Courseiva

SAP-C02 Practice Question: Accelerate Workload Migration and Modernization

A company is planning a large-scale migration of hundreds of applications to AWS. Which TWO strategies should the architect consider to reduce migration risks?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a wave-based migration approach with defined groups and dependencies

Option C is correct because a wave-based migration approach groups applications by dependencies, business criticality, and technical constraints, allowing the company to validate each wave before proceeding and limit the blast radius of any failures across hundreds of applications. Option D is correct because conducting a pilot migration of a small subset of applications lets the architect test the migration process, tooling (e.g., AWS Application Migration Service, AWS Database Migration Service), and runbooks on a low-risk sample, uncovering issues before committing the full portfolio. Option A is not appropriate because applying only rehosting to every application ignores the benefits of replatforming, refactoring, or repurchasing, and can carry forward technical debt and inefficiencies. Option B is incorrect because migrating all applications in a single wave maximizes risk, since a failure in one application or shared dependency can disrupt the entire migration with no incremental validation. Option E is incorrect because rolling back all migrations whenever any single application has issues is an overreactive, all-or-nothing response that would halt progress; instead, issues should be isolated and remediated per application or wave.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use only the rehosting strategy for all applications

    Why it's wrong here

    Applying rehosting to every application forgoes the risk reduction that replatforming or refactoring provides for workloads unsuited to lift-and-shift, such as those needing managed services or architectural change. Rehosting suits rapid, low-effort migrations of stable legacy applications where minimal modification is acceptable.

  • ✗

    Migrate all applications in a single wave to reduce coordination effort

    Why it's wrong here

    A single wave concentrates change across hundreds of applications simultaneously, amplifying blast radius and making rollback impractical. Waves are deliberately staggered to isolate failures and validate each increment. Batching everything together would only suit a small, tightly coupled set of applications with negligible interdependencies.

  • ✓

    Use a wave-based migration approach with defined groups and dependencies

    Why this is correct

    Wave-based migration groups applications by dependency and business function, so each wave can be migrated, tested and rolled back independently. This directly limits blast radius across hundreds of applications, satisfying the stem's requirement to reduce migration risk rather than attempting a single cutover.

  • ✓

    Conduct a pilot migration of a small subset of applications

    Why this is correct

    A pilot migration validates the migration process, tooling and runbooks against a small, low-risk subset before committing hundreds of applications. This surfaces integration, networking and cutover issues early, directly reducing the risk inherent in a large-scale migration.

  • ✗

    Roll back all migrations if any application experiences issues

    Why it's wrong here

    Rolling back every migration on any single application failure halts the whole programme and discards successful cutovers, multiplying risk rather than reducing it. It is tempting because rollback is a genuine risk control, and it would be correct as a scoped per-application rollback plan.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.