Courseiva

SAA-C03 · domain

disaster recovery

Practise SAA-C03 disaster recovery practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

935 questions204 easy489 medium242 hard

Focused practice

Practice disaster recovery questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about disaster recovery

disaster recovery questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common disaster recovery exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All disaster recovery questions (935)

Click any question to see the full explanation, or start a practice session above.

1

A production Amazon RDS database already has automated backups enabled. At 10:45 UTC, the team discovers that a faulty migration corrupted rows in a table at 10:30 UTC. The business wants the database restored to exactly the state it had at 10:30 UTC with minimal risk. Which two actions should the team take? Select two.

Medium
2

Based on the exhibit, the web team wants the application to continue serving traffic if one Availability Zone fails. Which change best meets the requirement with the least operational overhead?

Easy
3

You deploy a Web ACL with an AWS WAF rate-based rule intended to limit abusive traffic to your API. After the deployment, attackers still reach the backend service. ALB access logs show requests arrive at the ALB, but WAF logs indicate the Web ACL is not evaluating those requests. Which change most likely fixes the issue?

Medium
4

A startup runs a 24/7 web tier on Amazon EC2 with a stable baseline of 8 instances and a nightly analytics batch job that can resume from checkpoints if interrupted. The company wants to minimize monthly compute cost without hurting the always-on web tier. Which two actions should it take? Select two.

Medium
5

A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The architecture review board prefers a managed AWS-native control.

Medium
6

A trading dashboard uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The architecture review board prefers a managed AWS-native control.

Medium
7

Company A stores encrypted log files in its S3 bucket using SSE-KMS with a customer-managed KMS key. A partner application in Company B uploads objects into Company A's bucket using an IAM role in Company B. Uploads fail with an error indicating KMS access is denied (kms:Encrypt not authorized). Neither the partner IAM policy nor the S3 bucket policy currently mentions KMS. What is the most secure and correct change to allow cross-account uploads to succeed?

Medium
8

A marketing site runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost?

Medium
9

An internal worker consumes messages from an Amazon SQS queue. Occasionally, a message fails validation in the worker (for example, missing required fields). Reprocessing the same bad message repeatedly wastes processing time and delays healthy messages. What is the best AWS approach to handle these poison messages without blocking the rest of the queue?

Easy
10

A media processing pipeline runs batch jobs overnight. The jobs are stateless, can be restarted from checkpoints, and can tolerate interruptions. The team wants to minimize compute cost. Which EC2 approach is the best fit?

Easy
11

A team runs a stateless web app on Amazon EC2 behind an Application Load Balancer. During traffic spikes, new EC2 instances take several minutes to finish bootstrapping before they can receive traffic. Which Auto Scaling configuration most directly reduces the time until additional capacity is available?

Easy
12

Based on the exhibit, your application runs entirely in private subnets and only needs to reach Amazon S3, Amazon DynamoDB, AWS Secrets Manager, and CloudWatch Logs. The monthly bill is dominated by NAT Gateway charges. Which change most directly reduces cost while preserving private connectivity to these AWS services?

Hard
13

A production application uses an Amazon RDS Multi-AZ DB instance. During an unplanned failover, the database endpoint remains the same. What change should the application team make to handle the failover reliably?

Easy
14

A solutions architect is designing a cost-optimized data storage solution for a large dataset that is accessed infrequently but must be retained for compliance for 7 years. Which three actions should the architect take to minimize costs? (Choose three.)

Medium
15

A IoT ingestion API must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

Hard
16

A financial services firm stores trade confirmations in an Amazon S3 bucket. Regulations require that every object be encrypted at rest with a key the firm controls and can audit independently of AWS, and that key usage be logged. The firm wants to avoid changing application code. Which encryption approach should be used?

Hard
17

A analytics dashboard uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add?

Medium
18

A team serves static web assets (JS, CSS, images) from an Amazon S3 origin through CloudFront. Recently, the S3 origin has received a high number of requests for the same files, increasing origin data transfer costs. CloudFront access logs show many cache misses, and each request includes a unique query string used only for tracking (for example, ?utm=...). The application does not require query-string-specific content. What CloudFront change will most directly reduce origin fetches and cost?

Medium
19

A image sharing application uses CloudFront in front of an S3 origin. Which two settings help keep users from bypassing CloudFront and accessing the bucket directly?

Hard
20

Based on the exhibit, a web application must stay available if one Availability Zone fails. What is the best change to improve resilience?

Easy
21

An order-processing service consumes messages from an Amazon SQS Standard queue using a custom worker. During traffic spikes, the worker occasionally times out after performing some work but before acknowledging the message, so SQS redelivers it and it may be processed again. You also observe that a small set of “poison” messages always fail validation. What change most directly improves resilience by (1) preventing poison messages from retrying indefinitely and (2) avoiding duplicate side effects caused by legitimate retries?

Medium
22

Based on the exhibit, what change best reduces Lambda cold-start impact for a predictable user-upload workflow?

Easy
23

An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a customer analytics portal. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy? The design must avoid adding custom operational scripts.

Hard
24

A company is designing a high-performance database architecture for an e-commerce platform that experiences rapid spikes in read traffic during flash sales. The database must handle millions of reads per second with sub-millisecond latency. The data is key-value in nature, with a small number of attributes per item. Which three options should be included in the architecture? (Choose three.)

Medium
25

Account A hosts an IAM role (RoleInAccountA). The trust policy in Account A correctly allows a specific principal from Account B to call sts:AssumeRole. However, when Account B’s application calls sts:AssumeRole, it receives an AccessDenied error. What is the most likely missing requirement in Account B?

Easy
26

A microservice reads a secret from AWS Secrets Manager using its task role (ServiceRole). The secret is configured to use a customer-managed CMK. In production, the service fails with AccessDeniedException on GetSecretValue. CloudTrail shows that Secrets Manager attempted kms:Decrypt but was denied. Which IAM policy change is most appropriate to fix the failure while keeping least privilege?

Medium
27

In AWS Organizations, a Service Control Policy (SCP) denies kms:Decrypt on a production CMK for all principals in the Finance OU. A developer in the Finance OU created/updated an IAM policy that allows secrets access, but the application still fails with AccessDenied due to the SCP. You must enable only the Finance OU to decrypt that specific CMK while keeping the SCP restrictions for other OUs. What is the correct remediation?

Medium
28

A development team is building a new application that stores session state in a relational database. The application experiences unpredictable read traffic, and the team wants a fully managed database that can scale read capacity automatically and provide a reader endpoint that distributes connections across multiple replicas. Which AWS service should a solutions architect recommend?

Easy
29

A Lambda function needs to read the current value of exactly one AWS Secrets Manager secret at startup. Which least-privilege IAM permission (action and resource scope) should you grant to the Lambda execution role?

Easy
30

A company wants S3 access to be available only from private connectivity. They created an Interface VPC Endpoint for S3 (that provides private connectivity from their VPC to S3) and configured the application to use it from private subnets. The IAM role allows: - s3:GetObject on arn:aws:s3:::confidential-bucket/reports/* However, requests fail with AccessDenied. The S3 bucket policy includes an allow statement that permits GetObject only if: - aws:SourceVpce equals "vpce-0abc12345def6789" After redeploying the VPC endpoint, the application still uses the same IAM permissions but gets AccessDenied. What change is most likely to fix the issue?

Medium
31

Based on the exhibit, a public API is behind CloudFront. A single client IP is sending bursts of requests that are overwhelming the origin, and the team wants AWS to automatically mitigate the abuse at the edge without changing the application code. What should the team do?

Hard
32

A healthcare provider hosts a patient-records API on Amazon EC2 instances in a single Availability Zone behind an Application Load Balancer. An audit finds the architecture cannot tolerate the loss of that Availability Zone. Budget is limited, and the API reads from an Amazon Aurora MySQL cluster that currently has one writer instance and no replicas. Which change most effectively addresses the audit finding?

Medium
33

A company runs a stateless API on Amazon EC2 instances in a single Availability Zone behind an Application Load Balancer. The ALB currently has a listener on port 80 only. The company wants the API to remain available if the single Availability Zone fails. What should the solutions architect do to meet this requirement with the LEAST operational overhead?

Easy
34

A Lambda-based retail API has unpredictable traffic spikes and users see latency caused by cold starts. The function must respond consistently during expected campaign windows. What should be configured? The design must avoid adding custom operational scripts.

Hard
35

A web application runs on an EC2 Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ASG spans three Availability Zones. After a deployment, new instances frequently fail the ALB target group health checks with HTTP 5xx responses and are quickly terminated by the ASG. What change most improves resiliency during deployments with minimal downtime by preventing premature removal of instances that are still starting?

Medium
36

A team serves static assets from an S3 origin through CloudFront. Cache hit ratio is low. Analytics show that requests include an Authorization header (even though the assets are public) and the cache key currently varies on that header, causing CloudFront to treat the same asset as different cache entries. What is the best change to improve cache hit ratio without breaking access controls?

Medium
37

Based on the exhibit, the application sees several minutes of connection errors during an Aurora failover. What is the best change to reduce failover impact?

Medium
38

A SOC analyst needs an immutable, centralized audit record of configuration and API changes across multiple AWS accounts. Recently, an operator changed an IAM role trust policy, and investigators must determine exactly which principal made the change and which parameters were used. Your current setup sends application logs to CloudWatch Logs, but there is no organization-level API audit logging. Which approach best satisfies the requirement?

Medium
39

A read-heavy media archive repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The architecture review board prefers a managed AWS-native control.

Medium
40

A patient portal must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The architecture review board prefers a managed AWS-native control.

Hard
41

You store application logs in an S3 bucket. After 30 days, the logs are rarely accessed, but you must retain them for 1 year for compliance. Which S3 feature is the best way to reduce storage cost while meeting the retention requirement?

Easy
42

A security team requires that every object uploaded to s3://secure-bucket/uploads/ must be encrypted using SSE-KMS with a specific customer-managed KMS key. Which S3 bucket policy condition approach best enforces this requirement for PutObject requests?

Easy
43

A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The team wants the control to be enforceable during normal operations.

Medium
44

An application in Account B (IAM role arn:aws:iam::account-b:role/app-read) reads objects from an S3 bucket in Account A. The bucket uses SSE-KMS with a customer-managed KMS key in Account A. Object reads consistently fail with an error that includes "AccessDenied" and "kms:Decrypt". The IAM permissions in Account B for kms:Decrypt are correct, but the requests still fail. Which change will most directly fix the failure?

Medium
45

A healthcare analytics platform stores derived datasets in an Amazon S3 bucket. Regulatory rules require that every object remain recoverable for 90 days after creation even if an application bug issues a delete, and that no object version be permanently destroyed during that window. The team wants the strongest protection with the least custom code. Which S3 feature should the solutions architect enable?

Hard
46

A financial services company runs a high-traffic REST API on Amazon EC2 instances behind an Application Load Balancer. The API retrieves user session data from an Amazon DynamoDB table for every request. During peak hours, DynamoDB read capacity is exhausted, causing throttling and increased latency. The workload is read-heavy and the session data is accessed frequently but changes infrequently. The solutions architect needs to reduce DynamoDB read load and improve API response times with minimal application changes. Which solution meets these requirements?

Medium
47

A risk simulation workload generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used?

Hard
48

Based on the exhibit, a central deployment role in Account A is assumed by several CI/CD pipelines from Account B. The role must remain reusable, but the team wants the TeamA pipeline to upload artifacts only to s3://artifact-bucket/teamA/prod/ without creating a separate IAM role. What is the best approach?

Hard
49

A financial services company runs a three-tier web application on AWS. The application servers in a private subnet must retrieve database credentials from AWS Secrets Manager at startup. The security team requires that the credentials never be stored on disk and that access be granted only to the specific IAM role attached to the instances. Which solution meets these requirements with the LEAST operational overhead?

Hard
50

A company runs a critical two-tier web application on AWS. The web tier consists of Amazon EC2 instances behind an Application Load Balancer (ALB) in a single Availability Zone. The database tier is an Amazon RDS for MySQL DB instance in the same Availability Zone. A recent power outage in that Availability Zone caused a full application outage. The company wants to redesign the architecture to survive an Availability Zone failure with minimal operational overhead. Which solution meets these requirements?

Medium
51

An orders service publishes payment instructions to an Amazon SQS Standard queue. The downstream processor sometimes times out after it has already applied the payment, but before it can delete the message from the queue. As a result, the same payment instruction can be processed more than once. The team wants the strongest way to prevent duplicate side effects while keeping the system decoupled. What should they implement?

Medium
52

Your order-processing system uses EventBridge rules to send events to a Lambda function that updates order status. Over the last week, some events fail with a transient database timeout, and the Lambda retries intermittently but then the events are lost (no alerts after failures). You want at-least-once processing, bounded retries, and a way to inspect unprocessable events for later reprocessing. Which architecture change best meets these requirements?

Medium
53

A inventory service exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most? The architecture review board prefers a managed AWS-native control.

Easy
54

A company runs an internal API on Amazon EC2 instances in a private subnet. The API must call AWS Systems Manager Parameter Store to read configuration values. The security team wants to avoid long-lived credentials on the instances and avoid routing traffic over the public internet. Which combination of steps should be taken?

Hard
55

A ticket booking system stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured?

Medium
56

A company runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. The application experiences predictable traffic patterns: low traffic at night and high traffic during business hours. The company wants to optimize costs without compromising availability. Which two actions should be taken? (Choose two.)

Medium
57

A team stores important documents in Amazon S3. They want to recover earlier versions if someone overwrites or deletes a file by mistake. What should they enable?

Easy
58

A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The design must avoid adding custom operational scripts.

Medium
59

Based on the exhibit, a batch platform in Account B must assume a role in Account A. Only the specific role arn:aws:iam::222233334444:role/BatchRunner should be allowed to assume it, and the design must prevent any other role in Account B from reusing the same external ID. Which change best meets the requirement?

Hard
60

Based on the exhibit, a batch-processing service runs on Amazon EC2. The workload is Linux-based, can run on ARM64, and is CPU-bound during its nightly processing window. The team wants the best throughput per dollar without changing the application logic. Which EC2 instance family should the solutions architect recommend?

Hard
61

A media analytics company ingests a continuous stream of JSON clickstream events, roughly 20,000 records per second, into an Amazon Kinesis Data Streams stream with 32 shards. Downstream consumers must be able to re-read the same records up to 7 days later to rebuild a reporting index. Which combination of settings should the team use to maximize the number of records each consumer can read per second while preserving this replay capability?

Medium
62

Based on the exhibit, a CI pipeline assumes a shared deployment role in Account A. The role can access several artifact prefixes, but this pipeline must only upload to teamA/prod/ and decrypt using a single KMS key for this execution. Changing the shared role would affect other pipelines. Which approach should the pipeline use?

Hard
63

An Aurora PostgreSQL application has an OLTP writer and a reporting dashboard that issues many read-only queries. The writer is healthy, but read latency rises noticeably during reporting windows. Which two changes should you make? Select two.

Medium
64

A company runs EC2 instances in private subnets and needs to access Amazon S3 objects without using a NAT gateway. They want the traffic to stay within AWS private networking as much as possible (no internet egress). Which VPC endpoint type should they create for Amazon S3?

Easy
65

Based on the exhibit, a media company serves versioned JavaScript and CSS files from an Amazon S3 origin through CloudFront. After a frontend release, the cache hit ratio dropped sharply even though the file names are versioned. The application team says the browser requests include the same Authorization header on every asset request because the frontend and API share one domain. What should the solutions architect do to improve CloudFront cache hit ratio without changing the application authentication model for the API?

Hard
66

A DynamoDB-backed multi-tenant app experiences throttling during a promotion. Most writes and reads target tenant "ACME" and use the same partition key value, causing a hot partition. Which design change most directly improves performance?

Easy
67

A production application writes to an Amazon Aurora PostgreSQL cluster. Users report that during business-hour reporting runs, write latency increases. The application team wants to keep the writer focused on OLTP writes while still providing low-latency reads for reporting queries. What architectural approach should the solutions architect recommend?

Medium
68

An S3 bucket stores user-uploaded images. Access patterns are unpredictable: some objects are never read again, while others are occasionally retrieved months later. The team wants to reduce storage cost without having to manually track access frequency or run periodic analyses. Which S3 storage and lifecycle approach is the best fit?

Medium
69

Based on the exhibit, the security team wants centralized detection and alerting for both successful and failed attempts to change S3 bucket policies and KMS key policies across multiple accounts. Which approach best meets the requirement?

Hard
70

A small analytics team runs a nightly batch job on a single Amazon EC2 instance. The job starts at 2:00 AM and finishes by 4:00 AM. The instance is idle for the rest of the day. The team wants to reduce EC2 costs and is willing to accept that the instance may be stopped and started. Which action will reduce costs MOST effectively?

Easy
71

A retail API runs on Amazon EC2 instances behind an Application Load Balancer and stores orders in an Amazon RDS for PostgreSQL database. A test that stopped one Availability Zone caused the API to return errors because all application servers were in the same AZ and the database was single-AZ. Which two changes should the architect make to continue serving traffic during a single-AZ failure? Select two.

Medium
72

A company runs EC2 workloads in one region with somewhat steady overall demand. Over time, the team frequently changes instance families (for performance/optimization) and sometimes changes instance size, but wants predictable cost discounts. Which purchase option provides the best balance of cost savings and flexibility?

Easy
73

Match the disaster recovery strategy to the recovery posture it best fits for a Regional outage.

Medium
74

A payments service receives payment orders by consuming messages from an Amazon SQS Standard queue. The downstream processor occasionally exceeds its processing timeout. As a result, some messages reappear in the queue and may be processed more than once. The team wants to prevent duplicate side effects (for example, double-charging) and also ensure poison messages do not repeatedly consume processing capacity. What approach best satisfies both goals?

Medium
75

A telemetry pipeline uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add? The architecture review board prefers a managed AWS-native control.

Medium
76

A company stores sensitive customer data in an Amazon S3 bucket. The security team wants to ensure that all data is encrypted at rest using keys that the company controls, including the ability to rotate keys and audit key usage. They also want to minimize operational overhead for key management. Which solution meets these requirements?

Medium
77

A public API for a customer analytics portal is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used? The design must avoid adding custom operational scripts.

Medium
78

A financial services firm runs a batch settlement job on a fleet of Amazon EC2 instances that pull work from an Amazon SQS queue. The job must not lose messages if an instance is terminated mid-processing, and duplicate processing must be minimized because each settlement charge is expensive. The team also wants to avoid indefinite reprocessing of a message that repeatedly fails. Which two changes should the solutions architect make to meet these requirements? (Choose two.)

Hard
79

Based on the exhibit, a workload in Account B must assume a role in Account A. Security requires that only the specific role arn:aws:iam::444455556666:role/PipelineExecRole can assume it, and only when the caller supplies the external ID acct-b-prod-7788. Which change best satisfies the requirement with the least privilege?

Hard
80

A company runs a stateful workload on Amazon EC2 instances in an Auto Scaling group. The workload writes session data to the instance store and to an Amazon EBS volume attached at launch. The company wants the workload to survive an Availability Zone failure without losing session data. What should the solutions architect do?

Hard
81

A fintech company has a two-Region DR requirement: RPO must be within 15 minutes and RTO must be under 2 hours. To control cost, they do not want to run full production infrastructure in the secondary Region continuously. They plan to continuously replicate the database and keep the application infrastructure in the secondary Region prepared, but at reduced capacity. Which DR strategy best matches this requirement and accurately describes their plan?

Medium
82

A media company stores generated video thumbnails in an Amazon S3 bucket. The bucket currently uses the S3 Standard storage class, and the objects are accessed frequently for the first 30 days and then almost never. The company wants to reduce storage costs automatically without changing the application and must retain the objects for at least one year. Which action should a solutions architect take?

Easy
83

A company hosts a customer analytics portal on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

Medium
84

Your security team needs to detect and alert on any attempt to change sensitive policies, specifically S3 bucket policy changes and KMS key policy changes. The team wants alerts within minutes, and logs must be centrally retained for forensics. Which design best meets these detective control requirements using AWS-native services?

Medium
85

In an AWS Organizations environment, developers create IAM roles using an automation tool. The security team wants to guarantee that even if a developer attaches an overly permissive inline policy, the role cannot exceed a fixed set of allowed actions. The team already uses permission boundaries on each role. The tool’s role-creation API call succeeds, but one developer’s new role can still delete production S3 buckets. What is the most likely reason, and what should be corrected?

Medium
86

A batch analytics job has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity?

Medium
87

A logistics company runs an order-processing workflow using AWS Step Functions. A task state invokes a Lambda function that charges customer credit cards through a third-party gateway. Occasionally the gateway times out, and the workflow fails even though the charge may have succeeded. The architect must make the workflow resilient to these transient failures and avoid duplicate charges. (Choose two.)

Medium
88

A healthcare company runs a stateless patient-intake API on a fleet of Amazon EC2 instances in a single VPC. The compliance team requires the workload to survive the complete loss of one Availability Zone with no manual intervention, and the instances must be replaced automatically if they fail health checks. The application stores no local state and writes all data to Amazon RDS. Which approach meets these requirements with the LEAST operational effort?

Medium
89

A payments API uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure?

Hard
90

A content publishing system exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most?

Easy
91

Based on the exhibit, the team serves versioned JavaScript and CSS files from an S3 origin through CloudFront. After a release, the cache hit ratio dropped and origin fetches increased sharply. What change best reduces both CloudFront and S3 costs without changing the application’s public behavior?

Hard
92

A digital agency runs a web application on a fleet of Amazon EC2 instances behind an Application Load Balancer. Traffic is steady and predictable during business hours but drops to near zero overnight and on weekends. The operations team wants to reduce compute costs without impacting availability during peak periods. They cannot modify the application code and must keep the same instance types. What should a solutions architect recommend?

Medium
93

An application runs on EC2 in us-east-1 and frequently reads objects from an S3 bucket that is physically located in us-west-2. The finance team reports unexpectedly high inter-Region data transfer charges because the application retrieves objects for many user requests. A constraint: the bucket in us-west-2 must remain the system of record for compliance, but the application can read from a replica in us-east-1. What should the solutions architect do to minimize network spend while meeting the compliance constraint?

Medium
94

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences variable traffic patterns, with sudden spikes during marketing campaigns. The operations team wants to ensure that the application can scale out quickly to handle the spikes and scale in when traffic decreases, while minimizing costs. Which solution should a solutions architect recommend?

Easy
95

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The implementation must work across routine deployments without manual intervention.

Hard
96

A healthcare company is designing a new application on AWS. The application will store protected health information (PHI) in an Amazon S3 bucket. The security team requires that all data be encrypted at rest using a customer managed AWS KMS key so that they can control key rotation and audit key usage. They also need to ensure that only the application's IAM role can decrypt the data. Which solution meets these requirements?

Medium
97

A solutions architect is reviewing an Amazon S3 bucket that stores application assets. The bucket has S3 Versioning enabled and accumulates many noncurrent object versions that are no longer needed. The team wants to reduce storage cost while preserving the ability to recover from accidental deletions of current objects. Which two actions should the architect take? (Choose two.)

Hard
98

A partner company needs read-only access to reports in an S3 bucket for a B2B file exchange site. The partner has its own AWS account. What is the most secure scalable access pattern?

Medium
99

Based on the exhibit, which EBS volume type should the team use to meet the performance need at lower cost than overprovisioning capacity?

Easy
100

Your company needs a high-throughput, low-latency TCP service using a custom binary protocol. Requirements: preserve the original client source IP for rate limiting, keep latency minimal, and use TCP health checks. The current setup uses an Application Load Balancer and performance is inconsistent. Which load balancer choice best meets these requirements?

Medium
101

A company runs an application behind an Application Load Balancer (ALB). An Auto Scaling group (ASG) is configured with desired capacity 2, but it is attached only to subnets in a single Availability Zone. The ALB is healthy because it is configured across multiple Availability Zones. When the Availability Zone that contains the ASG subnets experiences an outage, what change most directly improves resilience and allows capacity to be restored automatically?

Medium
102

A company runs a stateless application tier behind an Application Load Balancer. Match each observed scaling pattern on the left to the best Auto Scaling strategy or metric on the right.

Hard
103

An administrator needs the ability to read and update infrastructure for a specific AWS account, but only when using MFA. The security team wants to eliminate long-lived administrator access keys and ensure that even if someone obtains temporary session credentials, actions are only allowed with MFA present. Which IAM design best meets these requirements?

Medium
104

A logistics company runs an order-processing workload that reads messages from an Amazon SQS queue and writes results to an Amazon DynamoDB table. Occasionally the same order is processed twice and produces duplicate shipments. The architects must ensure each order is processed exactly once end to end, while keeping throughput as high as possible. What should they do?

Hard
105

A company is deploying a new web application on AWS. The application will serve static content (HTML, CSS, JavaScript, images) and dynamic API requests. The company expects a global user base and wants to minimize latency for all users. The static content is stored in an Amazon S3 bucket, and the dynamic APIs are hosted on Amazon EC2 instances behind an Application Load Balancer. Which service should the company use to accelerate both static and dynamic content delivery?

Easy
106

A SaaS vendor needs temporary access to an S3 bucket in your AWS account to read customer exports. The vendor will assume an IAM role you created. During integration testing, the vendor reports that their AssumeRole requests succeed, but your security team is concerned about the possibility of confused-deputy attacks. Which trust policy approach most directly mitigates this risk?

Medium
107

A team runs a containerized API on Amazon ECS on Fargate in a single Region. Traffic is steady during business hours but drops to near zero overnight, and the team wants to reduce cost without rewriting the application. The team already uses Application Load Balancer and CloudWatch. Which two actions will reduce cost while keeping the API available? (Choose two.)

Medium
108

An engineering team runs application servers in private subnets. The instances must download patches and software packages from Amazon S3, but the company does not want the traffic to traverse the internet or a NAT gateway. Which design should they use?

Medium
109

A financial analytics team stores sensitive customer data in an Amazon S3 bucket. The bucket uses SSE-KMS with a customer-managed key. Analysts access objects using an IAM role attached to an EC2 instance in a private subnet. The role has s3:GetObject permission on the bucket. However, analysts report AccessDenied errors when downloading objects. The KMS key policy currently grants full access to the account root user only. What is the most likely cause of the AccessDenied errors?

Medium
110

A global application experiences frequent writes and must survive a full Regional outage with near-zero data loss. The product team also requires that users can continue to write during the incident using the closest Region. Which approach is most aligned with these requirements?

Medium
111

A server assumes an IAM role and must read export objects only from this prefix in an S3 bucket: s3://customer-data/exports/acme/ . The application also needs to list the objects under that exact prefix so it can discover which export folders exist. The application performs ListBucket requests with Prefix set to exactly "exports/acme/". The current role policy allows s3:ListBucket on the bucket ARN without a prefix condition, and security reports the role can list other tenants’ export object keys. Which IAM policy change best enforces least privilege for both ListBucket and GetObject?

Medium
112

A genomics research team stores about 400 TB of compressed sequence files in Amazon S3 and runs a distributed analysis on Amazon EC2 instances in the same Region. The analysis reads each file sequentially and writes intermediate results to local instance storage. The team reports that the S3 GET requests are a bottleneck and wants to improve read throughput while keeping data durable. (Choose two.)

Hard
113

An internal web application is exposed through an Application Load Balancer (ALB). The ALB currently has only an HTTP listener on port 80. Security requires that all client traffic be encrypted in transit. What is the best next step?

Easy
114

A company runs a batch processing job on Amazon EC2 instances that takes approximately 4 hours to complete. The job can be interrupted and resumed from a checkpoint. The company wants to minimize the cost of running this job. Which pricing model should they use?

Medium
115

A high-volume telemetry pipeline writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate?

Medium
116

A data analytics team runs an Amazon EMR cluster for 2 hours every weekday morning to process a daily batch. The cluster must be fully available during that window, and the team wants the lowest possible compute cost. The jobs are stateless and can be re-run if a node fails. Which configuration should a solutions architect recommend?

Medium
117

A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers?

Medium
118

An engineering team deploys a stateless web API on EC2 using an Auto Scaling group and an Application Load Balancer (ALB). During a recent test, they noticed that when one Availability Zone was unavailable, traffic failed until new instances were manually launched. Which change most directly improves automatic failover for the compute layer within a single Region?

Easy
119

A payments API requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The team wants the control to be enforceable during normal operations.

Hard
120

A CI/CD system creates an IAM role (CICDRole) used for deployments. Your organization uses IAM permission boundaries to prevent developers from granting themselves higher privileges. After an incident, you discover that CICDRole can perform unintended IAM actions because the role’s identity policy includes broad permissions. Which change most directly ensures permission boundaries continue to restrict CICDRole regardless of what is later added to the role’s identity policies?

Medium
121

A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load?

Medium
122

A healthcare company runs a containerized claims-processing service on Amazon ECS with the Fargate launch type in a single AWS Region. The service must survive the loss of an entire Availability Zone with no manual intervention, and the architecture must keep the same service endpoint for callers. The service is fronted by an Application Load Balancer. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?

Medium
123

A claims workflow uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure?

Hard
124

A company has a steady-state workload on Amazon EC2 that runs 24/7 for the next 3 years. They want to achieve the maximum possible discount and are willing to make a upfront payment. Which purchasing option should they choose?

Medium
125

An orders service publishes payment instructions to an Amazon SQS queue. After occasional processing timeouts, the downstream consumer sometimes processes the same instruction twice, resulting in duplicate payment attempts. The team currently uses an SQS Standard queue with a visibility timeout of 2 minutes and relies on the consumer to finish before the timeout expires. What approach best improves resilience against duplicate processing?

Medium
126

Based on the exhibit, why is the IAM role still receiving AccessDenied even though it has AdministratorAccess attached?

Medium
127

Based on the exhibit, which change best reduces latency during peak traffic without overprovisioning the fleet?

Hard
128

A healthcare company stores protected health information in an Amazon S3 bucket. Auditors require that every object be encrypted with a customer managed AWS KMS key, that key rotation be controlled by the company, and that the company be able to revoke access to the data immediately by disabling the key. Which encryption configuration meets these requirements?

Hard
129

A backend service in AWS uses an IAM role to upload large files to an S3 bucket using multipart upload. The upload typically succeeds, but it intermittently fails during cleanup with this error: "AccessDenied: User is not authorized to perform: s3:AbortMultipartUpload" The role identity policy currently allows only: - s3:PutObject on arn:aws:s3:::my-bucket/uploads/* - s3:ListBucket on arn:aws:s3:::my-bucket with a prefix condition What is the best least-privilege change to fix the cleanup failure?

Medium
130

A healthcare company stores 80 TB of medical imaging data in Amazon S3. The data is written once and must be retained for seven years for compliance. New images are accessed frequently for the first 30 days, then almost never after that, but auditors occasionally request a specific image with no advance notice and expect it within minutes. The company wants to minimize storage cost while meeting the retrieval requirement. Which two actions should a solutions architect recommend? (Choose two.)

Hard
131

A production internal reporting portal runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy?

Medium
132

An orders system sends payment instructions to an Amazon SQS queue. The consumer sometimes times out after it has already created the payment record but before it deletes the SQS message. As a result, the same instruction can be processed more than once. Which design best ensures the consumer remains resilient and does not create duplicate payments when the same instruction is delivered multiple times?

Medium
133

A company runs an application in private subnets (no inbound internet). The application must access Amazon S3 and AWS Secrets Manager endpoints without routing through the public internet and without exposing the instances to NAT gateways due to cost. Security requirements also state that only the required VPC traffic should be allowed to reach AWS services. Which architecture best satisfies these requirements?

Medium
134

A logistics company runs an order processing system on Amazon EC2 instances that read and write to an Amazon RDS for MySQL database. The database is currently a Single-AZ deployment. The company needs the database to survive an Availability Zone failure with automatic failover and minimal downtime. The application connects using a hardcoded DNS name. Which change should a solutions architect make?

Hard
135

CloudWatch metrics show your EC2 instances have average CPU utilization around 10% with stable performance over several weeks. The application does not require additional headroom right now. What is the most effective cost-optimization action?

Easy
136

A customer portal must recover from a regional outage within a few hours. The business wants lower ongoing cost than a fully active second Region and does not want to rebuild everything from scratch during the outage. Which two DR patterns best fit that goal? Select two.

Medium
137

A financial services company runs a three-tier web application on AWS. The application tier consists of EC2 instances in an Auto Scaling group behind an Application Load Balancer. Security policy requires that the EC2 instances never receive public IP addresses and that all outbound internet traffic from the application tier be routed through a NAT gateway. The company also wants to ensure that only the load balancer can initiate connections to the application instances on port 443. Which combination of VPC configuration and security group rules should a solutions architect implement to meet these requirements?

Medium
138

A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The architecture review board prefers a managed AWS-native control.

Medium
139

A company runs a microservices application on Amazon ECS with AWS Fargate. The tasks run continuously, and the company has committed to a 3-year term. The team wants to reduce Fargate compute cost while keeping the same task definitions and architecture. Which action should a solutions architect take?

Medium
140

A healthcare analytics company runs an Amazon RDS for MySQL database in a private subnet. A compliance requirement mandates that all data at rest be encrypted with a key that the company can rotate, audit, and immediately revoke. The database is currently unencrypted. What is the MOST operationally efficient way to meet this requirement?

Medium
141

A media company stores master video files in an Amazon S3 bucket in the us-east-1 Region. A compliance policy requires that the data remain readable even if the entire us-east-1 Region becomes unavailable, and the recovery point objective is 15 minutes. The team wants the lowest operational overhead and does not want to modify application code. Which solution should the architect implement?

Hard
142

A financial analytics platform runs an Amazon Aurora MySQL cluster with one writer and two readers. During month-end reporting, read traffic spikes and the application sometimes receives TooManyConnections errors on the reader endpoint. The architect wants to absorb bursts without changing application code and must keep failover behaviour intact. Which change meets these requirements?

Hard
143

A claims portal uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

Hard
144

A risk simulation workload in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost?

Hard
145

A DynamoDB table stores device status items. The partition key is deviceId, and the partition distribution is healthy (no single partition dominates). However, during peak periods the application experiences high read latency because many clients repeatedly request the latest status for the same devices. Which action best improves read latency without changing the DynamoDB partitioning model?

Medium
146

Based on the exhibit, the company runs a self-managed RabbitMQ cluster on EC2 for asynchronous work. The queue only needs durable at-least-once delivery, and the application does not require AMQP-specific features such as exchanges, routing keys, or broker plugins. Which change is the best cost-optimization move?

Hard
147

A company is designing a secure architecture for a three-tier web application on AWS. The web tier runs on Amazon EC2 instances in public subnets, the application tier runs on EC2 instances in private subnets, and the database tier runs on Amazon RDS in private subnets. The security team requires that the application tier instances can access the internet for software updates without being directly reachable from the internet, and that the database tier is not accessible from the internet. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Medium
148

A containerized service fleet running on EC2 instances needs to share user-uploaded files and access them with low latency. The workload is bursty: sometimes dozens of instances concurrently read the same directory for short periods, and then traffic drops. Which Amazon EFS configuration best matches these performance needs?

Medium
149

A batch process uploads artifacts to an Amazon S3 bucket using multipart uploads. The bucket policy contains a statement that explicitly denies PutObject and CreateMultipartUpload unless the request uses server-side encryption with AWS KMS (SSE-KMS) and includes these request headers/parameters: x-amz-server-side-encryption=aws:kms and x-amz-server-side-encryption-aws-kms-key-id set to a specific CMK. After the process was updated, uploads intermittently fail with AccessDenied errors. Which change is the best way to make uploads succeed while still meeting the bucket policy's encryption requirement?

Medium
150

A media company stores video masters in an Amazon S3 bucket encrypted with a customer managed AWS KMS key. Editors sign in through a corporate identity provider that is federated to AWS IAM Identity Center, and they must be able to download and re-upload objects. The security team wants every editor's read of the key material recorded in CloudTrail with the editor's own identity, and wants to be able to revoke one editor's access without affecting the others. Which configuration meets these requirements?

Medium
151

A logistics company runs a shipment-tracking service on a single Amazon EC2 instance in one Availability Zone. The instance stores tracking state in an attached Amazon EBS volume and writes nightly backups to Amazon S3. The company needs the service to survive the loss of an entire Availability Zone with minimal data loss and automatic recovery, while keeping changes minimal. Which design change should a solutions architect recommend?

Medium
152

A small e-commerce company hosts its website on a single EC2 instance in a public subnet. The site receives low but steady traffic. The company wants to reduce cost and is willing to accept a brief interruption if the instance is terminated. The workload can be restarted automatically. Which EC2 purchasing option should the company use to minimize cost?

Easy
153

A production Amazon RDS database has automated backups enabled. At 10:45 UTC, an issue is discovered. The team needs to restore the database to its state as of 10:30 UTC. Which capability should they use?

Easy
154

A startup runs a read-heavy product catalogue API on Amazon DynamoDB. The table uses on-demand capacity mode, and the team notices that repeated queries for the same popular items return consistently, causing high read request charges. The application can tolerate data that is a few seconds stale. Which change reduces read costs while keeping latency low?

Easy
155

A team serves static content (JavaScript, CSS, images) from S3 through CloudFront. After a recent release, CloudFront reports a low cache hit ratio and the S3 origin receives a much higher request rate. The site still works, but billing shows higher origin and data transfer costs. Which change is most likely to improve cache hit ratio and reduce origin load?

Medium
156

Based on the exhibit, an automation pipeline in several member accounts creates IAM roles for application deployments. Security says no future role may exceed the approved boundary arn:aws:iam::123456789012:policy/DeployBoundary, even if someone later attaches AdministratorAccess. What should you implement to enforce this across the organization?

Hard
157

A marketing site serves versioned JavaScript and CSS files from Amazon S3 through CloudFront. The origin bill is rising because CloudFront keeps fetching the same files too often, and the application never changes a file at the same URL once it is published. Which two changes should you make? Select two.

Medium
158

A solutions architect is designing a highly available and resilient architecture for a critical internal application that processes financial transactions. The application runs on Amazon EC2 instances inside an Auto Scaling group. The database layer uses an Amazon Aurora MySQL cluster. The company requires that if an entire AWS Availability Zone (AZ) fails, the application must remain operational with minimal impact and automatically recover without manual intervention. Which combination of architectural decisions will meet these requirements? (Choose four.)

Medium
159

A financial services company runs a three-tier web application on AWS. The application servers run on Amazon EC2 instances in private subnets and must retrieve database credentials from AWS Secrets Manager at startup. The security team wants to ensure that the credentials are never stored in plaintext on the instances and that access is auditable. Which solution meets these requirements with the LEAST operational overhead?

Medium
160

A startup runs a single Amazon EC2 instance hosting both a web application and its MySQL database. The founders want the application to survive the failure of the underlying hardware without changing the database engine, and they want the smallest possible operational change. What should the architect recommend?

Easy
161

A company is designing a secure architecture for a three-tier web application on AWS. The application runs on Amazon EC2 instances in private subnets, uses an Amazon RDS for MySQL database in private subnets, and is accessed by users over the internet through an Application Load Balancer. The security team requires that the database credentials be stored securely and rotated automatically, and that EC2 instances retrieve credentials without hardcoding them. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Medium
162

Your public API is hosted in two regions. You want Route 53 to automatically send traffic to the secondary region when the primary region’s endpoint fails. The primary API health check is returning failure codes, but clients still reach the primary region for several minutes. Which Route 53 configuration most directly addresses this behavior?

Medium
163

A company is designing a secure architecture for a new application on AWS. The application will store sensitive data in Amazon S3 and will be accessed by users from a web browser. The security team requires that data be encrypted in transit and at rest, and that access to the S3 bucket be limited to only the application's users. The company also wants to minimize operational overhead. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Hard
164

A company serves private images stored in S3 through Amazon CloudFront. Only authenticated users should be able to access each image, and access should expire after 1 hour. Which CloudFront feature best meets this requirement?

Easy
165

A company stores application logs in an Amazon S3 bucket and wants to protect them from accidental or malicious deletion for a fixed retention period. Legal requires that no user, including the AWS account root user, be able to delete or overwrite the log objects for 365 days, and that the protection be verifiable. Which solution should a solutions architect recommend?

Medium
166

Based on the exhibit, some SQS messages fail validation repeatedly and continue consuming worker time. What change best prevents the bad messages from being retried forever?

Easy
167

A retail company runs a stateless web tier on a fleet of On-Demand EC2 instances behind an Application Load Balancer. Traffic is steady and predictable throughout the year, and the team has committed to running this exact instance family and Region for at least the next three years. Leadership wants to reduce compute cost as much as possible while keeping the ability to change instance size within the same family. Which purchasing option should the solutions architect recommend?

Medium
168

A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The architecture review board prefers a managed AWS-native control.

Medium
169

A financial analytics team runs a nightly Monte Carlo simulation on a cluster of Amazon EC2 instances. The simulation writes checkpoint files to an Amazon EBS volume, and the job can be safely restarted from the last checkpoint if interrupted. The team needs the lowest possible compute cost and can tolerate interruptions. The job must run every night and finish within a 6-hour window. Which solution meets these requirements MOST cost-effectively?

Hard
170

A global mobile game backend serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The design must avoid adding custom operational scripts.

Medium
171

A team runs an Amazon RDS for MySQL database in a single Availability Zone. They want automatic failover with minimal downtime if the primary database instance becomes unavailable. Automated backups are already enabled. Which configuration change best meets the requirement?

Easy
172

An application serves static images through Amazon CloudFront. The team observes higher-than-expected origin fetches, which increases origin bandwidth costs. Which change most directly improves CloudFront cache reuse to reduce origin requests for the static content?

Easy
173

A company hosts an internal HTTP API on an internal Network Load Balancer (NLB) in VPC A. A partner team in a separate AWS account needs access, but their VPC CIDR overlaps with VPC A, so VPC peering is not feasible. Security requirements state the API must remain non-public (no internet-facing ALB/NLB) and access must use AWS private networking. Which architecture best meets these requirements?

Medium
174

A startup runs a nightly batch job on a single Amazon EC2 instance that stores results in an Amazon EBS volume. The job takes six hours, and the team wants to resume from the last completed step if the instance is terminated unexpectedly. Which approach provides the required durability with the least operational effort?

Easy
175

Your team runs a batch processing workload on EC2 that can tolerate interruptions. If an instance is terminated, the job can restart from checkpoints. To reduce compute costs, what is the most cost-optimized approach?

Easy
176

A DynamoDB table for a travel booking site has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The design must avoid adding custom operational scripts.

Hard
177

A marketing site stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost? The architecture review board prefers a managed AWS-native control.

Medium
178

A company runs a containerized application on Amazon ECS on AWS Fargate. The application must read from an Amazon DynamoDB table and write logs to Amazon CloudWatch Logs. Security policy requires that the application use only temporary credentials and that each task have the least privilege needed. What should the company configure?

Hard
179

A solutions architect is designing an S3 bucket for a mobile banking backend. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?

Medium
180

A travel booking site uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured? The architecture review board prefers a managed AWS-native control.

Easy
181

A platform team lets application teams create IAM roles in member accounts through Infrastructure as Code. Security says every new role must stay within a centrally approved permission ceiling, even if someone later attaches broader managed policies or inline policies. Which control should be used to enforce that maximum permission set?

Hard
182

A company runs a microservices application on Amazon ECS with AWS Fargate. The application experiences variable traffic throughout the day, with peak hours during business hours and minimal traffic at night. The company wants to optimize costs without affecting performance. Which action should they take?

Hard
183

Based on the exhibit, users must access private PDF reports only through CloudFront. Direct requests to the S3 object URL must fail, and the bucket should not be publicly readable. Which solution is the best fit?

Hard
184

A risk simulation workload generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used? The design must avoid adding custom operational scripts.

Hard
185

A company needs an Amazon RDS database that automatically fails over to a standby when the primary DB instance becomes unavailable. Which approach best meets the requirement with minimal operational effort?

Easy
186

A Lambda function for a order processing API needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used? The design must avoid adding custom operational scripts.

Medium
187

A backend service uses an IAM role to read files from an S3 bucket. It must only read objects under s3://prod-reporting/incoming/ but currently receives AccessDenied (403) on GetObject for that prefix. The role already has this statement: - Action: s3:ListBucket - Resource: arn:aws:s3:::prod-reporting Which policy statement would most directly follow least privilege to allow only the required reads under the incoming prefix?

Medium
188

A solutions architect must store application configuration data in AWS Systems Manager Parameter Store. Compliance requires that the values be encrypted with a key the company controls and can rotate on demand, and that only a specific IAM role used by the application can decrypt them. Which configuration meets these requirements?

Hard
189

An application repeatedly reads the same DynamoDB items with very low latency requirements. The application can tolerate slightly stale data (for example, within a few seconds). You want to improve read latency without changing the existing DynamoDB table schema. Which service is the best choice?

Easy
190

A web application for a healthcare document service is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

Medium
191

A DynamoDB-backed multi-tenant app experiences throttling. Most write traffic for tenant 'ACME' targets a single logical stream of events (you write items for ACME in near-real time). The table currently uses partition key = tenantId and sort key = eventTimestamp. CloudWatch shows partition-level throttling concentrated in the ACME partition. What design change most directly improves write throughput for the hottest tenant while still enabling efficient queries for recent events for that tenant?

Medium
192

A startup is deploying a new web application on AWS. The security team wants to ensure that all data stored in Amazon S3 is encrypted at rest and that the company retains full control over the encryption keys, including the ability to audit key usage and rotate keys on demand. The team also wants to minimize the operational burden of managing key infrastructure. Which S3 encryption option should a solutions architect recommend?

Easy
193

Based on the exhibit, a serverless API on AWS Lambda experiences a predictable cold-start penalty every weekday at 09:00 UTC when a marketing campaign begins. The team wants the first requests to stay fast while minimizing extra cost during quiet periods. What is the best approach?

Hard
194

Based on the exhibit, a workload in private subnets must reach only Amazon S3 and AWS Secrets Manager. The team wants to eliminate internet exposure for those calls and reduce NAT gateway charges. What change should be made?

Hard
195

A team runs an EC2-based API on a single Auto Scaling group (ASG). Over the last month, they observed: - Average CPU utilization is ~15%. - p95 latency is stable and within the performance target. - The attached EBS volumes are gp3, provisioned with high baseline IOPS/throughput “just to be safe,” but CloudWatch shows consistently low utilization of those provisioned IOPS/throughput limits. They want to reduce monthly cost while maintaining current performance. Which action is the best cost-optimized choice?

Medium
196

A company has an Amazon S3 bucket for sensitive reports. They must ensure that any object uploaded with s3:PutObject is encrypted using AWS KMS (SSE-KMS). Which S3 bucket policy approach best enforces this by denying uploads that do not use SSE-KMS?

Easy
197

A data processing application runs on a single EC2 instance and needs persistent block storage with sustained low-latency random read/write performance (high IOPS). Which storage choice is most appropriate?

Easy
198

A SaaS platform serves an API using two regional deployments: us-east-1 (primary) and us-west-2 (secondary). Each region has its own ALB. The business requires automated DNS-based failover when the primary region becomes unhealthy, and they do not want manual DNS changes during incidents. Which Route 53 configuration is the best match?

Medium
199

Based on the exhibit, DNS still sends traffic to the primary Region even though Route 53 health checks show the primary endpoint is unhealthy. What is the best change to make failover work as intended?

Hard
200

A media company runs a batch job that processes image thumbnails. The job can be restarted from checkpoints and does not have user-facing SLAs. The batch capacity can tolerate interruptions. Which EC2 purchasing option is the best cost optimization choice?

Easy
201

A patient portal must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used?

Hard
202

A public API for a image sharing application is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

Medium
203

A retail company is deploying a read-heavy product catalog on Amazon Aurora MySQL. The primary instance is heavily loaded with read traffic, and the team wants to offload reads to Aurora Replicas while keeping the application resilient to replica failures. The application connects using a single endpoint. Which two actions should the team take to meet these requirements? (Choose two.)

Medium
204

A claims workflow uses an RDS MySQL database and must remain available during an Availability Zone failure with minimal application changes. What should the architect enable?

Medium
205

A company stores sensitive documents in an Amazon S3 bucket and must ensure that every object is encrypted at rest with keys that the company can audit and rotate. The security team also wants to detect and automatically respond if anyone attempts to disable encryption on the bucket. Which approach best satisfies these goals?

Easy
206

Your EC2 instances run in private subnets with no NAT gateway. The instances use the AWS SDK to call STS AssumeRole to obtain temporary credentials for other services. Application logs show errors like: "EndpointConnectionError: Could not connect to https://sts.<region>.amazonaws.com". Which change most directly resolves this while keeping instances private?

Medium
207

A ticket booking system stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured? The architecture review board prefers a managed AWS-native control.

Medium
208

A financial services firm runs a containerized risk-analysis platform on Amazon EKS. The containers are stateless and the platform runs continuously, but the firm wants a pricing model that reduces compute cost for the steady baseline while still allowing occasional short bursts above the baseline. Which combination of actions best achieves this?

Hard
209

A developer accidentally corrupts part of a production Amazon RDS database, and the issue is discovered 45 minutes later. The team needs to restore the database to the state immediately before the change. Which two actions should be part of the recovery plan? Select two.

Easy
210

Account 3000 owns a customer-managed KMS key (key-K). A data processing team in account 4000 needs to decrypt data encrypted with key-K. The role in account 4000 already has an identity policy allowing kms:Decrypt on key-K. Despite this, decrypt requests fail with an AccessDenied error referencing KMS. What is the most likely missing authorization step?

Medium
211

A latency-sensitive video platform uploads large files to S3 from users around the world. Which two features can improve upload performance?

Hard
212

A development team expects their EC2 utilization to average about 40% of capacity across the next year. They want to lower costs but need flexibility to change instance families and sizes as requirements evolve (for example, moving from compute-optimized to memory-optimized instances). Which AWS purchasing commitment best meets the goal of reducing cost while keeping flexibility?

Medium
213

Based on the exhibit, an application role in Account B can reach an S3 bucket in Account A, but reads fail with AccessDenied on KMS. The bucket objects use SSE-KMS with a customer managed key in Account A. What change is required so the application can decrypt the objects while keeping the access restricted?

Hard
214

A retail analytics table stores events in Amazon DynamoDB with partition key tenantId and sort key eventTime. During a promotion, one tenant generates most writes and repeatedly polls the same latest-status items, causing throttling on a single partition key and high latency on reads. The business can tolerate read results that are a few seconds stale. Which two changes will most effectively reduce throttling and latency? Select two.

Hard
215

A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first? The architecture review board prefers a managed AWS-native control.

Hard
216

A media company serves versioned JavaScript and CSS files from Amazon S3 through CloudFront. After each release, the cache hit ratio drops sharply because the same distribution also fronts a personalized API path, and the current cache policy forwards cookies, all query strings, and several headers to every origin request. The static assets already use content-hashed filenames. Which two changes will most directly improve cache hit ratio for the static assets without changing the application behavior? Select two.

Hard
217

A company runs a real-time bidding platform on Amazon EC2 instances that must respond within milliseconds. The workload is highly variable, with unpredictable spikes during business hours. The company wants to minimize costs while ensuring the application always has enough capacity to handle sudden traffic surges. Which pricing model should they use?

Medium
218

Your media processing pipeline writes original uploads to an S3 bucket and later generates derivative files. An operator accidentally deletes a subset of original uploads in production. You need to (1) restore the deleted objects with minimal data loss and (2) protect against both regional disasters and future operator mistakes. The company requires recovery even if objects are deleted and later overwritten. What is the most effective change to meet these requirements?

Medium
219

A patient portal must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The design must avoid adding custom operational scripts.

Hard
220

A financial services firm runs a three-tier web application on AWS. The security team wants to ensure that only the application tier can connect to the database tier on TCP port 5432, and that no other subnet can initiate connections to the database. The database runs on Amazon RDS for PostgreSQL in a dedicated subnet group. Which combination of controls enforces this requirement with the LEAST administrative effort?

Hard
221

A company has a steady-state workload running on Amazon EC2 instances that must run 24/7 for the next 3 years. The workload uses a consistent instance family and size across multiple Availability Zones. The company wants to achieve the maximum possible discount and is willing to make an upfront payment. Which purchasing option should a solutions architect recommend?

Medium
222

A high-volume analytics dashboard writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate? The design must avoid adding custom operational scripts.

Medium
223

A company runs a batch processing job on Amazon EC2 that takes about 4 hours to complete. The job can be interrupted and resumed from checkpoints. The company wants to minimize compute costs. Which pricing model is MOST cost-effective?

Medium
224

A document portal needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable?

Hard
225

A healthcare provider runs a patient-record API on Amazon EC2 instances behind an Application Load Balancer in one AWS Region. The API reads from an Amazon RDS for MySQL DB instance. The provider must be able to continue serving read traffic if the primary database instance fails, and must minimize the time the application is unavailable. Which change should a solutions architect make?

Medium
226

A company stores RDS database credentials in AWS Systems Manager Parameter Store as SecureString parameters. The security team requires that database passwords rotate automatically every 30 days. Which change should a solutions architect recommend?

Medium
227

Based on the exhibit, an application in the same AWS account can upload and read objects in an S3 bucket encrypted with a customer managed KMS key, but GetObject fails with an AccessDenied error from AWS KMS. The IAM role already has s3:GetObject, s3:PutObject, kms:Decrypt, and kms:GenerateDataKey permissions. What change most directly fixes the issue while preserving least privilege?

Hard
228

A financial services company runs a three-tier web application on AWS. The application tier consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. A security audit reveals that the application instances are receiving large volumes of unwanted traffic directly from the internet on port 443, bypassing the load balancer. The company wants to ensure that only traffic from the ALB can reach the application instances, while allowing the instances to download software updates from the internet. What should a solutions architect recommend?

Medium
229

A log archive serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit?

Medium
230

A company stores user uploads in an S3 bucket. Objects are accessed rarely after upload, but when an object is accessed, it must be retrievable quickly (minutes to a few hours). Objects must be retained for at least 18 months. The team wants to reduce storage cost while meeting these requirements. Which lifecycle configuration best fits these requirements?

Easy
231

An organization hosts the same public API in two AWS Regions. Normal traffic should go to the primary Region. If the primary endpoint becomes unhealthy, Route 53 should automatically route users to the secondary Region. What is the best Route 53 configuration approach?

Easy
232

Developers for a e-learning platform need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?

Medium
233

A dev sandbox runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost?

Medium
234

A third-party payroll vendor in another AWS account must assume a role in your account to write a daily settlement file to Amazon S3. You want to prevent confused-deputy attacks and make every assumed session traceable in CloudTrail back to an individual vendor user. Which three trust-policy or session controls should be used? Select three.

Hard
235

Based on the exhibit, the web application must remain available even if one Availability Zone fails. What is the best change to improve resilience with the least redesign?

Medium
236

An API team runs an AWS Lambda function behind an Application Load Balancer (ALB). During predictable hourly traffic spikes, p95 response latency increases due to occasional cold starts. The team wants stable latency during those spikes without permanently overprovisioning resources for all functions. Which configuration is the most appropriate way to reduce cold starts for this Lambda function?

Medium
237

A logistics firm runs an order-processing service that reads from an Amazon SQS queue and writes results to an Amazon DynamoDB table. During a marketing event, the consumer fleet scaled out aggressively and DynamoDB began returning ProvisionedThroughputExceededException errors, causing messages to be retried and some orders to be processed twice. The architects want to absorb traffic spikes without overprovisioning capacity and without duplicate processing. Which combination of changes should they make?

Hard
238

Several EC2 instances in different Availability Zones need to read and write the same shared file system. The file storage should stay available if one AZ has a problem. Which service should the team choose?

Easy
239

A SaaS vendor will access your AWS resources by assuming an IAM role in your account. You want to prevent confused-deputy attacks and ensure the vendor can only assume the role using an agreed external identifier. Your role trust policy currently allows sts:AssumeRole from the vendor’s principal, but it does not include any external ID protection. Which change is the best next step?

Medium
240

A warehouse integration service must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable?

Hard
241

A company has a VPC with a CIDR block of 10.0.0.0/16. They need to allow an on-premises data center (192.168.0.0/24) to access a web application running on EC2 instances in a private subnet. The security team wants to ensure that only HTTP and HTTPS traffic from the on-premises network is allowed, and that the traffic is encrypted in transit. Which combination of AWS services should they use?

Hard
242

A team needs a relational database solution that can automatically fail over to a standby instance if the primary database becomes unavailable. They want the standby to be located in a different Availability Zone. Which RDS/Aurora configuration best satisfies this requirement?

Easy
243

Your web application runs on EC2 instances behind an Application Load Balancer (ALB). During traffic spikes, p95 response time increases, but average CPU utilization remains below 40%. The current Auto Scaling policy scales based on average CPU%. What should you change to improve performance during spikes?

Easy
244

A healthcare analytics platform processes streaming records with an AWS Lambda function that writes results to an Amazon DynamoDB table. The pipeline must not lose records if the function throws an error, and the operations team wants to inspect and reprocess failed records without writing custom retry code. Which approach should the solutions architect use?

Hard
245

A financial services firm runs a critical API on Amazon EC2 instances behind a Network Load Balancer. The API must handle a sudden loss of one Availability Zone and continue serving traffic with no manual failover. The instances are in an Auto Scaling group that currently uses a single subnet in one Availability Zone. Which change should the architect make?

Medium
246

A test environment runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost?

Medium
247

A trading dashboard runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The architecture review board prefers a managed AWS-native control.

Medium
248

A retail company runs an e-commerce platform on a fleet of Amazon EC2 instances behind an Application Load Balancer. Traffic follows a predictable pattern: high during business hours and very low overnight. The operations team wants to reduce EC2 costs without affecting availability during peak hours. The instances currently run continuously and are managed by an Auto Scaling group with a minimum capacity of 4 and a maximum of 20. Which solution will meet these requirements MOST cost-effectively?

Medium
249

A media archive needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable? The design must avoid adding custom operational scripts.

Hard
250

An event-driven order processing service consumes messages from an Amazon SQS Standard queue. After a deployment, about 1% of messages start failing validation because a required field is missing. The consumer catches the exception and returns control, so the messages are retried. However, those poison messages keep reappearing and repeatedly consuming processing time for hours, delaying handling of valid messages. What is the most resilient way to handle the poison messages while keeping the system available?

Medium
251

A order processing API must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

Hard
252

A claims workflow uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The architecture review board prefers a managed AWS-native control.

Hard
253

An application uses an Amazon RDS Multi-AZ DB instance. During a failover test, connections fail until the application is restarted, even though the database comes back online. Which two changes should the team make to improve resilience during failover? Select two.

Medium
254

A startup runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from specific IP addresses. Which AWS service should be used to meet these requirements?

Easy
255

A data lake stores raw files in a single Amazon S3 bucket that is shared by three internal analytics teams. Each team should access only its own prefix, and the company wants to eliminate ACL management because objects come from multiple producers. Which three changes should the architect make? Select three.

Medium
256

A solutions architect is designing a high-performance computing (HPC) workload that requires a shared file system with high throughput and low latency for thousands of compute instances. The workload also requires a caching layer to accelerate repeated reads of the same data. Which two AWS services should be combined to meet these requirements? (Choose two.)

Hard
257

A latency-sensitive video platform uploads large files to S3 from users around the world. Which two features can improve upload performance? The architecture review board prefers a managed AWS-native control.

Hard
258

An Auto Scaling group behind an Application Load Balancer frequently replaces new EC2 instances. The application needs ~6 minutes to warm up after instance launch. However, the ALB target group health checks start immediately and mark the targets unhealthy until the application is ready. Because the targets become unhealthy early, the Auto Scaling group then terminates the instances and launches replacements, creating a repeated unhealthy/termination loop. What configuration change will most directly improve recovery by preventing premature ASG termination while the application is warming up?

Medium
259

A startup runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. Traffic is steady during the day but drops to almost zero overnight, and the team wants to reduce compute cost without manual intervention or a service interruption. Which action should the team take?

Easy
260

A compute workload uses temporary scratch space for intermediate results (reproducible), and it can tolerate data loss if the instance is terminated. The workload benefits from very high local I/O throughput. Which storage option is the best fit for the scratch data?

Easy
261

A company runs an internet-facing API in two AWS Regions. Route 53 currently uses simple routing to a primary Application Load Balancer (ALB) DNS name. When the primary Region experiences an outage, customers wait a long time because the DNS entry is not changed automatically. The team wants automatic failover: if the primary Region ALB health check fails for a sustained period, Route 53 should route users to the secondary Region ALB. Which Route 53 approach best meets this requirement?

Medium
262

A global mobile game backend serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The architecture review board prefers a managed AWS-native control.

Medium
263

You use Amazon CloudFront in front of a private content S3 origin. To mitigate an OWASP Top 10 issue, you created a WAF web ACL and associated it to the CloudFront distribution, but attacks are still reaching the origin. CloudWatch logs show the web ACL rules never match for the CloudFront requests. What is the most likely configuration mistake?

Medium
264

A logistics company runs a REST API on Amazon ECS using the Fargate launch type behind an Application Load Balancer. The API's response times are acceptable, but the operations team wants to reduce the number of database calls per request by caching frequently accessed reference data in memory inside the tasks. The data changes infrequently and slight staleness is acceptable. Which approach best meets these requirements?

Medium
265

Based on the exhibit, which change will most improve the CloudFront cache hit ratio for the static assets while still serving the same files to all users?

Hard
266

A high-volume analytics dashboard writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate?

Medium
267

A team wants to delegate IAM management to developers, but must ensure developers can never grant themselves permissions beyond a specific limit. Which AWS mechanism best matches this requirement?

Easy
268

A web application uses an Amazon Aurora DB cluster. The workload is becoming read-heavy, and the application team wants to increase read throughput without changing the database schema. They can adjust the application to route reads differently. What should they do?

Easy
269

Your company currently uses an Application Load Balancer (ALB) in front of a service that receives a large number of TCP and UDP packets (including UDP-based telemetry). During load tests, you need to support both TCP and UDP traffic at high throughput while keeping stable IP endpoints for a downstream firewall allowlist. Which change best meets these requirements?

Medium
270

A company runs an internal analytics application on Amazon RDS for PostgreSQL. The database is used heavily from 08:00 to 18:00 on weekdays, but outside those hours it receives almost no queries. The company must keep the database available at all times and cannot tolerate downtime during business hours. The team wants to reduce the cost of running this database. Which approach is the MOST cost-effective while meeting the availability requirement?

Hard
271

A company runs a two-tier web application on Amazon EC2 instances in a public subnet. The EC2 instances must access an Amazon Aurora MySQL DB cluster in private subnets. A security engineer must ensure that only the web tier can reach the database on port 3306, and that no other resources in the VPC can connect. Which combination of security group configuration and subnet placement should the engineer implement?

Medium
272

A mobile app reads the same product catalog items repeatedly throughout the day. The DynamoDB table is already properly keyed, but read latency is still a problem during sales events. The team can tolerate eventually consistent reads and wants the least disruptive change. What should they add?

Medium
273

A claims portal stores audit logs in S3. The compliance team requires that logs cannot be overwritten or deleted for seven years. What should be configured?

Medium
274

A media company runs a nightly batch job that processes video thumbnails. The batch can be interrupted at any time, and workers can resume automatically from checkpoints (a termination does not corrupt progress). The business goal is the lowest possible compute cost, and occasional interruptions are acceptable as long as the job continues automatically. Which approach is most cost-optimized?

Medium
275

A data engineering team runs a nightly ETL job on EC2. The job can be checkpointed every 5 minutes and can be retried from the last checkpoint if the instance terminates. The job runtime varies from 2 to 4 hours, and the team has no need for a specific instance type, as long as it completes before 7:00 AM local time. They currently run the job on On-Demand EC2, leading to high monthly compute cost. Which change best reduces cost while maintaining the business deadline?

Medium
276

A healthcare company needs to store patient records in Amazon DynamoDB. The records must be highly available and durable across multiple Availability Zones. The company also requires the ability to recover the table to any point in time within the last 35 days in case of accidental writes or deletions. Which solution meets these requirements?

Medium
277

A media company serves video thumbnails from an Amazon S3 bucket in us-east-1 to viewers across Europe and Asia. The thumbnails are immutable after upload and are requested repeatedly by the same users. The company wants to reduce latency for the global audience and reduce data transfer costs, and it does not want to modify application code. Which solution meets these requirements with the LEAST operational effort?

Hard
278

A company stores critical documents in an Amazon S3 bucket in the us-east-1 Region. The documents must survive an unlikely loss of the entire us-east-1 Region. The company wants a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 1 hour. What should the solutions architect recommend?

Medium
279

A healthcare company runs a patient portal on Amazon EC2 instances behind an Application Load Balancer across two Availability Zones. A new compliance rule requires that if an entire Availability Zone fails, the portal must remain available with no manual intervention. The EC2 instances are stateless and store no session data. Which design change should the architect implement to meet this requirement?

Medium
280

A retail company runs a read-heavy product catalog on Amazon RDS for MySQL. During flash sales, read replicas lag behind the primary and the application serves stale prices. The team wants to scale read traffic while ensuring the application reads the most current data for price lookups. Which solution should a solutions architect recommend?

Easy
281

A retail analytics app uses Amazon RDS for PostgreSQL. Read traffic is growing, and the database CPU spikes mainly due to SELECT-heavy workloads. Writes are less frequent, and the app can tolerate eventually consistent reads for the reports. What is the most appropriate AWS-native way to improve read performance with minimal application changes?

Easy
282

A patient portal must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The team wants the control to be enforceable during normal operations.

Hard
283

A team accidentally updates critical rows in an Amazon RDS for PostgreSQL database. Automated backups are enabled. They need to recover the data to the exact state as of 90 minutes ago. They also cannot risk interrupting the current production database instance while investigators validate the restored data. Which recovery strategy best meets these constraints?

Medium
284

A company has a steady, predictable workload that must run continuously (24/7) in a single AWS Region. The team wants the lowest cost option available for this steady usage, but also expects they may choose different EC2 instance families in the future (without re-buying compute discounts). Which AWS purchase option best meets these goals?

Easy
285

A company hosts a public-facing static website and a set of downloadable software packages. Users are distributed globally, and the packages are large, so the company wants to reduce data transfer costs and improve download latency. The content changes only when a new release is published, a few times per month. Which solution should a solutions architect recommend?

Medium
286

You want to protect an Application Load Balancer (ALB) from common web exploits using AWS WAF. The application is not using CloudFront. Which AWS WAF deployment scope should you choose so the WAF rules apply to the ALB?

Easy
287

A solutions architect is optimizing the cost of a serverless data-processing pipeline. The pipeline uses AWS Lambda functions that process messages from an Amazon SQS queue and write results to Amazon DynamoDB. The team observes that Lambda invocations spike unpredictably, DynamoDB is provisioned with high capacity that is often idle, and the SQS queue occasionally accumulates a large backlog. Which two changes will most directly reduce cost while preserving the pipeline's ability to handle bursts? (Choose two.)

Hard
288

A mobile banking backend uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend? The design must avoid adding custom operational scripts.

Hard
289

A team runs an application on Amazon EC2 that connects to an Aurora database. The database password must rotate automatically every 30 days, and the application should retrieve the current secret at runtime using an IAM role. Which AWS service is the best fit?

Medium
290

Match each database availability event to the AWS failover behavior that best describes it.

Hard
291

Based on the exhibit, the company wants to lower CloudWatch and EC2 monitoring costs. Auditors require logs to be retained for 90 days, but operations only uses detailed per-instance metrics during rare troubleshooting events. Which change best reduces recurring cost while preserving the required visibility?

Hard
292

A startup runs a public web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in a public subnet and currently allow SSH from 0.0.0.0/0 so that engineers can troubleshoot. Auditors flagged this exposure. Engineers still need occasional shell access to the instances, and the company wants the access to be auditable per engineer without managing bastion hosts or distributing key pairs. Which solution best meets these requirements?

Easy
293

A service performs many repeated read requests for the same DynamoDB items. The reads are latency-sensitive, but the application can tolerate slightly stale data. Which AWS service is the best fit to reduce read latency?

Easy
294

Order the steps to create a static website using Amazon S3 and CloudFront.

Medium
295

A Lambda function for a claims portal needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?

Medium
296

A logistics company runs a stateless order-tracking API on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The architect must ensure the API survives the loss of an entire Availability Zone and that unhealthy instances are replaced automatically. (Choose two.)

Medium
297

A company runs a critical API on Amazon EC2 behind an Application Load Balancer in a single AWS Region. The business requires the API to keep serving traffic if an entire Availability Zone becomes unavailable, and the recovery must not depend on any manual step. The database is Amazon RDS for PostgreSQL configured as a Single-AZ instance. Which combination of changes should a solutions architect implement to meet these requirements?

Hard
298

A company runs a containerized API on Amazon ECS with AWS Fargate. Traffic is highly variable: it peaks during business hours and drops to near zero overnight. The team wants to pay only for what they use while keeping the API responsive during peaks. Which approach BEST optimizes cost for this workload?

Hard
299

A SaaS provider runs a multi-tenant application on Amazon EC2 instances behind an Application Load Balancer. Tenants are identified by a subdomain, and each tenant's data is stored in a separate Amazon S3 bucket. The provider wants HTTPS with a single certificate, automatic renewal, and the ability to add new tenant subdomains without redeploying or replacing the certificate. Which solution meets these requirements?

Hard
300

An application encrypts data directly with AWS KMS using an encryption context. Your KMS key policy includes a condition that allows kms:Decrypt only when the encryption context contains: "purpose" = "myapp-secrets" After a deployment, decryption fails. CloudTrail shows kms:Decrypt was called, but it was denied by the key policy due to the encryption context condition. What is the best fix?

Medium
301

A company runs a stateless web application on a fleet of EC2 instances behind an Application Load Balancer. The instances are in an Auto Scaling group that scales between 4 and 40 instances, and utilization is highly variable. The company wants to reduce compute cost while keeping the ability to change instance families and Regions over the next three years. Which purchasing strategy should the company use?

Medium
302

A company uses AWS Organizations to manage multiple AWS accounts. A security engineer needs to prevent any IAM user in the organization from disabling AWS CloudTrail logging in any account. The solution must apply automatically to all existing and future accounts. What should the security engineer do?

Hard
303

Based on the exhibit, the database must fail over automatically if the primary Availability Zone goes down. Which solution should the architect choose?

Easy
304

A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered?

Medium
305

A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The architecture review board prefers a managed AWS-native control.

Hard
306

A worker service consumes messages from an Amazon SQS queue. Some messages are malformed and always fail validation. The worker retries, but it keeps reprocessing the same bad messages and consumes processing capacity that should be used for valid work. What is the best solution to prevent “poison messages” from blocking progress?

Easy
307

A team runs a CPU-intensive image processing service on Amazon EC2. The service spends most of its time resizing and compressing images, and the team wants the best price-performance starting point for compute-heavy work. Which EC2 instance family should they choose?

Easy
308

A Lambda function behind an API needs consistent low latency. Traffic normally drops to near zero, then spikes several times per hour. During spikes, the p95 latency often spikes above 800 ms due to cold starts. The team wants to keep using Lambda (no containers) but minimize cold start impact during predictable spikes. What is the best AWS configuration to meet this goal?

Medium
309

A warehouse integration service receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The design must avoid adding custom operational scripts.

Medium
310

You use a customer managed AWS KMS key (CMK) to encrypt objects in an S3 bucket using SSE-KMS. A specific IAM role must be able to decrypt objects. Where should you grant kms:Decrypt permissions so that the role can decrypt data encrypted with that CMK?

Easy
311

A test environment stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost?

Medium
312

A company is designing a secure architecture for an internal microservices application running on Amazon ECS with the Fargate launch type. The security team wants each microservice to have its own fine-grained permissions to access specific AWS resources, and wants to avoid storing long-term AWS credentials in the container images or task definitions. The company also wants to encrypt data in transit between services. (Choose two.)

Hard
313

A media company stores video files in an Amazon S3 bucket in the us-east-1 Region. The company wants to ensure that the files are automatically replicated to us-west-2 for disaster recovery, and that replication occurs within 15 minutes of upload. Which solution meets these requirements with the LEAST operational overhead?

Medium
314

Your AWS Organization uses a Service Control Policy (SCP) that includes a Deny statement for secretsmanager:GetSecretValue for all member accounts in the "Finance" OU when requests are made outside us-east-1. An application role has an IAM policy that allows secretsmanager:GetSecretValue for the required secret in us-west-2. In us-west-2, requests fail with AccessDenied. What is the most appropriate action?

Medium
315

A company runs its customer-facing web app on EC2 behind an Application Load Balancer. The database is Amazon RDS for PostgreSQL. The requirement is that if a single Availability Zone fails, the database must automatically fail over within the same AWS Region with minimal application changes. Which database setup best meets this requirement?

Easy
316

A web application for a order processing API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

Medium
317

A solutions architect is designing an S3 bucket for a healthcare document service. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?

Medium
318

A company is deploying a stateless web application on Amazon ECS with Fargate. The application must be resilient to individual task failures and Availability Zone failures. Which three steps should the company take to achieve this resilience? (Choose three.)

Medium
319

Your company hosts an internal API in two AWS Regions. You want Amazon Route 53 to automatically send traffic to the secondary Region if the primary Region’s endpoint becomes unhealthy. Which Route 53 configuration best meets this requirement?

Easy
320

A partner company needs read-only access to reports in an S3 bucket for a e-learning platform. The partner has its own AWS account. What is the most secure scalable access pattern?

Medium
321

A media company runs a 24/7 ingestion API on EC2 behind an Application Load Balancer and a nightly transcoding job that can resume from checkpoints. The API fleet runs at roughly 65 percent CPU all day, while the batch workers sit idle most of the time. The company wants to cut compute cost without risking the API. Which two changes should they make? Select two.

Hard
322

A partner company needs read-only access to reports in an S3 bucket for a customer analytics portal. The partner has its own AWS account. What is the most secure scalable access pattern?

Medium
323

A company runs a containerized order-processing service on Amazon ECS with the Fargate launch type. The service scales out during business hours and scales down to a small baseline overnight. Usage is expected to remain stable for the next two years, and the team wants to reduce Fargate cost without managing any servers. Which action should the solutions architect take?

Medium
324

Company A runs an internal app in account A. The app needs to upload objects to an S3 bucket in account B. When the app calls S3, it receives AccessDenied for s3:PutObject. The team already created an IAM role in account B named UploadRole with a policy allowing s3:PutObject. They did not yet set up any trust relationship. Which change most directly fixes the access problem with least privilege?

Medium
325

A gaming company uses Amazon DynamoDB to store player session data. The table has a partition key of PlayerID and a sort key of SessionStartTime. The company needs to retrieve all sessions for a specific player within a date range, sorted by session start time. The table is large and the company wants to minimize read latency. Which approach should they use?

Hard
326

A public API for a image sharing application is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used? The design must avoid adding custom operational scripts.

Medium
327

A distributed analytics engine runs 12 EC2 instances in one Availability Zone. The nodes exchange thousands of tiny messages per second and must keep jitter as low as possible. The current design launches the instances across multiple placement groups and uses general-purpose burstable instances. Which two changes will most directly lower east-west network latency and variability? Select two.

Hard
328

A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The architecture review board prefers a managed AWS-native control.

Medium
329

A production application stores critical data on an Amazon EBS volume. The team wants a simple backup method that allows the volume to be restored later if the server is lost. What should they use?

Easy
330

A media processing service runs ECS tasks in multiple Availability Zones. Each task must read and write the same shared filesystem with low latency because tasks stream intermediate artifacts to other tasks. The team currently mounts an EBS volume per task, and cross-AZ tasks frequently cannot see each other’s files. Which option best resolves the shared filesystem requirement while supporting high-performing access?

Medium
331

A team wants detective controls to investigate suspected exfiltration from an S3 bucket. They need to know when objects are accessed (GetObject) and also when new encrypted objects are written. They already enabled AWS CloudTrail for management events, but their investigation shows no visibility into object-level reads/writes in the logs they review. Which CloudTrail configuration change most directly provides the missing object-level visibility?

Medium
332

A trading dashboard stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured? The architecture review board prefers a managed AWS-native control.

Medium
333

A high-frequency trading analytics service runs on several EC2 instances in the same Availability Zone. The application exchanges small messages between nodes and is sensitive to microsecond-level network latency. Which design best meets the requirement?

Medium
334

A marketing site has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations?

Medium
335

A genomics company stores 400 TB of compressed reference data in Amazon S3. Researchers in an on-premises lab must run high-throughput reads of this data over a 10 Gbps AWS Direct Connect connection. The team observes that reads are slower than expected and wants to maximize throughput per S3 request while minimizing request costs. Which S3 feature should they implement?

Hard
336

You manage multiple AWS accounts under AWS Organizations. A compliance requirement states: no account is allowed to create new IAM access keys for IAM users. Local administrators may attempt to override permissions. Which mechanism should you use to enforce this guardrail across all accounts?

Easy
337

A financial analytics platform runs a stateless containerized service on Amazon ECS with AWS Fargate tasks spread across three Availability Zones. The service reads from an Amazon Aurora MySQL cluster and must continue serving read traffic if one Availability Zone fails. The team wants the read capacity to remain available with the least operational overhead and no changes to application connection strings during a zone failure. Which approach meets these requirements?

Hard
338

Based on the exhibit, a DynamoDB-backed event processing system is throttling during a promotion. The table uses tenantId as the partition key and eventTime as the sort key. One tenant accounts for most of the write traffic, and the application must preserve fast lookups for that tenant without relying on a single hot partition. What change is the best fix?

Hard
339

A microservice needs to read exactly one secret value from AWS Secrets Manager. Which IAM permission statement provides the best least-privilege approach to allow the microservice to retrieve that secret value?

Easy
340

A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ASG uses the ALB target group health checks to decide when instances are healthy (for example, by using the ELB/target-group health check integration). During a deployment, the ASG performs instance replacement. Shortly after the deployment starts and while new instances are still bootstrapping, CloudWatch shows the ALB target group briefly has zero healthy targets, and users intermittently receive 502 responses. Which ASG deployment configuration best reduces the chance that there will be a period with zero healthy ALB targets, while still keeping failover behavior resilient?

Medium
341

A internal reporting portal has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances? The architecture review board prefers a managed AWS-native control.

Hard
342

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be accessible only to users from a specific IP range, and the company wants to protect against common web exploits such as SQL injection and cross-site scripting. The company also wants to monitor and rate-limit requests from specific IP addresses. Which solution should a solutions architect implement?

Medium
343

Based on the exhibit, the company stores application logs in Amazon S3 for 400 days. The logs are read heavily for the first 30 days, occasionally for the next 90 days, and very rarely after that. Retrieval after day 120 can take up to several hours, but the data must remain available until day 400. Which lifecycle policy is the most cost-effective fit?

Hard
344

A Lambda function processes CPU-heavy JSON transformations and often runs slower than expected. The team wants to improve performance without changing the code. What should they try first?

Easy
345

A financial services company stores monthly regulatory reports in an Amazon S3 bucket. The reports are accessed frequently for the first 60 days after creation for audits and internal review. After that period, they are almost never accessed but must be retained for seven years and retrieved within 12 hours if a regulator requests them. The compliance team requires that the objects remain in a single bucket and that retrieval costs be minimized. Which storage solution meets these requirements MOST cost-effectively?

Hard
346

A test environment has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations?

Medium
347

A legacy market-data service runs on EC2 and exposes a custom TCP protocol. Clients must connect over TCP with very low latency, and the team wants static IP addresses at the load-balancing layer. Which AWS service is the best fit?

Medium
348

A claims workflow uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The team wants the control to be enforceable during normal operations.

Hard
349

A startup runs a small internal tool on a single Amazon EC2 instance that uses an instance store volume for its database files. After a routine host maintenance event, the instance rebooted and the database was empty. The team wants the data to persist independently of the instance lifecycle and to survive a stop-and-start of the instance. What should they change?

Easy
350

A database administrator wants a regular backup of an Amazon RDS database so the team can restore to a recent point in time if needed. Which AWS feature should they use?

Easy
351

A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include?

Medium
352

A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost? The architecture review board prefers a managed AWS-native control.

Medium
353

An application runs on EC2 instances in private subnets behind an Application Load Balancer (ALB). Security groups allow inbound HTTPS (443) from the ALB’s security group to the instance security group, and outbound from instances is set to allow ephemeral ports. Despite this, clients see connection timeouts. After reviewing network ACLs, you find the NACL associated with the instance subnet has an inbound allow for destination port 443, but it does not have a corresponding outbound allow for ephemeral ports. What is the most likely reason the traffic fails, and what should be updated?

Medium
354

A company runs a three-tier web application on AWS. The database tier uses Amazon Aurora MySQL, and the application tier runs on Amazon EC2 instances behind an Application Load Balancer. A security audit reveals that the database credentials are stored in plaintext in a configuration file on the EC2 instances, and the same credentials have been in use for over a year. The security team must eliminate hardcoded credentials and ensure automatic rotation of the database password every 30 days without modifying application code to handle rotation events. Which solution meets these requirements with the LEAST operational overhead?

Medium
355

Based on the exhibit, a company wants EC2 instances in private subnets to access Amazon S3 without using a NAT gateway, and bucket access must be allowed only when requests come through the approved VPC endpoint. Which design is the most appropriate?

Hard
356

A solutions architect is designing a high-performance architecture for a real-time analytics application. The application ingests a continuous stream of data from thousands of IoT devices. The data must be processed in near real-time, and the results must be stored in a durable, scalable data store for later analysis. The architect needs to choose AWS services that can handle the ingestion and processing of the stream. (Choose two.)

Medium
357

A media company stores daily financial exports in Amazon S3. The files must be protected against accidental overwrite or deletion, and the business also wants a second copy in another Region for recovery after a regional outage. Which two actions should the architect take? Select two.

Medium
358

An order-processing application becomes slow when traffic spikes. The frontend should stay responsive even if downstream workers are temporarily overloaded. What should the team add to the design?

Easy
359

A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The architecture review board prefers a managed AWS-native control.

Medium
360

A public API for a financial reporting platform is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

Medium
361

An S3 bucket uses a customer-managed KMS key as the default for SSE-KMS encryption. A service role will upload objects using s3:PutObject. Assuming the role already has permission to write to the bucket, which KMS permission is most directly required for the role to let S3 encrypt the object during upload?

Easy
362

A serverless order-ingestion API writes directly to a database. During traffic spikes, the database occasionally throttles, Lambda retries create duplicate order records, and some requests time out. Which two changes best improve buffering and safe retry behavior? Select two.

Medium
363

A CI pipeline needs to upload build artifacts only to s3://ci-artifacts/uploads/*. You also want the pipeline to list only objects under uploads/ to verify that the upload succeeded. Which IAM policy approach is the best fit for least privilege?

Easy
364

A web service runs continuously on AWS 24/7. The team expects steady compute usage for the next 12–24 months, but may change instance families/sizes as performance tuning continues. Which purchase option best reduces cost while keeping flexibility to change instance types?

Easy
365

A company runs a production MySQL database on Amazon RDS in us-east-1. A read replica exists in us-west-2 for disaster recovery. The primary region experiences a complete outage. Which of the following describes the correct procedure to restore database service using the cross-region read replica?

Hard
366

A company runs a stateless web tier on a fleet of On-Demand EC2 instances behind an Application Load Balancer. Traffic is steady and predictable, and the team has committed to running this tier for the next three years with no planned architectural changes. Management wants the lowest possible compute cost while preserving the ability to change instance families during the term if a better price-performance option emerges. Which purchasing approach best meets these requirements?

Medium
367

A solutions architect is designing an S3 bucket for a claims portal. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?

Medium
368

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The architecture review board prefers a managed AWS-native control.

Hard
369

An orders service consumes payment instructions from an Amazon SQS queue. Sometimes the consumer times out after applying the payment but before deleting the SQS message. As a result, the same payment instruction is processed again. Which design change most directly prevents duplicate side effects caused by message retries?

Easy
370

Account B has an IAM role that includes kms:Decrypt for a specific KMS key ARN in account A. However, when the role tries to read an S3 object encrypted with that CMK, the application fails with AccessDenied: not authorized to perform kms:Decrypt. CloudTrail shows the KMS API call is denied by key policy. What is the most secure and correct fix?

Medium
371

A public API is deployed in two AWS Regions: us-east-1 (primary) and us-west-2 (secondary). The team wants Route 53 to automatically route users to the secondary region if the primary API becomes unhealthy. They will use Route 53 health checks that monitor the API’s /status endpoint over HTTPS. Which Route 53 configuration most directly implements this failover behavior?

Medium
372

A regional web application for a inventory service must fail over automatically to a secondary Region if the primary endpoint becomes unhealthy. Which two services or features are required? The team wants the control to be enforceable during normal operations.

Hard
373

A financial services company runs a critical application on Amazon EC2 instances in an Auto Scaling group. The application writes to an Amazon RDS for MySQL database. The company needs a recovery point objective (RPO) of 1 second and a recovery time objective (RTO) of 1 minute for the database in the event of a Regional disaster. Which solution meets these requirements?

Hard
374

Based on the exhibit, what is the most appropriate change to restore application access while keeping encryption at rest with customer-managed KMS controls?

Medium
375

A media company uses CloudFront in front of an S3 bucket origin for video thumbnails. They want to prevent users from bypassing CloudFront and accessing the S3 bucket directly, while still allowing CloudFront to fetch objects. What is the best option?

Easy
376

A payments platform requires disaster recovery across Regions. Requirements: RPO of 15 minutes and RTO of about 1 hour. The business cannot afford full duplicate capacity in both Regions all the time, but the team wants automated readiness so failover is mostly operationally guided rather than a slow rebuild. Which DR strategy is the best fit?

Medium
377

Your application uses ElastiCache Redis as a cache for user profiles stored in DynamoDB. You must ensure that when a profile is updated, subsequent reads see the latest value quickly. Which cache strategy is generally the best fit for this requirement?

Easy
378

A financial services firm runs a latency-sensitive trading application on Amazon EC2 instances distributed across three Availability Zones behind a Network Load Balancer. The application must continue serving traffic with no manual intervention if an entire Availability Zone becomes impaired, and each instance must receive a fair share of connections. Which combination of features meets these requirements?

Hard
379

A company runs a stateful web application on a fleet of Amazon EC2 instances in an Auto Scaling group. The application stores session state locally on each instance. During an Availability Zone failure, the Auto Scaling group replaces the unhealthy instances in a different AZ, but users lose their sessions and must log in again. The company wants to make the application resilient to AZ failures without requiring users to re-authenticate. Which solution should a solutions architect recommend?

Hard
380

An ECS service runs on EC2 capacity. During peak traffic, tasks frequently wait for available container instances. The team wants faster scale-out for the underlying EC2 capacity when tasks increase. What is the best first architectural step?

Easy
381

Based on the exhibit, the database must continue serving if the current Availability Zone fails. What should you change?

Easy
382

A company stores 500 TB of archival data in Amazon S3. The data is accessed only once a year for compliance audits. The company wants the most cost-effective storage solution that still allows retrieval within 48 hours. Which S3 storage class should they use?

Easy
383

A inventory service exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most?

Easy
384

A media company has users around the world uploading 1 to 5 GB files directly to a single Amazon S3 bucket. Upload times are slow from distant regions, but the app must keep using S3 as the destination. What should the architects enable to improve upload performance?

Medium
385

An application uses DynamoDB to store order status. Reads happen extremely frequently for the same few keys (for example, the most recent orders), and the team wants lower read latency without changing the table’s partition key design. Which AWS service best fits this requirement?

Easy
386

A web application for a mobile banking backend is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

Medium
387

Based on the exhibit, a faulty deployment corrupted production data at 10:30 UTC and the issue was discovered at 10:55 UTC. The team needs to recover the database to the last good state before the corruption. Which action should they take?

Medium
388

A travel booking site uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured? The design must avoid adding custom operational scripts.

Easy
389

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be reachable only from a specific corporate CIDR range, and the instances must not be directly reachable from the internet. Which combination of security group configurations meets these requirements?

Easy
390

A system uses multiple AWS Lambda functions behind different event sources. One Lambda occasionally spikes and causes other Lambdas to be throttled due to shared concurrency limits. Which setting best helps ensure the important Lambda keeps capacity during spikes?

Easy
391

A DynamoDB table for a retail API has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The design must avoid adding custom operational scripts.

Hard
392

A media processing pipeline uses EBS-backed storage for an application that performs sustained random I/O with low latency requirements. During peak processing windows, the team sees increased read latency and occasional timeouts at the application layer. They need predictable, high IOPS performance rather than best-effort throughput. Which EBS configuration choice is most appropriate?

Medium
393

A SaaS vendor’s automation account in Account B needs to assume a role in a customer account in Account A to read a specific S3 bucket and publish a deployment status file. The customer is worried about confused deputy attacks because multiple customers use the same vendor software. Which trust-policy design best meets the requirement?

Hard
394

An order system receives events and uses a Lambda function to write each order into a database. During traffic spikes, the database sometimes throttles, and Lambda retries lead to occasional message loss in the event flow. The team wants buffering, automatic retries, and a way to isolate messages that repeatedly fail so they can be inspected later. What design change best meets this need?

Easy
395

A company uses Amazon RDS for a PostgreSQL database powering a customer-facing application. The application’s availability depends on fast database failover with minimal manual intervention. The RDS instance currently runs as a single-AZ deployment in one DB subnet group. Which change most directly meets the goal?

Medium
396

A security analyst needs to let an external vendor (AWS account 555566667777) read data from a set of internal resources in your AWS account. You created an IAM role called VendorReadRole with a policy that allows the required API calls. However, when the vendor tries to access, CloudTrail shows the call fails at AssumeRole with: "Not authorized to perform: sts:AssumeRole". What is the most appropriate fix?

Medium
397

A public API for a e-learning platform is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

Medium
398

A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable?

Medium
399

A high-volume telemetry pipeline writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate? The design must avoid adding custom operational scripts.

Medium
400

A financial analytics firm runs a nightly batch job on a fleet of Amazon EC2 instances that read millions of small JSON objects from an Amazon S3 bucket and write aggregated results to another S3 bucket. The job currently takes over six hours and the team wants to reduce this time without modifying the application code. The S3 buckets are in the same AWS Region as the EC2 instances. Which action will most effectively improve the performance of the batch job?

Medium
401

A media company is designing a high-performance architecture to serve video content to users worldwide. The solution must minimize latency for end users and reduce the load on the origin servers. The video files are stored in an Amazon S3 bucket. Which three options should be combined to meet these requirements? (Choose three.)

Medium
402

A Lambda function for a healthcare document service needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?

Medium
403

A serverless checkout API uses AWS Lambda behind API Gateway. Every weekday at 09:00 UTC, marketing triggers a predictable surge. The first few minutes after each surge show cold-start latency, but traffic volume is forecastable and the business wants stable p95 latency. Which two changes should the team implement? Select two.

Hard
404

A company serves a public API through a CloudFront distribution. They want to automatically block common web exploits (for example, OWASP Top 10–style threats) without building custom detection logic. Which AWS service configuration best meets the goal?

Easy
405

A company runs a media-processing pipeline that ingests thousands of small files per minute into Amazon S3 and triggers AWS Lambda functions for each object. Processing each file takes 2-3 seconds, and the team is seeing throttling errors and duplicated processing under load. They want to decouple ingestion from processing, buffer bursty traffic, and avoid duplicate deliveries to Lambda. Which solution should a solutions architect recommend?

Medium
406

A trading dashboard runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include?

Medium
407

A trading dashboard stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured?

Medium
408

An internal service is hosted behind an Application Load Balancer (ALB) with targets spread across two Availability Zones. If the targets in one Availability Zone become unhealthy, the service must continue serving traffic from the healthy AZ. What change most directly improves resilience at the load-balancing layer?

Easy
409

A healthcare analytics company stores protected health information in an Amazon S3 bucket. An application running on Amazon EC2 instances in a private subnet must upload objects to the bucket using temporary credentials. The security team requires that the EC2 instances never store long-term AWS credentials on disk, and that access be limited to only the specific S3 bucket. Which solution meets these requirements?

Medium
410

A regional web application for a inventory service must fail over automatically to a secondary Region if the primary endpoint becomes unhealthy. Which two services or features are required? The design must avoid adding custom operational scripts.

Hard
411

A media company runs a stateless transcoding fleet on Amazon EC2 instances spread across three Availability Zones behind a Network Load Balancer. The fleet must keep processing jobs even if an entire Availability Zone becomes unavailable, and the architect wants to minimize manual intervention. Which combination of actions should the architect take to meet these requirements?

Medium
412

A static website uses an Amazon S3 bucket as the origin for an Amazon CloudFront distribution. The team accidentally configured the S3 bucket policy to allow s3:GetObject to Principal "*", so objects are accessible via direct S3 URLs. They want to ensure objects are retrievable only through CloudFront. What is the best corrective action?

Medium
413

A public API for a customer analytics portal is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

Medium
414

A company stores 500 TB of data in Amazon S3 Standard. The data is accessed frequently for the first 30 days after creation, then access drops to almost zero, but the data must be retained for 10 years for compliance. The company wants to minimize storage costs. Which solution is MOST cost-effective?

Medium
415

A company runs a two-tier web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The EC2 instances must access an Amazon Aurora MySQL DB cluster. A security engineer must ensure that only these EC2 instances can connect to the database, and that no credentials are stored on the instances. What should the security engineer do?

Medium
416

An event consumer sometimes processes the same SQS message more than once due to timeouts and retries. The consumer must ensure the payment is not charged twice. What design choice best addresses this requirement?

Easy
417

A inventory service uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The architecture review board prefers a managed AWS-native control.

Medium
418

A company’s private workload in a VPC uploads objects to an S3 bucket. Security requires that S3 requests are allowed only when they traverse a specific S3 Gateway VPC Endpoint (vpce-0abc123example). Which change best enforces this restriction at the S3 bucket level?

Easy
419

A media company runs a transcoding fleet on Amazon EC2 instances behind an Application Load Balancer in a single Availability Zone. The business requires the workload to survive the loss of that Availability Zone with no manual intervention and minimal downtime. The instances store intermediate files on instance store volumes and the fleet is managed by an Auto Scaling group. Which change should a solutions architect make to meet the requirement?

Medium
420

A company runs an EC2 Auto Scaling group behind an internet-facing Application Load Balancer. The security team must ensure that the instances accept HTTP traffic only from the ALB and never directly from the internet, while the ALB itself must accept traffic only from a specific corporate CIDR range. Which combination of security group configurations should a solutions architect implement?

Medium
421

A partner integration sends a custom binary TCP protocol to a service running on EC2 instances in private subnets. The partners require static endpoint IPs for allowlisting, and the application must see the original client source IP for rate limiting. Which two changes best fit the protocol and network requirements? Select two.

Hard
422

A media company runs a video transcoding pipeline on Amazon EC2 instances in a single Availability Zone. The pipeline writes intermediate files to an Amazon EBS volume attached to each instance. The company needs the pipeline to survive the failure of any single Availability Zone and to recover automatically with minimal data loss. Which change should a solutions architect make?

Medium
423

A company runs a steady-state web application on a fixed number of Amazon EC2 instances that have been running continuously for over a year. The workload is predictable and will remain in production for at least three more years. Management wants to reduce compute cost without changing the architecture. Which purchasing option should a solutions architect recommend?

Easy
424

A telemetry pipeline uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered?

Medium
425

A SaaS company uses an S3 bucket for database backups created daily. Backups are rarely restored; the company’s documented RTO is 24 hours, and the compliance policy requires backups be kept for 90 days. The team currently stores all backups in S3 Standard, which is costly. Which single lifecycle policy change is most cost-optimized while still meeting the 24-hour RTO and 90-day retention?

Medium
426

A inventory service uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured?

Medium
427

Based on the exhibit, the application team wants the database to keep the same connection endpoint during failover and to reconnect automatically after the primary instance becomes unavailable. Which change best meets the requirement?

Medium
428

A distributed system needs extremely low network latency between a set of EC2 instances running the same workload. The team wants the instances to be placed as close together as AWS allows to reduce round-trip time. Which placement strategy should the architect use?

Medium
429

A content publishing system uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The architecture review board prefers a managed AWS-native control.

Medium
430

A company runs a microservices application on Amazon ECS with AWS Fargate. The services communicate over HTTP/2 and gRPC. The architect needs to implement service-to-service communication that provides high throughput, low latency, and mutual TLS encryption. The solution must also support traffic splitting for canary deployments. Which approach should the architect take?

Hard
431

A healthcare company stores patient imaging studies in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. A security audit reveals that a former employee's IAM user still has s3:GetObject permissions on the bucket. The company wants to ensure the former employee can no longer decrypt any objects, even if they somehow regain S3 access, without affecting other users or applications. What should a security engineer do?

Medium
432

A team stores application logs in Amazon S3. They need access to the logs only occasionally for troubleshooting (infrequent access), and they want to reduce storage cost automatically over time without manually moving objects. What should they implement?

Easy
433

A internal reporting portal serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit?

Medium
434

A backup process restores a 2 TB production database from an EBS snapshot onto a new volume. During the first hours after restore, the application sees slow reads whenever previously unused blocks are accessed. What is the best way to avoid this performance issue in future restores?

Medium
435

Your global users access static images stored in S3. Origin bandwidth costs are higher than expected because CloudFront is not caching effectively. What change most directly reduces origin fetches (and typically lowers data transfer costs) without changing application logic?

Easy
436

Based on the exhibit, the application tier is not replacing unhealthy instances even though the Auto Scaling group spans two Availability Zones. What change most directly improves automatic recovery when the application process fails?

Hard
437

A team runs an EC2-based service and ships logs to Amazon CloudWatch Logs. They enabled long log retention and turned on detailed monitoring to improve troubleshooting. Their monthly CloudWatch costs have grown unexpectedly. Compliance requires that the logs remain available in CloudWatch Logs (for querying and audits) for 90 days, and alerts/alarms do not require detailed EC2 monitoring. What change best reduces cost while meeting requirements?

Medium
438

A high-volume telemetry pipeline writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate? The architecture review board prefers a managed AWS-native control.

Medium
439

A payments API requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The architecture review board prefers a managed AWS-native control.

Hard
440

A trading dashboard uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered?

Medium
441

A startup stores application configuration files in an Amazon S3 bucket. The security team wants to ensure that objects in the bucket are encrypted at rest with keys that the company manages and can rotate on its own schedule. Which S3 encryption option should a solutions architect choose?

Easy
442

A startup runs a stateless web application on a single Amazon EC2 instance in one Availability Zone. The application has become popular, and the startup wants to ensure that the application can survive the failure of an Availability Zone and can handle increased traffic. Which architecture change should the startup make FIRST?

Easy
443

An events service publishes critical notifications using Amazon SNS. Three independent downstream systems (A, B, and C) subscribe to the topic. Downstream system B sometimes fails to process certain messages (for example, it times out or returns an error while handling the message), and you want: 1) failures in B to be isolated so A and C keep processing unaffected, and 2) messages that B cannot successfully process after retries to be sent to a DLQ for B. Which design best meets these requirements?

Medium
444

A dev sandbox has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The architecture review board prefers a managed AWS-native control.

Medium
445

Based on the exhibit, what is the most appropriate fix so the workload in Account A can access the S3 bucket in Account B without using long-lived access keys?

Medium
446

A company hosts a image sharing application on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

Medium
447

A stateless web API runs on EC2 instances behind an Application Load Balancer (ALB). The Auto Scaling group (ASG) currently uses subnets from only one Availability Zone, even though the ALB spans two Availability Zones. During maintenance of that single AZ, the ALB remains up but clients see timeouts because there are no healthy targets. Which change most directly improves resilience against an AZ failure?

Medium
448

An orders service publishes payment instructions to an Amazon SQS Standard queue. A downstream consumer sometimes times out or crashes after it has partially completed processing, causing the same instruction to be processed more than once. You must keep the design resilient without attempting to guarantee exactly-once processing. Which approach best handles duplicates safely?

Medium
449

A reporting application in Account B must read files from an S3 bucket in Account A. The bucket contains objects encrypted with a customer managed KMS key in Account A. The application role in Account B already has an identity policy allowing s3:GetObject on the bucket prefix, but requests still fail with AccessDenied. Which two changes are required for the application to read the objects? Select two.

Hard
450

A marketing site runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost? The design must avoid adding custom operational scripts.

Medium
451

Your team runs a tightly coupled distributed workload (for example, synchronous training nodes) across many EC2 instances placed within a single cluster environment. The instances need low-latency networking to reduce delays at synchronization barriers. Which EC2 placement strategy should you use to improve inter-node latency?

Medium
452

A startup runs a stateless web application on a fleet of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. Traffic is steady during business hours, but the team has configured the scaling policy with a target tracking metric of average CPU utilization at 50 percent. Users report intermittent 5xx errors during sudden traffic surges. Which change will most directly improve the application's ability to absorb rapid traffic increases?

Easy
453

A financial services company runs an internal web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must authenticate employees against the corporate identity provider (IdP) that supports SAML 2.0, and the company wants to avoid managing custom sign-in code. Which solution should a solutions architect recommend?

Medium
454

A claims workflow uses an RDS MySQL database and must remain available during an Availability Zone failure with minimal application changes. What should the architect enable? The design must avoid adding custom operational scripts.

Medium
455

A CI/CD pipeline needs to deploy to your production environment. Security requires that the pipeline uses temporary credentials (not long-lived access keys) and only has permissions to read a specific set of parameters from AWS Systems Manager Parameter Store and write application logs to CloudWatch Logs. What is the best AWS approach?

Easy
456

A company runs a containerized microservices application on Amazon ECS with the Fargate launch type. The application experiences highly variable traffic, with long periods of low utilization and occasional sharp spikes. The company wants to minimize cost while ensuring the application can scale quickly during spikes. The tasks are stateless and can be restarted. Which combination of actions will meet these requirements MOST cost-effectively?

Hard
457

A healthcare company stores protected health information in an Amazon S3 bucket. Compliance requires that all data be encrypted at rest with keys that the company controls and can rotate on demand. The security team also needs to audit every use of the encryption keys and immediately revoke access for a compromised IAM role without affecting other roles. Which solution meets these requirements?

Hard
458

A retail company runs a stateless web tier on Amazon EC2 instances behind an Application Load Balancer. During flash sales, response times spike because each request triggers many database queries. The team wants to reduce database load and improve read latency for product catalog pages that change only a few times per day. Which solution is MOST appropriate?

Medium
459

Based on the exhibit, the team must restore an Amazon RDS for PostgreSQL database to the exact state just before a bad delete happened. What is the best recovery approach?

Hard
460

A company hosts a critical web application on Amazon EC2 instances in a VPC. The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. They also want to monitor and control access to the application at the HTTP/HTTPS level. Which AWS service should a solutions architect use to meet these requirements?

Medium
461

A company hosts a e-learning platform on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

Medium
462

A patient portal must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable?

Hard
463

Based on the exhibit, the team wants to minimize compute cost for a workload with a steady 24/7 baseline and a separate nightly batch job that can be interrupted and resumed from checkpoints. They also expect to change EC2 instance families during the year as performance needs evolve. Which approach is the best fit?

Hard
464

A worker consumes messages from an Amazon SQS queue. Some messages consistently fail validation and are retried until the worker can no longer process them. What is the most appropriate AWS mechanism to handle these poison messages while keeping the queue usable?

Easy
465

A retail API uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured?

Easy
466

A trading dashboard runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The team wants the control to be enforceable during normal operations.

Medium
467

A solutions architect is configuring a VPC for a three-tier web application. The database tier must not be reachable from the internet, and only the application tier should be able to initiate connections to the database on port 3306. The application tier runs on EC2 instances in a separate subnet. Which configuration enforces this requirement?

Easy
468

A media processing workflow generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used?

Hard
469

You run a web application on an EC2 Auto Scaling group behind an Application Load Balancer (ALB). During scheduled traffic spikes, new instances launch but customers occasionally see 5xx errors for the first few minutes after scale-out. Operational logs show instances need ~4 minutes to warm up (load caches and initialize dependencies). ALB target health becomes healthy only after this warm-up. Which change most directly improves performance during spikes by reducing the time to serve traffic after scaling?

Medium
470

A telemetry pipeline uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add?

Medium
471

A company serves public JavaScript and CSS files from S3 using CloudFront. After a frontend change, customers report a low CloudFront cache hit ratio. Requests now include an Authorization header, but these assets do not require authentication. The CloudFront distribution is configured such that Authorization is included in the cache key. Which change best maximizes cache reuse?

Easy
472

A order processing API uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

Hard
473

Based on the exhibit, the company wants DNS traffic to fail over automatically from the primary Region to a secondary Region when the primary endpoint is unhealthy. Which Route 53 change is best?

Medium
474

A mobile banking backend uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

Hard
475

A company has an application running on Amazon EC2 instances that needs to access an Amazon S3 bucket. The security team wants to avoid storing long-term AWS credentials on the instances. Which solution should they implement?

Easy
476

A IoT ingestion API uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

Hard
477

A microservice runs in private subnets and must read exactly one AWS Secrets Manager secret using its IAM task role: arn:aws:secretsmanager:us-east-1:111122223333:secret:prod/db-pass-AbCdEf Security requires that every Secrets Manager API call comes only through a specific Interface VPC Endpoint (vpce-0a1b2c3d4e5f6g7h), and must not be reachable over any other network path. Which IAM policy change best enforces this requirement?

Medium
478

A batch analytics job has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The design must avoid adding custom operational scripts.

Medium
479

A financial analytics platform stores results in an Amazon S3 bucket. Compliance requires that objects be recoverable for 30 days after deletion and that no user, including administrators, be able to permanently erase them during that window. Objects must also remain readable throughout the retention period. Which approach should the architect implement?

Hard
480

A document portal needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable? The architecture review board prefers a managed AWS-native control.

Hard
481

Your company allows application teams to create IAM roles. Each team must be prevented from granting permissions beyond a defined per-role baseline, even if they attach overly permissive identity-based policies to the role. Which AWS feature best enforces this ceiling at the IAM role level?

Easy
482

A test environment stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost? The architecture review board prefers a managed AWS-native control.

Medium
483

A healthcare company stores patient records in an Amazon S3 bucket. Compliance requires that every object be encrypted with a key that the company rotates on its own schedule, that key usage be logged separately from S3 data events, and that a specific group of IAM principals be the only identities allowed to use the key for cryptographic operations. The security team has already created a symmetric AWS KMS customer managed key. Which combination of actions should the team take to meet these requirements?

Medium
484

An order lookup API repeatedly reads the same few items from DynamoDB. The application can tolerate slightly stale data for a few seconds, and the team wants the lowest-latency design with minimal application changes. Which two changes should they make? Select two.

Medium
485

A analytics dashboard uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add? The architecture review board prefers a managed AWS-native control.

Medium
486

Based on the exhibit, a static asset distribution site uses Amazon CloudFront with an S3 origin. The assets are versioned by filename, but the cache hit ratio remains low after each release. Which CloudFront change is the best way to improve cache reuse without changing the origin objects?

Hard
487

A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used?

Hard
488

A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ASG is currently attached to subnets in only two Availability Zones (AZs). During a planned maintenance window, one AZ becomes unavailable for about 25 minutes. Monitoring shows that targets in the remaining AZ go healthy, and the ALB/target group health checks report normal. However, users still experience intermittent connection failures and slower responses during the AZ outage. What change will most directly improve resilience against an AZ loss while keeping the same ALB-based design?

Medium
489

A company runs a batch processing job on Amazon EC2 instances that runs for 4 hours every night. The job can be interrupted and restarted from a checkpoint. The company wants to minimize compute costs for this job. Which solution is MOST cost-effective?

Easy
490

A SaaS company serves a global web application from a single AWS Region. Users in distant geographies report high latency for static assets such as images and JavaScript bundles, and the company wants to reduce this latency without modifying the application code. Which action BEST achieves this?

Medium
491

A healthcare company stores patient imaging studies in an Amazon S3 bucket. Compliance requires that every object be encrypted at rest with a key the company fully controls, including the ability to rotate and revoke the key independently of AWS. The security team must also be able to audit every use of the key. Which solution meets these requirements with the LEAST operational overhead?

Medium
492

A solutions architect is designing an S3 bucket for a claims portal. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure? The design must avoid adding custom operational scripts.

Medium
493

A company is migrating a legacy application to AWS. The application uses a fixed set of credentials stored in a configuration file to access an Amazon RDS database. The security team wants to eliminate hardcoded credentials and automatically rotate them every 30 days. The application runs on Amazon EC2 instances and can be modified to retrieve credentials at startup. Which solution meets these requirements with the LEAST operational overhead?

Medium
494

A risk simulation workload uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured?

Medium
495

A warehouse integration service receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The architecture review board prefers a managed AWS-native control.

Medium
496

A nightly video rendering pipeline runs on Linux EC2 instances and is compatible with ARM64. The jobs are CPU-bound, checkpoint frequently, and can resume if interrupted. The business wants the best throughput per dollar for the batch window. Which two changes should the team make? Select two.

Hard
497

Company A must allow workloads in Company B to assume an IAM role in Company A (RoleInA). To mitigate confused-deputy attacks, a Security requirement is to use an External ID. Company A should restrict who can assume RoleInA. Which trust-policy configuration is the best choice?

Easy
498

Based on the exhibit, which AWS service should the team use so the database password can rotate automatically every 30 days and the application can retrieve it securely at runtime?

Medium
499

A company runs a web application on AWS and wants to reduce costs. The application uses an Application Load Balancer (ALB) to distribute traffic to Amazon EC2 instances in an Auto Scaling group. The company observes that the EC2 instances are underutilized during off-peak hours. They want to optimize costs without affecting performance during peak hours. Which two actions should they take? (Choose two.)

Hard
500

A data engineering team runs an Amazon EMR cluster that processes large datasets stored in Amazon S3. The cluster uses Amazon EBS volumes for temporary storage, and jobs frequently spill intermediate data to disk. The team notices that shuffle operations are slow and wants to improve performance without changing the data format or increasing the number of core nodes. Which change should the team make?

Hard
501

A team stores application logs in an S3 bucket. They keep logs for 18 months for compliance. Access patterns: logs are heavily accessed during the first 30 days, rarely accessed between days 31 and 180, and almost never accessed after day 180. They currently store everything in S3 Standard and want to reduce storage cost without violating the 18-month retention requirement. What should they implement?

Medium
502

Based on the exhibit, a web application runs on an Amazon EC2 Auto Scaling group behind an Application Load Balancer. During traffic surges, the average CPU utilization stays below 35%, but request latency increases sharply and the ALB access logs show far more requests per target than expected. Which change is the best way to improve scaling behavior?

Hard
503

A company is migrating its on-premises workloads to AWS and wants to optimize costs. Which three strategies should the company implement to achieve a cost-optimized architecture? (Choose three.)

Medium
504

A SaaS company hosts a REST API on Amazon API Gateway with AWS Lambda proxy integration. The API serves tenants in North America and Europe. European users report high latency, but the Lambda function and its Amazon RDS database must remain in the us-east-1 Region for data residency and cost reasons. The team wants to reduce latency for European users without moving the backend. Which solution meets these requirements?

Medium
505

A media processing workflow uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured?

Medium
506

A company needs to replicate a DynamoDB table to three AWS regions so that users in each region can read and write to a local copy with the lowest possible latency. Changes must propagate to all regions within seconds. Which solution should a solutions architect implement?

Medium
507

Based on the exhibit, an Amazon Aurora MySQL application is read-heavy, but the database writer is nearing CPU limits while the reader instance is mostly idle. The application currently sends all queries to the writer endpoint. Which change should you make first to increase read throughput?

Hard
508

A patient portal must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The design must avoid adding custom operational scripts.

Hard
509

A logistics company runs an Amazon RDS for MySQL database that supports a parcel-tracking API. During the morning peak, read queries for tracking history saturate the primary instance's CPU, slowing writes. The reads can tolerate a few seconds of staleness, and the team wants to offload them without changing the database engine. Which action should the team take?

Medium
510

A company runs an application on EC2 instances in private subnets. The instances must access Amazon S3, and the team currently routes all outbound traffic to the internet through a NAT Gateway. Monthly NAT Gateway charges increased significantly, even though the application only needs to call S3 (not access other public internet services). Which change will most directly reduce NAT Gateway charges while keeping S3 access working?

Medium
511

A team needs to distribute TCP traffic (not HTTP) across multiple services. The services must see the original client source IP for auditing. Which AWS load balancer is the best fit?

Easy
512

A web application for a healthcare document service is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy? The design must avoid adding custom operational scripts.

Medium
513

A security team must ensure that all data written to a new Amazon S3 bucket is encrypted with a specific customer-managed AWS KMS key, and that any PUT request that does not specify that key is rejected. The team also needs to detect and react if someone attempts to change the bucket policy to remove the restriction. Which combination of actions meets these requirements with the LEAST operational effort?

Hard
514

A payments API requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The design must avoid adding custom operational scripts.

Hard
515

A trading analytics system deploys multiple EC2 instances that exchange very frequent, low-latency, east-west messages. The application team wants the instances to be placed to minimize network latency and variability. Which AWS feature should they use?

Easy
516

A healthcare document service must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

Hard
517

A company hosts an internal API behind an Application Load Balancer (ALB) in two AWS Regions. They want Amazon Route 53 to automatically fail over to the secondary Region when the primary Region’s ALB is unhealthy. Health checks for the primary ALB are already configured, but the DNS record currently uses a latency-based routing policy. Which Route 53 configuration most directly provides automatic failover based on health status?

Medium
518

A central security account stores encrypted log files in S3 using a customer managed AWS KMS key. A partner account already has S3 bucket access through an assumed role and now must also be able to encrypt and decrypt objects that use the same KMS key. Which two actions are required? Select two.

Medium
519

An S3 bucket in account A uses default server-side encryption with an AWS KMS customer-managed key (CMK) in account A. A team created an IAM role in account B that is allowed by IAM policy to perform s3:GetObject on the bucket. When the account B role tries to read objects, it fails with: AccessDeniedException: 'User is not authorized to perform kms:Decrypt'. Which change is most likely to fix the issue?

Medium
520

A media company hosts a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from individual IP addresses to mitigate scraping. Which AWS service should a solutions architect associate with the load balancer to meet both requirements?

Medium
521

A media company streams live video from on-premises encoders to viewers across North America. The encoders push a single RTMP feed to AWS, and the company wants the lowest possible glass-to-glass latency for viewers while distributing to thousands of concurrent viewers. The team does not want to manage any streaming servers. Which solution BEST meets these requirements?

Medium
522

A web application uses an Amazon Aurora DB cluster for a read-heavy workload. The team wants to increase read throughput without changing the database schema or rewriting application data access patterns. Which two changes should they make? Select two.

Medium
523

A company uses AWS Organizations and wants to prevent any account in the organization from launching resources in regions other than us-east-1 and eu-west-1. This restriction must apply even if an administrator in a member account grants full IAM permissions. Which approach should a solutions architect use?

Hard
524

An orders service publishes payment instructions to an Amazon SQS Standard queue. A downstream consumer sometimes times out and retries the work, causing the consumer to process the same instruction more than once. Operationally, the team must ensure that duplicate processing does not create duplicate charges. The queue type cannot be changed. What is the most resilient application-side approach?

Medium
525

A startup runs a two-tier web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in private subnets and must reach the internet only to download operating system patches. Security policy forbids any inbound internet traffic to the instances. Which configuration meets these requirements with the least operational overhead?

Easy
526

A solutions architect is designing a high-performance computing (HPC) workload on AWS that requires a shared POSIX-compliant file system with high throughput and low latency for thousands of concurrent compute instances. The workload is temporary, running for a few hours each week, and the team wants to minimize cost. Which storage solution should the architect recommend?

Hard
527

A serverless API built with AWS Lambda serves latency-sensitive requests. The team observes intermittent slow responses during traffic ramp-ups and expects some users to hit the API immediately after a period of inactivity. Which configuration best reduces cold-start latency during these ramp-ups?

Medium
528

A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The architecture review board prefers a managed AWS-native control.

Medium
529

A solutions architect is designing an S3 bucket for a order processing API. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?

Medium
530

A solutions architect is designing an S3 bucket for a IoT ingestion API. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure? The design must avoid adding custom operational scripts.

Medium
531

A retail company hosts a product catalogue API on Amazon EC2 instances behind an Application Load Balancer. The API serves mostly small JSON responses and is read-heavy. Users in a distant continent report slow response times even though the origin servers are not heavily loaded. The company cannot change the application and wants the lowest-latency read experience globally. Which service should they use?

Easy
532

A service processes messages from an Amazon SQS queue. Sometimes the worker finishes the business logic but does not delete the message before the visibility timeout expires, so the message is delivered again. Which two changes improve resilience and reduce the impact of duplicate processing? Select two.

Easy
533

A analytics dashboard uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add? The team wants the control to be enforceable during normal operations.

Medium
534

Based on the exhibit, the team wants to stop poison messages from consuming worker capacity and also prevent duplicate side effects if the same message is delivered more than once. Which design change best meets the requirement?

Medium
535

Based on the exhibit, a company stores sensitive PDFs in S3 and serves them through CloudFront. Direct requests to the S3 object URL must fail, but CloudFront should still be able to fetch the files securely. Which solution best satisfies the requirement?

Hard
536

A latency-sensitive API is implemented with AWS Lambda. During traffic ramp-ups, users sometimes experience slow responses due to cold starts. The team wants to ensure fast initialization for a baseline level of concurrent requests. Which AWS feature should they use?

Easy
537

A caching layer uses Amazon ElastiCache for Redis in front of a stateless web service. The service must continue to read cached responses during maintenance events and should automatically fail over to another node if one AZ becomes impaired. Which design change best satisfies this requirement?

Medium
538

A company stores millions of small, rarely accessed backup objects in Amazon S3 Standard. The objects must remain immediately retrievable within milliseconds and be retained for at least five years, but the company wants to reduce storage cost. Which action should the company take?

Easy
539

An ECS service runs on EC2 instances and is fronted by an ALB. The ALB spans two Availability Zones, and the ECS service desired count is 2 tasks. The underlying EC2 capacity uses an Auto Scaling group (ASG) with min size set to 1, and the ASG also spans only one subnet in practice. What is the most effective change to meet the requirement that the service continues during a single-AZ instance loss?

Medium
540

A video platform uses Amazon Aurora. The workload has many short-lived database connections from Lambda functions, causing connection storms. What should be added? The design must avoid adding custom operational scripts.

Medium
541

A financial services company must store audit logs in S3 for 7 years and ensure that no one — including the AWS account root user — can delete or overwrite the logs during the retention period. Which S3 Object Lock configuration should a solutions architect use?

Hard
542

A small e-commerce company runs a web application on a single Amazon EC2 instance in one Availability Zone. The instance stores session state locally and the database runs on the same instance. The company wants the application to survive an Availability Zone failure with minimal changes and no data loss for committed orders. Which combination of changes should the architect recommend?

Easy
543

Based on the exhibit, which Amazon EFS performance mode is the best fit for this workload?

Easy
544

A warehouse integration service must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The architecture review board prefers a managed AWS-native control.

Hard
545

An order-processing worker consumes messages from Amazon SQS. Occasionally, the worker times out after successfully creating a payment record but before deleting the message, which causes duplicate charges during retries. Some messages also fail validation repeatedly because required fields are missing. Which two changes should the team make? Select two.

Medium
546

A analytics dashboard uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered?

Medium
547

A DynamoDB table for a retail API has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The architecture review board prefers a managed AWS-native control.

Hard
548

A SaaS provider runs a multi-tenant application on Amazon RDS for PostgreSQL. The database is 2 TB and experiences steady read-heavy traffic during business hours. The provider wants to offload read traffic to reduce load on the primary instance and lower cost compared to scaling up the primary. The application can tolerate slightly stale reads for reporting queries. Which solution is MOST cost-effective?

Hard
549

A payments API uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The design must avoid adding custom operational scripts.

Hard
550

A content publishing system exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most? The design must avoid adding custom operational scripts.

Easy
551

A marketing site stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost?

Medium
552

A marketing team runs a report-generation process that must execute once per day at 02:00 UTC. It usually completes in 10315 minutes, but sometimes takes up to 45 minutes due to varying data volumes. They currently run the workload on an EC2 instance that is always on, which wastes money during off-hours. The team wants to minimize operational overhead and pay mainly for actual execution time. What is the best architecture choice?

Medium
553

A startup runs a nightly batch job on a single EC2 instance that reads a large dataset from Amazon S3, performs transformations, and writes results back to S3. The job takes about two hours, and the team wants the job to restart automatically if the instance fails or is terminated by AWS. The job is idempotent and can safely resume from the beginning. What is the MOST operationally efficient way to meet this requirement?

Easy
554

Based on the exhibit, downstream payment timeouts cause EventBridge deliveries to back up and some events are retried until they age out. What change best improves resilience and preserves events during downstream outages?

Hard
555

You need to run batch jobs on EC2. The jobs can tolerate interruptions: if an instance is terminated, the job can restart from checkpoints. To reduce compute cost as much as possible, what is the best choice?

Easy
556

Account Y provides a role named AnalyticsReadOnly to engineers in Account X. The role trust policy currently allows sts:AssumeRole from the Account X principal. A new security requirement states that only STS sessions created with MFA are allowed to assume the role. Which trust policy condition is the best choice to enforce MFA for sts:AssumeRole?

Medium
557

A company has a critical application running on Amazon EC2 instances that must access an Amazon RDS for MySQL database. The security team requires that the database credentials are never stored on the EC2 instances and that access to the database is auditable. The database is in a private subnet and only accepts connections from the application's security group. The company wants to implement a solution that automatically rotates the database password every 90 days. Which solution meets these requirements?

Hard
558

A trading analytics system deploys 10 EC2 instances that exchange very frequent, low-latency messages over the network. The instances must be placed as close together as possible to minimize network hop count and inter-node jitter. Which deployment choice best matches this requirement?

Medium
559

A analytics dashboard uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered? The design must avoid adding custom operational scripts.

Medium
560

A company runs a stateful web application on a single Amazon EC2 instance in a public subnet. The application stores session data on the instance's root volume. The company wants to make the application highly available across two Availability Zones and ensure that session data is preserved if an instance fails. Which solution should a solutions architect recommend?

Hard
561

Based on the exhibit, what is the best change to improve read performance without increasing write latency on the primary database?

Hard
562

A healthcare company runs a critical patient-records API on Amazon EC2 instances behind an Application Load Balancer in a single AWS Region. The compliance team mandates that the API remain available even if an entire AWS Region becomes unavailable. The company wants a cost-effective solution that avoids running full production capacity in a second Region at all times. Which approach BEST meets these requirements?

Medium
563

A company runs a stateful analytics workload on EC2 instances that use EBS volumes. The data must be restorable in another Region after a major outage, with frequent point-in-time recovery. Which approach provides the most suitable replication mechanism for the EBS-backed data?

Medium
564

A company hosts a web application on EC2 instances behind an Application Load Balancer (ALB) in us-east-1. A static failover site is hosted in an S3 bucket with static website hosting enabled. The company needs automatic DNS failover to the S3 bucket if the primary ALB becomes unhealthy. Which Route 53 configuration achieves this?

Medium
565

A DynamoDB table for a travel booking site has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The architecture review board prefers a managed AWS-native control.

Hard
566

A company stores several petabytes of archived regulatory records in Amazon S3. The records must be retained for seven years and are almost never accessed, but if an auditor requests a record, it must be retrievable within 12 hours. The company wants the lowest storage cost that still meets the retrieval requirement. Which S3 storage class should the solutions architect choose?

Easy
567

A company hosts a public website on Amazon EC2 instances behind an Application Load Balancer. The site is static HTML, CSS, and images, and the same content is served to all visitors. Origin CPU is high because every request is forwarded to the instances, and visitors in remote Regions see slow page loads. The team wants to reduce origin load and improve global latency with the least operational effort. Which solution should be used?

Medium
568

A financial analytics company runs a nightly batch job that reads 4 TB of compressed log data from an Amazon S3 bucket and writes aggregated results to another S3 bucket. The job runs on a fleet of 8 Amazon EC2 instances in a single AWS Region, and the team wants the highest possible aggregate read throughput while minimizing request costs. The data is already stored in S3 Standard, and the team does not want to change the storage class. Which solution best meets these requirements?

Medium
569

A company needs to give an external auditing firm read-only access to specific objects in an Amazon S3 bucket for 30 days. The firm has its own AWS account and should not receive long-term credentials. The company wants to minimize the blast radius if the firm's account is compromised. Which two steps should the company take? (Choose two.)

Medium
570

A company runs a critical application on Amazon EC2 instances in a single Availability Zone. The application writes data to an Amazon RDS for MySQL DB instance that is not Multi-AZ. The company wants to improve the resilience of the database tier so that it can survive an Availability Zone failure with minimal downtime and no data loss. The application uses the database endpoint from the RDS console. Which solution meets these requirements?

Hard
571

A logistics company runs an Amazon RDS for MySQL database that supports a shipment tracking application. Read replicas are already in use, but the primary instance's CPU is saturated by a small number of long-running analytical queries that the reporting team runs directly against the primary. The company wants to offload these analytical queries and improve primary performance while keeping the application's transactional writes fast. (Choose two.)

Hard
572

Your team hosts versioned static assets (for example, /static/app-<buildHash>.js). Each build hash never changes, but you release new files on new URLs. To maximize cache hit rate and reduce origin load using CloudFront, what should you do when generating HTTP responses for these assets?

Easy
573

Based on the exhibit, which storage design best supports the application servers' shared working directory requirement?

Hard
574

A web application runs on an Amazon EC2 Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ALB is configured to use at least two Availability Zones (AZs), but the ASG currently uses subnets in only one AZ. If that AZ becomes unavailable, the application stops serving requests. Which change most directly improves resilience to an AZ outage?

Easy
575

A healthcare analytics platform ingests records into an Amazon Aurora MySQL cluster. Compliance rules require that the cluster remain writable even if an entire Availability Zone is lost, and that recovery happen without operator action. The team also wants read traffic to scale independently of the writer. Which configuration should a solutions architect choose?

Hard
576

A media company distributes on-demand video to viewers in North America, Europe, and Asia. The videos are stored in a single Amazon S3 bucket in us-east-1 and are served directly from S3. Viewers in Asia report slow start times and frequent buffering. The company wants to reduce latency for all viewers with minimal operational overhead. Which solution meets these requirements?

Medium
577

A test environment runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost? The design must avoid adding custom operational scripts.

Medium
578

An order-processing system publishes an event whenever a payment succeeds. Three downstream services (inventory, shipping, and analytics) must react independently. Analytics sometimes has high latency, but order processing must not be blocked. What is the best AWS approach to decouple these consumers?

Easy
579

An internal worker consumes messages from an Amazon SQS Standard queue. Recently, some messages fail validation in the worker (for example, missing required fields), causing the worker to crash before it can successfully process those messages. Those messages keep getting retried repeatedly, slowing down processing of valid messages. The team wants a resilient mechanism to quarantine bad messages after a limited number of receive attempts. What should they implement?

Medium
580

A company is deploying a web application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer. The company wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to restrict access to specific geographic regions. Which combination of AWS services should a solutions architect use to meet these requirements?

Medium
581

A logistics company stores shipment events in an Amazon S3 bucket. An analytics team must be able to recover any object version that is accidentally overwritten or deleted for at least 90 days, and objects must be protected from permanent deletion by any user, including the root user, during that window. Which combination of S3 features meets these requirements with the LEAST operational overhead?

Hard
582

A web application for a claims portal is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

Medium
583

A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The design must avoid adding custom operational scripts.

Medium
584

A company uses an Amazon Aurora DB cluster in a Multi-AZ configuration. During a planned failover of the writer instance, the database endpoints in the application are updated incorrectly. After failover, reads work but writes fail with connection errors and timeouts for several minutes. The team currently uses the instance endpoint for the writer. What should they change to improve write resilience during failovers?

Medium
585

A claims workflow requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The design must avoid adding custom operational scripts.

Hard
586

A web application uses an Amazon Aurora DB cluster for a read-heavy workload. The application team needs higher read throughput but cannot change the database schema. They want to avoid blocking writes and are willing to route read traffic separately. What is the most appropriate architecture change?

Medium
587

An S3 bucket stores application logs. After 30 days, the team rarely accesses the logs, but compliance requires keeping them for 18 months. Which setup most directly reduces storage cost while maintaining compliance?

Easy
588

A company is running a production web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The workload has predictable traffic spikes during business hours and low traffic at night. The current architecture uses On-Demand EC2 instances, leading to high costs. The company wants to reduce costs without sacrificing availability or performance. Which three of the following strategies would help achieve this goal? (Choose three.)

Medium
589

A web application for a IoT ingestion API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy? The design must avoid adding custom operational scripts.

Medium
590

A DynamoDB table for a retail API has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change?

Hard
591

A document portal requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The architecture review board prefers a managed AWS-native control.

Medium
592

A media processing workflow in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost? The design must avoid adding custom operational scripts.

Hard
593

A trading dashboard stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured? The design must avoid adding custom operational scripts.

Medium
594

A stateless web application runs on Amazon EC2 instances across two Availability Zones. The team wants unhealthy instances to be removed automatically and replaced without manual action. What is the best solution?

Easy
595

A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The team wants the control to be enforceable during normal operations.

Medium
596

An order-quote Lambda function is invoked directly by API Gateway. Traffic is predictable during the business day, and the first request after scaling from zero causes unacceptable latency. The team wants to keep the current architecture and reduce cold-start impact. Which configuration should they use?

Medium
597

An order processing workflow uses Amazon SQS as the decoupling layer between a producer and a consumer Lambda function. The consumer intermittently fails due to a downstream dependency. The team has observed that certain “poison” messages keep being retried repeatedly and prevent other messages from being processed efficiently. Which SQS configuration most directly addresses this issue?

Medium
598

A startup runs a stateless web application on a single Amazon EC2 instance in one Availability Zone. The application must remain available if the instance fails or if its Availability Zone becomes unavailable. The startup wants a managed solution that requires minimal operational overhead. Which solution should a solutions architect recommend?

Easy
599

Your application runs in private subnets with no NAT gateway. It needs to call AWS Secrets Manager to retrieve secrets. For private connectivity without internet egress, which VPC endpoint type should you create for AWS Secrets Manager?

Easy
600

A dev sandbox has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity?

Medium
601

A serverless checkout API runs on AWS Lambda behind API Gateway. Traffic spikes are predictable every weekday at 09:00 UTC, and p95 latency jumps for the first few minutes after each deployment because execution environments are cold. The team wants to reduce this startup impact without changing the API contract. Which changes should they make? Select three.

Hard
602

A production internal reporting portal runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy? The design must avoid adding custom operational scripts.

Medium
603

A website serves mostly cacheable images, CSS, and JavaScript from an ALB. Users in Europe and Asia report slower page loads, and the ALB receives far more requests than expected. The team also wants text assets compressed automatically. Which change is the best first step?

Medium
604

A system processes events from Amazon SQS and sometimes sees duplicate messages due to retries. The business requirement is that each payment must be charged at most once. What design choice best addresses this resiliency requirement?

Easy
605

A latency-sensitive API is implemented with AWS Lambda. The team enabled provisioned concurrency to avoid cold starts, setting provisioned concurrency to 50 because marketing campaigns occasionally cause spikes. However, during most weekdays the API receives little traffic (near zero), and the team is seeing high monthly Lambda costs from idle provisioned capacity. What is the best cost-optimized strategy that still meets the requirement of fast initial responses during traffic spikes?

Medium
606

A company hosts a web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The ALB and the Auto Scaling group are currently deployed in only one Availability Zone (AZ). The business wants the application to keep running if that AZ has an outage. What is the best change?

Easy
607

A containerized service on Amazon ECS connects to a database with a password that must never be stored in plaintext or hardcoded in the image. The application reads the password at startup and occasionally reconnects later, so it needs to retrieve the current secret when needed. Which three actions should the architect take? Select three.

Medium
608

A telemetry pipeline uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered? The design must avoid adding custom operational scripts.

Medium
609

Account A has an IAM role named FinanceDataRole that is assumed by a principal in Account B. The role’s trust policy includes a condition requiring sts:ExternalId to equal "Fin-2026-Q2". A developer in Account B calls AssumeRole but receives an error: AccessDenied: ExternalId mismatch. The security team requires that you do not remove the ExternalId condition. What is the correct remediation?

Medium
610

A company has a primary application in us-east-1 and a standby environment in us-west-2. Users should go to the primary site while it is healthy and automatically switch to the standby site if the primary fails. Which Route 53 routing policy should they use?

Easy
611

Based on the exhibit, an application runs on Amazon Aurora MySQL. The writer instance is frequently near 85% CPU while the reader instance is under 20% CPU. Application traces show that most of the database traffic is read-only SELECT queries, but the code currently sends all queries to the writer endpoint. What should the solutions architect recommend to improve performance with the smallest functional change?

Hard
612

A public API for a B2B file exchange site is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?

Medium
613

A product catalog system uses a relational database for orders and a simple key-value profile store for shopping carts. Traffic is unpredictable, and the company wants to avoid paying for large idle database instances. Which two choices are best? Select two.

Hard
614

A DynamoDB-backed event processing system experiences throttling during a promotion. All events are written and read using the same partition key value (tenantId = "ACME"). The workload is time-ordered per tenant, and the application can tolerate slight reordering across partitions. Which design change will most directly increase throughput and reduce hot-partition throttling?

Medium
615

A company runs a web application on Amazon EC2 instances in multiple Availability Zones. The application uses an Application Load Balancer and an Auto Scaling group. The company wants to reduce cost while maintaining high availability. The workload is steady and predictable, and the instances run continuously. Which two actions will reduce cost? (Choose two.)

Medium
616

Account A hosts a role named AppReadRole. Account B needs to access it using STS AssumeRole. Account A’s role trust policy includes this condition: - StringEquals: { "sts:ExternalId": "b-7f9a" } When Account B runs: aws sts assume-role --role-arn arn:aws:iam::111111111111:role/AppReadRole --role-session-name test the call fails with: "AccessDenied: ExternalId mismatch". What should Account B change?

Medium
617

Based on the exhibit, an EC2 application runs in private subnets with no NAT gateway and must retrieve a secret from AWS Secrets Manager. The secret uses a customer managed KMS key. Which change will allow the application to reach the service while keeping traffic off the internet?

Hard
618

A web application runs on an Amazon EC2 Auto Scaling group behind an Application Load Balancer (ALB). After each deployment, new instances take about 2 minutes to download artifacts and become ready to accept requests on the target port. In the last deployment, the ALB started marking targets unhealthy before the app was ready, and the Auto Scaling group then replaced those instances repeatedly, causing a prolonged outage. Which change best improves resilience during instance start-up without reducing actual availability once the application is healthy?

Medium
619

Account A hosts an IAM role that Account B developers must assume for a limited task. You want to require MFA for anyone assuming the role. Which trust policy condition most directly enforces that requirement for sts:AssumeRole?

Easy
620

A customer-facing application has a relational data model and needs frequent complex queries (joins and aggregations), but it also experiences a significant read-heavy workload. Which design choice best improves read performance while keeping relational features?

Easy
621

A media company runs a two-tier web application in a VPC. The web tier is in public subnets behind an internet-facing Application Load Balancer, and the database tier is in private subnets running Amazon RDS. A security review found that the RDS security group allows traffic from 0.0.0.0/0 on port 3306. What is the MOST secure way to restrict database access to only the web tier?

Medium
622

An internal API is deployed in two AWS Regions behind separate Application Load Balancers. The company wants clients to use the primary Region when it is healthy and automatically switch to the secondary Region if the primary health check fails. Which two Route 53 record configurations are required? Select two.

Medium
623

A company runs Amazon RDS for MySQL in a Multi-AZ configuration. If the primary database instance fails, what is the expected behavior?

Easy
624

A static web application uses CloudFront with an S3 origin for assets (JavaScript, CSS, images). After deploying a new frontend build, the CloudFront cache hit ratio dropped significantly because the S3 origin receives many repeated requests for the same assets. The team notices that requests now include the Authorization header in asset requests. Which change is most likely to restore cache efficiency and reduce origin request costs?

Medium
625

A dev sandbox has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The design must avoid adding custom operational scripts.

Medium
626

A SaaS platform plans to run in two AWS Regions for lower latency. The team wants to enable active-active writes (both regions accept updates) to avoid failover downtime. However, the business requires strong consistency for order status transitions (for example, only one transition from “Paid” to “Shipped” must be allowed). Which statement is the best architectural choice to meet the consistency requirement?

Medium
627

A consumer application reads from an Amazon SQS queue. Some messages have an invalid format and always fail processing. They are retried repeatedly and consume consumer capacity. What is the best way to prevent these "poison pill" messages from blocking normal processing?

Easy
628

A Lambda function in Account A must upload reports to an S3 bucket in Account B. Security does not want long-lived access keys anywhere, and the access should be easy to revoke from Account B. Which approach is best?

Medium
629

A healthcare company stores patient records in an Amazon DynamoDB table. The table must be recoverable to any point within the last 35 days, and the data must remain available if an entire AWS Region becomes unavailable. Which two actions should a solutions architect take to meet these requirements? (Choose two.)

Medium
630

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use?

Hard
631

A company serves versioned images from S3 through CloudFront. After a release, CloudFront origin fetches increased sharply and the monthly CloudFront bill went up. They reviewed CloudFront logs and found that many requests include a query string parameter `reqId` that is unique per request (for example, `...?v=2026-04-01&reqId=...`). The team currently forwards all query strings to the cache key. What change is most likely to reduce origin fetches and cost while keeping the versioned images correct?

Medium
632

A mobile game backend uses Amazon Aurora. The workload has many short-lived database connections from Lambda functions, causing connection storms. What should be added?

Medium
633

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The design must avoid adding custom operational scripts.

Hard
634

A media processing workflow uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured? The design must avoid adding custom operational scripts.

Medium
635

A risk simulation workload uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured? The design must avoid adding custom operational scripts.

Medium
636

A media company serves a global audience from an Amazon S3 bucket in the us-east-1 Region. Users in Asia and Europe report high latency when downloading large video files directly from the bucket. The company wants to reduce download latency for these users without changing the application's bucket names or rewriting the application to use a different endpoint. Which solution should a solutions architect recommend?

Hard
637

A company is building a serverless application that processes messages from an Amazon SQS queue using AWS Lambda. The application must not lose messages and must handle occasional downstream failures gracefully. The Lambda function sometimes fails due to a transient error in a downstream service. The company wants to ensure that failed messages are retried and eventually processed, but also wants to avoid infinite retries that could block the queue. What should the company do?

Hard
638

A healthcare analytics team runs a containerized reporting service on Amazon ECS with the Fargate launch type in a single Availability Zone. The service must remain available if one Availability Zone fails, and it must scale automatically based on CPU utilization. The tasks are stateless and write output to Amazon S3. Which configuration should a solutions architect implement?

Medium
639

A company is deploying a high-performance computing (HPC) cluster with 16 EC2 instances. The workload requires the lowest possible network latency and highest throughput between all nodes for tightly coupled parallel MPI computations. Which EC2 placement group type should a solutions architect recommend?

Medium
640

Based on the exhibit, the web tier becomes unavailable if us-west-2a has an outage. What is the best change to improve resilience with the least redesign?

Easy
641

You serve private reports stored in an S3 bucket through CloudFront. After a recent change, users report that they can access the S3 object URLs directly (bypassing CloudFront), which violates your design. You want to ensure S3 objects are readable only through CloudFront using Origin Access Control (OAC), even if someone guesses the S3 URL. Which update best enforces this at the S3 bucket level?

Medium
642

A log archive has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances?

Hard
643

A deployment engineer created an IAM role for an automation workflow (AppDeployRole). The role has an attached identity policy that allows iam:CreateRole for specific resource ARNs. However, the role is also created with a permission boundary named DeployBoundary. The DeployBoundary policy currently does not include the iam:CreateRole action. During execution, the automation fails with AccessDenied for iam:CreateRole, even though the attached identity policy allows it. What is the best fix?

Medium
644

A healthcare company stores patient records in an Amazon S3 bucket. Compliance requires that every object be encrypted at rest with a key that the company fully controls, including the ability to rotate and immediately revoke access. The security team also needs a record of every time the key is used to decrypt an object. Which encryption configuration should the company implement?

Medium
645

A company hosts an application on EC2 instances in private subnets. The instances must (1) read objects from Amazon S3 and (2) retrieve secrets from AWS Secrets Manager. The team currently sends all outbound traffic through a NAT gateway to reach both services. They want to reduce monthly cost while keeping traffic private (no internet egress) and without changing application logic. Which change is the most cost-effective?

Medium
646

A company uses AWS Organizations with multiple accounts. A security engineer must ensure that no IAM user in any member account can create an access key for the root user or perform any action as the root user, even if an administrator in that account tries to allow it. What should the security engineer do?

Hard
647

You must ensure that all requests to an S3 bucket use TLS (HTTPS). Which S3 bucket policy approach best enforces this requirement for S3 access?

Easy
648

A company keeps daily database backups in an S3 bucket. They may restore from backups during the first 30 days if there is an issue. After 30 days, backups are rarely restored, but must be retained for 2 years. Which lifecycle strategy most cost-effectively meets these requirements?

Easy
649

A media company uses an Amazon CloudFront distribution to serve content from a private S3 bucket. The security team wants to ensure that users cannot bypass CloudFront and access the S3 bucket directly, and that only the distribution can read objects. Which configuration should be implemented?

Hard
650

Based on the exhibit, what should the architect recommend to reduce inter-node latency for this workload?

Easy
651

A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The design must avoid adding custom operational scripts.

Hard
652

A research team runs a latency-sensitive distributed training job on Amazon EC2. They deploy 80 identical nodes that exchange small messages frequently and need low network jitter. The job must run entirely within one Availability Zone. Which placement group strategy should a solutions architect use to maximize intra-cluster network performance?

Medium
653

A Lambda function for a mobile banking backend needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?

Medium
654

A game streaming service must use UDP for real-time gameplay traffic. For external firewall allowlisting, the service requires stable, static IP addresses. The TLS handshake must be handled end-to-end by the application servers (the load balancer must not terminate TLS). Which AWS load balancing option best fits these requirements?

Medium
655

A company uses IAM permission boundaries to prevent developers from escalating privileges. The security team created a permission boundary that allows only read-only actions on most AWS services, but teams can still manage their own resources. A developer can create an IAM role with broad permissions, and the boundary does not appear to be restricting it. Which corrective action best aligns with how permission boundaries work?

Medium
656

Based on the exhibit, the security team needs to detect and alert on both successful and failed attempts to change S3 bucket policies and KMS key policies across the organization. Which solution best meets that requirement?

Hard
657

You have an S3 bucket that stores customer-specific private files. You want to serve these files through CloudFront, where clients must use signed cookies (or signed URLs) to access the content. In addition, you need to block common web exploits and rate-limit suspicious traffic at the edge. Which design best meets these requirements?

Medium
658

A media company stores finalized video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that the objects be recoverable if they are accidentally deleted or overwritten for at least 90 days, and that no user, including administrators, be able to permanently erase them during that period. Which S3 feature should the solutions architect enable?

Easy
659

Based on the exhibit, the database is manually promoted during an Availability Zone failure and the application outage lasts longer than the target. What change best improves resilience with the least operational intervention?

Hard
660

Based on the exhibit, which design change is the best way to reduce the observed read latency for this DynamoDB-backed service?

Hard
661

An application runs on an EC2 Auto Scaling group. Over the last month, CPU utilization averaged 8% with no sustained memory pressure, and response times are stable. The team wants to lower monthly cost without changing the application. What is the most appropriate next step for cost optimization?

Easy
662

A video platform uses Amazon Aurora. The workload has many short-lived database connections from Lambda functions, causing connection storms. What should be added?

Medium
663

A company runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in a relational database, which is becoming a bottleneck during peak hours. The team wants to improve performance and reduce database load while keeping the application stateless. Which solution should a solutions architect recommend?

Easy
664

A production log archive runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy? The design must avoid adding custom operational scripts.

Medium
665

An application writes to an Amazon Aurora DB cluster. After a planned Aurora failover, the application experiences several minutes of connection errors. The logs show the application continues connecting to the specific DB instance endpoint that was the primary before the failover. What change most directly improves resilience during Aurora failovers?

Medium
666

Based on the exhibit, a public API is behind CloudFront and is experiencing bursts of requests from the same client IP, causing upstream saturation. The team wants AWS to automatically block that IP when the request rate becomes excessive while keeping enforcement as close to the client as possible. Which control should they add?

Hard
667

A retail company runs a stateless web tier on Amazon EC2 instances behind an Application Load Balancer. Traffic is steady during the day but drops to near zero between 01:00 and 06:00, and the team wants to reduce cost without manual intervention. The instances take about four minutes to boot and warm up. Which configuration meets these requirements?

Medium
668

A media processing workflow generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used? The architecture review board prefers a managed AWS-native control.

Hard
669

A company stores 500 TB of archival data in Amazon S3. The data is accessed only for compliance audits, which occur once every two years. Retrieval times of up to 12 hours are acceptable. The company wants the lowest storage cost. Which S3 storage class should be used?

Easy
670

A media company runs a 24/7 recommendation engine on EC2 in one AWS Region. The workload is interruption-intolerant, and the team expects steady usage but may change instance families and sizes during planned optimizations. Compared to the current On-Demand setup, they want the lowest cost while avoiding the rigidity of locking to a specific instance type. What should the solutions architect recommend?

Medium
671

A website serves versioned JavaScript and CSS files through CloudFront, but origin fetches are still high and the CloudFront bill increased. Developers confirm that URLs include a version in the filename (for example, app.1.4.2.js). What CloudFront behavior/configuration is most likely to reduce origin fetches and associated costs?

Easy
672

A company runs an Amazon RDS for PostgreSQL database. The application performs frequent OLTP writes, but it also has a separate dashboard that runs heavy SELECT queries and is slowing down overall database performance. The writes must remain on the primary. What is the best approach to improve performance for the dashboard?

Easy
673

Based on the exhibit, an application runs in private subnets without a NAT gateway and must retrieve a secret from AWS Secrets Manager. Security requires the traffic to stay on the AWS network and not traverse the public internet. What is the best solution?

Hard
674

A company uses Amazon RDS with automated backups enabled (retention period: 7 days). At 10:30 UTC, a bad release corrupts specific rows in a production table. The team detects the issue at 11:10 UTC. They need to revert the database state to what it was from 10:00–10:30 UTC, recover quickly, and minimize risk to the currently running workload. What is the best option?

Medium
675

A service processes customer payments from a message queue. Because the queue provides at-least-once delivery, the same payment message can be delivered more than once if the consumer times out before committing its state. Currently, the service sometimes charges the customer twice. Which design change most directly prevents duplicate charges while still allowing safe retries?

Medium
676

A company stores private customer documents in an S3 bucket. They want only CloudFront to be able to read objects from the bucket (no direct S3 URL access), even if the bucket name and object key are known. Which configuration best meets this requirement?

Medium
677

An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a financial reporting platform. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy?

Hard
678

Based on the exhibit, a media rendering job runs on a single EC2 instance and writes a large working set of metadata to block storage. The workload performs sustained random reads and writes and must keep latency consistently low for the entire run. The instance may be stopped and started between jobs, and the data must persist. Which storage choice best meets the requirements?

Hard
679

A media company stores original uploads in an S3 bucket. They must recover from accidental overwrites/deletes and also recover quickly from a full Region outage. The required RPO is about 1 hour. Which configuration best meets these requirements?

Medium
680

A media platform runs a CPU-heavy thumbnail generation workload on an EC2 Auto Scaling group using t3.large instances. During peak traffic, p95 processing time increases significantly even though average CPU remains around 40–50%. CloudWatch also shows CPU credit depletion behavior. Which change will most directly improve performance predictability for this workload?

Medium
681

A DevOps team is designing a high-performance CI/CD pipeline to build and test code changes. The pipeline needs to scale to handle hundreds of concurrent builds, with fast build times and minimal idle compute cost. The builds are containerized and require consistent, reproducible environments. Which three options should be used to meet these requirements? (Choose three.)

Medium
682

A company runs EC2 workloads including web servers (m5.large), batch jobs (c5.xlarge), and a data processing service that will migrate from r5 to r6i instances within 6 months. The company wants to commit to 1 year to reduce costs but needs flexibility for the planned instance family migration. Which purchasing option provides the GREATEST savings while accommodating the change?

Hard
683

An application in Account B reads objects from an Amazon S3 bucket in Account A. The bucket uses SSE-KMS with a customer managed key in Account A. The role in Account B already has s3:GetObject, but downloads fail with AccessDenied on decrypt. Which two changes are required for the role to read the object successfully? Select two.

Medium
684

Your company has an internal service hosted behind a Network Load Balancer (NLB) in VPC 10.0.0.0/16. A consumer team in a different VPC (10.1.0.0/16) must call the service without using the public internet. You want private connectivity using AWS PrivateLink. Which configuration best enables least-privilege access while keeping the traffic private?

Medium
685

A warehouse integration service must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The design must avoid adding custom operational scripts.

Hard
686

A content publishing system uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The team wants the control to be enforceable during normal operations.

Medium
687

A SaaS application is deployed in us-east-1 and us-west-2 behind separate ALBs. The business wants DNS to send new clients to the primary Region when it is healthy and automatically fail over to the secondary Region when the primary endpoint is unhealthy. Which two Route 53 settings are required? Select two.

Medium
688

A logistics company runs an order-tracking API on a fleet of EC2 instances in a single Availability Zone behind a Network Load Balancer. The architecture team must make the API resilient to the loss of that Availability Zone without changing the API endpoint that clients already use. The instances are stateless and store session data in a shared Amazon ElastiCache cluster. Which change should the solutions architect make to meet these requirements?

Medium
689

A public web application is fronted by Amazon CloudFront and an ALB. The team is seeing SQL injection attempts and bursts of malicious HTTP requests that increase origin load. They want to block common web attacks before they reach the ALB. What should they do?

Medium
690

A dev sandbox currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first?

Hard
691

A CI pipeline in account A uploads build artifacts to an S3 bucket (arn:aws:s3:::build-artifacts-prod) under the prefix teamA/. The pipeline must not be able to list other prefixes, and it must only upload objects under teamA/. Which IAM policy design best enforces least privilege for this requirement?

Medium
692

An application uses an Amazon Aurora cluster. The workload becomes read-heavy, but the team cannot change the database schema. They need higher read throughput while keeping writes on the primary. What should they do?

Easy
693

A containerized web service on Amazon ECS reads a database password at startup. Today, the password is stored in a plain environment variable and updated manually. Auditors require that credentials: (1) are encrypted at rest using AWS-managed controls, (2) can be rotated without redeploying the task definition, and (3) are accessible only to the running task via least-privilege permissions. Which solution best meets these requirements?

Medium
694

A service runs in private subnets. It must call AWS APIs (for example, S3 and Secrets Manager). The team currently sends all outbound traffic through a NAT Gateway, and NAT charges have become a major cost driver. The workload must not traverse the public internet. What change most directly reduces NAT Gateway cost while maintaining private connectivity to those AWS services?

Medium
695

A payments API uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The architecture review board prefers a managed AWS-native control.

Hard
696

Your organization hosts an internet-facing application behind an Amazon CloudFront distribution. You want to mitigate common web exploits (for example, SQL injection and XSS) at the edge. Which action is the most appropriate way to do this using AWS services?

Easy
697

A log archive serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The design must avoid adding custom operational scripts.

Medium
698

A startup has three sandbox accounts and one production account. The CTO wants lower cost and operational overhead while keeping central purchasing and spend visibility. Which two actions are best? Select two.

Hard
699

A internal reporting portal serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The architecture review board prefers a managed AWS-native control.

Medium
700

Based on the exhibit, a distributed analytics workload runs on 12 EC2 instances in one Availability Zone. The nodes exchange thousands of small messages per second and require the lowest possible intra-cluster latency and jitter. Which EC2 placement strategy is the best fit?

Hard
701

A document portal needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable? The design must avoid adding custom operational scripts.

Hard
702

A startup runs an HTTP/2 API that also supports WebSocket connections. They need path-based routing to separate microservices (for example, /api/* to Service A and /metrics/* to Service B) and want TLS terminated at the load balancer. Which AWS option best meets these requirements while maintaining high request performance?

Medium
703

A company wants to give a third-party auditor read-only access to a specific Amazon S3 bucket for a limited period. The auditor has an AWS account and will use their own IAM credentials. The company must not share long-term credentials and wants to revoke access automatically when the audit ends. What is the most secure way to grant this access?

Easy
704

Your AWS Organizations environment has an SCP that explicitly denies kms:Decrypt for principals in the Production OU. A member account IAM policy for a user grants kms:Decrypt on the required KMS key. If that user attempts kms:Decrypt, what happens?

Easy
705

A company runs a stateless web application on a fleet of six On-Demand EC2 instances behind an Application Load Balancer. The instances are spread across three Availability Zones in a single AWS Region and run 24/7. The workload is steady and predictable, and the company wants to reduce compute costs without changing the application architecture or reducing availability. The company is willing to commit to a one-year term. Which two actions will reduce the EC2 compute cost for this workload? (Choose two.)

Medium
706

A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The design must avoid adding custom operational scripts.

Medium
707

An Auto Scaling group for a background worker runs EC2 instances continuously. Over the last 30 days, CloudWatch shows sustained CPU utilization around 6% with no memory pressure, and queue processing latency meets all SLAs. The team wants to lower monthly cost with minimal risk. What is the best next action?

Medium
708

A media company stores original video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that a readable copy of every object exist in the eu-west-1 Region within 15 minutes of upload, and that the objects in eu-west-1 be usable directly by an application there. No transformations are required. Which S3 feature should the solutions architect enable?

Medium
709

A company stores private report PDFs in an S3 bucket. They want users to access PDFs only through CloudFront. Even if someone knows the S3 object URL, direct S3 access must fail. What is the best S3 bucket policy approach?

Easy
710

A regional web application for a content publishing system must fail over automatically to a secondary Region if the primary endpoint becomes unhealthy. Which two services or features are required? The design must avoid adding custom operational scripts.

Hard
711

A logistics company runs an order-tracking service that exposes a REST API. The service must remain available during a single Availability Zone failure and must keep read latency low for a globally distributed user base. The data store must support automatic multi-AZ replication without the team managing database servers. Which solution meets these requirements?

Medium
712

A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The design must avoid adding custom operational scripts.

Medium
713

A team serves image files from S3 through CloudFront. During a performance review, they notice that CloudFront cache hit ratio is low and the S3 origin receives many repeated requests for the same images. Request URLs include a volatile query parameter called 'sessionId' that changes for each user, but the image content is identical regardless of 'sessionId'. What configuration change will most effectively increase cache hit ratio?

Medium
714

A financial analytics team runs a batch job every night that scans a 4 TB Amazon Redshift provisioned cluster table to compute aggregates for a reporting dashboard. The dashboard queries are read-only, run for several hours each morning, and compete with ETL writes on the same cluster, causing slow dashboard response times. The team wants to isolate the dashboard workload and improve query performance without changing the ETL job. Which solution meets these requirements with the LEAST operational effort?

Hard
715

Your web application is deployed in two AWS Regions (Region A and Region B). You want Route 53 to automatically fail over DNS traffic from Region A to Region B when Region A is unhealthy. The failover decision must be based on health checks that verify whether the application in Region A is reachable. Which Route 53 routing configuration best meets these requirements?

Medium
716

A test environment has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations? The architecture review board prefers a managed AWS-native control.

Medium
717

An application in account A needs to use an encrypted EBS volume whose snapshots were copied from account B. The EBS volume is encrypted with a customer-managed KMS key in account B. After attaching the volume, the instance fails to mount it and logs show KMS access errors (kms:Decrypt) for the instance role. The instance role in account A already has an IAM policy allowing kms:Decrypt on that key ARN, but the mount still fails. What must be updated in account B to allow the mount to succeed?

Medium
718

An internal team runs a report-generation job once per day. It typically finishes in a few minutes, and even on its slowest days it still completes in under 15 minutes. The team wants to reduce operational overhead and pay primarily for actual runtime instead of keeping servers running 24/7. Which AWS approach best matches these goals?

Easy
719

A claims portal must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

Hard
720

A media company stores original video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that a readable copy of every object exists in eu-west-1 within 15 minutes of upload, and that objects deleted in the source bucket do not automatically disappear from the destination. Which S3 feature should the solutions architect enable?

Medium
721

A media processing company runs a stateless thumbnail-generation fleet on Amazon EC2 instances behind an Application Load Balancer. The instances store no local state, and the team wants the fleet to survive the loss of an entire Availability Zone without manual intervention. The fleet must also scale out automatically based on CPU. Which combination of AWS services should the solutions architect use to meet these requirements with the LEAST operational overhead?

Medium
722

Based on the exhibit, the company has one shared S3 bucket for many internal teams. Security wants each team to access only its own prefix, ACLs must remain disabled, and the current bucket policy has become too large and error-prone. What is the best redesign?

Hard
723

A trading dashboard uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The design must avoid adding custom operational scripts.

Medium
724

A internal reporting portal serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The design must avoid adding custom operational scripts.

Medium
725

An e-commerce application uses Aurora MySQL. Writes are modest, but the product-detail page generates many read-only queries and the writer instance CPU is high. The application can tolerate a small amount of replication lag on those reads. What should the team do?

Medium
726

A company hosts a B2B file exchange site on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use? The design must avoid adding custom operational scripts.

Medium
727

A company hosts a B2B file exchange site on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

Medium
728

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be highly available and able to withstand the failure of an entire AWS Region. The company wants to minimize operational overhead and ensure that failover is automatic. Which solution should a solutions architect recommend?

Medium
729

A order processing API stores audit logs in S3. The compliance team requires that logs cannot be overwritten or deleted for seven years. What should be configured? The design must avoid adding custom operational scripts.

Medium
730

A dev sandbox currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first? The design must avoid adding custom operational scripts.

Hard
731

A startup runs two EC2-based workloads in the same AWS Region. Its customer-facing API is always on, and its nightly video transcoding fleet can restart jobs from checkpoints if an instance is interrupted. The finance team wants the lowest monthly compute cost without changing the application design. Which two actions should the team take? Select two.

Medium
732

A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The team wants the control to be enforceable during normal operations.

Medium
733

A marketing site runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost? The architecture review board prefers a managed AWS-native control.

Medium
734

A financial services firm runs a stateful trading application on EC2 instances in an Auto Scaling group. Each instance maintains an in-memory cache that takes several minutes to rebuild after a restart, and the team wants the application to survive the loss of an Availability Zone with minimal disruption. The application cannot be made stateless in the near term. Which approach should a solutions architect recommend?

Hard
735

A finance application stores invoices in Amazon S3. Security requires that the data be encrypted with a key they control, and they want the ability to disable access quickly if the application is suspected of compromise. Developers do not want to manage encryption in application code. Which solution best meets these requirements?

Medium
736

An EC2 workload runs in one region on a single instance type. For the last month, CloudWatch metrics show average CPU utilization of 12% and no sustained memory pressure. The team wants to reduce cost while maintaining the current performance level. What is the best first step?

Easy
737

A security operations team wants continuous compliance checks for AWS resources. They need to know when an EBS volume becomes unencrypted or when a security group starts allowing SSH from 0.0.0.0/0. Which AWS service should they use?

Medium
738

A startup runs a static website hosted on Amazon S3. The website is accessed globally, and users in Europe report slow load times. The company wants to improve performance for these users without changing the website's code. Which AWS service should the company use?

Easy
739

A healthcare company runs a patient portal on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in memory on each instance, and users are being logged out when the load balancer routes them to a different instance. The company wants to keep the application stateless and avoid modifying application code. Which solution best meets these requirements?

Hard
740

A workload runs in private subnets and must reach Amazon S3 and AWS Secrets Manager without using the internet or a NAT gateway. The team wants to keep the traffic on AWS private networking and avoid public IPs. Which two changes should the architect make? Select two.

Medium
741

A company runs an Amazon DynamoDB table that stores session data for a consumer application. The table is 800 GB and receives highly variable read and write traffic with sharp, unpredictable peaks during marketing campaigns. The team currently provisions 20,000 read capacity units and 10,000 write capacity units and frequently sees throttling during peaks and wasted capacity between them. A solutions architect must reduce cost and eliminate throttling with the least operational effort. Which solution meets these requirements?

Hard
742

An application uses an Amazon Aurora DB cluster. The cluster performs an automatic failover from the writer instance to a standby instance. After failover completes, reads succeed, but all new writes fail with errors indicating the application is connecting to the old writer endpoint. Which change best fixes the resiliency issue after failover?

Medium
743

A media platform stores originals in an S3 bucket. The application must: (1) prevent any public access to the bucket, (2) allow authenticated users to upload and download objects using presigned URLs, and (3) enforce that all requests use HTTPS and only touch objects under the user-specific prefix (for example, s3://media-originals/user-123/*). The bucket currently allows uploads but sometimes returns 403 AccessDenied for presigned URLs. Which change is the best fix while meeting the security requirements?

Medium
744

A media company has an Amazon RDS for MySQL database in a private subnet. A web application on Amazon EC2 instances must connect to the database, and the security team requires that the database credentials be rotated every 30 days without application downtime. Which solution should a solutions architect recommend?

Medium
745

A company needs to store application logs in a durable and highly available manner. The logs are written continuously by multiple EC2 instances and are accessed infrequently for compliance audits. The company wants a solution that provides 99.999999999% (11 9's) durability and automatically replicates data across multiple Availability Zones. Which AWS service should the company use?

Easy
746

A healthcare document service uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?

Hard
747

Based on the exhibit, which AWS service should the security team enable to continuously discover sensitive data stored inside Amazon S3 objects?

Medium
748

A startup expects steady compute usage around the clock for the next year. They want to reduce costs compared to On-Demand pricing, without tightly planning specific instance types. Which option best matches their goal?

Easy
749

Based on the exhibit, the application should continue serving requests if one Availability Zone fails. Which change best improves resilience with the least operational complexity?

Medium
750

A company hosts static images, CSS, and JavaScript files in an Amazon S3 bucket. Users around the world report slow page loads, and the origin receives many repeated requests for the same files. What should the team use to improve performance?

Easy
751

A batch analytics job has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The architecture review board prefers a managed AWS-native control.

Medium
752

A web application behind an Application Load Balancer (ALB) currently allows client connections over HTTP (port 80). The security policy requires all client traffic to use HTTPS. What is the best ALB change to enforce this requirement?

Easy
753

A partner company needs read-only access to reports in an S3 bucket for a image sharing application. The partner has its own AWS account. What is the most secure scalable access pattern?

Medium
754

A test environment stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost? The design must avoid adding custom operational scripts.

Medium
755

A log archive has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances? The design must avoid adding custom operational scripts.

Hard
756

A startup runs a stateless web tier on Amazon EC2 instances in an Auto Scaling group that spans three Availability Zones. The team wants the application to keep serving requests even if one instance becomes unresponsive, without operator involvement. What should the solutions architect configure?

Easy
757

A web API runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). During traffic spikes, users experience request timeouts even though CPU stays below 40%. After investigation, you find the ASG often has too few healthy targets to handle the current request rate. Which change will best improve responsiveness during spikes?

Medium
758

A startup runs a customer-facing web application on a single Amazon EC2 instance in one Availability Zone, with the database on the same instance. The founders want the application to survive the failure of that Availability Zone with minimal changes and no server management for the database tier. Which action should the solutions architect take first?

Easy
759

A startup runs a web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to encrypt data in transit between clients and the load balancer using a certificate managed by AWS, with minimal operational overhead. Which solution meets these requirements?

Easy
760

A media company uploads raw video thumbnails to an S3 bucket every hour. The application needs these thumbnails for active browsing for the first 7 days. After day 7, access becomes rare. Requirements: - Objects must remain available in S3 for at least 180 days total. - After day 7, the team can tolerate retrieval latency in the range of minutes to hours. - They want to minimize storage cost while keeping the ability to read objects (no application changes required). Which storage strategy is the most cost-optimized fit?

Medium
761

Based on the exhibit, the payment worker sometimes processes the same SQS Standard message more than once after a timeout. What change best prevents duplicate charges while keeping the queue architecture?

Medium
762

Multiple teams share one AWS Organization. Finance wants chargeback by project, alerts before overspend, and monthly views by account without manually opening each account. Which three actions best fit? Select three.

Hard
763

A healthcare company uses AWS Lambda functions to process sensitive patient data. The functions need to access an Amazon RDS for MySQL database. The security team requires that database credentials are never stored in the Lambda function code or environment variables, and that credentials are automatically rotated every 90 days. The company also wants to minimize the operational overhead of managing the rotation. Which solution should a solutions architect recommend?

Hard
764

Developers for a customer analytics portal need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?

Medium
765

A production Amazon RDS database has automated backups enabled. At 10:00 UTC, an application deploy accidentally overwrote a subset of rows due to a faulty migration. The issue is detected at 10:45 UTC. The team confirms that the required retention window is still available. Which approach offers the most resilient and least disruptive way to recover the affected data close to the time of the event?

Medium
766

Based on the exhibit, which storage choice best matches the workload requirements?

Hard
767

A company runs an Amazon Aurora DB cluster with a Multi-AZ deployment. The application is configured with a hard-coded endpoint that points to the current writer *DB instance* (an instance-specific endpoint), rather than the Aurora cluster writer endpoint. During an unexpected AZ failure, Aurora promotes the standby to become the new writer. However, the application continues to fail to connect until an operator updates the hard-coded endpoint. What change most directly improves resiliency so the application automatically reconnects after failover?

Medium
768

A latency-sensitive video platform uploads large files to S3 from users around the world. Which two features can improve upload performance? The design must avoid adding custom operational scripts.

Hard
769

A retailer runs a reporting-heavy relational app on Amazon RDS MySQL. Peak dashboard traffic lasts only three hours each day, but the database is sized for the peak all day. The business wants lower cost without rewriting the application. Which three actions are best? Select three.

Hard
770

A genomics company stores about 400 TB of compressed research data in Amazon S3 and runs a nightly analysis job on a fleet of EC2 instances in the same Region. The job reads the entire dataset every night, and the team wants to reduce the time the fleet spends waiting on storage without changing the data format or the S3 bucket. Which change best improves read throughput for the fleet?

Hard
771

Based on the exhibit, duplicate payment charges occasionally occur when the worker times out after the charge is submitted but before the message is deleted. What change best prevents duplicate charges while keeping retry behavior?

Hard
772

A team wants a web application to keep serving traffic if one Availability Zone fails. Match each architecture element to the resilience behavior it provides.

Medium
773

A data engineering team ingests a continuous stream of clickstream events into Amazon Kinesis Data Streams. Downstream consumers process the events, but the team observes that a single consumer is handling a disproportionate share of the records, causing hot shards and throttling. The team wants the stream to distribute records as evenly as possible across shards. Which change should the team make?

Hard
774

A fintech company runs a containerized payment API on Amazon ECS with AWS Fargate. The security team requires that the API access a stored database credential without hardcoding it in the task definition or environment variables. The credential must be encrypted at rest and automatically rotated every 90 days. The API also needs to retrieve the credential at container startup with minimal latency. Which solution meets these requirements?

Medium
775

A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The team wants the control to be enforceable during normal operations.

Medium
776

A team stores application logs in Amazon CloudWatch Logs. They enabled long retention and detailed dashboards, resulting in higher-than-expected monthly spend. Compliance requires retaining logs for 90 days, but operations only needs aggregated views. Which change most directly reduces CloudWatch Logs cost while meeting the requirement?

Easy
777

A financial services company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to inspect incoming requests for common web exploits and block malicious traffic before it reaches the application. They also need to monitor for SQL injection attempts and receive near-real-time metrics. Which AWS service should be used to meet these requirements?

Hard
778

You have an EC2 instance in private subnets with no NAT Gateway. The instance must access an Amazon S3 bucket (for example, to read configuration files) without sending traffic to the public internet. What VPC endpoint type should you use for S3?

Easy
779

A backend API uses an AWS Lambda function behind API Gateway. The first requests after every weekly deployment experience cold starts, causing p95 latency spikes for a few minutes. Which configuration most directly prevents those cold starts for the published version?

Easy
780

A site serves static assets (JS/CSS) through CloudFront from an S3 origin. After a recent frontend change, CloudFront shows a cache hit ratio below 20%. In CloudFront access logs, requests to the same asset URL path differ by a query parameter named rnd (a random value appended by the app on every request). The origin content is identical regardless of rnd. What is the best CloudFront configuration change to restore effective caching?

Medium
781

A logistics company runs an order-tracking service on Amazon EC2 instances that write state to an Amazon DynamoDB table. A recent incident showed that a single Availability Zone failure caused the service to lose capacity, and the team also discovered that a developer accidentally deleted a production table. The architect must improve both Availability Zone resilience and protection against accidental table deletion. (Choose two.)

Medium
782

A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The team wants the control to be enforceable during normal operations.

Hard
783

A company runs a media transcoding service on Amazon EC2 instances behind an Application Load Balancer. The workload is steady at 60% CPU utilization from 08:00 to 18:00 local time on weekdays and drops to under 5% overnight and on weekends. A solutions architect must reduce compute costs without changing the application code or degrading transcoding throughput during peak hours. (Choose two.)

Medium
784

An internal web application must require encrypted client connections. The company currently has an ALB listener on port 80 (HTTP), and users can access the application over plain HTTP. What is the best change to ensure all client traffic uses HTTPS?

Easy
785

A microservice runs in private subnets with no NAT gateway. It must retrieve a secret from AWS Secrets Manager. Security requires that traffic to Secrets Manager stays within AWS’s private network (no public internet egress). The IAM role already grants secretsmanager:GetSecretValue for the needed secret. What is the best network setup to meet the requirement?

Medium
786

A new feature stores user events in DynamoDB. Each event must be fetched by user_id and sorted by event_time. The team expects many different users and wants to avoid a single hot partition. Which partition key design is best?

Easy
787

A log archive has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances? The architecture review board prefers a managed AWS-native control.

Hard
788

A company is designing a high-performance web application that serves static and dynamic content to a global user base. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The static assets are stored in an S3 bucket. Which three architecture decisions will improve performance and reduce latency for users? (Choose three.)

Medium
789

A production log archive runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy?

Medium
790

Based on the exhibit, which AWS feature should the team use to minimize network latency between EC2 instances that exchange messages very frequently?

Easy
791

A team uses an S3 bucket to store important customer-generated exports. They need protection against accidental overwrites and also want copies of the data in another AWS Region for disaster recovery. Which S3 configuration best satisfies both requirements?

Easy
792

A media company runs a video-transcoding fleet on Amazon EC2 instances that read source files from an Amazon S3 bucket and write output to a second bucket. The fleet is spread across three Availability Zones in one Region, and instances are launched by an Auto Scaling group. The company needs the architecture to survive the loss of an entire Availability Zone without losing in-flight transcoding work or requiring manual intervention. Which combination of design elements should a solutions architect implement to meet these requirements?

Medium
793

A solutions architect is designing a high-performance architecture for a read-heavy web application backed by Amazon RDS for MySQL. The database is currently a single db.r6g.4xlarge instance that is CPU-bound during peak hours, and the application performs many repeated identical read queries. The architect must improve read scalability and reduce load on the primary instance. (Choose two.)

Medium
794

A company runs an internal API on Amazon EC2 instances in a private subnet. Clients in an on-premises data center must reach the API over a private connection, and the security team wants to inspect and filter the traffic using AWS managed security appliances before it reaches the application. The company has already established an AWS Site-to-Site VPN to a transit gateway. Which two actions should the security engineer take to route and inspect the traffic? (Choose two.)

Medium
795

A media archive needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable?

Hard
796

A media company hosts a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from specific IP addresses that exhibit abusive behavior. Which combination of AWS services should a solutions architect recommend?

Medium
797

Based on the exhibit, what is the best way to let private EC2 instances reach Amazon S3 and AWS Systems Manager without sending traffic through the internet or a NAT gateway?

Medium
798

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application stores user-uploaded images in an Amazon S3 bucket. Users report slow image upload times, especially from mobile devices in remote locations. The solutions architect needs to improve upload performance for these users. Which action should the architect take?

Easy
799

A media company runs a fleet of EC2 instances using Auto Scaling across multiple instance families (for example, m-series and c-series) in a single region. The business wants to commit to steady usage for one year to reduce cost, but the application team must retain flexibility to switch instance families and scale up/down as demand changes. They need the cost-reduction approach that best matches this flexibility. Which option is the best fit?

Medium
800

Based on the exhibit, a serverless checkout API is implemented in AWS Lambda and deployed in one Region. The function has a cold-start time of 700-900 ms on the first request after idle periods. Marketing launches a predictable traffic spike every weekday at 09:00 UTC, and the p95 latency target is under 150 ms during the first five minutes of the spike. What should the solutions architect do to meet the latency target while controlling cost?

Hard
801

A solutions architect is designing a high-performance architecture for a web application that serves static content from Amazon S3 and dynamic content from an Application Load Balancer. The application must deliver low latency to users across multiple continents and reduce origin load. The team wants to use Amazon CloudFront. Which two actions should the architect take to meet these requirements? (Choose two.)

Medium
802

A financial analytics team runs a read-heavy workload on Amazon Aurora MySQL. The primary instance is experiencing high CPU during end-of-day reporting, and read replicas are lagging by several seconds. The application requires strong read consistency for account balances but can tolerate eventual consistency for historical reports. Which change should a solutions architect make to improve performance while meeting consistency requirements?

Hard
803

A company is designing a disaster recovery plan for a critical application hosted on AWS. The application runs on EC2 instances with data stored in Amazon EBS volumes and Amazon S3. The recovery time objective (RTO) is 15 minutes, and the recovery point objective (RPO) is 1 hour. Which three strategies would help meet these objectives? (Choose three.)

Medium
804

A company needs to implement session management for a web application. Sessions must persist across multiple EC2 instances, survive EC2 failures, and be accessible with sub-millisecond latency. Sessions must also be sortable by last-access time to expire the oldest sessions first. Which caching solution should a solutions architect recommend?

Medium
805

A security team stores sensitive documents in an Amazon S3 bucket that is encrypted with SSE-KMS using a customer managed key. An auditor requires that every object upload be traceable to the IAM principal that performed it and that the key's usage be independently auditable. The team also wants to prevent any principal, including account administrators, from reading objects without a corresponding key grant. Which configuration combination meets these requirements?

Hard
806

A service consumes messages from an SQS queue. Recently, a new message format started failing validation in the consumer. The consumer catches the exception but cannot successfully process those messages without code changes. The team wants failed messages to be isolated for later investigation instead of being retried indefinitely. What should they configure?

Medium
807

A solutions architect is reviewing a workload that runs on a fleet of Amazon EC2 instances in a single AWS Region. The application serves a global user base, and the team wants to reduce both data transfer costs and latency for users in Europe and Asia. The application is stateless and stores assets in Amazon S3. The team is also evaluating how to pay for the compute layer over the next three years, as usage is expected to be steady. Which two actions will reduce cost in this scenario? (Choose two.)

Hard
808

A production Amazon RDS database has automated backups enabled with sufficient retention. At 10:30 UTC, a release corrupts specific rows. The issue is detected at 10:45 UTC. The team wants to restore the database state to before the corruption with minimal complexity. What should they do?

Easy
809

A Multi-AZ Amazon RDS database experiences incorrect writes at 10:15 UTC due to a buggy release. The team detects the problem at 10:25 UTC. They want to restore the data to a known-good point around 10:15 UTC, and validate the recovered data, without taking the current production instance offline during the recovery process. What is the most appropriate AWS action?

Medium
810

A financial services company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be accessible only from a specific corporate IP range (203.0.113.0/24). The security team wants to restrict access at the load balancer level and also ensure that the instances themselves only accept traffic from the ALB. Which combination of security group configurations should a solutions architect implement?

Easy
811

A financial analytics platform ingests events into an Amazon Kinesis Data Stream with four shards. During month-end peaks, producers receive ProvisionedThroughputExceededException errors and consumers fall behind. The architects want to increase capacity without changing producer code and must preserve the order of records that share the same partition key. What should they do?

Hard
812

Developers for a financial reporting platform need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?

Medium
813

A company runs a containerized web application on Amazon ECS with a steady baseline of 10 tasks that must run continuously. During business hours, traffic spikes require up to 30 additional tasks that can be terminated at any time. The company wants to minimize costs while ensuring the baseline tasks are always available. Which combination of purchasing options should be used for the ECS tasks?

Medium
814

A company runs a REST API on AWS Lambda behind Amazon API Gateway. The API is used by internal clients during a two-hour batch window each night and is completely idle the rest of the day. The team is concerned about the cost of API Gateway and wants to minimize it without changing the API contract for clients. Which change should a solutions architect recommend?

Medium
815

A production team accidentally deletes critical rows in an Amazon RDS for PostgreSQL database. The deletion occurred about 6 hours ago. The team wants to recover to a specific point in time with minimal disruption. Assuming automated backups are enabled, which approach provides the best resilience outcome?

Medium
816

An application uses Amazon Aurora MySQL. CloudWatch shows the writer instance near 85% CPU while the only reader instance averages 15% CPU. Trace logs show that all SELECT statements still target the writer endpoint. The workload is read-heavy, and the application already tolerates eventual consistency for reads. Which two changes will best increase total read throughput without a schema redesign? Select two.

Hard
817

A company stores sensitive data in an Amazon S3 bucket. The security team must ensure that all data is encrypted at rest using a customer managed AWS KMS key (CMK) and that the key's usage is auditable. They also need to be able to rotate the key annually. Which solution meets these requirements?

Medium
818

A mobile game backend uses Amazon Aurora. The workload has many short-lived database connections from Lambda functions, causing connection storms. What should be added? The design must avoid adding custom operational scripts.

Medium
819

A company wants a disaster recovery setup for a web application. They want to keep costs low but still recover within a couple of hours after a regional disruption. They are willing to run only minimal infrastructure in the secondary location and scale it up during the outage. Which DR approach best matches this requirement?

Easy
820

A financial services company is designing a new payment processing platform. The platform must continue to accept and process transactions even if an entire AWS Region becomes unavailable, and it must not lose any accepted transaction. The architects have decided to run active-active deployments in two Regions and use Amazon Route 53 for traffic management. Which two additional design elements are required to meet the durability and availability goals? (Choose two.)

Hard
821

A inventory service exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most? The design must avoid adding custom operational scripts.

Easy
822

A financial services company runs a critical application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application must be able to survive the failure of an entire AWS Region. The company wants a cost-effective solution that minimizes operational overhead. Which approach should the architect recommend?

Hard
823

A DynamoDB table for a travel booking site has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change?

Hard
824

A company stores nightly database backup files in an Amazon S3 bucket. Each backup is about 50 GB, and the files are written once and never modified. Regulatory policy requires that every backup be retained for exactly seven years, after which it may be deleted. Retrieval of a backup for an audit is extremely rare and the company can tolerate a retrieval time of up to 12 hours. Which S3 storage class is the MOST cost-effective choice for these backups?

Easy
825

A marketing team uses CloudFront with an S3 origin to serve a single-page web app. After a release, CloudFront cache hit ratio dropped sharply. The app requests the same static JS and CSS assets, but each request includes a unique tracking query parameter (for example, ?utm_source=campaign123, campaign456, etc.). You want CloudFront to cache those assets efficiently even when the tracking query parameter changes. What should you do?

Medium
826

A trading platform ingests market data events at very high volume and must deliver them with the lowest possible latency to multiple independent consumer applications. Each consumer must read the full stream independently, and ordering must be preserved per instrument symbol. Which solution meets these requirements?

Hard
827

A financial analytics company runs an Amazon RDS for MySQL database that supports a read-heavy web application. The primary DB instance is heavily loaded during business hours, and read replicas are already deployed and receiving traffic from the application. The team wants to reduce the load on the primary DB instance caused by read queries as much as possible, while keeping the application changes minimal. Which action should a solutions architect take?

Medium
828

A financial services company stores sensitive customer statements in an Amazon S3 bucket. The security team requires that all data be encrypted at rest using keys that the company manages and rotates on its own schedule. The company also needs an audit trail of every time a key was used to encrypt or decrypt data. Which solution meets these requirements?

Easy
829

Based on the exhibit, which Route 53 configuration should be used so traffic automatically returns to the secondary Region only when the primary Region becomes unhealthy?

Medium
830

A travel booking site uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured?

Easy
831

A video processing pipeline runs batch jobs that are safe to interrupt and restart. The jobs checkpoint progress to durable storage every few minutes, and the team can automatically resubmit from the last checkpoint. They want to minimize compute cost while accepting that capacity can be interrupted. Which launch configuration for the processing workers is the best cost-optimized choice?

Medium
832

A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first?

Hard
833

A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). After a new release, instances begin failing ALB health checks with errors like 502 while the application is still starting up. CloudWatch shows that the ASG replaces the instances before they finish initializing, so traffic never reaches healthy targets. Which change most directly prevents premature replacement during startup so traffic can resume as soon as the instances are actually healthy?

Medium
834

A company runs a stateless web API on Amazon EC2 behind an Application Load Balancer. The team notices that during business hours, the ALB starts queueing requests and the average request latency rises. They want to scale out quickly and reliably based on demand, not CPU alone. Which Auto Scaling approach best matches this requirement?

Easy
835

A SaaS company runs a production API on an EC2 Auto Scaling group with steady demand 24/7. The team uses multiple instance types over time (they switch types during tuning) but the overall compute hours are stable. They want a cost reduction without committing to a specific instance type or size. Which AWS pricing option best meets the requirement?

Medium
836

A company hosts a financial reporting platform on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?

Medium
837

A company is designing a multi-Region disaster recovery (DR) strategy for a stateless web application running on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses an Amazon RDS for MySQL database as its data store. The architecture must provide rapid failover with the lowest possible Recovery Point Objective (RPO) and Recovery Time Objective (RTO). Which of the following design choices will help achieve these objectives? (Choose four.)

Medium
838

A CPU-bound batch rendering service runs on EC2. The application is Linux-based, compatible with ARM64, and the team wants the best throughput per dollar without changing the workload's architecture. Which two instance-family choices should the team consider first? Select two.

Medium
839

A startup runs a static marketing website on Amazon S3 and wants to serve it to users worldwide with low latency. The site consists of HTML, CSS, JavaScript, and images stored in a single S3 bucket in the us-east-1 Region. The team wants to minimize cost while improving global performance. Which solution should the team implement?

Easy
840

A Lambda-based travel booking site has unpredictable traffic spikes and users see latency caused by cold starts. The function must respond consistently during expected campaign windows. What should be configured? The architecture review board prefers a managed AWS-native control.

Hard
841

Based on the exhibit, a single EC2 instance hosts a latency-sensitive cache that performs sustained random reads and writes to persistent block storage. The current EBS volume is a general-purpose SSD, but BurstBalance is repeatedly depleted and p95 I/O latency has risen above 20 ms. The workload needs more than 16,000 sustained IOPS. Which change is the best fix?

Hard
842

Multiple EC2 instances in different Availability Zones need concurrent read/write access to the same shared files. The files are actively modified by several application servers, and low-latency metadata operations matter more than extremely high aggregate throughput. Which two changes should the team make? Select two.

Hard
843

An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a financial reporting platform. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy? The design must avoid adding custom operational scripts.

Hard
844

A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost?

Medium
845

A company serves mostly static images and JavaScript files from an origin in one AWS Region. They want to reduce origin load and improve global performance. Which change most directly increases cache-hit ratio for static assets while avoiding stale content?

Easy
846

A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost? The design must avoid adding custom operational scripts.

Medium
847

A team wants to run containerized services with AWS-managed orchestration and autoscaling. They do NOT require Kubernetes compatibility. Which AWS service choice is most appropriate to meet these goals?

Easy
848

A startup runs a stateless image-resizing API on a fleet of EC2 instances behind an Application Load Balancer. The instances store uploaded source images on their own instance store volumes before processing. During a routine scale-in event, an instance was terminated and several in-flight uploads were lost. The architect must make the design resilient to instance loss without changing the API code. What should the architect do?

Easy
849

A retail API uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured? The design must avoid adding custom operational scripts.

Easy
850

A logistics company runs workloads in a VPC with private subnets that have no internet gateway route. Instances in these subnets must retrieve secrets from AWS Secrets Manager and download patches from an Amazon S3 bucket owned by the company. The security team requires that this traffic never traverse the public internet. (Choose two.)

Hard
851

A inventory service uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The design must avoid adding custom operational scripts.

Medium
852

A web application runs in private subnets with no NAT gateway. It needs to retrieve credentials from AWS Secrets Manager at runtime. After a recent network hardening change, the application logs timeout errors when calling Secrets Manager. Which change will most directly enable private connectivity to Secrets Manager while keeping the subnets NAT-free?

Medium
853

A team is designing a new workload that runs on Amazon EC2 instances in a private subnet. The instances must read and write objects in an Amazon S3 bucket in the same account, and security policy forbids long-term access keys on the instances. The team wants to grant least-privilege access and ensure the instances can reach S3 without traversing the public internet. (Choose two.)

Hard
854

A company runs a customer portal on an Amazon Aurora PostgreSQL cluster. The application currently connects directly to the writer instance endpoint and keeps long-lived connections open. During a maintenance failover, writes fail until clients are restarted. The team wants the application to reconnect to the correct Aurora endpoint automatically and reduce user-visible write interruptions. Which change is most likely to achieve this?

Medium
855

A media processing pipeline runs batch jobs on EC2. The jobs can tolerate interruptions because they checkpoint progress to durable storage and can restart. The total workload is variable week-to-week, and there is no need to guarantee capacity at specific times. To reduce compute cost while maintaining correctness, what EC2 purchase option and approach is the best fit?

Medium
856

A web application for a IoT ingestion API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?

Medium
857

A healthcare company runs a three-tier web application on AWS. The application tier consists of EC2 instances in an Auto Scaling group behind an Application Load Balancer. The security team must ensure that the application instances accept traffic only from the load balancer and that no instance can be reached directly from the internet. The instances are in private subnets and have a security group attached. What should a solutions architect do to meet these requirements?

Medium
858

A healthcare analytics firm stores protected health information in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. The firm's security team wants to ensure that only a specific IAM role used by an analytics application can decrypt objects, while other principals in the same account with broad S3 permissions cannot. The key policy currently grants kms:* to the account root. Which change should a solutions architect make to enforce the restriction?

Hard
859

A company has a VPC with a CIDR block of 10.0.0.0/16. They need to deploy a web application that must be accessible from the internet. The application will run on Amazon EC2 instances in an Auto Scaling group. The security team requires that the instances be in private subnets and that inbound traffic from the internet be allowed only on ports 80 and 443. They also want to use an Application Load Balancer (ALB) for load balancing and SSL termination. Which architecture meets these requirements?

Hard
860

A developer accidentally deletes important rows in an RDS database. The mistake is discovered 45 minutes later. The database has automated backups enabled with a retention period of 7 days. What is the best way to restore the database to a point just before the deletion?

Medium
861

Based on the exhibit, a partner account uploads encrypted objects to a central S3 bucket and later reads them back. The S3 permissions are correct, but the requests still fail. What change is required so the partner workload can use the customer-managed KMS key safely?

Hard
862

A claims portal uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend? The design must avoid adding custom operational scripts.

Hard
863

A payments API uses an RDS MySQL database and must remain available during an Availability Zone failure with minimal application changes. What should the architect enable?

Medium
864

You host a public API using Amazon API Gateway in two AWS Regions: us-east-1 (primary) and us-west-2 (secondary). You want Route 53 to send client traffic to the secondary region only when the primary API is unhealthy. Which Route 53 setup best meets this requirement?

Medium
865

A DynamoDB table uses this schema: partition key = customerId, sort key = timestamp. During a marketing campaign, one customer generates extremely high read traffic and the application sees ProvisionedThroughputExceeded errors even though the table’s total capacity is sufficient. What change most directly improves read distribution across partitions?

Medium
866

A media company stores its video uploads in an Amazon S3 bucket. The security team wants to ensure that any objects uploaded to the bucket are encrypted at rest using keys managed in AWS Key Management Service (AWS KMS) and that the encryption key is rotated annually. Which solution should a solutions architect recommend?

Easy
867

A security requirement states: all uploads to an S3 bucket must (1) use TLS in transit and (2) use server-side encryption with AWS KMS (SSE-KMS) using the CMK key id 'abcd-1234'; otherwise the upload should be rejected. A developer reports that uploads are succeeding even though clients are sometimes using non-encrypted requests. Which bucket policy approach most directly enforces both controls?

Medium
868

A media processing workflow in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost?

Hard
869

An ECS service runs on EC2 instances and is fronted by an ALB. The ALB spans two Availability Zones, and the ECS service desired count is 2 tasks. The underlying EC2 capacity uses an Auto Scaling group (ASG) with min size set to 1, and the ASG also spans only one subnet in practice. What is the most effective change to meet the requirement that the service continues during a single-AZ instance loss?

Medium
870

A web service runs on an Auto Scaling group (ASG). The team updates configuration (AMIs, environment variables) in a Launch Template and wants new instances created during scale-out to use the latest Launch Template version. What should the architect do?

Easy
871

A global mobile game backend serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most?

Medium
872

A fleet of test servers is rebuilt every week from AMIs. EBS volumes are often left behind after termination, and the team creates daily snapshots of every volume even when nothing changes. Which three actions most reduce storage cost while preserving recovery options? Select three.

Hard
873

A solutions architect is designing a highly available relational database tier for a customer-facing order system that must survive the loss of an entire Availability Zone with minimal administrative effort and no application connection-string changes during failover. (Choose two.)

Medium
874

A document portal requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable?

Medium
875

A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The design must avoid adding custom operational scripts.

Medium
876

A company runs a stateless containerized web application on Amazon ECS with the Fargate launch type behind an Application Load Balancer. The application must scale out quickly when request latency rises and scale in when traffic drops, and the operations team wants a managed target-tracking approach. Which solution meets these requirements?

Easy
877

A healthcare data platform stores patient documents in an Amazon S3 bucket in us-east-1. Regulations require that the data remain readable with low latency even if the entire us-east-1 Region becomes unavailable, and that writes continue in a secondary Region. The team wants object-level replication with minimal operational overhead and must preserve version history. Which solution BEST meets these requirements?

Hard
878

A mobile banking backend must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

Hard
879

Based on the exhibit, an administrator accidentally deleted data from Amazon RDS for PostgreSQL about 90 minutes ago. Which recovery approach best restores the database to the exact required point in time?

Medium
880

A partner company needs read-only access to reports in an S3 bucket for a B2B file exchange site. The partner has its own AWS account. What is the most secure scalable access pattern? The design must avoid adding custom operational scripts.

Medium
881

A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most?

Medium
882

A genomics research company runs a large-scale sequence alignment workload on AWS. The workload requires a shared file system that can be accessed concurrently by thousands of EC2 instances, provides high throughput and low latency, and supports POSIX permissions. The data set is about 500 TB and grows by 10 TB per month. The solutions architect needs to choose a storage solution that meets these performance and scalability requirements. Which solution should the architect use?

Hard
883

A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first? The design must avoid adding custom operational scripts.

Hard
884

You have EC2 instances in private subnets with no NAT gateway. They must retrieve secrets from AWS Secrets Manager without sending traffic to the public internet. Which VPC endpoint type is the correct choice for connecting to AWS Secrets Manager?

Easy
885

A company wants to protect a critical application from a full Region outage. The secondary Region should keep only a small amount of infrastructure running most of the time to control cost. Which disaster recovery strategy fits best?

Easy
886

A static marketing site is served through CloudFront from an S3 origin. After a product update, customers report a drop in CloudFront cache hit ratio and the CloudFront bill increases because the origin is receiving many more requests for the same JS/CSS assets. Asset URLs are versioned, but requests now include an Authorization header even though these assets are public. Which CloudFront change most directly improves the cache hit ratio for these assets?

Medium
887

A financial services company stores regulatory documents in an Amazon S3 bucket. The documents are accessed frequently for the first 90 days, then almost never, but must remain immediately retrievable for seven years. Retrieval latency of a few minutes is unacceptable, and the company wants the lowest storage cost that still meets the access requirement. Which S3 storage class should a solutions architect recommend?

Hard
888

A company has a VPC with a CIDR block of 10.0.0.0/16. The company wants to allow its EC2 instances in a private subnet to access Amazon S3 without traversing the public internet. The company also wants to minimize data transfer costs. Which solution should a solutions architect recommend?

Easy
889

A healthcare company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be accessible only to users connecting from a specific corporate IP range, and all traffic must be encrypted in transit. The security team wants to enforce these requirements at the load balancer level without modifying the application. Which combination of steps should a solutions architect take?

Hard
890

A startup runs an API on Amazon EC2. The instance must read items from one DynamoDB table and upload logs to one S3 bucket. Platform engineers also need a way to create new application roles, but those roles must never exceed a predefined set of permissions. Which three actions should the architect take? Select three.

Medium
891

A public API is served through an Application Load Balancer and protected by AWS WAF. The team wants AWS to automatically block clients that send too many requests from the same IP address within a short time window. Which AWS WAF feature is the best fit?

Easy
892

A company hosts a web application on Amazon EC2 instances in a VPC. The application must access an Amazon RDS for MySQL database. The security team requires that database credentials never be stored in application code or on disk, and that credentials be automatically rotated every 30 days. Which solution should a solutions architect implement?

Medium
893

A warehouse integration service receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers?

Medium
894

A workload runs in private subnets. It must access AWS services such as Amazon S3, but the company wants to avoid using a NAT Gateway to reduce outbound networking costs. What is the best solution?

Easy
895

A healthcare document service stores audit logs in S3. The compliance team requires that logs cannot be overwritten or deleted for seven years. What should be configured?

Medium
896

An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a image sharing application. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy?

Hard
897

A telemetry pipeline uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered? The architecture review board prefers a managed AWS-native control.

Medium
898

A small e-commerce company hosts its product catalog on a single Amazon EC2 instance in a public subnet. Traffic is steady and predictable, and the instance runs 24/7. The company wants to reduce its monthly compute bill without changing the architecture or risking availability. Which action should a solutions architect recommend?

Easy
899

A Lambda function for a order processing API needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?

Medium
900

A financial analytics platform runs a stateless API on Amazon EC2 instances in an Auto Scaling group behind a Network Load Balancer. The API reads from an Amazon Aurora MySQL cluster that has a single writer instance and one reader instance in a different Availability Zone. During a recent Availability Zone event, the writer instance failed and the API saw several minutes of failed writes. The team wants writes to resume automatically with minimal downtime and no application code changes. What should the solutions architect do?

Hard
901

A company runs an internal analytics application in a single AWS Region. A solutions architect is reviewing the Amazon RDS for MySQL deployment and finds a Multi-AZ DB instance with a standby in another Availability Zone, used only for failover. The application performs many read-heavy queries against the primary instance, driving up instance size and cost. The team wants to offload read traffic and reduce the primary instance size. Which change should the architect recommend?

Medium
902

Based on the exhibit, an application repeatedly reads the same DynamoDB items with extremely low latency requirements. The business can tolerate data that is a few seconds stale. Which architecture change best improves read performance?

Hard
903

An internal API is hosted in two AWS Regions behind Route 53. Under normal conditions, clients should use the primary region. If the primary endpoint becomes unhealthy, traffic must automatically switch to the secondary region. Which Route 53 setup best meets this requirement?

Easy
904

A Lambda function for a mobile banking backend needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used? The design must avoid adding custom operational scripts.

Medium
905

Based on the exhibit, what change should the team make to achieve the lowest possible network latency for the distributed workload?

Hard
906

A startup runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The application must call AWS APIs such as Amazon DynamoDB and Amazon S3. A security engineer must ensure that no long-term AWS credentials are stored on the instances and that each instance receives credentials automatically. Which solution should the engineer use?

Easy
907

A company stores millions of objects in Amazon S3. Access patterns are completely unpredictable — some objects are frequently accessed, others rarely. Objects range from 4 KB to 50 MB. The company wants to minimize storage costs automatically without managing lifecycle rules. Which storage class should a solutions architect recommend?

Medium
908

A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The design must avoid adding custom operational scripts.

Medium
909

A startup runs a public-facing web application on Amazon EC2 instances in a VPC. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to block traffic from specific countries. Which AWS service should a solutions architect use?

Easy
910

An orders service currently sends HTTP requests directly to two downstream services (inventory and shipping). During peak load, inventory slows down, causing the orders service to slow as well. The team wants the orders service to remain responsive even when a downstream service is temporarily slow or restarted. Which design change best achieves this resiliency goal?

Easy
911

A Lambda-based retail API has unpredictable traffic spikes and users see latency caused by cold starts. The function must respond consistently during expected campaign windows. What should be configured?

Hard
912

Your team serves static JavaScript and CSS files from an S3 origin through CloudFront. After a release, the CloudFront cache hit ratio dropped because clients keep re-downloading the same assets. What is the best next change to improve caching performance?

Easy
913

A content publishing system uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The design must avoid adding custom operational scripts.

Medium
914

A healthcare company runs a batch ingestion pipeline on Amazon EC2 instances that read messages from an Amazon SQS queue and write results to Amazon DynamoDB. The pipeline must be resilient so that a single instance failure does not stop processing and no messages are lost. Which two architectural changes should a solutions architect make to meet these requirements? (Choose two.)

Medium
915

A risk simulation workload in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost? The design must avoid adding custom operational scripts.

Hard
916

A financial services firm runs a stateless containerized trading dashboard on Amazon ECS with the Fargate launch type. The dashboard queries a backend over HTTPS and must present responses in under 200 ms. During market open, traffic triples within a few minutes and latency spikes because tasks take time to start. The team needs faster, more predictable scaling and wants to avoid over-provisioning during quiet periods. Which solution meets these requirements?

Hard
917

A service role has an IAM policy granting kms:Decrypt for a specific AWS KMS key. The application still fails to decrypt with an AccessDenied error. What change most directly fixes this when the KMS key policy is missing the role’s permissions?

Easy
918

A company runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. Traffic has grown, and the operations team notices that individual instances are often underutilized while others are saturated because traffic is not evenly distributed. The team wants the load balancer to distribute requests more evenly across healthy targets. Which action should the team take?

Easy
919

A media company serves on-demand video to viewers worldwide from an Amazon S3 bucket in us-east-1. Viewers in Asia and Europe report slow start times because the first byte takes several seconds to arrive. The videos are already stored as objects and must remain in the us-east-1 bucket as the origin. Which solution improves global read performance with the LEAST operational effort?

Medium
920

A company uses AWS Organizations and has separate development, test, and production accounts. The security team wants to ensure that no one in the sandbox organizational unit can disable AWS CloudTrail or delete the central audit bucket, even if an account administrator creates permissive IAM policies later. Which control should they use?

Medium
921

Your mobile app writes events to a single DynamoDB table with partition key = customerId and sort key = eventTime. During a promotional campaign, one tenant ("ACME") generates far more traffic than others. CloudWatch shows sustained throttling (ProvisionedThroughputExceeded) and elevated p99 latency only for that tenant. The workload pattern cannot be changed to a completely different schema, but you can change how items are partitioned. Which design change is most likely to reduce the hot-partition throttling while keeping efficient reads for ACME?

Medium
922

An Aurora PostgreSQL cluster is experiencing high read latency because 85% of traffic consists of read-only queries. The write workload must stay on the writer instance, and the team wants to offload reads without changing the application’s core query patterns. What is the best architectural option?

Medium
923

A media startup stores user-uploaded video files in an Amazon S3 bucket in the us-east-1 Region. The compliance team requires that the data remain recoverable if an entire AWS Region becomes unavailable, and that recovery can be performed by pointing applications at a different endpoint. Cost should be minimized while still meeting the requirement. Which solution should a solutions architect recommend?

Easy
924

Based on the exhibit, the current disaster recovery design misses the RTO target even though the database replica is current. Which deployment model best meets the requirements with the least always-on cost?

Hard
925

A team wants to remove a bastion host used for administrative access to EC2 instances in private subnets. The instances should be reachable only for occasional troubleshooting by engineers who authenticate with AWS SSO. What is the best secure alternative within AWS, assuming the instances already have an instance profile attached?

Medium
926

A retail platform needs disaster recovery across AWS Regions. The business requirement is: RTO up to 6 hours, RPO up to 1 hour, and they want the ability to start serving quickly during a Region outage but do not want to run full production capacity continuously. Which DR strategy best fits these requirements?

Easy
927

An event ingestion service writes to a DynamoDB table where the partition key is tenantId and the sort key is eventTime. During a campaign, one tenant generates a disproportionate share of traffic, causing write throttling and increased latency for that tenant’s writes. You can change the data model and application queries, but you must still efficiently retrieve events for a tenant for the last 10 minutes. Which change best improves write throughput by reducing hot partitions?

Medium
928

A containerized service needs to read exactly one secret value from AWS Secrets Manager. The secret’s ARN is already known, and the secret is encrypted with the AWS-managed KMS key for Secrets Manager, so no separate KMS permissions are needed for this question. The service does not need to list secrets, create secrets, rotate them, or write updates. What is the most least-privilege IAM permission statement to grant the service role?

Easy
929

A media company stores 50 TB of finalized video masters in Amazon S3 that must be retained for seven years for regulatory compliance. The files are accessed only during occasional legal audits, roughly once every two years, and retrieval latency of several hours is acceptable. The company wants the LOWEST possible storage cost while preserving durability. Which storage class should they choose?

Easy
930

A security team needs an audit trail to investigate suspicious API activity across multiple AWS accounts. Which AWS approach best provides centralized visibility into who did what, when, for service API calls?

Easy
931

Based on the exhibit, what should the security team implement so developers can create AWS Lambda execution roles, but no developer-created role can ever exceed the approved permission set?

Medium
932

Your team hosts a private web app on an S3 bucket and serves it through CloudFront using a modern Origin Access Control (OAC). After deployment, users receive HTTP 403 from CloudFront with the S3 origin error "AccessDenied". Which S3 bucket policy change best aligns with CloudFront OAC so the distribution can fetch objects privately?

Medium
933

A mobile app reads the same product details many times per minute from Amazon DynamoDB. The table design is already correct, but repeated reads are still causing noticeable latency. Which service should the team add to improve read performance?

Easy
934

A media company stores original video assets in an Amazon S3 bucket in the us-east-1 Region. Editors in Europe report slow downloads, and the legal team requires that a copy of every asset exist in eu-west-1 within 15 minutes of upload, with the ability to fail over reads to the European copy during a Regional impairment. Which S3 feature should the architects enable?

Medium
935

A Lambda function for a IoT ingestion API needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?

Medium

Frequently asked questions

What does the disaster recovery domain cover on the SAA-C03 exam?
disaster recovery questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 935 disaster recovery questions in the SAA-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only disaster recovery questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.