 bucket in account B. When the app calls S3, it receives AccessDenied for s3:PutObject. The team already created an IAM role in account B named UploadRole with a policy allowing s3:PutObject. They did not yet set up any trust relationship. Which change most directly fixes the access problem with least privilege?

A.Create IAM user access keys in account A and attach the UploadRole policy directly to those keys.
B.Update the trust policy on UploadRole (account B) to allow sts:AssumeRole from the app’s IAM role or principal in account A.
C.Add s3:PutObject permissions to the bucket policy in account B for all principals in account A.
D.Attach an SCP (service control policy) in AWS Organizations to deny sts:AssumeRole unless the caller uses an MFA device.
AnswerB

A cross-account role requires both an IAM permissions policy and a trust policy. The trust policy must allow the specific principal in account A to call sts:AssumeRole into account B’s role. With that trust in place, the app can obtain temporary credentials and then use the UploadRole permissions for s3:PutObject.

Why this answer

The app in account A needs to assume the UploadRole in account B to gain s3:PutObject permissions. Without a trust policy on UploadRole that allows sts:AssumeRole from the app's IAM principal in account A, the role cannot be assumed, resulting in AccessDenied. Updating the trust policy directly establishes the cross-account trust relationship with least privilege, as it grants only the necessary assume-role capability.

Exam trap

The trap here is that candidates often think bucket policies alone can solve cross-account access, but without a trust policy on the IAM role, the app cannot assume the role to obtain the required permissions.

Why the other options are wrong

A

IAM user access keys are long-term credentials and do not solve cross-account access; the app in account A needs to assume a role in account B, not use a user with a policy attached directly.

C

Option C grants s3:PutObject to all principals in account A, which violates least privilege by not restricting to the specific app role, and it does not address the missing trust relationship needed for cross-account access via role assumption.

D

The problem is lack of cross-account trust, not an SCP. SCPs deny actions at the OU/account level but don't grant permissions; they would only block access if already allowed, and here no trust exists.

When would these options actually be correct?

A

If the question asked for a solution where a single IAM user in account A needs to upload objects to an S3 bucket in account B without using roles, and the bucket policy allows access based on user ARN, then creating access keys for that user and attaching the necessary permissions would be correct.

C

This option would be correct if the question stated that the app in account A uses an IAM user with programmatic access keys (not a role) and the requirement is to allow that user to write to the bucket without assuming a role, using a bucket policy that grants access to the entire account A.

D

An SCP denying sts:AssumeRole unless MFA is used would be correct in a question where an organization wants to enforce MFA for all cross-account role assumptions, and the issue is that a role is being assumed without MFA.

Why candidates pick the wrong answer

A

Candidates may think that attaching a policy to access keys is a straightforward way to grant permissions, overlooking the cross-account nature of the problem and the need for role assumption.

C

Candidates may think a bucket policy is the simplest way to grant cross-account S3 access, overlooking that the app's IAM role still needs explicit permission to assume a role in account B, and that a bucket policy alone does not replace the need for a trust relationship.

D

Candidates may confuse SCPs with IAM policies or think that any denial of access can be fixed by adding a deny statement, not realizing SCPs are a guardrail, not a solution for missing trust relationships.

325
MCQhard

A gaming company uses Amazon DynamoDB to store player session data. The table has a partition key of PlayerID and a sort key of SessionStartTime. The company needs to retrieve all sessions for a specific player within a date range, sorted by session start time. The table is large and the company wants to minimize read latency. Which approach should they use?

A.Use DynamoDB Accelerator (DAX) to cache the results of a Scan operation.
B.Perform a Query operation on the table using the partition key and a condition on the sort key.
C.Perform a Scan operation with a FilterExpression on PlayerID and SessionStartTime.
D.Create a global secondary index with PlayerID as the partition key and SessionStartTime as the sort key, then Query the index.
AnswerB

A Query operation directly accesses items with a specific partition key and allows a condition on the sort key to retrieve a range of session start times. This is efficient and leverages the table's primary key design, providing low-latency retrieval of sorted results. It is the optimal approach for this access pattern.

Why this answer

The table's primary key already supports the required access pattern: partition key PlayerID and sort key SessionStartTime. A Query operation with a condition on the sort key retrieves exactly the items needed, sorted by session start time, with minimal latency. Scans, GSIs, and DAX do not provide a more efficient solution for this specific query.

Exam trap

The trap here is thinking that a GSI is needed to query by PlayerID and SessionStartTime, but the base table already has that key schema.

326
MCQmedium

A public API for a image sharing application is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used? The design must avoid adding custom operational scripts.

A.A VPC endpoint policy
B.API keys only
C.JWT authorizer configured for the OpenID Connect issuer
D.IAM authorization for all internet users
AnswerC

A JWT authorizer configured for the OpenID Connect issuer is the correct choice because API Gateway can automatically fetch the OIDC provider's JSON Web Key Set (JWKS) to validate the JWT signature, expiry, issuer, and audience. This allows the API to authenticate users who received tokens from a trusted OIDC-compatible identity provider (such as Amazon Cognito or Auth0) without managing a custom Lambda authorizer or session state. It also supports scopes and claims for fine-grained authorization, making it a low-operational-overhead and secure solution for public internet users.

Why this answer

C is correct because the scenario requires standards-based token authentication from an external OpenID Connect (OIDC) provider, and API Gateway's JWT authorizer natively validates JWTs issued by OIDC providers without requiring custom code. This authorizer verifies the token's signature, expiry, and issuer against the OIDC discovery endpoint, meeting the requirement to avoid custom operational scripts.

Exam trap

The trap here is that candidates often confuse API keys (simple identification) with token-based authentication (JWT/OIDC), or incorrectly assume IAM authorization can be used for external identity federation without custom Lambda authorizers or STS-based token exchange.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint policy controls access to API Gateway via VPC endpoints, not authentication for internet clients using OIDC tokens. Option B is wrong because API keys only provide simple identification and throttling, not authentication or authorization based on standards-based tokens from an external OIDC provider. Option D is wrong because IAM authorization is designed for AWS-authenticated principals (e.g., IAM users/roles), not for internet users presenting tokens from an external OIDC provider, and it would require custom scripts to map OIDC tokens to IAM roles.

327
Multi-Selecthard

A distributed analytics engine runs 12 EC2 instances in one Availability Zone. The nodes exchange thousands of tiny messages per second and must keep jitter as low as possible. The current design launches the instances across multiple placement groups and uses general-purpose burstable instances. Which two changes will most directly lower east-west network latency and variability? Select two.

Select 2 answers
A.Move all instances into a cluster placement group.
B.Use instance families that provide high network bandwidth and support enhanced networking.
C.Spread the instances across three Availability Zones for better fault tolerance.
D.Front the nodes with an Application Load Balancer to balance the internal messages.
E.Store the messages on EBS volumes so the nodes avoid network communication.
AnswersA, B

Cluster placement groups pack instances closely together in a single Availability Zone, which minimizes network distance and improves latency consistency. This is the best placement strategy when the workload is highly chatty and needs very low jitter between nodes. It directly targets east-west performance.

Why this answer

A cluster placement group provides a low-latency, high-bandwidth network connection by placing instances in a single Availability Zone within the same logical rack or cluster. This minimizes the physical distance and network hops between instances, directly reducing east-west latency and jitter for the thousands of tiny messages per second.

Exam trap

The trap here is that candidates often confuse 'fault tolerance' (spreading across AZs) with 'performance' (cluster placement group), or they mistakenly think a load balancer can optimize internal node-to-node traffic, when in fact it adds latency and is designed for client-facing traffic.

328
MCQmedium

A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The architecture review board prefers a managed AWS-native control.

A.Aurora Global Database
B.A single-AZ Aurora cluster
C.An ElastiCache Redis replica
D.Manual snapshots copied monthly
AnswerA

Aurora Global Database is the correct answer because it replicates MySQL data at the storage layer to up to five secondary AWS Regions with typical replication latency under one second. This enables a promoted secondary cluster to become the primary in minutes, yielding a Recovery Time Objective (RTO) of roughly 1–2 minutes and a Recovery Point Objective (RPO) measured in seconds. Unlike snapshot-based backups, this is continuous, automatic replication that keeps the ticket booking system’s data nearly current in the disaster recovery Region, making it the only option that satisfies fast DR while preserving data consistency at scale.

Why this answer

Aurora Global Database is the correct choice because it provides a managed, cross-Region disaster recovery solution with a Recovery Point Objective (RPO) of typically less than 1 second, using storage-based replication that does not impact database performance. This meets the requirement for fast failover and low data loss, while being fully AWS-native and controlled by the architecture review board.

Exam trap

The trap here is that candidates may confuse cross-Region read replicas (which have higher RPO and require manual promotion) with Aurora Global Database, or assume that any caching layer like ElastiCache can substitute for database DR, when in fact only Aurora Global Database provides the required low RPO and managed failover.

How to eliminate wrong answers

Option B is wrong because a single-AZ Aurora cluster lacks any cross-Region replication or failover capability, offering no disaster recovery across Regions. Option C is wrong because ElastiCache Redis is an in-memory cache, not a persistent database, and cannot serve as a primary data store for ticket bookings or provide cross-Region DR with low RPO. Option D is wrong because manual snapshots copied monthly result in an RPO of up to a month, which is far too high for fast disaster recovery requirements.

329
MCQeasy

A production application stores critical data on an Amazon EBS volume. The team wants a simple backup method that allows the volume to be restored later if the server is lost. What should they use?

A.Amazon S3 bucket versioning
B.Amazon EBS snapshots
C.AWS Security Hub
D.Amazon CloudFront invalidations
AnswerB

EBS snapshots are the native backup mechanism for EBS volumes. They capture point-in-time copies that can later be used to create a new volume, making them a simple and reliable way to restore data after a server or volume loss. Snapshots are incremental, so repeated backups are efficient and suitable for ongoing protection.

Why this answer

Amazon EBS snapshots are the correct choice because they provide a simple, incremental backup method for EBS volumes. Snapshots capture the data on the volume at a specific point in time and are stored in Amazon S3, allowing the volume to be restored to a new EC2 instance if the original server is lost. This directly meets the requirement for a backup that enables restoration after server failure.

Exam trap

The trap here is that candidates might confuse EBS snapshots with S3 versioning, thinking that S3 can directly back up EBS volumes, but EBS snapshots are the native, designed service for this purpose.

Why the other options are wrong

A

Amazon S3 bucket versioning protects objects within S3 from accidental deletion or overwrite, but it does not back up EBS volumes. EBS volumes are block-level storage attached to EC2 instances, and S3 versioning cannot capture or restore the volume's state.

C

AWS Security Hub is a security posture management service that aggregates and prioritizes security findings from various AWS services; it does not provide backup or restore capabilities for EBS volumes.

D

CloudFront invalidations are used to remove cached content from edge locations, not for backing up or restoring EBS volumes.

When would these options actually be correct?

A

A question asks for a backup method for files stored in an S3 bucket, where the requirement is to preserve previous versions of objects to recover from accidental deletions or overwrites. In that scenario, S3 bucket versioning is the correct answer.

C

A question asks: 'Which AWS service should be used to centrally view and manage security alerts and compliance status across multiple AWS accounts?' In that context, Security Hub would be the correct answer.

D

A company uses CloudFront to distribute a static website and updates the origin content. They need to ensure users see the latest version immediately. CloudFront invalidations would be the correct answer to clear the cache.

Why candidates pick the wrong answer

A

Candidates may think S3 versioning is a general-purpose backup feature, or they confuse it with EBS snapshots which are stored in S3, leading them to believe S3 versioning can back up EBS volumes.

C

Candidates may confuse 'security' with 'backup' or think that Security Hub includes backup features because it is a security-related service, leading them to select it incorrectly.

D

Candidates may confuse 'invalidations' with 'backups' or think that clearing cache is a form of data protection, but it serves a completely different purpose.

330
MCQmedium

A media processing service runs ECS tasks in multiple Availability Zones. Each task must read and write the same shared filesystem with low latency because tasks stream intermediate artifacts to other tasks. The team currently mounts an EBS volume per task, and cross-AZ tasks frequently cannot see each other’s files. Which option best resolves the shared filesystem requirement while supporting high-performing access?

A.Keep using EBS, but attach the same EBS volume to tasks in multiple Availability Zones using EBS multi-attach so all tasks share the filesystem.
B.Use Amazon EFS with mount targets in each Availability Zone so all tasks mount a common NFS filesystem over the AWS network.
C.Use Amazon S3 for the intermediate artifacts and rely on S3 event notifications to emulate POSIX file operations.
D.Switch to instance store on each task and use SQS messages between tasks to copy intermediate artifacts.
AnswerB

EFS is designed for shared, NFS-like file storage that can be mounted concurrently from compute resources across multiple Availability Zones. By creating mount targets in each AZ used by the ECS tasks, you enable low-latency network access patterns so tasks can read and write the same shared filesystem reliably.

Why this answer

Amazon EFS provides a fully managed, shared NFS filesystem that can be mounted concurrently by ECS tasks across multiple Availability Zones with low latency. It supports POSIX file operations, making it ideal for streaming intermediate artifacts between tasks. EFS mount targets in each AZ ensure local access, meeting the requirement for high-performing shared storage.

Exam trap

The trap here is that candidates may assume EBS multi-attach works across Availability Zones, but it is strictly limited to a single AZ and requires specific instance types, making it unsuitable for multi-AZ shared filesystem requirements.

Why the other options are wrong

A

EBS multi-attach does not support attaching a single volume to instances across different Availability Zones; it only works within a single AZ. Therefore, cross-AZ tasks cannot share the same EBS volume.

C

S3 does not provide a POSIX-compliant shared filesystem with low-latency file locking and immediate consistency needed for streaming intermediate artifacts between tasks; it is an object store, not a filesystem.

D

Instance store is ephemeral and not shared across tasks, so tasks in different AZs cannot access a common filesystem. SQS message copying adds latency and complexity, failing the low-latency shared filesystem requirement.

When would these options actually be correct?

A

If all ECS tasks are running in the same Availability Zone and require a shared block storage with low latency and consistent performance, EBS multi-attach would be the correct choice for a shared filesystem.

C

A question where the requirement is to store and process large volumes of static artifacts with event-driven workflows, and low-latency shared filesystem access is not needed. For example: 'A data pipeline processes uploaded images and triggers a Lambda function to generate thumbnails.'

D

A question where tasks need high-speed local scratch storage and can tolerate eventual consistency, such as a batch processing job that processes independent chunks and only needs to aggregate results via a queue.

Why candidates pick the wrong answer

A

Candidates may think EBS multi-attach provides cross-AZ sharing similar to EFS, but they overlook the single-AZ limitation of EBS multi-attach.

C

Candidates may think S3 can serve as a shared filesystem due to its durability and event notifications, overlooking the need for low-latency POSIX semantics and concurrent file access.

D

Candidates may think instance store offers high performance and SQS can coordinate file transfers, overlooking that instance store is ephemeral and not shared, and that SQS cannot provide a POSIX filesystem.

331
MCQmedium

A team wants detective controls to investigate suspected exfiltration from an S3 bucket. They need to know when objects are accessed (GetObject) and also when new encrypted objects are written. They already enabled AWS CloudTrail for management events, but their investigation shows no visibility into object-level reads/writes in the logs they review. Which CloudTrail configuration change most directly provides the missing object-level visibility?

A.Enable CloudTrail data events for the specific S3 bucket so that GetObject and PutObject operations are logged at the object level.
B.Enable AWS Config delivery to a separate bucket and create a rule to detect noncompliant S3 policies; this will automatically generate GetObject logs.
C.Turn on VPC Flow Logs for the VPC hosting the S3 gateway endpoint, because network logs show S3 object read and write details.
D.Add an S3 bucket policy that denies all GetObject requests unless the caller uses TLS; the denial events will create investigation logs automatically.
AnswerA

CloudTrail management events cover control-plane activity, not per-object access details in S3. Enabling S3 data events (object-level logging) causes CloudTrail to record events like GetObject and PutObject for the targeted bucket and prefixes. This directly addresses the missing visibility symptom described. It also limits logging scope when you specify the bucket/prefix.

Why this answer

CloudTrail management events do not include object-level operations like GetObject or PutObject. By enabling CloudTrail data events for the specific S3 bucket, you capture object-level read (GetObject) and write (PutObject) API calls, including those for encrypted objects, providing the missing visibility for detective controls.

Exam trap

The trap here is that candidates confuse management events (which log bucket-level operations like CreateBucket) with data events (which log object-level operations like GetObject), assuming management events cover all S3 activity.

Why the other options are wrong

B

AWS Config does not generate GetObject logs; it tracks resource configuration changes and compliance, not data plane operations like S3 object access.

C

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) but do not log S3 API operations like GetObject or PutObject; they lack object-level details.

D

Denial events from a bucket policy that denies GetObject requests do not provide visibility into successful object access or writes; they only log denied attempts, not the actual GetObject or PutObject operations needed for detective controls.

When would these options actually be correct?

B

A question asking how to automatically detect and alert on S3 bucket policies that allow public access or are noncompliant with security standards, using AWS Config rules.

C

A question asking for network-level visibility into traffic to/from an S3 gateway endpoint (e.g., to detect unusual data transfer volumes or IP addresses) would make VPC Flow Logs the correct answer.

D

If the question asked for a method to enforce encryption in transit for S3 access and log any non-compliant requests for security auditing, then adding a bucket policy that denies GetObject unless TLS is used would be correct, as it generates denial logs for non-TLS requests.

Why candidates pick the wrong answer

B

Candidates may confuse AWS Config's compliance monitoring with logging capabilities, thinking it can produce object-level access logs when it only evaluates configuration states.

C

Candidates may confuse network traffic logs with application-level API logs, assuming that all data movement is captured at the network layer, or they may overestimate the granularity of VPC Flow Logs.

D

Candidates may think that any policy action that generates logs provides visibility, but they overlook that detective controls require logging of successful operations, not just denials.

332
MCQmedium

A trading dashboard stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured? The architecture review board prefers a managed AWS-native control.

A.An EBS snapshot schedule
B.S3 Cross-Region Replication with versioning enabled
C.S3 lifecycle transition to Glacier Flexible Retrieval
D.A CloudFront distribution
AnswerB

S3 Cross-Region Replication requires versioning enabled on both the source and destination buckets and asynchronously replicates every new object upload to a chosen destination Region. This creates a geographically separate, durable copy of the trading dashboard's documents, satisfying disaster-recovery requirements without manual intervention. Versioning is also essential because CRR relies on object version IDs to track replication state and to replicate delete markers or overwrites consistently.

Why this answer

S3 Cross-Region Replication (CRR) is the correct AWS-native managed solution for automatically replicating objects from a source S3 bucket in one region to a destination bucket in another region, meeting the disaster recovery requirement. Versioning must be enabled on both source and destination buckets for CRR to function, as replication relies on version IDs to track and copy objects. This provides asynchronous, automatic replication without custom scripting or third-party tools.

Exam trap

The trap here is that candidates may confuse S3 lifecycle policies (which only manage storage tiers within a region) with cross-region replication, or incorrectly assume CloudFront's global edge caching provides durable DR storage in another region.

How to eliminate wrong answers

Option A is wrong because EBS snapshots are for Amazon Elastic Block Store volumes attached to EC2 instances, not for S3 objects; they cannot replicate data across regions for S3-based storage. Option C is wrong because S3 lifecycle transitions to Glacier Flexible Retrieval only change the storage class within the same region for cost optimization, not replicate data to another region for disaster recovery. Option D is wrong because CloudFront is a content delivery network (CDN) that caches content at edge locations for low-latency access, but it does not provide cross-region replication or persistent storage in a secondary region for DR.

333
MCQmedium

A high-frequency trading analytics service runs on several EC2 instances in the same Availability Zone. The application exchanges small messages between nodes and is sensitive to microsecond-level network latency. Which design best meets the requirement?

A.Place the instances in a cluster placement group in one Availability Zone.
B.Place the instances in a spread placement group across multiple Availability Zones.
C.Place the instances in a partition placement group within one Availability Zone.
D.Deploy the instances behind an Application Load Balancer in multiple Availability Zones.
AnswerA

A cluster placement group places instances physically close together within one Availability Zone, which improves network throughput and reduces latency between nodes. That is the right fit for tightly coupled workloads that exchange frequent small messages and need the lowest possible east-west latency. It also keeps the design simple because the application already runs in a single AZ.

Why this answer

A cluster placement group is designed for low-latency, high-throughput scenarios by placing instances in a single Availability Zone with non-blocking, fully bisectioned bandwidth and microsecond-level latency. This meets the requirement for microsecond-sensitive inter-node communication in high-frequency trading.

Exam trap

The trap here is that candidates confuse 'fault isolation' (spread/partition groups) with 'performance optimization' (cluster groups), or assume a load balancer can reduce latency when it actually adds overhead.

Why the other options are wrong

B

Spread placement groups are designed to reduce correlated failures by placing instances across distinct hardware, but they do not provide the low-latency, high-bandwidth network performance required for microsecond-level latency. Additionally, placing instances across multiple Availability Zones increases network distance and latency.

C

Partition placement groups are designed to reduce correlated hardware failures for large distributed workloads like HDFS or Cassandra, not to minimize network latency. They do not provide the low-latency, high-bandwidth network performance required for microsecond-level inter-node communication.

D

An Application Load Balancer (ALB) operates at Layer 7 and introduces significant latency (milliseconds), which is unacceptable for microsecond-sensitive trading. It also distributes traffic across AZs, increasing latency further.

When would these options actually be correct?

B

A question requiring high availability and fault isolation for a small number of critical instances, such as a distributed application that must survive an Availability Zone failure, where low latency is not the primary concern.

C

A question asks for a fault-tolerant deployment for a large-scale data processing job (e.g., Hadoop or Kafka) that must tolerate rack-level failures while still providing some network isolation. Partition placement groups spread instances across logical partitions, each with its own rack, to reduce the impact of a single rack failure.

D

For a web application requiring high availability, fault tolerance, and automatic scaling across multiple Availability Zones, with traffic distributed at the application layer (e.g., HTTP/HTTPS).

Why candidates pick the wrong answer

B

Candidates may think that spreading instances across multiple Availability Zones improves both fault tolerance and performance, but they overlook that this increases latency, which is unacceptable for latency-sensitive applications.

C

Candidates may confuse partition placement groups with cluster placement groups, assuming both offer low latency, or they may think that any placement group within one AZ improves network performance, overlooking the specific design goals of each type.

D

Candidates may think load balancing always improves performance and availability, overlooking the extreme low-latency requirement that makes ALB's overhead unsuitable.

334
MCQmedium

A marketing site has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations?

A.AWS Shield
B.AWS Compute Optimizer
C.AWS DataSync
D.AWS Artifact
AnswerB

AWS Compute Optimizer analyses CloudWatch metrics from EC2 instances to generate rightsizing recommendations, flagging over-provisioned CPU, memory and network capacity. It directly satisfies the stem's requirement to identify oversized instances, unlike Trusted Advisor's narrower checks or Cost Explorer's spend-only view.

Why this answer

AWS Compute Optimizer analyzes historical utilization metrics (CPU, memory, network, and storage) from CloudWatch and uses machine learning to identify over-provisioned or under-provisioned EC2 instances. It generates actionable rightsizing recommendations, including instance type changes, to optimize cost and performance. This directly addresses the scenario of oversized EC2 instances.

Exam trap

The trap here is confusing AWS Compute Optimizer with AWS Trusted Advisor, which also provides cost optimization checks but does not offer the same ML-driven, granular rightsizing recommendations for EC2 instances.

How to eliminate wrong answers

Option A is wrong because AWS Shield is a managed DDoS protection service, not a resource optimization or rightsizing tool. Option C is wrong because AWS DataSync is a data transfer service for moving large datasets between on-premises storage and AWS, not for analyzing instance utilization or making rightsizing recommendations. Option D is wrong because AWS Artifact is a self-service portal for downloading compliance reports and agreements (e.g., SOC, PCI), not a cost optimization or rightsizing service.

335
MCQhard

A genomics company stores 400 TB of compressed reference data in Amazon S3. Researchers in an on-premises lab must run high-throughput reads of this data over a 10 Gbps AWS Direct Connect connection. The team observes that reads are slower than expected and wants to maximize throughput per S3 request while minimizing request costs. Which S3 feature should they implement?

A.S3 Cross-Region Replication to a bucket in the lab's nearest Region.
B.S3 byte-range fetches using parallel GET requests against the same object.
C.S3 Transfer Acceleration on the bucket, because it speeds up long-distance transfers.
D.S3 Intelligent-Tiering to automatically move frequently accessed data to a faster tier.
AnswerB

Byte-range fetches let a client issue multiple concurrent GET requests for different portions of one large object, which multiplies achievable throughput and uses the available Direct Connect bandwidth more fully. This is the standard S3 pattern for high-throughput reads of large objects and can reduce total request cost by retrieving full object data efficiently.

Why this answer

Large-object throughput in S3 scales with concurrent connections, so issuing parallel byte-range GETs against each object saturates the Direct Connect link far better than a single sequential GET. Transfer Acceleration targets internet paths, replication moves copies without changing read mechanics, and Intelligent-Tiering is a cost tool rather than a throughput tool.

Exam trap

The trap here is reaching for Transfer Acceleration whenever S3 feels slow, even when the workload already uses private Direct Connect connectivity.

336
MCQeasy

You manage multiple AWS accounts under AWS Organizations. A compliance requirement states: no account is allowed to create new IAM access keys for IAM users. Local administrators may attempt to override permissions. Which mechanism should you use to enforce this guardrail across all accounts?

A.An IAM permissions policy attached to a role that only your security team uses
B.An Organizations service control policy (SCP) that explicitly denies CreateAccessKey
C.A KMS key policy that blocks key creation and reuse
D.A permission boundary on a single IAM role
AnswerB

SCPs provide guardrails that apply to all principals in member accounts. By explicitly denying the IAM action at the organization level, you can prevent access key creation even if local IAM policies would otherwise allow it.

Why this answer

An SCP is the correct mechanism because it operates at the AWS Organizations root, OU, or account level to define a central guardrail that cannot be overridden by any IAM principal, including account administrators. By explicitly denying the `iam:CreateAccessKey` action, the SCP ensures that no IAM user in any account can create new access keys, fulfilling the compliance requirement across all accounts.

Exam trap

The trap here is that candidates often confuse SCPs with IAM permission boundaries or think that a restrictive IAM policy on a single role can enforce a global guardrail, but only SCPs provide organization-wide, unoverridable control over all principals.

Why the other options are wrong

A

An IAM permissions policy attached to a role used only by the security team cannot enforce a guardrail across all accounts because it only applies to principals assuming that role, not to all IAM users in every account. Local administrators in other accounts can still create access keys unless explicitly denied by a centralized policy like an SCP.

C

KMS key policies control encryption key usage, not IAM user actions like creating access keys. They cannot enforce a guardrail against IAM operations across accounts.

D

A permission boundary applies only to a single IAM role, not to all users and roles across multiple accounts, so it cannot enforce the guardrail organization-wide.

When would these options actually be correct?

A

This option would be correct in a scenario where the requirement is to restrict access key creation only for users who assume a specific role (e.g., a cross-account role used by security auditors), and the organization does not need to enforce the restriction on all users across all accounts.

C

A question requiring encryption key management restrictions, such as 'You need to prevent users from disabling or deleting a specific KMS key used for S3 bucket encryption across multiple accounts.' In that case, a KMS key policy with explicit deny statements would be the correct mechanism.

D

In a scenario where you need to restrict the maximum permissions for a specific IAM role (e.g., a developer role) without affecting other roles or users, a permission boundary would be the correct mechanism.

Why candidates pick the wrong answer

A

Candidates may think that attaching a deny policy to a security team role is a simple way to enforce restrictions, but they overlook that it only applies to that role's sessions, not to all IAM users in the organization.

C

Candidates may confuse 'key' in KMS with 'access key' and think KMS policies can control access key creation, or they may mistakenly believe KMS policies can enforce IAM actions.

D

Candidates may confuse permission boundaries with service control policies, thinking they can be applied broadly, but permission boundaries are limited to individual IAM entities.

337
MCQhard

A financial analytics platform runs a stateless containerized service on Amazon ECS with AWS Fargate tasks spread across three Availability Zones. The service reads from an Amazon Aurora MySQL cluster and must continue serving read traffic if one Availability Zone fails. The team wants the read capacity to remain available with the least operational overhead and no changes to application connection strings during a zone failure. Which approach meets these requirements?

A.Place a Network Load Balancer in front of each Aurora Replica and configure the service to connect through the load balancer DNS name.
B.Add Aurora Replicas in multiple Availability Zones and connect the service to the cluster reader endpoint so reads are load-balanced and fail over automatically.
C.Increase the size of the Aurora writer instance so it can absorb read traffic if a replica becomes unavailable.
D.Create a separate Aurora cluster in each Availability Zone and have the service choose a cluster endpoint based on a health check.
AnswerB

Aurora Replicas in different Availability Zones provide redundant read capacity, and the cluster reader endpoint automatically distributes connections across healthy replicas. If a zone fails, Aurora removes the affected replica from the endpoint, so the application keeps reading without changing connection strings, satisfying the low-overhead and no-reconfiguration requirements.

Why this answer

The Aurora cluster reader endpoint is purpose-built to distribute read connections across replicas and to remove unhealthy replicas, including those in a failed Availability Zone. Deploying replicas in multiple zones and using that endpoint delivers automatic read failover with no application changes and minimal operational effort.

Exam trap

The trap here is adding external load balancing or per-zone clusters when Aurora's reader endpoint already provides managed read distribution and failover.

338
MCQhard

Based on the exhibit, a DynamoDB-backed event processing system is throttling during a promotion. The table uses tenantId as the partition key and eventTime as the sort key. One tenant accounts for most of the write traffic, and the application must preserve fast lookups for that tenant without relying on a single hot partition. What change is the best fix?

A.Add a sharding suffix to the partition key, such as tenantId#shardId, and query across the tenant's shards.
B.Enable DynamoDB Streams so the table can process writes more quickly.
C.Switch the table to on-demand capacity mode and keep the same key design.
D.Add a global secondary index on eventTime and query the index instead of the base table.
AnswerA

Sharding the partition key spreads ACME traffic across multiple partitions, which removes the hot key problem. Because the application still needs tenant-scoped time-range queries, it can fan out across the shard values and merge results.

Why this answer

Adding a sharding suffix (e.g., tenantId#shardId) to the partition key distributes write traffic for the hot tenant across multiple partitions, eliminating the single-partition bottleneck while preserving fast lookups by querying across all shards for that tenant. DynamoDB's partition key determines physical storage; without sharding, all writes for the hot tenant land on one partition, causing throttling even if the table has sufficient total capacity.

Exam trap

The trap here is that candidates often assume on-demand mode (Option C) eliminates all throttling, but it does not resolve the physical partition limit—a single hot partition still caps at 1,000 WCU/3,000 RCU, so throttling persists regardless of capacity mode.

How to eliminate wrong answers

Option B is wrong because enabling DynamoDB Streams does not increase write throughput; it captures item-level changes asynchronously and does not alleviate throttling caused by a hot partition. Option C is wrong because switching to on-demand capacity mode only removes the need to provision capacity manually, but it does not solve the underlying hot partition issue—DynamoDB still throttles if a single partition exceeds 1,000 WCU or 3,000 RCU, regardless of capacity mode. Option D is wrong because adding a GSI on eventTime does not distribute write load; the base table's partition key remains tenantId, so the hot tenant still causes throttling on the base table, and the GSI inherits the same write patterns.

339
MCQeasy

A microservice needs to read exactly one secret value from AWS Secrets Manager. Which IAM permission statement provides the best least-privilege approach to allow the microservice to retrieve that secret value?

A.Allow secretsmanager:GetSecretValue on all secrets using Resource: "*"
B.Allow secretsmanager:GetSecretValue only on the specific secret ARN required by the service
C.Allow secretsmanager:* on the secret name prefix using a wildcard pattern
D.Allow secretsmanager:GetSecretValue on the AWS account root ARN
AnswerB

Restricting the Resource to the exact Secrets Manager secret ARN limits retrieval to only that secret. This minimizes exposure and follows least-privilege practices. (If the secret is encrypted with a customer-managed KMS key, additional KMS permissions may be required for decrypting the ciphertext, but the Secrets Manager permission itself should still be scoped tightly.)

Why this answer

It grants the minimum necessary permission—secretsmanager:GetSecretValue—scoped to the exact Amazon Resource Name (ARN) of the secret the microservice needs. This follows the AWS least-privilege principle by restricting access to a single action on a single resource, preventing the microservice from reading other secrets even if compromised.

Exam trap

The trap here is that candidates often choose a broad wildcard or 'all resources' permission (Option A or C) thinking it simplifies management, but the SAA-C03 exam consistently tests the principle of least privilege by requiring the most restrictive resource and action scope.

How to eliminate wrong answers

Option A is wrong because using Resource: '*' allows the microservice to retrieve any secret in the account, violating least privilege by granting broad read access. Option C is wrong because allowing secretsmanager:* on a wildcard prefix grants all Secrets Manager actions (including rotation, deletion, and tagging) on multiple secrets, far exceeding the single read requirement. Option D is wrong because the AWS account root ARN is not a valid resource ARN for Secrets Manager; secrets are identified by their own ARNs, not the root account ARN.

340
MCQmedium

A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ASG uses the ALB target group health checks to decide when instances are healthy (for example, by using the ELB/target-group health check integration). During a deployment, the ASG performs instance replacement. Shortly after the deployment starts and while new instances are still bootstrapping, CloudWatch shows the ALB target group briefly has zero healthy targets, and users intermittently receive 502 responses. Which ASG deployment configuration best reduces the chance that there will be a period with zero healthy ALB targets, while still keeping failover behavior resilient?

A.Set the target group HealthCheckGracePeriod to a very short value so the ALB quickly declares instances healthy or unhealthy.
B.Use an ASG rolling update approach that launches replacement instances first, ensures the new instances pass the ALB target group health checks, and only then terminates the old instances (for example, by configuring sufficient minimum healthy capacity and waiting on ALB health).
C.Disable ALB target group health checks and route traffic to any registered targets so replacements do not depend on health check status.
D.Reduce the ASG desired capacity by one instance during deployments so the replacement happens faster.
AnswerB

This sequencing avoids a “no healthy targets” window. By keeping capacity stable (or maintaining a minimum healthy percentage) and waiting for the new instances to be marked healthy by the ALB, traffic is only sent to healthy targets during replacement.

Why this answer

It describes a rolling update strategy that launches new instances first, waits for them to pass ALB target group health checks, and only then terminates old instances. This ensures that at all times during the deployment, there is a sufficient number of healthy instances to serve traffic, preventing the ALB target group from ever having zero healthy targets. The ASG's minimum healthy capacity setting and the wait for ALB health check integration guarantee that failover remains resilient because the old instances continue to handle requests until the new ones are fully ready.

Exam trap

The trap here is that candidates often think reducing the health check grace period or disabling health checks will speed up recovery, but in reality, these actions either cause premature removal of healthy instances or allow traffic to unhealthy instances, both of which increase the likelihood of 502 errors and reduce resilience.

How to eliminate wrong answers

Option A is wrong because setting the HealthCheckGracePeriod to a very short value does not prevent zero healthy targets; it merely reduces the delay before the ALB marks instances as unhealthy, which could actually cause the ALB to prematurely remove instances and exacerbate the problem. Option C is wrong because disabling ALB target group health checks would cause the ALB to route traffic to any registered targets regardless of their actual health, leading to increased 502 errors and no failover resilience. Option D is wrong because reducing the ASG desired capacity by one instance during deployments does not address the root cause of zero healthy targets; it only reduces the number of instances being replaced, but the replacement process still creates a gap where old instances are terminated before new ones are healthy.

341
Multi-Selecthard

A internal reporting portal has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances? The architecture review board prefers a managed AWS-native control.

Select 2 answers
A.Disable CloudTrail logging
B.Stop all EC2 instances in the account
C.Delete unattached EBS volumes after verifying they are no longer needed
D.Apply snapshot lifecycle policies to expire obsolete snapshots
AnswersC, D

Unattached EBS volumes in an 'available' state continue to incur per-GB-month charges because AWS bills for allocated block storage capacity regardless of whether a volume is attached to an instance. After verifying that each orphaned volume contains no critical data or that its data is already safely backed up, deleting the volume is the direct, effective way to eliminate that recurring cost and is the primary cost optimization in this scenario.

Why this answer

Unattached EBS volumes incur storage costs without providing any benefit to running instances. Deleting them after verification directly reduces costs while having zero impact on running workloads. Option D is correct because snapshot lifecycle policies automate the deletion of obsolete snapshots based on age or count, eliminating manual cleanup and reducing storage costs without affecting running instances.

Exam trap

The trap here is that candidates may confuse stopping instances (which stops billing for instance hours but not for EBS storage) with a cost-saving measure, or think disabling logging reduces storage costs, when the actual savings come from removing orphaned storage resources.

342
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be accessible only to users from a specific IP range, and the company wants to protect against common web exploits such as SQL injection and cross-site scripting. The company also wants to monitor and rate-limit requests from specific IP addresses. Which solution should a solutions architect implement?

A.Configure an AWS WAF web ACL with rules for IP matching, SQL injection, and cross-site scripting, and associate it with the ALB. Use rate-based rules to limit requests from specific IPs.
B.Deploy AWS Firewall Manager to create a security policy that includes AWS WAF rules for IP matching and rate limiting, and apply it to the ALB.
C.Configure an Amazon CloudFront distribution in front of the ALB, use AWS WAF with the CloudFront distribution, and set up geo-restriction to allow only specific IPs.
D.Use security groups on the ALB to allow traffic only from the specific IP range, and enable AWS Shield Advanced for protection against web exploits.
AnswerA

AWS WAF can be associated with an ALB to inspect incoming traffic. It provides managed rule groups for SQL injection and cross-site scripting, and you can create IP match conditions to allow only specific IP ranges. Rate-based rules automatically block IPs that exceed a request threshold, meeting the rate-limiting requirement. This is the most direct and effective solution.

Why this answer

AWS WAF integrated with the ALB provides the required protections: IP matching to restrict access to a specific IP range, managed rules for SQL injection and cross-site scripting, and rate-based rules to limit requests from specific IPs. This solution directly addresses all requirements without unnecessary components.

Exam trap

The trap here is confusing AWS Shield Advanced with AWS WAF; Shield protects against DDoS attacks, while WAF protects against application-layer exploits like SQL injection.

343
MCQhard

Based on the exhibit, the company stores application logs in Amazon S3 for 400 days. The logs are read heavily for the first 30 days, occasionally for the next 90 days, and very rarely after that. Retrieval after day 120 can take up to several hours, but the data must remain available until day 400. Which lifecycle policy is the most cost-effective fit?

A.Keep all logs in S3 Standard for 400 days and enable requester pays to reduce the company's bill.
B.Transition logs to S3 Standard-IA after 30 days, then to S3 Glacier Flexible Retrieval after 120 days, and expire them at 400 days.
C.Transition logs directly from S3 Standard to S3 Glacier Deep Archive after 30 days and expire them at 400 days.
D.Move logs to S3 Intelligent-Tiering only and disable lifecycle transitions because access is unpredictable.
AnswerB

This follows the access pattern and the retrieval-time requirement. S3 Standard fits the heavy-read period in the first 30 days. Standard-IA is a lower-cost choice for the next 90 days when access is only occasional, and Glacier Flexible Retrieval is appropriate after day 120 because the logs are rarely read and can tolerate retrieval in hours. Expiration at day 400 satisfies the retention requirement exactly.

Why this answer

It aligns the storage class transitions with the access patterns: S3 Standard for the first 30 days (heavy reads), S3 Standard-IA for the next 90 days (occasional reads), and S3 Glacier Flexible Retrieval for the remaining period (rare access, with retrieval up to several hours acceptable). This minimizes storage costs while ensuring data availability until day 400, where lifecycle expiration removes the objects.

Exam trap

The trap here is that candidates may choose Option C (S3 Glacier Deep Archive) because it is the cheapest storage class, but they overlook the occasional access requirement between days 30 and 120 and the retrieval time constraints, which make S3 Glacier Flexible Retrieval the correct choice for the final tier.

How to eliminate wrong answers

Option A is wrong because keeping all logs in S3 Standard for 400 days is the most expensive option, and enabling requester pays does not reduce the company's bill for storage costs—it only shifts the cost of data retrieval to the requester, which is irrelevant here as the company owns the data. Option C is wrong because transitioning directly from S3 Standard to S3 Glacier Deep Archive after 30 days ignores the occasional access needs between days 30 and 120; Deep Archive has a retrieval time of 12–48 hours and is not suitable for data that may be accessed occasionally, plus it incurs a minimum storage charge of 180 days. Option D is wrong because S3 Intelligent-Tiering is designed for unpredictable access patterns, but here the access pattern is predictable (heavy, occasional, rare), and disabling lifecycle transitions would prevent automatic cost optimization, leading to higher costs than a tailored lifecycle policy.

344
MCQeasy

A Lambda function processes CPU-heavy JSON transformations and often runs slower than expected. The team wants to improve performance without changing the code. What should they try first?

A.Increase the Lambda memory setting
B.Move the function to Amazon S3
C.Change the function to an ALB target
D.Disable CloudWatch logging
AnswerA

Increasing the Lambda memory setting directly allocates more proportional vCPU power to the function. This is crucial for CPU-heavy JSON transformations because it provides the necessary computational resources to execute the intensive processing faster. By boosting the available vCPU, the function can complete its work more efficiently, directly addressing the performance constraint of slow execution without requiring any code modifications.

Why this answer

Increasing the Lambda memory setting allocates more CPU power proportionally, as AWS Lambda allocates CPU credits linearly with memory (up to 10,240 MB). For CPU-heavy JSON transformations, this directly reduces execution time without any code changes, making it the simplest and most effective first step.

Exam trap

The trap here is that candidates assume performance issues must be solved by code optimization or architectural changes, overlooking that Lambda's memory setting directly controls CPU power, making it the simplest fix for CPU-bound functions.

Why the other options are wrong

B

Moving a Lambda function to Amazon S3 is not possible because S3 is a storage service, not a compute service. Lambda functions cannot be hosted or executed on S3.

C

Changing the function to an ALB target does not improve CPU-heavy JSON transformation performance; it only changes how the function is invoked, not its execution resources.

D

Disabling CloudWatch logging does not improve CPU-bound performance; it only reduces logging overhead, which is negligible for CPU-heavy transformations.

When would these options actually be correct?

B

A question asks how to reduce costs for infrequently accessed data that must be stored for compliance. The correct answer would be to move the data to Amazon S3 Glacier or S3 Standard-IA, not the function itself.

C

When a question asks how to expose a Lambda function over HTTP/HTTPS with path-based routing or to integrate with an existing ALB, and the function is not already behind an API Gateway, then making it an ALB target would be correct.

D

A Lambda function is experiencing timeouts due to excessive logging (e.g., logging large payloads in a tight loop). Disabling or reducing logging would free up execution time and prevent throttling, making it the correct first step.

Why candidates pick the wrong answer

B

Candidates may confuse moving the function's code to S3 (e.g., storing deployment packages) with moving the function itself, or think S3 can execute code like Lambda.

C

Candidates may think that routing through an ALB can offload processing or improve performance, but ALB is a load balancer for HTTP traffic, not a compute optimizer.

D

Candidates may think logging consumes significant resources and disabling it will speed up execution, but for CPU-heavy tasks, the bottleneck is compute, not I/O from logging.

345
MCQhard

A financial services company stores monthly regulatory reports in an Amazon S3 bucket. The reports are accessed frequently for the first 60 days after creation for audits and internal review. After that period, they are almost never accessed but must be retained for seven years and retrieved within 12 hours if a regulator requests them. The compliance team requires that the objects remain in a single bucket and that retrieval costs be minimized. Which storage solution meets these requirements MOST cost-effectively?

A.Use S3 Intelligent-Tiering and let it move objects between frequent and infrequent access tiers automatically.
B.Keep all objects in S3 Standard and rely on S3 Versioning to reduce storage charges over time.
C.Apply a lifecycle policy that transitions objects to S3 Glacier Flexible Retrieval after 60 days.
D.Apply a lifecycle policy that transitions objects to S3 Glacier Instant Retrieval after 60 days.
AnswerC

S3 Glacier Flexible Retrieval is an archive class that supports retrieval in minutes to hours, and its Standard retrieval option completes within 3 to 5 hours, comfortably inside the 12-hour requirement. It has lower storage cost than S3 Standard and Glacier Instant Retrieval, so transitioning objects after the 60-day active period minimizes cost while meeting the retrieval and retention requirements.

Why this answer

The objects are hot for 60 days and then cold for years, with a retrieval-time requirement measured in hours rather than milliseconds. A lifecycle transition to S3 Glacier Flexible Retrieval after 60 days matches that pattern: it lowers storage cost for the long retention period and its standard retrieval completes well within 12 hours. Keeping everything in a single bucket is supported because lifecycle rules operate within the bucket.

Exam trap

The trap here is conflating Glacier Instant Retrieval with Glacier Flexible Retrieval, since the word Glacier appears in both but only the flexible class is appropriate when hours, not milliseconds, are acceptable for retrieval.

346
MCQmedium

A test environment has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations?

A.AWS DataSync
B.AWS Shield
C.AWS Artifact
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer uses machine learning to analyze historical CloudWatch telemetry, including CPU, memory, I/O, and network utilization, and generates right-sizing recommendations for EC2 instances, Auto Scaling groups, and EBS volumes. It identifies underutilized or overprovisioned instances, providing confidence scores and potential cost savings, which directly addresses the oversized compute problem. For existing resources, it offers optimized findings and can suggest smaller instance types based on observed load.

Why this answer

AWS Compute Optimizer uses machine learning to analyze historical utilization metrics (CPU, memory, network, and storage) and provides rightsizing recommendations for EC2 instances, including over-provisioned resources. It helps reduce costs by suggesting instance types or sizes that better match actual workload demands.

Exam trap

The trap here is that candidates may confuse AWS Compute Optimizer with AWS Trusted Advisor, but Trusted Advisor provides general cost optimization checks (e.g., idle instances) while Compute Optimizer delivers granular, ML-driven rightsizing recommendations for specific instance types.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is a data transfer service for moving large datasets between on-premises storage and AWS services, not a resource optimization tool. Option B is wrong because AWS Shield is a managed DDoS protection service that safeguards applications from distributed denial-of-service attacks, not a rightsizing advisor. Option C is wrong because AWS Artifact is a self-service portal for accessing AWS compliance reports and agreements, such as SOC and PCI reports, and does not provide compute optimization recommendations.

347
MCQmedium

A legacy market-data service runs on EC2 and exposes a custom TCP protocol. Clients must connect over TCP with very low latency, and the team wants static IP addresses at the load-balancing layer. Which AWS service is the best fit?

A.Application Load Balancer, because it provides advanced routing for all protocols.
B.Network Load Balancer, because it supports TCP, static IPs, and very low latency.
C.Amazon API Gateway, because it can front any network protocol with throttling.
D.Amazon CloudFront, because it can route traffic to EC2 instances at the edge.
AnswerB

A Network Load Balancer is the best fit for a custom TCP service that needs extremely low latency and static IP addresses. NLB operates at Layer 4, preserves high throughput, and is commonly used when protocol simplicity and performance matter more than application-layer routing features. It matches the workload's network requirements without adding unnecessary HTTP-specific behavior.

Why this answer

The Network Load Balancer (NLB) operates at Layer 4, supports TCP traffic natively, provides static IP addresses per Availability Zone, and delivers very low latency by processing packets without inspecting application-layer headers. This makes it the ideal choice for a legacy market-data service that requires a custom TCP protocol and fixed IPs at the load-balancing layer.

Exam trap

The trap here is that candidates often confuse the ALB's 'advanced routing' capabilities with support for all protocols, but ALB is strictly Layer 7 and cannot handle raw TCP or custom protocols, making NLB the only correct choice for TCP with static IPs and low latency.

Why the other options are wrong

A

Application Load Balancer does not support TCP at the transport layer; it operates at Layer 7 (HTTP/HTTPS) and cannot handle custom TCP protocols. It also does not provide static IP addresses.

C

Amazon API Gateway does not support custom TCP protocols; it only handles HTTP/HTTPS and WebSocket traffic, and it does not provide static IP addresses at the load-balancing layer.

When would these options actually be correct?

A

An Application Load Balancer would be correct for a web application requiring advanced HTTP/HTTPS routing (e.g., path-based or host-based routing) with SSL termination, where static IPs are not needed and clients use HTTP/HTTPS.

C

A question asking for a fully managed service to expose RESTful APIs or WebSocket endpoints with throttling, caching, and authentication, where the backend is an AWS service like Lambda or HTTP endpoints.

Why candidates pick the wrong answer

A

Candidates may assume ALB supports all protocols because it is a common load balancer, or they confuse its Layer 7 capabilities with Layer 4, overlooking the requirement for custom TCP and static IPs.

C

Candidates may think API Gateway can handle any protocol because it supports WebSocket, or they confuse its throttling and routing features with load balancing capabilities.

348
MCQhard

A claims workflow uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The team wants the control to be enforceable during normal operations.

A.A FIFO queue without a redrive policy
B.Short polling instead of long polling
C.A dead-letter queue with an appropriate maxReceiveCount
D.A larger message retention period only
AnswerC

A dead-letter queue with an appropriate maxReceiveCount is the formal SQS mechanism for poison messages. When a message is received more times than the configured threshold (e.g., 5), SQS automatically moves it to the DLQ using the source queue's redrive policy, isolating it from normal traffic. This lets the main queue continue processing healthy messages, while engineers can inspect and debug the quarantined messages later without disrupting the workflow.

Why this answer

A dead-letter queue (DLQ) with an appropriate maxReceiveCount is the correct solution because it automatically moves messages that have failed processing a specified number of times to a separate queue, preventing them from blocking subsequent retries. This enforces control during normal operations by isolating poison messages without manual intervention, allowing the main queue to continue processing valid messages.

Exam trap

The trap here is that candidates may confuse a dead-letter queue with simply increasing retention or changing polling methods, failing to recognize that only a DLQ with a maxReceiveCount enforces automatic removal of poison messages during normal operations.

How to eliminate wrong answers

Option A is wrong because a FIFO queue without a redrive policy does not handle poison messages; it only preserves message order and exactly-once processing, but without a DLQ, failed messages will continue to be retried indefinitely. Option B is wrong because short polling (returning immediately even if the queue is empty) does not address poison messages; it affects message availability timing, not retry behavior or failure handling. Option D is wrong because increasing the message retention period only extends how long messages stay in the queue; it does not limit retries or remove failing messages, so poison messages would still block retries until the retention period expires.

349
MCQeasy

A startup runs a small internal tool on a single Amazon EC2 instance that uses an instance store volume for its database files. After a routine host maintenance event, the instance rebooted and the database was empty. The team wants the data to persist independently of the instance lifecycle and to survive a stop-and-start of the instance. What should they change?

A.Enable termination protection on the instance and take an AMI of the instance before each maintenance window.
B.Increase the size of the instance store volume and enable detailed monitoring on the instance.
C.Move the database files to an Amazon EBS volume attached to the instance.
D.Place the instance in an Auto Scaling group with a minimum capacity of one so it is relaunched after maintenance.
AnswerC

Amazon EBS volumes are network-attached block storage that persists independently of the instance and remains available across stop and start operations within the same Availability Zone. Data is retained when the host is replaced, which directly fixes the loss the team observed. This is the standard persistent storage choice for EC2 databases.

Why this answer

Instance store volumes are physically attached to the host and their contents are lost when the host stops, fails, or is replaced during maintenance. Amazon EBS volumes live separately from the instance and retain data across stop and start, making them the correct storage layer for a database that must persist. The other options address compute lifecycle or monitoring rather than data durability.

Exam trap

The trap here is assuming that any storage attached to an instance survives a host event, when instance store is explicitly ephemeral.

350
MCQeasy

A database administrator wants a regular backup of an Amazon RDS database so the team can restore to a recent point in time if needed. Which AWS feature should they use?

A.RDS automated backups and snapshots
B.Amazon Route 53 alias records
C.Security groups
D.AWS WAF rules
AnswerA

RDS automated backups are enabled by default and provide a daily snapshot of the database plus transaction logs captured every five minutes. This combination enables point-in-time recovery to any second within the configured retention window, which can be set from 1 to 35 days. Manual snapshots, on the other hand, are user-initiated, persist indefinitely, and provide a baseline that can be used to restore a database after the automated retention period has lapsed. Together, these backup mechanisms are purpose-built for database recovery and are the correct way to ensure backup and restore capability for Amazon RDS.

Why this answer

Amazon RDS automated backups and snapshots provide the ability to restore a database to any point within the backup retention period (up to 35 days). Automated backups include transaction logs for point-in-time recovery, while manual snapshots are user-initiated backups stored until explicitly deleted. This directly meets the requirement for regular backups and point-in-time restore capability.

Exam trap

The trap here is that candidates may confuse security groups or WAF rules with backup mechanisms because they are common security services, but they have no role in data persistence or recovery.

Why the other options are wrong

B

Amazon Route 53 alias records are used for DNS routing, not for database backup or point-in-time recovery of RDS instances.

C

Security groups act as a virtual firewall for controlling inbound and outbound traffic to RDS instances, but they do not provide backup or point-in-time recovery capabilities.

D

AWS WAF rules are used to filter and monitor HTTP/HTTPS traffic to protect web applications from common web exploits, not for database backup or point-in-time recovery.

When would these options actually be correct?

B

A question asks: 'Which AWS service can be used to route traffic to an RDS database with a custom domain name?' In that context, Route 53 alias records would be correct.

C

A question asks: 'Which AWS feature should be used to restrict network access to an RDS database to only allow traffic from a specific application server?' In that scenario, security groups would be the correct answer.

D

A question asking how to block SQL injection or cross-site scripting attacks against an Application Load Balancer or CloudFront distribution would make AWS WAF rules the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse 'alias records' with 'backup records' or think Route 53 manages database snapshots due to its broad management capabilities.

C

Candidates may confuse security groups with database backup features because both are common RDS configuration tasks, leading them to select a familiar option without reading the question carefully.

D

Candidates might confuse 'rules' for backup policies or think WAF provides some form of data protection, but WAF is a web application firewall, not a backup service.

351
MCQmedium

A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include?

A.Subnets in at least two Availability Zones with health checks enabled
B.All instances in one larger subnet
C.A Network Load Balancer in one subnet
D.A single EC2 instance with detailed monitoring
AnswerA

Deploying an Auto Scaling group across subnets in at least two Availability Zones (AZs) is the core of high availability. Each AZ is an isolated failure domain, so if one AZ fails, the ASG continues to run instances in the other AZ(es). Coupled with ELB or ASG health checks, the group automatically detects unhealthy instances—whether due to EC2 failure or AZ impairment—and replaces them, maintaining desired capacity and absorbing request traffic. This design avoids any single point of failure at both the compute and network layers.

Why this answer

An Auto Scaling group configured with subnets in at least two Availability Zones and health checks enabled ensures that if one AZ fails, EC2 instances in the remaining AZs continue to serve traffic. The Application Load Balancer distributes requests across healthy instances in multiple AZs, and the Auto Scaling group replaces failed instances in the affected AZ, maintaining capacity. This design meets the requirement to tolerate the failure of one Availability Zone.

Exam trap

The trap here is that candidates often think a single larger subnet or a different load balancer type provides resilience, but only distributing subnets across multiple Availability Zones with health checks ensures the system can survive an AZ failure.

How to eliminate wrong answers

Option B is wrong because placing all instances in one larger subnet within a single Availability Zone creates a single point of failure; if that AZ goes down, all instances become unavailable. Option C is wrong because a Network Load Balancer operates at Layer 4 and does not provide the HTTP/HTTPS health checks or path-based routing needed for a ticket booking system, and placing it in one subnet does not address multi-AZ resilience. Option D is wrong because a single EC2 instance, even with detailed monitoring, cannot survive an AZ failure; there is no redundancy or automatic failover.

352
MCQmedium

A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost? The architecture review board prefers a managed AWS-native control.

A.On-Demand Instances only
B.Dedicated Hosts
C.Spot Instances
D.Provisioned IOPS volumes
AnswerC

Spot Instances exploit spare EC2 capacity at discounts up to 90%, and the job's interruptible, restartable nature satisfies their two-minute interruption notice without data loss. The architecture review board's managed AWS-native constraint is met because Spot is an AWS-native purchasing model, not a third-party broker.

Why this answer

Spot Instances are correct because the batch job is fault-tolerant (can be interrupted and restarted) and runs for several hours each night, making it an ideal candidate for Spot Instances, which offer up to 90% cost savings compared to On-Demand. AWS-managed services like EC2 Auto Scaling or Amazon EMR can automatically handle Spot Instance interruptions by replacing instances or checkpointing the job, aligning with the architecture review board's preference for a managed AWS-native control.

Exam trap

The trap here is that candidates may choose On-Demand Instances (Option A) due to a misconception that Spot Instances are unreliable for any workload, failing to recognize that fault-tolerant, interruptible jobs like batch processing are exactly the use case for which Spot Instances are designed and recommended for cost optimization.

How to eliminate wrong answers

Option A is wrong because On-Demand Instances provide no interruption but are significantly more expensive than Spot Instances for fault-tolerant workloads, failing to minimize cost. Option B is wrong because Dedicated Hosts are designed for licensing or compliance requirements (e.g., per-socket or per-core licensing) and are the most expensive option, not cost-optimal for a batch job that can tolerate interruptions. Option D is wrong because Provisioned IOPS volumes are a storage type (EBS), not an EC2 purchasing option, and thus irrelevant to the question of minimizing compute cost.

353
MCQmedium

An application runs on EC2 instances in private subnets behind an Application Load Balancer (ALB). Security groups allow inbound HTTPS (443) from the ALB’s security group to the instance security group, and outbound from instances is set to allow ephemeral ports. Despite this, clients see connection timeouts. After reviewing network ACLs, you find the NACL associated with the instance subnet has an inbound allow for destination port 443, but it does not have a corresponding outbound allow for ephemeral ports. What is the most likely reason the traffic fails, and what should be updated?

A.NACLs are stateless, so you must update the NACL to allow the return (outbound) ephemeral port range; security groups alone cannot override a blocked NACL.
B.NACLs are stateful and automatically track connections; the fix is to add a new inbound rule to the security group for client source ports.
C.The issue is caused by ALB health checks; configure a new target group health check on port 80 so traffic can be routed.
D.Because instances are in private subnets, add a NAT gateway so return traffic can reach the internet over dynamic routing.
AnswerA

NACLs are stateless, so return traffic from instances to clients on ephemeral ports needs an explicit outbound allow; the missing rule drops responses, causing timeouts. Security groups are stateful and cannot bypass a NACL denial.

Why this answer

Network ACLs are stateless, meaning they do not automatically allow return traffic. Even though the security group allows inbound HTTPS from the ALB, the NACL blocks the response traffic because it lacks an outbound rule for ephemeral ports (typically 1024-65535). Since NACLs are evaluated before security groups, a missing outbound allow rule causes the connection to time out.

Exam trap

The trap here is that candidates assume security groups alone handle all traffic filtering, forgetting that NACLs are stateless and require explicit outbound rules for return traffic, especially for ephemeral ports.

Why the other options are wrong

B

NACLs are stateless, not stateful; they do not automatically track connections. The issue is missing outbound ephemeral port rules in the NACL, not security group inbound rules for client source ports.

C

The question describes connection timeouts due to missing outbound NACL rules for ephemeral ports, not health check failures. ALB health checks are not mentioned as failing, and changing the health check port does not address the stateless NACL issue.

D

The issue is not about internet connectivity; instances are in private subnets but the ALB is in a public subnet and handles internet-facing traffic. A NAT gateway is for outbound internet access from private instances, not for fixing return traffic blocked by a stateless NACL.

When would these options actually be correct?

B

This option would be correct if the question stated that NACLs are stateful and the security group was blocking return traffic. For example: 'An application uses a stateful firewall (like a security group) and clients see timeouts; what is the fix?'

C

In a scenario where an ALB target group health check is failing because the health check path or port is not configured correctly (e.g., the application listens on port 8080 but health check targets port 80), updating the health check to the correct port would resolve the issue.

D

In a scenario where EC2 instances in private subnets need to download updates from the internet, and the outbound NACL blocks ephemeral ports, adding a NAT gateway would be correct to allow outbound traffic and its return traffic.

Why candidates pick the wrong answer

B

Candidates may confuse NACLs with security groups, assuming NACLs are stateful like security groups, and think the fix involves adding inbound rules to the security group for client ports.

C

Candidates may confuse connectivity issues with health check misconfigurations, especially when ALB is involved, and assume that adjusting health check settings can fix general traffic flow problems.

D

Candidates may confuse network connectivity issues with internet access requirements, assuming private subnets always need a NAT gateway for any traffic flow, even when the traffic is internal to the VPC via an ALB.

354
MCQmedium

A company runs a three-tier web application on AWS. The database tier uses Amazon Aurora MySQL, and the application tier runs on Amazon EC2 instances behind an Application Load Balancer. A security audit reveals that the database credentials are stored in plaintext in a configuration file on the EC2 instances, and the same credentials have been in use for over a year. The security team must eliminate hardcoded credentials and ensure automatic rotation of the database password every 30 days without modifying application code to handle rotation events. Which solution meets these requirements with the LEAST operational overhead?

A.Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter and configure automatic rotation using a custom Lambda function that updates the parameter.
B.Store the database credentials in an encrypted Amazon S3 object and use an AWS Lambda function triggered by Amazon EventBridge to rotate the password and update the object every 30 days.
C.Store the database credentials in AWS Secrets Manager and enable automatic rotation using a Lambda rotation function. Grant the EC2 instance role permission to call secretsmanager:GetSecretValue.
D.Use IAM database authentication for Aurora MySQL so that the EC2 instances authenticate using their IAM role, eliminating the need for a database password.
AnswerC

AWS Secrets Manager natively supports automatic rotation of database credentials for Amazon Aurora MySQL by using a provided Lambda rotation function. The application retrieves the secret at runtime via the AWS SDK, and the EC2 instance role grants access through secretsmanager:GetSecretValue. This eliminates hardcoded credentials and rotates the password every 30 days without requiring application code changes to handle rotation events.

Why this answer

AWS Secrets Manager is designed for this exact use case: it stores database credentials securely and provides managed rotation for Amazon Aurora MySQL without custom code. The EC2 instance role grants access to the secret, and the application retrieves it at runtime. This removes hardcoded credentials and automates password rotation every 30 days, meeting the requirements with minimal operational effort.

Exam trap

The trap here is assuming that AWS Systems Manager Parameter Store provides automatic rotation for database credentials, when in fact it only stores parameters and requires a custom rotation implementation.

355
MCQhard

Based on the exhibit, a company wants EC2 instances in private subnets to access Amazon S3 without using a NAT gateway, and bucket access must be allowed only when requests come through the approved VPC endpoint. Which design is the most appropriate?

A.Use the S3 gateway VPC endpoint and keep the bucket policy that denies requests unless aws:SourceVpce matches the approved endpoint.
B.Use an interface VPC endpoint for S3 only, because gateway endpoints cannot be used with bucket policies.
C.Add a NAT gateway and remove the bucket policy condition because the NAT route will automatically secure the S3 traffic.
D.Move the bucket policy restriction to a security group attached to the S3 bucket so only the VPC endpoint can reach it.
AnswerA

For S3, a gateway VPC endpoint is the correct private-connectivity option for EC2 instances in private subnets. The route table sends S3 prefix-list traffic to the gateway endpoint, so requests stay on the AWS network instead of traversing a NAT gateway or the public internet. The bucket policy condition on aws:SourceVpce then ensures that even valid AWS-authenticated requests are accepted only when they arrive through the approved endpoint ID.

Why this answer

An S3 gateway VPC endpoint allows EC2 instances in private subnets to access S3 without traversing the internet or requiring a NAT gateway. By adding a bucket policy condition that denies access unless `aws:SourceVpce` matches the approved VPC endpoint ID, you ensure that only requests originating from that specific endpoint are allowed, meeting the security requirement.

Exam trap

The trap here is that candidates often confuse gateway endpoints with interface endpoints, assuming gateway endpoints cannot enforce bucket policies, or they mistakenly think security groups can be applied to S3 buckets, leading them to choose option D.

How to eliminate wrong answers

Option B is wrong because gateway endpoints for S3 can absolutely be used with bucket policies; in fact, the `aws:SourceVpce` condition is specifically designed for gateway endpoints. Option C is wrong because adding a NAT gateway would route traffic through the internet, which is unnecessary and violates the requirement to avoid using a NAT gateway; also, removing the bucket policy condition would leave the bucket open to any request, not just those through the VPC endpoint. Option D is wrong because S3 buckets do not support security groups; security groups are network-level constructs for EC2 instances and cannot be attached to S3 buckets.

356
Multi-Selectmedium

A solutions architect is designing a high-performance architecture for a real-time analytics application. The application ingests a continuous stream of data from thousands of IoT devices. The data must be processed in near real-time, and the results must be stored in a durable, scalable data store for later analysis. The architect needs to choose AWS services that can handle the ingestion and processing of the stream. (Choose two.)

Select 2 answers
A.Use Amazon Kinesis Data Streams to ingest the data.
B.Use AWS Glue to process the stream in real time.
C.Use Amazon Redshift to ingest the data directly from the devices.
D.Use Amazon SQS FIFO queues to ingest the data.
E.Use AWS Lambda to process the stream in real time.
AnswersA, E

Amazon Kinesis Data Streams is designed for real-time streaming data ingestion at scale. It can handle thousands of data sources and provides durable, ordered storage of records for up to 7 days. It integrates with AWS Lambda, Kinesis Data Analytics, and other services for processing. This makes it ideal for ingesting the continuous stream from IoT devices, ensuring high throughput and low latency for the analytics application.

Why this answer

Amazon Kinesis Data Streams provides a scalable, durable ingestion layer for real-time streaming data, capable of handling thousands of IoT devices. AWS Lambda can be integrated as a consumer to process records in near real-time, automatically scaling with the stream. Together, they form a serverless pipeline that ingests and processes data with low latency, and can write results to a durable store like S3 or DynamoDB.

Exam trap

The trap here is assuming that any queue or ETL service can handle real-time streaming; SQS FIFO is for message decoupling with ordering, and Glue is for batch ETL, not continuous stream processing.

357
Multi-Selectmedium

A media company stores daily financial exports in Amazon S3. The files must be protected against accidental overwrite or deletion, and the business also wants a second copy in another Region for recovery after a regional outage. Which two actions should the architect take? Select two.

Select 2 answers
A.Enable bucket versioning on the S3 bucket.
B.Turn on S3 Transfer Acceleration for the bucket.
C.Use only lifecycle policies to move objects to Glacier.
D.Configure replication to a bucket in a second AWS Region.
E.Enable S3 Block Public Access on the bucket.
AnswersA, D

Bucket versioning preserves every object revision, so an accidental overwrite creates a new version while the prior data remains intact, and a delete merely adds a delete marker rather than erasing the object. This directly satisfies the stem's requirement to protect the daily financial exports against accidental overwrite or deletion.

Why this answer

Option A is correct because enabling S3 bucket versioning preserves every prior version of an object, so an accidental overwrite creates a new version and an accidental delete only adds a delete marker, allowing the original data to be restored rather than lost. Option D is correct because S3 Cross-Region Replication (CRR) automatically copies objects to a bucket in a second AWS Region, providing the required second copy for recovery from a regional outage; versioning must be enabled on both source and destination buckets for replication to work. Option B is not relevant because S3 Transfer Acceleration only speeds up uploads over long distances using edge locations, and does not protect data or create a second copy.

Option C is not appropriate because lifecycle policies to Glacier change storage class and cost, not immutability, and do not provide cross-Region recovery. Option E is not relevant because S3 Block Public Access only prevents public exposure and does not protect against overwrite, deletion, or regional failure.

Exam trap

The trap here is that candidates may confuse S3 Transfer Acceleration or Block Public Access with data protection features, when in fact only versioning and replication directly address the requirements for preventing accidental deletion and providing cross-region recovery.

Why the other options are wrong

B

S3 Transfer Acceleration speeds up uploads over long distances but does not protect against accidental deletion or overwrite, nor does it create a cross-region copy for disaster recovery.

C

Lifecycle policies to move objects to Glacier provide cost optimization for long-term storage, but do not protect against accidental overwrite/deletion or provide cross-region recovery.

E

Block Public Access prevents public access to S3 objects but does not protect against accidental overwrite or deletion by authorized users, nor does it provide cross-region replication for disaster recovery.

When would these options actually be correct?

B

A company needs to upload large files from multiple global locations to a central S3 bucket and requires faster upload speeds. Enabling Transfer Acceleration would be the correct action to reduce upload latency.

C

An architect needs to reduce storage costs for infrequently accessed data that must be retained for compliance, with no requirement for immediate retrieval or cross-region redundancy.

E

An exam question where the requirement is to prevent public access to sensitive data stored in S3, such as financial records or personal information, and no other access controls are specified.

Why candidates pick the wrong answer

B

Candidates may confuse 'acceleration' with 'protection' or think it helps with replication, not realizing it only optimizes data transfer speed, not durability or availability.

C

Candidates may confuse lifecycle policies with data protection mechanisms, assuming moving to Glacier inherently secures data, or they may think Glacier's durability alone addresses the requirements.

E

Candidates may mistakenly think Block Public Access provides general data protection, confusing it with versioning or replication features that actually prevent overwrites and enable recovery.

358
MCQeasy

An order-processing application becomes slow when traffic spikes. The frontend should stay responsive even if downstream workers are temporarily overloaded. What should the team add to the design?

A.Amazon SQS queue between the frontend and the workers
B.A larger NAT Gateway
C.A single bigger EC2 instance for the worker
D.An Amazon Route 53 health check on the frontend
AnswerA

Amazon SQS acts as a durable buffer between the frontend and the worker instances, so incoming orders are immediately acknowledged and stored in the queue while workers consume messages at a pace they can handle. During a traffic spike, the queue absorbs the burst, preventing the frontend from being overwhelmed and allowing workers to scale out independently. It also provides at-least-once delivery and retries, which improves resilience when processing is temporarily slow or fails.

Why this answer

Adding an Amazon SQS queue between the frontend and the workers decouples the components, allowing the frontend to remain responsive by immediately offloading requests to the queue even when downstream workers are overloaded. The workers can then process messages at their own pace, and the queue acts as a buffer to absorb traffic spikes without blocking the frontend.

Exam trap

The trap here is that candidates often confuse scaling solutions (like larger instances or NAT Gateways) with decoupling patterns, failing to recognize that asynchronous message queuing is the correct approach to keep the frontend responsive under load.

Why the other options are wrong

B

A larger NAT Gateway increases outbound bandwidth but does not decouple the frontend from workers; it does not help the frontend stay responsive when workers are overloaded.

C

Scaling vertically to a single bigger EC2 instance does not address traffic spikes that overwhelm workers; it creates a single point of failure and does not provide elasticity or decoupling. The frontend would still block if the single worker is overloaded.

D

Route 53 health checks monitor endpoint availability and trigger DNS failover, but they do not decouple the frontend from downstream workers or absorb traffic spikes. The frontend would still directly invoke workers, causing overload and slowdowns.

When would these options actually be correct?

B

In a scenario where the application experiences high outbound traffic from private subnets to the internet and is hitting NAT Gateway bandwidth limits, a larger NAT Gateway would be the correct answer to increase throughput.

C

A question where the bottleneck is CPU or memory on a single worker instance, and the goal is to handle increased load without redesigning the architecture (e.g., a legacy monolithic application that cannot be distributed).

D

A Route 53 health check on the frontend would be correct in a scenario where the application needs to detect frontend failure and route traffic to a standby frontend in a different region for high availability.

Why candidates pick the wrong answer

B

Candidates may think that scaling network capacity (NAT Gateway) will resolve performance issues, confusing network bandwidth with application-level decoupling needed to handle worker overload.

C

Candidates may think that a larger instance can handle more load, ignoring that spikes require horizontal scaling and decoupling to keep the frontend responsive.

D

Candidates may think health checks can detect worker overload and redirect traffic, but health checks only assess endpoint health (e.g., HTTP 200), not load or queue depth, and cannot buffer requests.

359
MCQmedium

A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The architecture review board prefers a managed AWS-native control.

A.Provisioned IOPS SSD such as io2
B.st1 Throughput Optimized HDD
C.Instance store only
D.sc1 Cold HDD
AnswerA

Provisioned IOPS SSD volumes such as io2 deliver a guaranteed, consistent level of IOPS that is ideal for media archive databases or applications requiring predictable high random I/O performance. io2 also offers 99.999% durability and, with Block Express, can scale up to 256,000 IOPS per volume, making it the only option that truly meets the stated requirement for sustained high IOPS without compromising persistence.

Why this answer

The io2 Provisioned IOPS SSD volume type is designed for latency-sensitive transactional workloads that require consistent, high IOPS. It provides a service-level agreement (SLA) of 99.999% durability and supports up to 256,000 IOPS per volume, making it ideal for a database on EC2 that demands predictable performance. As a managed AWS-native EBS volume, it aligns with the architecture review board's preference for a fully AWS-controlled storage solution.

Exam trap

The trap here is that candidates often confuse throughput-optimized HDD (st1) with IOPS requirements, mistakenly thinking high throughput equals high IOPS, but transactional databases need random I/O performance, not sequential throughput.

How to eliminate wrong answers

Option B (st1 Throughput Optimized HDD) is wrong because it is optimized for sequential throughput, not random IOPS, and cannot deliver the consistent high IOPS required by a transactional database. Option C (Instance store only) is wrong because instance store volumes are ephemeral and data is lost on instance stop or termination, making them unsuitable for a persistent database. Option D (sc1 Cold HDD) is wrong because it is designed for infrequently accessed data with the lowest cost and lowest IOPS, far below the needs of a transactional database.

360
MCQmedium

A public API for a financial reporting platform is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

A.JWT authorizer configured for the OpenID Connect issuer
B.IAM authorization for all internet users
C.API keys only
D.A VPC endpoint policy
AnswerA

A JWT authorizer is the correct choice because it natively validates RS256-signed OAuth2/OIDC tokens against the issuer's JSON Web Key Set (JWKS) without requiring custom Lambda code. For a financial reporting platform, it lets you use an existing enterprise identity provider (e.g., Auth0, Okta, Azure AD) so users authenticate with standard SSO, and you can enforce per-user scopes and claims. API Gateway automatically checks token expiry, issuer, and audience, giving low operational overhead while keeping authentication separate from application logic.

Why this answer

The scenario requires standards-based token authentication from an external OpenID Connect (OIDC) provider. API Gateway's JWT authorizer can validate JSON Web Tokens (JWTs) directly against the OIDC issuer's well-known configuration (JWKS URI) without custom Lambda code, making it the simplest and most secure choice for token-based authentication.

Exam trap

The trap here is that candidates often confuse IAM authorization (for AWS internal services) with token-based authentication for external clients, or they assume API keys alone are sufficient for security, ignoring the requirement for standards-based token validation.

How to eliminate wrong answers

Option B is wrong because IAM authorization is designed for AWS principals (users/roles) using Signature Version 4 signing, not for internet clients with external OIDC tokens. Option C is wrong because API keys only provide basic identification and rate limiting, not authentication or authorization against a standards-based token issuer. Option D is wrong because a VPC endpoint policy controls access to the API Gateway via VPC endpoints, not authentication of client tokens from an external OIDC provider.

361
MCQeasy

An S3 bucket uses a customer-managed KMS key as the default for SSE-KMS encryption. A service role will upload objects using s3:PutObject. Assuming the role already has permission to write to the bucket, which KMS permission is most directly required for the role to let S3 encrypt the object during upload?

A.kms:GenerateDataKey (and optionally kms:DescribeKey)
B.kms:Decrypt only
C.kms:CreateAlias and kms:UpdateAlias only
D.kms:ScheduleKeyDeletion and kms:CancelKeyDeletion only
AnswerA

For SSE-KMS uploads, S3 uses KMS to generate a data key for encrypting the object. kms:GenerateDataKey is the direct permission required for that flow. kms:DescribeKey can be useful for validation or troubleshooting, but it is not the core cryptographic permission.

Why this answer

When S3 uses SSE-KMS with a customer-managed KMS key, the service calls KMS to generate a data key for encrypting the object. The s3:PutObject operation requires the caller to have kms:GenerateDataKey permission on the KMS key so that S3 can obtain the plaintext and encrypted versions of the data key. Optionally, kms:DescribeKey may be needed for S3 to verify the key exists, but kms:GenerateDataKey is the most directly required permission.

Exam trap

The trap here is that candidates often confuse kms:Decrypt (needed for GET/read operations) with kms:GenerateDataKey (needed for PUT/write operations), or they assume any KMS permission will work because S3 handles encryption transparently.

How to eliminate wrong answers

Option B is wrong because kms:Decrypt is used for reading or decrypting objects, not for uploading new objects with SSE-KMS. Option C is wrong because kms:CreateAlias and kms:UpdateAlias are for managing key aliases, not for encrypting data during upload. Option D is wrong because kms:ScheduleKeyDeletion and kms:CancelKeyDeletion are key lifecycle management actions, unrelated to the encryption process for PutObject.

362
Multi-Selectmedium

A serverless order-ingestion API writes directly to a database. During traffic spikes, the database occasionally throttles, Lambda retries create duplicate order records, and some requests time out. Which two changes best improve buffering and safe retry behavior? Select two.

Select 2 answers
A.Increase the Lambda timeout and keep writing directly to the database.
B.Put an Amazon SQS queue between the API and the database-processing function.
C.Replace SQS with SNS so every request is delivered immediately to all subscribers.
D.Make the database write idempotent by using a unique request token or order ID.
E.Disable retries so failed writes are never duplicated.
AnswersB, D

Amazon SQS decouples ingestion from database writes, absorbing traffic spikes as a buffer while the processing function consumes at a controlled rate. It also enables safe retries via visibility timeouts and dead-letter queues, preventing duplicate order records and timeouts.

Why this answer

Option B is correct because inserting an Amazon SQS queue between the API and the database-processing function decouples ingestion from database writes, allowing the queue to absorb traffic spikes and buffer requests while the consumer processes them at a rate the database can sustain, which directly addresses throttling and timeouts. Option D is correct because making the database write idempotent using a unique request token or order ID ensures that Lambda retries of the same message do not create duplicate order records, which is the standard safe-retry pattern for at-least-once delivery systems like SQS. Option A is not appropriate because increasing the Lambda timeout while continuing direct database writes does nothing to buffer spikes or prevent duplicate records, and longer timeouts can worsen throttling pressure.

Option C is not appropriate because SNS is a pub/sub fan-out service, not a durable buffering queue, and immediate delivery to all subscribers does not provide the backpressure or retry buffering needed here. Option E is not appropriate because disabling retries sacrifices reliability and does not solve the underlying throttling or duplicate-write problem.

Exam trap

The trap here is that candidates often think SNS (Option C) is a suitable replacement for SQS because both are messaging services, but SNS lacks buffering and retry mechanics, making it inappropriate for smoothing traffic spikes and handling failures gracefully.

Why the other options are wrong

A

Increasing Lambda timeout does not address database throttling or duplicate records; it only allows the function to wait longer, but the database will still throttle under load, and retries will still create duplicates.

C

SNS pushes messages to all subscribers immediately without buffering or throttling, so it does not help with database throttling or retry management; it would still overwhelm the database and cause duplicate processing.

E

Disabling retries entirely would cause order writes to fail permanently during throttling, losing data and increasing timeouts, which contradicts the need for safe retry behavior.

When would these options actually be correct?

A

If the question were about handling a slow database that occasionally takes longer than the default Lambda timeout (e.g., 3 seconds) but never throttles, and idempotency is already handled, increasing the timeout would prevent timeouts.

C

A question where the goal is to fan out a single event to multiple downstream services (e.g., order placed triggers email, SMS, and analytics) and immediate delivery is acceptable, with no need for buffering or retry control.

E

In a scenario where duplicate processing is unacceptable and the system can tolerate occasional data loss (e.g., non-critical logging), and retries are handled externally (e.g., by a queue with DLQ), disabling Lambda retries prevents duplicate records.

Why candidates pick the wrong answer

A

Candidates think that giving Lambda more time will solve the throttling issue, but they overlook that the root cause is database capacity, not Lambda execution time.

C

Candidates may confuse SNS with SQS, thinking any messaging service provides buffering, or they may overvalue 'immediate delivery' without considering the need for decoupling and retry safety.

E

Candidates may think that disabling retries directly solves the duplication problem without considering that it also eliminates the ability to recover from transient failures, leading to data loss.

363
MCQeasy

A CI pipeline needs to upload build artifacts only to s3://ci-artifacts/uploads/*. You also want the pipeline to list only objects under uploads/ to verify that the upload succeeded. Which IAM policy approach is the best fit for least privilege?

A.Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts with a condition that restricts s3:prefix to uploads/.
B.Allow s3:PutObject on arn:aws:s3:::ci-artifacts/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts without any prefix condition.
C.Allow s3:GetObject on arn:aws:s3:::ci-artifacts/uploads/* so the pipeline can confirm artifacts exist.
D.Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and also allow s3:DeleteObject on arn:aws:s3:::ci-artifacts/uploads/*.
AnswerA

This scopes object writes to only the uploads/ prefix (resource-level restriction for s3:PutObject) and scopes object listing to only that same prefix by restricting the ListBucket request via the s3:prefix condition key (bucket-level authorization for s3:ListBucket).

Why this answer

It grants the minimum required permissions: s3:PutObject on the specific uploads/ path for uploading artifacts, and s3:ListBucket on the bucket with a condition restricting the s3:prefix to uploads/ to list only objects under that prefix. This follows the least privilege principle by scoping both actions to the exact resources needed.

Exam trap

The trap here is that candidates often confuse s3:GetObject with s3:ListBucket for verifying uploads, or they forget to restrict the s3:prefix condition on ListBucket, leading to overly permissive policies.

Why the other options are wrong

B

Option B allows s3:PutObject on all objects under ci-artifacts (not just uploads/), violating the least privilege requirement to restrict uploads to uploads/*. Additionally, it grants s3:ListBucket without a prefix condition, allowing listing of all objects in the bucket, which is broader than needed.

C

The pipeline needs to upload artifacts (PutObject) and list objects (ListBucket) to verify uploads, not download them. GetObject is for reading object content, which is not required for verification.

D

Option D includes s3:DeleteObject, which is not required for the pipeline's tasks of uploading and listing artifacts. Granting unnecessary permissions violates the principle of least privilege.

When would these options actually be correct?

B

This option would be correct if the requirement was to allow the pipeline to upload artifacts to any location under the bucket and list all objects (e.g., for general bucket management). For example, a CI pipeline that needs to upload build outputs to various folders and verify the entire bucket contents.

C

A scenario where the pipeline needs to download or read the content of uploaded artifacts (e.g., for validation or processing) would require s3:GetObject on the upload path.

D

This option would be correct if the pipeline also needed to delete old or failed uploads from the uploads/ prefix to manage storage or clean up after a failed build.

Why candidates pick the wrong answer

B

Candidates may think that allowing PutObject on the entire bucket is simpler and still meets the upload requirement, overlooking the need to restrict to uploads/. They may also underestimate the risk of granting ListBucket without a prefix condition.

C

Candidates may confuse 'verifying upload succeeded' with needing to read the object, or think that listing requires GetObject permission.

D

Candidates may think that including DeleteObject is harmless or might be needed for cleanup, overlooking that the question explicitly requires only upload and list capabilities.

364
MCQeasy

A web service runs continuously on AWS 24/7. The team expects steady compute usage for the next 12–24 months, but may change instance families/sizes as performance tuning continues. Which purchase option best reduces cost while keeping flexibility to change instance types?

A.Buy EC2 On-Demand instances and rely on future Spot capacity for discounts
B.Use Compute Savings Plans for the expected steady usage
C.Buy Reserved Instances with a fixed instance type and region
D.Buy Spot Instances and stop scaling to avoid interruption risk
AnswerB

Compute Savings Plans provide a discounted hourly rate in exchange for a commitment. They are the most flexible Savings Plans option and can apply across EC2 usage regardless of instance family or size changes, so the team can continue tuning instance types while still receiving discounted pricing for the committed usage.

Why this answer

Compute Savings Plans offer the lowest prices (up to 66% off On-Demand) in exchange for a commitment to a consistent amount of compute usage (measured in $/hour) for a 1- or 3-year term. Unlike Reserved Instances, they automatically apply to any EC2 instance family, size, OS, or region, giving you the flexibility to change instance types as performance tuning evolves, while still reducing costs for steady-state workloads.

Exam trap

The trap here is that candidates often confuse Reserved Instances (which lock instance family) with Savings Plans (which offer flexibility across families), leading them to choose Option C because they think 'Reserved' is the only way to get a discount for steady usage.

Why the other options are wrong

A

On-Demand instances with future Spot capacity do not guarantee cost reduction for steady 24/7 usage, as Spot instances can be interrupted and are not suitable for continuous workloads. Compute Savings Plans provide a consistent discount for steady usage while allowing instance family changes.

C

Reserved Instances lock you into a specific instance type and region, which contradicts the requirement to change instance families/sizes during performance tuning.

D

Spot Instances can be interrupted with little notice, making them unsuitable for a continuously running 24/7 web service that requires high availability and reliability.

When would these options actually be correct?

A

If the workload is fault-tolerant, flexible, and can handle interruptions (e.g., batch processing, stateless applications), and the question asks for the lowest cost option without requiring steady 24/7 operation, then using Spot Instances with On-Demand fallback would be correct.

C

A question where the workload has predictable, steady usage and the instance family and size are fixed and known for the entire term, with no need for future changes.

D

For a fault-tolerant, stateless, or batch processing workload that can handle interruptions and is not required to run continuously, Spot Instances offer significant cost savings.

Why candidates pick the wrong answer

A

Candidates may think that combining On-Demand with Spot offers flexibility and cost savings, but overlook that Spot instances are not reliable for steady, continuous workloads due to potential interruptions.

C

Candidates may think Reserved Instances always offer the best discount for steady usage, overlooking the flexibility trade-off required by the scenario.

D

Candidates see 'reduce cost' and know Spot Instances are cheaper, but overlook the requirement for continuous, steady compute usage that cannot tolerate interruptions.

365
MCQhard

A company runs a production MySQL database on Amazon RDS in us-east-1. A read replica exists in us-west-2 for disaster recovery. The primary region experiences a complete outage. Which of the following describes the correct procedure to restore database service using the cross-region read replica?

A.Wait for AWS to automatically fail over the read replica to become the new primary
B.Restore the primary database from the most recent automated snapshot in us-west-2
C.Manually promote the us-west-2 read replica to a standalone DB instance and update application endpoints
D.Create a new RDS instance in us-west-2 and manually restore data from application logs
AnswerC

Promoting the us-west-2 read replica is the correct DR procedure. Promotion converts the read replica into a standalone writable DB instance, and because the replica continuously replays transactions from the primary, it typically has only seconds of lag. After promotion, applications must update their connection strings to the new endpoint in us-west-2. This is the standard, lowest-RPO approach for cross-region failover.

Why this answer

Cross-region RDS read replicas support manual promotion to a standalone database instance. When the primary region fails, the replica must be manually promoted — this makes it an independent writable instance in us-west-2.

Key points: Promotion is NOT automatic (unlike RDS Multi-AZ failover). Promotion breaks the replication link — the replica becomes autonomous. After promotion, application connection strings must be updated to the new endpoint. Any replication lag at the time of the outage represents potential data loss (RPO > 0).

Exam trap

RDS Multi-AZ provides automatic failover — no manual action required. Cross-region read replicas do NOT failover automatically — promotion must be manually triggered. This distinction appears frequently.

For automatic cross-region failover with near-zero RPO, use Amazon Aurora Global Database.

Why the other options are wrong

A

RDS cross-region read replicas do NOT automatically failover. Only RDS Multi-AZ provides automatic same-region failover. Manual promotion is required for cross-region replicas.

B

Restoring from a snapshot creates a new instance from an older state. The read replica contains more recent data (continuously synchronized). Promotion is faster and yields less data loss than snapshot restoration when the replica is available.

D

Creating an empty new instance and manually re-entering data is not a valid DR procedure. The read replica already contains synchronized production data. Never manually re-enter data as part of a DR plan.

366
MCQmedium

A company runs a stateless web tier on a fleet of On-Demand EC2 instances behind an Application Load Balancer. Traffic is steady and predictable, and the team has committed to running this tier for the next three years with no planned architectural changes. Management wants the lowest possible compute cost while preserving the ability to change instance families during the term if a better price-performance option emerges. Which purchasing approach best meets these requirements?

A.Run the fleet on Spot Instances with a capacity-optimized allocation strategy.
B.Purchase a 3-year EC2 Instance Savings Plan scoped to the current instance family and Region.
C.Purchase a 3-year Compute Savings Plan with a committed hourly spend.
D.Purchase a 3-year Standard Reserved Instance for each instance in the fleet.
AnswerC

Compute Savings Plans apply the largest discount to a committed hourly spend and automatically cover any EC2 instance family, size, tenancy, Region, and even Lambda and Fargate usage. This satisfies the steady three-year commitment while preserving the flexibility to change instance families, which is exactly what the team requires here.

Why this answer

A Compute Savings Plan is the right choice because it discounts a committed hourly spend across any EC2 instance family, size, and Region, plus Lambda and Fargate. That flexibility directly supports the requirement to change instance families during the three-year term, unlike a Standard Reserved Instance or an EC2 Instance Savings Plan, which are tied to a specific family or Region. Spot capacity is cheaper but cannot guarantee availability for a steady production tier.

Exam trap

The trap here is assuming the deepest discount always wins, when the real constraint is the required flexibility to change instance families mid-term.

367
MCQmedium

A solutions architect is designing an S3 bucket for a claims portal. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?

A.Enable S3 Block Public Access at the account or bucket level
B.Create an IAM policy that denies s3:GetObject to anonymous users
C.Enable server access logging on the bucket
D.Enable S3 Transfer Acceleration
AnswerA

S3 Block Public Access provides a centralized, account- or bucket-level safety net that overrides both bucket policies and object ACLs. When enabled, the IgnorePublicAcls and BlockPublicPolicy settings cause S3 to reject any attempt to make objects publicly accessible via a public ACL or a policy that grants public access. This is the definitive control for a claims portal because it closes the two most common misconfiguration paths, ensuring claim documents remain private even if an administrator accidentally attaches a permissive policy.

Why this answer

S3 Block Public Access provides a definitive override that prevents any public access to objects, regardless of bucket policies or object ACLs. By enabling this setting at the account or bucket level, the architect ensures that even if a developer later adds an overly broad bucket policy, the S3 service will block all public access. This is the only option that directly and permanently prevents public exposure.

Exam trap

The trap here is that candidates often think an IAM deny policy (Option B) is sufficient, but they miss that bucket policies can grant access to anonymous users independently of IAM, making S3 Block Public Access the only reliable safeguard.

How to eliminate wrong answers

Option B is wrong because an IAM policy that denies s3:GetObject to anonymous users does not block access granted via a bucket policy that explicitly allows public access; bucket policies can override IAM policies for anonymous principals. Option C is wrong because server access logging only records requests to the bucket, it does not enforce any access restrictions. Option D is wrong because S3 Transfer Acceleration is a performance feature that speeds up uploads over long distances, it has no effect on access control or public accessibility.

368
Multi-Selecthard

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The architecture review board prefers a managed AWS-native control.

Select 2 answers
A.Interface VPC endpoint for Systems Manager
B.Internet gateway attached to the VPC
C.NAT gateway in each Availability Zone
D.Gateway VPC endpoint for Amazon S3
AnswersA, D

Interface VPC endpoints for Systems Manager are powered by AWS PrivateLink and create a private elastic network interface with a private IP address in each subnet. This allows instances in private subnets to communicate with the Systems Manager service (including the SSM agent and Parameter Store) without any internet-facing resources like NAT gateways or internet gateways. This is the correct and secure method for private instances to access Systems Manager.

Why this answer

Interface VPC endpoints (AWS PrivateLink) for Systems Manager allow EC2 instances in private subnets to access Parameter Store without traversing the internet. Gateway VPC endpoints for S3 provide a highly available, managed route to S3 via the VPC route table, requiring no NAT or internet gateway. Both are AWS-native, managed services that meet the architecture review board's preference.

Exam trap

The trap here is that candidates often confuse gateway VPC endpoints (for S3 and DynamoDB) with interface endpoints (for most other AWS services), or incorrectly assume NAT gateways are required for all private subnet outbound traffic, when managed endpoints can bypass the internet entirely.

369
MCQeasy

An orders service consumes payment instructions from an Amazon SQS queue. Sometimes the consumer times out after applying the payment but before deleting the SQS message. As a result, the same payment instruction is processed again. Which design change most directly prevents duplicate side effects caused by message retries?

A.Delete the SQS message immediately after it is received, before processing, to ensure it is not retried.
B.Implement idempotency by recording a processed marker keyed by the instruction ID and ignoring duplicates.
C.Increase the SQS visibility timeout to a maximum value to avoid retries entirely.
D.Convert the queue to FIFO and enable content-based deduplication.
AnswerB

Idempotency ensures that repeated deliveries of the same instruction do not cause repeated side effects. By persisting a record keyed by instruction ID (or enforcing a unique constraint in a transactional store), the service can detect duplicates and safely skip or reconcile them even if SQS redelivers the message.

Why this answer

Implementing idempotency ensures that even if the same payment instruction is processed multiple times due to a timeout and retry, the side effect (e.g., applying the payment) occurs only once. By recording a processed marker keyed by the instruction ID (e.g., using a DynamoDB table or Redis), the consumer can check the marker before processing and ignore duplicates. This directly addresses the root cause—duplicate processing—without altering the queue's retry behavior.

Exam trap

The trap here is that candidates confuse message deduplication (preventing duplicate deliveries) with idempotent processing (preventing duplicate side effects), leading them to choose Option D, which only prevents redelivery but does not handle the case where the same message is processed twice due to a consumer timeout before deletion.

How to eliminate wrong answers

Option A is wrong because deleting the SQS message immediately after receipt, before processing, defeats the purpose of at-least-once delivery; if the consumer crashes after deletion but before processing, the payment instruction is lost permanently, leading to data loss. Option C is wrong because increasing the visibility timeout to a maximum value (e.g., 12 hours) does not prevent retries entirely; the message will still be retried if the consumer fails to delete it within the timeout, and it can also delay processing of other messages. Option D is wrong because converting to a FIFO queue with content-based deduplication deduplicates based on the message body, not the processing outcome; if the same message is received again due to a consumer timeout, the deduplication ID (derived from the body) remains the same, so the message is not redelivered—but this does not prevent the duplicate side effect from the first retry that already occurred, and it also requires the queue to be FIFO, which may not suit the existing architecture.

370
MCQmedium

Account B has an IAM role that includes kms:Decrypt for a specific KMS key ARN in account A. However, when the role tries to read an S3 object encrypted with that CMK, the application fails with AccessDenied: not authorized to perform kms:Decrypt. CloudTrail shows the KMS API call is denied by key policy. What is the most secure and correct fix?

A.Update the IAM role in account B to include kms:Encrypt and kms:GenerateDataKey; then kms:Decrypt will start working automatically.
B.Update the KMS key policy in account A to allow the account B role principal to use kms:Decrypt on the key.
C.Disable key policy for the CMK by switching to S3-managed encryption, because KMS key policies are always enforced regardless of grants.
D.Create an SCP in account A that allows kms:Decrypt for all accounts, avoiding changes to the key policy.
AnswerB

Cross-account use of a CMK requires the KMS key policy (in the CMK’s account) to allow the external principal to perform kms:Decrypt. Since CloudTrail shows the denial is by key policy, updating the key policy to grant the account B role kms:Decrypt on the specific key is the correct and least-privilege solution.

Why this answer

Cross-account access to a customer managed KMS key (CMK) requires the key policy to explicitly grant the external IAM role principal the necessary permissions (e.g., kms:Decrypt). Even if the IAM role in Account B has an IAM policy allowing kms:Decrypt, the KMS key policy in Account A acts as a resource-based policy that must also allow the action; without this, the request is denied by the key policy, as shown in CloudTrail.

Exam trap

The trap here is that candidates often assume IAM permissions alone are sufficient for cross-account KMS operations, forgetting that KMS key policies are resource-based and must explicitly grant access to external principals.

How to eliminate wrong answers

Option A is wrong because adding kms:Encrypt and kms:GenerateDataKey to the IAM role does not resolve the key policy denial; the issue is the key policy in Account A, not the IAM permissions in Account B, and kms:Decrypt does not automatically work from other actions. Option C is wrong because disabling the CMK and switching to S3-managed encryption (SSE-S3) is not a secure fix for cross-account access; it removes customer control over encryption keys and does not address the need for cross-account KMS decryption. Option D is wrong because SCPs (Service Control Policies) are used to restrict permissions within an AWS organization, not to grant cross-account access; they cannot override a key policy denial, and creating an SCP that allows kms:Decrypt for all accounts would be insecure and ineffective.

371
MCQmedium

A public API is deployed in two AWS Regions: us-east-1 (primary) and us-west-2 (secondary). The team wants Route 53 to automatically route users to the secondary region if the primary API becomes unhealthy. They will use Route 53 health checks that monitor the API’s /status endpoint over HTTPS. Which Route 53 configuration most directly implements this failover behavior?

A.Create two latency-based alias records for the same name, each with different health checks; Route 53 will automatically shift to the secondary when primary is unhealthy.
B.Create a primary alias record and a failover alias record (secondary), configure failover routing policy, and attach health checks to both records.
C.Use geolocation routing with a health check; when the primary is unhealthy, Route 53 will automatically change the region mapping globally.
D.Use simple routing with weighted records and a low health check threshold so traffic quickly moves to the secondary region.
AnswerB

Route 53 failover routing (primary/secondary) is designed for active-passive regional DR. When the primary health check fails, Route 53 automatically stops returning the primary alias and returns the secondary alias target; attaching health checks ensures the change is driven by the /status endpoint health.

Why this answer

B is correct because the failover routing policy in Route 53 is specifically designed for active-passive failover. By creating a primary alias record and a secondary failover alias record, each with an associated health check, Route 53 will automatically route traffic to the secondary region when the health check for the primary fails. This directly implements the required behavior without relying on latency or geographic proximity.

Exam trap

The trap here is that candidates often confuse failover routing with latency-based or geolocation routing, assuming that health checks automatically trigger failover in those policies, but only failover routing provides the explicit active-passive failover behavior described in the question.

How to eliminate wrong answers

Option A is wrong because latency-based routing does not support automatic failover based on health checks; it routes based on lowest latency, and while health checks can be associated, Route 53 does not automatically shift traffic to the secondary when the primary is unhealthy—it continues to return the primary record if it is still considered healthy, and if both are healthy, latency determines the response. Option C is wrong because geolocation routing routes based on the user's geographic location, not health; even with a health check, Route 53 does not automatically change region mappings globally—it would only return no answer for the unhealthy location, not redirect to another region. Option D is wrong because simple routing with weighted records does not support health checks for automatic failover; weighted routing distributes traffic based on weights and does not automatically shift all traffic to the secondary when the primary is unhealthy—it would require manual intervention or complex scripting.

372
Multi-Selecthard

A regional web application for a inventory service must fail over automatically to a secondary Region if the primary endpoint becomes unhealthy. Which two services or features are required? The team wants the control to be enforceable during normal operations.

Select 2 answers
A.Route 53 failover routing with health checks
B.S3 Transfer Acceleration
C.A deployed standby application stack in the secondary Region
D.AWS Organizations service control policies
AnswersA, C

Route 53 failover routing with health checks monitors the primary endpoint and automatically redirects DNS queries to the secondary record when it becomes unhealthy. This satisfies the automatic failover requirement, and the routing policy remains enforceable during normal operations.

Why this answer

Option A (Route 53 failover routing with health checks) is correct because Route 53 failover routing policies use health checks on the primary endpoint; when the health check reports the primary as unhealthy, Route 53 automatically returns the secondary Region's record, providing the required automatic DNS-level failover. Option C (a deployed standby application stack in the secondary Region) is correct because failover routing can only redirect traffic to a target that actually exists and can serve requests, so a running standby stack (for example, on EC2, ECS, or Elastic Beanstalk) must already be deployed in the secondary Region for the failover to succeed. Option B (S3 Transfer Acceleration) is incorrect because it only speeds up uploads/downloads to S3 buckets using edge locations and does not provide health-check-based regional failover for a web application.

Option D (AWS Organizations service control policies) is incorrect because SCPs only set permission guardrails for accounts in an organization and cannot detect an unhealthy endpoint or redirect traffic between Regions.

Exam trap

The trap here is that candidates may think DNS-level failover alone is sufficient, forgetting that a fully deployed standby stack in the secondary Region is required to actually serve traffic after failover.

373
MCQhard

A financial services company runs a critical application on Amazon EC2 instances in an Auto Scaling group. The application writes to an Amazon RDS for MySQL database. The company needs a recovery point objective (RPO) of 1 second and a recovery time objective (RTO) of 1 minute for the database in the event of a Regional disaster. Which solution meets these requirements?

A.Configure an RDS for MySQL read replica in a second Region and promote it during a disaster.
B.Enable automated backups on the RDS for MySQL instance and copy the backups to a second Region using a cross-Region snapshot copy.
C.Use AWS Database Migration Service (DMS) to continuously replicate data from the primary RDS instance to a second Region, and switch the application to the replica during a disaster.
D.Use an Amazon Aurora global database with a secondary Region, and perform a managed planned failover or unplanned failover to the secondary Region.
AnswerD

Aurora global database replicates data to a secondary Region with a typical latency of under one second, meeting the 1-second RPO. Failover to the secondary Region can be completed in under a minute, meeting the 1-minute RTO. This is the only option that provides both low RPO and low RTO across Regions for MySQL-compatible workloads.

Why this answer

Amazon Aurora global database is designed for cross-Region disaster recovery with low latency replication and fast failover. Replication typically completes in under one second, satisfying the RPO. A managed failover promotes the secondary Region to primary in under a minute, satisfying the RTO.

This is the appropriate choice for a MySQL-compatible workload with stringent recovery requirements.

Exam trap

The trap here is assuming that cross-Region read replicas or snapshot copies can meet a 1-second RPO and 1-minute RTO, when their replication lag and restore times are much higher.

374
MCQmedium

Based on the exhibit, what is the most appropriate change to restore application access while keeping encryption at rest with customer-managed KMS controls?

A.Change the bucket to SSE-S3 so the application no longer depends on KMS permissions.
B.Update the KMS key policy or add a grant so AppServerRole can use the key for decrypt and data key operations.
C.Move the EC2 instance into the same Availability Zone as the S3 bucket to reduce encryption errors.
D.Attach AmazonS3FullAccess to the application role so S3 can bypass KMS authorization.
AnswerB

For SSE-KMS objects, the caller needs permission to use the KMS key as well as S3 permissions. The role already has S3 access, but KMS is denying Decrypt because the key policy does not allow the role. Adding the role through the key policy or a grant, together with the needed KMS actions, resolves the failure while preserving customer-managed encryption.

Why this answer

The application is failing because AppServerRole lacks the necessary permissions to use the customer-managed KMS key for decrypting S3 objects. By updating the KMS key policy or adding a grant to allow the role to perform `kms:Decrypt` and `kms:GenerateDataKey` operations, you restore access while maintaining encryption at rest with customer-managed KMS controls.

Exam trap

The trap here is that candidates often assume S3 bucket policies alone control access to encrypted objects, forgetting that SSE-KMS requires separate KMS key permissions that must be explicitly granted to the IAM role or user.

Why the other options are wrong

A

Changing to SSE-S3 removes customer-managed KMS controls, violating the requirement to keep encryption at rest with customer-managed KMS.

C

Moving the EC2 instance into the same Availability Zone as the S3 bucket does not resolve encryption errors related to KMS permissions, as S3 is a regional service and Availability Zone placement does not affect KMS authorization.

D

Attaching AmazonS3FullAccess does not bypass KMS authorization; S3 still requires KMS permissions to decrypt objects encrypted with customer-managed KMS keys, so the application would still fail.

When would these options actually be correct?

A

If the question required removing dependency on KMS permissions and allowed using AWS-managed keys, switching to SSE-S3 would simplify access without encryption errors.

C

This option would be correct in a scenario where the application is experiencing high latency or data transfer costs due to cross-AZ data retrieval from S3, and the question asks for a change to reduce latency or cost while maintaining encryption at rest.

D

This option would be correct if the question stated that the application needs full S3 access and encryption is not a concern (e.g., using SSE-S3 or no encryption), and the issue is a missing S3 permission rather than a KMS permission.

Why candidates pick the wrong answer

A

Candidates may think SSE-S3 eliminates KMS permission issues, overlooking the explicit requirement for customer-managed KMS controls.

C

Candidates may mistakenly believe that S3 operations are affected by network proximity at the AZ level, or confuse S3 with services like EC2 or EBS where AZ placement impacts performance and errors.

D

Candidates may think that granting full S3 access overrides all other permissions, not realizing that KMS has its own authorization layer that must be satisfied separately.

375
MCQeasy

A media company uses CloudFront in front of an S3 bucket origin for video thumbnails. They want to prevent users from bypassing CloudFront and accessing the S3 bucket directly, while still allowing CloudFront to fetch objects. What is the best option?

A.Keep the bucket public and rely on signed cookies for all thumbnail requests.
B.Use CloudFront Origin Access Control (OAC) or Origin Access Identity (OAI) and update the bucket policy to allow only CloudFront.
C.Enable S3 static website hosting so users access thumbnails directly from the S3 website endpoint.
D.Set S3 bucket permissions to allow all IAM users and block access only by using a WAF rule at CloudFront.
AnswerB

OAC or OAI makes CloudFront sign origin requests with a service principal, so the bucket policy can grant read access solely to that identity. This blocks direct S3 URLs, satisfying the requirement that users cannot bypass CloudFront while CloudFront still fetches objects.

Why this answer

CloudFront Origin Access Control (OAC) or Origin Access Identity (OAI) allows you to restrict direct access to an S3 bucket by configuring the bucket policy to grant read permissions only to the CloudFront distribution's service principal. This ensures that users can only retrieve thumbnails through CloudFront, leveraging its caching and security features, while blocking any direct S3 requests.

Exam trap

The trap here is that candidates often think signed cookies or URLs alone are sufficient to secure direct S3 access, but they forget that those mechanisms only control access through CloudFront and do not restrict the S3 bucket's public endpoint unless the bucket policy explicitly denies direct access.

Why the other options are wrong

A

Keeping the bucket public allows anyone with the S3 URL to access thumbnails directly, bypassing CloudFront. Signed cookies control access via CloudFront but do not prevent direct S3 access, so this fails to meet the requirement.

C

Enabling S3 static website hosting exposes the S3 bucket via its website endpoint, allowing users to bypass CloudFront and access thumbnails directly, which violates the requirement to prevent direct access.

D

WAF rules at CloudFront can block certain requests but do not prevent direct access to the S3 bucket; users could still bypass CloudFront and access the bucket directly if the bucket policy allows it.

When would these options actually be correct?

A

If the requirement were to restrict access to thumbnails while allowing both CloudFront and direct S3 access for authorized users, signed cookies (or signed URLs) could be used with a public bucket to control access at the CloudFront level, but the bucket itself would remain accessible.

C

This option would be correct if the requirement was to serve static content (e.g., a single-page application) directly from S3 without CloudFront, and the question asked for the simplest way to host a static website with public access.

D

In a scenario where the S3 bucket is already configured to allow only CloudFront access (e.g., via OAI/OAC) and the goal is to add an additional layer of security to block specific request patterns (e.g., SQL injection) at the CloudFront edge, a WAF rule would be appropriate.

Why candidates pick the wrong answer

A

Candidates may think signed cookies provide comprehensive access control, but they overlook that the bucket policy must also restrict direct access. The option seems to address user authentication without considering the need to block direct S3 access.

C

Candidates may confuse 'static website hosting' with a security feature, thinking it restricts access, or they may mistakenly believe it integrates with CloudFront to block direct access.

D

Candidates may think that a WAF rule at CloudFront can enforce access control globally, misunderstanding that WAF operates at the application layer and does not restrict network-level access to the S3 bucket.

Page 4

Page 5 of 13

Page 6