Courseiva

SAA-C03 (SAA-C03) — Questions 451–525

935 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
MCQmedium

Your team runs a tightly coupled distributed workload (for example, synchronous training nodes) across many EC2 instances placed within a single cluster environment. The instances need low-latency networking to reduce delays at synchronization barriers. Which EC2 placement strategy should you use to improve inter-node latency?

A.Create a placement group with the 'spread' strategy to separate instances across underlying hardware for fault tolerance.
B.Create a placement group with the 'cluster' strategy to place instances close together and reduce network latency.
C.Use the default placement strategy and rely on Auto Scaling to keep instances from drifting to different locations.
D.Avoid placement groups and instead use Amazon S3 for inter-node messaging to minimize direct network traffic between instances.
AnswerB

A cluster placement group is a hardware-level grouping within a single Availability Zone that places instances on the same high-speed, low-latency network segment. This strategy minimizes round-trip time and packet jitter between nodes, which is critical for tightly coupled workloads that frequently synchronize via message passing or shared state. Only cluster placement groups are specifically engineered to deliver the sub-millisecond, high-bandwidth interconnect (up to 100 Gbps with EFA/ENA) that such distributed applications require.

Why this answer

A cluster placement group is the correct choice because it groups instances in a single Availability Zone with low-latency, high-bandwidth networking, ideal for tightly coupled workloads like synchronous training nodes that require minimal delay at synchronization barriers. This strategy places instances physically close together within the same rack or cluster, reducing network round-trip time and maximizing throughput for inter-node communication.

Exam trap

The trap here is that candidates may confuse 'spread' with 'cluster' placement groups, assuming fault tolerance is always the priority, but for tightly coupled workloads requiring low latency, the cluster strategy is the correct choice despite its reduced fault tolerance.

Why the other options are wrong

A

The 'spread' strategy places instances on distinct hardware to maximize fault tolerance, which increases network latency between instances, opposite to the low-latency requirement for tightly coupled workloads.

C

The default placement strategy does not guarantee low latency; instances can be placed on different racks or AZs, increasing network latency. Auto Scaling does not control placement to minimize latency for tightly coupled workloads.

D

Amazon S3 is an object storage service, not a low-latency messaging system; using it for inter-node communication would introduce high latency and is unsuitable for tightly coupled, synchronous workloads that require fast networking.

When would these options actually be correct?

A

When the question emphasizes high availability and fault isolation for a small number of critical instances (e.g., a few application servers) and explicitly states that low latency is not a primary concern, the 'spread' strategy would be correct.

C

For a stateless web application that needs high availability and automatic scaling across multiple Availability Zones, using the default placement with Auto Scaling ensures resilience and load distribution without requiring low-latency inter-node communication.

D

For a loosely coupled, asynchronous workload where instances need to share large files or state data without strict timing constraints, using Amazon S3 for inter-node messaging can reduce direct network traffic and simplify architecture.

Why candidates pick the wrong answer

A

Candidates may confuse 'spread' with 'cluster' due to both being placement group strategies, or they may over-prioritize fault tolerance without recognizing the explicit low-latency requirement in the question.

C

Candidates may think Auto Scaling optimizes placement automatically, or they underestimate the need for explicit placement control in latency-sensitive workloads.

D

Candidates may think that reducing direct network traffic by offloading communication to a managed service like S3 could improve performance, but they overlook the high latency and lack of real-time messaging capabilities in S3.

452
MCQeasy

A startup runs a stateless web application on a fleet of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. Traffic is steady during business hours, but the team has configured the scaling policy with a target tracking metric of average CPU utilization at 50 percent. Users report intermittent 5xx errors during sudden traffic surges. Which change will most directly improve the application's ability to absorb rapid traffic increases?

A.Enable connection draining on the Application Load Balancer with a long deregistration delay so that in-flight requests complete before instances are removed.
B.Add a step scaling policy that reacts to Amazon CloudWatch alarms on request count per target and adds capacity in larger increments as the breach grows.
C.Switch the Auto Scaling group to a scheduled scaling policy that adds instances at fixed times each morning based on historical traffic patterns.
D.Increase the target tracking value for average CPU utilization from 50 percent to 80 percent so that existing instances are used more fully before scaling out.
AnswerB

Step scaling responds to CloudWatch alarms with tiered adjustments, so it can add many instances quickly when a metric breaches an upper threshold. This reacts to actual demand rather than a fixed schedule and scales faster than a single target tracking adjustment, which directly reduces the window where capacity lags behind a sudden surge.

Why this answer

Sudden traffic surges require capacity that reacts to demand quickly and in proportion to the breach. Step scaling with CloudWatch alarms adds instances in larger, tiered increments as the metric worsens, shortening the period where the fleet is undersized. Scheduled scaling fits predictable peaks, and raising the CPU target or tuning deregistration affects cost or scale-in, not surge response.

Exam trap

The trap here is assuming that any Auto Scaling policy will react quickly enough, when scheduled scaling cannot respond to unplanned spikes and a higher CPU target actually delays scale-out.

453
MCQmedium

A financial services company runs an internal web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must authenticate employees against the corporate identity provider (IdP) that supports SAML 2.0, and the company wants to avoid managing custom sign-in code. Which solution should a solutions architect recommend?

A.Create an IAM SAML identity provider and attach an IAM role to the EC2 instance profile so the instance can call the IdP.
B.Store the IdP SAML metadata in AWS Secrets Manager and have the application parse the SAML assertion on each request.
C.Configure the ALB to use an Amazon Cognito user pool as an authentication action, and federate the corporate IdP with the user pool.
D.Place AWS WAF in front of the ALB and create a rule that validates the SAML assertion signature before forwarding traffic.
AnswerC

ALB supports authenticate-cognito and authenticate-oidc actions on listener rules. A Cognito user pool can federate a SAML 2.0 IdP, so the ALB can offload the SAML exchange and issue its own session cookie. This meets the requirement without custom sign-in code on the EC2 instances.

Why this answer

The ALB can perform user authentication as a listener rule action using Amazon Cognito or an OIDC-compliant IdP. Because the corporate IdP speaks SAML 2.0, federating it with a Cognito user pool lets the ALB handle the SAML exchange and issue a session cookie, so the application receives only authenticated requests and no custom sign-in code is required.

Exam trap

The trap here is assuming that IAM SAML identity providers authenticate application users, when they actually federate identities for AWS API access.

454
MCQmedium

A claims workflow uses an RDS MySQL database and must remain available during an Availability Zone failure with minimal application changes. What should the architect enable? The design must avoid adding custom operational scripts.

A.S3 Cross-Region Replication
B.Multi-AZ deployment for the RDS DB instance
C.EBS snapshots every hour
D.Read replicas only
AnswerB

A Multi-AZ deployment is the correct RDS feature for availability because Amazon RDS automatically provisions and maintains a synchronous standby replica in a different Availability Zone within the same Region. The primary DB instance writes data synchronously to the standby before committing, and if the primary fails or its AZ becomes unavailable, RDS automatically performs failover to the standby by updating the DNS endpoint, typically within 60–120 seconds without requiring manual intervention. This eliminates the need for application-level failover logic and provides a clear improvement in availability for an RDS MySQL instance.

Why this answer

Multi-AZ deployment for RDS MySQL provides automatic failover to a standby replica in a different Availability Zone. This ensures high availability during an AZ failure with minimal application changes, as the DNS endpoint remains the same and failover is handled by AWS without custom scripts.

Exam trap

The trap here is that candidates often confuse read replicas with Multi-AZ deployments, assuming read replicas provide automatic failover, but they require manual promotion and do not maintain the same endpoint.

How to eliminate wrong answers

Option A is wrong because S3 Cross-Region Replication is for object storage replication across regions, not for database availability within a region, and it does not address RDS MySQL failover. Option C is wrong because EBS snapshots every hour provide point-in-time backups but do not enable automatic failover or maintain availability during an AZ failure; recovery would require manual intervention and data loss. Option D is wrong because read replicas are for read scaling and do not provide automatic failover for the primary instance; promoting a read replica requires manual steps or custom scripts, violating the 'no custom operational scripts' constraint.

455
MCQeasy

A CI/CD pipeline needs to deploy to your production environment. Security requires that the pipeline uses temporary credentials (not long-lived access keys) and only has permissions to read a specific set of parameters from AWS Systems Manager Parameter Store and write application logs to CloudWatch Logs. What is the best AWS approach?

A.Create an IAM user for the pipeline and store access keys in the CI system.
B.Create an IAM role in the production account, grant least-privilege policies, and let the CI assume it using STS AssumeRole.
C.Attach the required permissions to an IAM group and add the pipeline’s principal to that group directly.
D.Use AWS KMS to encrypt the pipeline’s access keys and store the ciphertext in the CI system.
AnswerB

STS AssumeRole issues short-lived credentials, eliminating long-lived access keys. Attaching least-privilege IAM policies scoped to the specific Parameter Store parameters and CloudWatch Logs write actions confines the pipeline to exactly the permissions required, satisfying both security constraints.

Why this answer

It uses an IAM role with least-privilege policies that the CI/CD pipeline can assume via AWS STS AssumeRole, providing temporary credentials that automatically expire. This avoids long-lived access keys and meets the security requirement of using temporary credentials. The role can be scoped to allow only reading specific parameters from Systems Manager Parameter Store and writing logs to CloudWatch Logs, adhering to the principle of least privilege.

Exam trap

The trap here is that candidates may think IAM users with access keys are acceptable for automation, but the question explicitly requires temporary credentials, making the IAM role with STS AssumeRole the only correct approach.

Why the other options are wrong

A

Option A uses long-lived access keys, violating the requirement for temporary credentials. IAM users with access keys are not temporary and increase security risk.

D

Using KMS to encrypt long-lived access keys does not eliminate the security risk of having permanent credentials; the pipeline still uses static keys, violating the requirement for temporary credentials.

When would these options actually be correct?

A

This option would be correct if the question specified that the CI system cannot assume IAM roles (e.g., due to network restrictions or lack of STS support) and the security policy allows long-lived keys with regular rotation.

D

A scenario where the pipeline must use pre-existing long-lived access keys (e.g., legacy CI system that cannot assume roles) and the goal is to protect the keys at rest in the CI system's storage, with KMS encryption required by compliance.

Why candidates pick the wrong answer

A

Candidates may default to using IAM users and access keys because it's a familiar pattern for CI/CD integration, overlooking the explicit requirement for temporary credentials.

D

Candidates may think that encrypting the keys with KMS satisfies security best practices, overlooking that the core requirement is temporary credentials, not just encryption of static keys.

456
MCQhard

A company runs a containerized microservices application on Amazon ECS with the Fargate launch type. The application experiences highly variable traffic, with long periods of low utilization and occasional sharp spikes. The company wants to minimize cost while ensuring the application can scale quickly during spikes. The tasks are stateless and can be restarted. Which combination of actions will meet these requirements MOST cost-effectively?

A.Use Fargate Spot for all tasks and enable ECS deployment circuit breaker to replace interrupted tasks.
B.Use Fargate On-Demand for all tasks and configure a scheduled scaling policy to add tasks at known peak times.
C.Use Fargate Spot capacity for all tasks and configure a target tracking scaling policy based on CPU utilization.
D.Use a mix of Fargate On-Demand for a baseline and Fargate Spot for additional capacity, with a target tracking scaling policy.
AnswerD

This approach uses On-Demand capacity to guarantee a reliable baseline and Spot capacity to handle bursts at a lower price. A target tracking policy scales the service based on demand, so during spikes more tasks are added. Since the tasks are stateless and restartable, Spot interruptions are tolerable, and the mix balances cost and availability.

Why this answer

For variable traffic with occasional spikes, a baseline of On-Demand capacity combined with Spot for burst capacity balances reliability and cost. Target tracking scaling responds to actual demand, and stateless tasks make Spot interruptions acceptable. Using Spot for everything risks availability, while using On-Demand for everything forgoes savings.

Exam trap

The trap here is assuming that Fargate Spot alone will always be cheaper and sufficient, ignoring the two-minute interruption notice and the need for a reliable baseline during sharp spikes.

457
MCQhard

A healthcare company stores protected health information in an Amazon S3 bucket. Compliance requires that all data be encrypted at rest with keys that the company controls and can rotate on demand. The security team also needs to audit every use of the encryption keys and immediately revoke access for a compromised IAM role without affecting other roles. Which solution meets these requirements?

A.Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3) and enable bucket versioning.
B.Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS), and manage access through the KMS key policy.
C.Use S3 server-side encryption with AWS KMS AWS managed keys (SSE-KMS) and enable S3 server access logging.
D.Use client-side encryption with an AWS KMS customer managed key and store the encrypted data key in S3 object metadata.
AnswerB

Customer managed KMS keys give the company full control over rotation, and every use is recorded in AWS CloudTrail for auditing. The KMS key policy can grant or deny permissions per principal, so revoking the compromised IAM role is immediate and does not affect other roles that retain access.

Why this answer

Customer managed KMS keys provide the needed control: the company can rotate them, audit every cryptographic operation through CloudTrail, and enforce or revoke access using the key policy. AWS managed keys and S3 managed keys lack customer-controlled rotation and granular, auditable access control, so they cannot meet the compliance and revocation requirements.

Exam trap

The trap here is treating AWS managed KMS keys as equivalent to customer managed keys, when only customer managed keys allow on-demand rotation and key policy changes for immediate revocation.

458
MCQmedium

A retail company runs a stateless web tier on Amazon EC2 instances behind an Application Load Balancer. During flash sales, response times spike because each request triggers many database queries. The team wants to reduce database load and improve read latency for product catalog pages that change only a few times per day. Which solution is MOST appropriate?

A.Add more EC2 instances to the web tier behind the load balancer.
B.Enable Amazon RDS Performance Insights and tune the slowest queries.
C.Deploy an Amazon ElastiCache for Redis cluster and cache the catalog query results.
D.Move the catalog tables to Amazon DynamoDB with on-demand capacity.
AnswerC

ElastiCache for Redis provides an in-memory cache that absorbs repeated catalog reads, cutting database load and returning results in sub-millisecond time. Because catalog data changes only a few times per day, a time-to-live cache with invalidation on update keeps data fresh while dramatically reducing query volume during flash sales.

Why this answer

Caching the catalog query results in ElastiCache for Redis removes most repeated database reads and serves product pages from memory, which directly cuts database load and read latency. DynamoDB migration is invasive, Performance Insights only diagnoses, and adding web instances increases pressure on the database rather than relieving it.

Exam trap

The trap here is scaling the web tier when the real bottleneck is repeated reads on the database, which caching solves far more directly.

459
MCQhard

Based on the exhibit, the team must restore an Amazon RDS for PostgreSQL database to the exact state just before a bad delete happened. What is the best recovery approach?

A.Restore the latest automated snapshot and accept data loss from the last backup window.
B.Perform a point-in-time restore to 2026-04-27 15:10 UTC into a new DB instance, then cut over after validation.
C.Promote a read replica because it will contain the deleted rows and can replace the primary immediately.
D.Enable Multi-AZ on the current database and wait for automatic failover to reverse the delete.
AnswerB

Point-in-time restore uses the automated backups and transaction logs to rebuild the database to an exact time before the bad change. The exhibit confirms the requested restore time is within the restorable window, and the business wants to validate the restored copy before switching traffic. Restoring to a new instance first is the safest way to recover without risking the current production database.

Why this answer

Point-in-time recovery (PITR) allows you to restore an Amazon RDS for PostgreSQL database to any second within the backup retention period, using automated backups and transaction logs. By restoring to 2026-04-27 15:10 UTC, just before the bad delete occurred, you can recover the exact state without data loss, then cut over after validation.

Exam trap

The trap here is that candidates often confuse read replicas or Multi-AZ as solutions for logical data corruption, when in fact they only protect against infrastructure failures, not user errors like a bad delete.

Why the other options are wrong

A

Restoring the latest automated snapshot would not recover to the exact state just before the bad delete at 2026-04-27 15:10 UTC; it would only restore to the last snapshot time, which could be hours earlier, causing data loss beyond the deleted rows.

C

A read replica is asynchronous and may not contain the exact state before the delete; it cannot be promoted to reverse a specific point-in-time deletion without data loss or inconsistency.

When would these options actually be correct?

A

This option would be correct if the question asked for the fastest recovery method to minimize downtime and the RPO allowed data loss up to the last backup window (e.g., a non-critical test database where losing recent changes is acceptable).

C

When the question asks for the fastest way to reduce read load on the primary database with minimal downtime, and the replica is already in sync and can be promoted to become the new primary.

Why candidates pick the wrong answer

A

Candidates may think restoring a snapshot is the simplest recovery method and overlook the need for precise point-in-time recovery, or they may not realize that automated snapshots are taken periodically and do not capture every transaction.

C

Candidates may think a read replica has the same data as the primary at all times and can be used for disaster recovery, overlooking replication lag and the need for point-in-time precision.

460
MCQmedium

A company hosts a critical web application on Amazon EC2 instances in a VPC. The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. They also want to monitor and control access to the application at the HTTP/HTTPS level. Which AWS service should a solutions architect use to meet these requirements?

A.AWS WAF integrated with an Application Load Balancer.
B.Amazon GuardDuty with VPC Flow Logs.
C.AWS Shield Advanced with an Elastic Load Balancer.
D.AWS Network Firewall with a stateless rule group.
AnswerA

AWS WAF is a web application firewall that protects against common web exploits such as SQL injection and cross-site scripting. When integrated with an Application Load Balancer, it inspects incoming HTTP/HTTPS requests and applies rules to block malicious traffic. It also provides monitoring and logging of requests, meeting the security team's requirements.

Why this answer

AWS WAF is specifically designed to protect web applications from application-layer attacks. When attached to an Application Load Balancer, it can inspect HTTP/HTTPS requests and apply rules to block SQL injection, XSS, and other exploits. It also provides logging and metrics for monitoring, satisfying the requirement to control access at the HTTP/HTTPS level.

Exam trap

The trap here is confusing network-level firewalls or DDoS protection with application-layer web exploit protection.

461
MCQmedium

A company hosts a e-learning platform on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

A.A public Elastic IP address on each instance
B.A bastion host with SSH open to 0.0.0.0/0
C.An internet gateway attached to the private subnet
D.AWS Systems Manager Session Manager with the required instance role
AnswerD

AWS Systems Manager Session Manager provides secure, auditable shell-level access to EC2 instances without requiring inbound SSH/RDP ports. An IAM instance role grants the SSM agent permission to connect outbound to the Systems Manager service, and users authenticate via IAM with the ability to enforce session policies and log sessions to CloudTrail/S3/CloudWatch Logs. This avoids public exposure, enables centralized permissions and auditing, and works for instances in private subnets or without public IPs.

Why this answer

AWS Systems Manager Session Manager allows secure shell access to EC2 instances without opening inbound ports (SSH/RDP) or using a bastion host. It uses the AWS Systems Manager agent and an IAM instance role to establish a bidirectional connection over HTTPS to the AWS Systems Manager service, eliminating the need for public IP addresses or internet-facing security groups.

Exam trap

The trap here is that candidates often assume a bastion host (Option B) is the only secure way to manage instances, but they overlook that Session Manager provides a more secure, agent-based solution that eliminates the need for any open inbound ports or public IP addresses.

How to eliminate wrong answers

Option A is wrong because assigning a public Elastic IP address to each instance would expose them directly to the internet, requiring open SSH or RDP ports, which violates the requirement to avoid opening those ports. Option B is wrong because a bastion host with SSH open to 0.0.0.0/0 exposes the bastion to the entire internet, creating a security risk and still requires opening SSH ports, which contradicts the requirement. Option C is wrong because an internet gateway attached to a private subnet does not provide connectivity; internet gateways must be attached to VPCs and associated with route tables for public subnets, and private subnets cannot directly use an internet gateway without a NAT device, which still does not solve the administrative access need without open ports.

462
MCQhard

A patient portal must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable?

A.Use an in-memory queue on one EC2 instance
B.Use UDP messages sent directly to workers
C.Use Amazon SQS standard queue and design consumers to be idempotent
D.Use CloudFront signed URLs
AnswerC

Amazon SQS standard queues provide durable storage across multiple Availability Zones and at-least-once delivery, meaning every message is guaranteed to be delivered eventually, but duplicates can occasionally occur due to the distributed architecture. Consumers must be idempotent so that processing the same event multiple times has the same effect as processing it once, preventing duplicate medical records or actions. This design satisfies the requirement while maintaining the high throughput needed by a patient portal.

Why this answer

Amazon SQS standard queues provide at-least-once delivery, meaning each message is delivered at least once but may occasionally be delivered more than once. This aligns with the requirement that every event must be processed at least once, and since duplicate processing is acceptable when consumers are idempotent, the standard queue is the most suitable choice. SQS handles the decoupling and durability of messages without requiring custom infrastructure.

Exam trap

The trap here is that candidates may confuse 'at-least-once' with 'exactly-once' and incorrectly choose a FIFO queue or another option, but the question explicitly accepts duplicates if the consumer handles idempotency, making the standard queue the correct choice.

How to eliminate wrong answers

Option A is wrong because an in-memory queue on a single EC2 instance is not durable, cannot survive instance failures, and does not provide at-least-once delivery guarantees across distributed consumers. Option B is wrong because UDP is a connectionless, unreliable protocol that does not guarantee message delivery, ordering, or duplicate detection, making it unsuitable for at-least-once processing. Option D is wrong because CloudFront signed URLs are used for secure content delivery and access control, not for event messaging or queue-based processing.

463
MCQhard

Based on the exhibit, the team wants to minimize compute cost for a workload with a steady 24/7 baseline and a separate nightly batch job that can be interrupted and resumed from checkpoints. They also expect to change EC2 instance families during the year as performance needs evolve. Which approach is the best fit?

A.Buy EC2 Instance Savings Plans for the baseline and run the nightly batch on On-Demand instances.
B.Use a Compute Savings Plan to cover the steady baseline and run the nightly batch on Spot Instances.
C.Purchase Standard Reserved Instances for all 12 instances and keep the current families fixed.
D.Run both tiers entirely on Spot Instances and rely on automatic restarts for the baseline web tier.
AnswerB

A Compute Savings Plan provides discount coverage while preserving flexibility across EC2 families and even other compute services. That makes it ideal for the steady baseline when future family changes are expected. Spot Instances are the lowest-cost choice for the restartable batch tier because interruptions are acceptable and checkpointing is already in place.

Why this answer

A Compute Savings Plan covers any EC2 instance family (or even container/Fargate usage) at a discounted rate, making it ideal for the steady 24/7 baseline. The nightly batch job can be interrupted and resumed from checkpoints, which is a perfect use case for Spot Instances, offering up to 90% cost savings. This combination minimizes compute cost while maintaining flexibility to change instance families during the year.

Exam trap

The trap here is that candidates often assume Reserved Instances or Instance Savings Plans are always cheaper, but they fail to recognize that the requirement to change instance families during the year makes Compute Savings Plans the only flexible discount option, and they overlook that Spot Instances are ideal for interruptible batch jobs.

How to eliminate wrong answers

Option A is wrong because EC2 Instance Savings Plans lock you into a specific instance family within a region, which conflicts with the requirement to change instance families during the year; also, running the nightly batch on On-Demand instances is more expensive than using Spot Instances. Option C is wrong because Standard Reserved Instances require a 1- or 3-year commitment and lock you into a specific instance family, which prevents the flexibility to change families and does not leverage Spot Instances for the interruptible batch job. Option D is wrong because running the steady baseline entirely on Spot Instances risks interruption (Spot Instances can be reclaimed with a 2-minute warning), which is unsuitable for a 24/7 workload that must remain stable and available.

464
MCQeasy

A worker consumes messages from an Amazon SQS queue. Some messages consistently fail validation and are retried until the worker can no longer process them. What is the most appropriate AWS mechanism to handle these poison messages while keeping the queue usable?

A.Enable SQS long polling and increase the maximum message size for the queue.
B.Send failing messages to an SQS dead-letter queue (DLQ) using a redrive policy based on receive count.
C.Change the queue to a FIFO queue and handle duplicates in the worker code without DLQs.
D.Delete the queue and recreate it hourly to clear out any problematic messages.
AnswerB

A DLQ with a redrive policy isolates poison messages. After a message is received and fails processing more than the configured maxReceiveCount, SQS moves it to the DLQ, preventing it from continually blocking retries in the source queue.

Why this answer

An SQS dead-letter queue (DLQ) with a redrive policy based on receive count allows messages that repeatedly fail processing (poison pills) to be moved out of the main queue after a specified number of retries. This keeps the main queue operational for valid messages and isolates problematic messages for later analysis or manual intervention.

Exam trap

The trap here is that candidates may think increasing retries or message size (Option A) solves the problem, but the exam specifically tests the concept of isolating poison messages via a DLQ with a receive-count-based redrive policy to maintain queue availability.

How to eliminate wrong answers

Option A is wrong because enabling long polling and increasing maximum message size does not address the core issue of messages that consistently fail validation; long polling reduces empty responses and larger message size allows bigger payloads, but neither prevents poison messages from blocking processing. Option C is wrong because changing to a FIFO queue does not inherently handle poison messages; FIFO queues preserve order and deduplicate based on message deduplication ID, but they still require a DLQ or explicit error handling to remove failing messages, and the worker code alone cannot prevent retries from exhausting resources. Option D is wrong because deleting and recreating the queue hourly is a disruptive, non-scalable approach that loses all messages (including valid ones) and does not provide a mechanism to isolate or analyze poison messages; it also violates the requirement to keep the queue usable.

465
MCQeasy

A retail API uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured?

A.Auto Scaling policy based on an appropriate CloudWatch metric
B.S3 Object Lock
C.A VPC endpoint for CloudWatch only
D.Disable health checks
AnswerA

Target tracking scaling adjusts EC2 capacity automatically in response to a CloudWatch metric such as average CPU utilisation, so the fleet expands before latency degrades. This directly addresses the stem's consistently high peak CPU and rising request latency behind the ALB.

Why this answer

An Auto Scaling policy based on an appropriate CloudWatch metric (such as CPUUtilization or ALBRequestCountPerTarget) dynamically adds or removes EC2 instances to match demand. This directly addresses the high CPU and rising latency by distributing the load across more instances, preventing performance degradation during peak traffic.

Exam trap

The trap here is that candidates may confuse operational features (like S3 Object Lock or VPC endpoints) with scaling mechanisms, or mistakenly think disabling health checks improves performance, when in fact it degrades reliability and latency.

How to eliminate wrong answers

Option B is wrong because S3 Object Lock is a data protection feature for Amazon S3 objects (preventing deletion or overwriting) and has no relevance to scaling compute resources or reducing request latency. Option C is wrong because a VPC endpoint for CloudWatch only enables private connectivity to CloudWatch APIs (e.g., for publishing metrics or logs) but does not scale EC2 capacity or reduce latency. Option D is wrong because disabling health checks would cause the ALB to continue routing traffic to unhealthy instances, worsening latency and potentially causing failures; health checks are essential for maintaining a reliable target group.

466
MCQmedium

A trading dashboard runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The team wants the control to be enforceable during normal operations.

A.A single EC2 instance with detailed monitoring
B.Subnets in at least two Availability Zones with health checks enabled
C.All instances in one larger subnet
D.A Network Load Balancer in one subnet
AnswerB

Deploying subnets (and therefore EC2 instances) in at least two Availability Zones removes any single AZ as a point of failure. An Auto Scaling group distributed across those subnets works with a load balancer's health checks to detect unhealthy instances, terminate them, and launch replacement capacity in a healthy AZ. If one AZ fails entirely, the ASG can continue to meet desired capacity in the surviving AZ and the load balancer routes traffic away from unhealthy targets, keeping the dashboard available.

Why this answer

Distributing EC2 instances across at least two Availability Zones (AZs) ensures that if one AZ fails, the Auto Scaling group can maintain capacity in the remaining AZ(s). Enabling health checks allows the group to detect instance failures and automatically replace them, providing fault tolerance. This configuration meets the requirement to tolerate a single AZ failure while remaining enforceable during normal operations.

Exam trap

The trap here is that candidates often confuse high availability (spanning multiple AZs) with fault tolerance at the instance level, mistakenly thinking a single instance with monitoring or a single subnet can survive an AZ failure.

How to eliminate wrong answers

Option A is wrong because a single EC2 instance, even with detailed monitoring, cannot tolerate the failure of an entire Availability Zone; if that AZ goes down, the instance becomes unavailable. Option C is wrong because placing all instances in one larger subnet within a single AZ creates a single point of failure; an AZ failure would take down all instances. Option D is wrong because a Network Load Balancer in one subnet does not provide AZ-level fault tolerance; it still relies on that single AZ, and the Auto Scaling group must span multiple AZs for resilience.

467
MCQeasy

A solutions architect is configuring a VPC for a three-tier web application. The database tier must not be reachable from the internet, and only the application tier should be able to initiate connections to the database on port 3306. The application tier runs on EC2 instances in a separate subnet. Which configuration enforces this requirement?

A.Place the database instances in a private subnet and attach a network ACL that allows inbound traffic from the application subnet's CIDR range on port 3306.
B.Place the database instances in a private subnet and attach a security group that allows inbound traffic on port 3306 from 0.0.0.0/0, relying on the subnet's lack of an internet route for protection.
C.Place the database instances in a private subnet and attach a security group that allows inbound MySQL traffic from the application tier's security group on port 3306.
D.Place the database instances in a public subnet and attach a security group that allows inbound MySQL traffic only from the application tier's public IP addresses.
AnswerC

Referencing the application tier's security group as the source means only instances that carry that group can open a connection to port 3306, regardless of their IP addresses. A private subnet has no route to an internet gateway, so the database tier is not reachable from the internet, satisfying both parts of the requirement.

Why this answer

A security group rule that names the application tier's security group as the source grants access based on identity rather than IP range, so only those instances can reach the database on port 3306. Hosting the database in a private subnet removes any internet route, which is what keeps the tier unreachable from outside the VPC.

Exam trap

The trap here is relying on subnet routing alone for isolation while leaving the database port open to a broad CIDR, which permits lateral access from other resources inside the VPC.

468
MCQhard

A media processing workflow generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used?

A.S3 Intelligent-Tiering
B.Manual monthly review and object copying
C.S3 Glacier Flexible Retrieval for all files
D.EFS One Zone for analytics files
AnswerA

S3 Intelligent-Tiering automatically tracks object access and moves data between frequent and infrequent access tiers, with optional archive tiers, while charging no retrieval fees. It preserves S3 Standard latency and throughput, so analytics files remain immediately available when accessed. Because the tiering is entirely automated and backed by an SLA, it removes the need for human intervention or lifecycle guessing.

Why this answer

S3 Intelligent-Tiering automatically moves objects between access tiers (frequent, infrequent, and archive instant access) based on changing access patterns, with no retrieval delays for hot objects. This is ideal for unpredictable access where some files become hot again months later, as it optimizes storage costs without manual intervention or retrieval latency.

Exam trap

The trap here is that candidates may choose S3 Glacier Flexible Retrieval (Option C) thinking it is the cheapest archival option, but they overlook the requirement for 'no retrieval delays' and the unpredictable access pattern that makes Intelligent-Tiering's automatic tiering the correct choice.

How to eliminate wrong answers

Option B is wrong because manual monthly review and object copying is labor-intensive, error-prone, and cannot react to unpredictable access patterns in real time, leading to either higher costs or retrieval delays. Option C is wrong because S3 Glacier Flexible Retrieval has retrieval delays (minutes to hours) and is not suitable for files that may become hot again unpredictably, as it would introduce unacceptable latency. Option D is wrong because EFS One Zone is a file system, not an object storage service, and is designed for low-latency shared access within a single AZ, not for cost-optimized archival of analytics files with unpredictable retrieval.

469
MCQmedium

You run a web application on an EC2 Auto Scaling group behind an Application Load Balancer (ALB). During scheduled traffic spikes, new instances launch but customers occasionally see 5xx errors for the first few minutes after scale-out. Operational logs show instances need ~4 minutes to warm up (load caches and initialize dependencies). ALB target health becomes healthy only after this warm-up. Which change most directly improves performance during spikes by reducing the time to serve traffic after scaling?

A.Configure a larger ALB deregistration delay so that old targets remain longer before termination.
B.Use an Auto Scaling warm pool so instances are pre-initialized and ready to register quickly when the ASG scales out.
C.Increase the number of desired instances immediately without using scaling policies, and then rely on manual reconfiguration.
D.Switch from ALB to NLB so instances become reachable sooner without waiting for health checks.
AnswerB

With a warm pool, Auto Scaling can launch and keep a set of instances in a pre-initialized state (for example, instances are already booted and have completed parts of startup/initialization as supported by warm pool behavior). When scaling triggers, these instances can transition to service faster and begin registering with the ALB. Because your bottleneck is that instances take ~4 minutes to become truly ready, warming them ahead of time most directly reduces the gap between scale-out and customer-ready capacity (and therefore reduces 5xx occurrences while waiting for targets to pass ALB health checks).

Why this answer

B is correct because a warm pool pre-initializes instances (e.g., loading caches and dependencies) before they are added to the Auto Scaling group. When the ASG scales out, these pre-warmed instances can be quickly moved into service, bypassing the ~4-minute warm-up delay and reducing the window for 5xx errors.

Exam trap

The trap here is that candidates may think NLB bypasses health checks entirely, but in reality NLB still requires health checks to mark targets as healthy, and the application warm-up delay remains the bottleneck.

How to eliminate wrong answers

Option A is wrong because increasing the deregistration delay keeps old targets alive longer, which does not help new instances serve traffic faster; it only delays termination of existing instances. Option C is wrong because manually setting desired instances without scaling policies is not automated and does not address the root cause of warm-up latency during spikes. Option D is wrong because switching to NLB does not eliminate the need for health checks or application warm-up; NLB health checks are still required and instances still need time to become healthy, so 5xx errors would persist.

470
MCQmedium

A telemetry pipeline uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add?

A.Multi-AZ standby and route reads to the standby
B.RDS read replica and route reporting queries to it
C.S3 lifecycle policy
D.A larger NAT gateway
AnswerB

An RDS read replica receives asynchronous copies of the primary's data via its engine's replication mechanism, then serves read-only traffic on its own endpoint. Routing reporting queries there removes that load from the primary, satisfying the requirement to stop reporting queries slowing it down.

Why this answer

RDS Read Replicas are designed specifically to offload read-heavy workloads from the primary database. By creating a read replica and routing the reporting queries to it, the primary database is freed from processing these read-only queries, reducing contention and improving overall performance. This is the most cost-effective and architecturally appropriate solution for read scaling in RDS MySQL.

Exam trap

The trap here is confusing Multi-AZ standby (which is for failover, not read scaling) with a read replica, leading candidates to incorrectly choose Option A.

How to eliminate wrong answers

Option A is wrong because a Multi-AZ standby is for high availability and disaster recovery, not for read scaling; the standby does not accept read traffic unless a failover occurs. Option C is wrong because S3 lifecycle policies manage object storage tiers and expiration, which have no relevance to offloading database read queries. Option D is wrong because a larger NAT gateway increases outbound internet bandwidth for private subnets, but does not address database read performance or query offloading.

471
MCQeasy

A company serves public JavaScript and CSS files from S3 using CloudFront. After a frontend change, customers report a low CloudFront cache hit ratio. Requests now include an Authorization header, but these assets do not require authentication. The CloudFront distribution is configured such that Authorization is included in the cache key. Which change best maximizes cache reuse?

A.Include the Authorization header in the cache key so responses vary correctly
B.Use a CloudFront Cache Policy that excludes Authorization from the cache key
C.Disable caching and always fetch from S3
D.Forward all headers and cookies to the origin to improve correctness
AnswerB

Because the assets are public and do not depend on Authorization, excluding Authorization from the cache key allows all users to share the same cached objects. This reduces cache fragmentation and increases cache hit ratio.

Why this answer

Excluding the Authorization header from the cache key ensures that all users, regardless of their authentication token, receive the same cached object. Since the static assets (JavaScript/CSS) do not require authentication, including Authorization in the cache key creates multiple cache entries for the same file, drastically reducing the cache hit ratio. A CloudFront cache policy that omits Authorization from the cache key maximizes reuse while still allowing the header to be forwarded to the origin if needed.

Exam trap

The trap here is that candidates may assume including the Authorization header is necessary for correctness, but for public static assets, excluding it from the cache key is the correct way to maximize cache reuse without affecting delivery.

How to eliminate wrong answers

Option A is wrong because including the Authorization header in the cache key would cause CloudFront to cache separate copies for each unique token value, which is exactly the problem that reduces the cache hit ratio. Option C is wrong because disabling caching entirely would increase latency and origin load, violating the goal of maximizing cache reuse. Option D is wrong because forwarding all headers and cookies to the origin would not only include unnecessary Authorization values but also further fragment the cache, worsening the hit ratio and adding overhead.

472
MCQhard

A order processing API uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

A.IAM database authentication for RDS with an EC2 instance role
B.Store the database password in user data
C.Use a security group rule that allows only application instances
D.Embed the database password in the AMI
AnswerA

IAM database authentication lets the EC2 instance's attached role call RDS's GenerateDBAuthToken API, producing a signed token that the PostgreSQL client presents as the password; the token expires after 15 minutes and the connection uses SSL, so no permanent secret exists in application code, configuration files, or disk. With this design, you create a DB user for IAM authentication in PostgreSQL and grant it privileges while controlling access via IAM policies, making credential rotation unnecessary for the application.

Why this answer

IAM database authentication for RDS allows EC2 instances to authenticate to PostgreSQL using a short-lived token generated via the AWS CLI or SDK, instead of a static password. By assigning an IAM instance role to the EC2 instance, the application can obtain the token without storing any credentials on the instance, meeting both security requirements. This approach uses the IAM role's temporary security credentials to generate a password token that is valid for 15 minutes, after which a new token must be obtained.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups) with authentication mechanisms, or they assume that storing credentials in user data or AMIs is acceptable because it is 'hidden,' but the exam explicitly tests the requirement for short-lived, non-persistent credentials.

How to eliminate wrong answers

Option B is wrong because storing the database password in user data leaves it in plaintext on the instance metadata, which can be accessed by any process or user with instance metadata access, and it does not use short-lived credentials. Option C is wrong because a security group rule only controls network access at the transport layer; it does not provide authentication credentials or eliminate the need to store them on the instance. Option D is wrong because embedding the database password in the AMI hardcodes the credential into the image, which persists across instances and cannot be rotated without rebuilding the AMI, violating the requirement for short-lived credentials.

473
MCQmedium

Based on the exhibit, the company wants DNS traffic to fail over automatically from the primary Region to a secondary Region when the primary endpoint is unhealthy. Which Route 53 change is best?

A.Keep simple routing and lower the TTL to 10 seconds.
B.Use weighted routing with equal weights for both ALBs.
C.Use geolocation routing so users in each continent reach a closer ALB.
D.Create Route 53 failover records with health checks for the primary and secondary ALBs.
AnswerD

Failover routing is the Route 53 policy intended for this use case. Route 53 returns the primary record while its health check passes, and automatically serves the secondary record when the primary health check fails. That provides DNS-based Regional failover without manual intervention.

Why this answer

Route 53 failover routing with health checks is the only option that automatically directs DNS traffic away from an unhealthy primary endpoint to a healthy secondary endpoint. When the health check for the primary ALB fails, Route 53 returns the secondary ALB's IP address in DNS responses, providing automatic failover across regions. Simple, weighted, and geolocation routing do not natively support automatic failover based on endpoint health.

Exam trap

The trap here is that candidates often confuse weighted routing with failover, assuming equal weights will somehow cause automatic failover, but weighted routing does not consider health status and requires manual intervention to shift traffic.

Why the other options are wrong

A

Simple routing does not support health checks or automatic failover; lowering TTL only speeds up DNS propagation but does not enable failover to a secondary endpoint when the primary is unhealthy.

B

Weighted routing distributes traffic based on weights, not health; it does not automatically failover to a healthy endpoint when the primary is unhealthy.

C

Geolocation routing directs traffic based on the user's geographic location, not health. It does not automatically failover to a secondary region when the primary endpoint is unhealthy; it would continue sending traffic from that region to the unhealthy endpoint.

When would these options actually be correct?

A

When the requirement is to distribute traffic evenly across multiple healthy endpoints without health-based failover, and the application can tolerate brief downtime during DNS propagation. For example, a static website hosted on multiple servers where manual failover is acceptable.

B

When you need to distribute traffic across multiple endpoints with a specified ratio (e.g., 10% to one ALB and 90% to another) for A/B testing or gradual migration, and health checks are not required for automatic failover.

C

A company wants to direct users to the nearest application endpoint based on their geographic location to reduce latency, and each region's endpoint is stateless and can serve all users. In that case, geolocation routing is appropriate.

Why candidates pick the wrong answer

A

Candidates may think that a low TTL combined with simple routing can achieve fast failover by quickly updating DNS records, but they overlook that simple routing lacks health checks and automatic record switching.

B

Candidates may think equal weights provide load balancing and failover, but weighted routing lacks health-based automatic failover; it only splits traffic proportionally.

C

Candidates may think geolocation routing can provide failover by routing users away from an unhealthy region, but it lacks health-based automatic failover and is designed for latency reduction, not disaster recovery.

474
MCQhard

A mobile banking backend uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

A.Store the database password in user data
B.IAM database authentication for RDS with an EC2 instance role
C.Use a security group rule that allows only application instances
D.Embed the database password in the AMI
AnswerB

IAM database authentication for RDS replaces a static database password with an authentication token generated from the EC2 instance profile using AWS Signature Version 4. The application requests the token via the RDS API (or AWS SDK), and the token is valid for only 15 minutes, so the credential is ephemeral and automatically rotated. This approach avoids long-lived secrets in application code or configuration, enforces least-privilege access because the IAM role governs which database user the instance can connect as, and logs all token generation in CloudTrail. Note that the RDS instance must have IAM DB authentication enabled, and the database user must be created with the `PASSWORD` clause set to `AUTHENTICATED OVER IAM` in PostgreSQL.

Why this answer

IAM database authentication for RDS with an EC2 instance role is the correct approach because it eliminates the need to store credentials on the instance. The EC2 instance assumes an IAM role, which obtains a short-lived (15-minute default) authentication token using the AWS CLI's `generate-db-auth-token` command. This token is used as the password for the PostgreSQL connection, ensuring credentials are never stored and automatically rotated.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups) with authentication mechanisms, or they assume that storing credentials in user data or AMIs is acceptable because they are 'hidden', but the exam strictly requires no static credentials on the instance and short-lived tokens.

How to eliminate wrong answers

Option A is wrong because storing the database password in user data leaves it in plaintext on the instance metadata, which is accessible to any process or user with access to the instance, violating the requirement to not store credentials on EC2. Option C is wrong because a security group rule only controls network access at the transport layer; it does not address authentication or credential storage, and the application would still need a static password to connect. Option D is wrong because embedding the database password in the AMI hardcodes the credential into the image, which persists across instances and violates the principle of not storing credentials on the instance, plus it cannot provide short-lived credentials.

475
MCQeasy

A company has an application running on Amazon EC2 instances that needs to access an Amazon S3 bucket. The security team wants to avoid storing long-term AWS credentials on the instances. Which solution should they implement?

A.Generate an AWS access key and secret key for an IAM user and embed them in the application code.
B.Store AWS credentials in a configuration file on each EC2 instance and restrict file permissions.
C.Create an IAM role with the necessary S3 permissions and attach it to the EC2 instances.
D.Use AWS Secrets Manager to store the credentials and retrieve them at runtime.
AnswerC

Attaching an IAM role to EC2 instances provides temporary credentials that are automatically rotated. The instances can then access S3 without storing long-term credentials. This is the AWS best practice for granting permissions to EC2 instances and meets the requirement to avoid long-term credentials.

Why this answer

Attaching an IAM role to EC2 instances allows the instances to obtain temporary credentials from the instance metadata service. These credentials are automatically rotated and do not need to be stored on the instance. This eliminates the need for long-term credentials and is the recommended approach for granting AWS permissions to EC2 instances.

Exam trap

The trap here is thinking that Secrets Manager eliminates the need for credentials; it still requires managing and rotating secrets, whereas IAM roles provide temporary credentials automatically.

476
MCQhard

A IoT ingestion API uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

A.Store the database password in user data
B.Embed the database password in the AMI
C.IAM database authentication for RDS with an EC2 instance role
D.Use a security group rule that allows only application instances
AnswerC

With IAM database authentication, an EC2 instance uses its attached IAM role to generate a temporary authentication token via the RDS generate_db_auth_token API, then supplies that token as the PostgreSQL password. The token is valid for 15 minutes and is cryptographically signed by the IAM role, so RDS can verify it without a stored password. This eliminates embedded secrets, enables rotation by simply refreshing the role credentials, and gives you centralized IAM policies to control which DB users can connect from which identity.

Why this answer

IAM database authentication for RDS allows EC2 instances to authenticate to PostgreSQL using short-lived credentials obtained via an IAM instance role, eliminating the need to store long-term credentials on the instance. The EC2 instance assumes the role, retrieves a temporary authentication token (valid for 15 minutes), and uses it to connect to the RDS database, meeting both security requirements.

Exam trap

The trap here is that candidates confuse network-level controls (security groups) with authentication mechanisms, assuming that restricting traffic alone satisfies credential security, while the real requirement is about eliminating stored long-term credentials entirely.

How to eliminate wrong answers

Option A is wrong because storing the database password in user data is insecure — user data is accessible from within the instance and can be retrieved by any process or user with access, and it does not provide short-lived credentials. Option B is wrong because embedding the database password in an AMI creates a static credential that persists across instances launched from that AMI, violating the requirement for short-lived credentials and increasing the risk of credential exposure. Option D is wrong because a security group rule controls network access at the transport layer but does not address authentication or credential management; it cannot provide short-lived credentials or eliminate the need to store passwords on the instance.

477
MCQmedium

A microservice runs in private subnets and must read exactly one AWS Secrets Manager secret using its IAM task role: arn:aws:secretsmanager:us-east-1:111122223333:secret:prod/db-pass-AbCdEf Security requires that every Secrets Manager API call comes only through a specific Interface VPC Endpoint (vpce-0a1b2c3d4e5f6g7h), and must not be reachable over any other network path. Which IAM policy change best enforces this requirement?

A.In the task role policy statement for secretsmanager:GetSecretValue on the secret ARN, add a condition that allows the action only when aws:SourceVpce equals vpce-0a1b2c3d4e5f6g7h.
B.Add a condition that allows secretsmanager:GetSecretValue only when aws:SourceIp is within 10.0.0.0/8.
C.Require TLS by adding a condition on aws:SecureTransport for the Secrets Manager permission.
D.Add a KMS condition using kms:ViaService=secretsmanager.us-east-1.amazonaws.com instead of restricting Secrets Manager directly.
AnswerA

For Interface VPC endpoints, aws:SourceVpce can be used as a condition key so KMS/Secrets Manager API authorization succeeds only when the request originates from the specified endpoint. Restricting the IAM permission to aws:SourceVpce=vpce-... directly matches the requirement that calls must not traverse other network paths (e.g., via NAT/egress).

Why this answer

The condition `aws:SourceVpce` in the IAM policy restricts the `secretsmanager:GetSecretValue` API call to originate only from the specified VPC Endpoint (vpce-0a1b2c3d4e5f6g7h). This ensures that the secret can only be accessed via that specific Interface Endpoint, blocking any other network path (e.g., internet, NAT gateway, or other VPC endpoints). The task role is attached to the microservice, so the policy directly enforces the security requirement at the API level.

Exam trap

The trap here is that candidates often confuse `aws:SourceVpce` with `aws:SourceIp` or `aws:SourceVpc`, thinking any network-level condition will work, but only `aws:SourceVpce` uniquely identifies the specific Interface VPC Endpoint required for this strict enforcement.

How to eliminate wrong answers

Option B is wrong because `aws:SourceIp` condition key is not effective for requests made through a VPC Endpoint; the source IP is replaced by the endpoint's private IP, making the condition unreliable for restricting traffic to a specific endpoint. Option C is wrong because requiring TLS (`aws:SecureTransport`) only ensures encryption in transit, not that the API call comes through a specific VPC Endpoint; it does not restrict the network path. Option D is wrong because `kms:ViaService` restricts KMS key usage to a specific AWS service (Secrets Manager), but it does not control which network path (e.g., VPC Endpoint) the Secrets Manager API call uses; it addresses KMS authorization, not network-level restriction.

478
MCQmedium

A batch analytics job has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The design must avoid adding custom operational scripts.

A.DynamoDB on-demand capacity mode
B.Reserved capacity for maximum daily traffic
C.Provisioned capacity set for peak traffic
D.Global tables in every Region
AnswerA

On-demand capacity mode enables DynamoDB to automatically scale to match your workload's actual traffic, charging per read and write request (pay-per-request) rather than for provisioned capacity. For a batch analytics job with unpredictable traffic, this eliminates manual capacity planning, avoids throttling during sudden spikes, and ensures you only pay for the requests actually processed, making it the most cost-effective and operationally simple choice.

Why this answer

DynamoDB on-demand capacity mode automatically scales to handle unpredictable traffic spikes and idle periods without requiring any capacity planning or management. It charges only for the reads and writes you perform, eliminating the cost of idle provisioned capacity and avoiding the need for custom scripts to adjust capacity.

Exam trap

The trap here is that candidates may confuse 'reserved capacity' (a pricing discount for provisioned capacity) with a capacity mode, or assume that provisioned capacity set for peak traffic is cost-effective, ignoring the cost of idle periods.

How to eliminate wrong answers

Option B is wrong because reserved capacity is a pricing model for provisioned capacity, not a capacity mode; it requires you to commit to a specific throughput level and does not eliminate idle costs. Option C is wrong because setting provisioned capacity for peak traffic would result in paying for unused capacity during long idle periods, increasing costs and requiring manual or scripted adjustments. Option D is wrong because global tables replicate data across Regions for disaster recovery or low-latency access, not for managing capacity or cost optimization; they add complexity and cost without addressing idle capacity.

479
MCQhard

A financial analytics platform stores results in an Amazon S3 bucket. Compliance requires that objects be recoverable for 30 days after deletion and that no user, including administrators, be able to permanently erase them during that window. Objects must also remain readable throughout the retention period. Which approach should the architect implement?

A.Enable S3 Object Lock in governance mode with a 30-day retention period on the bucket.
B.Enable S3 Versioning and add a bucket policy that denies s3:DeleteObject to all principals.
C.Configure an S3 Lifecycle rule to transition objects to S3 Glacier Instant Retrieval after one day and expire them after 30 days.
D.Enable S3 Object Lock in compliance mode with a 30-day retention period on the bucket.
AnswerD

Compliance mode enforces a write-once-read-many model in which no principal, including the root user, can overwrite or delete a locked object version before the retention date expires. Objects stay readable throughout the period, satisfying the availability clause. A 30-day retention directly matches the stated recovery window, and the protection is enforced by S3 itself rather than by policy that could be changed.

Why this answer

Meeting the requirement means using a control enforced by the storage service that no identity can override. S3 Object Lock in compliance mode provides exactly that: locked object versions cannot be deleted or overwritten by any principal until the retention period lapses, and they remain readable. Governance mode, versioning with policies, and lifecycle expiration all leave a deletion path open for privileged users.

Exam trap

The trap here is treating governance mode as equivalent to compliance mode, when governance mode still permits privileged users to bypass retention.

480
MCQhard

A document portal needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable? The architecture review board prefers a managed AWS-native control.

A.Amazon OpenSearch Service
B.AWS Config
C.Amazon EFS
D.Amazon SQS
AnswerA

Amazon OpenSearch Service is a managed implementation of the OpenSearch engine (fork of Elasticsearch), built on Apache Lucene. It creates inverted indexes from your documents so that every token is mapped to its location, enabling sub-second full-text queries with relevance scoring (e.g., BM25). This is exactly the low-latency, scalable search capability a document portal needs for rapid search across all stored content.

Why this answer

Amazon OpenSearch Service is a managed service that provides low-latency full-text search and analytics capabilities, making it ideal for indexing and searching product descriptions and filtered attributes. It is AWS-native and supports features like inverted indices, fuzzy search, and faceted filtering, which directly address the requirement for a high-performance document portal.

Exam trap

The trap here is that candidates may confuse Amazon CloudSearch (another managed search service) with OpenSearch Service, but the question emphasizes 'AWS-native control' and OpenSearch Service is the more modern, feature-rich choice for full-text search with filtering.

How to eliminate wrong answers

Option B is wrong because AWS Config is a service for resource inventory, compliance auditing, and configuration change tracking, not a full-text search engine. Option C is wrong because Amazon EFS is a scalable file storage service for shared access to files, not a search or indexing service. Option D is wrong because Amazon SQS is a fully managed message queuing service for decoupling microservices, not a search or query engine.

481
MCQeasy

Your company allows application teams to create IAM roles. Each team must be prevented from granting permissions beyond a defined per-role baseline, even if they attach overly permissive identity-based policies to the role. Which AWS feature best enforces this ceiling at the IAM role level?

A.Use an Organizations service control policy (SCP) to cap the maximum permissions for role creation in each account
B.Attach a permission boundary to every role that teams create so the boundary limits the role’s maximum effective permissions
C.Rely on KMS key policies to restrict permissions because IAM policies cannot override KMS restrictions
D.Require multi-factor authentication (MFA) for all role creation requests and deny any request without MFA
AnswerB

A permission boundary acts as a permissions ceiling for the role. Even if the team attaches an identity-based policy that grants broader permissions, the role’s effective permissions are only those allowed by both the identity policy and the permission boundary. This prevents privilege escalation by role policy changes while still allowing teams to manage which policies are attached, within the boundary.

Why this answer

Permission boundaries are an AWS IAM feature that sets the maximum permissions that an identity-based policy can grant to an IAM role. When a permission boundary is attached to a role, the effective permissions are the intersection of the boundary and the role's identity-based policy, ensuring that even if a team attaches an overly permissive policy, the role cannot exceed the boundary's defined limits. This directly enforces a per-role ceiling on permissions, making option B the correct choice.

Exam trap

The trap here is that candidates often confuse SCPs with permission boundaries, thinking SCPs can enforce per-role limits, but SCPs apply to all principals in an account and cannot be scoped to individual roles, whereas permission boundaries are specifically designed for that purpose.

Why the other options are wrong

A

SCPs apply to all principals in an account and cannot be scoped to individual roles; they set an account-wide ceiling, not a per-role boundary. The question requires a per-role limit, which SCPs cannot provide.

C

KMS key policies control access to encryption keys, not IAM role permissions. They cannot enforce a ceiling on the maximum permissions an IAM role can have, which is the requirement in this question.

When would these options actually be correct?

A

An exam question asks: 'How can an organization ensure that no IAM role in any account can exceed a certain set of permissions, regardless of the policies attached to the role?' In that case, an SCP at the root or OU level would enforce a maximum permission ceiling across all roles in the account.

C

A question asking how to restrict which AWS KMS keys a role can use for encryption/decryption, where you need to ensure that even if an IAM policy grants broad KMS access, the key policy overrides it to deny access.

Why candidates pick the wrong answer

A

Candidates know SCPs can cap permissions, so they mistakenly think they can be applied per role, overlooking that SCPs are account-wide and cannot differentiate between roles within an account.

C

Candidates may confuse permission boundaries with resource-based policies like KMS key policies, thinking that a restrictive key policy can cap permissions, but key policies only apply to the specific key, not to the role's overall permissions.

482
MCQmedium

A test environment stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost? The architecture review board prefers a managed AWS-native control.

A.Keep all logs in S3 Standard indefinitely
B.Move all logs immediately to S3 Glacier Deep Archive
C.S3 lifecycle policy that transitions objects to lower-cost storage classes over time
D.Use EBS snapshots for the logs
AnswerC

An S3 lifecycle policy automates object transitions between storage classes based on age, so you can keep recent logs in S3 Standard for fast querying and gradually move them to S3 Standard-IA, Glacier Flexible Retrieval, or Glacier Deep Archive as they age. For example, transition logs older than 30 days to Standard-IA, then to Glacier after 90 days, and finally expire them after a defined retention period. This matches storage cost to actual access patterns without manual intervention, and you retain the ability to query recent data instantly while old data is archived cheaply.

Why this answer

S3 Lifecycle policies allow you to automate the transition of objects from S3 Standard to lower-cost storage classes like S3 Standard-IA (after 30 days) and then to S3 Glacier Deep Archive (after one year) for long-term compliance. This matches the access pattern of frequent queries for 30 days, rare access for a year, and then retention-only, minimizing storage costs without manual intervention.

Exam trap

The trap here is that candidates may choose Option B (immediate move to Glacier Deep Archive) thinking it maximizes cost savings, but they overlook the requirement for 30 days of queryable access, which Glacier Deep Archive cannot support due to its multi-hour retrieval times.

How to eliminate wrong answers

Option A is wrong because keeping all logs in S3 Standard indefinitely incurs the highest storage cost, ignoring the infrequent access and long-term retention requirements. Option B is wrong because moving all logs immediately to S3 Glacier Deep Archive eliminates the ability to query them for 30 days, as retrieval times are hours and not suitable for active queries. Option D is wrong because EBS snapshots are designed for block-level backups of EC2 instances, not for storing log files; they are not a cost-effective or managed-native solution for S3 log storage and would introduce unnecessary complexity and cost.

483
MCQmedium

A healthcare company stores patient records in an Amazon S3 bucket. Compliance requires that every object be encrypted with a key that the company rotates on its own schedule, that key usage be logged separately from S3 data events, and that a specific group of IAM principals be the only identities allowed to use the key for cryptographic operations. The security team has already created a symmetric AWS KMS customer managed key. Which combination of actions should the team take to meet these requirements?

A.Enable SSE-C on the bucket and distribute the raw encryption key to the application team so they pass it in the x-amz-server-side-encryption-customer-key header with each request.
B.Enable S3 default encryption with SSE-S3 (AES-256) on the bucket, and rely on the AWS managed key aws/s3 for rotation and audit logging.
C.Use client-side encryption with the AWS Encryption SDK, store the data key in AWS Secrets Manager, and let any principal in the account retrieve it when needed.
D.Configure the bucket to use SSE-KMS with the customer managed key, and edit the key policy so only the designated principals have kms:Decrypt, kms:GenerateDataKey, and related permissions.
AnswerD

SSE-KMS with a customer managed key lets the company define its own rotation schedule, produces separate AWS CloudTrail entries for the KMS key, and enforces access through the key policy. Restricting the key policy to the designated IAM principals ensures only those identities can perform cryptographic operations, which directly meets the stated compliance requirements.

Why this answer

A customer managed key in AWS KMS is the only option that gives the organization control over rotation, produces dedicated CloudTrail logging of key usage, and enforces who may perform cryptographic operations through the key policy. Pairing it with SSE-KMS on the bucket applies that governance to every object written to the bucket without application changes.

Exam trap

The trap here is assuming that enabling any server-side encryption on the bucket automatically gives you control over rotation and key-level access, when only a customer managed KMS key provides that governance.

484
Multi-Selectmedium

An order lookup API repeatedly reads the same few items from DynamoDB. The application can tolerate slightly stale data for a few seconds, and the team wants the lowest-latency design with minimal application changes. Which two changes should they make? Select two.

Select 2 answers
A.Put Amazon DynamoDB Accelerator (DAX) in front of the table.
B.Use eventually consistent reads where the application can tolerate slightly stale data.
C.Switch all access to strongly consistent reads for faster results.
D.Increase the item size so fewer requests are needed.
E.Replace the table with Amazon EBS volumes mounted on EC2 instances.
AnswersA, B

DAX is an in-memory cache for DynamoDB reads, so repeated lookups for the same keys can be served with much lower latency than direct table reads. It is especially effective for hot-item access patterns like order lookups, product metadata, and profile reads.

Why this answer

Option A is correct because Amazon DynamoDB Accelerator (DAX) is a fully managed, in-memory cache for DynamoDB that delivers microsecond read latency for repeated access to the same items, and it requires minimal application changes since it is API-compatible with DynamoDB. Option B is correct because eventually consistent reads cost half as many read capacity units and typically have lower latency than strongly consistent reads, and the scenario explicitly states the application can tolerate slightly stale data for a few seconds. Option C is wrong because strongly consistent reads are slower and consume twice the read capacity of eventually consistent reads, so they do not provide faster results.

Option D is wrong because increasing item size does not reduce the number of requests and actually increases the cost and latency of each read. Option E is wrong because replacing DynamoDB with EBS volumes on EC2 would require major application changes, lose DynamoDB's managed scalability, and not provide the low-latency cached reads the team wants.

Exam trap

The trap here is that candidates may think strongly consistent reads are always faster, but they actually have higher latency and cannot be cached by DAX, making them unsuitable for this low-latency, minimal-change requirement.

Why the other options are wrong

C

Strongly consistent reads have higher latency and consume more read capacity units than eventually consistent reads, so switching to them would increase latency, not reduce it.

D

Increasing item size does not reduce the number of read requests for the same few items; it may increase read costs and latency due to larger data transfer.

E

EBS volumes do not provide a managed, low-latency caching layer for DynamoDB; they require significant application changes to migrate from DynamoDB to a self-managed database, contradicting the 'minimal application changes' requirement.

When would these options actually be correct?

C

If the application requires the most up-to-date data and cannot tolerate any staleness, and the team is willing to accept higher latency and cost, then strongly consistent reads would be the correct choice.

D

When the application needs to reduce the number of read requests to DynamoDB to lower costs or avoid throttling, and the items are frequently accessed together, combining them into a single larger item can be correct.

E

A question requiring a durable, block-level storage solution for a legacy application that needs to run on EC2 with low-latency local access, and where the team is willing to manage the database layer themselves, would make EBS the correct choice.

Why candidates pick the wrong answer

C

Candidates may mistakenly believe that 'strongly consistent' implies 'faster' because it sounds more authoritative, or they may not understand the trade-off between consistency and latency in DynamoDB.

D

Candidates may think larger items mean fewer requests, but the question specifies repeatedly reading the same few items, so request count is already low; larger items don't help latency.

E

Candidates may think EBS offers lower latency than DynamoDB because it is directly attached to EC2, overlooking the complexity of replacing a managed NoSQL service with a self-managed storage solution.

485
MCQmedium

A analytics dashboard uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add? The architecture review board prefers a managed AWS-native control.

A.S3 lifecycle policy
B.RDS read replica and route reporting queries to it
C.Multi-AZ standby and route reads to the standby
D.A larger NAT gateway
AnswerB

An RDS read replica is a separate, read-only MySQL instance that receives asynchronous updates from the primary database. By pointing the analytics dashboard's reporting queries at the replica's endpoint, you move the expensive SELECT and aggregation work off the primary, freeing CPU, memory, and I/O for transactional writes. Multiple replicas can be added to scale read capacity further, making this the correct answer for read-only dashboard traffic.

Why this answer

B is correct because an RDS read replica is a fully managed, native AWS solution that offloads read-heavy reporting queries from the primary RDS MySQL instance. The read replica asynchronously replicates data using the MySQL binlog, allowing reporting traffic to be routed to it without impacting the primary database's write performance. This directly addresses the slowdown caused by many read-only queries while satisfying the architecture review board's preference for a managed AWS-native control.

Exam trap

The trap here is confusing the Multi-AZ standby (which is for failover only and cannot serve reads) with a read replica (which is specifically designed to offload read traffic), leading candidates to incorrectly select Option C as a managed solution for read scaling.

How to eliminate wrong answers

Option A is wrong because an S3 lifecycle policy manages object transitions and expirations in S3, not database read traffic; it cannot offload SQL queries from RDS. Option C is wrong because a Multi-AZ standby is designed for high availability and automatic failover, not for serving read traffic — it does not accept direct connections for reads, and any attempt to route reads to it would fail or require unsupported workarounds. Option D is wrong because a NAT gateway provides outbound internet access for private subnets and has no role in distributing database read queries; it cannot reduce load on an RDS primary instance.

486
MCQhard

Based on the exhibit, a static asset distribution site uses Amazon CloudFront with an S3 origin. The assets are versioned by filename, but the cache hit ratio remains low after each release. Which CloudFront change is the best way to improve cache reuse without changing the origin objects?

A.Keep the current cache key and increase the S3 bucket's storage class.
B.Remove Authorization and unnecessary query strings from the CloudFront cache key.
C.Disable the CloudFront cache so every request is served directly from S3.
D.Switch the origin from Amazon S3 to an Application Load Balancer.
AnswerB

CloudFront's cache key includes headers and query strings by default, so Authorization headers and irrelevant parameters fragment cached objects. Removing them lets versioned filenames alone key the cache, raising hit ratios without altering origin objects.

Why this answer

Removing Authorization headers and unnecessary query strings from the CloudFront cache key ensures that multiple requests for the same versioned asset (e.g., style.v2.css) share a single cached object, regardless of user-specific headers or irrelevant query parameters. This directly increases the cache hit ratio without modifying the origin objects, as CloudFront will serve the same cached response for identical cache keys.

Exam trap

The trap here is that candidates may think increasing storage class or switching to an ALB improves caching, but the real issue is the cache key composition—specifically, unnecessary headers or query strings fragmenting the cache—which is solved by adjusting the CloudFront cache key settings.

How to eliminate wrong answers

Option A is wrong because changing the S3 bucket's storage class (e.g., to S3 Standard-IA or Glacier) has no effect on CloudFront's cache key or cache hit ratio; it only affects storage cost and retrieval latency, not caching behavior. Option C is wrong because disabling the CloudFront cache would force every request to go directly to the S3 origin, eliminating all caching benefits and increasing latency and origin load, which is the opposite of improving cache reuse. Option D is wrong because switching the origin from S3 to an Application Load Balancer (ALB) introduces unnecessary complexity and does not address the cache key issue; the ALB would still require the same cache key optimization to improve cache hits, and it would not inherently improve cache reuse.

487
MCQhard

A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used?

A.Amazon EFS with mount targets in multiple Availability Zones
B.S3 mounted as a POSIX file system without a file gateway
C.Instance store volumes
D.An EBS volume attached to all instances
AnswerA

Amazon EFS is a fully managed, regional file storage service that provides a standard POSIX file system interface (NFSv4.1) for EC2 instances. By configuring mount targets in multiple Availability Zones, instances across the VPC can concurrently read and write to the same file system with shared file locking and metadata guarantees. This architecture delivers both high availability and elastic scalability, making it the appropriate shared storage layer for a warehouse integration service that must be accessed by multiple compute resources simultaneously.

Why this answer

Amazon EFS provides a fully managed, scalable, and elastic NFS file system that can be mounted concurrently on multiple Linux EC2 instances across different Availability Zones. By configuring mount targets in each AZ, the file system remains accessible even if one AZ fails, because the other mount targets continue to serve traffic. This meets the requirement for shared, highly available file storage across AZs.

Exam trap

The trap here is that candidates may confuse EBS multi-attach (which has strict limitations and is not suitable for shared file systems across AZs) with a true distributed file system like EFS, or assume that S3 with a FUSE driver can replace a POSIX-compliant shared file system.

How to eliminate wrong answers

Option B is wrong because mounting S3 as a POSIX file system without a file gateway (e.g., using s3fs-fuse) does not provide true POSIX semantics (e.g., file locking, atomic operations) and introduces performance and consistency issues; it is not a native shared file system for Linux EC2 instances. Option C is wrong because instance store volumes are ephemeral and tied to a single EC2 instance; they are lost if the instance stops or fails, and cannot be shared across instances or survive an AZ failure. Option D is wrong because a single EBS volume can only be attached to one EC2 instance at a time (multi-attach EBS is limited to specific io1/io2 volumes and is not designed for shared file system workloads across multiple instances in different AZs).

488
MCQmedium

A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ASG is currently attached to subnets in only two Availability Zones (AZs). During a planned maintenance window, one AZ becomes unavailable for about 25 minutes. Monitoring shows that targets in the remaining AZ go healthy, and the ALB/target group health checks report normal. However, users still experience intermittent connection failures and slower responses during the AZ outage. What change will most directly improve resilience against an AZ loss while keeping the same ALB-based design?

A.Set the ASG min capacity to 0 so instances can be recreated faster when an AZ recovers.
B.Extend the ASG to use subnets in three AZs so there is placement redundancy during an AZ outage, while continuing to keep traffic behind the ALB.
C.Increase the ALB idle timeout to 120 seconds to reduce connection drops.
D.Disable health checks on the target group so instances are not deregistered during the maintenance window.
AnswerB

An AZ outage reduces the number of AZs where the ASG can place instances. With only two AZs, losing one significantly limits capacity and can cause temporary shortages and uneven load distribution, even if existing targets are marked healthy. Expanding the ASG to subnets in three (or more) AZs provides additional placement options so the ASG can maintain the desired number of instances across the remaining AZ(s). The ALB will continue routing only to healthy targets, and the system is more likely to sustain stable response times during the outage.

Why this answer

B is correct because deploying the ASG across three Availability Zones (AZs) ensures that when one AZ becomes unavailable, the remaining two AZs can handle the full traffic load without overloading the instances. This placement redundancy directly addresses the intermittent connection failures and slower responses, as the ALB can distribute traffic only to healthy targets in the remaining AZs, maintaining capacity and performance. The current two-AZ setup lacks sufficient buffer capacity, causing the single remaining AZ to become overwhelmed during the outage.

Exam trap

The trap here is that candidates may focus on connection-level settings (idle timeout) or health check behavior, missing the fundamental architectural need for multi-AZ redundancy to maintain capacity during an AZ outage.

How to eliminate wrong answers

Option A is wrong because setting the ASG min capacity to 0 does not help during an AZ outage; it would actually allow all instances to be terminated, making the application unavailable, and it does not address the lack of capacity in the remaining AZ. Option C is wrong because increasing the ALB idle timeout to 120 seconds only keeps idle connections open longer, which does not prevent connection failures or slow responses caused by insufficient capacity in the remaining AZ; it may even mask underlying issues. Option D is wrong because disabling health checks on the target group would prevent the ALB from deregistering unhealthy instances, causing traffic to be routed to failed instances in the unavailable AZ, leading to more connection failures and no improvement in resilience.

489
MCQeasy

A company runs a batch processing job on Amazon EC2 instances that runs for 4 hours every night. The job can be interrupted and restarted from a checkpoint. The company wants to minimize compute costs for this job. Which solution is MOST cost-effective?

A.Run the job on On-Demand Instances.
B.Use Dedicated Hosts for the instances.
C.Run the job on Spot Instances.
D.Purchase a 1-year All Upfront Reserved Instance for the instances.
AnswerC

Spot Instances offer the largest discounts on EC2 compute, often up to 90% off On-Demand, and are ideal for interruptible, stateless, or checkpointed workloads. Since the batch job runs for a short duration nightly and can resume from checkpoints, interruptions are tolerable. Using Spot Instances directly reduces compute costs substantially without requiring upfront commitments or long-term contracts, making it the most cost-effective option.

Why this answer

Spot Instances are the most cost-effective choice for interruptible, checkpointed batch workloads because they leverage spare EC2 capacity at a steep discount. The job runs for a short, predictable duration nightly and can resume after interruptions, which perfectly matches Spot's interruption model. Reserved Instances and Dedicated Hosts involve commitments or high fixed costs that are wasteful for intermittent usage, and On-Demand is more expensive than Spot.

Exam trap

The trap here is assuming that Reserved Instances always lower costs, when their benefit only materializes with steady, high-utilization workloads rather than short nightly batch jobs.

490
MCQmedium

A SaaS company serves a global web application from a single AWS Region. Users in distant geographies report high latency for static assets such as images and JavaScript bundles, and the company wants to reduce this latency without modifying the application code. Which action BEST achieves this?

A.Enable Amazon S3 Transfer Acceleration on the bucket that holds the static assets.
B.Move the application's static assets into an Amazon S3 bucket in a second Region and update the asset URLs.
C.Attach an Elastic Load Balancer with cross-zone load balancing to the web tier.
D.Create an Amazon CloudFront distribution with the application's origin and serve static assets through the distribution.
AnswerD

CloudFront caches static assets at edge locations close to viewers, so requests are served from a nearby point of presence instead of traveling to the single Region. This cuts latency for distant users without any application code changes, and it also reduces load on the origin by absorbing repeated requests for the same assets.

Why this answer

Reducing latency for globally distributed users of static content is the classic use case for a content delivery network. CloudFront caches assets at edge locations near viewers, so repeat requests never cross the globe to the origin Region. It requires no application code change, and it offloads the origin, which improves both latency and scalability.

Exam trap

The trap here is confusing transfer acceleration, which speeds transfers to a bucket, with edge caching, which serves repeated content from locations near viewers.

491
MCQmedium

A healthcare company stores patient imaging studies in an Amazon S3 bucket. Compliance requires that every object be encrypted at rest with a key the company fully controls, including the ability to rotate and revoke the key independently of AWS. The security team must also be able to audit every use of the key. Which solution meets these requirements with the LEAST operational overhead?

A.Enable SSE-KMS with a customer managed key in AWS KMS and enable AWS CloudTrail data events for KMS.
B.Enable SSE-C and store the encryption key in AWS Secrets Manager, rotating it every 90 days with a Lambda function.
C.Enable SSE-S3 with the default aws/s3 key and enable S3 server access logging on the bucket.
D.Use client-side encryption with the AWS Encryption SDK and store the data key in an Amazon S3 bucket protected by a bucket policy.
AnswerA

SSE-KMS with a customer managed key gives the company full control over rotation and revocation, and KMS integrates with CloudTrail to log every cryptographic operation. This satisfies encryption at rest, key ownership, and auditability with minimal operational effort because S3 and KMS handle the cryptographic work automatically when objects are written and read.

Why this answer

A customer managed key in AWS KMS combined with SSE-KMS lets the organization control key rotation and revocation while CloudTrail records every use of the key for audit. S3 performs the encryption transparently, so no application changes are needed. This combination meets the encryption, control, and audit requirements with less operational effort than managing keys in the application or supplying keys on every request.

Exam trap

The trap here is assuming that any encryption option provides equivalent key control, when only customer managed KMS keys allow independent rotation, revocation, and auditable key usage.

492
MCQmedium

A solutions architect is designing an S3 bucket for a claims portal. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure? The design must avoid adding custom operational scripts.

A.Enable S3 Block Public Access at the account or bucket level
B.Create an IAM policy that denies s3:GetObject to anonymous users
C.Enable server access logging on the bucket
D.Enable S3 Transfer Acceleration
AnswerA

Block Public Access applies an account- or bucket-level guardrail that overrides bucket policies and ACLs, so any later policy granting public access is refused. This enforces the never-publicly-accessible constraint declaratively, requiring no custom operational scripts.

Why this answer

S3 Block Public Access provides a definitive override that prevents any public access to S3 objects, even if a bucket policy or ACL later grants public access. This setting can be applied at the account or bucket level and ensures that all access is denied to anonymous users, meeting the requirement without custom scripts.

Exam trap

The trap here is that candidates may think an IAM policy can block anonymous users, but IAM policies only apply to authenticated IAM principals, not to anonymous (unauthenticated) requests, making S3 Block Public Access the only effective solution.

How to eliminate wrong answers

Option B is wrong because an IAM policy that denies s3:GetObject to anonymous users is not effective; anonymous users are not IAM principals, so IAM policies do not apply to them. Option C is wrong because server access logging records requests but does not enforce access controls or prevent public access. Option D is wrong because S3 Transfer Acceleration speeds up uploads over long distances but has no effect on access permissions or public accessibility.

493
MCQmedium

A company is migrating a legacy application to AWS. The application uses a fixed set of credentials stored in a configuration file to access an Amazon RDS database. The security team wants to eliminate hardcoded credentials and automatically rotate them every 30 days. The application runs on Amazon EC2 instances and can be modified to retrieve credentials at startup. Which solution meets these requirements with the LEAST operational overhead?

A.Store the credentials in AWS Secrets Manager and configure automatic rotation every 30 days. Modify the application to retrieve the secret using the AWS SDK.
B.Store the credentials in an encrypted Amazon S3 object and use S3 Object Lambda to decrypt them at runtime. Configure a lifecycle policy to delete and recreate the object every 30 days.
C.Use AWS KMS to encrypt the credentials and store them in an EC2 instance's user data. Use an AWS Lambda function to rotate the credentials and update the user data every 30 days.
D.Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter and write a custom Lambda function to rotate them every 30 days.
AnswerA

AWS Secrets Manager natively supports automatic rotation for Amazon RDS databases by using a Lambda rotation function. It eliminates hardcoded credentials and integrates with IAM for access control. Modifying the application to retrieve the secret at startup is a one-time change, and rotation is managed by the service, minimizing operational overhead.

Why this answer

AWS Secrets Manager is designed for this use case: it stores and automatically rotates database credentials using a Lambda rotation function, with minimal setup. The application retrieves the secret via the AWS SDK, eliminating hardcoded credentials. Other options lack built-in rotation or require custom development, increasing operational overhead.

Exam trap

The trap here is assuming that Parameter Store provides automatic rotation; it does not, and you must implement it yourself.

494
MCQmedium

A risk simulation workload uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured?

A.CloudWatch Logs retention policies per log group
B.AWS Config aggregation
C.CloudWatch detailed monitoring on all instances
D.Route 53 health checks
AnswerA

CloudWatch Logs retention policies per log group directly address the cost constraint by automatically expiring debug logs after a defined period, such as seven days. Retention is set at the log-group level, so each workload's logs can be tuned independently, eliminating indefinite storage charges without altering application logging behaviour.

Why this answer

CloudWatch Logs retention policies allow you to set per-log-group expiration rules (e.g., 30 days, 90 days) to automatically delete old log events, directly reducing storage costs for debug logs that are no longer needed. This is the most cost-effective and targeted solution for managing log lifecycle without affecting other monitoring or configuration services.

Exam trap

The trap here is that candidates may confuse log retention with monitoring frequency or configuration management, mistakenly thinking that reducing metric collection (detailed monitoring) or using Config aggregation will lower log storage costs.

How to eliminate wrong answers

Option B is wrong because AWS Config aggregation is used to collect and centrally view configuration and compliance data from multiple accounts/regions, not to manage log retention or storage costs. Option C is wrong because CloudWatch detailed monitoring on all instances increases metric frequency (1-minute intervals) and incurs additional costs, doing nothing to control log retention or delete old debug logs. Option D is wrong because Route 53 health checks monitor endpoint availability and DNS routing, not log storage or retention policies.

495
MCQmedium

A warehouse integration service receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The architecture review board prefers a managed AWS-native control.

A.AWS WAF
B.Amazon Route 53 weighted routing
C.Amazon SQS queue
D.Amazon CloudFront
AnswerC

Amazon SQS is a fully managed message queue that decouples the order ingestion service from the backend workers. Producers send order messages to the queue, and consumers poll messages at their own sustainable rate, which naturally absorbs bursts—the queue itself acts as a temporary, durable buffer. The visibility timeout ensures in-flight messages are not processed by multiple workers, and a dead-letter queue captures poison messages after repeated failures. Because SQS retains messages for up to 14 days and integrates with Auto Scaling via the ApproximateNumberOfMessages metric, it is the correct service for handling unpredictable spikes in order volume.

Why this answer

Amazon SQS is the correct choice because it acts as a fully managed message queue that decouples the web tier from the fulfilment workers, buffering incoming order bursts. It provides at-least-once delivery and allows workers to poll messages at their own pace, ensuring no requests are lost even during spikes. SQS also supports retries via a dead-letter queue (DLQ) for messages that fail processing, meeting the requirement for resilient, managed AWS-native control.

Exam trap

The trap here is that candidates may confuse AWS WAF or CloudFront as tools for handling traffic spikes, but neither provides the decoupling, buffering, and retry capabilities of a queue; they are designed for security and content delivery, respectively, not for asynchronous processing.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that filters HTTP/S traffic based on rules (e.g., SQL injection, XSS) and does not provide message buffering, queuing, or retry logic for downstream services. Option B is wrong because Amazon Route 53 weighted routing distributes DNS traffic across multiple endpoints based on weights, but it does not absorb spikes or provide retry mechanisms; it only controls which endpoint receives a request, and a failed request is lost unless the client retries. Option D is wrong because Amazon CloudFront is a content delivery network (CDN) that caches static and dynamic content at edge locations to reduce latency, but it cannot buffer or retry requests for a downstream fulfilment service; it is designed for accelerating content delivery, not for decoupling or absorbing processing spikes.

496
Multi-Selecthard

A nightly video rendering pipeline runs on Linux EC2 instances and is compatible with ARM64. The jobs are CPU-bound, checkpoint frequently, and can resume if interrupted. The business wants the best throughput per dollar for the batch window. Which two changes should the team make? Select two.

Select 2 answers
A.Use AWS Graviton-based instances for the render workers.
B.Run the workers in an Auto Scaling group with Spot Instances for interruption-tolerant capacity.
C.Use a single large x86 instance with On-Demand pricing to avoid interruptions.
D.Replace the batch workers with a Lambda function to eliminate instance management.
E.Move the workload to a spread placement group to increase cost efficiency.
AnswersA, B

Graviton instances are ARM-based and often deliver better price-performance than comparable x86 instances for CPU-bound workloads. Because the application is already compatible with ARM64, the team can adopt Graviton without rewriting the pipeline. That improves throughput per dollar while keeping the same batch-processing model.

Why this answer

AWS Graviton-based instances use ARM64 architecture, which is explicitly compatible with the video rendering pipeline. They offer up to 40% better price-performance compared to comparable x86 instances for CPU-bound workloads, directly improving throughput per dollar. This makes option A correct for maximizing cost efficiency.

Exam trap

The trap here is that candidates may overlook the compatibility requirement with ARM64 and choose a single large x86 instance for simplicity, or mistakenly think Lambda can handle long-running CPU-bound tasks, missing the cost and throughput benefits of Graviton and Spot Instances.

497
MCQeasy

Company A must allow workloads in Company B to assume an IAM role in Company A (RoleInA). To mitigate confused-deputy attacks, a Security requirement is to use an External ID. Company A should restrict who can assume RoleInA. Which trust-policy configuration is the best choice?

A.In Company A role trust policy, allow sts:AssumeRole for principal "arn:aws:iam::<company-b-account-id>:root" with no sts:ExternalId condition.
B.In Company A role trust policy, allow sts:AssumeRole only for principal "arn:aws:iam::<company-b-account-id>:role/<specific-role-in-b>" and require a condition where sts:ExternalId equals the expected External ID value.
C.In the trust policy, allow iam:PassRole for the Company B principal and include an sts:ExternalId condition.
D.In Company A, grant Company B access using an IAM permissions policy attached to RoleInA instead of using a trust policy.
AnswerB

This is the correct approach because the trust policy limits the takeover to exactly the IAM role ARN in Company B, ensuring no other principal in that account can assume RoleInA. The mandatory sts:ExternalId condition ties the request to your specific business engagement and prevents a confused deputy attack; even if Company B is compromised or acting on behalf of another organization, the request must present the unique ExternalId that you generated and shared only with the intended partner. Low-privilege principal and an external condition together meet AWS's recommended pattern for cross-account third-party access.

Why this answer

It restricts the trust policy to a specific IAM role in Company B (using the principal ARN) and requires the `sts:ExternalId` condition to match a predefined value. This ensures only the intended role in Company B can assume RoleInA, and the External ID prevents a confused-deputy attack by requiring the third party to provide a unique identifier that only the legitimate service knows.

Exam trap

The trap here is that candidates often confuse `iam:PassRole` with `sts:AssumeRole` or think that a permissions policy can restrict who assumes a role, but only the trust policy defines the trusted principals and conditions for role assumption.

How to eliminate wrong answers

Option A is wrong because it allows the entire Company B account (root principal) to assume the role without any External ID condition, which violates the security requirement and leaves the role open to confused-deputy attacks. Option C is wrong because `iam:PassRole` is used to pass a role to an AWS service, not to assume a role; the correct action for assuming a role is `sts:AssumeRole`, and the condition should be on the trust policy, not on a permissions policy. Option D is wrong because an IAM permissions policy attached to RoleInA controls what the role can do after it is assumed, but it does not control who can assume the role; the trust policy is the only place to define the trusted principals and conditions for assuming the role.

498
MCQmedium

Based on the exhibit, which AWS service should the team use so the database password can rotate automatically every 30 days and the application can retrieve it securely at runtime?

A.AWS Systems Manager Parameter Store with a standard String parameter
B.AWS Secrets Manager
C.Amazon Cognito user pools
D.AWS Key Management Service customer managed keys
AnswerB

Secrets Manager is built for storing and rotating credentials such as database passwords. It supports secret versioning, fine-grained access control, and managed rotation workflows, making it the best fit for a 30-day automated rotation requirement. The application can retrieve the current secret at runtime without embedding the password in code or environment variables.

Why this answer

AWS Secrets Manager is the correct service because it natively supports automatic rotation of database passwords on a configurable schedule (e.g., every 30 days) and provides secure retrieval at runtime via the AWS SDK, CLI, or Secrets Manager API. Unlike Parameter Store, Secrets Manager is designed specifically for managing secrets with built-in rotation, encryption, and fine-grained access control.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store encrypted parameters) with Secrets Manager, but Parameter Store lacks native automatic rotation and is not optimized for managing database credentials with scheduled rotation.

Why the other options are wrong

A

AWS Systems Manager Parameter Store with a standard String parameter does not support automatic rotation of passwords; it only stores static values. Secrets Manager is required for managed rotation.

C

Amazon Cognito user pools are designed for user authentication and identity management, not for rotating or securely storing database passwords. They do not provide automated password rotation for database credentials.

D

AWS KMS is a key management service for encryption keys, not for rotating or storing database passwords. It does not provide automatic password rotation or secure retrieval of secrets at runtime.

When would these options actually be correct?

A

This option would be correct if the question asked for storing a static configuration value (e.g., a database endpoint) that does not require rotation, and the application retrieves it at runtime using the Parameter Store API.

C

When the question asks for a service to manage user sign-up, sign-in, and access control for a web or mobile application, such as integrating with social identity providers or providing temporary AWS credentials via identity pools.

D

A question asks: 'Which AWS service should be used to encrypt data at rest in an S3 bucket using a key that the company manages and can rotate annually?' In that case, AWS KMS customer managed keys would be correct.

Why candidates pick the wrong answer

A

Candidates may confuse Parameter Store with Secrets Manager because both can store secrets, but they overlook that Parameter Store lacks built-in rotation capabilities.

C

Candidates may confuse Cognito's ability to handle secrets (like user tokens) with database credential management, or think its 'user pool' feature can manage any type of password rotation.

D

Candidates may confuse KMS with Secrets Manager because both involve encryption and security, and KMS can be used to encrypt secrets stored elsewhere, but it does not manage the secrets themselves.

499
Multi-Selecthard

A company runs a web application on AWS and wants to reduce costs. The application uses an Application Load Balancer (ALB) to distribute traffic to Amazon EC2 instances in an Auto Scaling group. The company observes that the EC2 instances are underutilized during off-peak hours. They want to optimize costs without affecting performance during peak hours. Which two actions should they take? (Choose two.)

Select 2 answers
A.Enable Application Load Balancer access logs and analyze them to identify cost-saving opportunities.
B.Configure the Auto Scaling group to use a mixed instances policy with a percentage of On-Demand and Spot Instances.
C.Use Spot Instances for all EC2 instances in the Auto Scaling group.
D.Implement scheduled scaling for the Auto Scaling group to reduce capacity during off-peak hours.
E.Reduce the size of the ALB to a smaller load balancer type.
AnswersB, D

A mixed instances policy allows you to combine On-Demand and Spot Instances, providing cost savings from Spot while maintaining a baseline of On-Demand for reliability. This approach can reduce costs without sacrificing performance, as the Auto Scaling group can maintain a minimum On-Demand capacity and use Spot for additional scalable capacity. It is a best practice for cost optimization in Auto Scaling groups.

Why this answer

Scheduled scaling reduces capacity during predictable off-peak periods, directly cutting EC2 costs. A mixed instances policy with On-Demand and Spot balances cost savings with reliability, ensuring performance during peaks. Together, these actions optimize costs without impacting performance.

Other options either do not directly save costs, introduce risk, or are not feasible.

Exam trap

The trap here is assuming that using Spot Instances for all capacity is a straightforward cost-saving measure, but it can jeopardize availability for a web application that must maintain performance; a mixed policy is safer and still cost-effective.

500
MCQhard

A data engineering team runs an Amazon EMR cluster that processes large datasets stored in Amazon S3. The cluster uses Amazon EBS volumes for temporary storage, and jobs frequently spill intermediate data to disk. The team notices that shuffle operations are slow and wants to improve performance without changing the data format or increasing the number of core nodes. Which change should the team make?

A.Increase the size of the existing EBS volumes and enable EBS optimization on the core nodes.
B.Move the intermediate data to an Amazon S3 bucket and configure EMR to use S3 for shuffle storage.
C.Enable EMR managed scaling to automatically add task nodes during shuffle-heavy stages.
D.Replace the EBS volumes with instance store volumes and configure EMR to use them for shuffle and temporary data.
AnswerD

Instance store volumes provide locally attached NVMe or SSD storage with higher throughput and lower latency than EBS for temporary data. EMR can be configured to use instance store for shuffle and scratch space, which speeds up spill-heavy operations. This improves performance without adding core nodes or changing the data format, directly addressing the shuffle bottleneck.

Why this answer

Shuffle-heavy EMR workloads benefit from fast local storage, and instance store volumes provide higher IOPS and lower latency than EBS. Configuring EMR to use instance store for shuffle and temporary data reduces spill time and improves job performance without adding core nodes or altering data formats. Managed scaling, larger EBS volumes, and S3-backed shuffle either do not address the local disk bottleneck or introduce additional latency.

Exam trap

The trap here is assuming that adding more nodes or increasing EBS size will fix a shuffle bottleneck that is actually caused by local disk latency.

501
MCQmedium

A team stores application logs in an S3 bucket. They keep logs for 18 months for compliance. Access patterns: logs are heavily accessed during the first 30 days, rarely accessed between days 31 and 180, and almost never accessed after day 180. They currently store everything in S3 Standard and want to reduce storage cost without violating the 18-month retention requirement. What should they implement?

A.Leave logs in S3 Standard for 18 months and add a tag for internal reporting
B.Create an S3 lifecycle policy to transition logs to Standard-IA after 30 days and to Glacier Deep Archive after 180 days
C.Immediately move all logs to Glacier Instant Retrieval and expire after 18 months
D.Enable versioning and rely on object lifecycle expiration to reduce costs; do not change storage classes
AnswerB

This is correct because it matches storage cost to actual access frequency: logs are typically accessed heavily in the first 30 days, so S3 Standard is appropriate, after which Standard-IA reduces storage cost while still allowing rapid access. At 180 days, the logs are unlikely to be needed for active operations, so Glacier Deep Archive provides the lowest-cost storage while still satisfying the 18-month retention requirement. The lifecycle transitions honor S3's minimum storage duration constraints (30 days and 180 days), so no early-deletion fees are incurred.

Why this answer

An S3 lifecycle policy can automatically transition objects from S3 Standard to S3 Standard-IA after 30 days (matching the heavy-access period) and then to S3 Glacier Deep Archive after 180 days (matching the near-zero-access period). This minimizes storage costs while retaining logs for the required 18 months, as Glacier Deep Archive offers the lowest storage cost for long-term archival data.

Exam trap

The trap here is that candidates may choose Option C, mistakenly thinking Glacier Instant Retrieval is the cheapest archival class, but it is actually more expensive than Glacier Deep Archive for data that is almost never accessed, and the immediate transition ignores the cost savings from using Standard-IA during the first 30 days.

How to eliminate wrong answers

Option A is wrong because leaving logs in S3 Standard for 18 months incurs the highest storage cost, and adding a tag does not reduce cost or change the storage class. Option C is wrong because immediately moving all logs to S3 Glacier Instant Retrieval is more expensive than using Standard-IA for the first 30 days and does not align with the access pattern; also, Glacier Instant Retrieval is designed for data accessed quarterly, not for data that is almost never accessed after 180 days. Option D is wrong because enabling versioning increases storage costs by retaining multiple versions of objects, and object lifecycle expiration alone does not change storage classes to lower-cost tiers; it only deletes objects, which would violate the 18-month retention requirement if set to expire earlier.

502
MCQhard

Based on the exhibit, a web application runs on an Amazon EC2 Auto Scaling group behind an Application Load Balancer. During traffic surges, the average CPU utilization stays below 35%, but request latency increases sharply and the ALB access logs show far more requests per target than expected. Which change is the best way to improve scaling behavior?

A.Lower the CPU target tracking threshold so the Auto Scaling group launches more instances sooner.
B.Replace the Application Load Balancer with a Network Load Balancer to reduce request latency.
C.Configure target tracking scaling on ALB RequestCountPerTarget for the Auto Scaling group.
D.Increase the ALB idle timeout so requests can wait longer before timing out.
AnswerC

RequestCountPerTarget directly reflects how many requests each instance is serving, which matches the symptom in the exhibit. It scales the fleet based on actual per-target demand instead of CPU, so the group can add capacity before queueing and latency grow.

Why this answer

The issue is that request latency increases sharply and the ALB logs show far more requests per target than expected, indicating that the Auto Scaling group is not scaling based on the actual load per instance. By configuring target tracking scaling on ALB RequestCountPerTarget, the Auto Scaling group will launch new instances when the average number of requests per target exceeds a defined threshold, directly addressing the root cause of high request volume per instance. This approach ensures scaling is driven by the actual workload distribution rather than CPU utilization, which remains low due to the application being I/O-bound or network-bound.

Exam trap

The trap here is that candidates often assume CPU utilization is the universal scaling metric, but the question explicitly states CPU stays low while latency spikes, indicating the bottleneck is request throughput, not compute, making RequestCountPerTarget the correct metric to scale on.

How to eliminate wrong answers

Option A is wrong because lowering the CPU target tracking threshold would not help when CPU utilization is already below 35% and the bottleneck is request latency, not CPU; this could lead to unnecessary scaling and increased costs without solving the latency issue. Option B is wrong because replacing the Application Load Balancer with a Network Load Balancer would not reduce request latency caused by high request volume per target; NLB operates at Layer 4 and does not inspect HTTP requests, so it cannot provide request-level metrics like RequestCountPerTarget for scaling decisions. Option D is wrong because increasing the ALB idle timeout only extends how long the load balancer keeps connections open without activity, which does not address the root cause of high request volume per target or the sharp increase in latency; it may mask the problem by allowing requests to wait longer before timing out.

503
Multi-Selectmedium

A company is migrating its on-premises workloads to AWS and wants to optimize costs. Which three strategies should the company implement to achieve a cost-optimized architecture? (Choose three.)

Select 3 answers
.Use Reserved Instances or Savings Plans for predictable workloads to reduce costs compared to On-Demand pricing.
.Provision additional EC2 instances to handle peak load at all times, ensuring maximum performance.
.Implement auto scaling to match capacity with demand, avoiding over-provisioning and reducing waste.
.Use Spot Instances for fault-tolerant, flexible workloads to achieve significant cost savings.
.Store all data in Amazon S3 Standard storage class to avoid any data retrieval costs.
.Deploy all resources in a single Availability Zone to minimize data transfer costs.

Why this answer

Reserved Instances or Savings Plans provide significant discounts (up to 72%) over On-Demand pricing for predictable workloads by committing to a specific usage term (1 or 3 years). This directly reduces compute costs for steady-state applications, making it a core cost-optimization strategy.

Exam trap

The trap here is that candidates often confuse 'maximizing performance' with 'cost optimization' and select the option to provision extra instances for peak load, failing to recognize that auto scaling and right-sizing are the correct approaches to balance cost and performance.

504
MCQmedium

A SaaS company hosts a REST API on Amazon API Gateway with AWS Lambda proxy integration. The API serves tenants in North America and Europe. European users report high latency, but the Lambda function and its Amazon RDS database must remain in the us-east-1 Region for data residency and cost reasons. The team wants to reduce latency for European users without moving the backend. Which solution meets these requirements?

A.Enable API Gateway caching on the stage and set a TTL of 300 seconds.
B.Create an Amazon CloudFront distribution with the API Gateway Regional endpoint as the origin and enable caching for cacheable responses.
C.Increase the Lambda function's memory and provisioned concurrency to reduce execution time.
D.Create a second API Gateway Regional endpoint in eu-west-1 and use a Lambda authorizer to route requests.
AnswerB

CloudFront caches responses at edge locations close to European users and forwards cache misses to the API Gateway endpoint in us-east-1. For cacheable API responses, this cuts the transatlantic round trip and reduces load on the backend, while the Lambda function and database stay in us-east-1, satisfying data residency and cost constraints.

Why this answer

CloudFront places edge caches near European users and forwards only cache misses to the API Gateway endpoint in us-east-1. For cacheable API responses, this removes most transatlantic round trips while keeping the Lambda function and RDS database in the required Region. Regional endpoints, stage caching, and Lambda tuning all leave the request path crossing the Atlantic or fail to address the geographic latency.

Exam trap

The trap here is assuming that any caching layer reduces latency, when a cache located in the same Region as the backend still forces distant users to make the long round trip.

505
MCQmedium

A media processing workflow uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured?

A.Route 53 health checks
B.CloudWatch Logs retention policies per log group
C.CloudWatch detailed monitoring on all instances
D.AWS Config aggregation
AnswerB

CloudWatch Logs retention policies are applied per log group and define the exact number of days that log events are kept before they are automatically deleted. By default, logs are set to 'Never Expire,' so configuring a retention period, such as 30 or 90 days, directly reduces log storage costs and helps meet compliance guidelines. This is the correct approach because it specifically automates the deletion of older logs without any external processes.

Why this answer

CloudWatch Logs retention policies per log group allow you to set an expiration time (e.g., 30 days) after which log events are automatically deleted. This directly reduces storage costs by preventing debug logs from accumulating indefinitely, without affecting other monitoring or routing functions.

Exam trap

The trap here is that candidates may confuse cost optimization with monitoring frequency or compliance aggregation, but the question specifically targets log storage costs, which only retention policies directly address.

How to eliminate wrong answers

Option A is wrong because Route 53 health checks are used for DNS failover and endpoint monitoring, not for managing log retention or cost optimization. Option C is wrong because CloudWatch detailed monitoring increases metric frequency (1-minute intervals) and incurs additional costs, which does not address log retention or cost reduction. Option D is wrong because AWS Config aggregation centralizes configuration snapshots and compliance rules across accounts/regions, but it does not control log group retention or deletion.

506
MCQmedium

A company needs to replicate a DynamoDB table to three AWS regions so that users in each region can read and write to a local copy with the lowest possible latency. Changes must propagate to all regions within seconds. Which solution should a solutions architect implement?

A.Enable DynamoDB Streams and use Lambda functions to replicate changes to tables in the other two regions
B.Configure DynamoDB Global Tables with replica tables in each of the three regions
C.Create DynamoDB read replicas in each region and use the primary table for all writes
D.Use Amazon S3 cross-region replication to back up DynamoDB exports to each region
AnswerB

DynamoDB Global Tables is the correct solution because it provides fully managed, multi-region, multi-active replication with submeter-second propagation between the three chosen replica tables. With Global Tables, writes to any replica are accepted and automatically propagated to all others, and built-in conflict resolution using last-writer-wins resolves concurrent updates without any custom code or operational overhead. This gives you active-active reads and writes in all three regions, which exactly matches the requirement for low-latency multi-region access.

Why this answer

DynamoDB Global Tables provide multi-region, multi-active (multi-master) replication. Each region maintains a full replica of the table, and applications can read and write to any region with local latency. Changes propagate to all other regions typically within one second.

DynamoDB Streams + Lambda is the underlying mechanism that Global Tables uses internally, but building a custom replication pipeline adds significant operational complexity. Global Tables is the managed, purpose-built solution requiring no custom code.

Exam trap

DynamoDB Streams captures item-level changes and can be processed by Lambda to replicate to other regions — this is a valid DIY approach. But when the question asks for multi-region multi-active replication with minimal complexity, Global Tables is the correct answer. Streams is the mechanism; Global Tables is the managed service.

Always choose the managed service over DIY for SAA-C03.

Why the other options are wrong

A

Custom DynamoDB Streams + Lambda replication works but requires significant development: Lambda functions per region, error handling, idempotency logic, and conflict resolution. Always choose the managed service (Global Tables) over custom Lambda pipelines.

C

DynamoDB does not have 'read replicas' like RDS. Global Tables creates full replica tables that support both reads and writes in each region. There is no read-only replica concept in DynamoDB.

D

S3 cross-region replication copies S3 objects between buckets. DynamoDB-to-S3 export is a data archival mechanism, not real-time database replication. Neither provides active database access with sub-second propagation.

507
MCQhard

Based on the exhibit, an Amazon Aurora MySQL application is read-heavy, but the database writer is nearing CPU limits while the reader instance is mostly idle. The application currently sends all queries to the writer endpoint. Which change should you make first to increase read throughput?

A.Keep using the writer endpoint so Aurora can route the reads automatically.
B.Change the application to send read-only queries to the Aurora reader endpoint.
C.Convert the cluster to a single-AZ deployment so network hops are reduced.
D.Add an Amazon DynamoDB Accelerator (DAX) cluster in front of Aurora.
AnswerB

The reader endpoint is a load-balancing DNS name that distributes each new connection across all available Aurora Replicas in the cluster. By explicitly routing read-only queries to this endpoint, the application offloads its SELECT-heavy workload from the primary to the idle replica, directly reducing CPU strain on the writer and increasing the cluster's aggregate read capacity. This is the intended scaling pattern for Aurora MySQL and resolves the described bottleneck.

Why this answer

The Aurora reader endpoint is specifically designed to distribute read-only traffic across all available reader instances, offloading the writer and increasing read throughput. Since the reader instance is idle, directing read queries to the reader endpoint immediately reduces CPU load on the writer without requiring any architectural changes.

Exam trap

The trap here is that candidates assume the writer endpoint automatically load-balances reads across all instances, but in Aurora the writer endpoint always points to the primary instance, and only the reader endpoint distributes read traffic.

How to eliminate wrong answers

Option A is wrong because the writer endpoint always routes queries to the writer instance, which is already near CPU limits; Aurora does not automatically redirect read queries to reader instances when using the writer endpoint. Option C is wrong because converting to a single-AZ deployment removes the reader instance entirely, eliminating the ability to offload reads and reducing availability, not increasing read throughput. Option D is wrong because adding a DAX cluster in front of Aurora introduces a caching layer for DynamoDB, not Aurora MySQL, and does not address the immediate need to offload read traffic from the writer instance.

508
MCQhard

A patient portal must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The design must avoid adding custom operational scripts.

A.Use an in-memory queue on one EC2 instance
B.Use UDP messages sent directly to workers
C.Use Amazon SQS standard queue and design consumers to be idempotent
D.Use CloudFront signed URLs
AnswerC

Using an Amazon SQS standard queue meets the at-least-once requirement: SQS stores messages durably across multiple Availability Zones and redelivers any message that is not deleted before the visibility timeout expires, so every event is processed at least once. Because standard queues can occasionally deliver duplicate copies, your consumer design must be idempotent—e.g., by tracking a unique event ID or a deterministic processing key—so that repeated handling of the same event does not corrupt patient data. This combination gives you high throughput, operational simplicity, and no single point of failure, which is why it is the correct choice.

Why this answer

Amazon SQS standard queues guarantee at-least-once delivery, which satisfies the requirement that every event is processed at least once. The design avoids custom operational scripts by leveraging a fully managed service, and the acceptance of duplicate processing is handled by making consumers idempotent. This combination provides a scalable, resilient, and cost-effective event-driven architecture without the need for custom infrastructure management.

Exam trap

The trap here is that candidates may confuse 'at-least-once' delivery with 'exactly-once' delivery and incorrectly choose a solution like a FIFO queue or a custom retry mechanism, but the question explicitly allows duplicate processing, making the standard queue the correct choice.

How to eliminate wrong answers

Option A is wrong because an in-memory queue on a single EC2 instance creates a single point of failure, lacks durability, and requires custom operational scripts for management and recovery, violating the 'avoid adding custom operational scripts' constraint. Option B is wrong because UDP is a connectionless, unreliable protocol that does not guarantee message delivery, so it cannot ensure at-least-once processing; it also requires custom application-level handling for reliability. Option D is wrong because CloudFront signed URLs are used for securing content delivery and controlling access to files, not for event processing or message queuing; they do not provide any event delivery guarantee or queue semantics.

509
MCQmedium

A logistics company runs an Amazon RDS for MySQL database that supports a parcel-tracking API. During the morning peak, read queries for tracking history saturate the primary instance's CPU, slowing writes. The reads can tolerate a few seconds of staleness, and the team wants to offload them without changing the database engine. Which action should the team take?

A.Enable Multi-AZ on the DB instance and point the read queries at the standby instance.
B.Create one or more read replicas and update the application to send tracking-history queries to the replica endpoint.
C.Increase the size of the RDS DB instance and enable storage autoscaling on the primary.
D.Migrate the database to Amazon DynamoDB with a global secondary index on the tracking ID.
AnswerB

RDS read replicas are separate DB instances that receive asynchronous replication from the primary and can serve read traffic. Directing the tracking-history queries to the replica endpoint removes that load from the primary, freeing CPU for writes. The asynchronous replication lag is typically seconds, which the workload tolerates, and no engine change is required.

Why this answer

A read replica is a dedicated copy of the primary that serves read-only queries, so routing the tracking-history requests to it removes that CPU pressure from the primary instance while writes continue unimpeded. Replication is asynchronous, producing lag on the order of seconds, which matches the workload's tolerance for slightly stale reads. This keeps the MySQL engine and requires only an endpoint change in the application.

Exam trap

The trap here is assuming the Multi-AZ standby can serve reads, when it is a passive failover target and is not accessible for query traffic.

510
MCQmedium

A company runs an application on EC2 instances in private subnets. The instances must access Amazon S3, and the team currently routes all outbound traffic to the internet through a NAT Gateway. Monthly NAT Gateway charges increased significantly, even though the application only needs to call S3 (not access other public internet services). Which change will most directly reduce NAT Gateway charges while keeping S3 access working?

A.Create a gateway VPC endpoint for S3 and update the private route tables so S3 traffic uses the endpoint instead of the NAT Gateway.
B.Enable S3 Transfer Acceleration on the bucket to reduce the number of S3 calls that go through the NAT Gateway.
C.Switch the EC2 instances to public subnets so S3 calls can use direct internet routing without NAT.
D.Increase the NAT Gateway TCP idle timeout so fewer connections are billed separately for S3 traffic.
AnswerA

A gateway VPC endpoint for S3 keeps S3 traffic within the AWS network. After you add the S3 gateway endpoint and update the private subnet route tables for the S3 prefix list to target the endpoint, S3 API calls from the private subnets no longer traverse the NAT Gateway. This directly reduces both NAT Gateway per-hour charges and NAT data-processing charges associated with S3 traffic. If the application truly only needs S3, you can remove the NAT route for those S3 destinations and rely on the endpoint for S3 connectivity.

Why this answer

A gateway VPC endpoint for S3 allows instances in private subnets to access S3 over the AWS network without traversing the internet. By updating the private route tables to direct S3 traffic to the endpoint, the NAT Gateway is bypassed, eliminating the per-GB data processing charges and hourly NAT Gateway fees for that traffic. This directly reduces costs while maintaining secure, private access to S3.

Exam trap

The trap here is that candidates may think S3 Transfer Acceleration or increasing NAT Gateway timeouts will reduce costs, but they fail to recognize that a gateway VPC endpoint eliminates the NAT Gateway entirely for S3 traffic, directly addressing the cost issue without compromising security.

How to eliminate wrong answers

Option B is wrong because S3 Transfer Acceleration speeds up uploads over long distances using AWS edge locations, but it does not reduce the amount of traffic going through the NAT Gateway; it actually adds additional costs per GB transferred and still requires internet routing. Option C is wrong because moving EC2 instances to public subnets exposes them directly to the internet, violating the requirement for private subnets and introducing security risks; it also does not reduce NAT Gateway charges since the NAT Gateway is no longer used, but the question asks for a change that reduces NAT Gateway charges while keeping S3 access working, not for a security redesign. Option D is wrong because increasing the TCP idle timeout does not reduce NAT Gateway charges; it may actually increase costs by keeping connections open longer, and NAT Gateway billing is based on data processing and hourly usage, not per-connection billing.

511
MCQeasy

A team needs to distribute TCP traffic (not HTTP) across multiple services. The services must see the original client source IP for auditing. Which AWS load balancer is the best fit?

A.Application Load Balancer (ALB) using HTTP/HTTPS listeners with host-based routing
B.Network Load Balancer (NLB) using TCP listeners
C.Classic Load Balancer (CLB) configured for TCP health checks only
D.API Gateway with a VPC Link to forward raw TCP traffic
AnswerB

NLB is a Layer 4 load balancer that supports TCP and UDP. When the traffic is routed to targets (for example, instance or IP targets), the backend connection maintains the original source IP/port at the networking layer, which supports IP-based auditing without requiring HTTP headers.

Why this answer

A Network Load Balancer (NLB) is the best fit because it operates at Layer 4 (TCP/UDP) and preserves the original client source IP address by default, which is required for auditing. It can distribute raw TCP traffic across multiple services without inspecting application-layer headers, making it ideal for non-HTTP TCP workloads.

Exam trap

The trap here is that candidates often assume an Application Load Balancer can handle any TCP traffic because of its 'listener' terminology, but ALB strictly requires HTTP/HTTPS protocols and cannot forward raw TCP streams.

Why the other options are wrong

A

ALB only supports HTTP/HTTPS listeners, not raw TCP traffic. It cannot distribute non-HTTP TCP traffic as required.

C

Classic Load Balancer (CLB) does not preserve the original client source IP for TCP traffic; it uses its own IP as the source. The question requires preserving the client IP for auditing, which CLB cannot do.

D

API Gateway does not support raw TCP traffic; it is designed for HTTP/HTTPS and WebSocket APIs. It cannot forward arbitrary TCP streams to backend services.

When would these options actually be correct?

A

When distributing HTTP/HTTPS traffic and needing advanced routing (e.g., host-based or path-based routing) with original client IP preserved via X-Forwarded-For headers.

C

A scenario where the requirement is to distribute TCP traffic across multiple EC2 instances using basic round-robin routing, and preserving the client IP is not needed. For example, a legacy application that only needs simple load balancing without advanced features like SNI or source IP preservation.

D

A team needs to expose RESTful or WebSocket APIs to external clients while keeping backend services in a private VPC. API Gateway with a VPC Link would securely forward HTTP/HTTPS requests to internal ALBs or NLBs.

Why candidates pick the wrong answer

A

Candidates may assume ALB supports all TCP traffic because it is a common load balancer, or they overlook the requirement for non-HTTP TCP traffic.

C

Candidates may think CLB is sufficient for TCP traffic because it supports TCP listeners and health checks, and they might overlook the specific requirement for preserving the original client source IP.

D

Candidates may think API Gateway can handle any protocol via VPC Link, but VPC Link only works with HTTP/HTTPS APIs, not raw TCP.

512
MCQmedium

A web application for a healthcare document service is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy? The design must avoid adding custom operational scripts.

A.Security groups on the application instances
B.AWS WAF associated with the Application Load Balancer
C.Network ACLs on the public subnets
D.AWS Shield Advanced only
AnswerB

AWS WAF attached to the Application Load Balancer inspects incoming HTTP requests and blocks SQL injection and cross-site scripting using managed rule groups, satisfying the minimum-operational-overhead constraint without custom scripts. Rules are evaluated at the load balancer before traffic reaches the application, providing managed protection with no code changes.

Why this answer

AWS WAF is a web application firewall that integrates directly with an Application Load Balancer to filter and monitor HTTP/HTTPS requests. It provides managed rules specifically designed to block common attack patterns like SQL injection and cross-site scripting (XSS) without requiring custom scripts or manual rule maintenance, thus meeting the requirement for minimum operational overhead.

Exam trap

The trap here is that candidates often confuse network-layer security controls (security groups, network ACLs, or Shield) with application-layer protection, assuming they can block SQL injection or XSS, when in fact only a web application firewall like AWS WAF can inspect and filter HTTP payloads for such attacks.

How to eliminate wrong answers

Option A is wrong because security groups act as a stateful virtual firewall at the instance level, filtering traffic based on IP addresses, ports, and protocols; they cannot inspect application-layer payloads to detect SQL injection or XSS patterns. Option C is wrong because network ACLs are stateless and operate at the subnet level, only filtering traffic based on IP, port, and protocol rules, with no capability to parse HTTP request bodies or headers for malicious content. Option D is wrong because AWS Shield Advanced provides DDoS protection at the network and transport layers, not application-layer attack mitigation for SQL injection or XSS; it does not include a web application firewall.

513
MCQhard

A security team must ensure that all data written to a new Amazon S3 bucket is encrypted with a specific customer-managed AWS KMS key, and that any PUT request that does not specify that key is rejected. The team also needs to detect and react if someone attempts to change the bucket policy to remove the restriction. Which combination of actions meets these requirements with the LEAST operational effort?

A.Configure an S3 Lifecycle rule to re-encrypt objects with the required KMS key and use AWS Config with the s3-bucket-server-side-encryption-enabled managed rule.
B.Use an S3 access point with a custom policy that allows only the required key, and enable AWS Shield Advanced on the bucket.
C.Attach a bucket policy that denies s3:PutObject when the request lacks the required KMS key condition, enable AWS CloudTrail data events, and create an Amazon EventBridge rule that matches PutBucketPolicy API calls and invokes an AWS Lambda function.
D.Enable default bucket encryption with the required KMS key and turn on S3 Block Public Access at the account level.
AnswerC

A bucket policy with a Deny on s3:PutObject using the s3:x-amz-server-side-encryption-aws-kms-key-id condition blocks unapproved encryption at the API layer. CloudTrail data events and an EventBridge rule on the PutBucketPolicy management event provide near-real-time detection and an automated response, requiring no servers to maintain.

Why this answer

A bucket policy with a Deny effect and the KMS key condition rejects any PUT that does not use the required key, which is the only option that enforces encryption at write time. Pairing CloudTrail data events with an EventBridge rule on the PutBucketPolicy API call provides automated detection and response to policy tampering without managing infrastructure.

Exam trap

The trap here is treating S3 default encryption as an enforcement mechanism, when it only supplies a key for requests that omit encryption headers.

514
Multi-Selecthard

A payments API requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The design must avoid adding custom operational scripts.

Select 2 answers
A.Deletion protection or tightly controlled delete permissions
B.Point-in-time recovery
C.Global secondary indexes
D.DAX
AnswersA, B

Deletion protection is a DynamoDB table attribute that blocks DeleteTable operations until explicitly disabled, while tightly scoped IAM policies that deny dynamodb:DeleteTable reduce the risk of a single misissued CLI command or console action taking down a payments table. Without this guard, an accidental deletion is immediate and permanent, taking all data, indexes, and backup history with it. It is therefore a required complement to backup features.

Why this answer

Deletion protection (option A) prevents accidental deletion of the DynamoDB table itself, which is critical for the accidental-delete protection requirement. Point-in-time recovery (option B) enables restoring the table to any point within the last 35 days, satisfying the point-in-time recovery requirement. Both features are native DynamoDB capabilities that require no custom scripts.

Exam trap

The trap here is that candidates may confuse deletion protection (which protects the table resource) with item-level delete prevention, or think that GSIs or DAX provide data durability or recovery features when they do not.

515
MCQeasy

A trading analytics system deploys multiple EC2 instances that exchange very frequent, low-latency, east-west messages. The application team wants the instances to be placed to minimize network latency and variability. Which AWS feature should they use?

A.EC2 Placement Groups with the "cluster" strategy
B.EC2 Placement Groups with the "spread" strategy
C.Auto Scaling cooldown adjustments only
D.Switching the instances to a larger instance size without any placement group
AnswerA

A cluster placement group launches a group of instances into a single Availability Zone using the same underlying infrastructure segments, which lets them communicate over a low-latency, high-bandwidth, non-blocking network path. For a trading analytics workload that needs consistent inter-instance latency and minimal jitter, this placement strategy provides the closest possible physical proximity and dedicated interconnect performance. Because all instances share the same logical and physical network segment, packet round-trip times become both shorter and more predictable.

Why this answer

The cluster placement group is the correct choice because it places instances into a low-latency, high-bandwidth group within a single Availability Zone, which minimizes network latency and variability for east-west traffic. This strategy is specifically designed for applications that require very frequent, low-latency communication between instances, such as trading analytics systems.

Exam trap

The trap here is that candidates confuse the 'spread' placement group's high availability benefit with low-latency requirements, not realizing that spreading instances across racks increases network hops and latency.

How to eliminate wrong answers

Option B is wrong because the spread placement group distributes instances across distinct hardware racks to reduce correlated failures, which increases network latency and variability rather than minimizing it. Option C is wrong because Auto Scaling cooldown adjustments only control the rate of scaling activities and have no impact on network latency or placement of instances. Option D is wrong because switching to a larger instance size may improve compute or memory capacity but does not inherently reduce network latency or variability between instances without a placement group.

516
MCQhard

A healthcare document service must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

A.Use an SCP that denies ec2:CreateVolume when the encrypted condition is false
B.Tag encrypted volumes after creation
C.Enable VPC Flow Logs
D.Run a daily Lambda function to encrypt unencrypted volumes
AnswerA

This SCP is a preventive guardrail at the AWS Organizations level. By applying a Deny statement for ec2:CreateVolume with a StringEquals condition on ec2:Encrypted set to false, the policy blocks any attempt to provision an unencrypted EBS volume in every account in the organization. Because SCPs act as a permission boundary above IAM, even an administrator with full IAM permissions cannot create a noncompliant volume.

Why this answer

An SCP (Service Control Policy) is a preventive control that can deny the ec2:CreateVolume action when the encryption condition (ec2:Encrypted) is false. This ensures that no unencrypted EBS volumes can be created in the account, providing a strong, proactive guardrail that cannot be overridden by IAM policies within the account.

Exam trap

The trap here is that candidates often confuse detective or corrective controls (like Lambda remediation or tagging) with preventive controls, failing to recognize that only SCPs or IAM policies with Deny effects can block the action before it occurs.

How to eliminate wrong answers

Option B is wrong because tagging encrypted volumes after creation is a detective or corrective control, not a preventive one; it does not stop the creation of unencrypted volumes. Option C is wrong because VPC Flow Logs capture network traffic metadata and have no ability to enforce encryption policies on EBS volumes. Option D is wrong because running a daily Lambda function to encrypt unencrypted volumes is a reactive/corrective control that only fixes volumes after they have been created, leaving a window of non-compliance.

517
MCQmedium

A company hosts an internal API behind an Application Load Balancer (ALB) in two AWS Regions. They want Amazon Route 53 to automatically fail over to the secondary Region when the primary Region’s ALB is unhealthy. Health checks for the primary ALB are already configured, but the DNS record currently uses a latency-based routing policy. Which Route 53 configuration most directly provides automatic failover based on health status?

A.Keep latency-based routing, and set the weights so the secondary Region rarely receives traffic unless manual changes are made.
B.Use a Route 53 failover routing policy: configure two alias records for the ALBs where the primary record is marked PRIMARY, the secondary is marked SECONDARY, and each record has an associated health check.
C.Use an alias A record that returns both ALBs simultaneously so clients automatically load balance across Regions during outages.
D.Use geolocation routing to route users to the primary Region and rely on ALB health checks to shift requests between Regions.
AnswerB

Route 53 failover routing is designed specifically for active-passive failover: you create two alias records pointing to the two ALBs, one marked PRIMARY and the other SECONDARY, each with an associated health check. Under normal conditions, Route 53 returns the PRIMARY record, but if that record's health check fails, Route 53 automatically stops returning it and returns the SECONDARY record instead. This gives the company an automated, DNS-level failover that does not depend on client latency, manual weight changes, or client-side load balancing.

Why this answer

Route 53 failover routing policy is specifically designed to automatically route traffic away from an unhealthy resource to a healthy one. By creating two alias records (one PRIMARY with an associated health check for the primary ALB, and one SECONDARY for the secondary ALB), Route 53 will automatically fail over to the secondary record when the primary health check fails. This directly meets the requirement for automatic failover based on health status, unlike latency-based routing which only optimizes for response time.

Exam trap

The trap here is that candidates often confuse latency-based routing with failover routing, assuming latency-based routing inherently provides health-based failover, but it only optimizes for latency and does not automatically reroute based on health status.

How to eliminate wrong answers

Option A is wrong because latency-based routing does not support automatic failover based on health status; weights only control traffic distribution and manual changes would be required to shift traffic, which contradicts the 'automatic failover' requirement. Option C is wrong because an alias A record cannot return multiple ALBs simultaneously; Route 53 alias records point to a single AWS resource, and returning multiple IPs would require a non-alias record with multiple values, which still does not provide health-based failover. Option D is wrong because geolocation routing routes based on user location, not health; ALB health checks alone cannot shift requests between Regions because the DNS record itself does not change based on health status without a failover routing policy.

518
Multi-Selectmedium

A central security account stores encrypted log files in S3 using a customer managed AWS KMS key. A partner account already has S3 bucket access through an assumed role and now must also be able to encrypt and decrypt objects that use the same KMS key. Which two actions are required? Select two.

Select 2 answers
A.Update the KMS key policy to allow the partner role or account to use the key.
B.Enable automatic key rotation to solve the cross-account access requirement.
C.Attach IAM permissions in the partner account for kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey on the CMK.
D.Replace the CMK with the AWS managed key alias/aws/s3.
E.Export the KMS key material and share it with the partner account.
AnswersA, C

A customer managed KMS key's access is governed by its key policy, which must explicitly grant the partner account or role permission to use the key. Without this cross-account grant, the partner's IAM policy alone cannot authorise any cryptographic operation on the CMK.

Why this answer

Option A is correct because a customer managed KMS key's key policy must explicitly grant the partner account or its role permission to use the key; cross-account KMS access is never granted by S3 bucket policies alone, and the key policy is the primary resource-based control that authorizes kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey for the external principal. Option C is correct because the partner account's identity-based IAM policy must also allow the KMS actions (kms:Encrypt, kms:Decrypt, kms:GenerateDataKey) on the CMK's ARN; for cross-account access both the key policy and the caller's IAM policy must permit the operation, so the partner role needs these permissions in addition to the key policy grant. Option B is wrong because automatic key rotation only rotates the backing key material on a schedule and has nothing to do with granting cross-account access.

Option D is wrong because replacing the CMK with the AWS managed key alias/aws/s3 removes customer control and cannot be used for cross-account access since its key policy cannot be modified. Option E is wrong because KMS key material for customer managed keys is non-exportable by default and exporting/sharing key material is not the mechanism for cross-account KMS authorization.

Exam trap

The trap here is that candidates often forget that cross-account KMS access requires both a key policy update in the central account AND IAM permissions in the partner account, not just one of them.

519
MCQmedium

An S3 bucket in account A uses default server-side encryption with an AWS KMS customer-managed key (CMK) in account A. A team created an IAM role in account B that is allowed by IAM policy to perform s3:GetObject on the bucket. When the account B role tries to read objects, it fails with: AccessDeniedException: 'User is not authorized to perform kms:Decrypt'. Which change is most likely to fix the issue?

A.Add kms:Decrypt permissions to the identity policy in account B only, without modifying the CMK key policy in account A.
B.Update the CMK key policy in account A to allow the account B role principal to call kms:Decrypt (and kms:DescribeKey if needed).
C.Disable SSE-KMS on the S3 bucket so objects use SSE-S3 instead, eliminating the need for KMS permissions.
D.Attach a broad permissions boundary to the account B role allowing all kms:* actions to override the key policy.
AnswerB

Updating the CMK key policy in Account A is the correct approach because KMS key policies are the authoritative resource-based policies that govern access to the key, especially for cross-account scenarios. By explicitly adding the Account B role's ARN as a `Principal` and granting `kms:Decrypt` (and `kms:DescribeKey` for context) within the key policy, Account A explicitly authorizes the external principal to use its CMK, satisfying the two-layer authorization model.

Why this answer

When an S3 bucket uses SSE-KMS with a customer-managed key (CMK) in account A, the account B role must have explicit kms:Decrypt permission on that CMK. The key policy in account A controls access to the CMK, so adding the account B role principal to the key policy with kms:Decrypt (and kms:DescribeKey if needed) is required. Without this, even if the S3 bucket policy and IAM role allow s3:GetObject, the KMS decrypt call will fail.

Exam trap

The trap here is that candidates assume IAM permissions in account B are sufficient for cross-account KMS operations, forgetting that the KMS key policy in the owning account must explicitly grant access to the external principal.

How to eliminate wrong answers

Option A is wrong because adding kms:Decrypt to the identity policy in account B alone is insufficient; the CMK key policy in account A must also grant access to the account B role, as KMS key policies act as a separate authorization layer. Option C is wrong because disabling SSE-KMS and switching to SSE-S3 would change the encryption method and potentially violate security requirements, but it would technically fix the KMS permission issue; however, it is not the most likely fix as it alters the encryption configuration rather than addressing the permission gap. Option D is wrong because a permissions boundary on the account B role cannot override the CMK key policy in account A; the key policy is the ultimate authority for KMS key access, and a boundary only limits the role's maximum permissions within its own account.

520
MCQmedium

A media company hosts a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from individual IP addresses to mitigate scraping. Which AWS service should a solutions architect associate with the load balancer to meet both requirements?

A.AWS WAF with a web ACL attached to the Application Load Balancer, using managed rule groups for SQL injection and XSS plus a rate-based rule.
B.AWS Shield Advanced with automatic application layer DDoS mitigation enabled on the load balancer.
C.Amazon GuardDuty with the S3 protection and EKS protection features enabled for the account.
D.AWS Network Firewall deployed in a subnet and referenced by the load balancer's target group.
AnswerA

AWS WAF integrates directly with Application Load Balancers and supports managed rule groups that detect SQL injection and cross-site scripting patterns, along with rate-based rules that count requests per originating IP over a rolling window. Attaching a web ACL to the ALB inspects incoming HTTP requests before they reach the instances, satisfying both the exploit filtering and rate-limiting requirements in a single service.

Why this answer

AWS WAF is the service designed to filter HTTP requests at the application layer and integrates natively with Application Load Balancers. Managed rule groups cover SQL injection and cross-site scripting signatures, and rate-based rules track request counts per originating IP. Attaching a web ACL to the ALB inspects traffic before it reaches the EC2 instances, meeting both protection goals with one service.

Exam trap

The trap here is confusing DDoS mitigation with application-layer exploit filtering, since Shield Advanced and WAF are often mentioned together but only WAF inspects HTTP payloads and enforces rate-based rules.

521
MCQmedium

A media company streams live video from on-premises encoders to viewers across North America. The encoders push a single RTMP feed to AWS, and the company wants the lowest possible glass-to-glass latency for viewers while distributing to thousands of concurrent viewers. The team does not want to manage any streaming servers. Which solution BEST meets these requirements?

A.Use AWS Elemental MediaConvert to ingest the live RTMP feed and deliver it through an Amazon API Gateway WebSocket API.
B.Use AWS Elemental MediaLive to ingest the RTMP feed and MediaPackage to package it, then deliver to viewers with Amazon CloudFront.
C.Store the RTMP feed in an Amazon S3 bucket and have viewers stream directly from S3 using presigned URLs.
D.Run FFmpeg on a large Amazon EC2 instance to transcode the feed and serve it to viewers through an Application Load Balancer.
AnswerB

MediaLive performs the real-time encoding/transcoding of the live input, MediaPackage origins the just-in-time HLS/DASH packaging, and CloudFront caches at edge locations for massive concurrent scale. This is fully managed with no streaming servers to operate, and the combination delivers low latency to a geographically dispersed audience.

Why this answer

A fully managed live workflow needs a live ingest/transcode stage, a packaging origin, and a global delivery layer. MediaLive handles the live input and encoding, MediaPackage produces just-in-time streaming formats, and CloudFront scales the last mile to many viewers. Together they deliver low latency without any streaming servers to operate or patch.

Exam trap

The trap here is assuming that a file-based transcoding service or object storage can accept and distribute a continuous live RTMP feed.

522
Multi-Selectmedium

A web application uses an Amazon Aurora DB cluster for a read-heavy workload. The team wants to increase read throughput without changing the database schema or rewriting application data access patterns. Which two changes should they make? Select two.

Select 2 answers
A.Add Aurora Replicas to scale out read traffic across multiple database instances.
B.Send read queries to the Aurora reader endpoint so they are distributed across the replicas.
C.Point all queries to the writer endpoint so Aurora can balance reads and writes internally.
D.Enable Multi-AZ standby for the cluster to increase the number of read-only connections.
E.Move the database to a single larger instance class instead of adding replicas.
AnswersA, B

Aurora Replicas are independent database instances in the same Aurora cluster that share the underlying storage volume, allowing them to serve read traffic without replicating data changes at the instance level. You can add up to 15 replicas, which adds CPU, memory, and connection capacity for concurrent SELECT queries, effectively scaling out the database layer horizontally. Because the storage is shared, replicas also offer near-zero replication lag, making them suitable for read-heavy workloads that need fresh data.

Why this answer

Adding Aurora Replicas (Option A) directly increases read throughput by distributing read-only queries across multiple database instances, which is ideal for a read-heavy workload. Sending read queries to the Aurora reader endpoint (Option B) ensures that these queries are load-balanced across all available replicas, offloading the writer instance and improving overall performance without requiring schema or application changes.

Exam trap

The trap here is that candidates confuse Multi-AZ standby (which provides high availability but not read scaling) with Aurora Replicas (which provide both read scaling and high availability), leading them to select Option D incorrectly.

523
MCQhard

A company uses AWS Organizations and wants to prevent any account in the organization from launching resources in regions other than us-east-1 and eu-west-1. This restriction must apply even if an administrator in a member account grants full IAM permissions. Which approach should a solutions architect use?

A.Create IAM policies with Deny for disallowed regions and attach them to all IAM users and roles in each account
B.Enable AWS Config rules to detect resources launched in disallowed regions and trigger auto-remediation to delete them
C.Use AWS Control Tower guardrails to enforce region restriction for all accounts
D.Create an SCP with a Deny on all actions for regions outside us-east-1 and eu-west-1, attached to the Organization root
AnswerD

SCPs apply to all principals in all member accounts and cannot be overridden by account-level IAM. Attached to the Organization root, this SCP covers every member account. The Deny with StringNotEquals condition on aws:RequestedRegion blocks all other regions.

Why this answer

Service Control Policies (SCPs) in AWS Organizations provide a guardrail that applies to all principals in member accounts — including IAM users, roles, and even the account root. SCPs restrict the maximum permissions that can be granted within an account.

An SCP with Deny on all actions for all regions except us-east-1 and eu-west-1, attached to the organization root, prevents any account from launching resources in other regions regardless of account-level IAM permissions. IAM policies in member accounts cannot override SCPs.

Exam trap

A common misconception is that an IAM Administrator or root user in a member account can override organization-level controls. SCPs define the permission ceiling — even AdministratorAccess (Action: *, Resource: *) cannot exceed what the SCP allows. SCPs are evaluated BEFORE account-level IAM policies.

Why the other options are wrong

A

IAM policies must be attached individually to each user and role in each account — unscalable across an Organization. Administrators in member accounts could also remove or bypass these policies by creating new roles without the restriction.

B

AWS Config rules detect non-compliant resources after they have been created. Auto-remediation adds latency. This is a detective control, not a preventive control — resources would exist temporarily before deletion.

C

AWS Control Tower uses SCPs under the hood for guardrails. However, the underlying mechanism is an SCP applied via Organizations. The direct answer for organizational prevention is an SCP.

524
MCQmedium

An orders service publishes payment instructions to an Amazon SQS Standard queue. A downstream consumer sometimes times out and retries the work, causing the consumer to process the same instruction more than once. Operationally, the team must ensure that duplicate processing does not create duplicate charges. The queue type cannot be changed. What is the most resilient application-side approach?

A.Rely on SQS Standard to provide exactly-once delivery for each message, since the consumer uses retries.
B.Implement idempotent processing using a persistent deduplication key (for example, paymentInstructionId) so repeated messages are ignored or safely merged.
C.Increase the queue’s visibility timeout to 24 hours so messages never reappear even if the consumer times out.
D.Delete and recreate the queue with a different name whenever duplicates are detected in production.
AnswerB

Because SQS Standard is at-least-once, the consumer must assume duplicates are possible. Persisting a record keyed by paymentInstructionId (or using a database unique constraint) lets the consumer detect that a given instruction was already processed successfully and safely skip the charge or merge results deterministically.

Why this answer

Implementing idempotent processing with a persistent deduplication key (e.g., paymentInstructionId) ensures that even if SQS Standard delivers the same message multiple times due to consumer timeouts and retries, the downstream logic will detect and ignore or safely merge duplicate charges. This is the most resilient application-side approach as it does not rely on queue configuration changes and works within the constraints of SQS Standard's at-least-once delivery model.

Exam trap

The trap here is that candidates often assume SQS Standard can provide exactly-once delivery if retries are handled properly, but the exam tests the understanding that SQS Standard inherently allows duplicates and that idempotency is the only reliable application-side solution.

How to eliminate wrong answers

Option A is wrong because SQS Standard queues provide at-least-once delivery, not exactly-once delivery; retries and timeouts can cause duplicate messages, and relying on exactly-once is a misconception. Option C is wrong because increasing the visibility timeout to 24 hours does not prevent duplicates if the consumer times out and retries before the timeout expires, and it can delay processing unnecessarily, making it impractical and not resilient. Option D is wrong because deleting and recreating the queue with a different name is a disruptive, manual, and non-scalable approach that does not address the root cause of duplicate processing and would cause data loss and operational chaos.

525
MCQeasy

A startup runs a two-tier web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in private subnets and must reach the internet only to download operating system patches. Security policy forbids any inbound internet traffic to the instances. Which configuration meets these requirements with the least operational overhead?

A.Assign each EC2 instance an Elastic IP address and open the security group to inbound HTTPS.
B.Create a VPC peering connection to a shared services VPC that has an internet gateway.
C.Deploy a NAT gateway in a public subnet and route the private subnets' outbound traffic through it.
D.Place the instances in public subnets and attach a security group that allows only outbound traffic.
AnswerC

A NAT gateway in a public subnet allows instances in private subnets to initiate outbound connections for patching while remaining unreachable from the internet. It is a managed, highly available service, so operational overhead is minimal. This satisfies the outbound-only requirement without exposing the instances, matching the security policy and simplicity goal.

Why this answer

Instances in private subnets need outbound internet access for patching but must not accept inbound connections. A NAT gateway placed in a public subnet provides that one-way connectivity and is a fully managed, highly available service, minimizing operational effort. Alternatives either expose the instances publicly or require extra cross-VPC routing, both of which conflict with the policy or the simplicity requirement.

Exam trap

The trap here is equating outbound internet access with public subnets, when a NAT gateway gives private instances outbound-only connectivity without inbound exposure.

Page 6

Page 7 of 13

Page 8