Courseiva

CCNA Design Cost Questions

20 of 170 questions · Page 3/3 · Design Cost topic · Answers revealed

151
MCQmedium

A company runs a containerized web application on Amazon ECS with a steady baseline of 10 tasks that must run continuously. During business hours, traffic spikes require up to 30 additional tasks that can be terminated at any time. The company wants to minimize costs while ensuring the baseline tasks are always available. Which combination of purchasing options should be used for the ECS tasks?

A.Use Dedicated Hosts for the baseline and On-Demand Instances for the additional tasks.
B.Use On-Demand Instances for the baseline and Spot Instances for the additional tasks.
C.Use Reserved Instances or Savings Plans for the baseline and Spot Instances for the additional tasks.
D.Use Spot Instances for all tasks, including the baseline, to maximize savings.
AnswerC

Reserved Instances or Savings Plans provide significant discounts for the steady baseline of 10 tasks, ensuring predictable capacity and cost. Spot Instances handle the variable additional tasks at up to 90% discount, and their interruptible nature is acceptable for the spike capacity. This combination minimizes cost while maintaining baseline availability.

Why this answer

The baseline of 10 tasks runs continuously, so Reserved Instances or Savings Plans offer the best discount for that predictable usage. The additional tasks are variable and can be interrupted, making Spot Instances ideal for cost savings. Combining these two purchasing options aligns cost with the characteristics of each workload component, ensuring availability for the baseline while minimizing spend on the spikes.

Exam trap

The trap here is using Spot Instances for the baseline tasks, which could be interrupted and violate the availability requirement, or using On-Demand for the baseline and missing the savings from Reserved Instances or Savings Plans.

152
MCQmedium

A company runs a REST API on AWS Lambda behind Amazon API Gateway. The API is used by internal clients during a two-hour batch window each night and is completely idle the rest of the day. The team is concerned about the cost of API Gateway and wants to minimize it without changing the API contract for clients. Which change should a solutions architect recommend?

A.Use an HTTP API instead of the REST API so requests are billed at the lower HTTP API rate.
B.Replace API Gateway and Lambda with an Application Load Balancer forwarding to an Auto Scaling group of EC2 instances.
C.Keep the REST API but enable API caching with a one-hour time-to-live.
D.Switch the API from a REST API to an HTTP API and configure the Lambda function with provisioned concurrency.
AnswerA

HTTP APIs cost substantially less per million requests than REST APIs while preserving the request-response contract for clients. Because the API is only invoked during the nightly batch window, the pay-per-request model means near-zero cost during the 22 idle hours, and the lower per-request price directly reduces spend without altering client behavior.

Why this answer

The workload is bursty and idle most of the day, so a per-request pricing model is the right foundation and provisioned or always-on resources should be avoided. Moving from a REST API to an HTTP API lowers the per-request charge while keeping the same client-facing contract, so the nightly batch pays less and the idle hours cost nothing. Caching and provisioned concurrency would both add continuous charges.

Exam trap

The trap here is reaching for performance-oriented features such as provisioned concurrency or API caching when the workload is idle most of the day and the actual goal is to reduce per-request and idle-time cost.

153
MCQeasy

A company stores nightly database backup files in an Amazon S3 bucket. Each backup is about 50 GB, and the files are written once and never modified. Regulatory policy requires that every backup be retained for exactly seven years, after which it may be deleted. Retrieval of a backup for an audit is extremely rare and the company can tolerate a retrieval time of up to 12 hours. Which S3 storage class is the MOST cost-effective choice for these backups?

A.S3 Glacier Deep Archive
B.S3 One Zone-IA
C.S3 Intelligent-Tiering
D.S3 Standard
AnswerA

S3 Glacier Deep Archive is the lowest-cost S3 storage class and is intended for data retained for long periods that is rarely, if ever, accessed. Its standard retrieval time is within 12 hours, which matches the stated tolerance, and it is well suited to seven-year compliance retention of immutable backup files, making it the most cost-effective fit.

Why this answer

The backups are immutable, retained for a fixed multi-year period, and almost never retrieved, with a retrieval tolerance of up to 12 hours. S3 Glacier Deep Archive is purpose-built for exactly this pattern and offers the lowest storage cost among S3 classes, so it satisfies both the compliance retention requirement and the cost-optimization goal without needing frequent access.

Exam trap

The trap here is choosing an automatic tiering class out of habit, when a predictable never-accessed retention pattern is cheaper with a purpose-built archive class than with per-object monitoring fees.

154
MCQmedium

A video processing pipeline runs batch jobs that are safe to interrupt and restart. The jobs checkpoint progress to durable storage every few minutes, and the team can automatically resubmit from the last checkpoint. They want to minimize compute cost while accepting that capacity can be interrupted. Which launch configuration for the processing workers is the best cost-optimized choice?

A.Launch the worker nodes as Spot Instances, and configure the job resubmission logic to restart from checkpoints upon interruption.
B.Launch the worker nodes as On-Demand Instances with no interruption handling so the pipeline never needs resubmission.
C.Launch the worker nodes as Reserved Instances to guarantee capacity and reduce cost, ignoring interruptions.
D.Use Savings Plans and also set the job scheduler to never start new jobs unless previous jobs finish without interruption.
AnswerA

Spot provides significantly lower pricing than On-Demand for EC2 capacity. Because the workload is designed to tolerate interruption (checkpointing + resubmission from the last checkpoint), the team can safely accept Spot interruptions. Resubmission from durable checkpoints preserves correctness while still capturing the cost advantage of Spot.

Why this answer

Spot Instances offer significant cost savings (up to 90% compared to On-Demand) and are ideal for fault-tolerant, interruptible workloads. Since the pipeline checkpoints progress to durable storage and can automatically resume from the last checkpoint, using Spot Instances minimizes compute cost while accepting interruptions.

Exam trap

The trap here is that candidates may choose On-Demand or Reserved Instances because they assume interruptions are unacceptable, but the question explicitly states the workload is safe to interrupt and restart, making Spot Instances the correct cost-optimized choice.

How to eliminate wrong answers

Option B is wrong because On-Demand Instances are more expensive and provide no cost optimization benefit for a workload that can tolerate interruptions. Option C is wrong because Reserved Instances require a 1- or 3-year commitment and are not designed for workloads that can be interrupted; they also do not inherently handle interruption recovery. Option D is wrong because Savings Plans still incur costs for unused capacity if jobs are delayed, and the suggestion to never start new jobs unless previous jobs finish without interruption contradicts the goal of minimizing cost by accepting interruptions.

155
MCQhard

A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first?

A.Replacing every NAT gateway with an internet gateway attached to private subnets
B.Whether one NAT gateway per AZ is sufficient for the required private subnets
C.Disabling route tables
D.Moving all workloads to public subnets
AnswerB

The right cost-optimization review here is to ask whether the batch analytics job truly needs a NAT gateway in every Availability Zone or whether one per AZ is sufficient. A NAT gateway is a zonal resource, and the standard high-availability pattern is to deploy one per AZ and route each AZ's private subnets to its local gateway; having two NAT gateways in the same AZ adds no resiliency because an AZ failure affects both, and the second gateway only doubles the hourly and per-GB costs. If the batch job is not required to be highly available or can tolerate an AZ outage, a single NAT gateway per AZ (or even one total) could be enough, which is exactly what should be evaluated before paying for four gateways.

Why this answer

The question asks what the architect should review first. Using two NAT gateways per Availability Zone (AZ) when only one private subnet per AZ needs outbound internet access is likely over-provisioned and costly. The architect should first verify if a single NAT gateway per AZ can handle the traffic load, as NAT gateways are highly available within an AZ and can support up to 45 Gbps of bandwidth.

This review directly addresses cost optimization without sacrificing functionality.

Exam trap

The trap here is that candidates may assume more NAT gateways always improve reliability, but the question emphasizes cost optimization, so the first review should be whether the existing number of gateways is necessary rather than immediately adding or removing resources.

How to eliminate wrong answers

Option A is wrong because replacing NAT gateways with an internet gateway attached to private subnets is technically invalid; internet gateways can only be attached to VPCs and provide outbound access only to resources with public IPs in public subnets, not private subnets. Option C is wrong because disabling route tables would break all network connectivity, not just outbound internet access, and is not a valid cost-optimization review step. Option D is wrong because moving all workloads to public subnets would expose them directly to the internet, violating security best practices and potentially incurring higher data transfer costs, and does not address the cost of NAT gateways.

156
MCQmedium

A SaaS company runs a production API on an EC2 Auto Scaling group with steady demand 24/7. The team uses multiple instance types over time (they switch types during tuning) but the overall compute hours are stable. They want a cost reduction without committing to a specific instance type or size. Which AWS pricing option best meets the requirement?

A.Buy EC2 Spot Instances for the Auto Scaling group to maximize savings
B.Purchase a Compute Savings Plan for the region and commit to a dollar-per-hour amount
C.Purchase Reserved Instances that are limited to a single specific instance type in the Auto Scaling group
D.Use on-demand only, and rely on Auto Scaling to reduce cost during low utilization
AnswerB

A Compute Savings Plan lets you commit to a specific dollar-per-hour amount for a one- or three-year term in a given region, and the discount automatically applies to any EC2 instance family or size in that region. This is ideal for an Auto Scaling group with steady 24/7 API traffic because it captures predictable usage while preserving the flexibility to scale or change instance families without renegotiating the commitment. Usage above the committed amount simply runs at normal on-demand rates, so you still receive the lower rate on the bulk of your steady baseline.

Why this answer

B is correct because a Compute Savings Plan provides the flexibility to change instance types, sizes, and even compute services (e.g., EC2, Fargate, Lambda) within a region while still receiving discounted rates (up to 66% vs. on-demand). This matches the requirement of reducing costs without committing to a specific instance type or size, as the plan is based on a dollar-per-hour commitment rather than instance family or tenancy.

Exam trap

The trap here is that candidates often confuse Compute Savings Plans with Reserved Instances, assuming that any savings plan requires a specific instance type, but Compute Savings Plans offer full flexibility across instance families and sizes within a region.

How to eliminate wrong answers

Option A is wrong because Spot Instances can be interrupted with a 2-minute warning, making them unsuitable for a production API with steady demand 24/7 where availability and reliability are critical. Option C is wrong because Reserved Instances are tied to a specific instance type (e.g., m5.large) and tenancy, which contradicts the requirement to avoid committing to a specific instance type or size. Option D is wrong because relying solely on on-demand instances with Auto Scaling does not reduce cost; Auto Scaling only adjusts capacity based on demand, but on-demand pricing is the highest, so no cost savings are achieved.

157
MCQmedium

A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost?

A.On-Demand Instances only
B.Dedicated Hosts
C.Spot Instances
D.Provisioned IOPS volumes
AnswerC

Spot Instances offer spare EC2 compute capacity at up to a 90% discount compared to On-Demand, with the tradeoff that AWS can reclaim this capacity with a two-minute warning for other customers' workloads. Because the batch analytics job runs nightly, lasts several hours, and can be interrupted and resumed, it is exactly the kind of fault-tolerant, flexible workload that Spot was designed for. Using Spot Instances dramatically reduces compute costs while accommodating the job's tolerance for interruptions, making it the correct answer for a cost-optimized architecture.

Why this answer

Spot Instances are the correct choice because they offer significant cost savings (up to 90% compared to On-Demand) and are ideal for fault-tolerant, interruptible workloads like batch processing. Since the job can be interrupted and restarted, it can handle Spot Instance terminations gracefully, making this the most cost-effective option.

Exam trap

The trap here is that candidates may choose On-Demand Instances thinking they need guaranteed uptime, overlooking the fact that the workload is explicitly described as interruptible and restartable, which makes Spot Instances the optimal cost-saving choice.

How to eliminate wrong answers

Option A is wrong because On-Demand Instances provide no interruption but are priced higher, which is unnecessary for a workload that can tolerate interruptions. Option B is wrong because Dedicated Hosts are designed for licensing or compliance requirements and are billed per host, making them far more expensive and unsuitable for cost minimization. Option D is wrong because Provisioned IOPS volumes (EBS) relate to storage performance, not compute pricing, and do not address the cost of EC2 instances.

158
MCQmedium

A batch analytics job runs for several hours each night and can be interrupted and restarted. Which EC2 purchasing option should minimize cost? The design must avoid adding custom operational scripts.

A.On-Demand Instances only
B.Dedicated Hosts
C.Spot Instances
D.Provisioned IOPS volumes
AnswerC

Spot Instances let you bid on spare EC2 capacity at steep discounts — often 60-90% off On-Demand prices. Since the batch analytics job runs for several hours each night and can be interrupted and resumed, it is exactly the type of fault-tolerant workload AWS designed Spot Instances for. You can use Spot with a checkpointing strategy to save intermediate results, making it the most cost-effective choice.

Why this answer

Spot Instances are ideal for fault-tolerant, interruptible batch workloads because they offer significant cost savings (up to 90% off On-Demand pricing) by using spare EC2 capacity. Since the job can be interrupted and restarted, it can handle Spot Instance reclaimations without requiring custom operational scripts—AWS handles the interruption notification and automatic instance termination, and the job's restart logic can be built into the application or orchestration layer (e.g., AWS Batch).

Exam trap

The trap here is that candidates may confuse Spot Instances with On-Demand Instances for cost savings, or incorrectly assume that Spot Instances require custom scripting to handle interruptions, when in fact AWS provides built-in mechanisms (e.g., lifecycle hooks, rebalance notifications) that can be leveraged without custom scripts.

How to eliminate wrong answers

Option A is wrong because On-Demand Instances provide no cost savings for interruptible workloads; they are priced at the standard rate and are intended for steady-state or unpredictable workloads that cannot tolerate interruptions. Option B is wrong because Dedicated Hosts are a physical server dedicated to your use, which is significantly more expensive and unnecessary for a batch job that can tolerate interruptions; they are used for licensing or compliance requirements, not cost optimization. Option D is wrong because Provisioned IOPS volumes (EBS) are a storage type, not an EC2 purchasing option; they affect storage performance and cost but do not address compute cost optimization for interruptible workloads.

159
MCQmedium

A media processing pipeline runs batch jobs on EC2. The jobs can tolerate interruptions because they checkpoint progress to durable storage and can restart. The total workload is variable week-to-week, and there is no need to guarantee capacity at specific times. To reduce compute cost while maintaining correctness, what EC2 purchase option and approach is the best fit?

A.Use EC2 Spot Instances with interruption handling and restart from checkpoints.
B.Use All Upfront Reserved Instances sized for the average weekly workload to minimize cost.
C.Use On-Demand Instances and scale only during business hours to reduce idle time.
D.Use Savings Plans with a fixed hourly commitment to ensure capacity for the entire year.
AnswerA

Spot capacity is typically the lowest-cost EC2 option and can be reclaimed by AWS with interruption notices. Because the workload is explicitly restartable and checkpoints to durable storage, interruptions do not break correctness. Since there is no requirement to reserve capacity, the variable workload aligns well with Spot’s spare-capacity model.

Why this answer

Spot Instances offer up to 90% cost savings compared to On-Demand and are ideal for fault-tolerant, stateless workloads that can checkpoint progress to durable storage. Since the batch jobs can tolerate interruptions and restart from checkpoints, Spot Instances provide the lowest compute cost while maintaining correctness. No other purchase option achieves the same level of cost reduction for this variable, interruption-tolerant workload.

Exam trap

The trap here is that candidates often choose Reserved Instances or Savings Plans thinking they always provide the best cost savings, but they fail to recognize that Spot Instances are significantly cheaper and perfectly suited for fault-tolerant, checkpointed batch workloads that do not require guaranteed capacity.

How to eliminate wrong answers

Option B is wrong because All Upfront Reserved Instances require a 1- or 3-year commitment and are sized for a fixed capacity, which does not match the variable week-to-week workload and would lead to over-provisioning or under-utilization, increasing cost. Option C is wrong because On-Demand Instances are the most expensive per-hour option and scaling only during business hours ignores the fact that the workload can run at any time; this approach does not minimize cost compared to Spot. Option D is wrong because Savings Plans with a fixed hourly commitment lock in a baseline spend and do not provide the deep discounts of Spot Instances; they also guarantee capacity only up to the committed amount, which is unnecessary for a workload that does not need guaranteed capacity.

160
MCQhard

A media processing workflow in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost?

A.S3 Object Lambda
B.AWS Shield Advanced
C.Gateway VPC endpoint for Amazon S3
D.A larger NAT gateway
AnswerC

A gateway VPC endpoint for Amazon S3 works by adding a prefix-list route to the VPC route table, directing S3-destined traffic from private subnets over the AWS backbone to the regional S3 endpoint. It requires no NAT gateway, no internet gateway, and no hourly charge, eliminating the per-GB NAT data processing fees on large media downloads. This is the correct cost-optimization mechanism for private-subnet access to S3.

Why this answer

A Gateway VPC endpoint for Amazon S3 allows instances in private subnets to access S3 directly via the AWS network without traversing a NAT gateway, eliminating NAT data processing charges. This is the most cost-effective solution because NAT gateway costs are incurred per GB of data processed, and using a gateway endpoint avoids those charges entirely.

Exam trap

The trap here is that candidates may think a larger NAT gateway would improve throughput and lower costs, but in reality, it only increases both hourly and per-GB charges, while a gateway VPC endpoint eliminates the data processing cost entirely.

How to eliminate wrong answers

Option A is wrong because S3 Object Lambda is used to transform data as it is retrieved from S3, not to reduce data transfer costs from private subnets. Option B is wrong because AWS Shield Advanced is a DDoS protection service that does not address NAT gateway data processing charges. Option D is wrong because a larger NAT gateway would increase, not reduce, costs due to higher hourly and data processing fees.

161
Multi-Selecthard

A fleet of test servers is rebuilt every week from AMIs. EBS volumes are often left behind after termination, and the team creates daily snapshots of every volume even when nothing changes. Which three actions most reduce storage cost while preserving recovery options? Select three.

Select 3 answers
A.Use gp3 for new EBS volumes instead of gp2 when similar performance is enough.
B.Automate snapshot creation and deletion with Amazon Data Lifecycle Manager.
C.Move old snapshots to the EBS Snapshot Archive tier once they are rarely restored.
D.Keep unattached volumes around for troubleshooting after instance termination.
E.Raise provisioned IOPS on every volume so snapshot restore time feels faster.
AnswersA, B, C

Switching from gp2 to gp3 decouples IOPS and throughput from volume capacity, so you pay only for the storage size needed rather than provisioning extra gigabytes to reach a performance tier. This directly cuts the per-GB cost of the test servers' volumes while preserving equivalent baseline performance and full snapshot recovery options.

Why this answer

Option A is correct because gp3 volumes are billed at a lower per-GB price than gp2 and let you provision IOPS and throughput independently of capacity, so workloads with similar performance needs cost less without sacrificing recovery capability. Option B is correct because Amazon Data Lifecycle Manager automates snapshot creation and, crucially, retention/deletion policies, which stops the accumulation of stale daily snapshots that drive storage cost. Option C is correct because the EBS Snapshot Archive tier stores rarely restored snapshots at a substantially lower price (up to ~75% cheaper) while still preserving them as a recovery option.

Option D is wrong because leaving unattached EBS volumes after termination incurs ongoing per-GB charges and directly increases cost rather than reducing it. Option E is wrong because raising provisioned IOPS increases cost and does not address the leftover volumes or redundant snapshots, and IOPS provisioning does not meaningfully speed snapshot restore.

Exam trap

The trap here is that candidates may think keeping unattached volumes is a valid recovery option, but it is more cost-effective to snapshot and delete them, and they may overlook that raising IOPS does not accelerate snapshot restore times.

162
MCQhard

A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first? The design must avoid adding custom operational scripts.

A.Replacing every NAT gateway with an internet gateway attached to private subnets
B.Whether one NAT gateway per AZ is sufficient for the required private subnets
C.Disabling route tables
D.Moving all workloads to public subnets
AnswerB

NAT gateways are provisioned per Availability Zone, and the standard high-availability pattern is one NAT gateway per AZ, not multiple in the same AZ. If the batch analytics job runs in only one AZ or its required private subnets are all within a single AZ, a second NAT gateway in that same AZ provides no additional resilience while doubling the hourly and data-processing charges. The cost optimization is to confirm that each AZ contains at least one private subnet needing egress; if not, the NAT gateway count should be reduced to one per AZ with active private workloads.

Why this answer

The current setup uses two NAT gateways per AZ, which is likely over-provisioned and incurs unnecessary costs. Since only one private subnet per AZ requires outbound internet access, a single NAT gateway per AZ is typically sufficient to handle the traffic, and this is the first cost-optimization step to review before making other changes.

Exam trap

The trap here is that candidates may assume more NAT gateways are always better for high availability, but the question explicitly states only one private subnet per AZ needs outbound access, making a single NAT gateway per AZ the cost-optimized starting point.

How to eliminate wrong answers

Option A is wrong because internet gateways cannot be attached to private subnets; they are attached to VPCs and only work with public subnets that have a route to the IGW. Option C is wrong because disabling route tables would break all network connectivity, not just outbound internet access, and is not a valid optimization strategy. Option D is wrong because moving all workloads to public subnets would expose them directly to the internet, violating security best practices and the requirement to avoid custom operational scripts.

163
MCQmedium

A static marketing site is served through CloudFront from an S3 origin. After a product update, customers report a drop in CloudFront cache hit ratio and the CloudFront bill increases because the origin is receiving many more requests for the same JS/CSS assets. Asset URLs are versioned, but requests now include an Authorization header even though these assets are public. Which CloudFront change most directly improves the cache hit ratio for these assets?

A.Increase the origin's max connections to handle more origin fetches
B.Configure the CloudFront cache policy so Authorization is not included in the cache key, and use an origin request policy that does not forward Authorization to the S3 origin for this behavior
C.Set CloudFront minimum TTL to 0 seconds so caches expire faster and origin fetches start again
D.Disable CloudFront compression because Authorization headers are not cacheable when compression is enabled
AnswerB

For public assets, Authorization should not vary the cache key. Removing it from the cache key allows CloudFront to reuse cached objects across requests, and not forwarding it to the origin avoids unnecessary origin variation and request overhead.

Why this answer

The drop in cache hit ratio is caused by the Authorization header being included in the cache key, which makes CloudFront treat each request as unique even when the asset URL is the same. By configuring the cache policy to exclude Authorization from the cache key and using an origin request policy that does not forward it to S3, CloudFront can serve cached responses for all users regardless of their Authorization header, restoring the cache hit ratio.

Exam trap

The trap here is that candidates may think increasing origin capacity or adjusting TTLs solves the problem, but the real issue is that the Authorization header is unnecessarily varying the cache key, which is a common misconfiguration in CloudFront when public assets are served alongside authenticated content.

How to eliminate wrong answers

Option A is wrong because increasing origin max connections addresses origin load but does not fix the root cause of cache misses caused by the Authorization header in the cache key. Option C is wrong because setting minimum TTL to 0 seconds forces CloudFront to revalidate every request with the origin, which would increase origin fetches and worsen the cache hit ratio and bill. Option D is wrong because CloudFront compression does not affect cacheability of Authorization headers; the header is simply not part of the cache key by default unless explicitly included, and disabling compression would not resolve the cache key issue.

164
MCQhard

A financial services company stores regulatory documents in an Amazon S3 bucket. The documents are accessed frequently for the first 90 days, then almost never, but must remain immediately retrievable for seven years. Retrieval latency of a few minutes is unacceptable, and the company wants the lowest storage cost that still meets the access requirement. Which S3 storage class should a solutions architect recommend?

A.S3 Glacier Flexible Retrieval
B.S3 One Zone-Infrequent Access (S3 One Zone-IA)
C.S3 Glacier Instant Retrieval
D.S3 Standard-Infrequent Access (S3 Standard-IA)
AnswerC

S3 Glacier Instant Retrieval is designed for long-lived archive data that is rarely accessed but requires millisecond retrieval. It costs less than S3 Standard-IA for long-term storage and meets the requirement that documents remain immediately retrievable for seven years. A lifecycle policy can transition objects after the active 90-day period.

Why this answer

The requirement is long-term, low-cost storage with immediate retrieval and no minutes-long latency. S3 Glacier Instant Retrieval provides millisecond access at a lower storage cost than S3 Standard-IA, making it the best fit for rarely accessed documents retained for years. A lifecycle rule can move objects from S3 Standard to Glacier Instant Retrieval after the active 90-day period.

Exam trap

The trap here is assuming any Glacier class introduces retrieval delay, when S3 Glacier Instant Retrieval actually provides millisecond access and is the intended low-cost class for archive data needing immediate retrieval.

165
MCQeasy

A workload runs in private subnets. It must access AWS services such as Amazon S3, but the company wants to avoid using a NAT Gateway to reduce outbound networking costs. What is the best solution?

A.Create VPC endpoints for the required AWS services and route traffic to them
B.Attach Elastic IP addresses to instances in private subnets
C.Install a NAT Gateway in every subnet to minimize routing hops
D.Open outbound internet access with a security group rule to reach service endpoints directly
AnswerA

VPC endpoints provide private connectivity from your VPC to supported AWS services without traversing the public internet or a NAT Gateway. For example, you can use a gateway endpoint for S3 (and interface endpoints for other services where supported), which avoids NAT Gateway hourly and data-processing charges.

Why this answer

VPC endpoints (Gateway Endpoints for S3 and DynamoDB, or Interface Endpoints for other services) allow instances in private subnets to access AWS services privately without traversing the internet or a NAT Gateway. This eliminates NAT Gateway data processing and hourly charges, directly reducing outbound networking costs while keeping traffic within the AWS network.

Exam trap

The trap here is that candidates often assume private subnets must use a NAT Gateway or internet gateway for any AWS service access, overlooking that VPC endpoints provide direct, cost-free connectivity to supported services within the AWS network.

Why the other options are wrong

B

Attaching Elastic IP addresses to instances in private subnets does not provide internet access because private subnets lack a route to an internet gateway; Elastic IPs require an internet gateway to be reachable.

C

Installing a NAT Gateway in every subnet increases costs (each NAT Gateway incurs hourly and data processing charges) and does not reduce outbound networking costs as required by the question.

D

Security group rules control inbound and outbound traffic at the instance level, but they cannot provide direct private connectivity to AWS services like S3. Instances in private subnets without a NAT Gateway or VPC Endpoint cannot reach public service endpoints over the internet.

166
MCQeasy

A small e-commerce company hosts its product catalog on a single Amazon EC2 instance in a public subnet. Traffic is steady and predictable, and the instance runs 24/7. The company wants to reduce its monthly compute bill without changing the architecture or risking availability. Which action should a solutions architect recommend?

A.Move the instance to a Spot Instance to take advantage of lower hourly rates.
B.Enable detailed monitoring and create a CloudWatch alarm to stop the instance when traffic is low.
C.Purchase a one-year Standard Reserved Instance for the instance.
D.Migrate the workload to a smaller instance type and enable burstable performance.
AnswerC

A Standard Reserved Instance is ideal for a steady, always-on instance that will not change family or Region. It provides a significant discount over On-Demand in exchange for a one- or three-year commitment, and it requires no architectural change. This directly lowers the monthly compute bill while preserving availability.

Why this answer

For a steady, always-on instance that will not change family or Region, a Standard Reserved Instance delivers a substantial discount over On-Demand with no architectural change and no availability risk. It is the simplest, lowest-risk way to cut the monthly compute bill for this predictable workload.

Exam trap

The trap here is reaching for Spot because the hourly rate is lower, when the availability requirement rules out any interruptible purchasing option.

167
MCQmedium

A company runs an internal analytics application in a single AWS Region. A solutions architect is reviewing the Amazon RDS for MySQL deployment and finds a Multi-AZ DB instance with a standby in another Availability Zone, used only for failover. The application performs many read-heavy queries against the primary instance, driving up instance size and cost. The team wants to offload read traffic and reduce the primary instance size. Which change should the architect recommend?

A.Convert the deployment to a Multi-AZ DB cluster with two readable standbys.
B.Migrate the database to Amazon DynamoDB with on-demand capacity.
C.Add RDS read replicas and direct read-heavy queries to them.
D.Enable RDS Performance Insights and rely on it to reduce query cost.
AnswerC

RDS read replicas serve read-only traffic on separate instances, letting the team offload read-heavy queries and shrink the primary instance. This directly addresses the cost driver, which is an oversized primary handling both reads and writes, and it works within a single Region while the Multi-AZ standby continues to provide high availability for failover.

Why this answer

Adding RDS read replicas moves read-heavy queries onto separate instances, relieving the primary and enabling a smaller, cheaper primary instance. The Multi-AZ standby exists only for failover and cannot serve reads, so the architect should introduce read replicas rather than re-architecting the deployment or switching database engines.

Exam trap

The trap here is assuming the Multi-AZ standby can serve read traffic, when a Multi-AZ DB instance standby is strictly for failover and never handles application reads.

168
MCQmedium

A company stores millions of objects in Amazon S3. Access patterns are completely unpredictable — some objects are frequently accessed, others rarely. Objects range from 4 KB to 50 MB. The company wants to minimize storage costs automatically without managing lifecycle rules. Which storage class should a solutions architect recommend?

A.S3 Standard — it is the default and handles all access patterns equally
B.S3 Standard-IA — it automatically detects infrequent access and reduces cost
C.S3 Intelligent-Tiering — it automatically moves objects between tiers based on access patterns
D.S3 One Zone-IA — it is the cheapest option with fast retrieval
AnswerC

S3 Intelligent-Tiering continuously monitors access at the object level and automatically shifts objects between frequent, infrequent, and optional archive-access tiers based on recent usage, all without retrieval fees and without requiring lifecycle transitions. It charges only a small monthly automation/monitoring fee per object, which is economical when access behavior is unknown. This idle-tier management matches unpredictable workloads precisely, unlike the fixed tiering of Standard-IA or the constant high cost of Standard.

Why this answer

S3 Intelligent-Tiering monitors access patterns and automatically moves objects between access tiers — Frequent Access, Infrequent Access, and optional Archive tiers — based on actual usage. It requires no management or lifecycle rules.

Important: Intelligent-Tiering charges a small monitoring fee per object per month. For objects under 128 KB, this fee may exceed the storage savings. With objects ranging from 4 KB to 50 MB and unpredictable access patterns, Intelligent-Tiering is the recommended answer — AWS explicitly recommends it for unknown access patterns where object size averages above 128 KB.

Exam trap

For purely small objects (all < 128 KB), Intelligent-Tiering's monitoring cost ($0.0025 per 1,000 objects) can exceed the storage savings — Standard would be cheaper. But for mixed sizes with unpredictable access (as in this question), Intelligent-Tiering is the correct recommendation. The key phrase 'automatically without managing lifecycle rules' points to Intelligent-Tiering.

Why the other options are wrong

A

S3 Standard is the highest cost per-GB storage class and does not automatically reduce cost based on access patterns. For unpredictable access, Intelligent-Tiering is more cost-effective for objects with average size above 128 KB.

B

S3 Standard-IA does NOT automatically detect access patterns. Objects placed in Standard-IA are statically in that class. It also charges a per-GB retrieval fee making it expensive for frequently accessed objects.

D

One Zone-IA stores data in a single AZ (lower durability). It does not automatically adjust to access patterns and charges retrieval fees. It's inappropriate for data requiring standard S3 durability.

169
MCQhard

A risk simulation workload in private subnets downloads large amounts of data from S3 through a NAT gateway. NAT data processing charges are high. What should the architect use to reduce cost? The design must avoid adding custom operational scripts.

A.A larger NAT gateway
B.Gateway VPC endpoint for Amazon S3
C.S3 Object Lambda
D.AWS Shield Advanced
AnswerB

A gateway VPC endpoint for S3 installs a prefix list route (e.g., com.amazonaws.region.s3) in the VPC route table, causing S3-bound traffic to be sent directly to S3 over the AWS private network instead of through the NAT gateway. Because the data path no longer passes through the NAT gateway, the per-GB NAT data processing charge for those large downloads is eliminated. The endpoint itself is free, highly available, and requires only route table updates plus an optional endpoint policy to control access, making this the correct cost optimization.

Why this answer

A Gateway VPC Endpoint for Amazon S3 allows instances in private subnets to access S3 directly over the AWS network without traversing a NAT gateway, eliminating NAT data processing charges. This is the most cost-effective and operationally simple solution because it requires no custom scripts and no changes to routing beyond adding the endpoint.

Exam trap

The trap here is that candidates often confuse Gateway VPC Endpoints with Interface VPC Endpoints, assuming both incur hourly charges, or mistakenly think a larger NAT gateway is a cost-saving measure when it actually increases costs.

How to eliminate wrong answers

Option A is wrong because a larger NAT gateway would increase, not reduce, data processing costs (charged per GB processed) and does not address the root cause of traffic going through the NAT. Option C is wrong because S3 Object Lambda is used to transform data as it is retrieved from S3, not to reduce network egress costs or replace NAT gateway traffic. Option D is wrong because AWS Shield Advanced is a DDoS protection service that does not affect data transfer costs or routing between VPC and S3.

170
MCQeasy

A media company stores 50 TB of finalized video masters in Amazon S3 that must be retained for seven years for regulatory compliance. The files are accessed only during occasional legal audits, roughly once every two years, and retrieval latency of several hours is acceptable. The company wants the LOWEST possible storage cost while preserving durability. Which storage class should they choose?

A.S3 Glacier Flexible Retrieval
B.S3 Standard-Infrequent Access
C.S3 One Zone-IA
D.S3 Glacier Deep Archive
AnswerD

S3 Glacier Deep Archive is designed for long-term retention of data accessed less than once per year, offering the lowest storage cost of any S3 class while maintaining eleven nines of durability. Retrieval takes up to 12 hours, which fits the acceptable latency stated for rare legal audits. For 50 TB held seven years with almost no access, this class minimizes spend without sacrificing durability.

Why this answer

Data accessed less than once per year and tolerant of hours-long retrieval belongs in S3 Glacier Deep Archive, which offers the lowest per-GB storage price in S3 while retaining eleven nines of durability. Glacier Flexible Retrieval and the IA classes cost more per GB and target more frequent access patterns, so they would increase seven-year spend without adding value.

Exam trap

The trap here is reaching for a mid-tier archive class or an Infrequent Access class out of habit, when the stated access frequency of once every two years and tolerance for hours of latency points squarely at the cheapest archive tier.

← PreviousPage 3 of 3 · 170 questions total

Ready to test yourself?

Try a timed practice session using only Design Cost questions.