SAP-C02 Practice Question: Accelerate Workload Migration and Modernization
Network Topology
A company is using AWS Migration Hub to track a server migration. The migration task has failed with the error shown in the exhibit. Which action should the solutions architect take to resolve the issue?
⚠ Common exam trap
SAP-C02 often presents SSL/certificate errors alongside network errors — candidates who see 'migration failed' reach for timeout or port changes, missing that the error text specifically indicates a certificate trust problem.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the source server's SSL certificate is signed by a trusted Certificate Authority (CA).
The migration task failed due to an SSL certificate validation error, which occurs when the source server presents a certificate not signed by a trusted Certificate Authority. AWS MGN (Application Migration Service) requires a valid, trusted certificate for the replication agent's TLS connection. Ensuring the source server's SSL certificate is signed by a trusted CA resolves the handshake failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the migration port from 443 to 80.
Why it's wrong here
Changing the port to 80 does not address the exhibited error, which concerns replication agent connectivity or credentials rather than the HTTPS port used for Migration Hub API calls. Port 80 would only be relevant if a proxy blocked outbound 443 traffic to the Migration Hub endpoint.
- ✗
Retry the migration using AWS CloudEndure instead of AWS MGN.
Why it's wrong here
CloudEndure is the former name of AWS Application Migration Service, so retrying with it repeats the same MGN replication path and cannot resolve the error. Switching tools would only help if the failure stemmed from a tool-specific defect rather than the underlying connectivity or permission issue shown.
- ✗
Increase the timeout value for the migration task.
Why it's wrong here
The migration task error is not a timeout condition, so extending the timeout leaves the actual cause unresolved. Timeout increases apply when a task fails because a defined wait period elapses during data replication or cutover, not when the agent cannot establish or authenticate its connection.
- ✓
Ensure the source server's SSL certificate is signed by a trusted Certificate Authority (CA).
Why this is correct
Replacing the self-signed certificate with one issued by a trusted Certificate Authority satisfies the Migration Hub validation requirement, because the agent's TLS handshake to the service endpoint is rejected when the chain cannot be verified. A publicly trusted CA resolves that trust failure without altering network paths or agent configuration.
Visual reference
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.