Focused practice
Practice nat gateway questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about nat gateway
Why learners struggle
Why nat gateway questions are commonly missed
NAT questions are missed when learners confuse the four address types (inside local, inside global, outside local, outside global) or misapply the interface direction. A translation rule can look correct but still fail if the ACL, interface, or direction is wrong.
- ·Inside local vs inside global — inside local is the private source, inside global is the translated public address
- ·PAT overloads — many sources share one public IP using unique port numbers
- ·Interface direction — ip nat inside and ip nat outside must be on the correct interfaces
- ·Static NAT vs dynamic NAT vs PAT — each serves a different use case
- ·The NAT ACL identifies traffic to translate, not traffic to permit or deny
- ·A missing translation can look like a routing problem if the interfaces are misconfigured
Watch out for
Common nat gateway exam traps
- ▸PAT allows many inside hosts to share one public address by using port numbers.
- ▸NAT rules depend on correct inside and outside interface configuration.
- ▸The ACL used for NAT identifies traffic to translate; it is not always a security filtering ACL.
- ▸Static NAT maps one private address to one public address, while PAT overloads translations.
Question index
All nat gateway questions (935)
Click any question to see the full explanation, or start a practice session above.
A production Amazon RDS database already has automated backups enabled. At 10:45 UTC, the team discovers that a faulty migration corrupted rows in a table at 10:30 UTC. The business wants the database restored to exactly the state it had at 10:30 UTC with minimal risk. Which two actions should the team take? Select two.
Medium2Based on the exhibit, the web team wants the application to continue serving traffic if one Availability Zone fails. Which change best meets the requirement with the least operational overhead?
Easy3You deploy a Web ACL with an AWS WAF rate-based rule intended to limit abusive traffic to your API. After the deployment, attackers still reach the backend service. ALB access logs show requests arrive at the ALB, but WAF logs indicate the Web ACL is not evaluating those requests. Which change most likely fixes the issue?
Medium4A startup runs a 24/7 web tier on Amazon EC2 with a stable baseline of 8 instances and a nightly analytics batch job that can resume from checkpoints if interrupted. The company wants to minimize monthly compute cost without hurting the always-on web tier. Which two actions should it take? Select two.
Medium5A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The architecture review board prefers a managed AWS-native control.
Medium6A trading dashboard uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The architecture review board prefers a managed AWS-native control.
Medium7Company A stores encrypted log files in its S3 bucket using SSE-KMS with a customer-managed KMS key. A partner application in Company B uploads objects into Company A's bucket using an IAM role in Company B. Uploads fail with an error indicating KMS access is denied (kms:Encrypt not authorized). Neither the partner IAM policy nor the S3 bucket policy currently mentions KMS. What is the most secure and correct change to allow cross-account uploads to succeed?
Medium8A marketing site runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost?
Medium9An internal worker consumes messages from an Amazon SQS queue. Occasionally, a message fails validation in the worker (for example, missing required fields). Reprocessing the same bad message repeatedly wastes processing time and delays healthy messages. What is the best AWS approach to handle these poison messages without blocking the rest of the queue?
Easy10A media processing pipeline runs batch jobs overnight. The jobs are stateless, can be restarted from checkpoints, and can tolerate interruptions. The team wants to minimize compute cost. Which EC2 approach is the best fit?
Easy11A team runs a stateless web app on Amazon EC2 behind an Application Load Balancer. During traffic spikes, new EC2 instances take several minutes to finish bootstrapping before they can receive traffic. Which Auto Scaling configuration most directly reduces the time until additional capacity is available?
Easy12Based on the exhibit, your application runs entirely in private subnets and only needs to reach Amazon S3, Amazon DynamoDB, AWS Secrets Manager, and CloudWatch Logs. The monthly bill is dominated by NAT Gateway charges. Which change most directly reduces cost while preserving private connectivity to these AWS services?
Hard13A production application uses an Amazon RDS Multi-AZ DB instance. During an unplanned failover, the database endpoint remains the same. What change should the application team make to handle the failover reliably?
Easy14A solutions architect is designing a cost-optimized data storage solution for a large dataset that is accessed infrequently but must be retained for compliance for 7 years. Which three actions should the architect take to minimize costs? (Choose three.)
Medium15A IoT ingestion API must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?
Hard16A financial services firm stores trade confirmations in an Amazon S3 bucket. Regulations require that every object be encrypted at rest with a key the firm controls and can audit independently of AWS, and that key usage be logged. The firm wants to avoid changing application code. Which encryption approach should be used?
Hard17A analytics dashboard uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add?
Medium18A team serves static web assets (JS, CSS, images) from an Amazon S3 origin through CloudFront. Recently, the S3 origin has received a high number of requests for the same files, increasing origin data transfer costs. CloudFront access logs show many cache misses, and each request includes a unique query string used only for tracking (for example, ?utm=...). The application does not require query-string-specific content. What CloudFront change will most directly reduce origin fetches and cost?
Medium19A image sharing application uses CloudFront in front of an S3 origin. Which two settings help keep users from bypassing CloudFront and accessing the bucket directly?
Hard20Based on the exhibit, a web application must stay available if one Availability Zone fails. What is the best change to improve resilience?
Easy21An order-processing service consumes messages from an Amazon SQS Standard queue using a custom worker. During traffic spikes, the worker occasionally times out after performing some work but before acknowledging the message, so SQS redelivers it and it may be processed again. You also observe that a small set of “poison” messages always fail validation. What change most directly improves resilience by (1) preventing poison messages from retrying indefinitely and (2) avoiding duplicate side effects caused by legitimate retries?
Medium22Based on the exhibit, what change best reduces Lambda cold-start impact for a predictable user-upload workflow?
Easy23An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a customer analytics portal. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy? The design must avoid adding custom operational scripts.
Hard24A company is designing a high-performance database architecture for an e-commerce platform that experiences rapid spikes in read traffic during flash sales. The database must handle millions of reads per second with sub-millisecond latency. The data is key-value in nature, with a small number of attributes per item. Which three options should be included in the architecture? (Choose three.)
Medium25Account A hosts an IAM role (RoleInAccountA). The trust policy in Account A correctly allows a specific principal from Account B to call sts:AssumeRole. However, when Account B’s application calls sts:AssumeRole, it receives an AccessDenied error. What is the most likely missing requirement in Account B?
Easy26A microservice reads a secret from AWS Secrets Manager using its task role (ServiceRole). The secret is configured to use a customer-managed CMK. In production, the service fails with AccessDeniedException on GetSecretValue. CloudTrail shows that Secrets Manager attempted kms:Decrypt but was denied. Which IAM policy change is most appropriate to fix the failure while keeping least privilege?
Medium27In AWS Organizations, a Service Control Policy (SCP) denies kms:Decrypt on a production CMK for all principals in the Finance OU. A developer in the Finance OU created/updated an IAM policy that allows secrets access, but the application still fails with AccessDenied due to the SCP. You must enable only the Finance OU to decrypt that specific CMK while keeping the SCP restrictions for other OUs. What is the correct remediation?
Medium28A development team is building a new application that stores session state in a relational database. The application experiences unpredictable read traffic, and the team wants a fully managed database that can scale read capacity automatically and provide a reader endpoint that distributes connections across multiple replicas. Which AWS service should a solutions architect recommend?
Easy29A Lambda function needs to read the current value of exactly one AWS Secrets Manager secret at startup. Which least-privilege IAM permission (action and resource scope) should you grant to the Lambda execution role?
Easy30A company wants S3 access to be available only from private connectivity. They created an Interface VPC Endpoint for S3 (that provides private connectivity from their VPC to S3) and configured the application to use it from private subnets. The IAM role allows: - s3:GetObject on arn:aws:s3:::confidential-bucket/reports/* However, requests fail with AccessDenied. The S3 bucket policy includes an allow statement that permits GetObject only if: - aws:SourceVpce equals "vpce-0abc12345def6789" After redeploying the VPC endpoint, the application still uses the same IAM permissions but gets AccessDenied. What change is most likely to fix the issue?
Medium31Based on the exhibit, a public API is behind CloudFront. A single client IP is sending bursts of requests that are overwhelming the origin, and the team wants AWS to automatically mitigate the abuse at the edge without changing the application code. What should the team do?
Hard32A healthcare provider hosts a patient-records API on Amazon EC2 instances in a single Availability Zone behind an Application Load Balancer. An audit finds the architecture cannot tolerate the loss of that Availability Zone. Budget is limited, and the API reads from an Amazon Aurora MySQL cluster that currently has one writer instance and no replicas. Which change most effectively addresses the audit finding?
Medium33A company runs a stateless API on Amazon EC2 instances in a single Availability Zone behind an Application Load Balancer. The ALB currently has a listener on port 80 only. The company wants the API to remain available if the single Availability Zone fails. What should the solutions architect do to meet this requirement with the LEAST operational overhead?
Easy34A Lambda-based retail API has unpredictable traffic spikes and users see latency caused by cold starts. The function must respond consistently during expected campaign windows. What should be configured? The design must avoid adding custom operational scripts.
Hard35A web application runs on an EC2 Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ASG spans three Availability Zones. After a deployment, new instances frequently fail the ALB target group health checks with HTTP 5xx responses and are quickly terminated by the ASG. What change most improves resiliency during deployments with minimal downtime by preventing premature removal of instances that are still starting?
Medium36A team serves static assets from an S3 origin through CloudFront. Cache hit ratio is low. Analytics show that requests include an Authorization header (even though the assets are public) and the cache key currently varies on that header, causing CloudFront to treat the same asset as different cache entries. What is the best change to improve cache hit ratio without breaking access controls?
Medium37Based on the exhibit, the application sees several minutes of connection errors during an Aurora failover. What is the best change to reduce failover impact?
Medium38A SOC analyst needs an immutable, centralized audit record of configuration and API changes across multiple AWS accounts. Recently, an operator changed an IAM role trust policy, and investigators must determine exactly which principal made the change and which parameters were used. Your current setup sends application logs to CloudWatch Logs, but there is no organization-level API audit logging. Which approach best satisfies the requirement?
Medium39A read-heavy media archive repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The architecture review board prefers a managed AWS-native control.
Medium40A patient portal must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The architecture review board prefers a managed AWS-native control.
Hard41You store application logs in an S3 bucket. After 30 days, the logs are rarely accessed, but you must retain them for 1 year for compliance. Which S3 feature is the best way to reduce storage cost while meeting the retention requirement?
Easy42A security team requires that every object uploaded to s3://secure-bucket/uploads/ must be encrypted using SSE-KMS with a specific customer-managed KMS key. Which S3 bucket policy condition approach best enforces this requirement for PutObject requests?
Easy43A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The team wants the control to be enforceable during normal operations.
Medium44An application in Account B (IAM role arn:aws:iam::account-b:role/app-read) reads objects from an S3 bucket in Account A. The bucket uses SSE-KMS with a customer-managed KMS key in Account A. Object reads consistently fail with an error that includes "AccessDenied" and "kms:Decrypt". The IAM permissions in Account B for kms:Decrypt are correct, but the requests still fail. Which change will most directly fix the failure?
Medium45A healthcare analytics platform stores derived datasets in an Amazon S3 bucket. Regulatory rules require that every object remain recoverable for 90 days after creation even if an application bug issues a delete, and that no object version be permanently destroyed during that window. The team wants the strongest protection with the least custom code. Which S3 feature should the solutions architect enable?
Hard46A financial services company runs a high-traffic REST API on Amazon EC2 instances behind an Application Load Balancer. The API retrieves user session data from an Amazon DynamoDB table for every request. During peak hours, DynamoDB read capacity is exhausted, causing throttling and increased latency. The workload is read-heavy and the session data is accessed frequently but changes infrequently. The solutions architect needs to reduce DynamoDB read load and improve API response times with minimal application changes. Which solution meets these requirements?
Medium47A risk simulation workload generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used?
Hard48Based on the exhibit, a central deployment role in Account A is assumed by several CI/CD pipelines from Account B. The role must remain reusable, but the team wants the TeamA pipeline to upload artifacts only to s3://artifact-bucket/teamA/prod/ without creating a separate IAM role. What is the best approach?
Hard49A financial services company runs a three-tier web application on AWS. The application servers in a private subnet must retrieve database credentials from AWS Secrets Manager at startup. The security team requires that the credentials never be stored on disk and that access be granted only to the specific IAM role attached to the instances. Which solution meets these requirements with the LEAST operational overhead?
Hard50A company runs a critical two-tier web application on AWS. The web tier consists of Amazon EC2 instances behind an Application Load Balancer (ALB) in a single Availability Zone. The database tier is an Amazon RDS for MySQL DB instance in the same Availability Zone. A recent power outage in that Availability Zone caused a full application outage. The company wants to redesign the architecture to survive an Availability Zone failure with minimal operational overhead. Which solution meets these requirements?
Medium51An orders service publishes payment instructions to an Amazon SQS Standard queue. The downstream processor sometimes times out after it has already applied the payment, but before it can delete the message from the queue. As a result, the same payment instruction can be processed more than once. The team wants the strongest way to prevent duplicate side effects while keeping the system decoupled. What should they implement?
Medium52Your order-processing system uses EventBridge rules to send events to a Lambda function that updates order status. Over the last week, some events fail with a transient database timeout, and the Lambda retries intermittently but then the events are lost (no alerts after failures). You want at-least-once processing, bounded retries, and a way to inspect unprocessable events for later reprocessing. Which architecture change best meets these requirements?
Medium53A inventory service exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most? The architecture review board prefers a managed AWS-native control.
Easy54A company runs an internal API on Amazon EC2 instances in a private subnet. The API must call AWS Systems Manager Parameter Store to read configuration values. The security team wants to avoid long-lived credentials on the instances and avoid routing traffic over the public internet. Which combination of steps should be taken?
Hard55A ticket booking system stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured?
Medium56A company runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. The application experiences predictable traffic patterns: low traffic at night and high traffic during business hours. The company wants to optimize costs without compromising availability. Which two actions should be taken? (Choose two.)
Medium57A team stores important documents in Amazon S3. They want to recover earlier versions if someone overwrites or deletes a file by mistake. What should they enable?
Easy58A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The design must avoid adding custom operational scripts.
Medium59Based on the exhibit, a batch platform in Account B must assume a role in Account A. Only the specific role arn:aws:iam::222233334444:role/BatchRunner should be allowed to assume it, and the design must prevent any other role in Account B from reusing the same external ID. Which change best meets the requirement?
Hard60Based on the exhibit, a batch-processing service runs on Amazon EC2. The workload is Linux-based, can run on ARM64, and is CPU-bound during its nightly processing window. The team wants the best throughput per dollar without changing the application logic. Which EC2 instance family should the solutions architect recommend?
Hard61A media analytics company ingests a continuous stream of JSON clickstream events, roughly 20,000 records per second, into an Amazon Kinesis Data Streams stream with 32 shards. Downstream consumers must be able to re-read the same records up to 7 days later to rebuild a reporting index. Which combination of settings should the team use to maximize the number of records each consumer can read per second while preserving this replay capability?
Medium62Based on the exhibit, a CI pipeline assumes a shared deployment role in Account A. The role can access several artifact prefixes, but this pipeline must only upload to teamA/prod/ and decrypt using a single KMS key for this execution. Changing the shared role would affect other pipelines. Which approach should the pipeline use?
Hard63An Aurora PostgreSQL application has an OLTP writer and a reporting dashboard that issues many read-only queries. The writer is healthy, but read latency rises noticeably during reporting windows. Which two changes should you make? Select two.
Medium64A company runs EC2 instances in private subnets and needs to access Amazon S3 objects without using a NAT gateway. They want the traffic to stay within AWS private networking as much as possible (no internet egress). Which VPC endpoint type should they create for Amazon S3?
Easy65Based on the exhibit, a media company serves versioned JavaScript and CSS files from an Amazon S3 origin through CloudFront. After a frontend release, the cache hit ratio dropped sharply even though the file names are versioned. The application team says the browser requests include the same Authorization header on every asset request because the frontend and API share one domain. What should the solutions architect do to improve CloudFront cache hit ratio without changing the application authentication model for the API?
Hard66A DynamoDB-backed multi-tenant app experiences throttling during a promotion. Most writes and reads target tenant "ACME" and use the same partition key value, causing a hot partition. Which design change most directly improves performance?
Easy67A production application writes to an Amazon Aurora PostgreSQL cluster. Users report that during business-hour reporting runs, write latency increases. The application team wants to keep the writer focused on OLTP writes while still providing low-latency reads for reporting queries. What architectural approach should the solutions architect recommend?
Medium68An S3 bucket stores user-uploaded images. Access patterns are unpredictable: some objects are never read again, while others are occasionally retrieved months later. The team wants to reduce storage cost without having to manually track access frequency or run periodic analyses. Which S3 storage and lifecycle approach is the best fit?
Medium69Based on the exhibit, the security team wants centralized detection and alerting for both successful and failed attempts to change S3 bucket policies and KMS key policies across multiple accounts. Which approach best meets the requirement?
Hard70A small analytics team runs a nightly batch job on a single Amazon EC2 instance. The job starts at 2:00 AM and finishes by 4:00 AM. The instance is idle for the rest of the day. The team wants to reduce EC2 costs and is willing to accept that the instance may be stopped and started. Which action will reduce costs MOST effectively?
Easy71A retail API runs on Amazon EC2 instances behind an Application Load Balancer and stores orders in an Amazon RDS for PostgreSQL database. A test that stopped one Availability Zone caused the API to return errors because all application servers were in the same AZ and the database was single-AZ. Which two changes should the architect make to continue serving traffic during a single-AZ failure? Select two.
Medium72A company runs EC2 workloads in one region with somewhat steady overall demand. Over time, the team frequently changes instance families (for performance/optimization) and sometimes changes instance size, but wants predictable cost discounts. Which purchase option provides the best balance of cost savings and flexibility?
Easy73Match the disaster recovery strategy to the recovery posture it best fits for a Regional outage.
Medium74A payments service receives payment orders by consuming messages from an Amazon SQS Standard queue. The downstream processor occasionally exceeds its processing timeout. As a result, some messages reappear in the queue and may be processed more than once. The team wants to prevent duplicate side effects (for example, double-charging) and also ensure poison messages do not repeatedly consume processing capacity. What approach best satisfies both goals?
Medium75A telemetry pipeline uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add? The architecture review board prefers a managed AWS-native control.
Medium76A company stores sensitive customer data in an Amazon S3 bucket. The security team wants to ensure that all data is encrypted at rest using keys that the company controls, including the ability to rotate keys and audit key usage. They also want to minimize operational overhead for key management. Which solution meets these requirements?
Medium77A public API for a customer analytics portal is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used? The design must avoid adding custom operational scripts.
Medium78A financial services firm runs a batch settlement job on a fleet of Amazon EC2 instances that pull work from an Amazon SQS queue. The job must not lose messages if an instance is terminated mid-processing, and duplicate processing must be minimized because each settlement charge is expensive. The team also wants to avoid indefinite reprocessing of a message that repeatedly fails. Which two changes should the solutions architect make to meet these requirements? (Choose two.)
Hard79Based on the exhibit, a workload in Account B must assume a role in Account A. Security requires that only the specific role arn:aws:iam::444455556666:role/PipelineExecRole can assume it, and only when the caller supplies the external ID acct-b-prod-7788. Which change best satisfies the requirement with the least privilege?
Hard80A company runs a stateful workload on Amazon EC2 instances in an Auto Scaling group. The workload writes session data to the instance store and to an Amazon EBS volume attached at launch. The company wants the workload to survive an Availability Zone failure without losing session data. What should the solutions architect do?
Hard81A fintech company has a two-Region DR requirement: RPO must be within 15 minutes and RTO must be under 2 hours. To control cost, they do not want to run full production infrastructure in the secondary Region continuously. They plan to continuously replicate the database and keep the application infrastructure in the secondary Region prepared, but at reduced capacity. Which DR strategy best matches this requirement and accurately describes their plan?
Medium82A media company stores generated video thumbnails in an Amazon S3 bucket. The bucket currently uses the S3 Standard storage class, and the objects are accessed frequently for the first 30 days and then almost never. The company wants to reduce storage costs automatically without changing the application and must retain the objects for at least one year. Which action should a solutions architect take?
Easy83A company hosts a customer analytics portal on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
Medium84Your security team needs to detect and alert on any attempt to change sensitive policies, specifically S3 bucket policy changes and KMS key policy changes. The team wants alerts within minutes, and logs must be centrally retained for forensics. Which design best meets these detective control requirements using AWS-native services?
Medium85In an AWS Organizations environment, developers create IAM roles using an automation tool. The security team wants to guarantee that even if a developer attaches an overly permissive inline policy, the role cannot exceed a fixed set of allowed actions. The team already uses permission boundaries on each role. The tool’s role-creation API call succeeds, but one developer’s new role can still delete production S3 buckets. What is the most likely reason, and what should be corrected?
Medium86A batch analytics job has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity?
Medium87A logistics company runs an order-processing workflow using AWS Step Functions. A task state invokes a Lambda function that charges customer credit cards through a third-party gateway. Occasionally the gateway times out, and the workflow fails even though the charge may have succeeded. The architect must make the workflow resilient to these transient failures and avoid duplicate charges. (Choose two.)
Medium88A healthcare company runs a stateless patient-intake API on a fleet of Amazon EC2 instances in a single VPC. The compliance team requires the workload to survive the complete loss of one Availability Zone with no manual intervention, and the instances must be replaced automatically if they fail health checks. The application stores no local state and writes all data to Amazon RDS. Which approach meets these requirements with the LEAST operational effort?
Medium89A payments API uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure?
Hard90A content publishing system exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most?
Easy91Based on the exhibit, the team serves versioned JavaScript and CSS files from an S3 origin through CloudFront. After a release, the cache hit ratio dropped and origin fetches increased sharply. What change best reduces both CloudFront and S3 costs without changing the application’s public behavior?
Hard92A digital agency runs a web application on a fleet of Amazon EC2 instances behind an Application Load Balancer. Traffic is steady and predictable during business hours but drops to near zero overnight and on weekends. The operations team wants to reduce compute costs without impacting availability during peak periods. They cannot modify the application code and must keep the same instance types. What should a solutions architect recommend?
Medium93An application runs on EC2 in us-east-1 and frequently reads objects from an S3 bucket that is physically located in us-west-2. The finance team reports unexpectedly high inter-Region data transfer charges because the application retrieves objects for many user requests. A constraint: the bucket in us-west-2 must remain the system of record for compliance, but the application can read from a replica in us-east-1. What should the solutions architect do to minimize network spend while meeting the compliance constraint?
Medium94A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences variable traffic patterns, with sudden spikes during marketing campaigns. The operations team wants to ensure that the application can scale out quickly to handle the spikes and scale in when traffic decreases, while minimizing costs. Which solution should a solutions architect recommend?
Easy95A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The implementation must work across routine deployments without manual intervention.
Hard96A healthcare company is designing a new application on AWS. The application will store protected health information (PHI) in an Amazon S3 bucket. The security team requires that all data be encrypted at rest using a customer managed AWS KMS key so that they can control key rotation and audit key usage. They also need to ensure that only the application's IAM role can decrypt the data. Which solution meets these requirements?
Medium97A solutions architect is reviewing an Amazon S3 bucket that stores application assets. The bucket has S3 Versioning enabled and accumulates many noncurrent object versions that are no longer needed. The team wants to reduce storage cost while preserving the ability to recover from accidental deletions of current objects. Which two actions should the architect take? (Choose two.)
Hard98A partner company needs read-only access to reports in an S3 bucket for a B2B file exchange site. The partner has its own AWS account. What is the most secure scalable access pattern?
Medium99Based on the exhibit, which EBS volume type should the team use to meet the performance need at lower cost than overprovisioning capacity?
Easy100Your company needs a high-throughput, low-latency TCP service using a custom binary protocol. Requirements: preserve the original client source IP for rate limiting, keep latency minimal, and use TCP health checks. The current setup uses an Application Load Balancer and performance is inconsistent. Which load balancer choice best meets these requirements?
Medium101A company runs an application behind an Application Load Balancer (ALB). An Auto Scaling group (ASG) is configured with desired capacity 2, but it is attached only to subnets in a single Availability Zone. The ALB is healthy because it is configured across multiple Availability Zones. When the Availability Zone that contains the ASG subnets experiences an outage, what change most directly improves resilience and allows capacity to be restored automatically?
Medium102A company runs a stateless application tier behind an Application Load Balancer. Match each observed scaling pattern on the left to the best Auto Scaling strategy or metric on the right.
Hard103An administrator needs the ability to read and update infrastructure for a specific AWS account, but only when using MFA. The security team wants to eliminate long-lived administrator access keys and ensure that even if someone obtains temporary session credentials, actions are only allowed with MFA present. Which IAM design best meets these requirements?
Medium104A logistics company runs an order-processing workload that reads messages from an Amazon SQS queue and writes results to an Amazon DynamoDB table. Occasionally the same order is processed twice and produces duplicate shipments. The architects must ensure each order is processed exactly once end to end, while keeping throughput as high as possible. What should they do?
Hard105A company is deploying a new web application on AWS. The application will serve static content (HTML, CSS, JavaScript, images) and dynamic API requests. The company expects a global user base and wants to minimize latency for all users. The static content is stored in an Amazon S3 bucket, and the dynamic APIs are hosted on Amazon EC2 instances behind an Application Load Balancer. Which service should the company use to accelerate both static and dynamic content delivery?
Easy106A SaaS vendor needs temporary access to an S3 bucket in your AWS account to read customer exports. The vendor will assume an IAM role you created. During integration testing, the vendor reports that their AssumeRole requests succeed, but your security team is concerned about the possibility of confused-deputy attacks. Which trust policy approach most directly mitigates this risk?
Medium107A team runs a containerized API on Amazon ECS on Fargate in a single Region. Traffic is steady during business hours but drops to near zero overnight, and the team wants to reduce cost without rewriting the application. The team already uses Application Load Balancer and CloudWatch. Which two actions will reduce cost while keeping the API available? (Choose two.)
Medium108An engineering team runs application servers in private subnets. The instances must download patches and software packages from Amazon S3, but the company does not want the traffic to traverse the internet or a NAT gateway. Which design should they use?
Medium109A financial analytics team stores sensitive customer data in an Amazon S3 bucket. The bucket uses SSE-KMS with a customer-managed key. Analysts access objects using an IAM role attached to an EC2 instance in a private subnet. The role has s3:GetObject permission on the bucket. However, analysts report AccessDenied errors when downloading objects. The KMS key policy currently grants full access to the account root user only. What is the most likely cause of the AccessDenied errors?
Medium110A global application experiences frequent writes and must survive a full Regional outage with near-zero data loss. The product team also requires that users can continue to write during the incident using the closest Region. Which approach is most aligned with these requirements?
Medium111A server assumes an IAM role and must read export objects only from this prefix in an S3 bucket: s3://customer-data/exports/acme/ . The application also needs to list the objects under that exact prefix so it can discover which export folders exist. The application performs ListBucket requests with Prefix set to exactly "exports/acme/". The current role policy allows s3:ListBucket on the bucket ARN without a prefix condition, and security reports the role can list other tenants’ export object keys. Which IAM policy change best enforces least privilege for both ListBucket and GetObject?
Medium112A genomics research team stores about 400 TB of compressed sequence files in Amazon S3 and runs a distributed analysis on Amazon EC2 instances in the same Region. The analysis reads each file sequentially and writes intermediate results to local instance storage. The team reports that the S3 GET requests are a bottleneck and wants to improve read throughput while keeping data durable. (Choose two.)
Hard113An internal web application is exposed through an Application Load Balancer (ALB). The ALB currently has only an HTTP listener on port 80. Security requires that all client traffic be encrypted in transit. What is the best next step?
Easy114A company runs a batch processing job on Amazon EC2 instances that takes approximately 4 hours to complete. The job can be interrupted and resumed from a checkpoint. The company wants to minimize the cost of running this job. Which pricing model should they use?
Medium115A high-volume telemetry pipeline writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate?
Medium116A data analytics team runs an Amazon EMR cluster for 2 hours every weekday morning to process a daily batch. The cluster must be fully available during that window, and the team wants the lowest possible compute cost. The jobs are stateless and can be re-run if a node fails. Which configuration should a solutions architect recommend?
Medium117A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers?
Medium118An engineering team deploys a stateless web API on EC2 using an Auto Scaling group and an Application Load Balancer (ALB). During a recent test, they noticed that when one Availability Zone was unavailable, traffic failed until new instances were manually launched. Which change most directly improves automatic failover for the compute layer within a single Region?
Easy119A payments API requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The team wants the control to be enforceable during normal operations.
Hard120A CI/CD system creates an IAM role (CICDRole) used for deployments. Your organization uses IAM permission boundaries to prevent developers from granting themselves higher privileges. After an incident, you discover that CICDRole can perform unintended IAM actions because the role’s identity policy includes broad permissions. Which change most directly ensures permission boundaries continue to restrict CICDRole regardless of what is later added to the role’s identity policies?
Medium121A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load?
Medium122A healthcare company runs a containerized claims-processing service on Amazon ECS with the Fargate launch type in a single AWS Region. The service must survive the loss of an entire Availability Zone with no manual intervention, and the architecture must keep the same service endpoint for callers. The service is fronted by an Application Load Balancer. Which combination of actions should a solutions architect take to meet these requirements with the LEAST operational overhead?
Medium123A claims workflow uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure?
Hard124A company has a steady-state workload on Amazon EC2 that runs 24/7 for the next 3 years. They want to achieve the maximum possible discount and are willing to make a upfront payment. Which purchasing option should they choose?
Medium125An orders service publishes payment instructions to an Amazon SQS queue. After occasional processing timeouts, the downstream consumer sometimes processes the same instruction twice, resulting in duplicate payment attempts. The team currently uses an SQS Standard queue with a visibility timeout of 2 minutes and relies on the consumer to finish before the timeout expires. What approach best improves resilience against duplicate processing?
Medium126Based on the exhibit, why is the IAM role still receiving AccessDenied even though it has AdministratorAccess attached?
Medium127Based on the exhibit, which change best reduces latency during peak traffic without overprovisioning the fleet?
Hard128A healthcare company stores protected health information in an Amazon S3 bucket. Auditors require that every object be encrypted with a customer managed AWS KMS key, that key rotation be controlled by the company, and that the company be able to revoke access to the data immediately by disabling the key. Which encryption configuration meets these requirements?
Hard129A backend service in AWS uses an IAM role to upload large files to an S3 bucket using multipart upload. The upload typically succeeds, but it intermittently fails during cleanup with this error: "AccessDenied: User is not authorized to perform: s3:AbortMultipartUpload" The role identity policy currently allows only: - s3:PutObject on arn:aws:s3:::my-bucket/uploads/* - s3:ListBucket on arn:aws:s3:::my-bucket with a prefix condition What is the best least-privilege change to fix the cleanup failure?
Medium130A healthcare company stores 80 TB of medical imaging data in Amazon S3. The data is written once and must be retained for seven years for compliance. New images are accessed frequently for the first 30 days, then almost never after that, but auditors occasionally request a specific image with no advance notice and expect it within minutes. The company wants to minimize storage cost while meeting the retrieval requirement. Which two actions should a solutions architect recommend? (Choose two.)
Hard131A production internal reporting portal runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy?
Medium132An orders system sends payment instructions to an Amazon SQS queue. The consumer sometimes times out after it has already created the payment record but before it deletes the SQS message. As a result, the same instruction can be processed more than once. Which design best ensures the consumer remains resilient and does not create duplicate payments when the same instruction is delivered multiple times?
Medium133A company runs an application in private subnets (no inbound internet). The application must access Amazon S3 and AWS Secrets Manager endpoints without routing through the public internet and without exposing the instances to NAT gateways due to cost. Security requirements also state that only the required VPC traffic should be allowed to reach AWS services. Which architecture best satisfies these requirements?
Medium134A logistics company runs an order processing system on Amazon EC2 instances that read and write to an Amazon RDS for MySQL database. The database is currently a Single-AZ deployment. The company needs the database to survive an Availability Zone failure with automatic failover and minimal downtime. The application connects using a hardcoded DNS name. Which change should a solutions architect make?
Hard135CloudWatch metrics show your EC2 instances have average CPU utilization around 10% with stable performance over several weeks. The application does not require additional headroom right now. What is the most effective cost-optimization action?
Easy136A customer portal must recover from a regional outage within a few hours. The business wants lower ongoing cost than a fully active second Region and does not want to rebuild everything from scratch during the outage. Which two DR patterns best fit that goal? Select two.
Medium137A financial services company runs a three-tier web application on AWS. The application tier consists of EC2 instances in an Auto Scaling group behind an Application Load Balancer. Security policy requires that the EC2 instances never receive public IP addresses and that all outbound internet traffic from the application tier be routed through a NAT gateway. The company also wants to ensure that only the load balancer can initiate connections to the application instances on port 443. Which combination of VPC configuration and security group rules should a solutions architect implement to meet these requirements?
Medium138A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The architecture review board prefers a managed AWS-native control.
Medium139A company runs a microservices application on Amazon ECS with AWS Fargate. The tasks run continuously, and the company has committed to a 3-year term. The team wants to reduce Fargate compute cost while keeping the same task definitions and architecture. Which action should a solutions architect take?
Medium140A healthcare analytics company runs an Amazon RDS for MySQL database in a private subnet. A compliance requirement mandates that all data at rest be encrypted with a key that the company can rotate, audit, and immediately revoke. The database is currently unencrypted. What is the MOST operationally efficient way to meet this requirement?
Medium141A media company stores master video files in an Amazon S3 bucket in the us-east-1 Region. A compliance policy requires that the data remain readable even if the entire us-east-1 Region becomes unavailable, and the recovery point objective is 15 minutes. The team wants the lowest operational overhead and does not want to modify application code. Which solution should the architect implement?
Hard142A financial analytics platform runs an Amazon Aurora MySQL cluster with one writer and two readers. During month-end reporting, read traffic spikes and the application sometimes receives TooManyConnections errors on the reader endpoint. The architect wants to absorb bursts without changing application code and must keep failover behaviour intact. Which change meets these requirements?
Hard143A claims portal uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?
Hard144A risk simulation workload in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost?
Hard145A DynamoDB table stores device status items. The partition key is deviceId, and the partition distribution is healthy (no single partition dominates). However, during peak periods the application experiences high read latency because many clients repeatedly request the latest status for the same devices. Which action best improves read latency without changing the DynamoDB partitioning model?
Medium146Based on the exhibit, the company runs a self-managed RabbitMQ cluster on EC2 for asynchronous work. The queue only needs durable at-least-once delivery, and the application does not require AMQP-specific features such as exchanges, routing keys, or broker plugins. Which change is the best cost-optimization move?
Hard147A company is designing a secure architecture for a three-tier web application on AWS. The web tier runs on Amazon EC2 instances in public subnets, the application tier runs on EC2 instances in private subnets, and the database tier runs on Amazon RDS in private subnets. The security team requires that the application tier instances can access the internet for software updates without being directly reachable from the internet, and that the database tier is not accessible from the internet. Which two actions should a solutions architect take to meet these requirements? (Choose two.)
Medium148A containerized service fleet running on EC2 instances needs to share user-uploaded files and access them with low latency. The workload is bursty: sometimes dozens of instances concurrently read the same directory for short periods, and then traffic drops. Which Amazon EFS configuration best matches these performance needs?
Medium149A batch process uploads artifacts to an Amazon S3 bucket using multipart uploads. The bucket policy contains a statement that explicitly denies PutObject and CreateMultipartUpload unless the request uses server-side encryption with AWS KMS (SSE-KMS) and includes these request headers/parameters: x-amz-server-side-encryption=aws:kms and x-amz-server-side-encryption-aws-kms-key-id set to a specific CMK. After the process was updated, uploads intermittently fail with AccessDenied errors. Which change is the best way to make uploads succeed while still meeting the bucket policy's encryption requirement?
Medium150A media company stores video masters in an Amazon S3 bucket encrypted with a customer managed AWS KMS key. Editors sign in through a corporate identity provider that is federated to AWS IAM Identity Center, and they must be able to download and re-upload objects. The security team wants every editor's read of the key material recorded in CloudTrail with the editor's own identity, and wants to be able to revoke one editor's access without affecting the others. Which configuration meets these requirements?
Medium151A logistics company runs a shipment-tracking service on a single Amazon EC2 instance in one Availability Zone. The instance stores tracking state in an attached Amazon EBS volume and writes nightly backups to Amazon S3. The company needs the service to survive the loss of an entire Availability Zone with minimal data loss and automatic recovery, while keeping changes minimal. Which design change should a solutions architect recommend?
Medium152A small e-commerce company hosts its website on a single EC2 instance in a public subnet. The site receives low but steady traffic. The company wants to reduce cost and is willing to accept a brief interruption if the instance is terminated. The workload can be restarted automatically. Which EC2 purchasing option should the company use to minimize cost?
Easy153A production Amazon RDS database has automated backups enabled. At 10:45 UTC, an issue is discovered. The team needs to restore the database to its state as of 10:30 UTC. Which capability should they use?
Easy154A startup runs a read-heavy product catalogue API on Amazon DynamoDB. The table uses on-demand capacity mode, and the team notices that repeated queries for the same popular items return consistently, causing high read request charges. The application can tolerate data that is a few seconds stale. Which change reduces read costs while keeping latency low?
Easy155A team serves static content (JavaScript, CSS, images) from S3 through CloudFront. After a recent release, CloudFront reports a low cache hit ratio and the S3 origin receives a much higher request rate. The site still works, but billing shows higher origin and data transfer costs. Which change is most likely to improve cache hit ratio and reduce origin load?
Medium156Based on the exhibit, an automation pipeline in several member accounts creates IAM roles for application deployments. Security says no future role may exceed the approved boundary arn:aws:iam::123456789012:policy/DeployBoundary, even if someone later attaches AdministratorAccess. What should you implement to enforce this across the organization?
Hard157A marketing site serves versioned JavaScript and CSS files from Amazon S3 through CloudFront. The origin bill is rising because CloudFront keeps fetching the same files too often, and the application never changes a file at the same URL once it is published. Which two changes should you make? Select two.
Medium158A solutions architect is designing a highly available and resilient architecture for a critical internal application that processes financial transactions. The application runs on Amazon EC2 instances inside an Auto Scaling group. The database layer uses an Amazon Aurora MySQL cluster. The company requires that if an entire AWS Availability Zone (AZ) fails, the application must remain operational with minimal impact and automatically recover without manual intervention. Which combination of architectural decisions will meet these requirements? (Choose four.)
Medium159A financial services company runs a three-tier web application on AWS. The application servers run on Amazon EC2 instances in private subnets and must retrieve database credentials from AWS Secrets Manager at startup. The security team wants to ensure that the credentials are never stored in plaintext on the instances and that access is auditable. Which solution meets these requirements with the LEAST operational overhead?
Medium160A startup runs a single Amazon EC2 instance hosting both a web application and its MySQL database. The founders want the application to survive the failure of the underlying hardware without changing the database engine, and they want the smallest possible operational change. What should the architect recommend?
Easy161A company is designing a secure architecture for a three-tier web application on AWS. The application runs on Amazon EC2 instances in private subnets, uses an Amazon RDS for MySQL database in private subnets, and is accessed by users over the internet through an Application Load Balancer. The security team requires that the database credentials be stored securely and rotated automatically, and that EC2 instances retrieve credentials without hardcoding them. Which two actions should a solutions architect take to meet these requirements? (Choose two.)
Medium162Your public API is hosted in two regions. You want Route 53 to automatically send traffic to the secondary region when the primary region’s endpoint fails. The primary API health check is returning failure codes, but clients still reach the primary region for several minutes. Which Route 53 configuration most directly addresses this behavior?
Medium163A company is designing a secure architecture for a new application on AWS. The application will store sensitive data in Amazon S3 and will be accessed by users from a web browser. The security team requires that data be encrypted in transit and at rest, and that access to the S3 bucket be limited to only the application's users. The company also wants to minimize operational overhead. Which two actions should a solutions architect take to meet these requirements? (Choose two.)
Hard164A company serves private images stored in S3 through Amazon CloudFront. Only authenticated users should be able to access each image, and access should expire after 1 hour. Which CloudFront feature best meets this requirement?
Easy165A company stores application logs in an Amazon S3 bucket and wants to protect them from accidental or malicious deletion for a fixed retention period. Legal requires that no user, including the AWS account root user, be able to delete or overwrite the log objects for 365 days, and that the protection be verifiable. Which solution should a solutions architect recommend?
Medium166Based on the exhibit, some SQS messages fail validation repeatedly and continue consuming worker time. What change best prevents the bad messages from being retried forever?
Easy167A retail company runs a stateless web tier on a fleet of On-Demand EC2 instances behind an Application Load Balancer. Traffic is steady and predictable throughout the year, and the team has committed to running this exact instance family and Region for at least the next three years. Leadership wants to reduce compute cost as much as possible while keeping the ability to change instance size within the same family. Which purchasing option should the solutions architect recommend?
Medium168A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The architecture review board prefers a managed AWS-native control.
Medium169A financial analytics team runs a nightly Monte Carlo simulation on a cluster of Amazon EC2 instances. The simulation writes checkpoint files to an Amazon EBS volume, and the job can be safely restarted from the last checkpoint if interrupted. The team needs the lowest possible compute cost and can tolerate interruptions. The job must run every night and finish within a 6-hour window. Which solution meets these requirements MOST cost-effectively?
Hard170A global mobile game backend serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The design must avoid adding custom operational scripts.
Medium171A team runs an Amazon RDS for MySQL database in a single Availability Zone. They want automatic failover with minimal downtime if the primary database instance becomes unavailable. Automated backups are already enabled. Which configuration change best meets the requirement?
Easy172An application serves static images through Amazon CloudFront. The team observes higher-than-expected origin fetches, which increases origin bandwidth costs. Which change most directly improves CloudFront cache reuse to reduce origin requests for the static content?
Easy173A company hosts an internal HTTP API on an internal Network Load Balancer (NLB) in VPC A. A partner team in a separate AWS account needs access, but their VPC CIDR overlaps with VPC A, so VPC peering is not feasible. Security requirements state the API must remain non-public (no internet-facing ALB/NLB) and access must use AWS private networking. Which architecture best meets these requirements?
Medium174A startup runs a nightly batch job on a single Amazon EC2 instance that stores results in an Amazon EBS volume. The job takes six hours, and the team wants to resume from the last completed step if the instance is terminated unexpectedly. Which approach provides the required durability with the least operational effort?
Easy175Your team runs a batch processing workload on EC2 that can tolerate interruptions. If an instance is terminated, the job can restart from checkpoints. To reduce compute costs, what is the most cost-optimized approach?
Easy176A DynamoDB table for a travel booking site has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The design must avoid adding custom operational scripts.
Hard177A marketing site stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost? The architecture review board prefers a managed AWS-native control.
Medium178A company runs a containerized application on Amazon ECS on AWS Fargate. The application must read from an Amazon DynamoDB table and write logs to Amazon CloudWatch Logs. Security policy requires that the application use only temporary credentials and that each task have the least privilege needed. What should the company configure?
Hard179A solutions architect is designing an S3 bucket for a mobile banking backend. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?
Medium180A travel booking site uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured? The architecture review board prefers a managed AWS-native control.
Easy181A platform team lets application teams create IAM roles in member accounts through Infrastructure as Code. Security says every new role must stay within a centrally approved permission ceiling, even if someone later attaches broader managed policies or inline policies. Which control should be used to enforce that maximum permission set?
Hard182A company runs a microservices application on Amazon ECS with AWS Fargate. The application experiences variable traffic throughout the day, with peak hours during business hours and minimal traffic at night. The company wants to optimize costs without affecting performance. Which action should they take?
Hard183Based on the exhibit, users must access private PDF reports only through CloudFront. Direct requests to the S3 object URL must fail, and the bucket should not be publicly readable. Which solution is the best fit?
Hard184A risk simulation workload generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used? The design must avoid adding custom operational scripts.
Hard185A company needs an Amazon RDS database that automatically fails over to a standby when the primary DB instance becomes unavailable. Which approach best meets the requirement with minimal operational effort?
Easy186A Lambda function for a order processing API needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used? The design must avoid adding custom operational scripts.
Medium187A backend service uses an IAM role to read files from an S3 bucket. It must only read objects under s3://prod-reporting/incoming/ but currently receives AccessDenied (403) on GetObject for that prefix. The role already has this statement: - Action: s3:ListBucket - Resource: arn:aws:s3:::prod-reporting Which policy statement would most directly follow least privilege to allow only the required reads under the incoming prefix?
Medium188A solutions architect must store application configuration data in AWS Systems Manager Parameter Store. Compliance requires that the values be encrypted with a key the company controls and can rotate on demand, and that only a specific IAM role used by the application can decrypt them. Which configuration meets these requirements?
Hard189An application repeatedly reads the same DynamoDB items with very low latency requirements. The application can tolerate slightly stale data (for example, within a few seconds). You want to improve read latency without changing the existing DynamoDB table schema. Which service is the best choice?
Easy190A web application for a healthcare document service is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?
Medium191A DynamoDB-backed multi-tenant app experiences throttling. Most write traffic for tenant 'ACME' targets a single logical stream of events (you write items for ACME in near-real time). The table currently uses partition key = tenantId and sort key = eventTimestamp. CloudWatch shows partition-level throttling concentrated in the ACME partition. What design change most directly improves write throughput for the hottest tenant while still enabling efficient queries for recent events for that tenant?
Medium192A startup is deploying a new web application on AWS. The security team wants to ensure that all data stored in Amazon S3 is encrypted at rest and that the company retains full control over the encryption keys, including the ability to audit key usage and rotate keys on demand. The team also wants to minimize the operational burden of managing key infrastructure. Which S3 encryption option should a solutions architect recommend?
Easy193Based on the exhibit, a serverless API on AWS Lambda experiences a predictable cold-start penalty every weekday at 09:00 UTC when a marketing campaign begins. The team wants the first requests to stay fast while minimizing extra cost during quiet periods. What is the best approach?
Hard194Based on the exhibit, a workload in private subnets must reach only Amazon S3 and AWS Secrets Manager. The team wants to eliminate internet exposure for those calls and reduce NAT gateway charges. What change should be made?
Hard195A team runs an EC2-based API on a single Auto Scaling group (ASG). Over the last month, they observed: - Average CPU utilization is ~15%. - p95 latency is stable and within the performance target. - The attached EBS volumes are gp3, provisioned with high baseline IOPS/throughput “just to be safe,” but CloudWatch shows consistently low utilization of those provisioned IOPS/throughput limits. They want to reduce monthly cost while maintaining current performance. Which action is the best cost-optimized choice?
Medium196A company has an Amazon S3 bucket for sensitive reports. They must ensure that any object uploaded with s3:PutObject is encrypted using AWS KMS (SSE-KMS). Which S3 bucket policy approach best enforces this by denying uploads that do not use SSE-KMS?
Easy197A data processing application runs on a single EC2 instance and needs persistent block storage with sustained low-latency random read/write performance (high IOPS). Which storage choice is most appropriate?
Easy198A SaaS platform serves an API using two regional deployments: us-east-1 (primary) and us-west-2 (secondary). Each region has its own ALB. The business requires automated DNS-based failover when the primary region becomes unhealthy, and they do not want manual DNS changes during incidents. Which Route 53 configuration is the best match?
Medium199Based on the exhibit, DNS still sends traffic to the primary Region even though Route 53 health checks show the primary endpoint is unhealthy. What is the best change to make failover work as intended?
Hard200A media company runs a batch job that processes image thumbnails. The job can be restarted from checkpoints and does not have user-facing SLAs. The batch capacity can tolerate interruptions. Which EC2 purchasing option is the best cost optimization choice?
Easy201A patient portal must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used?
Hard202A public API for a image sharing application is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?
Medium203A retail company is deploying a read-heavy product catalog on Amazon Aurora MySQL. The primary instance is heavily loaded with read traffic, and the team wants to offload reads to Aurora Replicas while keeping the application resilient to replica failures. The application connects using a single endpoint. Which two actions should the team take to meet these requirements? (Choose two.)
Medium204A claims workflow uses an RDS MySQL database and must remain available during an Availability Zone failure with minimal application changes. What should the architect enable?
Medium205A company stores sensitive documents in an Amazon S3 bucket and must ensure that every object is encrypted at rest with keys that the company can audit and rotate. The security team also wants to detect and automatically respond if anyone attempts to disable encryption on the bucket. Which approach best satisfies these goals?
Easy206Your EC2 instances run in private subnets with no NAT gateway. The instances use the AWS SDK to call STS AssumeRole to obtain temporary credentials for other services. Application logs show errors like: "EndpointConnectionError: Could not connect to https://sts.<region>.amazonaws.com". Which change most directly resolves this while keeping instances private?
Medium207A ticket booking system stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured? The architecture review board prefers a managed AWS-native control.
Medium208A financial services firm runs a containerized risk-analysis platform on Amazon EKS. The containers are stateless and the platform runs continuously, but the firm wants a pricing model that reduces compute cost for the steady baseline while still allowing occasional short bursts above the baseline. Which combination of actions best achieves this?
Hard209A developer accidentally corrupts part of a production Amazon RDS database, and the issue is discovered 45 minutes later. The team needs to restore the database to the state immediately before the change. Which two actions should be part of the recovery plan? Select two.
Easy210Account 3000 owns a customer-managed KMS key (key-K). A data processing team in account 4000 needs to decrypt data encrypted with key-K. The role in account 4000 already has an identity policy allowing kms:Decrypt on key-K. Despite this, decrypt requests fail with an AccessDenied error referencing KMS. What is the most likely missing authorization step?
Medium211A latency-sensitive video platform uploads large files to S3 from users around the world. Which two features can improve upload performance?
Hard212A development team expects their EC2 utilization to average about 40% of capacity across the next year. They want to lower costs but need flexibility to change instance families and sizes as requirements evolve (for example, moving from compute-optimized to memory-optimized instances). Which AWS purchasing commitment best meets the goal of reducing cost while keeping flexibility?
Medium213Based on the exhibit, an application role in Account B can reach an S3 bucket in Account A, but reads fail with AccessDenied on KMS. The bucket objects use SSE-KMS with a customer managed key in Account A. What change is required so the application can decrypt the objects while keeping the access restricted?
Hard214A retail analytics table stores events in Amazon DynamoDB with partition key tenantId and sort key eventTime. During a promotion, one tenant generates most writes and repeatedly polls the same latest-status items, causing throttling on a single partition key and high latency on reads. The business can tolerate read results that are a few seconds stale. Which two changes will most effectively reduce throttling and latency? Select two.
Hard215A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first? The architecture review board prefers a managed AWS-native control.
Hard216A media company serves versioned JavaScript and CSS files from Amazon S3 through CloudFront. After each release, the cache hit ratio drops sharply because the same distribution also fronts a personalized API path, and the current cache policy forwards cookies, all query strings, and several headers to every origin request. The static assets already use content-hashed filenames. Which two changes will most directly improve cache hit ratio for the static assets without changing the application behavior? Select two.
Hard217A company runs a real-time bidding platform on Amazon EC2 instances that must respond within milliseconds. The workload is highly variable, with unpredictable spikes during business hours. The company wants to minimize costs while ensuring the application always has enough capacity to handle sudden traffic surges. Which pricing model should they use?
Medium218Your media processing pipeline writes original uploads to an S3 bucket and later generates derivative files. An operator accidentally deletes a subset of original uploads in production. You need to (1) restore the deleted objects with minimal data loss and (2) protect against both regional disasters and future operator mistakes. The company requires recovery even if objects are deleted and later overwritten. What is the most effective change to meet these requirements?
Medium219A patient portal must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The design must avoid adding custom operational scripts.
Hard220A financial services firm runs a three-tier web application on AWS. The security team wants to ensure that only the application tier can connect to the database tier on TCP port 5432, and that no other subnet can initiate connections to the database. The database runs on Amazon RDS for PostgreSQL in a dedicated subnet group. Which combination of controls enforces this requirement with the LEAST administrative effort?
Hard221A company has a steady-state workload running on Amazon EC2 instances that must run 24/7 for the next 3 years. The workload uses a consistent instance family and size across multiple Availability Zones. The company wants to achieve the maximum possible discount and is willing to make an upfront payment. Which purchasing option should a solutions architect recommend?
Medium222A high-volume analytics dashboard writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate? The design must avoid adding custom operational scripts.
Medium223A company runs a batch processing job on Amazon EC2 that takes about 4 hours to complete. The job can be interrupted and resumed from checkpoints. The company wants to minimize compute costs. Which pricing model is MOST cost-effective?
Medium224A document portal needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable?
Hard225A healthcare provider runs a patient-record API on Amazon EC2 instances behind an Application Load Balancer in one AWS Region. The API reads from an Amazon RDS for MySQL DB instance. The provider must be able to continue serving read traffic if the primary database instance fails, and must minimize the time the application is unavailable. Which change should a solutions architect make?
Medium226A company stores RDS database credentials in AWS Systems Manager Parameter Store as SecureString parameters. The security team requires that database passwords rotate automatically every 30 days. Which change should a solutions architect recommend?
Medium227Based on the exhibit, an application in the same AWS account can upload and read objects in an S3 bucket encrypted with a customer managed KMS key, but GetObject fails with an AccessDenied error from AWS KMS. The IAM role already has s3:GetObject, s3:PutObject, kms:Decrypt, and kms:GenerateDataKey permissions. What change most directly fixes the issue while preserving least privilege?
Hard228A financial services company runs a three-tier web application on AWS. The application tier consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. A security audit reveals that the application instances are receiving large volumes of unwanted traffic directly from the internet on port 443, bypassing the load balancer. The company wants to ensure that only traffic from the ALB can reach the application instances, while allowing the instances to download software updates from the internet. What should a solutions architect recommend?
Medium229A log archive serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit?
Medium230A company stores user uploads in an S3 bucket. Objects are accessed rarely after upload, but when an object is accessed, it must be retrievable quickly (minutes to a few hours). Objects must be retained for at least 18 months. The team wants to reduce storage cost while meeting these requirements. Which lifecycle configuration best fits these requirements?
Easy231An organization hosts the same public API in two AWS Regions. Normal traffic should go to the primary Region. If the primary endpoint becomes unhealthy, Route 53 should automatically route users to the secondary Region. What is the best Route 53 configuration approach?
Easy232Developers for a e-learning platform need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?
Medium233A dev sandbox runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost?
Medium234A third-party payroll vendor in another AWS account must assume a role in your account to write a daily settlement file to Amazon S3. You want to prevent confused-deputy attacks and make every assumed session traceable in CloudTrail back to an individual vendor user. Which three trust-policy or session controls should be used? Select three.
Hard235Based on the exhibit, the web application must remain available even if one Availability Zone fails. What is the best change to improve resilience with the least redesign?
Medium236An API team runs an AWS Lambda function behind an Application Load Balancer (ALB). During predictable hourly traffic spikes, p95 response latency increases due to occasional cold starts. The team wants stable latency during those spikes without permanently overprovisioning resources for all functions. Which configuration is the most appropriate way to reduce cold starts for this Lambda function?
Medium237A logistics firm runs an order-processing service that reads from an Amazon SQS queue and writes results to an Amazon DynamoDB table. During a marketing event, the consumer fleet scaled out aggressively and DynamoDB began returning ProvisionedThroughputExceededException errors, causing messages to be retried and some orders to be processed twice. The architects want to absorb traffic spikes without overprovisioning capacity and without duplicate processing. Which combination of changes should they make?
Hard238Several EC2 instances in different Availability Zones need to read and write the same shared file system. The file storage should stay available if one AZ has a problem. Which service should the team choose?
Easy239A SaaS vendor will access your AWS resources by assuming an IAM role in your account. You want to prevent confused-deputy attacks and ensure the vendor can only assume the role using an agreed external identifier. Your role trust policy currently allows sts:AssumeRole from the vendor’s principal, but it does not include any external ID protection. Which change is the best next step?
Medium240A warehouse integration service must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable?
Hard241A company has a VPC with a CIDR block of 10.0.0.0/16. They need to allow an on-premises data center (192.168.0.0/24) to access a web application running on EC2 instances in a private subnet. The security team wants to ensure that only HTTP and HTTPS traffic from the on-premises network is allowed, and that the traffic is encrypted in transit. Which combination of AWS services should they use?
Hard242A team needs a relational database solution that can automatically fail over to a standby instance if the primary database becomes unavailable. They want the standby to be located in a different Availability Zone. Which RDS/Aurora configuration best satisfies this requirement?
Easy243Your web application runs on EC2 instances behind an Application Load Balancer (ALB). During traffic spikes, p95 response time increases, but average CPU utilization remains below 40%. The current Auto Scaling policy scales based on average CPU%. What should you change to improve performance during spikes?
Easy244A healthcare analytics platform processes streaming records with an AWS Lambda function that writes results to an Amazon DynamoDB table. The pipeline must not lose records if the function throws an error, and the operations team wants to inspect and reprocess failed records without writing custom retry code. Which approach should the solutions architect use?
Hard245A financial services firm runs a critical API on Amazon EC2 instances behind a Network Load Balancer. The API must handle a sudden loss of one Availability Zone and continue serving traffic with no manual failover. The instances are in an Auto Scaling group that currently uses a single subnet in one Availability Zone. Which change should the architect make?
Medium246A test environment runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost?
Medium247A trading dashboard runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The architecture review board prefers a managed AWS-native control.
Medium248A retail company runs an e-commerce platform on a fleet of Amazon EC2 instances behind an Application Load Balancer. Traffic follows a predictable pattern: high during business hours and very low overnight. The operations team wants to reduce EC2 costs without affecting availability during peak hours. The instances currently run continuously and are managed by an Auto Scaling group with a minimum capacity of 4 and a maximum of 20. Which solution will meet these requirements MOST cost-effectively?
Medium249A media archive needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable? The design must avoid adding custom operational scripts.
Hard250An event-driven order processing service consumes messages from an Amazon SQS Standard queue. After a deployment, about 1% of messages start failing validation because a required field is missing. The consumer catches the exception and returns control, so the messages are retried. However, those poison messages keep reappearing and repeatedly consuming processing time for hours, delaying handling of valid messages. What is the most resilient way to handle the poison messages while keeping the system available?
Medium251A order processing API must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?
Hard252A claims workflow uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The architecture review board prefers a managed AWS-native control.
Hard253An application uses an Amazon RDS Multi-AZ DB instance. During a failover test, connections fail until the application is restarted, even though the database comes back online. Which two changes should the team make to improve resilience during failover? Select two.
Medium254A startup runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from specific IP addresses. Which AWS service should be used to meet these requirements?
Easy255A data lake stores raw files in a single Amazon S3 bucket that is shared by three internal analytics teams. Each team should access only its own prefix, and the company wants to eliminate ACL management because objects come from multiple producers. Which three changes should the architect make? Select three.
Medium256A solutions architect is designing a high-performance computing (HPC) workload that requires a shared file system with high throughput and low latency for thousands of compute instances. The workload also requires a caching layer to accelerate repeated reads of the same data. Which two AWS services should be combined to meet these requirements? (Choose two.)
Hard257A latency-sensitive video platform uploads large files to S3 from users around the world. Which two features can improve upload performance? The architecture review board prefers a managed AWS-native control.
Hard258An Auto Scaling group behind an Application Load Balancer frequently replaces new EC2 instances. The application needs ~6 minutes to warm up after instance launch. However, the ALB target group health checks start immediately and mark the targets unhealthy until the application is ready. Because the targets become unhealthy early, the Auto Scaling group then terminates the instances and launches replacements, creating a repeated unhealthy/termination loop. What configuration change will most directly improve recovery by preventing premature ASG termination while the application is warming up?
Medium259A startup runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. Traffic is steady during the day but drops to almost zero overnight, and the team wants to reduce compute cost without manual intervention or a service interruption. Which action should the team take?
Easy260A compute workload uses temporary scratch space for intermediate results (reproducible), and it can tolerate data loss if the instance is terminated. The workload benefits from very high local I/O throughput. Which storage option is the best fit for the scratch data?
Easy261A company runs an internet-facing API in two AWS Regions. Route 53 currently uses simple routing to a primary Application Load Balancer (ALB) DNS name. When the primary Region experiences an outage, customers wait a long time because the DNS entry is not changed automatically. The team wants automatic failover: if the primary Region ALB health check fails for a sustained period, Route 53 should route users to the secondary Region ALB. Which Route 53 approach best meets this requirement?
Medium262A global mobile game backend serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most? The architecture review board prefers a managed AWS-native control.
Medium263You use Amazon CloudFront in front of a private content S3 origin. To mitigate an OWASP Top 10 issue, you created a WAF web ACL and associated it to the CloudFront distribution, but attacks are still reaching the origin. CloudWatch logs show the web ACL rules never match for the CloudFront requests. What is the most likely configuration mistake?
Medium264A logistics company runs a REST API on Amazon ECS using the Fargate launch type behind an Application Load Balancer. The API's response times are acceptable, but the operations team wants to reduce the number of database calls per request by caching frequently accessed reference data in memory inside the tasks. The data changes infrequently and slight staleness is acceptable. Which approach best meets these requirements?
Medium265Based on the exhibit, which change will most improve the CloudFront cache hit ratio for the static assets while still serving the same files to all users?
Hard266A high-volume analytics dashboard writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate?
Medium267A team wants to delegate IAM management to developers, but must ensure developers can never grant themselves permissions beyond a specific limit. Which AWS mechanism best matches this requirement?
Easy268A web application uses an Amazon Aurora DB cluster. The workload is becoming read-heavy, and the application team wants to increase read throughput without changing the database schema. They can adjust the application to route reads differently. What should they do?
Easy269Your company currently uses an Application Load Balancer (ALB) in front of a service that receives a large number of TCP and UDP packets (including UDP-based telemetry). During load tests, you need to support both TCP and UDP traffic at high throughput while keeping stable IP endpoints for a downstream firewall allowlist. Which change best meets these requirements?
Medium270A company runs an internal analytics application on Amazon RDS for PostgreSQL. The database is used heavily from 08:00 to 18:00 on weekdays, but outside those hours it receives almost no queries. The company must keep the database available at all times and cannot tolerate downtime during business hours. The team wants to reduce the cost of running this database. Which approach is the MOST cost-effective while meeting the availability requirement?
Hard271A company runs a two-tier web application on Amazon EC2 instances in a public subnet. The EC2 instances must access an Amazon Aurora MySQL DB cluster in private subnets. A security engineer must ensure that only the web tier can reach the database on port 3306, and that no other resources in the VPC can connect. Which combination of security group configuration and subnet placement should the engineer implement?
Medium272A mobile app reads the same product catalog items repeatedly throughout the day. The DynamoDB table is already properly keyed, but read latency is still a problem during sales events. The team can tolerate eventually consistent reads and wants the least disruptive change. What should they add?
Medium273A claims portal stores audit logs in S3. The compliance team requires that logs cannot be overwritten or deleted for seven years. What should be configured?
Medium274A media company runs a nightly batch job that processes video thumbnails. The batch can be interrupted at any time, and workers can resume automatically from checkpoints (a termination does not corrupt progress). The business goal is the lowest possible compute cost, and occasional interruptions are acceptable as long as the job continues automatically. Which approach is most cost-optimized?
Medium275A data engineering team runs a nightly ETL job on EC2. The job can be checkpointed every 5 minutes and can be retried from the last checkpoint if the instance terminates. The job runtime varies from 2 to 4 hours, and the team has no need for a specific instance type, as long as it completes before 7:00 AM local time. They currently run the job on On-Demand EC2, leading to high monthly compute cost. Which change best reduces cost while maintaining the business deadline?
Medium276A healthcare company needs to store patient records in Amazon DynamoDB. The records must be highly available and durable across multiple Availability Zones. The company also requires the ability to recover the table to any point in time within the last 35 days in case of accidental writes or deletions. Which solution meets these requirements?
Medium277A media company serves video thumbnails from an Amazon S3 bucket in us-east-1 to viewers across Europe and Asia. The thumbnails are immutable after upload and are requested repeatedly by the same users. The company wants to reduce latency for the global audience and reduce data transfer costs, and it does not want to modify application code. Which solution meets these requirements with the LEAST operational effort?
Hard278A company stores critical documents in an Amazon S3 bucket in the us-east-1 Region. The documents must survive an unlikely loss of the entire us-east-1 Region. The company wants a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 1 hour. What should the solutions architect recommend?
Medium279A healthcare company runs a patient portal on Amazon EC2 instances behind an Application Load Balancer across two Availability Zones. A new compliance rule requires that if an entire Availability Zone fails, the portal must remain available with no manual intervention. The EC2 instances are stateless and store no session data. Which design change should the architect implement to meet this requirement?
Medium280A retail company runs a read-heavy product catalog on Amazon RDS for MySQL. During flash sales, read replicas lag behind the primary and the application serves stale prices. The team wants to scale read traffic while ensuring the application reads the most current data for price lookups. Which solution should a solutions architect recommend?
Easy281A retail analytics app uses Amazon RDS for PostgreSQL. Read traffic is growing, and the database CPU spikes mainly due to SELECT-heavy workloads. Writes are less frequent, and the app can tolerate eventually consistent reads for the reports. What is the most appropriate AWS-native way to improve read performance with minimal application changes?
Easy282A patient portal must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The team wants the control to be enforceable during normal operations.
Hard283A team accidentally updates critical rows in an Amazon RDS for PostgreSQL database. Automated backups are enabled. They need to recover the data to the exact state as of 90 minutes ago. They also cannot risk interrupting the current production database instance while investigators validate the restored data. Which recovery strategy best meets these constraints?
Medium284A company has a steady, predictable workload that must run continuously (24/7) in a single AWS Region. The team wants the lowest cost option available for this steady usage, but also expects they may choose different EC2 instance families in the future (without re-buying compute discounts). Which AWS purchase option best meets these goals?
Easy285A company hosts a public-facing static website and a set of downloadable software packages. Users are distributed globally, and the packages are large, so the company wants to reduce data transfer costs and improve download latency. The content changes only when a new release is published, a few times per month. Which solution should a solutions architect recommend?
Medium286You want to protect an Application Load Balancer (ALB) from common web exploits using AWS WAF. The application is not using CloudFront. Which AWS WAF deployment scope should you choose so the WAF rules apply to the ALB?
Easy287A solutions architect is optimizing the cost of a serverless data-processing pipeline. The pipeline uses AWS Lambda functions that process messages from an Amazon SQS queue and write results to Amazon DynamoDB. The team observes that Lambda invocations spike unpredictably, DynamoDB is provisioned with high capacity that is often idle, and the SQS queue occasionally accumulates a large backlog. Which two changes will most directly reduce cost while preserving the pipeline's ability to handle bursts? (Choose two.)
Hard288A mobile banking backend uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend? The design must avoid adding custom operational scripts.
Hard289A team runs an application on Amazon EC2 that connects to an Aurora database. The database password must rotate automatically every 30 days, and the application should retrieve the current secret at runtime using an IAM role. Which AWS service is the best fit?
Medium290Match each database availability event to the AWS failover behavior that best describes it.
Hard291Based on the exhibit, the company wants to lower CloudWatch and EC2 monitoring costs. Auditors require logs to be retained for 90 days, but operations only uses detailed per-instance metrics during rare troubleshooting events. Which change best reduces recurring cost while preserving the required visibility?
Hard292A startup runs a public web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in a public subnet and currently allow SSH from 0.0.0.0/0 so that engineers can troubleshoot. Auditors flagged this exposure. Engineers still need occasional shell access to the instances, and the company wants the access to be auditable per engineer without managing bastion hosts or distributing key pairs. Which solution best meets these requirements?
Easy293A service performs many repeated read requests for the same DynamoDB items. The reads are latency-sensitive, but the application can tolerate slightly stale data. Which AWS service is the best fit to reduce read latency?
Easy294Order the steps to create a static website using Amazon S3 and CloudFront.
Medium295A Lambda function for a claims portal needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?
Medium296A logistics company runs a stateless order-tracking API on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The architect must ensure the API survives the loss of an entire Availability Zone and that unhealthy instances are replaced automatically. (Choose two.)
Medium297A company runs a critical API on Amazon EC2 behind an Application Load Balancer in a single AWS Region. The business requires the API to keep serving traffic if an entire Availability Zone becomes unavailable, and the recovery must not depend on any manual step. The database is Amazon RDS for PostgreSQL configured as a Single-AZ instance. Which combination of changes should a solutions architect implement to meet these requirements?
Hard298A company runs a containerized API on Amazon ECS with AWS Fargate. Traffic is highly variable: it peaks during business hours and drops to near zero overnight. The team wants to pay only for what they use while keeping the API responsive during peaks. Which approach BEST optimizes cost for this workload?
Hard299A SaaS provider runs a multi-tenant application on Amazon EC2 instances behind an Application Load Balancer. Tenants are identified by a subdomain, and each tenant's data is stored in a separate Amazon S3 bucket. The provider wants HTTPS with a single certificate, automatic renewal, and the ability to add new tenant subdomains without redeploying or replacing the certificate. Which solution meets these requirements?
Hard300An application encrypts data directly with AWS KMS using an encryption context. Your KMS key policy includes a condition that allows kms:Decrypt only when the encryption context contains: "purpose" = "myapp-secrets" After a deployment, decryption fails. CloudTrail shows kms:Decrypt was called, but it was denied by the key policy due to the encryption context condition. What is the best fix?
Medium301A company runs a stateless web application on a fleet of EC2 instances behind an Application Load Balancer. The instances are in an Auto Scaling group that scales between 4 and 40 instances, and utilization is highly variable. The company wants to reduce compute cost while keeping the ability to change instance families and Regions over the next three years. Which purchasing strategy should the company use?
Medium302A company uses AWS Organizations to manage multiple AWS accounts. A security engineer needs to prevent any IAM user in the organization from disabling AWS CloudTrail logging in any account. The solution must apply automatically to all existing and future accounts. What should the security engineer do?
Hard303Based on the exhibit, the database must fail over automatically if the primary Availability Zone goes down. Which solution should the architect choose?
Easy304A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered?
Medium305A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The architecture review board prefers a managed AWS-native control.
Hard306A worker service consumes messages from an Amazon SQS queue. Some messages are malformed and always fail validation. The worker retries, but it keeps reprocessing the same bad messages and consumes processing capacity that should be used for valid work. What is the best solution to prevent “poison messages” from blocking progress?
Easy307A team runs a CPU-intensive image processing service on Amazon EC2. The service spends most of its time resizing and compressing images, and the team wants the best price-performance starting point for compute-heavy work. Which EC2 instance family should they choose?
Easy308A Lambda function behind an API needs consistent low latency. Traffic normally drops to near zero, then spikes several times per hour. During spikes, the p95 latency often spikes above 800 ms due to cold starts. The team wants to keep using Lambda (no containers) but minimize cold start impact during predictable spikes. What is the best AWS configuration to meet this goal?
Medium309A warehouse integration service receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The design must avoid adding custom operational scripts.
Medium310You use a customer managed AWS KMS key (CMK) to encrypt objects in an S3 bucket using SSE-KMS. A specific IAM role must be able to decrypt objects. Where should you grant kms:Decrypt permissions so that the role can decrypt data encrypted with that CMK?
Easy311A test environment stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost?
Medium312A company is designing a secure architecture for an internal microservices application running on Amazon ECS with the Fargate launch type. The security team wants each microservice to have its own fine-grained permissions to access specific AWS resources, and wants to avoid storing long-term AWS credentials in the container images or task definitions. The company also wants to encrypt data in transit between services. (Choose two.)
Hard313A media company stores video files in an Amazon S3 bucket in the us-east-1 Region. The company wants to ensure that the files are automatically replicated to us-west-2 for disaster recovery, and that replication occurs within 15 minutes of upload. Which solution meets these requirements with the LEAST operational overhead?
Medium314Your AWS Organization uses a Service Control Policy (SCP) that includes a Deny statement for secretsmanager:GetSecretValue for all member accounts in the "Finance" OU when requests are made outside us-east-1. An application role has an IAM policy that allows secretsmanager:GetSecretValue for the required secret in us-west-2. In us-west-2, requests fail with AccessDenied. What is the most appropriate action?
Medium315A company runs its customer-facing web app on EC2 behind an Application Load Balancer. The database is Amazon RDS for PostgreSQL. The requirement is that if a single Availability Zone fails, the database must automatically fail over within the same AWS Region with minimal application changes. Which database setup best meets this requirement?
Easy316A web application for a order processing API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?
Medium317A solutions architect is designing an S3 bucket for a healthcare document service. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?
Medium318A company is deploying a stateless web application on Amazon ECS with Fargate. The application must be resilient to individual task failures and Availability Zone failures. Which three steps should the company take to achieve this resilience? (Choose three.)
Medium319Your company hosts an internal API in two AWS Regions. You want Amazon Route 53 to automatically send traffic to the secondary Region if the primary Region’s endpoint becomes unhealthy. Which Route 53 configuration best meets this requirement?
Easy320A partner company needs read-only access to reports in an S3 bucket for a e-learning platform. The partner has its own AWS account. What is the most secure scalable access pattern?
Medium321A media company runs a 24/7 ingestion API on EC2 behind an Application Load Balancer and a nightly transcoding job that can resume from checkpoints. The API fleet runs at roughly 65 percent CPU all day, while the batch workers sit idle most of the time. The company wants to cut compute cost without risking the API. Which two changes should they make? Select two.
Hard322A partner company needs read-only access to reports in an S3 bucket for a customer analytics portal. The partner has its own AWS account. What is the most secure scalable access pattern?
Medium323A company runs a containerized order-processing service on Amazon ECS with the Fargate launch type. The service scales out during business hours and scales down to a small baseline overnight. Usage is expected to remain stable for the next two years, and the team wants to reduce Fargate cost without managing any servers. Which action should the solutions architect take?
Medium324Company A runs an internal app in account A. The app needs to upload objects to an S3 bucket in account B. When the app calls S3, it receives AccessDenied for s3:PutObject. The team already created an IAM role in account B named UploadRole with a policy allowing s3:PutObject. They did not yet set up any trust relationship. Which change most directly fixes the access problem with least privilege?
Medium325A gaming company uses Amazon DynamoDB to store player session data. The table has a partition key of PlayerID and a sort key of SessionStartTime. The company needs to retrieve all sessions for a specific player within a date range, sorted by session start time. The table is large and the company wants to minimize read latency. Which approach should they use?
Hard326A public API for a image sharing application is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used? The design must avoid adding custom operational scripts.
Medium327A distributed analytics engine runs 12 EC2 instances in one Availability Zone. The nodes exchange thousands of tiny messages per second and must keep jitter as low as possible. The current design launches the instances across multiple placement groups and uses general-purpose burstable instances. Which two changes will most directly lower east-west network latency and variability? Select two.
Hard328A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The architecture review board prefers a managed AWS-native control.
Medium329A production application stores critical data on an Amazon EBS volume. The team wants a simple backup method that allows the volume to be restored later if the server is lost. What should they use?
Easy330A media processing service runs ECS tasks in multiple Availability Zones. Each task must read and write the same shared filesystem with low latency because tasks stream intermediate artifacts to other tasks. The team currently mounts an EBS volume per task, and cross-AZ tasks frequently cannot see each other’s files. Which option best resolves the shared filesystem requirement while supporting high-performing access?
Medium331A team wants detective controls to investigate suspected exfiltration from an S3 bucket. They need to know when objects are accessed (GetObject) and also when new encrypted objects are written. They already enabled AWS CloudTrail for management events, but their investigation shows no visibility into object-level reads/writes in the logs they review. Which CloudTrail configuration change most directly provides the missing object-level visibility?
Medium332A trading dashboard stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured? The architecture review board prefers a managed AWS-native control.
Medium333A high-frequency trading analytics service runs on several EC2 instances in the same Availability Zone. The application exchanges small messages between nodes and is sensitive to microsecond-level network latency. Which design best meets the requirement?
Medium334A marketing site has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations?
Medium335A genomics company stores 400 TB of compressed reference data in Amazon S3. Researchers in an on-premises lab must run high-throughput reads of this data over a 10 Gbps AWS Direct Connect connection. The team observes that reads are slower than expected and wants to maximize throughput per S3 request while minimizing request costs. Which S3 feature should they implement?
Hard336You manage multiple AWS accounts under AWS Organizations. A compliance requirement states: no account is allowed to create new IAM access keys for IAM users. Local administrators may attempt to override permissions. Which mechanism should you use to enforce this guardrail across all accounts?
Easy337A financial analytics platform runs a stateless containerized service on Amazon ECS with AWS Fargate tasks spread across three Availability Zones. The service reads from an Amazon Aurora MySQL cluster and must continue serving read traffic if one Availability Zone fails. The team wants the read capacity to remain available with the least operational overhead and no changes to application connection strings during a zone failure. Which approach meets these requirements?
Hard338Based on the exhibit, a DynamoDB-backed event processing system is throttling during a promotion. The table uses tenantId as the partition key and eventTime as the sort key. One tenant accounts for most of the write traffic, and the application must preserve fast lookups for that tenant without relying on a single hot partition. What change is the best fix?
Hard339A microservice needs to read exactly one secret value from AWS Secrets Manager. Which IAM permission statement provides the best least-privilege approach to allow the microservice to retrieve that secret value?
Easy340A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ASG uses the ALB target group health checks to decide when instances are healthy (for example, by using the ELB/target-group health check integration). During a deployment, the ASG performs instance replacement. Shortly after the deployment starts and while new instances are still bootstrapping, CloudWatch shows the ALB target group briefly has zero healthy targets, and users intermittently receive 502 responses. Which ASG deployment configuration best reduces the chance that there will be a period with zero healthy ALB targets, while still keeping failover behavior resilient?
Medium341A internal reporting portal has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances? The architecture review board prefers a managed AWS-native control.
Hard342A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be accessible only to users from a specific IP range, and the company wants to protect against common web exploits such as SQL injection and cross-site scripting. The company also wants to monitor and rate-limit requests from specific IP addresses. Which solution should a solutions architect implement?
Medium343Based on the exhibit, the company stores application logs in Amazon S3 for 400 days. The logs are read heavily for the first 30 days, occasionally for the next 90 days, and very rarely after that. Retrieval after day 120 can take up to several hours, but the data must remain available until day 400. Which lifecycle policy is the most cost-effective fit?
Hard344A Lambda function processes CPU-heavy JSON transformations and often runs slower than expected. The team wants to improve performance without changing the code. What should they try first?
Easy345A financial services company stores monthly regulatory reports in an Amazon S3 bucket. The reports are accessed frequently for the first 60 days after creation for audits and internal review. After that period, they are almost never accessed but must be retained for seven years and retrieved within 12 hours if a regulator requests them. The compliance team requires that the objects remain in a single bucket and that retrieval costs be minimized. Which storage solution meets these requirements MOST cost-effectively?
Hard346A test environment has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations?
Medium347A legacy market-data service runs on EC2 and exposes a custom TCP protocol. Clients must connect over TCP with very low latency, and the team wants static IP addresses at the load-balancing layer. Which AWS service is the best fit?
Medium348A claims workflow uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The team wants the control to be enforceable during normal operations.
Hard349A startup runs a small internal tool on a single Amazon EC2 instance that uses an instance store volume for its database files. After a routine host maintenance event, the instance rebooted and the database was empty. The team wants the data to persist independently of the instance lifecycle and to survive a stop-and-start of the instance. What should they change?
Easy350A database administrator wants a regular backup of an Amazon RDS database so the team can restore to a recent point in time if needed. Which AWS feature should they use?
Easy351A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include?
Medium352A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost? The architecture review board prefers a managed AWS-native control.
Medium353An application runs on EC2 instances in private subnets behind an Application Load Balancer (ALB). Security groups allow inbound HTTPS (443) from the ALB’s security group to the instance security group, and outbound from instances is set to allow ephemeral ports. Despite this, clients see connection timeouts. After reviewing network ACLs, you find the NACL associated with the instance subnet has an inbound allow for destination port 443, but it does not have a corresponding outbound allow for ephemeral ports. What is the most likely reason the traffic fails, and what should be updated?
Medium354A company runs a three-tier web application on AWS. The database tier uses Amazon Aurora MySQL, and the application tier runs on Amazon EC2 instances behind an Application Load Balancer. A security audit reveals that the database credentials are stored in plaintext in a configuration file on the EC2 instances, and the same credentials have been in use for over a year. The security team must eliminate hardcoded credentials and ensure automatic rotation of the database password every 30 days without modifying application code to handle rotation events. Which solution meets these requirements with the LEAST operational overhead?
Medium355Based on the exhibit, a company wants EC2 instances in private subnets to access Amazon S3 without using a NAT gateway, and bucket access must be allowed only when requests come through the approved VPC endpoint. Which design is the most appropriate?
Hard356A solutions architect is designing a high-performance architecture for a real-time analytics application. The application ingests a continuous stream of data from thousands of IoT devices. The data must be processed in near real-time, and the results must be stored in a durable, scalable data store for later analysis. The architect needs to choose AWS services that can handle the ingestion and processing of the stream. (Choose two.)
Medium357A media company stores daily financial exports in Amazon S3. The files must be protected against accidental overwrite or deletion, and the business also wants a second copy in another Region for recovery after a regional outage. Which two actions should the architect take? Select two.
Medium358An order-processing application becomes slow when traffic spikes. The frontend should stay responsive even if downstream workers are temporarily overloaded. What should the team add to the design?
Easy359A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The architecture review board prefers a managed AWS-native control.
Medium360A public API for a financial reporting platform is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?
Medium361An S3 bucket uses a customer-managed KMS key as the default for SSE-KMS encryption. A service role will upload objects using s3:PutObject. Assuming the role already has permission to write to the bucket, which KMS permission is most directly required for the role to let S3 encrypt the object during upload?
Easy362A serverless order-ingestion API writes directly to a database. During traffic spikes, the database occasionally throttles, Lambda retries create duplicate order records, and some requests time out. Which two changes best improve buffering and safe retry behavior? Select two.
Medium363A CI pipeline needs to upload build artifacts only to s3://ci-artifacts/uploads/*. You also want the pipeline to list only objects under uploads/ to verify that the upload succeeded. Which IAM policy approach is the best fit for least privilege?
Easy364A web service runs continuously on AWS 24/7. The team expects steady compute usage for the next 12–24 months, but may change instance families/sizes as performance tuning continues. Which purchase option best reduces cost while keeping flexibility to change instance types?
Easy365A company runs a production MySQL database on Amazon RDS in us-east-1. A read replica exists in us-west-2 for disaster recovery. The primary region experiences a complete outage. Which of the following describes the correct procedure to restore database service using the cross-region read replica?
Hard366A company runs a stateless web tier on a fleet of On-Demand EC2 instances behind an Application Load Balancer. Traffic is steady and predictable, and the team has committed to running this tier for the next three years with no planned architectural changes. Management wants the lowest possible compute cost while preserving the ability to change instance families during the term if a better price-performance option emerges. Which purchasing approach best meets these requirements?
Medium367A solutions architect is designing an S3 bucket for a claims portal. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?
Medium368A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The architecture review board prefers a managed AWS-native control.
Hard369An orders service consumes payment instructions from an Amazon SQS queue. Sometimes the consumer times out after applying the payment but before deleting the SQS message. As a result, the same payment instruction is processed again. Which design change most directly prevents duplicate side effects caused by message retries?
Easy370Account B has an IAM role that includes kms:Decrypt for a specific KMS key ARN in account A. However, when the role tries to read an S3 object encrypted with that CMK, the application fails with AccessDenied: not authorized to perform kms:Decrypt. CloudTrail shows the KMS API call is denied by key policy. What is the most secure and correct fix?
Medium371A public API is deployed in two AWS Regions: us-east-1 (primary) and us-west-2 (secondary). The team wants Route 53 to automatically route users to the secondary region if the primary API becomes unhealthy. They will use Route 53 health checks that monitor the API’s /status endpoint over HTTPS. Which Route 53 configuration most directly implements this failover behavior?
Medium372A regional web application for a inventory service must fail over automatically to a secondary Region if the primary endpoint becomes unhealthy. Which two services or features are required? The team wants the control to be enforceable during normal operations.
Hard373A financial services company runs a critical application on Amazon EC2 instances in an Auto Scaling group. The application writes to an Amazon RDS for MySQL database. The company needs a recovery point objective (RPO) of 1 second and a recovery time objective (RTO) of 1 minute for the database in the event of a Regional disaster. Which solution meets these requirements?
Hard374Based on the exhibit, what is the most appropriate change to restore application access while keeping encryption at rest with customer-managed KMS controls?
Medium375A media company uses CloudFront in front of an S3 bucket origin for video thumbnails. They want to prevent users from bypassing CloudFront and accessing the S3 bucket directly, while still allowing CloudFront to fetch objects. What is the best option?
Easy376A payments platform requires disaster recovery across Regions. Requirements: RPO of 15 minutes and RTO of about 1 hour. The business cannot afford full duplicate capacity in both Regions all the time, but the team wants automated readiness so failover is mostly operationally guided rather than a slow rebuild. Which DR strategy is the best fit?
Medium377Your application uses ElastiCache Redis as a cache for user profiles stored in DynamoDB. You must ensure that when a profile is updated, subsequent reads see the latest value quickly. Which cache strategy is generally the best fit for this requirement?
Easy378A financial services firm runs a latency-sensitive trading application on Amazon EC2 instances distributed across three Availability Zones behind a Network Load Balancer. The application must continue serving traffic with no manual intervention if an entire Availability Zone becomes impaired, and each instance must receive a fair share of connections. Which combination of features meets these requirements?
Hard379A company runs a stateful web application on a fleet of Amazon EC2 instances in an Auto Scaling group. The application stores session state locally on each instance. During an Availability Zone failure, the Auto Scaling group replaces the unhealthy instances in a different AZ, but users lose their sessions and must log in again. The company wants to make the application resilient to AZ failures without requiring users to re-authenticate. Which solution should a solutions architect recommend?
Hard380An ECS service runs on EC2 capacity. During peak traffic, tasks frequently wait for available container instances. The team wants faster scale-out for the underlying EC2 capacity when tasks increase. What is the best first architectural step?
Easy381Based on the exhibit, the database must continue serving if the current Availability Zone fails. What should you change?
Easy382A company stores 500 TB of archival data in Amazon S3. The data is accessed only once a year for compliance audits. The company wants the most cost-effective storage solution that still allows retrieval within 48 hours. Which S3 storage class should they use?
Easy383A inventory service exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most?
Easy384A media company has users around the world uploading 1 to 5 GB files directly to a single Amazon S3 bucket. Upload times are slow from distant regions, but the app must keep using S3 as the destination. What should the architects enable to improve upload performance?
Medium385An application uses DynamoDB to store order status. Reads happen extremely frequently for the same few keys (for example, the most recent orders), and the team wants lower read latency without changing the table’s partition key design. Which AWS service best fits this requirement?
Easy386A web application for a mobile banking backend is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?
Medium387Based on the exhibit, a faulty deployment corrupted production data at 10:30 UTC and the issue was discovered at 10:55 UTC. The team needs to recover the database to the last good state before the corruption. Which action should they take?
Medium388A travel booking site uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured? The design must avoid adding custom operational scripts.
Easy389A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be reachable only from a specific corporate CIDR range, and the instances must not be directly reachable from the internet. Which combination of security group configurations meets these requirements?
Easy390A system uses multiple AWS Lambda functions behind different event sources. One Lambda occasionally spikes and causes other Lambdas to be throttled due to shared concurrency limits. Which setting best helps ensure the important Lambda keeps capacity during spikes?
Easy391A DynamoDB table for a retail API has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The design must avoid adding custom operational scripts.
Hard392A media processing pipeline uses EBS-backed storage for an application that performs sustained random I/O with low latency requirements. During peak processing windows, the team sees increased read latency and occasional timeouts at the application layer. They need predictable, high IOPS performance rather than best-effort throughput. Which EBS configuration choice is most appropriate?
Medium393A SaaS vendor’s automation account in Account B needs to assume a role in a customer account in Account A to read a specific S3 bucket and publish a deployment status file. The customer is worried about confused deputy attacks because multiple customers use the same vendor software. Which trust-policy design best meets the requirement?
Hard394An order system receives events and uses a Lambda function to write each order into a database. During traffic spikes, the database sometimes throttles, and Lambda retries lead to occasional message loss in the event flow. The team wants buffering, automatic retries, and a way to isolate messages that repeatedly fail so they can be inspected later. What design change best meets this need?
Easy395A company uses Amazon RDS for a PostgreSQL database powering a customer-facing application. The application’s availability depends on fast database failover with minimal manual intervention. The RDS instance currently runs as a single-AZ deployment in one DB subnet group. Which change most directly meets the goal?
Medium396A security analyst needs to let an external vendor (AWS account 555566667777) read data from a set of internal resources in your AWS account. You created an IAM role called VendorReadRole with a policy that allows the required API calls. However, when the vendor tries to access, CloudTrail shows the call fails at AssumeRole with: "Not authorized to perform: sts:AssumeRole". What is the most appropriate fix?
Medium397A public API for a e-learning platform is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?
Medium398A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable?
Medium399A high-volume telemetry pipeline writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate? The design must avoid adding custom operational scripts.
Medium400A financial analytics firm runs a nightly batch job on a fleet of Amazon EC2 instances that read millions of small JSON objects from an Amazon S3 bucket and write aggregated results to another S3 bucket. The job currently takes over six hours and the team wants to reduce this time without modifying the application code. The S3 buckets are in the same AWS Region as the EC2 instances. Which action will most effectively improve the performance of the batch job?
Medium401A media company is designing a high-performance architecture to serve video content to users worldwide. The solution must minimize latency for end users and reduce the load on the origin servers. The video files are stored in an Amazon S3 bucket. Which three options should be combined to meet these requirements? (Choose three.)
Medium402A Lambda function for a healthcare document service needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?
Medium403A serverless checkout API uses AWS Lambda behind API Gateway. Every weekday at 09:00 UTC, marketing triggers a predictable surge. The first few minutes after each surge show cold-start latency, but traffic volume is forecastable and the business wants stable p95 latency. Which two changes should the team implement? Select two.
Hard404A company serves a public API through a CloudFront distribution. They want to automatically block common web exploits (for example, OWASP Top 10–style threats) without building custom detection logic. Which AWS service configuration best meets the goal?
Easy405A company runs a media-processing pipeline that ingests thousands of small files per minute into Amazon S3 and triggers AWS Lambda functions for each object. Processing each file takes 2-3 seconds, and the team is seeing throttling errors and duplicated processing under load. They want to decouple ingestion from processing, buffer bursty traffic, and avoid duplicate deliveries to Lambda. Which solution should a solutions architect recommend?
Medium406A trading dashboard runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include?
Medium407A trading dashboard stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured?
Medium408An internal service is hosted behind an Application Load Balancer (ALB) with targets spread across two Availability Zones. If the targets in one Availability Zone become unhealthy, the service must continue serving traffic from the healthy AZ. What change most directly improves resilience at the load-balancing layer?
Easy409A healthcare analytics company stores protected health information in an Amazon S3 bucket. An application running on Amazon EC2 instances in a private subnet must upload objects to the bucket using temporary credentials. The security team requires that the EC2 instances never store long-term AWS credentials on disk, and that access be limited to only the specific S3 bucket. Which solution meets these requirements?
Medium410A regional web application for a inventory service must fail over automatically to a secondary Region if the primary endpoint becomes unhealthy. Which two services or features are required? The design must avoid adding custom operational scripts.
Hard411A media company runs a stateless transcoding fleet on Amazon EC2 instances spread across three Availability Zones behind a Network Load Balancer. The fleet must keep processing jobs even if an entire Availability Zone becomes unavailable, and the architect wants to minimize manual intervention. Which combination of actions should the architect take to meet these requirements?
Medium412A static website uses an Amazon S3 bucket as the origin for an Amazon CloudFront distribution. The team accidentally configured the S3 bucket policy to allow s3:GetObject to Principal "*", so objects are accessible via direct S3 URLs. They want to ensure objects are retrievable only through CloudFront. What is the best corrective action?
Medium413A public API for a customer analytics portal is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?
Medium414A company stores 500 TB of data in Amazon S3 Standard. The data is accessed frequently for the first 30 days after creation, then access drops to almost zero, but the data must be retained for 10 years for compliance. The company wants to minimize storage costs. Which solution is MOST cost-effective?
Medium415A company runs a two-tier web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The EC2 instances must access an Amazon Aurora MySQL DB cluster. A security engineer must ensure that only these EC2 instances can connect to the database, and that no credentials are stored on the instances. What should the security engineer do?
Medium416An event consumer sometimes processes the same SQS message more than once due to timeouts and retries. The consumer must ensure the payment is not charged twice. What design choice best addresses this requirement?
Easy417A inventory service uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The architecture review board prefers a managed AWS-native control.
Medium418A company’s private workload in a VPC uploads objects to an S3 bucket. Security requires that S3 requests are allowed only when they traverse a specific S3 Gateway VPC Endpoint (vpce-0abc123example). Which change best enforces this restriction at the S3 bucket level?
Easy419A media company runs a transcoding fleet on Amazon EC2 instances behind an Application Load Balancer in a single Availability Zone. The business requires the workload to survive the loss of that Availability Zone with no manual intervention and minimal downtime. The instances store intermediate files on instance store volumes and the fleet is managed by an Auto Scaling group. Which change should a solutions architect make to meet the requirement?
Medium420A company runs an EC2 Auto Scaling group behind an internet-facing Application Load Balancer. The security team must ensure that the instances accept HTTP traffic only from the ALB and never directly from the internet, while the ALB itself must accept traffic only from a specific corporate CIDR range. Which combination of security group configurations should a solutions architect implement?
Medium421A partner integration sends a custom binary TCP protocol to a service running on EC2 instances in private subnets. The partners require static endpoint IPs for allowlisting, and the application must see the original client source IP for rate limiting. Which two changes best fit the protocol and network requirements? Select two.
Hard422A media company runs a video transcoding pipeline on Amazon EC2 instances in a single Availability Zone. The pipeline writes intermediate files to an Amazon EBS volume attached to each instance. The company needs the pipeline to survive the failure of any single Availability Zone and to recover automatically with minimal data loss. Which change should a solutions architect make?
Medium423A company runs a steady-state web application on a fixed number of Amazon EC2 instances that have been running continuously for over a year. The workload is predictable and will remain in production for at least three more years. Management wants to reduce compute cost without changing the architecture. Which purchasing option should a solutions architect recommend?
Easy424A telemetry pipeline uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered?
Medium425A SaaS company uses an S3 bucket for database backups created daily. Backups are rarely restored; the company’s documented RTO is 24 hours, and the compliance policy requires backups be kept for 90 days. The team currently stores all backups in S3 Standard, which is costly. Which single lifecycle policy change is most cost-optimized while still meeting the 24-hour RTO and 90-day retention?
Medium426A inventory service uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured?
Medium427Based on the exhibit, the application team wants the database to keep the same connection endpoint during failover and to reconnect automatically after the primary instance becomes unavailable. Which change best meets the requirement?
Medium428A distributed system needs extremely low network latency between a set of EC2 instances running the same workload. The team wants the instances to be placed as close together as AWS allows to reduce round-trip time. Which placement strategy should the architect use?
Medium429A content publishing system uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The architecture review board prefers a managed AWS-native control.
Medium430A company runs a microservices application on Amazon ECS with AWS Fargate. The services communicate over HTTP/2 and gRPC. The architect needs to implement service-to-service communication that provides high throughput, low latency, and mutual TLS encryption. The solution must also support traffic splitting for canary deployments. Which approach should the architect take?
Hard431A healthcare company stores patient imaging studies in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. A security audit reveals that a former employee's IAM user still has s3:GetObject permissions on the bucket. The company wants to ensure the former employee can no longer decrypt any objects, even if they somehow regain S3 access, without affecting other users or applications. What should a security engineer do?
Medium432A team stores application logs in Amazon S3. They need access to the logs only occasionally for troubleshooting (infrequent access), and they want to reduce storage cost automatically over time without manually moving objects. What should they implement?
Easy433A internal reporting portal serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit?
Medium434A backup process restores a 2 TB production database from an EBS snapshot onto a new volume. During the first hours after restore, the application sees slow reads whenever previously unused blocks are accessed. What is the best way to avoid this performance issue in future restores?
Medium435Your global users access static images stored in S3. Origin bandwidth costs are higher than expected because CloudFront is not caching effectively. What change most directly reduces origin fetches (and typically lowers data transfer costs) without changing application logic?
Easy436Based on the exhibit, the application tier is not replacing unhealthy instances even though the Auto Scaling group spans two Availability Zones. What change most directly improves automatic recovery when the application process fails?
Hard437A team runs an EC2-based service and ships logs to Amazon CloudWatch Logs. They enabled long log retention and turned on detailed monitoring to improve troubleshooting. Their monthly CloudWatch costs have grown unexpectedly. Compliance requires that the logs remain available in CloudWatch Logs (for querying and audits) for 90 days, and alerts/alarms do not require detailed EC2 monitoring. What change best reduces cost while meeting requirements?
Medium438A high-volume telemetry pipeline writes streaming click events that must be processed by multiple independent consumers. Which service is most appropriate? The architecture review board prefers a managed AWS-native control.
Medium439A payments API requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The architecture review board prefers a managed AWS-native control.
Hard440A trading dashboard uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered?
Medium441A startup stores application configuration files in an Amazon S3 bucket. The security team wants to ensure that objects in the bucket are encrypted at rest with keys that the company manages and can rotate on its own schedule. Which S3 encryption option should a solutions architect choose?
Easy442A startup runs a stateless web application on a single Amazon EC2 instance in one Availability Zone. The application has become popular, and the startup wants to ensure that the application can survive the failure of an Availability Zone and can handle increased traffic. Which architecture change should the startup make FIRST?
Easy443An events service publishes critical notifications using Amazon SNS. Three independent downstream systems (A, B, and C) subscribe to the topic. Downstream system B sometimes fails to process certain messages (for example, it times out or returns an error while handling the message), and you want: 1) failures in B to be isolated so A and C keep processing unaffected, and 2) messages that B cannot successfully process after retries to be sent to a DLQ for B. Which design best meets these requirements?
Medium444A dev sandbox has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The architecture review board prefers a managed AWS-native control.
Medium445Based on the exhibit, what is the most appropriate fix so the workload in Account A can access the S3 bucket in Account B without using long-lived access keys?
Medium446A company hosts a image sharing application on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
Medium447A stateless web API runs on EC2 instances behind an Application Load Balancer (ALB). The Auto Scaling group (ASG) currently uses subnets from only one Availability Zone, even though the ALB spans two Availability Zones. During maintenance of that single AZ, the ALB remains up but clients see timeouts because there are no healthy targets. Which change most directly improves resilience against an AZ failure?
Medium448An orders service publishes payment instructions to an Amazon SQS Standard queue. A downstream consumer sometimes times out or crashes after it has partially completed processing, causing the same instruction to be processed more than once. You must keep the design resilient without attempting to guarantee exactly-once processing. Which approach best handles duplicates safely?
Medium449A reporting application in Account B must read files from an S3 bucket in Account A. The bucket contains objects encrypted with a customer managed KMS key in Account A. The application role in Account B already has an identity policy allowing s3:GetObject on the bucket prefix, but requests still fail with AccessDenied. Which two changes are required for the application to read the objects? Select two.
Hard450A marketing site runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost? The design must avoid adding custom operational scripts.
Medium451Your team runs a tightly coupled distributed workload (for example, synchronous training nodes) across many EC2 instances placed within a single cluster environment. The instances need low-latency networking to reduce delays at synchronization barriers. Which EC2 placement strategy should you use to improve inter-node latency?
Medium452A startup runs a stateless web application on a fleet of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. Traffic is steady during business hours, but the team has configured the scaling policy with a target tracking metric of average CPU utilization at 50 percent. Users report intermittent 5xx errors during sudden traffic surges. Which change will most directly improve the application's ability to absorb rapid traffic increases?
Easy453A financial services company runs an internal web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must authenticate employees against the corporate identity provider (IdP) that supports SAML 2.0, and the company wants to avoid managing custom sign-in code. Which solution should a solutions architect recommend?
Medium454A claims workflow uses an RDS MySQL database and must remain available during an Availability Zone failure with minimal application changes. What should the architect enable? The design must avoid adding custom operational scripts.
Medium455A CI/CD pipeline needs to deploy to your production environment. Security requires that the pipeline uses temporary credentials (not long-lived access keys) and only has permissions to read a specific set of parameters from AWS Systems Manager Parameter Store and write application logs to CloudWatch Logs. What is the best AWS approach?
Easy456A company runs a containerized microservices application on Amazon ECS with the Fargate launch type. The application experiences highly variable traffic, with long periods of low utilization and occasional sharp spikes. The company wants to minimize cost while ensuring the application can scale quickly during spikes. The tasks are stateless and can be restarted. Which combination of actions will meet these requirements MOST cost-effectively?
Hard457A healthcare company stores protected health information in an Amazon S3 bucket. Compliance requires that all data be encrypted at rest with keys that the company controls and can rotate on demand. The security team also needs to audit every use of the encryption keys and immediately revoke access for a compromised IAM role without affecting other roles. Which solution meets these requirements?
Hard458A retail company runs a stateless web tier on Amazon EC2 instances behind an Application Load Balancer. During flash sales, response times spike because each request triggers many database queries. The team wants to reduce database load and improve read latency for product catalog pages that change only a few times per day. Which solution is MOST appropriate?
Medium459Based on the exhibit, the team must restore an Amazon RDS for PostgreSQL database to the exact state just before a bad delete happened. What is the best recovery approach?
Hard460A company hosts a critical web application on Amazon EC2 instances in a VPC. The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. They also want to monitor and control access to the application at the HTTP/HTTPS level. Which AWS service should a solutions architect use to meet these requirements?
Medium461A company hosts a e-learning platform on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
Medium462A patient portal must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable?
Hard463Based on the exhibit, the team wants to minimize compute cost for a workload with a steady 24/7 baseline and a separate nightly batch job that can be interrupted and resumed from checkpoints. They also expect to change EC2 instance families during the year as performance needs evolve. Which approach is the best fit?
Hard464A worker consumes messages from an Amazon SQS queue. Some messages consistently fail validation and are retried until the worker can no longer process them. What is the most appropriate AWS mechanism to handle these poison messages while keeping the queue usable?
Easy465A retail API uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured?
Easy466A trading dashboard runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The team wants the control to be enforceable during normal operations.
Medium467A solutions architect is configuring a VPC for a three-tier web application. The database tier must not be reachable from the internet, and only the application tier should be able to initiate connections to the database on port 3306. The application tier runs on EC2 instances in a separate subnet. Which configuration enforces this requirement?
Easy468A media processing workflow generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used?
Hard469You run a web application on an EC2 Auto Scaling group behind an Application Load Balancer (ALB). During scheduled traffic spikes, new instances launch but customers occasionally see 5xx errors for the first few minutes after scale-out. Operational logs show instances need ~4 minutes to warm up (load caches and initialize dependencies). ALB target health becomes healthy only after this warm-up. Which change most directly improves performance during spikes by reducing the time to serve traffic after scaling?
Medium470A telemetry pipeline uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add?
Medium471A company serves public JavaScript and CSS files from S3 using CloudFront. After a frontend change, customers report a low CloudFront cache hit ratio. Requests now include an Authorization header, but these assets do not require authentication. The CloudFront distribution is configured such that Authorization is included in the cache key. Which change best maximizes cache reuse?
Easy472A order processing API uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?
Hard473Based on the exhibit, the company wants DNS traffic to fail over automatically from the primary Region to a secondary Region when the primary endpoint is unhealthy. Which Route 53 change is best?
Medium474A mobile banking backend uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?
Hard475A company has an application running on Amazon EC2 instances that needs to access an Amazon S3 bucket. The security team wants to avoid storing long-term AWS credentials on the instances. Which solution should they implement?
Easy476A IoT ingestion API uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?
Hard477A microservice runs in private subnets and must read exactly one AWS Secrets Manager secret using its IAM task role: arn:aws:secretsmanager:us-east-1:111122223333:secret:prod/db-pass-AbCdEf Security requires that every Secrets Manager API call comes only through a specific Interface VPC Endpoint (vpce-0a1b2c3d4e5f6g7h), and must not be reachable over any other network path. Which IAM policy change best enforces this requirement?
Medium478A batch analytics job has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The design must avoid adding custom operational scripts.
Medium479A financial analytics platform stores results in an Amazon S3 bucket. Compliance requires that objects be recoverable for 30 days after deletion and that no user, including administrators, be able to permanently erase them during that window. Objects must also remain readable throughout the retention period. Which approach should the architect implement?
Hard480A document portal needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable? The architecture review board prefers a managed AWS-native control.
Hard481Your company allows application teams to create IAM roles. Each team must be prevented from granting permissions beyond a defined per-role baseline, even if they attach overly permissive identity-based policies to the role. Which AWS feature best enforces this ceiling at the IAM role level?
Easy482A test environment stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost? The architecture review board prefers a managed AWS-native control.
Medium483A healthcare company stores patient records in an Amazon S3 bucket. Compliance requires that every object be encrypted with a key that the company rotates on its own schedule, that key usage be logged separately from S3 data events, and that a specific group of IAM principals be the only identities allowed to use the key for cryptographic operations. The security team has already created a symmetric AWS KMS customer managed key. Which combination of actions should the team take to meet these requirements?
Medium484An order lookup API repeatedly reads the same few items from DynamoDB. The application can tolerate slightly stale data for a few seconds, and the team wants the lowest-latency design with minimal application changes. Which two changes should they make? Select two.
Medium485A analytics dashboard uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add? The architecture review board prefers a managed AWS-native control.
Medium486Based on the exhibit, a static asset distribution site uses Amazon CloudFront with an S3 origin. The assets are versioned by filename, but the cache hit ratio remains low after each release. Which CloudFront change is the best way to improve cache reuse without changing the origin objects?
Hard487A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used?
Hard488A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ASG is currently attached to subnets in only two Availability Zones (AZs). During a planned maintenance window, one AZ becomes unavailable for about 25 minutes. Monitoring shows that targets in the remaining AZ go healthy, and the ALB/target group health checks report normal. However, users still experience intermittent connection failures and slower responses during the AZ outage. What change will most directly improve resilience against an AZ loss while keeping the same ALB-based design?
Medium489A company runs a batch processing job on Amazon EC2 instances that runs for 4 hours every night. The job can be interrupted and restarted from a checkpoint. The company wants to minimize compute costs for this job. Which solution is MOST cost-effective?
Easy490A SaaS company serves a global web application from a single AWS Region. Users in distant geographies report high latency for static assets such as images and JavaScript bundles, and the company wants to reduce this latency without modifying the application code. Which action BEST achieves this?
Medium491A healthcare company stores patient imaging studies in an Amazon S3 bucket. Compliance requires that every object be encrypted at rest with a key the company fully controls, including the ability to rotate and revoke the key independently of AWS. The security team must also be able to audit every use of the key. Which solution meets these requirements with the LEAST operational overhead?
Medium492A solutions architect is designing an S3 bucket for a claims portal. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure? The design must avoid adding custom operational scripts.
Medium493A company is migrating a legacy application to AWS. The application uses a fixed set of credentials stored in a configuration file to access an Amazon RDS database. The security team wants to eliminate hardcoded credentials and automatically rotate them every 30 days. The application runs on Amazon EC2 instances and can be modified to retrieve credentials at startup. Which solution meets these requirements with the LEAST operational overhead?
Medium494A risk simulation workload uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured?
Medium495A warehouse integration service receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The architecture review board prefers a managed AWS-native control.
Medium496A nightly video rendering pipeline runs on Linux EC2 instances and is compatible with ARM64. The jobs are CPU-bound, checkpoint frequently, and can resume if interrupted. The business wants the best throughput per dollar for the batch window. Which two changes should the team make? Select two.
Hard497Company A must allow workloads in Company B to assume an IAM role in Company A (RoleInA). To mitigate confused-deputy attacks, a Security requirement is to use an External ID. Company A should restrict who can assume RoleInA. Which trust-policy configuration is the best choice?
Easy498Based on the exhibit, which AWS service should the team use so the database password can rotate automatically every 30 days and the application can retrieve it securely at runtime?
Medium499A company runs a web application on AWS and wants to reduce costs. The application uses an Application Load Balancer (ALB) to distribute traffic to Amazon EC2 instances in an Auto Scaling group. The company observes that the EC2 instances are underutilized during off-peak hours. They want to optimize costs without affecting performance during peak hours. Which two actions should they take? (Choose two.)
Hard500A data engineering team runs an Amazon EMR cluster that processes large datasets stored in Amazon S3. The cluster uses Amazon EBS volumes for temporary storage, and jobs frequently spill intermediate data to disk. The team notices that shuffle operations are slow and wants to improve performance without changing the data format or increasing the number of core nodes. Which change should the team make?
Hard501A team stores application logs in an S3 bucket. They keep logs for 18 months for compliance. Access patterns: logs are heavily accessed during the first 30 days, rarely accessed between days 31 and 180, and almost never accessed after day 180. They currently store everything in S3 Standard and want to reduce storage cost without violating the 18-month retention requirement. What should they implement?
Medium502Based on the exhibit, a web application runs on an Amazon EC2 Auto Scaling group behind an Application Load Balancer. During traffic surges, the average CPU utilization stays below 35%, but request latency increases sharply and the ALB access logs show far more requests per target than expected. Which change is the best way to improve scaling behavior?
Hard503A company is migrating its on-premises workloads to AWS and wants to optimize costs. Which three strategies should the company implement to achieve a cost-optimized architecture? (Choose three.)
Medium504A SaaS company hosts a REST API on Amazon API Gateway with AWS Lambda proxy integration. The API serves tenants in North America and Europe. European users report high latency, but the Lambda function and its Amazon RDS database must remain in the us-east-1 Region for data residency and cost reasons. The team wants to reduce latency for European users without moving the backend. Which solution meets these requirements?
Medium505A media processing workflow uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured?
Medium506A company needs to replicate a DynamoDB table to three AWS regions so that users in each region can read and write to a local copy with the lowest possible latency. Changes must propagate to all regions within seconds. Which solution should a solutions architect implement?
Medium507Based on the exhibit, an Amazon Aurora MySQL application is read-heavy, but the database writer is nearing CPU limits while the reader instance is mostly idle. The application currently sends all queries to the writer endpoint. Which change should you make first to increase read throughput?
Hard508A patient portal must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The design must avoid adding custom operational scripts.
Hard509A logistics company runs an Amazon RDS for MySQL database that supports a parcel-tracking API. During the morning peak, read queries for tracking history saturate the primary instance's CPU, slowing writes. The reads can tolerate a few seconds of staleness, and the team wants to offload them without changing the database engine. Which action should the team take?
Medium510A company runs an application on EC2 instances in private subnets. The instances must access Amazon S3, and the team currently routes all outbound traffic to the internet through a NAT Gateway. Monthly NAT Gateway charges increased significantly, even though the application only needs to call S3 (not access other public internet services). Which change will most directly reduce NAT Gateway charges while keeping S3 access working?
Medium511A team needs to distribute TCP traffic (not HTTP) across multiple services. The services must see the original client source IP for auditing. Which AWS load balancer is the best fit?
Easy512A web application for a healthcare document service is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy? The design must avoid adding custom operational scripts.
Medium513A security team must ensure that all data written to a new Amazon S3 bucket is encrypted with a specific customer-managed AWS KMS key, and that any PUT request that does not specify that key is rejected. The team also needs to detect and react if someone attempts to change the bucket policy to remove the restriction. Which combination of actions meets these requirements with the LEAST operational effort?
Hard514A payments API requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The design must avoid adding custom operational scripts.
Hard515A trading analytics system deploys multiple EC2 instances that exchange very frequent, low-latency, east-west messages. The application team wants the instances to be placed to minimize network latency and variability. Which AWS feature should they use?
Easy516A healthcare document service must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?
Hard517A company hosts an internal API behind an Application Load Balancer (ALB) in two AWS Regions. They want Amazon Route 53 to automatically fail over to the secondary Region when the primary Region’s ALB is unhealthy. Health checks for the primary ALB are already configured, but the DNS record currently uses a latency-based routing policy. Which Route 53 configuration most directly provides automatic failover based on health status?
Medium518A central security account stores encrypted log files in S3 using a customer managed AWS KMS key. A partner account already has S3 bucket access through an assumed role and now must also be able to encrypt and decrypt objects that use the same KMS key. Which two actions are required? Select two.
Medium519An S3 bucket in account A uses default server-side encryption with an AWS KMS customer-managed key (CMK) in account A. A team created an IAM role in account B that is allowed by IAM policy to perform s3:GetObject on the bucket. When the account B role tries to read objects, it fails with: AccessDeniedException: 'User is not authorized to perform kms:Decrypt'. Which change is most likely to fix the issue?
Medium520A media company hosts a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from individual IP addresses to mitigate scraping. Which AWS service should a solutions architect associate with the load balancer to meet both requirements?
Medium521A media company streams live video from on-premises encoders to viewers across North America. The encoders push a single RTMP feed to AWS, and the company wants the lowest possible glass-to-glass latency for viewers while distributing to thousands of concurrent viewers. The team does not want to manage any streaming servers. Which solution BEST meets these requirements?
Medium522A web application uses an Amazon Aurora DB cluster for a read-heavy workload. The team wants to increase read throughput without changing the database schema or rewriting application data access patterns. Which two changes should they make? Select two.
Medium523A company uses AWS Organizations and wants to prevent any account in the organization from launching resources in regions other than us-east-1 and eu-west-1. This restriction must apply even if an administrator in a member account grants full IAM permissions. Which approach should a solutions architect use?
Hard524An orders service publishes payment instructions to an Amazon SQS Standard queue. A downstream consumer sometimes times out and retries the work, causing the consumer to process the same instruction more than once. Operationally, the team must ensure that duplicate processing does not create duplicate charges. The queue type cannot be changed. What is the most resilient application-side approach?
Medium525A startup runs a two-tier web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in private subnets and must reach the internet only to download operating system patches. Security policy forbids any inbound internet traffic to the instances. Which configuration meets these requirements with the least operational overhead?
Easy526A solutions architect is designing a high-performance computing (HPC) workload on AWS that requires a shared POSIX-compliant file system with high throughput and low latency for thousands of concurrent compute instances. The workload is temporary, running for a few hours each week, and the team wants to minimize cost. Which storage solution should the architect recommend?
Hard527A serverless API built with AWS Lambda serves latency-sensitive requests. The team observes intermittent slow responses during traffic ramp-ups and expects some users to hit the API immediately after a period of inactivity. Which configuration best reduces cold-start latency during these ramp-ups?
Medium528A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The architecture review board prefers a managed AWS-native control.
Medium529A solutions architect is designing an S3 bucket for a order processing API. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure?
Medium530A solutions architect is designing an S3 bucket for a IoT ingestion API. The objects must never be publicly accessible, even if a developer later adds an overly broad bucket policy. What should the architect configure? The design must avoid adding custom operational scripts.
Medium531A retail company hosts a product catalogue API on Amazon EC2 instances behind an Application Load Balancer. The API serves mostly small JSON responses and is read-heavy. Users in a distant continent report slow response times even though the origin servers are not heavily loaded. The company cannot change the application and wants the lowest-latency read experience globally. Which service should they use?
Easy532A service processes messages from an Amazon SQS queue. Sometimes the worker finishes the business logic but does not delete the message before the visibility timeout expires, so the message is delivered again. Which two changes improve resilience and reduce the impact of duplicate processing? Select two.
Easy533A analytics dashboard uses RDS MySQL and receives many read-only reporting queries that slow down the primary database. What should the architect add? The team wants the control to be enforceable during normal operations.
Medium534Based on the exhibit, the team wants to stop poison messages from consuming worker capacity and also prevent duplicate side effects if the same message is delivered more than once. Which design change best meets the requirement?
Medium535Based on the exhibit, a company stores sensitive PDFs in S3 and serves them through CloudFront. Direct requests to the S3 object URL must fail, but CloudFront should still be able to fetch the files securely. Which solution best satisfies the requirement?
Hard536A latency-sensitive API is implemented with AWS Lambda. During traffic ramp-ups, users sometimes experience slow responses due to cold starts. The team wants to ensure fast initialization for a baseline level of concurrent requests. Which AWS feature should they use?
Easy537A caching layer uses Amazon ElastiCache for Redis in front of a stateless web service. The service must continue to read cached responses during maintenance events and should automatically fail over to another node if one AZ becomes impaired. Which design change best satisfies this requirement?
Medium538A company stores millions of small, rarely accessed backup objects in Amazon S3 Standard. The objects must remain immediately retrievable within milliseconds and be retained for at least five years, but the company wants to reduce storage cost. Which action should the company take?
Easy539An ECS service runs on EC2 instances and is fronted by an ALB. The ALB spans two Availability Zones, and the ECS service desired count is 2 tasks. The underlying EC2 capacity uses an Auto Scaling group (ASG) with min size set to 1, and the ASG also spans only one subnet in practice. What is the most effective change to meet the requirement that the service continues during a single-AZ instance loss?
Medium540A video platform uses Amazon Aurora. The workload has many short-lived database connections from Lambda functions, causing connection storms. What should be added? The design must avoid adding custom operational scripts.
Medium541A financial services company must store audit logs in S3 for 7 years and ensure that no one — including the AWS account root user — can delete or overwrite the logs during the retention period. Which S3 Object Lock configuration should a solutions architect use?
Hard542A small e-commerce company runs a web application on a single Amazon EC2 instance in one Availability Zone. The instance stores session state locally and the database runs on the same instance. The company wants the application to survive an Availability Zone failure with minimal changes and no data loss for committed orders. Which combination of changes should the architect recommend?
Easy543Based on the exhibit, which Amazon EFS performance mode is the best fit for this workload?
Easy544A warehouse integration service must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The architecture review board prefers a managed AWS-native control.
Hard545An order-processing worker consumes messages from Amazon SQS. Occasionally, the worker times out after successfully creating a payment record but before deleting the message, which causes duplicate charges during retries. Some messages also fail validation repeatedly because required fields are missing. Which two changes should the team make? Select two.
Medium546A analytics dashboard uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered?
Medium547A DynamoDB table for a retail API has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The architecture review board prefers a managed AWS-native control.
Hard548A SaaS provider runs a multi-tenant application on Amazon RDS for PostgreSQL. The database is 2 TB and experiences steady read-heavy traffic during business hours. The provider wants to offload read traffic to reduce load on the primary instance and lower cost compared to scaling up the primary. The application can tolerate slightly stale reads for reporting queries. Which solution is MOST cost-effective?
Hard549A payments API uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The design must avoid adding custom operational scripts.
Hard550A content publishing system exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most? The design must avoid adding custom operational scripts.
Easy551A marketing site stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost?
Medium552A marketing team runs a report-generation process that must execute once per day at 02:00 UTC. It usually completes in 10315 minutes, but sometimes takes up to 45 minutes due to varying data volumes. They currently run the workload on an EC2 instance that is always on, which wastes money during off-hours. The team wants to minimize operational overhead and pay mainly for actual execution time. What is the best architecture choice?
Medium553A startup runs a nightly batch job on a single EC2 instance that reads a large dataset from Amazon S3, performs transformations, and writes results back to S3. The job takes about two hours, and the team wants the job to restart automatically if the instance fails or is terminated by AWS. The job is idempotent and can safely resume from the beginning. What is the MOST operationally efficient way to meet this requirement?
Easy554Based on the exhibit, downstream payment timeouts cause EventBridge deliveries to back up and some events are retried until they age out. What change best improves resilience and preserves events during downstream outages?
Hard555You need to run batch jobs on EC2. The jobs can tolerate interruptions: if an instance is terminated, the job can restart from checkpoints. To reduce compute cost as much as possible, what is the best choice?
Easy556Account Y provides a role named AnalyticsReadOnly to engineers in Account X. The role trust policy currently allows sts:AssumeRole from the Account X principal. A new security requirement states that only STS sessions created with MFA are allowed to assume the role. Which trust policy condition is the best choice to enforce MFA for sts:AssumeRole?
Medium557A company has a critical application running on Amazon EC2 instances that must access an Amazon RDS for MySQL database. The security team requires that the database credentials are never stored on the EC2 instances and that access to the database is auditable. The database is in a private subnet and only accepts connections from the application's security group. The company wants to implement a solution that automatically rotates the database password every 90 days. Which solution meets these requirements?
Hard558A trading analytics system deploys 10 EC2 instances that exchange very frequent, low-latency messages over the network. The instances must be placed as close together as possible to minimize network hop count and inter-node jitter. Which deployment choice best matches this requirement?
Medium559A analytics dashboard uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered? The design must avoid adding custom operational scripts.
Medium560A company runs a stateful web application on a single Amazon EC2 instance in a public subnet. The application stores session data on the instance's root volume. The company wants to make the application highly available across two Availability Zones and ensure that session data is preserved if an instance fails. Which solution should a solutions architect recommend?
Hard561Based on the exhibit, what is the best change to improve read performance without increasing write latency on the primary database?
Hard562A healthcare company runs a critical patient-records API on Amazon EC2 instances behind an Application Load Balancer in a single AWS Region. The compliance team mandates that the API remain available even if an entire AWS Region becomes unavailable. The company wants a cost-effective solution that avoids running full production capacity in a second Region at all times. Which approach BEST meets these requirements?
Medium563A company runs a stateful analytics workload on EC2 instances that use EBS volumes. The data must be restorable in another Region after a major outage, with frequent point-in-time recovery. Which approach provides the most suitable replication mechanism for the EBS-backed data?
Medium564A company hosts a web application on EC2 instances behind an Application Load Balancer (ALB) in us-east-1. A static failover site is hosted in an S3 bucket with static website hosting enabled. The company needs automatic DNS failover to the S3 bucket if the primary ALB becomes unhealthy. Which Route 53 configuration achieves this?
Medium565A DynamoDB table for a travel booking site has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The architecture review board prefers a managed AWS-native control.
Hard566A company stores several petabytes of archived regulatory records in Amazon S3. The records must be retained for seven years and are almost never accessed, but if an auditor requests a record, it must be retrievable within 12 hours. The company wants the lowest storage cost that still meets the retrieval requirement. Which S3 storage class should the solutions architect choose?
Easy567A company hosts a public website on Amazon EC2 instances behind an Application Load Balancer. The site is static HTML, CSS, and images, and the same content is served to all visitors. Origin CPU is high because every request is forwarded to the instances, and visitors in remote Regions see slow page loads. The team wants to reduce origin load and improve global latency with the least operational effort. Which solution should be used?
Medium568A financial analytics company runs a nightly batch job that reads 4 TB of compressed log data from an Amazon S3 bucket and writes aggregated results to another S3 bucket. The job runs on a fleet of 8 Amazon EC2 instances in a single AWS Region, and the team wants the highest possible aggregate read throughput while minimizing request costs. The data is already stored in S3 Standard, and the team does not want to change the storage class. Which solution best meets these requirements?
Medium569A company needs to give an external auditing firm read-only access to specific objects in an Amazon S3 bucket for 30 days. The firm has its own AWS account and should not receive long-term credentials. The company wants to minimize the blast radius if the firm's account is compromised. Which two steps should the company take? (Choose two.)
Medium570A company runs a critical application on Amazon EC2 instances in a single Availability Zone. The application writes data to an Amazon RDS for MySQL DB instance that is not Multi-AZ. The company wants to improve the resilience of the database tier so that it can survive an Availability Zone failure with minimal downtime and no data loss. The application uses the database endpoint from the RDS console. Which solution meets these requirements?
Hard571A logistics company runs an Amazon RDS for MySQL database that supports a shipment tracking application. Read replicas are already in use, but the primary instance's CPU is saturated by a small number of long-running analytical queries that the reporting team runs directly against the primary. The company wants to offload these analytical queries and improve primary performance while keeping the application's transactional writes fast. (Choose two.)
Hard572Your team hosts versioned static assets (for example, /static/app-<buildHash>.js). Each build hash never changes, but you release new files on new URLs. To maximize cache hit rate and reduce origin load using CloudFront, what should you do when generating HTTP responses for these assets?
Easy573Based on the exhibit, which storage design best supports the application servers' shared working directory requirement?
Hard574A web application runs on an Amazon EC2 Auto Scaling group (ASG) behind an Application Load Balancer (ALB). The ALB is configured to use at least two Availability Zones (AZs), but the ASG currently uses subnets in only one AZ. If that AZ becomes unavailable, the application stops serving requests. Which change most directly improves resilience to an AZ outage?
Easy575A healthcare analytics platform ingests records into an Amazon Aurora MySQL cluster. Compliance rules require that the cluster remain writable even if an entire Availability Zone is lost, and that recovery happen without operator action. The team also wants read traffic to scale independently of the writer. Which configuration should a solutions architect choose?
Hard576A media company distributes on-demand video to viewers in North America, Europe, and Asia. The videos are stored in a single Amazon S3 bucket in us-east-1 and are served directly from S3. Viewers in Asia report slow start times and frequent buffering. The company wants to reduce latency for all viewers with minimal operational overhead. Which solution meets these requirements?
Medium577A test environment runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost? The design must avoid adding custom operational scripts.
Medium578An order-processing system publishes an event whenever a payment succeeds. Three downstream services (inventory, shipping, and analytics) must react independently. Analytics sometimes has high latency, but order processing must not be blocked. What is the best AWS approach to decouple these consumers?
Easy579An internal worker consumes messages from an Amazon SQS Standard queue. Recently, some messages fail validation in the worker (for example, missing required fields), causing the worker to crash before it can successfully process those messages. Those messages keep getting retried repeatedly, slowing down processing of valid messages. The team wants a resilient mechanism to quarantine bad messages after a limited number of receive attempts. What should they implement?
Medium580A company is deploying a web application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer. The company wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to restrict access to specific geographic regions. Which combination of AWS services should a solutions architect use to meet these requirements?
Medium581A logistics company stores shipment events in an Amazon S3 bucket. An analytics team must be able to recover any object version that is accidentally overwritten or deleted for at least 90 days, and objects must be protected from permanent deletion by any user, including the root user, during that window. Which combination of S3 features meets these requirements with the LEAST operational overhead?
Hard582A web application for a claims portal is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?
Medium583A ticket booking system runs on EC2 instances behind an Application Load Balancer. The design must tolerate the failure of one Availability Zone. What should the Auto Scaling group configuration include? The design must avoid adding custom operational scripts.
Medium584A company uses an Amazon Aurora DB cluster in a Multi-AZ configuration. During a planned failover of the writer instance, the database endpoints in the application are updated incorrectly. After failover, reads work but writes fail with connection errors and timeouts for several minutes. The team currently uses the instance endpoint for the writer. What should they change to improve write resilience during failovers?
Medium585A claims workflow requires point-in-time recovery and accidental-delete protection for a DynamoDB table. Which two settings should the architect enable? The design must avoid adding custom operational scripts.
Hard586A web application uses an Amazon Aurora DB cluster for a read-heavy workload. The application team needs higher read throughput but cannot change the database schema. They want to avoid blocking writes and are willing to route read traffic separately. What is the most appropriate architecture change?
Medium587An S3 bucket stores application logs. After 30 days, the team rarely accesses the logs, but compliance requires keeping them for 18 months. Which setup most directly reduces storage cost while maintaining compliance?
Easy588A company is running a production web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The workload has predictable traffic spikes during business hours and low traffic at night. The current architecture uses On-Demand EC2 instances, leading to high costs. The company wants to reduce costs without sacrificing availability or performance. Which three of the following strategies would help achieve this goal? (Choose three.)
Medium589A web application for a IoT ingestion API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy? The design must avoid adding custom operational scripts.
Medium590A DynamoDB table for a retail API has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change?
Hard591A document portal requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The architecture review board prefers a managed AWS-native control.
Medium592A media processing workflow in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost? The design must avoid adding custom operational scripts.
Hard593A trading dashboard stores uploaded documents in S3. The business requires a copy in another AWS Region for disaster recovery. What should be configured? The design must avoid adding custom operational scripts.
Medium594A stateless web application runs on Amazon EC2 instances across two Availability Zones. The team wants unhealthy instances to be removed automatically and replaced without manual action. What is the best solution?
Easy595A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The team wants the control to be enforceable during normal operations.
Medium596An order-quote Lambda function is invoked directly by API Gateway. Traffic is predictable during the business day, and the first request after scaling from zero causes unacceptable latency. The team wants to keep the current architecture and reduce cold-start impact. Which configuration should they use?
Medium597An order processing workflow uses Amazon SQS as the decoupling layer between a producer and a consumer Lambda function. The consumer intermittently fails due to a downstream dependency. The team has observed that certain “poison” messages keep being retried repeatedly and prevent other messages from being processed efficiently. Which SQS configuration most directly addresses this issue?
Medium598A startup runs a stateless web application on a single Amazon EC2 instance in one Availability Zone. The application must remain available if the instance fails or if its Availability Zone becomes unavailable. The startup wants a managed solution that requires minimal operational overhead. Which solution should a solutions architect recommend?
Easy599Your application runs in private subnets with no NAT gateway. It needs to call AWS Secrets Manager to retrieve secrets. For private connectivity without internet egress, which VPC endpoint type should you create for AWS Secrets Manager?
Easy600A dev sandbox has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity?
Medium601A serverless checkout API runs on AWS Lambda behind API Gateway. Traffic spikes are predictable every weekday at 09:00 UTC, and p95 latency jumps for the first few minutes after each deployment because execution environments are cold. The team wants to reduce this startup impact without changing the API contract. Which changes should they make? Select three.
Hard602A production internal reporting portal runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy? The design must avoid adding custom operational scripts.
Medium603A website serves mostly cacheable images, CSS, and JavaScript from an ALB. Users in Europe and Asia report slower page loads, and the ALB receives far more requests than expected. The team also wants text assets compressed automatically. Which change is the best first step?
Medium604A system processes events from Amazon SQS and sometimes sees duplicate messages due to retries. The business requirement is that each payment must be charged at most once. What design choice best addresses this resiliency requirement?
Easy605A latency-sensitive API is implemented with AWS Lambda. The team enabled provisioned concurrency to avoid cold starts, setting provisioned concurrency to 50 because marketing campaigns occasionally cause spikes. However, during most weekdays the API receives little traffic (near zero), and the team is seeing high monthly Lambda costs from idle provisioned capacity. What is the best cost-optimized strategy that still meets the requirement of fast initial responses during traffic spikes?
Medium606A company hosts a web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The ALB and the Auto Scaling group are currently deployed in only one Availability Zone (AZ). The business wants the application to keep running if that AZ has an outage. What is the best change?
Easy607A containerized service on Amazon ECS connects to a database with a password that must never be stored in plaintext or hardcoded in the image. The application reads the password at startup and occasionally reconnects later, so it needs to retrieve the current secret when needed. Which three actions should the architect take? Select three.
Medium608A telemetry pipeline uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered? The design must avoid adding custom operational scripts.
Medium609Account A has an IAM role named FinanceDataRole that is assumed by a principal in Account B. The role’s trust policy includes a condition requiring sts:ExternalId to equal "Fin-2026-Q2". A developer in Account B calls AssumeRole but receives an error: AccessDenied: ExternalId mismatch. The security team requires that you do not remove the ExternalId condition. What is the correct remediation?
Medium610A company has a primary application in us-east-1 and a standby environment in us-west-2. Users should go to the primary site while it is healthy and automatically switch to the standby site if the primary fails. Which Route 53 routing policy should they use?
Easy611Based on the exhibit, an application runs on Amazon Aurora MySQL. The writer instance is frequently near 85% CPU while the reader instance is under 20% CPU. Application traces show that most of the database traffic is read-only SELECT queries, but the code currently sends all queries to the writer endpoint. What should the solutions architect recommend to improve performance with the smallest functional change?
Hard612A public API for a B2B file exchange site is deployed on API Gateway. Clients must authenticate with standards-based tokens issued by an external OpenID Connect provider. Which authorization mechanism should be used?
Medium613A product catalog system uses a relational database for orders and a simple key-value profile store for shopping carts. Traffic is unpredictable, and the company wants to avoid paying for large idle database instances. Which two choices are best? Select two.
Hard614A DynamoDB-backed event processing system experiences throttling during a promotion. All events are written and read using the same partition key value (tenantId = "ACME"). The workload is time-ordered per tenant, and the application can tolerate slight reordering across partitions. Which design change will most directly increase throughput and reduce hot-partition throttling?
Medium615A company runs a web application on Amazon EC2 instances in multiple Availability Zones. The application uses an Application Load Balancer and an Auto Scaling group. The company wants to reduce cost while maintaining high availability. The workload is steady and predictable, and the instances run continuously. Which two actions will reduce cost? (Choose two.)
Medium616Account A hosts a role named AppReadRole. Account B needs to access it using STS AssumeRole. Account A’s role trust policy includes this condition: - StringEquals: { "sts:ExternalId": "b-7f9a" } When Account B runs: aws sts assume-role --role-arn arn:aws:iam::111111111111:role/AppReadRole --role-session-name test the call fails with: "AccessDenied: ExternalId mismatch". What should Account B change?
Medium617Based on the exhibit, an EC2 application runs in private subnets with no NAT gateway and must retrieve a secret from AWS Secrets Manager. The secret uses a customer managed KMS key. Which change will allow the application to reach the service while keeping traffic off the internet?
Hard618A web application runs on an Amazon EC2 Auto Scaling group behind an Application Load Balancer (ALB). After each deployment, new instances take about 2 minutes to download artifacts and become ready to accept requests on the target port. In the last deployment, the ALB started marking targets unhealthy before the app was ready, and the Auto Scaling group then replaced those instances repeatedly, causing a prolonged outage. Which change best improves resilience during instance start-up without reducing actual availability once the application is healthy?
Medium619Account A hosts an IAM role that Account B developers must assume for a limited task. You want to require MFA for anyone assuming the role. Which trust policy condition most directly enforces that requirement for sts:AssumeRole?
Easy620A customer-facing application has a relational data model and needs frequent complex queries (joins and aggregations), but it also experiences a significant read-heavy workload. Which design choice best improves read performance while keeping relational features?
Easy621A media company runs a two-tier web application in a VPC. The web tier is in public subnets behind an internet-facing Application Load Balancer, and the database tier is in private subnets running Amazon RDS. A security review found that the RDS security group allows traffic from 0.0.0.0/0 on port 3306. What is the MOST secure way to restrict database access to only the web tier?
Medium622An internal API is deployed in two AWS Regions behind separate Application Load Balancers. The company wants clients to use the primary Region when it is healthy and automatically switch to the secondary Region if the primary health check fails. Which two Route 53 record configurations are required? Select two.
Medium623A company runs Amazon RDS for MySQL in a Multi-AZ configuration. If the primary database instance fails, what is the expected behavior?
Easy624A static web application uses CloudFront with an S3 origin for assets (JavaScript, CSS, images). After deploying a new frontend build, the CloudFront cache hit ratio dropped significantly because the S3 origin receives many repeated requests for the same assets. The team notices that requests now include the Authorization header in asset requests. Which change is most likely to restore cache efficiency and reduce origin request costs?
Medium625A dev sandbox has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The design must avoid adding custom operational scripts.
Medium626A SaaS platform plans to run in two AWS Regions for lower latency. The team wants to enable active-active writes (both regions accept updates) to avoid failover downtime. However, the business requires strong consistency for order status transitions (for example, only one transition from “Paid” to “Shipped” must be allowed). Which statement is the best architectural choice to meet the consistency requirement?
Medium627A consumer application reads from an Amazon SQS queue. Some messages have an invalid format and always fail processing. They are retried repeatedly and consume consumer capacity. What is the best way to prevent these "poison pill" messages from blocking normal processing?
Easy628A Lambda function in Account A must upload reports to an S3 bucket in Account B. Security does not want long-lived access keys anywhere, and the access should be easy to revoke from Account B. Which approach is best?
Medium629A healthcare company stores patient records in an Amazon DynamoDB table. The table must be recoverable to any point within the last 35 days, and the data must remain available if an entire AWS Region becomes unavailable. Which two actions should a solutions architect take to meet these requirements? (Choose two.)
Medium630A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use?
Hard631A company serves versioned images from S3 through CloudFront. After a release, CloudFront origin fetches increased sharply and the monthly CloudFront bill went up. They reviewed CloudFront logs and found that many requests include a query string parameter `reqId` that is unique per request (for example, `...?v=2026-04-01&reqId=...`). The team currently forwards all query strings to the cache key. What change is most likely to reduce origin fetches and cost while keeping the versioned images correct?
Medium632A mobile game backend uses Amazon Aurora. The workload has many short-lived database connections from Lambda functions, causing connection storms. What should be added?
Medium633A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The design must avoid adding custom operational scripts.
Hard634A media processing workflow uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured? The design must avoid adding custom operational scripts.
Medium635A risk simulation workload uses CloudWatch Logs heavily. Retaining all debug logs forever is increasing costs. What should be configured? The design must avoid adding custom operational scripts.
Medium636A media company serves a global audience from an Amazon S3 bucket in the us-east-1 Region. Users in Asia and Europe report high latency when downloading large video files directly from the bucket. The company wants to reduce download latency for these users without changing the application's bucket names or rewriting the application to use a different endpoint. Which solution should a solutions architect recommend?
Hard637A company is building a serverless application that processes messages from an Amazon SQS queue using AWS Lambda. The application must not lose messages and must handle occasional downstream failures gracefully. The Lambda function sometimes fails due to a transient error in a downstream service. The company wants to ensure that failed messages are retried and eventually processed, but also wants to avoid infinite retries that could block the queue. What should the company do?
Hard638A healthcare analytics team runs a containerized reporting service on Amazon ECS with the Fargate launch type in a single Availability Zone. The service must remain available if one Availability Zone fails, and it must scale automatically based on CPU utilization. The tasks are stateless and write output to Amazon S3. Which configuration should a solutions architect implement?
Medium639A company is deploying a high-performance computing (HPC) cluster with 16 EC2 instances. The workload requires the lowest possible network latency and highest throughput between all nodes for tightly coupled parallel MPI computations. Which EC2 placement group type should a solutions architect recommend?
Medium640Based on the exhibit, the web tier becomes unavailable if us-west-2a has an outage. What is the best change to improve resilience with the least redesign?
Easy641You serve private reports stored in an S3 bucket through CloudFront. After a recent change, users report that they can access the S3 object URLs directly (bypassing CloudFront), which violates your design. You want to ensure S3 objects are readable only through CloudFront using Origin Access Control (OAC), even if someone guesses the S3 URL. Which update best enforces this at the S3 bucket level?
Medium642A log archive has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances?
Hard643A deployment engineer created an IAM role for an automation workflow (AppDeployRole). The role has an attached identity policy that allows iam:CreateRole for specific resource ARNs. However, the role is also created with a permission boundary named DeployBoundary. The DeployBoundary policy currently does not include the iam:CreateRole action. During execution, the automation fails with AccessDenied for iam:CreateRole, even though the attached identity policy allows it. What is the best fix?
Medium644A healthcare company stores patient records in an Amazon S3 bucket. Compliance requires that every object be encrypted at rest with a key that the company fully controls, including the ability to rotate and immediately revoke access. The security team also needs a record of every time the key is used to decrypt an object. Which encryption configuration should the company implement?
Medium645A company hosts an application on EC2 instances in private subnets. The instances must (1) read objects from Amazon S3 and (2) retrieve secrets from AWS Secrets Manager. The team currently sends all outbound traffic through a NAT gateway to reach both services. They want to reduce monthly cost while keeping traffic private (no internet egress) and without changing application logic. Which change is the most cost-effective?
Medium646A company uses AWS Organizations with multiple accounts. A security engineer must ensure that no IAM user in any member account can create an access key for the root user or perform any action as the root user, even if an administrator in that account tries to allow it. What should the security engineer do?
Hard647You must ensure that all requests to an S3 bucket use TLS (HTTPS). Which S3 bucket policy approach best enforces this requirement for S3 access?
Easy648A company keeps daily database backups in an S3 bucket. They may restore from backups during the first 30 days if there is an issue. After 30 days, backups are rarely restored, but must be retained for 2 years. Which lifecycle strategy most cost-effectively meets these requirements?
Easy649A media company uses an Amazon CloudFront distribution to serve content from a private S3 bucket. The security team wants to ensure that users cannot bypass CloudFront and access the S3 bucket directly, and that only the distribution can read objects. Which configuration should be implemented?
Hard650Based on the exhibit, what should the architect recommend to reduce inter-node latency for this workload?
Easy651A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The design must avoid adding custom operational scripts.
Hard652A research team runs a latency-sensitive distributed training job on Amazon EC2. They deploy 80 identical nodes that exchange small messages frequently and need low network jitter. The job must run entirely within one Availability Zone. Which placement group strategy should a solutions architect use to maximize intra-cluster network performance?
Medium653A Lambda function for a mobile banking backend needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?
Medium654A game streaming service must use UDP for real-time gameplay traffic. For external firewall allowlisting, the service requires stable, static IP addresses. The TLS handshake must be handled end-to-end by the application servers (the load balancer must not terminate TLS). Which AWS load balancing option best fits these requirements?
Medium655A company uses IAM permission boundaries to prevent developers from escalating privileges. The security team created a permission boundary that allows only read-only actions on most AWS services, but teams can still manage their own resources. A developer can create an IAM role with broad permissions, and the boundary does not appear to be restricting it. Which corrective action best aligns with how permission boundaries work?
Medium656Based on the exhibit, the security team needs to detect and alert on both successful and failed attempts to change S3 bucket policies and KMS key policies across the organization. Which solution best meets that requirement?
Hard657You have an S3 bucket that stores customer-specific private files. You want to serve these files through CloudFront, where clients must use signed cookies (or signed URLs) to access the content. In addition, you need to block common web exploits and rate-limit suspicious traffic at the edge. Which design best meets these requirements?
Medium658A media company stores finalized video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that the objects be recoverable if they are accidentally deleted or overwritten for at least 90 days, and that no user, including administrators, be able to permanently erase them during that period. Which S3 feature should the solutions architect enable?
Easy659Based on the exhibit, the database is manually promoted during an Availability Zone failure and the application outage lasts longer than the target. What change best improves resilience with the least operational intervention?
Hard660Based on the exhibit, which design change is the best way to reduce the observed read latency for this DynamoDB-backed service?
Hard661An application runs on an EC2 Auto Scaling group. Over the last month, CPU utilization averaged 8% with no sustained memory pressure, and response times are stable. The team wants to lower monthly cost without changing the application. What is the most appropriate next step for cost optimization?
Easy662A video platform uses Amazon Aurora. The workload has many short-lived database connections from Lambda functions, causing connection storms. What should be added?
Medium663A company runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in a relational database, which is becoming a bottleneck during peak hours. The team wants to improve performance and reduce database load while keeping the application stateless. Which solution should a solutions architect recommend?
Easy664A production log archive runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy? The design must avoid adding custom operational scripts.
Medium665An application writes to an Amazon Aurora DB cluster. After a planned Aurora failover, the application experiences several minutes of connection errors. The logs show the application continues connecting to the specific DB instance endpoint that was the primary before the failover. What change most directly improves resilience during Aurora failovers?
Medium666Based on the exhibit, a public API is behind CloudFront and is experiencing bursts of requests from the same client IP, causing upstream saturation. The team wants AWS to automatically block that IP when the request rate becomes excessive while keeping enforcement as close to the client as possible. Which control should they add?
Hard667A retail company runs a stateless web tier on Amazon EC2 instances behind an Application Load Balancer. Traffic is steady during the day but drops to near zero between 01:00 and 06:00, and the team wants to reduce cost without manual intervention. The instances take about four minutes to boot and warm up. Which configuration meets these requirements?
Medium668A media processing workflow generates analytics files that are accessed unpredictably. Some files become hot again months later. The team wants automatic storage cost optimisation without retrieval delays. What should be used? The architecture review board prefers a managed AWS-native control.
Hard669A company stores 500 TB of archival data in Amazon S3. The data is accessed only for compliance audits, which occur once every two years. Retrieval times of up to 12 hours are acceptable. The company wants the lowest storage cost. Which S3 storage class should be used?
Easy670A media company runs a 24/7 recommendation engine on EC2 in one AWS Region. The workload is interruption-intolerant, and the team expects steady usage but may change instance families and sizes during planned optimizations. Compared to the current On-Demand setup, they want the lowest cost while avoiding the rigidity of locking to a specific instance type. What should the solutions architect recommend?
Medium671A website serves versioned JavaScript and CSS files through CloudFront, but origin fetches are still high and the CloudFront bill increased. Developers confirm that URLs include a version in the filename (for example, app.1.4.2.js). What CloudFront behavior/configuration is most likely to reduce origin fetches and associated costs?
Easy672A company runs an Amazon RDS for PostgreSQL database. The application performs frequent OLTP writes, but it also has a separate dashboard that runs heavy SELECT queries and is slowing down overall database performance. The writes must remain on the primary. What is the best approach to improve performance for the dashboard?
Easy673Based on the exhibit, an application runs in private subnets without a NAT gateway and must retrieve a secret from AWS Secrets Manager. Security requires the traffic to stay on the AWS network and not traverse the public internet. What is the best solution?
Hard674A company uses Amazon RDS with automated backups enabled (retention period: 7 days). At 10:30 UTC, a bad release corrupts specific rows in a production table. The team detects the issue at 11:10 UTC. They need to revert the database state to what it was from 10:00–10:30 UTC, recover quickly, and minimize risk to the currently running workload. What is the best option?
Medium675A service processes customer payments from a message queue. Because the queue provides at-least-once delivery, the same payment message can be delivered more than once if the consumer times out before committing its state. Currently, the service sometimes charges the customer twice. Which design change most directly prevents duplicate charges while still allowing safe retries?
Medium676A company stores private customer documents in an S3 bucket. They want only CloudFront to be able to read objects from the bucket (no direct S3 URL access), even if the bucket name and object key are known. Which configuration best meets this requirement?
Medium677An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a financial reporting platform. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy?
Hard678Based on the exhibit, a media rendering job runs on a single EC2 instance and writes a large working set of metadata to block storage. The workload performs sustained random reads and writes and must keep latency consistently low for the entire run. The instance may be stopped and started between jobs, and the data must persist. Which storage choice best meets the requirements?
Hard679A media company stores original uploads in an S3 bucket. They must recover from accidental overwrites/deletes and also recover quickly from a full Region outage. The required RPO is about 1 hour. Which configuration best meets these requirements?
Medium680A media platform runs a CPU-heavy thumbnail generation workload on an EC2 Auto Scaling group using t3.large instances. During peak traffic, p95 processing time increases significantly even though average CPU remains around 40–50%. CloudWatch also shows CPU credit depletion behavior. Which change will most directly improve performance predictability for this workload?
Medium681A DevOps team is designing a high-performance CI/CD pipeline to build and test code changes. The pipeline needs to scale to handle hundreds of concurrent builds, with fast build times and minimal idle compute cost. The builds are containerized and require consistent, reproducible environments. Which three options should be used to meet these requirements? (Choose three.)
Medium682A company runs EC2 workloads including web servers (m5.large), batch jobs (c5.xlarge), and a data processing service that will migrate from r5 to r6i instances within 6 months. The company wants to commit to 1 year to reduce costs but needs flexibility for the planned instance family migration. Which purchasing option provides the GREATEST savings while accommodating the change?
Hard683An application in Account B reads objects from an Amazon S3 bucket in Account A. The bucket uses SSE-KMS with a customer managed key in Account A. The role in Account B already has s3:GetObject, but downloads fail with AccessDenied on decrypt. Which two changes are required for the role to read the object successfully? Select two.
Medium684Your company has an internal service hosted behind a Network Load Balancer (NLB) in VPC 10.0.0.0/16. A consumer team in a different VPC (10.1.0.0/16) must call the service without using the public internet. You want private connectivity using AWS PrivateLink. Which configuration best enables least-privilege access while keeping the traffic private?
Medium685A warehouse integration service must process every event at least once, but duplicate processing is acceptable if the consumer handles idempotency. Which eventing approach is most suitable? The design must avoid adding custom operational scripts.
Hard686A content publishing system uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The team wants the control to be enforceable during normal operations.
Medium687A SaaS application is deployed in us-east-1 and us-west-2 behind separate ALBs. The business wants DNS to send new clients to the primary Region when it is healthy and automatically fail over to the secondary Region when the primary endpoint is unhealthy. Which two Route 53 settings are required? Select two.
Medium688A logistics company runs an order-tracking API on a fleet of EC2 instances in a single Availability Zone behind a Network Load Balancer. The architecture team must make the API resilient to the loss of that Availability Zone without changing the API endpoint that clients already use. The instances are stateless and store session data in a shared Amazon ElastiCache cluster. Which change should the solutions architect make to meet these requirements?
Medium689A public web application is fronted by Amazon CloudFront and an ALB. The team is seeing SQL injection attempts and bursts of malicious HTTP requests that increase origin load. They want to block common web attacks before they reach the ALB. What should they do?
Medium690A dev sandbox currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first?
Hard691A CI pipeline in account A uploads build artifacts to an S3 bucket (arn:aws:s3:::build-artifacts-prod) under the prefix teamA/. The pipeline must not be able to list other prefixes, and it must only upload objects under teamA/. Which IAM policy design best enforces least privilege for this requirement?
Medium692An application uses an Amazon Aurora cluster. The workload becomes read-heavy, but the team cannot change the database schema. They need higher read throughput while keeping writes on the primary. What should they do?
Easy693A containerized web service on Amazon ECS reads a database password at startup. Today, the password is stored in a plain environment variable and updated manually. Auditors require that credentials: (1) are encrypted at rest using AWS-managed controls, (2) can be rotated without redeploying the task definition, and (3) are accessible only to the running task via least-privilege permissions. Which solution best meets these requirements?
Medium694A service runs in private subnets. It must call AWS APIs (for example, S3 and Secrets Manager). The team currently sends all outbound traffic through a NAT Gateway, and NAT charges have become a major cost driver. The workload must not traverse the public internet. What change most directly reduces NAT Gateway cost while maintaining private connectivity to those AWS services?
Medium695A payments API uses Amazon SQS. Poison messages are repeatedly failing and blocking useful retries. What should the architect configure? The architecture review board prefers a managed AWS-native control.
Hard696Your organization hosts an internet-facing application behind an Amazon CloudFront distribution. You want to mitigate common web exploits (for example, SQL injection and XSS) at the edge. Which action is the most appropriate way to do this using AWS services?
Easy697A log archive serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The design must avoid adding custom operational scripts.
Medium698A startup has three sandbox accounts and one production account. The CTO wants lower cost and operational overhead while keeping central purchasing and spend visibility. Which two actions are best? Select two.
Hard699A internal reporting portal serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The architecture review board prefers a managed AWS-native control.
Medium700Based on the exhibit, a distributed analytics workload runs on 12 EC2 instances in one Availability Zone. The nodes exchange thousands of small messages per second and require the lowest possible intra-cluster latency and jitter. Which EC2 placement strategy is the best fit?
Hard701A document portal needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable? The design must avoid adding custom operational scripts.
Hard702A startup runs an HTTP/2 API that also supports WebSocket connections. They need path-based routing to separate microservices (for example, /api/* to Service A and /metrics/* to Service B) and want TLS terminated at the load balancer. Which AWS option best meets these requirements while maintaining high request performance?
Medium703A company wants to give a third-party auditor read-only access to a specific Amazon S3 bucket for a limited period. The auditor has an AWS account and will use their own IAM credentials. The company must not share long-term credentials and wants to revoke access automatically when the audit ends. What is the most secure way to grant this access?
Easy704Your AWS Organizations environment has an SCP that explicitly denies kms:Decrypt for principals in the Production OU. A member account IAM policy for a user grants kms:Decrypt on the required KMS key. If that user attempts kms:Decrypt, what happens?
Easy705A company runs a stateless web application on a fleet of six On-Demand EC2 instances behind an Application Load Balancer. The instances are spread across three Availability Zones in a single AWS Region and run 24/7. The workload is steady and predictable, and the company wants to reduce compute costs without changing the application architecture or reducing availability. The company is willing to commit to a one-year term. Which two actions will reduce the EC2 compute cost for this workload? (Choose two.)
Medium706A patient portal receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers? The design must avoid adding custom operational scripts.
Medium707An Auto Scaling group for a background worker runs EC2 instances continuously. Over the last 30 days, CloudWatch shows sustained CPU utilization around 6% with no memory pressure, and queue processing latency meets all SLAs. The team wants to lower monthly cost with minimal risk. What is the best next action?
Medium708A media company stores original video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that a readable copy of every object exist in the eu-west-1 Region within 15 minutes of upload, and that the objects in eu-west-1 be usable directly by an application there. No transformations are required. Which S3 feature should the solutions architect enable?
Medium709A company stores private report PDFs in an S3 bucket. They want users to access PDFs only through CloudFront. Even if someone knows the S3 object URL, direct S3 access must fail. What is the best S3 bucket policy approach?
Easy710A regional web application for a content publishing system must fail over automatically to a secondary Region if the primary endpoint becomes unhealthy. Which two services or features are required? The design must avoid adding custom operational scripts.
Hard711A logistics company runs an order-tracking service that exposes a REST API. The service must remain available during a single Availability Zone failure and must keep read latency low for a globally distributed user base. The data store must support automatic multi-AZ replication without the team managing database servers. Which solution meets these requirements?
Medium712A media archive requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable? The design must avoid adding custom operational scripts.
Medium713A team serves image files from S3 through CloudFront. During a performance review, they notice that CloudFront cache hit ratio is low and the S3 origin receives many repeated requests for the same images. Request URLs include a volatile query parameter called 'sessionId' that changes for each user, but the image content is identical regardless of 'sessionId'. What configuration change will most effectively increase cache hit ratio?
Medium714A financial analytics team runs a batch job every night that scans a 4 TB Amazon Redshift provisioned cluster table to compute aggregates for a reporting dashboard. The dashboard queries are read-only, run for several hours each morning, and compete with ETL writes on the same cluster, causing slow dashboard response times. The team wants to isolate the dashboard workload and improve query performance without changing the ETL job. Which solution meets these requirements with the LEAST operational effort?
Hard715Your web application is deployed in two AWS Regions (Region A and Region B). You want Route 53 to automatically fail over DNS traffic from Region A to Region B when Region A is unhealthy. The failover decision must be based on health checks that verify whether the application in Region A is reachable. Which Route 53 routing configuration best meets these requirements?
Medium716A test environment has EC2 instances that are oversized based on CPU, memory, and network utilisation. Which AWS service should identify rightsizing recommendations? The architecture review board prefers a managed AWS-native control.
Medium717An application in account A needs to use an encrypted EBS volume whose snapshots were copied from account B. The EBS volume is encrypted with a customer-managed KMS key in account B. After attaching the volume, the instance fails to mount it and logs show KMS access errors (kms:Decrypt) for the instance role. The instance role in account A already has an IAM policy allowing kms:Decrypt on that key ARN, but the mount still fails. What must be updated in account B to allow the mount to succeed?
Medium718An internal team runs a report-generation job once per day. It typically finishes in a few minutes, and even on its slowest days it still completes in under 15 minutes. The team wants to reduce operational overhead and pay primarily for actual runtime instead of keeping servers running 24/7. Which AWS approach best matches these goals?
Easy719A claims portal must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?
Hard720A media company stores original video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that a readable copy of every object exists in eu-west-1 within 15 minutes of upload, and that objects deleted in the source bucket do not automatically disappear from the destination. Which S3 feature should the solutions architect enable?
Medium721A media processing company runs a stateless thumbnail-generation fleet on Amazon EC2 instances behind an Application Load Balancer. The instances store no local state, and the team wants the fleet to survive the loss of an entire Availability Zone without manual intervention. The fleet must also scale out automatically based on CPU. Which combination of AWS services should the solutions architect use to meet these requirements with the LEAST operational overhead?
Medium722Based on the exhibit, the company has one shared S3 bucket for many internal teams. Security wants each team to access only its own prefix, ACLs must remain disabled, and the current bucket policy has become too large and error-prone. What is the best redesign?
Hard723A trading dashboard uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The design must avoid adding custom operational scripts.
Medium724A internal reporting portal serves infrequently accessed user documents that must be available immediately when requested. Which S3 storage class is likely the best cost fit? The design must avoid adding custom operational scripts.
Medium725An e-commerce application uses Aurora MySQL. Writes are modest, but the product-detail page generates many read-only queries and the writer instance CPU is high. The application can tolerate a small amount of replication lag on those reads. What should the team do?
Medium726A company hosts a B2B file exchange site on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use? The design must avoid adding custom operational scripts.
Medium727A company hosts a B2B file exchange site on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
Medium728A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be highly available and able to withstand the failure of an entire AWS Region. The company wants to minimize operational overhead and ensure that failover is automatic. Which solution should a solutions architect recommend?
Medium729A order processing API stores audit logs in S3. The compliance team requires that logs cannot be overwritten or deleted for seven years. What should be configured? The design must avoid adding custom operational scripts.
Medium730A dev sandbox currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first? The design must avoid adding custom operational scripts.
Hard731A startup runs two EC2-based workloads in the same AWS Region. Its customer-facing API is always on, and its nightly video transcoding fleet can restart jobs from checkpoints if an instance is interrupted. The finance team wants the lowest monthly compute cost without changing the application design. Which two actions should the team take? Select two.
Medium732A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The team wants the control to be enforceable during normal operations.
Medium733A marketing site runs on x86 EC2 instances and uses open-source software with no architecture-specific licensing restriction. What should be evaluated to reduce compute cost? The architecture review board prefers a managed AWS-native control.
Medium734A financial services firm runs a stateful trading application on EC2 instances in an Auto Scaling group. Each instance maintains an in-memory cache that takes several minutes to rebuild after a restart, and the team wants the application to survive the loss of an Availability Zone with minimal disruption. The application cannot be made stateless in the near term. Which approach should a solutions architect recommend?
Hard735A finance application stores invoices in Amazon S3. Security requires that the data be encrypted with a key they control, and they want the ability to disable access quickly if the application is suspected of compromise. Developers do not want to manage encryption in application code. Which solution best meets these requirements?
Medium736An EC2 workload runs in one region on a single instance type. For the last month, CloudWatch metrics show average CPU utilization of 12% and no sustained memory pressure. The team wants to reduce cost while maintaining the current performance level. What is the best first step?
Easy737A security operations team wants continuous compliance checks for AWS resources. They need to know when an EBS volume becomes unencrypted or when a security group starts allowing SSH from 0.0.0.0/0. Which AWS service should they use?
Medium738A startup runs a static website hosted on Amazon S3. The website is accessed globally, and users in Europe report slow load times. The company wants to improve performance for these users without changing the website's code. Which AWS service should the company use?
Easy739A healthcare company runs a patient portal on Amazon EC2 instances behind an Application Load Balancer. The application stores session state in memory on each instance, and users are being logged out when the load balancer routes them to a different instance. The company wants to keep the application stateless and avoid modifying application code. Which solution best meets these requirements?
Hard740A workload runs in private subnets and must reach Amazon S3 and AWS Secrets Manager without using the internet or a NAT gateway. The team wants to keep the traffic on AWS private networking and avoid public IPs. Which two changes should the architect make? Select two.
Medium741A company runs an Amazon DynamoDB table that stores session data for a consumer application. The table is 800 GB and receives highly variable read and write traffic with sharp, unpredictable peaks during marketing campaigns. The team currently provisions 20,000 read capacity units and 10,000 write capacity units and frequently sees throttling during peaks and wasted capacity between them. A solutions architect must reduce cost and eliminate throttling with the least operational effort. Which solution meets these requirements?
Hard742An application uses an Amazon Aurora DB cluster. The cluster performs an automatic failover from the writer instance to a standby instance. After failover completes, reads succeed, but all new writes fail with errors indicating the application is connecting to the old writer endpoint. Which change best fixes the resiliency issue after failover?
Medium743A media platform stores originals in an S3 bucket. The application must: (1) prevent any public access to the bucket, (2) allow authenticated users to upload and download objects using presigned URLs, and (3) enforce that all requests use HTTPS and only touch objects under the user-specific prefix (for example, s3://media-originals/user-123/*). The bucket currently allows uploads but sometimes returns 403 AccessDenied for presigned URLs. Which change is the best fix while meeting the security requirements?
Medium744A media company has an Amazon RDS for MySQL database in a private subnet. A web application on Amazon EC2 instances must connect to the database, and the security team requires that the database credentials be rotated every 30 days without application downtime. Which solution should a solutions architect recommend?
Medium745A company needs to store application logs in a durable and highly available manner. The logs are written continuously by multiple EC2 instances and are accessed infrequently for compliance audits. The company wants a solution that provides 99.999999999% (11 9's) durability and automatically replicates data across multiple Availability Zones. Which AWS service should the company use?
Easy746A healthcare document service uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend?
Hard747Based on the exhibit, which AWS service should the security team enable to continuously discover sensitive data stored inside Amazon S3 objects?
Medium748A startup expects steady compute usage around the clock for the next year. They want to reduce costs compared to On-Demand pricing, without tightly planning specific instance types. Which option best matches their goal?
Easy749Based on the exhibit, the application should continue serving requests if one Availability Zone fails. Which change best improves resilience with the least operational complexity?
Medium750A company hosts static images, CSS, and JavaScript files in an Amazon S3 bucket. Users around the world report slow page loads, and the origin receives many repeated requests for the same files. What should the team use to improve performance?
Easy751A batch analytics job has unpredictable DynamoDB traffic with long idle periods and occasional spikes. Which capacity mode should minimize operational overhead and avoid paying for idle provisioned capacity? The architecture review board prefers a managed AWS-native control.
Medium752A web application behind an Application Load Balancer (ALB) currently allows client connections over HTTP (port 80). The security policy requires all client traffic to use HTTPS. What is the best ALB change to enforce this requirement?
Easy753A partner company needs read-only access to reports in an S3 bucket for a image sharing application. The partner has its own AWS account. What is the most secure scalable access pattern?
Medium754A test environment stores logs in S3. Logs are queried for 30 days, rarely accessed for one year, and then retained for compliance. What should reduce storage cost? The design must avoid adding custom operational scripts.
Medium755A log archive has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances? The design must avoid adding custom operational scripts.
Hard756A startup runs a stateless web tier on Amazon EC2 instances in an Auto Scaling group that spans three Availability Zones. The team wants the application to keep serving requests even if one instance becomes unresponsive, without operator involvement. What should the solutions architect configure?
Easy757A web API runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). During traffic spikes, users experience request timeouts even though CPU stays below 40%. After investigation, you find the ASG often has too few healthy targets to handle the current request rate. Which change will best improve responsiveness during spikes?
Medium758A startup runs a customer-facing web application on a single Amazon EC2 instance in one Availability Zone, with the database on the same instance. The founders want the application to survive the failure of that Availability Zone with minimal changes and no server management for the database tier. Which action should the solutions architect take first?
Easy759A startup runs a web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to encrypt data in transit between clients and the load balancer using a certificate managed by AWS, with minimal operational overhead. Which solution meets these requirements?
Easy760A media company uploads raw video thumbnails to an S3 bucket every hour. The application needs these thumbnails for active browsing for the first 7 days. After day 7, access becomes rare. Requirements: - Objects must remain available in S3 for at least 180 days total. - After day 7, the team can tolerate retrieval latency in the range of minutes to hours. - They want to minimize storage cost while keeping the ability to read objects (no application changes required). Which storage strategy is the most cost-optimized fit?
Medium761Based on the exhibit, the payment worker sometimes processes the same SQS Standard message more than once after a timeout. What change best prevents duplicate charges while keeping the queue architecture?
Medium762Multiple teams share one AWS Organization. Finance wants chargeback by project, alerts before overspend, and monthly views by account without manually opening each account. Which three actions best fit? Select three.
Hard763A healthcare company uses AWS Lambda functions to process sensitive patient data. The functions need to access an Amazon RDS for MySQL database. The security team requires that database credentials are never stored in the Lambda function code or environment variables, and that credentials are automatically rotated every 90 days. The company also wants to minimize the operational overhead of managing the rotation. Which solution should a solutions architect recommend?
Hard764Developers for a customer analytics portal need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?
Medium765A production Amazon RDS database has automated backups enabled. At 10:00 UTC, an application deploy accidentally overwrote a subset of rows due to a faulty migration. The issue is detected at 10:45 UTC. The team confirms that the required retention window is still available. Which approach offers the most resilient and least disruptive way to recover the affected data close to the time of the event?
Medium766Based on the exhibit, which storage choice best matches the workload requirements?
Hard767A company runs an Amazon Aurora DB cluster with a Multi-AZ deployment. The application is configured with a hard-coded endpoint that points to the current writer *DB instance* (an instance-specific endpoint), rather than the Aurora cluster writer endpoint. During an unexpected AZ failure, Aurora promotes the standby to become the new writer. However, the application continues to fail to connect until an operator updates the hard-coded endpoint. What change most directly improves resiliency so the application automatically reconnects after failover?
Medium768A latency-sensitive video platform uploads large files to S3 from users around the world. Which two features can improve upload performance? The design must avoid adding custom operational scripts.
Hard769A retailer runs a reporting-heavy relational app on Amazon RDS MySQL. Peak dashboard traffic lasts only three hours each day, but the database is sized for the peak all day. The business wants lower cost without rewriting the application. Which three actions are best? Select three.
Hard770A genomics company stores about 400 TB of compressed research data in Amazon S3 and runs a nightly analysis job on a fleet of EC2 instances in the same Region. The job reads the entire dataset every night, and the team wants to reduce the time the fleet spends waiting on storage without changing the data format or the S3 bucket. Which change best improves read throughput for the fleet?
Hard771Based on the exhibit, duplicate payment charges occasionally occur when the worker times out after the charge is submitted but before the message is deleted. What change best prevents duplicate charges while keeping retry behavior?
Hard772A team wants a web application to keep serving traffic if one Availability Zone fails. Match each architecture element to the resilience behavior it provides.
Medium773A data engineering team ingests a continuous stream of clickstream events into Amazon Kinesis Data Streams. Downstream consumers process the events, but the team observes that a single consumer is handling a disproportionate share of the records, causing hot shards and throttling. The team wants the stream to distribute records as evenly as possible across shards. Which change should the team make?
Hard774A fintech company runs a containerized payment API on Amazon ECS with AWS Fargate. The security team requires that the API access a stored database credential without hardcoding it in the task definition or environment variables. The credential must be encrypted at rest and automatically rotated every 90 days. The API also needs to retrieve the credential at container startup with minimal latency. Which solution meets these requirements?
Medium775A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The team wants the control to be enforceable during normal operations.
Medium776A team stores application logs in Amazon CloudWatch Logs. They enabled long retention and detailed dashboards, resulting in higher-than-expected monthly spend. Compliance requires retaining logs for 90 days, but operations only needs aggregated views. Which change most directly reduces CloudWatch Logs cost while meeting the requirement?
Easy777A financial services company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to inspect incoming requests for common web exploits and block malicious traffic before it reaches the application. They also need to monitor for SQL injection attempts and receive near-real-time metrics. Which AWS service should be used to meet these requirements?
Hard778You have an EC2 instance in private subnets with no NAT Gateway. The instance must access an Amazon S3 bucket (for example, to read configuration files) without sending traffic to the public internet. What VPC endpoint type should you use for S3?
Easy779A backend API uses an AWS Lambda function behind API Gateway. The first requests after every weekly deployment experience cold starts, causing p95 latency spikes for a few minutes. Which configuration most directly prevents those cold starts for the published version?
Easy780A site serves static assets (JS/CSS) through CloudFront from an S3 origin. After a recent frontend change, CloudFront shows a cache hit ratio below 20%. In CloudFront access logs, requests to the same asset URL path differ by a query parameter named rnd (a random value appended by the app on every request). The origin content is identical regardless of rnd. What is the best CloudFront configuration change to restore effective caching?
Medium781A logistics company runs an order-tracking service on Amazon EC2 instances that write state to an Amazon DynamoDB table. A recent incident showed that a single Availability Zone failure caused the service to lose capacity, and the team also discovered that a developer accidentally deleted a production table. The architect must improve both Availability Zone resilience and protection against accidental table deletion. (Choose two.)
Medium782A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The team wants the control to be enforceable during normal operations.
Hard783A company runs a media transcoding service on Amazon EC2 instances behind an Application Load Balancer. The workload is steady at 60% CPU utilization from 08:00 to 18:00 local time on weekdays and drops to under 5% overnight and on weekends. A solutions architect must reduce compute costs without changing the application code or degrading transcoding throughput during peak hours. (Choose two.)
Medium784An internal web application must require encrypted client connections. The company currently has an ALB listener on port 80 (HTTP), and users can access the application over plain HTTP. What is the best change to ensure all client traffic uses HTTPS?
Easy785A microservice runs in private subnets with no NAT gateway. It must retrieve a secret from AWS Secrets Manager. Security requires that traffic to Secrets Manager stays within AWS’s private network (no public internet egress). The IAM role already grants secretsmanager:GetSecretValue for the needed secret. What is the best network setup to meet the requirement?
Medium786A new feature stores user events in DynamoDB. Each event must be fetched by user_id and sorted by event_time. The team expects many different users and wants to avoid a single hot partition. Which partition key design is best?
Easy787A log archive has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances? The architecture review board prefers a managed AWS-native control.
Hard788A company is designing a high-performance web application that serves static and dynamic content to a global user base. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The static assets are stored in an S3 bucket. Which three architecture decisions will improve performance and reduce latency for users? (Choose three.)
Medium789A production log archive runs continuously on EC2 with predictable usage for the next three years. The team wants a discount while retaining some instance-family flexibility. What should they buy?
Medium790Based on the exhibit, which AWS feature should the team use to minimize network latency between EC2 instances that exchange messages very frequently?
Easy791A team uses an S3 bucket to store important customer-generated exports. They need protection against accidental overwrites and also want copies of the data in another AWS Region for disaster recovery. Which S3 configuration best satisfies both requirements?
Easy792A media company runs a video-transcoding fleet on Amazon EC2 instances that read source files from an Amazon S3 bucket and write output to a second bucket. The fleet is spread across three Availability Zones in one Region, and instances are launched by an Auto Scaling group. The company needs the architecture to survive the loss of an entire Availability Zone without losing in-flight transcoding work or requiring manual intervention. Which combination of design elements should a solutions architect implement to meet these requirements?
Medium793A solutions architect is designing a high-performance architecture for a read-heavy web application backed by Amazon RDS for MySQL. The database is currently a single db.r6g.4xlarge instance that is CPU-bound during peak hours, and the application performs many repeated identical read queries. The architect must improve read scalability and reduce load on the primary instance. (Choose two.)
Medium794A company runs an internal API on Amazon EC2 instances in a private subnet. Clients in an on-premises data center must reach the API over a private connection, and the security team wants to inspect and filter the traffic using AWS managed security appliances before it reaches the application. The company has already established an AWS Site-to-Site VPN to a transit gateway. Which two actions should the security engineer take to route and inspect the traffic? (Choose two.)
Medium795A media archive needs low-latency full-text search across product descriptions and filtered attributes. Which managed service is most suitable?
Hard796A media company hosts a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to rate-limit requests from specific IP addresses that exhibit abusive behavior. Which combination of AWS services should a solutions architect recommend?
Medium797Based on the exhibit, what is the best way to let private EC2 instances reach Amazon S3 and AWS Systems Manager without sending traffic through the internet or a NAT gateway?
Medium798A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application stores user-uploaded images in an Amazon S3 bucket. Users report slow image upload times, especially from mobile devices in remote locations. The solutions architect needs to improve upload performance for these users. Which action should the architect take?
Easy799A media company runs a fleet of EC2 instances using Auto Scaling across multiple instance families (for example, m-series and c-series) in a single region. The business wants to commit to steady usage for one year to reduce cost, but the application team must retain flexibility to switch instance families and scale up/down as demand changes. They need the cost-reduction approach that best matches this flexibility. Which option is the best fit?
Medium800Based on the exhibit, a serverless checkout API is implemented in AWS Lambda and deployed in one Region. The function has a cold-start time of 700-900 ms on the first request after idle periods. Marketing launches a predictable traffic spike every weekday at 09:00 UTC, and the p95 latency target is under 150 ms during the first five minutes of the spike. What should the solutions architect do to meet the latency target while controlling cost?
Hard801A solutions architect is designing a high-performance architecture for a web application that serves static content from Amazon S3 and dynamic content from an Application Load Balancer. The application must deliver low latency to users across multiple continents and reduce origin load. The team wants to use Amazon CloudFront. Which two actions should the architect take to meet these requirements? (Choose two.)
Medium802A financial analytics team runs a read-heavy workload on Amazon Aurora MySQL. The primary instance is experiencing high CPU during end-of-day reporting, and read replicas are lagging by several seconds. The application requires strong read consistency for account balances but can tolerate eventual consistency for historical reports. Which change should a solutions architect make to improve performance while meeting consistency requirements?
Hard803A company is designing a disaster recovery plan for a critical application hosted on AWS. The application runs on EC2 instances with data stored in Amazon EBS volumes and Amazon S3. The recovery time objective (RTO) is 15 minutes, and the recovery point objective (RPO) is 1 hour. Which three strategies would help meet these objectives? (Choose three.)
Medium804A company needs to implement session management for a web application. Sessions must persist across multiple EC2 instances, survive EC2 failures, and be accessible with sub-millisecond latency. Sessions must also be sortable by last-access time to expire the oldest sessions first. Which caching solution should a solutions architect recommend?
Medium805A security team stores sensitive documents in an Amazon S3 bucket that is encrypted with SSE-KMS using a customer managed key. An auditor requires that every object upload be traceable to the IAM principal that performed it and that the key's usage be independently auditable. The team also wants to prevent any principal, including account administrators, from reading objects without a corresponding key grant. Which configuration combination meets these requirements?
Hard806A service consumes messages from an SQS queue. Recently, a new message format started failing validation in the consumer. The consumer catches the exception but cannot successfully process those messages without code changes. The team wants failed messages to be isolated for later investigation instead of being retried indefinitely. What should they configure?
Medium807A solutions architect is reviewing a workload that runs on a fleet of Amazon EC2 instances in a single AWS Region. The application serves a global user base, and the team wants to reduce both data transfer costs and latency for users in Europe and Asia. The application is stateless and stores assets in Amazon S3. The team is also evaluating how to pay for the compute layer over the next three years, as usage is expected to be steady. Which two actions will reduce cost in this scenario? (Choose two.)
Hard808A production Amazon RDS database has automated backups enabled with sufficient retention. At 10:30 UTC, a release corrupts specific rows. The issue is detected at 10:45 UTC. The team wants to restore the database state to before the corruption with minimal complexity. What should they do?
Easy809A Multi-AZ Amazon RDS database experiences incorrect writes at 10:15 UTC due to a buggy release. The team detects the problem at 10:25 UTC. They want to restore the data to a known-good point around 10:15 UTC, and validate the recovered data, without taking the current production instance offline during the recovery process. What is the most appropriate AWS action?
Medium810A financial services company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application must be accessible only from a specific corporate IP range (203.0.113.0/24). The security team wants to restrict access at the load balancer level and also ensure that the instances themselves only accept traffic from the ALB. Which combination of security group configurations should a solutions architect implement?
Easy811A financial analytics platform ingests events into an Amazon Kinesis Data Stream with four shards. During month-end peaks, producers receive ProvisionedThroughputExceededException errors and consumers fall behind. The architects want to increase capacity without changing producer code and must preserve the order of records that share the same partition key. What should they do?
Hard812Developers for a financial reporting platform need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?
Medium813A company runs a containerized web application on Amazon ECS with a steady baseline of 10 tasks that must run continuously. During business hours, traffic spikes require up to 30 additional tasks that can be terminated at any time. The company wants to minimize costs while ensuring the baseline tasks are always available. Which combination of purchasing options should be used for the ECS tasks?
Medium814A company runs a REST API on AWS Lambda behind Amazon API Gateway. The API is used by internal clients during a two-hour batch window each night and is completely idle the rest of the day. The team is concerned about the cost of API Gateway and wants to minimize it without changing the API contract for clients. Which change should a solutions architect recommend?
Medium815A production team accidentally deletes critical rows in an Amazon RDS for PostgreSQL database. The deletion occurred about 6 hours ago. The team wants to recover to a specific point in time with minimal disruption. Assuming automated backups are enabled, which approach provides the best resilience outcome?
Medium816An application uses Amazon Aurora MySQL. CloudWatch shows the writer instance near 85% CPU while the only reader instance averages 15% CPU. Trace logs show that all SELECT statements still target the writer endpoint. The workload is read-heavy, and the application already tolerates eventual consistency for reads. Which two changes will best increase total read throughput without a schema redesign? Select two.
Hard817A company stores sensitive data in an Amazon S3 bucket. The security team must ensure that all data is encrypted at rest using a customer managed AWS KMS key (CMK) and that the key's usage is auditable. They also need to be able to rotate the key annually. Which solution meets these requirements?
Medium818A mobile game backend uses Amazon Aurora. The workload has many short-lived database connections from Lambda functions, causing connection storms. What should be added? The design must avoid adding custom operational scripts.
Medium819A company wants a disaster recovery setup for a web application. They want to keep costs low but still recover within a couple of hours after a regional disruption. They are willing to run only minimal infrastructure in the secondary location and scale it up during the outage. Which DR approach best matches this requirement?
Easy820A financial services company is designing a new payment processing platform. The platform must continue to accept and process transactions even if an entire AWS Region becomes unavailable, and it must not lose any accepted transaction. The architects have decided to run active-active deployments in two Regions and use Amazon Route 53 for traffic management. Which two additional design elements are required to meet the durability and availability goals? (Choose two.)
Hard821A inventory service exposes a static website from S3 and CloudFront. Users should still receive cached pages if the S3 origin has a short outage. Which feature helps most? The design must avoid adding custom operational scripts.
Easy822A financial services company runs a critical application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application must be able to survive the failure of an entire AWS Region. The company wants a cost-effective solution that minimizes operational overhead. Which approach should the architect recommend?
Hard823A DynamoDB table for a travel booking site has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change?
Hard824A company stores nightly database backup files in an Amazon S3 bucket. Each backup is about 50 GB, and the files are written once and never modified. Regulatory policy requires that every backup be retained for exactly seven years, after which it may be deleted. Retrieval of a backup for an audit is extremely rare and the company can tolerate a retrieval time of up to 12 hours. Which S3 storage class is the MOST cost-effective choice for these backups?
Easy825A marketing team uses CloudFront with an S3 origin to serve a single-page web app. After a release, CloudFront cache hit ratio dropped sharply. The app requests the same static JS and CSS assets, but each request includes a unique tracking query parameter (for example, ?utm_source=campaign123, campaign456, etc.). You want CloudFront to cache those assets efficiently even when the tracking query parameter changes. What should you do?
Medium826A trading platform ingests market data events at very high volume and must deliver them with the lowest possible latency to multiple independent consumer applications. Each consumer must read the full stream independently, and ordering must be preserved per instrument symbol. Which solution meets these requirements?
Hard827A financial analytics company runs an Amazon RDS for MySQL database that supports a read-heavy web application. The primary DB instance is heavily loaded during business hours, and read replicas are already deployed and receiving traffic from the application. The team wants to reduce the load on the primary DB instance caused by read queries as much as possible, while keeping the application changes minimal. Which action should a solutions architect take?
Medium828A financial services company stores sensitive customer statements in an Amazon S3 bucket. The security team requires that all data be encrypted at rest using keys that the company manages and rotates on its own schedule. The company also needs an audit trail of every time a key was used to encrypt or decrypt data. Which solution meets these requirements?
Easy829Based on the exhibit, which Route 53 configuration should be used so traffic automatically returns to the secondary Region only when the primary Region becomes unhealthy?
Medium830A travel booking site uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured?
Easy831A video processing pipeline runs batch jobs that are safe to interrupt and restart. The jobs checkpoint progress to durable storage every few minutes, and the team can automatically resubmit from the last checkpoint. They want to minimize compute cost while accepting that capacity can be interrupted. Which launch configuration for the processing workers is the best cost-optimized choice?
Medium832A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first?
Hard833A web application runs on an Auto Scaling group (ASG) behind an Application Load Balancer (ALB). After a new release, instances begin failing ALB health checks with errors like 502 while the application is still starting up. CloudWatch shows that the ASG replaces the instances before they finish initializing, so traffic never reaches healthy targets. Which change most directly prevents premature replacement during startup so traffic can resume as soon as the instances are actually healthy?
Medium834A company runs a stateless web API on Amazon EC2 behind an Application Load Balancer. The team notices that during business hours, the ALB starts queueing requests and the average request latency rises. They want to scale out quickly and reliably based on demand, not CPU alone. Which Auto Scaling approach best matches this requirement?
Easy835A SaaS company runs a production API on an EC2 Auto Scaling group with steady demand 24/7. The team uses multiple instance types over time (they switch types during tuning) but the overall compute hours are stable. They want a cost reduction without committing to a specific instance type or size. Which AWS pricing option best meets the requirement?
Medium836A company hosts a financial reporting platform on EC2. Administrators must connect without opening SSH or RDP ports to the internet. What should the architect use?
Medium837A company is designing a multi-Region disaster recovery (DR) strategy for a stateless web application running on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses an Amazon RDS for MySQL database as its data store. The architecture must provide rapid failover with the lowest possible Recovery Point Objective (RPO) and Recovery Time Objective (RTO). Which of the following design choices will help achieve these objectives? (Choose four.)
Medium838A CPU-bound batch rendering service runs on EC2. The application is Linux-based, compatible with ARM64, and the team wants the best throughput per dollar without changing the workload's architecture. Which two instance-family choices should the team consider first? Select two.
Medium839A startup runs a static marketing website on Amazon S3 and wants to serve it to users worldwide with low latency. The site consists of HTML, CSS, JavaScript, and images stored in a single S3 bucket in the us-east-1 Region. The team wants to minimize cost while improving global performance. Which solution should the team implement?
Easy840A Lambda-based travel booking site has unpredictable traffic spikes and users see latency caused by cold starts. The function must respond consistently during expected campaign windows. What should be configured? The architecture review board prefers a managed AWS-native control.
Hard841Based on the exhibit, a single EC2 instance hosts a latency-sensitive cache that performs sustained random reads and writes to persistent block storage. The current EBS volume is a general-purpose SSD, but BurstBalance is repeatedly depleted and p95 I/O latency has risen above 20 ms. The workload needs more than 16,000 sustained IOPS. Which change is the best fix?
Hard842Multiple EC2 instances in different Availability Zones need concurrent read/write access to the same shared files. The files are actively modified by several application servers, and low-latency metadata operations matter more than extremely high aggregate throughput. Which two changes should the team make? Select two.
Hard843An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a financial reporting platform. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy? The design must avoid adding custom operational scripts.
Hard844A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost?
Medium845A company serves mostly static images and JavaScript files from an origin in one AWS Region. They want to reduce origin load and improve global performance. Which change most directly increases cache-hit ratio for static assets while avoiding stale content?
Easy846A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost? The design must avoid adding custom operational scripts.
Medium847A team wants to run containerized services with AWS-managed orchestration and autoscaling. They do NOT require Kubernetes compatibility. Which AWS service choice is most appropriate to meet these goals?
Easy848A startup runs a stateless image-resizing API on a fleet of EC2 instances behind an Application Load Balancer. The instances store uploaded source images on their own instance store volumes before processing. During a routine scale-in event, an instance was terminated and several in-flight uploads were lost. The architect must make the design resilient to instance loss without changing the API code. What should the architect do?
Easy849A retail API uses EC2 instances behind an ALB. CPU is consistently high during peak traffic, and request latency rises. What should be configured? The design must avoid adding custom operational scripts.
Easy850A logistics company runs workloads in a VPC with private subnets that have no internet gateway route. Instances in these subnets must retrieve secrets from AWS Secrets Manager and download patches from an Amazon S3 bucket owned by the company. The security team requires that this traffic never traverse the public internet. (Choose two.)
Hard851A inventory service uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The design must avoid adding custom operational scripts.
Medium852A web application runs in private subnets with no NAT gateway. It needs to retrieve credentials from AWS Secrets Manager at runtime. After a recent network hardening change, the application logs timeout errors when calling Secrets Manager. Which change will most directly enable private connectivity to Secrets Manager while keeping the subnets NAT-free?
Medium853A team is designing a new workload that runs on Amazon EC2 instances in a private subnet. The instances must read and write objects in an Amazon S3 bucket in the same account, and security policy forbids long-term access keys on the instances. The team wants to grant least-privilege access and ensure the instances can reach S3 without traversing the public internet. (Choose two.)
Hard854A company runs a customer portal on an Amazon Aurora PostgreSQL cluster. The application currently connects directly to the writer instance endpoint and keeps long-lived connections open. During a maintenance failover, writes fail until clients are restarted. The team wants the application to reconnect to the correct Aurora endpoint automatically and reduce user-visible write interruptions. Which change is most likely to achieve this?
Medium855A media processing pipeline runs batch jobs on EC2. The jobs can tolerate interruptions because they checkpoint progress to durable storage and can restart. The total workload is variable week-to-week, and there is no need to guarantee capacity at specific times. To reduce compute cost while maintaining correctness, what EC2 purchase option and approach is the best fit?
Medium856A web application for a IoT ingestion API is behind an Application Load Balancer. The application must be protected from common SQL injection and cross-site scripting attacks with minimum operational overhead. What should the architect deploy?
Medium857A healthcare company runs a three-tier web application on AWS. The application tier consists of EC2 instances in an Auto Scaling group behind an Application Load Balancer. The security team must ensure that the application instances accept traffic only from the load balancer and that no instance can be reached directly from the internet. The instances are in private subnets and have a security group attached. What should a solutions architect do to meet these requirements?
Medium858A healthcare analytics firm stores protected health information in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. The firm's security team wants to ensure that only a specific IAM role used by an analytics application can decrypt objects, while other principals in the same account with broad S3 permissions cannot. The key policy currently grants kms:* to the account root. Which change should a solutions architect make to enforce the restriction?
Hard859A company has a VPC with a CIDR block of 10.0.0.0/16. They need to deploy a web application that must be accessible from the internet. The application will run on Amazon EC2 instances in an Auto Scaling group. The security team requires that the instances be in private subnets and that inbound traffic from the internet be allowed only on ports 80 and 443. They also want to use an Application Load Balancer (ALB) for load balancing and SSL termination. Which architecture meets these requirements?
Hard860A developer accidentally deletes important rows in an RDS database. The mistake is discovered 45 minutes later. The database has automated backups enabled with a retention period of 7 days. What is the best way to restore the database to a point just before the deletion?
Medium861Based on the exhibit, a partner account uploads encrypted objects to a central S3 bucket and later reads them back. The S3 permissions are correct, but the requests still fail. What change is required so the partner workload can use the customer-managed KMS key safely?
Hard862A claims portal uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend? The design must avoid adding custom operational scripts.
Hard863A payments API uses an RDS MySQL database and must remain available during an Availability Zone failure with minimal application changes. What should the architect enable?
Medium864You host a public API using Amazon API Gateway in two AWS Regions: us-east-1 (primary) and us-west-2 (secondary). You want Route 53 to send client traffic to the secondary region only when the primary API is unhealthy. Which Route 53 setup best meets this requirement?
Medium865A DynamoDB table uses this schema: partition key = customerId, sort key = timestamp. During a marketing campaign, one customer generates extremely high read traffic and the application sees ProvisionedThroughputExceeded errors even though the table’s total capacity is sufficient. What change most directly improves read distribution across partitions?
Medium866A media company stores its video uploads in an Amazon S3 bucket. The security team wants to ensure that any objects uploaded to the bucket are encrypted at rest using keys managed in AWS Key Management Service (AWS KMS) and that the encryption key is rotated annually. Which solution should a solutions architect recommend?
Easy867A security requirement states: all uploads to an S3 bucket must (1) use TLS in transit and (2) use server-side encryption with AWS KMS (SSE-KMS) using the CMK key id 'abcd-1234'; otherwise the upload should be rejected. A developer reports that uploads are succeeding even though clients are sometimes using non-encrypted requests. Which bucket policy approach most directly enforces both controls?
Medium868A media processing workflow in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost?
Hard869An ECS service runs on EC2 instances and is fronted by an ALB. The ALB spans two Availability Zones, and the ECS service desired count is 2 tasks. The underlying EC2 capacity uses an Auto Scaling group (ASG) with min size set to 1, and the ASG also spans only one subnet in practice. What is the most effective change to meet the requirement that the service continues during a single-AZ instance loss?
Medium870A web service runs on an Auto Scaling group (ASG). The team updates configuration (AMIs, environment variables) in a Launch Template and wants new instances created during scale-out to use the latest Launch Template version. What should the architect do?
Easy871A global mobile game backend serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most?
Medium872A fleet of test servers is rebuilt every week from AMIs. EBS volumes are often left behind after termination, and the team creates daily snapshots of every volume even when nothing changes. Which three actions most reduce storage cost while preserving recovery options? Select three.
Hard873A solutions architect is designing a highly available relational database tier for a customer-facing order system that must survive the loss of an entire Availability Zone with minimal administrative effort and no application connection-string changes during failover. (Choose two.)
Medium874A document portal requires consistent high IOPS for a transactional database on EC2. Which EBS volume type is most suitable?
Medium875A ticket booking system uses Aurora MySQL. The company wants fast cross-Region disaster recovery with low RPO. Which architecture should be considered? The design must avoid adding custom operational scripts.
Medium876A company runs a stateless containerized web application on Amazon ECS with the Fargate launch type behind an Application Load Balancer. The application must scale out quickly when request latency rises and scale in when traffic drops, and the operations team wants a managed target-tracking approach. Which solution meets these requirements?
Easy877A healthcare data platform stores patient documents in an Amazon S3 bucket in us-east-1. Regulations require that the data remain readable with low latency even if the entire us-east-1 Region becomes unavailable, and that writes continue in a secondary Region. The team wants object-level replication with minimal operational overhead and must preserve version history. Which solution BEST meets these requirements?
Hard878A mobile banking backend must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?
Hard879Based on the exhibit, an administrator accidentally deleted data from Amazon RDS for PostgreSQL about 90 minutes ago. Which recovery approach best restores the database to the exact required point in time?
Medium880A partner company needs read-only access to reports in an S3 bucket for a B2B file exchange site. The partner has its own AWS account. What is the most secure scalable access pattern? The design must avoid adding custom operational scripts.
Medium881A global video platform serves mostly static images and JavaScript files from an S3 origin. Users in distant countries report slow load times. What should improve performance most?
Medium882A genomics research company runs a large-scale sequence alignment workload on AWS. The workload requires a shared file system that can be accessed concurrently by thousands of EC2 instances, provides high throughput and low latency, and supports POSIX permissions. The data set is about 500 TB and grows by 10 TB per month. The solutions architect needs to choose a storage solution that meets these performance and scalability requirements. Which solution should the architect use?
Hard883A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first? The design must avoid adding custom operational scripts.
Hard884You have EC2 instances in private subnets with no NAT gateway. They must retrieve secrets from AWS Secrets Manager without sending traffic to the public internet. Which VPC endpoint type is the correct choice for connecting to AWS Secrets Manager?
Easy885A company wants to protect a critical application from a full Region outage. The secondary Region should keep only a small amount of infrastructure running most of the time to control cost. Which disaster recovery strategy fits best?
Easy886A static marketing site is served through CloudFront from an S3 origin. After a product update, customers report a drop in CloudFront cache hit ratio and the CloudFront bill increases because the origin is receiving many more requests for the same JS/CSS assets. Asset URLs are versioned, but requests now include an Authorization header even though these assets are public. Which CloudFront change most directly improves the cache hit ratio for these assets?
Medium887A financial services company stores regulatory documents in an Amazon S3 bucket. The documents are accessed frequently for the first 90 days, then almost never, but must remain immediately retrievable for seven years. Retrieval latency of a few minutes is unacceptable, and the company wants the lowest storage cost that still meets the access requirement. Which S3 storage class should a solutions architect recommend?
Hard888A company has a VPC with a CIDR block of 10.0.0.0/16. The company wants to allow its EC2 instances in a private subnet to access Amazon S3 without traversing the public internet. The company also wants to minimize data transfer costs. Which solution should a solutions architect recommend?
Easy889A healthcare company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application must be accessible only to users connecting from a specific corporate IP range, and all traffic must be encrypted in transit. The security team wants to enforce these requirements at the load balancer level without modifying the application. Which combination of steps should a solutions architect take?
Hard890A startup runs an API on Amazon EC2. The instance must read items from one DynamoDB table and upload logs to one S3 bucket. Platform engineers also need a way to create new application roles, but those roles must never exceed a predefined set of permissions. Which three actions should the architect take? Select three.
Medium891A public API is served through an Application Load Balancer and protected by AWS WAF. The team wants AWS to automatically block clients that send too many requests from the same IP address within a short time window. Which AWS WAF feature is the best fit?
Easy892A company hosts a web application on Amazon EC2 instances in a VPC. The application must access an Amazon RDS for MySQL database. The security team requires that database credentials never be stored in application code or on disk, and that credentials be automatically rotated every 30 days. Which solution should a solutions architect implement?
Medium893A warehouse integration service receives bursts of orders that sometimes overwhelm a downstream fulfilment service. The architecture must absorb spikes and retry processing without losing requests. Which service should be placed between the web tier and fulfilment workers?
Medium894A workload runs in private subnets. It must access AWS services such as Amazon S3, but the company wants to avoid using a NAT Gateway to reduce outbound networking costs. What is the best solution?
Easy895A healthcare document service stores audit logs in S3. The compliance team requires that logs cannot be overwritten or deleted for seven years. What should be configured?
Medium896An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a image sharing application. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy?
Hard897A telemetry pipeline uses an Application Load Balancer in one Region. Global users need lower network latency to the application without caching dynamic responses. What should be considered? The architecture review board prefers a managed AWS-native control.
Medium898A small e-commerce company hosts its product catalog on a single Amazon EC2 instance in a public subnet. Traffic is steady and predictable, and the instance runs 24/7. The company wants to reduce its monthly compute bill without changing the architecture or risking availability. Which action should a solutions architect recommend?
Easy899A Lambda function for a order processing API needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?
Medium900A financial analytics platform runs a stateless API on Amazon EC2 instances in an Auto Scaling group behind a Network Load Balancer. The API reads from an Amazon Aurora MySQL cluster that has a single writer instance and one reader instance in a different Availability Zone. During a recent Availability Zone event, the writer instance failed and the API saw several minutes of failed writes. The team wants writes to resume automatically with minimal downtime and no application code changes. What should the solutions architect do?
Hard901A company runs an internal analytics application in a single AWS Region. A solutions architect is reviewing the Amazon RDS for MySQL deployment and finds a Multi-AZ DB instance with a standby in another Availability Zone, used only for failover. The application performs many read-heavy queries against the primary instance, driving up instance size and cost. The team wants to offload read traffic and reduce the primary instance size. Which change should the architect recommend?
Medium902Based on the exhibit, an application repeatedly reads the same DynamoDB items with extremely low latency requirements. The business can tolerate data that is a few seconds stale. Which architecture change best improves read performance?
Hard903An internal API is hosted in two AWS Regions behind Route 53. Under normal conditions, clients should use the primary region. If the primary endpoint becomes unhealthy, traffic must automatically switch to the secondary region. Which Route 53 setup best meets this requirement?
Easy904A Lambda function for a mobile banking backend needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used? The design must avoid adding custom operational scripts.
Medium905Based on the exhibit, what change should the team make to achieve the lowest possible network latency for the distributed workload?
Hard906A startup runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The application must call AWS APIs such as Amazon DynamoDB and Amazon S3. A security engineer must ensure that no long-term AWS credentials are stored on the instances and that each instance receives credentials automatically. Which solution should the engineer use?
Easy907A company stores millions of objects in Amazon S3. Access patterns are completely unpredictable — some objects are frequently accessed, others rarely. Objects range from 4 KB to 50 MB. The company wants to minimize storage costs automatically without managing lifecycle rules. Which storage class should a solutions architect recommend?
Medium908A read-heavy document portal repeatedly queries the same product catalogue data from DynamoDB with millisecond latency requirements. Which service can reduce read latency and table load? The design must avoid adding custom operational scripts.
Medium909A startup runs a public-facing web application on Amazon EC2 instances in a VPC. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to block traffic from specific countries. Which AWS service should a solutions architect use?
Easy910An orders service currently sends HTTP requests directly to two downstream services (inventory and shipping). During peak load, inventory slows down, causing the orders service to slow as well. The team wants the orders service to remain responsive even when a downstream service is temporarily slow or restarted. Which design change best achieves this resiliency goal?
Easy911A Lambda-based retail API has unpredictable traffic spikes and users see latency caused by cold starts. The function must respond consistently during expected campaign windows. What should be configured?
Hard912Your team serves static JavaScript and CSS files from an S3 origin through CloudFront. After a release, the CloudFront cache hit ratio dropped because clients keep re-downloading the same assets. What is the best next change to improve caching performance?
Easy913A content publishing system uses Lambda functions that call an unreliable third-party API. Failed events must be retained for later investigation after retries are exhausted. What should be configured? The design must avoid adding custom operational scripts.
Medium914A healthcare company runs a batch ingestion pipeline on Amazon EC2 instances that read messages from an Amazon SQS queue and write results to Amazon DynamoDB. The pipeline must be resilient so that a single instance failure does not stop processing and no messages are lost. Which two architectural changes should a solutions architect make to meet these requirements? (Choose two.)
Medium915A risk simulation workload in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost? The design must avoid adding custom operational scripts.
Hard916A financial services firm runs a stateless containerized trading dashboard on Amazon ECS with the Fargate launch type. The dashboard queries a backend over HTTPS and must present responses in under 200 ms. During market open, traffic triples within a few minutes and latency spikes because tasks take time to start. The team needs faster, more predictable scaling and wants to avoid over-provisioning during quiet periods. Which solution meets these requirements?
Hard917A service role has an IAM policy granting kms:Decrypt for a specific AWS KMS key. The application still fails to decrypt with an AccessDenied error. What change most directly fixes this when the KMS key policy is missing the role’s permissions?
Easy918A company runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. Traffic has grown, and the operations team notices that individual instances are often underutilized while others are saturated because traffic is not evenly distributed. The team wants the load balancer to distribute requests more evenly across healthy targets. Which action should the team take?
Easy919A media company serves on-demand video to viewers worldwide from an Amazon S3 bucket in us-east-1. Viewers in Asia and Europe report slow start times because the first byte takes several seconds to arrive. The videos are already stored as objects and must remain in the us-east-1 bucket as the origin. Which solution improves global read performance with the LEAST operational effort?
Medium920A company uses AWS Organizations and has separate development, test, and production accounts. The security team wants to ensure that no one in the sandbox organizational unit can disable AWS CloudTrail or delete the central audit bucket, even if an account administrator creates permissive IAM policies later. Which control should they use?
Medium921Your mobile app writes events to a single DynamoDB table with partition key = customerId and sort key = eventTime. During a promotional campaign, one tenant ("ACME") generates far more traffic than others. CloudWatch shows sustained throttling (ProvisionedThroughputExceeded) and elevated p99 latency only for that tenant. The workload pattern cannot be changed to a completely different schema, but you can change how items are partitioned. Which design change is most likely to reduce the hot-partition throttling while keeping efficient reads for ACME?
Medium922An Aurora PostgreSQL cluster is experiencing high read latency because 85% of traffic consists of read-only queries. The write workload must stay on the writer instance, and the team wants to offload reads without changing the application’s core query patterns. What is the best architectural option?
Medium923A media startup stores user-uploaded video files in an Amazon S3 bucket in the us-east-1 Region. The compliance team requires that the data remain recoverable if an entire AWS Region becomes unavailable, and that recovery can be performed by pointing applications at a different endpoint. Cost should be minimized while still meeting the requirement. Which solution should a solutions architect recommend?
Easy924Based on the exhibit, the current disaster recovery design misses the RTO target even though the database replica is current. Which deployment model best meets the requirements with the least always-on cost?
Hard925A team wants to remove a bastion host used for administrative access to EC2 instances in private subnets. The instances should be reachable only for occasional troubleshooting by engineers who authenticate with AWS SSO. What is the best secure alternative within AWS, assuming the instances already have an instance profile attached?
Medium926A retail platform needs disaster recovery across AWS Regions. The business requirement is: RTO up to 6 hours, RPO up to 1 hour, and they want the ability to start serving quickly during a Region outage but do not want to run full production capacity continuously. Which DR strategy best fits these requirements?
Easy927An event ingestion service writes to a DynamoDB table where the partition key is tenantId and the sort key is eventTime. During a campaign, one tenant generates a disproportionate share of traffic, causing write throttling and increased latency for that tenant’s writes. You can change the data model and application queries, but you must still efficiently retrieve events for a tenant for the last 10 minutes. Which change best improves write throughput by reducing hot partitions?
Medium928A containerized service needs to read exactly one secret value from AWS Secrets Manager. The secret’s ARN is already known, and the secret is encrypted with the AWS-managed KMS key for Secrets Manager, so no separate KMS permissions are needed for this question. The service does not need to list secrets, create secrets, rotate them, or write updates. What is the most least-privilege IAM permission statement to grant the service role?
Easy929A media company stores 50 TB of finalized video masters in Amazon S3 that must be retained for seven years for regulatory compliance. The files are accessed only during occasional legal audits, roughly once every two years, and retrieval latency of several hours is acceptable. The company wants the LOWEST possible storage cost while preserving durability. Which storage class should they choose?
Easy930A security team needs an audit trail to investigate suspicious API activity across multiple AWS accounts. Which AWS approach best provides centralized visibility into who did what, when, for service API calls?
Easy931Based on the exhibit, what should the security team implement so developers can create AWS Lambda execution roles, but no developer-created role can ever exceed the approved permission set?
Medium932Your team hosts a private web app on an S3 bucket and serves it through CloudFront using a modern Origin Access Control (OAC). After deployment, users receive HTTP 403 from CloudFront with the S3 origin error "AccessDenied". Which S3 bucket policy change best aligns with CloudFront OAC so the distribution can fetch objects privately?
Medium933A mobile app reads the same product details many times per minute from Amazon DynamoDB. The table design is already correct, but repeated reads are still causing noticeable latency. Which service should the team add to improve read performance?
Easy934A media company stores original video assets in an Amazon S3 bucket in the us-east-1 Region. Editors in Europe report slow downloads, and the legal team requires that a copy of every asset exist in eu-west-1 within 15 minutes of upload, with the ability to fail over reads to the European copy during a Regional impairment. Which S3 feature should the architects enable?
Medium935A Lambda function for a IoT ingestion API needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?
MediumOther domains
All SAA-C03 exam domains
Frequently asked questions
- What does the nat gateway domain cover on the SAA-C03 exam?
- NAT questions usually test how private addresses are translated, when to use static NAT, dynamic NAT or PAT, and how inside/outside interfaces affect traffic flow.
- How many questions are in this domain?
- This page lists all 935 nat gateway questions in the SAA-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only nat gateway questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.