SAP-C02 Practice Question: Accelerate Workload Migration and Modernization
A company is migrating a legacy on-premises .NET application to AWS. The application uses Windows Authentication and relies on Active Directory. The company wants to minimize code changes. Which solution should the architect recommend?
⚠ Common exam trap
SAP-C02 often tests the misconception that AWS identity services like Cognito or IAM can replace Active Directory for Windows Authentication, but they cannot; the key is recognizing that legacy Windows Authentication requires an actual AD domain, and AWS Managed Microsoft AD is the managed solution for that.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the application on Amazon EC2 instances joined to an AWS Managed Microsoft AD directory.
AWS Managed Microsoft AD is a fully managed Active Directory service in AWS that supports domain join for EC2 instances. By joining the EC2 instances to the directory, the legacy .NET application can continue using Windows Authentication (Kerberos/NTLM) without code changes. This preserves the existing authentication mechanism and minimizes migration effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Systems Manager to store credentials and inject them at runtime.
Why it's wrong here
Systems Manager Parameter Store holds secrets and configuration strings, not Kerberos tickets or domain identities, so Windows Authentication against Active Directory cannot function and application code would need rewriting. It suits injecting database passwords or API keys at runtime, whereas AWS Managed Microsoft AD with domain join preserves existing authentication unchanged.
- ✗
Migrate the application to Amazon WorkDocs and configure single sign-on.
Why it's wrong here
WorkDocs is a managed document storage and collaboration service with SSO, not an application hosting platform, so the .NET application cannot run there and its Windows Authentication calls have nothing to authenticate against. It would fit sharing and syncing files among staff, while AWS Managed Microsoft AD joined to EC2 preserves the existing authentication model.
- ✗
Use Amazon Cognito user pools for authentication.
Why it's wrong here
Cognito user pools issue OIDC and OAuth tokens for web and mobile applications; they do not speak Kerberos or NTLM, so the .NET application's Windows Authentication calls fail and code changes are unavoidable. Cognito suits new consumer-facing sign-in flows, whereas AWS Managed Microsoft AD with domain-joined instances keeps authentication intact.
- ✓
Deploy the application on Amazon EC2 instances joined to an AWS Managed Microsoft AD directory.
Why this is correct
Joining EC2 instances to AWS Managed Microsoft AD lets the .NET application continue using Windows Authentication and Kerberos against a managed domain, so no code changes are needed. This satisfies the minimise-code-changes constraint while retaining Active Directory integration.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.