Courseiva
← Back to SAA-C03 questions

Scenario-based practice

Hard Difficulty Questions

Practise SAA-C03 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
SAA-C03
exam code
Amazon Web Services
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SAA-C03 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Based on the exhibit, which storage choice best matches the workload requirements?

Exhibit

fio benchmark on the selected EC2 family:
- Device: /dev/nvme1n1
- 4 KiB random read IOPS: 710,000
- Average latency: 0.18 ms
- Sequential throughput: 2.8 GiB/s
Workload notes:
- Workers download source video files from S3
- They generate temporary frame extracts and intermediate artifacts locally
- Final MP4 outputs are uploaded to S3 immediately after processing
- If an instance terminates, the job is retried from the original source file
Question 2hardmultiple choice
Read the full DNS explanation →

Based on the exhibit, DNS still sends traffic to the primary Region even though Route 53 health checks show the primary endpoint is unhealthy. What is the best change to make failover work as intended?

Exhibit

Route 53 record sets for app.example.com:
- Record 1: Type A, RoutingPolicy=Simple, AliasTarget=alb-use1.amazonaws.com
- Record 2: Type A, RoutingPolicy=Simple, AliasTarget=alb-usw2.amazonaws.com

Health check status:
hc-primary: FAILED
hc-secondary: HEALTHY

Resolver test:
$ dig +short app.example.com
alb-use1.amazonaws.com

Ops note:
The intent is to send all traffic to us-east-1 normally and fail over to us-west-2 only when the primary is unhealthy.
Question 3hardmultiple choice
Full question →

Based on the exhibit, which change best reduces latency during peak traffic without overprovisioning the fleet?

Exhibit

ALB and ASG snapshot (15-minute peak):
- RequestCountPerTarget: 1,920
- TargetResponseTime p95: 2.9 seconds
- HTTPCode_Target_5XX_Count: 0
EC2 application metrics from CloudWatch agent:
- CPUUtilization: 33%
- MemoryUtilization: 46%
- NetworkIn/Out: steady
Application logs:
[WARN] worker queue depth reached 5,000
[INFO] rejecting requests after thread pool saturation
Current Auto Scaling policy:
- Target tracking on CPUUtilization = 55%
Question 4hardmultiple choice
Full question →

Based on the exhibit, a serverless API on AWS Lambda experiences a predictable cold-start penalty every weekday at 09:00 UTC when a marketing campaign begins. The team wants the first requests to stay fast while minimizing extra cost during quiet periods. What is the best approach?

Exhibit

Lambda monitoring and deployment notes:
- Function: checkout-api-prod
- Current alias: live
- Invocations per day: low except weekdays 09:00-09:15 UTC
- REPORT log sample at 09:00 UTC:
  Init Duration: 842.31 ms
  Duration: 128.42 ms
  Billed Duration: 1000 ms
- REPORT log sample at 09:05 UTC:
  Init Duration: 0.00 ms
  Duration: 121.77 ms

Traffic pattern:
- Spikes are predictable and last about 15 minutes
- No need to keep high concurrency all day
Question 5hardmatching
Full question →

Match each data-retention scenario to the most cost-effective Amazon S3 storage class. Assume the retrieval pattern and access-latency requirement are the most important constraints.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Amazon S3 Standard

Amazon S3 Standard-IA

Amazon S3 Glacier Instant Retrieval

Amazon S3 Glacier Deep Archive

Question 6hardmultiple choice
Full question →

Based on the exhibit, which change will most improve the CloudFront cache hit ratio for the static assets while still serving the same files to all users?

Exhibit

CloudFront behavior summary for path pattern /static/*:
- Allowed methods: GET, HEAD
- Cache policy: forwards all query strings
- Origin request policy: forwards all cookies and the Authorization header
- Average cache hit ratio: 11%
Sample request log lines:
GET /static/app.js?v=18&userId=123 Cookie: session=abcd
GET /static/app.js?v=18&userId=987 Cookie: session=xyzt
GET /static/logo.svg?v=18&locale=en Cookie: session=mnop
Origin responses:
- All objects are identical for every viewer
- Objects are versioned only by the v query parameter

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The design must avoid adding custom operational scripts.

Question 8hardmultiple choice
Full question →

A patient portal must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The design must avoid adding custom operational scripts.

Question 9hardmultiple choice
Full question →

A mobile banking backend uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend? The design must avoid adding custom operational scripts.

Question 10hardmultiple choice
Full question →

Based on the exhibit, the company wants to lower CloudWatch and EC2 monitoring costs. Auditors require logs to be retained for 90 days, but operations only uses detailed per-instance metrics during rare troubleshooting events. Which change best reduces recurring cost while preserving the required visibility?

Exhibit

CloudWatch billing snapshot:
  Logs ingestion: moderate
  Logs storage: high
  Custom metrics: low
  Detailed monitoring charges: high
EC2 fleet:
  200 instances across 4 Auto Scaling groups
  Detailed monitoring enabled on every instance
CloudWatch Logs groups:
  /app/prod/web: retention = Never Expire
  /app/prod/api: retention = Never Expire
  /app/prod/batch: retention = 365 days
Compliance note:
  Keep logs available for at least 90 days
  No requirement for 1-minute EC2 metrics on all instances
Question 11hardmultiple choice
Full question →

Based on the exhibit, a DynamoDB-backed event processing system is throttling during a promotion. The table uses tenantId as the partition key and eventTime as the sort key. One tenant accounts for most of the write traffic, and the application must preserve fast lookups for that tenant without relying on a single hot partition. What change is the best fix?

Exhibit

Table schema:
- TableName: EventStore
- PartitionKey: tenantId (String)
- SortKey: eventTime (Number)

CloudWatch metrics during promotion:
- WriteThrottleEvents: increasing steadily
- ConsumedWriteCapacityUnits: near provisioned limit
- SuccessfulRequestLatency p95: 14 ms

Sample traffic distribution:
- tenantId=ACME: 82% of writes, 79% of reads
- all other tenants combined: 18% of writes, 21% of reads

Application note:
- Queries must continue to support tenant-scoped lookups by time range.
Question 12hardmulti select
Full question →

A internal reporting portal has old unattached EBS volumes and many stale snapshots. Which two actions reduce storage cost without affecting running instances? The architecture review board prefers a managed AWS-native control.

Question 13hardmultiple choice
Full question →

A company runs a production MySQL database on Amazon RDS in us-east-1. A read replica exists in us-west-2 for disaster recovery. The primary region experiences a complete outage. Which of the following describes the correct procedure to restore database service using the cross-region read replica?

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The architecture review board prefers a managed AWS-native control.

Question 15hardmultiple choice
Full question →

A DynamoDB table for a retail API has a partition key based only on the current date. Write throttling occurs during business hours. What is the best design change? The design must avoid adding custom operational scripts.

Question 16hardmultiple choice
Full question →

A SaaS vendor’s automation account in Account B needs to assume a role in a customer account in Account A to read a specific S3 bucket and publish a deployment status file. The customer is worried about confused deputy attacks because multiple customers use the same vendor software. Which trust-policy design best meets the requirement?

Question 17hardmultiple choice
Full question →

Based on the exhibit, the application tier is not replacing unhealthy instances even though the Auto Scaling group spans two Availability Zones. What change most directly improves automatic recovery when the application process fails?

Network Topology
$ aws autoscaling describe-auto-scaling-groupsauto-scaling-group-names orders-asg$ aws elbv2 describe-target-healthtarget-group-arn arn:aws:elasticloadbalancing:us-east-1:111122223333:targetgroup/orders-tg/abcd1234"AutoScalingGroups": ["AutoScalingGroupName": "orders-asg","DesiredCapacity": 4,"MinSize": 4,"MaxSize": 8,"AvailabilityZones": ["us-east-1a", "us-east-1b"],"HealthCheckType": "EC2","HealthCheckGracePeriod": 300,"TargetGroupARNs": ["arn:aws:elasticloadbalancing:us-east-1:111122223333:targetgroup/orders-tg/abcd1234"]TARGETSi-01e2a3b4: healthyi-02e3b4c5: healthyi-03f4c5d6: unhealthyi-04a5d6e7: unhealthyApplication health endpoint:2026-04-27T13:05:22Z GET /health -> 500EC2 status checks: passing
Question 18hardmultiple choice
Full question →

A warehouse integration service must use shared file storage across Linux EC2 instances in multiple Availability Zones. The storage must remain available during an AZ failure. Which service should be used? The architecture review board prefers a managed AWS-native control.

Question 19hardmulti select
Full question →

A reporting application in Account B must read files from an S3 bucket in Account A. The bucket contains objects encrypted with a customer managed KMS key in Account A. The application role in Account B already has an identity policy allowing s3:GetObject on the bucket prefix, but requests still fail with AccessDenied. Which two changes are required for the application to read the objects? Select two.

Question 20hardmultiple choice
Full question →

Based on the exhibit, the team must restore an Amazon RDS for PostgreSQL database to the exact state just before a bad delete happened. What is the best recovery approach?

Exhibit

RDS backup status:
- Automated backups: Enabled
- Backup retention period: 14 days
- Latest automated snapshot: 2026-04-27 09:00 UTC
- Latest restorable time: 2026-04-27 15:14 UTC

Incident timeline:
- 2026-04-27 15:11 UTC: deployment script accidentally deleted critical rows
- 2026-04-27 15:12 UTC: application detected missing data
- Required restore point: 2026-04-27 15:10 UTC

Operations note:
The business wants to recover to a new database first, verify data, and then cut over the application.

These SAA-C03 practice questions are part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style SAA-C03 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.